WO2026014100A1 - 車両管理装置、管理サーバ、および管理システム - Google Patents

車両管理装置、管理サーバ、および管理システム

Info

Publication number
WO2026014100A1
WO2026014100A1 PCT/JP2025/019473 JP2025019473W WO2026014100A1 WO 2026014100 A1 WO2026014100 A1 WO 2026014100A1 JP 2025019473 W JP2025019473 W JP 2025019473W WO 2026014100 A1 WO2026014100 A1 WO 2026014100A1
Authority
WO
WIPO (PCT)
Prior art keywords
vehicle
digital key
key
stored
key information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/JP2025/019473
Other languages
English (en)
French (fr)
Inventor
純也 小林
大幹 本間
洋祐 長谷川
順司 村瀬
柚樹 森
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Toyota Motor Corp
Original Assignee
Toyota Motor Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Toyota Motor Corp filed Critical Toyota Motor Corp
Publication of WO2026014100A1 publication Critical patent/WO2026014100A1/ja
Pending legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • G06F21/35User authentication involving the use of external additional devices, e.g. dongles or smart cards communicating wirelessly
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/45Structures or tools for the administration of authentication

Definitions

  • This disclosure relates to a vehicle management device, a management server, and a management system.
  • Patent Document 1 discloses a digital key system technology that uses a device such as a smartphone as a vehicle key.
  • the digital key system stores information related to the digital key in the vehicle.
  • the digital key system also stores digital key information in the device. This makes it possible to use the vehicle using a device registered as a digital key without the need for a physical key.
  • the digital key system communicates between the device that has stored the digital key information and another person's device to issue a registration request to enable the other person's device to function as a digital key. This allows the digital key system to register the other person's device as a digital key to the vehicle. In other words, the digital key can generate a new digital key.
  • the digital key system makes it possible to lend a vehicle to another person without the need to exchange a physical key.
  • a vehicle management device mounted on a vehicle.
  • the vehicle management device includes a vehicle processing circuit and a vehicle storage device configured to store one or more digital key information units.
  • the digital key information units are information units related to a digital key.
  • the vehicle storage device has a predetermined number of stored digital key information units that can be stored in the vehicle storage device. When the number of stored digital key information units has reached the predetermined number and a new digital key information unit is received, the vehicle processing circuit is configured to delete one of the one or more digital key information units stored in the vehicle storage device.
  • a management server including a server processing circuit.
  • the server processing circuit receives a storage request to store one or more digital key information units in a vehicle in order to manage one or more digital keys.
  • the one or more digital key information units are information units related to one or more of the digital keys.
  • the server processing circuit determines whether the number of stored digital key information units stored in the vehicle has reached a predetermined number of digital key information units that the vehicle can store.
  • the server processing circuit receives the storage request for a vehicle for which the number of stored digital key information units has reached the predetermined number, it transmits a command to the vehicle to delete one of the one or more digital key information units stored in the vehicle.
  • the management system includes a vehicle management device mounted on a vehicle and a management server including a server processing circuit.
  • the vehicle management device includes a vehicle processing circuit and a vehicle storage device.
  • the server processing circuit manages one or more digital keys.
  • the vehicle storage device stores one or more digital key information units as information units related to the one or more digital keys.
  • the vehicle storage device has a predetermined number of digital key information units that can be stored. At least one of the vehicle processing circuit and the server processing circuit is configured to delete one of the one or more digital key information units already stored in the vehicle storage device when a new digital key information unit is received when the number of digital key information units already stored in the vehicle storage device has reached the predetermined number.
  • the vehicle management device described above eliminates the need for the user to select which digital key information units to delete from those already stored in the vehicle. This reduces the burden on the user.
  • the above-mentioned management server eliminates the need for the user to select which digital key information units to delete from those already stored in the vehicle. This reduces the burden on the user.
  • the above management system eliminates the need for the user to select which digital key information units to delete from those already stored in the vehicle, thereby reducing the burden on the user.
  • FIG. 1 is a schematic diagram showing a management system according to a first embodiment.
  • FIG. 2 is a schematic diagram showing owner key information according to the first embodiment.
  • FIG. 3 is a schematic diagram showing the share key information of the first embodiment.
  • FIG. 4 is a schematic diagram showing data in the database of the first embodiment.
  • FIG. 5 is an explanatory diagram showing a series of processes performed by the management system when registering an owner key according to the first embodiment.
  • FIG. 6 is an explanatory diagram showing a series of processes performed by the management system when a friend key is registered in the first embodiment.
  • FIG. 7 is an explanatory diagram showing a series of processes performed by the management system when a non-friend key is registered in the first embodiment.
  • FIG. 1 is a schematic diagram showing a management system according to a first embodiment.
  • FIG. 2 is a schematic diagram showing owner key information according to the first embodiment.
  • FIG. 3 is a schematic diagram showing the share key information of the first embodiment.
  • FIG. 4 is a
  • FIG. 8 is an explanatory diagram showing a series of processes performed by the management system when a non-friend key is deleted in response to a request from a friend device in the first embodiment.
  • FIG. 9 is an explanatory diagram showing a series of processes performed by the management system when a non-friend key is deleted in response to a request from a non-friend device in the first embodiment.
  • FIG. 10 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with the vehicle management device of the first embodiment and a management server.
  • FIG. 11 is a flowchart showing the flow of the process executed by the vehicle control device in FIGS. FIG.
  • FIG. 12 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with a vehicle management device of the second embodiment and a management server.
  • FIG. 13 is an explanatory diagram showing a continuation of the processing of FIG.
  • FIG. 14 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with a vehicle management device of the third embodiment and a management server.
  • FIG. 15 is a flowchart showing the flow of the processing executed by the management server in FIGS. 14, 16, 18, and 20.
  • FIG. 16 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with a vehicle management device of the fourth embodiment and a management server.
  • FIG. 17 is an explanatory diagram showing a continuation of the processing of FIG.
  • FIG. 18 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with a vehicle management device of the fifth embodiment and a management server.
  • FIG. 19 is an explanatory diagram showing a continuation of the processing of FIG.
  • FIG. 20 is an explanatory diagram showing a series of processes performed by a management system including a vehicle equipped with a vehicle management device of the modified example and a management server.
  • FIG. 21 is an explanatory diagram showing a series of processes for prompting the user to select whether or not to permit deletion of the digital key information unit.
  • FIG. 22 is a diagram showing an example of an image displayed to prompt the user to select whether or not to permit deletion of the digital key information unit.
  • the management server 70 is one of multiple devices that make up the management system 10.
  • the management system 10 includes a vehicle 20, multiple devices 30, a device server 60, and a management server 70.
  • the management server 70 is a server that manages digital keys.
  • CCC Car Connectivity Consortium
  • the digital key-related aspects of this embodiment comply with the CCC.
  • Vehicle 20 has a communication module 21, a vehicle HMI 22, a BLE module 23, a UWB module 24, an NFC module 25, and a vehicle management device 26.
  • HMI Human Machine Interface
  • BLE stands for Bluetooth (registered trademark) Low Energy
  • UWB stands for Ultra Wide Band.
  • NFC stands for Near Field Communication.
  • the communication module 21 communicates with the management server 70 via a wireless communication network.
  • the vehicle HMI_22 includes an input device that accepts operations by the user of the vehicle 20, and a presentation device that presents information to the user using images, audio, etc.
  • the presentation device is, for example, a monitor and speaker.
  • the BLE module 23 performs short-range communication with the device 30 via BLE communication.
  • the UWB module 24 communicates with the device 30 via UWB communication.
  • the UWB module 24 measures the distance between the device 30 and the vehicle 20.
  • the NFC module 25 performs short-range communication with the device 30 via NFC communication.
  • the vehicle management device 26 is mounted on the vehicle 20.
  • the vehicle management device 26 manages the digital key of the vehicle 20.
  • the vehicle management device 26 is, for example, a vehicle control circuit having a digital key ECU.
  • the vehicle management device 26 has a vehicle execution device 27 and a vehicle storage device 28.
  • the vehicle storage device 28 has stored therein a vehicle program PV and an authentication information unit AT.
  • the authentication information unit AT is information for authenticating the digital key. Therefore, when the digital key is used, control of the vehicle 20 using the digital key is possible.
  • An authentication information unit AT is provided for each digital key to be authenticated.
  • the vehicle execution device 27 is a vehicle processing circuit having a CPU. When the vehicle execution device 27 executes the vehicle program PV, it performs processes related to the storage, deletion, and replacement of the authentication information unit AT.
  • Authenticating a digital key means allowing the vehicle 20 to be controlled by the digital key. For example, when the vehicle management device 26 authenticates the digital key, the vehicle management device 26 allows the vehicle 20 to be unlocked using the digital key. Also, for example, when the vehicle management device 26 authenticates the digital key, the vehicle management device 26 allows the vehicle 20 to be started using the digital key.
  • Device 30 is a mobile information terminal such as a smartphone.
  • Device 30 has a communication module 31, a device HMI_32, a BLE module 33, a UWB module 34, an NFC module 35, a device execution device 36, and a device storage device 37.
  • the communication module 31 communicates with the device server 60 via a wireless communication line.
  • the device HMI_32 includes an input device that accepts operations by the user of the device 30, and a presentation device that presents information to the user using images, audio, etc.
  • the presentation device is, for example, a monitor and speaker.
  • the BLE module 33 performs short-range communication with the vehicle 20 using BLE communication.
  • the UWB module 34 communicates with the vehicle 20 using UWB communication.
  • the NFC module 35 performs short-range communication with the vehicle 20 using NFC communication.
  • the device storage device 37 already stores the device program PD and key information DK.
  • the device program PD causes the device execution device 36 to execute various device processes, causing the device execution device 36 to store and delete key information DK.
  • the key information DK is information that indicates a digital key.
  • the device program PD includes, for example, a device application and a digital key framework.
  • the device application is an application for storing and deleting key information DK.
  • the digital key framework is a program that uses APIs provided by the OS to provide functions for pairing devices 30 and sharing digital keys.
  • the device execution unit 36 is a device processing circuit that executes the device program PD to perform processes related to the storage and deletion of key information DK.
  • the multiple devices 30 include an owner device 40 and multiple shared devices 50.
  • the owner device 40 has stored owner key information DKO indicating the owner key KO as key information DK. Only one owner key KO can be registered per vehicle 20. Therefore, only one owner key KO exists per vehicle 20.
  • the owner key information DKO has owner key structure information STO.
  • the owner key structure information STO includes vehicle identification information ST1, in-device key identification information ST2, digital key identification information ST3, and slot identification information ST4.
  • the owner key structure information STO further includes certificate information ST5, device public key information ST6, vehicle public key information ST7, and permission public key information ST8.
  • the vehicle identification information ST1 is information that identifies the vehicle 20 for which one or more digital keys are set.
  • the vehicle identification information ST1 is the ID of the vehicle 20.
  • the intra-device key identification information ST2 is used to manage the digital key within the device 30.
  • the intra-device key identification information ST2 is information that enables the digital key to be identified within the application of the device 30.
  • Digital key identification information ST3 is used to manage digital keys within the management server 70.
  • Slot identification information ST4 is information that allows the digital key to be identified locally on the device 30.
  • Certificate information ST5 indicates a certificate that certifies the digital key.
  • Device public key information ST6 indicates the device public key PKD, which is the public key of the device 30.
  • the device public key PKD in the owner key information DKO indicates the public key of the owner device 40.
  • Vehicle public key information ST7 indicates the vehicle public key PKV, which is the public key of the vehicle 20.
  • Authorization public key information ST8 indicates an already authorized vehicle public key PKV.
  • the share device 50 has stored share key information DKS indicating a share key KS as key information DK.
  • a share key KS is a digital key that can be registered multiple times for one vehicle 20 when registering a digital key to enable use of the digital key. In other words, multiple share keys KS can exist for one vehicle 20.
  • the multiple share devices 50 include one or more friend devices 51 and one or more non-friend devices 52.
  • the friend device 51 has stored friend key information DKF indicating the friend key KF as the share key information DKS.
  • the non-friend device 52 has stored non-friend key information DKN indicating the non-friend key KN as the share key information DKS.
  • the share keys KS include a friend key KF and a non-friend key KN.
  • the friend key KF is a share key KS that has been registered based on a registration request D21 directly from the owner device 40, as described below.
  • the registration request D21 requests the device 30 to store the friend key information DKF, which is key information DK.
  • the non-friend key KN is a share key KS that has been registered based on a registration request D31 from the friend device 51, as described below.
  • the registration request D31 is a request for the device 30 to store the non-friend key information DKN, which is key information DK.
