Entry system and entry authentication method
Patent Information
- Application Number
- PCT/JP2025/012955
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-28
- Publication Date
- 2026-10-01
Smart Images

Figure JP2025012955_01102026_PF_FP_ABST
Abstract
Description
Entry System and Entry Authentication Method
[0001] The present invention relates to an entry system and an entry authentication method.
[0002] In recent years, efforts have been activated to provide access to sustainable transportation systems that also take into account vulnerable people such as the elderly, people with disabilities, and children among traffic participants. To achieve this goal, efforts are focused on research and development to further improve the safety and convenience of traffic through development related to the boarding and alighting performance of vehicles.
[0003] Patent Document 1 discloses a technique in which when a moving object around a vehicle is detected in a low-resolution mode image by an on-vehicle imaging device that operates in a low-resolution mode and a high-resolution mode, a face image of the moving object is acquired in the high-resolution mode to perform authentication processing. Patent Document 2 discloses a technique for performing OTA (Over The Air) software update processing on an on-vehicle device using an update program received via wireless communication from outside the vehicle in a parking lot based on the permission of a vehicle user.
[0004] International Publication No. 2019 / 003826 Japanese Patent Application Laid-Open No. 2021-149701
[0005] Incidentally, regarding the boarding and alighting performance of vehicles, it is an issue to solve the inconvenience that while software update is being performed for an entry system that automatically locks and unlocks vehicle doors through user authentication, there occurs a period during which the user authentication cannot be performed and smooth boarding cannot be achieved.
[0006] In order to solve the above problem, the present application aims to enable smooth boarding of a vehicle and improve the convenience of the vehicle even during software update for an entry system that automatically locks and unlocks vehicle doors through user authentication, and ultimately contributes to the development of sustainable transportation systems.
[0007] One aspect of the present invention is an entry system comprising: a first authentication device that performs a first detection operation to detect a person in the vicinity of a vehicle as a target, and a first authentication operation to authenticate the target detected by the first detection operation; and a second authentication device that performs a second detection operation to detect a person in the vicinity of the vehicle as a target, and a second authentication operation to authenticate the target detected by the second detection operation, wherein the first authentication device performs a software update using update data provided wirelessly from outside the vehicle, and the second authentication device performs the second detection operation and the second authentication operation while the first authentication device is not performing the first detection operation and the first authentication operation in order to perform a software update. Another aspect of the present invention is an entry authentication method comprising: a first authentication step in which a first authentication device performs a first detection operation to detect a person in the vicinity of a vehicle as a target, and a first authentication operation to authenticate the target detected by the first detection operation; an update instruction step instructing the first authentication device to perform a software update using update data provided wirelessly from outside the vehicle; and an update step in which the first authentication device performs the software update instructed by the update instruction step, wherein in the update step, while the first authentication device does not perform the first detection operation and the first authentication operation to perform the software update, a second authentication device performs a second detection operation to detect a person in the vicinity of the vehicle as a target, and a second authentication operation to authenticate the target detected by the second detection operation.
[0008] According to the present invention, even when updating the software for the entry system, it is possible to improve the convenience of the vehicle by enabling smooth boarding.
[0009] Figure 1 is a diagram showing an example of the configuration of a vehicle equipped with an entry system according to one embodiment of the present invention. Figure 2 is a diagram showing the overall configuration of the entry system. Figure 3 is a diagram showing the configuration of the first camera device installed in the vehicle. Figure 4 is a diagram showing the configuration of the first authentication device and the second authentication device that constitute the entry system. Figure 5 is a diagram illustrating the detection operation of a person approaching the vehicle. Figure 6 is a flowchart showing the operation procedure in the entry system.
[0010] Embodiments of the present invention will be described below with reference to the drawings. [1. Overall configuration of the entry system] Figure 1 is a diagram showing the configuration of a vehicle 2 equipped with the entry system 1 of this embodiment. Figure 2 is a diagram showing the overall configuration of the entry system 1.
[0011] The entry system 1 comprises a first authentication device 3 and a second authentication device 4. In this embodiment, the first authentication device 3 and the second authentication device 4 are provided by an entry control device 5, which is an electronic control device. That is, in this embodiment, the first authentication device 3 and the second authentication device 4 are provided by the same electronic control device. Alternatively, the first authentication device 3 and the second authentication device 4 may be provided by separate electronic control devices.
[0012] The first authentication device 3 and the second authentication device 4, which constitute the entry system 1, automatically lock and unlock the vehicle doors 6 of the vehicle 2 based on user authentication. In this embodiment, the first authentication device 3 and the second authentication device 4 each authenticate a target person P, who is any person who intends to enter the vehicle 2, and if they can authenticate that the target person P has the right to use the vehicle 2, they unlock the vehicle doors 6, allowing the target person P to use the vehicle 2. Here, "entering" the vehicle 2 means at least getting into the vehicle 2 from outside the vehicle 2, and in addition to this, it may include turning on the power to the vehicle 2 after getting in, or otherwise transitioning the vehicle 2 to a state in which the target person P can use the vehicle 2.
[0013] In this embodiment, vehicle 2 is, for example, an electric vehicle, and it moves by operating a drive unit 15, which is a motor, using a battery 14 provided in vehicle 2. Vehicle 2 may also be, for example, a shared car that can be used by multiple people in turns.
[0014] Vehicle 2 includes an object sensor device 7 that detects objects around Vehicle 2, and a first camera device 8 and a second camera device 9 that capture images of the area around Vehicle 2.
