Vehicle management device, management server, and management system
The vehicle management device and server system addresses the storage limitations in digital key systems by automatically managing and deleting units, enhancing user experience by reducing manual intervention.
Patent Information
- Application Number
- PCT/JP2025/019473
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-12
- Filing Date
- 2025-05-29
- Publication Date
- 2026-01-15
AI Technical Summary
Existing digital key systems for vehicles face limitations in storage capacity, requiring users to manually select which digital key information units to delete when the maximum number is reached, leading to user burden.
A vehicle management device and management server system that automatically manages digital key information units, including a vehicle processing circuit and server processing circuit, to delete existing units when a new unit is received, reducing user intervention.
Automated management of digital key units reduces user burden by eliminating the need for manual selection, ensuring seamless addition of new keys without overwriting existing ones.
Smart Images

Figure JP2025019473_15012026_PF_FP_ABST
Abstract
Description
Vehicle management device, management server, and management system
[0001] The present disclosure relates to a vehicle management device, a management server, and a management system.
[0002] Patent Literature 1 discloses a digital key system technology that uses a device such as a smartphone as a vehicle key. The digital key system stores digital key information in the vehicle. The digital key system stores digital key information in the device. This allows a vehicle to be used using a device registered as a digital key without the need for a physical key. Furthermore, the digital key system communicates between the device storing the digital key information and another person's device to issue a registration request to enable the other person's device to function as a digital key. This allows the other person's device to be registered as a digital key to the vehicle. In other words, the digital key can generate a new digital key. The digital key system allows a vehicle to be loaned to another person without the need to exchange a physical key.
[0003] JP 2023-184349 A
[0004] There may be a limit to the number of digital key information units that a vehicle is configured to be able to store.
[0005] According to one aspect of the present disclosure, there is provided a vehicle management device mounted on a vehicle. The vehicle management device includes a vehicle processing circuit and a vehicle storage device configured to store one or more digital key information units. The digital key information units are information units related to a digital key. The vehicle storage device has a predetermined number of stored digital key information units. When the stored number has reached the predetermined number and a new digital key information unit is received, the vehicle processing circuit is configured to delete one of the one or more digital key information units stored in the vehicle storage device.
[0006] According to another aspect of the present disclosure, there is provided a management server including a server processing circuit. The server processing circuit receives a storage request to store one or more digital key information units in a vehicle to manage one or more digital keys. The one or more digital key information units are information units related to one or more of the digital keys. The server processing circuit determines whether a stored number, which is the number of digital key information units stored in the vehicle, has reached a predetermined number of digital key information units that the vehicle can store. When the server processing circuit receives the storage request for a vehicle for which the stored number has reached the predetermined number, the server processing circuit transmits a command to the vehicle to delete any of the one or more digital key information units stored in the vehicle.
[0007] According to yet another aspect of the present disclosure, there is provided a management system. The management system includes a vehicle management device mounted on a vehicle and a management server including a server processing circuit. The vehicle management device includes a vehicle processing circuit and a vehicle storage device. The server processing circuit manages one or more digital keys. The vehicle storage device stores one or more digital key information units as information units related to the one or more digital keys. The vehicle storage device has a predetermined number of digital key information units that can be stored. At least one of the vehicle processing circuit and the server processing circuit is configured to delete one of the one or more digital key information units already stored in the vehicle storage device when a new digital key information unit is received when the number of digital key information units already stored in the vehicle storage device has reached the predetermined number.
[0008] According to the vehicle management device, the user does not need to select which digital key information units to delete from among the digital key information units already stored in the vehicle, thereby reducing the burden on the user.
[0009] The management server eliminates the need for the user to select which digital key information units to delete from among those stored in the vehicle, thereby reducing the burden on the user.
[0010] The management system described above eliminates the need for the user to select which digital key information units to delete from among those stored in the vehicle, thereby reducing the burden on the user.
[0011] Now, there is a limit to the number of digital key information units that a vehicle can store. When the number of digital key information units already stored in the vehicle has reached the preset number, storing a new digital key information unit in the vehicle requires the following: the vehicle user must select which digital key information unit to delete from the digital key information units already stored in the vehicle. The various configurations described above address this requirement.
[0012] FIG. 1 is a schematic diagram showing a management system of the first embodiment. FIG. 2 is a schematic diagram showing owner key information of the first embodiment. FIG. 3 is a schematic diagram showing share key information of the first embodiment. FIG. 4 is a schematic diagram showing data in a database of the first embodiment. FIG. 5 is an explanatory diagram showing a series of processes performed by the management system when registering an owner key of the first embodiment. FIG. 6 is an explanatory diagram showing a series of processes performed by the management system when registering a friend key of the first embodiment. FIG. 7 is an explanatory diagram showing a series of processes performed by the management system when registering a non-friend key of the first embodiment. FIG. 8 is an explanatory diagram showing a series of processes performed by the management system when deleting a non-friend key in response to a request from a friend device of the first embodiment. FIG. 9 is an explanatory diagram showing a series of processes performed by the management system when deleting a non-friend key in response to a request from a non-friend device of the first embodiment. FIG. 10 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with a vehicle management device of the first embodiment and a management server. FIG. 11 is a flowchart showing the flow of processing executed by the vehicle management device in FIGS. 10 and 12 . FIG. 12 is an explanatory diagram showing a series of processing executed by a management system including a vehicle equipped with the vehicle management device of the second embodiment and a management server. FIG. 13 is an explanatory diagram showing a continuation of the processing in FIG. 12 . FIG. 14 is an explanatory diagram showing a series of processing executed by a management system including a vehicle equipped with the vehicle management device of the third embodiment and a management server. FIG. 15 is a flowchart showing the flow of processing executed by the management server in FIGS. 14 , 16 , 18 , and 20 . FIG. 16 is an explanatory diagram showing a series of processing executed by a management system including a vehicle equipped with the vehicle management device of the fourth embodiment and a management server. FIG. 17 is an explanatory diagram showing a continuation of the processing in FIG. 16 . FIG. 18 is an explanatory diagram showing a series of processing executed by a management system including a vehicle equipped with the vehicle management device of the fifth embodiment and a management server. FIG. 19 is an explanatory diagram showing a continuation of the processing in FIG. 18 . FIG. 20 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with a vehicle management device of the modified example and a management server.Fig. 21 is an explanatory diagram showing a series of processes for prompting a user to select whether or not to permit deletion of a digital key information unit, and Fig. 22 is a diagram showing an example of an image displayed to prompt a user to select whether or not to permit deletion of a digital key information unit.
[0013] 1 to 11 illustrate a first embodiment of a management server, a setting method, a setting process, a program, and a program product. <Outline of Management System 10> As shown in FIG. 1, a management server 70 is one of multiple devices that make up the management system 10. The management system 10 includes a vehicle 20, multiple devices 30, a device server 60, and a management server 70. The management server 70 is a server that manages digital keys. There is a standard for digital keys, the Car Connectivity Consortium (CCC). Matters related to the digital key in this embodiment comply with the CCC.
[0014] The vehicle 20 includes a communication module 21, a vehicle HMI 22, a BLE module 23, a UWB module 24, an NFC module 25, and a vehicle management device 26. HMI stands for Human Machine Interface. BLE stands for Bluetooth (registered trademark) Low Energy. UWB stands for Ultra Wide Band. NFC stands for Near Field Communication.
[0015] The communication module 21 communicates with the management server 70 via a wireless communication network. The vehicle HMI 22 includes an input device that accepts operations by the user of the vehicle 20 and a presentation device that presents information to the user using images, audio, etc. The presentation device is, for example, a monitor and a speaker.
[0016] The BLE module 23 performs short-range communication with the device 30 using BLE communication. The UWB module 24 communicates with the device 30 using UWB communication. The UWB module 24 measures the distance between the device 30 and the vehicle 20. The NFC module 25 performs short-range communication with the device 30 using NFC communication.
[0017] The vehicle management device 26 is mounted on the vehicle 20. The vehicle management device 26 manages the digital key of the vehicle 20. The vehicle management device 26 is, for example, a vehicle control circuit having a digital key ECU. The vehicle management device 26 has a vehicle execution device 27 and a vehicle storage device 28. The vehicle storage device 28 has stored therein a vehicle program PV and an authentication information unit AT. When the vehicle execution device 27 executes the vehicle program PV, the vehicle execution device 27 stores, deletes, and replaces the authentication information unit AT. The authentication information unit AT is information for authenticating the digital key. Therefore, when the digital key is used, control of the vehicle 20 using the digital key is possible. An authentication information unit AT is provided for each digital key to be authenticated. The vehicle execution device 27 is a vehicle processing circuit having a CPU. When the vehicle execution device 27 executes the vehicle program PV, the vehicle execution device 27 performs processes related to storing, deleting, and replacing the authentication information unit AT.
[0018] Authenticating the digital key means allowing the digital key to control the vehicle 20. For example, when the vehicle management device 26 authenticates the digital key, the vehicle management device 26 allows the digital key to unlock the vehicle 20. Also, for example, when the vehicle management device 26 authenticates the digital key, the vehicle management device 26 allows the digital key to start the vehicle 20.
[0019] The device 30 is a mobile information terminal such as a smartphone, and includes a communication module 31, a device HMI 32, a BLE module 33, a UWB module 34, an NFC module 35, a device execution device 36, and a device storage device 37.
[0020] The communication module 31 communicates with the device server 60 via a wireless communication line. The device HMI_32 includes an input device that accepts operations by the user of the device 30, and a presentation device that presents information to the user using images, audio, etc. The presentation device is, for example, a monitor and a speaker.
[0021] The BLE module 33 performs short-range communication with the vehicle 20 using BLE communication. The UWB module 34 communicates with the vehicle 20 using UWB communication. The NFC module 35 performs short-range communication with the vehicle 20 using NFC communication.
[0022] The device storage device 37 stores a device program PD and key information DK. The device program PD causes the device execution unit 36 to execute various device processes, thereby causing the device execution unit 36 to store and delete key information DK. The key information DK is information indicating a digital key.
[0023] The device program PD includes, for example, a device application and a digital key framework. The device application is an application for storing and deleting key information DK. The digital key framework is a program that provides functions for pairing devices 30 and sharing digital keys using APIs provided by the OS. The device execution unit 36 is a device processing circuit that executes the device program PD to perform processes related to the storage and deletion of key information DK.
[0024] The multiple devices 30 include an owner device 40 and multiple shared devices 50. The owner device 40 has stored therein owner key information DKO indicating an owner key KO as key information DK. Only one owner key KO can be registered to one vehicle 20. Therefore, only one owner key KO exists for one vehicle 20.
[0025] 2, the owner key information DKO includes owner key structure information STO. The owner key structure information STO includes vehicle identification information ST1, in-device key identification information ST2, digital key identification information ST3, and slot identification information ST4. The owner key structure information STO further includes certificate information ST5, device public key information ST6, vehicle public key information ST7, and permission public key information ST8.
[0026] The vehicle identification information ST1 is information that identifies the vehicle 20 for which one or more digital keys are set. For example, the vehicle identification information ST1 is the ID of the vehicle 20. The in-device key identification information ST2 is used to manage the digital keys within the device 30. The in-device key identification information ST2 is information that allows the digital keys to be identified within the application of the device 30.
[0027] The digital key identification information ST3 is used for managing the digital key in the management server 70. The slot identification information ST4 is information that enables the device 30 to identify the digital key locally.
[0028] Certificate information ST5 indicates a certificate that certifies the digital key. Device public key information ST6 indicates a device public key PKD that is the public key of the device 30. The device public key PKD in the owner key information DKO indicates the public key of the owner device 40. Vehicle public key information ST7 indicates a vehicle public key PKV that is the public key of the vehicle 20. Authorization public key information ST8 indicates an already authorized vehicle public key PKV.
[0029] 1, the share device 50 has stored therein share key information DKS indicating a share key KS as key information DK. A share key KS is a digital key that can be registered in multiple numbers for one vehicle 20 in order to enable the use of the digital key. In other words, multiple share keys KS can exist for one vehicle 20.
[0030] The multiple share devices 50 include one or more friend devices 51 and one or more non-friend devices 52. The friend device 51 has already stored, as the share key information DKS, friend key information DKF indicating the friend key KF. The non-friend device 52 has already stored, as the share key information DKS, non-friend key information DKN indicating the non-friend key KN. In other words, the share keys KS include the friend key KF and the non-friend key KN. The friend key KF is a share key KS that has been registered based on a registration request D21 directly from the owner device 40, as described below. The registration request D21 requests the device 30 to store the friend key information DKF, which is key information DK. The non-friend key KN is a share key KS that has been registered based on a registration request D31 from the friend device 51, as described below. In other words, the registration request D31 is a request to have the device 30 store the non-friend key information DKN, which is key information DK. The non-friend key KN is a shared key KS that is registered based on a registration request from a shared device 50, which is a device 30 different from the owner device 40. The registration request from the shared device 50 is a so-called indirect registration request.
[0031] When a digital key is registered, the digital key is usable. That is, when a digital key is registered, the vehicle 20 stores an authentication information unit AT, and the device 30 has already stored key information DK. The authentication information unit AT is a digital key information unit, which is an information unit related to the digital key. That is, when a digital key is registered, the vehicle 20 has already stored the digital key information unit. The key information DK is a digital key information unit. That is, when a digital key is registered, the device 30 has already stored the digital key information unit.
[0032] As shown in Figure 3, the shared key information DKS includes shared key structure information STS and an authentication package ATP. The shared key structure information STS includes vehicle identification information ST1, in-device key identification information ST2, digital key identification information ST3, and slot identification information ST4. The shared key structure information STS also includes certificate information ST5, vehicle public key information ST7, and permission public key information ST8. In other words, the shared key structure information STS is the owner key structure information STO minus the device public key information ST6.
[0033] The authentication package ATP includes signature information ATP1, password information ATP2, validity start time information ATP3, expiration date information ATP4, name information ATP5, and device public key information ATP6.
[0034] The signature information ATP1 indicates that the share device 50 is a legitimate target with which the digital key is shared. For example, if the share device 50 is a friend device 51, the signature information ATP1 indicates a signature by the owner device 40. The owner signature information indicates that the owner device 40 has signed the device public key PKD of the friend device 51, which is indicated by the device public key information ATP6. Also, for example, if the share device 50 is a non-friend device 52, the signature information ATP1 indicates a signature by the friend device 51. The friend signature information indicates that the friend device 51 has signed the device public key PKD of the non-friend device 52, which is indicated by the device public key information ATP6.
[0035] The password information ATP2 indicates the pairing password PAS used to establish a secure channel when pairing the vehicle 20 and the owner device 40. The validity start time information ATP3 indicates the earliest date and time at which the shared key KS can be used. The expiration date information ATP4 indicates the latest date and time at which the shared key KS can be used. The name information ATP5 indicates a name that identifies the shared key KS. For example, the name information ATP5 is set as an identifiable name for each shared device 50 by operation from the owner device 40.
[0036] As shown in FIG. 1 , the device server 60 relays communication between the devices 30 and the management server 70. A device server 60 is provided for each type of device 30. That is, the device server 60 with which a first type of device 30 communicates is different from the device server 60 with which a second type of device 30 communicates. For example, the type of device 30 refers to the model of the device 30, and a device server 60 is provided for each model of the device 30. For example, the type of device 30 refers to the communication line used by the device 30, and a device server 60 is provided for each communication line used by the device 30. Since all device servers 60 relay communication with the management server 70, different types of devices 30 can communicate with the management server 70 via the device server 60. FIG. 1 illustrates only one device server 60.
[0037] <Management Server 70> The management server 70 is configured to be able to communicate with the vehicle 20 and multiple devices 30. The management server 70 includes a server execution device 71, a server storage device 72, and a communication module 73. The communication module 73 communicates with the device server 60 via a wireless communication line. The communication module 73 is also configured to be able to wirelessly communicate with the communication module 21 of the vehicle 20. The server storage device 72 stores a server program PS, a replacement program PM, and a database DB. The server program PS causes the server execution device 71 to execute various server processes, causing the server execution device 71 to register a digital key in the database DB and delete a digital key from the database DB. The replacement program PM causes the server execution device 71 to execute various server processes, causing the server execution device 71 to send a command to the vehicle storage device 28 to replace the authentication information unit AT. The server execution device 71 executes the replacement program PM to perform processes related to the replacement of the authentication information unit AT. The server execution device 71 includes a server processing circuit.
[0038] The database DB is divided into data blocks DA for each vehicle 20. When a digital key is registered, the management server 70 has already stored, in the data block DA, information indicating the device 30 that stores the key information DK indicating the digital key.
[0039] As shown in Figure 4, the data block DA for one vehicle 20 includes the type of digital key registered to the vehicle 20, the registered devices 30, and the relationships between the registered devices 30. The hierarchy of digital keys is determined by the type of digital key. The digital keys are arranged in order from top to bottom in the hierarchy as owner keys KO, friend keys KF, and non-friend keys KN.
[0040] The authority of a digital key includes, for example, the number of share keys KS that can be requested to be registered, the range of control of the vehicle 20 that can be achieved by authenticating the digital key, etc. The higher the hierarchy of the digital key, the greater the authority of the digital key, so, for example, the greater the number of share keys KS that the digital key can request to be registered. More specifically, for example, the number of friend keys KF that the owner device 40 can request to be registered is greater than the number of non-friend keys KN that the friend device 51 can request to be registered.
