Information management device, terminal device, program, and information management method
The information management device and method enhance safe operation of machinery by managing digital keys with a communication and restriction unit to enforce safe operation conditions.
Patent Information
- Application Number
- JP2025509456
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-29
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2043-03-29
AI Technical Summary
Existing digital key systems lack the capability to ensure safe operation of machinery by restricting or releasing functions based on predetermined conditions.
An information management device and method that includes a communication unit, determination unit, and restriction unit to manage digital keys, ensuring they are set to a restricted state if predetermined conditions are not met.
Enhances safe operation of machinery by using digital keys, restricting or releasing functions as necessary, thereby encouraging safe operation.
Smart Images

Figure 0007911148000001 
Figure 0007911148000002 
Figure 0007911148000003
Abstract
Description
Technical Field
[0001] The present invention relates to an information management device, a terminal device, a program, and an information management method.
Background Art
[0002] Patent Document 1 discloses a digital key system capable of accurately estimating the distance from a vehicle to a smartphone.
[0003] In addition, there is a need to make the person driving a moving object such as a vehicle or other machine drive safely.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] The problem to be solved by the embodiments of the present invention is to provide an information management device, a terminal device, a program, and an information management method that can encourage a person driving a machine to drive safely using a digital key system.
Means for Solving the Problems
[0006] The information management device according to the embodiment includes a communication unit, a determination unit, and a restriction unit. The communication unit communicates with a first terminal device used as a digital key for performing at least one of restriction and release of at least one function of a machine. The determination unit determines that a first user using the first terminal device satisfies a predetermined condition. The restriction unit sets the digital key to a restricted state in which at least one of the restriction and release of the function cannot be performed when the predetermined condition is satisfied.
Effects of the Invention
[0007] This invention uses a digital key system to encourage safe operation by those operating machinery. [Brief explanation of the drawing]
[0008] [Figure 1] A block diagram showing an example of the main components of a digital key system and its constituent elements according to an embodiment. [Figure 2] A block diagram showing an example of the main components of a digital key system and its constituent elements according to an embodiment. [Figure 3] A flowchart showing an example of processing performed by the processor of the server device in Figure 1. [Figure 4] A flowchart showing an example of processing performed by the processor of the server device in Figure 1. [Figure 5] A flowchart showing an example of processing performed by the processor of the server device in Figure 1. [Figure 6] A flowchart showing an example of processing by the processor of the key terminal device in Figure 1. [Figure 7] A flowchart showing an example of processing by the processor of the key terminal device in Figure 1. [Figure 8] A flowchart showing an example of processing by the processor of the control unit in Figure 2. [Figure 9] A flowchart showing an example of processing by the processor of the control unit in Figure 2. [Figure 10] A flowchart showing an example of processing performed by the processor of the terminal device in Figure 2. [Modes for carrying out the invention]
[0009] The digital key system according to the embodiment will be described below with reference to the drawings. Note that the scale of the parts in the drawings used in the description of the embodiment below may have been changed as appropriate. Also, for illustrative purposes, some components may be omitted from the drawings used in the description of the embodiment below. Furthermore, in the drawings and this specification, the same reference numerals indicate the same elements. Figures 1 and 2 are block diagrams illustrating an embodiment of the digital key system 1 and an example of the main components included in the digital key system 1. Note that each component of each device may be internal or external. The digital key system 1 is a system that provides a digital key service. The digital key service is a service that enables the use of a digital key as a vehicle key. The digital key is a portable electronic device with communication capabilities, such as a smartphone, that can be used as a key. Furthermore, the digital key service is a service that can restrict the functionality of the digital key if certain conditions are not met. The digital key system 1, as an example, includes a server device 100, a key terminal device 200, a vehicle 300, and a terminal device 400. Note that the digital key system 1 may include only a part of these components. Also, while Figures 1 and 2 show one each of the server device 100, key terminal device 200, vehicle 300, and terminal device 400, the number of each component is not limited.
[0010] The server device 100, key terminal device 200, vehicle 300, and terminal device 400 are connected to a network NW. The network NW is typically a communication network including the Internet. The network NW is typically a communication network including a WAN (wide area network). The network NW may also be a communication network including a private network such as an intranet. Furthermore, the network NW may also be a communication network including a dedicated line or a public mobile phone network.
[0011] Server device 100 is a server for providing digital key services. Server device 100 manages various data in the digital key service and controls digital keys. Server device 100 includes, as an example, a processor 101, ROM (read-only memory) 102, RAM (random-access memory) 103, auxiliary storage device 104, and a communication interface 105. A bus 106 connects these parts. Server device 100 is an example of an information management device.
[0012] The processor 101 is the central part of the computer that performs calculations and control necessary for the operation of the server device 100, and performs various calculations and processes. The processor 101 is, for example, a CPU (central processing unit), MPU (micro processing unit), SoC (system on a chip), DSP (digital signal processor), GPU (graphics processing unit), ASIC (application specific integrated circuit), PLD (programmable logic device), or FPGA (field-programmable gate array). Alternatively, the processor 101 is a combination of several of these. Furthermore, the processor 101 may also be a combination of these with hardware accelerators. Based on programs such as firmware, system software, and application software stored in ROM 102 or auxiliary storage device 104, the processor 101 controls each part to realize various functions of the server device 100. The processor 101 also executes the processes described later based on the said program. Note that some or all of the said program may be incorporated into the circuit of the processor 101.
[0013] ROM102 and RAM103 are the main memory of the computer, which is centered around processor 101. The ROM 102 is a non-volatile memory used exclusively for data reading. The ROM 102 stores, for example, firmware among the above programs. Also, the ROM 102 stores data used when the processor 101 performs various processes. The RAM 103 is a memory used for data reading and writing. The RAM 103 is utilized as a work area that stores data temporarily used when the processor 101 performs various processes. The RAM 103 is typically a volatile memory.
[0014] The auxiliary storage device 104 is an auxiliary storage device of a computer centered on the processor 101. The auxiliary storage device 104 is, for example, an EEPROM (electric erasable programmable read-only memory), an HDD (hard disk drive), or a flash memory. The auxiliary storage device 104 stores, for example, system software and application software among the above programs. Also, the auxiliary storage device 104 stores data used when the processor 101 performs various processes, data generated by the processing in the processor 101, and various setting values.
[0015] The data stored in the auxiliary storage device 104 includes, as an example, a user DB (database).
[0016] The user DB is a database that stores and manages information about users who use the digital key service. The user DB stores information about each user (hereinafter referred to as "user information") in association with a user ID (identifier). Note that the user ID is identification information uniquely assigned to each user. The user information includes, for example, various settings related to the digital key service (hereinafter referred to as "key service settings") and server limit variables. Each setting included in the key service settings may have a default value. The default value is determined in advance by, for example, the designer or administrator of the key system 1 or the seller of the vehicle 300. The key service settings may include those that can be changed by the user and those that cannot be changed. The server limit variable indicates whether the digital key of the user specified by the associated user ID is in a restricted state or an unrestricted state. The restricted state and the unrestricted state will be described later.
[0017] The communication interface 105 is an interface for the server device 100 to communicate via a network NW or the like. Note that the communication interface 105 functions as an example of a communication unit that communicates with the first terminal device. Also, the communication interface 105 is an example of a communication device. Further, the processor 101 functions as an example of a communication control unit that controls the communication device to communicate with the first terminal device by controlling the communication interface 105 to communicate with the first terminal device.
[0018] The bus 106 includes a control bus, an address bus, a data bus, etc., and transmits signals exchanged between the respective parts of the server device 100.
[0019] The key terminal device 200 is a portable electronic device with communication capabilities that can be used as a digital key. The digital key can restrict and / or unlock at least one function of the vehicle 300. The key terminal device 200 is a general-purpose electronic device such as a smartphone, tablet, or smartwatch. Alternatively, the key terminal device 200 may be an electronic device dedicated to digital keys. The key terminal device 200 includes, as an example, a processor 201, ROM 202, RAM 203, auxiliary storage device 204, communication interface 205, wireless interface 206, display device 207, and input device 208. A bus 209, etc., connects these parts. The key terminal device 200 is an example of the first terminal device. The user of the key terminal device 200 is an example of the first user using the first terminal device.
[0020] The processor 201 is the central part of the computer that performs calculations and control necessary for the operation of the key terminal device 200, and performs various calculations and processes. The processor 201 is, for example, a CPU, MPU, SoC, DSP, GPU, ASIC, PLD, or FPGA. Alternatively, the processor 201 is a combination of several of these. Furthermore, the processor 201 may also be a combination of these with hardware accelerators. Based on programs such as firmware, system software, and application software stored in ROM 202 or auxiliary storage device 204, the processor 201 controls each part to realize various functions of the key terminal device 200. The processor 201 also executes the processes described later based on the said program. Note that some or all of the said program may be incorporated into the circuit of the processor 201.
[0021] ROM202 and RAM203 are the main memory of the computer, which is centered around processor 201. ROM202 is a non-volatile memory used exclusively for reading data. ROM202 stores programs such as firmware, among others. It also stores data used by the processor 201 for various processing tasks. RAM203 is memory used for reading and writing data. RAM203 is used as a work area to temporarily store data used by the processor 201 during various processes. RAM203 is typically volatile memory.
[0022] The auxiliary storage device 204 is an auxiliary storage device of a computer centered around the processor 201. The auxiliary storage device 204 is, for example, an EEPROM, HDD, or flash memory. The auxiliary storage device 204 stores, for example, system software and application software from the above-mentioned programs. Furthermore, the auxiliary storage device 204 stores data used by the processor 201 in performing various processes, data generated by the processing performed by the processor 201, and various setting values. The auxiliary storage device 204 is an example of a storage device.
