User authentication method, user authentication system, and program
Patent Information
- Application Number
- JP2024570053
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2025-07-02
- Publication Date
- 2025-09-22
AI Technical Summary
Current vehicle security systems do not adequately address the need for continuous user authentication during vehicle operation, particularly in scenarios where unauthorized access could compromise safety and functionality, and fail to restrict functions effectively in case of authentication failure.
A user authentication method and system that authenticates a first user at a initial time point and continuously verifies if the user remains the same during vehicle operation, enabling or restricting vehicle functions based on the authentication results, with mechanisms to prioritize safety and prevent unauthorized use.
Enhances vehicle security by ensuring only authorized users can access contracted functions, maintaining safety features even if the initial user is replaced, and effectively limiting unauthorized access to prevent safety and operational compromises.
Abstract
Description
User authentication method and user authentication system
[0001] The present disclosure relates to a user authentication method and a user authentication system.
[0002] Various studies have been conducted on vehicle security. For example, Patent Document 1 discloses a vehicle control system that can improve vehicle theft prevention measures.
[0003] Japanese Patent Application Laid-Open No. 2017-202708
[0004] Meanwhile, it is desirable to improve security performance in vehicles.
[0005] Therefore, the present disclosure provides a user authentication method and a user authentication system with improved security performance.
[0006] A user authentication method according to one aspect of the present disclosure is a user authentication method for authenticating a user riding in a vehicle, which authenticates a first user riding in the vehicle at a first point in time, enables a function of the vehicle corresponding to the authenticated first user, determines whether the second user riding in the vehicle is the same person as the first user at a second point in time that is later than the first point in time and while the vehicle is traveling, and performs processing related to restricting the enabled function depending on the determination result of whether they are the same person.
[0007] A user authentication system according to one aspect of the present disclosure is a user authentication system that authenticates a user riding in a vehicle, and includes: an authentication unit that authenticates a first user riding in the vehicle at a first point in time; a first control unit that enables a function of the vehicle according to the authenticated first user; a determination unit that determines whether the second user riding in the vehicle is the same person as the first user at a second point in time that is later than the first point in time and while the vehicle is traveling; and a second control unit that executes processing related to restricting the enabled function according to the determination result of whether they are the same person.
[0008] According to one aspect of the present disclosure, it is possible to realize a user authentication method with improved security performance.
[0009] FIG. 1 is a block diagram showing the functional configuration of a user authentication system according to an embodiment. FIG. 2 is a diagram showing a correspondence relationship between a vehicle state and a user authentication method according to an embodiment. FIG. 3 is a diagram showing SFOP classification information according to an embodiment. FIG. 4 is a diagram showing authority information according to an embodiment. FIG. 5 is a flowchart showing an overview of a user authentication method in a user authentication system according to an embodiment. FIG. 6A is a flowchart showing a user authentication method before a vehicle starts moving in a user authentication system according to an embodiment. FIG. 6B is a flowchart showing a user authentication method while a vehicle is moving in a user authentication system according to an embodiment. FIG. 7A is a diagram schematically showing a case where a user at a second time point is the same person as at a first time point. FIG. 7B is a diagram schematically showing a case where a user at a second time point is not the same person as at a first time point.
[0010] (Background to the Invention of the Present Disclosure) Before describing the embodiments of the present disclosure, the background to the invention of the present disclosure will be described.
[0011] It is being considered to provide a service for which a user has previously signed up while the vehicle is in motion (for example, to enable a vehicle function for realizing the service). In providing such a service, the user is authenticated by personal authentication before getting into the vehicle and starting to drive (for example, before driving), and the user can receive the service for which the user previously signed up while the vehicle is in motion (for example, while driving).
[0012] In recent years, attention has been focused on zero trust as a new security measure. Zero trust involves suspecting and controlling all access, not only from the outside but also from within.
[0013] It is desirable that such security measures be applied to vehicles as well. For example, when zero trust is applied to a vehicle, all access, even from inside the vehicle, is suspected and controlled. Therefore, when zero trust is applied to a vehicle, it is desirable to perform personal authentication while the vehicle is traveling, in addition to personal authentication before the vehicle begins to travel. However, the above-mentioned Patent Document 1 does not disclose authentication that takes zero trust into consideration.
[0014] Therefore, the inventors of the present application have conducted extensive research into user authentication methods and systems with improved security performance, and have devised the following user authentication method and system. The inventors have also devised a user authentication method and system that can safely restrict functions when authentication fails.
[0015] A user authentication method according to a first aspect of the present disclosure is a user authentication method for authenticating a user riding in a vehicle, which authenticates a first user riding in the vehicle at a first point in time, enables a function of the vehicle according to the authenticated first user, determines whether the second user riding in the vehicle is the same person as the first user at a second point in time that is later than the first point in time and while the vehicle is traveling, and performs processing related to restricting the enabled function according to the determination result of whether they are the same person.
[0016] This allows a determination as to whether the first user at the first point in time and the second user at the second point in time are the same person, thereby improving the security performance of the vehicle compared to, for example, performing user authentication only once. For example, if the vehicle is stolen or the system is hacked and the enabled functions are changed after user authentication at the first point in time, the user authentication method according to one aspect of the present disclosure can restrict the vehicle functions accordingly.
