Vehicle-mounted device, driving assistance system, server, and computer program

JPWO2024150657A5Active Publication Date: 2025-09-09SUMITOMO ELECTRIC INDUSTRIES LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024570136
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-09-09
Estimated Expiration
2043-12-25

AI Technical Summary

Technical Problem

Existing in-vehicle systems fail to provide personalized driving experiences across different vehicles, as notification models are not shared, leading to inconsistent passenger environments and wasted learning results.

Method used

An in-vehicle device and driving support system that acquires passenger information through a server, authenticates passengers, and adjusts vehicle settings via an in-vehicle network, ensuring a personalized environment regardless of the vehicle ridden, by transmitting and updating adjustment information.

Benefits of technology

Enables passengers to enjoy a consistently personalized environment across various vehicles, improving comfort and safety by automatically adjusting settings based on individual preferences and vehicle type.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This vehicle-mounted device for providing a vehicle-mounted device that makes it possible for a passenger to enjoy an environment that is appropriate for the passenger, regardless of a vehicle in which the passenger is riding, includes: an information acquiring unit for acquiring information associated with the passenger of the vehicle by means of communication with a server; and a processing execution unit which is connected to a vehicle-mounted network of the vehicle and which uses a resource that can communicate via the vehicle-mounted network to execute processing in accordance with the information acquired by the information acquiring unit.
Need to check novelty before this filing date? Find Prior Art

Description

In-vehicle device, driving assistance system, server, and computer program

[0001] This disclosure relates to an in-vehicle device, a driving assistance system, a server, and a computer program. This application claims priority to Japanese Application No. 2023-002768 filed on January 12, 2023, and incorporates by reference all of the contents of that Japanese application.

[0002] The increasing number of functions required of automobiles is due to the tightening of automobile regulations in various countries, responses to environmental issues, and the response to user needs, and in order to address these issues, the electronics of automobiles is advancing.Vehicle electronics is being used not only to ensure the safe driving of vehicles, but also to provide comfort to passengers such as the driver.

[0003] A proposal for this purpose is disclosed in Patent Document 1, which is listed below. The technology disclosed in Patent Document 1 is a technology that provides appropriate recommendations regarding rest breaks while driving, taking into account individual differences between passengers. The device disclosed in Patent Document 1 authenticates passengers of a vehicle in which the device is installed and detects the passenger's biometric information. Furthermore, for each authenticated passenger, the device obtains behavioral information corresponding to the biometric information based on a notification model, and notifies the passenger of notification content (recommendation content) including the behavioral information. The device further learns the notification model based on the passenger's behavior in response to the notification.

[0004] Japanese Patent Application Laid-Open No. 2021-149617

[0005] An in-vehicle device according to one aspect of the present disclosure includes an information acquisition unit that acquires information associated with a vehicle occupant by communicating with a server, and a processing execution unit that is connected to the vehicle's in-vehicle network and executes processing according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network.

[0006] This disclosure can be realized not only as an in-vehicle device having such a characteristic processing unit, but also as an operating method of the in-vehicle device having such characteristic processing steps, as a program for causing a computer to execute such steps, as a semiconductor integrated circuit that realizes part or all of the in-vehicle device, or as a driving assistance system including the in-vehicle device.

[0007] FIG. 1 is a hardware block diagram showing the configuration of a driving assistance system including a function-expanded ECU (Electronic Control Unit) according to a first embodiment of the present disclosure. FIG. 2 is a block diagram showing the hardware and software configuration of the function-expanded ECU shown in FIG. 1. FIG. 3 is a block diagram showing the hardware configuration of a processor shown in FIG. 2. FIG. 4 is a block diagram showing the relationship between functions realized by the function-expanded ECU shown in FIG. 1. FIG. 5 is a diagram showing the configuration of an adjustment instruction unit shown in FIG. 4. FIG. 6 is a block diagram showing the hardware configuration of a server shown in FIG. 5. FIG. 7 is a block diagram showing the functional configuration of the server shown in FIG. 5. FIG. 8 is a flowchart showing the control structure of a program executed by the function-expanded ECU of the driving assistance system shown in FIG. 1. FIG. 9 is a flowchart showing the control structure of a program realizing the change information transmission unit shown in FIG. 4, which is executed by the function-expanded ECU shown in FIG. 1 when it is detected that a vehicle occupant has adjusted on-board equipment. FIG. 10 is a flowchart showing the control structure of a program realizing the information transmission request receiving unit, setting information searching unit, and setting information transmission unit shown in FIG. 7, which is executed by the server shown in FIG. 5 when it receives an information transmission request from the function-expanded ECU. Fig. 11 is a flowchart showing a control structure of a program that realizes processing executed when the server shown in Fig. 5 receives a setting information update request from the function expansion ECU. Fig. 12 is a block diagram showing a functional configuration of a personalized driving assistance system according to a second embodiment of the present disclosure. Fig. 13 is a block diagram showing the relationship between functions realized by the function expansion ECU according to the second embodiment shown in Fig. 12. Fig. 14 is a flowchart showing the control structure of a program that the function expansion ECU shown in Fig. 12 executes upon completion of occupant authentication, for realizing the function of the information acquisition unit shown in Fig. 13. Fig. 15 is a functional block diagram showing the relationship between functions realized by the server shown in Fig. 12. Fig. 16 is a flowchart showing the control structure of a program that is executed in the server shown in Fig. 12 and that realizes the key information transmission request receiving unit, setting information searching unit, key information extracting unit, and key information transmitting unit shown in Fig. 15.FIG. 17 is a functional block diagram showing the relationship between the functions realized by the function expansion ECU according to the modified example of the second embodiment shown in FIG. 12 . FIG. 18 is a flowchart showing the control structure of a program for realizing the functions of the function expansion ECU shown in FIG. 17 . FIG. 19 is a functional block diagram showing the relationship between the functions realized by a server according to the modified example of the second embodiment. FIG. 20 is a flowchart showing the control structure of a program for realizing the key information update unit shown in FIG. 19 , which is a program executed by the server according to the modified example of the second embodiment when it receives a key information addition request from a third party. FIG. 21 is a block diagram showing the configuration of a personalized driving assistance system according to a third embodiment of this disclosure. FIG. 22 is a block diagram showing the relationship between the functions realized by the function expansion ECU according to the third embodiment shown in FIG. 21 . FIG. 23 is a flowchart showing the control structure of a program for realizing the functions of the function expansion EC according to the third embodiment shown in FIG. 21 . FIG. 24 is a flowchart showing the control structure of a program executed by the function expansion ECU according to the third embodiment shown in FIG. 21 , which is a program for realizing the physical condition recognition unit shown in FIG. 22 . Fig. 25 is a flowchart showing a control structure of a program executed by the function-enhanced ECU according to the third embodiment shown in Fig. 21, which program implements the scheduling unit 1 shown in Fig. 22. Fig. 26 is a state transition diagram showing state transitions in a program executed by the function-enhanced ECU according to the third embodiment shown in Fig. 21. Fig. 27 is a block diagram showing the relationship between functions implemented by the server according to the third embodiment shown in Fig. 21. Fig. 28 is a flowchart showing a control structure of a program executed by the server according to the third embodiment shown in Fig. 21, which program implements the equipment control unit shown in Fig. 27.

[0008] [Problem to be Solved by the Present Disclosure] The technology disclosed in Patent Document 1 is believed to still have room for improvement. For example, even if a notification model is learned, the results are reflected only in the vehicle equipped with this device, and not in other devices. When the same passenger drives a vehicle equipped with another device, a different notification model is used. Therefore, there is a possibility that the learning results will not be utilized.

[0009] The present disclosure aims to provide an in-vehicle device, a driving assistance system, a server, and a computer program that allow an individual to enjoy an environment appropriate for that individual, regardless of the vehicle in which the individual is riding.

[0010] [Effects of the present disclosure]

[0011] As described above, this disclosure provides an in-vehicle device, a driving assistance system, a server, and a computer program that enable a passenger to enjoy an appropriate environment for the passenger regardless of the vehicle they are riding in. [Description of Embodiments of the Present Disclosure] In the following description and drawings, the same components are designated by the same reference numerals. Therefore, detailed description thereof will not be repeated. Note that at least some of the embodiments described below may be combined in any manner.

[0012] (1) According to a first aspect of the present disclosure, an in-vehicle device includes: an information acquisition unit that acquires information associated with a vehicle occupant by communicating with a server; and a process execution unit that is connected to an in-vehicle network of the vehicle and executes a process according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network. This configuration makes it possible to provide an in-vehicle device that allows an individual to enjoy an appropriate environment for that individual, regardless of the vehicle in which the individual is riding.

[0013] (2) In the above (1), the in-vehicle device further includes an occupant authentication unit that authenticates the occupant. By authenticating the occupant, the security of the in-vehicle device can be improved.

[0014] (3) In the above (2), the passenger authentication unit may include a face image authentication unit provided in the vehicle and configured to perform authentication using a face image of the passenger. This configuration provides an in-vehicle device that allows an individual to enjoy an appropriate environment for that individual, regardless of the vehicle they are riding in.

[0015] (4) In any one of (1) to (3) above, the information may include adjustment information regarding adjustment of equipment in the vehicle when the passenger boards the vehicle, and the processing execution unit may include an adjustment instruction unit that instructs another device via the in-vehicle network to automatically adjust the position of the part used by the passenger in the vehicle equipped with the in-vehicle device using the adjustment information. With this configuration, an in-vehicle device can be provided that allows an individual to use equipment that is appropriately adjusted for that individual, regardless of the vehicle they are boarding.

[0016] (5) In the above (4), the adjustment information may include state designation information that designates a state of the equipment when the passenger boards the vehicle, and the adjustment instruction unit may include a state identification unit that identifies a state that is closest to the state designated by the state designation information among states that the equipment can be in in the vehicle equipped with the in-vehicle device, and an equipment adjustment instruction unit that instructs the other device to adjust the state of the equipment used by the passenger to the state identified by the state identification unit. With this configuration, an in-vehicle device can be provided that allows an individual to enjoy an environment in which the vehicle's equipment is set to a state appropriate for that individual, regardless of the vehicle they board.

[0017] (6) In the above (5), the in-vehicle device may further include a change information transmission unit that, in response to a manual change by the occupant of a vehicle after the state of the equipment used by the occupant has been adjusted by the other device, transmits to the server information identifying the occupant and the state of the equipment after the change. This configuration makes it possible to provide an in-vehicle device that allows an individual to use equipment that has been appropriately adjusted for that individual, regardless of the vehicle they are riding in, based on the results of adjusting the equipment in a certain vehicle.

[0018] (7) In the above (5), the in-vehicle device may further include a change information transmission unit that transmits to the server, in response to the occupant manually changing the state of the equipment used by the occupant after the state of the equipment has been adjusted by the other device, information identifying the occupant, the state of the equipment after the change, and information about the vehicle model. This configuration makes it possible to provide an in-vehicle device that allows an individual to use equipment that has been appropriately adjusted for the individual based on the results of adjusting the equipment in a certain vehicle, as long as the vehicle is of the same type, even if it is not the same model as the vehicle they are using.

[0019] (8) In any one of (5) to (7) above, the equipment may include at least one of a seat position adjustment device for one of the seats in the vehicle used by the passenger, an electric mirror device for the vehicle, and an air conditioning device provided in the vehicle. This configuration makes it possible to provide an in-vehicle device that allows an individual to enjoy an environment in which the equipment has been appropriately adjusted for the individual in a vehicle of the same type, even if the vehicle is not the same model as the vehicle in which the individual is riding, based on the results of adjusting the seat position adjustment device, the electric mirror device, or the air conditioning device in the vehicle.

[0020] (9) In any one of (1) to (3) above, the information may include key information for an automatic opening / closing device of a garage used by the passenger, and the processing execution unit may include an opening / closing instruction unit that instructs another device via the in-vehicle network to operate the automatic opening / closing device using the key information in response to a predetermined condition being satisfied. This configuration makes it possible to provide an in-vehicle device that allows an individual to use the automatic opening / closing function of a garage regardless of the vehicle they are driving.

[0021] (10) In the above (9), the information may further include validity control information for controlling the validity of the key information included in the information, and the processing execution unit may further include a validity determination unit for prohibiting the opening / closing instruction unit from using key information included in the information that is determined to be invalid by referring to the validity control information. This configuration makes it possible to provide an in-vehicle device that allows an individual to use the automatic opening / closing function in a garage other than their own during the validity period, regardless of the vehicle they are driving.

