Access management device, access management system, access management program, and access management method

JPWO2024143201A5Active Publication Date: 2025-05-14DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024567741
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-14
Estimated Expiration
2043-12-22

AI Technical Summary

Technical Problem

Existing access management systems for vehicle-mounted devices lack effective mechanisms to appropriately manage access to in-vehicle devices, particularly in ensuring secure and authorized access by users and applications.

Method used

An access management system comprising an in-vehicle access management device that utilizes manifests to manage access, with a storage unit storing a first manifest indicating the correspondence between application programs and their authorities, and a second manifest indicating user authorities, allowing the access management unit to control access based on these manifests, and communicating with a server to manage vehicle data and provide services.

Benefits of technology

Enables secure and appropriate management of access to in-vehicle devices by users and applications, ensuring that only authorized entities can access specific vehicle data and functions, enhancing security and usability.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

An onboard access management device 60 that manages vehicle data acquired from a plurality of vehicles 50 and communicates with servers 10, 30 for providing vehicle-related services on the basis of the vehicle data, wherein the access management device manages access, by a user using an application program, to an onboard device 100 on the basis of a first manifest that indicates the correspondence between the application program and a program right for the application program to access the onboard device 100 and a second manifest that indicates the correspondence between the user and a user right for the user to access the onboard device using the application program.
Need to check novelty before this filing date? Find Prior Art

Description

Access management device, access management system, access management program, and access management method CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This international application claims priority based on Japanese Patent Application No. 2022-212240, filed with the Japan Patent Office on December 28, 2022, the entire contents of which are incorporated herein by reference.

[0002] The present disclosure relates to a technique for managing access to an in-vehicle device using an application program installed in a vehicle.

[0003] When using an application program installed in a vehicle, a technique is known for determining whether a user has access authority.

[0004] For example, in the technology described in Patent Document 1 below, when a vehicle application program that controls vehicle functions is executed, an authentication level and user authority required for execution are specified, and a user who is authenticated based on the authentication level and user authority can use the application program.

[0005] The authentication level is expressed in ascending order of security level when authenticating a user, for example, from level 1 to level 3. User authority includes, for example, vehicle owner, family member, guest, service provider, etc.

[0006] For example, to use a certain application program, authentication level 1 is designated as the authentication level and owner or family is designated as the user authority.

[0007] Japanese Patent Application Laid-Open No. 2022-57228

[0008] As a result of detailed investigations by the inventors, it has been found that when an application program is used, it is necessary to appropriately manage access of the application program to the in-vehicle device.

[0009] One aspect of the present disclosure is to provide a technique for appropriately managing access to an in-vehicle device using an application program.

[0010] An in-vehicle access management device according to one aspect of the present disclosure is an access management device that manages vehicle data obtained from multiple vehicles and communicates with a server that provides vehicle-related services based on the vehicle data, and is equipped with a memory unit and an access management unit.

[0011] The memory unit stores a first manifest that indicates the correspondence between an application program and the program authority with which the application program accesses the in-vehicle device, and a second manifest that indicates the correspondence between a user and the user authority with which the user accesses the in-vehicle device using the application program.

[0012] The access management unit manages access to the in-vehicle device by a user using an application program, based on the first manifest and the second manifest stored in the storage unit.

[0013] In addition, an access management system according to another aspect of the present disclosure includes a server that manages vehicle data obtained from multiple vehicles and provides services related to the vehicles based on the vehicle data, and an on-board access management device that communicates with the server.

[0014] The access management device includes a device storage unit, an access management unit, and a first management unit.

[0015] The device memory unit stores a first manifest that indicates the correspondence between an application program and the program authority with which the application program accesses the in-vehicle device, and a second manifest that indicates the correspondence between a user and the user authority with which the user accesses the in-vehicle device using the application program.

[0016] The access management unit manages access to the in-vehicle device by a user using an application program based on the first manifest and the second manifest stored in the device storage unit. The first management unit manages storage of data received from the server.

[0017] The server includes a communication unit, a server storage unit, and a second management unit.

[0018] The communication unit communicates with the vehicle. The second management unit stores the first manifest and the second manifest in the server storage unit.

[0019] The second management unit transmits the first manifest and the second manifest stored in the server storage unit from the communication unit to the vehicle.

[0020] The first management unit stores the first manifest and the second manifest acquired from the server through communication in the device storage unit.

[0021] An access management program according to another aspect of the present disclosure is an access management program that causes a computer to function as the above-described access management device.

[0022] An access management method according to another aspect of the present disclosure is an access management method using the above-described access management system.

[0023] According to this configuration, access to the in-vehicle device can be appropriately managed based on the first manifest corresponding to the application program and the second manifest corresponding to the user who uses the application program.