[0017] Also, for example, a user authentication method according to a second aspect of the present disclosure may be a user authentication method according to a first aspect, and if the determination result indicates that the persons are not the same person, the enabled function may be stopped as a process related to the restriction.
[0018] As a result, if the first user and the second user are different persons, the second user can be restricted from using the function corresponding to the first user (for example, the function subscribed to by the first user). Therefore, the user authentication method can improve the security performance of the vehicle in terms of preventing unauthorized use of the function corresponding to the first user.
[0019] Furthermore, for example, a user authentication method according to a third aspect of the present disclosure may be the user authentication method according to the second aspect, and when the determination result indicates that the person is not the same person, the restriction-related processing may further determine whether the enabled function is a function related to the safety of the vehicle during operation, and if it is determined that the enabled function is not a function related to safety, the enabled function may be stopped.
[0020] As a result, even if the first user and the second user are different people, safety-related functions remain enabled, thereby preventing a decrease in safety when driving the vehicle.
[0021] Furthermore, for example, the user authentication method according to the fourth aspect of the present disclosure may be the user authentication method according to the third aspect, and if it is determined that the function is related to safety, the processing related to the restriction may be to stop the enabled function after the state of the vehicle reaches a safe state in which the enabled function can be safely stopped.
[0022] This allows the function corresponding to the first user to be stopped after the vehicle has reached a state where the function can be stopped safely, so the user authentication method can achieve both improved security performance of the vehicle and safety when the vehicle is driven.
[0023] Also, for example, a user authentication method according to a fifth aspect of the present disclosure may be a user authentication method according to the fourth aspect, in which the vehicle state includes a state in which the vehicle is running, a state in which the vehicle is temporarily stopped, and a state in which the engine is stopped, and the safe state may be a state in which the engine is stopped.
[0024] As a result, when the vehicle is traveling or is temporarily stopped, safety-related functions are not stopped, so that a decrease in safety during vehicle traveling can be effectively suppressed.
[0025] Furthermore, for example, the user authentication method according to the sixth aspect of the present disclosure may be the user authentication method according to the third aspect, and when it is determined that the function is related to safety, the processing related to the restriction may involve forcibly moving the vehicle to a position where the enabled function can be safely stopped, and stopping the enabled function after the vehicle has moved to that position.
[0026] This shortens the time that the second user uses the function corresponding to the first user, thereby further improving the security performance of the vehicle in terms of preventing unauthorized use of the function.
[0027] Furthermore, for example, a user authentication method according to a seventh aspect of the present disclosure may be a user authentication method according to any of the first to sixth aspects, in which the state of the vehicle is determined at the first point in time, and an authentication method for the user at the first point in time is determined based on the determination result, and the state of the vehicle is determined at the second point in time, and an authentication method for the user at the second point in time is determined based on the determination result.
[0028] This allows user authentication to be performed at each of the first and second points in time using an authentication method appropriate for the state of the vehicle at that time.
[0029] Furthermore, for example, a user authentication method according to an eighth aspect of the present disclosure may be the user authentication method according to the seventh aspect, wherein the first point in time is a point in time when the first user gets into the vehicle but before the vehicle starts moving, and at the first point in time, authentication of the user is performed by an input-type authentication method that accepts input from the first user or a contactless authentication method that uses the results of sensing the first user, and at the second point in time, authentication of the user is performed by the contactless authentication method of the input-type and contactless methods.
[0030] This allows user authentication to be performed using an authentication method that causes less driver distraction while the vehicle is in motion, allowing the user to concentrate on driving. Therefore, the user authentication method can improve the security performance of the vehicle without distracting the user while driving.
[0031] Also, for example, a user authentication method according to a ninth aspect of the present disclosure is a user authentication method according to any one of the first to eighth aspects, and the determination of whether the person is the same may be performed multiple times while the vehicle is traveling.
[0032] This allows the determination of whether or not the persons are the same to be performed multiple times, making it possible to detect early on that a second user, who is a different person from the first user, has entered the vehicle and disable the function, thereby further improving the security performance of the vehicle.
[0033] A user authentication system according to a tenth aspect of the present disclosure is a user authentication system that authenticates a user riding in a vehicle, and includes an authentication unit that authenticates a first user riding in the vehicle at a first point in time, a first control unit that enables a function of the vehicle according to the authenticated first user, a determination unit that determines whether the second user riding in the vehicle is the same person as the first user at a second point in time that is later than the first point in time and while the vehicle is traveling, and a second control unit that executes processing related to restricting the enabled function according to the determination result of whether they are the same person.
[0034] This provides the same effect as the above-mentioned user authentication method.
[0035] These general or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of the system, the method, the integrated circuit, the computer program, or the recording medium. The program may be pre-stored in the recording medium, or may be supplied to the recording medium via a wide area communication network including the Internet.
[0036] Hereinafter, the embodiments will be specifically described with reference to the drawings.
[0037] The embodiments described below are all comprehensive or specific examples. The numerical values, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not described in independent claims are described as optional components.
[0038] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.
[0039] Furthermore, in this specification, numerical values and numerical ranges are not expressions that express only the strict meaning, but are expressions that mean that they also include a substantially equivalent range, for example, a difference of about several percent (or about 10%).
[0040] (Embodiment) Hereinafter, a user authentication system according to the present embodiment will be described with reference to Figs. 1 to 7B.
[0041] [1. Configuration of User Authentication System] First, the configuration of a user authentication system according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a block diagram showing the functional configuration of a user authentication system 1 according to this embodiment.
