WO2019098020A1 - Car sharing system - Google Patents

Car sharing system Download PDF

Info

Publication number
WO2019098020A1
WO2019098020A1 PCT/JP2018/040404 JP2018040404W WO2019098020A1 WO 2019098020 A1 WO2019098020 A1 WO 2019098020A1 JP 2018040404 W JP2018040404 W JP 2018040404W WO 2019098020 A1 WO2019098020 A1 WO 2019098020A1
Authority
WO
WIPO (PCT)
Prior art keywords
vehicle
mode
share
car
key
Prior art date
Application number
PCT/JP2018/040404
Other languages
French (fr)
Japanese (ja)
Inventor
将宏 荒川
雅彦 大矢
雄一 稲波
穣 久保
Original Assignee
株式会社東海理化電機製作所
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 株式会社東海理化電機製作所 filed Critical 株式会社東海理化電機製作所
Publication of WO2019098020A1 publication Critical patent/WO2019098020A1/en

Links

Images

Classifications

    • BPERFORMING OPERATIONS; TRANSPORTING
    • B60VEHICLES IN GENERAL
    • B60RVEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
    • B60R25/00Fittings or systems for preventing or indicating unauthorised use or theft of vehicles
    • B60R25/20Means to switch the anti-theft system on or off
    • B60R25/24Means to switch the anti-theft system on or off using electronic identifiers containing a code not memorised by the user
    • EFIXED CONSTRUCTIONS
    • E05LOCKS; KEYS; WINDOW OR DOOR FITTINGS; SAFES
    • E05BLOCKS; ACCESSORIES THEREFOR; HANDCUFFS
    • E05B49/00Electric permutation locks; Circuits therefor ; Mechanical aspects of electronic locks; Mechanical keys therefor
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q30/00Commerce
    • G06Q30/06Buying, selling or leasing transactions
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q50/00Information and communication technology [ICT] specially adapted for implementation of business processes of specific business sectors, e.g. utilities or tourism
    • G06Q50/10Services