[0024] FIG. 1 is a block diagram showing the configuration of an access management system; FIG. 2 is a block diagram showing the configuration of an access management device; FIG. 3 is another block diagram showing the configuration of an access management device; FIG. 4 is an explanatory diagram showing the relationship between access rights of an application program, a user, an in-vehicle device, and data; FIG. 5 is a sequence diagram showing access management processing; FIG. 6 is a sequence diagram showing another access management processing.

[0025] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0026] 1 includes a management server 10, a service server 30, and an access management device 60. The access management device 60 is mounted on a vehicle 50. Although three vehicles 50 are illustrated in FIG. 1 , the number of vehicles 50 is not limited to three, and any number of vehicles 50 may be used. Each vehicle 50 has a common configuration in that it includes an exterior communication device 54, an access management device 60, and an in-vehicle device 100.

[0027] The management server 10 , the service server 30 , and the access management device 60 communicate with each other via a network 4 .

[0028] The management server 10 includes a communication unit 12, a storage unit 14, and a manifest management unit 20. The management server 10 communicates with the service server 30, the access management device 60, and a mobile terminal (not shown) via the communication unit 12. The management server 10 and the service server 30 manage vehicle data acquired from a plurality of vehicles 50, and provide vehicle services related to the vehicles 50 based on the vehicle data. The vehicle data includes, for example, the position and speed of the vehicle 50, and operation data of the vehicle 50 such as the steering wheel, accelerator, and brake.

[0029] A program manifest is stored in the storage unit 14. In the program manifest, application programs that are used by the service user 200 (described later) among the application programs installed in the vehicle 50 are set as application programs. An application program is also abbreviated as an app.

[0030] The apps installed in the vehicle 50 are installed in the access management device 60 and an in-vehicle electronic control device 52 (described later) other than the access management device 60. The apps installed in the vehicle 50 are also referred to as in-vehicle apps.

[0031] The manifest management unit 20 includes a CPU 22, a ROM 24, a RAM 26, etc. Various functions of the manifest management unit 20 are realized by the CPU 22 executing a program stored in a non-transient tangible recording medium such as the ROM 24. Furthermore, the execution of this program causes a method corresponding to the program to be executed.

[0032] The manifest management unit 20 manages the program manifest stored in the storage unit 14. The program manifest indicates the correspondence between an app and a program authority, which is the authority for the app to access an in-vehicle device 100 installed in the vehicle 50. The in-vehicle device is also called a device. The manifest management unit 20 included in the management server 10 is also called a first manifest management unit.

[0033] 4 shows an example of a program manifest that indicates the correspondence between an app and the program authority for the app to access the in-vehicle device 100. In FIG. 4, a circle indicates that the app has program authority, i.e., the app can access the in-vehicle device 100, and an × indicates that the app does not have program authority, i.e., the app cannot access the in-vehicle device 100.

[0034] The in-vehicle device 100 is a device related to the vehicle 50, and includes, for example, a Wi-Fi communication device for communicating with the management server 10, a Bluetooth communication device for directly communicating with a mobile device such as a smartphone, a GNSS sensor for detecting the position, a front camera for capturing images outside the vehicle, and an in-vehicle camera for capturing images inside the vehicle. Wi-Fi and Bluetooth are registered trademarks. GNSS stands for Global Navigation Satellite System.

[0035] 1, these in-vehicle devices 100 may be built into the access management device 60, or may be controlled by the electronic control device 52 and connected to a bus that enables communication between the access management device 60 and the electronic control device 52. The electronic control device is also called an ECU.

[0036] In addition, a mobile terminal such as a smartphone that can communicate with the management server 10 and the vehicle 50 may be considered as part of the in-vehicle device 100 and may be subject to access management.

[0037] 4, for example, the in-vehicle device 100 that a driving diagnosis application can access is different from the in-vehicle device 100 that a drive recorder application can access. In this way, a program manifest specifying different access permissions is set depending on the application.

[0038] When an application is installed in the vehicle 50 , the program manifest is obtained from the management server 10 and stored in the memory unit 64 of the access management device 60 .

[0039] The apps set in the program manifest may be apps that come standard with the vehicle 50, or apps that are not standardly installed in the vehicle 50 but are developed later and added to the vehicle 50.

[0040] Furthermore, the in-vehicle device 100 set in the program manifest may be one that is installed as standard in the vehicle 50, or one that is not installed as standard in the vehicle 50 but is added to the vehicle 50 later.

[0041] The in-vehicle device 100 that an application accesses can be divided into two types: one that the application can access via a private API and one that the application can access via a public API. API stands for Application Programming Interface. The access management device 60 provides the application with the private API and the public API.

[0042] An in-vehicle device 100 accessed via a private API requires access authority. An in-vehicle device 100 accessed via a public API does not require access authority. Whether to access via a private API or a public API is determined for each in-vehicle device 100.