[0042] 1, the user authentication system 1 includes a vehicle 10 and a server 20. The vehicle 10 and the server 20 are connected to each other so as to be able to communicate with each other.
[0043] Vehicle 10 is an example of a moving body that a user rides in, such as an automobile, a bus, or a train. In the present embodiment, vehicle 10 is an automobile, and more specifically, an autonomously driven vehicle that can be driven autonomously. Vehicle 10 may be a fully autonomously driven vehicle, or may be a vehicle that can switch between autonomous driving and manual driving.
[0044] The user is a person, such as a driver, who rides in the vehicle 10. The user may have previously signed up for a service related to the vehicle 10, and may receive the service while traveling.
[0045] The vehicle 10 has a camera 11a, a fingerprint authentication sensor 11b, a pressure sensor 11c, a distraction determination unit 12, an authentication unit 13, an execution control unit 14, a safety determination unit 15, a memory unit 16, a navigation system 17a, an autonomous driving system 17b, and a device linkage unit 17c.
[0046] The camera 11a and the fingerprint authentication sensor 11b are sensors for authenticating a user.
[0047] The camera 11a is an example of a sensor for performing face authentication, and captures an image of the user's face. By using the camera 11a, user authentication can be performed without contact. The camera 11a may be capable of acquiring an iris. The camera 11a may be a sensor for performing iris authentication. The camera 11a may be provided integrally with a rearview mirror, for example.
[0048] The fingerprint authentication sensor 11b is an example of a sensor for performing biometric authentication, and reads a fingerprint of a user when the user touches the fingerprint authentication sensor 11b. The fingerprint authentication sensor 11b is a sensor that requires a user operation of touching the fingerprint authentication sensor 11b.
[0049] The sensors for authenticating a user are not limited to those described above, and the vehicle 10 may have other sensors instead of or in addition to the camera 11 a and the fingerprint authentication sensor 11 b. The vehicle 10 may also have, as sensors for authenticating a user, a reception unit (e.g., a touch sensor, a button, or the like) that receives input of a password for password authentication, a microphone for voiceprint authentication, or the like.
[0050] As described above, there are multiple user authentication methods, and in this embodiment, an authentication method is selected according to the user authentication timing. Face authentication and voiceprint authentication are examples of contactless authentication methods (authentication methods that do not involve user operation) that use the results of sensing the user, while fingerprint authentication and password authentication are examples of input-based authentication methods that accept input from the user (authentication methods that involve user operation). Below, examples of using face authentication, fingerprint authentication, and password authentication as user authentication methods will be described.
[0051] The pressure sensor 11c is a sensor that detects whether a user gets in or out of the vehicle 10, and is arranged, for example, on the steering wheel or the seat of the vehicle 10. Note that the vehicle 10 may have an opening / closing sensor that detects whether a door is opened or closed instead of or together with the pressure sensor 11c.
[0052] The distraction determination unit 12 determines whether or not a distraction (distraction) occurs to the user due to an authentication operation while the vehicle 10 is traveling (for example, while the user is driving). The distraction determination unit 12 acquires at least one of the state of the user and the state of the vehicle 10 when the authentication operation is performed from a sensor, and determines whether or not a distraction (driver distraction) occurs to the user based on the acquired at least one of the state of the user and the state of the vehicle 10.
[0053] The user state indicates the operation being performed by the user, and includes wiper operation, light operation, etc. The user state can be acquired, for example, from an image captured by the camera 11a. The state of the vehicle 10 is the running state of the vehicle 10, and includes running, being temporarily stopped, and the engine being stopped. The state of the vehicle 10 can be acquired from the speed information of the vehicle 10, whether the engine is stopped, the location of the vehicle 10, etc. The engine being stopped is an example of a safe state in which an enabled function of the vehicle 10 can be safely stopped.
[0054] Furthermore, the distraction determination unit 12 determines the authentication method depending on the state of the vehicle 10. The distraction determination unit 12 varies the authentication method depending on the state of the vehicle 10. Fig. 2 is a diagram showing the correspondence between the state of the vehicle 10 and the user authentication method according to this embodiment. Fig. 2 shows sensors that can be used for each state of the vehicle 10.
[0055] 2, the states of the vehicle 10 include running, temporarily stopping, and engine stop, and the authentication methods include face authentication, fingerprint authentication, and password authentication. When running (for example, while driving), authentication is performed by face authentication only, when temporarily stopping, authentication is performed by face authentication and fingerprint authentication, and when the engine is stopped, authentication is performed by face authentication, fingerprint authentication, and password authentication.
[0056] Fingerprint authentication is not used for authentication while the vehicle is moving because it requires the user to touch the fingerprint authentication device (fingerprint authentication sensor 11b) and is a driver distraction. Password authentication is not used while the vehicle is moving or stopped because it requires the user to enter a password and is a driver distraction for a certain period of time.
[0057] In this way, user authentication is performed using an authentication method that causes less driver distraction while the vehicle is running than before the vehicle is running, that is, requires less user operation and is less likely to attract the user's attention.
[0058] The distraction determination unit 12 determines the authentication method to be used for the current authentication based on the current state of the vehicle 10 and the correspondence relationship shown in Fig. 2. Information indicating the correspondence relationship shown in Fig. 2 is set in advance and stored in the storage unit 16.