  • the non-friend key KN is a shared key KS that is registered based on a registration request from a shared device 50, which is a device 30 different from the owner device 40.
  • a registration request from the shared device 50 is a so-called indirect registration request.
  • the digital key When a digital key is registered, the digital key is usable. In other words, when a digital key is registered, the vehicle 20 stores the authentication information unit AT, and the device 30 has stored the key information DK.
  • the authentication information unit AT is a digital key information unit, which is an information unit related to the digital key. In other words, when a digital key is registered, the vehicle 20 has stored the digital key information unit.
  • the key information DK is a digital key information unit. In other words, when a digital key is registered, the device 30 has stored the digital key information unit.
  • the shared key information DKS includes shared key structure information STS and an authentication package ATP.
  • the shared key structure information STS includes vehicle identification information ST1, in-device key identification information ST2, digital key identification information ST3, and slot identification information ST4.
  • the shared key structure information STS further includes certificate information ST5, vehicle public key information ST7, and permission public key information ST8.
  • the shared key structure information STS is the owner key structure information STO minus the device public key information ST6.
  • the authentication package ATP includes signature information ATP1, password information ATP2, validity start time information ATP3, expiration date information ATP4, name information ATP5, and device public key information ATP6.
  • the signature information ATP1 indicates that the shared device 50 is a legitimate party with whom the digital key is being shared. For example, if the shared device 50 is a friend device 51, the signature information ATP1 indicates a signature by the owner device 40. The owner signature information indicates that the owner device 40 has signed the device public key PKD of the friend device 51, which is indicated by the device public key information ATP6. For example, if the shared device 50 is a non-friend device 52, the signature information ATP1 indicates a signature by the friend device 51. The friend signature information indicates that the friend device 51 has signed the device public key PKD of the non-friend device 52, which is indicated by the device public key information ATP6.
  • Password information ATP2 indicates the pairing password PAS used to establish a secure channel when pairing the vehicle 20 and owner device 40.
  • Validity start time information ATP3 indicates the earliest date and time at which the share key KS can be used.
  • Expiration date information ATP4 indicates the latest date and time at which the share key KS can be used.
  • Name information ATP5 indicates a name that identifies the share key KS. For example, name information ATP5 is set as an identifiable name for each share device 50 by operation from the owner device 40.
  • the device server 60 relays communication between the devices 30 and the management server 70.
  • a device server 60 is provided for each type of device 30. That is, the device server 60 with which a first type of device 30 communicates is different from the device server 60 with which a second type of device 30 communicates.
  • the type of device 30 refers to the model of the device 30, and a device server 60 is provided for each model of device 30.
  • the type of device 30 refers to the communication line used by the device 30, and a device server 60 is provided for each communication line used by the device 30. Since all device servers 60 relay communication with the management server 70, devices 30 of different types can communicate with the management server 70 via the device server 60. Only one device server 60 is shown in FIG. 1.
  • the management server 70 is configured to be able to communicate with the vehicle 20 and multiple devices 30.
  • the management server 70 includes a server execution device 71, a server storage device 72, and a communication module 73.
  • the communication module 73 communicates with the device server 60 via a wireless communication line.
  • the communication module 73 is also configured to be able to wirelessly communicate with the communication module 21 of the vehicle 20.
  • the server storage device 72 stores a server program PS, a replacement program PM, and a database DB.
  • the server program PS causes the server execution device 71 to execute various server processes, causing the server execution device 71 to register a digital key in the database DB and delete a digital key from the database DB.
  • the replacement program PM causes the server execution device 71 to execute various server processes, causing the server execution device 71 to send a command to the vehicle storage device 28 to replace the authentication information unit AT.
  • the server execution device 71 executes the replacement program PM to perform processes related to the replacement of the authentication information unit AT.
  • the server execution device 71 includes a server processing circuit.
  • the database DB is divided into data blocks DA for each vehicle 20.
  • the management server 70 has already stored in the data block DA information indicating the device 30 that stores the key information DK indicating the digital key.
  • the data block DA for one vehicle 20 includes the type of digital key registered to the vehicle 20, the registered devices 30, and the relationships between the registered devices 30.
  • the hierarchy of digital keys is determined by the type of digital key. From top to bottom in the hierarchy of digital keys, the owner key KO, friend key KF, and non-friend key KN are arranged.
  • the authority of a digital key includes, for example, the number of share keys KS that can be requested to be registered, the range of control of the vehicle 20 that can be achieved by authenticating the digital key, etc.
  • the higher the hierarchy of the digital key the greater the authority of the digital key, so, for example, the greater the number of share keys KS that the digital key can request to be registered. More specifically, for example, the number of friend keys KF that the owner device 40 can request to be registered is greater than the number of non-friend keys KN that the friend device 51 can request to be registered.
  • the control range of the controllable vehicle 20 indicates, for example, the possible controls of (a) starting the engine of the vehicle 20, (b) turning on the power of the vehicle 20, and (c) unlocking and locking the doors of the vehicle 20.
  • the control range of the controllable vehicle 20 is the three controls described above, the control range of the controllable vehicle 20 is wider than if the control range of the controllable vehicle 20 is only one of (c) unlocking and locking the doors of the vehicle 20.
  • the control range of the vehicle 20 that the friend key KF can control is the three controls described above.
  • the control range of the vehicle 20 that the non-friend key KN can control is only one of (c) unlocking and locking the doors of the vehicle 20.
  • the seven devices 30 are a first device 30A, a second device 30B, a third device 30C, a fourth device 30D, a fifth device 30E, a sixth device 30F, and a seventh device 30G.
  • the digital key registered to the first device 30A is referred to as the first digital key.
  • the digital key registered to the second device 30B is referred to as the second digital key.
  • the digital key registered to the third device 30C is referred to as the third digital key.
  • the digital key registered to the fourth device 30D is referred to as the fourth digital key.
  • the digital key registered to the fifth device 30E is referred to as the fifth digital key.
  • the digital key registered to the sixth device 30F is referred to as the sixth digital key.
  • the digital key registered to the seventh device 30G is referred to as the seventh digital key.
  • the device 30 whose digital key type is registered as owner key KO is the first device 30A.
  • the first device 30A is the owner device 40.
  • the first digital key is the owner key KO.
  • the devices 30 whose digital key type is registered as a shared key KS are the second device 30B, the third device 30C, the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G.
  • the second device 30B, the third device 30C, the fourth device 30D, the fifth device 30E, the sixth device 30F, and the seventh device 30G are shared devices 50.
  • the second digital key, the third digital key, the fourth digital key, the fifth digital key, the sixth digital key, and the seventh digital key are all shared keys KS.
  • the devices 30 whose digital key type is registered as a friend key KF are the second device 30B and the fifth device 30E.
  • the second device 30B and the fifth device 30E are friend devices 51.
  • the devices 30 whose digital key type is registered as non-friend key KN are the third device 30C, the fourth device 30D, the sixth device 30F, and the seventh device 30G.
  • the third device 30C, the fourth device 30D, the sixth device 30F, and the seventh device 30G are non-friend devices 52.
  • the relationship between the second device 30B and the first device 30A is such that a friend key KF is registered in the second device 30B based on a registration request from the first device 30A.
  • the second digital key is generated based on the first digital key.
  • the relationship between the fifth device 30E and the first device 30A is such that a friend key KF is registered in the fifth device 30E based on a registration request from the first device 30A.
  • the fifth digital key is generated based on the first digital key.
  • the relationship between the third device 30C and the second device 30B is such that a non-friend key KN is registered in the third device 30C based on a registration request from the second device 30B.
  • the third digital key is generated based on the second digital key.
  • the relationship between the fourth device 30D and the second device 30B is such that a non-friend key KN is registered in the fourth device 30D based on a registration request from the second device 30B.
  • the fourth digital key is generated based on the second digital key.
  • the relationship between the sixth device 30F and the fifth device 30E is such that the non-friend key KN is registered in the sixth device 30F based on a registration request from the fifth device 30E.
  • the sixth digital key is generated based on the fifth digital key.
  • the relationship between the seventh device 30G and the fifth device 30E is such that the non-friend key KN is registered in the seventh device 30G based on a registration request from the fifth device 30E.
  • the seventh digital key is generated based on the fifth digital key.
  • the data block DA already stores the devices 30 that have been registered as digital keys. Furthermore, when a device 30 is registered, information indicating the device 30 that made the request that caused the registration is linked to the digital key. The data block DA also contains information indicating which digital key each digital key was generated based on.
  • the management system 10 registers digital keys by registering an owner key KO, a friend key KF, and a non-friend key KN.
  • the following describes the series of processes from when each digital key is not registered to when it is registered.
  • the processes executed by the vehicle execution unit 27 of the vehicle management device 26 will be described as processes executed by the vehicle 20.
  • the processes executed by the device execution unit 36 will be described as processes executed by the device 30.
  • the processes executed by the server execution unit 71 will be described as processes executed by the management server 70.
  • the management system 10 performs a series of processes to register the owner key KO.
  • the devices 30 that do not store the key information DK indicating the owner key KO the device 30 that will be registered as the owner device 40 is referred to as a first device 30A.
  • the management system 10 In order to register the owner key KO, the management system 10 stores key information DK indicating the owner key KO in the first device 30A. By registering the owner key KO, the management system 10 stores an authentication information unit AT for authenticating the owner key KO in the vehicle 20. This causes the first device 30A to become the owner device 40. When registering the owner key KO, it is assumed that the necessary applications are installed in the first device 30A.
  • the management server 70 When the management server 70 receives a registration request D11 for the owner key KO from the first device 30A or the like, the management server 70 first performs the process of step S11. In step S11, the management server 70 generates a pairing password PAS. Then, the management server 70 transmits information indicating the pairing password PAS to the vehicle 20 and the first device 30A.
  • the vehicle 20 receives the pairing password PAS.
  • the vehicle 20 is set to pairing mode via the vehicle HMI_22 and waits in a state where it can receive a password from the first device 30A. The vehicle 20 then proceeds to step S12.
  • step S12 the vehicle 20 performs pairing with the first device 30A. Once pairing is complete, the vehicle 20 establishes a secure channel for data communication with the first device 30A. Pairing is performed using a pairing password PAS transmitted from the management server 70 to the vehicle 20 and the first device 30A. Once pairing is complete, the vehicle 20 proceeds to step S13.
  • step S13 the vehicle 20 generates a vehicle public key PKV, which is the public key of the vehicle 20, and a vehicle private key SKV, which is the private key of the vehicle 20.
  • the vehicle 20 then transmits generated data DC for generating the owner key KO to the first device 30A via the secure channel.
  • the generated data DC includes vehicle identification information ST1 and vehicle public key information indicating the vehicle public key PKV.
  • the first device 30A then receives the generated data DC.
  • the first device 30A then proceeds to step S14.
  • step S14 the first device 30A generates owner key information DKO indicating the owner key KO.
  • step S15 the first device 30A stores the owner key information DKO.
  • the first device 30A becomes the owner device 40. That is, the registration request D11 is a request to store the owner key information DKO as key information DK in the device 30.
  • the first device 30A transmits, to the vehicle 20, certificate information ST5 related to the owner key KO and device public key information ST6 indicating the device public key PKD.
  • step S16 vehicle 20 verifies certificate information ST5. Once verification of certificate information ST5 is complete, vehicle 20 proceeds to step S17.
  • step S17 the vehicle 20 stores the device public key information ST6 indicating the device public key PKD as the authentication information unit AT.
  • the vehicle 20 then transmits a completion notification M11 to the first device 30A indicating that storage of the authentication information unit AT has been completed.
  • step S18 the first device 30A generates a key track request D12 for the owner key KO.
  • the key track request D12 is a signal that requests the management server 70 to update the database DB.
  • the first device 30A transmits the key track request D12 for the owner key KO to the management server 70 via the device server 60.
  • step S19 the management server 70 performs registration management of the owner key KO. Specifically, the management server 70 stores the first device 30A as the device 30 registered as the owner key KO in the data block DA of the vehicle 20 in the database DB. This marks the end of the series of processes in the management system 10 for registering the owner key KO.
  • the management system 10 performs a series of processes to register a friend key KF.
  • a device 30 that will be registered as a friend device 51 through the series of processes is referred to as a second device 30B.
  • step S21 the owner device 40 transmits a friend key KF registration request D21 to a relay server (not shown). The owner device 40 then proceeds to step S22.
  • step S22 the owner device 40 obtains invitation information IV1 for sharing the digital key from the relay server.
  • the invitation information IV1 is, for example, a URL link.