[0041] Furthermore, for example, the higher the hierarchy of the digital key, the greater the authority of the digital key, and therefore the wider the control range of the vehicle 20 that the digital key can control. The control range of the vehicle 20 that can be controlled indicates, for example, the possible controls among (a) engine start control of the vehicle 20, (b) power-on control of the vehicle 20, and (c) unlocking and locking control of the doors of the vehicle 20. For example, if the control range of the vehicle 20 that can be controlled includes the above-mentioned three controls, the control range of the vehicle 20 that can be controlled is wider than if the control range of the vehicle 20 that can be controlled includes only one of (c) unlocking and locking control of the doors of the vehicle 20. More specifically, the control range of the vehicle 20 that can be controlled by the friend key KF includes the above-mentioned three controls. On the other hand, the control range of the vehicle 20 that can be controlled by the non-friend key KN is only one of (c) unlocking and locking control of the doors of the vehicle 20.
[0042] A state in which digital keys are registered to seven devices 30 for one vehicle 20 will be described. The seven devices 30 are a first device 30A, a second device 30B, a third device 30C, a fourth device 30D, a fifth device 30E, a sixth device 30F, and a seventh device 30G. The digital key registered to the first device 30A is referred to as the first digital key. The digital key registered to the second device 30B is referred to as the second digital key. The digital key registered to the third device 30C is referred to as the third digital key. The digital key registered to the fourth device 30D is referred to as the fourth digital key. The digital key registered to the fifth device 30E is referred to as the fifth digital key. The digital key registered to the sixth device 30F is referred to as the sixth digital key. The digital key registered to the seventh device 30G is referred to as the seventh digital key.
[0043] In the data block DA, the device 30 whose type of digital key is registered as the owner key KO is the first device 30A. That is, the first device 30A is the owner device 40. That is, the first digital key is the owner key KO.
[0044] In data block DA, the devices 30 whose digital key type is registered as a shared key KS are the second device 30B, the third device 30C, the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G. That is, the second device 30B, the third device 30C, the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G are shared devices 50. The second digital key, the third digital key, the fourth digital key, the fifth digital key, the sixth digital key, and the seventh digital key are all shared keys KS.
[0045] More specifically, in the data block DA, the devices 30 whose digital key type is registered as the friend key KF are the second device 30B and the fifth device 30E. In other words, the second device 30B and the fifth device 30E are friend devices 51.
[0046] In the data block DA, the devices 30 whose digital key type is registered as a non-friend key KN are the third device 30C, the fourth device 30D, the sixth device 30F, and the seventh device 30G. In other words, the third device 30C, the fourth device 30D, the sixth device 30F, and the seventh device 30G are non-friend devices 52.
[0047] In the data block DA, the relationship between the second device 30B and the first device 30A is such that a friend key KF is registered in the second device 30B based on a registration request from the first device 30A. In other words, the second digital key is generated based on the first digital key.
[0048] In the data block DA, the relationship between the fifth device 30E and the first device 30A is such that a friend key KF is registered in the fifth device 30E based on a registration request from the first device 30A. In other words, the fifth digital key is generated based on the first digital key.
[0049] In the data block DA, the relationship between the third device 30C and the second device 30B is such that the non-friend key KN is registered in the third device 30C based on a registration request from the second device 30B. In other words, the third digital key is generated based on the second digital key.
[0050] In data block DA, the relationship between the fourth device 30D and the second device 30B is such that the non-friend key KN is registered in the fourth device 30D based on a registration request from the second device 30B. In other words, the fourth digital key is generated based on the second digital key.
[0051] In the data block DA, the relationship between the sixth device 30F and the fifth device 30E is such that the non-friend key KN is registered in the sixth device 30F based on a registration request from the fifth device 30E. In other words, the sixth digital key is generated based on the fifth digital key.
[0052] In data block DA, the relationship between the seventh device 30G and the fifth device 30E is such that the non-friend key KN is registered in the seventh device 30G based on a registration request from the fifth device 30E. In other words, the seventh digital key is generated based on the fifth digital key.
[0053] In this way, the data block DA already stores the devices 30 registered as digital keys. When a device 30 is registered, information indicating the device 30 that made the request that caused the registration is linked to the digital key. The data block DA also includes information indicating which digital key each digital key was generated based on.
[0054] <Digital Key Registration> Next, a series of processes for registering a digital key in the management system 10 will be described. The management system 10 registers the owner key KO, the friend key KF, and the non-friend key KN as digital key registrations. The following describes the series of processes from when each digital key is not registered to when it is registered. In the following description, the processes executed by the vehicle execution unit 27 of the vehicle management device 26 will be described as processes executed by the vehicle 20. Similarly, in the following description, the processes executed by the device execution unit 36 will be described as processes executed by the device 30. In the following description, the processes executed by the server execution unit 71 will be described as processes executed by the management server 70.
[0055] 5, the management system 10 performs a series of processes to register the owner key KO. Among the devices 30 that do not store key information DK indicating the owner key KO, the device 30 that will be registered as the owner device 40 is referred to as a first device 30A.
[0056] To register the owner key KO, the management system 10 stores key information DK indicating the owner key KO in the first device 30A. By registering the owner key KO, the management system 10 stores an authentication information unit AT for authenticating the owner key KO in the vehicle 20. This causes the first device 30A to become the owner device 40. When registering the owner key KO, it is assumed that the necessary applications are installed in the first device 30A.
[0057] When management server 70 receives a registration request D11 for the owner key KO from the first device 30A or the like, management server 70 first performs the process of step S11. In step S11, management server 70 generates a pairing password PAS. Then, management server 70 transmits information indicating the pairing password PAS to vehicle 20 and first device 30A.
[0058] The vehicle 20 then receives the pairing password PAS. After receiving the pairing password PAS, the vehicle 20 is set to pairing mode via the vehicle HMI_22 and waits in a state in which it can receive a password from the first device 30A. The vehicle 20 then proceeds to step S12.
[0059] In step S12, vehicle 20 performs pairing with first device 30A. Once pairing is performed, vehicle 20 establishes a secure channel for data communication with first device 30A. Pairing is performed using a pairing password PAS transmitted from management server 70 to vehicle 20 and first device 30A. Once pairing is complete, vehicle 20 proceeds to step S13.
[0060] In step S13, the vehicle 20 generates a vehicle public key PKV, which is the public key of the vehicle 20, and a vehicle private key SKV, which is the private key of the vehicle 20. Then, the vehicle 20 transmits generation data DC for generating the owner key KO to the first device 30A via the secure channel. The generation data DC includes vehicle identification information ST1 and vehicle public key information indicating the vehicle public key PKV. The first device 30A then receives the generation data DC. The first device 30A then proceeds to step S14.
[0061] In step S14, the first device 30A generates owner key information DKO indicating the owner key KO. Then, the first device 30A proceeds to step S15. In step S15, the first device 30A stores the owner key information DKO. As a result, the first device 30A becomes the owner device 40. In other words, the registration request D11 is a request to store the owner key information DKO as key information DK in the device 30. Then, the first device 30A transmits certificate information ST5 related to the owner key KO and device public key information ST6 indicating the device public key PKD to the vehicle 20.
[0062] Thereafter, when vehicle 20 receives certificate information ST5 and device public key information ST6, vehicle 20 performs the process of step S16. In step S16, vehicle 20 verifies certificate information ST5. When the verification of certificate information ST5 is completed, vehicle 20 proceeds to the process of step S17.
[0063] In step S17, the vehicle 20 stores the device public key information ST6 indicating the device public key PKD as the authentication information unit AT, and then transmits a completion notification M11 to the first device 30A indicating that the storage of the authentication information unit AT has been completed.
[0064] Thereafter, when the first device 30A receives the completion notification M11, the first device 30A performs the process of step S18. In step S18, the first device 30A generates a key track request D12 for the owner key KO. The key track request D12 is a signal for requesting the management server 70 to update the database DB. The first device 30A transmits the key track request D12 for the owner key KO to the management server 70 via the device server 60.
[0065] Thereafter, upon receiving the key track request D12, the management server 70 performs processing in step S19. In step S19, the management server 70 performs registration management of the owner key KO. Specifically, the management server 70 stores the first device 30A as the device 30 registered as the owner key KO in the data block DA of the vehicle 20 in the database DB. This completes the series of processes for registering the owner key KO in the management system 10.
[0066] 6, the management system 10 performs a series of processes to register a friend key KF. Among the devices 30 that do not store friend key information DKF, a device 30 that will be registered as a friend device 51 through the series of processes is referred to as a second device 30B.
[0067] When an operation to request registration of a friend key KF is executed in the owner device 40, the owner device 40 first performs the process of step S21. In step S21, the owner device 40 transmits a friend key KF registration request D21 to a relay server (not shown). Thereafter, the owner device 40 proceeds to step S22.
[0068] In step S22, the owner device 40 obtains invitation information IV1 for sharing the digital key from the relay server. The invitation information IV1 is, for example, a URL link. The URL link stores share information SH1 required for sharing the digital key. The owner device 40 then transmits the invitation information IV1 to the second device 30B.
[0069] After that, when the second device 30B receives the invitation information IV1, it performs the process of step S23. In step S23, the second device 30B acquires the share information SH1 based on the invitation information IV1. Specifically, the second device 30B downloads the share information SH1 from the link source of the URL link.
[0070] The share information SH1 includes, for example, share key structure information STS, password information ATP2, validity start time information ATP3, expiration date information ATP4, and name information ATP5. The validity start time information ATP3, expiration date information ATP4, and name information ATP5 are set by the owner device 40. The second device 30B then proceeds to step S24.
[0071] In step S24, the second device 30B generates the signature-less friend key information DKFN using the share information SH1. The signature-less friend key information DKFN is friend key information DKF that does not include the signature information ATP1. Specifically, the second device 30B generates each piece of information included in the acquired share information SH1 as the signature-less friend key information DKFN. The second device 30B then transmits to the owner device 40 a completion notification M21 indicating that the generated signature-less friend key information DKFN has been uploaded to the URL link, and a signature request D22 requesting a signature.
[0072] The owner device 40 then receives a completion notification M21 and a signature request D22 from the second device 30B. Upon receiving the completion notification M21, the owner device 40 acquires the unsigned friend key information DKFN. Upon receiving the signature request D22, the owner device 40 performs the process of step S25 in response to an operation of the owner device 40.
[0073] In step S25, the owner device 40 generates signature information ATP1. Specifically, the owner device 40 causes the device HMI_32 to present the acquired signature-free friend key information DKFN and accepts an operation indicating that the user of the owner device 40 agrees to the registration of the friend key KF. When the consent operation is performed, the owner device 40 acquires a signature based on the consent operation. The owner device 40 then proceeds to step S26.
[0074] In step S26, the owner device 40 adds the signature information ATP1 to the unsigned friend key information DKFN. This causes the owner device 40 to generate friend key information DKF. The owner device 40 then uploads the generated friend key information DKF to the URL link, which is the invitation information IV1. The owner device 40 then transmits a completion notification M22 to the second device 30B, indicating that the completed friend key information DKF has been uploaded to the URL link.
[0075] The second device 30B then receives the completion notification M22. The second device 30B then performs the process of step S27. In step S27, the second device 30B downloads and stores the friend key information DKF. As a result, the second device 30B becomes a friend device 51. The second device 30B then proceeds to step S28.
[0076] In step S28, the second device 30B generates a key track request D23 for the friend key KF. The second device 30B transmits the friend key information DKF and the key track request D23 for the friend key KF to the management server 70.
[0077] Thereafter, when the management server 70 receives a key track request D23 for the friend key KF, the management server 70 performs processing in step S29. In step S29, the management server 70 performs registration management of the friend key KF. The key track request D23 is a request to store a new authentication information unit AT in the vehicle 20.
[0078] Specifically, as part of the registration management, the management server 70 verifies that the friend key KF that is the target of the key track request D23 is not listed on the reject list. The reject list is a list of share keys KS that have friend keys KF and non-friend keys KN for which a deletion request has already been received. If the friend key KF is listed on the reject list, the management server 70 sends a notification to the second device 30B that the key track request D23 cannot be fulfilled.
[0079] On the other hand, if the friend key KF that has received the key track request D23 is not on the rejection list, the management server 70 registers the friend key KF that has received the key track request D23 in the database DB. Specifically, the management server 70 stores the second device 30B as a device 30 registered as a friend device 51 in the data block DA of the vehicle 20 in the database DB. The management server 70 stores the relationship between the second device 30B and the owner device 40 by referring to the acquired friend key information DKF.
[0080] Thereafter, the management server 70 transmits the authentication package ATP included in the friend key information DKF and a storage request D24 for requesting storage of the authentication package ATP to the vehicle 20. That is, the management server 70 transmits device public key information ST6 indicating the device public key PKD of the friend device 51 to the vehicle 20. The management server 70 also notifies the vehicle 20 that the device public key PKD has been signed by the owner device 40.
[0081] Thereafter, when the vehicle 20 receives the storage request D24 and the authentication package ATP from the management server 70, the vehicle 20 performs the process of step S30. In step S30, the vehicle 20 stores the received authentication package ATP as an authentication information unit AT for authenticating the friend key KF.
[0082] After completing the registration management, the management server 70 transmits a key track completion notification M23 to the second device 30B. After that, upon receiving the key track completion notification M23, the second device 30B performs the process of step S31. In the process of step S31, the second device 30B presents information indicating the completion of the registration of the friend key KF on the device HMI_32. For example, the second device 30B displays an image indicating the completion of the registration of the friend key KF on the device HMI_32. This causes the management system 10 to complete the series of processes for registering the friend key KF.
[0083] 7, the management system 10 performs a series of processes to register a non-friend key KN. Among the devices 30 that do not store non-friend key information DKN, a device 30 that will be registered as a non-friend device 52 through the series of processes is referred to as a third device 30C.
[0084] When an operation to request registration of a non-friend key KN is executed on the friend device 51, the friend device 51 first performs processing in step S41. In step S41, the friend device 51 transmits a registration request D31 of the non-friend key KN to a relay server (not shown). Thereafter, the friend device 51 proceeds to processing in step S42.
[0085] In step S42, the friend device 51 obtains invitation information IV2 for sharing the digital key from the relay server. The invitation information IV2 is, for example, a URL link. The URL link stores share information SH2 required for sharing the digital key. The friend device 51 then transmits the invitation information IV2 to the third device 30C.
[0086] After that, when the third device 30C receives the invitation information IV2, it performs the process of step S43. In step S43, the third device 30C acquires the share information SH2 based on the invitation information IV2. Specifically, the second device 30B downloads the share information SH2 from the URL link.
[0087] The share information SH2 includes, for example, share key structure information STS, password information ATP2, validity start time information ATP3, expiration date information ATP4, and name information ATP5. The validity start time information ATP3, expiration date information ATP4, and name information ATP5 are set by the friend device 51. The third device 30C then proceeds to step S44.
[0088] In step S44, the third device 30C generates the unsigned non-friend key information DKNN using the share information SH2. The unsigned non-friend key information DKNN is non-friend key information DKN that does not have the signature information ATP1. Specifically, the third device 30C generates each piece of information included in the acquired share information SH2 as the unsigned non-friend key information DKNN. The third device 30C then transmits to the friend device 51 a completion notification M31 indicating that the generated unsigned non-friend key information DKNN has been uploaded to the URL link, and a signature request D32 requesting a signature.
[0089] Thereafter, the friend device 51 receives a completion notification M31 and a signature request D32 from the third device 30C. Upon receiving the completion notification M31, the friend device 51 acquires the unsigned non-friend key information DKNN. Upon receiving the signature request D32, the friend device 51 performs the process of step S45 in response to an operation of the friend device 51.
[0090] In step S45, the friend device 51 generates signature information ATP1. Specifically, the friend device 51 causes the device HMI_32 to present the acquired signature-free non-friend key information DKNN, and accepts an operation indicating that the user of the friend device 51 agrees to the generation of the non-friend key KN. When the agreement operation is performed, the friend device 51 acquires a signature based on the agreement operation. The friend device 51 then proceeds to step S46.
[0091] In step S46, the friend device 51 adds the signature information ATP1 to the unsigned non-friend key information DKNN. This causes the friend device 51 to generate the non-friend key information DKN. The friend device 51 then uploads the generated non-friend key information DKN to the URL link, which is the invitation information IV2. The friend device 51 then transmits a completion notification M32 to the third device 30C, indicating that the completed non-friend key information DKN has been uploaded to the URL link.
[0092] The third device 30C then receives the completion notification M32. The third device 30C then performs the process of step S47. In step S47, the third device 30C downloads and stores the non-friend key information DKN. As a result, the third device 30C becomes a non-friend device 52. The third device 30C then proceeds to the process of step S48.
[0093] In step S48, the third device 30C generates a key track request D33 for the non-friend key KN. The third device 30C transmits the non-friend key information DKN and the key track request D33 for the non-friend key KN to the management server 70.
[0094] Thereafter, when the management server 70 receives a key track request D33 for the non-friend key KN, the management server 70 performs the process of step S49. In step S49, the management server 70 performs registration management of the non-friend key KN.