[0059] The authentication unit 13 performs user authentication by identifying an individual user based on information acquired from the sensor. The authentication unit 13 identifies which user in the authentication information 21 a stored in the storage unit 21 of the server 20 the user who boarded the vehicle 10 is.
[0060] The authentication unit 13 also acquires authority information 21b including services and functions that the authenticated user has subscribed to. The authority information 21b will be described later with reference to FIG.
[0061] The authentication unit 13 also performs user authentication while the vehicle 10 is traveling, and determines whether the user authenticated before the vehicle 10 is traveling and the user authenticated while the vehicle 10 is traveling are the same person. Hereinafter, authentication while traveling will also be referred to as re-authentication, and a determination that the two users are the same person in the determination of whether they are the same person will also be referred to as re-authentication success, and a determination that the two users are not the same person in the determination of whether they are the same person will also be referred to as re-authentication failure.
[0062] The execution control unit 14 performs control to realize the services and functions to which the user authenticated by the authentication unit 13 has subscribed. If the authenticated user has subscribed to a navigation service, the execution control unit 14 controls the navigation system 17a to execute navigation while the vehicle 10 is traveling. If the authenticated user has subscribed to an autonomous driving service, the execution control unit 14 controls the autonomous driving system 17b to execute autonomous driving of the vehicle 10. If the authenticated user has subscribed to a device cooperation service, the execution control unit 14 controls the device cooperation unit 17c to execute device cooperation within the vehicle 10.
[0063] The device may be, for example, an information terminal such as a smartphone, and device linkage may be, for example, communication between a device (for example, an in-vehicle display) mounted on the vehicle 10 and the information terminal, enabling navigation settings, music playback, etc. The device linkage unit 17c may be, for example, a component for realizing in-vehicle infotainment (IVI).
[0064] The execution control unit 14 also executes access to information that is permitted for the user authenticated by the authentication unit 13 (for example, the user information 16b or the billing-related information 16c).
[0065] Furthermore, if the re-authentication fails, the execution control unit 14 executes a process to restrict the execution of the service / function determined by the safety determination unit 15 .
[0066] Based on the SFOP classification, the safety determination unit 15 determines whether or not the service / function to be stopped when the authentication unit 13 fails in re-authentication is a service / function related to the safety of traveling of the vehicle 10. The SFOP classification indicates four categories: safety, financial, operational, and privacy. The SFOP classification will be described later with reference to FIG. 3 .
[0067] The storage unit 16 is a storage device that stores various information for performing user authentication in the vehicle 10. The storage unit 16 is realized by, for example, a semiconductor memory, but is not limited to this.
[0068] The storage unit 16 stores, for example, SFOP classification information 16a, user information 16b, and billing-related information 16c.
[0069] SFOP classification information 16a is information used for the judgment of safety judgment unit 15, and includes information indicating which service / function corresponds to which SFOP classification. Fig. 3 is a diagram showing SFOP classification information 16a according to this embodiment.
[0070] As shown in FIG. 3, SFOP classification information 16a is information in which an SFOP classification is associated with each service / function, and includes information on the service / function, SFOP classification, vehicle status, and whether or not the function can be stopped at the present time.
[0071] The user information 16b is information including personal information of the user, such as, but not limited to, location information of the user's home, an address book, a music playlist, etc. If the authenticated user is a user permitted to access the user information 16b, the user information 16b can be accessed by the execution control unit 14.
[0072] The billing-related information 16c is information including a payment history of fees such as ETC (Electronic Toll Collection System) fees. If the authenticated user is a user permitted to access the billing-related information 16c, the execution control unit 14 can access the billing-related information 16c.
[0073] Whether access is permitted or not can be obtained from the authority information 21b.
[0074] The navigation system 17a, the automatic driving system 17b, and the device linkage unit 17c are components for realizing services that can be used by a user. When a user signs a contract with an automobile manufacturer or a service provider, functions such as navigation, automatic driving, and device linkage become available in the vehicle 10.
[0075] The navigation system 17a is a system that provides route guidance to a destination by registering the destination or a route to the destination on a map, and outputs images and sounds including information for guiding the vehicle 10 equipped with the navigation system 17a to an output device (e.g., a display device, a sound output device, etc.) equipped on the vehicle 10. The navigation system 17a is composed of, for example, a camera that captures images of the surroundings of the vehicle 10, an image processing device that generates an image in which information acquired from a navigation device of the vehicle 10 is superimposed on the image captured by the camera, an output device, etc. The navigation device has a function of receiving GPS (Global Positioning System) radio waves emitted from GPS satellites and calculating various parameters extracted from the GPS radio waves to identify the current position of the vehicle as the vehicle position.
[0076] If a user makes a contract for a navigation service, software for navigation is installed in the vehicle 10, and when the contracted user gets into the vehicle 10 and user authentication is successful, the navigation function becomes active.
[0077] The automatic driving system 17b is a system that performs automatic driving of the vehicle 10, and is composed of various sensors that detect the surrounding conditions of the vehicle 10, a control device that predicts danger based on the detection results of the various sensors, determines the operation content of the vehicle 10, and controls the autonomous driving of the vehicle 10.
[0078] If a user signs up for an autonomous driving service, software for autonomous driving is installed in the vehicle 10, and when the contracted user gets into the vehicle 10 and user authentication is successful, the autonomous driving function is enabled.