[0023] The application software stored in the auxiliary storage device 204 includes a key application. The key application is application software for using the digital key service. The key application is application software that enables the key terminal device 200 to function as a digital key. The processor 201 downloads the key application, for example, via the communication interface 205. Alternatively, the processor 201 installs the downloaded key application. Or, the key application may be pre-installed on the key terminal device 200.
[0024] In order for the key terminal device 200 to function as a digital key, key information must be registered in the key application. The key application uses the key information to unlock the vehicle 300. The key application performs authentication using the key information by transmitting it to the vehicle 300. The key information is unique to each combination of the vehicle 300 and the user. By registering multiple key information entries, the key application can unlock the lock states of multiple vehicles 300 corresponding to each key information entry. Furthermore, the key information may have an expiration date. In this case, the key information is only valid within the expiration date.
[0025] A key application includes a restriction variable. This restriction variable indicates whether the digital key functioning through the key application is in a restricted or unrestricted state. The restricted and unrestricted states are described later.
[0026] Note that some or all of the digital key services require users to be logged into the digital key service in order to use them. The key terminal device 200 logs into the digital key service, for example, using a user ID. The processor 201 may perform this login automatically or based on an operation by the operator of the key terminal device 200. The key terminal device 200 stores the user ID used for login. This user ID is hereinafter referred to as the "login ID".
[0027] The communication interface 205 is an interface for the key terminal device 200 to communicate via a network NW or the like.
[0028] The wireless interface 206 is an interface for the key terminal device 200 to communicate wirelessly with the vehicle 300. The wireless interface 206 includes an antenna for wireless communication, etc.
[0029] The display device 207 displays a screen for notifying the operator of the key terminal device 200 of various information. The display device 207 is, for example, a liquid crystal display or an organic electroluminescent (EL) display.
[0030] The input device 208 accepts input from the operator of the key terminal device 200. The input device 208 may be, for example, a keyboard, keypad, touchpad, mouse, or controller. The input device 208 may also be a device for voice input. A touch panel can also be used as the display device 207 and the input device 208. In this case, the display panel of the touch panel functions as the display device 207. The touch input pointing device of the touch panel functions as the input device 208.
[0031] Bus 209 includes a control bus, an address bus, and a data bus, and transmits signals exchanged between the various parts of the key terminal device 200.
[0032] Vehicle 300 is, for example, an automobile. Vehicle 300 includes, as an example, a control device 310, a key interface 320, a door 330, a power unit 340, an electrical unit 350, and a start button 360.
[0033] The control device 310 performs various controls on the vehicle 300, for example. The control device 310 has a function to authenticate key information read from the key terminal device 200. When valid key information is authenticated, the control device 310 has a function to release the lock state of the vehicle 300 and return it to an unlocked state. In the locked state, the electronic lock 331 described later is locked, and all parts of the vehicle 300, including the power unit 340 and the electrical unit 350, cannot be started. The locked state is an example of a state in which the vehicle 300 is locked, preventing it from being driven. The locked state is an example of a state in which at least one function of the vehicle 300 is restricted. In the unlocked state, the electronic lock 331 is unlocked, and all parts of the vehicle 300, including the power unit 340 and the electrical unit 350, can be started. The control device 310 is, for example, an ECU (electronic control unit). The control device 310 includes, for example, a processor 311, ROM 312, RAM 313, auxiliary storage device 314, communication interface 315, and control interface 316. A bus 317 and the like connect these components.
[0034] The processor 311 is the central part of the computer that performs calculations and control necessary for the operation of the vehicle 300, and performs various calculations and processes. The processor 311 is, for example, a CPU, MPU, SoC, DSP, GPU, ASIC, PLD, or FPGA. Alternatively, the processor 311 is a combination of several of these. Furthermore, the processor 311 may be a combination of these with hardware accelerators. Based on programs such as firmware, system software, and application software stored in the ROM 312 or auxiliary storage device 314, the processor 311 controls each part to realize various functions of the vehicle 300. The processor 311 also executes the processes described later based on the said programs. Note that some or all of the said programs may be incorporated into the circuit of the processor 311.
[0035] ROM312 and RAM313 are the main memory of the computer, which is centered around processor 311. ROM312 is a non-volatile memory used exclusively for reading data. ROM312 stores programs such as firmware. It also stores data used by the processor 311 for various processing tasks. RAM313 is memory used for reading and writing data. RAM313 is used as a work area to store data that the processor 311 temporarily uses when performing various processes. RAM313 is typically volatile memory.
[0036] The auxiliary storage device 314 is an auxiliary storage device of a computer centered on the processor 311. The auxiliary storage device 314 is, for example, an EEPROM, HDD, or flash memory. The auxiliary storage device 314 stores, for example, system software and application software from the above-mentioned programs. The auxiliary storage device 314 also stores data used by the processor 311 in performing various processes, data generated by processing by the processor 311, and various setting values.
[0037] The data stored in the auxiliary storage device 314 includes the vehicle ID and vehicle configuration information of the vehicle 300 equipped with it. The vehicle ID is a unique identification information for each vehicle 300. The vehicle configuration information includes settings related to the operation of the vehicle 300 among the settings related to the digital key service. Each setting included in the vehicle configuration information may have a default value. The default value is predetermined, for example, by the designer or administrator of the key system 1 or the seller of the vehicle 300. Some of the vehicle configuration information may be changeable by the user, while others may not.
[0038] The communication interface 315 is an interface for the vehicle 300 to communicate via a network NW or the like.
[0039] The control interface 316 is an interface for the control device 310 to communicate with various parts of the vehicle 300. The control device 310 controls various parts of the vehicle 300 via the control interface 316. These parts include, for example, the key interface 320, the doors 330, the power unit 340, the electrical unit 350, and the start button 360.
[0040] Bus 317 includes a control bus, an address bus, and a data bus, and transmits signals exchanged between the various parts of the control device 310.
[0041] The key interface 320 is an interface for wireless communication with the key terminal device 200, which functions as a digital key. The key interface 320 includes an antenna for wireless communication, etc.
[0042] Door 330 is a door for entering and exiting the vehicle 300. Door 330 is, for example, a door for entering and exiting the driver's seat, which is the place for driving the vehicle 300. Door 330 is equipped with an electronic lock 331.
[0043] The electronic lock 331 is an electronic lock that can be unlocked with a digital key.
[0044] The power unit 340 consists of components and equipment necessary for the vehicle 300 to run. The power unit 340 includes, for example, a power unit, battery, and drive system. The power unit is, for example, an engine or motor.
[0045] The electrical components 350 consist of electrical system parts and equipment. Examples of electrical components 350 include car air conditioners, in-car Wi-Fi, in-car entertainment systems, car audio systems, in-car displays, car navigation systems, in-car devices, and instruments.
[0046] The start button 360 is a button used to start some or all of the power unit 340 and the electrical unit 350.
[0047] Terminal device 400 is a device that can view various information related to the digital key service and change various settings. Terminal device 400 is, for example, a PC (personal computer), a tablet terminal, or a smartphone. Terminal device 400 may also be the key terminal device 200. Terminal device 400 includes, as an example, a processor 401, ROM 402, RAM 403, auxiliary storage device 404, communication interface 405, display device 406, and input device 407. A bus 408 connects these parts. Terminal device 400 is an example of a second terminal device. Also, the user of terminal device 400 is an example of a second user using the second terminal device.
[0048] The application software stored in the terminal device 400 includes a browsing application. The browsing application is application software that allows users to view various information related to the digital key service and change various settings. The browsing application may be general-purpose application software such as a web browser, or it may be application software specifically for the digital key system 1.
[0049] The terminal device 400 logs into the digital key service in the same way as the key terminal device 200. The terminal device 400 stores the login ID.
[0050] The processor 401 is the central part of the computer that performs calculations and control necessary for the operation of the terminal device 400, and performs various calculations and processes. The processor 401 is, for example, a CPU, MPU, SoC, DSP, GPU, ASIC, PLD, or FPGA. Alternatively, the processor 401 is a combination of several of these. Furthermore, the processor 401 may also be a combination of these with hardware accelerators. The processor 401 controls each part to realize various functions of the terminal device 400 based on programs such as firmware, system software, and application software stored in the ROM 402 or auxiliary storage device 404. The processor 401 also executes the processes described later based on the said program. Note that some or all of the said program may be incorporated into the circuit of the processor 401.
[0051] ROM402 and RAM403 are the main memory of the computer, which is centered around processor 401. ROM402 is a non-volatile memory used exclusively for reading data. ROM402 stores programs such as firmware. It also stores data used by the processor 401 for various processing tasks. RAM403 is memory used for reading and writing data. RAM403 is used as a work area to temporarily store data used by the processor 401 during various processes. RAM403 is typically volatile memory.
[0052] The auxiliary storage device 404 is an auxiliary storage device of a computer centered on the processor 401. The auxiliary storage device 404 is, for example, an EEPROM, HDD, or flash memory. The auxiliary storage device 404 stores, for example, system software and application software from the above-mentioned programs. The auxiliary storage device 404 also stores data used by the processor 401 in performing various processes, data generated by processing by the processor 401, and various setting values.
[0053] The communication interface 405 is an interface for the terminal device 400 to communicate via a network NW or the like.
[0054] The display device 406 displays a screen for notifying the operator of the terminal device 400 of various information. The display device 406 is, for example, a liquid crystal display or an organic EL display.
[0055] The input device 407 accepts input from the operator of the terminal device 400. The input device 407 may be, for example, a keyboard, keypad, touchpad, mouse, or controller. The input device 407 may also be a device for voice input. A touch panel can also be used as the display device 406 and the input device 407. In this case, the display panel of the touch panel functions as the display device 406, and the touch input pointing device of the touch panel functions as the input device 407.