[0095] Specifically, as part of the registration management, the management server 70 verifies that the non-friend key KN that is the target of the key track request D33 is not on the rejection list. If the non-friend key KN is on the rejection list, the management server 70 sends a notification to the third device 30C that the key track request D33 cannot be fulfilled.
[0096] On the other hand, if the non-friend key KN is not on the rejection list, the management server 70 registers the non-friend key KN that is the target of the key track request D33 in the database DB. Specifically, the management server 70 stores the third device 30C in the data block DA of the vehicle 20 in the database DB as a device 30 registered as a non-friend device 52. The management server 70 stores the relationship between the third device 30C and the friend device 51 by referring to the acquired non-friend key information DKN. Specifically, the management server 70 stores the third device 30C as a device 30 having the non-friend key KN registered in response to the registration request D31 from the second device 30B.
[0097] Thereafter, the management server 70 transmits the authentication package ATP included in the non-friend key information DKN and a storage request D34 for requesting storage of the authentication package ATP to the vehicle 20. That is, the management server 70 transmits device public key information ST6 indicating the device public key PKD of the non-friend device 52 to the vehicle 20. The management server 70 also notifies the vehicle 20 that the device public key PKD is signed by the friend device 51.
[0098] Thereafter, when the vehicle 20 receives the authentication package ATP and the storage request D34, it performs the process of step S50. In step S50, the vehicle 20 stores the received authentication package ATP. That is, the vehicle 20 stores the authentication package ATP as an authentication information unit AT for authenticating the non-friend key KN.
[0099] After completing the registration management, the management server 70 transmits a key track completion notification M33 to the second device 30B. After that, upon receiving the key track completion notification M33, the second device 30B performs processing in step S51. In the processing in step S51, the third device 30C presents information indicating the completion of registration of the non-friend key KN on the device HMI_32. For example, the third device 30C displays an image indicating the completion of registration of the non-friend key KN on the device HMI_32. This causes the management system 10 to complete the series of processes for registering the non-friend key KN.
[0100] <Deleting a Non-Friend Key KN> Next, a series of processes for deleting a non-friend key KN in the management system 10 will be described. Below, a series of steps from when a non-friend key KN is registered to when a non-friend key KN is not registered will be described. In the following explanation, the processes executed by the vehicle execution unit 27 will be described as processes executed by the vehicle 20. Similarly, the processes executed by the device execution unit 36 will be described as processes executed by the device 30, and the processes executed by the server execution unit 71 will be described as processes executed by the management server 70.
[0101] <Deletion of Non-Friend Key KN Based on Deletion Reservation D41 from Friend Device 51> As shown in FIG. 8, the management system 10 performs a series of processes to delete the non-friend key KN based on the deletion reservation D41 from the friend device 51.
[0102] When an operation to request the deletion of the non-friend key KN is executed in the friend device 51, the friend device 51 first performs the process of step S61. In step S61, a deletion reservation D41 for the non-friend key KN is generated. The deletion reservation D41 is a command for reserving the deletion of the non-friend key KN.
[0103] The deletion reservation D41 includes a signal for requesting the deletion of the non-friend key KN, digital key identification information ST3 indicating the non-friend key KN, and information indicating a predetermined condition RC. The predetermined condition RC is a condition required to start the deletion of the non-friend key KN after receiving the deletion reservation D41. The predetermined condition RC is predetermined. For example, the predetermined condition RC is that a predetermined fade-out period has elapsed since the deletion reservation D41 was received. The friend device 51 transmits the deletion reservation D41 of the non-friend key KN to the management server 70.
[0104] After that, when the management server 70 receives the deletion reservation D41 of the non-friend key KN, the management server 70 performs the process of step S62. In step S62, the management server 70 generates a pending notification M41 in accordance with the deletion reservation D41. The management server 70 transmits the pending notification M41 to the friend device 51.
[0105] Thereafter, when the friend device 51 receives the pending notification M41, the friend device 51 performs the process of step S63. In step S63, the friend device 51 presents, to the device HMI_32, information indicating that the deletion of the non-friend key KN that is the target of the deletion reservation D41 is pending.
[0106] After the process of step S62, the management server 70 performs the process of step S64. In step S64, the management server 70 stores the state of the non-friend key KN that is the target of the deletion reservation D41 in the database DB as a fade-out state. The fade-out state is a state in which the deletion reservation D41 has been received but the execution of deletion is still pending. The management server 70 then proceeds to the process of step S65.
[0107] In step S65, the management server 70 confirms that the predetermined condition RC is satisfied. If the management server 70 confirms that the predetermined condition RC is satisfied, the management server 70 proceeds to step S66.
[0108] In step S66, the management server 70 generates a deletion request D42 for deleting the non-friend key information DKN indicating the non-friend key KN that is the target of the deletion reservation D41. The management server 70 transmits the deletion request D42 to the non-friend device 52.
[0109] Thereafter, when the non-friend device 52 receives the deletion request D42, it performs the process of step S67. In step S67, the non-friend device 52 deletes the non-friend key information DKN in accordance with the deletion request D42. The non-friend device 52 transmits a deletion completion notification M42 to the management server 70, indicating that the deletion in accordance with the deletion request D42 has been completed.
[0110] Thereafter, when the management server 70 receives the completion notification M42, the management server 70 performs the process of step S68. In step S68, the management server 70 stores the history of the deletion of the non-friend key information DKN in the non-friend device 52. Thereafter, the management server 70 proceeds to the process of step S69.
[0111] In step S69, the management server 70 generates a deletion request D43 for the authentication information unit AT. The deletion request D43 for the authentication information unit AT indicates a request to delete the authentication information unit AT that was required when the non-friend key KN that is the subject of the deletion reservation D41 was authenticated. The management server 70 transmits the deletion request D43 to the vehicle 20.
[0112] Thereafter, when the vehicle 20 receives the deletion request D43, the vehicle 20 performs the process of step S70. In step S70, the vehicle 20 deletes the authentication information unit AT that was required when the non-friend key KN that is the subject of the deletion reservation D41 was authenticated in accordance with the deletion request D43. That is, the vehicle 20 deletes the authentication package ATP of the non-friend key KN. The vehicle 20 then transmits a deletion completion notification M43 to the management server 70, indicating that the deletion of the authentication information unit AT in accordance with the deletion request D43 has been completed.
[0113] Thereafter, when the management server 70 receives the completion notification M43, the management server 70 performs the process of step S71. In step S71, the management server 70 stores the history of the deletion of the authentication information unit AT that was required to authenticate the non-friend key KN that is to be deleted in the current series of deletion-related processes in the vehicle 20. Thereafter, the management server 70 proceeds to the process of step S72.
[0114] In step S72, the management server 70 updates the database DB. Specifically, the management server 70 deletes the non-friend device 52 having the non-friend key KN to be deleted in this series of processes from the data block DA of the vehicle 20 in the database DB. Thereafter, the management server 70 transmits a deletion completion notification M44 to the friend device 51, indicating that the series of deletions of the non-friend key KN in accordance with the deletion reservation D41 have been completed.
[0115] Thereafter, when the friend device 51 receives the completion notification M44, the friend device 51 performs the process of step S73. In step S73, the friend device 51 presents, to the device HMI_32, information indicating that the deletion of the non-friend key KN that is the target of the deletion reservation D41 has been completed. For example, the friend device 51 displays, on the device HMI_32, an image indicating that the deletion of the non-friend key KN has been completed. Thereafter, the management system 10 ends the series of processes for the deletion of this non-friend key KN.
[0116] <Deletion of non-friend key KN due to deletion in non-friend device 52> As shown in Figure 9, the management system 10 performs a series of processes to delete the non-friend key KN indicated by the non-friend key information DKN stored in the non-friend device 52 due to a deletion operation in the non-friend device 52.
[0117] When a predetermined operation requesting the deletion of the non-friend key KN is executed in the non-friend device 52, the non-friend device 52 first performs the process of step S81. In step S81, the non-friend device 52 deletes the non-friend key information DKN in accordance with the predetermined operation. Thereafter, the non-friend device 52 transmits a deletion completion notification M51 indicating that the non-friend key information DKN has been deleted to the management server 70.
[0118] Thereafter, when the management server 70 receives the completion notification M51, the management server 70 performs the process of step S82. In step S82, the management server 70 stores the history of the deletion of the non-friend key information DKN in the non-friend device 52. Thereafter, the management server 70 transmits a deletion completion notification M52 to the friend device 51, indicating that the non-friend key information DKN has been deleted.
[0119] Thereafter, when the friend device 51 receives the completion notification M52, the friend device 51 performs the process of step S83. In step S83, the friend device 51 presents, to the device HMI_32, information indicating that the deletion of the non-friend key information DKN of the non-friend device 52 has been completed. For example, the friend device 51 displays, on the device HMI_32, an image indicating that the deletion of the non-friend key KN has been completed.
[0120] After the process of step S82, the management server 70 performs the process of step S84. In step S84, the management server 70 generates a deletion request D51 for deleting the authentication information unit AT that was required when authenticating the non-friend key information DKN that has been deleted in step S81. The management server 70 transmits the deletion request D51 to the vehicle 20.
[0121] Thereafter, when vehicle 20 receives deletion request D51, vehicle 20 performs processing in step S85. In step S85, vehicle 20 deletes authentication information unit AT that was required when authenticating non-friend key information DKN that has been deleted in step S81 in accordance with deletion request D51. Vehicle 20 transmits completion notification M53 to management server 70 indicating that deletion of authentication information unit AT in accordance with deletion request D51 has been completed.
[0122] Thereafter, when management server 70 receives completion notification M53, management server 70 performs processing in step S86. In step S86, management server 70 stores a history of the deletion of authentication information unit AT that was required to authenticate non-friend key information DKN that has been deleted in step S81. Thereafter, management server 70 proceeds to processing in step S87.
[0123] In step S87, the management server 70 updates the database DB. Specifically, the management server 70 deletes the non-friend device 52 having the non-friend key KN to be deleted in this series of processes from the data block DA of the vehicle 20 in the database DB. This causes the management system 10 to end the series of processes for deleting the non-friend key KN.
[0124] <Replacement of authentication information unit AT by vehicle management device 26> Now, the number of authentication information units AT that the vehicle storage device 28 is configured to be able to store is limited. In other words, there is an upper limit to the amount of authentication information that the vehicle storage device 28 can store. When the number of one or more authentication information units AT already stored in the vehicle storage device 28 has reached the predetermined number that can be stored, the vehicle 20 performs the following process when it receives a new authentication information unit AT. In other words, the vehicle 20 stores the new authentication information unit AT in place of one of the one or more authentication information units AT already stored in the vehicle storage device 28.
[0125] Specifically, when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored, and the vehicle 20 receives a new authentication information unit AT, the vehicle 20 performs the following process: That is, the vehicle 20 deletes one of the one or more authentication information units AT stored in the vehicle storage device 28. Thereafter, the vehicle 20 stores the received new authentication information unit AT in the vehicle storage device 28.
[0126] <Series of processes performed by vehicle 20> Figure 10 is an explanatory diagram showing the flow of a series of processes performed by vehicle 20 in the management system 10 when a new authentication information unit AT is received when the number of one or more authentication information units AT stored in the vehicle memory device 28 has reached the specified number that can be stored.
[0127] 1, in the vehicle 20, the vehicle storage device 28 has already stored therein a vehicle program PV. The vehicle execution device 27 executes the vehicle program PV stored in the vehicle storage device 28. As a result, the vehicle 20 executes a series of processes.
[0128] 10 is one of one or more devices 30 that do not store non-friend key information DKN and that is designated as a non-friend device 52 by the series of processes. When a friend device 51 (not shown) executes an operation to request registration of a non-friend key KN for the third device 30C, the management system 10 performs the series of processes shown in FIG. 7 to register the non-friend key KN.
[0129] Step S101 shown in Fig. 10 is similar to step S47 shown in Fig. 7. After processing step S101, the third device 30C performs processing step S102. The processing step S102 shown in Fig. 10 is similar to step S48 shown in Fig. 7. The third device 30C transmits non-friend key information DKN and a key track request D33 for the non-friend key KN to the management server 70.
[0130] Thereafter, when the management server 70 receives the key track request D33 for the non-friend key KN, the management server 70 performs processing in step S103. In step S103, similar to step S49 shown in FIG. 7, the management server 70 performs registration management of the non-friend key KN. In the processing in step S103, the management server 70 transmits to the vehicle 20 the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing the authentication package ATP. In addition, if there is a digital key stored in a faded-out state in the database DB for the vehicle 20, the management server 70 transmits information about the faded-out digital key to the vehicle 20. If there is a digital key stored in a faded-out state in the database DB for the vehicle 20, this means that the deletion reservation D41 remains unexecuted.
[0131] Thereafter, when the vehicle 20 receives the authentication package ATP and the storage request D34, the vehicle 20 performs the process of step S104. At this time, if there is a digital key stored in the database DB for the vehicle 20 in a faded-out state, the vehicle 20 receives information about the digital key that is in a faded-out state.
[0132] <Selection of authentication information unit AT to be deleted> In step S104, the vehicle 20 selects an authentication information unit AT to be replaced by the authentication package ATP included in the non-friend key information DKN of the third device 30C from among one or more authentication information units AT stored in the vehicle storage device 28. That is, in step S104, the vehicle 20 selects an authentication information unit AT to be deleted from among one or more authentication information units AT stored in the vehicle storage device 28. The process by which the vehicle 20 selects the authentication information unit AT will be described later. Once the vehicle 20 selects the authentication information unit AT to be replaced by the authentication package ATP included in the non-friend key information DKN of the third device 30C, the vehicle 20 performs the process of step S105.
[0133] 11 is a flowchart showing the process performed by the vehicle 20 in step S104 to select an authentication information unit AT to be replaced by the authentication package ATP included in the non-friend key information DKN of the third device 30C. The vehicle 20 performs this series of processes as the process of step S104.
[0134] 11 , when this series of processes starts, the vehicle 20 determines in step S200 whether any deletion reservations D41 remain. If the vehicle storage device 28 has stored authentication information units AT for one or more digital keys in the fade-out state, the vehicle 20 determines that any deletion reservations D41 remain. If any deletion reservations D41 remain (step S200: YES), the vehicle 20 proceeds to step S210.
[0135] In step S210, the vehicle 20 determines whether multiple deletion reservations D41 remain. If the vehicle storage device 28 has stored authentication information units AT for multiple digital keys in the fade-out state, the vehicle 20 determines that multiple deletion reservations D41 remain. If multiple deletion reservations D41 remain (step S210: YES), the vehicle 20 proceeds to step S220.
[0136] In step S220, the vehicle 20 deletes all authentication information units AT of the multiple digital keys in the faded-out state that are stored in the vehicle storage device 28. As a result, the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored. The vehicle 20 then ends the series of processes shown in Figure 11. After completing the series of processes shown in Figure 11, the vehicle 20 performs the process of step S105 shown in Figure 10.
[0137] If the vehicle storage device 28 has stored only one authentication information unit AT of the faded-out digital key, i.e., if there are not multiple remaining deletion reservations D41 (step S210: NO), the vehicle management device 26 proceeds to step S230.
[0138] In step S230, the vehicle management device 26 selects the authentication information unit AT of the faded-out digital key as the authentication information unit AT to be deleted. The vehicle 20 then completes the series of processes shown in Fig. 11. After completing the series of processes shown in Fig. 11, the vehicle 20 performs the process of step S105 shown in Fig. 10.
[0139] In the process of step S200, if no deletion reservation D41 remains (step S200: NO), the vehicle 20 proceeds to step S240. <Determining Whether or Not an Authentication Information Unit AT Has Been Selected as a Protection Target> The vehicle management device 26 is configured to be able to select authentication information units AT to be protected from one or more authentication information units AT stored in the vehicle storage device 28. For example, the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as protection targets via the vehicle HMI_22 of the vehicle 20. For example, the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as protection targets via the device HMI_32 of the owner device 40. For example, the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as protection targets via the device HMI_32 of the friend device 51. For example, the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as targets for protection via the device HMI_32 of the non-friend device 52.
[0140] In step S240, the vehicle 20 determines whether or not there is an authentication information unit AT that has been selected as a protection target among one or more authentication information units AT stored in the vehicle storage device 28. If there is an authentication information unit AT that has been selected as a protection target (step S240: YES), the vehicle 20 proceeds to step S250. In step S250, the vehicle 20 determines that in subsequent processing, an authentication information unit AT that should be deleted will be selected from among the authentication information units AT that have not been selected as a protection target. Thereafter, the vehicle 20 proceeds to step S260. If there is no authentication information unit AT that has been selected as a protection target (step S240: NO), the vehicle 20 proceeds to step S260.
[0141] <Determining Whether Priority Has Been Set for Authentication Information Unit AT> The vehicle management device 26 is configured to be able to set priorities for one or more authentication information units AT stored in the vehicle storage device 28. For example, the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the vehicle HMI_22 of the vehicle 20. For example, the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the device HMI_32 of the owner device 40. For example, the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the device HMI_32 of the friend device 51. For example, the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the device HMI_32 of the non-friend device 52.
[0142] In step S260, the vehicle 20 determines whether priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28. If priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S260: YES), the vehicle 20 proceeds to step S270.