  • the URL link stores share information SH1 required to share the digital key.
  • the owner device 40 then transmits the invitation information IV1 to the second device 30B.
  • step S23 the second device 30B acquires the share information SH1 based on the invitation information IV1. Specifically, the second device 30B downloads the share information SH1 from the link source of the URL link.
  • the share information SH1 includes, for example, share key structure information STS, password information ATP2, validity start time information ATP3, expiration date information ATP4, and name information ATP5.
  • the validity start time information ATP3, expiration date information ATP4, and name information ATP5 are set by the owner device 40.
  • the second device 30B then proceeds to step S24.
  • the second device 30B In step S24, the second device 30B generates unsigned friend key information DKFN using the share information SH1.
  • the unsigned friend key information DKFN is friend key information DKF that does not include signature information ATP1.
  • the second device 30B generates each piece of information contained in the acquired share information SH1 as the unsigned friend key information DKFN.
  • the second device 30B then sends to the owner device 40 a completion notification M21 indicating that the generated unsigned friend key information DKFN has been uploaded to the URL link, and a signature request D22 requesting a signature.
  • the owner device 40 receives a completion notification M21 and a signature request D22 from the second device 30B. Upon receiving the completion notification M21, the owner device 40 acquires the unsigned friend key information DKFN. Upon receiving the signature request D22, the owner device 40 performs the process of step S25 by operating the owner device 40.
  • step S25 the owner device 40 generates signature information ATP1.
  • the owner device 40 causes the device HMI_32 to present the acquired unsigned friend key information DKFN, and accepts an operation indicating that the user of the owner device 40 agrees to the registration of the friend key KF.
  • the owner device 40 acquires a signature based on the consent operation. The owner device 40 then proceeds to step S26.
  • step S26 the owner device 40 adds the signature information ATP1 to the unsigned friend key information DKFN. As a result, the owner device 40 generates friend key information DKF. The owner device 40 then uploads the generated friend key information DKF to the URL link, which is the invitation information IV1. The owner device 40 sends a completion notification M22 to the second device 30B, indicating that the completed friend key information DKF has been uploaded to the URL link.
  • step S27 the second device 30B downloads and stores the friend key information DKF. As a result, the second device 30B becomes a friend device 51. The second device 30B then proceeds to the process of step S28.
  • step S28 the second device 30B generates a key track request D23 for the friend key KF.
  • the second device 30B transmits the friend key information DKF and the key track request D23 for the friend key KF to the management server 70.
  • step S29 the management server 70 performs registration management of the friend key KF.
  • the key track request D23 is a request to store a new authentication information unit AT in the vehicle 20.
  • the management server 70 verifies that the friend key KF that is the target of the key track request D23 is not listed on the rejection list.
  • the rejection list is a list that shows share keys KS that have friend keys KF and non-friend keys KN for which a deletion request has already been received. If the friend key KF is listed on the rejection list, the management server 70 sends a notification to the second device 30B that the key track request D23 cannot be fulfilled.
  • the management server 70 registers the friend key KF that has received the key track request D23 in the database DB.
  • the management server 70 stores the second device 30B as a device 30 registered as a friend device 51 in the data block DA of the vehicle 20 in the database DB.
  • the management server 70 references the acquired friend key information DKF and stores the relationship between the second device 30B and the owner device 40.
  • the management server 70 sends the authentication package ATP included in the friend key information DKF and a storage request D24 to the vehicle 20 to request storage of the authentication package ATP. That is, the management server 70 sends the device public key information ST6 indicating the device public key PKD of the friend device 51 to the vehicle 20. The management server 70 also notifies the vehicle 20 that the device public key PKD has been signed by the owner device 40.
  • step S30 the vehicle 20 stores the received authentication package ATP as an authentication information unit AT for authenticating the friend key KF.
  • the management server 70 transmits a key track completion notification M23 to the second device 30B. Thereafter, upon receiving the key track completion notification M23, the second device 30B performs the process of step S31.
  • the second device 30B presents information indicating the completion of the registration of the friend key KF on the device HMI_32. For example, the second device 30B displays an image indicating the completion of the registration of the friend key KF on the device HMI_32. This causes the management system 10 to end the series of processes for registering the friend key KF.
  • the management system 10 performs a series of processes to register a non-friend key KN.
  • a device 30 that will be registered as a non-friend device 52 through the series of processes is referred to as a third device 30C.
  • step S41 the friend device 51 transmits a registration request D31 of the non-friend key KN to a relay server (not shown). The friend device 51 then proceeds to the process of step S42.
  • step S42 the friend device 51 obtains invitation information IV2 for sharing the digital key from the relay server.
  • the invitation information IV2 is, for example, a URL link.
  • the URL link stores share information SH2 required to share the digital key.
  • the friend device 51 then transmits the invitation information IV2 to the third device 30C.
  • step S43 the third device 30C acquires the share information SH2 based on the invitation information IV2. Specifically, the second device 30B downloads the share information SH2 from the URL link.
  • the share information SH2 includes, for example, share key structure information STS, password information ATP2, validity start time information ATP3, expiration date information ATP4, and name information ATP5.
  • the validity start time information ATP3, expiration date information ATP4, and name information ATP5 are set by the friend device 51.
  • the third device 30C then proceeds to step S44.
  • step S44 the third device 30C generates unsigned non-friend key information DKNN using the share information SH2.
  • the unsigned non-friend key information DKNN is non-friend key information DKN that does not have signature information ATP1.
  • the third device 30C generates each piece of information contained in the acquired share information SH2 as the unsigned non-friend key information DKNN.
  • the third device 30C then sends to the friend device 51 a completion notification M31 indicating that the generated unsigned non-friend key information DKNN has been uploaded to the URL link, and a signature request D32 requesting a signature.
  • the friend device 51 receives a completion notification M31 and a signature request D32 from the third device 30C. Upon receiving the completion notification M31, the friend device 51 acquires the unsigned non-friend key information DKNN. Upon receiving the signature request D32, the friend device 51 performs the process of step S45 in response to the friend device 51 being operated.
  • step S45 the friend device 51 generates signature information ATP1.
  • the friend device 51 causes the device HMI_32 to present the acquired unsigned non-friend key information DKNN, and accepts an operation indicating that the user of the friend device 51 agrees to the generation of the non-friend key KN.
  • the friend device 51 acquires a signature based on the consent operation. The friend device 51 then proceeds to step S46.
  • step S46 the friend device 51 adds the signature information ATP1 to the unsigned non-friend key information DKNN. As a result, the friend device 51 generates the non-friend key information DKN. The friend device 51 then uploads the generated non-friend key information DKN to the URL link, which is the invitation information IV2. The friend device 51 sends a completion notification M32 to the third device 30C, indicating that the completed non-friend key information DKN has been uploaded to the URL link.
  • step S47 the third device 30C downloads and stores the non-friend key information DKN. As a result, the third device 30C becomes a non-friend device 52. The third device 30C then proceeds to the process of step S48.
  • step S48 the third device 30C generates a key track request D33 for the non-friend key KN.
  • the third device 30C transmits the non-friend key information DKN and the key track request D33 for the non-friend key KN to the management server 70.
  • step S49 the management server 70 performs registration management of the non-friend key KN.
  • the management server 70 verifies that the non-friend key KN that is the target of the key track request D33 is not listed on the rejection list. If the non-friend key KN is listed on the rejection list, the management server 70 sends a notification to the third device 30C that the key track request D33 cannot be fulfilled.
  • the management server 70 registers the non-friend key KN that is the subject of the key track request D33 in the database DB.
  • the management server 70 stores the third device 30C in the data block DA of the vehicle 20 in the database DB as a device 30 registered as a non-friend device 52.
  • the management server 70 references the acquired non-friend key information DKN to store the relationship between the third device 30C and the friend device 51.
  • the management server 70 stores the third device 30C as a device 30 having the non-friend key KN registered in response to the registration request D31 from the second device 30B.
  • the management server 70 sends the authentication package ATP included in the non-friend key information DKN and a storage request D34 to the vehicle 20 to request storage of the authentication package ATP. That is, the management server 70 sends the device public key information ST6 indicating the device public key PKD of the non-friend device 52 to the vehicle 20. The management server 70 also notifies the vehicle 20 that the device public key PKD has been signed by the friend device 51.
  • step S50 the vehicle 20 stores the received authentication package ATP. That is, the vehicle 20 stores the authentication package ATP as an authentication information unit AT for authenticating the non-friend key KN.
  • the management server 70 transmits a key track completion notification M33 to the second device 30B. Thereafter, upon receiving the key track completion notification M33, the second device 30B performs the process of step S51.
  • the third device 30C presents information indicating the completion of registration of the non-friend key KN to the device HMI_32. For example, the third device 30C displays an image indicating the completion of registration of the non-friend key KN on the device HMI_32. This causes the management system 10 to end the series of processes for registering the non-friend key KN.
  • the management system 10 performs a series of processes to delete the non-friend key KN based on the deletion reservation D41 from the friend device 51.
  • step S61 a deletion reservation D41 for the non-friend key KN is generated.
  • the deletion reservation D41 is a command for reserving the deletion of the non-friend key KN.
  • the deletion reservation D41 includes a signal requesting the deletion of the non-friend key KN, digital key identification information ST3 indicating the non-friend key KN, and information indicating the default condition RC.
  • the default condition RC is a condition required to start deleting the non-friend key KN after receiving the deletion reservation D41.
  • the default condition RC is determined in advance. For example, the default condition RC is that a predetermined fade-out period has elapsed since receiving the deletion reservation D41.
  • the friend device 51 transmits the deletion reservation D41 for the non-friend key KN to the management server 70.
  • step S62 the management server 70 generates a pending notification M41 in accordance with the deletion reservation D41.
  • the management server 70 sends the pending notification M41 to the friend device 51.
  • step S63 the friend device 51 presents to the device HMI_32 information indicating that the deletion of the non-friend key KN that is the target of the deletion reservation D41 is pending.
  • step S64 the management server 70 stores the state of the non-friend key KN that is the target of the deletion reservation D41 in the database DB as a fade-out state.
  • the fade-out state is a state in which the deletion reservation D41 has been received, but the execution of deletion is still pending.
  • the management server 70 then proceeds to processing step S65.
  • step S65 the management server 70 confirms that the default conditions RC are met. If the management server 70 confirms that the default conditions RC are met, the management server 70 proceeds to step S66.
  • step S66 the management server 70 generates a deletion request D42 to delete the non-friend key information DKN indicating the non-friend key KN that is the target of the deletion reservation D41.
  • the management server 70 sends the deletion request D42 to the non-friend device 52.
  • step S67 the non-friend device 52 deletes the non-friend key information DKN in accordance with the deletion request D42.
  • the non-friend device 52 sends a deletion completion notification M42 to the management server 70, indicating that the deletion in accordance with the deletion request D42 has been completed.
  • step S68 the management server 70 stores the history of the deletion of the non-friend key information DKN from the non-friend device 52. The management server 70 then proceeds to step S69.
  • step S69 the management server 70 generates a deletion request D43 for the authentication information unit AT.
  • the deletion request D43 for the authentication information unit AT indicates a request to delete the authentication information unit AT that was required when the non-friend key KN that is the subject of the deletion reservation D41 was authenticated.
  • the management server 70 transmits the deletion request D43 to the vehicle 20.
  • step S70 the vehicle 20 deletes the authentication information unit AT that was required when the non-friend key KN that is the subject of the deletion reservation D41 was authenticated in accordance with the deletion request D43. In other words, the vehicle 20 deletes the authentication package ATP of the non-friend key KN.
  • the vehicle 20 transmits a deletion completion notification M43 to the management server 70 indicating that the deletion of the authentication information unit AT in accordance with the deletion request D43 has been completed.
  • step S71 the management server 70 stores the deletion history of the authentication information unit AT that was required when authenticating the non-friend key KN that is to be deleted in the current series of deletion-related processes in the vehicle 20. The management server 70 then proceeds to the process of step S72.
  • step S72 the management server 70 updates the database DB. Specifically, the management server 70 deletes the non-friend device 52 that has the non-friend key KN to be deleted in this series of processes from the data block DA of the vehicle 20 in the database DB. The management server 70 then sends a deletion completion notification M44 to the friend device 51, indicating that the series of deletions of the non-friend key KN in accordance with the deletion reservation D41 have been completed.
  • step S73 the friend device 51 presents information indicating that the deletion of the non-friend key KN that is the subject of the deletion reservation D41 has been completed to the device HMI_32.
  • the friend device 51 displays an image indicating the completion of the deletion of the non-friend key KN on the device HMI_32.
