WO2024201844A1 - 情報管理装置、端末装置、プログラム及び情報管理方法 - Google Patents

情報管理装置、端末装置、プログラム及び情報管理方法 Download PDF

Info

Publication number
WO2024201844A1
WO2024201844A1 PCT/JP2023/012965 JP2023012965W WO2024201844A1 WO 2024201844 A1 WO2024201844 A1 WO 2024201844A1 JP 2023012965 W JP2023012965 W JP 2023012965W WO 2024201844 A1 WO2024201844 A1 WO 2024201844A1
Authority
WO
WIPO (PCT)
Prior art keywords
processor
terminal device
key
digital key
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2023/012965
Other languages
English (en)
French (fr)
Inventor
諒 竹林
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Honda Motor Co Ltd
Original Assignee
Honda Motor Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Honda Motor Co Ltd filed Critical Honda Motor Co Ltd
Priority to JP2025509456A priority Critical patent/JPWO2024201844A1/ja
Priority to PCT/JP2023/012965 priority patent/WO2024201844A1/ja
Publication of WO2024201844A1 publication Critical patent/WO2024201844A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • BPERFORMING OPERATIONS; TRANSPORTING
    • B60VEHICLES IN GENERAL
    • B60RVEHICLES, VEHICLE FITTINGS, OR VEHICLE PARTS, NOT OTHERWISE PROVIDED FOR
    • B60R25/00Fittings or systems for preventing or indicating unauthorised use or theft of vehicles
    • B60R25/20Means to switch the anti-theft system on or off
    • B60R25/24Means to switch the anti-theft system on or off using electronic identifiers containing a code not memorised by the user
    • EFIXED CONSTRUCTIONS
    • E05LOCKS; KEYS; WINDOW OR DOOR FITTINGS; SAFES
    • E05BLOCKS; ACCESSORIES THEREFOR; HANDCUFFS
    • E05B49/00Electric permutation locks; Circuits therefor ; Mechanical aspects of electronic locks; Mechanical keys therefor