[0143] In step S270, the vehicle 20 determines whether multiple authentication information units AT with different priorities have been stored in the vehicle storage device 28. If the vehicle storage device 28 has stored multiple authentication information units AT with different priorities (step S270: YES), the vehicle 20 proceeds to step S280.
[0144] In step S280, the vehicle 20 selects an authentication information unit AT to be deleted based on the priority. For example, the vehicle 20 selects the authentication information unit AT with the lowest priority as the authentication information unit AT to be deleted. Then, the vehicle 20 ends the series of processes shown in Figure 11. After ending the series of processes shown in Figure 11, the vehicle 20 performs the process of step S105 shown in Figure 10.
[0145] 11, if no priority order has been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S260: NO), the vehicle 20 proceeds to step S290. If the vehicle storage device 28 does not store multiple authentication information units AT with different priorities (step S270: NO), the vehicle 20 proceeds to step S290.
[0146] In step S290, the vehicle 20 determines whether the authentication information unit AT for the non-friend key KN has been stored in the vehicle storage device 28. If the authentication information unit AT for the non-friend key KN has been stored in the vehicle storage device 28 (step S290: YES), the vehicle 20 proceeds to step S300.
[0147] In step S300, the vehicle management device 26 selects the authentication information unit AT corresponding to the non-friend key information DKN as the authentication information unit AT to be deleted from one or more authentication information units AT stored in the vehicle storage device 28. After that, the vehicle 20 ends the series of processes shown in Figure 11. After ending the series of processes shown in Figure 11, the vehicle 20 performs the process of step S105 shown in Figure 10.
[0148] In step S290, if the vehicle storage device 28 does not store an authentication information unit AT for the non-friend key KN (step S290: NO), the vehicle 20 proceeds to step S310. In step S310, the vehicle 20 selects, from among one or more authentication information units AT stored in the vehicle storage device 28, the authentication information unit AT corresponding to the shared key information DKS with the oldest last usage date as the authentication information unit AT to be deleted. The vehicle 20 then ends the series of processes shown in Figure 11. After completing the series of processes shown in Figure 11, the vehicle 20 performs the process of step S105 shown in Figure 10.
[0149] 10 , the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of one or more authentication information units AT already stored in the vehicle storage device 28. Specifically, the vehicle 20 deletes the authentication information unit AT selected in step S105 from the vehicle storage device 28. Thereafter, the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
[0150] When step S220 is processed, the vehicle 20 deletes all authentication information units AT of multiple digital keys in a faded-out state that are stored in the vehicle storage device 28. As a result, in step S104, the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored. When step S105 is processed, if the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that can be stored, the vehicle 20 does not delete the authentication information units AT from the vehicle storage device 28 in step S105. In this case, the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
[0151] <Processing After Replacing Authentication Information Unit AT> After performing the process of step S105, the vehicle 20 proceeds to step S106. In step S106, the vehicle 20 generates a completion notification M61. The completion notification M61 includes a signal indicating that the authentication package ATP included in the non-friend key information DKN of the third device 30C is the authentication information unit AT selected by the vehicle management device 26 in step S104 and has been stored in place of one or more authentication information units AT already stored in the vehicle storage device 28. The vehicle management device 26 transmits the completion notification M61 to the management server 70.
[0152] When the management server 70 receives the completion notification M61, the management server 70 performs the process of step S107. In step S107, the management server 70 generates a completion notification M62. The completion notification M62 includes information indicating that the vehicle storage device 28 has stored the authentication package ATP included in the non-friend key information DKN of the third device 30C as an authentication information unit AT for authenticating the non-friend key KN of the third device 30C. The management server 70 transmits the completion notification M62 to the third device 30C.
[0153] When the third device 30C receives the completion notification M62, the third device 30C performs the process of step S108. In step S108, the non-friend device 52 presents to the device HMI_32 registration completion information indicating that the registration of the non-friend key KN of the third device 30C to the vehicle 20 has been completed. Thereafter, the management system 10 ends the series of processes for replacing the current authentication information unit AT.
[0154] <Operation of First Embodiment> When the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached a predetermined number and a new authentication information unit AT is received, the vehicle management device 26 deletes one of the one or more authentication information units AT stored in the vehicle storage device 28 without user intervention. The authentication information unit AT is a digital key information unit.
[0155] <Effects of the First Embodiment> (1-1) According to the vehicle management device 26, when a new authentication information unit AT is stored, the user of the vehicle 20 does not have to select which authentication information unit AT to delete from one or more authentication information units AT already stored in the vehicle 20. In other words, the vehicle management device 26 is configured to reduce the burden on the user of the vehicle 20.
[0156] (1-2) The following describes a case where the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored, and one or more deletion reservations D41 remain unexecuted when the predetermined condition RC is met. The deletion reservation D41 is a command to execute the deletion of the target authentication information unit AT. In this case, when the vehicle management device 26 receives a new authentication information unit AT, it deletes the authentication information unit AT that is the target of the unexecuted deletion reservation D41 from the vehicle storage device 28. The vehicle management device 26 then stores the new authentication information unit AT in the vehicle storage device 28. In other words, the vehicle management device 26 selects, as the authentication information to be deleted, an authentication information unit AT for authenticating the digital key that is scheduled to be deleted. This allows the vehicle management device 26 to store a new authentication information unit AT while still storing authentication information units AT for authenticating digital keys that are not scheduled to be deleted.
[0157] (1-3) The following describes a case where the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored, and multiple deletion reservations D41 remain unexecuted. In this case, when the vehicle management device 26 receives a new authentication information unit AT, it deletes all of the authentication information units AT that are the subject of the remaining unexecuted deletion reservations D41. The vehicle management device 26 then stores the new authentication information unit AT in the vehicle storage device 28. This allows the vehicle management device 26 to store the new authentication information unit AT that has been received, and also ensures that the vehicle storage device 28 has sufficient storage capacity to store another authentication information unit AT.
[0158] (1-4) The vehicle management device 26 is configured to be able to set priorities for one or more authentication information units AT stored in the vehicle storage device 28 by the user of the vehicle 20. When the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored, and the vehicle management device 26 receives a new authentication information unit AT, the vehicle management device 26 selects an authentication information unit AT to be deleted from the vehicle storage device 28 based on the set priorities. In this way, the vehicle management device 26 is configured to be able to select an authentication information unit AT to be deleted from the vehicle storage device 28, reflecting the intention of the user who set the priorities.
[0159] (1-5) The vehicle management device 26 is configured to be able to select an authentication information unit AT to be protected from one or more authentication information units AT already stored in the vehicle storage device 28. When the vehicle management device 26 receives a new authentication information unit AT, it deletes one or more authentication information units AT that have not been selected as protection targets. The vehicle management device 26 is configured to be able to set two levels of priority for one or more authentication information units AT already stored in the vehicle storage device 28: authentication information units AT that are to be protected and authentication information units AT that are not to be protected. The vehicle management device 26 can reflect the intention of the user of the vehicle 20 by preventing the deletion of an authentication information unit AT that has already been set as protection target.
[0160] (1-6) The multiple digital keys include a first digital key, a second digital key generated based on the first digital key, and a third digital key generated based on the second digital key. The first digital key is an owner key KO. The second digital key is a friend key KF. The third digital key is a non-friend key KN. The following describes a case where the vehicle storage device 28 stores an authentication information unit AT for authenticating the friend key KF, which is the second digital key, and an authentication information unit AT for authenticating the non-friend key KN, which is the third digital key, and the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored. In this case, when the vehicle management device 26 receives a new authentication information unit AT, it deletes the authentication information unit AT corresponding to the non-friend key KN, which is the third digital key, from the one or more authentication information units AT stored in the vehicle storage device 28. This allows the vehicle management device 26 to protect the authentication information unit AT corresponding to the registered friend key KF based on the owner key KO. This makes it possible to reduce the frequency of situations where, for example, the authentication information unit AT corresponding to the friend key KF is replaced by a new authentication information unit AT, forcing the owner to re-register the friend key KF.
[0161] (1-7) The management system 10 includes a vehicle management device 26 mounted on the vehicle 20 and a management server 70 that manages the digital key. The vehicle 20 includes a vehicle storage device 28. When the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached a predetermined number that can be stored and a new authentication information unit AT is received, the management system 10 deletes one of the authentication information units already stored in the vehicle storage device 28. According to the management system 10, when the vehicle storage device 28 stores a new authentication information unit AT, the user of the vehicle 20 does not have to select which authentication information unit AT to delete from the one or more authentication information units AT already stored in the vehicle 20. In other words, the management system 10 is configured to reduce the burden on the user of the vehicle 20.
[0162] <Modifications of the First Embodiment> The first embodiment described above can be modified as follows: The first embodiment described above and the following modifications of the first embodiment can be combined and implemented within a range that does not cause technical contradictions.
[0163] The following describes a case where the vehicle 20 receives a new authentication information unit AT when the number of one or more authentication information units AT already stored in the vehicle storage device 28 has reached the preset number that can be stored. In this case, the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT already stored in the vehicle storage device 28. The vehicle management device 26 does not need to store the new authentication information unit AT in the vehicle storage device 28.
[0164] The following describes a case where the vehicle 20 receives a new authentication information unit AT when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored. In this case, the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The vehicle management device 26 does not need to select the authentication information unit AT to be deleted. For example, the vehicle management device 26 may randomly delete one or more authentication information units AT stored in the vehicle storage device 28.
[0165] The following describes a case where a new authentication information unit AT is received when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored. In this case, the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The vehicle management device 26 may be configured so that one or more authentication information units AT stored in the vehicle storage device 28 cannot be selected as targets for protection.
[0166] The following describes a case where a new authentication information unit AT is received when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored. In this case, the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The vehicle management device 26 may be configured not to be able to set a priority order for the one or more authentication information units AT stored in the vehicle storage device 28.
[0167] The following describes the case where a new authentication information unit AT is received when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored. In this case, the vehicle management device 26 is only required to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The vehicle management device 26 is not limited to deleting all of the one or more authentication information units AT that are the subject of unexecuted deletion reservations D41.
[0168] The following describes a case where a new authentication information unit AT is received when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored. In this case, the vehicle management device 26 only needs to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The vehicle management device 26 does not need to delete an authentication information unit AT that is the subject of an unexecuted deletion reservation D41.
[0169] The following describes the case where a new authentication information unit AT is received when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored. In this case, the vehicle management device 26 may delete the authentication information unit AT corresponding to the friend key KF, which is the second digital key, from the authentication information unit AT corresponding to the friend key KF, which is the second digital key, and the authentication information unit AT corresponding to the non-friend key KN, which is the third digital key.
[0170] The vehicle management device 26 may be configured to be able to set a priority for an authentication information unit AT that is the subject of an unexecuted deletion reservation D41 stored in the vehicle storage device 28. For example, the vehicle management device 26 may be configured to set a lower priority for an authentication information unit AT with a shorter remaining fade-out period. For example, the vehicle management device 26 may be configured to set a lower priority for an authentication information unit AT with an earlier time that the authentication information unit AT entered the fade-out state.
[0171] When the vehicle execution device 27 executes the vehicle program PV to perform processing related to the replacement of the authentication information unit AT, the server execution device 71 of the management server 70 does not need to execute the replacement program PM. When the vehicle execution device 27 executes the vehicle program PV to perform processing related to the replacement of the authentication information unit AT, the server storage device 72 of the management server 70 does not need to store the replacement program PM.
[0172] 7, 12, and 13 illustrate a vehicle management device 26 and a management server 70 according to a second embodiment. The second embodiment will be explained mainly focusing on the differences from the first embodiment.
[0173] The following describes the case where the vehicle administration device 26 receives a new authentication information unit AT when the number of one or more authentication information units AT already stored in the vehicle storage device 28 has reached the predetermined number that can be stored. At this time, the vehicle administration device 26 in the second embodiment deletes one or more authentication information units AT already stored in the vehicle storage device 28 based on another registration request D31 from the device 30 that has made the registration request D31 to store key information DK corresponding to the new authentication information unit AT in the device 30. In other words, if the device 30 that made the registration request D31 to store key information DK corresponding to the new authentication information unit AT in the device 30 has also made a registration request D31 in the past, the vehicle administration device 26 deletes the authentication information unit AT corresponding to the previous registration request D31 from the vehicle storage device 28.
[0174] <Series of processes performed by vehicle 20> Figure 12 is an explanatory diagram showing the flow of a series of processes performed by vehicle 20 in the management system 10 when the number of one or more authentication information units AT stored in the vehicle memory device 28 has reached the specified number that can be stored and vehicle 20 receives a new authentication information unit AT.
[0175] The second device 30B is a friend device 51 in which a friend key KF is registered based on a registration request D21 from the owner device 40. The fourth device 30D is a non-friend device 52 in which a non-friend key KN is registered based on a registration request D31 from the second device 30B (friend device 51). The third device 30C is a device 30 that does not store non-friend key information DKN and is designated as a non-friend device 52 by this series of processes.
[0176] When an operation requesting registration of a non-friend key KN for the third device 30C is executed in the second device 30B, which is the friend device 51, the management system 10 performs a series of processes shown in Figure 7 to register the non-friend key KN for the third device 30C.
[0177] 7, the management server 70 transmits the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing the authentication package ATP to the vehicle 20. After that, when the vehicle 20 receives the authentication package ATP and the storage request D34, the vehicle 20 performs the processing of step S104 shown in FIG.
[0178] <Selection of authentication information unit AT to be deleted and replacement of authentication information unit AT> In step S104, similarly to the first embodiment, the vehicle 20 selects an authentication package ATP included in the non-friend key information DKN of the third device 30C from one or more authentication information units AT stored in the vehicle storage device 28. Thereafter, the vehicle 20 performs the process of step S401.
[0179] In step S401, if the vehicle 20 has already stored an authentication information unit AT based on another (i.e., past) registration request D31 from the second device 30B (friend device 51) that has made the registration request D31 to store the authentication information unit AT in the third device 30C, the vehicle 20 selects the authentication information unit AT as the authentication information unit AT to be deleted. The result of the selection made by the vehicle 20 in step S401 takes priority over the result of the selection made by the vehicle 20 in step S102.
[0180] The fourth device 30D is a non-friend device 52 in which a non-friend key KN has been registered based on a registration request D31 from the second device 30B (friend device 51). In other words, the second device 30B (friend device 51) not only recently issued the registration request D31 to register the non-friend key KN in the third device 30C, but also previously issued a registration request D31 to register the non-friend key KN in the fourth device 30D. The vehicle 20 deletes the authentication information unit AT corresponding to the non-friend key information DKN indicating the non-friend key KN of the fourth device 30D. The vehicle 20 then stores the authentication package ATP included in the non-friend key information DKN of the third device 30C.
[0181] That is, the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D. In other words, when storing the authentication package ATP of the non-friend key information DKN of the third device 30C, the vehicle 20 stores the authentication package ATP of the non-friend key information DKN of the third device 30C in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D. The vehicle 20 then performs the process of step S402.
[0182] <Processing After Replacing the Authentication Information Unit AT> In step S402, the vehicle management device 26 generates a completion notification M71. The completion notification M71 includes a signal indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D. The completion notification M71 includes a signal for causing the management server 70 to transmit to the third device 30C a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C. The completion notification M71 includes a signal for causing the management server 70 to transmit to the fourth device 30D (non-friend device 52), the second device 30B (friend device 51), and the owner device 40 a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C. The vehicle management device 26 transmits the completion notification M71 to the management server 70.
[0183] When the management server 70 receives the completion notification M71, the management server 70 executes the process of step S403. In step S403, the management server 70 generates a completion notification M72. The completion notification M72 includes a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C. The management server 70 transmits the completion notification M72 to the third device 30C.
[0184] After the process of step S403, the management server 70 executes the process of step S404. In step S404, the management server 70 generates a replacement notification M73, a replacement notification M74, and a replacement notification M75. The replacement notification M73, the replacement notification M74, and the replacement notification M75 each include a signal indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D. The management server 70 transmits the replacement notification M73 to the fourth device 30D (non-friend device 52). The management server 70 transmits the replacement notification M74 to the second device 30B (friend device 51). The management server 70 transmits the replacement notification M75 to the owner device 40. The process continues to FIG. 14 .
[0185] 13 , when the third device 30C receives the completion notification M72, the third device 30C performs the process of step S405. In step S405, the third device 30C presents, to the device HMI_32, information indicating that the registration of the non-friend key KN of the third device 30C in the vehicle 20 has been completed.
[0186] When the fourth device 30D (non-friend device 52) receives the replacement notification M73, the fourth device 30D performs the process of step S406. In step S406, the fourth device 30D presents to the device HMI_32 information indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in the vehicle storage device 28 instead of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
[0187] When the second device 30B (friend device 51) receives the replacement notification M74, the second device 30B performs the process of step S407. In step S407, the second device 30B presents to the device HMI_32 information indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in the vehicle storage device 28 instead of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
[0188] When the owner device 40 receives the replacement notification M75, the owner device 40 performs the process of step S408. In step S408, the owner device 40 presents to the device HMI_32 information indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D in the vehicle storage device 28. Thereafter, the management system 10 ends the series of processes for replacing the authentication information unit AT this time.