Definitions

  • the present invention relates to a car sharing system in which a plurality of people share one vehicle.
  • the valet parking service when using the valet parking service with a share vehicle, it is necessary to pass the vehicle key of the share vehicle to a third party such as a valet, but at this time, the portable terminal is lent to the third party as a vehicle key It is not realistic. However, there is a cost if the vehicle is always equipped with a dedicated bullet key taking into consideration the use of the valet parking service.
  • An object of the present invention is to provide a car sharing system capable of lending a shared vehicle without using a dedicated bullet key.
  • a car sharing system includes an operation terminal for a share vehicle operable as a vehicle key that operates on-vehicle equipment through an electronic key system, and a car share device capable of wirelessly communicating with a portable terminal operable as the vehicle key. Equipped with The car sharing apparatus authenticates key information through wireless communication with the portable terminal, and operates the in-vehicle device through the electronic key system according to an operation of the portable terminal having the authenticated key information. The car sharing system further operates the operation mode of the share vehicle by the portable terminal of the car share user when the share vehicle is used by a car share user other than the owner of the share vehicle. And a mode switching unit for changing the valid state and the invalid state of the mode to a switchable mode.
  • the mobile terminal of the car share user can switch the operation terminal of the share vehicle from the invalid state to the valid state.
  • the car share user can use the valet parking service by handing the operation terminal, which originally exists in the share vehicle, to a third party such as a valet, instead of the portable terminal of the car share user.
  • sharing vehicles can be lent without using a dedicated bullet key.
  • the car sharing apparatus may be capable of wirelessly communicating with a plurality of portable terminals operable as the vehicle key.
  • the plurality of mobile terminals may include a first mobile terminal used by the owner of the share vehicle, and a second mobile terminal used by the car share user.
  • the mode switching unit is configured to The mode may be changed to a mode in which the second mobile terminal can switch between the valid state and the invalid state of the operation terminal.
  • the operation mode of the share vehicle can not be changed unless the owner of the share vehicle using the first portable terminal permits the change of the operation mode. Therefore, the operation terminal is operated by the second portable terminal of the car share user You can not switch between the enabled and disabled states of. Therefore, the operating mode can be prevented from being tampered with, and security can be improved.
  • the mode switching unit may set the operation terminal to an invalid state as an initial state when the share vehicle is used by the car share user.
  • the mode switching unit is configured to operate the operation terminal when the portable terminal of the car share user is operated through wireless communication between the portable terminal of the car share user and the car share apparatus. Can be switched from the disabled state to the enabled state.
  • the operation mode of the share vehicle is changed by the car share user's portable terminal to a mode capable of switching between the enabled state and the disabled state of the operating terminal, the operating mode is switched to the disabled state without forgetting the operating terminal It becomes possible to set.
  • the mode switching unit can use a normal mode in which each of the operation terminal and the first mobile terminal can be used as the vehicle key, and can use the second mobile terminal as the vehicle key.
  • the operation mode may be switchable with the first share mode in which the operation terminal is in an invalid state. Further, the mode switching unit uses the first share mode, the operation terminal, and the second portable terminal as the vehicle key after the operation mode is changed from the normal mode to the first share mode.
  • the operation mode may be switchable between an available second share mode.
  • the mode switching unit is configured to use the normal mode suitable for the use of the car share vehicle by the owner, the first share mode suitable for the use of the car share vehicle by the car share user other than the owner, and the use of the car share
  • One of the second share modes suitable for the user to use the valet parking service can be set as an operation mode suitable for each use situation of the share vehicle.
  • the operation terminal may be one of a plurality of operation terminals of the share vehicle.
  • the electronic key system may include a verification device capable of communicating with each of the plurality of operation terminals and the car sharing device.
  • the mode switching unit is capable of switching the operation mode among a plurality of operation modes, and setting any one of the plurality of operation terminals and the car sharing device as a device to communicate with the verification device in each operation mode By doing this, any one of the plurality of operation terminals and the portable terminal can be used as the vehicle key in each operation mode. According to this configuration, only one device needs to be operated in each operation mode of the share vehicle, which is advantageous for reducing the power consumption of each device.
  • a shared vehicle can be lent out without using a dedicated bullet key.
  • FIG. 6 is a communication sequence diagram when operating the on-vehicle device by operating the mobile terminal. State diagram of each operation mode of the shared vehicle. State diagram of each operation mode of the shared vehicle. Sequence diagram of on / off switching in car sharing mode. The sequence diagram of on-off switching of valet parking mode. The state diagram of each operation mode of the share vehicle of 2nd Embodiment. Communication sequence diagram of smart verification. The specification figure which put together the command in each operation mode, and the device response with respect to each command.
  • the vehicle 1 is provided with an electronic key system 4.
  • the electronic key system 4 includes a verification ECU (Electronic Control Unit) 9 that performs ID verification of the electronic key 2 through wireless communication with the electronic key 2.
  • the collation ECU 9 is an example of a collation device.
  • the verification ECU 9 executes or permits the operation of the in-vehicle device 3 based on the establishment of the electronic key ID verification.
  • electronic key ID collation also referred to as smart collation
  • the on-vehicle device 3 may include, but is not limited to, the door lock device 5 and the engine 6, for example.
  • the electronic key 2 is an example of the operation terminal 2 a originally prepared as a vehicle key dedicated to the vehicle 1.
  • the vehicle 1 is provided with a verification ECU 9, a body ECU 10 that manages the power supply of in-vehicle electrical components, and an engine ECU 11 that controls the engine 6.
  • Each of the body ECU 10 and the engine ECU 11 is also called an in-vehicle device ECU.
  • the ECUs 9 to 11 are electrically connected to each other via a communication line 12 in the vehicle 1.
  • the communication line 12 is, for example, a controller area network (CAN), a local interconnect network (LIN), or a combination thereof.
  • Each of the verification ECU 9 and the electronic key 2 includes a memory (not shown), and the memory stores an electronic key ID and an electronic key specific encryption key.
  • the electronic key ID and the electronic key unique encryption key are information unique to the electronic key 2 registered in the vehicle 1 and are used for electronic key ID verification.
  • the body ECU 10 controls a door lock device 5 that switches locking and unlocking of the vehicle door 13.
  • the electronic key system 4 further includes a radio wave transmitter 16 and a radio wave receiver 17 provided in the vehicle 1.
  • the radio wave transmitter 16 may include an outdoor transmitter that transmits radio waves outdoors, and an indoor transmitter that transmits radio waves indoors.
  • the radio wave transmitter 16 transmits radio waves in the LF (Low Frequency) band.
  • the radio receiver 17 receives radio waves in the UHF (Ultra High Frequency) band. Therefore, in the electronic key system 4, the verification ECU 9 communicates with the electronic key 2 by the two-way communication of LF-UHF.
  • the verification ECU 9 executes ID verification (smart verification) of the electronic key 2.
  • ID verification smart verification
  • electronic key ID verification for authenticating the electronic key 2 and challenge response authentication using an electronic key unique encryption key may be performed.
  • the electronic key ID verification performed under the situation where the electronic key 2 is outside the vehicle 1 may be called outdoor smart verification.
  • the verification ECU 9 permits or executes the locking and unlocking of the vehicle door 13 via the body ECU 10.
  • the verification ECU 9 permits the power supply transition operation according to the operation of the engine switch 18. For example, when the engine switch 18 is operated in a state where the brake pedal is depressed, the verification ECU 9 starts the engine 6 via the engine ECU 11.
  • the vehicle 1 is provided with a car sharing system 21 which shares the vehicle 1 with a plurality of people.
  • the car sharing system 21 includes a car share device 23 mounted on the vehicle 1.
  • the car share device 23 can execute verification of the electronic key ID used in the electronic key system 4 provided in the vehicle 1. Further, the car share device 23 can wirelessly communicate with the portable terminal 22.
  • encrypted key information Dk acquired from an external device such as the server 20 is registered.
  • the car share device 23 acquires key information Dk from the portable terminal 22 and authenticates the key information Dk.
  • the car share device 23 has an encryption key (car share device unique encryption key) that can decrypt the key information Dk, and decrypts the key information Dk using the encryption key.
  • the key information Dk is authenticated. After the authentication of the key information Dk is established, the portable terminal 22 can transmit an operation request for requesting the operation of the in-vehicle device 3 to the car share device 23.
  • the mobile terminal 22 can be, for example, a high-performance mobile phone such as a smartphone.
  • the key information Dk is preferably, for example, a one-time key (one-time password) whose use is permitted only once.
  • the car share device 23 is independent of the hardware configuration of the electronic key system 4 and can be retrofitted to the vehicle 1.
  • the car share device 23 is, for example, positioning of an electronic key (vehicle key) that is enabled only within the reserved time of the vehicle 1 and is treated the same as the spare key.
  • the car sharing device 23 cooperates with the portable terminal 22 so that the portable terminal 22 can operate as a vehicle key replacing the electronic key 2.
  • the car share device 23 has a key function (electronic key function) switched between the enabled state and the disabled state.
  • the key function of the car sharing device 23 When the key function of the car sharing device 23 is activated, it looks as if an electronic key appeared in the vehicle 1, while when the key function is invalidated, it seems as if the electronic key has disappeared from the vehicle 1 It looks like
  • the car share device 23 is supplied with power from the battery + B of the vehicle 1.
  • the portable terminal 22 includes a terminal control unit 26 that controls the operation of the portable terminal 22, and a network communication module 27 for performing network communication between the portable terminal 22 and an external device such as a server, A short distance wireless communication module 28 for performing short distance wireless communication between the portable terminal 22 and the car sharing device 23 and a memory 29 capable of rewriting data are provided.
  • the portable terminal 22 acquires key information Dk from the server 20 through the network communication module 27 and writes the key information Dk in the memory 29.
  • the near field communication is, for example, Bluetooth (registered trademark), preferably Bluetooth (registered trademark) Low Energy (BLE).
  • the mobile terminal 22 comprises a user interface (UI) application 30 that manages the operation of the car sharing system 21.
  • the UI application 30 is installed in the terminal control unit 26 by being downloaded from the server 20, for example.
  • the memory 29 of the portable terminal 22 has a user authentication key used when the portable terminal 22 communicates with the car share device 23 of the vehicle 1 and operates the on-vehicle device 3 by operating the portable terminal 22. be registered.
  • the user authentication key can be, for example, a random number whose value changes each time it is generated.
  • the user authentication key may be registered in advance in the car sharing system 21 or may be generated and registered when the vehicle 1 is used.
  • the car share device 23 performs smart communication (short range wireless communication) between the controller 33 that controls the operation of the car share device 23 and the car share device 23 and the electronic key system 4 (collation ECU 9) Communication block 34 for performing communication, a near field wireless module 35 for performing near field communication between the car share device 23 and the portable terminal 22, a memory 36 capable of rewriting data, and the car share device 23 And a timer unit 37 that manages the date and time.
  • the memory 36 stores a car sharing device ID, a car sharing device unique encryption key, an electronic key ID, and an electronic key unique encryption key.
  • the car share device ID and the car share device unique encryption key are information unique to the car share device 23.
  • the car share device unique encryption key is used for cryptographic communication between the portable terminal 22 and the car share device 23.
  • the portable terminal 22 can obtain, from the server 20, key information Dk encrypted by the car sharing device unique encryption key. Then, the car sharing device unique encryption key may be used to transmit the key information Dk from the portable terminal 22 to the car sharing device 23.
  • the electronic key ID and the electronic key unique encryption key are used for electronic key ID verification (in this example, smart verification) through the electronic key system 4 as described above.
  • the timer unit 37 includes, for example, a soft timer.
  • the car share device 23 is associated with the vehicle 1 on a one-on-one basis, for example, by associating the car share device ID with the vehicle ID (body number).
  • the car share device 23 is a key function unit that executes electronic key ID collation (in this example, smart collation) between the car share device 23 and the electronic key system 4 (collation ECU 9) through smart communication by the smart communication block 34. It has 38.
  • the key function unit 38 is provided in the controller 33.
  • the car share device 23 includes one or more processors and a memory storing one or more instructions, and causes the controller 33 to operate as the key function unit 38 by executing the instructions.
  • the key function unit 38 may be implemented by a dedicated circuit.
  • the key function unit 38 acquires key information Dk from the portable terminal 22 and authenticates the key information Dk.
  • the key function unit 38 can execute electronic key ID collation through smart communication with the collation ECU 9.
  • the key function unit 38 is similar to the electronic key ID collation performed between the electronic key 2 and the collation ECU 9
  • Electronic key ID collation (in this example, smart collation) is performed between the car share device 23 and the collation ECU 9 through the processing, and the operation of the in-vehicle device 3 according to the operation of the portable terminal 22 under the establishment of the electronic key ID collation Perform or allow
  • step S101 the server 20 authenticates the user (user who reserves the vehicle 1) of the mobile terminal 22 through network communication with the mobile terminal 22 (UI application 30).
  • user authentication is performed using a user ID and a password.
  • the use reservation procedure which registers the reservation information of the vehicle 1 is implemented.
  • the reservation information of the vehicle 1 includes, for example, a reservation vehicle, a reservation date and time, and the like.
  • the user ID and password are input to the mobile terminal 22 and transmitted to the server 20 through network communication.
  • the server 20 authenticates the user based on the user ID and the password, the process proceeds to step S102. If the user authentication is not established, the process is forcibly terminated.
  • the server 20 In step S102, the server 20 generates key information Dk.
  • the server 20 may store, for example, a car share apparatus unique encryption key of the car share apparatus 23 mounted on the vehicle 1.
  • the server 20 can generate key information Dk using the car sharing device unique encryption key.
  • the server 20 encrypts the plaintext with the car-sharing apparatus unique encryption key using an encryption method (encryption algorithm), and obtains the ciphertext as the key information Dk.
  • the key information Dk includes, for example, the “reservation date and time” of the vehicle 1, the “terminal ID” unique to the portable terminal 22, and an encryption key for performing encryption communication between the portable terminal 22 and the car sharing device 23.
  • step S103 the server 20 transmits the key information Dk to the portable terminal 22 through network communication.
  • step S104 the portable terminal 22 (UI application 30) performs short-distance wireless communication (in this example, BLE) connection with the car sharing apparatus 23.
  • BLE short-distance wireless communication
  • the car sharing device 23 periodically transmits an advertising packet.
  • the portable terminal 22 transmits a communication connection request to the car share device 23 when receiving the advertising packet within the reservation time to borrow the vehicle 1.
  • the car share device 23 establishes BLE communication with the portable terminal 22 in response to the communication connection request from the portable terminal 22.
  • the car share device 23 transmits, to the portable terminal 22, a communication connection confirmation for communicating establishment of BLE communication.
  • step S105 the car sharing device 23 transmits a key information request for requesting key information Dk to the portable terminal 22.
  • the portable terminal 22 (UI application 30) transmits the key information Dk to the car share device 23 in response to the key information request.
  • step S107 the car share device 23 authenticates the key information Dk.
  • the car share device 23 decrypts the key information Dk using a predetermined encryption key (for example, a car share device unique encryption key).
  • a predetermined encryption key for example, a car share device unique encryption key.
  • the car share device 23 determines that the key information Dk received from the portable terminal 22 is correct. If the authentication is successful, the car share device 23 acquires “reservation date and time”, “terminal ID” and “user authentication key” from the key information Dk. On the other hand, if the authentication is not established, the car sharing apparatus 23 determines that the key information Dk is not correct, and disconnects the BLE communication.
  • step S108 the car share device 23 transmits the user authentication key to the portable terminal 22.
  • step S109 the portable terminal 22 (UI application 30) transmits a key function on request to the car share apparatus 23.
  • the key function on request is a request for switching the key function (key function unit 38) of the car sharing device 23 to the enabled state.
  • step S110 in response to the key function on request from the portable terminal 22, the car share device 23 switches the key function unit 38 to the on state (valid state). As a result, the car share device 23 can execute electronic key ID collation through bidirectional communication of LF-UHF with the collation ECU 9.
  • step S111 the car sharing apparatus 23 stores key information Dk including the user authentication key in the memory 36 of the car sharing apparatus 23.
  • the key information Dk user authentication key
  • both the portable terminal 22 and the car sharing device 23 shift to the authentication completed state. This makes it possible to use the portable terminal 22 as a vehicle key in place of the electronic key 2.
  • step S201 the user turns on the operation request button on the portable terminal 22 in the authentication completed state.
  • the operation request button for example, an unlock request button for unlocking the vehicle door 13, a locking request button for locking the vehicle door 13, an engine start request button for allowing the vehicle 1 to start the engine 6, etc.
  • buttons corresponding to the in-vehicle device 3 There are various buttons corresponding to the in-vehicle device 3.
  • step S202 the portable terminal 22 (UI application 30) encrypts the operation request signal corresponding to the operation request button with the user authentication key.
  • the operation request signal includes a device operation command corresponding to the operation request button.
  • step S203 the portable terminal 22 (UI application 30) transmits the encrypted operation request signal to the car share device 23 through near field communication.
  • step S 204 when the car share device 23 receives the operation request signal, the car share device 23 transmits a request acceptance response to the portable terminal 22. Then, the car share device 23 communicates with the electronic key system 4 and operates the on-vehicle device 3 according to the received operation request signal.
  • the car share device 23 may communicate smartly with the verification ECU 9 of the electronic key system 4 through the smart communication block 34, and transmit the device operation command and the electronic key ID to the verification ECU 9.
  • the verification ECU 9 performs electronic key ID verification, and when electronic key ID verification is established, sends a device operation command to the corresponding in-vehicle device ECU to operate the corresponding in-vehicle device 3.
  • the body ECU 10 operates the door lock device 5 to unlock the vehicle door 13 and the device operation command is a lock request command for the vehicle door 13. If so, the body ECU 10 operates the door lock device 5 to lock the vehicle door 13.
  • the engine ECU 11 permits the start of the engine 6. For example, when the engine switch 18 is operated with the brake pedal depressed, the engine ECU 11 starts the engine 6.
  • challenge response authentication using an electronic key unique encryption key may be performed between the collation ECU 9 and the car sharing apparatus 23.
  • the smart verification may be performed between the car sharing device 23 and the verification ECU 9.
  • the verification ECU 9 and the car sharing device 23 may be wired connected by a wire 40 instead of being connected wirelessly.
  • the car share device 23 receives an operation request signal (a device operation command such as a lock request comment, an unlock request command, or a start request command) from the portable terminal 22, the operation request signal is collated through the wiring 40. It outputs to ECU9.
  • the verification ECU 9 performs electronic key ID verification, and operates the corresponding in-vehicle device 3 by sending a device activation command to the corresponding in-vehicle device ECU. .
  • the car sharing system 21 has a function of switching the operation mode of the share vehicle (vehicle 1).
  • the operation mode is “normal mode” set when the owner of the vehicle 1 uses the vehicle 1, and a car share user other than the owner makes a use reservation of the vehicle 1 to share vehicle (vehicle 1 Between “car share mode” set when using) and “valet parking mode” set when the car share user lends the share vehicle (vehicle 1) to a third party It is possible to switch on.
  • the car share mode is an example of a first share mode
  • the valet parking mode is an example of a second share mode.
  • the operation terminal 2a In the normal mode, the operation terminal 2a is validated, and the vehicle 1 can be operated (that is, the in-vehicle device 3 is operated) by the operation terminal 2a. Further, in the normal mode, the vehicle 1 can be operated by the first portable terminal 22 a possessed by the owner of the vehicle 1.
  • the operation terminal 2a (electronic key 2) is a standard vehicle key provided as standard on the vehicle 1, and is also called a smart key (registered trademark).
  • the vehicle 1 can be operated by the second portable terminal 22 b during the use reservation period of the vehicle 1 performed by the second portable terminal 22 b possessed by the car share user.
  • the second mobile terminal 22b can have the same configuration as the first mobile terminal 22a shown in FIG.
  • the operation terminal 2a is invalidated, and the vehicle 1 can not be operated by the operation terminal 2a.
  • the operation terminal 2a is disabled in the car share mode, there is no concern that the operation terminal 2a is illegally used while the vehicle 1 is being shared.
  • the vehicle 1 can be operated by any of the second portable terminal 22b and the operation terminal 2a.
  • a car share user uses the valet parking service.
  • the car share user changes the operation mode of the vehicle 1 to the valet parking mode to switch the operation terminal 2a from the invalid state to the valid state.
  • the car share user can hand over the operation terminal 2a to the valet clerk and can use the valet parking service.
  • the car sharing system 21 includes a mode switching unit 41 that sets the operation mode of the share vehicle 1.
  • the mode switching unit 41 is provided in the verification ECU 9.
  • the vehicle 1 includes one or more processors and a memory storing one or more instructions, and causes the processors to operate as the verification ECU 9 and the mode switching unit 41 by executing the instructions.
  • the mode switching unit 41 may be mounted by a dedicated circuit different from the verification ECU 9 and may be provided to communicate with the verification ECU 9.
  • the mode switching unit 41 sets the operation mode of the share vehicle 1 to the mobile terminal of the car share user (in this example, the second portable terminal 22 b).
  • the mode is switched to a mode (in the present example, a car share mode) in which it is possible to switch between the valid state and the invalid state of the operation terminal 2a of the share vehicle 1 by the above.
  • step S301 the first portable terminal 22a and the car sharing device 23 are activated by operating the first portable terminal 22a (US application 30) and activating the key function (key function unit 38) of the car sharing device 23. Move to authentication complete state (connection complete state).
  • step S302 the car share mode on operation is performed in the first portable terminal 22a (UI application 30).
  • UI application 30 In the car share mode on operation, for example, a button of "car share mode on” is displayed on the screen of the first portable terminal 22a, and the button is touch-operated.
  • step S303 the first portable terminal 22a (UI application 30) wirelessly transmits a car share mode on request (smart function disable request) to the car share apparatus 23 in response to the execution of the car share mode on operation.
  • a car share mode on request smart function disable request
  • step S304 the car share device 23 outputs the car share mode on request (smart function disable request) transmitted from the first portable terminal 22a to the verification ECU 9.
  • this car share mode on request is sent to the verification ECU 9 through the electronic key system 4, and the car share device 23 and the verification ECU 9 are wire connected. If it is, it is sent to the verification ECU 9 through the wiring 40.
  • step S305 the verification ECU 9 (mode switching unit 41) switches the operation mode of the share vehicle 1 to the car share mode in response to the car share mode ON request (smart function disable request) from the car share device 23. This will disable the smart feature.
  • the smart function is invalidated, for example, by disabling the wake signal transmission function of the verification ECU 9.
  • the LF radio transmission function of the vehicle 1 (radio wave transmitter 16) is enabled and the vehicle 11 is the operation terminal
  • the UHF radio wave from 2a can be received, after the smart function is invalidated, the vehicle 1 does not receive the UHF radio wave from the operation terminal 2a because the LF radio wave transmission function is invalidated.
  • step S306 the verification ECU 9 (mode switching unit 41) outputs a car share mode on response (smart function invalid response) to the car share device 23.
  • the car share mode ON response is sent to the car share device 23 through the electronic key system 4 in the case of wireless connection, and is sent to the car share device 23 through the wire 40 in the case of wired connection.
  • step S307 the car share device 23 wirelessly transmits the car share mode on response (smart function invalid response) from the verification ECU 9 to the first portable terminal 22a. Then, the first mobile terminal 22a (UI application 30) displays the car share mode on notification, for example, on the screen of the first mobile terminal 22a. Thus, the owner of the share vehicle 1 is notified that the car share mode has been turned on.
  • the process of turning off the car share mode from the first portable terminal 22a is performed in the same manner as the process of turning on the car share mode in the procedure shown in steps S308 to S314 of FIG.
  • the car share mode is turned off by transmitting a car share mode off request (smart function enable request) from the first portable terminal 22 a to the verification ECU 9 via the car share device 23.
  • the car share mode off response (smart function valid response) is transmitted from the verification ECU 9 to the first portable terminal 22a via the car share device 23, so that the owner of the share vehicle 1 has the car share mode turned off. Will be notified.
  • step S401 the second mobile terminal 22b and the car share device 23 are activated by the second mobile terminal 22b (UI application 30) being operated and the key function (key function unit 38) of the car share device 23 being enabled. Move to authentication complete state (connection complete state).
  • step S402 the bullet parking mode on operation is performed in the second portable terminal 22b (UI application 30).
  • the bullet parking mode on operation for example, a button of "ballet parking mode on” is displayed on the screen of the second portable terminal 22b, and the button is touch-operated.
  • step S403 the second portable terminal 22b (UI application 30) wirelessly transmits a valet parking mode on request (smart function activation request) to the car share device 23 in response to the execution of the valet parking mode on operation.
  • step S404 the car share device 23 outputs the valet parking mode on request (smart function enable request) transmitted from the second portable terminal 22b to the verification ECU 9.
  • the valet parking mode ON request is sent to the verification ECU 9 through the electronic key system 4 when the car sharing device 23 and the verification ECU 9 are wirelessly connected, and the car sharing device 23 and the verification ECU 9 are wire connected In this case, it is sent to the verification ECU 9 through the wiring 40.
  • step S405 the verification ECU 9 (mode switching unit 41) switches the operation mode of the share vehicle 1 to the bullet parking mode in response to the bullet parking mode on request (smart function activation request) from the car sharing device 23.
  • the smart function is validated by, for example, enabling the wake signal transmission function of the verification ECU 9.
  • the LF radio transmission function of the vehicle 1 radio wave transmitter 16
  • the vehicle 1 can receive UHF radio waves from the operation terminal 2a.
  • the smart feature is enabled.
  • the functions available on the share vehicle 1 may be limited.
  • the expiration date of the share vehicle 1 is set by date and time etc.
  • unlocking of the trunk is invalidated
  • unlocking of the glove box is invalidated
  • step S406 the verification ECU 9 (mode switching unit 41) outputs a bullet parking mode on response (smart function valid response) to the car share device 23.
  • the valet parking mode on response is sent to the car sharing device 23 through the electronic key system 4 in the case of wireless connection, and is sent to the car sharing device 23 through the wire 40 in the case of wired connection.
  • step S407 the car sharing device 23 wirelessly transmits the bullet parking mode on response (smart function valid response) from the verification ECU 9 to the second portable terminal 22b. Then, the second mobile terminal 22b (UI application 30) displays a valet parking mode on notification, for example, on the screen of the second mobile terminal 22b. Thus, the car sharing user is notified that the valet parking mode has been turned on.
  • the process of turning off the valet parking mode from the second portable terminal 22b is performed in the same manner as the process of turning on the valet parking mode in the procedure shown in steps S408 to S414 of FIG.
  • the valet parking mode is turned off by transmitting a bullet parking mode off request (smart function invalidation request) from the second portable terminal 22 b to the verification ECU 9 via the car sharing device 23.
  • the valet parking mode is turned off for the car share user by the valence parking mode off response (smart function invalidation response) being transmitted from the verification ECU 9 to the second portable terminal 22 b via the car sharing device 23. Is notified.
  • the car sharing system 21 described above has the following advantages.
  • the second mobile terminal 22 b of the car share user is operated to switch the operation terminal 2 a of the share vehicle 1 from the disabled state to the enabled state.
  • the car share user can use the valet parking service by handing the operation terminal 2a which originally exists in the share vehicle 1 instead of the second portable terminal 22b to a third party such as a valet person. . Therefore, it is not necessary to prepare a dedicated bullet key for using the valet parking service in the car sharing system 21.
  • the mode switching unit 41 When the mode switching unit 41 is permitted to change the operation mode by the operation of the first mobile terminal 22a through the wireless communication between the first mobile terminal 22a used by the owner of the share vehicle 1 and the car sharing device 23,
  • the operation mode of the shared vehicle 1 is changed to a mode (in the present example, a car share mode) in which the second mobile terminal 22b of the car share user can switch between the valid state and the invalid state of the operation terminal 2a.
  • the operation mode of the share vehicle 1 can not be changed to the car share mode unless the first portable terminal 22a is operated to change the operation mode. Therefore, security can be improved by preventing the operating mode from being illegally changed.
  • the mode switching unit 41 sets the operation terminal 2a as an initial state to an invalid state, and operates the second portable terminal 22b. Switches the operation terminal 2a from the disabled state to the enabled state. As described above, when the operation mode of the share vehicle 1 is changed from the normal mode to the car share mode, the operation terminal 2a is set in the invalid state, so there is a concern that the operation terminal 2a is used illegally when using the car share mode There is no
  • the car sharing system 21 of the second embodiment includes a first operation terminal 2s and a second operation terminal 2t.
  • the first operation terminal 2 s is a main vehicle key (also called an owner key) of the share vehicle 1
  • the second operation terminal 2 t is a sub-vehicle key of the share vehicle 1.
  • the first and second operation terminals 2s and 2t can be, for example, smart keys configured similarly to the electronic key 2 of FIG.
  • the second operation terminal 2t can be stored, for example, in a car.
  • the mode switching unit 41 of the second embodiment sets one of the first operation terminal 2s, the second operation terminal 2t, and the car sharing device 23 as a device 45 that communicates with the verification ECU 9 of the vehicle 1 in each operation mode. By doing this, any one of the first operation terminal 2s, the second operation terminal 2t, and the portable terminal 22 can be used as a vehicle key in each operation mode.
  • the on-vehicle device 3 in the normal mode, can be operated only at the first operation terminal 2s (for example, locking and unlocking of the vehicle door 13, start of the engine 6, and the like can be performed). That is, in the normal mode, only the first operation terminal 2s is validated and can be used as a vehicle key.
  • the car share mode only the second mobile terminal 22b (car share device 23) of the car share user is validated and can be used as a vehicle key.
  • the valet parking mode only the second operation terminal 2t is validated and can be used as a vehicle key.
  • the switching from the normal mode to the car share mode can be performed by the first operation terminal 2s or the first portable terminal 22a. Switching from the car share mode to the valet parking mode can be performed only at the second portable terminal 22 b.
  • the verification ECU 9 periodically or irregularly transmits a wake signal from the radio wave transmitter 16, and a specific device 45 located around the verification ECU 9 (in this example, a communication target with the verification ECU 9) Waits for an acknowledgment (ACK) signal from any one of the first operation terminal 2s, the second operation terminal 2t, and the car sharing device 23 set as (1).
  • ACK acknowledgment
  • the verification ECU 9 transmits a challenge code for a specific device 45, and receives from the device 45 a response code calculated using the challenge code. Further, the collation ECU 9 also calculates a response code from the challenge code, and compares the calculated response code with the response code transmitted from the device 45. When the two response codes match, the matching ECU 9 determines that the challenge response authentication has been established.
  • the device 45 in communication with the verification ECU 9 is set to the first operation terminal 2s of the main vehicle key. Therefore, the verification ECU 9 communicates only with the first operation terminal 2s to perform ID verification (smart verification or wireless verification).
  • ID verification smart verification is performed, and the verification ECU 9 transmits “wake signal 1” that can be responded to by only the first operation terminal 2s.
  • the first operation terminal 2s receives the wake signal 1 transmitted from the radio wave transmitter 16, the first operation terminal 2s sends back an ACK signal to the verification ECU 9.
  • the device 45 the first operation terminal 2s, the second operation terminal 2t, or the car sharing device 23
  • ID verification is performed.
  • the verification ECU 9 When the verification ECU 9 receives an ACK signal corresponding to the wake signal 1 from the first operation terminal 2s, the verification ECU 9 transmits "challenge 1" as a challenge code.
  • the challenge 1 is a challenge code that can be used only by the first operation terminal 2s for the response code calculation.
  • the first operation terminal 2s calculates a response code from the challenge 1 and a given encryption key, and transmits the calculated response code to the verification ECU 9.
  • the verification ECU 9 also calculates the response code from the same encryption key and the challenge 1.
  • the comparison ECU 9 compares the calculated response code with the response code transmitted from the first operation terminal 2s, and if both match, it is determined that the challenge response authentication is established.
  • the verification ECU 9 In addition to the challenge response authentication, the verification ECU 9 also performs electronic key ID verification of the first operation terminal 2s. Then, when the challenge response authentication and the electronic key ID collation are established, the collation ECU 9 determines that the smart collation with the first operation terminal 2s is established. As a result, in the normal mode, only the first operation terminal 2s (main vehicle key) is validated and can be used as a vehicle key for operating the on-vehicle device 3.
  • the device 45 communicating with the verification ECU 9 is set in the car share device 23.
  • the verification ECU 9 communicates only with the car share device 23 to perform ID verification (smart verification or wireless verification).
  • the verification ECU 9 transmits the “wake signal 2” that only the car share device 23 can respond to.
  • the verification ECU 9 receives the ACK signal from the car sharing device 23
  • the verification ECU 9 transmits "challenge 2" as a challenge code.
  • the challenge 2 is a challenge code that can be used only by the car sharing device 23 for response code calculation.
  • the verification ECU 9 performs challenge response authentication via communication with the car share device 23, and when challenge response authentication and electronic key ID verification are established, the smart with the car share device 23 is performed. It is determined that the collation has been established.
  • the car share mode only the car share device 23 is enabled, and only the second mobile terminal 22 b of the car share user can be used as a vehicle key for operating the on-vehicle device 3 through the car share device 23.
  • the device 45 communicating with the verification ECU 9 is set to the second operation terminal 2t of the sub vehicle key.
  • the verification ECU 9 communicates only with the second operation terminal 2t to perform ID verification (smart verification or wireless verification).
  • ID verification smartt verification or wireless verification.
  • the verification ECU 9 transmits the “wake signal 3” which can be responded only by the second operation terminal 2t.
  • collation ECU9 will transmit "challenge 3" as a challenge code
  • the challenge 3 is a challenge code that can be used only by the second operation terminal 2t for response code calculation.
  • the verification ECU 9 performs challenge response authentication via communication with the second operation terminal 2t, and when challenge response authentication and electronic key ID verification are established, the second operation terminal 2t and It is determined that the smart verification of has been established.
  • the valet parking mode only the second operation terminal 2t (sub vehicle key) is validated and can be used as a vehicle key for operating the in-vehicle device 3.
  • the car sharing system 21 of the second embodiment has the following advantages.
  • the mode switching unit 41 sets any one of the first operation terminal 2s, the second operation terminal 2t, and the car sharing device 23 as a device 45 that communicates with the verification ECU 9 in each operation mode.
  • any one of the first operation terminal 2s, the second operation terminal 2t, and the portable terminal 22 (in this example, the second portable terminal 22b of the car sharing user) can be used as a vehicle key in each operation mode It becomes. Therefore, since only one device 45 needs to be operated in each operation mode of the share vehicle 1, it is advantageous to keep the power consumption of each device 45 low.
  • the operation mode of the share vehicle 1 is not limited to the normal mode, the car share mode, and the valet parking mode, and other modes may be adopted.
  • the mode capable of switching between the valid state and the invalid state of the operation terminals 2a, 2s, and 2t is not limited to the car share mode, and may be another mode.
  • the change from the normal mode to the car share mode is not limited to being performed by the first portable terminal 22 a possessed by the owner of the share vehicle 1.
  • the share vehicle 1 may be switched from the normal mode to the car share mode by an instruction from the server 20 or another communication device owned by the owner.
  • the operation terminal 2a is not limited to an electronic key, What is necessary is just an arbitrary vehicle key.
  • the present invention is not limited to setting the operation terminal 2a in the invalid state as the initial state.
  • the operation mode may shift to a setting mode for setting the operation terminal 2a to the valid state or the invalid state.
  • the operation terminal 2a may be set to the valid state or the invalid state at the timing when the car share user borrows and uses the share vehicle 1.
  • the mode switching unit 41 may be provided not in the matching ECU 9 but in another device.
  • the encryption key may be changed to any other encryption key other than the user authentication key.
  • the portable terminal 22 or the car sharing device 23 may obtain the user authentication key by any procedure or method.
  • the key information Dk is not limited to the information encrypted by the car sharing device unique encryption key, and may be encrypted by any other encryption key.
  • the content of the key information Dk is not limited to the content described above, and may include other arbitrary information.
  • the key information Dk is not limited to being generated by the server 20, and may be generated by any other external device.
  • condition for switching the key function unit 38 from the invalid state to the valid state is not limited to the condition described above, and may be another arbitrary condition.
  • the start of the engine 6 may be started by, for example, displaying a button of “engine start” on the screen of the portable terminal 22 and operating this button.
  • an external transmitter and an external vehicle for determining whether the electronic key 2 is inside the vehicle 1 or outside the vehicle 1 It is not limited to using an in-vehicle transmitter. For example, if antennas (LF antennas) are arranged on the left and right of the vehicle body and the combination of the response of the electronic key 2 to the radio waves (communication area) transmitted from each antenna is confirmed, is the electronic key 2 in the vehicle 1? Alternatively, it may be determined whether the vehicle 1 is outside.
  • the smart verification of the electronic key system 4 is not limited to performing both the electronic key ID verification and the challenge response authentication. Any method may be used as the collation method as long as at least electronic key ID collation is performed. Also, any other authentication may be used instead of the challenge response authentication.
  • the electronic key system 4 may adopt a wireless key system in which the electronic key 2 starts wireless communication and executes electronic key ID collation instead of the collation ECU 9.
  • the electronic key 2 is not limited to the smart key (registered trademark), and may be any other wireless key.
  • the near field communication is not limited to the Bluetooth communication, and can be changed to any other communication method.
  • the key information Dk is not limited to the one-time key, and may be any other restricted information.
  • any of a car share device unique encryption key, a user authentication key, and an electronic key unique encryption key can be used, for example.
  • switching the encryption key to be used in the middle of the process is advantageous for further improving the communication security.
  • the mounting location of the car sharing apparatus 23 is not particularly limited.
  • the mobile terminal 22 is not limited to a high-performance mobile phone such as a smartphone, and can be changed to any other mobile terminal.