[0015] In this embodiment, the vehicle 2 is equipped with an object sensor device 7, a first camera device 8, and a second camera device 9, which are located on the right side of the vehicle 2. The object sensor device 7a detects objects located to the right of the vehicle 2, and the first camera device 8a and second camera device 9a photograph the right side of the vehicle 2.
[0016] Furthermore, the left side of the vehicle 2 is equipped with an object sensor device 7b for detecting objects located to the left of the vehicle 2, and a first camera device 8b and a second camera device 9b for photographing the left side of the vehicle 2.
[0017] Furthermore, the rear of the vehicle 2 is equipped with an object sensor device 7c for detecting objects located behind the vehicle 2, and a first camera device 8c and a second camera device 9c for photographing the area behind the vehicle 2.
[0018] The object sensor device 7 may comprise a sensor body and a processing unit that processes the sensor signal output by the sensor body. The sensor body is, for example, a distance measuring sensor capable of detecting surrounding objects and measuring the distance to those objects, and in this embodiment, it is a millimeter-wave radar. The sensor body of the object sensor device 7 is not limited to radar, but can be any distance measuring sensor capable of object detection and distance measurement. Such sensors may include, for example, LiDAR or sonar, in addition to radar.
[0019] The first camera device 8 and the second camera device 9 may each comprise, for example, a camera body composed of CCD (Charge Coupled Device) cameras with different pixel counts, and a processing unit for controlling the operation of the camera body and processing the images captured by the camera body. The camera body of the second camera device 9 has a higher resolution and consumes more power than the camera body of the first camera device 8.
[0020] Vehicle 2 also includes an external control device 10 for an external person to instruct vehicle 2 to lock or unlock the vehicle door 6, and a door control device 11 for locking and unlocking the door lock of the vehicle door 6. The external control device 10 may be a touch sensor and / or touch switch provided on the door handle of the vehicle door 6 or on the pillar surrounding the vehicle door 6.
[0021] The door control device 11 controls the locking and unlocking of the vehicle door 6 and the actuator that opens and closes the vehicle door 6, thereby controlling the locking and unlocking and opening and closing operations of the vehicle door 6.
[0022] In this embodiment, the vehicle 2 includes external operating devices 10 and door control devices 11 provided on the vehicle doors 6: an external operating device 10a and door control device 11a provided on the driver's side door 6a on the right front of the vehicle 2, and an external operating device 10b and door control device 11b provided on the right rear passenger door 6b on the right rear of the vehicle 2. The vehicle 2 also includes an external operating device 10c and door control device 11c provided on the passenger side door 6c on the left front of the vehicle 2, and an external operating device 10d and door control device 11d provided on the left rear passenger door 6d on the left rear of the vehicle 2. The vehicle 2 further includes an external operating device 10e and door control device 11e provided on the back door (tailgate door) 6e of the vehicle 2.
[0023] Vehicle 2 is also equipped with a communication device 12. The communication device 12 is equipped with a transceiver for communicating wirelessly with an external OTA server 20 via an external communication network NW. The OTA server 20 manages software updates for the onboard electronic control devices of multiple pre-registered vehicles. New update data is registered to the OTA server 20 from the manufacturer of each vehicle, etc. If new update data for updating the software of the electronic control device installed in vehicle 2 is registered, the OTA server 20 transmits the update data to vehicle 2 upon request from vehicle 2.
[0024] Vehicle 2 may also be equipped with an interior camera 13 located at the front of the interior of Vehicle 2, which captures images of the interior of Vehicle 2. The interior camera 13 can capture images of the interior, including the face of the driver seated in the cockpit of Vehicle 2.
[0025] Vehicle 2 also includes a drive control device 16 that controls the operation of the drive unit 15. The drive control device 16 performs preparatory operations to operate the drive unit 15 when the start switch 17 of vehicle 2 is pressed, provided that it has received permission to operate from the first authentication device 3 or the second authentication device 4. These preparatory operations may include, for example, checking and initializing the status of the inverter (not shown), battery 14, and drive unit 15 of the drive control device 16, as well as starting the cooling system (not shown) for the drive unit 15 and the inverter, in accordance with the prior art. After the preparatory operations are completed, the drive control device 16 controls the operation of the drive unit 15 to drive vehicle 2 in accordance with driving operations performed by a control device such as an accelerator pedal (not shown), in accordance with the prior art.
[0026] Vehicle 2 also includes an update management device 18 having an update management unit 19. The update management unit 19 receives update data from an OTA server 20 outside of vehicle 2 via wireless communication through a communication network NW using a communication device 12, and instructs the electronic control unit of vehicle 2 to perform a software update using the update data. The update management unit 19 is a functional element or functional unit realized by a processor (not shown) in the update management device 18 executing a program.
[0027] The devices shown in Figure 2 are connected to each other via an in-vehicle communication cable 21, enabling them to communicate with one another. For example, each device can communicate via the communication cable 21 using CAN communication standards or Ethernet® communication.
[0028] Software updates for the electronic control unit using update data are performed according to prior art, for example, as follows. In the following description, it is assumed that the electronic control unit of vehicle 2 has a memory capacity that not only stores the current software in memory, but also stores new software provided by the update management unit 19 in that memory.
[0029] First, the update management unit 19 downloads update data from the OTA server 20. Specifically, at predetermined timings, such as when the vehicle 2's start switch 17 is turned on, it queries the OTA server 20 to see if new update data has been registered for any of the vehicle 2's electronic control devices. The OTA server 20 replies to the update management unit 19 with information regarding the presence or absence of update data for the vehicle 2's electronic control devices.