  • the management system 10 ends the series of processes for the deletion of this non-friend key KN.
  • the management system 10 performs a series of processes to delete the non-friend key KN indicated by the non-friend key information DKN stored in the non-friend device 52 due to a deletion operation in the non-friend device 52 .
  • the non-friend device 52 When a predetermined operation requesting the deletion of the non-friend key KN is executed in the non-friend device 52, the non-friend device 52 first performs processing in step S81. In step S81, the non-friend device 52 deletes the non-friend key information DKN in accordance with the predetermined operation. Thereafter, the non-friend device 52 transmits a deletion completion notification M51 to the management server 70 indicating that the non-friend key information DKN has been deleted.
  • step S82 the management server 70 stores the history of the deletion of the non-friend key information DKN in the non-friend device 52.
  • the management server 70 then sends a deletion completion notification M52 to the friend device 51, indicating that the non-friend key information DKN has been deleted.
  • step S83 the friend device 51 presents information indicating that the deletion of the non-friend key information DKN of the non-friend device 52 has been completed to the device HMI_32.
  • the friend device 51 displays an image indicating that the deletion of the non-friend key KN has been completed on the device HMI_32.
  • step S84 the management server 70 generates a deletion request D51 to delete the authentication information unit AT that was required when authenticating the non-friend key information DKN that was completely deleted in step S81.
  • the management server 70 transmits the deletion request D51 to the vehicle 20.
  • step S85 vehicle 20, in accordance with deletion request D51, deletes the authentication information unit AT that was required when authenticating the non-friend key information DKN that has been completely deleted in step S81.
  • Vehicle 20 transmits a completion notification M53 to management server 70 indicating that deletion of authentication information unit AT in accordance with deletion request D51 has been completed.
  • step S86 the management server 70 stores the history of the deletion of the authentication information unit AT that was required when authenticating the non-friend key information DKN that has been completely deleted in step S81. The management server 70 then proceeds to the process of step S87.
  • step S87 the management server 70 updates the database DB. Specifically, the management server 70 deletes the non-friend device 52 having the non-friend key KN that is the target of deletion in this series of processes from the data block DA of the vehicle 20 in the database DB. This causes the management system 10 to end the series of processes for deleting the non-friend key KN.
  • the number of authentication information units AT that the vehicle storage device 28 is configured to be able to store is limited. In other words, there is an upper limit to the amount of authentication information that the vehicle storage device 28 can store.
  • the vehicle 20 performs the following process. In other words, the vehicle 20 stores the new authentication information unit AT in place of one of the one or more authentication information units AT already stored in the vehicle storage device 28.
  • the vehicle 20 performs the following process. That is, the vehicle 20 deletes one of the one or more authentication information units AT stored in the vehicle storage device 28. The vehicle 20 then stores the new authentication information unit AT that has been received in the vehicle storage device 28.
  • Figure 10 is an explanatory diagram showing the flow of a series of processes performed by the vehicle 20 in the management system 10 when a new authentication information unit AT is received when the number of one or more authentication information units AT stored in the vehicle memory device 28 has reached the specified number that can be stored.
  • the vehicle storage device 28 has already stored therein the vehicle program PV.
  • the vehicle execution device 27 executes the vehicle program PV stored in the vehicle storage device 28. This causes the vehicle 20 to execute a series of processes.
  • the third device 30C shown in FIG. 10 is one of one or more devices 30 that do not store non-friend key information DKN and is designated as a non-friend device 52 through this series of processes.
  • a friend device 51 (not shown) executes an operation to request registration of a non-friend key KN for the third device 30C
  • the management system 10 performs the series of processes shown in FIG. 7 to register the non-friend key KN.
  • Step S101 shown in FIG. 10 is similar to step S47 shown in FIG. 7.
  • the third device 30C performs processing step S102.
  • the processing step S102 shown in FIG. 10 is similar to step S48 shown in FIG. 7.
  • the third device 30C transmits non-friend key information DKN and a key track request D33 for the non-friend key KN to the management server 70.
  • step S103 similar to step S49 shown in FIG. 7, the management server 70 performs registration management of the non-friend key KN.
  • the management server 70 transmits to the vehicle 20 the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing the authentication package ATP.
  • the management server 70 transmits information about the digital key in a faded-out state to the vehicle 20. If there is a digital key stored in a faded-out state in the database DB for the vehicle 20, this means that the deletion reservation D41 remains unexecuted.
  • step S104 the vehicle 20 performs the process of step S104.
  • the vehicle 20 receives information about the digital key that is in a faded-out state.
  • step S104 the vehicle 20 selects an authentication information unit AT to be replaced by the authentication package ATP included in the non-friend key information DKN of the third device 30C from among one or more authentication information units AT stored in the vehicle storage device 28. That is, in step S104, the vehicle 20 selects an authentication information unit AT to be deleted from among one or more authentication information units AT stored in the vehicle storage device 28. The process by which the vehicle 20 selects the authentication information unit AT will be described later. Once the vehicle 20 selects the authentication information unit AT to be replaced by the authentication package ATP included in the non-friend key information DKN of the third device 30C, the vehicle 20 performs the process of step S105.
  • FIG. 11 is a flowchart showing the process performed by the vehicle 20 in step S104 to select the authentication information unit AT to be replaced by the authentication package ATP included in the non-friend key information DKN of the third device 30C.
  • the vehicle 20 performs this series of processes as the process of step S104.
  • step S200 determines whether a deletion reservation D41 remains. If the vehicle storage device 28 has stored authentication information units AT for one or more faded-out digital keys, the vehicle 20 determines that a deletion reservation D41 remains. If a deletion reservation D41 remains (step S200: YES), the vehicle 20 proceeds to step S210.
  • step S210 the vehicle 20 determines whether multiple deletion reservations D41 remain. If the vehicle storage device 28 has stored authentication information units AT for multiple digital keys in a fade-out state, the vehicle 20 determines that multiple deletion reservations D41 remain. If multiple deletion reservations D41 remain (step S210: YES), the vehicle 20 proceeds to step S220.
  • step S220 the vehicle 20 deletes all authentication information units AT for multiple digital keys in a faded-out state that are stored in the vehicle storage device 28. As a result, the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored.
  • the vehicle 20 then ends the series of processes shown in FIG. 11. After completing the series of processes shown in FIG. 11, the vehicle 20 performs the process of step S105 shown in FIG. 10.
  • step S210 If the vehicle storage device 28 has stored only one authentication information unit AT for the faded-out digital key, i.e., if there are not multiple remaining deletion reservations D41 (step S210: NO), the vehicle management device 26 proceeds to step S230.
  • step S230 the vehicle management device 26 selects the authentication information unit AT of the faded-out digital key as the authentication information unit AT to be deleted.
  • the vehicle 20 then ends the series of processes shown in FIG. 11. After completing the series of processes shown in FIG. 11, the vehicle 20 performs the process of step S105 shown in FIG. 10.
  • step S200 if there is no deletion reservation D41 remaining (step S200: NO), vehicle 20 proceeds to the process of step S240.
  • the vehicle management device 26 is configured to be able to select authentication information units AT to be protected from among one or more authentication information units AT stored in the vehicle storage device 28.
  • the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as the authentication information units to be protected via the vehicle HMI_22 of the vehicle 20.
  • the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as the authentication information units to be protected via the device HMI_32 of the owner device 40.
  • the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as the authentication information units to be protected via the device HMI_32 of the friend device 51.
  • the user of the vehicle 20 can select one or more authentication information units AT stored in the vehicle storage device 28 as the authentication information units to be protected via the device HMI_32 of the non-friend device 52.
  • step S240 the vehicle 20 determines whether or not there is an authentication information unit AT that has been selected as a protection target among one or more authentication information units AT stored in the vehicle storage device 28. If there is an authentication information unit AT that has been selected as a protection target (step S240: YES), the vehicle 20 proceeds to step S250. In step S250, the vehicle 20 decides to select an authentication information unit AT to be deleted from among the authentication information units AT that have not been selected as a protection target in subsequent processing. The vehicle 20 then proceeds to step S260. If there is no authentication information unit AT that has been selected as a protection target (step S240: NO), the vehicle 20 proceeds to step S260.
  • the vehicle management device 26 is configured to be able to set priorities for one or more authentication information units AT stored in the vehicle storage device 28.
  • the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the vehicle HMI_22 of the vehicle 20.
  • the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the device HMI_32 of the owner device 40.
  • the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the device HMI_32 of the friend device 51.
  • the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the vehicle storage device 28 via the device HMI_32 of the non-friend device 52.
  • step S260 the vehicle 20 determines whether priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28. If priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S260: YES), the vehicle 20 proceeds to step S270.
  • step S270 the vehicle 20 determines whether the vehicle storage device 28 has stored multiple authentication information units AT with different priorities. If the vehicle storage device 28 has stored multiple authentication information units AT with different priorities (step S270: YES), the vehicle 20 proceeds to step S280.
  • step S280 the vehicle 20 selects the authentication information unit AT to be deleted based on priority. For example, the vehicle 20 selects the authentication information unit AT with the lowest priority as the authentication information unit AT to be deleted. The vehicle 20 then ends the series of processes shown in FIG. 11. After completing the series of processes shown in FIG. 11, the vehicle 20 performs the process of step S105 shown in FIG. 10.
  • step S260 if priorities have not been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S260: NO), the vehicle 20 proceeds to step S290.
  • step S270 if the vehicle storage device 28 has not stored multiple authentication information units AT with different priorities (step S270: NO), the vehicle 20 proceeds to step S290.
  • step S290 the vehicle 20 determines whether the authentication information unit AT of the non-friend key KN has been stored in the vehicle storage device 28. If the authentication information unit AT of the non-friend key KN has been stored in the vehicle storage device 28 (step S290: YES), the vehicle 20 proceeds to step S300.
  • step S300 the vehicle management device 26 selects, from one or more authentication information units AT stored in the vehicle storage device 28, the authentication information unit AT corresponding to the non-friend key information DKN as the authentication information unit AT to be deleted.
  • the vehicle 20 then ends the series of processes shown in FIG. 11. After completing the series of processes shown in FIG. 11, the vehicle 20 performs the process of step S105 shown in FIG. 10.
  • step S290 if the vehicle storage device 28 does not store an authentication information unit AT for the non-friend key KN (step S290: NO), the vehicle 20 proceeds to step S310.
  • step S310 the vehicle 20 selects, from among one or more authentication information units AT stored in the vehicle storage device 28, the authentication information unit AT corresponding to the shared key information DKS with the oldest last usage date as the authentication information unit AT to be deleted. The vehicle 20 then ends the series of processes shown in FIG. 11. After completing the series of processes shown in FIG. 11, the vehicle 20 performs the process of step S105 shown in FIG. 10.
  • the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of one or more authentication information units AT already stored in the vehicle storage device 28. Specifically, the vehicle 20 deletes the authentication information unit AT selected in step S105 from the vehicle storage device 28. Thereafter, the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
  • step S220 the vehicle 20 deletes all authentication information units AT of multiple digital keys in a faded-out state that are stored in the vehicle storage device 28.
  • step S104 the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored.
  • step S105 if the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that can be stored, the vehicle 20 does not delete the authentication information units AT from the vehicle storage device 28 in step S105.
  • the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
  • step S106 the vehicle 20 generates a completion notification M61.
  • the completion notification M61 includes a signal indicating that the authentication package ATP included in the non-friend key information DKN of the third device 30C is the authentication information unit AT selected by the vehicle management device 26 in step S104 and has been stored in place of one or more authentication information units AT already stored in the vehicle storage device 28.
  • the vehicle management device 26 transmits the completion notification M61 to the management server 70.
  • the management server 70 When the management server 70 receives the completion notification M61, the management server 70 performs the process of step S107. In step S107, the management server 70 generates a completion notification M62.
  • the completion notification M62 includes information indicating that the vehicle storage device 28 has stored the authentication package ATP included in the non-friend key information DKN of the third device 30C as an authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
  • the management server 70 transmits the completion notification M62 to the third device 30C.
  • step S108 the non-friend device 52 presents to the device HMI_32 registration completion information indicating that registration of the non-friend key KN of the third device 30C to the vehicle 20 has been completed. Thereafter, the management system 10 ends the series of processes for replacing the current authentication information unit AT.
  • the vehicle management device 26 deletes any of the one or more authentication information units AT stored in the vehicle storage device 28 without user intervention.
  • the authentication information unit AT is a digital key information unit.