[0022] (11) In any one of (1) to (3) above, the information may include information about externally controllable equipment present at a residence that the passenger uses after using the vehicle, and the processing execution unit may include a physical condition recognition unit that recognizes the physical condition of the passenger, and a scheduling unit that selects at least one of functions of the equipment at the passenger's residence in accordance with the physical condition recognized by the physical condition recognition unit and schedules activation of the selected function. With this configuration, an in-vehicle device can be provided that allows an individual to prepare an environment in advance in which they can improve their physical condition when they return to their residence, regardless of the vehicle they use.

[0023] (12) In the above (11), the scheduling unit may include a schedule creation unit that selects at least one of the functions of the equipment at the occupant's residence in accordance with the physical condition recognized by the physical condition recognition unit and creates a schedule for activation of the selected function, and a request unit that transmits the schedule created by the schedule creation unit to the server and requests that the equipment at the residence be controlled in accordance with the schedule. With this configuration, an in-vehicle device can be provided in which an environment for improving physical condition can be prepared in advance for each piece of equipment when an individual returns to their residence, regardless of the vehicle they are riding in.

[0024] (13) In the above (11), the scheduling unit may include a schedule creation unit that selects at least one of the functions of the equipment at the occupant's residence in accordance with the physical condition recognized by the physical condition recognition unit and creates a schedule for activation of the selected function, and a request unit that transmits the schedule created by the schedule creation unit to a home server in the residence and requests that the equipment at the residence be controlled in accordance with the schedule. With this configuration, it is possible to provide an in-vehicle device that, regardless of the vehicle in which the individual is riding, pre-adjusts each facility so that the individual can improve their physical condition when they return to their residence.

[0025] (14) In any one of (1) to (13) above, the passenger may be a driver of the vehicle. With this configuration, the above-mentioned effects can be obtained even when an individual is the driver.

[0026] (15) In any one of (1) to (14) above, the in-vehicle device may further include a memory unit that stores the information acquired by the information acquisition unit, and the information acquisition unit may include a search unit that searches the memory unit for information associated with the occupant, an information storage unit that acquires the information associated with the occupant through communication with the server and stores the information in the memory unit in response to a failure of the search by the search unit, and a selection unit that selectively outputs an output of the search unit and the information acquired by the information storage unit to the processing execution unit depending on whether the search by the search unit is successful. With this configuration, it is possible to provide an in-vehicle device that allows only individuals whose information is stored in the information acquisition unit to enjoy the various effects described above.

[0027] (16) A driving assistance system according to a second aspect of the present disclosure is a personalized driving assistance system including a server, a sensor mounted on a vehicle, and an on-board device, wherein the server includes a storage unit that stores an individual's identification information and information related to the individual in association with each other, and an information transmission unit that, in response to receiving an information transmission request from the on-board device specifying the individual's identification information, reads information associated with the identification information from the storage unit and transmits the information to the on-board device, and the on-board device includes an information acquisition unit that acquires information associated with the vehicle occupant from the server by requesting the information transmission unit of the server to transmit the information, and a processing execution unit that is connected to the on-board network of the vehicle and executes processing according to the information acquired by the information acquisition unit using resources that can communicate via the on-board network. This configuration makes it possible to provide a driving assistance system that allows an individual to enjoy an appropriate environment for that individual, regardless of the vehicle they are riding in.

[0028] (17) A server according to a third aspect of this disclosure includes a storage unit that stores personal identification information and information related to the personal in association with each other, and an information transmission unit that, in response to receiving an information transmission request specifying the personal identification information from an external in-vehicle device, reads information associated with the personal identification information from the storage unit and transmits the information to the in-vehicle device. This configuration provides a function that allows a person to enjoy an appropriate environment for the person, regardless of the vehicle they are riding in.

[0029] (18) In the above (17), the information may include at least one of adjustment information regarding adjustment of equipment in the vehicle when the individual gets into the vehicle, key information for an automatic door opener of a garage used by the individual, and information regarding externally controllable equipment present in a residence used by the individual after using the vehicle. With this configuration, the individual can enjoy an appropriate environment for controlling the equipment in the vehicle, the automatic door opener of the garage, or the equipment in the residence, regardless of the vehicle they get into.

[0030] (19) In the above (17) or (18), the server may further include an update unit that, in response to receiving from the external in-vehicle device an individual's identification information and information related to the individual, adds and stores a combination of the identification information and the information in the storage unit if the combination is not already stored in the storage unit, and, if the combination is stored in the storage unit, updates the stored information about the individual using the information about the individual received from the external in-vehicle device. This configuration makes it possible to provide a service that allows only individuals whose information is stored in the information acquisition unit to enjoy the various effects described above.

[0031] (20) In the above (18), the information may include information about externally controllable equipment present at the residence that the individual uses after using the vehicle, and the server may further include an equipment control unit that controls the equipment related to the individual based on the control instructions in response to receiving from the external in-vehicle device the individual's identification information and a scheduling request for the controllable equipment related to the individual. With this configuration, it is possible to provide a service in which each equipment is pre-adjusted so that the individual can improve their physical condition when they return to their residence, regardless of the vehicle they are riding in.

[0032] (21) A computer program according to a fourth aspect of this disclosure causes a computer to function as an information acquisition unit that acquires information associated with a vehicle occupant by communicating with a server, and a process execution unit that is connected to an in-vehicle network of the vehicle and executes a process according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network. This configuration provides a function that allows an individual to enjoy an appropriate environment for that individual, regardless of the vehicle they are riding in.

[0033] [Details of Embodiments of the Present Disclosure] Specific examples of an in-vehicle device, a driving assistance system, a server, and a computer program according to embodiments of the present disclosure will be described below with reference to the drawings. Note that the present disclosure is not limited to these examples, but is defined by the claims, and is intended to include all modifications within the meaning and scope of the claims.

[0034] 1. First Embodiment A. Configuration A1. Overall Configuration Fig. 1 shows a hardware block diagram of a driving assistance system 50 according to a first embodiment of the present disclosure. Referring to Fig. 1, this driving assistance system 50 includes an in-vehicle system 60 and a server 62. The in-vehicle system 60 is wirelessly connected to the Internet and can communicate with the server 62 via the Internet.

[0035] A2. Configuration of the In-Vehicle System 60 The in-vehicle system 60 includes an automatic driving ECU 70 for processing automatic driving of the vehicle in which the in-vehicle system 60 is installed, a number of ECUs (not shown) for controlling other parts of the vehicle, and a function expansion ECU 72 equipped with functions for realizing various driving assistance functions. The function expansion ECU 72 is connected to ECUs such as the automatic driving ECU 70 via an in-vehicle network (not shown). Among the functional parts such as the various ECUs described below, the functional parts connected to the in-vehicle network can communicate with each other via the in-vehicle network.

[0036] As described below, the function expansion ECU 72 can execute various applications and can execute multiple applications in parallel. Therefore, it is difficult for the function expansion ECU 72 to provide core functions for safe driving, such as driving, stopping, and turning. However, by switching between and executing various apps, various functions can be provided. For example, by transferring some functions from the autonomous driving ECU 70 to the function expansion ECU 72, the load on the autonomous driving ECU 70 can be reduced. Furthermore, compared to using dedicated ECUs for implementing those functions, the number of ECUs can be reduced, and the harness for connecting the ECUs to a network can also be reduced. Furthermore, the function expansion ECU 72 according to this embodiment is equipped with various input / output interfaces, and data required for executing apps can be received from other devices via those interfaces.

[0037] The in-vehicle system 60 further includes a biometric sensor 76 connected to the function expansion ECU 72 for acquiring and outputting biometric information for biometric authentication of a passenger attempting to board the vehicle. The function expansion ECU 72 has a function for performing facial authentication of the passenger using the output of the biometric sensor 76, as described below. In this embodiment, the authentication process is performed by the function expansion ECU 72 installed in the vehicle. However, the present disclosure is not limited to such an embodiment. For example, the passenger may be authenticated by an authentication device installed outside the vehicle (e.g., in a garage), and the in-vehicle system 60 may receive the authentication result from the authentication device. Authentication may be performed not only by facial authentication, but also by biometric authentication using fingerprints, veins, irises, gait, voice, signature, or other authentication mechanisms other than biometric authentication (e.g., passwords, authentication IC (Integrated Circuit) cards, or authentication using a smartphone with authentication functionality). Furthermore, a combination of multiple types of biometric authentication, or a combination of biometric authentication and a non-biometric authentication mechanism, may also be used.

[0038] The in-vehicle system 60 further includes a TCU (Telematics Control Unit) 74 that is communicatively connected to the function expansion ECU 72 via an in-vehicle network and that performs wireless communication using various communication standards, and a BCU (Body Control Unit) 78 that is communicatively connected to the function expansion ECU 72 via the in-vehicle network and that adjusts various parts of the vehicle body. Connected to the BCU 78 are a seat adjustment unit 80 that adjusts the seat position under control of the BCU 78, and a mirror adjustment unit 82 that adjusts the positions (postures, angles) of power mirrors such as the interior mirror and the door mirrors on both sides under control of the BCU 78. The BCU 78 is further connected to an air conditioning adjustment unit 84 for controlling the air conditioner (hereinafter simply referred to as "air conditioner") installed in the vehicle under the control of the BCU 78, a lighting adjustment unit 86 for turning on and off the interior lights and adjusting the illuminance under the control of the BCU 78, and various other adjustment units 88 for adjusting other parts.

[0039] 2 shows the hardware and software configuration of the function expansion ECU 72. Referring to Fig. 2, the function expansion ECU 72 includes a hardware layer 130 that provides resources that are the basis for various functions, a base software layer 132 that is executed by the resources provided by the hardware layer 130 and that provides an execution environment for various applications by utilizing the resources provided by the hardware layer 130, and an application layer 134 that includes multiple applications that can be executed in parallel by the hardware layer 130 via services provided by the base software layer 132.

[0040] The hardware layer 130 includes an ECU, which is a basic hardware resource, a processor mounted on the ECU, a dedicated image compression processor used when transmitting images, and various communication I / Fs, which are interfaces (I / Fs) between the processor and the dedicated image compression processor and various external devices and networks.

[0041] The base software layer 132 includes an OS (Operating System) similar to that used in a normal computer, a security system, an I / F driver, and an OTA (Over-The-Air) that run on the OS, and middleware that determines the timing of the start and end of each application's operation based on the vehicle's state and launches and terminates each application.

[0042] The application layer 134 includes multiple applications as described above. Each application independently or in cooperation with other applications realizes various functions. These applications can be replaced or updated at any time via OTA.

[0043] 3 shows the hardware configuration of the processor 180 shown in FIG. 2. Referring to FIG. 3, this processor includes an MPU (Micro Processing Unit) 202, a high-speed bus 200 to which the MPU 202 is connected, an SRAM (Static Random Access Memory) 204 connected to the high-speed bus 200, a flash memory 206 connected to the high-speed bus 200, and a ROM (Read-Only Memory) 208 connected to the high-speed bus 200. The SRAM 204 holds data necessary for program execution, etc. The flash memory 206 stores a program 226 for implementing the functions realized by the platform software layer 132. The ROM 208 stores a boot-up program for the MPU 202, etc.

[0044] The processor further includes a low-speed bus 210 connected to the high-speed bus 200 via a bridge 212, and a serial I / F 214, an ADC (Analog-to-Digital Converter) 216, a timer / counter 218, a clock generator 220, a power supply control unit 222, and a general-purpose I / F 224, all of which are connected to the low-speed bus 210.

[0045] The operation of a processor is well known, and since what is meaningful in the embodiment is the function of the program that it executes, the operation of the processor itself will not be described below.

[0046] Fig. 4 is a block diagram showing the relationship between the functions realized by the function expansion ECU 72 shown in Fig. 1. Referring to Fig. 4, the functions realized by the function expansion ECU 72 include an occupant identifier storage unit 276 that stores an identifier that uniquely identifies an individual (a vehicle occupant such as a driver) who is the subject of biometric authentication, a biometric authentication unit 274 that performs biometric authentication of the individual using the output of the biometric sensor 76 shown in Fig. 1 and, when the authentication is successful, reads and outputs the identifier of the authenticated individual from the occupant identifier storage unit 276, and an information acquisition unit 278 that transmits an information transmission request including the occupant identifier output by the biometric authentication unit 274 to the server 62 shown in Fig. 1 and receives setting information related to the authenticated occupant from the server 62.

[0047] The setting information in this embodiment includes the seat position when a specific individual is in the vehicle, the position (posture and angle) of the power mirrors, the on / off status of the air conditioner and the set temperature when it is on, the illuminance of the interior lights, etc., and is maintained by the server 62 shown in Fig. 1. This setting information is held and maintained in the server 62 in association with the identifier of the occupant and, for example, the model information of the vehicle in which the specific occupant has been in the past.