[0056] Bus 408 includes a control bus, an address bus, and a data bus, and transmits signals exchanged between various parts of the terminal device 400.
[0057] The operation of the digital key system 1 according to this embodiment will be described below with reference to Figures 3 to 10 and others. Note that the processing content in the following operation description is an example, and various processing that can obtain similar results can be used as appropriate. Figures 3 to 5 are flowcharts showing an example of processing by the processor 101 of the server device 100. The processor 101 executes the processing in Figures 3 to 5 based on a program stored in, for example, ROM 102 or auxiliary storage device 104. The processor 101 executes the processing in Figures 3 to 5 in parallel or in parallel. Figures 6 and 7 are flowcharts showing an example of processing by the processor 201 of the key terminal device 200. The processor 201 executes the processing in Figures 6 and 7 based on a program stored in, for example, ROM 202 or auxiliary storage device 204. Figures 8 and 9 are flowcharts showing an example of processing by the processor 311 of the control device 310. The processor 311 executes the processing in Figures 8 and 9 based on a program stored in, for example, ROM 312 or auxiliary storage device 314. The processor 311 executes the processes shown in Figures 8 and 9 in parallel or in parallel, for example. Figure 10 is a flowchart showing an example of processing by the processor 401 of the terminal device 400. The processor 401 executes the processes shown in Figure 10 based on a program stored in, for example, the ROM 402 or the auxiliary storage device 404.
[0058] In step ST61 of Figure 6, the processor 201 of the key terminal device 200 determines whether or not to change the key service settings. If the processor 201 determines that it does not want to change the key service settings, it determines No in step ST61 and proceeds to step ST62.
[0059] In step ST62, the processor 201 determines whether or not to register new key information. If the processor 201 does not determine to register new key information, it determines No in step ST62 and proceeds to step ST63.
[0060] In step ST63, the processor 201 determines whether or not to connect to the key interface 320. If the processor 201 does not determine to connect to the key interface 320, it determines No in step ST63 and proceeds to step ST64.
[0061] In step ST64, the processor 201 determines whether or not a restriction request has been received via the communication interface 205. If no restriction request has been received, the processor 201 determines "No" in step ST64 and proceeds to step ST65.
[0062] In step ST65, the processor 201 determines whether or not notification information has been received via the communication interface 205. If no notification information has been received, the processor 201 determines "No" in step ST65 and proceeds to step ST66.
[0063] In step ST66, the processor 201 determines whether or not to start checking the operating status. If the processor 201 does not decide to start checking the operating status, it determines No in step ST64 and proceeds to step ST67.
[0064] In step ST67, the processor 201 determines whether or not a restriction release request has been received via the communication interface 205. If no restriction release request has been received, the processor 201 determines "No" in step ST67 and proceeds to step ST68.
[0065] In step ST68, the processor 201 determines whether or not to lock the vehicle 300. For example, if an operation to instruct the vehicle 300 to be locked is performed using the input device 208, the processor 201 determines to lock the vehicle 300. If the processor 201 does not determine to lock the vehicle 300, it determines No in step ST68 and returns to step ST61. Thus, the processor 201 enters a waiting state, repeating steps ST61 in Figure 6 to ST68 in Figure 7 until it determines to change the key service settings, register new key information, connect to the key interface 320, start checking the driving status, receive a restriction request, notification information, or restriction release request, or determines to lock the vehicle 300. Notification information, restriction requests, and restriction release requests will be described later.
[0066] If the operator of the key terminal device 200 wants to change the key service settings, they input the changes to the key service settings, for example, by operating the input device 208. The processor 201 determines, based on the input, that the key service settings should be changed.
[0067] If processor 201 determines that it wants to change the key service settings while in a waiting state repeating steps ST61 in Figure 6 to step ST68 in Figure 7, it determines Yes in step ST61 in Figure 6 and proceeds to step ST68.
[0068] In step ST69, the processor 201 generates a change request. The change request includes, for example, a login ID and change information. The change information indicates the changes to the key service settings. After generating the change request, the processor 201 instructs the communication interface 205 to send the change request to the server device 100. Upon receiving this instruction, the communication interface 205 sends the change request to the server device 100. The transmitted change request is received by the communication interface 105 of the server device 100. After processing in step ST69, the processor 201 returns to step ST61.
[0069] Meanwhile, in step ST11 of Figure 3, the processor 101 of the server device 100 determines whether or not a change request has been received via the communication interface 105. If no change request has been received, the processor 101 determines "No" in step ST11 and proceeds to step ST12.
[0070] In step ST12, the processor 101 determines whether or not a key request has been received via the communication interface 105. If no key request has been received, the processor 101 determines "No" in step ST12 and proceeds to step ST13.
[0071] In step ST13, the processor 101 determines whether or not a start request has been received via the communication interface 105. If no start request has been received, the processor 101 determines "No" in step ST13 and proceeds to step ST14.
[0072] In step ST14, the processor 101 determines whether or not an acknowledgment has been received via the communication interface 105. If no acknowledgment has been received, the processor 101 determines "No" in step ST14 and returns to step ST11. Thus, the processor 101 enters a waiting state, repeating steps ST11 to ST14 until a change request, key request, start request, or acknowledgment is received. Key requests, start requests, and acknowledgments will be described later.
[0073] If a change request is received while the processor 101 is in a waiting state repeating steps ST11 to ST14, it determines "Yes" in step ST11 and proceeds to step ST15.
[0074] In step ST15, the processor 101 modifies the key service settings by updating the user DB based on the change request received in step ST11. That is, the processor 101 modifies the key service settings associated with the user ID included in the change request according to the change information included in the change request.
[0075] Furthermore, if the changes to the key service settings include those that require a change in the operation of the vehicle 300, the processor 101 generates setting information. The setting information indicates the settings that will change the operation of the vehicle 300. After generating the setting information, the processor 101 instructs the communication interface 105 to send the setting information to the control device 310. Upon receiving this instruction, the communication interface 105 sends the setting information to the control device 310. The transmitted setting information is received by the communication interface 315 of the control device 310. After processing in step ST15, the processor 101 returns to step ST11.
[0076] On the other hand, in step ST91 of Figure 8, the processor 311 of the control device 310 determines whether or not setting information has been received via the communication interface 315. If no setting information has been received, the processor 311 determines "No" in step ST91 and proceeds to step ST92.
[0077] In step ST92, the processor 311 determines whether or not to transmit driving data. If the processor 311 does not determine to transmit driving data, it determines "No" in step ST92 and returns to step ST91. Thus, the processor 311 enters a waiting state, repeating steps ST91 and ST92 until setting information is received or it determines to transmit driving data. Driving data will be described later.
[0078] If the processor 311 receives configuration information while in a waiting state repeating steps ST91 and ST92, it determines "Yes" in step ST91 and proceeds to step ST93.
[0079] In step ST93, the processor 311 updates the vehicle configuration information according to the configuration information received in step ST91. After processing in step ST93, the processor 311 returns to step ST91.
[0080] When an operator of the key terminal device 200 wants to register new key information in the key application, they provide input to the key terminal device 200 instructing it to register new key information in a predetermined manner. The processor 201, for example, determines to register a new digital key in response to the input instructing it to register new key information.
[0081] If the processor 201 determines that it is time to register a new digital key while in a waiting state repeating steps ST61 in Figure 6 to step ST68 in Figure 7, it determines Yes in step ST62 and proceeds to step ST70 in Figure 6.
[0082] In step ST70, the processor 201 generates a key request. The key request includes target information. The key request is information requesting the transmission of key information identified by the target information. The target information is information that can identify the vehicle 300 that the key information targets and the user who will use the key information. After generating the key request, the processor 201 instructs the communication interface 315 to send the key request to the server device 100. Upon receiving this transmission instruction, the communication interface 315 transmits the key request to the server device 100. The transmitted key request is received by the communication interface 105 of the server device 100.
[0083] Meanwhile, if the processor 101 of the server device 100 receives a key request while in a waiting state repeating steps ST11 to ST14 in Figure 3, it determines "Yes" in step ST12 and proceeds to step ST16.
[0084] In step ST16, the processor 101 generates key information according to the target information contained in the key request received in step ST12.
[0085] In step ST17, the processor 101 generates a key response. The key response includes key information generated in step ST16. The key response is, for example, information instructing the registration of the key information. After generating the key response, the processor 101 instructs the communication interface 105 to send the key response to the key terminal device 200 that sent the key request. Upon receiving this instruction, the communication interface 105 sends the key response to the key terminal device 200. The transmitted key response is received by the communication interface 315 of the key terminal device 200. After processing in step ST17, the processor 101 returns to step ST11.
[0086] Meanwhile, in step ST71 of Figure 6, the processor 201 of the key terminal device 200 is waiting for a key response to be received via the communication interface 315. If a key response is received, the processor 201 determines Yes in step ST71 and proceeds to step ST72.
[0087] In step ST72, the processor 201 registers the key information contained in the key response received in step ST71 into the key application. At this time, the processor 201 stores the key information in the auxiliary storage device 204. After processing in step ST72, the processor 201 returns to step ST61.
[0088] The processor 201 determines, for example, to connect to the key interface 320 when the distance between the key terminal device 200 and the key interface 320 becomes within a predetermined distance. The processor 201 determines to connect to the key interface 320 when it receives radio waves transmitted by the key interface 320. The processor 201 determines to connect to the key interface 320 when it becomes possible to communicate with the key interface 320. The processor 201 determines to connect to the key interface 320 when, for example, the holder of the key terminal device 200 touches the door 330.