[0030] If the above reply from the OTA server 20 indicates that there is new update data, the update management unit 19 requests the OTA server 20 to send the update data. In response, the OTA server 20 sends the update data to the vehicle 2. The update data may include information about which electronic control device the update data pertains to. The update management unit 19 receives the update data sent from the OTA server 20 and stores it in a storage device (not shown) within the update management device 18.
[0031] Next, the update management unit 19 installs the new software included in the update data received from the OTA server 20 into the corresponding electronic control unit. That is, the update management unit 19 obtains the new software from the update data and transmits the obtained new software to the corresponding electronic control unit. The electronic control unit saves the new software in its memory according to the installation instructions from the update management unit 19. Note that the above download and installation can also be performed while the vehicle 2 is in motion.
[0032] Next, when the start switch 17 of the vehicle 2 is turned off, the update management unit 19 inquires with the user of the vehicle 2 whether or not to perform a software update of the electronic control unit. This inquiry may be sent to a touch panel (not shown) on the vehicle 2 or to the user's mobile terminal.
[0033] When the user responds to the above inquiry with permission to perform the software update, the update management unit 19 sends an activation instruction to the electronic control unit on which the new software is installed, instructing it to switch from the current software to the new software. Upon receiving the activation instruction, the electronic control unit executes the new software installed in its memory, performs initial setup and checks such as self-diagnosis, and then automatically performs a hardware reset. As a result, the software update of the electronic control unit is completed, and the next time the start switch 17 is turned on, the electronic control unit operates with the new software as the current software.
[0034] Furthermore, if the electronic control unit does not have sufficient storage capacity to store the new software in addition to the currently used software, the update management unit 19 may make the above inquiry before the installation and perform the installation on the electronic control unit only after receiving a response granting permission to run the software. The electronic control unit may then run the new software after the installation to perform a software update.
[0035] Hereafter, unless otherwise specified, "software update" refers to a software update using update data received from the OTA server 20.
[0036] In this embodiment, the update management unit 19, for example, instructs the first camera device 8 and the entry control device 5, which perform processing related to the entry of the vehicle 2, to perform a software update.
[0037] Furthermore, in this embodiment, the first authentication device 3 has the function of performing software updates based on update data received by the update management unit 19 from the OTA server 20. On the other hand, the second authentication device 4 does not have the function of performing software updates based on the above update data, and performs the detection and authentication operations for the target person P while the first authentication device 3 is not performing the detection and authentication operations for the target person P in order to execute the software update.
[0038] As a result, even while the software update of the first authentication device 3 is being performed due to a software update of the entry system 1 (in this embodiment, a software update of the entry control device 5), the second authentication device 4 can authenticate the registered user, the target person P. Therefore, the registered user can board the vehicle 2 smoothly, improving the convenience of the vehicle 2.
[0039] [2. Configuration of the First Camera Device] The first camera device 8 detects a person approaching the vehicle and notifies the first authentication device 3 of the person's approach. As described above, the camera body of the first camera device 8 consumes less power than the camera body of the second camera device 9. When the first authentication device 3 receives notification from the first camera device 8 that a person's approach has been detected, it activates the second camera device 9 to confirm the person approaching the vehicle 2 and detects that person as the subject P. As a result, the first authentication device 3 can detect the subject P early while suppressing the power consumption of the vehicle 2, and can complete the authentication of the subject P before the subject P reaches the immediate vicinity of the vehicle 2.
[0040] Figure 3 shows the configuration of the first camera device 8. The first camera devices 8a, 8b, and 8c all share the same configuration as shown in Figure 3. In this embodiment, the first camera device 8 has the function of performing software updates using update data in response to instructions from the update management unit 19.
[0041] The first camera device 8 comprises a processor 30, a memory 31, and a first camera body 32. The first camera body 32 is, for example, a CCD camera, which has a lower resolution and lower power consumption than the camera body of the second camera device 9.
[0042] The memory 31 is constituted of, for example, volatile and / or non-volatile semiconductor memory. The memory 31 stores active software 33 currently executed by the processor 30 and update control software 34. In the present embodiment, the memory 31 is further assumed to have a storage capacity capable of storing new-version software received from the update management unit 19.
[0043] The processor 30 is an arithmetic processing device such as a CPU. The processor 30 includes a common software unit 35. The common software unit 35 may include a BIOS (Basic Input / Output System), device drivers, and an OS (Operating System).
[0044] The processor 30 further includes, as application units operating on the common software unit 35, an approach detection unit 36, a preceding recognition unit 37, and a preceding determination unit 38. The common software unit 35, the approach detection unit 36, the preceding recognition unit 37, and the preceding determination unit 38 are functional elements or functional units implemented by the processor 30 executing programs included in the active software 33.
[0045] The update control software 34 is executed by the processor 30 when the first camera device 8 receives a new-version software installation instruction and an activation instruction from the update management unit 19. Accordingly, software update of the first camera device 8 based on update data provided from the OTA server 20 is performed. As an example, in the first camera device 8, software update for updating the common software unit 35 to a new version is executed by using the update data provided from the OTA server 20. The aforementioned software update of the first camera device 8 is executed, for example, at the same timing as the software update of the first authentication device 3 described later.
[0046] Hereinafter, operations of the approach detection unit 36, the preceding recognition unit 37, and the preceding determination unit 38 shown in FIG. 3 will be described with reference also to FIG. 6. FIG. 6 is an explanatory diagram for explaining an entry operation in the entry system 1 performed by using the first camera device 8 and the first authentication device 3.