Definitions

  • the present invention relates to an information management device, a terminal device, a program, and an information management method.
  • Patent Document 1 discloses a digital key system that can accurately estimate the distance from a smartphone to a vehicle.
  • the problem that the embodiments of the present invention aim to solve is to provide an information management device, terminal device, program, and information management method that can encourage safe driving by operators of machines using a digital key system.
  • the information management device of the embodiment includes a communication unit, a determination unit, and a restriction unit.
  • the communication unit communicates with a first terminal device used as a digital key that restricts and/or releases at least one function of a machine.
  • the determination unit determines whether a first user who uses the first terminal device satisfies a predetermined condition. If the predetermined condition is satisfied, the restriction unit places the digital key in a restricted state in which the digital key cannot restrict and/or release the function.
  • the present invention uses a digital key system to encourage operators of machinery to drive safely.
  • FIG. 1 is a block diagram showing an example of a main configuration of a digital key system according to an embodiment and components included in the digital key system.
  • FIG. 1 is a block diagram showing an example of a main configuration of a digital key system according to an embodiment and components included in the digital key system.
  • 4 is a flowchart showing an example of processing by a processor of the server device in FIG. 1 .
  • 4 is a flowchart showing an example of processing by a processor of the server device in FIG. 1 .
  • 4 is a flowchart showing an example of processing by a processor of the server device in FIG. 1 .
  • 4 is a flowchart showing an example of processing by a processor of the key terminal device in FIG. 1 .
  • FIG. 4 is a flowchart showing an example of processing by a processor of the key terminal device in FIG. 1 .
  • 3 is a flowchart showing an example of processing by a processor of the control device in FIG. 2 .
  • 3 is a flowchart showing an example of processing by a processor of the control device in FIG. 2 .
  • 3 is a flowchart showing an example of processing by a processor of the terminal device in FIG. 2 .
  • the digital key system 1 is a system that provides a digital key service.
  • the digital key service is a service that enables a digital key to be used as a key for a vehicle.
  • the digital key is a service that enables a portable electronic device having a communication function, such as a smartphone, to be used as a key.
  • the digital key service is a service that can limit the function of the digital key if a predetermined condition is not satisfied.
  • the digital key system 1 includes, as an example, a server device 100, a key terminal device 200, a vehicle 300, and a terminal device 400. Note that the digital key system 1 may include some of these. Note that, although one each of the server device 100, the key terminal device 200, the vehicle 300, and the terminal device 400 is shown in FIG. 1 and FIG. 2, the number of each component is not limited.
  • the server device 100, the key terminal device 200, the vehicle 300, and the terminal device 400 are connected to a network NW.
  • the network NW is typically a communication network including the Internet.
  • the network NW is typically a communication network including a WAN (wide area network).
  • the network NW may be a communication network including a private network such as an intranet.
  • the network NW may also be a communication network including a dedicated line or a public mobile phone network.
  • the server device 100 is a server for providing the digital key service.
  • the server device 100 manages various data in the digital key service and controls the digital keys.
  • the server device 100 includes a processor 101, a ROM (read-only memory) 102, a RAM (random-access memory) 103, an auxiliary storage device 104, and a communication interface 105.
  • a bus 106 and the like connect these components.
  • the server device 100 is an example of an information management device.
  • the processor 101 is the central part of the computer that performs calculations and control processes necessary for the operation of the server device 100, and performs various calculations and processes.
  • the processor 101 is, for example, a CPU (central processing unit), an MPU (micro processing unit), a SoC (system on a chip), a DSP (digital signal processor), a GPU (graphics processing unit), an ASIC (application specific integrated circuit), a PLD (programmable logic device), or an FPGA (field-programmable gate array).
  • the processor 101 is a combination of several of these.
  • the processor 101 may also be a combination of these with a hardware accelerator.
  • the processor 101 controls each part to realize various functions of the server device 100 based on programs such as firmware, system software, and application software stored in the ROM 102 or the auxiliary storage device 104.
  • the processor 101 also executes the processes described below based on the programs.
  • part or all of the program may be incorporated into the circuitry of the processor 101.
  • the ROM 102 and the RAM 103 are main memory devices of the computer with the processor 101 at its core.
  • the ROM 102 is a non-volatile memory used exclusively for reading data.
  • the ROM 102 stores, for example, firmware among the above programs.
  • the ROM 102 also stores data used by the processor 101 when performing various processes.
  • the RAM 103 is a memory used for reading and writing data.
  • the RAM 103 is used as a work area for storing data that is temporarily used when the processor 101 performs various processes.
  • the RAM 103 is typically a volatile memory.
  • the auxiliary storage device 104 is an auxiliary storage device of a computer with the processor 101 at its core.
  • the auxiliary storage device 104 is, for example, an EEPROM (electrical erasable programmable read-only memory), a HDD (hard disk drive), or flash memory.
  • the auxiliary storage device 104 stores, for example, system software and application software from among the above programs.
  • the auxiliary storage device 104 also stores data used by the processor 101 in performing various processes, data generated by the processes in the processor 101, various setting values, etc.
  • the data stored in the auxiliary storage device 104 includes, for example, a user DB (database).
  • the user DB is a database that stores and manages information about users who use the digital key service.
  • the user DB stores information about each user (hereinafter referred to as "user information") in association with a user ID (identifier).
  • the user ID is identification information that is uniquely assigned to each user.
  • the user information includes, for example, various settings related to the digital key service (hereinafter referred to as "key service settings") and server restriction variables. Default values may be set for each setting included in the key service settings. The default values are set in advance, for example, by the designer or administrator of the key system 1 or the seller of the vehicle 300. Some key service settings may be changeable by the user, and some may not be changeable.
  • the server restriction variable indicates whether the digital key of the user identified by the associated user ID is in a restricted or unrestricted state. The restricted and unrestricted states will be described later.
  • the communication interface 105 is an interface through which the server device 100 communicates via a network NW or the like.
  • the communication interface 105 functions as an example of a communication unit that communicates with a first terminal device.
  • the communication interface 105 is also an example of a communication device.
  • the processor 101 also functions as an example of a communication control unit that controls the communication device to communicate with the first terminal device by controlling the communication interface 105 to communicate with the first terminal device.
  • Bus 106 includes a control bus, an address bus, a data bus, etc., and transmits signals exchanged between each part of server device 100.
  • the key terminal device 200 is a portable electronic device with a communication function that can be used as a digital key.
  • the digital key can at least restrict and/or release at least one function of the vehicle 300.
  • the key terminal device 200 is, for example, a general-purpose electronic device such as a smartphone, a tablet terminal, or a smartwatch.
  • the key terminal device 200 may be an electronic device dedicated to digital keys.
  • the key terminal device 200 includes a processor 201, a ROM 202, a RAM 203, an auxiliary storage device 204, a communication interface 205, a wireless interface 206, a display device 207, and an input device 208.
  • a bus 209 and the like connect these components.
  • the key terminal device 200 is an example of a first terminal device.
  • a user of the key terminal device 200 is an example of a first user who uses the first terminal device.
  • the processor 201 is the central part of the computer that performs the calculations and control processes required for the operation of the key terminal device 200, and performs various calculations and processes.
  • the processor 201 is, for example, a CPU, MPU, SoC, DSP, GPU, ASIC, PLD, or FPGA. Alternatively, the processor 201 is a combination of two or more of these. The processor 201 may also be a combination of these with a hardware accelerator or the like.
  • the processor 201 controls each part to realize various functions of the key terminal device 200 based on programs such as firmware, system software, and application software stored in the ROM 202 or the auxiliary storage device 204.
  • the processor 201 also executes the processes described below based on the programs. Note that some or all of the programs may be incorporated into the circuitry of the processor 201.
  • the ROM 202 and the RAM 203 are main memory devices of the computer with the processor 201 at its core.
  • the ROM 202 is a non-volatile memory used exclusively for reading data.
  • the ROM 202 stores, for example, firmware among the above programs.
  • the ROM 202 also stores data used by the processor 201 when performing various processes.
  • the RAM 203 is a memory used for reading and writing data.
  • the RAM 203 is used as a work area for storing data that is temporarily used when the processor 201 performs various processes.
  • the RAM 203 is typically a volatile memory.
  • the auxiliary storage device 204 is an auxiliary storage device of a computer with the processor 201 at its core.
  • the auxiliary storage device 204 is, for example, an EEPROM, HDD, or flash memory.
  • the auxiliary storage device 204 stores, for example, system software and application software among the above programs.
  • the auxiliary storage device 204 also stores data used by the processor 201 when performing various processes, data generated by the processes in the processor 201, various setting values, and the like.
  • the auxiliary storage device 204 is an example of a storage device.
  • the application software stored in the auxiliary storage device 204 includes a key app.
  • the key app is application software for using a digital key service.
  • the key app is application software that enables the key terminal device 200 to function as a digital key.
  • the processor 201 downloads the key app, for example, via the communication interface 205.
  • the processor 201 also installs the downloaded key app. Alternatively, the key app may be installed in advance in the key terminal device 200.
  • the key app uses the key information to unlock the vehicle 300.
  • the key app transmits the key information to the vehicle 300 to allow authentication using the key information.
  • the key information is unique for each combination of the target vehicle 300 and the user who will use it. By registering multiple pieces of key information, the key app is able to unlock multiple vehicles 300 that correspond to each piece of key information.
  • An expiration date may also be set for the key information. In this case, the key information is only valid within the expiration date.
  • the key app includes a restriction variable.
  • the restriction variable indicates whether the digital key operated by the key app is in a restricted or unrestricted state.
  • the restricted and unrestricted states are described below.
  • the key terminal device 200 logs in to the digital key service using a user ID, for example.
  • the processor 201 may perform the login automatically, or may perform the login based on an operation by the operator of the key terminal device 200.
  • the key terminal device 200 stores the user ID used for logging in. This user ID will be referred to as the "login ID" below.
  • the communication interface 205 is an interface that allows the key terminal device 200 to communicate via a network NW, etc.
  • the wireless interface 206 is an interface that allows the key terminal device 200 to wirelessly communicate with the vehicle 300.
  • the wireless interface 206 includes an antenna for wireless communication, etc.
  • the display device 207 displays a screen for notifying the operator of the key terminal device 200 of various information.
  • the display device 207 is, for example, a liquid crystal display or an organic electroluminescence (EL) display.
  • the input device 208 accepts operations by the operator of the key terminal device 200.
  • the input device 208 is, for example, a keyboard, a keypad, a touchpad, a mouse, or a controller.
  • the input device 208 may also be a device for voice input.
  • a touch panel may also be used as the display device 207 and the input device 208. In this case, the display panel provided in the touch panel functions as the display device 207. And the pointing device provided in the touch panel that uses touch input functions as the input device 208.
  • the bus 209 includes a control bus, an address bus, a data bus, etc., and transmits signals exchanged between each part of the key terminal device 200.
  • the vehicle 300 is, for example, an automobile.
  • the vehicle 300 includes, as an example, a control device 310, a key interface 320, a door 330, a power unit 340, an electrical unit 350, and a start button 360.
  • the control device 310 performs various controls of the vehicle 300.
  • the control device 310 has a function of authenticating key information read from the key terminal device 200.
  • the control device 310 authenticates valid key information, it has a function of unlocking the locked state of the vehicle 300 to an unlocked state.
  • the vehicle 300 in the locked state is in a state in which the electronic lock 331 described below is locked, and each part of the vehicle 300, including the power unit 340 and the electrical unit 350, cannot be started.
  • the locked state is an example of a locked state in which the vehicle 300 cannot be driven.
  • the locked state is an example of a state in which at least one function of the vehicle 300 is restricted.
  • the vehicle 300 in the unlocked state is in a state in which the electronic lock 331 is unlocked, and each part of the vehicle 300, including the power unit 340 and the electrical unit 350, can be started.
  • the control device 310 is, for example, an ECU (electronic control unit).
  • the control device 310 includes, for example, a processor 311, a ROM 312, a RAM 313, an auxiliary storage device 314, a communication interface 315, and a control interface 316.
  • a bus 317 and the like connect these components.
  • the processor 311 is the central part of the computer that performs calculations and control processes necessary for the operation of the vehicle 300, and performs various calculations and processes.
  • the processor 311 is, for example, a CPU, MPU, SoC, DSP, GPU, ASIC, PLD, or FPGA. Alternatively, the processor 311 is a combination of two or more of these. The processor 311 may also be a combination of these with a hardware accelerator or the like.
  • the processor 311 controls each part to realize various functions of the vehicle 300 based on programs such as firmware, system software, and application software stored in the ROM 312 or the auxiliary storage device 314.
  • the processor 311 also executes processes described below based on the programs. Some or all of the programs may be incorporated into the circuitry of the processor 311.
  • the ROM 312 and the RAM 313 are main memory devices of the computer with the processor 311 at its core.
  • the ROM 312 is a non-volatile memory used exclusively for reading data.
  • the ROM 312 stores, for example, firmware among the above programs.
  • the ROM 312 also stores data used by the processor 311 when performing various processes.
  • the RAM 313 is a memory used for reading and writing data.
  • the RAM 313 is used as a work area for storing data that is temporarily used when the processor 311 performs various processes.
  • the RAM 313 is typically a volatile memory.
  • the auxiliary storage device 314 is an auxiliary storage device of a computer with the processor 311 at its core.
  • the auxiliary storage device 314 is, for example, an EEPROM, a HDD, or a flash memory.
  • the auxiliary storage device 314 stores, for example, system software and application software from among the above programs.
  • the auxiliary storage device 314 also stores data used by the processor 311 when performing various processes, data generated by the processes in the processor 311, various setting values, etc.
  • the data stored in the auxiliary storage device 314 includes the vehicle ID and vehicle setting information of the vehicle 300 in which it is installed.
  • the vehicle ID is identification information unique to each vehicle 300.
  • the vehicle setting information is information related to the digital key service that includes settings related to the operation of the vehicle 300.
  • a default value may be set for each setting included in the vehicle setting information. The default value is set in advance, for example, by the designer or administrator of the key system 1 or the seller of the vehicle 300. Some vehicle setting information may be changeable by the user, and some may not be changeable.
  • the communication interface 315 is an interface that allows the vehicle 300 to communicate via a network NW, etc.
  • the control interface 316 is an interface through which the control device 310 communicates with each part of the vehicle 300.
  • the control device 310 controls each part of the vehicle 300 via the control interface 316.
  • These parts include, for example, a key interface 320, a door 330, a power unit 340, an electrical unit 350, and a start button 360.
  • Bus 317 includes a control bus, an address bus, a data bus, etc., and transmits signals exchanged between each part of the control device 310.
  • the key interface 320 is an interface for wireless communication with the key terminal device 200 that functions as a digital key.
  • the key interface 320 includes an antenna for wireless communication, etc.
  • Door 330 is a door for entering and exiting vehicle 300.
  • Door 330 is, for example, a door for entering and exiting the driver's seat, which is the place where vehicle 300 is driven.
  • Door 330 is equipped with an electronic lock 331.
  • the electronic lock 331 is an electronic lock that can be opened with a digital key.
  • the power unit 340 is the parts and equipment that allow the vehicle 300 to run.
  • the power unit 340 is, for example, a power unit, a battery, a drive system, etc.
  • the power unit is, for example, an engine or a motor.
  • the electrical equipment unit 350 is the components and equipment of the electrical system.
  • Examples of the electrical equipment unit 350 include a car air conditioner, in-car Wi-Fi, in-car entertainment, car audio, an in-car display, a car navigation system, in-car devices, and instruments.
  • the start button 360 is a button that is operated to start up the power unit 340 and part or all of the electrical unit 350.
  • the terminal device 400 is a device that can view various information related to the digital key service and change various settings.
  • the terminal device 400 is, for example, a PC (personal computer), a tablet terminal, or a smartphone.
  • the terminal device 400 may be the key terminal device 200.
  • the terminal device 400 includes a processor 401, a ROM 402, a RAM 403, an auxiliary storage device 404, a communication interface 405, a display device 406, and an input device 407.
  • a bus 408 and the like connect these components.
  • the terminal device 400 is an example of a second terminal device.
  • a user of the terminal device 400 is an example of a second user who uses the second terminal device.
  • the application software stored in the terminal device 400 includes a viewing application.
  • the viewing application is application software that allows the user to view various information related to the digital key service and change various settings.
  • the viewing application may be general-purpose application software such as a web browser, or it may be application software dedicated to the digital key system 1.
  • the terminal device 400 logs in to the digital key service in the same way as the key terminal device 200.
  • the terminal device 400 stores the login ID.
  • the processor 401 is the central part of the computer that performs the calculations and control processes required for the operation of the terminal device 400, and performs various calculations and processes.
  • the processor 401 is, for example, a CPU, MPU, SoC, DSP, GPU, ASIC, PLD, or FPGA. Alternatively, the processor 401 is a combination of two or more of these. The processor 401 may also be a combination of these with a hardware accelerator.
  • the processor 401 controls each part to realize various functions of the terminal device 400 based on programs such as firmware, system software, and application software stored in the ROM 402 or auxiliary storage device 404.
  • the processor 401 also executes the processes described below based on the programs. Some or all of the programs may be incorporated into the circuitry of the processor 401.
  • the ROM 402 and the RAM 403 are main storage devices of the computer with the processor 401 at its core.
  • the ROM 402 is a non-volatile memory used exclusively for reading data.
  • the ROM 402 stores, for example, firmware among the above programs.
  • the ROM 402 also stores data used by the processor 401 when performing various processes.
  • the RAM 403 is a memory used for reading and writing data.
  • the RAM 403 is used as a work area for storing data that is temporarily used when the processor 401 performs various processes.
  • the RAM 403 is typically a volatile memory.
  • the auxiliary storage device 404 is an auxiliary storage device of a computer with the processor 401 at its core.
  • the auxiliary storage device 404 is, for example, an EEPROM, a HDD, or a flash memory.
  • the auxiliary storage device 404 stores, for example, system software and application software from among the above programs.
  • the auxiliary storage device 404 also stores data used by the processor 401 when performing various processes, data generated by the processes in the processor 401, various setting values, etc.
  • the communication interface 405 is an interface through which the terminal device 400 communicates via a network NW, etc.
  • the display device 406 displays a screen for notifying the operator of the terminal device 400 of various information.
  • the display device 406 is, for example, a display such as a liquid crystal display or an organic EL display.
  • the input device 407 accepts operations by the operator of the terminal device 400.
  • the input device 407 is, for example, a keyboard, a keypad, a touchpad, a mouse, or a controller.
  • the input device 407 may also be a device for voice input.
  • a touch panel may also be used as the display device 406 and the input device 407. In this case, the display panel provided in the touch panel functions as the display device 406. And the pointing device provided in the touch panel that is used for touch input functions as the input device 407.
  • Bus 408 includes a control bus, an address bus, a data bus, etc., and transmits signals exchanged between each part of terminal device 400.
  • FIGS 3 to 5 are flowcharts showing an example of the process by the processor 101 of the server device 100.
  • the processor 101 executes the processes of Figures 3 to 5 based on a program stored in, for example, the ROM 102 or the auxiliary storage device 104.
  • the processor 101 executes the processes of Figures 3 to 5 in parallel or in parallel, for example.
  • Figures 6 and 7 are flowcharts showing an example of the process by the processor 201 of the key terminal device 200.
  • the processor 201 executes the processes of Figures 6 and 7 based on a program stored in, for example, the ROM 202 or the auxiliary storage device 204.
  • Figures 8 and 9 are flowcharts showing an example of the process by the processor 311 of the control device 310.
  • the processor 311 executes the processes of Figures 8 and 9 based on a program stored in, for example, the ROM 312 or the auxiliary storage device 314.
  • the processor 311 executes, for example, the processes of FIG. 8 and FIG. 9 in parallel or in parallel.
  • FIG. 10 is a flowchart showing an example of the process by the processor 401 of the terminal device 400.
  • the processor 401 executes the process of FIG. 10 based on a program stored in, for example, the ROM 402 or the auxiliary storage device 404.
  • step ST61 of FIG. 6 the processor 201 of the key terminal device 200 determines whether or not to change the key service settings. If the processor 201 determines not to change the key service settings, it determines No in step ST61 and proceeds to step ST62.
  • step ST62 processor 201 determines whether or not to newly register key information. If processor 201 determines not to newly register key information, it determines No in step ST62 and proceeds to step ST63.
  • step ST63 the processor 201 determines whether or not to connect to the key interface 320. If the processor 201 does not determine to connect to the key interface 320, the processor 201 determines No in step ST63 and proceeds to step ST64.
  • step ST64 the processor 201 determines whether or not a restriction request has been received by the communication interface 205. If a restriction request has not been received, the processor 201 determines No in step ST64 and proceeds to step ST65.
  • step ST65 the processor 201 determines whether or not notification information has been received by the communication interface 205. If notification information has not been received, the processor 201 determines No in step ST65 and proceeds to step ST66.
  • step ST66 processor 201 determines whether or not to start checking the driving situation. If processor 201 does not determine to start checking the driving situation, it determines No in step ST64 and proceeds to step ST67.
  • step ST67 the processor 201 determines whether or not a restriction removal request has been received by the communication interface 205. If a restriction removal request has not been received, the processor 201 determines No in step ST67 and proceeds to step ST68.
  • step ST68 the processor 201 determines whether or not to lock the vehicle 300.
  • the processor 201 determines that the vehicle 300 is to be locked when, for example, an operation instructing that the vehicle 300 is to be locked is performed using the input device 208. If the processor 201 does not determine that the vehicle 300 is to be locked, it determines No in step ST68 and returns to step ST61. Thus, the processor 201 enters a standby state in which it repeats steps ST61 in FIG. 6 to ST68 in FIG.
  • the operator When an operator of the key terminal device 200 wishes to change the key service settings, the operator operates the input device 208, for example, to input the changes to the key service settings.
  • the processor 201 determines that the key service settings should be changed in response to the input.
  • step ST61 in FIG. 6 determines Yes in step ST61 in FIG. 6 and proceeds to step ST68.
  • step ST69 the processor 201 generates a change request.
  • the change request includes, for example, a login ID and change information.
  • the change information indicates the changes to be made to the key service settings.
  • the processor 201 instructs the communication interface 205 to send the change request to the server device 100.
  • the communication interface 205 sends the change request to the server device 100.
  • the sent change request is received by the communication interface 105 of the server device 100.
  • the processor 201 returns to step ST61.
  • step ST11 of FIG. 3 the processor 101 of the server device 100 determines whether or not a change request has been received by the communication interface 105. If a change request has not been received, the processor 101 determines No in step ST11 and proceeds to step ST12.
  • step ST12 the processor 101 determines whether or not a key request has been received by the communication interface 105. If a key request has not been received, the processor 101 determines No in step ST12 and proceeds to step ST13.
  • step ST13 the processor 101 determines whether or not a start request has been received by the communication interface 105. If a start request has not been received, the processor 101 determines No in step ST13 and proceeds to step ST14.
  • step ST14 the processor 101 determines whether or not a confirmation notification has been received by the communication interface 105. If the processor 101 has not received a confirmation notification, the processor 101 determines No in step ST14 and returns to step ST11. Thus, the processor 101 goes into a standby state in which it repeats steps ST11 to ST14 until a change request, a key request, a start request, or a confirmation notification is received. The key request, start request, and confirmation notification will be described later.