[0089] If the processor 201 determines to connect to the key interface 320 while in a waiting state repeating steps ST61 in Figure 6 to step ST68 in Figure 7, it determines Yes in step ST63 and proceeds to step ST73 in Figure 6.
[0090] In step ST73, the processor 201 establishes communication between the wireless interface 206 and the key interface 320.
[0091] In step ST74, the processor 201 determines whether the digital key is in a restricted state or not. If the digital key is not in a restricted state, i.e., if the digital key is in an unrestricted state, the processor 201 determines No in step ST74 and proceeds to step ST75. The restricted and unrestricted states will be explained later.
[0092] In step ST75, the processor 201 generates an unlock request. The unlock request is information requesting that the vehicle 300 be released from its locked state. The unlock request includes, for example, a login ID, a restriction variable stored in the auxiliary storage device 204, and key information registered in the key application. The value of the restriction variable is a value indicating an unrestricted state. After generating the unlock request, the processor 201 instructs the wireless interface 206 to send the unlock request to the vehicle 300. Upon receiving this instruction, the wireless interface 206 sends the unlock request to the vehicle 300. The transmitted unlock request is received by the key interface 320 of the vehicle 300. After processing in step ST75, the processor 201 returns to step ST61.
[0093] Based on the above, the processor 201 of the key terminal device 200 functions as an example of a digital key unit that enables the first terminal device to function as a digital key by executing the processes of steps ST63 and ST73 to ST75 in Figure 6.
[0094] For example, if the vehicle 300 enters a locked state, the processor 311 of the control device 310 starts the process shown in Figure 9. In step ST101 of Figure 9, the processor 311 of the control device 310 determines whether or not an unlock request has been received by the key interface 320. If no unlock request has been received, the processor 311 determines "No" in step ST101 and proceeds to step ST102.
[0095] In step ST102, the processor 311 determines whether or not to lock the vehicle 300. If the processor 311 does not determine to lock the vehicle 300, it determines No in step ST102 and returns to step ST101. Thus, the processor 311 enters a waiting state, repeating steps ST101 and ST102 until it receives an unlock request or determines to lock the vehicle 300.
[0096] If the processor 311 receives a lock release request while in a waiting state repeating steps ST101 and ST102, it determines Yes in step ST101 and proceeds to step ST103.
[0097] In step ST103, the processor 311 performs authentication using the key information included in the unlock request received in step ST101. The processor 311 then determines whether the authentication was successful or not. If the authentication was unsuccessful, the processor 311 determines No in step ST103 and returns to step ST101. Conversely, if the authentication was successful, the processor 311 determines Yes in step ST103 and proceeds to step ST104.
[0098] In step ST104, the processor 311 refers to the restriction variable included in the unlock request received in step ST101 to determine whether the digital key is in a restricted state. If the digital key is not in a restricted state, the processor 311 determines No in step ST104 and proceeds to step ST104.
[0099] In step ST105, the processor 311 controls the electronic lock 331 to unlock it. This allows the holder of the key terminal device 200 to enter the vehicle 300. Once inside the vehicle 300, the holder or other person who wishes to start the various parts of the vehicle 300, such as the power unit 340, performs an operation to start the vehicle 300, such as operating the start button 360.
[0100] In step ST106, the processor 311 waits for an operation to start the vehicle 300. That is, the processor 311 waits for a predetermined operation, such as pressing the start button 360, to be performed. If an operation to start the vehicle 300 is performed, the processor 311 determines Yes in step ST106 and proceeds to step ST107.
[0101] In step ST107, the processor 311 refers to the restriction variable included in the unlock request received in step ST101 to determine whether the digital key is in a restricted state. If the digital key is not in a restricted state, the processor 311 determines No in step ST107 and proceeds to step ST108.
[0102] In step ST108, the processor 311 starts the various parts of the vehicle 300. After the processing in step ST108, the processor 311 completes the process shown in Figure 9.
[0103] Vehicle 300 has a function to record driving data for each driver. The driver of vehicle 300 is identified by the user ID included in the unlock request received in step ST101 of Figure 9. The control device 310 records driving data using, for example, various sensors. The driving data includes, for example, the driving route, speed history, acceleration history, jerk history, brake opening history, brake timing history, sudden braking occurrence history, accelerator opening history, accelerator timing history, steering angle history, steering timing history, lane departure occurrence history, collision mitigation brake operation history, failure to stop at stop signs, failure to signal at intersections, etc., failure to slow down at intersections, etc., history of driving in the wrong direction, speeding occurrence history, excessive acceleration due to speeding, information indicating whether each road on the driving route is a highway, information indicating whether the driver recognized each road sign that should be checked while driving, driver drowsiness occurrence history, and the driver's health status. Furthermore, the vehicle 300 has a function to transmit the driving data to the server device 100. The control device 310 transmits the driving data at a predetermined timing, for example. The predetermined timing is, for example, a periodic timing. Alternatively, the predetermined timing is when the driver has finished driving the vehicle 300. Alternatively, the predetermined timing is when the vehicle 300 has entered a locked state. The processor 311 of the control device 310 determines to transmit the driving data when the predetermined timing has arrived.
[0104] If the processor 311 determines that it is time to transmit driving data while in a waiting state repeating steps ST91 and ST92 in Figure 8, it determines Yes in step ST92 and proceeds to step ST94.
[0105] In step ST94, the processor 311 retrieves any untransmitted driver driving data from the unlock request received in step ST101 in Figure 9, which is identified by the user ID.
[0106] In step ST95 of Figure 8, the processor 311 generates driving data information. The driving data information includes the driving data acquired in step ST94 and the user ID included in the unlock request received in step ST101 of Figure 9. After generating the driving data information, the processor 311 instructs the communication interface 315 to send the driving data information to the server device 100. Upon receiving this instruction, the communication interface 315 sends the driving data information to the server device 100. The transmitted driving data information is received by the communication interface 105 of the server device 100. After processing in step ST95, the processor 311 returns to step ST91.
[0107] Meanwhile, in step ST31 of Figure 4, the processor 101 of the server device 100 is waiting for driving data information to be received via the communication interface 105. If the driving data information is received, the processor 101 determines Yes in step ST31 and proceeds to step ST32.
[0108] In step ST32, the processor 101 analyzes the driving data included in the driving data information received in step ST31. This analysis includes diagnosing the driving conditions. The processor 101 may also use driving data previously stored in the user database for analysis.
[0109] The processor 101 acquires driving data by controlling the communication interface 105 to receive driving data information. The processor 101 acquires the results of the driving data analysis by executing the process in step ST32. Therefore, the processor 101 functions as an example of an acquisition unit that acquires the operating status of the machine by a first user by performing at least one of receiving driving data information and executing the process in step ST32.
[0110] In step ST33, the processor 101 stores the driving data included in the driving data information received in step ST31 and the analysis results from step ST32 in the user database, associating them with the user ID included in the driving data information.
[0111] Therefore, the processor 101 functions as an example of a memory unit that stores the operating status by cooperating with the auxiliary storage device 104 to perform the processing in step ST33. Alternatively, the processor 101 functions as an example of a memory unit by controlling the auxiliary storage device 104 to perform the processing in step ST33.
[0112] In step ST34, the processor 101 determines whether or not to restrict the digital key used by the user and put it into a restricted state, based on the driving data and the analysis results from step ST32. The user in question is the user identified by the user ID included in the driving data information received in step ST31. For example, if the processor 101 determines that there is a problem with the user's driving that warrants restricting the digital key, it decides to put the digital key into a restricted state. Examples of situations where the digital key is deemed to have a problem serious enough to warrant restrictions include: the number of sudden brakes exceeding a predetermined number; the number of lane departures exceeding a predetermined number; the collision mitigation brake activating exceeding a predetermined number of times; the number of times the driver fails to stop at stop signs exceeding a predetermined number of times; the number of times the driver fails to signal at intersections exceeding a predetermined number of times; the number of times the driver drives in the wrong direction exceeding a predetermined number of times; the driver exceeding a predetermined speed limit with excessive acceleration; the frequency of highway use is within a predetermined frequency range; the number of times the driver fails to recognize road signs that should be checked while driving exceeds a predetermined number of times; the driver falls asleep at the wheel for a predetermined number of times or for a predetermined duration exceeding a predetermined number of times; the frequency of driving is less than a predetermined frequency; the driver's health is determined to be poor; and other abnormal or dangerous driving is detected. The processor 101 may also consider the user's driving to be unsafe as a problem serious enough to warrant restrictions on the digital key. If the processor 101 does not decide to restrict the digital key, it determines No in step ST34 and returns to step ST31. On the other hand, if processor 101 determines that the digital key should be put into a restricted state, it determines Yes in step ST34 and proceeds to step ST35.
[0113] Based on the above, the processor 101 functions as an example of a determination unit that determines whether a first user using the first terminal device meets predetermined conditions by executing the process in step ST34. Furthermore, a problem that is equivalent to restricting the use of a digital key is an example of a problem with the first user's operation. Therefore, the predetermined condition in step ST34 is that there is a problem with the first user's operation.
[0114] In step ST35, the processor 101 updates the user database to set the value of the server restriction variable associated with the user ID included in the driving data information received in step ST31 to a value indicating the restriction status. The processor 101 also updates the user database to reset the date and time when each user last checked the driving status identified by that user ID. The date and time for checking the driving status will be described later.
[0115] In step ST36, the processor 101 instructs the communication interface 105 to send a restriction request to the key terminal device 200 used by the user ID included in the driving data information received in step ST31. The restriction request is information that instructs the digital key to be put into a restricted state. Upon receiving this instruction to send, the communication interface 105 sends the restriction request to the key terminal device 200. The transmitted restriction request is received by the communication interface 315 of the key terminal device 200. After processing in step ST36, the processor 101 returns to step ST31.