[0048] 4 , the function expansion ECU 72 further includes a process execution unit 280 for executing predetermined processes based on the setting information acquired by the information acquisition unit 278. In this embodiment, the process execution unit 280 includes an adjustment instruction unit 300 for transmitting setting information for adjusting the seat adjustment unit 80, the mirror adjustment unit 82, the air conditioning adjustment unit 84, the lighting adjustment unit 86, etc., to the BCU 78 using the setting information acquired by the information acquisition unit 278, and instructing the BCU 78 to adjust each unit. The BCU 78 adjusts each unit in accordance with this instruction.

[0049] The function expansion ECU 72 further includes a vehicle model information storage unit 282 that stores vehicle model information indicating the vehicle model of the vehicle in which the function expansion ECU 72 is installed, and a change information transmission unit 284 that, in response to receiving information from the BCU 78 indicating that the occupant has readjusted the settings of each part after the BCU 78 adjusted each part, transmits the setting information after readjustment by the occupant together with the vehicle model information stored in the vehicle model information storage unit 282 and the occupant's identifier as an update request to the server 62, requesting that the setting information related to this occupant be updated.

[0050] 5 shows the configuration of the adjustment instruction unit 300. The adjustment instruction unit 300 shown in FIG. 5 shows a configuration for adjusting each unit, for example, the seat adjustment unit 80. The adjustment instruction unit 300 also has individual configurations for the mirror adjustment unit 82, the air conditioning adjustment unit 84, the lighting adjustment unit 86, and the like.

[0051] 5, the adjustment instruction unit 300 includes a configurable information storage unit 352 for storing configurable information indicating what values ​​can be set as seat positions in a vehicle in which the in-vehicle system 60 is installed, a state identification unit 350 for comparing the seat setting information received from the information acquisition unit 278 (see FIG. 4) with the configurable information stored in the configurable information storage unit 352, and, if the received seat setting information differs from the configurable information, determining the seat setting, among the configurable values, so as to be closest to the position determined by the received seat setting information, and an equipment adjustment instruction unit 354 for instructing the BCU 78 to adjust the seat position in accordance with the seat setting identified by the state identification unit 350.

[0052] A3. Configuration of Server 62 Figure 6 is a block diagram showing an example of the hardware configuration of server 62 shown in Figure 1. Referring to Figure 6, this server 62 includes a computer 470 having a DVD (Digital Versatile Disc) drive 502, and a keyboard 474, a mouse 476, and a monitor 472, all of which are connected to computer 470, for interacting with a user. Of course, this is just one example of a configuration for when user interaction is required, and any general hardware and software that can be used for user interaction (e.g., a touch panel, voice input, or a general pointing device) can be used.

[0053] In addition to a DVD drive 502, the computer 470 includes a CPU (Central Processing Unit) 490, a GPU (Graphics Processing Unit) 492, a bus 510 connected to the CPU 490, the GPU 492, and the DVD drive 502, a ROM 496 connected to the bus 510 and storing a boot-up program for the computer 470, etc., a RAM (Random Access Memory) 498 connected to the bus 510 and storing instructions constituting the program, system programs, working data, etc., and an SSD (Solid State Drive) 500 which is a non-volatile memory connected to the bus 510. The SSD 500 is used to store programs executed by the CPU 490 and the GPU 492, as well as data used by the programs executed by the CPU 490 and the GPU 492. The computer 470 further includes a network I / F 508 that provides connection to a network 486, and a USB (Universal Serial Bus) port 506 that allows a removable USB memory 484 to be connected and that provides communication between the USB memory 484 and each component within the computer 470. In this embodiment, the network 486 is the Internet.

[0054] The computer 470 further includes an audio I / F 504 that is connected to the microphone 482, the speaker 480, and the bus 510, and that reads out audio signals, video signals, and text data generated by the CPU 490 and stored in the RAM 498 or the SSD 500 in accordance with instructions from the CPU 490, converts the signals to analog, amplifies the signals, and drives the speaker 480, and digitizes the analog audio signals from the microphone 482 and stores them at any address in the RAM 498 or the SSD 500 specified by the CPU 490.

[0055] Computer programs for operating this server 62 to realize each function described below are stored on a DVD 478 inserted into the DVD drive 502 and transferred from the DVD drive 502 to the SSD 500. Alternatively, these programs may be stored in a USB memory 484, which may be inserted into the USB port 506 and transferred to the SSD 500. Alternatively, these programs may be transmitted to the computer 470 via the network 486 and stored in the SSD 500.

[0056] The program is loaded into RAM 498 when executed. Of course, a source program may be input using keyboard 474, monitor 472, and mouse 476, and the compiled object program may be stored in SSD 500. In the case of a program that runs on a virtual machine, a program that functions as a virtual machine must be installed in advance on computer 470. Note that if it is expected that a large number of in-vehicle systems 60 will be connected to server 62 as clients, it is desirable to distribute the load by using server 62 as a distributed system.

[0057] The CPU 490 reads the program from the RAM 498, executes it, and stores the execution result data at a predetermined address. The computer program may be loaded directly into the RAM 498 from the DVD 478, from the USB memory 484, or via a network.

[0058] The program for implementing the functions of each server unit according to each embodiment described below includes a plurality of instructions written and arranged to operate the computer 470 to implement those functions. The program may include instructions for performing each of the intended functions by statically or dynamically linking appropriate functions or program routines to achieve the desired results. The method for operating the computer 470 to achieve this is well known and will not be repeated here.

[0059] Fig. 7 is a functional block diagram showing the functional configuration of server 62. Referring to Fig. 7, server 62 includes a setting information database (DB) 566 that stores various personal identifiers and in-vehicle system setting information related to the individuals in association with each other, and an information transmission request receiving unit 560 for receiving an information transmission request from in-vehicle system 60 or the like. Server 62 further includes a setting information searching unit 562 that searches setting information DB 566 using the personal identifier included in the information transmission request received by information transmission request receiving unit 560 and extracts setting information corresponding to the identifier from setting information DB 566, and a setting information transmitting unit 564 that transmits the setting information extracted by setting information searching unit 562 to in-vehicle system 60 that is the sender of the information transmission request.

[0060] The server 62 further includes an update request receiving unit 568 for receiving a request to update the setting information from the in-vehicle system 60, and a setting information update unit 570 for updating the setting information stored in the setting information DB 566, which is stored in association with the identifier included in the update request received by the update request receiving unit 568, using the setting value included in the update request.

[0061] A4. Program Configuration of In-Vehicle System 60 Figure 8 is a flowchart showing the control structure of a program executed by in-vehicle system 60. The functions realized by this program correspond to biometric authentication unit 274 and information acquisition unit 278 shown in Figure 4. Referring to Figure 8, this program includes step 620, which performs facial image authentication based on the output of biometric sensor 76, and step 622, which branches the control flow depending on whether facial image authentication in step 620 was successful. If facial image authentication fails, step 632 notifies the user of the authentication failure and terminates the process. The "notification" in this case may, for example, be a voice notification to the person attempting to get into the vehicle, or may simply involve logging a record of the authentication failure within the system.

[0062] The program further includes a step 624 that is executed in response to a positive determination in step 622, for transmitting to the server 62 a setting information transmission request for setting information corresponding to the combination of the personal identifier obtained as a result of the authentication and the vehicle model information of the vehicle in which the in-vehicle system 60 is installed, and a step 626 that receives a reply from the server 62 in response to the setting information transmission request transmitted in step 624 and branches the control flow according to whether or not the setting information is present in the server 62 as a result. The program further includes a step 630 that, in response to a positive determination in step 624, transmits the setting information received from the server 62 to the adjustment instruction unit 300 shown in Fig. 4 and terminates execution of the program, and a step 628 that, in response to a negative determination in step 624, notifies the adjustment instruction unit 300 that there is no setting information and terminates execution of the program.

[0063] Fig. 9 shows a control structure of a program that realizes processing equivalent to that of the change information transmission unit 284 shown in Fig. 4. As described above, when the seat position is automatically adjusted by the adjustment instruction unit 300 and then the occupant resets the seat position, information relating to the reset seat position is output from the BCU 78 to the change information transmission unit 284. The program shown in Fig. 9 is started when the information relating to the reset seat position is input from the BCU 78 to the function expansion ECU 72.

[0064] 9, this program includes step 690 in which information acquisition unit 278 compares the original setting information received from server 62 with the changed setting information received from BCU 78, step 692 in which the flow of control branches depending on whether the two are identical as a result of step 690, and step 694 in which, if the determination in step 692 is negative, an identifier of the passenger (driver) and the vehicle model information stored in vehicle model information storage unit 282 are added to the changed setting information, transmitted to server 62, and execution of this program is terminated. If the determination in step 692 is positive, execution of this program is immediately terminated.

[0065] Even if the user resets the seat position, there is a chance that the user will end up returning to the original seat position after repeating the setting several times. In such a case, there is no point in sending the reset setting value to the server 62, and therefore the determination in step 692 is provided. Note that, if the information on the reset seat position is sent to the server 62 in step 694, the server 62 uses that information to update the setting information for that passenger. This point will be described later.

[0066] Fig. 10 is a flowchart showing a control structure of a program realizing information transmission request receiving unit 560, setting information searching unit 562, and setting information transmitting unit 564 of server 62 shown in Fig. 7. Referring to Fig. 10, this program includes a step 720 of extracting an occupant identifier and vehicle model information from the received information transmission request, a step 722 of searching setting information DB 566 (see Fig. 7) using the extracted identifier and vehicle model information as a key, and a step 724 of branching the control flow depending on whether a record corresponding to the key is found as a result of step 722.

[0067] This program further includes step 732, in which if the determination in step 724 is affirmative, the setting information retrieved from the setting information DB 566 as a result of the search is transmitted to the in-vehicle system 60, and the execution of this program is terminated.

[0068] This program further includes step 726, when the determination in step 724 is negative, replacing the vehicle model information with information about a vehicle model similar to the vehicle model identified by the vehicle model information searched and extracted in step 722, and searching setting information DB 566 using the identifier and the vehicle model information as keys, and step 728, which branches the flow of control depending on whether or not a corresponding record is found as a result of the processing in step 726. When the determination in step 728 is negative, control proceeds to step 732, as when the determination in step 724 is positive.

[0069] This program further includes step 730, in which, if the determination in step 728 is negative, a reply indicating that no setting information corresponding to the information transmission request exists is sent to the in-vehicle system 60, and execution of this program is terminated. Note that, if multiple matching records are found in step 728, one of them may be selected according to some criteria and sent to the in-vehicle system 60. For example, a method may be used in which priority is given to models of the same manufacturer, or to models of the same grade regardless of the manufacturer.

[0070] 11 is a flowchart showing a control structure of a program for implementing processing executed when server 62 receives a request to update setting information from in-vehicle system 60. The functions implemented by this program correspond to update request receiving unit 568 and setting information updating unit 570 in FIG.

[0071] This program includes step 760 of extracting the occupant identifier, vehicle model information, and adjustment information from the update request, step 762 of searching setting information DB 566 (Figure 7) using the identifier and vehicle model information obtained in step 760 as keys, and step 764 of branching the control flow depending on whether or not a corresponding record is found as a result of the processing in step 762.

[0072] This program further includes step 768, in which, when the determination in step 764 is positive, the setting information in setting information DB 566 is updated with the received setting information using the occupant's identifier and vehicle model information as keys; step 766, in which, when the determination in step 764 is negative, setting information is added to setting information DB 566 using the occupant's identifier and vehicle model information as keys; and step 770, in which, after processing in steps 766 and 768, the control flow is branched depending on whether or not any error has occurred in setting information DB 566 as a result of these processes.

[0073] This program further includes step 774, which notifies the in-vehicle system 60 that the setting information has been updated and terminates execution of the program when the determination in step 770 is negative, i.e., when the setting information has been updated or added successfully, and step 772, which notifies the in-vehicle system 60 that the setting information update has failed and terminates execution of the program when the determination in step 770 is positive, i.e., when the setting information has not been updated or added successfully.

[0074] B. Operation The driving assistance system 50 according to the first embodiment, the configuration of which has been described above, operates as follows. Referring to FIG. 4, the occupant identifier storage unit 276 stores in advance an identifier that uniquely identifies an individual (a vehicle occupant, such as a driver) who is the subject of biometric authentication. The biometric authentication unit 274 performs biometric authentication of the individual using the output of the biometric sensor 76 shown in FIG. 1, and if authentication is successful, reads the identifier of the authenticated individual from the occupant identifier storage unit 276 and outputs it to the information acquisition unit 278. If authentication fails (the determination in step 622 of FIG. 8 is negative), the individual is notified of the authentication failure. A person cannot use the vehicle unless they are authenticated.