  • the vehicle management device 26 when a new authentication information unit AT is stored, the user of the vehicle 20 does not have to select which authentication information unit AT to delete from one or more authentication information units ATs already stored in the vehicle 20. In other words, the vehicle management device 26 is configured to reduce the burden on the user of the vehicle 20.
  • the deletion reservation D41 is a command to execute the deletion of the target information, that is, the authentication information unit AT.
  • the vehicle management device 26 receives a new authentication information unit AT, it deletes the authentication information unit AT that is the target of the unexecuted deletion reservation D41 from the vehicle storage device 28. The vehicle management device 26 then stores the new authentication information unit AT in the vehicle storage device 28.
  • the vehicle management device 26 selects, as the authentication information to be deleted, an authentication information unit AT for authenticating the digital key that is scheduled to be deleted.
  • the vehicle management device 26 is configured to be able to store a new authentication information unit AT while still storing authentication information units AT for authenticating digital keys that are not scheduled to be deleted.
  • (1-3) The following describes a case where the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored, and multiple deletion reservations D41 remain unexecuted.
  • the vehicle management device 26 receives a new authentication information unit AT, it deletes all authentication information units AT that are the subject of the remaining unexecuted deletion reservations D41.
  • the vehicle management device 26 then stores the new authentication information unit AT in the vehicle storage device 28. This allows the vehicle management device 26 to store the new authentication information unit AT that has been received, and also to secure storage capacity in the vehicle storage device 28 for storing another authentication information unit AT.
  • the vehicle management device 26 is configured to allow the user of the vehicle 20 to set priorities for one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 selects the authentication information unit AT to be deleted from the vehicle storage device 28 based on the set priorities. In this way, the vehicle management device 26 is configured to be able to select the authentication information unit AT to be deleted from the vehicle storage device 28, reflecting the intentions of the user who set the priorities.
  • the vehicle management device 26 is configured to be able to select an authentication information unit AT to be protected from one or more authentication information units AT already stored in the vehicle storage device 28. When the vehicle management device 26 receives a new authentication information unit AT, it deletes one or more authentication information units AT that have not been selected as protection targets.
  • the vehicle management device 26 is configured to be able to set two levels of priority for one or more authentication information units AT already stored in the vehicle storage device 28: authentication information units AT that are to be protected and authentication information units AT that are not to be protected.
  • the vehicle management device 26 can reflect the intentions of the user of the vehicle 20 by preventing the deletion of authentication information units ATs that have already been set as protection targets.
  • the multiple digital keys include a first digital key, a second digital key generated based on the first digital key, and a third digital key generated based on the second digital key.
  • the first digital key is the owner key KO.
  • the second digital key is the friend key KF.
  • the third digital key is the non-friend key KN.
  • the following describes a case where the vehicle storage device 28 stores an authentication information unit AT for authenticating the friend key KF, which is the second digital key, and an authentication information unit AT for authenticating the non-friend key KN, which is the third digital key, and the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the specified number that can be stored.
  • the vehicle management device 26 when the vehicle management device 26 receives a new authentication information unit AT, it deletes the authentication information unit AT corresponding to the non-friend key KN, which is the third digital key, from the one or more authentication information units AT stored in the vehicle storage device 28. This allows the vehicle management device 26 to protect the authentication information unit AT corresponding to the registered friend key KF based on the owner key KO. This makes it possible to reduce the frequency of situations where, for example, the authentication information unit AT corresponding to the friend key KF is replaced with a new authentication information unit AT, forcing the owner to re-register the friend key KF.
  • the management system 10 includes a vehicle management device 26 mounted on the vehicle 20 and a management server 70 that manages the digital key.
  • the vehicle 20 includes a vehicle storage device 28.
  • the management system 10 deletes one of the authentication information units stored in the vehicle storage device 28.
  • the management system 10 is configured to reduce the burden on the user of the vehicle 20.
  • the first embodiment described above can be modified as follows: The first embodiment described above and the following modifications of the first embodiment can be combined with each other to the extent that they are not technically inconsistent.
  • the vehicle 20 receives a new authentication information unit AT when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored.
  • the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 does not need to store the new authentication information unit AT in the vehicle storage device 28.
  • the vehicle 20 receives a new authentication information unit AT when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored.
  • the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 does not need to select the authentication information unit AT to be deleted.
  • the vehicle management device 26 may randomly delete one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 may also be configured so that one or more authentication information units AT stored in the vehicle storage device 28 cannot be selected as targets for protection.
  • the vehicle management device 26 only needs to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 may also be configured not to be able to set a priority order for the one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 is only required to be able to delete any of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 is not limited to deleting all of the one or more authentication information units AT that are the subject of an unexecuted deletion reservation D41.
  • the vehicle management device 26 only needs to delete any of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the vehicle management device 26 does not need to delete an authentication information unit AT that is the subject of an unexecuted deletion reservation D41.
  • the vehicle management device 26 may delete the authentication information unit AT corresponding to the friend key KF, which is the second digital key, from the authentication information unit AT corresponding to the friend key KF, which is the second digital key, and the authentication information unit AT corresponding to the non-friend key KN, which is the third digital key.
  • the vehicle management device 26 may be configured to be able to set a priority for an authentication information unit AT that is the subject of an unexecuted deletion reservation D41 stored in the vehicle storage device 28.
  • the vehicle management device 26 may be configured to set a lower priority for an authentication information unit AT with a shorter remaining fade-out period.
  • the vehicle management device 26 may be configured to set a lower priority for an authentication information unit AT with an earlier time that the authentication information unit AT entered the fade-out state.
  • the server execution device 71 of the management server 70 does not need to execute the replacement program PM.
  • the server storage device 72 of the management server 70 does not need to store the replacement program PM.
  • FIGS 7, 12, and 13 explain the vehicle management device 26 and management server 70 according to the second embodiment.
  • the second embodiment will be explained, focusing on the differences from the first embodiment.
  • the vehicle management device 26 receives a new authentication information unit AT when the number of one or more authentication information units AT already stored in the vehicle storage device 28 has reached the preset number that can be stored. At this time, the vehicle management device 26 in the second embodiment deletes one or more authentication information units AT already stored in the vehicle storage device 28 based on another registration request D31 from the device 30 that made the registration request D31 to store key information DK corresponding to the new authentication information unit AT in the device 30.
  • the vehicle management device 26 deletes the authentication information unit AT corresponding to the previous registration request D31 from the vehicle storage device 28.
  • Figure 12 is an explanatory diagram showing the flow of a series of processes performed by vehicle 20 in management system 10 when vehicle 20 receives a new authentication information unit AT when the number of one or more authentication information units AT stored in vehicle memory device 28 has reached the specified number that can be stored.
  • the second device 30B is a friend device 51 in which a friend key KF has been registered based on a registration request D21 from the owner device 40.
  • the fourth device 30D is a non-friend device 52 in which a non-friend key KN has been registered based on a registration request D31 from the second device 30B (friend device 51).
  • the third device 30C is a device 30 that does not store non-friend key information DKN and is designated as a non-friend device 52 by this series of processes.
  • the management system 10 When a request to register a non-friend key KN for the third device 30C is executed on the second device 30B, which is the friend device 51, the management system 10 performs the series of processes shown in Figure 7 to register the non-friend key KN for the third device 30C.
  • step S49 shown in FIG. 7 the management server 70 transmits to the vehicle 20 the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing the authentication package ATP. After that, when the vehicle 20 receives the authentication package ATP and the storage request D34, the vehicle 20 performs the process of step S104 shown in FIG. 12.
  • step S104 similarly to the first embodiment, the vehicle 20 selects an authentication package ATP included in the non-friend key information DKN of the third device 30C from one or more authentication information units AT stored in the vehicle storage device 28. Thereafter, the vehicle 20 performs the process of step S401.
  • step S401 if the vehicle 20 has already stored an authentication information unit AT based on another (i.e., past) registration request D31 from the second device 30B (friend device 51) that made the registration request D31 to store the authentication information unit AT in the third device 30C, the vehicle 20 selects the authentication information unit AT as the authentication information unit AT to be deleted.
  • the result of the selection made by the vehicle 20 in step S401 takes priority over the result of the selection made by the vehicle 20 in step S102.
  • the fourth device 30D is a non-friend device 52 in which a non-friend key KN has been registered based on a registration request D31 from the second device 30B (friend device 51).
  • the second device 30B (friend device 51) not only made a new registration request D31 to register a non-friend key KN in the third device 30C this time, but also made a registration request D31 in the past to register a non-friend key KN in the fourth device 30D.
  • the vehicle 20 deletes the authentication information unit AT corresponding to the non-friend key information DKN indicating the non-friend key KN of the fourth device 30D.
  • the vehicle 20 then stores the authentication package ATP included in the non-friend key information DKN of the third device 30C.
  • the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • the vehicle 20 when storing the authentication package ATP of the non-friend key information DKN of the third device 30C, stores the authentication package ATP of the non-friend key information DKN of the third device 30C in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • the vehicle 20 then performs the process of step S402.
  • the vehicle management device 26 generates a completion notification M71.
  • the completion notification M71 includes a signal indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • the completion notification M71 includes a signal for causing the management server 70 to transmit to the third device 30C a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C.
  • the completion notification M71 includes a signal for causing the management server 70 to transmit to the fourth device 30D (non-friend device 52), the second device 30B (friend device 51), and the owner device 40 a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C.
  • the vehicle management device 26 transmits the completion notification M71 to the management server 70.
  • the management server 70 executes the process of step S403.
  • the management server 70 generates a completion notification M72.
  • the completion notification M72 includes a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C.
  • the management server 70 transmits the completion notification M72 to the third device 30C.
  • the management server 70 executes processing step S404.
  • step S404 the management server 70 generates a replacement notification M73, a replacement notification M74, and a replacement notification M75.
  • the replacement notification M73, the replacement notification M74, and the replacement notification M75 each include a signal indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • the management server 70 transmits the replacement notification M73 to the fourth device 30D (non-friend device 52).
  • the management server 70 transmits the replacement notification M74 to the second device 30B (friend device 51).
  • the management server 70 transmits the replacement notification M75 to the owner device 40. Processing continues to FIG. 14.
  • step S405 the third device 30C presents to the device HMI_32 information indicating that registration of the non-friend key KN of the third device 30C in the vehicle 20 has been completed.
  • step S406 the fourth device 30D presents to the device HMI_32 information indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in the vehicle storage device 28 instead of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • step S407 the second device 30B presents to the device HMI_32 information indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in the vehicle storage device 28 instead of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • step S408 the owner device 40 presents to the device HMI_32 information indicating that the authentication information unit AT of the non-friend key KN of the third device 30C has been stored in the vehicle storage device 28 in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • the management system 10 then terminates the series of processes for replacing the authentication information unit AT this time.
  • the vehicle management device 26 When the vehicle management device 26 has already received the authentication information unit AT corresponding to the key information DK of the third device 30C, the vehicle management device 26 deletes the authentication information unit AT corresponding to the key information DK of the third device 30C that has been stored in the vehicle storage device 28 based on another registration request D31 from the second device 30B (friend device 51) that made the registration request D31 corresponding to the authentication information unit AT that corresponds to the key information DK of the third device 30C. In other words, the vehicle management device 26 deletes from the vehicle storage device 28 the authentication information unit AT that corresponds to the previous registration request D31 from the second device 30B (friend device 51) that made the current registration request D31.
  • one or more authentication information units AT that have been stored in the vehicle storage device 28 based on a registration request D31 from a device other than the second device 30B (friend device 51) and one or more authentication information units AT that have been stored in the vehicle storage device 28 based on a registration request D21 from the owner device 40 are not deleted.
  • the vehicle management device 26 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D31 from a device other than the second device 30B (friend device 51) from being deleted due to the registration request D31 from the second device 30B (friend device 51).
  • the vehicle management device 26 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D21 from the owner device 40 from being deleted due to the registration request D31 from the second device 30B (friend device 51).
  • the second embodiment can be modified as follows: The second embodiment can be combined with the following modifications to the second embodiment as long as they are not technically inconsistent.
  • the vehicle management device 26 deletes one or more authentication information units AT already stored in the vehicle storage device 28 based on another (i.e., past) registration request D31 from the device 30 that made the registration request D31 corresponding to the new authentication information unit AT.
  • the vehicle management device 26 does not need to generate a signal indicating that the vehicle storage device 28 has stored the authentication information unit AT of the non-friend key KN of the third device 30C.
  • the vehicle management device 26 does not need to generate a signal indicating that the authentication package ATP included in the non-friend key information DKN of the third device 30C has been stored in place of the authentication information unit AT of the non-friend key KN of the fourth device 30D.