[0116] Based on the above, the processor 101 functions as an example of a restriction unit that, when certain conditions are met, puts the digital key into a restricted state where at least part of the machine's lock cannot be released by executing the process of sending a restriction request. Alternatively, the processor 101 functions as an example of a restriction unit by cooperating with the communication interface 105 to send a restriction request.
[0117] On the other hand, if the processor 201 of the key terminal device 200 receives a restriction request while in a waiting state repeating steps ST61 in Figure 6 to ST68 in Figure 7, it determines Yes in step ST64 and proceeds to step ST78 in Figure 7.
[0118] In step ST78, processor 201 sets the digital key to a restricted state. To do this, processor 201 rewrites the value of the restriction variable to a value indicating the restricted state.
[0119] Based on the above, the processor 201, in cooperation with the auxiliary storage device 204, performs the processing in step ST78 in response to the receipt of a restriction request, and functions as an example of a restriction storage device that stores that the digital key is in a restricted state in accordance with the control of the restriction unit. Furthermore, the processor 201 also functions as an example of a restriction storage device that stores in the storage device that the digital key is in a restricted state in accordance with the control of the restriction unit, by performing the processing in step ST78 in response to the receipt of a restriction request.
[0120] In step ST79, the processor 201 notifies the holder of the key terminal device 200 that the digital key has entered a restricted state. For example, the processor 201 displays an image on the display device 207 indicating that the digital key has entered a restricted state and that the restriction will be released once the operating status is confirmed. The processor 201 may also notify by outputting sound from the speaker, illuminating a light-emitting device, or vibrating a vibrator. Alternatively, the processor 201 may notify by push notification. After processing in step ST79, the processor 201 returns to step ST61 in Figure 6.
[0121] Users of the digital key service can check the driving status of vehicle 300, whether driven by themselves or other users. The driving status is based on the driving data and analysis results stored in step ST33.
[0122] Furthermore, the digital key system 1 has a function to restrict the use of the digital key by a user (hereinafter referred to as the "driving user" for distinction purposes) if the driving status of the driving user has not been confirmed by a predetermined user (hereinafter referred to as the "designated user" for distinction purposes) within a predetermined period P1. The predetermined period P1 is, for example, the period from the present to a predetermined time ago. This predetermined time can be determined by hours, days, weeks, months, or years. The driving user and the designated user may be the same or different. Which user the designated user is is determined by the driving user's key service settings. For example, the designated user may be a family member or user of the driving user. There may be multiple designated users. If there are multiple designated users, the driving user may or may not be included. If there are multiple designated users, the digital key system 1 restricts the use of the digital key if, for example, none of the designated users have confirmed the driving status within the predetermined period P1. Alternatively, if there are multiple designated users, the digital key system 1 restricts the use of the digital key if at least N of the designated users have not confirmed the driving status within the predetermined period P1. N is an integer greater than or equal to 1 and less than the number of specified users. The conditions for restricting the digital key when there are multiple specified users are determined, for example, by the driver user's key service settings. The conditions for restricting the digital key when there is only one specified user are that the driving status has not been confirmed by the specified user within a specified period P1. The condition for restricting the digital key due to the driver user's driving status not being confirmed by the specified user within a specified period P1 is referred to as "the deadline for confirming the driving status has passed." The length of the specified period P1 is determined, for example, by the driver user's key service settings. Note that the specified period P1 is an example of a first specified period.
[0123] In step ST41 of Figure 5, the processor 101 of the server device 100 determines whether there are any operating users whose operating status check period has exceeded the deadline and is less than or equal to a predetermined period P2. The processor 101 makes this determination by, for example, referring to the user database. The user database stores the date and time when a predetermined user last checked the operating status for each operating user. If there are no operating users whose operating status check period has exceeded the deadline and is less than or equal to the predetermined period P2, the processor 101 determines No in step ST41 and proceeds to step ST42.
[0124] In step ST42, the processor 101 determines whether or not there are any operating users whose operating status check has expired. The processor 101 makes this determination by, for example, referring to the user DB. If there are no operating users whose operating status check has expired, the processor 101 determines No in step ST42 and returns to step ST41. Thus, the processor 101 enters a waiting state in which steps ST41 and ST42 are repeated until the period until the operating status check expires becomes less than or equal to a predetermined period P2, or until the operating status check expires.
[0125] When the processor 101 is in a waiting state repeating steps ST41 and ST42, if it determines that there is a user whose operating status check period has exceeded the deadline and is less than or equal to a predetermined period P2, it determines Yes in step ST41 and proceeds to step ST43.
[0126] In step ST43, the processor 101 instructs the communication interface 105 to transmit first notification information to the key terminal device 200 used by the driver user whose period until the deadline for checking the operating status has passed is less than or equal to a predetermined period P2, and to the terminal device 400 used by a predetermined user other than the driver user among the predetermined users of the driver user. The first notification information is information indicating that the deadline for checking the operating status is about to be exceeded. The first notification information is a type of notification information. Upon receiving this transmission instruction, the communication interface 105 transmits the first notification information to the key terminal device 200 and the terminal device 400. The transmitted first notification information is received by the communication interface 315 of the key terminal device 200. The transmitted first notification information is received by the communication interface 405 of the terminal device 400. After processing in step ST43, the processor 101 returns to step ST41.
[0127] An example of a second predetermined period is a period during which the period during which the operating status has not been checked is less than or equal to a predetermined period P1, and the period during which the operating status has not been checked is less than or equal to a predetermined period P2. Expressed as a formula, this is (second predetermined period) = (predetermined period P1) - (predetermined period P2). Therefore, by executing the processes of steps ST41 and ST43, the processor 101 functions as an example of a notification control unit that notifies the first terminal device that a predetermined condition is likely to be met if the period during which the first user has not checked the operating status is less than or equal to the first predetermined period, and the period during which the operating status has not been checked is less than or equal to the second predetermined period.
[0128] On the other hand, if notification information is received while the processor 201 of the key terminal device 200 is in a waiting state repeating steps ST61 in Figure 6 to step ST68 in Figure 7, it determines Yes in step ST65 and proceeds to step ST80 in Figure 7.
[0129] In step ST80, the processor 201 notifies the user of the content indicated by the notification information. For example, the processor 201 displays an image on the display device 207 indicating that the deadline for checking the operating status is about to expire. The processor 201 may also notify the user by outputting sound from the speaker, illuminating a light-emitting device, or vibrating a vibrator. The processor 201 may also notify the user via push notification. After processing in step ST80, the processor 201 returns to step ST61 in Figure 6.
[0130] The processor 401 of the terminal device 400 performs the same processing as the processor 201 of the key terminal device 200 in parts of Figures 6 and 7, as shown in Figure 10. These parts are steps ST61, ST65, ST66, ST69, and ST80 to ST84. Regarding the processing of the processor 401 of the terminal device 400 in Figure 10, the part that is the same as the processing of the processor 201 of the key terminal device 200 in Figures 6 and 7 will not be explained. However, the processing of the processor 401 in Figure 10 is the same as the processing of the processor 201 of the key terminal device 200 in Figures 6 and 7, except that "key terminal device 200" is read as "terminal device 400", "processor 201" as "processor 401", "communication interface 205" as "communication interface 405", "display device 207" as "display device 406", and "input device 208" as "input device 407".
[0131] If the processor 401 of the terminal device 400 determines No in step ST61 in Figure 10, it proceeds to step ST65. If the processor 401 determines No in step ST66, it returns to step ST61. Thus, the processor 401 remains in a waiting state, repeating steps ST61, ST65, and ST66 in Figure 10 until it determines that the key service setting needs to be changed, that notification information has been received, or that it needs to start checking the operating status.
[0132] On the other hand, when the processor 101 of the server device 100 is in a waiting state repeating steps ST41 and ST42 in Figure 5, if it determines that there is an operating user whose operating status has exceeded the deadline for checking the operating status, it determines Yes in step ST42 and proceeds to step ST44.
[0133] In step ST44, the processor 101 updates the user DB to change the value of the server limit variable associated with the user ID of a user whose operating status check has exceeded the deadline to a value indicating the limit status.
[0134] In step ST45, the processor 101 instructs the communication interface 105 to send a restriction request to the key terminal device 200 used by the driver whose operating status check has exceeded the deadline. Upon receiving this instruction, the communication interface 105 sends the restriction request to the key terminal device 200. The transmitted restriction request is received by the communication interface 315 of the key terminal device 200.
[0135] Based on the above, the processor 101 functions as an example of a determination unit that determines whether a predetermined condition is met by executing the process in step ST42, which is used by a first terminal device that functions as a digital key used to unlock a lock that prevents the machine from being operated. The predetermined condition in step ST42 when the operating user is the predetermined user is that the first user has not checked the operating status for a first predetermined period of time or longer. The predetermined condition in step ST42 when someone other than the operating user is the predetermined user is that a second user has not checked the operating status for a first predetermined period of time or longer.
[0136] In step ST46, the processor 101 instructs the communication interface 105 to transmit second notification information to a terminal device 400 used by a predetermined user other than the operating user, among the predetermined users of the operating user whose operating status check has exceeded the deadline. The second notification information is information indicating that the operating status check has exceeded the deadline. The second notification information is a type of notification information. Upon receiving this transmission instruction, the communication interface 105 transmits the second notification information to the terminal device 400. The transmitted second notification information is received by the communication interface 405 of the terminal device 400. After processing in step ST46, the processor 101 returns to step ST41.
[0137] Furthermore, after processing in step ST36 in Figure 4, the processor 101 proceeds to step ST37. In step ST37, the processor 101 instructs the communication interface 105 to transmit the second notification information to a terminal device 400 used by a predetermined user other than the operating user, among the predetermined users of the operating user whose operating status check has exceeded the deadline. Upon receiving this transmission instruction, the communication interface 105 transmits the second notification information to the terminal device 400. The transmitted second notification information is received by the communication interface 405 of the terminal device 400.