  • step ST11 If the processor 101 receives a change request while in a standby state in which it repeats steps ST11 to ST14, it determines Yes in step ST11 and proceeds to step ST15.
  • step ST15 the processor 101 changes the key service settings by updating the user DB based on the change request received in step ST11. That is, the processor 101 changes the key service settings associated with the user ID included in the change request in accordance with the change information included in the change request.
  • the processor 101 determines whether the changes to the key service settings include changes that require changes to the operation of the vehicle 300. If the changes to the key service settings include changes that require changes to the operation of the vehicle 300, the processor 101 generates setting information.
  • the setting information indicates the setting that changes the operation of the vehicle 300.
  • the processor 101 instructs the communication interface 105 to transmit the setting information to the control device 310.
  • the communication interface 105 Upon receiving this transmission instruction, the communication interface 105 transmits the setting information to the control device 310.
  • the transmitted setting information is received by the communication interface 315 of the control device 310. After processing step ST15, the processor 101 returns to step ST11.
  • step ST91 of FIG. 8 the processor 311 of the control device 310 determines whether or not the setting information has been received by the communication interface 315. If the setting information has not been received, the processor 311 determines No in step ST91 and proceeds to step ST92.
  • step ST92 processor 311 determines whether or not to transmit driving data. If processor 311 does not determine to transmit driving data, it determines No in step ST92 and returns to step ST91. Thus, processor 311 enters a standby state in which it repeats steps ST91 and ST92 until it receives setting information or determines to transmit driving data. Driving data will be described later.
  • step ST91 If the processor 311 receives setting information while in a standby state in which steps ST91 and ST92 are repeated, it determines Yes in step ST91 and proceeds to step ST93.
  • step ST93 the processor 311 updates the vehicle setting information according to the setting information received in step ST91. After processing step ST93, the processor 311 returns to step ST91.
  • the operator When an operator of the key terminal device 200 wishes to register new key information in the key app, the operator inputs an instruction to the key terminal device 200 to register new key information using a predetermined method.
  • the processor 201 determines to register a new digital key in response to the input instructing the user to register new key information.
  • step ST61 in FIG. 6 to step ST68 in FIG. 7 are repeated, the processor 201 determines Yes in step ST62 and proceeds to step ST70 in FIG. 6.
  • the processor 201 In step ST70, the processor 201 generates a key request.
  • the key request includes target information.
  • the key request is information requesting the transmission of key information identified by the target information.
  • the target information is information that can identify the vehicle 300 that the key information targets and the user who will use the key information.
  • the processor 201 instructs the communication interface 315 to transmit the key request to the server device 100.
  • the communication interface 315 Upon receiving this transmission instruction, the communication interface 315 transmits the key request to the server device 100.
  • the transmitted key request is received by the communication interface 105 of the server device 100.
  • step ST12 determines Yes in step ST12 and proceeds to step ST16.
  • step ST16 the processor 101 generates key information according to the target information included in the key request received in step ST12.
  • step ST17 the processor 101 generates a key response.
  • the key response includes the key information generated in step ST16.
  • the key response is, for example, information instructing to register the key information.
  • the processor 101 instructs the communication interface 105 to transmit the key response to the key terminal device 200 that sent the key request.
  • the communication interface 105 Upon receiving this transmission instruction, transmits the key response to the key terminal device 200.
  • the transmitted key response is received by the communication interface 315 of the key terminal device 200.
  • the processor 101 returns to step ST11.
  • step ST71 of FIG. 6 the processor 201 of the key terminal device 200 waits for a key response to be received by the communication interface 315. If a key response is received, the processor 201 determines Yes in step ST71 and proceeds to step ST72.
  • step ST72 the processor 201 registers the key information included in the key response received in step ST71 in the key app. At this time, the processor 201 stores the key information in the auxiliary storage device 204. After processing in step ST72, the processor 201 returns to step ST61.
  • the processor 201 determines to connect to the key interface 320, for example, when the distance between the key terminal device 200 and the key interface 320 is within a predetermined distance.
  • the processor 201 determines to connect to the key interface 320, for example, when it receives radio waves transmitted by the key interface 320.
  • the processor 201 determines to connect to the key interface 320, for example, when it becomes possible to communicate with the key interface 320.
  • the processor 201 determines to connect to the key interface 320 in response to, for example, the holder of the key terminal device 200 waving at the door 330.
  • step ST61 in FIG. 6 If the processor 201 determines to connect to the key interface 320 while in a standby state in which it repeats step ST61 in FIG. 6 to step ST68 in FIG. 7, it determines Yes in step ST63 and proceeds to step ST73 in FIG. 6.
  • step ST73 the processor 201 establishes communication between the wireless interface 206 and the key interface 320.
  • step ST74 the processor 201 determines whether or not the digital key is in a restricted state. If the digital key is not in a restricted state, i.e., if the digital key is in an unrestricted state, the processor 201 determines No in step ST74 and proceeds to step ST75.
  • the restricted and unrestricted states will be described later.
  • step ST75 the processor 201 generates an unlock request.
  • the unlock request is information requesting that the vehicle 300 be unlocked.
  • the unlock request includes, for example, a login ID, a restriction variable stored in the auxiliary storage device 204, and key information registered in the key app.
  • the value of the restriction variable is a value indicating an unrestricted state.
  • the processor 201 instructs the wireless interface 206 to transmit the unlock request to the vehicle 300.
  • the wireless interface 206 Upon receiving this transmission instruction, the wireless interface 206 transmits the unlock request to the vehicle 300.
  • the transmitted unlock request is received by the key interface 320 of the vehicle 300.
  • the processor 201 returns to step ST61.
  • the processor 201 of the key terminal device 200 functions as an example of a digital key section that causes the first terminal device to function as a digital key by executing the processes of step ST63 and steps ST73 to ST75 in FIG. 6.
  • the processor 311 of the control device 310 starts the process shown in FIG. 9 when, for example, the vehicle 300 is locked. 9, the processor 311 of the control device 310 determines whether or not an unlock request has been received by the key interface 320. If an unlock request has not been received, the processor 311 determines No in step ST101 and proceeds to step ST102.
  • step ST102 processor 311 determines whether or not to lock vehicle 300. If processor 311 does not determine that vehicle 300 should be locked, it determines No in step ST102 and returns to step ST101. Thus, processor 311 enters a standby state in which it repeats steps ST101 and ST102 until it receives an unlock request or determines that vehicle 300 should be locked.
  • step ST101 If the processor 311 receives an unlock request while in a standby state in which it repeats steps ST101 and ST102, it determines Yes in step ST101 and proceeds to step ST103.
  • step ST103 processor 311 performs authentication using the key information included in the unlock request received in step ST101. Processor 311 then determines whether or not the authentication is successful. If the authentication is not successful, processor 311 determines No in step ST103 and returns to step ST101. On the other hand, if the authentication is successful, processor 311 determines Yes in step ST103 and proceeds to step ST104.
  • step ST104 the processor 311 refers to the restriction variable included in the unlock request received in step ST101 to determine whether the digital key is in a restricted state. If the digital key is not in a restricted state, the processor 311 determines No in step ST104 and proceeds to step ST104.
  • step ST105 the processor 311 controls the electronic lock 331 to unlock it. This allows the holder of the key terminal device 200 to enter the vehicle 300. Once inside the vehicle 300, if the holder or the like wishes to start each part of the vehicle 300, such as the power unit 340, the holder or the like performs an operation to start the vehicle 300, for example, by operating the start button 360.
  • step ST106 processor 311 waits for an operation to start vehicle 300 to be performed. That is, processor 311 waits for a predetermined operation, such as operating start button 360, to be performed. If an operation to start vehicle 300 has been performed, processor 311 determines Yes in step ST106 and proceeds to step ST107.
  • step ST107 processor 311 refers to the restriction variable included in the unlock request received in step ST101 to determine whether the digital key is in a restricted state. If the digital key is not in a restricted state, processor 311 determines No in step ST107 and proceeds to step ST108.
  • step ST108 processor 311 starts each part of vehicle 300. After processing step ST108, processor 311 ends the processing shown in FIG. 9.
  • the vehicle 300 has a function of recording driving data for each driver.
  • the driver of the vehicle 300 is identified by the user ID included in the unlock request received in step ST101 of FIG. 9.
  • the control device 310 records the driving data using, for example, various sensors.
  • the driving data includes, for example, a driving route, a speed history, an acceleration history, a jerk history, a brake opening history, a braking timing history, a history of sudden braking, an accelerator opening history, an accelerator timing history, a steering angle history, a steering timing history, a history of deviation from the driving lane, a collision mitigation brake operation history, a history of failure to stop at a stop sign, a history of failure to signal at an intersection, etc., a history of slow-down violations at an intersection, etc., a history of wrong-way driving, a history of speeding, an excessive acceleration when speeding, information indicating whether each road on the driving route is an expressway, information indicating whether the driver recognized each road sign that should be checked while driving, a
  • the vehicle 300 also has a function of transmitting the driving data to the server device 100.
  • the control device 310 transmits the driving data at a predetermined timing, for example.
  • the predetermined timing is, for example, a regular timing.
  • the predetermined timing is the timing when the driver stops driving the vehicle 300.
  • the predetermined timing is the timing when the vehicle 300 is locked.
  • the processor 311 of the control device 310 determines to transmit the driving data when the predetermined timing arrives.
  • step ST92 If the processor 311 determines that driving data is to be transmitted while in a standby state in which steps ST91 and ST92 in FIG. 8 are repeated, it determines Yes in step ST92 and proceeds to step ST94.
  • step ST94 the processor 311 acquires any unsent driving data of the driver identified by the user ID included in the unlock request received in step ST101 of FIG. 9.
  • step ST95 of FIG. 8 the processor 311 generates driving data information.
  • the driving data information includes the driving data acquired in step ST94 and the user ID included in the unlock request received in step ST101 of FIG. 9.
  • the processor 311 instructs the communication interface 315 to transmit the driving data information to the server device 100.
  • the communication interface 315 transmits the driving data information to the server device 100.
  • the transmitted driving data information is received by the communication interface 105 of the server device 100.
  • the processor 311 returns to step ST91.
  • step ST31 of FIG. 4 the processor 101 of the server device 100 waits for the reception of driving data information by the communication interface 105. If the driving data information is received, the processor 101 judges Yes in step ST31 and proceeds to step ST32.
  • step ST32 the processor 101 analyzes the driving data included in the driving data information received in step ST31.
  • the analysis includes a diagnosis of the driving situation.
  • the processor 101 may also use driving data previously stored in the user DB for analysis.
  • the processor 101 acquires the driving data by controlling the communication interface 105 to receive driving data information.
  • the processor 101 acquires the analysis results of the driving data by executing the processing of step ST32.
  • the processor 101 functions as an example of an acquisition unit that acquires the operating status of the machine by the first user by at least one of receiving the driving data information and executing the processing of step ST32.
  • step ST33 the processor 101 stores the driving data included in the driving data information received in step ST31 and the analysis results of step ST32 in the user DB in association with the user ID included in the driving data information.
  • the processor 101 functions as an example of a storage unit that stores the driving status by performing the processing of step ST33 in cooperation with the auxiliary storage device 104.
  • the processor 101 functions as an example of a storage unit by controlling the auxiliary storage device 104 to perform the processing of step ST33.
  • step ST34 processor 101 determines whether to place restrictions on the digital key used by the user and put it into a restricted state based on the driving data and the analysis results of step ST32.
  • the user in question is the user identified by the user ID included in the driving data information received in step ST31.
  • Processor 101 determines to put the digital key into a restricted state, for example, if it determines that there is a problem with the user's driving that is sufficient to warrant putting restrictions on the digital key.
  • Examples of problems that may be considered to be problematic to the extent that the digital key is restricted include, for example, the number of sudden braking is more than a predetermined number, the number of deviations from the driving lane is more than a predetermined number, the collision mitigation brake is activated more than a predetermined number, the number of failures to stop at a stop sign is more than a predetermined number, the number of failures to signal at an intersection is more than a predetermined number, the number of violations of slowing down at an intersection is more than a predetermined number, the number of times that the vehicle is traveling in the wrong direction is more than a predetermined number, the number of times that the vehicle is overspeeding is more than a predetermined number, the number of times that the vehicle is overspeeding by a speeding rate more than a predetermined number, the frequency of use of the expressway is within a predetermined frequency range, the number of times that the driver does not recognize each road sign that must be checked while driving is more than a predetermined number, the number of times that the driver falls asleep
  • the processor 101 may also consider that there is a problem that may be considered to be problematic to the extent that the digital key is restricted when the processor 101 determines that the user's driving is not safe. If the processor 101 does not determine that the digital key is to be restricted, the processor 101 determines No in step ST34 and returns to step ST31. On the other hand, if the processor 101 determines that the digital key should be placed in a restricted state, it judges Yes in step ST34 and proceeds to step ST35.
  • the processor 101 functions as an example of a determination unit that determines whether the first user using the first terminal device satisfies a specified condition. Furthermore, a problem that is severe enough to place restrictions on the digital key is an example of a problem with the first user's driving. Therefore, the specified condition in step ST34 is that there is a problem with the first user's driving.
  • step ST35 the processor 101 updates the user DB, and sets the value of the server restriction variable associated with the user ID included in the driving data information received in step ST31 to a value indicating a restricted state.
  • the processor 101 also updates the user DB, and resets the date and time when each user last checked the driving situation identified by the user ID. The date and time when the driving situation was checked will be described later.
  • step ST36 the processor 101 instructs the communication interface 105 to send a restriction request to the key terminal device 200 used by the user ID included in the driving data information received in step ST31.
  • the restriction request is information that instructs the digital key to be placed in a restricted state.
  • the communication interface 105 Upon receiving this instruction to send, the communication interface 105 sends the restriction request to the key terminal device 200.
  • the sent restriction request is received by the communication interface 315 of the key terminal device 200.
  • the processor 101 returns to step ST31.
  • the processor 101 executes a process to send a restriction request, and functions as an example of a restriction unit that places the digital key in a restricted state in which at least a portion of the machine lock cannot be released if a specified condition is met.
  • the processor 101 cooperates with the communication interface 105 to send a restriction request, and functions as an example of a restriction unit.
  • the processor 201 of the key terminal device 200 receives a restriction request while in a standby state in which it repeats step ST61 in FIG. 6 to step ST68 in FIG. 7, it determines Yes in step ST64 and proceeds to step ST78 in FIG. 7.
  • step ST78 the processor 201 places the digital key in a restricted state. To do so, the processor 201 rewrites the value of the restricted variable to a value that indicates the restricted state.
  • the processor 201 in cooperation with the auxiliary storage device 204, performs the processing of step ST78 in response to receiving a restriction request, thereby functioning as an example of a restriction storage unit that stores the fact that the digital key is in a restricted state in accordance with control by the restriction unit. Also, the processor 201 performs the processing of step ST78 in response to receiving a restriction request, thereby functioning as an example of a restriction storage unit that stores in the storage device that the digital key is in a restricted state in accordance with control by the restriction unit.
  • step ST79 the processor 201 notifies the holder of the key terminal device 200 that the digital key has entered a restricted state by notifying the holder of the key terminal device 200 that the digital key has entered a restricted state.
  • the processor 201 for example, causes the display device 207 to display an image indicating that the digital key has entered a restricted state and that the restricted state will be released if the driving situation is confirmed.
  • the processor 201 may also notify by outputting sound from a speaker, illuminating a light-emitting device, vibrating a vibrator, or the like.
  • the processor 201 may also notify by a push notification.
  • the processor 201 returns to step ST61 in FIG. 6.
  • a user of the digital key service can check the driving status of the vehicle 300 being driven by himself or another user.
  • the driving status is based on the driving data and analysis results stored in step ST33.
  • the digital key system 1 also has a function of restricting the digital key used by a user (hereinafter referred to as the "driving user” for distinction) when the driving status of the user has not been confirmed by a predetermined user (hereinafter referred to as the "predetermined user” for distinction) within a predetermined period P1.
  • the predetermined period P1 is, for example, a period from the present to a predetermined time ago.
  • the predetermined time is determined by hours, days, weeks, months, or years.
  • the driving user and the predetermined user may be the same or different. Which user is the predetermined user is determined by the key service settings of the driving user. It is assumed that the predetermined user is set to, for example, a family member or user of the driving user. There may be multiple predetermined users.
  • the driving user may or may not be included.
  • the digital key system 1 restricts the digital key, for example, when none of the predetermined users have confirmed the driving status within the predetermined period P1.
  • the digital key system 1 restricts the digital key when at least N of the predetermined users have not confirmed the driving status within the predetermined period P1.
  • N is an integer equal to or greater than 1 and less than the number of specified users.
  • the condition for restricting the digital key when there are multiple specified users is determined, for example, by the key service settings of the driving user.
  • the condition for restricting the digital key when there is one specified user is that the driving status has not been confirmed by the specified user within a specified period P1.
  • the condition for restricting the digital key is met when the driving status of the driving user is not confirmed by the specified user within the specified period P1, which is referred to as "the confirmation of the driving status exceeding the deadline."
  • the length of the specified period P1 is determined, for example, by the key service settings of the driving user.
  • the specified period P1 is an example of a first specified period.
  • step ST41 of FIG. 5 the processor 101 of the server device 100 determines whether there is a driving user whose period until the deadline for checking the driving status is exceeded is equal to or less than the predetermined period P2.
  • the processor 101 makes this determination, for example, by referring to the user DB.
  • the user DB stores, for each driving user, the date and time when the specified user last checked the driving status. If there is no driving user whose period until the deadline for checking the driving status is exceeded is equal to or less than the predetermined period P2, the processor 101 determines No in step ST41 and proceeds to step ST42.
  • step ST42 the processor 101 determines whether there is a driving user whose confirmation of the driving status has expired.
  • the processor 101 makes this determination by, for example, referring to a user DB. If there is no driving user whose confirmation of the driving status has expired, the processor 101 determines No in step ST42 and returns to step ST41. Thus, the processor 101 enters a standby state in which it repeats steps ST41 and ST42 until the period until the confirmation of the driving status expires becomes equal to or shorter than the predetermined period P2 or until the confirmation of the driving status expires.
  • step ST41 When the processor 101 is in a standby state in which steps ST41 and ST42 are repeated, if the processor 101 determines that there is a driving user whose driving status confirmation deadline is within the predetermined period P2, the processor 101 determines Yes in step ST41 and proceeds to step ST43.
  • step ST43 the processor 101 instructs the communication interface 105 to transmit the first notification information to the key terminal device 200 used by the driving user for whom the period until the deadline for checking the driving status has fallen below the predetermined period P2, and to the terminal device 400 used by a predetermined user other than the driving user among the predetermined users of the driving user.
  • the first notification information is information indicating that the deadline for checking the driving status is about to expire.
  • the first notification information is a type of notification information.
  • the communication interface 105 transmits the first notification information to the key terminal device 200 and the terminal device 400.
  • the transmitted first notification information is received by the communication interface 315 of the key terminal device 200.
  • the transmitted first notification information is received by the communication interface 405 of the terminal device 400.
  • the processor 101 returns to step ST41.
  • the period during which the driving status has not been checked until the predetermined period P1 has elapsed is equal to or less than the predetermined period P2, which is an example of a second predetermined period.
  • (second predetermined period) (predetermined period P1) - (predetermined period P2).
  • the processor 201 of the key terminal device 200 receives notification information while in a standby state in which it repeats step ST61 in FIG. 6 to step ST68 in FIG. 7, it determines Yes in step ST65 and proceeds to step ST80 in FIG. 7.
  • processor 201 notifies the user of the content indicated by the notification information in order to notify the user of the content.
  • Processor 201 for example, causes display device 207 to display an image indicating that the deadline for checking the driving status is about to expire.
  • Processor 201 may also notify the user by outputting sound from a speaker, illuminating a light-emitting device, vibrating a vibrator, or the like.
  • Processor 201 may also notify the user by a push notification.
  • processor 201 returns to step ST61 in FIG. 6.
  • the processor 401 of the terminal device 400 performs the same processing as part of the processing performed by the processor 201 of the key terminal device 200 in FIG. 6 and FIG. 7.
  • the part in question is steps ST61, ST65, ST66, ST69, and ST80 to ST84.
  • the same parts as the processing performed by the processor 201 of the key terminal device 200 in FIG. 6 and FIG. 7 will not be described.
  • the processing performed by the processor 401 in FIG. 10 is the same as that in FIG. 6 and FIG.
  • keyboard terminal device 200 is replaced with “terminal device 400”, "processor 201” with “processor 401”, “communication interface 205" with “communication interface 405", "display device 207” with “display device 406”, and “input device 208” with “input device 407”.
  • step ST61 of the terminal device 400 determines No in step ST61 of FIG. 10 If the processor 401 of the terminal device 400 determines No in step ST61 of FIG. 10, it proceeds to step ST65. If the processor 401 determines No in step ST66, it returns to step ST61. Thus, the processor 401 enters a standby state in which it repeats steps ST61, ST65, and ST66 of FIG. 10 until it determines that the key service setting should be changed, notification information has been received, or confirmation of the driving situation has begun.
  • step ST42 determines Yes in step ST42 and proceeds to step ST44.
  • step ST44 the processor 101 updates the user DB and sets the value of the server restriction variable associated with the user ID of the driving user whose driving status confirmation deadline has expired to a value indicating the restricted state.
  • step ST45 the processor 101 instructs the communication interface 105 to send a restriction request to the key terminal device 200 used by the driving user whose driving status confirmation deadline has expired.
  • the communication interface 105 Upon receiving this instruction to send, the communication interface 105 sends the restriction request to the key terminal device 200.
  • the sent restriction request is received by the communication interface 315 of the key terminal device 200.
  • the processor 101 functions as an example of a determination unit that determines whether a predetermined condition is met by a first user using a first terminal device that functions as a digital key used to release a lock that prevents the machine from being operated.
  • the predetermined condition in step ST42 when the driving user is a predetermined user is that the first user has not checked the driving status for a first predetermined period or more.
  • the predetermined condition in step ST42 when the predetermined user is someone other than the driving user is that a second user has not checked the driving status for a first predetermined period or more.
  • step ST46 the processor 101 instructs the communication interface 105 to transmit the second notification information to a terminal device 400 used by a specified user other than the driving user whose driving status confirmation deadline has expired.
  • the second notification information is information indicating that the deadline for confirming the driving status has expired.
  • the second notification information is a type of notification information.