[0075] If the authentication is successful, the information acquisition unit 278 transmits an information transmission request including the passenger identifier and vehicle model information output by the biometric authentication unit 274 to the server 62 shown in FIG.

[0076] 7, the information transmission request receiving unit 560 of the server 62 receives an information transmission request from the in-vehicle system 60 and provides it to the setting information searching unit 562. The setting information DB 566 stores various personal identifiers associated with the in-vehicle system setting information related to the individual. The setting information searching unit 562 searches the setting information DB 566 using the personal identifier included in the received information transmission request, retrieves setting information corresponding to the identifier from the setting information DB 566, and provides the setting information transmitting unit 564. If the setting information retrieved by the setting information searching unit 562 includes the specified vehicle model information, the setting information transmitting unit 564 transmits the information to the information acquiring unit 278 (FIG. 4) of the in-vehicle system 60, which is the sender of the information transmission request. If the setting information searching unit 562 does not find any setting information corresponding to the specified identifier and vehicle model information (the determination in step 724 of FIG. 10 is negative), a search is performed again using the identifier of a similar vehicle model (step 726 of FIG. 10). If a matching record is found in this search (YES in step 728 in FIG. 10), the setting information is transmitted from the setting information transmitting unit 564 to the information acquiring unit 278 of the in-vehicle system 60 (step 732 in FIG. 10). If the determination in step 728 is NO, a message indicating the absence of setting information is transmitted to the information acquiring unit 278 (step 730 in FIG. 10).

[0077] 4, information acquisition unit 278 receives setting information related to the authenticated occupant from server 62 and provides the setting information to adjustment instruction unit 300 of process execution unit 280. Using the setting information acquired by information acquisition unit 278, adjustment instruction unit 300 transmits setting information for adjusting seat adjustment unit 80, mirror adjustment unit 82, air conditioning adjustment unit 84, lighting adjustment unit 86, etc. to BCU 78, thereby instructing BCU 78 to adjust each unit. BCU 78 adjusts each unit in accordance with this instruction.

[0078] As a result, when a passenger gets in, the seat position, the position and angle of the power mirrors, the air conditioner, the lighting, etc. are all adjusted to the settings that the passenger will normally use, so the passenger can usually start driving comfortably without having to adjust any further settings.

[0079] However, human senses are not always the same, and there may be cases where settings are changed (readjusted). In such cases, in response to receiving information from the BCU 78 indicating that the occupant has readjusted the settings of each section after the BCU 78 adjusted each section, the change information transmission unit 284 transmits the setting information readjusted by the occupant to the server 62 as a setting information update request, together with the vehicle type information stored in the vehicle type information storage unit 282 and the occupant's identifier.

[0080] 5, for example, the state identification unit 350 of the adjustment instruction unit 300 compares the seat setting information received from the information acquisition unit 278 (see FIG. 4) with the configurable information stored in the configurable information storage unit 352, and if the received seat setting information differs from the configurable information, determines the seat setting so that, among the configurable values, it is closest to the position determined by the received seat setting information. The equipment adjustment instruction unit 354 instructs the BCU 78 to adjust the seat position in accordance with the seat setting identified by the state identification unit 350.

[0081] On the other hand, upon receiving an update request from the change information transmission unit 284, the server 62 operates as follows. Referring to FIG. 7 , the update request reception unit 568 receives a request to update the setting information from the in-vehicle system 60. The setting information update unit 570 updates, using the setting values ​​included in the update request, the setting information stored in the setting information DB 566, which is stored in association with the identifier and vehicle model information included in the update request received by the update request reception unit 568. As a result, the setting information stored in the server 62 is updated with the latest information. If such information does not exist, the setting information update unit 570 adds the information to the setting information for the corresponding identifier.

[0082] As described above, according to the first embodiment, the occupant's setting information is stored in the server 62 in association with the occupant's identifier along with vehicle model information. When the occupant uses a vehicle and is authenticated using biometric information, setting information for each part of the vehicle for the combination of that vehicle and the occupant is downloaded from the server to the vehicle, and each part of the vehicle is configured to the state that the occupant frequently uses based on that setting information. Therefore, no matter which vehicle the occupant uses, the occupant can use the vehicle with the setting state that the occupant most frequently uses when using that vehicle. If the occupant changes the setting, information about the change is sent to the server, and the information stored in the server is updated using that information. Therefore, the occupant can always use a vehicle configured according to the latest setting information. This has the advantage of eliminating the need to configure each vehicle separately, as was previously required.

[0083] 2. Second Embodiment A. Configuration A1. Overall Configuration The functional configuration of a driving assistance system 810 according to this second embodiment is shown in Fig. 12. Referring to Fig. 12, the driving assistance system 810 includes an in-vehicle system 820 and a server 822. The in-vehicle system 820 and the server 822 are capable of communicating with each other. The driving assistance system 810 according to this embodiment relates to a system that can automatically open and close the garage door of a passenger's home, for example, even if the passenger is riding in a vehicle different from usual.

[0084] 12 , the in-vehicle system 820 includes a biosensor 76, an automatic driving ECU 70, a TCU 74, a function expansion ECU 840 according to the second embodiment, and a garage opening / closing unit 842 connected to the function expansion ECU 840. The garage opening / closing unit 842 wirelessly communicates with a nearby garage using garage key information received from the function expansion ECU 840 and opens and closes the garage using an automatic opening / closing device controllable by the key information. In this embodiment, the function expansion ECU 840 can store multiple keys for a given passenger's identifier up to a predetermined upper limit. When new key information is stored, the function expansion ECU 840 adds and stores the new key information and deletes the oldest stored key information or the least recently used key information instead.

[0085] Fig. 13 is a block diagram showing the relationship between the functions realized by function expansion ECU 840 of in-vehicle system 820 shown in Fig. 12. Referring to Fig. 13, in addition to biometric authentication unit 274 and occupant identifier storage unit 276, function expansion ECU 840 includes a key information storage unit 872 for storing key information usable for each identifier of an authenticated occupant, and an information acquisition unit 870 that, when biometric authentication by biometric authentication unit 274 is successful, outputs key information corresponding to the identifier of the authenticated occupant if the key information storage unit 872 stores the key information, or, if the key information is not stored, transmits an information transmission request regarding the key information associated with the identifier of the occupant to server 822 shown in Fig. 12, receives the corresponding key information, and adds the key information to key information storage unit 872. The information acquisition unit 870 outputs the acquired key information.

[0086] The function expansion ECU 840 further includes a process execution unit 874 that executes predetermined processes using the key information output from the key information storage unit 872. In this embodiment, the process execution unit 874 includes an opening / closing instruction unit 900 that transmits the key information output from the key information storage unit 872 to a garage opening / closing unit 842, which is an automatic garage opening / closing device, and thereby issues an instruction to open or close a nearby garage door using the key information.

[0087] Fig. 14 shows a control structure of a program for realizing information acquisition unit 870 shown in Fig. 13. Referring to Fig. 14, this program includes step 620 of performing biometric authentication, and step 920 of branching the control flow depending on whether the biometric authentication in step 620 is successful. If the determination in step 920 is negative, control proceeds to step 936, where the passenger is notified that there is no key information available, and execution of this program is terminated.

[0088] When the determination in step 920 is affirmative, the program includes a step 924 for searching the key information storage unit 872 shown in Figure 13 for key information corresponding to the occupant's identifier obtained as a result of the authentication; a step 926 for branching the flow of control depending on whether or not key information corresponding to this identifier was found as a result of the search in step 924; and a garage opening / closing unit 842 for transmitting the key information found in the key information storage unit 872 in relation to this identifier to the garage opening / closing unit 842 shown in Figure 13 when the determination in step 926 is affirmative, thereby terminating execution of this program.

[0089] This program further includes step 928, in response to a negative determination in step 926, requesting server 822 to transmit key information corresponding to this identifier, step 930, in which, as a result of the processing in step 928, valid key information exists in server 822 and the control flow branches depending on whether or not the key information has been received, and step 932, in which, when the determination in step 930 is positive, the key information received in step 930 is stored in key information storage unit 872 shown in Figure 13 in association with the identifier being processed. After step 932, control proceeds to step 934, in which this program transmits the key information to garage opening / closing unit 842 shown in Figure 13, and execution ends.

[0090] The program further includes step 936, which, if the determination in step 920 is negative or if the determination in step 930 is negative, notifies the passenger that no key information is available and terminates execution of the program.

[0091] Fig. 15 is a functional block diagram showing the relationship between the functions realized by server 822. Referring to Fig. 15, server 822 includes: a setting information DB 958 that stores identifiers of garage users and key information for garages that the users can use, in association with each other; a key information transmission request receiving unit 950 that receives a key information transmission request from information acquisition unit 870 of function expansion ECU 840 shown in Fig. 13; and a setting information searching unit 952 that, in response to the reception of the key information transmission request by key information transmission request receiving unit 950, searches setting information DB 958 using the identifier as a key, and, if corresponding setting information is found, extracts the setting information from setting information DB 958; The server 822 further includes a key information extraction unit 954 that extracts further key information from the setting information retrieved from the setting information DB 958 when the search by the setting information search unit 952 is successful, and a key information transmission unit 956 that selects the key information extracted by the key information extraction unit 954 when the search by the setting information search unit 952 is successful, or selects information indicating that the search has failed and transmits the information to the function-enhancing ECU 840 when the search by the setting information search unit 952 is successful.

[0092] The server 822 further includes a key information addition request 960 for receiving a key information addition request from another device, for example, a garage user, requesting that key information be newly stored in the setting information DB 958, and a key information update unit 962 for adding and storing the setting information associated with the user identifier attached to the key information addition request in the setting information DB 958 in response to the key information addition request 960 receiving the key information addition request.

[0093] Fig. 16 is a flowchart showing a control structure of a program for realizing key information transmission request receiving unit 950, setting information searching unit 952, key information extracting unit 954, and key information transmitting unit 956 shown in Fig. 15. Referring to Fig. 16, this program includes a step 990 for extracting an identifier of a passenger from the key information transmission request, a step 992 for searching setting information DB 958 for setting information using the identifier extracted in step 990 as a key, and a step 994 for branching the control flow depending on whether the search in step 992 is successful and a record of setting information corresponding to the identifier is found.

[0094] This program further includes step 996, in response to the determination in step 994 being positive, extracting key information from the setting information of the searched record if it is present; step 998, in which the control flow branches depending on whether or not key information is present as a result of the processing in step 996; step 1000, in which, when the determination in step 998 is positive, the key information is sent to the function-expanding ECU 840 and execution of this program is terminated; and step 1002, in which, when the result of the determination in step 994 or the result of the determination in step 998 is negative, the absence of key information corresponding to the received identification information is sent to the function-expanding ECU 840 and execution of this program is terminated.

[0095] B. Operation The driving assistance system 810 according to the second embodiment operates as follows: According to the driving assistance system 810 according to this embodiment, even if a passenger is riding in a vehicle different from usual, for example, the garage door of the passenger's home can be automatically opened and closed.

[0096] 12, the function expansion ECU 840 of the in-vehicle system 820 according to the second embodiment stores a plurality of key information items up to a predetermined upper limit for a given occupant's identifier. When new key information is stored, the function expansion ECU 840 adds and stores the new key information item and deletes the oldest stored key information item or the least recently used key information item.

[0097] 13 , the key information storage unit 872 of the function expansion ECU 840 stores usable key information for each identifier of an authenticated occupant. When the biometric authentication unit 274 has successfully performed biometric authentication, the information acquisition unit 870 outputs key information corresponding to the authenticated occupant's identifier if the key information storage unit 872 stores the key information. If such key information is not present, the information acquisition unit 870 transmits an information transmission request for the key information associated with the occupant's identifier to the server 822 shown in FIG. 12 , receives the corresponding key information, and adds it to the key information storage unit 872.

[0098] 15 , the setting information DB 958 of the server 822 stores a pre-associated identifier of a garage user and key information for the garage available for use. When the key information transmission request receiving unit 950 receives a key information transmission request from the information acquisition unit 870 of the function expansion ECU 840, the setting information search unit 952 searches the setting information DB 958 using the identifier as a key. If matching setting information is found, the setting information search unit 952 extracts the matching setting information from the setting information DB 958. If the search by the setting information search unit 952 is successful, the key information extraction unit 954 further extracts key information from the setting information extracted from the setting information DB 958. If the search by the setting information search unit 952 is successful, the key information transmission unit 956 selects the key information extracted by the key information extraction unit 954. If the search by the setting information search unit 952 is successful, the key information transmission unit 956 selects the key information extracted by the key information extraction unit 954. If the search by the setting information search unit 952 is not successful, the key information transmission unit 956 selects information indicating the search failure and transmits the information to the function expansion ECU 840.