Landscapes

  • Business, Economics & Management (AREA)
  • Engineering & Computer Science (AREA)
  • Finance (AREA)
  • Tourism & Hospitality (AREA)
  • Economics (AREA)
  • Accounting & Taxation (AREA)
  • Marketing (AREA)
  • Theoretical Computer Science (AREA)
  • Strategic Management (AREA)
  • Physics & Mathematics (AREA)
  • General Business, Economics & Management (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Primary Health Care (AREA)
  • Human Resources & Organizations (AREA)
  • General Health & Medical Sciences (AREA)
  • Development Economics (AREA)
  • Mechanical Engineering (AREA)
  • Lock And Its Accessories (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

A car sharing system (21) is provided with: an operation terminal (2a) for a share vehicle (1), the operation terminal (2a) being capable of operating as a vehicle key for actuating an onboard apparatus (3) through an electronic key system (4); a car share device (23) that communicates wirelessly with a portable terminal (22) capable of operating as a vehicle key and actuates the onboard apparatus (3) through the electronic key system (4) in accordance with the operation of a portable terminal having authenticated key information (Dk); and a mode switching unit (41) capable of switching a share vehicle operation mode, when the share vehicle is used by a car share user other than the owner of the share vehicle, between a state in which the operation terminal (2a) is enabled and a state in which the operation terminal (2a) is disabled by the portable terminal (22) of the car share user.