[0189] <Operation of Second Embodiment> When the vehicle management device 26 has already received the authentication information unit AT corresponding to the key information DK of the third device 30C, the vehicle management device 26 deletes the authentication information unit AT corresponding to the key information DK of the third device 30C that has been stored in the vehicle storage device 28 based on another registration request D31 from the second device 30B (friend device 51) that made the registration request D31 corresponding to the authentication information unit AT corresponding to the key information DK of the third device 30C. In other words, the vehicle management device 26 deletes from the vehicle storage device 28 the authentication information unit AT corresponding to the previous registration request D31 from the second device 30B (friend device 51) that made the current registration request D31. Therefore, one or more authentication information units AT already stored in the vehicle storage device 28 based on the registration request D31 from a device other than the second device 30B (friend device 51) and one or more authentication information units AT already stored in the vehicle storage device 28 based on the registration request D21 from the owner device 40 are not deleted.
[0190] <Effects of the Second Embodiment> (2-1) The vehicle management device 26 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D31 from a device other than the second device 30B (friend device 51) from being deleted due to the registration request D31 from the second device 30B (friend device 51). The vehicle management device 26 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D21 from the owner device 40 from being deleted due to the registration request D31 from the second device 30B (friend device 51).
[0191] <Modifications of Second Embodiment> The second embodiment described above can be modified as follows: The second embodiment described above and the following modifications of the second embodiment can be combined and implemented within a range that does not cause technical contradictions.
[0192] The following describes a case in which, when a new authentication information unit AT is received, the vehicle management device 26 deletes one or more authentication information units AT already stored in the vehicle storage device 28 based on another (i.e., past) registration request D31 from the device 30 that made the registration request D31 corresponding to the new authentication information unit AT. In this case, the vehicle management device 26 does not need to generate a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C. Similarly, the vehicle management device 26 does not need to generate a signal indicating that the authentication package ATP included in the non-friend key information DKN of the third device 30C has been stored instead of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
[0193] The vehicle management device 26 may delete one or more authentication information units AT stored in the vehicle storage device 28 based on another registration request D21 from the owner device 40 that has made a registration request D21 corresponding to a new authentication information unit AT. In other words, when the owner device 40 makes a new registration request D21, one or more authentication information units AT stored in the vehicle storage device 28 based on a previous registration request D21 from the owner device 40 are deleted.
[0194] 1, 7, 14, and 15 explain a vehicle management device 26 and a management server 70 according to a third embodiment. The following describes a case where the management server 70 receives a storage request for a new authentication information unit AT for a vehicle 20 when the number of one or more authentication information units AT already stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 of the third embodiment transmits to the vehicle 20 a command to store the new authentication information unit AT in place of any of the one or more authentication information units AT already stored in the vehicle storage device 28.
[0195] Specifically, when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored, and the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20, the management server 70 deletes one of the one or more authentication information units AT stored in the vehicle storage device 28. Thereafter, the management server 70 stores the received authentication information unit AT in the vehicle storage device 28.
[0196] <Series of processes performed by the management server 70> Figure 14 is an explanatory diagram showing the flow of a series of processes performed by the management server 70 in the management system 10 when the management server 70 receives a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the vehicle memory device 28 has reached the specified number that can be stored.
[0197] 1, in the management server 70, the server storage device 72 has already stored therein a replacement program PM. The server execution device 71 executes the replacement program PM stored in the server storage device 72. This causes the management server 70 to execute a series of processes.
[0198] 14 is a device 30 that does not store non-friend key information DKN and is designated as a non-friend device 52 by the series of processes. When a friend device 51 (not shown) executes an operation to request registration of a non-friend key KN for the third device 30C, the management system 10 performs the series of processes shown in FIG. 7 to register the non-friend key KN for the third device 30C.
[0199] Step S501 shown in Figure 14 is similar to step S47 shown in Figure 7. After processing step S501, the third device 30C performs processing step S502. The processing step S502 shown in Figure 14 is similar to step S48 shown in Figure 7. In processing step S502, the third device 30C transmits non-friend key information DKN and a key track request D33 for the non-friend key KN to the management server 70. The key track request D33 is a request to store a new authentication information unit AT in the vehicle 20.
[0200] Thereafter, when the management server 70 receives the key track request D33 for the non-friend key KN, the management server 70 performs processing in step S503. As the processing in step S503, the management server 70 performs registration management of the non-friend key KN. Specifically, the management server 70 confirms that the non-friend key KN that is the target of the key track request D33 is not listed on the rejection list. If the non-friend key KN is listed on the rejection list, the management server 70 sends a notification to the third device 30C that the key track request D33 cannot be fulfilled.
[0201] On the other hand, if the non-friend key KN is not on the rejection list, the management server 70 registers the non-friend key KN that is the target of the key track request D33 in the database DB. Specifically, the management server 70 stores the third device 30C in the data block DA of the vehicle 20 in the database DB as a device 30 registered as a non-friend device 52. The management server 70 stores the relationship between the third device 30C and the friend device 51 by referring to the acquired non-friend key information DKN. Specifically, the management server 70 stores the third device 30C as a device 30 that has the non-friend key KN registered in response to the registration request D31 from the second device 30B (friend device 51). Then, the management server 70 performs the process of step S504.
[0202] The management server 70 of the third embodiment has stored, as data blocks DA of the vehicle 20 in the database DB, the number of one or more authentication information units AT stored in the vehicle storage device 28 and the number of authentication information units AT that can be stored in the vehicle storage device 28. In other words, the management server 70 is configured to be able to determine whether the number of one or more authentication information units AT stored in the vehicle 20 has reached the predetermined number that can be stored in the vehicle 20. In step S504, the management server 70 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
[0203] If the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that the vehicle storage device 28 can store, the management server 70 transmits the authentication package ATP and a storage request D34 for storing the authentication package ATP to the vehicle 20. Thereafter, the management system 10 performs the processes from step S50 onwards shown in FIG.
[0204] If the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle memory device 28 has reached the specified number that the vehicle memory device 28 can store, the management server 70 performs processing in step S505.
[0205] <Selection of Authentication Information Unit AT to be Deleted> In step S505, the management server 70 selects an authentication information unit AT to be deleted from one or more authentication information units AT already stored in the vehicle storage device 28.
[0206] 15 is a flowchart showing the process of selecting an authentication information unit AT to be deleted, which is performed by the management server 70 in step S505. The management server 70 performs this series of processes as the process of step S505.
[0207] 15, when this series of processes starts, the management server 70 determines in step S510 whether any deletion reservations D41 remain unexecuted. If authentication information units AT for one or more digital keys in the fade-out state have been stored in the vehicle storage device 28, the management server 70 determines that any deletion reservations D41 remain unexecuted. If any deletion reservations D41 remain unexecuted (step S510: YES), the management server 70 proceeds to step S511.
[0208] In step S511, the management server 70 determines whether multiple deletion reservations D41 remain unexecuted. If authentication information units AT of multiple digital keys in the fade-out state have been stored in the vehicle storage device 28, the management server 70 determines that multiple deletion reservations D41 remain unexecuted. If multiple deletion reservations D41 remain unexecuted (step S511: YES), the management server 70 proceeds to step S512.
[0209] In step S512, the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT of multiple digital keys in a faded-out state that have been stored in the vehicle storage device 28. That is, the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT that are the subject of the remaining unexecuted deletion reservation D41 from the vehicle storage device 28. The management server 70 then transmits the signal to the vehicle 20. The management server 70 then terminates the series of processes shown in FIG. 15 . In response to the signal, the vehicle 20 deletes all authentication information units AT of multiple digital keys in a faded-out state that have been stored in the vehicle storage device 28. As a result, the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored.
[0210] Thereafter, the management server 70 transmits the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing this authentication package ATP to the vehicle 20. The management server 70 transmits a key track completion notification M33 to the third device 30C. The vehicle 20, which has received the authentication package ATP included in the non-friend key information DKN and the storage request D34 for storing the authentication package ATP, performs the process of step S50 shown in FIG. 7. The third device 30C, which has received the key track completion notification M33, performs the process of step S51 shown in FIG. 7. This causes the management system 10 to end the series of processes.
[0211] If the vehicle storage device 28 has stored only one authentication information unit AT for the faded-out digital key, i.e., if there are not multiple remaining deletion reservations D41 (step S511: NO), the management server 70 proceeds to step S513.
[0212] In step S513, the management server 70 selects the authentication information unit AT of the faded-out digital key as the authentication information unit AT to be deleted, and then the management server 70 ends the series of processes shown in FIG.
[0213] In the processing of step S510, if no deletion reservation D41 remains (step S510: NO), the management server 70 proceeds to step S514. <Determining Whether or Not There Is an Authentication Information Unit AT Selected as a Protection Target> The management server 70 is configured to be able to select one or more authentication information units AT stored in the database DB as protection targets. For example, the user of the vehicle 20 is configured to be able to select, via the device HMI_32 of the owner device 40, each of one or more authentication information units AT stored in the database DB as protection targets. For example, the user of the vehicle 20 can select, via the device HMI_32 of the friend device 51, each of one or more authentication information units AT stored in the database DB as protection targets. For example, the user of the vehicle 20 can select, via the device HMI_32 of the non-friend device 52, each of one or more authentication information units AT stored in the database DB as protection targets.
[0214] In step S514, the management server 70 determines whether or not there is an authentication information unit AT that has been selected as a protection target among one or more authentication information units AT stored in the vehicle storage device 28. If there is an authentication information unit AT that has been selected as a protection target (step S514: YES), the management server 70 selects an authentication information unit AT to be deleted from among the authentication information units AT that are not a protection target in subsequent processing. The management server 70 then proceeds to step S516. If there is not an authentication information unit AT that has been selected as a protection target among one or more authentication information units AT stored in the vehicle storage device 28 (step S514: NO), the management server 70 proceeds to step S516.
[0215] <Determining Whether Priority Has Been Set for Authentication Information Unit AT> The management server 70 is configured to be able to set priorities for one or more authentication information units AT stored in the database DB. For example, the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the database DB via the device HMI_32 of the owner device 40. For example, the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the database DB via the device HMI_32 of the friend device 51. For example, the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the database DB via the device HMI_32 of the non-friend device 52.
[0216] In step S516, the management server 70 determines whether priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28. If priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S516: YES), the management server 70 proceeds to step S517.
[0217] In step S517, the management server 70 determines whether multiple authentication information units AT with different priorities have been stored in the vehicle storage device 28. If the vehicle storage device 28 has stored multiple authentication information units AT with different priorities (step S517: YES), the management server 70 proceeds to step S518.
[0218] In step S518, the management server 70 selects an authentication information unit AT to be deleted based on the priority. For example, the management server 70 selects the authentication information unit AT with the lowest priority as the authentication information unit AT to be deleted. After that, the management server 70 ends the series of processes shown in FIG. 15.
[0219] In step S516, if no priority order has been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S516: NO), the management server 70 proceeds to step S519. In step S517, if the vehicle storage device 28 does not store multiple authentication information units AT with different priorities (step S517: NO), the management server 70 proceeds to step S519.
[0220] <Determining Whether the Authentication Information Unit AT of the Non-Friend Key KN Has Been Stored> In step S519, the management server 70 determines whether the authentication information unit AT of the non-friend key KN has been stored in the vehicle storage device 28. If the authentication information unit AT of the non-friend key KN has been stored in the vehicle storage device 28 (step S519: YES), the management server 70 proceeds to step S520.
[0221] In step S520, the management server 70 selects the authentication information unit AT of the non-friend key KN as the authentication information unit AT to be deleted from one or more authentication information units AT stored in the vehicle storage device 28. Thereafter, the management server 70 ends the series of processes shown in FIG.
[0222] In step S519, if the vehicle storage device 28 does not store an authentication information unit AT for the non-friend key KN (step S519: NO), the management server 70 proceeds to step S521. In step S521, the management server 70 selects, from among one or more authentication information units AT stored in the vehicle storage device 28, the authentication information unit AT for the share key KS with the oldest last used date as the authentication information unit AT to be deleted. Thereafter, the management server 70 ends the series of processes shown in FIG. 15.
[0223] 14, after step S505, the management server 70 transmits the authentication package ATP and a replacement request D81 to the vehicle 20. The replacement request D81 is a request for the management server 70 to store the authentication package ATP in place of the authentication information unit AT selected by the management server 70 in step S505. The replacement request D81 includes a command for the vehicle 20 to delete the authentication information unit AT selected by the management server 70 in step S505 from the vehicle storage device 28, and a command for the vehicle 20 to store the authentication package ATP as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
[0224] The vehicle 20, which has received the authentication package ATP and the replacement request D81, performs the process of step S506. In step S506, the vehicle 20 stores the authentication package ATP in place of one or more authentication information units AT already stored in the vehicle storage device 28. Specifically, the management server 70 deletes the authentication information unit AT selected by the management server 70 in step S505 from the vehicle storage device 28. Thereafter, the vehicle 20 stores the authentication package ATP as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
[0225] After performing the process of step S505, the management server 70 proceeds to step S507. In step S507, the management server 70 generates a completion notification M81. The completion notification M81 includes a signal indicating that the vehicle 20 has stored the authentication package ATP in place of one or more authentication information units AT already stored in the vehicle storage device 28. The management server 70 transmits the completion notification M81 to the third device 30C.
[0226] When the third device 30C receives the completion notification M81, the third device 30C performs the process of step S508. In step S508, the third device 30C presents registration completion information indicating that the registration of the non-friend key KN is completed to the device HMI_32. Thereafter, the management system 10 ends the series of processes for replacing the current authentication information unit AT.
[0227] <Operation of Third Embodiment> When the number of one or more authentication information units AT stored in the vehicle 20 has reached a predetermined number and a new authentication information unit AT is received, the management server 70 transmits a command to the vehicle storage device 28 to delete any of the one or more authentication information units AT stored therein without user intervention. The authentication information unit AT is a unit for handling information related to the digital key.
[0228] <Effects of the Third Embodiment> (3-1) According to the management server 70, when a new authentication information unit AT is stored in the vehicle 20, the user of the vehicle 20 does not have to select which authentication information unit AT to delete from one or more authentication information units ATs already stored in the vehicle 20. In other words, the management server 70 is configured to reduce the burden on the user of the vehicle 20.
[0229] (3-2) The management server 70 is configured to be able to receive a deletion reservation D41. The deletion reservation D41 is a command to cause the vehicle 20 to delete the target information, that is, the authentication information unit AT, when the predetermined condition RC is met. The management server 70 has already stored whether or not any unexecuted deletion reservations D41 remain in the database DB for the vehicle 20. The following describes a case where the management server 70 receives a storage request for a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the predetermined number that can be stored. In other words, the deletion reservation D41 remains unexecuted in the database DB for the vehicle 20. At this time, the management server 70 transmits a command to the vehicle 20 to delete one or more of the one or more authentication information units AT that are the target of the unexecuted deletion reservation D41. As a result, the management server 70 stores the new authentication information unit AT in the vehicle 20 by replacing one or more authentication information units AT that are the subject of the unexecuted deletion reservation D41 with the new authentication information unit AT. That is, the management server 70 selects the authentication information unit AT that is scheduled to be deleted as the authentication information to be replaced by the new authentication information unit AT. In other words, the management server 70 can store the new authentication information unit AT while keeping the authentication information units AT that are not scheduled to be deleted stored.
[0230] (3-3) The following describes a case where the management server 70 receives a storage request for a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT already stored in the database DB for the vehicle 20 has reached the preset number that can be stored. A plurality of unexecuted deletion reservations D41 remain in the vehicle 20. At this time, the management server 70 transmits the authentication information unit AT and the following command to the vehicle 20. That is, this command is a command to delete all of the plurality of authentication information units AT that are the subject of the deletion reservations D41, thereby storing a new authentication information unit AT corresponding to the storage request. The management server 70 causes the vehicle 20 to delete all of the plurality of authentication information units AT that are the subject of the deletion reservations D41. The management server 70 causes the vehicle 20 to store the new authentication information unit AT and also causes the vehicle 20 to secure storage capacity for storing the authentication information unit AT.
[0231] (3-4) The management server 70 is configured to allow the user of the vehicle 20 to set priorities for one or more authentication information units ATs already stored in the vehicle 20. When the management server 70 receives a request to register a new authentication information unit AT for a vehicle 20 for which the number of one or more authentication information units ATs already stored in the vehicle storage device 28 has reached the predetermined number that can be stored, the management server 70 selects an authentication information unit AT to be deleted based on the set priorities. The management server 70 transmits a command to the vehicle 20 to delete the authentication information unit AT that has been selected by the management server 70. The management server 70 selects the authentication information unit AT to be deleted in accordance with the already stored priorities. The management server 70 is configured to allow the selection of the authentication information unit AT to be deleted to reflect the intention of the user who set the priorities.
[0232] (3-5) The management server 70 is configured to be able to select an authentication information unit AT to be set as a protection target by the user of the vehicle 20 from among one or more authentication information units AT stored in the vehicle 20. The management server 70 transmits to the vehicle 20 a command to delete one or more authentication information units AT that have not been selected as a protection target. The management server 70 is configured to be able to set two levels of priority for the one or more authentication information units AT stored in the vehicle 20: authentication information units AT that are set as a protection target and authentication information units AT that are not a protection target. The management server 70 can reflect the user's intention by preventing the deletion of an authentication information unit AT that has been set as a protection target.