[0099] When the key information storage unit 872 receives the corresponding key information from the server 822, it adds the key information to the key information storage unit 872. The process execution unit 874 executes a predetermined process using the key information output from the key information storage unit 872. Specifically, the opening / closing instruction unit 900 of the process execution unit 874 transmits the key information output by the key information storage unit 872 to the garage opening / closing unit 842. As a result, the garage opening / closing unit 842 can use the key information to open and close the door of a nearby garage.

[0100] As described above, according to the second embodiment, the key information of the garage used by the passenger is stored in the server 822 together with the passenger's identifier, and when the passenger is successfully authenticated, the key information is automatically downloaded to the vehicle from the server 822. As a result, even if the passenger rides in a different vehicle, the key information of the garage used by the passenger can always be used, and there is an advantage that it is not necessary to register the same key information for each vehicle.

[0101] C. Modifications C1. Configuration Figure 17 is a functional block diagram showing the relationship between the functions realized by the function expansion ECU 1030 according to the modification of the second embodiment. Referring to Figure 17, in addition to the biometric authentication unit 274 and the passenger identifier storage unit 276, the function expansion ECU 1030 includes a key information storage unit 1040 that stores the passenger's identifier, key information for a garage available to the passenger, and use restriction information for the key information, and an information acquisition unit 870 that receives the authentication result by the biometric authentication unit 274, searches the key information storage unit 1040 for key information corresponding to the authenticated passenger's identifier, and, if the key information is stored, extracts the key information. If the key information is not stored, the information acquisition unit 870 transmits an information transmission request to a server (not shown) requesting transmission of the key information corresponding to the passenger's identifier to acquire the key information.

[0102] The function-enhancing ECU 1030 further includes a processing execution unit 1042 that receives key information from the information acquisition unit 870 and instructs the garage opening / closing unit 842 to use the key information to open and close the garage door only if the key information is available.

[0103] The processing execution unit 1042 includes a validity determination unit 1060 that determines whether or not use restriction information is attached to the key information received from the information acquisition unit 870, and if use restriction information is attached, whether or not the restriction has been cleared; an opening / closing instruction unit 900 that, when valid key information is received from the validity determination unit 1060, instructs the garage opening / closing unit 842 to open or close the garage door using the key information; and an update unit 1062 that, when the opening / closing instruction unit 900 uses the key information to instruct the garage opening / closing unit 842, updates the key information stored in the key information storage unit 1040 to indicate that the key information has been used, and also transmits information indicating that the key information has been used to the server, and requests that information regarding the use of the key information be similarly updated in the server as well.

[0104] The process execution unit 1042 has two specific functions, which are as follows:

[0105] In relation to the first function, in this embodiment, the key information storage unit 1040 stores only a limited number of keys. For example, the upper limit is three. When a request is made to store more than the upper limit of keys, the key information with the least recently used history is deleted and the most recently used key information is stored instead. Therefore, each time a key is used, the date and time when the key was last used must be stored. This is the first function of the processing execution unit 1042, and this function is actually realized by the update unit 1062.

[0106] The second function relates to usage restrictions that can be imposed on key information in this embodiment. For example, if someone wants to temporarily borrow another person's vehicle and store it in their own garage, or conversely, if they temporarily allow another person to store their vehicle in their own garage, the key information for that garage must be made available for use in the other person's vehicle. This is also true, for example, when using a vehicle rental service or a so-called car share service. However, their key information cannot be stored in the vehicle without any restrictions; some kind of restriction is necessary. For this reason, this embodiment makes it possible to impose restrictions on the number of times or the period during which the key information can be used. The function required for this is the second function of the processing execution unit 1042. For example, if a restriction is imposed on the number of times the key information can be used, it is necessary to add a usage notification to the key information each time the key information is used. This function is specifically implemented by the update unit 1062. Furthermore, if a restriction is imposed on the period during which the key information can be used, it is necessary to determine whether the date and time at which the key information is used is within the usable period, and use is permitted only within the usable period. This function is specifically implemented by the validity determination unit 1060.

[0107] Fig. 18 is a flowchart showing a control structure of a program for realizing function-enhanced ECU 1030 according to this modification. Referring to Fig. 18, this program includes step 620 of performing biometric authentication, step 922 of branching the control flow depending on whether the authentication is successful or not, step 924 of searching for key information corresponding to the identifier of the authenticated occupant in key information storage unit 1040 shown in Fig. 17 when the determination in step 922 is affirmative, and step 926 of branching the control flow depending on whether key information corresponding to the identifier is found as a result of the search.

[0108] This program further includes a step 928 of transmitting key information related to the identifier to the server and receiving the result when the result of the determination in step 926 is negative, a step 930 of branching the control flow according to whether or not the server has key information corresponding to the identifier being processed as a result of the processing in step 928, and a step 932 of associating the key information and the identifier received from the server with each other and adding and storing them in key information storage unit 1040 shown in Figure 17 when the determination in step 930 is positive.

[0109] The program further includes step 1090, which is executed when the determination in step 926 is positive, or when the determination in step 926 is negative and the processing in step 932 is completed, and which branches the control flow depending on whether restriction information is attached to the key information corresponding to the identifier; step 1092, which branches the control flow depending on whether the restriction information has been cleared when the determination in step 1090 is positive; step 936, which notifies that there is no key information available and terminates execution of the program when the result of the determination in step 1092 is negative or when it is determined in step 922 that authentication has failed; and step 934, which sends the key information extracted in step 924 or the key information received from the server in step 928 to the garage opening / closing unit 842 shown in FIG. 7 when the determination in step 1090 or step 1092 is positive, and terminates execution of the program.

[0110] 19 is a functional block diagram showing the relationship between the functions realized by the server 1032 used in the driving assistance system according to this modification. Referring to FIG. 19 , the server 1032 includes a setting information DB 1150 that stores setting information including key information in association with an identifier of an individual authorized to use the garage corresponding to the key information, a key information transmission request receiving unit 950, a setting information searching unit 952 that retrieves setting information corresponding to the key information from the setting information DB 1150 by searching the setting information DB 1150 using the identifier included in the key information transmission request received by the key information transmission request receiving unit 950 as a key, a key information extraction unit 954 that extracts and outputs key information from the setting information retrieved from the setting information DB 1150 by the setting information searching unit 952, and a key information transmission unit 956 that transmits the key information output by the key information extraction unit 954 to the function expansion ECU 1030 ( FIG. 17 ). If the setting information search unit 952 does not have setting information corresponding to the identifier, or if there is corresponding setting information but it does not contain key information, the key information transmission unit 956 notifies the function-enhancing ECU 1030 that there is no key information corresponding to the identification.

[0111] The server 1032 further includes a key information addition request receiving unit 1152 that receives a key information addition request requesting the addition of new key information by specifying an identifier, and a key information updating unit 1154 that associates the key information included in the key information addition request received by the key information addition request receiving unit 1152 with the passenger identifier included in the key information addition request and adds the associated key information to the setting information DB 1150. In this embodiment, the key information addition request received by the key information addition request receiving unit 1152 may include, as described above, in addition to the passenger identifier and key information, usage restriction information for the key information. The key information updating unit 1154 registers the identifier and key information, including this usage restriction information, in the setting information DB 1150.

[0112] The server 1032 further includes a key information use restriction update request receiving unit 1156 that receives a key information use restriction update request from the update unit 1062 of the function expansion ECU 1030, requesting an update of the use restriction information of the key information, and a key information use restriction update unit 1158 that updates the use restriction information of the key information included in the setting information corresponding to the identifier included in the key information use restriction update request in the setting information DB 1150. In this embodiment, the key information use restriction update unit 1158 updates the last used date and time to the latest date and time, and adds 1 to the number of uses of the key information.

[0113] Fig. 20 is a flowchart showing a control structure of a program for realizing key information update unit 1154 shown in Fig. 19. Referring to Fig. 20, this program includes step 1200 of extracting, from a key addition request, an identifier of the individual who owns the key, an identifier of the garage controllable by the key information, and key use restriction information, if any, step 1202 of searching setting information DB 1150 using the identifier extracted in step 1200 as a key, and step 1204 of branching the control flow depending on whether a target record is found as a result of the search in step 1202.

[0114] This program further includes step 1206 of attempting to extract key information for the specified garage identifier from the searched setting information when the determination in step 1204 is affirmative, and step 1207 of branching the flow of control depending on whether the specified key information exists in step 1206. This program further includes step 1208 of extracting, when the determination in step 1206 is affirmative, the identifier of the individual to whom the key information is to be added from the key addition request, step 1210 of searching setting information DB 1150 using the individual identifier extracted in step 1208 as a key, and step 1211 of branching the flow of control depending on whether the target record is stored in setting information DB 1150 as a result of the search in step 1210.

[0115] This program further includes step 1212, which, when the determination in step 1211 is positive, adds the key information to a record of the setting information using the identifier searched in step 1210 as a key, updates that record in setting information DB 1150, and terminates execution of this program; and step 1214, which, when the determination in step 1211 is negative, notifies function-enhancing ECU 1030 that the corresponding key information cannot be added, and terminates execution of this program.

[0116] C2. Operation The function expansion ECU 1030 and server 1032 according to this modified example of the second embodiment operate as follows. Referring to FIG. 17 , the key information storage unit 1040 of the function expansion ECU 1030 pre-stores an individual's identifier, key information for a garage available to the individual, and usage restriction information for the key information. The information acquisition unit 870 receives the authentication result from the biometric authentication unit 274, searches the key information storage unit 1040 for key information corresponding to the authenticated occupant's identifier, and extracts the key information if it is stored. If such key information is not present in the key information storage unit 1040, the information acquisition unit 870 acquires the key information by transmitting an information transmission request to the server 1032 shown in FIG. 19 to request transmission of key information corresponding to the occupant's identifier.

[0117] Referring to FIG. 19 , upon receiving an information transmission request from information acquisition unit 870, server 1032 operates as follows. Setting information DB 1150 of server 1032 pre-stores setting information, including key information, in association with a personal identifier. Some of this key information may be accompanied by usage restriction information. When key information transmission request reception unit 950 receives a key information transmission request, setting information search unit 952 searches setting information DB 1150 using the identifier included in the key information transmission request received by key information transmission request reception unit 950 as a key, thereby extracting setting information corresponding to the key information from setting information DB 1150. Key information extraction unit 954 extracts and outputs key information from the setting information extracted from setting information DB 1150 by setting information search unit 952. Key information transmission unit 956 transmits the key information output by key information extraction unit 954 to function expansion ECU 1030 ( FIG. 17 ). If the setting information search unit 952 does not have setting information corresponding to the identifier, or if there is corresponding setting information but it does not contain key information, the key information transmission unit 956 notifies the function-enhancing ECU 1030 that there is no key information corresponding to the identification.

[0118] The processing execution unit 1042 of the function expansion ECU 1030 receives the key information from the information acquisition unit 870, and instructs the garage opening / closing unit 842 to use the key information to open or close the garage door only if the key information is usable. If the key information has usage restriction information, the key information can be used if the usage restriction information is cleared, but cannot be used if the information is not cleared.

[0119] The validity determination unit 1060 of the processing execution unit 1042 determines whether the key information received from the information acquisition unit 870 has usage restriction information attached, and if usage restrictions are attached, whether the restrictions have been satisfied. The opening / closing instruction unit 900 receives the determination result from the validity determination unit 1060 and, if valid key information is received, instructs the garage opening / closing unit 842 to use the key information to open or close the garage door. When the opening / closing instruction unit 900 uses the key information to instruct the garage opening / closing unit 842, the update unit 1062 updates the key information stored in the key information storage unit 1040 to indicate that the key information has been used. The update unit 1062 further transmits information indicating that the key information has been used to the server 1032 and requests that the server 1032 also update information regarding the use of the key information.

[0120] 19, when it is necessary to add new key information to server 1032, a key information addition request including the key information and the identifier of the garage corresponding to the key information must be sent to server 1032. If a third party is permitted to use the garage, the request for adding key information must further include the identifier of the third party and, if further usage restrictions are to be imposed, information specifying the usage restrictions.