  • the vehicle management device 26 may delete one or more authentication information units AT stored in the vehicle storage device 28 based on another registration request D21 from the owner device 40 that has made a registration request D21 corresponding to a new authentication information unit AT.
  • one or more authentication information units AT stored in the vehicle storage device 28 based on a previous registration request D21 from the owner device 40 are deleted when the owner device 40 makes a new registration request D21.
  • FIGS 1, 7, 14, and 15 explain the vehicle management device 26 and management server 70 according to the third embodiment.
  • the following describes a case where the management server 70 receives a request to store a new authentication information unit AT for a vehicle 20 when the number of one or more authentication information units AT already stored in the database DB for the vehicle 20 has reached the preset number that can be stored.
  • the management server 70 of the third embodiment transmits to the vehicle 20 a command to store the new authentication information unit AT in place of one of the one or more authentication information units AT already stored in the vehicle storage device 28.
  • the management server 70 when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored, and the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20, the management server 70 deletes one of the one or more authentication information units AT stored in the vehicle storage device 28. The management server 70 then stores the received authentication information unit AT in the vehicle storage device 28.
  • Figure 14 is an explanatory diagram showing the flow of a series of processes performed by the management server 70 in the management system 10 when the number of one or more authentication information units AT stored in the vehicle memory device 28 has reached the specified number that can be stored and the management server 70 receives a new authentication information unit AT for the vehicle 20.
  • the server storage device 72 already stores the replacement program PM.
  • the server execution device 71 executes the replacement program PM stored in the server storage device 72. This causes the management server 70 to execute a series of processes.
  • the third device 30C shown in FIG. 14 is a device 30 that does not store non-friend key information DKN and is designated as a non-friend device 52 through this series of processes.
  • a friend device 51 (not shown) executes an operation to request registration of a non-friend key KN for the third device 30C
  • the management system 10 performs the series of processes shown in FIG. 7 to register the non-friend key KN for the third device 30C.
  • Step S501 shown in FIG. 14 is similar to step S47 shown in FIG. 7.
  • the third device 30C performs processing step S502.
  • the processing step S502 shown in FIG. 14 is similar to step S48 shown in FIG. 7.
  • the third device 30C transmits non-friend key information DKN and a key track request D33 for the non-friend key KN to the management server 70.
  • the key track request D33 is a request to store a new authentication information unit AT in the vehicle 20.
  • step S503 the management server 70 performs registration management of the non-friend key KN. Specifically, the management server 70 checks whether the non-friend key KN, which is the target of the key track request D33, is listed on the rejection list. If the non-friend key KN is listed on the rejection list, the management server 70 sends a notification to the third device 30C that the key track request D33 cannot be fulfilled.
  • the management server 70 registers the non-friend key KN that is the subject of the key track request D33 in the database DB. Specifically, the management server 70 stores the third device 30C in the data block DA of the vehicle 20 in the database DB as a device 30 registered as a non-friend device 52. The management server 70 references the acquired non-friend key information DKN to store the relationship between the third device 30C and the friend device 51. Specifically, the management server 70 stores the third device 30C as a device 30 that has the non-friend key KN registered in response to the registration request D31 from the second device 30B (friend device 51). The management server 70 then performs the process of step S504.
  • the management server 70 has stored, as data blocks DA of the vehicle 20 in the database DB, the number of one or more authentication information units AT stored in the vehicle storage device 28 and the number of authentication information units AT that the vehicle storage device 28 can store.
  • the management server 70 is configured to be able to determine whether the number of one or more authentication information units AT stored in the vehicle 20 has reached the predetermined number that the vehicle 20 can store.
  • the management server 70 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that the vehicle 20 can store.
  • the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that the vehicle storage device 28 can store, the management server 70 sends the authentication package ATP and a storage request D34 for storing the authentication package ATP to the vehicle 20.
  • the management system 10 then performs the processes from step S50 onwards shown in FIG. 7.
  • the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that the vehicle storage device 28 can store, the management server 70 performs the process of step S505.
  • step S505 the management server 70 selects an authentication information unit AT to be deleted from one or more authentication information units AT already stored in the vehicle storage device 28.
  • FIG. 15 is a flowchart showing the process performed by the management server 70 in step S505 to select an authentication information unit AT to be deleted.
  • the management server 70 performs this series of processes as the process of step S505.
  • step S510 the management server 70 determines whether any pending deletion reservations D41 remain.
  • the management server 70 determines that any pending deletion reservations D41 remain if authentication information units AT for one or more faded-out digital keys have been stored in the vehicle storage device 28. If any pending deletion reservations D41 remain (step S510: YES), the management server 70 proceeds to step S511.
  • step S511 the management server 70 determines whether multiple deletion reservations D41 remain unexecuted. If authentication information units AT for multiple digital keys in a fade-out state have been stored in the vehicle storage device 28, the management server 70 determines that multiple deletion reservations D41 remain unexecuted. If multiple deletion reservations D41 remain unexecuted (step S511: YES), the management server 70 proceeds to step S512.
  • step S512 the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT of multiple digital keys in a faded-out state that have been stored in the vehicle storage device 28. That is, the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT that are the subject of unexecuted deletion reservations D41 from the vehicle storage device 28. The management server 70 then transmits the signal to the vehicle 20. The management server 70 then terminates the series of processes shown in FIG. 15. In accordance with the signal, the vehicle 20 deletes all authentication information units AT of multiple digital keys in a faded-out state that have been stored in the vehicle storage device 28. As a result, the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored.
  • the management server 70 transmits the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing this authentication package ATP to the vehicle 20.
  • the management server 70 transmits a key track completion notification M33 to the third device 30C.
  • the vehicle 20, which has received the authentication package ATP included in the non-friend key information DKN and the storage request D34 for storing the authentication package ATP performs the process of step S50 shown in FIG. 7.
  • the third device 30C which has received the key track completion notification M33, performs the process of step S51 shown in FIG. 7. This marks the end of the series of processes for the management system 10.
  • step S511 NO
  • the management server 70 proceeds to step S513.
  • step S513 the management server 70 selects the authentication information unit AT of the faded-out digital key as the authentication information unit AT to be deleted. The management server 70 then terminates the series of processes shown in FIG. 15.
  • the management server 70 is configured to be able to select one or more authentication information units AT stored in the database DB as targets for protection.
  • the user of the vehicle 20 is configured to be able to select, via the device HMI_32 of the owner device 40, each of one or more authentication information units AT stored in the database DB as targets for protection.
  • the user of the vehicle 20 can select, via the device HMI_32 of the friend device 51, each of one or more authentication information units AT stored in the database DB as targets for protection.
  • the user of the vehicle 20 can select, via the device HMI_32 of the non-friend device 52, each of one or more authentication information units AT stored in the database DB as targets for protection.
  • step S514 the management server 70 determines whether or not there is an authentication information unit AT that has been selected as a target for protection among one or more authentication information units AT stored in the vehicle storage device 28. If there is an authentication information unit AT that has been selected as a target for protection (step S514: YES), the management server 70 selects an authentication information unit AT to be deleted from among the authentication information units AT that are not a target for protection in subsequent processing. The management server 70 then proceeds to step S516. If there is not an authentication information unit AT that has been selected as a target for protection among one or more authentication information units AT stored in the vehicle storage device 28 (step S514: NO), the management server 70 proceeds to step S516.
  • the management server 70 is configured to be able to set priorities for one or more authentication information units AT stored in the database DB.
  • the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the database DB via the device HMI_32 of the owner device 40.
  • the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the database DB via the device HMI_32 of the friend device 51.
  • the user of the vehicle 20 can set priorities for one or more authentication information units AT stored in the database DB via the device HMI_32 of the non-friend device 52.
  • step S5166 the management server 70 determines whether priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28. If priorities have been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S516: YES), the management server 70 proceeds to step S517.
  • step S517 the management server 70 determines whether the vehicle storage device 28 has stored multiple authentication information units AT with different priorities. If the vehicle storage device 28 has stored multiple authentication information units AT with different priorities (step S517: YES), the management server 70 proceeds to step S518.
  • step S5128 the management server 70 selects the authentication information unit AT to be deleted based on priority. For example, the management server 70 selects the authentication information unit AT with the lowest priority as the authentication information unit AT to be deleted. The management server 70 then terminates the series of processes shown in FIG. 15.
  • step S516 if no priority has been set for one or more authentication information units AT stored in the vehicle storage device 28 (step S516: NO), the management server 70 proceeds to step S519.
  • step S517 if the vehicle storage device 28 does not store multiple authentication information units AT with different priorities (step S517: NO), the management server 70 proceeds to step S519.
  • step S519 the management server 70 determines whether the authentication information unit AT of the non-friend key KN has been stored in the vehicle storage device 28. If the authentication information unit AT of the non-friend key KN has been stored in the vehicle storage device 28 (step S519: YES), the management server 70 proceeds to step S520.
  • step S520 the management server 70 selects the authentication information unit AT of the non-friend key KN from among one or more authentication information units AT stored in the vehicle storage device 28 as the authentication information unit AT to be deleted. The management server 70 then terminates the series of processes shown in FIG. 15.
  • step S519 if the vehicle storage device 28 does not store an authentication information unit AT for the non-friend key KN (step S519: NO), the management server 70 proceeds to step S521.
  • step S521 the management server 70 selects, from among one or more authentication information units AT stored in the vehicle storage device 28, the authentication information unit AT for the shared key KS with the oldest last usage date as the authentication information unit AT to be deleted. The management server 70 then terminates the series of processes shown in FIG. 15.
  • the management server 70 transmits the authentication package ATP and a replacement request D81 to the vehicle 20.
  • the replacement request D81 is a request for the management server 70 to store the authentication package ATP in place of the authentication information unit AT selected by the management server 70 in step S505.
  • the replacement request D81 includes an instruction for the vehicle 20 to delete the authentication information unit AT selected by the management server 70 in step S505 from the vehicle storage device 28, and an instruction for the vehicle 20 to store the authentication package ATP as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
  • step S506 the vehicle 20 stores the authentication package ATP in place of one or more authentication information units AT already stored in the vehicle storage device 28. Specifically, the management server 70 deletes the authentication information unit AT selected by the management server 70 in step S505 from the vehicle storage device 28. The vehicle 20 then stores the authentication package ATP as the authentication information unit AT for authenticating the non-friend key KN of the third device 30C.
  • step S507 the management server 70 generates a completion notification M81.
  • the completion notification M81 includes a signal indicating that the vehicle 20 has stored the authentication package ATP in place of one or more authentication information units AT already stored in the vehicle storage device 28.
  • the management server 70 transmits the completion notification M81 to the third device 30C.
  • step S508 the third device 30C presents registration completion information indicating that the registration of the non-friend key KN has been completed to the device HMI_32. Thereafter, the management system 10 ends the series of processes for replacing the current authentication information unit AT.
  • the management server 70 transmits a command to delete any of the one or more authentication information units AT stored in the vehicle storage device 28 without user intervention.
  • the authentication information unit AT is a unit for handling information related to the digital key.
  • the management server 70 when a new authentication information unit AT is stored in the vehicle 20, the user of the vehicle 20 does not have to select which authentication information unit AT to delete from one or more authentication information units ATs already stored in the vehicle 20. In other words, the management server 70 is configured to reduce the burden on the user of the vehicle 20.
  • the management server 70 is configured to receive a deletion reservation D41.
  • the deletion reservation D41 is a command to cause the vehicle 20 to execute the deletion of the target information, that is, the authentication information unit AT, when the predetermined condition RC is met.
  • the management server 70 has already stored whether or not any deletion reservations D41 remain unexecuted in the database DB for the vehicle 20.
  • the following describes a case where the management server 70 receives a storage request for a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the predetermined number that can be stored. In other words, the deletion reservation D41 remains unexecuted in the database DB for the vehicle 20.
  • the management server 70 sends a command to the vehicle 20 to delete one or more of the one or more authentication information units AT that are the target of the unexecuted deletion reservation D41.
  • the management server 70 stores the new authentication information unit AT in the vehicle 20 by replacing one or more authentication information units AT that are the subject of an unexecuted deletion reservation D41 with the new authentication information unit AT.
  • the management server 70 selects the authentication information unit AT that is scheduled to be deleted as the authentication information to be replaced by the new authentication information unit AT.
  • the management server 70 can store the new authentication information unit AT while still storing the authentication information units AT that are not scheduled to be deleted.
  • the management server 70 receives a storage request for a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. Multiple deletion reservations D41 remain unexecuted in the vehicle 20.
  • the management server 70 transmits the authentication information unit AT and the following command to the vehicle 20.