[0138] If the operator of the key terminal device 200 wishes to check the operating status, they may, for example, use the input device 208 to make an operation input indicating that they want to start checking the operating status. The processor 201 of the key terminal device 200 may, for example, determine in response to the operation input that it will start checking the operating status.
[0139] If the processor 201 of the key terminal device 200 determines that it should start checking the operating status while in a standby state repeating steps ST61 in Figure 6 to ST68 in Figure 7, it determines Yes in step ST64 and proceeds to step ST81 in Figure 7.
[0140] In step ST81, the processor 201 generates a start request. The start request includes, for example, a login ID and a target ID. The target ID indicates which user's operation status to start. The target ID is the user ID of that user. Here, the target ID is the same as the login ID. The start request is information indicating that the operation status should be started. The start request is also information requesting the transmission of information necessary to confirm the operation status of the user identified by the target ID. After generating the start request, the processor 201 instructs the communication interface 205 to send the start request to the server device 100. Upon receiving this transmission instruction, the communication interface 205 sends the start request to the server device 100. The transmitted start request is received by the communication interface 105 of the server device 100.
[0141] Furthermore, if the operator of terminal device 400 wishes to check the operating status, they can, for example, use input device 407 to input an operation to indicate that they want to start checking the operating status. The operator of terminal device 400 can also use input device 407 to input an operation to specify which user's operating status to check. The users that can be specified are the operating users whose login IDs are designated users. The users that can be specified are also users who have granted permission to check the operating status to the user identified by the login ID. Which users a user has granted permission to check the operating status to is determined by the key service settings of the user granting permission to check the operating status.
[0142] In step ST81 of Figure 10, the target ID generated by the processor 401 in the start request is the user ID of the user designated as the target for checking the operating status.
[0143] On the other hand, if the processor 101 of the server device 100 receives a start request while in a waiting state repeating steps ST11 to ST14 in Figure 3, it determines Yes in step ST13 and proceeds to step ST18.
[0144] In step ST18, the processor 101 refers to the user DB and obtains the analysis results and driving data associated with the target ID included in the start request received in step ST13.
[0145] In step ST19, the processor 101 generates a start response. The start response includes the analysis results and driving data acquired in step ST18, as well as the target ID included in the start request received in step ST13. The start response is information that instructs the system to display the analysis results and driving data. After generating the start response, the processor 101 instructs the communication interface 105 to send the start response to the key terminal device 200 or terminal device 400, which is the source of the start request. Upon receiving this instruction, the communication interface 105 sends the start response to the key terminal device 200 or terminal device 400. The transmitted start response is received by the communication interface 205 of the key terminal device 200 or the communication interface 405 of the terminal device 400. After processing in step ST19, the processor 101 returns to step ST11.
[0146] The processor 101 functions as an example of a display control unit that communicates with the first terminal device by performing a process to send a start response to the key terminal device 200, thereby displaying the operating status on the first terminal device. Alternatively, the processor 101 functions as an example of a display control unit in cooperation with the communication interface 105. The processor 101 also functions as an example of a display control unit that displays the operating status on the second terminal device by performing a process to send a start response to the terminal device 400.
[0147] Meanwhile, in step ST82 of Figure 7, the processor 201 of the key terminal device 200 is waiting for a start response to be received by the communication interface 205. If a start response is received, the processor 201 determines Yes in step ST82 and proceeds to step ST83.
[0148] In step ST83, the processor 201 starts processing to check the driving status. For this purpose, the processor 201 displays a confirmation screen on the display device 207, for example. The confirmation screen includes, for example, the driving data and analysis results included in the start response received in step ST82. The confirmation screen may span multiple pages. The confirmation screen may be scrollable.
[0149] The operator of the key terminal device 200 checks the driving status. That is, the operator views the driving data and analysis results displayed on the display device 207. When the operator finishes checking the driving status, they use the input device 407 to input an operation indicating that they want to end the check of the driving status.
[0150] In step ST84, the processor 201 waits for an operation to be performed that instructs it to terminate the process for checking the operating status. That is, the processor 201 waits for a predetermined operation to be performed, such as pressing a button that instructs it to terminate the process for checking the operating status. If an operation to instruct it to terminate the process for checking the operating status is performed, the processor 201 determines Yes in step ST84 and proceeds to step ST85.
[0151] In step ST85, the processor 201 determines whether the operator of the key terminal device 200 has checked the operating status. For example, the processor 201 determines that the operator has checked the operating status if the time spent by the operator to check the operating status is longer than a predetermined time. The time spent by the operator to check the operating status is, for example, the time from the execution of the process in step ST83 to the determination of Yes in step ST84. For example, the processor 201 determines that the operator has checked the operating status if the confirmation screen has been displayed for a predetermined number of pages or all pages have been displayed. For example, the processor 201 determines that the operator has checked the operating status if the confirmation screen has been scrolled for a predetermined number of pages or all pages have been scrolled. The confirmation screen may also display a test related to the operating status. For example, the processor 201 determines that the operator has checked the operating status if the operator's answer result to the test is higher than a predetermined score. The confirmation screen may also include a video. For example, the processor 201 determines that the operator has checked the operating status if the video has been played for a predetermined time or all pages have been played. Furthermore, the processor 201 may determine that the operator has confirmed the operating status if a combination of the above conditions is met. If the processor 201 does not determine that the operator has confirmed the operating status, it determines No in step ST85 and returns to step ST61 in Figure 6. On the other hand, if the processor 201 determines that the operator has confirmed the operating status, it determines Yes in step ST85 and proceeds to step ST86.
[0152] The processor 201 may assume, without any particular conditions, that the operator of the key terminal device 200 has confirmed the operating status. In this case, if the processor 201 determines Yes in step ST8, for example, it proceeds to step ST86.
[0153] In step ST86, the processor 201 generates an acknowledgment notice. The acknowledgment notice includes the login ID and the target ID included in the start response received in step ST82. The acknowledgment notice is information indicating that the user identified by the login ID has confirmed the operating status of the user identified by the target ID. After generating the acknowledgment notice, the processor 201 instructs the communication interface 205 to send the acknowledgment notice to the server device 100. Upon receiving this instruction, the communication interface 205 sends the acknowledgment notice to the server device 100. The transmitted acknowledgment notice is received by the communication interface 105 of the server device 100. After processing in step ST86, the processor 201 returns to step ST61 in Figure 6.
[0154] On the other hand, if the processor 101 of the server device 100 receives a confirmation notification while in a waiting state repeating steps ST11 to ST14 in Figure 3, it determines "Yes" in step ST14 and proceeds to step ST20.
[0155] Meanwhile, in step ST20 of Figure 3, the processor 101 of the server device 100 stores in the user DB the date and time when the user identified by the login ID last checked the operating status. For example, the processor 101 stores the current date and time associated with the login ID and target ID included in the confirmation notice received in step ST14. This current date and time indicates the date and time when the user identified by the login ID checked the operating status of the user identified by the target ID.
[0156] In step ST21, processor 101 determines whether or not to release the restriction on the digital key of the user identified by the target ID included in the confirmation notice received in step ST14. If the user identified by the login ID included in the confirmation notice received in step ST14 is not a designated user of the driver user identified by the target ID, processor 101 does not determine to release the restriction on the digital key. On the other hand, if the user identified by the login ID is a designated user of the driver user identified by the target ID, processor 101 refers to the user DB and checks the value of the server restriction variable associated with the target ID included in the confirmation notice received in step ST14. If the value indicates an unrestricted state, processor 101 does not determine to release the restriction on the digital key. On the other hand, if the value indicates a restricted state, processor 101 checks whether the confirmation of the driver status of the user identified by the target ID has expired. If the confirmation of the driver status has expired, processor 101 does not determine to release the restriction on the digital key. On the other hand, if the operating status check has not exceeded the deadline, the processor 101 determines to release the restriction on the digital key. If the processor 101 does not determine to release the restriction on the digital key, it determines No in step ST21 and returns to step ST11. On the other hand, if the processor 101 determines to release the restriction on the digital key, it determines Yes in step ST21 and proceeds to step ST22.
[0157] In step ST22, the processor 101 updates the user DB to set the value of the server restriction variable associated with the target ID included in the confirmation notice received in step ST14 to a value indicating the restriction status.
[0158] In step ST23, processor 101 instructs communication interface 105 to send a restriction release request to key terminal device 200 used by the user identified by the target ID included in the confirmation notice received in step ST14. The restriction release request is information that instructs the digital key to be released from its restricted state and returned to an unrestricted state. Upon receiving this transmission instruction, communication interface 105 sends the restriction release request to the key terminal device 200. The transmitted restriction release request is received by the communication interface 205 of the key terminal device 200. After processing in step ST23, processor 101 returns to step ST11.
[0159] On the other hand, if the processor 201 of the key terminal device 200 receives a restriction release request while in a waiting state repeating steps ST61 in Figure 6 to ST68 in Figure 7, it determines Yes in step ST67 and proceeds to step ST87 in Figure 7.
[0160] In step ST87, the processor 201 removes the restriction state of the digital key and sets it to an unrestricted state. To do this, the processor 201 rewrites the value of the restriction variable to a value indicating the unrestricted state.
[0161] In step ST88, the processor 201 notifies the holder of the key terminal device 200 that the restriction state of the digital key has been released and the key has become unrestricted. The processor 201 displays, for example, an image on the display device 207 indicating that the restriction state of the digital key has been released and the key has become unrestricted. The processor 201 may also notify by outputting sound from the speaker, illuminating the light-emitting device, or vibrating the vibrator. The processor 201 may also notify by push notification. After processing in step ST88, the processor 201 returns to step ST61 in Figure 6.