[0043] Alternatively, the method of accessing the in-vehicle device 100 may be changed such that, for example, when the in-vehicle device 100 reads the status of the in-vehicle camera, it is accessed via a public API, and when turning on the in-vehicle camera or reading images captured by the in-vehicle camera, it is accessed via a private API.

[0044] When an application accesses the in-vehicle device 100 via a private API that requires access authorization, a valid period during which the application can access the in-vehicle device 100 is set. The valid period during which the application can access the in-vehicle device 100 is included in the program manifest and managed by the management server 10.

[0045] The service server 30 includes a communication unit 32, a storage unit 34, and a manifest management unit 40. The service server 30 communicates with the management server 10, the vehicle 50, and a mobile terminal (not shown) via the communication unit 32.

[0046] The manifest management unit 40 includes a CPU 42, a ROM 44, a RAM 46, etc. The various functions of the manifest management unit 40 are realized by the CPU 42 executing a program stored in a non-transient physical recording medium such as the ROM 44. Furthermore, the execution of this program executes a method corresponding to the program. The manifest management unit 40 included in the service server 30 is also referred to as a second manifest management unit.

[0047] The manifest management unit 40 manages the user manifest stored in the storage unit 34. The user manifest indicates the correspondence between the ID of the service user 200 who accesses the in-vehicle device 100 using an app and the user authority for the service user 200 to access the in-vehicle device 100.

[0048] 4 is an ID managed by the service server 30 in association with the service user 200. Also, the service user ID shown in FIG. 4 is an ID managed by the management server 10 in association with the user ID.

[0049] The storage unit 34 stores a user manifest.

[0050] As with the program manifest, the in-vehicle device 100 set in the user manifest may be one that is installed as standard in the vehicle 50, or one that is not installed as standard in the vehicle 50 but is added to the vehicle 50 later.

[0051] 4 shows an example of correspondence between the service user 200 and the user authority for the service user 200 to access the in-vehicle device 100. As shown in Fig. 4, the user authority includes not only the authority to access the in-vehicle device 100 but also authority regarding how to access data, such as whether the service user 200 can save, refer to, or edit data stored in the in-vehicle device 100 that the service user 200 can access.

[0052] The user authority may also include authority regarding data items or data types that indicate which data the service user 200 can access from among the data stored in the in-vehicle device 100 that the service user 200 can access.

[0053] In FIG. 4, a circle indicates that the user has authority, and a cross indicates that the user does not have authority.

[0054] For example, as shown in Fig. 4, the in-vehicle device 100 that can be accessed by an administrator who is a user is different from the in-vehicle device 100 that can be accessed by a guest. In this way, different user manifests are set depending on the user.

[0055] As shown in Fig. 4, the program manifest and the user manifest may be set as one manifest, or the program manifest and the user manifest may be set as separate manifests.

[0056] 4, with regard to the user authority of the driving diagnosis app, the in-vehicle device 100 that can be accessed when the user's attribute is an administrator is different from the in-vehicle device 100 that can be accessed when the user's attribute is a guest. With regard to the user authority of the drive recorder app, the in-vehicle device 100 that can be accessed when the user is an administrator is different from the in-vehicle device 100 that can be accessed when the user is a guest.

[0057] The storage unit 34 also stores data other than the above-mentioned user manifest.

[0058] In addition to the above, the user rights also include the following rights (1) and (2), for example.

[0059] (1) Among the multiple in-vehicle devices 100 that the application can access, the in-vehicle devices 100 that the user can access.

[0060] (2) The permitted operations for the in-vehicle device 100 include, for example, starting and shutting down the in-vehicle device 100 .

[0061] The vehicle 50 includes a plurality of ECUs 52 that execute vehicle control, an external communication device 54 that communicates with the outside of the vehicle 50 via a network 4 or the like, an access management device 60, and an in-vehicle device 100. ECU is an abbreviation for Electronic Control Unit.

[0062] The ECU 52 includes one or more microcomputers and controls the vehicle 50. The external communication device 54 communicates with the outside of the vehicle 50 via the network 4 or the like.

[0063] The access management device 60 manages the access of the service user 200 to the in-vehicle device 100 using the in-vehicle application.

[0064] 2, the access management device 60 includes a communication unit 62, a storage unit 64, and a control unit 70. The control unit 70 includes an access management unit 72 and a manifest management unit 74. The access management device 60 communicates with the management server 10 and the service server 30 via the communication unit 62.

[0065] 3, the control unit 70 includes, as hardware components, a CPU 80, a ROM 82, a RAM 84, etc. Various functions of the control unit 70, including the access management unit 72 and the manifest management unit 74, are realized by the CPU 80 executing a program stored in a non-transient physical recording medium such as the ROM 82. Furthermore, by executing this program, a method corresponding to the program is executed.