  • this command is a command to delete all of the multiple authentication information units AT that are the subject of the deletion reservations D41, thereby storing a new authentication information unit AT corresponding to the storage request.
  • the management server 70 causes the vehicle 20 to delete all of the multiple authentication information units AT that are the subject of the deletion reservations D41.
  • the management server 70 causes the vehicle 20 to store the new authentication information unit AT and also causes the vehicle 20 to secure storage capacity for storing the authentication information unit AT.
  • the management server 70 is configured to allow the user of the vehicle 20 to set priorities for one or more authentication information units AT stored in the vehicle 20.
  • the management server 70 receives a request to register a new authentication information unit AT for a vehicle 20 for which the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the preset number that can be stored, the management server 70 selects the authentication information unit AT to be deleted based on the set priorities.
  • the management server 70 sends a command to the vehicle 20 to delete the authentication information unit AT that the management server 70 has selected.
  • the management server 70 selects the authentication information unit AT to be deleted in accordance with the priorities that have already been stored.
  • the management server 70 is configured to allow the selection of the authentication information unit AT to be deleted to reflect the intentions of the user who set the priorities.
  • the management server 70 is configured to be able to select an authentication information unit AT to be set as a protection target by the user of the vehicle 20 from among one or more authentication information units AT stored in the vehicle 20.
  • the management server 70 transmits to the vehicle 20 a command to delete one or more authentication information units AT that have not been selected as a protection target.
  • the management server 70 is configured to be able to set two levels of priority for one or more authentication information units AT stored in the vehicle 20: authentication information units AT that are set as a protection target and authentication information units AT that are not a protection target.
  • the management server 70 can reflect the user's intentions by preventing the deletion of authentication information units ATs that have been set as a protection target.
  • the vehicle storage device 28 has already stored an authentication information unit AT for authenticating the friend key KF and an authentication information unit AT for authenticating the non-friend key KN.
  • the management server 70 sends to the vehicle 20 a command to delete the authentication information unit AT that was required to authenticate the non-friend key KN.
  • the management server 70 is configured to be able to protect the authentication information unit AT for authenticating the friend key KF registered by the owner of the vehicle 20. This makes it possible to reduce the frequency of situations where, for example, the authentication information unit AT required to authenticate the friend key KF is deleted, forcing the owner to re-register the friend key KF.
  • the third embodiment is configured to be able to be implemented with the following modifications:
  • the third embodiment and the following modifications are configured to be able to be implemented in combination with each other within a range that does not cause technical contradictions.
  • the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 may cause the vehicle 20 to delete any of the one or more authentication information units AT stored in the vehicle 20. The management server 70 does not have to select the authentication information unit AT to be deleted from the one or more authentication information units AT stored in the vehicle 20. For example, the management server 70 may send a command to the vehicle 20 to randomly delete any of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the management server 70 receives a request to store a new authentication information unit AT for a vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 only needs to be able to send to the vehicle 20 a command to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The management server 70 does not need to be able to select an authentication information unit AT as a target for protection.
  • the management server 70 receives a request to store a new authentication information unit AT for a vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 only needs to be able to send to the vehicle 20 a command to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The management server 70 does not need to be able to set priorities for the authentication information units AT.
  • the management server 70 receives a request to store a new authentication information unit AT for a vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 only needs to send to the vehicle 20 a command to delete any of the one or more authentication information units AT stored in the vehicle storage device 28. The management server 70 does not need to cause the vehicle 20 to delete one or more authentication information units AT that are the subject of an unexecuted deletion reservation D41.
  • the management server 70 receives a request to store a new authentication information unit AT for a vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored. At this time, the management server 70 may cause the vehicle 20 to delete authentication information units AT other than the one or more authentication information units AT that are the subject of an unexecuted deletion reservation D41.
  • the management server 70 receives a request to store a new authentication information unit AT for a vehicle 20 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the preset number that can be stored.
  • the vehicle storage device 28 already stores an authentication information unit AT for authenticating the friend key KF and an authentication information unit AT for authenticating the non-friend key KN.
  • the management server 70 may cause the vehicle 20 to delete an authentication information unit AT that was required when authenticating the friend key KF from among the one or more authentication information units AT stored in the vehicle storage device 28.
  • the management server 70 may be configured to be able to set priorities for multiple authentication information units AT that are the subject of unexecuted deletion reservations D41 stored in the database DB for the vehicle 20. For example, the management server 70 may be configured to set a lower priority for an authentication information unit AT with a shorter remaining fade-out period. For example, the management server 70 may be configured to set a lower priority for an authentication information unit AT that entered the fade-out state earlier.
  • FIG. 7 and 14 to 17 illustrate a vehicle management device 26 and a management server 70 according to a fourth embodiment.
  • the fourth embodiment will be explained mainly focusing on the differences from the third embodiment.
  • the following describes a case where the management server 70 receives a storage request for a new authentication information unit AT for the vehicle 20 when the number of one or more authentication information units AT already stored in the database DB for the vehicle 20 has reached the preset number that can be stored.
  • the management server 70 transmits to the vehicle 20 a command to delete one or more authentication information units AT already stored in the vehicle storage device 28 based on another registration request D31 from the device 30 that has made the registration request D31 for storing the new authentication information unit AT and key information DK corresponding to the new authentication information unit AT in the device 30.
  • the management server 70 deletes the authentication information unit AT corresponding to the previous registration request D31 from the vehicle storage device 28.
  • Figure 16 is an explanatory diagram showing the flow of a series of processes performed by the management server 70 in the management system 10 when the number of one or more authentication information units AT stored in the database DB for the vehicle 20 has reached the specified number that can be stored and the management server 70 receives a request to store a new authentication information unit AT for the vehicle 20.
  • the second device 30B is a friend device 51 in which a friend key KF has been registered based on a registration request D21 from the owner device 40.
  • the second device 30B (friend device 51) has already stored friend key information DKF.
  • the fourth device 30D is a non-friend device 52 in which a non-friend key KN has been registered based on a registration request D31 from the second device 30B, which is the friend device 51.
  • the fourth device 30D (non-friend device 52) has already stored non-friend key information DKN.
  • the third device 30C is a device 30 that does not store non-friend key information DKN and that will be newly designated as a non-friend device 52 through this series of processes.
  • the management system 10 When the second device 30B, which is the friend device 51, executes an operation to request registration of a non-friend key KN for the third device 30C, the management system 10 performs the series of processes shown in Figure 7 to register the non-friend key KN.
  • step S48 shown in FIG. 7 the third device 30C generates a key track request D33 for the non-friend key KN.
  • the third device 30C transmits the non-friend key information DKN and the key track request D33 for the non-friend key KN to the management server 70.
  • the management server 70 When the management server 70 receives a key track request D33 for a non-friend key KN, the management server 70 performs the process of step S503 shown in FIG. 14. The process performed by the management server 70 in step S503 is the same as in the third embodiment. Thereafter, the management server 70 performs the process of step S504 shown in FIG. 16. The process performed by the management server 70 in step S504 is the same as in the third embodiment.
  • the management server 70 has stored, as data blocks DA of the vehicle 20 in the database DB, the number of one or more authentication information units AT stored in the vehicle storage device 28 and the number of authentication information units AT that the vehicle storage device 28 can store. In step S504, the management server 70 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
  • the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that the vehicle storage device 28 can store. In this case, the management server 70 sends to the vehicle 20 the authentication package ATP included in the non-friend key information DKN of the third device 30C and a storage request D34 for storing the authentication package ATP. The management system 10 then performs the processes from step S50 onwards shown in Figure 7.
  • the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that the vehicle storage device 28 can store. In this case, the management server 70 performs the processing from step S601 onwards shown in Figure 16.
  • step S601 the management server 70 selects an authentication information unit AT to be replaced by the authentication package ATP from one or more authentication information units AT stored in the vehicle storage device 28.
  • FIG. 15 is a flowchart showing the process performed by the management server 70 in step S601 to select an authentication information unit AT to be replaced by the authentication package ATP.
  • the management server 70 performs the series of processes shown in FIG. 15 as the process of step S601, similar to step S505 in the third embodiment.
  • the management server 70 determines whether the vehicle storage device 28 has stored an authentication information unit AT based on another registration request D31 by the second device 30B (friend device 51), which made the registration request D31 to store key information DK in the third device 30C. In other words, the management server 70 determines whether the vehicle storage device 28 has stored an authentication information unit AT corresponding to a past registration request D31 by the second device 30B (friend device 51), which made the current registration request D31. If the vehicle storage device 28 has stored an authentication information unit AT corresponding to a different (past) registration request D31, the management server 70 selects the authentication information unit AT as the authentication information unit AT to be deleted. The result of this selection takes precedence over the result of the selection by the series of processes shown in FIG. 15.
  • the fourth device 30D is a non-friend device 52 in which non-friend key information DKN indicating the non-friend key KN has been stored based on a registration request D31 from the second device 30B (friend device 51).
  • the vehicle storage device 28 has stored an authentication information unit AT corresponding to the non-friend key information DKN stored in the fourth device 30D (non-friend device 52).
  • the management server 70 selects the authentication information unit AT corresponding to the non-friend key information DKN stored in the fourth device 30D (non-friend device 52) as the authentication information unit AT to be replaced.
  • the management server 70 transmits the authentication package ATP and a replacement request D91 to the vehicle 20.
  • the replacement request D91 is a command to store the authentication package ATP in place of the authentication information unit AT corresponding to the non-friend key information DKN already stored in the fourth device 30D (non-friend device 52).
  • the replacement request D91 includes a command to delete the authentication information unit AT corresponding to the non-friend key information DKN already stored in the fourth device 30D (non-friend device 52).
  • the replacement request D91 includes a command to store the authentication package ATP included in the non-friend key information DKN of the third device 30C.
  • step S602. the vehicle 20 deletes the authentication information unit AT corresponding to the non-friend key information DKN already stored in the fourth device 30D (non-friend device 52).
  • the vehicle 20 then stores the authentication package ATP included in the non-friend key information DKN of the third device 30C.
  • the vehicle 20 stores the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of the authentication information unit AT corresponding to the non-friend key information DKN already stored in the fourth device 30D (non-friend device 52).
  • step S603 the management server 70 executes the process of step S603.
  • step S603 the management server 70 generates a completion notification M92.
  • the completion notification M92 includes a signal indicating that the authentication information unit AT included in the non-friend key information DKN of the third device 30C has been stored in the vehicle storage device 28.
  • the management server 70 transmits the completion notification M92 to the third device 30C.
  • the management server 70 executes processing step S604.
  • the management server 70 generates a replacement notification M93, a replacement notification M94, and a replacement notification M95.
  • the replacement notification M93, the replacement notification M94, and the replacement notification M95 each include a signal indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced by the authentication package ATP included in the key information DK of the third device 30C.
  • the management server 70 sends the replacement notification M93 to the fourth device 30D (non-friend device 52).
  • the management server 70 sends the replacement notification M94 to the second device 30B (friend device 51).
  • the management server 70 sends the replacement notification M95 to the owner device 40. Processing then continues to FIG. 17.
  • step S605 the third device 30C presents to the device HMI_32 a registration completion message indicating that the authentication package ATP included in the key information DK of the third device 30C has been registered in the vehicle 20 as an authentication information unit AT.
  • step S606 the fourth device 30D (non-friend device 52) presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced by the authentication package ATP included in the key information DK of the third device 30C.
  • step S607 the second device 30B (friend device 51) presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced with the authentication package ATP included in the key information DK of the third device 30C.
  • step S608 the owner device 40 presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the key information DK of the fourth device 30D (non-friend device 52) has been replaced with the authentication package ATP included in the key information DK of the third device 30C.
  • the management system 10 then terminates the series of processes for replacing the authentication information unit AT.
  • the management server 70 transmits to the vehicle 20 a command to delete one or more authentication information units AT stored in the vehicle storage device 28 based on another (i.e., past) registration request D31 by the second device 30B (friend device 51) that made the registration request D31 corresponding to the new authentication information unit AT. That is, the one or more authentication information units AT stored in the vehicle storage device 28 based on the past registration request D31 by the second device 30B (friend device 51) that made the registration request D31 corresponding to the new authentication information unit AT are deleted.
  • the one or more authentication information units AT stored in the vehicle storage device 28 based on the registration request D31 by a device other than the second device 30B (friend device 51) and the one or more authentication information units AT stored in the vehicle storage device 28 based on the registration request D21 by the owner device 40 are not deleted.