Description

カーシェアリングシステムCar sharing system
 本発明は、1台の車両を複数人で共有するカーシェアリングシステムに関する。 The present invention relates to a car sharing system in which a plurality of people share one vehicle.
 従来、1台の車両を複数人で共有するカーシェアリングシステムが周知である(特許文献1,2等参照)。この種のカーシェアリングシステムでは、例えばカーシェア使用の登録を予め行っておき、例えば携帯端末(高機能携帯電話等)で車両予約を行った上で、予約時間内において車両の使用が許可される。 BACKGROUND Conventionally, a car sharing system in which one vehicle is shared by a plurality of people is known (see Patent Documents 1 and 2, etc.). In this type of car sharing system, for example, registration of use of car sharing is performed in advance, and for example, use of a vehicle is permitted within a reservation time after making vehicle reservation with a portable terminal (high-performance mobile phone etc.) .
特開2016-115077号公報JP, 2016-115077, A 特開2016-71834号公報JP, 2016-71834, A
 ところで、シェア車両でバレットパーキングサービスを利用する場合、シェア車両の車両キーをバレット係等の第三者に渡す必要があるが、このときに携帯端末を車両キーとして第三者に貸与するのは現実的ではない。しかし、バレットパーキングサービスの利用を考慮に入れて専用のバレットキーを車両に常備する場合にはコストがかかる。 By the way, when using the valet parking service with a share vehicle, it is necessary to pass the vehicle key of the share vehicle to a third party such as a valet, but at this time, the portable terminal is lent to the third party as a vehicle key It is not realistic. However, there is a cost if the vehicle is always equipped with a dedicated bullet key taking into consideration the use of the valet parking service.
 本発明の目的は、専用のバレットキーを使用しなくともシェア車両の貸し出しを可能にしたカーシェアリングシステムを提供することにある。 An object of the present invention is to provide a car sharing system capable of lending a shared vehicle without using a dedicated bullet key.
 一実施形態におけるカーシェアリングシステムは、電子キーシステムを通じて車載機器を作動させる車両キーとして動作可能なシェア車両用の操作端末と、前記車両キーとして動作可能な携帯端末と無線通信可能なカーシェア装置とを備える。前記カーシェア装置は、前記携帯端末との無線通信を通じて鍵情報を認証し、認証された前記鍵情報を有する前記携帯端末の操作に応じて前記電子キーシステムを通じて前記車載機器を作動させる。前記カーシェアリングシステムはさらに、前記シェア車両のオーナ以外のカーシェア利用者によって前記シェア車両が使用される場合に、前記シェア車両の作動モードを、前記カーシェア利用者の前記携帯端末によって前記操作端末の有効状態と無効状態を切り替え可能なモードに変更するモード切替部を備える。 A car sharing system according to one embodiment includes an operation terminal for a share vehicle operable as a vehicle key that operates on-vehicle equipment through an electronic key system, and a car share device capable of wirelessly communicating with a portable terminal operable as the vehicle key. Equipped with The car sharing apparatus authenticates key information through wireless communication with the portable terminal, and operates the in-vehicle device through the electronic key system according to an operation of the portable terminal having the authenticated key information. The car sharing system further operates the operation mode of the share vehicle by the portable terminal of the car share user when the share vehicle is used by a car share user other than the owner of the share vehicle. And a mode switching unit for changing the valid state and the invalid state of the mode to a switchable mode.
 この構成によれば、シェア車両のオーナ以外のカーシェア利用者がバレットパーキングサービスを利用する場合、カーシェア利用者の携帯端末によって、シェア車両の操作端末を無効状態から有効状態に切り替えることができる。これにより、カーシェア利用者は、自身の携帯端末ではなく、シェア車両に元から存在する操作端末をバレット係等の第三者に渡すことにより、バレットパーキングサービスを利用することができる。よって、専用のバレットキーを使用しなくともシェア車両の貸し出しが可能となる。 According to this configuration, when a car share user other than the owner of the share vehicle uses the valet parking service, the mobile terminal of the car share user can switch the operation terminal of the share vehicle from the invalid state to the valid state. . As a result, the car share user can use the valet parking service by handing the operation terminal, which originally exists in the share vehicle, to a third party such as a valet, instead of the portable terminal of the car share user. Thus, sharing vehicles can be lent without using a dedicated bullet key.
 前記カーシェアリングシステムにおいて、前記カーシェア装置は、前記車両キーとして動作可能な複数の携帯端末と無線通信可能であり得る。前記複数の携帯端末は、前記シェア車両のオーナが用いる第1携帯端末と、前記カーシェア利用者が用いる第2携帯端末とを含み得る。前記モード切替部は、前記第1携帯端末と前記カーシェア装置との無線通信を介して前記第1携帯端末の操作により前記作動モードを変更することが許可された場合に、前記作動モードを、前記第2携帯端末によって前記操作端末の有効状態と無効状態を切り替えることが可能なモードに変更し得る。
 この構成によれば、第1携帯端末を使用するシェア車両のオーナが作動モードの変更を許可しなければ、シェア車両の作動モードを変更できないため、カーシェア利用者の第2携帯端末によって操作端末の有効状態と無効状態を切り替えることができない。従って、作動モードが不正に変更されることが防止され、セキュリティを向上することが可能となる。
In the car sharing system, the car sharing apparatus may be capable of wirelessly communicating with a plurality of portable terminals operable as the vehicle key. The plurality of mobile terminals may include a first mobile terminal used by the owner of the share vehicle, and a second mobile terminal used by the car share user. When the mode switching unit is permitted to change the operation mode by the operation of the first portable terminal via wireless communication between the first portable terminal and the car sharing apparatus, the mode switching unit is configured to The mode may be changed to a mode in which the second mobile terminal can switch between the valid state and the invalid state of the operation terminal.
According to this configuration, the operation mode of the share vehicle can not be changed unless the owner of the share vehicle using the first portable terminal permits the change of the operation mode. Therefore, the operation terminal is operated by the second portable terminal of the car share user You can not switch between the enabled and disabled states of. Therefore, the operating mode can be prevented from being tampered with, and security can be improved.
 前記カーシェアリングシステムにおいて、前記モード切替部は、前記シェア車両が前記カーシェア利用者によって使用される場合に、初期状態として前記操作端末を無効状態に設定し得る。この場合において、前記モード切替部は、前記カーシェア利用者の前記携帯端末と前記カーシェア装置との無線通信を介して前記カーシェア利用者の前記携帯端末が操作された場合に、前記操作端末を無効状態から有効状態に切り替え得る。
 この構成によれば、シェア車両の作動モードが、カーシェア利用者の携帯端末によって操作端末の有効状態と無効状態を切り替え可能なモードに変更されたときに、操作端末を忘れずに無効状態に設定することが可能となる。
In the car sharing system, the mode switching unit may set the operation terminal to an invalid state as an initial state when the share vehicle is used by the car share user. In this case, the mode switching unit is configured to operate the operation terminal when the portable terminal of the car share user is operated through wireless communication between the portable terminal of the car share user and the car share apparatus. Can be switched from the disabled state to the enabled state.
According to this configuration, when the operation mode of the share vehicle is changed by the car share user's portable terminal to a mode capable of switching between the enabled state and the disabled state of the operating terminal, the operating mode is switched to the disabled state without forgetting the operating terminal It becomes possible to set.
 前記カーシェアリングシステムにおいて、前記モード切替部は、前記操作端末及び前記第1携帯端末の各々を前記車両キーとして使用可能な通常モードと、前記第2携帯端末を前記車両キーとして使用可能であり前記操作端末が無効状態とされる第1シェアモードとの間で前記作動モードを切替え可能としてもよい。また、前記モード切替部は、前記作動モードが前記通常モードから前記第1シェアモードに変更された後、前記第1シェアモードと、前記操作端末及び前記第2携帯端末の各々を前記車両キーとして使用可能な第2シェアモードとの間で前記作動モードを切替え可能としてもよい。
 この構成によれば、モード切替部は、オーナによるカーシェア車両の利用に適した通常モードと、オーナ以外のカーシェア利用者によるカーシェア車両の利用に適した第1シェアモードと、カーシェア利用者によるバレットパーキングサービスの利用に適した第2シェアモードとのうちの1つを、シェア車両の各利用状況に適した作動モードとして設定することができる。
 前記カーシェアリングシステムにおいて、前記操作端末は、前記シェア車両の複数の操作端末のうちの1つであり得る。前記電子キーシステムは、前記複数の操作端末及び前記カーシェア装置の各々と通信可能な照合装置を備え得る。前記モード切替部は、前記作動モードを複数の作動モード間で切り替え可能であり、前記複数の操作端末及び前記カーシェア装置のいずれか1つを各作動モードで前記照合装置と通信するデバイスとして設定することにより、前記複数の操作端末及び前記携帯端末のいずれか1つを各作動モードでの前記車両キーとして使用可能にする。
 この構成によれば、シェア車両の各作動モードにおいて1つのデバイスのみ作動させればよいので、各デバイスの消費電力を低く抑えるのに有利となる。
In the car sharing system, the mode switching unit can use a normal mode in which each of the operation terminal and the first mobile terminal can be used as the vehicle key, and can use the second mobile terminal as the vehicle key. The operation mode may be switchable with the first share mode in which the operation terminal is in an invalid state. Further, the mode switching unit uses the first share mode, the operation terminal, and the second portable terminal as the vehicle key after the operation mode is changed from the normal mode to the first share mode. The operation mode may be switchable between an available second share mode.
According to this configuration, the mode switching unit is configured to use the normal mode suitable for the use of the car share vehicle by the owner, the first share mode suitable for the use of the car share vehicle by the car share user other than the owner, and the use of the car share One of the second share modes suitable for the user to use the valet parking service can be set as an operation mode suitable for each use situation of the share vehicle.
In the car sharing system, the operation terminal may be one of a plurality of operation terminals of the share vehicle. The electronic key system may include a verification device capable of communicating with each of the plurality of operation terminals and the car sharing device. The mode switching unit is capable of switching the operation mode among a plurality of operation modes, and setting any one of the plurality of operation terminals and the car sharing device as a device to communicate with the verification device in each operation mode By doing this, any one of the plurality of operation terminals and the portable terminal can be used as the vehicle key in each operation mode.
According to this configuration, only one device needs to be operated in each operation mode of the share vehicle, which is advantageous for reducing the power consumption of each device.
 本発明によれば、専用のバレットキーを使用しなくともシェア車両を貸し出すことができる。 According to the present invention, a shared vehicle can be lent out without using a dedicated bullet key.
第1実施形態のカーシェアリングシステムの構成図。BRIEF DESCRIPTION OF THE DRAWINGS The block diagram of the car sharing system of 1st Embodiment. 鍵情報認証の通信シーケンス図。Communication sequence diagram of key information authentication. 携帯端末を操作して車載機器を作動させるときの通信シーケンス図。FIG. 6 is a communication sequence diagram when operating the on-vehicle device by operating the mobile terminal. シェア車両の各作動モードの状態図。State diagram of each operation mode of the shared vehicle. シェア車両の各作動モードの状態図。State diagram of each operation mode of the shared vehicle. カーシェアモードのオンオフ切り替えのシーケンス図。Sequence diagram of on / off switching in car sharing mode. バレットパーキングモードのオンオフ切り替えのシーケンス図。The sequence diagram of on-off switching of valet parking mode. 第2実施形態のシェア車両の各作動モードの状態図。The state diagram of each operation mode of the share vehicle of 2nd Embodiment. スマート照合の通信シーケンス図。Communication sequence diagram of smart verification. 各作動モードにおけるコマンドと各コマンドに対するデバイス応答とをまとめた仕様図。The specification figure which put together the command in each operation mode, and the device response with respect to each command.
 (第1実施形態)
 以下、カーシェアリングシステムの第1実施形態を図1~図7に従って説明する。
 図1に示すように、車両1には、電子キーシステム4が設けられている。一実施形態では、電子キーシステム4は、電子キー2との無線通信を通じて電子キー2のID照合を行う照合ECU(Electronic Control Unit)9を備える。照合ECU9は、照合装置の一例である。照合ECU9は、電子キーID照合の成立に基づいて車載機器3の作動を実行又は許可する。キー操作フリーシステムとも呼ばれる電子キーシステム4では、車両1(照合ECU9)によって開始される狭域無線通信を通じて電子キーID照合(スマート照合とも呼ばれる)が実行される。キー操作フリーシステムでは、電子キー2を直接操作することなく電子キーID照合が自動で行われ得る。車載機器3は、これらに限定されないが、例えばドアロック装置5やエンジン6を含み得る。なお、電子キー2は、車両1に専用の車両キーとして元から用意された操作端末2aの一例である。
First Embodiment
Hereinafter, a first embodiment of the car sharing system will be described with reference to FIGS. 1 to 7.
As shown in FIG. 1, the vehicle 1 is provided with an electronic key system 4. In one embodiment, the electronic key system 4 includes a verification ECU (Electronic Control Unit) 9 that performs ID verification of the electronic key 2 through wireless communication with the electronic key 2. The collation ECU 9 is an example of a collation device. The verification ECU 9 executes or permits the operation of the in-vehicle device 3 based on the establishment of the electronic key ID verification. In the electronic key system 4 also called a key operation free system, electronic key ID collation (also referred to as smart collation) is performed through the short-range wireless communication started by the vehicle 1 (collation ECU 9). In the key operation free system, electronic key ID verification can be automatically performed without directly operating the electronic key 2. The on-vehicle device 3 may include, but is not limited to, the door lock device 5 and the engine 6, for example. The electronic key 2 is an example of the operation terminal 2 a originally prepared as a vehicle key dedicated to the vehicle 1.
 車両1には、照合ECU9と、車載電装品の電源を管理するボディECU10と、エンジン6を制御するエンジンECU11とが設けられている。ボディECU10やエンジンECU11は各々、車載機器ECUとも呼ばれる。これらのECU9~11は、車両1内の通信線12を介して相互に電気的に接続されている。通信線12は、例えばCAN(Controller Area Network)、LIN(Local Interconnect Network)、又はその組み合わせである。照合ECU9及び電子キー2の各々は、メモリ(図示略)を含み、このメモリには、電子キーIDと電子キー固有暗号鍵が記憶されている。電子キーID及び電子キー固有暗号鍵は、車両1に登録された電子キー2に固有の情報であり、電子キーID照合に使用される。ボディECU10は、車両ドア13の施解錠を切り替えるドアロック装置5を制御する。 The vehicle 1 is provided with a verification ECU 9, a body ECU 10 that manages the power supply of in-vehicle electrical components, and an engine ECU 11 that controls the engine 6. Each of the body ECU 10 and the engine ECU 11 is also called an in-vehicle device ECU. The ECUs 9 to 11 are electrically connected to each other via a communication line 12 in the vehicle 1. The communication line 12 is, for example, a controller area network (CAN), a local interconnect network (LIN), or a combination thereof. Each of the verification ECU 9 and the electronic key 2 includes a memory (not shown), and the memory stores an electronic key ID and an electronic key specific encryption key. The electronic key ID and the electronic key unique encryption key are information unique to the electronic key 2 registered in the vehicle 1 and are used for electronic key ID verification. The body ECU 10 controls a door lock device 5 that switches locking and unlocking of the vehicle door 13.
 電子キーシステム4は、車両1に設けられた電波送信機16と電波受信機17とをさらに備える。図示しないが、例えば、電波送信機16は、室外に電波を送信する室外送信機と、室内に電波を送信する室内送信機とを含み得る。電波送信機16は、LF(Low Frequency)帯の電波を送信する。電波受信機17は、UHF(Ultra High Frequency)帯の電波を受信する。従って、電子キーシステム4において、照合ECU9は、LF-UHFの双方向通信により電子キー2と通信する。 The electronic key system 4 further includes a radio wave transmitter 16 and a radio wave receiver 17 provided in the vehicle 1. Although not shown, for example, the radio wave transmitter 16 may include an outdoor transmitter that transmits radio waves outdoors, and an indoor transmitter that transmits radio waves indoors. The radio wave transmitter 16 transmits radio waves in the LF (Low Frequency) band. The radio receiver 17 receives radio waves in the UHF (Ultra High Frequency) band. Therefore, in the electronic key system 4, the verification ECU 9 communicates with the electronic key 2 by the two-way communication of LF-UHF.
 電子キー2は、電波送信機16から送信されるLF電波のウェイク信号によって形成された通信エリアに進入すると、ウェイク信号を受信して待機状態から起動する。電子キー2が起動すると、照合ECU9は、電子キー2のID照合(スマート照合)を実行する。限定ではなく一例として、スマート照合では、電子キー2を認証するための電子キーID照合と、電子キー固有暗号鍵を用いたチャレンジレスポンス認証が行われ得る。電子キー2が車両1外にある状況下で行われる電子キーID照合は、室外スマート照合と呼ばれ得る。室外スマート照合が成立すると、照合ECU9は、ボディECU10を介して車両ドア13の施解錠を許可又は実行する。 When the electronic key 2 enters a communication area formed by the wake signal of the LF radio wave transmitted from the radio wave transmitter 16, the electronic key 2 receives the wake signal and starts from the standby state. When the electronic key 2 is activated, the verification ECU 9 executes ID verification (smart verification) of the electronic key 2. By way of example and not limitation, in smart verification, electronic key ID verification for authenticating the electronic key 2 and challenge response authentication using an electronic key unique encryption key may be performed. The electronic key ID verification performed under the situation where the electronic key 2 is outside the vehicle 1 may be called outdoor smart verification. When the outdoor smart verification is established, the verification ECU 9 permits or executes the locking and unlocking of the vehicle door 13 via the body ECU 10.
 電子キー2が車両1内にある状況下で行われる電子キーID照合は、室内スマート照合と呼ばれ得る。室内スマート照合が成立すると、照合ECU9は、エンジンスイッチ18の操作に応じた電源遷移操作を許可する。例えば、ブレーキペダルを踏み込まれた状態でエンジンスイッチ18が操作されると、照合ECU9は、エンジンECU11を介してエンジン6を始動する。 Electronic key ID verification performed under the condition that the electronic key 2 is in the vehicle 1 may be referred to as indoor smart verification. When the indoor smart verification is established, the verification ECU 9 permits the power supply transition operation according to the operation of the engine switch 18. For example, when the engine switch 18 is operated in a state where the brake pedal is depressed, the verification ECU 9 starts the engine 6 via the engine ECU 11.
 車両1には、車両1を複数人で共有するカーシェアリングシステム21が設けられている。本例では、カーシェアリングシステム21は、車両1に搭載されたカーシェア装置23を備える。カーシェア装置23は、車両1に設けられた電子キーシステム4で使用される電子キーIDの照合を実行可能である。また、カーシェア装置23は、携帯端末22と無線通信可能である。携帯端末22には、例えばサーバ20等の外部装置から取得される、暗号化された鍵情報Dkが登録される。カーシェア装置23は、携帯端末22から鍵情報Dkを取得してその鍵情報Dkを認証する。本例では、カーシェア装置23は、鍵情報Dkを復号可能な暗号鍵(カーシェア装置固有暗号鍵)を有し、その暗号鍵により鍵情報Dkを復号する。鍵情報Dkの復号が成功すれば、鍵情報Dkが認証される。この鍵情報Dkの認証が成立した後、携帯端末22は、車載機器3の作動を要求する操作要求をカーシェア装置23に送信可能となる。携帯端末22は、例えばスマートフォン等の高機能携帯電話とすることができる。鍵情報Dkは、例えば、その使用が1度のみ許可されたワンタイムキー(ワンタイムパスワード)であることが好ましい。 The vehicle 1 is provided with a car sharing system 21 which shares the vehicle 1 with a plurality of people. In this example, the car sharing system 21 includes a car share device 23 mounted on the vehicle 1. The car share device 23 can execute verification of the electronic key ID used in the electronic key system 4 provided in the vehicle 1. Further, the car share device 23 can wirelessly communicate with the portable terminal 22. In the mobile terminal 22, encrypted key information Dk acquired from an external device such as the server 20 is registered. The car share device 23 acquires key information Dk from the portable terminal 22 and authenticates the key information Dk. In this example, the car share device 23 has an encryption key (car share device unique encryption key) that can decrypt the key information Dk, and decrypts the key information Dk using the encryption key. If decryption of the key information Dk is successful, the key information Dk is authenticated. After the authentication of the key information Dk is established, the portable terminal 22 can transmit an operation request for requesting the operation of the in-vehicle device 3 to the car share device 23. The mobile terminal 22 can be, for example, a high-performance mobile phone such as a smartphone. The key information Dk is preferably, for example, a one-time key (one-time password) whose use is permitted only once.
 カーシェア装置23は、電子キーシステム4のハードウェア構成からは独立しており、車両1に対して後付け可能である。カーシェア装置23は、例えば車両1の予約時間内のときのみ有効になる電子キー(車両キー)の位置付けであり、スペアキーと同様の扱いである。本例では、このカーシェア装置23が携帯端末22と協働することによって、携帯端末22は電子キー2に代わる車両キーとして動作可能である。カーシェア装置23は、有効状態と無効状態の間で切り替えられるキー機能(電子キー機能)を有する。カーシェア装置23のキー機能が有効にされると、車両1内に電子キーが出現したかのように見える一方、キー機能が無効にされると、車両1から電子キーが消滅したかのように見える。カーシェア装置23には、車両1のバッテリ+Bから電源が供給されている。 The car share device 23 is independent of the hardware configuration of the electronic key system 4 and can be retrofitted to the vehicle 1. The car share device 23 is, for example, positioning of an electronic key (vehicle key) that is enabled only within the reserved time of the vehicle 1 and is treated the same as the spare key. In this example, the car sharing device 23 cooperates with the portable terminal 22 so that the portable terminal 22 can operate as a vehicle key replacing the electronic key 2. The car share device 23 has a key function (electronic key function) switched between the enabled state and the disabled state. When the key function of the car sharing device 23 is activated, it looks as if an electronic key appeared in the vehicle 1, while when the key function is invalidated, it seems as if the electronic key has disappeared from the vehicle 1 It looks like The car share device 23 is supplied with power from the battery + B of the vehicle 1.
 限定ではなく一例として、携帯端末22は、携帯端末22の作動を制御する端末制御部26と、携帯端末22とサーバ等の外部装置との間においてネットワーク通信を行うためのネットワーク通信モジュール27と、携帯端末22とカーシェア装置23との間において近距離無線通信を行うための近距離無線通信モジュール28と、データ書き替え可能なメモリ29とを備える。携帯端末22は、サーバ20からネットワーク通信モジュール27を通じて鍵情報Dkを取得し、この鍵情報Dkをメモリ29に書き込む。近距離無線通信は、例えばブルートゥース(Bluetooth:登録商標)であり、好ましくはBluetooth(登録商標)Low Energy(BLE)である。 By way of example and not limitation, the portable terminal 22 includes a terminal control unit 26 that controls the operation of the portable terminal 22, and a network communication module 27 for performing network communication between the portable terminal 22 and an external device such as a server, A short distance wireless communication module 28 for performing short distance wireless communication between the portable terminal 22 and the car sharing device 23 and a memory 29 capable of rewriting data are provided. The portable terminal 22 acquires key information Dk from the server 20 through the network communication module 27 and writes the key information Dk in the memory 29. The near field communication is, for example, Bluetooth (registered trademark), preferably Bluetooth (registered trademark) Low Energy (BLE).
 携帯端末22は、カーシェアリングシステム21の作動を管理するユーザインターフェース(UI)アプリケーション30を備える。UIアプリケーション30は、例えばサーバ20からダウンロードされるなどして、端末制御部26にインストールされる。本例では、携帯端末22のメモリ29には、携帯端末22が車両1のカーシェア装置23と通信して、携帯端末22の操作により車載機器3を作動させる際に使用されるユーザ認証鍵が登録される。ユーザ認証鍵は、例えば、生成の度にその値が毎回変わる乱数とすることができる。ユーザ認証鍵は、予めカーシェアリングシステム21に登録されたものでもよいし、あるいは車両1の使用時に生成されて登録されるものでもよい。 The mobile terminal 22 comprises a user interface (UI) application 30 that manages the operation of the car sharing system 21. The UI application 30 is installed in the terminal control unit 26 by being downloaded from the server 20, for example. In this example, the memory 29 of the portable terminal 22 has a user authentication key used when the portable terminal 22 communicates with the car share device 23 of the vehicle 1 and operates the on-vehicle device 3 by operating the portable terminal 22. be registered. The user authentication key can be, for example, a random number whose value changes each time it is generated. The user authentication key may be registered in advance in the car sharing system 21 or may be generated and registered when the vehicle 1 is used.
 限定ではなく一例として、カーシェア装置23は、カーシェア装置23の作動を制御するコントローラ33と、カーシェア装置23と電子キーシステム4(照合ECU9)との間においてスマート通信(狭域無線通信)を行うためのスマート通信ブロック34と、カーシェア装置23と携帯端末22との間において近距離無線通信を行うための近距離無線モジュール35と、データ書き替え可能なメモリ36と、カーシェア装置23において日時を管理するタイマ部37とを備える。メモリ36には、カーシェア装置IDと、カーシェア装置固有暗号鍵と、電子キーIDと、電子キー固有暗号鍵とが記憶されている。カーシェア装置ID及びカーシェア装置固有暗号鍵は、カーシェア装置23に固有の情報である。カーシェア装置固有暗号鍵は、携帯端末22とカーシェア装置23との間の暗号通信に使用される。例えば、携帯端末22は、カーシェア装置固有暗号鍵により暗号化された鍵情報Dkをサーバ20から取得し得る。そして、携帯端末22からカーシェア装置23への鍵情報Dkの送信にカーシェア装置固有暗号鍵が使用され得る。電子キーIDと電子キー固有暗号鍵は、上記のように、電子キーシステム4を通じた電子キーID照合(本例では、スマート照合)に使用される。タイマ部37は、例えばソフトタイマからなる。カーシェア装置23は、例えばカーシェア装置IDが車両ID(車体番号)と紐付けされることで、車両1に一対一で関連付けられる。 By way of example and not limitation, the car share device 23 performs smart communication (short range wireless communication) between the controller 33 that controls the operation of the car share device 23 and the car share device 23 and the electronic key system 4 (collation ECU 9) Communication block 34 for performing communication, a near field wireless module 35 for performing near field communication between the car share device 23 and the portable terminal 22, a memory 36 capable of rewriting data, and the car share device 23 And a timer unit 37 that manages the date and time. The memory 36 stores a car sharing device ID, a car sharing device unique encryption key, an electronic key ID, and an electronic key unique encryption key. The car share device ID and the car share device unique encryption key are information unique to the car share device 23. The car share device unique encryption key is used for cryptographic communication between the portable terminal 22 and the car share device 23. For example, the portable terminal 22 can obtain, from the server 20, key information Dk encrypted by the car sharing device unique encryption key. Then, the car sharing device unique encryption key may be used to transmit the key information Dk from the portable terminal 22 to the car sharing device 23. The electronic key ID and the electronic key unique encryption key are used for electronic key ID verification (in this example, smart verification) through the electronic key system 4 as described above. The timer unit 37 includes, for example, a soft timer. The car share device 23 is associated with the vehicle 1 on a one-on-one basis, for example, by associating the car share device ID with the vehicle ID (body number).
 カーシェア装置23は、スマート通信ブロック34によるスマート通信を通じて、カーシェア装置23と電子キーシステム4(照合ECU9)との間で電子キーID照合(本例では、スマート照合)を実行するキー機能部38を備える。キー機能部38は、コントローラ33に設けられている。例えば、カーシェア装置23は、1つ又は複数のプロセッサと、1つ又は複数の命令を記憶したメモリとを含み、プロセッサが命令を実行することによりコントローラ33をキー機能部38として動作させる。或いは、キー機能部38は、専用の回路により実装されてもよい。キー機能部38は、携帯端末22から鍵情報Dkを取得し、その鍵情報Dkを認証する。そして、鍵情報Dkの認証が成立すると、キー機能部38は、照合ECU9とのスマート通信を通じて電子キーID照合を実行可能となる。例えば、シェア車両(車両1)の車載機器3を作動させるべく携帯端末22が操作されると、キー機能部38は、電子キー2と照合ECU9との間で行われる電子キーID照合と同様な処理を通じて、カーシェア装置23と照合ECU9との間で電子キーID照合(本例では、スマート照合)を行い、電子キーID照合の成立下で携帯端末22の操作に応じた車載機器3の作動を実行又は許可する。 The car share device 23 is a key function unit that executes electronic key ID collation (in this example, smart collation) between the car share device 23 and the electronic key system 4 (collation ECU 9) through smart communication by the smart communication block 34. It has 38. The key function unit 38 is provided in the controller 33. For example, the car share device 23 includes one or more processors and a memory storing one or more instructions, and causes the controller 33 to operate as the key function unit 38 by executing the instructions. Alternatively, the key function unit 38 may be implemented by a dedicated circuit. The key function unit 38 acquires key information Dk from the portable terminal 22 and authenticates the key information Dk. Then, when the authentication of the key information Dk is established, the key function unit 38 can execute electronic key ID collation through smart communication with the collation ECU 9. For example, when the portable terminal 22 is operated to operate the on-vehicle device 3 of the share vehicle (vehicle 1), the key function unit 38 is similar to the electronic key ID collation performed between the electronic key 2 and the collation ECU 9 Electronic key ID collation (in this example, smart collation) is performed between the car share device 23 and the collation ECU 9 through the processing, and the operation of the in-vehicle device 3 according to the operation of the portable terminal 22 under the establishment of the electronic key ID collation Perform or allow