[0066] The access management unit 72 manages the service user 200's access to the in-vehicle device 100 using the in-vehicle application based on the program manifest and the user manifest stored in the storage unit 64. The access management unit 72 also manages and provides the private API and public API described above.

[0067] In addition, the program manifest stored in the memory unit 64 specifies the correspondence between the in-vehicle applications installed in the access management device 60 and the ECU 52 other than the access management device 60, and the program permissions for the in-vehicle applications to access the in-vehicle device 100.

[0068] That is, in the vehicle 50, the access management device 60 centrally manages the service user 200's access to the in-vehicle device 100 using the in-vehicle app based on the program manifest and the user manifest.

[0069] The manifest management unit 74 stores the program manifest acquired from the management server 10 and the user manifest acquired from the service server 30 in the storage unit 64 .

[0070] The manifest management unit 74 may receive an integrated manifest that integrates the program manifest and the user manifest from the management server 10, which has acquired the user manifest from the service server 30, and store the integrated manifest in the storage unit 64. The manifest management unit 74 in the access management device 60 provided in the vehicle 50 is also referred to as a third manifest management unit.

[0071] As shown in FIG. 4, the integrated manifest is a manifest in which access authority to the in-vehicle device 100 is set for each application and for each user indicated by a user ID or for each user attribute.

[0072] The user attributes are set for one or more users having the same attribute. The user attributes indicate, for example, the level of access to the in-vehicle device 100. The higher the access level, the more in-vehicle devices 100 the user can access, or the more specific in-vehicle devices 100 the user can access.

[0073] Furthermore, the integrated manifest may be divided for each application and stored in the storage unit 64. For example, a driving diagnosis application has a manifest in which access permissions for the driving diagnosis application are set for each user or each user attribute, and a drive recorder application has a manifest in which access permissions for the drive recorder application are set for each user or each user attribute.

[0074] When apps are installed in the vehicle 50, the manifest management unit 74 stores the manifests of these apps in the storage unit 64. Each app references the manifest related to its own app stored in the storage unit 64, and requests access to the in-vehicle device 100 using a private API or a public API based on user attributes.

[0075] The apps to be installed in the vehicle 50 are stored and installed in the access management device 60 and the other ECU 52 .

[0076] [2. Processing] Next, the access management processing executed by the access management system 2 will be described with reference to the sequence diagrams of Fig. 5 and Fig. 6. The service user 200 shown in Fig. 5 is, for example, a business operator that develops or uses an app, a driver who is an employee of the business operator and drives the vehicle 50, a manufacturer of the vehicle 50, or a management company that manages data on the vehicle 50.

[0077] (1) Pre-processing The access management process shown in Fig. 5 is executed as pre-processing before the service user 200 uses the app, between the management server 10, the service server 30, and the service user 200. The process for the service user 200 is performed via an information processing terminal such as a smartphone or a PC.

[0078] 5, the service user 200 applies to have the service user 200 registered in the management server 10. For example, the name of a business operator is applied as the service user 200.

[0079] In S2, the manifest management unit 20 of the management server 10 stores and registers the applied business name in the storage unit 14. In S3, the manifest management unit 20 of the management server 10 issues an ID of the service user 200 to the service user 200. If the service user 200 is a business, a business ID is issued.

[0080] In S4, the service user 200 applies for the device ID of the in-vehicle device 100 used in the vehicle 50 to be registered in the management server 10 and the service server 30. In S5, the manifest management unit 40 of the service server 30 stores and registers the device ID applied for by the service user 200 in the storage unit 34.

[0081] In S6, the manifest management unit 20 of the management server 10 stores and registers the device ID applied for by the service user 200 in the storage unit 14. If the in-vehicle device 100 indicated by the device ID registered in the storage unit 14 is accessed via a private API that requires access authority, the manifest management unit 20 of the management server 10 stores and registers in the storage unit 14 the validity period during which the in-vehicle device 100 can be accessed.

[0082] In S7, the service user 200 applies for the application developed by the service user 200 to be registered in the management server 10. In S8, the manifest management unit 20 of the management server 10 stores and registers the application applied for by the service user 200 in the storage unit 14. In S9, the manifest management unit 20 of the management server 10 issues to the service user 200 an ID of the application applied for by the service user 200.

[0083] In S10, the service user 200 requests that the application ID issued by the management server 10 be registered in the service server 30. In S11, the manifest management unit 40 of the service server 30 stores and registers the application ID requested by the service user 200 in the storage unit 34.

[0084] In S12, the service user 200 requests the management server 10 to register an application ID registered in the management server 10 in association with the device ID of the in-vehicle device 100 used by the application indicated by the application ID.