[0079] The device linking unit 17c links devices mounted on the vehicle 10 with devices such as a smartphone carried by the user in order to realize in-vehicle infotainment. Linking may mean enabling communication from one device to another device and further enabling control of the other device from one device.
[0080] When a user makes a contract for the device linkage service, software for device linkage is installed in the vehicle 10, and when the contracted user gets into the vehicle 10 and user authentication is successful, the device linkage function becomes effective.
[0081] Note that being enabled means that the executive control unit 14 is able to control the navigation system 17a, the automatic driving system 17b, and the device linkage unit 17c.
[0082] The server 20 is a server that executes processing for user authentication, and includes a storage unit 21 that stores, for example, authentication information 21 a and authority information 21 b. The storage unit 21 is realized by, for example, a semiconductor memory, but is not limited to this.
[0083] The authentication information 21a includes information that can identify a user authenticated by the authentication unit 13. For example, when facial authentication is performed, the authentication information 21a may include information for facial authentication of the user (for example, a facial image of the user).
[0084] The authority information 21b includes, for each user, authority regarding access to various information and execution of functions of the vehicle 10. The authority regarding access to various information is an example of an access right, and is, for example, the authority required to read information stored in the memory unit 16. The authority regarding execution of functions of the vehicle 10 is an example of an execution right, and is the authority to enable functions installed in the vehicle 10 in order to receive the provision of services to which the user has subscribed. Figure 4 is a diagram showing the authority information 21b according to this embodiment.
[0085] As shown in Fig. 4, the authority information 21b includes, for each user, the details of the services and functions to which the user has subscribed. In the example of Fig. 4, user A has subscribed to an autonomous driving service, and user B has subscribed to a music distribution service. The authority information 21b may also include, for each user, information indicating information that the user can access (e.g., user information 16b or billing-related information 16c in the storage unit 16).
[0086] 2. Operation of the User Authentication System Next, the operation of the user authentication system 1 configured as above will be described with reference to Fig. 5 to Fig. 7B. Fig. 5 is a flowchart showing an outline of the user authentication method in the user authentication system 1 according to this embodiment.
[0087] 5 , first, before the vehicle 10 starts traveling (for example, before the user starts driving), the authentication unit 13 authenticates the user who has boarded the vehicle 10 (S1). The authentication unit 13 authenticates the user using at least one of face authentication, fingerprint authentication, and password authentication. Note that before traveling is an example of a first time point.
[0088] Next, the execution control unit 14 starts executing a service / function corresponding to the user authenticated by the authentication unit 13 (S2). The execution control unit 14 controls, for example, at least one of the navigation system 17a, the automatic driving system 17b, and the device linkage unit 17c to enable a function of the vehicle 10 corresponding to the service subscribed to by the user, and starts executing the service / function. In this way, the execution control unit 14 functions as a first control unit that enables a function of the vehicle 10 corresponding to the authenticated user.
[0089] Next, the vehicle 10 determines whether or not it has started to travel based on information from the speed sensor, etc. (S3). If it is determined that it has started to travel (Yes in S3), the process proceeds to step S4. If it is determined that it has not started to travel (No in S3), the process returns to step S3 and continues.
[0090] Next, the authentication unit 13 determines whether the user aboard the vehicle 10 while it is moving is the same person as the user authenticated before it started moving (S4). The authentication unit 13 performs re-authentication while the vehicle 10 is moving, and determines whether the user is the same person based on the result of the re-authentication and the result of the authentication in step S1. In this way, the authentication unit 13 functions as a determination unit. Note that while the vehicle 10 is moving is an example of a second time point.
[0091] The first and second time points are different times between the time when the user gets into the vehicle 10 and the time when the vehicle 10 arrives at the destination.
[0092] Next, if the execution control unit 14 determines that the user is the same person as before driving (Yes in S4), it continues executing the services and functions corresponding to the user (S5), and if it determines that the user is not the same person as before driving (No in S4), it stops executing the services and functions corresponding to the user authenticated in step S1 unless the safety of the vehicle 10 would be reduced (S6). In other words, if the re-authentication fails and stopping the services and functions corresponding to the user authenticated in step S1 would reduce the safety of the vehicle 10, the execution control unit 14 continues executing the services and functions corresponding to the user authenticated in step S1.
[0093] In this way, the execution control unit 14 functions as a second control unit that executes processing related to limiting the enabled functions depending on the determination result of whether or not the persons are the same.
[0094] 6A and 6B, the method for authenticating a user before and after the vehicle 10 starts to travel will be described below. Fig. 6A is a flowchart showing the method for authenticating a user before the vehicle 10 starts to travel in the user authentication system 1 according to this embodiment.
[0095] 6A, the execution control unit 14 initializes the access rights and execution rights (S10). The execution control unit 14, for example, disables all access rights and disables all execution rights. The process of step S10 may be executed, for example, when a predetermined time or more has elapsed since the previous user authentication.
[0096] Next, the authentication unit 13 authenticates the user (first user) using the available sensors (S20). The authentication unit 13 identifies the sensors that are currently available (before driving in this case) from the information indicating the correspondence relationships shown in Fig. 2. Here, the authentication unit 13 can use any of face authentication, fingerprint authentication, and password authentication.