[0121] When the key information addition request receiving unit 1152 of the server 1032 receives this key information addition request, it provides the key information to the key information updating unit 1154. The key information updating unit 1154 associates the key information included in the key information addition request with the passenger identifier included in the key information addition request and adds it to the setting information DB 1150. If the key information addition request includes use restriction information for the key information, the identifier and key information are registered in the setting information DB 1150, including the use restriction information.

[0122] The key information use restriction update request receiving unit 1156 of the server 1032 receives a key information use restriction update request from the update unit 1062 of the function expansion ECU 1030, which requests an update of the use restriction information of the key information, and uses the use restriction information of the key information to update the use restriction information of the key information included in the setting information corresponding to the identifier included in the key information use restriction update request in the setting information DB 1150. In this embodiment, the update of the key information use restriction information by the key information use restriction update unit 1158 is, as described above, to update the date and time of last use to the latest date and time and to increment the number of uses of the key information by one.

[0123] As described above, according to this embodiment, a garage owner can not only use common key information for any of his or her own vehicles, but also lend key information for the garage he or she manages to third parties. In this case, it is also possible to set restrictions on the period or number of times the key information can be used. Conversely, when parking a vehicle used for rental or car sharing in his or her garage, the owner can download key information so that the owner can use the garage. Even in this case, if the key information is restricted in use, even if the key information remains in the vehicle after the vehicle is returned, there is no risk of the owner's garage being used by a third party using the key. Therefore, key information for using the owner's garage can be shared among multiple vehicles, including vehicles other than the owner's, while preventing third parties from using the garage. This has the effect of simplifying management of garage key information.

[0124] 3. Third Embodiment A. Configuration A1. Overall Configuration Fig. 21 shows in block diagram form the configuration of a driving assistance system 1220 according to a third embodiment of the present disclosure. Referring to Fig. 21, the driving assistance system 1220 includes an in-vehicle system 1230 that recognizes the physical condition of a passenger and, based on the recognition result, schedules in advance the operation of facilities in the passenger's room (e.g., home) for relaxation when the passenger returns to the room, and, when a user instructs the scheduling, transmits a schedule request according to the instruction to an external device; a server 1232 that, based on the schedule request received from the in-vehicle system 1230, sets schedules for various facilities in the passenger's room of the vehicle equipped with the in-vehicle system 1230 and requests such scheduling from a home computer that controls the passenger's room; and a home server system 1234 installed in the passenger's home.

[0125] In addition to ECUs such as the autonomous driving ECU 70, a biosensor 76, and a TCU 74, the in-vehicle system 1230 includes a driver monitor 1240 for acquiring information to know the physical condition of the occupant, a function expansion ECU 1242 that generates in advance a schedule for controlling the operation of various facilities of the home server system 1234 based on the output of the biosensor 76 and the output of the driver monitor 1240, makes recommendations to the occupant, and obtains instructions from the occupant, and an IVI (In-Vehicle Infotainment system) 1244 that presents the recommendations made by the function expansion ECU 1242 to the occupant and receives input instructions such as acceptance or correction from the occupant.

[0126] In this embodiment, the driver monitor 1240 includes a camera 1250 that captures a facial image of the occupant and a biosensor 1252 that captures biometric information of the occupant. The biosensor 1252 may be, for example, a wearable device that is worn on the wrist and can measure the wearer's pulse, heart rate variability, and skin temperature. Note that a device capable of detecting body temperature, such as a thermal camera, may be used instead of or in addition to the camera 1250.

[0127] In this embodiment, the home server system 1234 includes a home server 1300 provided in the passenger's room, a home network 1302 to which the home server 1300 is connected, and a water heater 1304, an air conditioner 1306, lighting 1308, and a floor heating unit 1310, all of which can communicate with the home server 1300 via the home network 1302. In this embodiment, the water heater 1304, the air conditioner 1306, lighting 1308, and floor heating unit 1310 can all operate under control from the home server 1300.

[0128] In this embodiment, the home server 1300 has a function of operating the water heater 1304, air conditioner 1306, lighting 1308, and floor heating 1310 via the home network 1302 according to the schedule received from the server 1232, at events according to the schedule and according to settings specified by the schedule. For example, the home server 1300 has a function of controlling the water heater 1304 so that the bath is available at the time specified by the schedule. In addition, the home server 1300 operates the air conditioner 1306, lighting 1308, and floor heating 1310 according to the schedule.

[0129] Of course, this disclosure is not limited to such an embodiment. For example, if the water heater 1304, air conditioner 1306, floor heating 1310, etc. can themselves operate according to a specified schedule, the home server 1300 only needs to provide a function of setting schedules for these. Furthermore, if the home server 1300 does not exist but the water heater 1304, etc. can communicate directly with the outside, the server 1232 can also individually control these devices and individually set schedules for them.

[0130] A2. Configuration of the Function-Expanding ECU 1242 FIG. 22 is a block diagram showing the relationship between the various functions realized by the function-expanding ECU 1242. Referring to FIG. 22, the function-expanding ECU 1242 includes an occupant identifier storage unit 276, an occupant identifier storage unit 276, a setting information storage unit 1352, and an information acquisition unit 1350 that receives the occupant's identifier as a result of authentication by the biometric authentication unit 274, acquires setting information corresponding to the identifier by transmitting it to the server 1232, and stores it in the setting information storage unit 1352. The setting information storage unit 1352 stores, in correspondence with the occupant's identifier, information regarding various facilities installed at the occupant's residence that can be controlled directly or indirectly from the outside. The same type of information is also stored in the server 1232, and the information acquisition unit 1350 has the function of downloading the information from the server 1232 and storing it in the setting information storage unit 1352.

[0131] The function expansion ECU 1242 further includes a processing execution unit 1354 having a function of predicting the physical condition (fatigue level, etc.) of the occupant based on various sensor outputs from the driver monitor 1240 shown in Fig. 21, equipment information in the occupant's room stored in the setting information storage unit 1352, and the occupant's driving schedule, and if the prediction result satisfies predetermined conditions, creating a schedule for operating each unit of the home server system 1234 and recommending it to the occupant. The processing execution unit 1354 has a function of presenting the recommended contents via the in-vehicle navigation system via the IVI 1244, obtaining an instruction from the occupant to accept, not accept, or modify and accept the recommended contents, and if there is consent to performing processing based on the schedule, requesting the server 1232 to operate each unit of the home server system 1234 based on the schedule.

[0132] More specifically, the processing execution unit 1354 includes a physical condition recognition unit 1370 for predicting the physical condition of the occupant based on various sensor outputs from the driver monitor 1240, and a scheduling unit 1372 for recommending an operation schedule for various facilities in the occupant's home based on the equipment information of the occupant's room and the driving schedule stored in the setting information storage unit 1352, if the occupant's physical condition predicted by the physical condition recognition unit 1370 satisfies predetermined conditions, and receiving instructions from the occupant.

[0133] The scheduling unit 1372 includes a schedule creation unit 1400 that creates a schedule for operating various facilities so that the passenger can relax and recover from fatigue without having to do any tedious work when the passenger returns home when the passenger's physical condition predicted by the physical condition recognition unit 1370 meets predetermined conditions. The schedule creation unit 1400 reads out facility information corresponding to the passenger's identifier from the setting information storage unit 1352, and creates the above-mentioned schedule based on this facility information and the traveling plan.

[0134] The scheduling unit 1372 further includes a schedule recommendation unit 1402 that displays the schedule on a display device connected to the IVI 1244 by passing information about the schedule created by the schedule creation unit 1400 to the IVI 1244 and receives instructions from the passenger to approve, reject, or modify the schedule via an input device connected to the IVI 1244, and a scheduling request unit 1404 that receives the schedule approved by the passenger from the schedule recommendation unit 1402 and transmits it as a schedule request to the server 1232. The schedule includes the passenger's identifier and a list of the status of each piece of equipment in the passenger's room at what time.

[0135] Fig. 23 is a flowchart showing a control structure of a program for implementing the functions of function expansion ECU 1242 shown in Fig. 21. Referring to Fig. 23, this program includes step 620 for performing biometric authentication, and step 1450 for branching the control flow depending on whether the biometric authentication has been successful. If the determination in step 1450 is negative, execution of this program ends.

[0136] This program further includes step 1452, which starts the physical condition recognition unit 1370 shown in Fig. 22 when the determination in step 1450 is affirmative, step 1454, which starts the scheduling unit 1372 shown in Fig. 22 after step 1452, and step 1456, which executes regular processing other than these in a loop after step 1454. Steps 1452 and 1454 are started when the authentication of the passenger is successful, and continue to operate until a predetermined termination condition is met.

[0137] FIG. 24 is a flowchart showing a control structure of a program for implementing physical condition recognition unit 1370 shown in FIG. 22 . Referring to FIG. 24 , this program includes, upon startup, step 1500 for clearing a memory for storing sensor outputs used for fatigue level calculation, and step 1502 for reading various sensor outputs from driver monitor 1240 and storing the values ​​of those outputs for a predetermined period of time in memory. The values ​​stored in memory at this time are the sensor outputs for the most recent period of time, for example, one minute. The sampling of the sensor outputs does not need to be so short, and may be every one second or two seconds, for example. Regarding facial images, it is preferable to use a filter including a neural network that outputs information such as the presence or absence of blinking, gaze movement, and pupil dilation from the image, rather than directly using the image output.

[0138] This program further includes step 1504, which branches the flow of control depending on whether a predetermined time (e.g., one minute) has elapsed, and step 1506, which, when the determination in step 1504 is affirmative, outputs the occupant's fatigue level (either 0 (no fatigue), 1 (mild fatigue), or 2 (fatigue)) using the value stored in memory, adds the result to an array for storing fatigue levels in memory, and returns control to step 1502. When the determination in step 1504 is negative, control skips step 1506 and returns to step 1502. The array for storing fatigue levels is intended to store the fatigue level values ​​calculated in step 1502 over, for example, the most recent 60 minutes. When the fatigue level accumulation time exceeds 60 minutes, the oldest values ​​are overwritten with the newest values ​​in order.

[0139] In step 1502, a pre-trained neural network is used, which receives as input a vector concatenated with vectors consisting of the time series of outputs from various sensors over one minute, and has three outputs corresponding to whether the occupant's fatigue level is 0, 1, or 2. These three outputs output the probabilities that the occupant's fatigue level is 0, 1, or 2, respectively. The fatigue level corresponding to the output with the highest probability is adopted as the fatigue level at that time. In this embodiment, the fatigue level is limited to three levels, so there is little risk of difficulty in collecting learning data.

[0140] 25 is a flowchart showing a control structure of a program that realizes scheduling unit 1372 shown in FIG. 22. Referring to FIG. 25, this program includes step 1550 of reading a fatigue level sequence for a specified time period most recently from the fatigue level array in memory, and step 1552 of calculating a previous fatigue level F0 and a current fatigue level F1. In this embodiment, the previous fatigue level F0 uses the average value of the first half of the fatigue level array, and the current fatigue level F1 uses the average value of the second half of the fatigue level array. Of course, the fatigue level calculated in the previous processing may be stored and used as the previous fatigue level F0.

[0141] This program further includes step 1554 for calculating a state transition according to a predetermined state transition diagram based on the values ​​of the previous fatigue level F0 and the current fatigue level F1, and step 1556 for branching the control flow depending on whether or not a state transition has occurred as a result of the processing in step 1554.

[0142] FIG. 26 shows an example of a state transition diagram used in step 1554. Referring to FIG. 26, this state transition diagram includes a state node 1600 corresponding to fatigue level 0, a state node 1602 corresponding to fatigue level 1, and a state node 1604 corresponding to fatigue level 2. Two unidirectional edges representing state transitions exist between each of these three nodes. The base of the arrow for each unidirectional edge is referred to as the "head" and the tip of the arrow as the "tail." A threshold value is assigned to each of these edges. Each threshold value indicates that when the current state (corresponding to the previous fatigue level F0 calculated in step 1554) is at the head of the edge, and the value of the current fatigue level F1 calculated in step 1554 of FIG. 25 is greater than the threshold value for that edge, the state transition indicated by that edge is performed. However, in this embodiment, for example, from state node 1600, there is an edge (threshold value 0.7) leading to state node 1602 and an edge (threshold value 1.6) leading to state node 1604. In such a case, the state transition is calculated by first testing the higher threshold, and if that test is negative, then testing the lower threshold. The reverse is also true. That is, from state node 1604, there is an edge (threshold 1.4) pointing to state node 1602 and an edge (threshold 0.3) pointing to state node 1600. In such a case, the state transition is first tested for the edge with the lower threshold, and if that test is negative, then the state transition is tested for the edge with the higher threshold.