[0233] (3-6) The following describes a case where the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. The vehicle storage device 28 has already stored an authentication information unit AT for authenticating the friend key KF and an authentication information unit AT for authenticating the non-friend key KN. At this time, the management server 70 transmits to the vehicle 20 a command to delete the authentication information unit AT that was required to authenticate the non-friend key KN. The management server 70 is configured to be able to protect the authentication information unit AT for authenticating the friend key KF registered by the owner of the vehicle 20. This makes it possible to reduce the frequency of a situation in which, for example, the authentication information unit AT required for authenticating the friend key KF is deleted, forcing the owner to re-register the friend key KF.
[0234] <Modifications of the Third Embodiment> The third embodiment is configured to be able to be implemented with the following modifications: The third embodiment and the following modifications are configured to be able to be implemented in combination with each other within a range that does not cause technical contradictions.
[0235] The following describes a case where the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT already stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 may cause the vehicle 20 to delete any of the one or more authentication information units AT already stored in the vehicle 20. The management server 70 does not have to select an authentication information unit AT to be deleted from the one or more authentication information units AT already stored in the vehicle 20. For example, the management server 70 may transmit to the vehicle 20 a command to randomly delete any of the one or more authentication information units AT already stored in the vehicle storage device 28.
[0236] The following describes a case where the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 only needs to transmit to the vehicle 20 a command to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The management server 70 does not need to be able to select an authentication information unit AT as a target for protection.
[0237] The following describes a case where the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 only needs to transmit to the vehicle 20 a command to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The management server 70 does not need to be able to set priorities for the authentication information units AT.
[0238] The following describes a case where the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 only needs to transmit to the vehicle 20 a command to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The management server 70 does not need to cause the vehicle 20 to delete one or more authentication information units AT that are the subject of an unexecuted deletion reservation D41.
[0239] The following describes a case where the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 may cause the vehicle 20 to delete authentication information units AT other than the one or more authentication information units AT that are the subject of an unexecuted deletion reservation D41.
[0240] The following describes a case where the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. The vehicle storage device 28 already stores an authentication information unit AT for authenticating the friend key KF and an authentication information unit AT for authenticating the non-friend key KN. At this time, the management server 70 may cause the vehicle 20 to delete, from the one or more authentication information units AT stored in the vehicle storage device 28, an authentication information unit AT that was required when the friend key KF was authenticated.
[0241] The management server 70 may be configured to be able to set priorities for multiple authentication information units ATs that are the subject of unexecuted deletion reservations D41 stored in the database DB for the vehicle 20. For example, the management server 70 may be configured to set a lower priority for an authentication information unit AT with a shorter remaining fade-out period. For example, the management server 70 may be configured to set a lower priority for an authentication information unit AT with an earlier time that the authentication information unit AT entered the fade-out state.
[0242] 7 and 14 to 17 illustrate a vehicle management device 26 and a management server 70 according to a fourth embodiment. The fourth embodiment will be described, focusing on differences from the third embodiment. The following describes a case in which the management server 70 receives a storage request for a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached a predetermined number that can be stored. At this time, the management server 70 transmits to the vehicle 20 a command to delete one or more authentication information units AT stored in the vehicle storage device 28 based on another registration request D31 from the device 30 that has issued the registration request D31 for storing the new authentication information unit AT and key information DK corresponding to the new authentication information unit AT in the device 30. In other words, if the device 30 that issued the registration request D31 for storing key information DK corresponding to the new authentication information unit AT in the device 30 has also issued a registration request D31 in the past, the management server 70 deletes the authentication information unit AT corresponding to the previous registration request D31 from the vehicle storage device 28.
[0243] <Series of processes executed by management server 70> Figure 16 is an explanatory diagram showing the flow of a series of processes executed by management server 70 in management system 10 when the number of one or more authentication information units AT stored in the database DB for vehicle 20 has reached the specified number that can be stored and management server 70 receives a request to store a new authentication information unit AT for vehicle 20.
[0244] The second device 30B is a friend device 51 in which a friend key KF has been registered based on a registration request D21 from the owner device 40. The second device 30B (friend device 51) has already stored friend key information DKF. The fourth device 30D is a non-friend device 52 in which a non-friend key KN has been registered based on a registration request D31 from the second device 30B, which is the friend device 51. The fourth device 30D (non-friend device 52) has already stored non-friend key information DKN. The third device 30C is a device 30 that does not store non-friend key information DKN and that will be newly designated as a non-friend device 52 by this series of processes.
[0245] When an operation to request registration of a non-friend key KN for the third device 30C is executed in the second device 30B, which is the friend device 51, the management system 10 performs a series of processes shown in Figure 7 to register the non-friend key KN.
[0246] 7, the third device 30C generates a key track request D33 for the non-friend key KN. The third device 30C transmits the non-friend key information DKN and the key track request D33 for the non-friend key KN to the management server 70.
[0247] When the management server 70 receives the key track request D33 for the non-friend key KN, the management server 70 performs the process of step S503 shown in Fig. 14. The process executed by the management server 70 in step S503 is the same as that in the third embodiment. Thereafter, the management server 70 performs the process of step S504 shown in Fig. 16. The process executed by the management server 70 in step S504 is the same as that in the third embodiment.
[0248] The management server 70 has stored, as data blocks DA of the vehicle 20 in the database DB, the number of one or more authentication information units AT stored in the vehicle storage device 28 and the number of authentication information units AT that can be stored in the vehicle storage device 28. In step S504, the management server 70 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
[0249] The following describes a case where the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that can be stored by the vehicle storage device 28. In this case, the management server 70 transmits to the vehicle 20 the authentication package ATP included in the non-friend key information DKN of the third device 30C and a storage request D34 for storing the authentication package ATP. Thereafter, the management system 10 performs the processes from step S50 onwards shown in FIG. 7.
[0250] The following describes a case where the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored in the vehicle storage device 28. In this case, the management server 70 performs the processes from step S601 onward shown in FIG.
[0251] In step S601, the management server 70 selects an authentication information unit AT to be replaced by the authentication package ATP from one or more authentication information units AT already stored in the vehicle storage device 28.
[0252] 15 is a flowchart showing the process of selecting an authentication information unit AT to be replaced by the authentication package ATP, which is performed by the management server 70 in step S601. The management server 70 performs the series of processes shown in FIG. 15 as the process of step S601, similar to step S505 in the third embodiment.
[0253] After performing the series of processes shown in FIG. 15 , the management server 70 determines whether the vehicle storage device 28 has stored an authentication information unit AT based on another registration request D31 from the second device 30B (friend device 51) that made the registration request D31 to store the key information DK in the third device 30C. In other words, the management server 70 determines whether the vehicle storage device 28 has stored an authentication information unit AT corresponding to a previous registration request D31 from the second device 30B (friend device 51) that made the current registration request D31. If the vehicle storage device 28 has stored an authentication information unit AT corresponding to another (past) registration request D31, the management server 70 selects the authentication information unit AT as the authentication information unit AT to be deleted. The result of this selection takes priority over the result of the selection by the series of processes shown in FIG. 15 .
[0254] The fourth device 30D is a non-friend device 52 in which non-friend key information DKN indicating the non-friend key KN has been stored based on a registration request D31 from the second device 30B (friend device 51). The vehicle storage device 28 has stored an authentication information unit AT corresponding to the non-friend key information DKN stored in the fourth device 30D (non-friend device 52). The management server 70 selects the authentication information unit AT corresponding to the non-friend key information DKN stored in the fourth device 30D (non-friend device 52) as the authentication information unit AT to be replaced.
[0255] The management server 70 transmits the authentication package ATP and a replacement request D91 to the vehicle 20. The replacement request D91 is a command to cause the fourth device 30D (non-friend device 52) to store the authentication package ATP in place of the authentication information unit AT corresponding to the non-friend key information DKN already stored therein. The replacement request D91 includes a command to cause the fourth device 30D (non-friend device 52) to delete the authentication information unit AT corresponding to the non-friend key information DKN already stored therein. The replacement request D91 includes a command to store the authentication package ATP included in the non-friend key information DKN of the third device 30C.
[0256] After receiving the authentication package ATP and the replacement request D91, the vehicle 20 performs the process of step S602. In step S602, the vehicle 20 deletes the authentication information unit AT corresponding to the non-friend key information DKN already stored in the fourth device 30D (non-friend device 52). The vehicle 20 then stores the authentication package ATP included in the non-friend key information DKN of the third device 30C. In other words, the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of the authentication information unit AT corresponding to the non-friend key information DKN already stored in the fourth device 30D (non-friend device 52).
[0257] <Processing after vehicle 20 stores authentication information unit AT> After processing in step S601, the management server 70 executes processing in step S603. In step S603, the management server 70 generates a completion notification M92. The completion notification M92 includes a signal indicating that the authentication information unit AT included in the non-friend key information DKN of the third device 30C has been stored in the vehicle storage device 28. The management server 70 transmits the completion notification M92 to the third device 30C.
[0258] After the process of step S603, the management server 70 executes the process of step S604. In step S604, the management server 70 generates a replacement notification M93, a replacement notification M94, and a replacement notification M95. The replacement notification M93, the replacement notification M94, and the replacement notification M95 include signals indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced with the authentication package ATP included in the key information DK of the third device 30C. The management server 70 transmits the replacement notification M93 to the fourth device 30D (non-friend device 52). The management server 70 transmits the replacement notification M94 to the second device 30B (friend device 51). The management server 70 transmits the replacement notification M95 to the owner device 40. The process then continues to FIG. 17 .
[0259] 17 , upon receiving the completion notification M92, the third device 30C performs the process of step S605. In step S605, the third device 30C notifies the device HMI_32 of the registration completion, which indicates that the authentication package ATP included in the key information DK of the third device 30C has been registered in the vehicle 20 as an authentication information unit AT.
[0260] When the fourth device 30D (non-friend device 52) receives the replacement notification M93, it performs the process of step S606. In step S606, the fourth device 30D (non-friend device 52) presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced with the authentication package ATP included in the key information DK of the third device 30C.
[0261] When the second device 30B (friend device 51) receives the replacement notification M94, it performs the process of step S607. In step S607, the second device 30B (friend device 51) presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced with the authentication package ATP included in the key information DK of the third device 30C.
[0262] When the owner device 40 receives the replacement notification M95, it performs the process of step S608. In step S608, the owner device 40 presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced with the authentication package ATP included in the key information DK of the third device 30C. Thereafter, the management system 10 ends the series of processes for replacing the authentication information unit AT.
[0263] <Operation of Fourth Embodiment> When a new authentication information unit AT is received, the management server 70 transmits to the vehicle 20 a command to delete one or more authentication information units AT stored in the vehicle storage device 28 based on another (i.e., past) registration request D31 from the second device 30B (friend device 51) that made the registration request D31 corresponding to the new authentication information unit AT. That is, the one or more authentication information units AT stored in the vehicle storage device 28 based on the past registration request D31 from the second device 30B (friend device 51) that made the registration request D31 corresponding to the new authentication information unit AT are deleted. Therefore, the one or more authentication information units AT stored in the vehicle storage device 28 based on the registration request D31 from a device other than the second device 30B (friend device 51) and the one or more authentication information units AT stored in the vehicle storage device 28 based on the registration request D21 from the owner device 40 are not deleted.
[0264] Advantages of the Fourth Embodiment (4-1) The management server 70 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D31 from a device other than the second device 30B (friend device 51) from being deleted due to the registration request D31 from the second device 30B (friend device 51). The management server 70 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D21 from the owner device 40 from being deleted due to the registration request D31 from the second device 30B (friend device 51).
[0265] (4-2) The following describes the case where the management server 70 transmits a new authentication information unit AT and the next command to the vehicle 20. That is, this command is a command to delete one of one or more authentication information units AT stored in the vehicle storage device 28. At this time, the management server 70 notifies the owner device 40 that the authentication information unit AT has been deleted from the vehicle 20. This allows the management server 70 to inform the owner of the vehicle 20 that one of the authentication information units AT stored in the vehicle 20 has been deleted.
[0266] (4-3) The following describes the case where the management server 70 transmits a new authentication information unit AT and the next command to the vehicle 20. That is, this command is for deleting one of one or more authentication information units AT stored in the vehicle storage device 28. At this time, the management server 70 notifies the shared device 50 that has made the registration request D31 corresponding to the authentication information unit AT to be deleted that the authentication information unit AT has been deleted. This allows the user of the shared device 50 that has made the registration request D31 corresponding to the deleted authentication information unit AT to understand that the authentication information unit AT has been deleted.
[0267] (4-4) The following describes the case where the management server 70 transmits a new authentication information unit AT and the next command to the vehicle 20. That is, this command is for deleting one or more authentication information units AT stored in the vehicle storage device 28. At this time, the management server 70 notifies the shared device 50 that has stored the key information DK corresponding to the deleted authentication information unit AT that the authentication information unit AT has been deleted. The device 30 that has stored the key information DK corresponding to the deleted authentication information unit AT will no longer be able to use the vehicle 20. That is, the management server 70 is configured to be able to notify the user of the shared device 50 that the digital key registered in the shared device 50 has become unusable. This allows the user to realize that the digital key is no longer usable before actually attempting to use the vehicle 20.
[0268] <Modifications of Fourth Embodiment> The fourth embodiment described above can be modified and implemented as follows: The fourth embodiment described above and the following modifications of the fourth embodiment can be combined and implemented within a range that does not cause technical contradictions.
[0269] The management server 70 may notify the owner device 40 of only the deleted authentication information unit AT. The management server 70 may not send a notification to the owner device 40. Even in these cases, the management server 70 can delete the authentication information unit AT without intervention by the user of the vehicle 20. Therefore, the management server 70 is configured to reduce the burden on the user.
[0270] When deleting an authentication information unit AT, the management server 70 does not have to send a notification to the shared device 50 that requested registration of the digital key corresponding to the authentication information unit AT. Even in this case, the management server 70 can delete the authentication information unit AT without intervention by the user of the vehicle 20. Therefore, the management server 70 is configured to reduce the burden on the user.
[0271] The management server 70 does not need to send a notification to the shared device 50 whose authentication information unit AT is to be replaced. Even in this case, the management server 70 can delete the authentication information unit AT without intervention by the user of the vehicle 20. Thus, the management server 70 is configured to reduce the burden on the user.
[0272] - When a new authentication information unit AT is received, the management server 70 may send an instruction to the vehicle 20 to delete one or more authentication information units AT stored in the vehicle memory device 28 based on another registration request D21 from the owner device 40 that made the registration request D21 corresponding to the authentication information unit AT.
[0273] 7, 15, 18, and 19 illustrate a vehicle management device 26 and a management server 70 according to a fifth embodiment. The fifth embodiment will be described, focusing on the differences from the third embodiment. In the fifth embodiment, a database DB for a vehicle 20 has multiple digital keys stored in a faded-out state. The management server 70 according to the fifth embodiment transmits to the vehicle 20 a command to delete all of the multiple authentication information units AT that are the subject of the deletion reservation D41, a new authentication information unit AT, and a command to store the new authentication information unit AT. At this time, the management server 70 notifies the multiple shared devices that have stored the key information DK corresponding to the multiple authentication information units AT that are the subject of the deletion reservation D41 that the authentication information unit AT corresponding to the key information DK has been deleted.
[0274] 18 , in step S700, the management server 70 has already stored that the friend key KF indicated by the friend key information DKF stored in the fifth device 30E is in a fade-out state. The management server 70 has already stored that the non-friend key KN indicated by the non-friend key information DKN stored in the sixth device 30F is in a fade-out state. In other words, in step S700, the management server 70 is in a state where multiple deletion reservations D41 remain unexecuted.
[0275] 18 is a device 30 that does not store non-friend key information DKN and is designated as a non-friend device 52 by the series of processes. When a second device 30B, which is a friend device 51 (not shown), executes an operation to request registration of a non-friend key KN for the third device 30C, the management system 10 performs the series of processes shown in FIG.
[0276] Step S701 shown in Fig. 18 is similar to step S47 shown in Fig. 7. After the processing of step S701, the third device 30C performs the processing of step S702. The processing of step S702 shown in Fig. 18 is similar to step S48 shown in Fig. 7. In the processing of step S702, the third device 30C transmits the non-friend key information DKN and a key track request D33 of the non-friend key KN to the management server 70.
[0277] Thereafter, when the management server 70 receives the key track request D33 for the non-friend key KN, the management server 70 performs processing in step S703. As the processing in step S703, the management server 70 performs registration management of the non-friend key KN. Specifically, the management server 70 confirms that the non-friend key KN that is the target of the key track request D33 is not listed on the rejection list. If the non-friend key KN is listed on the rejection list, the management server 70 sends a notification to the third device 30C that the key track request D33 cannot be fulfilled.
[0278] On the other hand, if the non-friend key KN is not on the rejection list, the management server 70 registers the non-friend key KN that is the target of the key track request D33 in the database DB. Specifically, the management server 70 stores the third device 30C in the data block DA of the vehicle 20 in the database DB as a device 30 registered as a non-friend device 52. The management server 70 stores the relationship between the third device 30C and the friend device 51 by referring to the acquired non-friend key information DKN. Specifically, the management server 70 stores the third device 30C as a device 30 that has the non-friend key KN registered in response to the registration request D31 from the second device 30B (friend device 51). Then, the management server 70 performs the process of step S704.