[0085] In S13, the manifest management unit 20 of the management server 10 associates the application ID and the device ID stored in the storage unit 14, stores and registers the association in the storage unit 14 as a program manifest.

[0086] In S14, the service user 200 applies to the service server 30 to register a user ID assigned to each employee of the business. In S15, the manifest management unit 40 of the service server 30 stores and registers the user ID requested by the service user 200 in the storage unit 34.

[0087] In S16, the service user 200 requests the management server 10 to issue the requested number of service user IDs. In S17, the manifest management unit 20 of the management server 10 issues the requested number of service user IDs to the service user 200.

[0088] In S18, the service user 200 requests the service server 30 to register the correspondence between the user ID and the service user ID. In S19, the manifest management unit 40 of the service server 30 stores and registers the requested correspondence between the user ID and the service user ID in the storage unit 34.

[0089] A service user ID is set corresponding to a user ID and managed by the management server 10. The user ID is managed by the service server 30. In the example shown in Fig. 4, there is a one-to-one correspondence between the user ID and the service user ID, but one service user ID may correspond to multiple user IDs.

[0090] In S20, the service user 200 requests the service server 30 to register a user manifest corresponding to each service user ID set by the service user 200. In S21, the manifest management unit 40 of the service server 30 stores and registers the user manifest for each service user ID in the storage unit 34.

[0091] In S22, the service user 200 applies to the service server 30 to register a correspondence between the user ID and the device ID used by the user, based on, for example, a usage plan of which vehicle 50 the service user 200 will ride and when.

[0092] In S23, the manifest management unit 40 of the service server 30 stores and registers the correspondence between the requested user ID and the service user ID in the storage unit 34.

[0093] (2) Processing During Use The access management processing shown in FIG. 6 is executed between the management server 10, the service server 30, the access management device 60, and the service user 200 as processing when the service user 200 uses an application.

[0094] In S30, the service user 200 starts up the access management device 60, for example, by turning on the start switch of the vehicle 50.

[0095] In S31, the access management unit 72 of the access management device 60 checks with the management server 10 whether there are any apps that have not been installed on the vehicle 50, and if there are any apps that have not been installed, which in-vehicle device 100 the apps use.

[0096] If there is an app that is not installed on the vehicle 50, in S32 the manifest management unit 20 of the management server 10 transmits the not-installed app and a program manifest corresponding to the app to the vehicle 50.

[0097] The program manifest sets a validity period during which the in-vehicle device 100 can be accessed when the in-vehicle device 100 is accessed via a private API that requires access authority. The program manifest is transmitted to the vehicle 50 prior to or simultaneously with the installation of the app.

[0098] In S33, the manifest management unit 74 of the access management device 60 stores and registers the application received from the management server 10 in the memory unit 64 or in a memory unit (not shown) of the ECU 52 other than the memory unit 64.

[0099] Furthermore, in S33, the manifest management unit 74 of the access management device 60 stores and registers the program manifest received from the management server 10 in the storage unit 64. The program manifest has the aforementioned validity period set therein.

[0100] In S34, the access management unit 72 of the access management device 60 starts the app managed by the access management unit 72. If the program manifest has not been stored correctly, the access management unit 72 does not start the app, or, even if the app is started, prohibits access by the app to all of the in-vehicle devices 100.

[0101] In S35, the service user 200 notifies the service server 30 using a mobile terminal or the like that he or she will log in with a user ID.

[0102] In S36, the service user 200 requests login using a user ID from the access management device 60 using a mobile terminal or the like. In S37 and S38, the access management unit 72 of the access management device 60 notifies the management server 10 and the service server 30 of the user ID and the device ID used with the user ID as user information for logging in, and requests login. The access management unit 72 may request login from the management server 10, and the management server 10 may request login from the service server 30.

[0103] When a login request is received from the vehicle 50, the service server 30 reads out the service user ID corresponding to the user ID and the user manifest corresponding to the service user ID from the storage unit 34. Then, in S39 and S40, the service server 30 transmits the service user ID and the corresponding user manifest to the management server 10 and the vehicle 50. The user manifest is transmitted to the vehicle 50 in response to the login request from the vehicle 50.

[0104] The service server 30 may transmit the service user ID and a user manifest corresponding to the service user ID to the management server 10, and the management server 10 may transmit them to the vehicle 50. The user manifest may specify access authority to the in-vehicle device 100 for the service user ID. The user manifest may also specify attributes for the service user ID and access authority to the in-vehicle device 100 for the attributes.

[0105] In S41 , the manifest management unit 74 of the access management device 60 stores the service user ID and the user manifest received from the service server 30 in the storage unit 64 .