[0162] The operation of the key terminal device 200 and the vehicle 300 when the digital key is in a restricted state will be described below.
[0163] If the digital key is in a restricted state, the processor 201 of the key terminal device 200 determines Yes in step ST74 and proceeds to step ST76.
[0164] In step ST76, the processor 201 generates an unlock request. The value of the restriction variable included in the unlock request is a value indicating the restriction state. After generating the unlock request, the processor 201 instructs the radio interface 206 to transmit the unlock request to the vehicle 300. Upon receiving this transmission instruction, the radio interface 206 transmits the unlock request to the vehicle 300. The transmitted unlock request is received by the key interface 320 of the vehicle 300.
[0165] In step ST77, the processor 201 notifies the holder of the key terminal device 200 that the digital key is in a restricted state. For example, the processor 201 displays an image on the display device 207 indicating that the digital key is in a restricted state and that the restriction will be lifted once the operating status is confirmed. The processor 201 may also notify by outputting sound from the speaker, illuminating a light-emitting device, or vibrating a vibrator. The processor 201 may also notify by push notification. After processing in step ST77, the processor 201 returns to step ST61.
[0166] On the other hand, if the digital key is in a restricted state, the processor 311 of the control device 310 determines Yes in step ST104 in Figure 9 and proceeds to step ST109.
[0167] In step ST109, the processor 311 notifies the user of the digital key that the digital key is in a restricted state. The processor 311 provides this notification, for example, by voice.
[0168] In step ST110, the processor 311 refers to the vehicle setting information and determines whether the electronic lock 331 is set to unlock when the digital key is in a restricted state. If the processor 311 is set not to unlock the electronic lock 331 when the digital key is in a restricted state, it determines No in step ST110 and returns to step ST101. On the other hand, if the processor 311 is set to unlock the electronic lock 331 when the digital key is in a restricted state, it determines Yes in step ST110 and proceeds to step ST104.
[0169] When the processor 311 proceeds from step ST110 to step ST106 and performs the processing in step S103, the vehicle 300 changes from a locked state to a partially locked state. The partially locked state is a state in which some of the locks on the vehicle 300 are released. This partially includes at least the electronic lock 331. Therefore, the partially locked state is a state in which some or all of the parts of the vehicle 300 cannot be started. It is preferable that the vehicle 300 in the partially locked state cannot be driven. The partially locked state is an example of a state in which at least one function of the vehicle 300 is restricted.
[0170] Furthermore, if the digital key is in a restricted state, the processor 311 determines Yes in step ST107 and proceeds to step ST111.
[0171] In step ST111, the processor 311 refers to the vehicle setting information and identifies the parts and equipment that are set to start even when the digital key is in a restricted state. The processor 311 then starts the operation of the identified parts and equipment. However, it is preferable that the processor 311 does not allow the vehicle 300 to be driven. Note that if there are no parts or equipment other than the electronic lock 331 that are set to start even when the digital key is in a restricted state, the processor 311 does not need to start the operation of any of the parts and equipment in the process of step ST111. Even after the process of step ST111, the vehicle 300 remains in a partially locked state.
[0172] In step ST112, the processor 311 waits for an unlock request to be received by the key interface 320. If an unlock request is received, the processor 311 determines Yes in step ST112 and proceeds to step ST113.
[0173] In step ST113, the processor 311 refers to the restriction variable included in the unlock request received in step ST112 to determine whether the digital key is in a restricted state. If the digital key is in a restricted state, the processor 311 determines Yes in step ST113 and returns to step ST112. Conversely, if the digital key is not in an unrestricted state, the processor 311 determines No in step ST113 and proceeds to step ST114.
[0174] In step ST114, the processor 311 starts the various parts of the vehicle 300. After processing in step ST114, the processor 311 completes the process shown in Figure 9. In this way, when the digital key changes from a restricted state to an unrestricted state, the vehicle 300 changes from a partially locked state to an unlocked state.
[0175] When the operator of the key terminal device 200 wants to lock the vehicle 300, they use the input device 208 to instruct the key terminal device 200 to lock the vehicle 300. This operation may only be possible when the vehicle 300 is partially locked or unlocked.
[0176] Alternatively, if the operator wishes to lock the vehicle 300, they may take the key terminal device 200 and move away from the vehicle 300.
[0177] If the processor 201 of the key terminal device 200 determines that the vehicle 300 should be locked while in a standby state repeating steps ST61 in Figure 6 to step ST68 in Figure 7, it determines Yes in step ST in Figure 7 and proceeds to step ST89.
[0178] In step ST89, the processor 201 generates a lock request. The lock request is information requesting that the vehicle 300 be put into a locked state. The lock request includes, for example, a login ID, a restriction variable stored in the auxiliary storage device 204, and key information registered in the key application. After generating the lock request, the processor 201 instructs the wireless interface 206 to send the lock request to the vehicle 300. Upon receiving this instruction, the wireless interface 206 sends the lock request to the vehicle 300. The transmitted lock request is received by the key interface 320 of the vehicle 300. After processing in step ST89, the processor 201 returns to step ST61.
[0179] On the other hand, the processor 311 of the control device 310 determines that the vehicle 300 should be locked when a lock request is received via the key interface 320. The processor 311 also determines that the vehicle 300 should be locked when the key terminal device 200 moves beyond a predetermined distance from the vehicle 300.
[0180] If the processor 311 of the control device 310 determines that the vehicle 300 should be locked while in a waiting state repeating steps ST101 and ST102, it determines Yes in step ST102 and proceeds to step ST115.
[0181] In step ST115, the processor 311 locks the vehicle 300. That is, the processor 311 stops all parts of the vehicle 300 that were started in steps ST108, ST111, and ST114. Furthermore, the processor 311 controls the electronic lock 331 to lock it. After processing in step ST115, the processor 311 returns to step ST101.
[0182] The digital key system 1 of the embodiment puts the digital key into a restricted state if the driver using the digital key meets predetermined conditions. This allows the digital key system 1 of the embodiment to encourage the driver not to meet the predetermined conditions. If the predetermined conditions relate to safe driving, the digital key system 1 of the embodiment can encourage the driver to drive safely.
[0183] Furthermore, the digital key system 1 of the embodiment displays the driver's driving status on the key terminal device 200, which functions as a digital key. The digital key system 1 of the embodiment also restricts the digital key if the driver has not checked the driving status for a predetermined period of P1 or longer. This allows the digital key system 1 of the embodiment to allow the driver to check the driving status. Checking the driving status gives the driver an opportunity to reflect on their driving. Therefore, the digital key system 1 of the embodiment can encourage safe driving from the driver.
[0184] Furthermore, the digital key system 1 of the embodiment notifies the key terminal device 200 or terminal device 400 that the operating status check is about to expire if the remaining period until the check expires is less than or equal to a predetermined period P2. This allows the digital key system 1 of the embodiment to inform the user that the operating status check is about to expire and that restrictions on the digital key are about to be imposed.
[0185] Furthermore, the digital key system 1 of the embodiment puts the digital key into a restricted state if there is a problem with the driver's driving. In response, it is assumed that the driver will drive in a way that prevents the digital key from entering a restricted state. Therefore, the digital key system 1 of the embodiment can encourage safe driving by the driver.
[0186] Furthermore, the digital key system 1 of this embodiment can display the driving status on a terminal device 400 used by a user other than the driver. This allows, for example, if the other user is a family member of the driver, the family member to know the driver's driving status. Also, for example, if the other user is a rental car company that is about to provide a rental car to the driver, the rental car company can know the driver's driving status before providing the rental car. The rental car company can also decide not to provide the rental car if the driving status is poor.
[0187] Furthermore, the digital key system 1 of this embodiment displays the driver's driving status on a terminal device 400 used by a predetermined user other than the driver. In addition, the digital key system 1 of this embodiment restricts the digital key if the predetermined user has not checked the driving status for a predetermined period P1 or longer. This allows the digital key system 1 of this embodiment to allow a family member of the driver to check the driving status.
[0188] Furthermore, the digital key system 1 of this embodiment stores the driving status of the driver. This allows the digital key system 1 of this embodiment to accumulate the driving status of the driver. Therefore, the digital key system 1 of this embodiment can also perform a more accurate analysis of the driving status.
[0189] Furthermore, according to the digital key system 1 of the embodiment, the digital key is used to unlock the electronic lock 331 of the door 330. Therefore, the digital key system 1 of the embodiment can prevent the driver from driving by restricting the use of the digital key.
[0190] Furthermore, according to the digital key system 1 of this embodiment, the electronic lock 331 can be unlocked even when the digital key is in a restricted state. In this case, the driver can enter the vehicle 300 even if the digital key is in a restricted state. Therefore, the driver can retrieve luggage from inside the vehicle, take a break inside the vehicle, etc., even if the digital key is in a restricted state.
[0191] Furthermore, according to the digital key system 1 of the embodiment, even when the digital key is in a restricted state, if the start button 360 is operated, some of the parts and equipment of the vehicle 300 can be started. In this case, even if the digital key is in a restricted state, the driver can, for example, use the car audio system, use the in-car Wi-Fi, use the car navigation system, etc.
[0192] The above embodiment can also be modified as follows: The key terminal device 200 does not need to send an unlock request if the digital key is in a restricted state. In this case, if the processor 201 determines Yes in step ST74, for example, it proceeds to step ST77. Also in this case, the processor 311 of the control device 310 does not need to determine whether the digital key is in a restricted state or not. That is, if the processor 311 determines Yes in step ST103, it proceeds to step ST104. And if the processor 311 determines Yes in step ST106, it proceeds to step ST108.