[0279] The management server 70 has stored, as data blocks DA of the vehicle 20 in the database DB, the number of one or more authentication information units AT stored in the vehicle storage device 28 and the number of authentication information units AT that can be stored in the vehicle storage device 28. In step S704, the management server 70 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
[0280] If the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that the vehicle storage device 28 can store, the management server 70 transmits the authentication package ATP and a storage request D34 to the vehicle 20. Thereafter, the management system 10 performs the processes from step S50 onward shown in FIG.
[0281] If the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle memory device 28 has reached the specified number that the vehicle memory device 28 can store, the management server 70 performs processing in step S705.
[0282] In step S705, the management server 70 selects an authentication information unit AT to be replaced by the authentication package ATP from one or more authentication information units AT already stored in the vehicle storage device 28.
[0283] 15 is a flowchart showing the process of selecting the authentication information unit AT to be replaced by the authentication package ATP, which is performed by the management server 70 in step S705. The management server 70 performs this series of processes as the process of step S705.
[0284] 15 , when this series of processes starts, in step S510, the management server 70 determines whether one or more unexecuted deletion reservations D41 remain. If authentication information units AT of one or more faded-out digital keys have been stored in the vehicle storage device 28, the management server 70 determines that one or more unexecuted deletion reservations D41 remain. The vehicle storage device 28 has already stored, as faded-out digital keys, the friend key KF of the fifth device 30E, which is the friend device 51, and the non-friend key KN of the sixth device 30F, which is the non-friend device 52. In other words, at least one unexecuted deletion reservation D41 remains (step S510: YES). Therefore, the management server 70 proceeds to step S511.
[0285] In step S511, the management server 70 determines whether multiple deletion reservations D41 remain unexecuted. If authentication information units AT for multiple digital keys in a fade-out state have already been stored in the vehicle storage device 28, the management server 70 determines that multiple deletion reservations D41 remain unexecuted. The vehicle storage device 28 has already stored, as authentication information units AT for multiple digital keys in a fade-out state, the authentication information unit AT for the friend key KF of the fifth device 30E and the authentication information unit AT for the non-friend key KN of the sixth device 30F. In other words, multiple deletion reservations D41 remain unexecuted (step S511: YES). Therefore, the management server 70 proceeds to step S512.
[0286] In step S512, the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT of multiple digital keys that are in a faded-out state and that have been stored in the vehicle storage device 28. That is, the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT that are the subject of unexecuted deletion reservations D41 from the vehicle storage device 28. The management server 70 generates a deletion request D101 shown in FIG. 18 as the signal. Thereafter, the management server 70 transmits the deletion request D101 to the vehicle 20. Thereafter, the management server 70 ends the series of processes shown in FIG. 15.
[0287] After completing the series of processes shown in Fig. 15, in step S705 shown in Fig. 18, the management server 70 generates a storage request D102. The storage request D102 is a signal for storing the authentication package ATP in the vehicle storage device 28. The management server 70 transmits the storage request D102 and the authentication package ATP to the vehicle 20.
[0288] When the vehicle 20 receives the deletion request D101, the vehicle 20 performs the process of step S706. In step S706, the vehicle 20 deletes all authentication information units AT of the multiple digital keys in the faded-out state stored in the vehicle storage device 28 in accordance with the deletion request D101. As a result, the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored. Thereafter, the vehicle 20 performs the process of step S707 shown in FIG. 19 .
[0289] In step S707, the vehicle 20 stores the received authentication package ATP in accordance with the storage request D102. That is, the vehicle 20 stores the authentication package ATP as an authentication information unit AT for authenticating the non-friend key KN.
[0290] <Processing after vehicle 20 stores authentication information unit AT> After the process of step S705, the management server 70 generates a key tracking completion notification M101 as the process of step S708. The management server 70 transmits the key tracking completion notification M101 to the third device 30C.
[0291] When the third device 30C receives the key track completion notification M101, the third device 30C performs the process of step S709. In the process of step S709, the third device 30C presents information indicating the completion of the registration of the non-friend key KN to the device HMI_32. For example, the third device 30C presents an image indicating the completion of the registration of the non-friend key KN to the device HMI_32.
[0292] After processing step S708, the management server 70 generates a deletion notification M102 and a deletion notification M103 in processing step S710. The deletion notification M102 is a notification indicating that the authentication information unit AT corresponding to the non-friend key information DKN of the sixth device 30F has been deleted from the vehicle 20. The deletion notification M103 is a notification indicating that the authentication information unit AT corresponding to the friend key information DKF of the fifth device 30E and the authentication information unit AT corresponding to the non-friend key information DKN of the sixth device 30F have been deleted from the vehicle 20. The management server 70 transmits the deletion notification M102 to the sixth device 30F. The management server 70 transmits the deletion notification M103 to the fifth device 30E.
[0293] When the sixth device 30F receives the deletion notification M102, the sixth device 30F executes the process of step S711 in accordance with the deletion notification M102. In step S711, the sixth device 30F deletes the non-friend key information DKN corresponding to the authentication information unit AT deleted by the vehicle 20 from the device storage device 37 of the sixth device 30F.
[0294] In step S711, the sixth device 30F presents to the device HMI_32 information indicating that the non-friend key information DKN has been deleted. The sixth device 30F presents to the device HMI_32 information indicating that the authentication information unit AT included in the non-friend key information DKN of the sixth device 30F has been deleted from the vehicle storage device 28.
[0295] When the fifth device 30E receives the deletion notification M103, the fifth device 30E executes the process of step S712 in accordance with the deletion notification M103. In step S712, the fifth device 30E deletes, from the device storage device 37 of the fifth device 30E, the non-friend key information DKN corresponding to the authentication information unit AT deleted by the vehicle 20. The fifth device 30E presents, to the device HMI_32, information indicating that the non-friend key information DKN corresponding to the authentication information unit AT deleted by the vehicle 20 has been deleted from the device storage device 37 of the fifth device 30E.
[0296] In step S712, the fifth device 30E presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the friend key information DKF of the fifth device 30E has been deleted from the vehicle 20. The fifth device 30E presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the non-friend key information DKN of the sixth device 30F has been deleted from the vehicle 20. Thereafter, the management system 10 ends the series of processes.
[0297] <Operation of Fifth Embodiment> The shared device 50 that has stored therein the key information DK corresponding to the deleted authentication information unit AT becomes unable to use the vehicle 20 .
[0298] <Effects of the Fifth Embodiment> (5-1) The management server 70 is configured to be able to notify the user of the shared device 50 that the digital key registered in the shared device 50 can no longer be used. This allows the user of the shared device 50 to realize that the digital key can no longer be used before actually attempting to use the vehicle.
[0299] <Modifications of Fifth Embodiment> The fifth embodiment described above can be modified as follows: The fifth embodiment described above and the following modifications of the fifth embodiment can be combined with each other to the extent that they are not technically inconsistent.
[0300] When the server execution device 71 of the management server 70 executes the replacement program PM to perform processing related to the replacement of the authentication information unit AT, the server execution device 71 of the vehicle management device 26 does not need to perform processing related to the replacement of the authentication information unit AT in the vehicle program PV. When the server execution device 71 of the management server 70 executes the replacement program PM to perform processing related to the replacement of the authentication information unit AT, the vehicle storage device 28 does not need to store processing related to the replacement of the authentication information unit AT as the vehicle program PV.
[0301] <Other Modifications> Other elements that can be modified in common to the above embodiments include the following: The following modifications can be implemented in combination with each other within the scope of technical compatibility.
[0302] The digital key-related matters in the above embodiments do not need to comply with the CCC. The series of processes including the process of deleting an authentication information unit AT when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored is not limited to the examples in the above embodiments. For example, the management server 70 shown in FIG. 20 is configured to select one of the one or more authentication information units AT stored in the vehicle storage device 28 as an authentication information unit AT to be deleted. However, the management server 70 does not determine whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored. The vehicle 20 shown in FIG. 20 is configured to determine whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored. However, the vehicle 20 does not select an authentication information unit AT to be deleted from the one or more authentication information units AT stored in the vehicle storage device 28. The third device 30C shown in FIG. 20 is a device 30 that does not store non-friend key information DKN and is determined to be a non-friend device 52 through the series of processes.
[0303] Continuing with the example of FIG. 20 , an operation to request registration of a non-friend key KN for the third device 30C is executed in the friend device 51 (not shown), and the management system 10 performs the series of processes shown in FIG. 7 to register the non-friend key KN. Step S801 shown in FIG. 20 is similar to step S47 shown in FIG. 7 . After the process of step S801, the third device 30C performs the process of step S802. The process of step S802 shown in FIG. 20 is similar to step S48 shown in FIG. 7 . The process of step S803 shown in FIG. 20 is similar to step S48 shown in FIG. 7 .
[0304] In the process of step S803, the management server 70 transmits the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing the authentication package ATP to the vehicle 20. After that, when the vehicle 20 receives the authentication package ATP and the storage request D34, the vehicle 20 performs the process of step S804.
[0305] In step S804, the vehicle 20 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored. If the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored, the vehicle 20 generates an upper limit notification M111. The upper limit notification M111 includes a signal indicating that the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored. The vehicle 20 transmits the upper limit notification M111 to the management server 70. By receiving the upper limit notification M111, the management server 70 is configured to be able to recognize that the number of one or more authentication information units AT stored in the vehicle 20 has reached the predetermined number that can be stored in the vehicle 20.
[0306] After receiving the upper limit notification M111, the management server 70 executes the process of step S805. In step S805, the management server 70 performs the same process as step S505 shown in FIG. 14. As a result, the management server 70 selects the authentication information unit AT to be deleted. Thereafter, the management server 70 transmits a replacement request D111 shown in FIG. 10 to the vehicle 20.
[0307] Vehicle 20 that has received replacement request D111 performs the process of step S806. In the process of step S806, vehicle 20 performs the same process as step S105 shown in Fig. 10. After performing the process of step S806, vehicle 20 proceeds to the process of step S807 shown in Fig. 20.
[0308] In step S807, the vehicle 20 generates a completion notification M112. The completion notification M112 includes a signal indicating that the vehicle 20 has replaced the authentication information unit AT selected by the management server 70 in step S805 with the authentication package ATP included in the non-friend key information DKN of the third device 30C and stored it in the vehicle storage device 28. In other words, the completion notification M112 includes information in which the authentication information unit AT selected by the management server 70 in step S805 has been deleted. The vehicle 20 transmits the completion notification M112 to the management server 70. Having received the completion notification M112, the management server 70 performs the process of step S808.
[0309] In step S808, the management server 70 generates a completion notification M113. The completion notification M113 includes a signal indicating that the vehicle 20 has stored the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of one or more authentication information units AT already stored in the vehicle storage device 28. In other words, the completion notification M113 includes information that the authentication information unit AT selected by the management server 70 in step S805 has been deleted. The management server 70 transmits the completion notification M113 to the third device 30C.
[0310] When the third device 30C receives the completion notification M113, the third device 30C performs the process of step S809. In step S809, the third device 30C presents to the device HMI_32 registration completion information indicating that the registration of the non-friend key KN of the third device 30C to the vehicle 20 has been completed. Thereafter, the management system 10 ends the series of processes for replacing the current authentication information unit AT.
[0311] <Sending confirmation notification M121> - When the management system 10 selects an authentication information unit AT to be deleted from one or more authentication information units AT stored in the vehicle memory device 28, it may confirm with the user of the owner device 40 whether or not to allow the deletion of the authentication information unit AT.
[0312] 21 is an explanatory diagram showing the flow of a series of processes executed by the vehicle 20 after the vehicle 20 selects an authentication information unit AT to be deleted from one or more authentication information units AT stored in the vehicle storage device 28 in the series of processes shown in FIG. 10. As shown in FIG. 1, in the vehicle 20, the vehicle storage device 28 has already stored a vehicle program PV. The vehicle execution device 27 executes the vehicle program PV stored in the vehicle storage device 28. This causes the vehicle 20 to execute a series of processes. The owner device 40 is the first device 30A that has already stored key information DK indicating the owner key KO through the series of processes shown in FIG. 5.
[0313] In step S104, the vehicle 20 performs the same process as in step S104 shown in Fig. 10. When the vehicle 20 selects the authentication information unit AT to be deleted, the vehicle 20 performs the process of step S105.
[0314] In step S901, the vehicle 20 generates a confirmation request D121. The confirmation request D121 is a request to the user of the owner device 40 for permission to delete the authentication information unit AT selected by the vehicle 20 in step S104. The vehicle 20 transmits the confirmation request D121 and name information ATP5 to the management server 70. The name information ATP5 is included in the authentication information unit AT selected by the vehicle 20 in step S104.
[0315] The management server 70 is configured to be able to receive a confirmation request D121 from the vehicle 20. Upon receiving the confirmation request D121, the management server 70 performs processing in step S902. In step S902, the management server 70 generates a confirmation notification M121, which is a notification requesting permission to delete the authentication information unit AT, in accordance with the confirmation request D121. The confirmation notification M121 includes information for enabling the device 30 to set whether or not to permit deletion of the authentication information unit AT through operation of the device 30. The management server 70 transmits the name information ATP5 received from the vehicle 20 and the confirmation notification M121 to the owner device 40.
[0316] <Processing Performed by the Owner Device 40 After Receiving the Confirmation Notification M121> The owner device 40 is configured to be able to receive the confirmation notification M121 from the management server 70. When the owner device 40 receives the confirmation notification M121, the owner device 40 performs the process of step S903. In step S903, the owner device 40 presents to the device HMI_32 an image that allows the user of the owner device 40 to set whether or not to permit deletion of the authentication information unit AT.
[0317] 22 is an example of an image presented on the device HMI_32 of the owner device 40 to ask the user of the owner device 40 whether or not to permit the deletion of the authentication information unit AT. The "Name Information" field shown in Fig. 22 displays the name information ATP5 that the owner device 40 has received from the management server 70. The user of the owner device 40 follows the guidance presented on the device HMI_32 and selects either "YES" or "NO" using the radio button to indicate whether or not to permit the deletion of the authentication information unit AT.
[0318] <Step S903: YES> If the user of the owner device 40 selects "YES" using the radio button and then presses "OK" (step S903: YES), the owner device 40 generates a permission notification M122. The permission notification M122 is a notification that permits the deletion of the authentication information unit AT. The owner device 40 transmits the permission notification M122 to the management server 70.
[0319] <Processing Performed by Management System 10 After Receiving Permission Notification M122> When the management server 70 receives the permission notification M122, it performs the process of step S904. In step S904, the management server 70 generates a continuation request D122. The continuation request D122 includes a signal for permitting the vehicle 20 to delete the authentication information unit AT. The management server 70 transmits the continuation request D122 to the vehicle 20.
[0320] When vehicle 20 receives continuation request D122, it performs the process of step S105. In step S105, vehicle 20 performs the same process as step S105 shown in Fig. 10. That is, vehicle 20 deletes authentication information unit AT from vehicle storage device 28. Thereafter, management system 10 performs the processes from step S106 onwards shown in Fig. 10.
[0321] <Step S93: NO> In step S903 shown in Fig. 21, if the user of the owner device 40 selects "NO" shown in Fig. 22 using the radio button and then presses "OK" (step S903: NO), the owner device 40 generates a rejection notification M123. The rejection notification M123 is a notification that rejects the deletion of the authentication information unit AT. The owner device 40 transmits the rejection notification M123 to the management server 70.
[0322] <Processing Performed by Management System 10 After Receiving Rejection Notification M123> When the management server 70 receives the rejection notification M123, it performs the process of step S905. In step S905, the management server 70 generates a cancellation request D123. The cancellation request D123 requests the vehicle 20 to cancel the deletion of the authentication information unit AT. The management server 70 transmits the cancellation request D123 to the vehicle 20.
[0323] When the vehicle 20 receives the cancellation request D123, the vehicle 20 performs the process of step S906. In step S906, the vehicle 20 cancels the deletion of the authentication information unit AT. Thereafter, the management system 10 ends the series of processes without deleting the authentication information unit AT from the vehicle storage device 28. In this case, no new authentication information unit AT is stored in the vehicle storage device 28.
[0324] By executing this series of processes, the management system 10 is configured to be able to ask the user of the owner device 40 whether or not to permit deletion of the authentication information unit.
[0325] The management server 70 may transmit the confirmation notification M121 to the shared device 50. For example, the management server 70 may transmit the confirmation notification M121 to the next shared device 50. That is, the shared device 50 to which the confirmation notification M121 is to be transmitted has stored the same name information ATP as the name information ATP5 received from the vehicle 20 in step S903. The management server 70 may transmit the confirmation notification M121 to the owner device 40 and the shared device 50.
[0326] <Registration of a new non-friend key KN by the non-friend device 52> The non-friend device 52 may be able to transmit a request for registering a new non-friend key KN. In other words, a share device 50 that has stored a share key KS may transmit a request for registering a new non-friend key KN, regardless of whether the share device 50 is a friend device 51 or a non-friend device 52. In this case, the management system 10 may register the new non-friend key KN by the series of processes shown in FIG. 7 .