[0106] In S42 , the access management unit 72 manages access to the in-vehicle device 100 by the service user 200 using the application, based on the program manifest and the user manifest stored in the storage unit 64 .

[0107] In S43 and S44, the access management device 60 transmits the service user ID, the device ID used by the service user 200 indicated by the service user ID, and the vehicle data obtained from the vehicle-mounted device 100 indicated by the device ID to the management server 10 and the service server 30.

[0108] In the embodiment described above, the management server 10 and the service server 30 correspond to the servers, the communication unit 12 corresponds to the first communication unit, and the communication unit 32 corresponds to the second communication unit.

[0109] Furthermore, the manifest management units 20 and 40 correspond to the second management unit, the manifest management unit 20 corresponds to the third management unit, the manifest management unit 40 corresponds to the fourth management unit, and the storage units 14 and 34 correspond to the server storage units. The storage unit 14 corresponds to the first server storage unit, the storage unit 34 corresponds to the second server storage unit, and the storage unit 64 corresponds to the device storage unit. The manifest management unit 74 corresponds to the first management unit.

[0110] Furthermore, the program manifest corresponds to the first manifest, the user manifest corresponds to the second manifest, the private API corresponds to the first API, and the public API corresponds to the second API.

[0111] Furthermore, S13 corresponds to the processing of the third management unit of the management server, S21 corresponds to the processing of the fourth management unit of the service server, S33 and S41 correspond to the processing of the manifest management unit of the access management device, and S42 corresponds to the processing of the access management unit of the access management device.

[0112] 3. Effects According to the embodiment described above, the following effects can be obtained.

[0113] (3a) Applicable access to the in-vehicle device 100 can be appropriately managed based on the program manifest and the user manifest.

[0114] (3b) A program manifest and a user manifest are set for an added app and an in-vehicle device 100 in addition to the apps and the in-vehicle device 100 that are installed as standard in the vehicle 50. Therefore, for the added app and the in-vehicle device 100, access of the app to the in-vehicle device 100 can be appropriately managed based on the program manifest and the user manifest.

[0115] 4. Other Embodiments Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments and can be implemented in various modifications.

[0116] (4a) In the above-described embodiment, the access management device 60 stores the apps used by the service user 200 in the memory unit 64 of the access management device 60, but the apps may also be stored in a memory unit (not shown) of another ECU 52 other than the memory unit 64.

[0117] (4b) In the above-described embodiment, two servers, the management server 10 and the service server 30, were set up as servers, but the functions of the management server 10 and the service server 30 may be combined into one server.

[0118] (4c) In the above-described embodiment, the in-vehicle applications for which the access management device 60 manages access to the in-vehicle device 100 are applications installed in the access management device 60 and an ECU 52 other than the access management device 60.

[0119] Without being limited to this, the in-vehicle app for which the access management device 60 manages access to the in-vehicle device 100 may be an app installed in at least one of the access management device 60 and an ECU 52 other than the access management device 60.

[0120] In this case, the program manifest only needs to specify the correspondence between the in-vehicle applications for which the access management device 60 manages access to the in-vehicle device 100 and the program permissions that allow the applications to access the in-vehicle device.

[0121] (4d) The access control device 60 and the techniques described herein may be implemented by a special purpose computer provided by configuring a processor and memory programmed to perform one or more functions embodied in a computer program.

[0122] Alternatively, the access control device 60 and the techniques described in this disclosure may be implemented by a special purpose computer provided by configuring a processor with one or more dedicated hardware logic circuits.

[0123] Alternatively, the access management device 60 and the techniques described herein may be implemented by one or more special-purpose computers configured by a combination of a processor and memory programmed to perform one or more functions, and a processor configured with one or more hardware logic circuits.

[0124] The computer program may be stored as instructions executed by a computer on a non-transitory computer-readable storage medium. The method for realizing the functions of each unit included in the access management device 60 does not necessarily need to include software, and all of the functions may be realized using one or more pieces of hardware.

[0125] (4e) Multiple functions possessed by one component in the above-described embodiments may be realized by multiple components, or one function possessed by one component may be realized by multiple components. Furthermore, multiple functions possessed by multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, part of the configuration of the above-described embodiments may be omitted. Furthermore, at least part of the configuration of the above-described embodiments may be added to or substituted for the configuration of another of the above-described embodiments.

[0126] (4f) In addition to the access management device 60 described above, the present disclosure can also be realized in various forms, such as an access management system 2 having the access management device 60 as a component, an access management program for causing a computer to function as the access management device 60, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and an access management method using the access management system 2 or the access management device 60. [Technical Ideas Disclosed in the Specification] [Item 1] An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, the access management device comprising: a memory unit (64) configured to store a first manifest indicating the correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating the correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; and an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the memory unit.