 続いて、図2及び図3を用いて、携帯端末22を用いて車両1の使用を予約し、車両キーとして機能する携帯端末22で車両1の車載機器3を作動させる際の手順を説明する。
 ステップS101において、サーバ20は、携帯端末22(UIアプリケーション30)とのネットワーク通信を通じて携帯端末22のユーザ(車両1を予約するユーザ)を認証する。本例では、ユーザ認証は、ユーザID及びパスワードを用いて行われる。また、このユーザ認証では、車両1の予約情報を登録する利用予約手続きが実施される。車両1の予約情報は、例えば、予約車両や予約日時等を含む。例えば、ユーザID及びパスワードは携帯端末22に入力され、ネットワーク通信を通じてサーバ20に送信される。サーバ20はユーザID及びパスワードに基づいてユーザを認証すると、処理はステップS102に進む。ユーザ認証が不成立であれば処理は強制終了する。
Subsequently, using FIG. 2 and FIG. 3, the procedure for reserving use of the vehicle 1 using the portable terminal 22 and operating the on-vehicle device 3 of the vehicle 1 with the portable terminal 22 functioning as a vehicle key will be described. .
In step S101, the server 20 authenticates the user (user who reserves the vehicle 1) of the mobile terminal 22 through network communication with the mobile terminal 22 (UI application 30). In this example, user authentication is performed using a user ID and a password. Moreover, in this user authentication, the use reservation procedure which registers the reservation information of the vehicle 1 is implemented. The reservation information of the vehicle 1 includes, for example, a reservation vehicle, a reservation date and time, and the like. For example, the user ID and password are input to the mobile terminal 22 and transmitted to the server 20 through network communication. When the server 20 authenticates the user based on the user ID and the password, the process proceeds to step S102. If the user authentication is not established, the process is forcibly terminated.
 ステップS102において、サーバ20は、鍵情報Dkを生成する。サーバ20には、例えば、車両1に搭載されたカーシェア装置23のカーシェア装置固有暗号鍵が記憶され得る。サーバ20は、このカーシェア装置固有暗号鍵を使用して、鍵情報Dkを生成し得る。本例では、サーバ20は、暗号式(暗号アルゴリズム)を用いてカーシェア装置固有暗号鍵で平文を暗号化し、その暗号文を鍵情報Dkとして得る。この鍵情報Dkには、例えば、車両1の「予約日時」や、携帯端末22に固有の「端末ID」や、携帯端末22とカーシェア装置23との間で暗号通信を行うための暗号鍵として使用される「ユーザ認証鍵」などが含まれる。 In step S102, the server 20 generates key information Dk. The server 20 may store, for example, a car share apparatus unique encryption key of the car share apparatus 23 mounted on the vehicle 1. The server 20 can generate key information Dk using the car sharing device unique encryption key. In this example, the server 20 encrypts the plaintext with the car-sharing apparatus unique encryption key using an encryption method (encryption algorithm), and obtains the ciphertext as the key information Dk. The key information Dk includes, for example, the “reservation date and time” of the vehicle 1, the “terminal ID” unique to the portable terminal 22, and an encryption key for performing encryption communication between the portable terminal 22 and the car sharing device 23. And “user authentication key” used as
 ステップS103において、サーバ20は、鍵情報Dkを携帯端末22にネットワーク通信を通じて送信する。
 ステップS104において、携帯端末22(UIアプリケーション30)はカーシェア装置23との近距離無線通信(本例では、BLE)接続を実行する。例えば、カーシェア装置23は、定期的にアドバタイジングパケットを送信する。携帯端末22は、車両1を借りる予約時間内のときにアドバタイジングパケットを受信すると、通信接続要求をカーシェア装置23に送信する。カーシェア装置23は、携帯端末22からの通信接続要求に応答して携帯端末22とのBLE通信を確立する。そして、カーシェア装置23は、BLE通信の確立を通信する通信接続確認を携帯端末22に送信する。
In step S103, the server 20 transmits the key information Dk to the portable terminal 22 through network communication.
In step S104, the portable terminal 22 (UI application 30) performs short-distance wireless communication (in this example, BLE) connection with the car sharing apparatus 23. For example, the car sharing device 23 periodically transmits an advertising packet. The portable terminal 22 transmits a communication connection request to the car share device 23 when receiving the advertising packet within the reservation time to borrow the vehicle 1. The car share device 23 establishes BLE communication with the portable terminal 22 in response to the communication connection request from the portable terminal 22. Then, the car share device 23 transmits, to the portable terminal 22, a communication connection confirmation for communicating establishment of BLE communication.
 ステップS105において、カーシェア装置23は、鍵情報Dkを要求する鍵情報要求を携帯端末22に送信する。
 ステップS106において、携帯端末22(UIアプリケーション30)は、鍵情報要求に応答して鍵情報Dkをカーシェア装置23に送信する。
In step S105, the car sharing device 23 transmits a key information request for requesting key information Dk to the portable terminal 22.
In step S106, the portable terminal 22 (UI application 30) transmits the key information Dk to the car share device 23 in response to the key information request.
 ステップS107において、カーシェア装置23は鍵情報Dkを認証する。本例では、カーシェア装置23は、所定の暗号鍵(例えば、カーシェア装置固有暗号鍵)を用いて鍵情報Dkを復号する。このとき、鍵情報Dkの復号が成功すれば、カーシェア装置23は、携帯端末22から受信した鍵情報Dkが正しいと判断する。認証が成功すると、カーシェア装置23は、鍵情報Dkから「予約日時」、「端末ID」、「ユーザ認証鍵」を取得する。一方、認証が不成立であれば、カーシェア装置23は、鍵情報Dkが正しくないと判断して、BLE通信を切断する。 In step S107, the car share device 23 authenticates the key information Dk. In this example, the car share device 23 decrypts the key information Dk using a predetermined encryption key (for example, a car share device unique encryption key). At this time, if the decryption of the key information Dk is successful, the car share device 23 determines that the key information Dk received from the portable terminal 22 is correct. If the authentication is successful, the car share device 23 acquires “reservation date and time”, “terminal ID” and “user authentication key” from the key information Dk. On the other hand, if the authentication is not established, the car sharing apparatus 23 determines that the key information Dk is not correct, and disconnects the BLE communication.
 ステップS108において、カーシェア装置23はユーザ認証鍵を携帯端末22に送信する。
 ステップS109において、携帯端末22(UIアプリケーション30)は、キー機能オン要求をカーシェア装置23に送信する。キー機能オン要求は、カーシェア装置23のキー機能(キー機能部38)を有効状態に切り替えるための要求である。
In step S108, the car share device 23 transmits the user authentication key to the portable terminal 22.
In step S109, the portable terminal 22 (UI application 30) transmits a key function on request to the car share apparatus 23. The key function on request is a request for switching the key function (key function unit 38) of the car sharing device 23 to the enabled state.
 ステップS110において、カーシェア装置23は、携帯端末22からのキー機能オン要求に応答して、キー機能部38をオン状態(有効状態)に切り替える。これにより、カーシェア装置23は、照合ECU9とのLF-UHFの双方向通信を通じて電子キーID照合を実行することが可能となる。 In step S110, in response to the key function on request from the portable terminal 22, the car share device 23 switches the key function unit 38 to the on state (valid state). As a result, the car share device 23 can execute electronic key ID collation through bidirectional communication of LF-UHF with the collation ECU 9.
 ステップS111において、カーシェア装置23は、ユーザ認証鍵を含む鍵情報Dkをカーシェア装置23のメモリ36に保存する。鍵情報Dk(ユーザ認証鍵)がメモリ36に保存されると、携帯端末22及びカーシェア装置23の双方が認証完了状態に移行する。これにより、携帯端末22を電子キー2に代わる車両キーとして使用することが可能となる。 In step S111, the car sharing apparatus 23 stores key information Dk including the user authentication key in the memory 36 of the car sharing apparatus 23. When the key information Dk (user authentication key) is stored in the memory 36, both the portable terminal 22 and the car sharing device 23 shift to the authentication completed state. This makes it possible to use the portable terminal 22 as a vehicle key in place of the electronic key 2.
 図3に示すように、ステップS201において、ユーザは、認証完了状態の携帯端末22において操作要求ボタンをオン操作する。操作要求ボタンとしては、例えば車両ドア13を解錠するための解錠要求ボタン、車両ドア13を施錠するための施錠要求ボタン、エンジン6の始動を車両1に許可させるためのエンジン始動要求ボタンなど、車載機器3に応じた種々のボタンがある。 As shown in FIG. 3, in step S201, the user turns on the operation request button on the portable terminal 22 in the authentication completed state. As the operation request button, for example, an unlock request button for unlocking the vehicle door 13, a locking request button for locking the vehicle door 13, an engine start request button for allowing the vehicle 1 to start the engine 6, etc. There are various buttons corresponding to the in-vehicle device 3.
 ステップS202において、携帯端末22(UIアプリケーション30)は、操作要求ボタンに応じた操作要求信号をユーザ認証鍵で暗号化する。操作要求信号は、操作要求ボタンに応じた機器作動コマンドを含む。 In step S202, the portable terminal 22 (UI application 30) encrypts the operation request signal corresponding to the operation request button with the user authentication key. The operation request signal includes a device operation command corresponding to the operation request button.
 ステップS203において、携帯端末22(UIアプリケーション30)は、暗号化された操作要求信号を、近距離無線通信を通じてカーシェア装置23に送信する。 In step S203, the portable terminal 22 (UI application 30) transmits the encrypted operation request signal to the car share device 23 through near field communication.
 ステップS204において、カーシェア装置23は、操作要求信号を受信すると、要求受付応答を携帯端末22に送信する。そして、カーシェア装置23は、電子キーシステム4と通信し、受信した操作要求信号に応じて車載機器3を作動させる。限定ではなく一例として、カーシェア装置23は、スマート通信ブロック34を通じて電子キーシステム4の照合ECU9とスマート通信し、機器作動コマンドと電子キーIDとを照合ECU9に送信し得る。この場合、照合ECU9は、電子キーID照合を行い、電子キーID照合が成立すると、対応する車載機器ECUに機器作動コマンドを送り、対応する車載機器3を作動させる。例えば、機器作動コマンドが車両ドア13の解錠要求コマンドであれば、ボディECU10は、ドアロック装置5を作動させて車両ドア13を解錠し、機器作動コマンドが車両ドア13の施錠要求コマンドであれば、ボディECU10は、ドアロック装置5を作動させて車両ドア13を施錠する。 In step S 204, when the car share device 23 receives the operation request signal, the car share device 23 transmits a request acceptance response to the portable terminal 22. Then, the car share device 23 communicates with the electronic key system 4 and operates the on-vehicle device 3 according to the received operation request signal. By way of example and not limitation, the car share device 23 may communicate smartly with the verification ECU 9 of the electronic key system 4 through the smart communication block 34, and transmit the device operation command and the electronic key ID to the verification ECU 9. In this case, the verification ECU 9 performs electronic key ID verification, and when electronic key ID verification is established, sends a device operation command to the corresponding in-vehicle device ECU to operate the corresponding in-vehicle device 3. For example, if the device operation command is an unlock request command for the vehicle door 13, the body ECU 10 operates the door lock device 5 to unlock the vehicle door 13, and the device operation command is a lock request command for the vehicle door 13. If so, the body ECU 10 operates the door lock device 5 to lock the vehicle door 13.
 また、機器作動コマンドがエンジン6の始動要求コマンドであれば、エンジンECU11はエンジン6の始動を許可する。例えば、ブレーキペダルが踏み込まれた状態でエンジンスイッチ18が操作されると、エンジンECU11はエンジン6を始動する。なお、任意で、電子キーID照合に加えて、電子キー固有暗号鍵を用いたチャレンジレスポンス認証を照合ECU9とカーシェア装置23との間で行ってもよい。このように、電子キー2と照合ECU9との間で行われるスマート照合と同様に、カーシェア装置23と照合ECU9との間でスマート照合を行ってもよい。 If the device operation command is a start request command of the engine 6, the engine ECU 11 permits the start of the engine 6. For example, when the engine switch 18 is operated with the brake pedal depressed, the engine ECU 11 starts the engine 6. Optionally, in addition to the electronic key ID collation, challenge response authentication using an electronic key unique encryption key may be performed between the collation ECU 9 and the car sharing apparatus 23. As described above, as in the smart verification performed between the electronic key 2 and the verification ECU 9, the smart verification may be performed between the car sharing device 23 and the verification ECU 9.
 なお、図4に示すように、照合ECU9及びカーシェア装置23は、無線接続されることに代えて、配線40により有線接続されてもよい。この場合、カーシェア装置23は、携帯端末22から操作要求信号(施錠要求コメント、解錠要求コマンド、または始動要求コマンド等の機器作動コマンド)を受信すると、その操作要求信号を、配線40を通じて照合ECU9に出力する。照合ECU9は、配線40を通じてカーシェア装置23からの操作要求信号を取得すると、電子キーID照合を行って、対応する車載機器ECUに機器作動コマンドを送ることで、対応する車載機器3を作動させる。 Note that, as shown in FIG. 4, the verification ECU 9 and the car sharing device 23 may be wired connected by a wire 40 instead of being connected wirelessly. In this case, when the car share device 23 receives an operation request signal (a device operation command such as a lock request comment, an unlock request command, or a start request command) from the portable terminal 22, the operation request signal is collated through the wiring 40. It outputs to ECU9. When acquiring the operation request signal from the car sharing device 23 through the wiring 40, the verification ECU 9 performs electronic key ID verification, and operates the corresponding in-vehicle device 3 by sending a device activation command to the corresponding in-vehicle device ECU. .
 図5に示すように、カーシェアリングシステム21は、シェア車両(車両1)の作動モードを切り替える機能を有する。本例において、作動モードは、車両1のオーナが車両1を使用するときに設定される「通常モード」と、オーナ以外のカーシェア利用者が車両1の使用予約を行ってシェア車両(車両1)を使用するときに設定される「カーシェアモード」と、そのカーシェア利用者がシェア車両(車両1)を第三者に貸し出すときに設定される「バレットパーキングモード」との3つのモード間で切り替え可能とされている。カーシェアモードは第1シェアモードの一例であり、バレットパーキングモードは第2シェアモードの一例である。 As shown in FIG. 5, the car sharing system 21 has a function of switching the operation mode of the share vehicle (vehicle 1). In this example, the operation mode is “normal mode” set when the owner of the vehicle 1 uses the vehicle 1, and a car share user other than the owner makes a use reservation of the vehicle 1 to share vehicle (vehicle 1 Between "car share mode" set when using) and "valet parking mode" set when the car share user lends the share vehicle (vehicle 1) to a third party It is possible to switch on. The car share mode is an example of a first share mode, and the valet parking mode is an example of a second share mode.
 通常モードでは、操作端末2aが有効とされ、操作端末2aで車両1を操作する(すなわち、車載機器3を作動させる)ことができる。また、通常モードでは、車両1のオーナが所持する第1携帯端末22aで車両1を操作することができる。操作端末2a(電子キー2)は、車両1に標準装備された標準車両キーであって、スマートキー(登録商標)とも呼ばれるものである。 In the normal mode, the operation terminal 2a is validated, and the vehicle 1 can be operated (that is, the in-vehicle device 3 is operated) by the operation terminal 2a. Further, in the normal mode, the vehicle 1 can be operated by the first portable terminal 22 a possessed by the owner of the vehicle 1. The operation terminal 2a (electronic key 2) is a standard vehicle key provided as standard on the vehicle 1, and is also called a smart key (registered trademark).
 カーシェアモードでは、カーシェア利用者が所持する第2携帯端末22bで行った車両1の使用予約期間中、第2携帯端末22bで車両1を操作することができる。なお、第2携帯端末22bは、図1に示す第1携帯端末22aと同様な構成を有し得る。カーシェアモードでは、操作端末2aは無効とされて、操作端末2aで車両1の操作を行うことはできない。このように、カーシェアモードでは操作端末2aが使用不可とされるため、車両1のシェア中に操作端末2aが不正に使用されるといった心配がない。 In the car share mode, the vehicle 1 can be operated by the second portable terminal 22 b during the use reservation period of the vehicle 1 performed by the second portable terminal 22 b possessed by the car share user. The second mobile terminal 22b can have the same configuration as the first mobile terminal 22a shown in FIG. In the car share mode, the operation terminal 2a is invalidated, and the vehicle 1 can not be operated by the operation terminal 2a. As described above, since the operation terminal 2a is disabled in the car share mode, there is no concern that the operation terminal 2a is illegally used while the vehicle 1 is being shared.
 バレットパーキングモードでは、第2携帯端末22bのみならず、操作端末2aも有効とされる。従って、第2携帯端末22b及び操作端末2aのいずれでも車両1の操作を行うことができる。例えば、カーシェア利用者がバレットパーキングサービスを利用することが想定される。この場合、バレット係等の第三者に、カーシェア利用者自身の携帯端末(第2携帯端末22b)を渡すのは現実的ではない。この点を考慮し、カーシェア利用者は、バレットパーキングサービスを利用する場合には、車両1の作動モードをバレットパーキングモードに変更することで操作端末2aを無効状態から有効状態に切り替える。これにより、カーシェア利用者は、操作端末2aをバレット係に渡してバレットパーキングサービスを利用することができる。 In the valet parking mode, not only the second mobile terminal 22 b but also the operation terminal 2 a is validated. Therefore, the vehicle 1 can be operated by any of the second portable terminal 22b and the operation terminal 2a. For example, it is assumed that a car share user uses the valet parking service. In this case, it is not realistic to hand over the car share user's own portable terminal (the second portable terminal 22b) to a third party such as a valet clerk. In consideration of this point, when using the valet parking service, the car share user changes the operation mode of the vehicle 1 to the valet parking mode to switch the operation terminal 2a from the invalid state to the valid state. Thereby, the car share user can hand over the operation terminal 2a to the valet clerk and can use the valet parking service.
 図1に戻り、カーシェアリングシステム21は、シェア車両1の作動モードを設定するモード切替部41を備える。本例では、モード切替部41は、照合ECU9に設けられている。例えば、車両1は、1つ又は複数のプロセッサと、1つ又は複数の命令を記憶したメモリとを含み、プロセッサが命令を実行することにより、そのプロセッサを照合ECU9及びモード切替部41として動作させる。或いは、モード切替部41は、照合ECU9とは別の専用の回路により実装され、照合ECU9と通信するように設けられてもよい。モード切替部41は、シェア車両1がオーナ以外のカーシェア利用者に使用される場合に、シェア車両1の作動モードを、カーシェア利用者自身の携帯端末(本例では第2携帯端末22b)によってシェア車両1の操作端末2aの有効状態と無効状態を切り替えることが可能なモード(本例ではカーシェアモード)に変更する。 Returning to FIG. 1, the car sharing system 21 includes a mode switching unit 41 that sets the operation mode of the share vehicle 1. In the present example, the mode switching unit 41 is provided in the verification ECU 9. For example, the vehicle 1 includes one or more processors and a memory storing one or more instructions, and causes the processors to operate as the verification ECU 9 and the mode switching unit 41 by executing the instructions. . Alternatively, the mode switching unit 41 may be mounted by a dedicated circuit different from the verification ECU 9 and may be provided to communicate with the verification ECU 9. When the share vehicle 1 is used by a car share user other than the owner, the mode switching unit 41 sets the operation mode of the share vehicle 1 to the mobile terminal of the car share user (in this example, the second portable terminal 22 b). The mode is switched to a mode (in the present example, a car share mode) in which it is possible to switch between the valid state and the invalid state of the operation terminal 2a of the share vehicle 1 by the above.
 次に、図6及び図7を用いて、カーシェアリングシステム21の作用を説明する。なお、ここでは、第1携帯端末22aが前述のステップS101~S111の処理によってカーシェア装置23に登録されていることとする。 Next, the operation of the car sharing system 21 will be described using FIGS. 6 and 7. Here, it is assumed that the first portable terminal 22a is registered in the car sharing apparatus 23 by the process of the above-mentioned steps S101 to S111.
 [カーシェアモード有効無効切り替えシーケンス]
 図6に示すように、カーシェアモードのオン(有効)及びオフ(無効)の切り替えは、第1携帯端末22aから行われる。まず、カーシェアモードをオンする場合について説明する。ステップS301では、第1携帯端末22a(USアプリケーション30)が操作されてカーシェア装置23のキー機能(キー機能部38)が有効にされることにより、第1携帯端末22a及びカーシェア装置23が認証完了状態(接続完了状態)に移行する。
[Car share mode enable / disable switching sequence]
As shown in FIG. 6, switching between on (valid) and off (invalid) of the car share mode is performed from the first portable terminal 22a. First, the case where the car share mode is turned on will be described. In step S301, the first portable terminal 22a and the car sharing device 23 are activated by operating the first portable terminal 22a (US application 30) and activating the key function (key function unit 38) of the car sharing device 23. Move to authentication complete state (connection complete state).
 ステップS302において、第1携帯端末22a(UIアプリケーション30)においてカーシェアモードオン操作が実行される。カーシェアモードオン操作では、例えば第1携帯端末22aの画面に「カーシェアモードオン」のボタンが表示されて、そのボタンがタッチ操作される。 In step S302, the car share mode on operation is performed in the first portable terminal 22a (UI application 30). In the car share mode on operation, for example, a button of "car share mode on" is displayed on the screen of the first portable terminal 22a, and the button is touch-operated.
 ステップS303において、第1携帯端末22a(UIアプリケーション30)は、カーシェアモードオン操作の実行に応答して、カーシェアモードオン要求(スマート機能無効要求)をカーシェア装置23に無線送信する。 In step S303, the first portable terminal 22a (UI application 30) wirelessly transmits a car share mode on request (smart function disable request) to the car share apparatus 23 in response to the execution of the car share mode on operation.
 ステップS304において、カーシェア装置23は、第1携帯端末22aから送信されたカーシェアモードオン要求(スマート機能無効要求)を照合ECU9に出力する。このカーシェアモードオン要求は、カーシェア装置23と照合ECU9とが無線接続されている場合には、電子キーシステム4を通じて照合ECU9に送られ、カーシェア装置23と照合ECU9とが有線接続されている場合には、配線40を通じて照合ECU9に送られる。 In step S304, the car share device 23 outputs the car share mode on request (smart function disable request) transmitted from the first portable terminal 22a to the verification ECU 9. When the car share device 23 and the verification ECU 9 are wirelessly connected, this car share mode on request is sent to the verification ECU 9 through the electronic key system 4, and the car share device 23 and the verification ECU 9 are wire connected. If it is, it is sent to the verification ECU 9 through the wiring 40.
 ステップS305において、照合ECU9(モード切替部41)は、カーシェア装置23からのカーシェアモードオン要求(スマート機能無効要求)に応答して、シェア車両1の作動モードをカーシェアモードに切り替える。これにより、スマート機能が無効にされる。ここで、照合ECU9及びカーシェア装置23が無線接続の場合は、例えば照合ECU9のウェイク信号送信機能が無効にされることにより、スマート機能が無効化される。また、照合ECU9及びカーシェア装置23が有線接続の場合は、例えば、スマート機能が有効である間は、車両1(電波送信機16)のLF電波送信機能が有効にされて車両11は操作端末2aからのUHF電波を受信可能であるが、スマート機能が無効にされた後は、LF電波送信機能が無効にされることにより車両1は操作端末2aからのUHF電波を受信しなくなる。 In step S305, the verification ECU 9 (mode switching unit 41) switches the operation mode of the share vehicle 1 to the car share mode in response to the car share mode ON request (smart function disable request) from the car share device 23. This will disable the smart feature. Here, when the verification ECU 9 and the car share device 23 are wirelessly connected, the smart function is invalidated, for example, by disabling the wake signal transmission function of the verification ECU 9. When the verification ECU 9 and the car sharing device 23 are connected by wire, for example, while the smart function is valid, the LF radio transmission function of the vehicle 1 (radio wave transmitter 16) is enabled and the vehicle 11 is the operation terminal Although the UHF radio wave from 2a can be received, after the smart function is invalidated, the vehicle 1 does not receive the UHF radio wave from the operation terminal 2a because the LF radio wave transmission function is invalidated.
 ステップS306において、照合ECU9(モード切替部41)は、カーシェアモードオン応答(スマート機能無効応答)をカーシェア装置23に出力する。カーシェアモードオン応答は、無線接続の場合には電子キーシステム4を通じてカーシェア装置23に送られ、有線接続の場合には配線40を通じてカーシェア装置23に送られる。 In step S306, the verification ECU 9 (mode switching unit 41) outputs a car share mode on response (smart function invalid response) to the car share device 23. The car share mode ON response is sent to the car share device 23 through the electronic key system 4 in the case of wireless connection, and is sent to the car share device 23 through the wire 40 in the case of wired connection.
 ステップS307において、カーシェア装置23は、照合ECU9からのカーシェアモードオン応答(スマート機能無効応答)を第1携帯端末22aに無線送信する。そして、第1携帯端末22a(UIアプリケーション30)は、カーシェアモードオン通知を、例えば第1携帯端末22aの画面に表示するなどする。これにより、シェア車両1のオーナに、カーシェアモードがオンされたことが通知される。 In step S307, the car share device 23 wirelessly transmits the car share mode on response (smart function invalid response) from the verification ECU 9 to the first portable terminal 22a. Then, the first mobile terminal 22a (UI application 30) displays the car share mode on notification, for example, on the screen of the first mobile terminal 22a. Thus, the owner of the share vehicle 1 is notified that the car share mode has been turned on.
 なお、第1携帯端末22aからカーシェアモードをオフする処理は、図6のステップS308~S314に示す手順でカーシェアモードをオンする処理と同様に行われる。本例では、カーシェアモードオフ要求(スマート機能有効要求)が第1携帯端末22aからカーシェア装置23を介して照合ECU9に送信されることで、カーシェアモードがオフされる。そして、カーシェアモードオフ応答(スマート機能有効応答)が照合ECU9からカーシェア装置23を介して第1携帯端末22aに送信されることで、シェア車両1のオーナに、カーシェアモードがオフされたことが通知される。 The process of turning off the car share mode from the first portable terminal 22a is performed in the same manner as the process of turning on the car share mode in the procedure shown in steps S308 to S314 of FIG. In this example, the car share mode is turned off by transmitting a car share mode off request (smart function enable request) from the first portable terminal 22 a to the verification ECU 9 via the car share device 23. Then, the car share mode off response (smart function valid response) is transmitted from the verification ECU 9 to the first portable terminal 22a via the car share device 23, so that the owner of the share vehicle 1 has the car share mode turned off. Will be notified.
 [バレットパーキングモード有効無効切り替えシーケンス]
 図7に示すように、バレットパーキングモードのオン(有効)及びオフ(無効)の切り替えは、第2携帯端末22bから行うことができる。まず、バレットパーキングモードをオンする場合について説明する。ステップS401では、第2携帯端末22b(UIアプリケーション30)が操作されてカーシェア装置23のキー機能(キー機能部38)が有効にされることにより、第2携帯端末22b及びカーシェア装置23が認証完了状態(接続完了状態)に移行する。
[Ballet parking mode enable / disable switching sequence]
As shown in FIG. 7, switching of the valet parking mode on (valid) and off (invalid) can be performed from the second portable terminal 22 b. First, the case where the valet parking mode is turned on will be described. In step S401, the second mobile terminal 22b and the car share device 23 are activated by the second mobile terminal 22b (UI application 30) being operated and the key function (key function unit 38) of the car share device 23 being enabled. Move to authentication complete state (connection complete state).
 ステップS402において、第2携帯端末22b(UIアプリケーション30)においてバレットパーキングモードオン操作が実行される。バレットパーキングモードオン操作では、例えば第2携帯端末22bの画面に「バレットパーキングモードオン」のボタンが表示されて、そのボタンがタッチ操作される。 In step S402, the bullet parking mode on operation is performed in the second portable terminal 22b (UI application 30). In the bullet parking mode on operation, for example, a button of "ballet parking mode on" is displayed on the screen of the second portable terminal 22b, and the button is touch-operated.
 ステップS403において、第2携帯端末22b(UIアプリケーション30)は、バレットパーキングモードオン操作の実行に応答して、バレットパーキングモードオン要求(スマート機能有効要求)をカーシェア装置23に無線送信する。 In step S403, the second portable terminal 22b (UI application 30) wirelessly transmits a valet parking mode on request (smart function activation request) to the car share device 23 in response to the execution of the valet parking mode on operation.
 ステップS404において、カーシェア装置23は、第2携帯端末22bから送信されたバレットパーキングモードオン要求(スマート機能有効要求)を照合ECU9に出力する。バレットパーキングモードオン要求は、カーシェア装置23と照合ECU9とが無線接続されている場合には、電子キーシステム4を通じて照合ECU9に送られ、カーシェア装置23と照合ECU9とが有線接続されている場合には、配線40を通じて照合ECU9に送られる。 In step S404, the car share device 23 outputs the valet parking mode on request (smart function enable request) transmitted from the second portable terminal 22b to the verification ECU 9. The valet parking mode ON request is sent to the verification ECU 9 through the electronic key system 4 when the car sharing device 23 and the verification ECU 9 are wirelessly connected, and the car sharing device 23 and the verification ECU 9 are wire connected In this case, it is sent to the verification ECU 9 through the wiring 40.
 ステップS405において、照合ECU9(モード切替部41)は、カーシェア装置23からのバレットパーキングモードオン要求(スマート機能有効要求)に応答して、シェア車両1の作動モードをバレットパーキングモードに切り替える。これにより、スマート機能が有効にされる。ここで、照合ECU9及びカーシェア装置23が無線接続の場合には、例えば照合ECU9のウェイク信号送信機能が有効にされることによりスマート機能が有効化される。また、照合ECU9及びカーシェア装置23が有線接続の場合は、車両1(電波送信機16)のLF電波送信機能が有効にされて車両1が操作端末2aからのUHF電波を受信可能となることで、スマート機能が有効化される。 In step S405, the verification ECU 9 (mode switching unit 41) switches the operation mode of the share vehicle 1 to the bullet parking mode in response to the bullet parking mode on request (smart function activation request) from the car sharing device 23. This enables the smart function. Here, when the verification ECU 9 and the car sharing device 23 are wirelessly connected, the smart function is validated by, for example, enabling the wake signal transmission function of the verification ECU 9. When the verification ECU 9 and the car sharing device 23 are connected by wire, the LF radio transmission function of the vehicle 1 (radio wave transmitter 16) is enabled and the vehicle 1 can receive UHF radio waves from the operation terminal 2a. The smart feature is enabled.