[0047] The approach detection unit 36 detects a real object approaching the vehicle 2 by using the object sensor device 7 closest to the first camera device 8. As shown in FIG. 6, the approach detection unit 36 determines, for example, whether a real object has entered a range of distance D1 from the vehicle 2. The real object may be any object including living things and non-living things.
[0048] The preceding recognition unit 37 performs recognition processing on the real object detected by the approach detection unit 36, and determines whether the real object is a person. Specifically, when the approach detection unit 36 detects a real object, the preceding recognition unit 37 activates the first camera body 32, and continuously acquires first images of the surroundings of the vehicle 2 at predetermined time intervals by the activated first camera body 32. The preceding recognition unit 37 performs image recognition processing on the first images captured by the first camera device 8, and determines whether the real object is a person.
[0049] When the preceding recognition unit 37 determines that the real object is a person, the preceding determination unit 38 performs preceding intention determination on whether the person has an intention to get on the vehicle 2 prior to the start of operation of the first authentication device 3. Specifically, the preceding determination unit 38 determines, based on the first images continuously acquired by the first camera body 32 at predetermined time intervals, whether the person determined to be a person by the preceding recognition unit 37 is moving in a direction approaching the vehicle 2. Then, when the person is moving in a direction approaching the vehicle 2, it is determined that the person has an intention to get on the vehicle 2.
[0050] As shown in FIG. 6, the preceding determination unit 38 determines whether the person has an intention to get on the vehicle based on the behavior of the person until the person reaches a position at distance D2 from the vehicle 2, for example. The value of the distance D2 is predetermined. When the preceding determination unit 38 determines that the person has an intention to get on the vehicle, it sends a detection notification indicating that a person has been detected to the first authentication device 3. The preceding determination unit 38 may include detection position information, which is information on the moving direction and distance of the detected person, in the detection notification.
[0051] In the prior intent determination performed by the prior determination unit 38 regarding whether or not the person intends to board the vehicle, if the person merely passes by the vehicle 2 within the range from distance D1 to distance D2, no detection notification is sent to the first authentication device 3, thus suppressing unnecessary power consumption in the first authentication device 3.
[0052] In the above explanation, distances D1 and D2 do not need to be predetermined distances, and the detection of a real object by the proximity detection unit 36, the recognition of a person by the prior recognition unit 37, and the determination of the intention to board by the prior judgment unit 38 can be a series of processes. For example, distance D1 may be the maximum distance at which the object sensor device 7 can detect a real object. Distance D2 may be determined by distance D1, the movement speed of the real object (the person), the time required for the prior recognition unit 37 to recognize the person, and the time required for the prior judgment unit 38 to determine the person's intention to board.
[0053] [3. Configuration of the First and Second Authentication Devices] In this embodiment, both the first authentication device 3 and the second authentication device 4 are provided in an entry control device 5, which is a single electronic control device. In this embodiment, as an example, the first authentication device 3 and the second authentication device 4 are composed of different processor cores of the multicore processor provided in the entry control device 5.
[0054] Figure 4 shows the configuration of the first authentication device 3 and the second authentication device 4 provided in the entry control device 5. The entry control device 5 includes a multi-core processor 40, a first memory 41, a common memory 42, and a second memory 43. The first memory 41, the common memory 42, and the second memory 43 are composed of, for example, volatile and / or non-volatile semiconductor memories.
[0055] The multicore processor 40 comprises two processor cores: a first processor core 40a and a second processor core 40b. The first processor core 40a and the second processor core 40b of the multicore processor 40 perform processing independently of each other, but are communicated with each other via on-chip shared memory (not shown).
[0056] The first authentication device 3 is composed of a first processor core 40a, a first memory 41, and a common memory 42. The second authentication device 4 is composed of a second processor core 40b, a second memory 43, and a common memory 42. In other words, the first authentication device 3 is equipped with the first processor core 40a as its processor, and the second authentication device 4 is equipped with the second processor core 40b as its processor. Instead of a multi-core processor 40, the first authentication device 3 and the second authentication device 4 may each be composed of separate processors.
[0057] The common memory 42 is shared by the first authentication device 3 and the second authentication device 4, and is accessed by both the first processor core 40a and the second processor core 40b. The common memory 42 may be, for example, a dual-port memory having two ports, including an address bus and a data bus. The common memory 42 stores authentication data 44, which includes the facial images of one or more registered users who have been pre-registered as having legitimate authority to use the vehicle 2.
[0058] [3.1. Configuration of the First Authentication Device] As described above, the first authentication device 3 is composed of a first processor core 40a, a first memory 41, and a common memory 42. The first memory 41 stores the first active software 51 currently executed by the first processor core 40a and the update control software 52. In this embodiment, the first memory 41 also has a storage capacity that can store new software versions received from the update management unit 19.
[0059] The first processor core 40a has a common software unit 53. The common software unit 53 may include a BIOS, a device driver, and an OS.
[0060] The first processor core 40a also includes a first detection unit 54, a possession determination unit 55, an intent determination unit 56, a first authentication unit 57, and a registration unit 58, all of which are application units operating on the common software unit 53. The common software unit 53, the first detection unit 54, the possession determination unit 55, the intent determination unit 56, the first authentication unit 57, and the registration unit 58 are functional elements or functional units realized by the first processor core 40a executing programs included in the first active software 51.