  • the communication interface 105 Upon receiving this instruction to transmit, the communication interface 105 transmits the second notification information to the terminal device 400.
  • the transmitted second notification information is received by the communication interface 405 of the terminal device 400.
  • the processor 101 returns to step ST41.
  • step ST37 the processor 101 instructs the communication interface 105 to transmit the second notification information to a terminal device 400 used by a predetermined user other than the driving user, among the predetermined users of the driving users whose driving status confirmation deadline has expired.
  • the communication interface 105 Upon receiving this transmission instruction, transmits the second notification information to the terminal device 400.
  • the transmitted second notification information is received by the communication interface 405 of the terminal device 400.
  • the operator of the key terminal device 200 wishes to check the driving situation, for example, the operator uses the input device 208 to perform an operation input indicating that checking of the driving situation should be started.
  • the processor 201 of the key terminal device 200 determines to start checking the driving situation in response to the operation input.
  • step ST61 in FIG. 6 to step ST68 in FIG. 7 are repeated, it determines Yes in step ST64 and proceeds to step ST81 in FIG. 7.
  • the processor 201 In step ST81, the processor 201 generates a start request.
  • the start request includes, for example, a login ID and a target ID.
  • the target ID indicates which user's driving status is to be started.
  • the target ID is the user ID of the user. In this case, the target ID is the same as the login ID.
  • the start request is information indicating that the driving status is to be started.
  • the start request is also information requesting the transmission of information necessary to check the driving status of the user identified by the target ID.
  • the processor 201 instructs the communication interface 205 to transmit the start request to the server device 100.
  • the communication interface 205 Upon receiving this transmission instruction, the communication interface 205 transmits the start request to the server device 100.
  • the transmitted start request is received by the communication interface 105 of the server device 100.
  • the operator of the terminal device 400 wishes to check the driving status
  • the operator uses the input device 407 to perform an operation input indicating that he or she wishes to start checking the driving status.
  • the operator of the terminal device 400 also uses the input device 407 to perform an operation input specifying which user's driving status to check.
  • a user who can be designated is a driving user for whom the user specified by the login ID is the specified user.
  • a user who can be designated is a user who has given permission to check the driving status to the user specified by the login ID. Which users a user has given permission to check the driving status is determined by the key service settings of the user who has given permission to check the driving status.
  • the target ID in the start request generated by the processor 401 in step ST81 of FIG. 10 is the user ID of the user designated as the target for checking the driving status.
  • step ST13 determines Yes in step ST13 and proceeds to step ST18.
  • step ST18 the processor 101 refers to the user DB to obtain the analysis results and driving data associated with the target ID included in the start request received in step ST13.
  • step ST19 the processor 101 generates a start response.
  • the start response includes the analysis results and driving data acquired in step ST18, and the target ID included in the start request received in step ST13.
  • the start response is information that instructs the analysis results and driving data to be displayed.
  • the processor 101 instructs the communication interface 105 to transmit the start response to the key terminal device 200 or the terminal device 400 that sent the start request.
  • the communication interface 105 transmits the start response to the key terminal device 200 or the terminal device 400.
  • the transmitted start response is received by the communication interface 205 of the key terminal device 200 or the communication interface 405 of the terminal device 400.
  • the processor 101 returns to step ST11.
  • the processor 101 performs a process of transmitting a start response to the key terminal device 200, thereby communicating with the first terminal device, and functions as an example of a display control unit that displays the driving status on the first terminal device.
  • the processor 101 functions as an example of a display control unit in cooperation with the communication interface 105.
  • the processor 101 performs a process of transmitting a start response to the terminal device 400, thereby functions as an example of a display control unit that displays the driving status on the second terminal device.
  • step ST82 of FIG. 7 the processor 201 of the key terminal device 200 waits for a start response to be received by the communication interface 205. If a start response is received, the processor 201 judges Yes in step ST82 and proceeds to step ST83.
  • step ST83 the processor 201 starts a process for checking the driving situation.
  • the processor 201 causes, for example, the display device 207 to display a confirmation screen.
  • the confirmation screen includes, for example, the driving data and analysis results included in the start response received in step ST82.
  • the confirmation screen may span multiple pages.
  • the confirmation screen may be scrollable.
  • the operator of the key terminal device 200 checks the driving situation. That is, the operator looks at the driving data and analysis results displayed on the display device 207.
  • the operator wants to finish checking the driving situation he or she uses the input device 407 to input an operation indicating that he or she is instructing the operator to finish checking the driving situation.
  • step ST84 processor 201 waits for an operation to be performed that instructs the process for checking the driving status to end. That is, processor 201 waits for a predetermined operation, such as operating a button that instructs the process for checking the driving status to end. If an operation to instruct the process for checking the driving status to end is performed, processor 201 determines Yes in step ST84 and proceeds to step ST85.
  • step ST85 the processor 201 determines whether the operator of the key terminal device 200 has checked the driving situation.
  • the processor 201 determines that the operator has checked the driving situation, for example, when the time taken by the operator to check the driving situation is equal to or longer than a predetermined time.
  • the time taken by the operator to check the driving situation is, for example, the time from the execution of the process of step ST83 to the determination of Yes in step ST84.
  • the processor 201 determines that the operator has checked the driving situation, for example, when a predetermined number of pages or more or all pages of the confirmation screen are displayed.
  • the processor 201 determines that the operator has checked the driving situation, for example, when the confirmation screen is scrolled to a predetermined number of pages or more or when the confirmation screen is completely scrolled.
  • the confirmation screen may also display a test regarding the driving situation.
  • the processor 201 determines that the operator has checked the driving situation, for example, when the answer to the test by the operator is equal to or higher than a predetermined score.
  • the confirmation screen may also include a video.
  • processor 201 determines that the operator has checked the driving situation when the video has been played for a predetermined time or in its entirety.
  • Processor 201 may also determine that the operator has checked the driving situation when a combination of the above conditions is met. If processor 201 does not determine that the operator has checked the driving situation, it determines No in step ST85 and returns to step ST61 in FIG. 6. On the other hand, if processor 201 determines that the operator has checked the driving situation, it determines Yes in step ST85 and proceeds to step ST86.
  • the processor 201 may also assume that the operator of the key terminal device 200 has confirmed the driving situation without any particular conditions. In this case, for example, if the processor 201 judges Yes in step ST8, it proceeds to step ST86.
  • step ST86 the processor 201 generates a confirmation notification.
  • the confirmation notification includes the login ID and the target ID included in the start response received in step ST82.
  • the confirmation notification is information indicating that the user identified by the login ID has confirmed the driving status of the user identified by the target ID.
  • the processor 201 instructs the communication interface 205 to transmit the confirmation notification to the server device 100.
  • the communication interface 205 transmits the confirmation notification to the server device 100.
  • the transmitted confirmation notification is received by the communication interface 105 of the server device 100.
  • the processor 201 returns to step ST61 in FIG. 6.
  • step ST14 determines Yes in step ST14 and proceeds to step ST20.
  • step ST20 of FIG. 3 the processor 101 of the server device 100 stores in the user DB the date and time when the user identified by the login ID last checked the driving status.
  • the processor 101 stores, for example, the current date and time in association with the login ID and target ID included in the confirmation notification received in step ST14.
  • the current date and time indicates the date and time when the user identified by the login ID checked the driving status of the user identified by the target ID.
  • step ST21 the processor 101 determines whether or not to lift the restriction on the digital key of the user identified by the target ID included in the confirmation notification received in step ST14. If the user identified by the login ID included in the confirmation notification received in step ST14 is not the specified user of the driving user identified by the target ID, the processor 101 does not determine to lift the restriction on the digital key. On the other hand, if the user identified by the login ID is the specified user of the driving user identified by the target ID, the processor 101 refers to the user DB and checks the value of the server restriction variable associated with the target ID included in the confirmation notification received in step ST14. If the value indicates a non-restricted state, the processor 101 does not determine to lift the restriction on the digital key.
  • the processor 101 checks whether the confirmation of the driving status of the user identified by the target ID has expired. If the confirmation of the driving status has expired, the processor 101 does not determine to lift the restriction on the digital key. On the other hand, if the deadline for confirming the driving status has not passed, the processor 101 determines that the restriction on the digital key is to be lifted. If the processor 101 does not determine that the restriction on the digital key is to be lifted, the processor 101 determines No in step ST21 and returns to step ST11. On the other hand, if the processor 101 determines that the restriction on the digital key is to be lifted, the processor 101 determines Yes in step ST21 and proceeds to step ST22.
  • step ST22 the processor 101 updates the user DB and sets the value of the server restriction variable associated with the target ID included in the confirmation notification received in step ST14 to a value indicating the restricted state.
  • step ST23 the processor 101 instructs the communication interface 105 to send a restriction release request to the key terminal device 200 used by the user identified by the target ID included in the confirmation notification received in step ST14.
  • the restriction release request is information that instructs the restriction state of the digital key to be released and put into an unrestricted state.
  • the communication interface 105 Upon receiving this instruction to send, the communication interface 105 sends the restriction release request to the key terminal device 200.
  • the sent restriction release request is received by the communication interface 205 of the key terminal device 200.
  • the processor 101 returns to step ST11.
  • the processor 201 of the key terminal device 200 receives a restriction release request while in a standby state in which it repeats step ST61 in FIG. 6 to step ST68 in FIG. 7, it determines Yes in step ST67 and proceeds to step ST87 in FIG. 7.
  • step ST87 the processor 201 releases the restricted state of the digital key and sets it to an unrestricted state. To do this, the processor 201 rewrites the value of the restricted variable to a value that indicates an unrestricted state.
  • step ST88 the processor 201 notifies the holder of the key terminal device 200 that the restricted state of the digital key has been released and is now in an unrestricted state by issuing a notification that the restricted state of the digital key has been released and is now in an unrestricted state.
  • the processor 201 for example, causes the display device 207 to display an image indicating that the restricted state of the digital key has been released and is now in an unrestricted state.
  • the processor 201 may also issue the notification by outputting sound from a speaker, by causing a light-emitting device to emit light, by causing a vibrator to vibrate, or by other means.
  • the processor 201 may also issue the notification by a push notification.
  • the processor 201 returns to step ST61 in FIG. 6.
  • the following describes the operation of the key terminal device 200 and the vehicle 300 when the digital key is in a restricted state.
  • step ST74 If the digital key is in a restricted state, the processor 201 of the key terminal device 200 judges Yes in step ST74 and proceeds to step ST76.
  • step ST76 the processor 201 generates an unlock request.
  • the value of the restriction variable included in the unlock request indicates the restricted state.
  • the processor 201 instructs the wireless interface 206 to transmit the unlock request to the vehicle 300.
  • the wireless interface 206 Upon receiving this transmission instruction, the wireless interface 206 transmits the unlock request to the vehicle 300.
  • the transmitted unlock request is received by the key interface 320 of the vehicle 300.
  • step ST77 the processor 201 notifies the holder of the key terminal device 200 that the digital key is in a restricted state, by notifying the holder of the key terminal device 200 that the digital key is in a restricted state.
  • the processor 201 for example, causes the display device 207 to display an image indicating that the digital key is in a restricted state and that the restricted state will be released if the driving situation is confirmed.
  • the processor 201 may also notify by outputting sound from a speaker, by illuminating a light-emitting device, by vibrating a vibrator, or the like.
  • the processor 201 may also notify by a push notification.
  • the processor 201 After processing of step ST77, the processor 201 returns to step ST61.
  • step ST104 in FIG. 9 judges step ST104 in FIG. 9 as Yes and proceeds to step ST109.
  • step ST109 the processor 311 notifies the user of the digital key that the digital key is in a restricted state.
  • the processor 311 notifies the user by voice, for example.
  • processor 311 refers to the vehicle setting information and determines whether or not electronic lock 331 is set to unlock when the digital key is in a restricted state. If processor 311 determines that electronic lock 331 is not set to unlock when the digital key is in a restricted state, processor 311 determines No in step ST110 and returns to step ST101. On the other hand, if processor 311 determines that electronic lock 331 is set to unlock when the digital key is in a restricted state, processor 311 determines Yes in step ST110 and proceeds to step ST104.
  • the vehicle 300 goes from a locked state to a partially locked state.
  • the partially locked state is a state in which a part of the vehicle 300 is unlocked.
  • the part includes at least the electronic lock 331.
  • the partially locked state is therefore a state in which some or all of the parts of the vehicle 300 cannot be started. It is preferable that the vehicle 300 in the partially locked state cannot be driven.
  • the partially locked state is an example of a state in which at least one function of the vehicle 300 is restricted.
  • step ST107 the processor 311 determines Yes in step ST107 and proceeds to step ST111.
  • processor 311 refers to the vehicle setting information to identify parts and equipment that are set to start even when the digital key is in a restricted state. Processor 311 then starts the operation of the identified parts and equipment. However, it is preferable that processor 311 does not allow vehicle 300 to be driven. Note that if there are no parts or equipment other than electronic lock 331 that are set to start even when the digital key is in a restricted state, processor 311 does not start the operation of any parts or equipment in the processing of step ST111. Even after processing of step ST111, vehicle 300 remains in a partially locked state.
  • step ST112 the processor 311 waits for an unlock request to be received by the key interface 320. If an unlock request is received, the processor 311 determines Yes in step ST112 and proceeds to step ST113.
  • step ST113 processor 311 refers to the restriction variable included in the unlock request received in step ST112 to determine whether or not the digital key is in a restricted state. If the digital key is in a restricted state, processor 311 determines Yes in step ST113 and returns to step ST112. On the other hand, if the digital key is in an unrestricted state, processor 311 determines No in step ST113 and proceeds to step ST114.
  • step ST114 processor 311 starts each part of vehicle 300.
  • processor 311 ends the processing shown in FIG. 9. In this way, when the digital key changes from a restricted state to an unrestricted state, vehicle 300 changes from a partially locked state to an unlocked state.
  • the operator of the key terminal device 200 wishes to lock the vehicle 300
  • the operator uses the input device 208 to perform an operation to instruct the key terminal device 200 to lock the vehicle 300. Note that this operation may be possible only when the vehicle 300 is in a partially locked or unlocked state.
  • the operator wishes to lock the vehicle 300, he or she leaves the vehicle 300 while holding the key terminal device 200.
  • step ST89 If the processor 201 of the key terminal device 200 determines that the vehicle 300 should be locked while in a standby state in which steps ST61 in FIG. 6 to ST68 in FIG. 7 are repeated, it determines Yes in step ST in FIG. 7 and proceeds to step ST89.
  • step ST89 the processor 201 generates a lock request.
  • the lock request is information requesting that the vehicle 300 be locked.
  • the lock request includes, for example, a login ID, a restriction variable stored in the auxiliary storage device 204, and key information registered in the key app.
  • the processor 201 instructs the wireless interface 206 to transmit the lock request to the vehicle 300.
  • the wireless interface 206 transmits the lock request to the vehicle 300.
  • the transmitted lock request is received by the key interface 320 of the vehicle 300.
  • the processor 201 returns to step ST61.
  • the processor 311 of the control device 310 determines to lock the vehicle 300 when a lock request is received by the key interface 320.
  • the processor 311 also determines to lock the vehicle 300 when the key terminal device 200 moves away from the vehicle 300 by a predetermined distance or more.
  • step ST102 determines Yes in step ST102 and proceeds to step ST115.
  • step ST115 processor 311 puts vehicle 300 into a locked state. That is, processor 311 stops each part of vehicle 300 that was started in steps ST108, ST111, and ST114. Furthermore, processor 311 controls electronic lock 331 to lock electronic lock 331. After processing step ST115, processor 311 returns to step ST101.
  • the digital key system 1 of the embodiment puts the digital key into a restricted state when a driver using the digital key meets a specified condition. This allows the digital key system 1 of the embodiment to encourage the driver not to meet the specified condition. If the specified condition is related to safe driving, the digital key system 1 of the embodiment can encourage the driver to drive safely.
  • the digital key system 1 of the embodiment also displays the driving status of the driver on the key terminal device 200, which functions as a digital key.
  • the digital key system 1 of the embodiment also places the digital key in a restricted state if the driver has not checked the driving status for a predetermined period of time P1 or more. This allows the digital key system 1 of the embodiment to prompt the driver to check the driving status. Checking the driving status provides an opportunity for the driver to reflect on his or her driving. Therefore, the digital key system 1 of the embodiment can encourage the driver to drive safely.
  • the digital key system 1 of the embodiment notifies the key terminal device 200 or the terminal device 400 that the deadline for checking the driving status is about to expire. This allows the digital key system 1 of the embodiment to inform the user that the deadline for checking the driving status is about to expire and that restrictions are about to be imposed on the digital key.
  • the digital key system 1 of the embodiment also puts the digital key into a restricted state if there is a problem with the driving of the driving user. In response to this, the driving user is expected to drive in such a way that the digital key is not put into a restricted state. Therefore, the digital key system 1 of the embodiment can encourage the driving user to drive safely.
  • the digital key system 1 of the embodiment can also display the driving status on the terminal device 400 used by a user other than the driver. This allows, for example, if the different user is a family member of the driver, the family member to know the driving status of the driver. Also, for example, if the different user is a rental car company that is planning to provide a rental car to the driver, the rental car company can know the driving status of the driver before providing the rental car. The rental car company can also cancel the provision of the rental car if the driving status is poor.
  • the digital key system 1 of the embodiment also displays the driving status of the driving user on the terminal device 400 used by a specified user different from the driving user.
  • the digital key system 1 of the embodiment also places the digital key in a restricted state if the specified user has not checked the driving status for a specified period of time P1 or more. This allows the digital key system 1 of the embodiment to allow the family of the driving user to check the driving status.
  • the digital key system 1 of the embodiment also stores the driving status of the driving user. This allows the digital key system 1 of the embodiment to accumulate the driving status of the driving user. Therefore, the digital key system 1 of the embodiment can also analyze the driving status more accurately.
  • the digital key is used to unlock the electronic lock 331 of the door 330. Therefore, the digital key system 1 of the embodiment can restrict the digital key, thereby preventing the driving user from driving the vehicle.
  • the electronic lock 331 can be unlocked even when the digital key is in a restricted state.
  • the driver can enter the vehicle 300 even if the digital key is in a restricted state. Therefore, the driver can retrieve luggage from the vehicle, take a rest in the vehicle, etc., even if the digital key is in a restricted state.
  • the digital key system 1 of the embodiment even if the digital key is in a restricted state, when the start button 360 is operated, it is possible to start some of the parts and equipment of the vehicle 300. In this case, even if the digital key is in a restricted state, the driver can use, for example, the car audio, the in-car Wi-Fi, and the car navigation system.
  • the above embodiment can be modified as follows. If the digital key is in a restricted state, the key terminal device 200 does not need to send an unlock request. In this case, for example, if the processor 201 determines Yes in step ST74, it proceeds to step ST77. Also, in this case, the processor 311 of the control device 310 does not need to determine whether the digital key is in a restricted state. That is, if the processor 311 determines Yes in step ST103, it proceeds to step ST104. And if the processor 311 determines Yes in step ST106, it proceeds to step ST108.
  • step ST63 determines Yes in step ST63
  • step ST74 determines Yes in step ST74
  • step ST77 determines No in step ST74
  • step ST73 the processor 201 proceeds to step ST75.
  • the control device 310 may determine whether the digital key is in a restricted state by inquiring of the server device 100. In this case, the key terminal device 200 does not need to determine whether the digital key is in a restricted state.
  • the vehicle 300 can be locked regardless of whether the digital key is in a restricted state. However, it is not necessary that the vehicle 300 cannot be locked when the digital key is in a restricted state.
  • the processor 201 of the key terminal device 200 does not send a lock request when the digital key is in a restricted state, for example.
  • the processor 311 of the control device 310 refers to a restriction variable included in the received lock request to determine whether the digital key is in a restricted state. Then, the processor 311 does not lock the vehicle 300 when the digital key is in a restricted state. Whether or not to lock the vehicle 300 when the digital key is in a restricted state may be changeable by settings.
  • the setting is stored in the auxiliary storage device 314 as vehicle setting information.
  • the processor 311 refers to the vehicle setting information and locks the parts and equipment that are set to be lockable even in a restricted state. That is, the processor 311 stops the parts and equipment of the vehicle 300 that are set to be lockable even in the restricted state among the parts that were started in steps ST108, ST111, and ST114. Also, if the electronic lock 331 is set to be lockable even in the restricted state, the processor 311 controls the electronic lock 331 to lock the electronic lock 331. Note that the parts and equipment that are set to start even when the digital key is in the restricted state and the parts and equipment that are set to be lockable even in the restricted state may have the same settings, for example, so that they are the same parts and equipment.
  • the specified conditions may be conditions other than those listed above.
  • the functions of the vehicle itself may be restricted.
  • the digital key system 1 has been described as being applied to the vehicle 300, which is an automobile.
  • the digital key system of the embodiment can also be applied to moving bodies other than automobiles. Examples of moving bodies other than automobiles include railroad cars, aircraft, ships, submarines, and spacecraft.
  • the moving body to which the digital key system of the embodiment is applied may be one that is remotely operated (remotely controlled).
  • the digital key system 1 of the embodiment can also be applied to machines other than moving bodies. Examples of machines other than moving bodies include non-mobile cranes.
  • the digital key system of the embodiment applied to machines other than automobiles has a door for entering a place for operating (operating) the machine, such as a driver's seat (cockpit) or a driver's room (cockpit), instead of the door 330.
  • the door has an electronic lock 331, just like the door 330.
  • the place in question in a machine for remote operation is outside the machine.
  • the place in question in a machine for non-remote operation is inside the machine.
  • part of the processing performed by the server device 100 may be executed by the key terminal device 200, the control device 310, or the terminal device 400.
  • part of the processing performed by the key terminal device 200 may be executed by the server device 100 or the control device 310.
  • part of the processing performed by the control device 310 may be executed by the server device 100 or the key terminal device 200.
  • part of the processing performed by the terminal device 400 may be executed by the server device 100.
  • Processor 101, processor 201, processor 311, and processor 401 may implement some or all of the processing implemented by programs in the above embodiments through a hardware circuit configuration.
  • the program that realizes the processing of the embodiment is transferred, for example, in a state stored in a non-transitory storage medium within the device.
  • the device may be transferred without the program stored therein.
  • the program may then be transferred separately and written to the device.
  • the program may be transferred, for example, by recording it on a removable, non-transitory storage medium, or by downloading it via a network such as the Internet or a LAN.
  • Digital key system 100 Server device 101, 201, 311, 401 Processor 102, 202, 312, 402 ROM 103,203,313,403 RAM 104, 204, 314, 404 Auxiliary storage device 105, 205, 315, 405 Communication interface 106, 209, 317, 408 Bus 200 Key terminal device 206 Wireless interface 207, 406 Display device 208, 407 Input device 300 Vehicle 310 Control device 316 Control interface 320 Key interface 330 Door 331 Electronic lock 340 Power unit 350 Electrical unit 360 Start button 400 Terminal device