 ここで、バレットパーキングモードにおいてスマート機能が有効化される場合、シェア車両1において使用可能な機能を制限してもよい。この機能制限としては、例えば日時等でシェア車両1の使用期限を設定したり、トランクの解錠を無効にしたり、グローブボックスの解錠に無効にしたり、携帯端末22(車両キー)の追加登録を無効にしたりすることなどが挙げられる。 Here, when the smart function is enabled in the valet parking mode, the functions available on the share vehicle 1 may be limited. As this function limitation, for example, the expiration date of the share vehicle 1 is set by date and time etc., unlocking of the trunk is invalidated, unlocking of the glove box is invalidated, and additional registration of the portable terminal 22 (vehicle key) And the like.
 シェア車両1の作動モードがバレットパーキングモードに切り替わった後、ステップS406において、照合ECU9(モード切替部41)は、バレットパーキングモードオン応答(スマート機能有効応答)をカーシェア装置23に出力する。バレットパーキングモードオン応答は、無線接続の場合には電子キーシステム4を通じてカーシェア装置23に送られ、有線接続の場合には配線40を通じてカーシェア装置23に送られる。 After the operation mode of the shared vehicle 1 is switched to the bullet parking mode, in step S406, the verification ECU 9 (mode switching unit 41) outputs a bullet parking mode on response (smart function valid response) to the car share device 23. The valet parking mode on response is sent to the car sharing device 23 through the electronic key system 4 in the case of wireless connection, and is sent to the car sharing device 23 through the wire 40 in the case of wired connection.
 ステップS407において、カーシェア装置23は、照合ECU9からのバレットパーキングモードオン応答(スマート機能有効応答)を第2携帯端末22bに無線送信する。そして、第2携帯端末22b(UIアプリケーション30)は、バレットパーキングモードオン通知を、例えば第2携帯端末22bの画面に表示するなどする。これにより、カーシェア利用者に、バレットパーキングモードがオンされたことが通知される。 In step S407, the car sharing device 23 wirelessly transmits the bullet parking mode on response (smart function valid response) from the verification ECU 9 to the second portable terminal 22b. Then, the second mobile terminal 22b (UI application 30) displays a valet parking mode on notification, for example, on the screen of the second mobile terminal 22b. Thus, the car sharing user is notified that the valet parking mode has been turned on.
 なお、第2携帯端末22bからバレットパーキングモードをオフする処理は、図7のステップS408~S414に示す手順でバレットパーキングモードをオンする処理と同様に行われる。本例では、バレットパーキングモードオフ要求(スマート機能無効要求)が第2携帯端末22bからカーシェア装置23を介して照合ECU9に送信されることで、バレットパーキングモードがオフされる。そして、バレットパーキングモードオフ応答(スマート機能無効応答)が照合ECU9からカーシェア装置23を介して第2携帯端末22bに送信されることで、カーシェア利用者に、バレットパーキングモードがオフされたことが通知される。 The process of turning off the valet parking mode from the second portable terminal 22b is performed in the same manner as the process of turning on the valet parking mode in the procedure shown in steps S408 to S414 of FIG. In this example, the valet parking mode is turned off by transmitting a bullet parking mode off request (smart function invalidation request) from the second portable terminal 22 b to the verification ECU 9 via the car sharing device 23. Then, the valet parking mode is turned off for the car share user by the valence parking mode off response (smart function invalidation response) being transmitted from the verification ECU 9 to the second portable terminal 22 b via the car sharing device 23. Is notified.
 上記説明したカーシェアリングシステム21は、以下の利点を有する。
 シェア車両1のオーナ以外のカーシェア利用者がバレットパーキングサービスを利用する場合、カーシェア利用者の第2携帯端末22bを操作してシェア車両1の操作端末2aを無効状態から有効状態に切り替える。これにより、カーシェア利用者は、第2携帯端末22bではなく、シェア車両1に元から存在する操作端末2aをバレット係等の第三者に渡すことにより、バレットパーキングサービスを利用することができる。よって、カーシェアリングシステム21でバレットパーキングサービスを利用するために専用のバレットキーを用意する必要がない。
The car sharing system 21 described above has the following advantages.
When a car share user other than the owner of the shared vehicle 1 uses the valet parking service, the second mobile terminal 22 b of the car share user is operated to switch the operation terminal 2 a of the share vehicle 1 from the disabled state to the enabled state. Thereby, the car share user can use the valet parking service by handing the operation terminal 2a which originally exists in the share vehicle 1 instead of the second portable terminal 22b to a third party such as a valet person. . Therefore, it is not necessary to prepare a dedicated bullet key for using the valet parking service in the car sharing system 21.
 モード切替部41は、シェア車両1のオーナが用いる第1携帯端末22aとカーシェア装置23との無線通信を経て第1携帯端末22aの操作により作動モードを変更することが許可された場合に、シェア車両1の作動モードを、カーシェア利用者の第2携帯端末22bによって操作端末2aの有効状態と無効状態を切り替えることが可能なモード(本例ではカーシェアモード)に変更する。これにより、第1携帯端末22aが操作されて作動モードを変更することが許可されなければ、シェア車両1の作動モードをカーシェアモードに変更することができない。よって、作動モードが不正に変更されることを防止してセキュリティを向上することができる。 When the mode switching unit 41 is permitted to change the operation mode by the operation of the first mobile terminal 22a through the wireless communication between the first mobile terminal 22a used by the owner of the share vehicle 1 and the car sharing device 23, The operation mode of the shared vehicle 1 is changed to a mode (in the present example, a car share mode) in which the second mobile terminal 22b of the car share user can switch between the valid state and the invalid state of the operation terminal 2a. Thus, the operation mode of the share vehicle 1 can not be changed to the car share mode unless the first portable terminal 22a is operated to change the operation mode. Therefore, security can be improved by preventing the operating mode from being illegally changed.
 モード切替部41は、シェア車両1がオーナ以外のカーシェア利用者によって使用される場合(カーシェアモード時)に、初期状態として操作端末2aを無効状態に設定し、第2携帯端末22bの操作を通じて操作端末2aを無効状態から有効状態に切り替える。このように、シェア車両1の作動モードを通常モードからカーシェアモードに変更したときに操作端末2aが無効状態に設定されるため、カーシェアモードの使用時に操作端末2aが不正に使用される懸念がない。 When the share vehicle 1 is used by a car share user other than the owner (in the car share mode), the mode switching unit 41 sets the operation terminal 2a as an initial state to an invalid state, and operates the second portable terminal 22b. Switches the operation terminal 2a from the disabled state to the enabled state. As described above, when the operation mode of the share vehicle 1 is changed from the normal mode to the car share mode, the operation terminal 2a is set in the invalid state, so there is a concern that the operation terminal 2a is used illegally when using the car share mode There is no
 (第2実施形態)
 次に、第2実施形態を図8~図10に従って説明する。第2実施形態では、シェア車両1の各作動モードにおいて車両キーとして動作可能な端末(操作端末/形態端末)の種類が第1実施形態から変更されている。以下、第1実施形態と同一部分には同じ符号を付して説明を省略し、異なる部分についてのみ詳述する。
Second Embodiment
Next, a second embodiment will be described with reference to FIGS. In the second embodiment, the type of terminal (operation terminal / form terminal) operable as a vehicle key in each operation mode of the share vehicle 1 is changed from the first embodiment. Hereinafter, the same parts as those of the first embodiment are denoted by the same reference numerals, and the description thereof is omitted. Only different parts will be described in detail.
 図8に示すように、第2実施形態のカーシェアリングシステム21では、第1実施形態と同様、複数の作動モード(本例では、通常モード、カーシェアモード、及び、バレットパーキングモード)のうちの一つがシェア車両1の作動モードとして選択される。また、第2実施形態のカーシェアリングシステム21は、第1操作端末2sと第2操作端末2tとを含む。ここで、第1操作端末2sは、シェア車両1のメイン車両キー(オーナーキーとも呼ばれる)であり、第2操作端末2tは、シェア車両1のサブ車両キーである。第1及び第2操作端末2s,2tは、例えば、図1の電子キー2と同様に構成されるスマートキーとすることができる。第2操作端末2tは、例えば、車内に保管され得る。第2実施形態のモード切替部41は、第1操作端末2s、第2操作端末2t、及びカーシェア装置23のいずれか一つを各作動モードで車両1の照合ECU9と通信するデバイス45として設定することにより、第1操作端末2s、第2操作端末2t、及び携帯端末22のいずれか一つを各作動モードでの車両キーとして使用可能にする。 As shown in FIG. 8, in the car sharing system 21 of the second embodiment, as in the first embodiment, among the plurality of operation modes (in this example, the normal mode, the car share mode, and the valet parking mode) One is selected as the operation mode of the share vehicle 1. The car sharing system 21 of the second embodiment includes a first operation terminal 2s and a second operation terminal 2t. Here, the first operation terminal 2 s is a main vehicle key (also called an owner key) of the share vehicle 1, and the second operation terminal 2 t is a sub-vehicle key of the share vehicle 1. The first and second operation terminals 2s and 2t can be, for example, smart keys configured similarly to the electronic key 2 of FIG. The second operation terminal 2t can be stored, for example, in a car. The mode switching unit 41 of the second embodiment sets one of the first operation terminal 2s, the second operation terminal 2t, and the car sharing device 23 as a device 45 that communicates with the verification ECU 9 of the vehicle 1 in each operation mode. By doing this, any one of the first operation terminal 2s, the second operation terminal 2t, and the portable terminal 22 can be used as a vehicle key in each operation mode.
 本例では、通常モードでは、第1操作端末2sでのみ車載機器3を作動させる(例えば車両ドア13の施解錠やエンジン6の始動等を行う)ことができる。つまり、通常モードでは、第1操作端末2sのみが有効にされて車両キーとして使用可能となる。カーシェアモードでは、カーシェア利用者の第2携帯端末22b(カーシェア装置23)のみが有効にされて車両キーとして使用可能となる。バレットパーキングモードでは、第2操作端末2tのみが有効にされて車両キーとして使用可能となる。通常モードからカーシェアモードへの切り替えは、第1操作端末2s又は第1携帯端末22aで行うことが可能である。カーシェアモードからバレットパーキングモードへの切り替えは、第2携帯端末22bでのみ行うことが可能である。 In the present embodiment, in the normal mode, the on-vehicle device 3 can be operated only at the first operation terminal 2s (for example, locking and unlocking of the vehicle door 13, start of the engine 6, and the like can be performed). That is, in the normal mode, only the first operation terminal 2s is validated and can be used as a vehicle key. In the car share mode, only the second mobile terminal 22b (car share device 23) of the car share user is validated and can be used as a vehicle key. In the valet parking mode, only the second operation terminal 2t is validated and can be used as a vehicle key. The switching from the normal mode to the car share mode can be performed by the first operation terminal 2s or the first portable terminal 22a. Switching from the car share mode to the valet parking mode can be performed only at the second portable terminal 22 b.
 次に、図9及び図10を用いて、第2実施形態のカーシェアリングシステム21の作用を説明する。
 図9に示すように、照合ECU9は、定期的又は不定期にウェイク信号を電波送信機16から送信し、照合ECU9の周囲に位置した特定のデバイス45(本例では、照合ECU9との通信対象として設定された、第1操作端末2s、第2操作端末2t、カーシェア装置23のうちのいずれか一つ)からのアックノレジメント(ACK)信号を待つ。照合ECU9は、特定のデバイス45からウェイク信号に対するACK信号を受信すると、そのデバイス45との通信を通じてチャレンジレスポンス認証を実行する。本例では、照合ECU9は、特定のデバイス45用のチャレンジコードを送信し、チャレンジコードを用いて演算されたレスポンスコードをそのデバイス45から受信する。また、照合ECU9も、チャレンジコードからレスポンスコードを演算し、その演算したレスポンスコードをデバイス45から送信されたレスポンスコードと比較する。そして、2つのレスポンスコードが一致すると、照合ECU9は、チャレンジレスポンス認証が成立したと判断する。
Next, the operation of the car sharing system 21 of the second embodiment will be described using FIGS. 9 and 10.
As shown in FIG. 9, the verification ECU 9 periodically or irregularly transmits a wake signal from the radio wave transmitter 16, and a specific device 45 located around the verification ECU 9 (in this example, a communication target with the verification ECU 9) Waits for an acknowledgment (ACK) signal from any one of the first operation terminal 2s, the second operation terminal 2t, and the car sharing device 23 set as (1). When the verification ECU 9 receives an ACK signal to the wake signal from a specific device 45, it executes challenge response authentication through communication with the device 45. In this example, the verification ECU 9 transmits a challenge code for a specific device 45, and receives from the device 45 a response code calculated using the challenge code. Further, the collation ECU 9 also calculates a response code from the challenge code, and compares the calculated response code with the response code transmitted from the device 45. When the two response codes match, the matching ECU 9 determines that the challenge response authentication has been established.
 図10に示すように、通常モード時は、照合ECU9と通信するデバイス45がメイン車両キーの第1操作端末2sに設定される。従って、照合ECU9は、第1操作端末2sとのみ通信してID照合(スマート照合又はワイヤレス照合)を行う。本例では、スマート照合が行われ、照合ECU9は、第1操作端末2sのみ応答可能な「ウェイク信号1」を送信する。第1操作端末2sは、電波送信機16から送信されたウェイク信号1を受信すると、ACK信号を照合ECU9に返信する。なお、スマート照合に代えてワイヤレス照合が行われる場合には、デバイス45(第1操作端末2s、第2操作端末2t、又はカーシェア装置23)が通信を開始してID照合が実行される。 As shown in FIG. 10, in the normal mode, the device 45 in communication with the verification ECU 9 is set to the first operation terminal 2s of the main vehicle key. Therefore, the verification ECU 9 communicates only with the first operation terminal 2s to perform ID verification (smart verification or wireless verification). In the present example, smart verification is performed, and the verification ECU 9 transmits “wake signal 1” that can be responded to by only the first operation terminal 2s. When the first operation terminal 2s receives the wake signal 1 transmitted from the radio wave transmitter 16, the first operation terminal 2s sends back an ACK signal to the verification ECU 9. In the case where wireless verification is performed instead of smart verification, the device 45 (the first operation terminal 2s, the second operation terminal 2t, or the car sharing device 23) starts communication and ID verification is performed.
 照合ECU9は、ウェイク信号1に対するACK信号を第1操作端末2sから受信すると、チャレンジコードとして「チャレンジ1」を送信する。チャレンジ1は、レスポンスコード演算に第1操作端末2sのみが使用可能なチャレンジコードである。第1操作端末2sは、チャレンジ1を受信すると、チャレンジ1と所与の暗号鍵とからレスポンスコードを演算し、演算したレスポンスコードを照合ECU9に送信する。また、照合ECU9も、同じ暗号鍵とチャレンジ1とからレスポンスコードを演算する。そして、照合ECU9は、演算したレスポンスコードと第1操作端末2sから送信されたレスポンスコードとを比較して、両者が一致すれば、チャレンジレスポンス認証が成立したと判断する。このチャレンジレスポンス認証に加えて、照合ECU9は、第1操作端末2sの電子キーID照合も行う。そして、チャレンジレスポンス認証と電子キーID照合が成立すると、照合ECU9は、第1操作端末2sとのスマート照合が成立したと判断する。その結果、通常モードでは、第1操作端末2s(メイン車両キー)のみが有効にされて車載機器3を作動する車両キーとして使用可能となる。 When the verification ECU 9 receives an ACK signal corresponding to the wake signal 1 from the first operation terminal 2s, the verification ECU 9 transmits "challenge 1" as a challenge code. The challenge 1 is a challenge code that can be used only by the first operation terminal 2s for the response code calculation. When receiving the challenge 1, the first operation terminal 2s calculates a response code from the challenge 1 and a given encryption key, and transmits the calculated response code to the verification ECU 9. The verification ECU 9 also calculates the response code from the same encryption key and the challenge 1. Then, the comparison ECU 9 compares the calculated response code with the response code transmitted from the first operation terminal 2s, and if both match, it is determined that the challenge response authentication is established. In addition to the challenge response authentication, the verification ECU 9 also performs electronic key ID verification of the first operation terminal 2s. Then, when the challenge response authentication and the electronic key ID collation are established, the collation ECU 9 determines that the smart collation with the first operation terminal 2s is established. As a result, in the normal mode, only the first operation terminal 2s (main vehicle key) is validated and can be used as a vehicle key for operating the on-vehicle device 3.
 カーシェアモード時には、照合ECU9と通信するデバイス45がカーシェア装置23に設定される。この場合、照合ECU9は、カーシェア装置23とのみ通信してID照合(スマート照合又はワイヤレス照合)を行う。本例では、カーシェアモードでは、照合ECU9は、カーシェア装置23のみが応答可能な「ウェイク信号2」を送信する。そして、照合ECU9は、カーシェア装置23からACK信号を受信すると、チャレンジコードとして「チャレンジ2」を送信する。チャレンジ2は、レスポンスコード演算にカーシェア装置23のみが使用可能なチャレンジコードである。そして、通常モードの場合と同様にして、照合ECU9は、カーシェア装置23との通信を介してチャレンジレスポンス認証を行い、チャレンジレスポンス認証と電子キーID照合が成立すると、カーシェア装置23とのスマート照合が成立したと判断する。その結果、カーシェアモードでは、カーシェア装置23のみが有効にされ、カーシェア利用者の第2携帯端末22bのみがカーシェア装置23を通じて車載機器3を作動する車両キーとして使用可能となる。 In the car share mode, the device 45 communicating with the verification ECU 9 is set in the car share device 23. In this case, the verification ECU 9 communicates only with the car share device 23 to perform ID verification (smart verification or wireless verification). In the present embodiment, in the car share mode, the verification ECU 9 transmits the “wake signal 2” that only the car share device 23 can respond to. Then, when the verification ECU 9 receives the ACK signal from the car sharing device 23, the verification ECU 9 transmits "challenge 2" as a challenge code. The challenge 2 is a challenge code that can be used only by the car sharing device 23 for response code calculation. Then, in the same manner as in the normal mode, the verification ECU 9 performs challenge response authentication via communication with the car share device 23, and when challenge response authentication and electronic key ID verification are established, the smart with the car share device 23 is performed. It is determined that the collation has been established. As a result, in the car share mode, only the car share device 23 is enabled, and only the second mobile terminal 22 b of the car share user can be used as a vehicle key for operating the on-vehicle device 3 through the car share device 23.
 バレットパーキングモード時には、照合ECU9と通信するデバイス45がサブ車両キーの第2操作端末2tに設定される。この場合、照合ECU9は、第2操作端末2tとのみ通信してID照合(スマート照合やワイヤレス照合)を行う。本例では、バレットパーキングモードでは、照合ECU9は、第2操作端末2tのみが応答可能な「ウェイク信号3」を送信する。そして、照合ECU9は、第2操作端末2tからACK信号を受信すると、チャレンジコードとして「チャレンジ3」を送信する。チャレンジ3は、レスポンスコード演算に第2操作端末2tのみが使用可能なチャレンジコードである。そして、通常モードの場合と同様にして、照合ECU9は、第2操作端末2tとの通信を介してチャレンジレスポンス認証を行い、チャレンジレスポンス認証と電子キーID照合が成立すると、第2操作端末2tとのスマート照合が成立したと判断する。その結果、バレットパーキングモードでは、第2操作端末2t(サブ車両キー)のみが有効にされて車載機器3を作動する車両キーとして使用可能となる。 In the bullet parking mode, the device 45 communicating with the verification ECU 9 is set to the second operation terminal 2t of the sub vehicle key. In this case, the verification ECU 9 communicates only with the second operation terminal 2t to perform ID verification (smart verification or wireless verification). In the present embodiment, in the valet parking mode, the verification ECU 9 transmits the “wake signal 3” which can be responded only by the second operation terminal 2t. And collation ECU9 will transmit "challenge 3" as a challenge code | cord, if an ACK signal is received from the 2nd operation terminal 2t. The challenge 3 is a challenge code that can be used only by the second operation terminal 2t for response code calculation. Then, as in the case of the normal mode, the verification ECU 9 performs challenge response authentication via communication with the second operation terminal 2t, and when challenge response authentication and electronic key ID verification are established, the second operation terminal 2t and It is determined that the smart verification of has been established. As a result, in the valet parking mode, only the second operation terminal 2t (sub vehicle key) is validated and can be used as a vehicle key for operating the in-vehicle device 3.
 第2実施形態のカーシェアリングシステム21は、以下の利点を有する。
 モード切替部41は、第1操作端末2s、第2操作端末2t、及びカーシェア装置23のいずれか一つを各作動モードで照合ECU9と通信するデバイス45として設定する。これにより、第1操作端末2s、第2操作端末2t、及び携帯端末22(本例では、カーシェア利用者の第2携帯端末22b)のいずれか一つが各作動モードでの車両キーとして使用可能となる。よって、シェア車両1の各作動モードにおいて1つのデバイス45のみを作動させればよいので、各デバイス45の消費電力を低く抑えるのに有利となる。
The car sharing system 21 of the second embodiment has the following advantages.
The mode switching unit 41 sets any one of the first operation terminal 2s, the second operation terminal 2t, and the car sharing device 23 as a device 45 that communicates with the verification ECU 9 in each operation mode. Thereby, any one of the first operation terminal 2s, the second operation terminal 2t, and the portable terminal 22 (in this example, the second portable terminal 22b of the car sharing user) can be used as a vehicle key in each operation mode It becomes. Therefore, since only one device 45 needs to be operated in each operation mode of the share vehicle 1, it is advantageous to keep the power consumption of each device 45 low.
 なお、上記実施形態はこれまでに述べた構成に限らず、以下に変更してもよい。
 ・各実施形態において、シェア車両1の作動モードは、通常モード、カーシェアモード及びバレットパーキングモードに限定されず、他のモードも採用可能である。
The above embodiment is not limited to the configuration described above, and may be modified as follows.
In each embodiment, the operation mode of the share vehicle 1 is not limited to the normal mode, the car share mode, and the valet parking mode, and other modes may be adopted.
 ・各実施形態において、操作端末2a,2s,2tの有効状態と無効状態を切り替えることが可能なモードは、カーシェアモードに限定されず、他のモードとしてもよい。
 ・各実施形態において、通常モードからカーシェアモードへの変更は、シェア車両1のオーナが有する第1携帯端末22aで行うことに限定されない。例えば、サーバ20又はオーナが所持する他の通信機器等からの指示で、シェア車両1が通常モードからカーシェアモードに切り替えられてもよい。
In each embodiment, the mode capable of switching between the valid state and the invalid state of the operation terminals 2a, 2s, and 2t is not limited to the car share mode, and may be another mode.
In each embodiment, the change from the normal mode to the car share mode is not limited to being performed by the first portable terminal 22 a possessed by the owner of the share vehicle 1. For example, the share vehicle 1 may be switched from the normal mode to the car share mode by an instruction from the server 20 or another communication device owned by the owner.
 ・各実施形態において、操作端末2aは、電子キーに限定されず、任意の車両キーであればよい。
 ・各実施形態において、作動モードが通常モードからカーシェアモードに切り替えられたときに、初期状態として操作端末2aを無効状態に設定することに限定されない。例えば、カーシェアモードに切り替えられたときに、操作端末2aを有効状態又は無効状態に設定するための設定モードに作動モードが移行してもよい。この場合、カーシェア利用者がシェア車両1を借りて使用するタイミングで、操作端末2aを有効状態又は無効状態に設定すればよい。
-In each embodiment, the operation terminal 2a is not limited to an electronic key, What is necessary is just an arbitrary vehicle key.
In each embodiment, when the operation mode is switched from the normal mode to the car share mode, the present invention is not limited to setting the operation terminal 2a in the invalid state as the initial state. For example, when the mode is switched to the car share mode, the operation mode may shift to a setting mode for setting the operation terminal 2a to the valid state or the invalid state. In this case, the operation terminal 2a may be set to the valid state or the invalid state at the timing when the car share user borrows and uses the share vehicle 1.
 ・各実施形態において、モード切替部41は、照合ECU9ではなく、他のデバイスに設けられてもよい。
 ・各実施形態において、暗号鍵は、ユーザ認証鍵以外の他の任意の暗号鍵に変更してもよい。
In each embodiment, the mode switching unit 41 may be provided not in the matching ECU 9 but in another device.
In each embodiment, the encryption key may be changed to any other encryption key other than the user authentication key.
 ・各実施形態において、携帯端末22やカーシェア装置23は、ユーザ認証鍵をどのような手順や方式で取得してもよい。
 ・各実施形態において、鍵情報Dkは、カーシェア装置固有暗号鍵によって暗号化された情報に限定されず、他の任意の暗号鍵で暗号化されてもよい。
In each embodiment, the portable terminal 22 or the car sharing device 23 may obtain the user authentication key by any procedure or method.
In each embodiment, the key information Dk is not limited to the information encrypted by the car sharing device unique encryption key, and may be encrypted by any other encryption key.
 ・各実施形態において、鍵情報Dkの内容は、上記説明した内容に限定されず、他の任意の情報を含むことができる。
 ・各実施形態において、鍵情報Dkは、サーバ20で生成されることに限定されず、他の任意の外部装置で生成されてもよい。
In each embodiment, the content of the key information Dk is not limited to the content described above, and may include other arbitrary information.
In each embodiment, the key information Dk is not limited to being generated by the server 20, and may be generated by any other external device.
 ・各実施形態において、キー機能部38を無効状態から有効状態へ切り替える条件は、上記説明した条件に限定されず、他の任意の条件としてもよい。
 ・各実施形態において、エンジン6の始動は、例えば携帯端末22の画面に「エンジン始動」のボタンを表示させ、このボタンが操作されることにより開始されてもよい。
In each embodiment, the condition for switching the key function unit 38 from the invalid state to the valid state is not limited to the condition described above, and may be another arbitrary condition.
In each embodiment, the start of the engine 6 may be started by, for example, displaying a button of “engine start” on the screen of the portable terminal 22 and operating this button.
 ・各実施形態において、キー操作フリーシステム(電子キーシステム4)で実施されるスマート照合では、電子キー2が車両1内にあるのかそれとも車両1外にあるのかを判定するために車外送信機及び車内送信機を用いることに限定されない。例えば、車体の左右にアンテナ(LFアンテナ)を配置し、各アンテナから送信される電波(通信エリア)に対する電子キー2の応答の組み合わせを確認することにより、電子キー2が車両1内にあるのかそれとも車両1外にあるのかを判定してもよい。 In each embodiment, in smart verification performed in the key operation free system (electronic key system 4), an external transmitter and an external vehicle for determining whether the electronic key 2 is inside the vehicle 1 or outside the vehicle 1 It is not limited to using an in-vehicle transmitter. For example, if antennas (LF antennas) are arranged on the left and right of the vehicle body and the combination of the response of the electronic key 2 to the radio waves (communication area) transmitted from each antenna is confirmed, is the electronic key 2 in the vehicle 1? Alternatively, it may be determined whether the vehicle 1 is outside.
 ・各実施形態において、電子キーシステム4のスマート照合では、電子キーID照合及びチャレンジレスポンス認証の双方を行うことに限定されない。少なくとも電子キーID照合が行われるものであればよく、照合方法には任意の方法を用いることができる。また、チャレンジレスポンス認証に代えて、任意の他の認証を用いてもよい。 In each embodiment, the smart verification of the electronic key system 4 is not limited to performing both the electronic key ID verification and the challenge response authentication. Any method may be used as the collation method as long as at least electronic key ID collation is performed. Also, any other authentication may be used instead of the challenge response authentication.
 ・各実施形態において、電子キーシステム4では、照合ECU9の代わりに電子キー2が無線通信を開始して電子キーID照合を実行するワイヤレスキーシステムを採用してもよい。
 ・各実施形態において、電子キー2は、スマートキー(登録商標)に限定されず、任意の他のワイヤレスキーとしてもよい。
In each embodiment, the electronic key system 4 may adopt a wireless key system in which the electronic key 2 starts wireless communication and executes electronic key ID collation instead of the collation ECU 9.
In each embodiment, the electronic key 2 is not limited to the smart key (registered trademark), and may be any other wireless key.
 ・各実施形態において、近距離無線通信は、ブルートゥース通信に限定されず、任意の他の通信方式に変更可能である。
 ・各実施形態において、鍵情報Dkは、ワンタイムキーに限定されず、任意の他の使用が制限された情報であればよい。
In each embodiment, the near field communication is not limited to the Bluetooth communication, and can be changed to any other communication method.
In each embodiment, the key information Dk is not limited to the one-time key, and may be any other restricted information.
 ・各実施形態において、暗号通信に使用する暗号鍵としては、例えばカーシェア装置固有暗号鍵、ユーザ認証鍵、電子キー固有暗号鍵のうちのいずれを使用することもできる。この場合、例えば、処理の途中で使用する暗号鍵を切り替えれば、通信セキュリティをより向上するのに有利となる。 In each embodiment, as an encryption key used for encryption communication, any of a car share device unique encryption key, a user authentication key, and an electronic key unique encryption key can be used, for example. In this case, for example, switching the encryption key to be used in the middle of the process is advantageous for further improving the communication security.
 ・各実施形態において、カーシェア装置23の搭載場所は、特に限定されない。
 ・各実施形態において、携帯端末22は、スマートフォン等の高機能携帯電話に限定されず、任意の他の携帯端末に変更可能である。
In each embodiment, the mounting location of the car sharing apparatus 23 is not particularly limited.
In each embodiment, the mobile terminal 22 is not limited to a high-performance mobile phone such as a smartphone, and can be changed to any other mobile terminal.