[0127] [Item 2] The access management device according to Item 1, wherein the user authority indicates at least one of the in-vehicle devices that the user can access among the in-vehicle devices that the application program can access, the data related to the in-vehicle devices that the user can access, and the operations that are permitted for the in-vehicle devices that the user can access.

[0128] [Item 3] The access management device according to Item 1 or 2, further comprising: a manifest management unit (74, S33) configured to, when acquiring the application program from the server via communication, acquire the first manifest corresponding to the application program from the server via communication and store the first manifest in the storage unit.

[0129] [Item 4] The access management device according to any one of Items 1 to 3, further comprising: a manifest management unit (74, S41) configured to store the second manifest, acquired through communication from the server, in the storage unit based on information about the user.

[0130] [Item 5] The access management device according to any one of Items 1 to 4, wherein the access management unit is configured to provide, when accessing the in-vehicle device, a first API that requires access authority to the in-vehicle device and a second API that does not require the access authority to the in-vehicle device.

[0131] [Item 6] The access management device according to Item 5, wherein the access management unit is configured to, when the user uses the application program to access the in-vehicle device for which the access authority is required, acquire a validity period of the access authority from the server via communication, and permit the user to use the application program to access the in-vehicle device for which the access authority is required during the acquired validity period.

[0132] [Item 7] An access management device according to any one of items 1 to 6, wherein the first manifest specifies the correspondence between the application programs installed in the access management device and an in-vehicle electronic control device other than the access management device, and the program authority for the application programs to access the in-vehicle device.

[0133] [Item 8] An access management system (2) comprising: a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; and an in-vehicle access management device (60) that communicates with the server, wherein the access management device comprises: a device storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access an in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the device storage unit; and a first management unit (74, S33, 341) configured to manage storage of data received from the server, wherein the server comprises: a communication unit (12, 32) configured to communicate with the vehicles; and a server storage unit (14, 34), An access management system comprising: a second management unit (20, 40, S13, S21) configured to store the first manifest and the second manifest in the server memory unit; wherein the second management unit is configured to transmit the first manifest and the second manifest stored in the server memory unit from the communication unit to the vehicle; and the first management unit is configured to store the first manifest and the second manifest obtained from the server through communication in the device memory unit.

[0134] [Item 9] An access management system according to Item 8, wherein the second management unit is configured to transmit the first manifest stored in the server memory unit corresponding to the application program to the vehicle when transmitting the application program from the communication unit to the vehicle, and the second management unit is configured to, when acquiring the application program from the server via communication, acquire the first manifest corresponding to the application program from the server via communication and store it in the device memory unit.

[0135] [Item 10] In the access management system described in Item 8 or 9, the server comprises: a management server (10) and a service server (30); the management server comprises: a first communication unit (12) as the communication unit that communicates with the vehicle; a first server storage unit (14) of the server storage unit configured to store the first manifest; and a third management unit (20, S13) of the second management unit configured to store the first manifest in the first server storage unit; the service server comprises: a second communication unit (32) as the communication unit that communicates with the vehicle; a second server storage unit (34) of the server storage unit configured to store the second manifest; and a fourth management unit (40, S21) of the second management unit configured to store the second manifest in the second server storage unit; and the third management unit is configured to transmit the first manifest stored in the first server storage unit to the vehicle from the first communication unit, An access management system, wherein the fourth management unit is configured to transmit the second manifest stored in the second server memory unit to the vehicle from the second communication unit, and the first management unit is configured to store the first manifest obtained from the management server via communication in the device memory unit, and to store the second manifest obtained from the service server via communication in the device memory unit.

[0136] [Item 11] An access management program installed in an in-vehicle access management device (60) that manages vehicle data acquired from multiple vehicles (50) and causes a computer to communicate with a server (10, 30) that provides services related to the vehicles based on the vehicle data, the access management program causing a computer to function as: a memory unit (64) configured to store a first manifest indicating the correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating the correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; and an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the memory unit.

[0137] [Item 12] An access management method using an access management system comprising: a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; and an in-vehicle access management device (60) that communicates with the server, wherein the server stores a first manifest indicating a correspondence between an application program and a program authority for the application program to access an in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; the server transmits the stored first manifest and second manifest to the vehicle; the access management device acquires the first manifest and the second manifest from the server via communication and stores them; and manages access by the user to the in-vehicle device using the application program based on the stored first manifest and second manifest.

Claims

1. An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; a manifest management unit (74, S33, S41) configured to store at least one of the first manifest and the second manifest acquired from the server through communication in the device storage unit; An access management device comprising:

2. The access management device according to claim 1, The user authority indicates at least one of the in-vehicle devices that the user can access among the in-vehicle devices that the application program can access, data that the user can access among data related to the in-vehicle devices, and operations that are permitted for the in-vehicle devices that the user can access. Access control devices.