[0061] The first detection unit 54 performs a first detection operation to detect people around the vehicle 2 as targets. Specifically, when the first detection unit 54 receives a detection notification from the first camera device 8, it activates the second camera device 9, which is closest to the first camera device 8, the source of the detection notification. The activated second camera device 9 acquires a second image, which is a high-definition image of the area around the vehicle 2, at predetermined time intervals and transmits it to the first authentication device 3. The first detection unit 54 performs image analysis of the second image and, when it can recognize a person around the vehicle 2, detects that person as a target P. Alternatively, if the detection notification from the first camera device 8 includes detection location information, the first detection unit 54 may narrow the range of analysis during the image analysis of the second image to the area around the location indicated by the detection location information to detect the target P.
[0062] The possession determination unit 55 performs image analysis of the second image and determines whether the subject P detected by the first detection unit 54 is holding luggage in their hand.
[0063] The intention determination unit 56 determines whether or not the subject P intends to board the vehicle 2 from the image of the subject P detected by the first detection unit 54 in the first detection operation. Specifically, the intention determination unit 56 determines whether or not the subject P intends to board the vehicle 2 based on the movement of the subject P recognized from a plurality of second images taken at predetermined time intervals. Referring to Figure 6, the intention determination unit 56 may determine that the subject P intends to board the vehicle 2 when, for example, the subject P approaches the vehicle 2 to a distance D3, the subject P stops at the distance D3, or the subject P reaches for the door handle of any of the vehicle doors 6 at the distance D3.
[0064] The first authentication unit 57 performs a first authentication operation to authenticate the subject P detected by the first detection operation of the first detection unit 54. In this embodiment, the first authentication unit 57 performs the first authentication operation when the intention determination unit 56 determines that the subject P has the intention to board. In this embodiment, the facial image of the subject P acquired from the second camera device 9 is used for the authentication of the subject P in the first authentication operation.
[0065] Specifically, the first authentication unit 57 extracts a high-resolution facial image of the subject P from the second image transmitted from the second camera device 9, and compares the extracted facial image of subject P with the facial image included in the authentication data 44 of the registered user recorded in the common memory 42. Based on the acquired facial image of subject P, the first authentication unit 57 authenticates that subject P is a registered user. The first authentication unit 57 also instructs the door control device 11 of the vehicle door 6 closest to subject P to unlock the door lock of that vehicle door 6, provided that the authentication of subject P is successful.
[0066] Here, the first authentication unit 57 can perform the first authentication operation in parallel with the intention determination unit 56. For example, as shown in the example in Figure 6, the first authentication unit 57 can operate to complete the authentication of the subject P at a distance D3 where the intention determination unit 56 completes its determination of whether or not the subject P intends to board the vehicle. As a result, the subject P can board the vehicle 2 smoothly.
[0067] The first authentication unit 57 may also, when the possession determination unit 55 determines that the subject P is carrying luggage, instruct the door control device 11 to unlock the vehicle door 6 and automatically open the vehicle door 6.
[0068] The first authentication unit 57 authenticates the person sitting in the driver's seat of the vehicle 2, and when it is authenticated that the driver's seat occupant is a registered user, it grants permission to operate the drive control device 16 that controls the drive unit 15. The driver's seat occupant's facial image can be obtained by the interior camera 13 located inside the vehicle 2. The registration unit 58 manages the authentication data 44 of the registered user.
[0069] In the above explanation, distance D3 does not have to be a predetermined distance, and the boarding intention determination process in the intention determination unit 56 and the authentication process in the first authentication unit 57 may be a series of processes that follow object detection and boarding intention determination in the first camera device 8. For example, distance D3 may be determined by the distances D1 and D2 described above, the speed of movement of the subject P, the time required for the intention determination unit 56 to determine the boarding intention of the subject P, and / or the time required for the first authentication unit 57 to authenticate the subject P.
[0070] In this embodiment, the first authentication device 3 can perform a software update using update data provided by the OTA server 20 via the update control software 52 stored in the first memory 41. The first processor core 40a executes the update control software 52 to perform the above-mentioned software update for the first authentication device 3 when the entry control device 5 receives an installation instruction and an activation instruction for the new version of the software from the update management unit 19. For example, in the first authentication device 3, the above-mentioned software update updates the functions of the common software unit 53, the first detection unit 54, the possession determination unit 55, the intention determination unit 56, the first authentication unit 57, or the registration unit 58.
[0071] When the software of the first authentication device 3 is updated, the first detection operation in the first detection unit 54 and the first authentication operation in the first authentication unit 57 are stopped. For this reason, when the first processor core 40a starts executing the update control software 52, it notifies the second processor core 40b, which constitutes the second authentication device 4, of the operation stop. Also, when the first processor core 40a starts executing the first active software 51, it notifies the second processor core 40b, which constitutes the second authentication device 4, of the operation start.
[0072] [3.2. Configuration of the Second Authentication Device] As described above, the second authentication device 4 is composed of a second processor core 40b, a second memory 43, and a common memory 42.
[0073] The second memory 43 stores the second active software 61 currently being executed by the second processor core 40b. In this embodiment, the second memory 43 does not store the update control software executed by the second processor core 40b. That is, the second authentication device 4 does not have the function to perform software updates using update data provided by the OTA server 20.
[0074] The second processor core 40b includes a second detection unit 62 and a second authentication unit 63 as functional elements or functional units. These functional elements of the second processor core 40b are realized by the second processor core 40b executing the second active software 61.