Claims (5)

  1.  カーシェアリングシステムであって、
     電子キーシステムを通じて車載機器を作動させる車両キーとして動作可能なシェア車両用の操作端末と、
     前記車両キーとして動作可能な携帯端末と無線通信可能であり、前記携帯端末との無線通信を通じて鍵情報を認証し、認証された前記鍵情報を有する前記携帯端末の操作に応じて前記電子キーシステムを通じて前記車載機器を作動させるカーシェア装置と、
     前記シェア車両のオーナ以外のカーシェア利用者によって前記シェア車両が使用される場合に、前記シェア車両の作動モードを、前記カーシェア利用者の前記携帯端末によって前記操作端末の有効状態と無効状態を切り替え可能なモードに変更するモード切替部と
    を備えたカーシェアリングシステム。
    A car sharing system,
    An operation terminal for a share vehicle operable as a vehicle key for operating the in-vehicle device through the electronic key system;
    The electronic key system is wirelessly communicable with a portable terminal operable as the vehicle key, authenticates key information through wireless communication with the portable terminal, and operates the portable terminal having the authenticated key information. A car sharing device for operating the in-vehicle device through
    When the share vehicle is used by a car share user other than the owner of the share vehicle, the operation mode of the share vehicle is determined by the portable terminal of the car share user. A car sharing system provided with a mode switching unit that changes to a switchable mode.
  2.  前記カーシェア装置は、前記車両キーとして動作可能な複数の携帯端末と無線通信可能であり、
     前記複数の携帯端末は、前記シェア車両のオーナが用いる第1携帯端末と、前記カーシェア利用者が用いる第2携帯端末とを含み、
     前記モード切替部は、前記第1携帯端末と前記カーシェア装置との無線通信を介して前記第1携帯端末の操作により前記作動モードを変更することが許可された場合に、前記作動モードを、前記第2携帯端末によって前記操作端末の有効状態と無効状態を切り替え可能なモードに変更する、
    請求項1に記載のカーシェアリングシステム。
    The car sharing apparatus can wirelessly communicate with a plurality of portable terminals operable as the vehicle key,
    The plurality of mobile terminals include a first mobile terminal used by the owner of the share vehicle, and a second mobile terminal used by the car share user.
    When the mode switching unit is permitted to change the operation mode by the operation of the first portable terminal via wireless communication between the first portable terminal and the car sharing apparatus, the mode switching unit is configured to Changing the enabled state and the disabled state of the operation terminal to a switchable mode by the second mobile terminal;
    The car sharing system according to claim 1.
  3.  前記モード切替部は、
     前記シェア車両が前記カーシェア利用者によって使用される場合に、初期状態として前記操作端末を無効状態に設定し、
     前記カーシェア利用者の前記携帯端末と前記カーシェア装置との無線通信を介して前記カーシェア利用者の前記携帯端末が操作された場合に、前記操作端末を無効状態から有効状態に切り替える、
    請求項1又は2に記載のカーシェアリングシステム。
    The mode switching unit is
    When the shared vehicle is used by the car sharing user, the operating terminal is set to an invalid state as an initial state,
    When the mobile terminal of the car share user is operated through wireless communication between the mobile terminal of the car share user and the car share apparatus, the operation terminal is switched from the disabled state to the enabled state.
    The car sharing system according to claim 1 or 2.
  4.  前記モード切替部は、
     前記操作端末及び前記第1携帯端末の各々を前記車両キーとして使用可能な通常モードと、前記第2携帯端末を前記車両キーとして使用可能であり前記操作端末が無効状態とされる第1シェアモードとの間で前記作動モードを切替え可能であり、
     前記作動モードが前記通常モードから前記第1シェアモードに変更された後、前記第1シェアモードと、前記操作端末及び前記第2携帯端末の各々を前記車両キーとして使用可能な第2シェアモードとの間で前記作動モードを切替え可能である、
    請求項2に記載のカーシェアリングシステム。
    The mode switching unit is
    A normal mode in which each of the operation terminal and the first mobile terminal can be used as the vehicle key, and a first share mode in which the second mobile terminal can be used as the vehicle key and the operation terminal is disabled Switching between the operating modes, and
    After the operation mode is changed from the normal mode to the first share mode, the first share mode, and a second share mode in which each of the operation terminal and the second portable terminal can be used as the vehicle key Switching between the operating modes between
    The car sharing system according to claim 2.
  5.  前記操作端末は、前記シェア車両の複数の操作端末のうちの1つであり、
     前記電子キーシステムは、前記複数の操作端末及び前記カーシェア装置の各々と通信可能な照合装置を備え、
     前記モード切替部は、前記作動モードを複数の作動モード間で切り替え可能であり、前記複数の操作端末及び前記カーシェア装置のいずれか1つを各作動モードで前記照合装置と通信するデバイスとして設定することにより、前記複数の操作端末及び前記携帯端末のいずれか1つを各作動モードでの前記車両キーとして使用可能にする、
    請求項1~3のうちいずれか一項に記載のカーシェアリングシステム。
    The operation terminal is one of a plurality of operation terminals of the share vehicle,
    The electronic key system includes a verification device capable of communicating with each of the plurality of operation terminals and the car sharing device.
    The mode switching unit is capable of switching the operation mode among a plurality of operation modes, and setting any one of the plurality of operation terminals and the car sharing device as a device to communicate with the verification device in each operation mode To enable any one of the plurality of operation terminals and the portable terminal to be used as the vehicle key in each operation mode,
    The car sharing system according to any one of claims 1 to 3.
PCT/JP2018/040404 2017-11-14 2018-10-30 Car sharing system WO2019098020A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2017-219254 2017-11-14
JP2017219254A JP6993186B2 (en) 2017-11-14 2017-11-14 Car sharing system