Landscapes

  • Engineering & Computer Science (AREA)
  • Mechanical Engineering (AREA)
  • Lock And Its Accessories (AREA)

Abstract

実施形態の情報管理装置は、通信部、判定部及び制限部を備える。通信部は、機械の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うデジタルキーとして使用する第1の端末装置と通信する。判定部は、前記第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する。制限部は、前記所定条件を満たしている場合、前記デジタルキーを、前記機能の前記制限及び前記解除の少なくともいずれかを行えない制限状態にする。

Description

情報管理装置、端末装置、プログラム及び情報管理方法
 本発明は、情報管理装置、端末装置、プログラム及び情報管理方法に関する。
 特許文献1には、車両に対するスマートフォンまでの距離を精度よく推定することができるデジタルキーシステムが開示されている。
 また、車両などの移動体、又はその他の機械を運転する者に安全な運転させたいという需要がある。
特開2021-85719号公報
 本発明の実施形態が解決しようとする課題は、デジタルキーシステムを用いて、機械を運転する者に安全な運転を奨励することができる情報管理装置、端末装置、プログラム及び情報管理方法を提供することである。
 実施形態の情報管理装置は、通信部、判定部及び制限部を備える。通信部は、機械の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うデジタルキーとして使用する第1の端末装置と通信する。判定部は、前記第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する。制限部は、前記所定条件を満たしている場合、前記デジタルキーを、前記機能の前記制限及び前記解除の少なくともいずれかを行えない制限状態にする。
 本発明は、デジタルキーシステムを用いて、機械を運転する者に安全な運転を奨励することができる。
実施形態に係るデジタルキーシステム及び当該デジタルキーシステムに含まれる構成要素の要部構成の一例を示すブロック図。 実施形態に係るデジタルキーシステム及び当該デジタルキーシステムに含まれる構成要素の要部構成の一例を示すブロック図。 図1中のサーバー装置のプロセッサーによる処理の一例を示すフローチャート。 図1中のサーバー装置のプロセッサーによる処理の一例を示すフローチャート。 図1中のサーバー装置のプロセッサーによる処理の一例を示すフローチャート。 図1中のキー端末装置のプロセッサーによる処理の一例を示すフローチャート。 図1中のキー端末装置のプロセッサーによる処理の一例を示すフローチャート。 図2中の制御装置のプロセッサーによる処理の一例を示すフローチャート。 図2中の制御装置のプロセッサーによる処理の一例を示すフローチャート。 図2中の端末装置のプロセッサーによる処理の一例を示すフローチャート。
 以下、実施形態に係るデジタルキーシステムについて図面を用いて説明する。なお、以下の実施形態の説明に用いる各図面は、各部の縮尺を適宜変更している場合がある。また、以下の実施形態の説明に用いる各図面は、説明のため、構成を省略して示している場合がある。また、各図面及び本明細書中において、同一の符号は同様の要素を示す。
 図1及び図2は、実施形態に係るデジタルキーシステム1及びデジタルキーシステム1に含まれる構成要素の要部構成の一例を示すブロック図である。なお、各装置の各構成要素は、内蔵であっても外付けであっても良い。デジタルキーシステム1は、デジタルキーサービスを提供するシステムである。デジタルキーサービスは、車両用のキーとしてデジタルキーを使用可能にするサービスである。デジタルキーは、スマートフォンなどの、通信機能を有する携帯型電子機器をキーとして使用可能にしたものである。また、デジタルキーサービスは、所定条件を満たしていない場合、デジタルキーの機能に制限を加えることができるサービスである。デジタルキーシステム1は、一例として、サーバー装置100、キー端末装置200、車両300及び端末装置400を含む。なお、デジタルキーシステム1は、このうちの一部を含むものであっても良い。また、図1及び図2には、サーバー装置100、キー端末装置200、車両300及び端末装置400を各1台ずつ示すが、それぞれの構成要素の数は限定しない。
 サーバー装置100、キー端末装置200、車両300及び端末装置400は、ネットワークNWに接続する。ネットワークNWは、典型的にはインターネットを含む通信網である。ネットワークNWは、典型的にはWAN(wide area network)を含む通信網である。ネットワークNWは、イントラネットなどのプライベートネットワークを含む通信網であっても良い。また、ネットワークNWは、専用線又は公衆携帯電話網などを含む通信網であっても良い。
 サーバー装置100は、デジタルキーサービスを提供するためのサーバーである。サーバー装置100は、デジタルキーサービスにおける各種のデータの管理及びデジタルキーの制御などを行う。サーバー装置100は、一例として、プロセッサー101、ROM(read-only memory)102、RAM(random-access memory)103、補助記憶装置104及び通信インターフェース105を含む。そして、バス106などが、これら各部を接続する。サーバー装置100は、情報管理装置の一例である。
 プロセッサー101は、サーバー装置100の動作に必要な演算及び制御などの処理を行うコンピューターの中枢部分であり、各種演算及び処理などを行う。プロセッサー101は、例えば、CPU(central processing unit)、MPU(micro processing unit)、SoC(system on a chip)、DSP(digital signal processor)、GPU(graphics processing unit)、ASIC(application specific integrated circuit)、PLD(programmable logic device)又はFPGA(field-programmable gate array)などである。あるいは、プロセッサー101は、これらのうちの複数を組み合わせたものである。また、プロセッサー101は、これらにハードウェアアクセラレーターなどを組み合わせたものであっても良い。プロセッサー101は、ROM102又は補助記憶装置104などに記憶されたファームウェア、システムソフトウェア及びアプリケーションソフトウェアなどのプログラムに基づいて、サーバー装置100の各種の機能を実現するべく各部を制御する。また、プロセッサー101は、当該プログラムに基づいて後述する処理を実行する。なお、当該プログラムの一部又は全部は、プロセッサー101の回路内に組み込まれていても良い。
 ROM102及びRAM103は、プロセッサー101を中枢としたコンピューターの主記憶装置である。
 ROM102は、専らデータの読み出しに用いられる不揮発性メモリである。ROM102は、上記のプログラムのうち、例えばファームウェアなどを記憶する。また、ROM102は、プロセッサー101が各種の処理を行う上で使用するデータなども記憶する。
 RAM103は、データの読み書きに用いられるメモリである。RAM103は、プロセッサー101が各種の処理を行う上で一時的に使用するデータを記憶するワークエリアなどとして利用される。RAM103は、典型的には揮発性メモリである。
 補助記憶装置104は、プロセッサー101を中枢としたコンピューターの補助記憶装置である。補助記憶装置104は、例えばEEPROM(electric erasable programmable read-only memory)、HDD(hard disk drive)又はフラッシュメモリなどである。補助記憶装置104は、上記のプログラムのうち、例えば、システムソフトウェア及びアプリケーションソフトウェアなどを記憶する。また、補助記憶装置104は、プロセッサー101が各種の処理を行う上で使用するデータ、プロセッサー101での処理によって生成されたデータ及び各種の設定値などを記憶する。
 補助記憶装置104が記憶するデータは、一例としてユーザーDB(database)を含む。
 ユーザーDBは、デジタルキーサービスを利用するユーザーについての情報を記憶及び管理するデータベースである。ユーザーDBは、例えば、各ユーザーについて、ユーザーID(identifier)と関連付けてユーザーについての情報(以下「ユーザー情報」という。)を記憶する。なお、ユーザーIDは、ユーザーごとにユニークに付与される識別情報である。ユーザー情報は、例えば、デジタルキーサービスに関する各種の設定(以下「キーサービス設定」という。)、及びサーバー制限変数を含む。キーサービス設定に含まれる各設定は、デフォルトの値が定められていても良い。デフォルトの値は、例えば、キーシステム1の設計者若しくは管理者又は車両300の販売者などによって予め定められる。キーサービス設定は、ユーザーによって変更可能なものと変更不可能なものがあっても良い。サーバー制限変数は、関連付けられたユーザーIDで特定されるユーザーのデジタルキーが制限状態であるか非制限状態であるかを示す。制限状態及び非制限状態については後述する。
 通信インターフェース105は、サーバー装置100がネットワークNWなどを介して通信するためのインターフェースである。なお、通信インターフェース105は、第1の端末装置と通信する通信部の一例として機能する。また、通信インターフェース105は、通信装置の一例である。また、プロセッサー101は、第1の端末装置と通信するように通信インターフェース105を制御することで、第1の端末装置と通信するように通信装置を制御する通信制御部の一例として機能する。
 バス106は、コントロールバス、アドレスバス及びデータバスなどを含み、サーバー装置100の各部で授受される信号を伝送する。
 キー端末装置200は、デジタルキーとして使用可能な、通信機能を有する携帯型電子機器である。デジタルキーは、車両300の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うことができる。キー端末装置200は、例えば、スマートフォン、タブレット端末又はスマートウォッチなどの汎用の電子機器である。あるいは、キー端末装置200は、デジタルキー専用の電子機器であっても良い。キー端末装置200は、一例として、プロセッサー201、ROM202、RAM203、補助記憶装置204、通信インターフェース205、無線インターフェース206、表示デバイス207及び入力デバイス208を含む。そして、バス209などが、これら各部を接続する。なお、キー端末装置200は、第1の端末装置の一例である。また、キー端末装置200の使用者は、第1の端末装置を使用する第1のユーザーの一例である。
 プロセッサー201は、キー端末装置200の動作に必要な演算及び制御などの処理を行うコンピューターの中枢部分であり、各種演算及び処理などを行う。プロセッサー201は、例えば、CPU、MPU、SoC、DSP、GPU、ASIC、PLD又はFPGAなどである。あるいは、プロセッサー201は、これらのうちの複数を組み合わせたものである。また、プロセッサー201は、これらにハードウェアアクセラレーターなどを組み合わせたものであっても良い。プロセッサー201は、ROM202又は補助記憶装置204などに記憶されたファームウェア、システムソフトウェア及びアプリケーションソフトウェアなどのプログラムに基づいて、キー端末装置200の各種の機能を実現するべく各部を制御する。また、プロセッサー201は、当該プログラムに基づいて後述する処理を実行する。なお、当該プログラムの一部又は全部は、プロセッサー201の回路内に組み込まれていても良い。
 ROM202及びRAM203は、プロセッサー201を中枢としたコンピューターの主記憶装置である。
 ROM202は、専らデータの読み出しに用いられる不揮発性メモリである。ROM202は、上記のプログラムのうち、例えばファームウェアなどを記憶する。また、ROM202は、プロセッサー201が各種の処理を行う上で使用するデータなども記憶する。
 RAM203は、データの読み書きに用いられるメモリである。RAM203は、プロセッサー201が各種の処理を行う上で一時的に使用するデータを記憶するワークエリアなどとして利用される。RAM203は、典型的には揮発性メモリである。
 補助記憶装置204は、プロセッサー201を中枢としたコンピューターの補助記憶装置である。補助記憶装置204は、例えばEEPROM、HDD又はフラッシュメモリなどである。補助記憶装置204は、上記のプログラムのうち、例えば、システムソフトウェア及びアプリケーションソフトウェアなどを記憶する。また、補助記憶装置204は、プロセッサー201が各種の処理を行う上で使用するデータ、プロセッサー201での処理によって生成されたデータ及び各種の設定値などを記憶する。補助記憶装置204は、記憶装置の一例である。
 補助記憶装置204が記憶するアプリケーションソフトウェアは、キーアプリを含む。キーアプリは、デジタルキーサービスを利用するためのアプリケーションソフトウェアである。キーアプリは、キー端末装置200をデジタルキーとして機能させることができるアプリケーションソフトウェアである。プロセッサー201は、例えば、通信インターフェース205を介してキーアプリをダウンロードする。また、プロセッサー201は、ダウンロードしたキーアプリをインストールする。あるいは、キーアプリは、予めキー端末装置200にインストールされていても良い。
 キー端末装置200をデジタルキーとして機能させるためには、キーアプリにキー情報を登録する必要がある。キーアプリは、キー情報を、車両300のロック状態を解除するために使用する。キーアプリは、キー情報を車両300に送信することでキー情報を用いた認証を行わせる。キー情報は、使用対象の車両300と使用するユーザーとの組み合わせごとにユニークな情報である。キーアプリは、複数のキー情報を登録することで、それぞれのキー情報に対応する複数の車両300のロック状態を解除することが可能である。また、キー情報は、有効期限が設定されていても良い。この場合、キー情報は、有効期限内に限り有効である。
 キーアプリは、制限変数を含む。制限変数は、当該キーアプリによって機能するデジタルキーが制限状態であるか非制限状態であるかを示す。制限状態及び非制限状態については後述する。
 なお、デジタルキーサービスの一部又は全部は、利用するためにデジタルキーサービスにログインしている必要がある。キー端末装置200は、例えば、ユーザーIDを使用してデジタルキーサービスにログインする。プロセッサー201は、当該ログインを自動で行っても良いし、キー端末装置200の操作者による操作に基づいて行っても良い。キー端末装置200は、ログインに使用するユーザーIDを記憶している。当該ユーザーIDを以下「ログインID」という。
 通信インターフェース205は、キー端末装置200がネットワークNWなどを介して通信するためのインターフェースである。
 無線インターフェース206は、キー端末装置200が車両300と無線通信するためのインターフェースである。無線インターフェース206は、無線通信のためのアンテナなどを含む。
 表示デバイス207は、キー端末装置200の操作者などに各種情報を通知するための画面を表示する。表示デバイス207は、例えば、液晶ディスプレイ又は有機EL(electro-luminescence)ディスプレイなどのディスプレイである。
 入力デバイス208は、キー端末装置200の操作者による操作を受け付ける。入力デバイス208は、例えば、キーボード、キーパッド、タッチパッド、マウス又はコントローラーなどである。また、入力デバイス208は、音声入力用のデバイスであっても良い。また、表示デバイス207及び入力デバイス208としては、タッチパネルを用いることもできる。この場合、タッチパネルが備える表示パネルは、表示デバイス207として機能する。そして、タッチパネルが備える、タッチ入力によるポインティングデバイスは、入力デバイス208として機能する。
 バス209は、コントロールバス、アドレスバス及びデータバスなどを含み、キー端末装置200の各部で授受される信号を伝送する。
 車両300は、例えば、自動車である。車両300は、一例として、制御装置310、キーインターフェース320、ドア330、動力部340、電装部350及びスタートボタン360を含む。
 制御装置310は、例えば、車両300の各種の制御を行う。制御装置310は、キー端末装置200から読み取ったキー情報を認証する機能を有する。制御装置310は、有効なキー情報を認証した場合、車両300のロック状態を解除して非ロック状態にする機能を有する。ロック状態の車両300は、後述の電子ロック331が施錠された状態、且つ動力部340及び電装部350を含む車両300の各部を始動できない状態である。ロック状態は、車両300を運転できないようにするロックがかかった状態の一例である。ロック状態は、車両300の少なくとも1つの機能が制限された状態の一例である。非ロック状態の車両300は、電子ロック331が開錠された状態、且つ動力部340及び電装部350を含む車両300の各部を始動可能な状態である。制御装置310は、例えばECU(electronic control unit)などである。制御装置310は、一例として、プロセッサー311、ROM312、RAM313、補助記憶装置314、通信インターフェース315及び制御インターフェース316を含む。そして、バス317などが、これら各部を接続する。
 プロセッサー311は、車両300の動作に必要な演算及び制御などの処理を行うコンピューターの中枢部分であり、各種演算及び処理などを行う。プロセッサー311は、例えば、CPU、MPU、SoC、DSP、GPU、ASIC、PLD又はFPGAなどである。あるいは、プロセッサー311は、これらのうちの複数を組み合わせたものである。また、プロセッサー311は、これらにハードウェアアクセラレーターなどを組み合わせたものであっても良い。プロセッサー311は、ROM312又は補助記憶装置314などに記憶されたファームウェア、システムソフトウェア及びアプリケーションソフトウェアなどのプログラムに基づいて、車両300の各種の機能を実現するべく各部を制御する。また、プロセッサー311は、当該プログラムに基づいて後述する処理を実行する。なお、当該プログラムの一部又は全部は、プロセッサー311の回路内に組み込まれていても良い。
 ROM312及びRAM313は、プロセッサー311を中枢としたコンピューターの主記憶装置である。
 ROM312は、専らデータの読み出しに用いられる不揮発性メモリである。ROM312は、上記のプログラムのうち、例えばファームウェアなどを記憶する。また、ROM312は、プロセッサー311が各種の処理を行う上で使用するデータなども記憶する。
 RAM313は、データの読み書きに用いられるメモリである。RAM313は、プロセッサー311が各種の処理を行う上で一時的に使用するデータを記憶するワークエリアなどとして利用される。RAM313は、典型的には揮発性メモリである。
 補助記憶装置314は、プロセッサー311を中枢としたコンピューターの補助記憶装置である。補助記憶装置314は、例えばEEPROM、HDD又はフラッシュメモリなどである。補助記憶装置314は、上記のプログラムのうち、例えば、システムソフトウェア及びアプリケーションソフトウェアなどを記憶する。また、補助記憶装置314は、プロセッサー311が各種の処理を行う上で使用するデータ、プロセッサー311での処理によって生成されたデータ及び各種の設定値などを記憶する。
 補助記憶装置314が記憶するデータは、自身を備える車両300の車両ID及び車両設定情報を含む。車両IDは、車両300ごとにユニークな識別情報である。車両設定情報は、デジタルキーサービスに関する設定のうち、車両300の動作に関する設定を含む情報である。車両設定情報に含まれる各設定は、デフォルトの値が定められていても良い。デフォルトの値は、例えば、キーシステム1の設計者若しくは管理者又は車両300の販売者などによって予め定められる。車両設定情報は、ユーザーによって変更可能なものと変更不可能なものがあっても良い。
 通信インターフェース315は、車両300がネットワークNWなどを介して通信するためのインターフェースである。
 制御インターフェース316は、制御装置310が車両300の各部と通信するためのインターフェースである。制御装置310は、制御インターフェース316を介して車両300の各部を制御する。当該各部は、例えば、キーインターフェース320、ドア330、動力部340、電装部350及びスタートボタン360を含む。
 バス317は、コントロールバス、アドレスバス及びデータバスなどを含み、制御装置310の各部で授受される信号を伝送する。
 キーインターフェース320は、デジタルキーとして機能するキー端末装置200と無線通信するためのインターフェースである。キーインターフェース320は、無線通信のためのアンテナなどを含む。
 ドア330は、車両300内に出入りするためのドアである。ドア330は、例えば、車両300を運転するための場所である運転席に出入りするためのドアである。ドア330は、電子ロック331を備える。
 電子ロック331は、デジタルキーによって開錠可能な電子ロック(電子錠)である。
 動力部340は、車両300が走行するための部品及び装備である。動力部340は、例えば、パワーユニット、バッテリー、駆動系などである。パワーユニットは、例えば、エンジン又はモーターである。
 電装部350は、電気系統の部品及び装備である。電装部350は、例えば、カーエアコン、車内Wi-Fi、車内エンターテインメント、カーオーディオ、車載ディスプレイ、カーナビゲーションシステム、車載装置及び計器類などである。
 スタートボタン360は、動力部340及び電装部350の一部又は全部を始動させる場合に操作するボタンである。
 端末装置400は、デジタルキーサービスに関する各種の情報の閲覧及び各種の設定の変更などを行うことができる装置である。端末装置400は、例えば、PC(personal computer)、タブレット端末又はスマートフォンなどである。端末装置400は、キー端末装置200であっても良い。端末装置400は、一例として、プロセッサー401、ROM402、RAM403、補助記憶装置404、通信インターフェース405、表示デバイス406及び入力デバイス407を含む。そして、バス408などが、これら各部を接続する。端末装置400は、第2の端末装置の一例である。また、端末装置400の使用者は、第2の端末装置を使用する第2のユーザーの一例である。
 端末装置400が記憶するアプリケーションソフトウェアは、閲覧アプリを含む。閲覧アプリは、デジタルキーサービスに関する各種の情報の閲覧及び各種の設定の変更などを行うことが可能なアプリケーションソフトウェアである。閲覧アプリは、Webブラウザーなどの汎用のアプリケーションソフトウェアであっても良いし、デジタルキーシステム1専用のアプリケーションソフトウェアであっても良い。
 なお、端末装置400は、キー端末装置200と同様にデジタルキーサービスにログインを行う。端末装置400は、ログインIDを記憶する。
 プロセッサー401は、端末装置400の動作に必要な演算及び制御などの処理を行うコンピューターの中枢部分であり、各種演算及び処理などを行う。プロセッサー401は、例えば、CPU、MPU、SoC、DSP、GPU、ASIC、PLD又はFPGAなどである。あるいは、プロセッサー401は、これらのうちの複数を組み合わせたものである。また、プロセッサー401は、これらにハードウェアアクセラレーターなどを組み合わせたものであっても良い。プロセッサー401は、ROM402又は補助記憶装置404などに記憶されたファームウェア、システムソフトウェア及びアプリケーションソフトウェアなどのプログラムに基づいて、端末装置400の各種の機能を実現するべく各部を制御する。また、プロセッサー401は、当該プログラムに基づいて後述する処理を実行する。なお、当該プログラムの一部又は全部は、プロセッサー401の回路内に組み込まれていても良い。
 ROM402及びRAM403は、プロセッサー401を中枢としたコンピューターの主記憶装置である。
 ROM402は、専らデータの読み出しに用いられる不揮発性メモリである。ROM402は、上記のプログラムのうち、例えばファームウェアなどを記憶する。また、ROM402は、プロセッサー401が各種の処理を行う上で使用するデータなども記憶する。
 RAM403は、データの読み書きに用いられるメモリである。RAM403は、プロセッサー401が各種の処理を行う上で一時的に使用するデータを記憶するワークエリアなどとして利用される。RAM403は、典型的には揮発性メモリである。
 補助記憶装置404は、プロセッサー401を中枢としたコンピューターの補助記憶装置である。補助記憶装置404は、例えばEEPROM、HDD又はフラッシュメモリなどである。補助記憶装置404は、上記のプログラムのうち、例えば、システムソフトウェア及びアプリケーションソフトウェアなどを記憶する。また、補助記憶装置404は、プロセッサー401が各種の処理を行う上で使用するデータ、プロセッサー401での処理によって生成されたデータ及び各種の設定値などを記憶する。
 通信インターフェース405は、端末装置400がネットワークNWなどを介して通信するためのインターフェースである。
 表示デバイス406は、端末装置400の操作者などに各種情報を通知するための画面を表示する。表示デバイス406は、例えば、液晶ディスプレイ又は有機ELディスプレイなどのディスプレイである。
 入力デバイス407は、端末装置400の操作者による操作を受け付ける。入力デバイス407は、例えば、キーボード、キーパッド、タッチパッド、マウス又はコントローラーなどである。また、入力デバイス407は、音声入力用のデバイスであっても良い。また、表示デバイス406及び入力デバイス407としては、タッチパネルを用いることもできる。この場合、タッチパネルが備える表示パネルは、表示デバイス406として機能する。そして、タッチパネルが備える、タッチ入力によるポインティングデバイスは、入力デバイス407として機能する。
 バス408は、コントロールバス、アドレスバス及びデータバスなどを含み、端末装置400の各部で授受される信号を伝送する。
 以下、実施形態に係るデジタルキーシステム1の動作を図3~図10などに基づいて説明する。なお、以下の動作説明における処理の内容は一例であって、同様な結果を得ることが可能な様々な処理を適宜に利用できる。図3~図5は、サーバー装置100のプロセッサー101による処理の一例を示すフローチャートである。プロセッサー101は、例えば、ROM102又は補助記憶装置104などに記憶されたプログラムに基づいて図3~図5の処理を実行する。プロセッサー101は、例えば、図3~図5の処理を並行又は並列で実行する。図6及び図7は、キー端末装置200のプロセッサー201による処理の一例を示すフローチャートである。プロセッサー201は、例えば、ROM202又は補助記憶装置204などに記憶されたプログラムに基づいて図6及び図7の処理を実行する。図8及び図9は、制御装置310のプロセッサー311による処理の一例を示すフローチャートである。プロセッサー311は、例えば、ROM312又は補助記憶装置314などに記憶されたプログラムに基づいて図8及び図9の処理を実行する。プロセッサー311は、例えば、図8及び図9の処理を並行又は並列で実行する。図10は、端末装置400のプロセッサー401による処理の一例を示すフローチャートである。プロセッサー401は、例えば、ROM402又は補助記憶装置404などに記憶されたプログラムに基づいて図10の処理を実行する。
 図6のステップST61においてキー端末装置200のプロセッサー201は、キーサービス設定を変更するか否かを判定する。プロセッサー201は、キーサービス設定を変更すると判定しないならば、ステップST61においてNoと判定してステップST62へと進む。
 ステップST62においてプロセッサー201は、キー情報を新規に登録するか否かを判定する。プロセッサー201は、キー情報を新規に登録すると判定しないならば、ステップST62においてNoと判定してステップST63へと進む。
 ステップST63においてプロセッサー201は、キーインターフェース320と接続するか否かを判定する。プロセッサー201は、キーインターフェース320と接続すると判定しないならば、ステップST63においてNoと判定してステップST64へと進む。
 ステップST64においてプロセッサー201は、通信インターフェース205によって制限要求が受信されたか否かを判定する。プロセッサー201は、制限要求が受信されないならば、ステップST64においてNoと判定してステップST65へと進む。
 ステップST65においてプロセッサー201は、通信インターフェース205によって通知情報が受信されたか否かを判定する。プロセッサー201は、通知情報が受信されないならば、ステップST65においてNoと判定してステップST66へと進む。
 ステップST66においてプロセッサー201は、運転状況の確認を開始するか否かを判定する。プロセッサー201は、運転状況の確認を開始すると判定しないならば、ステップST64においてNoと判定してステップST67へと進む。
 ステップST67においてプロセッサー201は、通信インターフェース205によって制限解除要求が受信されたか否かを判定する。プロセッサー201は、制限解除要求が受信されないならば、ステップST67においてNoと判定してステップST68へと進む。
 ステップST68においてプロセッサー201は、車両300をロック状態にするか否かを判定する。プロセッサー201は、例えば、車両300をロック状態にすることを指示する操作が入力デバイス208を用いて行われた場合に、車両300をロック状態にすると判定する。プロセッサー201は、車両300をロック状態にすると判定しないならば、ステップST68においてNoと判定してステップST61へと戻る。かくして、プロセッサー201は、キーサービス設定を変更すると判定するか、キー情報を新規に登録すると判定するか、キーインターフェース320と接続すると判定するか、運転状況の確認を開始すると判定するか、制限要求、通知情報、又は制限解除要求が受信されか、車両300をロック状態にすると判定するまで図6のステップST61~図7のステップST68を繰り返す待受状態となる。なお、通知情報、制限要求及び制限解除要求については後述する。
 キー端末装置200の操作者は、キーサービス設定を変更したい場合、例えば、入力デバイス208を操作して、キーサービス設定の変更内容を入力する。プロセッサー201は、当該入力に応じて、キーサービス設定を変更すると判定する。
 プロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときにキーサービス設定を変更すると判定するならば、図6のステップST61においてYesと判定してステップST68へと進む。
 ステップST69においてプロセッサー201は、変更要求を生成する。変更要求は、例えば、ログインID及び変更情報を含む。変更情報は、キーサービス設定の変更内容を示す。プロセッサー201は、変更要求を生成した後、当該変更要求をサーバー装置100に送信するように通信インターフェース205に対して指示する。この送信の指示を受けて通信インターフェース205は、当該変更要求をサーバー装置100に送信する。送信された当該変更要求は、サーバー装置100の通信インターフェース105によって受信される。プロセッサー201は、ステップST69の処理の後、ステップST61へと戻る。