[0097] Next, if the authentication unit 13 fails to authenticate the user (No in S30), the execution control unit 14 returns to step S20 to continue the process. If the authentication unit 13 successfully authenticates the user (Yes in S30), the execution control unit 14 identifies the individual user, obtains service / function information (authority information 21b) for which the user has subscribed from the server 20 (S40), and sets access rights and execution rights for services / functions according to the authority corresponding to the user (S50). Setting the access rights means that information according to the authority corresponding to the user can be read, and setting the execution rights means that the function of the vehicle 10 according to the authority corresponding to the user is enabled (made available).
[0098] Next, a user authentication method performed while the vehicle 10 is traveling will be described with reference to FIG. 6B . FIG. 6B is a flowchart showing a user authentication method performed while the vehicle 10 is traveling in the user authentication system 1 according to the present embodiment. While the vehicle 10 is traveling, the process shown in FIG. 6B is executed at least once, and in this embodiment, it is executed multiple times. The process shown in FIG. 6B may be executed periodically, for example, or may be executed the next time the user gets into the vehicle 10 if there is a possibility that the user has exited the vehicle 10 based on the pressure sensor 11c, the door opening / closing sensor, or the like.
[0099] First, the distraction determination unit 12 acquires the status of the user (second user) and the vehicle 10 from the sensors (S110). The distraction determination unit 12 acquires information indicating whether the user's status, such as whether the user is operating a device or checking the situation around the vehicle 10, is in a state in which authentication can be performed, from the image captured by the camera 11a. The distraction determination unit 12 also acquires, from a speed sensor or the like, the status of the vehicle 10, indicating whether the vehicle 10 is currently running, temporarily stopped, or with the engine stopped. The status of the vehicle 10 is information indicating how much attention the user needs to pay to the driving of the vehicle 10. The status of the vehicle 10 may include a state in which the user needs to pay particular attention to driving, such as the driving speed, overtaking, or parking.
[0100] Next, the distraction determination unit 12 determines whether or not the authentication operation will cause a driver distraction based on at least one of the acquired user state and vehicle state (S120). The distraction determination unit 12 may determine that a driver distraction will occur if, for example, the state of the vehicle 10 is one in which the user must pay particular attention, or may determine that a driver distraction will occur if the user is operating a device or the like. The distraction determination unit 12 may make the determination in step S120 using a table in which at least one of the user state and the vehicle state 10 is associated with whether or not a driver distraction will occur. The table is stored in advance in the storage unit 16.
[0101] Next, if the distraction determination unit 12 determines that no driver distraction will occur (No in S120), the authentication unit 13 performs user authentication using available sensors (see FIG. 2 ) (S130) and further determines whether authentication of the same user is successful (S140). In step S140, it is determined whether the current user is the same person as the user who was authenticated before driving. For example, in step S140, the current user is authenticated, the current user is identified, and it is determined whether the identified user is the same person as the user before driving. Successful authentication of the same user means that it is determined that the user is the same person, and failure of authentication of the same user means that it is determined that the user is not the same person. Note that no driver distraction will occur includes not only no driver distraction at all but also driver distraction occurring within an acceptable range.
[0102] Fig. 7A is a diagram schematically illustrating a case where the user at the second time point is the same person as the user at the first time point. Fig. 7A shows an example where user A at the second time point is the same person as user A at the first time point. Fig. 7B is a diagram schematically illustrating a case where the user at the second time point is not the same person as user A at the first time point. Fig. 7B shows an example where user D at the second time point is not the same person as user A at the first time point.
[0103] As shown in Fig. 7A, if user A is still in the vehicle (e.g., as the driver) at the second time point, authentication is successful in step S140. On the other hand, as shown in Fig. 7B, if user D, who is different from user A, is still in the vehicle (e.g., as the driver) at the second time point, authentication fails in step S140.
[0104] 6B, next, if the authentication of the same user is successful (Yes in S140), the authentication unit 13 identifies the individual user whose authentication was successful, acquires service / function information (e.g., authority information 21b) for which the user has subscribed from the server 20 (S150), and continues the access rights and execution rights according to the authority corresponding to the user based on the acquired service / function information (S160). In other words, if the user authenticated before driving and the user authenticated at the current time are the same person, the authentication unit 13 continues the access rights and execution rights set in step S50 shown in FIG. 6A because the available services and functions do not change.
[0105] Note that step S150 may be omitted, but since the user's authority information may have been updated between before driving and the current time, for example, step S150 may be executed to reflect the update.
[0106] If the distraction determination unit 12 determines that a driver distraction will occur (Yes in S120), the authentication unit 13 returns to step S110 and continues the process.
[0107] Furthermore, if authentication of the same user fails (No in S140), that is, if the current user is different from the user before the start of driving, the authentication unit 13 extracts the access rights and execution rights that were granted in the past authentication (S170). The authentication unit 13 may, for example, extract the access rights and execution rights that were granted most recently. Furthermore, the authentication unit 13 may, for example, extract the access rights and execution rights corresponding to services or functions that were subscribed to by the user before the start of driving but that are not subscribed to by the current user.
[0108] Next, the safety determination unit 15 determines the SFOP of the access rights and execution rights extracted by the authentication unit 13 (S180). The safety determination unit 15 performs the determination of step S180 based on the extracted access rights and execution rights and the table shown in FIG. 3. If the access rights and execution rights most recently granted are based on the service / function to which user A (a user who has subscribed for the autonomous driving service / function as shown in FIG. 4) has subscribed), the safety determination unit 15 determines the SFOP classification of the autonomous driving function to be "Safety." If user A has subscribed to multiple services / functions, the SFOP classification determination is performed for each of the services / functions.