[0143] 26, for example, the threshold value of the edge from state node 1600 to state node 1602 is 0.7, whereas the threshold value of the edge from state node 1602 to state node 1600 is 0.3, which is lower than 0.7. This is to prevent frequent state transitions near the threshold value if the two threshold values ​​are made equal. The same applies to transitions between other state nodes.

[0144] 25, this program further includes step 1560, in which, when the determination in step 1556 is affirmative, a plan corresponding to the state after the transition is passed to IVI 1244, thereby recommending the plan to the passenger and obtaining instructions from the passenger. In this embodiment, as described above, only three fatigue states are assumed, and predetermined recommendations are prepared in advance for each of these states. The schedule creation unit 1400 applies information about the facilities in the passenger's room to these recommendations to create recommendations suitable for the passenger.

[0145] This program further includes step 1562 for receiving an instruction from the passenger in step 1560 (approval, instruction not to approve, or instruction to approve with modifications), step 1564 for branching the flow of control depending on whether the instruction from the passenger indicates the execution of the schedule, step 1566 for transmitting the schedule to server 1232 (see FIG. 21) to request the execution of the schedule when the determination in step 1564 is affirmative, and step 1558 for waiting a predetermined time after step 1566 and then returning control to step 1550. When the result of the determination in step 1556 or step 1564 is negative, control proceeds to step 1558.

[0146] A3. Configuration of server 1232 Fig. 27 shows the relationship between the functions realized by server 1232 shown in Fig. 21. Referring to Fig. 27, server 1232 includes: a setting information DB 1660 that associates and stores various setting information including facility information related to the facility at the person's residence with an identifier of each person; a facility information update request receiving unit 1656 that specifies an identifier of an individual to setting information DB 1660 and receives a facility information update request related to addition, modification, or deletion of facility information related to the person's room; a facility information update unit 1658 that adds, changes, or deletes facility information related to the identifier in setting information DB 1660 in response to the facility information update request received by facility information update request receiving unit 1656; and a facility specification information DB 1662 that stores specification information related to various facilities in advance.

[0147] The server 1232 further includes an information transmission request receiving unit 1650 for receiving an information transmission request requesting the transmission of equipment information specifying an individual's identifier from the information acquisition unit 1350 shown in FIG. 22 , a setting information search unit 1654 for searching the setting information DB 1660 using the received identifier as a key in response to the information transmission request being received by the information transmission request receiving unit 1650, extracting the relevant setting information, and further extracting equipment information from the setting information, and an information transmission unit 1652 for transmitting the setting information including the equipment information extracted by the setting information search unit 1654 to the information acquisition unit 1350.

[0148] The server 1232 further includes a scheduling request receiving unit 1664 for receiving a scheduling request from the scheduling request unit 1404 shown in FIG. 22 , an equipment control unit 1666 for, in response to the scheduling request receiving unit 1664 receiving the scheduling request, reading details of the various pieces of equipment included in the scheduling request from the setting information search unit 1654, and further reading the specifications of those various pieces of equipment from the equipment specification information DB 1662, thereby generating respective instruction sequences for individually operating the various pieces of equipment in the passenger's room according to the schedule received by the scheduling request receiving unit 1664, or instruction sequences for the home server in the passenger's room to operate those pieces of equipment according to the schedule, and a control information transmitting unit 1668 for transmitting the instruction sequences generated by the equipment control unit 1666 to the respective pieces of equipment in the passenger's room stored in the setting information search unit 1654 or to a specified address of the home computer.

[0149] Fig. 28 is a flowchart showing a control structure of a program executed by the server according to the third embodiment shown in Fig. 21, for realizing facility control unit 1666 shown in Fig. 27. Referring to Fig. 28, this program includes step 1700 of extracting a passenger identifier, a facility identifier, and schedule details (operation details and times of each facility) from a scheduling request received from scheduling request unit 1404 (Fig. 22), step 1702 of executing step 1704 for each facility extracted in step 1700, and step 1706 of transmitting a result of schedule execution to scheduling request unit 1404 after completion of step 1702.

[0150] 27 using the identifier of the equipment to be processed in the schedule as a key, step 1722 branches the control flow depending on whether or not corresponding equipment specification information exists as a result of the search in step 1720, and step 1724 generates control information for the equipment based on the schedule information and the retrieved equipment specifications if the determination in step 1722 is affirmative. If the determination in step 1722 is negative, the equipment cannot be operated, and therefore execution of step 1704 is terminated.

[0151] Step 1704 further includes step 1726, which, after step 1724, sends the control information created in step 1724 to the destination address of commands for each piece of equipment included in the setting information corresponding to the passenger's identifier, and terminates step 1704. If there is no home server at the passenger's residence, this address may be an individual address for controlling each piece of equipment. If there is a home server at the passenger's residence and that server can control the external equipment, this destination address may be the address of the home server.

[0152] B. Operation The driving assistance system 1220 according to the third embodiment described above operates as follows.

[0153] 27 , facility information update request receiving unit 1656 of server 1232 specifies an individual's identifier to setting information DB 1660 and receives a facility information update request for adding, modifying, or deleting facility information related to the individual's room. In response to this facility information update request, facility information update unit 1658 adds facility information related to the identifier to setting information DB 1660, changes stored facility information, or deletes facility information. As a result, setting information DB 1660 pre-stores each individual's identifier in association with various setting information, including facility information related to the facilities in the individual's residence.

[0154] The equipment specification information DB 1662 stores specification information relating to various types of equipment in advance. This specification information may be acquired not from individuals but from manufacturers or sellers of the various types of equipment.

[0155] 21 , the sensors (camera 1250 and biosensor 1252) included in the driver monitor 1240 of the in-vehicle system 1230 acquire information for determining the physical condition of the occupant and input the information to the function expansion ECU 1242. The function expansion ECU 1242 generates in advance a schedule for controlling the operation of various facilities of the home server system 1234 based on the output of the biosensor 76 and the output of the driver monitor 1240, and performs the process of making recommendations to the occupant and obtaining instructions from the occupant as follows: The IVI 1244 presents the recommendations made by the function expansion ECU 1242 to the occupant, receives input of instructions such as acceptance or modification from the occupant, and then provides the results to the function expansion ECU 1242.

[0156] 22 , the setting information storage unit 1352 stores, in correspondence with the identifier of the occupant, information relating to various facilities provided in the occupant's residence that can be controlled directly or indirectly from the outside. The information acquisition unit 1350 of the function expansion ECU 1242 receives the occupant's identifier as a result of authentication by the biometric authentication unit 274, and transmits to the server 1232 a request to send setting information corresponding to the identifier (information transmission request).

[0157] 27 , information transmission request receiving unit 1650 of server 1232 receives an information transmission request from information acquiring unit 1350. In response to information transmission request receiving unit 1650 receiving the information transmission request, setting information searching unit 1654 searches setting information DB 1660 using the received identifier as a key, extracts corresponding setting information, and further extracts facility information from the extracted setting information. Information transmitting unit 1652 transmits setting information including the facility information extracted by setting information searching unit 1654 to information acquiring unit 1350.

[0158] 22 again, the information acquisition unit 1350 receives setting information from the server 1232 and stores it in the setting information storage unit 1352. The processing execution unit 1354 of the function expansion ECU 1242 predicts the physical condition (fatigue level, etc.) of the occupant based on various sensor outputs from the driver monitor 1240 shown in FIG. 21 , equipment information in the occupant's room stored in the setting information storage unit 1352, and the occupant's driving schedule, and if the prediction result satisfies predetermined conditions, creates a schedule for operating each unit of the home server system 1234 and recommends it to the occupant. The processing execution unit 1354 presents the recommended content on a display device such as an in-vehicle navigation system via the IVI 1244, and similarly receives an instruction from the occupant via an input device such as the in-vehicle navigation system to accept, not accept, or modify and accept the schedule. If the occupant agrees to perform processing based on the schedule, the processing execution unit 1354 requests the server 1232 to operate each unit of the home server system 1234 based on the schedule.

[0159] More specifically, the physical condition recognition unit 1370 of the processing execution unit 1354 predicts the physical condition of the occupant based on the outputs of various sensors from the driver monitor 1240. If the physical condition of the occupant predicted by the physical condition recognition unit 1370 satisfies predetermined conditions, the scheduling unit 1372 recommends an operation schedule for various facilities in the occupant's home based on the equipment information of the occupant's room stored in the setting information storage unit 1352 and the driving schedule, and receives instructions from the occupant.

[0160] When the physical condition of the passenger predicted by the physical condition recognition unit 1370 satisfies a predetermined condition, the schedule creation unit 1400 of the scheduling unit 1372 creates a schedule for operating various facilities so that the passenger can relax and recover from fatigue without having to do any tedious work when he or she returns home. At this time, the schedule creation unit 1400 reads out facility information corresponding to the passenger's identifier from the setting information storage unit 1352 and uses this facility information and the traveling schedule.

[0161] The schedule recommendation unit 1402 of the scheduling unit 1372 passes information about the schedule created by the schedule creation unit 1400 to the IVI 1244, thereby displaying the schedule on a display device connected to the IVI 1244. The schedule recommendation unit 1402 further receives an instruction to approve, reject, or modify the schedule from the passenger via an input device connected to the IVI 1244. The scheduling request unit 1404 receives the schedule approved by the passenger from the schedule recommendation unit 1402 and transmits it to the server 1232 as a schedule request. The schedule includes the passenger's identifier and a list of the status of each piece of equipment in the passenger's room at what time.

[0162] Referring to Figure 24, the process of recognizing the physical condition of a passenger by the physical condition recognition unit 1370 will be described. Upon startup, this program clears the memory that stores the sensor outputs used to calculate the fatigue level in step 1500. In the following step 1502, various sensor outputs are read from the driver monitor 1240, and the values ​​of these outputs for the most recent predetermined time period are stored in memory. The values ​​stored in memory at this time are the sensor outputs for the most recent one minute.

[0163] In the next step 1504, it is checked whether a predetermined time has elapsed. If the predetermined time has elapsed, in step 1506, the occupant's fatigue level (either 0 (no fatigue), 1 (mild fatigue), or 2 (fatigue)) is output using the values ​​accumulated in memory and added to and stored in an array for storing fatigue levels in memory. In other words, a value (0, 1, or 2) indicating the occupant's fatigue level is stored every minute. The array for storing fatigue levels stores the fatigue level values ​​calculated in step 1502 over, for example, the most recent 60 minutes. If the fatigue level accumulation time exceeds 60 minutes, the oldest values ​​are overwritten with newer fatigue levels.

[0164] 25, when a program for realizing the scheduling unit 1372 shown in FIG. 22 is executed, a fatigue level sequence for a most recent predetermined time period is read from the fatigue level array in memory in step 1550. Next, a previous fatigue level F0 and a current fatigue level F1 are calculated in step 1552. In this embodiment, the previous fatigue level F0 uses the average value of the first half of the fatigue level array, and the current fatigue level F1 uses the average value of the second half of the fatigue level array.

[0165] In step 1554, a state transition is calculated according to the state transition diagram shown in FIG. 26 based on the values ​​of the previous fatigue level F0 and the current fatigue level F1. In step 1556, it is determined whether a state transition has occurred as a result of the processing in step 1554. If a state transition has occurred, in step 1560, a plan corresponding to the state after the transition is passed to IVI 1244, which is recommended to the passenger and the passenger's instructions are obtained. Furthermore, in step 1562, the program receives instructions from the passenger (approval, instruction to not require, instruction to approve with modifications). If the passenger's instruction indicates the execution of the schedule (deterministic in step 1564), in step 1566, the schedule is sent to server 1232 (see FIG. 21) to request the execution of the schedule, and in step 1558, the program waits for a predetermined time for execution, after which control is returned to step 1550. If the result of the determination at step 1556 or step 1564 is negative, nothing is done, and step 1558 waits for the program to execute for a predetermined time, after which control returns to step 1550 .

[0166] Through the above process, for example, if the average fatigue level is 0.7 or less for a predetermined period of time and then exceeds 0.7, the fatigue level transitions from 0 to 1 as shown in Figure 26. Furthermore, if the fatigue level is 0.3 or more and 0.1.4 or less in that state, the state of fatigue level = 1 is maintained. If the average fatigue level for a predetermined period of time falls below 0.3, the fatigue level transitions to 0. On the other hand, if the average fatigue level for a predetermined period of time exceeds 1.6 when the fatigue level is 1, the fatigue level becomes 2.

[0167] The principle of state transition after the fatigue level reaches 2 is the same as when the fatigue level is 1. However, the threshold value in this case is different from when the fatigue level is 1.