[0193] The key terminal device 200 does not need to establish a connection with the key interface 320 if the digital key is in a restricted state. In this case, if the processor 201 determines Yes in step ST63, for example, it proceeds to step ST74. Then, if the processor 201 determines Yes in step ST74, it proceeds to step ST77. Conversely, if the processor 201 determines No in step ST74, it proceeds to step ST73. Then, after processing in step ST73, the processor 201 proceeds to step ST75.
[0194] The control device 310 may determine whether the digital key is in a restricted state by querying the server device 100. In this case, the key terminal device 200 does not need to determine whether the digital key is in a restricted state.
[0195] In the above embodiment, the vehicle 300 can be locked regardless of whether the digital key is in a restricted state or not. However, it is not necessary to lock the vehicle 300 when the digital key is in a restricted state. In this case, the processor 201 of the key terminal device 200 does not send a lock request if the digital key is in a restricted state, for example. Alternatively, the processor 311 of the control device 310 refers to the restriction variable included in the received lock request and determines whether the digital key is in a restricted state or not. The processor 311 then does not lock the vehicle 300 when the digital key is in a restricted state. Whether or not to lock the vehicle 300 when the digital key is in a restricted state may be changeable by a setting. This setting is stored in the auxiliary storage device 314 as vehicle setting information. It is also possible to set parts and equipment that can be locked even when the key is in a restricted state. In this case, when the processor 311 receives a lock request, it refers to the vehicle setting information and locks the parts and equipment that are set to be lockable even when the key is in a restricted state. In other words, the processor 311 stops the parts and equipment of the vehicle 300 that were started in steps ST108, ST111, and ST114 that are set to be lockable even in a restricted state. Also, if the electronic lock 331 is set to be lockable even in a restricted state, the processor 311 controls the electronic lock 331 to lock it. Note that the parts and equipment that are set to start even when the digital key is in a restricted state and the parts and equipment that are set to be lockable even in a restricted state may be the same parts and equipment, for example, they may have the same settings.
[0196] The specified conditions may be other conditions than those listed above.
[0197] The digital key system of this embodiment may restrict the functions of the vehicle itself instead of restricting the digital key.
[0198] In the above embodiment, the digital key system 1 was described using the example of application to a vehicle 300, which is an automobile. However, the digital key system of the embodiment can also be applied to mobile bodies other than automobiles. Examples of mobile bodies other than automobiles include railway vehicles, aircraft, ships, submarines, and spacecraft. Furthermore, the mobile body to which the digital key system of the embodiment is applied may be remotely operated (remotely controlled). In addition, the digital key system 1 of the embodiment can also be applied to machinery other than mobile bodies. Examples of machinery other than mobile bodies include non-mobile cranes. In the digital key system of the embodiment applied to machinery other than automobiles, instead of a door 330, a door is provided for entering a place for operating (controlling) the machine, such as a driver's seat (cockpit) or control room (cockpit). This door is equipped with an electronic lock 331, similar to the door 330. In machines for remote operation, this place is located outside the machine. In machines not for remote operation, this place is located inside the machine.
[0199] In the above embodiment, a portion of the processing performed by the server device 100 may be performed by the key terminal device 200, the control device 310, or the terminal device 400. In the above embodiment, a portion of the processing performed by the key terminal device 200 may be performed by the server device 100 or the control device 310. In the above embodiment, a portion of the processing performed by the control device 310 may be performed by the server device 100 or the key terminal device 200. In the above embodiment, a portion of the processing performed by the terminal device 400 may be performed by the server device 100.
[0200] Processors 101, 201, 311, and 401 may implement some or all of the processing implemented by the program in the above embodiment through the hardware configuration of the circuit.
[0201] The program that implements the processing of the embodiment is transferred, for example, while stored in a non-temporary storage medium within the device. However, the device may be transferred without the program stored in it. Alternatively, the program may be transferred separately and written to the device. This transfer of the program can be achieved, for example, by recording it on a removable non-temporary storage medium or by downloading it via a network such as the Internet or a LAN.
[0202] The embodiments of the present invention have been described above, but these are merely examples and do not limit the scope of the invention. Embodiments of the present invention can be implemented in various ways without departing from the spirit of the invention. [Explanation of Symbols]
[0203] 1. Digital Key System 100 Server Devices 101,201,311,401 Processors 102,202,312,402 ROM 103,203,313,403 RAM 104,204,314,404 Auxiliary storage device 105,205,315,405 Communication Interfaces 106,209,317,408 buses 200 Key Terminal Devices 206 Wireless Interface 207,406 display devices 208,407 Input Devices 300 vehicles 310 Control device 316 Control Interface 320-key interface 330 doors 331 Electronic lock 340 Power section 350 Electrical System 360 Start button 400 terminal devices
Claims
1. A communication unit that communicates with a first terminal device used as a digital key for restricting and unlocking at least one function of the machine, An acquisition unit that acquires the operating status of the machine by a first user using the first terminal device, A determination unit that determines whether the first user meets predetermined conditions, If the predetermined conditions are met, the restriction unit puts the digital key into a restricted state in which at least one of the restrictions and releases of the function cannot be performed, Equipped with, The aforementioned predetermined condition is that the first user has not checked the operating status for a first predetermined period of time or longer. The acquisition unit is an information management device that acquires the driving status by analyzing driving data, including speed history, included in the driving data information received by the communication unit.
2. The information management device according to claim 1, further comprising a display control unit that communicates with the first terminal device to display the operating status on the first terminal device.
3. The information management device according to claim 2, further comprising a notification control unit that notifies the first terminal device that the predetermined condition is likely to be met if the period until the period during which the first user has not checked the operating status exceeds a first predetermined period is less than or equal to a second predetermined period.
4. The information management device according to claim 1, wherein the determination unit further determines, as a predetermined condition, that there is a problem with the operation of the first user.
5. The information management device according to claim 1, further comprising a display control unit that displays the operating status on a second terminal device used by a second user different from the first user.
6. The information management device according to claim 5, wherein the predetermined condition is that the second user has not checked the operating status for a first predetermined period of time or longer.
7. The information management device according to claim 2 or claim 5, further comprising a storage unit for storing the aforementioned operating conditions.
8. The at least one of the functions includes locking a door for entering a place to operate the machine, The information management device according to claim 1, wherein the limiting unit, when the predetermined conditions are met, puts the digital key into the restricted state in which the door cannot be unlocked.
9. The processor in an information management device equipped with a communication device is A communication control unit controls a communication device to communicate with a first terminal device used as a digital key for restricting and unlocking at least one function of the machine, An acquisition unit that acquires the operating status of the machine by a first user using the first terminal device, A determination unit that determines whether the first user meets predetermined conditions, If the predetermined conditions are met, the digital key is made to function as a limiting unit that puts the function into a restricted state where at least one of the restrictions and releases of the function cannot be performed. The aforementioned predetermined condition is that the first user has not checked the operating status for a first predetermined period of time or longer. The acquisition unit is a program that acquires the driving conditions by analyzing driving data, including speed history, included in the driving data information received by the communication device.
10. The system comprises a communication unit that communicates with a first terminal device used as a digital key for restricting and releasing at least one of the functions of the machine, an acquisition unit that acquires the operating status of the machine by a first user using the first terminal device, a determination unit that determines whether the first user satisfies predetermined conditions, and a restriction unit that, if the predetermined conditions are met, puts the digital key into a restricted state where at least one of the restrictions and releases of the function cannot be performed, The aforementioned predetermined condition is that the first user has not checked the operating status for a first predetermined period of time or longer. The acquisition unit, together with an information management device that acquires the driving status by analyzing the driving data, including the speed history, contained in the driving data information received by the communication unit, constitutes a digital key system. A digital key unit that causes the first terminal device to function as the digital key, The first terminal device comprises a restriction storage unit that stores that the digital key is in a restricted state in accordance with the control of the restriction unit.
11. The system comprises a communication unit that communicates with a first terminal device used as a digital key for restricting and releasing at least one of the functions of the machine, an acquisition unit that acquires the operating status of the machine by a first user using the first terminal device, a determination unit that determines whether the first user satisfies predetermined conditions, and a restriction unit that, if the predetermined conditions are met, puts the digital key into a restricted state where at least one of the restrictions and releases of the function cannot be performed, The aforementioned predetermined condition is that the first user has not checked the operating status for a first predetermined period of time or longer. The acquisition unit, together with an information management device that acquires the driving status by analyzing the driving data, including the speed history, contained in the driving data information received by the communication unit, constitutes a digital key system, and the processor provided in the first terminal device equipped with a storage device, A digital key unit that causes the first terminal device to function as the digital key, A program that functions as a restriction storage unit, which stores in the storage device that the digital key is in a restricted state in accordance with the control of the restriction unit.
12. Communicating with a first terminal device used as a digital key to restrict and unlock at least one function of the machine, The operating status of the machine is obtained by the first user using the first terminal device, It is determined that the first user meets the predetermined conditions, If the predetermined conditions are met, the digital key is placed in a restricted state where at least one of the restrictions and releases of the function cannot be performed. The aforementioned predetermined condition is that the first user has not checked the operating status for a first predetermined period of time or longer. The acquisition of the aforementioned driving conditions is an information management method that receives driving data information and acquires the aforementioned driving conditions by analyzing the driving data, including the speed history, contained in the received driving data information.
Citation Information
Patent Citations
Vehicle control system and qualification control program
JP2008189261A
Electronic key control system for vehicle
JP2008297721A
Lease system with engine-start / renewal control apparatus, and lease method
JP2014085758A
Digital key system and onboard system
JP2021085719A
Vehicle control system
WO2019043954A1