[0109] Next, the safety determination unit 15 determines whether or not the results determined in step S180 include an access right (or execution right) related to Safety (S190). The safety determination unit 15 determines whether or not the most recently authenticated user has subscribed to a service / function classified as "Safety" in the SFOP classification. The determination in step S190 is an example of determining whether or not the function enabled in step S50 shown in FIG. 6A is a function related to the safety of the vehicle 10 during driving.
[0110] Next, if the access right (or execution right) is related to safety, i.e., if the extracted access right and execution right include an access right (or execution right) related to safety (Yes in S190), the safety determination unit 15 acquires the status of the user and the vehicle 10 from the sensors (S200) and determines whether or not stopping the access will reduce safety based on the acquired information from the sensors (S210). Since the user is different before and at the current time, the safety determination unit 15 needs to stop the service / function subscribed to by the user authenticated before driving. However, if the service / function is suddenly stopped while the vehicle 10 is driving, for example, this may affect the safety of the vehicle 10. In other words, the safety determination unit 15 determines whether or not safety will reduce when the service / function that was enabled because the previous authentication was successful is stopped in step S210. For example, if the service / function is an autonomous driving function, stopping the autonomous driving function while the vehicle 10 is driving reduces the safety of the vehicle 10.
[0111] The safety determination unit 15 determines whether or not stopping access will reduce safety based on the current state of the vehicle 10 and the table shown in Fig. 3. For example, if the service / function is an autonomous driving function and the vehicle 10 is in a driving or temporarily stopped state, the safety determination unit 15 determines that safety will reduce because the function cannot be stopped, whereas if the service / function is an autonomous driving function and the vehicle 10 is in an engine-stopped state, the safety determination unit 15 determines that safety will not reduce because the function can be stopped. Furthermore, for example, if the service / function is ETC (toll payment) and the vehicle 10 is in a driving state, the safety determination unit 15 determines that safety will reduce because the function cannot be stopped, whereas if the service / function is ETC (toll payment) and the vehicle 10 is in a temporary stop or an engine-stopped state, the safety determination unit 15 determines that safety will not reduce because the function can be stopped.
[0112] If the safety determination unit 15 determines that stopping access will reduce safety (Yes in S210), the execution control unit 14 continues to execute the service / function corresponding to the user authenticated before driving. Although the service / function is not currently subscribed to by the authenticated user, the execution control unit 14 continues the service / function without stopping it, from the perspective of prioritizing the safety of the vehicle 10.
[0113] If it is determined that safety will be reduced (for example, if it is determined that the function is related to safety), the execution control unit 14 may stop the enabled function as the processing related to the above restriction after the state of the vehicle 10 becomes a safe state in which the enabled function can be safely stopped. Furthermore, if it is determined that safety will be reduced (for example, if it is determined that the function is related to safety), the execution control unit 14 may forcibly move the vehicle 10 to a position where the enabled function can be safely stopped (for example, by causing the vehicle 10 to autonomously drive), and stop the enabled function after the vehicle 10 has moved to that position. The position may be, for example, a position where the engine can be stopped.
[0114] Furthermore, if the safety determination unit 15 determines that the access right (or execution right) related to Safety is not included (No in S190), or if it determines that the suspension of access will not reduce safety (No in S210), the execution control unit 14 suspends the access right and execution right (S220). The execution control unit 14 suspends the access right and execution right without stopping the vehicle 10 (for example, by stopping the engine). The execution control unit 14 may suspend the access right and execution right immediately.
[0115] The vehicle 10 may be equipped with a sound output device such as a speaker or a display device, and the authentication unit 13 may notify the user in the vehicle 10 of the authentication result (e.g., the determination result of whether authentication of the same user has been successful). For example, the notification may also be made at a timing when there is little driver distraction. The distraction determination unit 12 determines whether there is little driver distraction (e.g., below a predetermined level) based on at least one of the state of the user and the state of the vehicle 10, and the authentication unit 13 may make the notification when the distraction determination unit 12 determines that there is little driver distraction (or no driver distraction). An example of a situation in which it is determined that there is little driver distraction is a situation in which the authentication operation does not interfere with driving, such as when the vehicle is temporarily stopped at a traffic light.
[0116] Then, after step S160 or S220 is executed, or after the determination in step S210 is Yes, step S110 is executed again after a predetermined time has elapsed.
[0117] (Other Embodiments) While the user authentication method according to one or more aspects has been described above based on the embodiments, the present disclosure is not limited to these embodiments. As long as it does not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art to the present embodiments and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.
[0118] For example, in the above embodiment, the first time point is before the vehicle starts moving, but the first time point may be while the vehicle is moving and may be a time point that is earlier than the second time point.
[0119] In the above embodiment, the determination of whether the access right is related to Safety (S190) shown in FIG. 6B may not be performed, and step S20 may be performed after step S180.
[0120] In the above embodiment, the vehicle 10 is described as an example of a vehicle that uses a fossil fuel such as gasoline as an energy source and runs on an engine, but the vehicle 10 may also be a vehicle that uses electricity as an energy source and runs on an electric motor, such as an electric vehicle. If the vehicle 10 is an electric vehicle, the "engine stopped" described above may be replaced with "ignition power off."