[0327] For example, the third device 30C shown in FIG. 4 is a non-friend device 52 that has stored therein key information DK indicating the non-friend key KN of the vehicle 20. The third device 30C may transmit a request to register a new non-friend key KN of the vehicle 20. As a result, a new device 30 that has stored therein key information DK for the new non-friend key KN of the vehicle 20 is registered as the non-friend device 52. In this case, the second device 30B that has stored therein friend key information DKF indicating the friend key KF is a device 30 that has stored therein key information DK indicating the first digital key (friend key KF). In other words, the first digital key is not limited to the owner key KO. The third device 30C has stored therein non-friend key information DKN indicating the non-friend key KN to be registered based on the registration request D31 from the second device 30B. The third device 30C is a device 30 that has stored therein key information DK indicating the second digital key (non-friend key KN). The new device that has stored key information DK indicating a new non-friend key KN to be registered based on a registration request from the third device 30C is a device 30 that has stored key information DK indicating a third digital key (non-friend key KN).
[0328] In this case, the vehicle storage device 28 has already stored an authentication information unit AT for authenticating the friend key KF as the authentication information unit AT for authenticating the first digital key (friend key KF). The vehicle storage device 28 has already stored an authentication information unit AT for authenticating the non-friend key KN as the authentication information unit AT for authenticating the second digital key (non-friend key KN). The vehicle storage device 28 has already stored an authentication information unit AT for authenticating the new non-friend key KN as the authentication information unit AT for authenticating the third digital key (non-friend key KN).
[0329] The following describes a vehicle 20 in which an authentication information unit AT for authenticating a second digital key (non-friend key KN) and an authentication information unit AT for authenticating a third digital key (non-friend key KN) are stored in the vehicle storage device 28, and the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored. When the vehicle 20 receives a new authentication information unit AT, the vehicle 20 may select the authentication information unit AT for authenticating the new non-friend key KN that is already stored in the vehicle 20 as the authentication information unit AT to be deleted. Similarly, when the management server 70 receives a request to store a new authentication information unit AT in the vehicle 20, the management server 70 may transmit to the vehicle 20 a command to delete the authentication information unit AT that was needed to authenticate the new non-friend key KN that is already stored in the vehicle 20.
[0330] <Management System 10> The vehicle 20 does not need to have some of the BLE module 23, the UWB module 24, or the NFC module 25. As long as the vehicle 20 has at least one short-range communication module, it can perform short-range communication with the device 30. Furthermore, the vehicle 20 is not limited to having these communication modules, and it is sufficient if the vehicle 20 has a module that performs short-range communication with the device 30.
[0331] The vehicle management device 26 does not have to be an ECU that mainly processes digital keys. For example, the vehicle management device 26 may be a central ECU that manages multiple ECUs in the vehicle 20.
[0332] The vehicle management device 26 may be configured as a circuit having one or more processors that execute various processes according to a computer program (software) or program product. The vehicle management device 26 may be configured as a circuit having one or more dedicated hardware circuits, such as an application-specific integrated circuit (ASIC), or a combination thereof, that execute at least some of the various processes. The processor includes a CPU and memory such as RAM and ROM. The memory stores program code, programs, program products, or instructions that cause the CPU to execute various processes. The memory, i.e., a non-transitory computer-readable storage medium, includes any available medium that can be accessed by a general-purpose or dedicated computer. The same applies to the device 30 and the management server 70.
[0333] The device 30 is not limited to a smartphone. It may be a smartwatch. The device 30 may also be a predetermined server. In this case, the predetermined server may include the device 30. For example, if a rental business and / or a sharing business is the owner of the vehicle 20, the owner device 40 may be included in the predetermined server. For example, the friend device 51 may also be included in the predetermined server.
[0334] In each of the above embodiments, the multiple digital keys are arranged in a hierarchy from top to bottom, in the order of owner key KO, friend key KF, and non-friend key KN, with the higher the hierarchy, the greater the authority of the digital key. The higher the hierarchy, the greater the authority of the digital key. For example, the same authority may be set for the three hierarchies of owner key KO, friend key KF, and non-friend key KN.
[0335] The device server 60 does not have to be provided for each type of device 30. It is sufficient that multiple devices 30 and the management server 70 are capable of wireless communication. The device server 60 may be omitted. It is sufficient that multiple devices 30 and the management server 70 are capable of direct wireless communication.
[0336] The management server 70 may be configured with multiple servers. For example, the management server 70 may be configured with a server portion that stores the database DB and a server portion that executes a server program. Alternatively, for example, the management server 70 may be configured with a server portion that communicates with the vehicle 20 and a server portion that communicates with the device server 60, and these server portions may be able to communicate with each other.
[0337] The management server 70 does not need to store the database DB. The management server 70 only needs to manage, for at least one digital key in the management system 10, a combination of the key information DK of the device 30 and the authentication information unit AT of the vehicle management device 26.
[0338] The share device 50 has a function to receive the share key KS, as in the above embodiment. A device 30 having a function to receive a digital key, such as the share device 50, is sometimes called a receiver device.
[0339] <Various Information> The authentication information unit AT may be any information for authenticating the digital key when the digital key is used, and is not limited to the examples in the above embodiments. For example, the authentication information unit AT may be a common key shared by the vehicle management device 26 and the device 30. Also, for example, the authentication information unit AT may be a common secret key.
[0340] The information included in the key information DK is not limited to the configuration described in the above embodiment. For example, the owner key information DKO does not need to include the slot identification information ST4. Furthermore, the key information DK may include information indicating the type of digital key. The type of digital key is, for example, information indicating one of the owner key KO, friend key KF, and non-friend key KN.
[0341] The database DB may include information indicating the type of the device 30. The type of the device 30 is information indicating, for example, one of a smartphone, a smartwatch, a predetermined server as in the above-described modified example, and the like.
[0342] The structure of the data blocks DA in the database DB is not limited to the examples in the above embodiments. The database DB only needs to include information necessary for the management server 70 in the management system 10 to manage it.
[0343] <Processing for Registering a Digital Key> The processing for registering the owner key KO is not limited to the examples in the above embodiments. For example, even if pairing is not performed by the processing in step S12, the owner device 40 may store the owner key information DKO by transmitting and receiving information such as the generated data DC between the vehicle 20 and the first device 30A via the management server 70. The processing for registering the owner key KO may be modified as appropriate depending on the structure of the information included in the owner key information DKO and the structure of the information included in the authentication information unit AT.
[0344] The series of processes for registering the friend key KF is not limited to the examples in the above embodiments. For example, the management server 70 may update the database DB by processing in step S29 after transmitting the authentication package ATP and the storage request D24 to the vehicle 20. The series of processes for registering the friend key KF may be modified as appropriate depending on the structure of the information included in the friend key information DKF and the structure of the information included in the authentication information unit AT.
[0345] The series of processes for registering a non-friend key KN is not limited to the examples in the above embodiments. The order of the series of processes for registering a non-friend key KN may be different from the order of the series of processes for registering a friend key KF. The series of processes for registering a non-friend key KN may be changed as appropriate depending on the structure of the information included in the non-friend key information DKN and the structure of the information included in the authentication information unit AT.
[0346] The types of digital keys do not have to include the non-friend key KN. In other words, in the management system 10, the share key KS may only be the friend key KF. <Processing for Deleting a Digital Key> In each of the above embodiments, the friend device 51 sends a deletion reservation D41 to the management server 70 when deleting the non-friend key KN, but it does not have to be a reservation. In other words, the friend device 51 may send a request to delete the non-friend key KN to the management server 70 regardless of the default condition RC. Furthermore, the deletion request is not necessarily issued by the friend device 51; the management server 70 may proceed with the processing from step S62 onwards when the owner device 40 issues a request to delete the non-friend key KN.
[0347] The following describes a case where an operation to request deletion of the non-friend key KN is executed in the non-friend device 52. In this case, instead of the processing in step S81 of FIG. 9 , the non-friend device 52 may transmit a request to delete the non-friend key KN registered in the non-friend device 52 to the management server 70. Upon receiving the deletion request, the management server 70 generates a request to delete the non-friend key information DKN, similar to step S66 of FIG. 8 . Thereafter, the management server 70 transmits a request to delete the non-friend key information DKN to the non-friend device 52. The non-friend device 52 that has received the request to delete the non-friend key information DKN deletes the non-friend key information DKN, similar to step S67 of FIG. 8 . Thereafter, the non-friend device 52 transmits a notification to the management server 70 indicating that the non-friend key information DKN has been deleted. After receiving the notification indicating that the non-friend key information DKN has been deleted in the non-friend device 52, the management server 70 proceeds with the processing from step S82 onward shown in FIG. 9 . The non-friend device 52 does not need to send a notification indicating that the non-friend key information DKN has been deleted to the management server 70. In this case, the management server 70 transmits a request to delete the non-friend key information DKN to the non-friend device 52, and then proceeds with the processing from step S82 onwards shown in FIG.
[0348] - A deletion reservation may be requested from the management server 70 in either the case where a non-friend key KN is deleted due to operation of the friend device 51 or the case where a non-friend key KN is deleted due to operation of the non-friend device 52.
[0349] The owner device 40 and / or the vehicle 20 may request the deletion of the non-friend key KN. Alternatively, for example, the management server 70 may generate a deletion request for the non-friend key KN when a predetermined condition is satisfied.
Claims
1. A vehicle management device mounted on a vehicle, the vehicle management device comprising: a vehicle processing circuit; and a vehicle storage device configured to store one or more digital key information units, wherein the digital key information units are information units related to a digital key, and the vehicle storage device has a predetermined number of stored digital key information units that can be stored in the vehicle storage device; wherein the vehicle processing circuit is configured to delete any of the one or more digital key information units already stored in the vehicle storage device when a new digital key information unit is received when the number of stored digital key information units has reached the predetermined number.
2. The vehicle management device of claim 1, wherein one or more deletion reservations are commands to execute the deletion of the digital key information unit to be deleted when corresponding predetermined conditions are met, and the vehicle processing circuit is configured to delete the digital key information unit that is the subject of the unexecuted deletion reservation when a new digital key information unit is received when the stored number has reached the predetermined number and one or more deletion reservations remain unexecuted.
3. The vehicle management device of claim 1 or 2, wherein one or more deletion reservations are commands to execute the deletion of the digital key information unit to be deleted when corresponding predetermined conditions are met, and the vehicle processing circuit is configured to delete all of the digital key information units that are the subject of the remaining plurality of deletion reservations when a new digital key information unit is received when the stored number has reached the predetermined number and multiple deletion reservations remain unexecuted.
4. A vehicle management device as claimed in any one of claims 1 to 3, wherein the vehicle processing circuit is configured to allow the user of the vehicle to set priorities for one or more of the digital key information units already stored in the vehicle storage device, and when the number of stored digital key information units has reached the predetermined number and a new digital key information unit is received, the vehicle processing circuit is configured to select the digital key information unit to be deleted based on the set priorities.
5. A vehicle management device as claimed in any one of claims 1 to 4, wherein the vehicle processing circuit is configured to: determine that a digital key information unit to be protected has been selected from among the plurality of digital key information units already stored in the vehicle storage device; and, when a new digital key information unit is received, delete any of the plurality of digital key information units that have not been selected as the digital key information unit to be protected.
6. A vehicle management device as claimed in any one of claims 1 to 5, wherein the digital keys comprise a first digital key, a second digital key generated based on the first digital key, and a third digital key generated based on the second digital key, and wherein the vehicle processing circuit is configured such that the vehicle storage device stores the digital key information unit corresponding to the second digital key and the digital key information unit corresponding to the third digital key, and when a new digital key information unit is received when the number of stored digital key information units has reached the predetermined number, the vehicle processing circuit deletes the digital key information unit corresponding to the third digital key.
7. A vehicle management device as claimed in any one of claims 1 to 6, wherein when the vehicle processing circuit receives a new digital key information unit when the stored number has reached the predetermined number, it is configured to delete one or more of the digital key information units stored in the vehicle storage device based on another registration request from a device that has made a registration request corresponding to the newly received digital key information unit.
8. A management server including a server processing circuit configured to: receive a storage request to store one or more digital key information units as information units related to one or more digital keys in a vehicle in order to manage one or more digital keys; determine whether the number of stored digital key information units stored in the vehicle has reached a predetermined number of digital key information units that the vehicle can store; and, when the storage request is received for a vehicle for which the number of stored digital key information units has reached the predetermined number, send a command to the vehicle to delete one of the one or more digital key information units that the vehicle has stored.
9. The management server according to claim 8, wherein one or more deletion reservations are instructions to the vehicle to delete the corresponding digital key information units when a predetermined condition is met, and the server processing circuit is configured to: determine whether one or more of the deletion reservations remain unexecuted in the vehicle; and, when receiving the storage request for a vehicle for which the stored number has reached the predetermined number and one or more of the deletion reservations remain unexecuted, send to the vehicle a command to delete any of the one or more digital key information units that are the subject of the unexecuted deletion reservations.
10. The management server according to claim 8 or 9, wherein one or more deletion reservations are instructions to the vehicle to delete the corresponding digital key information units when a predetermined condition is met, and the server processing circuit is configured to: determine whether one or more deletion reservations remain unexecuted in the vehicle; and, when receiving the storage request for a vehicle for which the number of stored reservations has reached the predetermined number and multiple deletion reservations remain unexecuted, send to the vehicle a command to delete all of the digital key information units that are the subject of multiple deletion reservations.
11. The management server according to any one of claims 8 to 10, wherein the server processing circuit is configured to: identify one or more of the digital key information units already stored in the vehicle; identify the priority of the one or more of the digital key information units already stored in the vehicle, the priority being set by a user of the vehicle; and, when receiving a storage request for a vehicle whose stored number has reached the predetermined number, send to the vehicle a command to select a digital key information unit to be deleted based on the priority.
12. The management server according to any one of claims 8 to 11, wherein the server processing circuit is configured to: determine that a digital key information unit to be protected has been selected from among the plurality of digital key information units stored in the vehicle; and, when the storage request is received for the vehicle in which the number of one or more stored digital key information units has reached the predetermined number, send to the vehicle a command to delete one of the plurality of digital key information units that has not been selected as the target of protection.
13. The management server according to any one of claims 8 to 12, wherein the plurality of digital keys comprise a first digital key, a second digital key generated based on the first digital key, and a third digital key generated based on the second digital key, and the server processing circuit is configured to, when the storage request is received from a vehicle in which the digital key information unit corresponding to the second digital key and the digital key information unit corresponding to the third digital key have been stored and the number of stored digital key information units has reached the predetermined number, send to the vehicle a command to delete the digital key information unit corresponding to the third digital key stored in the vehicle.
14. The management server according to any one of claims 8 to 13, wherein the server processing circuit is configured to, when receiving a storage request for a vehicle for which the stored number has reached the predetermined number, send to the vehicle an instruction to delete one or more of the stored digital key information units based on another registration request from a device that has made a registration request corresponding to the digital key information unit corresponding to the storage request.
15. The management server according to any one of claims 8 to 14, wherein the plurality of digital keys include a first digital key, the first digital key being the only digital key that exists for the vehicle, and the server processing circuit is configured, when a command to delete one of the one or more digital key information units stored in the vehicle is transmitted to the vehicle, to send a digital key information unit corresponding to the first digital key to a device that has stored the digital key information unit, to notify the device that one of the one or more digital key information units stored in the vehicle will be deleted from the vehicle.
16. The management server according to any one of claims 8 to 15, wherein the server processing circuit is configured, when a command to delete one or more of the digital key information units stored in the vehicle is transmitted to the vehicle, to notify a device that has made a registration request corresponding to the digital key information unit to be deleted that the digital key information unit will be deleted.
17. The management server according to any one of claims 8 to 16, wherein the server processing circuit is configured, when a command to delete one or more of the digital key information units stored in the vehicle is transmitted to the vehicle, to notify a device that has stored a digital key information unit corresponding to the digital key information unit to be deleted that the digital key information unit will be deleted.
18. The management server according to any one of claims 8 to 17, wherein the server processing circuit is configured, when a command to delete all of the digital key information units that are the subject of multiple deletion reservations is transmitted to the vehicle, to notify multiple devices that have stored digital key information units corresponding to the multiple digital key information units that are the subject of multiple deletion reservations that the digital key information units that are the subject of the deletion reservations will be deleted.
19. A management system comprising: a vehicle management device mounted on a vehicle, the vehicle management device comprising a vehicle processing circuit and a vehicle storage device; and a management server comprising a server processing circuit for managing one or more digital keys, the vehicle storage device being configured to store one or more digital key information units, the one or more digital key information units being information units related to one or more digital keys, the vehicle storage device having a predetermined number of storable digital key information units, and at least one of the vehicle processing circuit and the server processing circuit being configured to delete one of the one or more digital key information units already stored in the vehicle storage device when a new digital key information unit is received when the number of digital key information units already stored in the vehicle storage device has reached the predetermined number.
Citation Information
Patent Citations
Device and method for managing document security
JP2001084175A
Communication system, communication terminal used therefor, authentication information management method, authentication information management program, and storage medium storing authentication information management program
JP2006031097A
Key device, lock control device, control program and control method
JP2011256561A
Locking / unlocking system, server and method
JP2018005353A