3. The access management device according to claim 1, the manifest management unit is configured to, when acquiring the application program from the server through communication, acquire the first manifest corresponding to the application program from the server through communication and store the first manifest in the storage unit; Access control devices.

4. The access management device according to claim 1, The manifest management unit is configured to store the second manifest acquired from the server through communication in the storage unit based on information of the user. Access control devices.

5. An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; Equipped with the access management unit is configured to, when the user uses the application program to access the in-vehicle device requiring access authority, acquire a validity period of the access authority from the server through communication, and permit the user to access the in-vehicle device requiring access authority using the application program during the acquired validity period. Access control devices.

6. 6. The access management device according to claim 5, the access management unit is configured to provide, when accessing the in-vehicle device, a first API that requires the access authority to the in-vehicle device and a second API that does not require the access authority to the in-vehicle device. Access control devices.

7. An in-vehicle access management device (60) that manages vehicle data acquired from a plurality of vehicles (50) and communicates with a server (10, 30) that provides services related to the vehicles based on the vehicle data, a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; Equipped with The first manifest specifies a correspondence between the application program installed in the access management device and an in-vehicle electronic control device (52) other than the access management device, and the program authority for the application program to access the in-vehicle device. Access control devices.

8. a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; an access management device (60) mounted on the vehicle in communication with the server; An access control system (2) comprising: The access management device includes: a device storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access to the in-vehicle device by the user using the application program based on the first manifest and the second manifest stored in the device storage unit; A first management unit (74, S33, 341) configured to manage storage of data received from the server; Equipped with The server, A communication unit (12, 32) configured to communicate with the vehicle; A server storage unit (14, 34); A second management unit (20, 40, S13, S21) configured to store the first manifest and the second manifest in the server storage unit; Equipped with the second management unit is configured to transmit the first manifest and the second manifest stored in the server storage unit from the communication unit to the vehicle, The first management unit is configured to store the first manifest and the second manifest acquired from the server through communication in the device storage unit. Access control system.

9. 9. The access control system according to claim 8, the second management unit is configured to transmit, to the vehicle, the first manifest stored in the server storage unit in correspondence with the application program when transmitting the application program from the communication unit to the vehicle; the first management unit is configured to, when acquiring the application program from the server through communication, acquire the first manifest corresponding to the application program from the server through communication and store the first manifest in the device storage unit; Access control system.

10. 10. The access management system according to claim 8 or 9, The server, The system comprises a management server (10) and a service server (30), The management server includes: As the communication unit, a first communication unit (12) that communicates with the vehicle; A first server storage unit (14) configured to store the first manifest in the server storage unit; A third management unit (20, S13) of the second management unit configured to store the first manifest in the first server storage unit; Equipped with The service server includes: As the communication unit, a second communication unit (32) that communicates with the vehicle; A second server storage unit (34) configured to store the second manifest in the server storage unit; A fourth management unit (40, S21) of the second management unit configured to store the second manifest in the second server storage unit; Equipped with the third management unit is configured to transmit the first manifest stored in the first server storage unit from the first communication unit to the vehicle, the fourth management unit is configured to transmit the second manifest stored in the second server storage unit from the second communication unit to the vehicle, the first management unit is configured to store the first manifest acquired from the management server through communication in the device storage unit, and to store the second manifest acquired from the service server through communication in the device storage unit; Access control system.

11. An access management program installed in an access management device (60) installed in a vehicle, the access management program managing vehicle data acquired from a plurality of vehicles (50) and causing a computer to function to communicate with a server (10, 30) that provides a service related to the vehicles based on the vehicle data, the access management program comprising: a storage unit (64) configured to store a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; an access management unit (72, S42) configured to manage access by the user to the in-vehicle device using the application program based on the first manifest and the second manifest stored in the storage unit; a manifest management unit (74, S33, S41) configured to store at least one of the first manifest and the second manifest acquired from the server through communication in the device storage unit; Access control program that enables a computer to function as a

12. a server (10, 30) that manages vehicle data acquired from a plurality of vehicles (50) and provides services related to the vehicles based on the vehicle data; an access management device (60) mounted on the vehicle in communication with the server; An access management method by an access management system comprising: the server stores a first manifest indicating a correspondence between an application program and a program authority for the application program to access the in-vehicle device (100), and a second manifest indicating a correspondence between a user and a user authority for the user to access the in-vehicle device using the application program; Transmitting the stored first manifest and the stored second manifest to the vehicle; The access management device includes: acquiring the first manifest and the second manifest from the server through communication and storing the first manifest and the second manifest; managing access to the in-vehicle device by the user using the application program based on the stored first manifest and the stored second manifest; Access management methods.