[0075] The second processor core 40b starts operating when it receives a notification of operation stoppage from the first processor core 40a, which constitutes the first authentication device 3. That is, the second authentication device 4 performs the second detection operation and the second authentication operation described later while the first authentication device 3 is not performing the first detection operation and the first authentication operation described above in order to perform a software update.
[0076] The second processor core 40b also stops operating after it has started operating when it receives a notification of operation start from the first processor core 40a, which constitutes the first authentication device 3.
[0077] Unlike the first authentication device 3, the second authentication device 4 does not perform advanced processing such as determining prior intent or identifying belongings using the first camera device 8. However, the second detection unit 62 and the second authentication unit 63 enable the subject P to board the vehicle 2 smoothly with simpler operation than the first authentication device 3.
[0078] The second detection unit 62 performs a second detection operation to detect a person around the vehicle 2 as a target person P. As a second detection operation, the second detection unit 62 detects a person operating an external control device 10 located outside the vehicle 2 as a target person P when the person operating the external control device 10 located outside the vehicle 2 is detected as such. As described above, the external control device 10 may be a touch sensor and / or touch switch located on the door handle of the vehicle door 6 or on a pillar around the vehicle door 6. This ensures that the second detection unit 62 reliably detects a target person P who intends to board the vehicle 2.
[0079] The second authentication unit 63 performs a second authentication operation to authenticate the subject P detected by the second detection operation. The second authentication unit 63 performs the second authentication operation using the face image of the subject P acquired from the second camera device 9, similar to the first authentication unit 57 of the first authentication device 3.
[0080] Specifically, the second authentication unit 63 activates the second camera device 9 that is closest to the external control unit 10 used to detect the subject P in the second detection operation described above. The activated second camera device 9 acquires a second image, which is a high-definition image of the area around the vehicle 2, at predetermined time intervals and transmits it to the second authentication device 4.
[0081] The second authentication unit 63 extracts a high-resolution facial image of subject P from the second image transmitted from the second camera device 9, and compares the extracted facial image of subject P with the facial image included in the authentication data 44 of registered users recorded in the common memory 42. Based on the acquired facial image of subject P, the second authentication unit 63 authenticates that subject P is a registered user.
[0082] The second authentication unit 63 also, on the condition that the authentication of the subject P is successful, instructs the door control device 11 of the vehicle door 6 closest to the external control device 10 operated by the subject P to unlock the door lock of that vehicle door 6. This allows the subject P to board the vehicle 2 smoothly.
[0083] Furthermore, in the second authentication operation, when the second authentication unit 63 determines that the subject P detected by the second detection operation in the second detection unit 62 is a registered user, that is, when authentication of subject P is successful, it issues an instruction to the drive control device 16 to prohibit operation. This prevents the start switch 17 from being operated and the vehicle 2 from mistakenly starting to drive while the second authentication device 4 is operating, that is, while the software of the first authentication device 3 is being updated.
[0084] [3. Operation of the Entry System] Next, the procedure for the operation of the entry system 1 will be described. Figure 5 is a flowchart showing the procedure for the entry authentication method executed by the entry system 1 when performing a software update for the first authentication device 3 using update data provided by the OTA server 20. The process shown in Figure 5 starts when the start switch 17 of the vehicle 2 is turned off, after the update management device 18 has finished installing the new version of the software included in the update data downloaded from the OTA server 20 to the first authentication device 3, and before the activation of the new version of the software has been performed.
[0085] When processing begins, the update management unit 19 of the update management device 18 first inquires with the user of the vehicle 2 whether or not to perform a software update on the first authentication device 3 (S100). This inquiry can be made via the touch panel (not shown) on the vehicle 2 or via the user's mobile terminal. The update management unit 19 determines whether or not permission to perform the software update has been received within a predetermined time after making the inquiry (S102). If the update management unit 19 does not receive permission to perform the software update within the predetermined time (S102, NO), the first authentication device 3 continues the first detection operation and first authentication operation described above (S104) and terminates this process. In this case, since the new software installed on the first authentication device 3 has not been activated, this process starts again when the start switch 17 of the vehicle 2 is turned off afterward.
[0086] On the other hand, if permission to perform the software update is received within a predetermined time in step S102 (S102, YES), the update management unit 19 instructs the first authentication device 3 to perform the software update (S106). In this embodiment, the instruction to perform the software update is an instruction to activate the new version of the software already installed on the first authentication device 3.
[0087] Next, the first authentication device 3 notifies the second authentication device 4 of the shutdown (S108). In this embodiment, the shutdown notification is made from the first processor core 40a constituting the first authentication device 3 to the second processor core 40b constituting the second authentication device 4.
[0088] Next, the first authentication device 3 performs a software update using the new software version (S110). The second authentication device 4 starts operating in response to receiving a notification of operation stoppage from the first authentication device 3 (S112). After starting operation, the second detection unit 62 of the second authentication device 4 performs a second detection operation, and the second authentication unit 63 performs a second authentication operation (S114).
[0089] Next, the second authentication device 4 determines whether the software update of the first authentication device 3 is complete (S116). The second authentication device 4 can determine that the software update of the first authentication device 3 is complete when it receives a notification of operation start from the first authentication device 3. In this embodiment, the notification of operation start is made from the first processor core 40a constituting the first authentication device 3 to the second processor core 40b constituting the second authentication device 4.
[0090] If the software update of the first authentication device 3 is not completed in step S116 (S116, NO), the second authentication device 4 returns to step S114 and repeats the process. On the other hand, if the software update of the first authentication device 3 is completed (S116, YES), the second authentication device 4 stops operating (S118). At the same time, the first authentication device 3 starts the first detection operation and the first authentication operation (S120) and terminates this process. After the termination of this process, the first authentication device 3 continues the first detection operation and the first authentication operation. In this case, since the new software installed on the first authentication device 3 has completed activation and is the first active software 51, this process does not start even if the vehicle 2's start switch 17 is turned off afterward.