[0168] In the state transition diagram shown in Figure 26, the thresholds assigned to the two edges between a pair of state nodes are different. These values ​​are selected so that after a state transition from one direction to the other, the state transition is unlikely to occur in the opposite direction. As a result, the fatigue calculation is stable, preventing recommendations from being displayed multiple times.

[0169] Referring to FIG. 27 , in the server 1232, the scheduling request receiving unit 1664 receives a scheduling request from the scheduling request unit 1404 shown in FIG. In response to the scheduling request received by the scheduling request receiving unit 1664, the equipment control unit 1666 reads details of the various pieces of equipment included in the scheduling request from the setting information searching unit 1654. The equipment control unit 1666 further reads specifications of the various pieces of equipment from the equipment specification information DB 1662. Using this information, the equipment control unit 1666 generates, in accordance with the schedule received by the scheduling request receiving unit 1664, respective instruction sequences for individually operating the various pieces of equipment in the passenger's room, or instruction sequences for the home server in the passenger's room to operate the pieces of equipment in accordance with the schedule. The control information transmitting unit 1668 transmits the instruction sequences generated by the equipment control unit 1666 to the designated addresses of the pieces of equipment or home computers in the passenger's room stored in the setting information searching unit 1654.

[0170] In the home server system 1234 shown in Figure 21, for example, when the home server 1300 receives the above-mentioned command sequence, it operates each piece of equipment connected to the home network 1302 according to the schedule indicated by the command sequence. Alternatively, when an individual piece of equipment connected to the home network 1302 receives the above-mentioned command sequence, that equipment executes the process specified by the schedule at the time specified by the schedule according to the schedule. As a result, when the vehicle occupant returns to their room, each unit connected to the home network 1302 will be in a predetermined state according to the fatigue caused by driving the vehicle, and the occupant can efficiently recover from fatigue by returning to a room adjusted to a moderate temperature and appropriate lighting, and taking a bath with water at a moderate temperature.

[0171] Each process (each function) in the above-described embodiments is realized by a processing circuit (circuitry) including one or more processors. The processing circuit may be configured with an integrated circuit that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the processes. The one or more processors may execute each of the processes according to the program read from the one or more memories, or according to a logic circuit designed in advance to execute each of the processes. The processor may be a CPU, GPU, DSP (Digital Signal Processor), FPGA (Field-Programmable Gate Array), ASIC (Application Specific Integrated Circuit), or any other processor suitable for computer control. The physically separated processors may cooperate with each other to execute the processes. For example, the processors installed in the physically separated computers may cooperate with each other via a network such as a local area network (LAN), a wide area network (WAN), or the Internet to execute the processes. The program may be installed in the memory from an external server device or the like via the network, or may be distributed in a state stored on a recording medium such as a compact disc read-only memory (CD-ROM), a digital versatile disc read-only memory (DVD-ROM), or a semiconductor memory, and installed in the memory from the recording medium.

[0172] In the above-described embodiment, the driver is primarily considered as the passenger. However, this disclosure is not limited to such an embodiment. A passenger in the front passenger seat can also be targeted. Furthermore, by providing a facial recognition device in both the driver's seat and the front passenger seat, the driver and the front passenger can be recognized separately. Using this information, the in-vehicle device can process setting information for the two passengers separately. In this case, if settings for the two passengers conflict, the conflict can be resolved according to some standard. For example, the settings for the driver's seat passenger can be prioritized for vehicle control settings. Furthermore, instead of managing the settings for the two passengers separately, setting information for a specific combination of driver and front passenger seat passengers can be stored in a server, and the vehicle can be configured according to setting information for that specific combination that differs from when each passenger is alone.

[0173] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present disclosure is not defined by the detailed description of the disclosure, but by the claims of the appended claims, and is intended to include all modifications within the meaning and scope of the claims.

[0174] 50, 810, 1220 Driving assistance system 60, 820, 1230 In-vehicle system 62, 822, 1032, 1232 Server 70 Autonomous driving ECU 72, 840, 1030, 1242 Function extension ECU 74 TCU 76, 1252 Biometric sensor 78 BCU 80 Seat adjustment unit 82 Mirror adjustment unit 84 Air conditioner adjustment unit 86 Lighting adjustment unit 88 Other adjustment unit 130 Hardware layer 132 Base software layer 134 Application layer 180 Processor 200 High-speed bus 202 MPU 204 SRAM 206 Flash memory 208, 496 ROM 210 Low-speed bus 212 Bridge 214 Serial I / F 216 ADC 218 Timer / counter 220 Clock generator 222 Power supply control unit 224 General-purpose I / F 226 Program 274 Biometric authentication unit 276 Passenger identifier storage unit 278, 870, 1350 Information acquisition unit 280, 874, 1042, 1354 Processing execution unit 282 Vehicle type information storage unit 284 Change information transmission unit 300 Adjustment instruction unit 350 State identification unit 352 Settable information storage unit 354 Equipment adjustment instruction unit 470 Computer 472 Monitor 474 Keyboard 476 Mouse 478 DVD 480 Speaker 482 Microphone 484 USB memory 486 Network 490 CPU 492 GPU 498 RAM 500 SSD 502 DVD drive 504 Audio I / F 506 USB port 508 Network I / F 510 Bus 560, 1650 Information transmission request receiving unit 562, 952, 1654 Setting information searching unit 564 Setting information transmitting unit 566, 958, 1150, 1660 Setting information DB 568 Update request receiving unit 570 Setting information updating unit 842 Garage opening / closing unit 872, 1040 Key information storage unit 900 Opening / closing instruction unit 950 Key information transmission request receiving unit 954 Key information extracting unit 956 Key information transmitting unit 960 Key information addition request 962, 1154 Key information updating unit 1060 Validity determining unit 1062 Update unit 1152 Key information addition request receiving unit 1156 Key information use restriction update request receiving unit 1158 Key information use restriction updating unit 1234 Home Server System 1240 Driver Monitor 1244 IVI1250 Camera 1300 Home server 1302 Home network 1304 Water heater 1306 Air conditioner 1308 Lighting 1310 Floor heating 1352 Setting information storage unit 1370 Physical condition recognition unit 1372 Scheduling unit 1400 Schedule creation unit 1402 Schedule recommendation unit 1404 Scheduling request unit 1600, 1602, 1604 State node 1652 Information transmission unit 1656 Equipment information update request reception unit 1658 Equipment information update unit 1662 Equipment specification information DB 1664 Scheduling request reception unit 1666 Equipment control unit 1668 Control information transmission unit

Claims

1. an information acquisition unit that acquires information associated with a vehicle occupant through communication with a server; a processing execution unit connected to an in-vehicle network of the vehicle and executing processing according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network.

2. The in-vehicle device according to claim 1 , further comprising an occupant authentication unit that authenticates the occupant.

3. The in-vehicle device according to claim 2 , wherein the passenger authentication unit includes a face image authentication unit provided in the vehicle and configured to perform authentication using a face image of the passenger.

4. The information includes adjustment information regarding adjustment of equipment in the vehicle when the passenger boards the vehicle; 4. The in-vehicle device according to claim 1, wherein the processing execution unit includes an adjustment instruction unit that instructs another device via the in-vehicle network to automatically adjust the position of the part used by the occupant of the vehicle in which the in-vehicle device is installed, using the adjustment information.

5. the adjustment information includes state designation information that designates a state of the equipment when the passenger boards the vehicle, The adjustment instruction unit a state specifying unit that specifies a state that is closest to the state specified by the state specifying information among states that the equipment can take in the vehicle equipped with the on-vehicle device; The in-vehicle device according to claim 4 , further comprising an equipment adjustment instruction unit that instructs the other device to adjust the state of the equipment used by the passenger to the state specified by the state specifying unit.

6. The in-vehicle device of claim 5 further includes a change information transmission unit that transmits information identifying the occupant and the state of the equipment after the change to the server in response to the occupant manually changing the state after the state of the equipment used by the occupant has been adjusted by the other device.

7. The in-vehicle device of claim 5 further includes a change information transmission unit that transmits to the server information identifying the occupant, the state of the equipment after the change, and information regarding the vehicle model in response to the occupant manually changing the state after the state of the equipment used by the occupant has been adjusted by the other device.

8. 6. The in-vehicle device according to claim 5, wherein the equipment includes at least one of a position adjustment device for a seat used by the passenger among the seats of the vehicle, an electric mirror device of the vehicle, and an air conditioning device provided in the vehicle.

9. the information includes key information for an automatic garage door opener used by the passenger; 4. The in-vehicle device according to claim 1, wherein the processing execution unit includes an opening / closing instruction unit that instructs another device via the in-vehicle network to operate the automatic opening / closing device using the key information in response to a predetermined condition being satisfied.

10. the information further includes validity control information for controlling validity of the key information included in the information; 10. The in-vehicle device according to claim 9, wherein the processing execution unit further includes a validity determination unit that prohibits the opening / closing instruction unit from using key information included in the information that is determined to be invalid by referring to the validity control information.

11. The information includes information about externally controllable facilities present at a residence used by the passenger after using the vehicle, The processing execution unit a physical condition recognition unit that recognizes the physical condition of the passenger; 4. The in-vehicle device according to claim 1, further comprising: a scheduling unit that selects at least one of the functions of the equipment at the location of the occupant in accordance with the physical condition recognized by the physical condition recognition unit and schedules the activation of that function.

12. The scheduling unit a schedule creation unit that selects at least one of the functions of the facility at the location of the passenger in accordance with the physical condition recognized by the physical condition recognition unit and creates a schedule for activation of the selected function; The in-vehicle device according to claim 11 , further comprising: a request unit that transmits the schedule created by the schedule creation unit to the server and requests that the facility at the residence be controlled in accordance with the schedule.

13. The scheduling unit a schedule creation unit that selects at least one of the functions of the facility at the location of the passenger in accordance with the physical condition recognized by the physical condition recognition unit and creates a schedule for activation of the selected function; 12. The in-vehicle device according to claim 11, further comprising: a request unit that transmits the schedule created by the schedule creation unit to a home server in the residence and requests the home server to control the facility in the residence according to the schedule.

14. The in-vehicle device according to claim 1 , wherein the passenger is a driver of the vehicle.

15. Further, a storage unit that stores the information acquired by the information acquisition unit, The information acquisition unit a search unit that searches the storage unit for information associated with the passenger; an information storage unit that, in response to a failure of the search by the search unit, acquires information associated with the passenger through communication with the server and stores the information in the memory unit; 4. The in-vehicle device according to claim 1, further comprising: a selection unit that selectively outputs an output of the search unit and the information acquired by the information storage unit to the processing execution unit depending on whether a search by the search unit is successful or not.

16. A server; A personalized driving assistance system including a sensor and an on-board device mounted on a vehicle, The server a storage unit that stores personal identification information and information related to the personal information in association with each other; an information transmission unit that, in response to receiving an information transmission request specifying personal identification information from the in-vehicle device, reads information associated with the identification information from the storage unit and transmits the information to the in-vehicle device; The in-vehicle device an information acquisition unit that acquires information associated with the occupant of the vehicle from the server by requesting the information transmission unit of the server to transmit the information associated with the occupant; a processing execution unit connected to the vehicle's in-vehicle network and executing processing according to the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network.

17. a storage unit that stores personal identification information and information related to the personal information in association with each other; A server including an information transmission unit that, in response to receiving an information transmission request specifying personal identification information from an external vehicle-mounted device, reads information associated with the identification information from the storage unit and transmits the information to the vehicle-mounted device.

18. The server of claim 17, wherein the information includes at least one of adjustment information regarding adjustment of equipment in the vehicle when the individual gets into the vehicle, key information for an automatic opening and closing device of a garage used by the individual, and information regarding externally controllable equipment present at a residence used by the individual after using the vehicle.

19. The server according to claim 17 or claim 18, further comprising an update unit that, in response to receiving an individual's identification information and information related to the individual from the external in-vehicle device, adds and stores a combination of the identification information and the information in the memory unit if the combination is not stored in the memory unit, and updates the stored information about the individual using the information about the individual received from the external in-vehicle device if the combination is stored in the memory unit.

20. The information includes information about externally controllable facilities present at a residence used by the individual after use of the vehicle; The server according to claim 18, further comprising an equipment control unit that, in response to receiving from the external in-vehicle device personal identification information and a scheduling request for the controllable equipment related to the individual, controls the equipment related to the individual based on the control instruction.

21. Computer, an information acquisition unit that acquires information associated with a vehicle occupant through communication with a server; A computer program that is connected to the vehicle's in-vehicle network and functions as a processing execution unit that executes processing in accordance with the information acquired by the information acquisition unit using resources that can communicate via the in-vehicle network.