 一方、図3のステップST11においてサーバー装置100のプロセッサー101は、通信インターフェース105によって変更要求が受信されたか否かを判定する。プロセッサー101は、変更要求が受信されないならば、ステップST11においてNoと判定してステップST12へと進む。
 ステップST12においてプロセッサー101は、通信インターフェース105によってキー要求が受信されたか否かを判定する。プロセッサー101は、キー要求が受信されないならば、ステップST12においてNoと判定してステップST13へと進む。
 ステップST13においてプロセッサー101は、通信インターフェース105によって開始要求が受信されたか否かを判定する。プロセッサー101は、開始要求が受信されないならば、ステップST13においてNoと判定してステップST14へと進む。
 ステップST14においてプロセッサー101は、通信インターフェース105によって確認通知が受信されたか否かを判定する。プロセッサー101は、確認通知が受信されないならば、ステップST14においてNoと判定してステップST11へと戻る。かくして、プロセッサー101は、変更要求、キー要求、開始要求、又は確認通知が受信されるまでステップST11~ステップST14を繰り返す待受状態となる。なお、キー要求、開始要求及び確認通知については後述する。
 プロセッサー101は、ステップST11~ステップST14を繰り返す待受状態にあるときに変更要求が受信されたならば、ステップST11においてYesと判定してステップST15へと進む。
 ステップST15においてプロセッサー101は、ステップST11で受信された変更要求に基づきユーザーDBを更新することで、キーサービス設定を変更する。すなわち、プロセッサー101は、当該変更要求に含まれるユーザーIDに関連付けられたキーサービス設定を、当該変更要求に含まれる変更情報に従って変更する。
 また、プロセッサー101は、キーサービス設定の変更内容が、車両300の動作を変更する必要があるものを含む場合、設定情報を生成する。設定情報は、車両300の動作を変更する設定内容を示す。そして、プロセッサー101は、設定情報を生成した後、当該設定情報を制御装置310に送信するように通信インターフェース105に対して指示する。この送信の指示を受けて通信インターフェース105は、当該設定情報を制御装置310に送信する。送信された当該設定情報は、制御装置310の通信インターフェース315によって受信される。プロセッサー101は、ステップST15の処理の後、ステップST11へと戻る。
 一方、図8のステップST91において制御装置310のプロセッサー311は、通信インターフェース315によって設定情報が受信されたか否かを判定する。プロセッサー311は、設定情報が受信されないならば、ステップST91においてNoと判定してステップST92へと進む。
 ステップST92においてプロセッサー311は、走行データを送信するか否かを判定する。プロセッサー311は、走行データを送信すると判定しないならば、ステップST92においてNoと判定してステップST91へと戻る。かくして、プロセッサー311は、設定情報が受信されるか、走行データを送信すると判定するまでステップST91及びステップST92を繰り返す待受状態となる。なお、走行データについては後述する。
 プロセッサー311は、ステップST91及びステップST92を繰り返す待受状態にあるときに設定情報が受信されたならば、ステップST91においてYesと判定してステップST93へと進む。
 ステップST93においてプロセッサー311は、ステップST91で受信された設定情報に従って車両設定情報を更新する。プロセッサー311は、ステップST93の処理の後、ステップST91へと戻る。
 キー端末装置200の操作者は、新規にキー情報をキーアプリに登録したい場合、キー端末装置200に対して所定の方法によりキー情報を新規に登録するよう指示する入力を行う。プロセッサー201は、例えば、キー情報を新規に登録するよう指示する入力に応じてデジタルキーを新規に登録すると判定する。
 プロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときにデジタルキーを新規に登録すると判定するならば、ステップST62においてYesと判定して図6のステップST70へと進む。
 ステップST70においてプロセッサー201は、キー要求を生成する。キー要求は、対象情報を含む。キー要求は、当該対象情報で特定されるキー情報を送信するように要求する情報である。対象情報は、当該キー情報が対象とする車両300、及び当該キー情報を使用するユーザーを特定可能な情報である。プロセッサー201は、キー要求を生成した後、当該キー要求をサーバー装置100に送信するように通信インターフェース315に対して指示する。この送信の指示を受けて通信インターフェース315は、当該キー要求をサーバー装置100に送信する。送信された当該キー要求は、サーバー装置100の通信インターフェース105によって受信される。
 一方、サーバー装置100のプロセッサー101は、図3のステップST11~ステップST14を繰り返す待受状態にあるときにキー要求が受信されたならば、ステップST12においてYesと判定してステップST16へと進む。
 ステップST16においてプロセッサー101は、ステップST12で受信されたキー要求に含まれる対象情報に従ってキー情報を生成する。
 ステップST17においてプロセッサー101は、キー応答を生成する。キー応答は、ステップST16で生成されたキー情報を含む。キー応答は、例えば、当該キー情報を登録するように指示する情報である。プロセッサー101は、キー応答を生成した後、当該キー応答を、キー要求の送信元のキー端末装置200に送信するように通信インターフェース105に対して指示する。この送信の指示を受けて通信インターフェース105は、当該キー応答を当該キー端末装置200に送信する。送信された当該キー応答は、当該キー端末装置200の通信インターフェース315によって受信される。プロセッサー101は、ステップST17の処理の後、ステップST11へと戻る。
 一方、図6のステップST71においてキー端末装置200のプロセッサー201は、通信インターフェース315によってキー応答が受信されるのを待ち受けている。プロセッサー201は、キー応答が受信されたならば、ステップST71においてYesと判定してステップST72へと進む。
 ステップST72においてプロセッサー201は、ステップST71で受信されたキー応答に含まれるキー情報をキーアプリに登録する。この際、プロセッサー201は、当該キー情報を補助記憶装置204に記憶させる。プロセッサー201は、ステップST72の処理の後、ステップST61へと戻る。
 プロセッサー201は、例えば、キー端末装置200とキーインターフェース320の距離が所定距離以内となった場合にキーインターフェース320と接続すると判定する。プロセッサー201は、例えば、キーインターフェース320が送信する電波を受信した場合にキーインターフェース320と接続すると判定する。プロセッサー201は、例えば、キーインターフェース320と通信可能となった場合にキーインターフェース320と接続すると判定する。プロセッサー201は、例えば、キー端末装置200の所持者がドア330に振れたことに応じてキーインターフェース320と接続すると判定する。
 プロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときにキーインターフェース320と接続すると判定するならば、ステップST63においてYesと判定して図6のステップST73へと進む。
 ステップST73においてプロセッサー201は、無線インターフェース206とキーインターフェース320との間の通信を確立する。
 ステップST74においてプロセッサー201は、デジタルキーが制限状態であるか否かを判定する。プロセッサー201は、デジタルキーが制限状態でないならば、すなわちデジタルキーが非制限状態であるならば、ステップST74においてNoと判定してステップST75へと進む。なお、制限状態及び非制限状態については後述する。
 ステップST75においてプロセッサー201は、ロック解除要求を生成する。ロック解除要求は、車両300のロック状態を解除するように要求する情報である。ロック解除要求は、例えば、ログインID、補助記憶装置204に記憶された制限変数、及びキーアプリに登録されたキー情報を含む。当該制限変数の値は、非制限状態を示す値である。プロセッサー201は、ロック解除要求を生成した後、当該ロック解除要求を車両300に送信するように無線インターフェース206に対して指示する。この送信の指示を受けて無線インターフェース206は、当該ロック解除要求を車両300に送信する。送信された当該ロック解除要求は、車両300のキーインターフェース320によって受信される。プロセッサー201は、ステップST75の処理の後、ステップST61へと戻る。
 以上より、キー端末装置200のプロセッサー201は、図6のステップST63、及びステップST73~ステップST75の処理を実行することで、第1の端末装置をデジタルキーとして機能させるデジタルキー部の一例として機能する。
 制御装置310のプロセッサー311は、例えば、車両300がロック状態になった場合、図9に示す処理を開始する。
 図9のステップST101において制御装置310のプロセッサー311は、キーインターフェース320によってロック解除要求が受信されたか否かを判定する。プロセッサー311は、ロック解除要求が受信されないならば、ステップST101においてNoと判定してステップST102へと進む。
 ステップST102においてプロセッサー311は、車両300をロック状態にするか否かを判定する。プロセッサー311は、車両300をロック状態にすると判定しないならば、ステップST102においてNoと判定してステップST101へと戻る。かくして、プロセッサー311は、ロック解除要求が受信されるか、車両300をロック状態にすると判定するまでステップST101及びステップST102を繰り返す待受状態となる。
 プロセッサー311は、ステップST101及びステップST102を繰り返す待受状態にあるときにロック解除要求が受信されたならば、ステップST101においてYesと判定してステップST103へと進む。
 ステップST103においてプロセッサー311は、ステップST101で受信されたロック解除要求に含まれるキー情報を用いて認証を行う。そして、プロセッサー311は、当該認証に成功したか否かを判定する。プロセッサー311は、認証に成功していないならば、ステップST103においてNoと判定してステップST101へと戻る。対して、プロセッサー311は、認証に成功したならば、ステップST103においてYesと判定してステップST104へと進む。
 ステップST104においてプロセッサー311は、ステップST101で受信されたロック解除要求に含まれる制限変数を参照して、デジタルキーが制限状態であるか否かを判定する。プロセッサー311は、デジタルキーが制限状態でないならば、ステップST104においてNoと判定してステップST104へと進む。
 ステップST105においてプロセッサー311は、電子ロック331を制御して、電子ロック331を開錠する。これにより、キー端末装置200の所持者は車両300内に入れるようになる。車内300内に入った当該所持者などは、動力部340などの車両300の各部を始動させたい場合、例えば、スタートボタン360を操作するなどの、車両300を始動させる操作を行う。
 ステップST106においてプロセッサー311は、車両300を始動させる操作が行われるのを待ち受ける。すなわちプロセッサー311は、スタートボタン360を操作するなどの予め定められた操作が行われるのを待ち受ける。プロセッサー311は、車両300を始動させる操作が行われたならば、ステップST106においてYesと判定してステップST107へと進む。
 ステップST107においてプロセッサー311は、ステップST101で受信されたロック解除要求に含まれる制限変数を参照して、デジタルキーが制限状態であるか否かを判定する。プロセッサー311は、デジタルキーが制限状態でないならば、ステップST107においてNoと判定してステップST108へと進む。
 ステップST108においてプロセッサー311は、車両300の各部を始動する。プロセッサー311は、ステップST108の処理の後、図9に示す処理を終了する。
 車両300は、運転手ごとに走行データを記録する機能を有する。車両300の運転手は、図9のステップST101で受信されたロック解除要求に含まれるユーザーIDで特定される。制御装置310は、例えば、各種のセンサーなどを用いて走行データを記録する。走行データは、例えば、走行ルート、速度の履歴、加速度の履歴、躍度の履歴、ブレーキ開度の履歴、ブレーキのタイミングの履歴、急ブレーキの発生履歴、アクセル開度の履歴、アクセルのタイミングの履歴、ステアリングの操舵角の履歴、ステアリングのタイミングの履歴、走行車線を逸脱したことの発生履歴、衝突軽減ブレーキの動作履歴、一時停止不停止の発生履歴、交差点等での合図不履行の発生履歴、交差点等での徐行違反の発生履歴、逆走の発生履歴、速度超過の発生履歴、速度超過の超加速度、走行ルート上の各道路が高速道路であるか否かを示す情報、走行中に確認しなければいけない各道路標識を運転手が認識したか否かを示す情報、運転手の居眠りの発生履歴、及び運転手の健康状態を含む。また、車両300は、及び当該走行データをサーバー装置100に送信する機能を有する。制御装置310は、例えば、所定のタイミングで走行データを送信する。所定のタイミングは、例えば、定期的なタイミングである。あるいは、所定のタイミングは、運転手が車両300の運転を終了したタイミングである。あるいは、所定のタイミングは、車両300がロック状態になったタイミングである。制御装置310のプロセッサー311は、所定のタイミングになったならば、走行データを送信すると判定する。
 プロセッサー311は、図8のステップST91及びステップST92を繰り返す待受状態にあるときに走行データを送信すると判定するならば、ステップST92においてYesと判定してステップST94へと進む。
 ステップST94においてプロセッサー311は、図9のステップST101で受信されたロック解除要求に含まれるユーザーIDで特定される運転手の走行データのうち、未送信であるものを取得する。
 図8のステップST95においてプロセッサー311は、走行データ情報を生成する。走行データ情報は、ステップST94で取得された走行データ、及び図9のステップST101で受信されたロック解除要求に含まれるユーザーIDを含む。プロセッサー311は、走行データ情報を生成した後、当該走行データ情報をサーバー装置100に送信するように通信インターフェース315に対して指示する。この送信の指示を受けて通信インターフェース315は、当該走行データ情報をサーバー装置100に送信する。送信された当該走行データ情報は、サーバー装置100の通信インターフェース105によって受信される。プロセッサー311は、ステップST95の処理の後、ステップST91へと戻る。
 一方、図4のステップST31においてサーバー装置100のプロセッサー101は、通信インターフェース105によって走行データ情報が受信されるのを待ち受けている。プロセッサー101は、走行データ情報が受信されたならば、ステップST31においてYesと判定してステップST32へと進む。
 ステップST32においてプロセッサー101は、ステップST31で受信された走行データ情報に含まれる走行データを分析する。当該分析は、運転状況の診断を含む。また、プロセッサー101は、過去にユーザーDBに記憶した走行データも用いて分析しても良い。
 プロセッサー101は、通信インターフェース105を制御して走行データ情報を受信することで走行データを取得する。プロセッサー101は、ステップST32の処理を実行することで、走行データの分析結果を取得する。したがって、プロセッサー101は、走行データ情報の受信及びステップST32の処理の実行の少なくともいずれかを行うことで第1のユーザーによる機械の運転状況を取得する取得部の一例として機能する。
 ステップST33においてプロセッサー101は、ステップST31で受信された走行データ情報に含まれる走行データ、及びステップST32の分析結果を、当該走行データ情報に含まれるユーザーIDと関連付けてユーザーDBに記憶する。
 したがって、プロセッサー101は、補助記憶装置104と協働してステップST33の処理を行うことで、運転状況を記憶する記憶部の一例として機能する。あるいは、プロセッサー101は、補助記憶装置104を制御してステップST33の処理を行うことで、記憶部の一例として機能する。
 ステップST34においてプロセッサー101は、走行データ及びステップST32の分析結果に基づき、ユーザーが使用するデジタルキーに制限をかけて制限状態にするか否かを判定する。当該ユーザーは、ステップST31で受信された走行データ情報に含まれるユーザーIDで特定されるユーザーである。プロセッサー101は、例えば、当該ユーザーの走行に、デジタルキーに制限をかけるに相当する程度に問題があると判定する場合に、デジタルキーを制限状態にすると判定する。デジタルキーに制限をかけるに相当する程度に問題がある場合とは、例えば、急ブレーキの回数が所定回数以上である場合、走行車線の逸脱が所定回数以上発生している場合、衝突軽減ブレーキが所定回数以上動作している場合、一時停止不停止が所定回数以上発生している場合、交差点等での合図不履行が所定回数以上発生している場合、交差点等での徐行違反が所定回数以上発生している場合、所定回数以上逆走している場合、所定回数以上速度超過している場合、所定以上の超加速度の速度超過をしている場合、高速道路の使用頻度が所定の頻度範囲内である場合、走行中に確認しなければいけない各道路標識を運転手が認識していない回数が所定回数以上である場合、運転手の居眠りが所定回数又は所定時間以上である場合、運転の頻度が所定の頻度よりも少ない場合、運転手の健康状態が悪いと判定した場合及びその他異常な運転又は危険な運転を検知した場合などである。また、プロセッサー101は、ユーザーの運転が安全運転でないと判定した場合も、デジタルキーに制限をかけるに相当する程度に問題があるとみなしても良い。プロセッサー101は、デジタルキーを制限状態にすると判定しないならば、ステップST34においてNoと判定してステップST31へと戻る。対して、プロセッサー101は、デジタルキーを制限状態にすると判定するならば、ステップST34においてYesと判定してステップST35へと進む。
 以上より、プロセッサー101は、ステップST34の処理を実行することで、第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する判定部の一例として機能する。また、デジタルキーに制限をかけるに相当する程度に問題があることは、第1のユーザーの運転に問題があることの一例である。したがって、ステップST34における当該所定条件は、第1のユーザーの運転に問題があることである。
 ステップST35においてプロセッサー101は、ユーザーDBを更新して、ステップST31で受信された走行データ情報に含まれるユーザーIDに関連付けられたサーバー制限変数の値を、制限状態を示す値にする。また、プロセッサー101は、ユーザーDBを更新して、当該ユーザーIDで特定される運転状況を各ユーザーが最後に確認した日時をリセットする。運転状況の確認日時については後述する。
 ステップST36においてプロセッサー101は、制限要求を、ステップST31で受信された走行データ情報に含まれるユーザーIDが使用するキー端末装置200に送信するように通信インターフェース105に対して指示する。制限要求は、デジタルキーを制限状態にするように指示する情報である。この送信の指示を受けて通信インターフェース105は、当該制限要求をキー端末装置200に送信する。送信された当該制限要求は、キー端末装置200の通信インターフェース315によって受信される。プロセッサー101は、ステップST36の処理の後、ステップST31へと戻る。
 以上より、プロセッサー101は、制限要求を送信する処理を実行することで、所定条件を満たしている場合、デジタルキーを、機械のロックの少なくとも一部を解除できない制限状態にする制限部の一例として機能する。あるいは、プロセッサー101は、通信インターフェース105と協働して、制限要求を送信することで、制限部の一例として機能する。
 一方、キー端末装置200のプロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときに制限要求が受信されたならば、ステップST64においてYesと判定して図7のステップST78へと進む。
 ステップST78においてプロセッサー201は、デジタルキーを制限状態にする。このために、プロセッサー201は、制限変数の値を、制限状態を示す値に書き換える。
 以上より、プロセッサー201は、補助記憶装置204と協働して、制限要求の受信に応じてステップST78の処理を行うことで、制限部による制御に従ってデジタルキーが制限状態であることを記憶する制限記憶部の一例として機能する。また、プロセッサー201は、制限要求の受信に応じてステップST78の処理を行うことで、制限部による制御に従ってデジタルキーが制限状態であることを記憶装置に記憶させる制限記憶部の一例として機能させる。
 ステップST79においてプロセッサー201は、デジタルキーが制限状態になったことをキー端末装置200の所持者に通知するため、デジタルキーが制限状態になったことを報知する。プロセッサー201は、例えば、表示デバイス207に、デジタルキーが制限状態になったこと及び運転状況を確認すれば制限状態が解除されることを示す画像を表示させる。また、プロセッサー201は、スピーカーから音声を出力すること、発光デバイスを発光させること、及びバイブレーターを振動させることなどによっても報知しても良い。また、プロセッサー201は、プッシュ通知によって報知しても良い。プロセッサー201は、ステップST79の処理の後、図6のステップST61へと戻る。
 デジタルキーサービスのユーザーは、自身又は他のユーザーによる車両300の運転の運転状況を確認することができる。運転状況は、ステップST33で記憶された走行データ及び分析結果に基づくものである。
 また、デジタルキーシステム1は、ユーザー(以下、区別のために「運転ユーザー」という。)の運転状況が予め定められたユーザー(以下、区別のために「所定ユーザー」という。)によって所定期間P1内に確認されていない場合に当該運転ユーザーが使用するデジタルキーを制限する機能を有する。所定期間P1は、例えば、現在から所定時間前までの期間である。当該所定時間は、時間、日数、週数、月数又は年数などによって定められる。運転ユーザーと所定ユーザーは、同一であっても異なっていても良い。所定ユーザーがどのユーザーであるかは、運転ユーザーのキーサービス設定によって定められる。所定ユーザーとしては、例えば運転ユーザーの家族又は使用者などを設定することが想定される。所定ユーザーは、複数であっても良い。所定ユーザーが複数である場合、運転ユーザーを含んでも含まなくても良い。所定ユーザーが複数である場合、デジタルキーシステム1は、例えば、所定ユーザーのいずれも所定期間P1内に運転状況を確認していない場合にデジタルキーを制限する。あるいは、所定ユーザーが複数である場合、デジタルキーシステム1は、所定ユーザーのうちの少なくともN人が所定期間P1内に運転状況を確認していない場合にデジタルキーを制限する。Nは、1以上、所定ユーザーの人数未満の整数である。所定ユーザーが複数である場合のデジタルキーを制限する条件は、例えば、運転ユーザーのキーサービス設定によって定められる。所定ユーザーが一人である場合のデジタルキーを制限する条件は、運転状況が所定ユーザーによって所定期間P1内に確認されていないことである。なお、運転ユーザーの運転状況が所定ユーザーによって所定期間P1内に確認されないことによってデジタルキーを制限する条件を満たすことを、「運転状況の確認が期限超過する」というものとする。所定期間P1の長さは、例えば、運転ユーザーのキーサービス設定によって定められる。なお、所定期間P1は、第1の所定期間の一例である。
 図5のステップST41においてサーバー装置100のプロセッサー101は、運転状況の確認が期限超過するまでの期間が所定の期間P2以下となった運転ユーザーがいるか否かを判定する。プロセッサー101は、例えば、ユーザーDBを参照して、この判定を行う。なお、ユーザーDBは、各運転ユーザーについて、所定ユーザーが最後に運転状況を確認した日時を記憶している。プロセッサー101は、運転状況の確認が期限超過するまでの期間が所定の期間P2以下となった運転ユーザーがいないならば、ステップST41においてNoと判定してステップST42へと進む。
 ステップST42においてプロセッサー101は、運転状況の確認が期限超過した運転ユーザーがいるか否かを判定する。プロセッサー101は、例えば、ユーザーDBを参照して、この判定を行う。プロセッサー101は、運転状況の確認が期限超過した運転ユーザーがいないならば、ステップST42においてNoと判定してステップST41へと戻る。かくして、プロセッサー101は、運転状況の確認が期限超過するまでの期間が所定の期間P2以下となるか、運転状況の確認が期限超過するまでステップST41及びステップST42を繰り返す待受状態となる。
 プロセッサー101は、ステップST41及びステップST42を繰り返す待受状態にあるときに、運転状況の確認が期限超過するまでの期間が所定の期間P2以下となった運転ユーザーがいると判定するならば、ステップST41においてYesと判定してステップST43へと進む。
 ステップST43においてプロセッサー101は、第1通知情報を、運転状況の確認が期限超過するまでの期間が所定の期間P2以下となった運転ユーザーが使用するキー端末装置200、及び当該運転ユーザーの所定ユーザーのうち、当該運転ユーザー以外の所定ユーザーが使用する端末装置400に送信するように通信インターフェース105に対して指示する。第1通知情報は、運転状況の確認が期限超過しそうであることを示す情報である。第1通知情報は、通知情報の一種である。この送信の指示を受けて通信インターフェース105は、当該第1通知情報を当該キー端末装置200及び当該端末装置400に送信する。送信された当該第1通知情報は、当該キー端末装置200の通信インターフェース315によって受信される。送信された当該第1通知情報は、端末装置400の通信インターフェース405によって受信される。プロセッサー101は、ステップST43の処理の後、ステップST41へと戻る。
 運転状況を確認していない期間が所定期間P1する経過までの期間が所定期間P2以下である期間は、第2の所定期間の一例である。数式で示すと、(第2の所定期間)=(所定期間P1)-(所定期間P2)である。以上より、プロセッサー101は、ステップST41及びステップST43の処理を実行することで、第1のユーザーが運転状況を確認していない期間が第1の所定期間以上となるまでの期間が第2の所定期間以下である場合、所定条件を満たしそうであることを第1の端末装置に報知させる報知制御部の一例として機能する。
 一方、キー端末装置200のプロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときに通知情報が受信されたならば、ステップST65においてYesと判定して図7のステップST80へと進む。
 ステップST80においてプロセッサー201は、通知情報が示す内容を通知するために、当該内容を報知する。プロセッサー201は、例えば、表示デバイス207に、運転状況の確認が期限超過しそうであることを示す画像を表示させる。また、プロセッサー201は、スピーカーから音声を出力すること、発光デバイスを発光させること、及びバイブレーターを振動させることなどによっても報知しても良い。また、プロセッサー201は、プッシュ通知によって報知しても良い。プロセッサー201は、ステップST80の処理の後、図6のステップST61へと戻る。
 端末装置400のプロセッサー401は、図10に示すように、キー端末装置200のプロセッサー201による図6及び図7の一部と同様の処理を行う。当該一部とは、ステップST61、ステップST65、ステップST66、ステップST69及びステップST80~ステップST84である。端末装置400のプロセッサー401による図10の処理について、キー端末装置200のプロセッサー201による図6及び図7の処理と同様の部分は説明を省略する。ただし、プロセッサー401が行う図10の処理は、図6及び図7の処理の説明における「キー端末装置200」を「端末装置400」に、「プロセッサー201」を「プロセッサー401」に、「通信インターフェース205」を「通信インターフェース405」に、「表示デバイス207」を「表示デバイス406」に、「入力デバイス208」を「入力デバイス407」に読み替えたものである。
 端末装置400のプロセッサー401は、図10のステップST61においてNoと判定したならばステップST65へと進む。プロセッサー401は、ステップST66においてNoと判定したならばステップST61へと戻る。かくして、プロセッサー401は、キーサービス設定を変更すると判定するか、通知情報が受信されるか、運転状況の確認を開始すると判定するまで図10のステップST61、ステップST65及びステップST66を繰り返す待ち受け状態となる。
 一方、サーバー装置100のプロセッサー101は、図5のステップST41及びステップST42を繰り返す待受状態にあるときに、運転状況の確認が期限超過した運転ユーザーがいると判定するならば、ステップST42においてYesと判定してステップST44へと進む。
 ステップST44においてプロセッサー101は、ユーザーDBを更新して、運転状況の確認が期限超過した運転ユーザーのユーザーIDに関連付けられたサーバー制限変数の値を、制限状態を示す値にする。
 ステップST45においてプロセッサー101は、制限要求を、運転状況の確認が期限超過した運転ユーザーが使用するキー端末装置200に送信するように通信インターフェース105に対して指示する。この送信の指示を受けて通信インターフェース105は、当該制限要求をキー端末装置200に送信する。送信された当該制限要求は、キー端末装置200の通信インターフェース315によって受信される。
 以上より、プロセッサー101は、ステップST42の処理を実行することで、機械を運転できないようにするロックを解除するために使用するデジタルキーとして機能する第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する判定部の一例として機能する。運転ユーザーが所定ユーザーである場合のステップST42における当該所定条件は、第1のユーザーが運転状況を第1の所定期間以上確認していないことである。運転ユーザー以外が所定ユーザーである場合のステップST42における当該所定条件は、第2のユーザーが運転状況を第1の所定期間以上確認していないことである。
 ステップST46においてプロセッサー101は、第2通知情報を、運転状況の確認が期限超過した運転ユーザーの所定ユーザーのうち、当該運転ユーザー以外の所定ユーザーが使用する端末装置400に送信するように通信インターフェース105に対して指示する。第2通知情報は、運転状況の確認が期限超過したことを示す情報である。第2通知情報は、通知情報の一種である。この送信の指示を受けて通信インターフェース105は、当該第2通知情報を当該端末装置400に送信する。送信された当該第2通知情報は、当該端末装置400の通信インターフェース405によって受信される。プロセッサー101は、ステップST46の処理の後、ステップST41へと戻る。