[0091] In Figure 5, steps S104 and S122 correspond to the first authentication step in this disclosure. Step S106 corresponds to the update instruction step in this disclosure. Furthermore, the processing from steps S110 to S116 corresponds to the update step in this disclosure.
[0092] [4. Other Embodiments] In the embodiments described above, the memory 31 of the first camera device 8 and the first memory 41 of the first authentication device 3 each have a storage capacity capable of storing the new version software in addition to the current software 33 and the first current software 51. Alternatively, the memory 31 of the first camera device 8 and the first memory 41 of the first authentication device 3 may not have a storage capacity capable of storing the new version software while the respective current software is being stored. In this case, when the start switch 17 of the vehicle 2 is turned off and permission to perform a software update is received from the user of the vehicle 2, the update management unit 19 can install the new version software on the first camera device 8 and the first authentication device 3, respectively, and instruct them to perform the software update.
[0093] In the embodiment described above, the second authentication device 4 does not have a function to perform software updates using update data provided by the OTA server 20. However, the second authentication device 4 may be updated by reprogramming, for example, during maintenance work at a dealer of the vehicle 2. For example, the second authentication device 4 may perform software updates by reprogramming in accordance with instructions given from an external device via a data link connector (DLC, Data Link Connector) (not shown) provided on the communication cable 21 of the vehicle 2.
[0094] In the above-described embodiment, the first camera device 8 is provided with a proximity detection unit 36, a prior recognition unit 37, and a prior determination unit 38. Alternatively, the first authentication device 3 may be provided with a proximity detection unit 36, a prior recognition unit 37, and a prior determination unit 38.
[0095] It should be noted that the present invention is not limited to the configuration of the embodiments described above, and can be implemented in various forms without departing from the spirit of the invention.
[0096] [5. Configurations Supported by the Above Embodiments] The above embodiments support the following configurations.
[0097] (Configuration 1) An entry system comprising: a first authentication device that performs a first detection operation to detect a person in the vicinity of a vehicle as a target, and a first authentication operation to authenticate the target person detected by the first detection operation; and a second authentication device that performs a second detection operation to detect a person in the vicinity of the vehicle as a target, and a second authentication operation to authenticate the target person detected by the second detection operation, wherein the first authentication device performs software updates using update data provided wirelessly from outside the vehicle, and the second authentication device performs the second detection operation and the second authentication operation while the first authentication device is not performing the first detection operation and the first authentication operation in order to perform a software update. According to Configuration 1, even when the software update of the first authentication device is being performed, the second authentication device can detect and authenticate the target person, thereby enabling the target person to board the vehicle smoothly and improving the convenience of the vehicle.
[0098] (Configuration 2) The entry system described in Configuration 1, wherein the first authentication device and the second authentication device are provided in the same electronic control unit. According to Configuration 2, the first authentication device and the second authentication device can use shared resources such as power supply circuits and memory in common within the same electronic control unit, so the overall size of the device including the first authentication device and the second authentication device can be reduced.
[0099] (Configuration 3) The entry system according to Configuration 2, wherein the first authentication device and the second authentication device are each composed of separate processors provided in the same electronic control unit. According to Configuration 3, the second authentication device can be easily realized within the same electronic control unit as an independent device that is not affected by software updates in the first authentication device.
[0100] (Configuration 4) The entry system according to Configuration 2, wherein the first authentication device and the second authentication device are each composed of separate processor cores of a multicore processor provided in the same electronic control unit. According to Configuration 4, the overall size of the first authentication device and the second authentication device can be further reduced.
[0101] (Configuration 5) The entry system according to Configuration 1, wherein the first authentication device and the second authentication device are each separate electronic control devices. According to Configuration 5, the first authentication device and the second authentication device mounted on the vehicle can be individually replaced, thereby facilitating maintenance of the vehicle 2.
[0102] (Configuration 6) The entry system according to any one of Configurations 1 to 5, wherein the first authentication device comprises a first detection unit that performs the first detection operation, an intention determination unit that determines whether or not the subject intends to board the vehicle from the image of the subject detected by the first detection operation, and a first authentication unit that performs the first authentication operation when it is determined that the subject intends to board, and the functions of the first detection unit, the intention determination unit, or the first authentication unit are updated by the software update. According to Configuration 6, the updates of various functions in the first authentication device can be performed by OTA.
[0103] (Configuration 7) The entry system according to any one of Configurations 1 to 6, wherein the second authentication device detects the person who operated the external control device located outside the vehicle as the target person when the person operating the external control device located outside the vehicle is the second detection operation. According to Configuration 7, the second authentication device can reliably detect a target person who intends to board the vehicle without performing complex processing.
[0104] (Configuration 8) An entry system according to any one of Configurations 1 to 7, wherein the first authentication device grants permission to operate to the drive control device that controls the vehicle's drive system when it can authenticate that the person sitting in the driver's seat of the vehicle is a registered user from a facial image of the person sitting in the driver's seat of the vehicle acquired by an interior camera installed in the vehicle's cabin, and the second authentication device gives an instruction to the drive control device to prohibit operation when it succeeds in authenticating the person detected by the second detection operation in the second authentication operation. According to Configuration 8, it is possible to prevent the vehicle from being accidentally started to drive while the software of the first authentication device is being updated.