Publications (1)

Publication Number Publication Date
WO2019098020A1 true WO2019098020A1 (en) 2019-05-23

Family

ID=66540229

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2018/040404 WO2019098020A1 (en) 2017-11-14 2018-10-30 Car sharing system

Country Status (2)

Country Link
JP (1) JP6993186B2 (en)
WO (1) WO2019098020A1 (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP7287102B2 (en) 2019-05-14 2023-06-06 株式会社リコー Contact member, drying device, and printing device
JP7172871B2 (en) * 2019-06-19 2022-11-16 株式会社オートネットワーク技術研究所 Portable devices, in-vehicle devices, communication systems
JP2021197638A (en) * 2020-06-15 2021-12-27 株式会社東海理化電機製作所 Communication control device and communication control method
JP2022079326A (en) * 2020-11-16 2022-05-26 パナソニックIpマネジメント株式会社 Vehicle and control device

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2013037568A (en) * 2011-08-09 2013-02-21 Aisin Seiki Co Ltd Operation authority imparting system in vehicle sharing, in-vehicle control device and program thereof
JP2016016835A (en) * 2014-07-11 2016-02-01 株式会社東海理化電機製作所 Car sharing system

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2013037568A (en) * 2011-08-09 2013-02-21 Aisin Seiki Co Ltd Operation authority imparting system in vehicle sharing, in-vehicle control device and program thereof
JP2016016835A (en) * 2014-07-11 2016-02-01 株式会社東海理化電機製作所 Car sharing system

Also Published As

Publication number Publication date
JP6993186B2 (en) 2022-01-13
JP2019091220A (en) 2019-06-13

Similar Documents

Publication Publication Date Title
JP6585664B2 (en) Car sharing system
CN109649332B (en) Vehicle sharing system
JP6588518B2 (en) Car sharing system
JP5999108B2 (en) Vehicle remote operation information providing device, in-vehicle remote operation information acquisition device, and vehicle remote operation system including these devices
WO2019098020A1 (en) Car sharing system
CN109649330B (en) Vehicle sharing system
WO2019004310A1 (en) Car sharing system and car sharing program
CN111989706A (en) Sharing system
JP6676597B2 (en) Car sharing system
JP2020176442A (en) Communication control system and communication control method
JP6916101B2 (en) Sharing system
JP2019091221A (en) Valet key and valet key control method
CN111989723B (en) Sharing system
JP6898139B2 (en) User authentication system and user authentication method
WO2019221016A1 (en) Shared system and control method therefor
JP2019090229A (en) Valet key and valet key control method
JP2019091222A (en) Bullet key control system and bullet key
JP2019191647A (en) Sharing system
JP6663886B2 (en) Car sharing system
WO2019221017A1 (en) Shared system and connection mode switching method
JP2020046812A (en) Authentication system and authentication method

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 18878866

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 18878866

Country of ref document: EP

Kind code of ref document: A1