 また、プロセッサー101は、図4のステップST36の処理の後、ステップST37へと進む。
 ステップST37においてプロセッサー101は、第2通知情報を、運転状況の確認が期限超過した運転ユーザーの所定ユーザーのうち、当該運転ユーザー以外の所定ユーザーが使用する端末装置400に送信するように通信インターフェース105に対して指示する。この送信の指示を受けて通信インターフェース105は、当該第2通知情報を当該端末装置400に送信する。送信された当該第2通知情報は、当該端末装置400の通信インターフェース405によって受信される。
 キー端末装置200の操作者は、運転状況を確認したい場合、例えば、入力デバイス208を用いて、運転状況の確認を開始することを示す操作入力を行う。キー端末装置200のプロセッサー201は、例えば、当該操作入力に応じて、運転状況の確認を開始すると判定する。
 キー端末装置200のプロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときに運転状況の確認を開始すると判定するならば、ステップST64においてYesと判定して図7のステップST81へと進む。
 ステップST81においてプロセッサー201は、開始要求を生成する。開始要求は、例えば、ログインID及び対象IDを含む。対象IDは、どのユーザーの運転状況を開始するかを示す。対象IDは、当該ユーザーのユーザーIDである。ここでは、対象IDは、ログインIDと同一である。開始要求は、運転状況を開始することを示す情報である。また、開始要求は、対象IDで特定されるユーザーの運転状況の確認に必要な情報を送信するように要求する情報である。プロセッサー201は、開始要求を生成した後、当該開始要求をサーバー装置100に送信するように通信インターフェース205に対して指示する。この送信の指示を受けて通信インターフェース205は、当該開始要求をサーバー装置100に送信する。送信された当該開始要求は、サーバー装置100の通信インターフェース105によって受信される。
 また、端末装置400の操作者は、運転状況を確認したい場合、例えば、入力デバイス407を用いて、運転状況の確認を開始することを示す操作入力を行う。また、端末装置400の操作者は、入力デバイス407を用いて、どのユーザーの運転状況を確認するかを指定する操作入力を行う。指定可能なユーザーは、ログインIDで特定されるユーザーが所定ユーザーとなっている運転ユーザーである。また、指定可能なユーザーは、ログインIDで特定されるユーザーに対して、運転状況の確認の許可を出しているユーザーである。ユーザーがどのユーザーに対して運転状況の確認の許可を出しているかは、運転状況の確認の許可を出すユーザーのキーサービス設定によって定められる。
 図10のステップST81においてプロセッサー401が生成する開始要求中の対象IDは、運転状況を確認する対象として指定されたユーザーのユーザーIDである。
 一方、サーバー装置100のプロセッサー101は、図3のステップST11~ステップST14を繰り返す待受状態にあるときに開始要求が受信されたならば、ステップST13においてYesと判定してステップST18へと進む。
 ステップST18においてプロセッサー101は、ユーザーDBを参照して、ステップST13で受信された開始要求に含まれる対象IDに関連付けられた分析結果及び走行データを取得する。
 ステップST19においてプロセッサー101は、開始応答を生成する。開始応答は、ステップST18で取得された分析結果及び走行データ、並びにステップST13で受信された開始要求に含まれる対象IDを含む。開始応答は、当該分析結果及び当該走行データを表示するように指示する情報である。プロセッサー101は、開始応答を生成した後、当該開始応答を開始要求の送信元であるキー端末装置200又は端末装置400に送信するように通信インターフェース105に対して指示する。この送信の指示を受けて通信インターフェース105は、当該開始応答をキー端末装置200又は端末装置400に送信する。送信された当該開始応答は、キー端末装置200の通信インターフェース205又は端末装置400の通信インターフェース405によって受信される。プロセッサー101は、ステップST19の処理の後、ステップST11へと戻る。
 プロセッサー101は、キー端末装置200に開始応答を送信する処理を行うことで、第1の端末装置と通信することで、運転状況を第1の端末装置に表示させる表示制御部の一例として機能する。あるいは、プロセッサー101は、通信インターフェース105と協働して表示制御部の一例として機能する。プロセッサー101は、端末装置400に開始応答を送信する処理を行うことで、運転状況を第2の端末装置に表示させる表示制御部の一例として機能する。
 一方、図7のステップST82においてキー端末装置200のプロセッサー201は、通信インターフェース205によって開始応答が受信されるのを待ち受けている。プロセッサー201は、開始応答が受信されたならば、ステップST82においてYesと判定してステップST83へと進む。
 ステップST83においてプロセッサー201は、運転状況を確認するための処理を開始する。このために、プロセッサー201は、例えば、確認画面を表示デバイス207に表示させる。確認画面は、例えば、ステップST82で受信された開始応答に含まれる走行データ及び分析結果を含む。確認画面は、複数ページに渡るものであっても良い。確認画面は、スクロール可能であっても良い。
 キー端末装置200の操作者は、運転状況を確認する。すなわち、当該操作者は、表示デバイス207に表示された走行データ及び分析結果を見る。当該操作者は、運転状況の確認を終了する場合、入力デバイス407を用いて、運転状況の確認を終了するように指示することを示す操作入力を行う。
 ステップST84においてプロセッサー201は、運転状況を確認するための処理を終了するように指示する操作が行われるのを待ち受ける。すなわちプロセッサー201は、運転状況を確認するための処理を終了するように指示するボタンを操作するなどの予め定められた操作が行われるのを待ち受ける。プロセッサー201は、運転状況を確認するための処理を終了するように指示する操作が行われたならば、ステップST84においてYesと判定してステップST85へと進む。
 ステップST85においてプロセッサー201は、キー端末装置200の操作者が運転状況を確認したか否かを判定する。プロセッサー201は、例えば、当該操作者が運転状況を確認するのにかけた時間が所定時間以上である場合に、当該操作者が運転状況を確認したと判定する。当該操作者が運転状況を確認するのにかけた時間は、例えば、ステップST83の処理の実行からステップST84においてYesと判定するまでの時間である。プロセッサー201は、例えば、確認画面を所定ページ以上又は全ページが表示された場合に当該操作者が運転状況を確認したと判定する。プロセッサー201は、例えば、確認画面が所定以上又は全てスクロールされた場合に当該操作者が運転状況を確認したと判定する。また、確認画面は、運転状況に関するテストを表示しても良い。プロセッサー201は、例えば、当該操作者による当該テストの解答結果が所定の点数以上である場合に当該操作者が運転状況を確認したと判定する。また、確認画面は、動画を含んでも良い。プロセッサー201は、例えば、当該動画を所定時間又は全て再生済みである場合に当該操作者が運転状況を確認したと判定する。また、プロセッサー201は、上記に示した各条件を複合した条件を満たした場合に操作者が運転状況を確認したと判定しても良い。プロセッサー201は、当該操作者が運転状況を確認したと判定しないならば、ステップST85においてNoと判定して図6のステップST61へと戻る。対して、プロセッサー201は、当該操作者が運転状況を確認したと判定するならば、ステップST85においてYesと判定してステップST86へと進む。
 なお、プロセッサー201は、特に条件無くキー端末装置200の操作者が運転状況を確認したとみなしても良い。この場合、プロセッサー201は、例えば、ステップST8でYesと判定した場合ステップST86へと進む。
 ステップST86においてプロセッサー201は、確認通知を生成する。確認通知は、ログインID及びステップST82で受信された開始応答に含まれる対象IDを含む。確認通知は、当該ログインIDで特定されるユーザーが、当該対象IDで特定されるユーザーの運転状況を確認したことを示す情報である。プロセッサー201は、確認通知を生成した後、当該確認通知をサーバー装置100に送信するように通信インターフェース205に対して指示する。この送信の指示を受けて通信インターフェース205は、当該確認通知をサーバー装置100に送信する。送信された当該確認通知は、サーバー装置100の通信インターフェース105によって受信される。プロセッサー201は、ステップST86の処理の後、図6のステップST61へと戻る。
 一方、サーバー装置100のプロセッサー101は、図3のステップST11~ステップST14を繰り返す待受状態にあるときに確認通知が受信されたならば、ステップST14においてYesと判定してステップST20へと進む。
 一方、図3のステップST20においてサーバー装置100のプロセッサー101は、ログインIDで特定されるユーザーが最後に運転状況を確認した日時をユーザーDBに記憶する。プロセッサー101は、例えば、ステップST14で受信された確認通知に含まれるログインID及び対象IDに現在日時を関連付けて記憶する。当該現在日時は、当該対象IDで特定されるユーザーの運転状況を当該ログインIDで特定されるユーザーが確認した日時を示す。
 ステップST21においてプロセッサー101は、ステップST14で受信された確認通知に含まれる対象IDで特定されるユーザーのデジタルキーの制限を解除するか否かを判定する。プロセッサー101は、ステップST14で受信された確認通知に含まれるログインIDで特定されるユーザーが、対象IDで特定される運転ユーザーの所定ユーザーでない場合、当該デジタルキーの制限を解除すると判定しない。対して、プロセッサー101は、当該ログインIDで特定されるユーザーが、対象IDで特定される運転ユーザーの所定ユーザーである場合、ユーザーDBを参照して、ステップST14で受信された確認通知に含まれる対象IDに関連付けられたサーバー制限変数の値を確認する。プロセッサー101は、当該値が非制限状態を示す値である場合、当該デジタルキーの制限を解除すると判定しない。対して、プロセッサー101は、当該値が制限状態を示す値である場合、当該対象IDで特定されるユーザーの運転状況の確認が期限超過しているか否かを確認する。プロセッサー101は、当該運転状況の確認が期限超過している場合、当該デジタルキーの制限を解除すると判定しない。対して、プロセッサー101は、当該運転状況の確認が期限超過していない場合、当該デジタルキーの制限を解除すると判定する。プロセッサー101は、当該デジタルキーの制限を解除すると判定しないならば、ステップST21においてNoと判定してステップST11へと戻る。対して、プロセッサー101は、当該デジタルキーの制限を解除すると判定するならば、ステップST21においてYesと判定してステップST22へと進む。
 ステップST22においてプロセッサー101は、ユーザーDBを更新して、ステップST14で受信された確認通知に含まれる対象IDに関連付けられたサーバー制限変数の値を、制限状態を示す値にする。
 ステップST23においてプロセッサー101は、制限解除要求を、ステップST14で受信された確認通知に含まれる対象IDで特定されるユーザーが使用するキー端末装置200に送信するように通信インターフェース105に対して指示する。制限解除要求は、デジタルキーの制限状態を解除して非制限状態にするように指示する情報である。この送信の指示を受けて通信インターフェース105は、当該制限解除要求を当該キー端末装置200に送信する。送信された当該制限解除要求は、当該キー端末装置200の通信インターフェース205によって受信される。プロセッサー101は、ステップST23の処理の後、ステップST11へと戻る。
 一方、キー端末装置200のプロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときに制限解除要求が受信されたならば、ステップST67においてYesと判定して図7のステップST87へと進む。
 ステップST87においてプロセッサー201は、デジタルキーの制限状態を解除して非制限状態にする。このために、プロセッサー201は、制限変数の値を、非制限状態を示す値に書き換える。
 ステップST88においてプロセッサー201は、デジタルキーの制限状態が解除されて非制限状態になったことをキー端末装置200の所持者に通知するため、デジタルキーの制限状態が解除されて非制限状態になったことを報知する。プロセッサー201は、例えば、表示デバイス207に、デジタルキーの制限状態が解除されて非制限状態になったことを示す画像を表示させる。また、プロセッサー201は、スピーカーから音声を出力すること、発光デバイスを発光させること、及びバイブレーターを振動させることなどによっても報知しても良い。また、プロセッサー201は、プッシュ通知によって報知しても良い。プロセッサー201は、ステップST88の処理の後、図6のステップST61へと戻る。
 以下、デジタルキーが制限状態である場合のキー端末装置200及び車両300の動作について説明する。
 キー端末装置200のプロセッサー201は、デジタルキーが制限状態であるならば、ステップST74においてYesと判定してステップST76へと進む。
 ステップST76においてプロセッサー201は、ロック解除要求を生成する。当該ロック解除要求に含まれる制限変数の値は、制限状態を示す値である。プロセッサー201は、ロック解除要求を生成した後、当該ロック解除要求を車両300に送信するように無線インターフェース206に対して指示する。この送信の指示を受けて無線インターフェース206は、当該ロック解除要求を車両300に送信する。送信された当該ロック解除要求は、車両300のキーインターフェース320によって受信される。
 ステップST77においてプロセッサー201は、デジタルキーが制限状態であることをキー端末装置200の所持者に通知するため、デジタルキーが制限状態であることを報知する。プロセッサー201は、例えば、表示デバイス207に、デジタルキーが制限状態であること及び運転状況を確認すれば制限状態が解除されることを示す画像を表示させる。また、プロセッサー201は、スピーカーから音声を出力すること、発光デバイスを発光させること、及びバイブレーターを振動させることなどによっても報知しても良い。また、プロセッサー201は、プッシュ通知によって報知しても良い。プロセッサー201は、ステップST77の処理の後、ステップST61へと戻る。
 一方、制御装置310のプロセッサー311は、デジタルキーが制限状態であるならば、図9のステップST104においてYesと判定してステップST109へと進む。
 ステップST109においてプロセッサー311は、デジタルキーが制限状態であることを、デジタルキーの使用者に報知する。プロセッサー311は、例えば音声などによって報知を行う。
 ステップST110においてプロセッサー311は、車両設定情報を参照して、デジタルキーが制限状態である場合に電子ロック331を開錠する設定になっているか否かを判定する。プロセッサー311は、デジタルキーが制限状態である場合に電子ロック331を開錠しない設定になっているならば、ステップST110においてNoと判定してステップST101へと戻る。対して、プロセッサー311は、デジタルキーが制限状態である場合に電子ロック331を開錠する設定になっているならば、ステップST110においてYesと判定してステップST104へと進む。
 プロセッサー311がステップST110からステップST106へと進んで当該ステップS103の処理を行った場合、車両300はロック状態から一部ロック状態になる。一部ロック状態は、車両300の一部のロックが解除された状態である。当該一部は、少なくとも電子ロック331を含む。したがって、一部ロック状態は、車両300の各部のうちの一部又は全部を始動できない状態である。一部ロック状態の車両300は、走行できないことが好ましい。一部ロック状態は、車両300の少なくとも1つの機能が制限された状態の一例である。
 また、プロセッサー311は、デジタルキーが制限状態であるならば、ステップST107においてYesと判定してステップST111へと進む。
 ステップST111においてプロセッサー311は、車両設定情報を参照して、デジタルキーが制限状態である場合でも始動すると設定されている部品及び装備を特定する。そして、プロセッサー311は、特定した部品及び装備の動作を開始させる。ただし、プロセッサー311は、車両300が走行可能とはならないようにすることが好ましい。なお、プロセッサー311は、デジタルキーが制限状態である場合でも始動すると設定されている部品及び装備が電子ロック331以外に無い場合には、ステップST111の処理においていずれの部品及び装備の動作も開始させるには及ばない。ステップST111の処理の後も、車両300は一部ロック状態である。
 ステップST112においてプロセッサー311は、キーインターフェース320によってロック解除要求が受信されるのを待ち受けている。プロセッサー311は、ロック解除要求が受信されたならば、ステップST112においてYesと判定してステップST113へと進む。
 ステップST113においてプロセッサー311は、ステップST112で受信されたロック解除要求に含まれる制限変数を参照して、デジタルキーが制限状態であるか否かを判定する。プロセッサー311は、デジタルキーが制限状態であるならば、ステップST113においてYesと判定してステップST112へと戻る。対して、プロセッサー311は、デジタルキーが非制限状態であるならば、ステップST113においてNoと判定してステップST114へと進む。
 ステップST114においてプロセッサー311は、車両300の各部を始動する。プロセッサー311は、ステップST114の処理の後、図9に示す処理を終了する。このように、デジタルキーが制限状態から非制限状態になれば、車両300は一部ロック状態から非ロック状態となる。
 キー端末装置200の操作者は、車両300をロック状態にしたい場合、入力デバイス208を用いて、車両300をロック状態にすることをキー端末装置200に指示する操作を行う。なお、当該操作は、車両300が一部ロック状態又はロック解除状態である場合にのみ操作できるようになっていても良い。
 あるいは、当該操作者は、車両300をロック状態にしたい場合、キー端末装置200を所持して車両300から離れる。
 キー端末装置200のプロセッサー201は、図6のステップST61~図7のステップST68を繰り返す待受状態にあるときに車両300をロック状態にすると判定したならば、図7のステップSTにおいてYesと判定してステップST89へと進む。
 ステップST89においてプロセッサー201は、ロック要求を生成する。ロック要求は、車両300をロック状態にするように要求する情報である。ロック要求は、例えば、ログインID、補助記憶装置204に記憶された制限変数、及びキーアプリに登録されたキー情報を含む。プロセッサー201は、ロック要求を生成した後、当該ロック要求を車両300に送信するように無線インターフェース206に対して指示する。この送信の指示を受けて無線インターフェース206は、当該ロック要求を車両300に送信する。送信された当該ロック要求は、車両300のキーインターフェース320によって受信される。プロセッサー201は、ステップST89の処理の後、ステップST61へと戻る。
 一方、制御装置310のプロセッサー311は、キーインターフェース320によってロック要求が受信された場合に車両300をロック状態にすると判定する。また、プロセッサー311は、キー端末装置200が所定以上に車両300から離れた場合に車両300をロック状態にすると判定する。
 制御装置310のプロセッサー311は、ステップST101及びステップST102を繰り返す待受状態にあるときに車両300をロック状態にすると判定するならば、ステップST102においてYesと判定してステップST115へと進む。
 ステップST115においてプロセッサー311は、車両300をロック状態にする。すなわち、プロセッサー311は、ステップST108、ステップST111及びステップST114で始動した車両300の各部を停止する。さらに、プロセッサー311は、電子ロック331を制御して電子ロック331を施錠する。プロセッサー311は、ステップST115の処理の後、ステップST101へと戻る。
 実施形態のデジタルキーシステム1は、デジタルキーを使用する運転ユーザーが所定条件を満たしている場合、デジタルキーを制限状態にする。これにより、実施形態のデジタルキーシステム1は、運転ユーザーに対して所定条件を満たさないように奨励することができる。所定条件が安全運転に関する内容であれば、実施形態のデジタルキーシステム1は、運転ユーザーに対して安全運転を奨励することができる。
 また、実施形態のデジタルキーシステム1は、デジタルキーとして機能するキー端末装置200に、運転ユーザーの運転状況を表示させる。また、実施形態のデジタルキーシステム1は、運転ユーザーが当該運転状況を所定期間P1以上確認していない場合にデジタルキーを制限状態にする。これにより、実施形態のデジタルキーシステム1は、運転ユーザーに運転状況を確認させることができる。運転ユーザーは、運転状況を確認することで、自分の運転を振り返るきっかけになる。したがって、実施形態のデジタルキーシステム1は、運転ユーザーに対して安全運転を奨励することができる。
 また、実施形態のデジタルキーシステム1は、運転状況の確認が期限超過するまでの期間が所定の期間P2以下である場合、キー端末装置200又は端末装置400に対して、運転状況の確認が期限超過しそうであることを報知させる。これにより、実施形態のデジタルキーシステム1は、ユーザーに対して、運転状況の確認が期限超過しそうであること、及びデジタルキーに制限がかかりそうであることを知らせることができる。
 また、実施形態のデジタルキーシステム1は、運転ユーザーの運転に問題がある場合にデジタルキーを制限状態にする。これに対して、運転ユーザーは、デジタルキーが制限状態にならないように運転すると考えられる。このため、実施形態のデジタルキーシステム1は、運転ユーザーに対して安全運転を奨励することができる。
 また、実施形態のデジタルキーシステム1は、運転ユーザーとは異なるユーザーが使用する端末装置400に運転状況を表示させることができる。これにより、例えば、当該異なるユーザーが運転ユーザーの家族であれば、当該家族は運転ユーザーの運転状況を知ることができる。また、例えば、当該異なるユーザーが運転ユーザーにレンタカーを提供しようとしているレンタカー業者であれば、当該レンタカー業者は、レンタカーの提供前に運転ユーザーの運転状況を知ることができる。当該レンタカー業者は、運転状況が悪い場合にはレンタカーの提供を中止することもできる。
 また、実施形態のデジタルキーシステム1は、運転ユーザーとは異なる所定ユーザーが使用する端末装置400に、運転ユーザーの運転状況を表示させる。また、実施形態のデジタルキーシステム1は、当該所定ユーザーが当該運転状況を所定期間P1以上確認していない場合にデジタルキーを制限状態にする。これにより、実施形態のデジタルキーシステム1は、運転ユーザーの家族に運転状況を確認させることができる。
 また、実施形態のデジタルキーシステム1は、運転ユーザーの運転状況を記憶する。これにより、実施形態のデジタルキーシステム1は、運転ユーザーの運転状況の蓄積が可能である。したがって、実施形態のデジタルキーシステム1は、より正確な運転状況の分析も可能である。
 また、実施形態のデジタルキーシステム1によれば、デジタルキーは、ドア330の電子ロック331のロックを解除するために使用される。したがって、実施形態のデジタルキーシステム1は、デジタルキーを制限することで、運転ユーザーに運転をできなくすることができる。
 また、実施形態のデジタルキーシステム1によれば、デジタルキーが制限状態である場合も電子ロック331のロックを解除することができる。この場合、デジタルキーが制限状態であっても運転ユーザーは車両300内に入ることができる。したがって、運転ユーザーは、デジタルキーが制限状態であっても車内の荷物を取り出すこと、車内で休憩することなどが可能である。
 また、実施形態のデジタルキーシステム1によれば、デジタルキーが制限状態である場合もスタートボタン360が操作された場合、車両300に車両300の部品及び装備の一部を始動させることができる。この場合、デジタルキーが制限状態であっても運転ユーザーは、例えばカーオーディオの使用、車内Wi-fiの使用、カーナビゲーションシステムの使用などが可能である。
 上記の実施形態は、以下のような変形も可能である。
 キー端末装置200は、デジタルキーが制限状態にある場合、ロック解除要求を送信しなくても良い。この場合、プロセッサー201は、例えば、ステップST74においてYesと判定したならばステップST77へと進む。また、この場合、制御装置310のプロセッサー311は、デジタルキーが制限状態であるか否かの判定を行わなくても良い。すなわち、プロセッサー311は、ステップST103でYesと判定したならばステップST104へと進む。そして、プロセッサー311は、ステップST106においてYesと判定したならば、ステップST108へと進む。
 キー端末装置200は、デジタルキーが制限状態にある場合、キーインターフェース320との接続を確立しなくても良い。この場合、プロセッサー201は、例えば、ステップST63においてYesと判定したならば、ステップST74へと進む。そして、プロセッサー201は、ステップST74においてYesと判定したならばステップST77へと進む。対して、プロセッサー201は、ステップST74においてNoと判定したならば、ステップST73へと進む。そして、プロセッサー201は、ステップST73の処理の後、ステップST75へと進む。
 制御装置310は、デジタルキーが制限状態であるか否かを、サーバー装置100に問い合わせることで判定しても良い。この場合、キー端末装置200は、デジタルキーが制限状態であるか否かの判定を行わなくても良い。
 上記の実施形態では、デジタルキーが制限状態であるか否かにかかわらず車両300をロック状態にすることができる。しかしながら、デジタルキーが制限状態にある場合には車両300をロック状態にすることができなくても良い。この場合、キー端末装置200のプロセッサー201は、例えば、デジタルキーが制限状態にある場合、ロック要求を送信しない。あるいは、制御装置310のプロセッサー311は、受信されたロック要求に含まれる制限変数を参照して、デジタルキーが制限状態であるか否かを判定する。そして、プロセッサー311は、デジタルキーが制限状態である場合には車両300をロック状態にしない。デジタルキーが制限状態である場合には車両300をロック状態にするか否かは、設定によって変更可能であっても良い。当該設定は、車両設定情報として補助記憶装置314に記憶される。また、制限状態でもロック可能な部品及び装備を設定することが可能であっても良い。この場合、プロセッサー311は、ロック要求が受信された場合、車両設定情報を参照して、制限状態でもロック可能であると設定されている部品及び装備をロックする。すなわち、プロセッサー311は、ステップST108、ステップST111及びステップST114で始動した車両300の各部のうち、制限状態でもロック可能であると設定されている部品及び装備を停止する。また、プロセッサー311は、電子ロック331が制限状態でもロック可能であると設定されている場合、電子ロック331を制御して電子ロック331を施錠する。なお、デジタルキーが制限状態である場合でも始動すると設定されている部品及び装備と、制限状態でもロック可能であると設定されている部品及び装備とは、同じ部品及び装備となるように、例えば、設定が共通であっていても良い。
 所定条件は上記で示した以外の条件でも良い。
 実施形態のデジタルキーシステムは、デジタルキーを制限状態にすることに代えて、車両自体の機能を制限しても良い。
 上記の実施形態では、自動車である車両300に適用する場合を例にデジタルキーシステム1を説明した。しかしながら、実施形態のデジタルキーシステムは、自動車以外の移動体に適用することも可能である。自動車以外の移動体は、例えば、鉄道車両、航空機、船舶、潜水艦及び宇宙船などである。また、実施形態のデジタルキーシステムを適用する移動体は、遠隔運転(遠隔操縦)するものであっても良い。また、実施形態のデジタルキーシステム1は、移動体以外の機械に適用することも可能である。移動体以外の機械は、例えば、移動式でないクレーンなどである。自動車以外の機械に適用する実施形態のデジタルキーシステムは、ドア330に代えて、例えば、運転席(操縦席)又は運転室(操縦室)などの、当該機械を運転(操縦)するための場所に入るためのドアを備える。当該ドアは、ドア330と同様に電子ロック331を備える。遠隔運転用の機械における当該場所は、当該機械の外部に存在する。遠隔運転用ではない機械における当該場所は、当該機械の内部に存在する。
 上記の実施形態においてサーバー装置100が実行する処理の一部をキー端末装置200、制御装置310又は端末装置400が実行しても良い。上記の実施形態においてキー端末装置200が実行する処理の一部をサーバー装置100又は制御装置310が実行しても良い。上記の実施形態において制御装置310が実行する処理の一部をサーバー装置100又はキー端末装置200が実行しても良い。上記の実施形態において端末装置400が実行する処理の一部をサーバー装置100が実行しても良い。
 プロセッサー101、プロセッサー201、プロセッサー311及びプロセッサー401は、上記実施形態においてプログラムによって実現する処理の一部又は全部を、回路のハードウェア構成によって実現するものであっても良い。
 実施形態の処理を実現するプログラムは、例えば装置内の非一時的な記憶媒体に記憶された状態で譲渡される。しかしながら、当該装置は、当該プログラムが記憶されない状態で譲渡されても良い。そして、当該プログラムが別途に譲渡され、当該装置へと書き込まれても良い。このときのプログラムの譲渡は、例えば、リムーバブルで非一時的な記憶媒体に記録して、あるいはインターネット又はLANなどのネットワークを介したダウンロードによって実現できる。
 以上、本発明の実施形態を説明したが、例として示したものであり、本発明の範囲を限定するものではない。本発明の実施形態は、本発明の要旨を逸脱しない範囲において種々の態様で実施可能である。
 1 デジタルキーシステム
 100 サーバー装置
 101,201,311,401 プロセッサー
 102,202,312,402 ROM
 103,203,313,403 RAM
 104,204,314,404 補助記憶装置
 105,205,315,405 通信インターフェース
 106,209,317,408 バス
 200 キー端末装置
 206 無線インターフェース
 207,406 表示デバイス
 208,407 入力デバイス
 300 車両
 310 制御装置
 316 制御インターフェース
 320 キーインターフェース
 330 ドア
 331 電子ロック
 340 動力部
 350 電装部
 360 スタートボタン
 400 端末装置