[0105] (Configuration 9) An entry system according to any one of Configurations 1 to 8, wherein the first authentication device and the second authentication device each perform the first authentication operation and the second authentication operation using a facial image of the subject obtained from a camera installed in the vehicle. According to Configuration 9, since it is possible to capture a subject approaching the vehicle from a distance and authenticate the subject based on an image obtained from an on-board camera, the processing in the first authentication device and the second authentication device can be made easier.
[0106] (Configuration 10) An entry authentication method comprising: a first authentication step in which a first authentication device performs a first detection operation to detect a person in the vicinity of a vehicle as a target, and a first authentication operation to authenticate the target person detected by the first detection operation; an update instruction step instructing the first authentication device to perform a software update using update data provided wirelessly from outside the vehicle; and an update step in which the first authentication device performs the software update instructed by the update instruction step, wherein in the update step, while the first authentication device does not perform the first detection operation and the first authentication operation to perform the software update, the second authentication device performs a second detection operation to detect a person in the vicinity of the vehicle as a target, and a second authentication operation to authenticate the target person detected by the second detection operation. Configuration 10 provides the same effects as Configuration 1.
[0107] 1...Entry system, 2...Vehicle, 3...First authentication device, 4...Second authentication device, 5...Entry control device, 6...Vehicle door, 6a...Driver's side door, 6b...Right rear passenger door, 6c...Passenger side door, 6d...Left rear passenger door, 6e...Back door, 7, 7a, 7b, 7c...Object sensor device, 8, 8a, 8b, 8c...First camera device, 9, 9a, 9b, 9c...Second camera device, 10, 10a, 10b, 10c, 10d, 10e...External control device, 11, 11a, 11b, 11c, 11d, 11e...Door control device, 12...Communication device, 13...Interior camera, 14...Battery, 15...Drive device, 16...Drive control device, 17...Start switch, 18...Update management device, 19...Update management unit, 20 ...OTA server, 21...communication cable, 30...processor, 31...memory, 32...first camera body, 33...current software, 34, 52...update control software, 35, 53...common software unit, 36...proximity detection unit, 37...pre-recognition unit, 38...pre-determination unit, 40...multicore processor, 40a...first processor core, 40b...second processor core, 41...first memory, 42...common memory, 43...second memory, 44...authentication data, 51...first current software, 54...first detection unit, 55...possession determination unit, 56...intention determination unit, 57...first authentication unit, 58...registration unit, 61...second current software, 62...second detection unit, 63...second authentication unit, P...target person.
Claims
1. An entry system comprising: a first authentication device that performs a first detection operation to detect a person in the vicinity of a vehicle as a target, and a first authentication operation to authenticate the target detected by the first detection operation; and a second authentication device that performs a second detection operation to detect a person in the vicinity of the vehicle as a target, and a second authentication operation to authenticate the target detected by the second detection operation, wherein the first authentication device performs a software update using update data provided wirelessly from outside the vehicle, and the second authentication device performs the second detection operation and the second authentication operation while the first authentication device is not performing the first detection operation and the first authentication operation in order to perform a software update.
2. The entry system according to claim 1, wherein the first authentication device and the second authentication device are provided in the same electronic control unit.
3. The entry system according to claim 2, wherein the first authentication device and the second authentication device are each composed of separate processors provided in the same electronic control unit.
4. The entry system according to claim 2, wherein the first authentication device and the second authentication device are each composed of separate processor cores of a multicore processor provided in the same electronic control unit.
5. The entry system according to claim 1, wherein the first authentication device and the second authentication device are each separate electronic control devices.
6. The entry system according to claim 1, wherein the first authentication device comprises: a first detection unit that performs the first detection operation; an intention determination unit that determines whether or not the subject intends to board the vehicle from the image of the subject detected by the first detection operation; and a first authentication unit that performs the first authentication operation when it is determined that the subject intends to board the vehicle, and the functions of the first detection unit, the intention determination unit, or the first authentication unit are updated by the software update.
7. The entry system according to claim 1, wherein the second authentication device, as the second detection operation, detects the person who operated the external control device provided outside the vehicle as the target when the person in the vicinity of the vehicle operates the external control device provided outside the vehicle.
8. The entry system according to claim 1, wherein the first authentication device grants permission to operate to a drive control device that controls the vehicle's drive system when it can authenticate that the person sitting in the driver's seat of the vehicle is a registered user from a facial image of the person sitting in the driver's seat of the vehicle acquired by an interior camera installed in the vehicle's interior, and the second authentication device gives an instruction to the drive control device to prohibit operation when it succeeds in authenticating the person detected by the second detection operation in the second authentication operation.
9. The entry system according to any one of claims 1 to 8, wherein the first authentication device and the second authentication device each perform the first authentication operation and the second authentication operation using the facial image of the subject obtained from a camera installed in the vehicle.
10. An entry authentication method comprising: a first authentication step in which a first authentication device performs a first detection operation to detect a person in the vicinity of a vehicle as a target, and a first authentication operation to authenticate the target person detected by the first detection operation; an update instruction step instructing the first authentication device to perform a software update using update data provided wirelessly from outside the vehicle; and an update step in which the first authentication device performs the software update instructed by the update instruction step, wherein in the update step, while the first authentication device is not performing the first detection operation and the first authentication operation to perform the software update, a second authentication device performs a second detection operation to detect a person in the vicinity of the vehicle as a target, and a second authentication operation to authenticate the target person detected by the second detection operation.