[0121] Furthermore, in the above-described embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0122] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and other orders may be used. Some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.
[0123] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.
[0124] Furthermore, the user authentication system according to the above embodiment may be realized as a single device or may be realized by multiple devices. When the user authentication system is realized by multiple devices, the components of the user authentication system may be distributed among the multiple devices in any manner. When the user authentication system is realized by multiple devices, the communication method between the multiple devices is not particularly limited, and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.
[0125] Although the above embodiments and the like have been described as cybersecurity measures for vehicles (e.g., automobiles), the scope of application of the present disclosure is not limited to this. For example, the present disclosure may be applied not only to automobiles but also to mobility such as construction machinery, agricultural machinery, ships, trains, and airplanes.
[0126] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, which is an integrated circuit. These components may be individually integrated into a single chip, or some or all of them may be integrated into a single chip. Here, the term "LSI" is used, but depending on the level of integration, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI. Furthermore, the integrated circuit implementation method is not limited to LSI, and may be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. After LSI fabrication, a field programmable gate array (FPGA) that can be programmed or a reconfigurable processor that can reconfigure the connections or settings of circuit cells within the LSI may also be used. Furthermore, if an integrated circuit technology that replaces LSI emerges due to advances in semiconductor technology or a derivative technology, that technology may naturally be used to integrate the components.
[0127] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip. Specifically, it is a computer system that includes a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), etc. Computer programs are stored in the ROM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.
[0128] Furthermore, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the user authentication method shown in any of FIGS. 5 to 6B.
[0129] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes.
[0130] The present disclosure is useful for user authentication systems used in vehicles and the like.
[0131] REFERENCE SIGNS LIST 1 User authentication system 10 Vehicle 11a Camera 11b Fingerprint authentication sensor 11c Pressure sensor 12 Distraction determination unit 13 Authentication unit (determination unit) 14 Execution control unit (first control unit, second control unit) 15 Safety determination unit 16, 21 Storage unit 16a SFOP classification information 16b User information 16c Charging-related information 17a Navigation system 17b Autonomous driving system 17c Device linkage unit 20 Server 21a Authentication information 21b Authority information
Claims
1. A user authentication method for authenticating a user riding in a vehicle, comprising: authenticating a first user who is in the vehicle at a first time point; enabling functionality of the vehicle responsive to the authenticated first user; determining whether a second user riding in the vehicle is the same person as the first user at a second time point that is later than the first time point and that is during the vehicle's travel, According to the result of the determination as to whether or not the person is the same, a process for restricting the enabled function is executed; the first time point is a time point when the first user gets into the vehicle and before the vehicle starts moving, At the first point in time, authentication of the first user is performed by an input-based authentication method that accepts input from the first user; At the second point in time, authentication of the first user is performed by a contactless authentication method using a result of sensing the first user. User authentication method.
2. If the determination result indicates that the person is not the same person, the enabled function is stopped as a process related to the restriction. The user authentication method according to claim 1 .
3. If the determination result indicates that the persons are not the same person, the processing related to the restriction further includes: determining whether the enabled function is a function related to safety during driving of the vehicle; If it is determined that the function is not related to safety, the enabled function is stopped. The user authentication method according to claim 2 .
4. If it is determined that the function is related to safety, the processing related to the restriction is to stop the enabled function after the state of the vehicle becomes a safe state in which the enabled function can be safely stopped. The user authentication method according to claim 3 .
5. The vehicle state includes: running, stopped, and engine stopped; The safe state is when the engine is stopped. The user authentication method according to claim 4.
6. If it is determined that the function is related to safety, the processing related to the restriction is to forcibly move the vehicle to a position where the enabled function can be safely stopped, and after the vehicle has moved to that position, to stop the enabled function. The user authentication method according to claim 3 .
7. determining a state of the vehicle at the first time point, and determining an authentication method for the user at the first time point according to a result of the determination; At the second time point, a state of the vehicle is determined, and an authentication method for the user at the second time point is determined according to the determination result. The user authentication method according to any one of claims 1 to 6.
8. The determination of whether or not the person is the same is performed multiple times while the vehicle is traveling. The user authentication method according to any one of claims 1 to 6.
9. The vehicle functions include at least one of navigation, automated driving, and device linkage. The user authentication method according to any one of claims 1 to 6.
10. The input authentication method for accepting input from the first user is fingerprint authentication or password authentication, The contactless authentication method using the result of sensing the first user is face authentication or voiceprint authentication. The user authentication method according to any one of claims 1 to 6.
11. A user authentication system for authenticating a user riding in a vehicle, comprising: an authentication unit that authenticates a first user who is riding in the vehicle at a first time point; a first control unit that enables a function of the vehicle according to the authenticated first user; a determination unit that determines whether a second user riding in the vehicle is the same person as the first user at a second time point that is later than the first time point and during the vehicle's travel; a second control unit that executes a process related to limiting the enabled function according to a determination result of whether or not the person is the same; the first time point is a time point when the first user gets into the vehicle and before the vehicle starts moving, The authentication unit authenticates the user at the first point in time by an input-type authentication method that accepts input from the first user, and authenticates the user at the second point in time by a contactless authentication method that uses a result of sensing the first user. User authentication system.
12. A method for authenticating a user comprising: causing one or more processors to execute the user authentication method according to any one of claims 1 to 6; program.