Claims (12)

  1.  機械の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うデジタルキーとして使用する第1の端末装置と通信する通信部と、
     前記第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する判定部と、
     前記所定条件を満たしている場合、前記デジタルキーを、前記機能の前記制限及び前記解除の少なくともいずれかを行えない制限状態にする制限部と、を備える情報管理装置。
  2.  前記第1のユーザーによる前記機械の運転状況を取得する取得部と、
     前記第1の端末装置と通信することで、前記運転状況を前記第1の端末装置に表示させる表示制御部と、をさらに備え、
     前記所定条件は、前記第1のユーザーが前記運転状況を第1の所定期間以上確認していないことである、請求項1に記載の情報管理装置。
  3.  前記第1のユーザーが前記運転状況を確認していない期間が第1の所定期間以上となるまでの期間が第2の所定期間以下である場合、前記所定条件を満たしそうであることを前記第1の端末装置に報知させる報知制御部をさらに備える、請求項2に記載の情報管理装置。
  4.  前記判定部は、前記所定条件として、前記第1のユーザーの運転に問題があることを判定する、請求項1に記載の情報管理装置。
  5.  前記第1のユーザーによる前記機械の運転状況を取得する取得部と、
     前記運転状況を前記第1のユーザーとは異なる第2のユーザーが使用する第2の端末装置に表示させる表示制御部と、をさらに備える、請求項1に記載の情報管理装置。
  6.  前記所定条件は、前記第2のユーザーが前記運転状況を第1の所定期間以上確認していないことである、請求項5に記載の情報管理装置。
  7.  前記運転状況を記憶する記憶部をさらに備える、請求項2又は請求項5に記載の情報管理装置。
  8.  前記少なくとも1つの機能は、前記機械を運転するための場所に入るためのドアのロックを含み、
     前記制限部は、前記所定条件を満たしている場合、前記デジタルキーを、前記ドアのロックを解除できない前記制限状態にする、請求項1に記載の情報管理装置。
  9.  通信装置を備える情報管理装置が備えるプロセッサーを、
     機械の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うデジタルキーとして使用する第1の端末装置と通信するように前記通信装置を制御する通信制御部と、
     前記第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する判定部と、
     前記所定条件を満たしている場合、前記デジタルキーを、前記機能の前記制限及び前記解除の少なくともいずれかを行えない制限状態にする制限部と、して機能させるプログラム。
  10.  機械の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うデジタルキーとして使用する第1の端末装置と通信する通信部、前記第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する判定部、及び前記所定条件を満たしている場合、前記デジタルキーを、前記機能の前記制限及び前記解除の少なくともいずれかを行えない制限状態にする制限部を備える情報管理装置とともにデジタルキーシステムを構成し、
     前記第1の端末装置を前記デジタルキーとして機能させるデジタルキー部と、
     前記制限部による制御に従って前記デジタルキーが制限状態であることを記憶する制限記憶部と、を備える前記第1の端末装置。
  11.  機械の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うデジタルキーとして使用する第1の端末装置と通信する通信部、前記第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定する判定部、及び前記所定条件を満たしている場合、前記デジタルキーを、前記機能の前記制限及び前記解除の少なくともいずれかを行えない制限状態にする制限部を備える情報管理装置とともにデジタルキーシステムを構成し、記憶装置を備える前記第1の端末装置が備えるプロセッサーを、
     前記第1の端末装置を前記デジタルキーとして機能させるデジタルキー部と、
     前記制限部による制御に従って前記デジタルキーが制限状態であることを前記記憶装置に記憶させる制限記憶部と、して機能させるプログラム。
  12.  機械の少なくとも1つの機能の制限及び解除の少なくともいずれかを行うデジタルキーとして使用する第1の端末装置と通信し、
     前記第1の端末装置を使用する第1のユーザーが所定条件を満たしていることを判定し、
     前記所定条件を満たしている場合、前記デジタルキーを、前記機能の前記制限及び前記解除の少なくともいずれかを行えない制限状態にする、情報管理方法。
PCT/JP2023/012965 2023-03-29 2023-03-29 情報管理装置、端末装置、プログラム及び情報管理方法 Ceased WO2024201844A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
JP2025509456A JPWO2024201844A1 (ja) 2023-03-29 2023-03-29
PCT/JP2023/012965 WO2024201844A1 (ja) 2023-03-29 2023-03-29 情報管理装置、端末装置、プログラム及び情報管理方法

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2023/012965 WO2024201844A1 (ja) 2023-03-29 2023-03-29 情報管理装置、端末装置、プログラム及び情報管理方法

Publications (1)

Publication Number Publication Date
WO2024201844A1 true WO2024201844A1 (ja) 2024-10-03

Family

ID=92903660

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2023/012965 Ceased WO2024201844A1 (ja) 2023-03-29 2023-03-29 情報管理装置、端末装置、プログラム及び情報管理方法

Country Status (2)

Country Link
JP (1) JPWO2024201844A1 (ja)
WO (1) WO2024201844A1 (ja)

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008189261A (ja) * 2007-02-07 2008-08-21 Quality Kk 車両管理システムおよび資格管理プログラム
JP2008297721A (ja) * 2007-05-29 2008-12-11 Mitsubishi Electric Corp 車両電子鍵制御システム
JP2009127285A (ja) * 2007-11-22 2009-06-11 Toyota Motor Corp 電子キーシステム、車両用電子キー装置、解錠方法
JP2014085758A (ja) * 2012-10-22 2014-05-12 Itako Auto Service Co Ltd エンジン始動更新制御装置付きリースシステム及びリース方法
WO2019043954A1 (ja) * 2017-09-04 2019-03-07 本田技研工業株式会社 車両用制御システム
JP2020157860A (ja) * 2019-03-26 2020-10-01 本田技研工業株式会社 車両制御装置

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2008189261A (ja) * 2007-02-07 2008-08-21 Quality Kk 車両管理システムおよび資格管理プログラム
JP2008297721A (ja) * 2007-05-29 2008-12-11 Mitsubishi Electric Corp 車両電子鍵制御システム
JP2009127285A (ja) * 2007-11-22 2009-06-11 Toyota Motor Corp 電子キーシステム、車両用電子キー装置、解錠方法
JP2014085758A (ja) * 2012-10-22 2014-05-12 Itako Auto Service Co Ltd エンジン始動更新制御装置付きリースシステム及びリース方法
WO2019043954A1 (ja) * 2017-09-04 2019-03-07 本田技研工業株式会社 車両用制御システム
JP2020157860A (ja) * 2019-03-26 2020-10-01 本田技研工業株式会社 車両制御装置

Also Published As

Publication number Publication date
JPWO2024201844A1 (ja) 2024-10-03

Similar Documents

Publication Publication Date Title
JP4228930B2 (ja) 車両用セキュリティシステム
CN104245442B (zh) 车载控制系统及车载控制装置
JP4403985B2 (ja) 車両遠隔操作装置
JP6561811B2 (ja) 車載通信装置、車載通信システム及び車両特定処理禁止方法
JP2006193919A (ja) 遠隔制御システム及び遠隔制御装置を備える車両
CN102152773A (zh) 车载通信装置
CN111770127B (zh) 车辆控制系统
JP6813689B2 (ja) 車両用制御システム
JP7447679B2 (ja) 情報処理装置および車両システム
JP2011074721A (ja) 移動体のキー情報管理システム
JP2011166585A (ja) 車載システム、および、車載装置
CN110304015B (zh) 车载认证装置、认证方法及存储介质
JP4462185B2 (ja) 個人認証制御装置
JP2020113065A (ja) 情報管理システム
WO2024201844A1 (ja) 情報管理装置、端末装置、プログラム及び情報管理方法
JP2019119250A (ja) 車両用警報システム
JP7439810B2 (ja) サーバ、情報処理システムおよび情報処理方法
JP2014180937A (ja) 車両操作権限認証システム、車両操作権限認証装置、車両操作権限認証方法、及び車両操作権限認証プログラム
JP2019109868A (ja) 車両管理システムおよび車両管理方法
JP2019105633A (ja) 車両の位置を探し出すための方法、車両を操作するための方法、並びに、システム
JP2021067531A (ja) ナビゲーション装置
JP6267818B1 (ja) 処理装置、処理方法およびプログラム
CN117774886A (zh) 控制装置以及控制方法
CN109841082A (zh) 通知系统、通知装置及通知方法
JP4946266B2 (ja) 車両用認証装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23930482

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2025509456

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 2025509456

Country of ref document: JP

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 23930482

Country of ref document: EP

Kind code of ref document: A1