  • the management server 70 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D31 from a device other than the second device 30B (friend device 51) from being deleted due to the registration request D31 from the second device 30B (friend device 51).
  • the management server 70 can prevent one or more authentication information units AT already stored in the vehicle storage device 28 based on a registration request D21 from the owner device 40 from being deleted due to the registration request D31 from the second device 30B (friend device 51).
  • this command is a command to delete one of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the management server 70 notifies the owner device 40 that the authentication information unit AT has been deleted from the vehicle 20. This allows the management server 70 to inform the owner of the vehicle 20 that one of the authentication information units AT stored in the vehicle 20 has been deleted.
  • the management server 70 sends a new authentication information unit AT and the next command to the vehicle 20.
  • this command is to delete one of the one or more authentication information units AT stored in the vehicle storage device 28.
  • the management server 70 notifies the share device 50 that made the registration request D31 corresponding to the authentication information unit AT to be deleted that the authentication information unit AT has been deleted. This allows the management server 70 to inform the user of the share device 50 that made the registration request D31 corresponding to the deleted authentication information unit AT that the authentication information unit AT has been deleted.
  • the management server 70 sends a new authentication information unit AT and the next command to the vehicle 20. That is, this command is to delete one of the one or more authentication information units AT stored in the vehicle storage device 28. At this time, the management server 70 notifies the shared device 50 that has stored the key information DK corresponding to the deleted authentication information unit AT that the authentication information unit AT has been deleted. The device 30 that has stored the key information DK corresponding to the deleted authentication information unit AT will no longer be able to use the vehicle 20. That is, the management server 70 is configured to be able to notify the user of the shared device 50 that the digital key registered to the shared device 50 has become unusable. This allows the user to realize that the digital key is no longer usable before actually attempting to use the vehicle 20.
  • the fourth embodiment can be modified as follows:
  • the fourth embodiment can be implemented in combination with the following modifications of the fourth embodiment as long as they are not technically inconsistent.
  • the management server 70 may notify the owner device 40 of only the deleted authentication information unit AT.
  • the management server 70 may not send a notification to the owner device 40. Even in these cases, the management server 70 can delete the authentication information unit AT without intervention by the user of the vehicle 20. Therefore, the management server 70 is configured to reduce the burden on the user.
  • the management server 70 When deleting an authentication information unit AT, the management server 70 does not need to send a notification to the shared device 50 that requested registration of the digital key corresponding to the authentication information unit AT. Even in this case, the management server 70 can delete the authentication information unit AT without intervention by the user of the vehicle 20. Therefore, the management server 70 is configured to reduce the burden on the user.
  • the management server 70 does not need to send a notification to the shared device 50 whose authentication information unit AT is being replaced. Even in this case, the management server 70 can delete the authentication information unit AT without intervention by the user of the vehicle 20. Therefore, the management server 70 is configured to reduce the burden on the user.
  • the management server 70 may send a command to the vehicle 20 to delete one or more authentication information units AT stored in the vehicle storage device 28 based on another registration request D21 from the owner device 40 that made the registration request D21 corresponding to the authentication information unit AT.
  • FIGS 7, 15, 18, and 19 explain the vehicle management device 26 and management server 70 according to the fifth embodiment.
  • the fifth embodiment will be explained mainly focusing on the differences from the third embodiment.
  • the management server 70 according to the fifth embodiment transmits to the vehicle 20 a command to delete all of the multiple authentication information units AT that are the subject of the deletion reservation D41, a new authentication information unit AT, and a command to store the new authentication information unit AT.
  • the management server 70 notifies the multiple shared devices that have stored the key information DK corresponding to the multiple authentication information units AT that are the subject of the deletion reservation D41 that the authentication information unit AT corresponding to the key information DK has been deleted.
  • step S700 the management server 70 has already stored that the friend key KF indicated by the friend key information DKF stored in the fifth device 30E is in a fade-out state.
  • the management server 70 has already stored that the non-friend key KN indicated by the non-friend key information DKN stored in the sixth device 30F is in a fade-out state.
  • the management server 70 is in a state where multiple deletion reservations D41 remain unexecuted.
  • the third device 30C shown in FIG. 18 is a device 30 that does not store non-friend key information DKN and is designated as a non-friend device 52 through this series of processes.
  • a second device 30B which is a friend device 51 (not shown) executes an operation to request registration of a non-friend key KN for the third device 30C
  • the management system 10 performs the series of processes shown in FIG. 7.
  • Step S701 shown in FIG. 18 is similar to step S47 shown in FIG. 7.
  • the third device 30C performs processing step S702.
  • the processing step S702 shown in FIG. 18 is similar to step S48 shown in FIG. 7.
  • the third device 30C transmits non-friend key information DKN and a key track request D33 for the non-friend key KN to the management server 70.
  • step S703 the management server 70 performs registration management of the non-friend key KN. Specifically, the management server 70 checks whether the non-friend key KN, which is the target of the key track request D33, is listed on the rejection list. If the non-friend key KN is listed on the rejection list, the management server 70 sends a notification to the third device 30C that the key track request D33 cannot be fulfilled.
  • the management server 70 registers the non-friend key KN that is the subject of the key track request D33 in the database DB. Specifically, the management server 70 stores the third device 30C in the data block DA of the vehicle 20 in the database DB as a device 30 registered as a non-friend device 52. The management server 70 references the acquired non-friend key information DKN to store the relationship between the third device 30C and the friend device 51. Specifically, the management server 70 stores the third device 30C as a device 30 that has the non-friend key KN registered in response to the registration request D31 from the second device 30B (friend device 51). The management server 70 then performs the process of step S704.
  • the management server 70 has stored, as data blocks DA of the vehicle 20 in the database DB, the number of one or more authentication information units AT stored in the vehicle storage device 28 and the number of authentication information units AT that the vehicle storage device 28 can store. In step S704, the management server 70 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
  • the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has not reached the predetermined number that the vehicle storage device 28 can store, the management server 70 sends the authentication package ATP and a storage request D34 to the vehicle 20.
  • the management system 10 then performs the processes from step S50 onwards shown in FIG. 7.
  • the management server 70 determines that the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that the vehicle storage device 28 can store, the management server 70 performs processing in step S705.
  • step S705 the management server 70 selects an authentication information unit AT to be replaced by the authentication package ATP from among one or more authentication information units AT stored in the vehicle storage device 28.
  • FIG. 15 is a flowchart showing the process performed by the management server 70 in step S705 to select the authentication information unit AT to be replaced by the authentication package ATP.
  • the management server 70 performs this series of processes as the process of step S705.
  • step S510 the management server 70 determines whether one or more unexecuted deletion reservations D41 remain. If authentication information units AT for one or more faded-out digital keys have been stored in the vehicle storage device 28, the management server 70 determines that one or more unexecuted deletion reservations D41 remain.
  • the vehicle storage device 28 has stored, as faded-out digital keys, the friend key KF of the fifth device 30E, which is the friend device 51, and the non-friend key KN of the sixth device 30F, which is the non-friend device 52. In other words, at least one unexecuted deletion reservation D41 remains (step S510: YES). Therefore, the management server 70 proceeds to step S511.
  • step S511 the management server 70 determines whether multiple deletion reservations D41 remain unexecuted. If authentication information units AT for multiple digital keys in a fade-out state have already been stored in the vehicle storage device 28, the management server 70 determines that multiple deletion reservations D41 remain unexecuted.
  • the vehicle storage device 28 has already stored the authentication information unit AT for the friend key KF of the fifth device 30E and the authentication information unit AT for the non-friend key KN of the sixth device 30F as authentication information units AT for multiple digital keys in a fade-out state. In other words, multiple deletion reservations D41 remain unexecuted (step S511: YES). Therefore, the management server 70 proceeds to step S512.
  • step S512 the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT of multiple digital keys that are in a faded-out state and stored in the vehicle storage device 28.
  • the management server 70 generates a signal to cause the vehicle 20 to delete all authentication information units AT that are the subject of unexecuted deletion reservations D41 from the vehicle storage device 28.
  • the management server 70 generates a deletion request D101 shown in FIG. 18 as the signal.
  • the management server 70 then transmits the deletion request D101 to the vehicle 20.
  • the management server 70 then terminates the series of processes shown in FIG. 15.
  • the management server 70 After completing the series of processes shown in FIG. 15, in step S705 shown in FIG. 18, the management server 70 generates a storage request D102.
  • the storage request D102 is a signal for storing the authentication package ATP in the vehicle storage device 28.
  • the management server 70 transmits the storage request D102 and the authentication package ATP to the vehicle 20.
  • step S706 the vehicle 20 deletes all authentication information units AT of multiple faded-out digital keys stored in the vehicle storage device 28 in accordance with the deletion request D101. As a result, the number of one or more authentication information units AT stored in the vehicle storage device 28 becomes less than the predetermined number that can be stored. The vehicle 20 then performs the process of step S707 shown in FIG. 19.
  • step S707 the vehicle 20 stores the received authentication package ATP in accordance with the storage request D102. That is, the vehicle 20 stores the authentication package ATP as an authentication information unit AT for authenticating the non-friend key KN.
  • the management server 70 After the process of step S705, the management server 70 generates a key track completion notification M101 as the process of step S708, and transmits the key track completion notification M101 to the third device 30C.
  • the third device 30C When the third device 30C receives the key track completion notification M101, it performs the process of step S709. In the process of step S709, the third device 30C presents information indicating the completion of registration of the non-friend key KN to the device HMI_32. For example, the third device 30C presents an image indicating the completion of registration of the non-friend key KN to the device HMI_32.
  • the management server 70 After processing step S708, the management server 70 generates a deletion notification M102 and a deletion notification M103 in processing step S710.
  • the deletion notification M102 is a notification indicating that the authentication information unit AT corresponding to the non-friend key information DKN of the sixth device 30F has been deleted from the vehicle 20.
  • the deletion notification M103 is a notification indicating that the authentication information unit AT corresponding to the friend key information DKF of the fifth device 30E and the authentication information unit AT corresponding to the non-friend key information DKN of the sixth device 30F have been deleted from the vehicle 20.
  • the management server 70 transmits the deletion notification M102 to the sixth device 30F.
  • the management server 70 transmits the deletion notification M103 to the fifth device 30E.
  • step S711 the sixth device 30F deletes the non-friend key information DKN corresponding to the authentication information unit AT deleted by the vehicle 20 from the device storage device 37 of the sixth device 30F.
  • step S711 the sixth device 30F presents to the device HMI_32 information indicating that the non-friend key information DKN has been deleted.
  • the sixth device 30F presents to the device HMI_32 information indicating that the authentication information unit AT included in the non-friend key information DKN of the sixth device 30F has been deleted from the vehicle storage device 28.
  • the fifth device 30E executes the process of step S712 in accordance with the deletion notification M103.
  • the fifth device 30E deletes the non-friend key information DKN corresponding to the authentication information unit AT deleted by the vehicle 20 from the device storage device 37 of the fifth device 30E.
  • the fifth device 30E presents to the device HMI_32 information indicating that the non-friend key information DKN corresponding to the authentication information unit AT deleted by the vehicle 20 has been deleted from the device storage device 37 of the fifth device 30E.
  • step S712 the fifth device 30E presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the friend key information DKF of the fifth device 30E has been deleted from the vehicle 20.
  • the fifth device 30E presents to the device HMI_32 information indicating that the authentication information unit AT corresponding to the non-friend key information DKN of the sixth device 30F has been deleted from the vehicle 20.
  • the management system 10 then terminates the series of processes.
  • the shared device 50 that has stored therein the key information DK corresponding to the deleted authentication information unit AT will no longer be able to use the vehicle 20.
  • the management server 70 is configured to be able to notify the user of the sharing device 50 that the digital key registered to the sharing device 50 has become unusable. This allows the user of the sharing device 50 to realize that the digital key is no longer usable before actually attempting to use the vehicle.
  • the fifth embodiment can be modified as follows:
  • the fifth embodiment can be implemented in combination with the following modifications of the fifth embodiment as long as they are not technically inconsistent.
  • the server execution device 71 of the management server 70 executes the replacement program PM to perform processing related to replacing the authentication information unit AT
  • the server execution device 71 of the vehicle management device 26 does not need to perform processing related to replacing the authentication information unit AT in the vehicle program PV.
  • the vehicle storage device 28 does not need to store processing related to replacing the authentication information unit AT as the vehicle program PV.
  • the digital key-related matters in the above embodiments do not have to comply with the CCC.
  • the series of processes including the process of deleting an authentication information unit AT when the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored is not limited to the examples of the above-described embodiments.
  • the management server 70 shown in FIG. 20 is configured to select one of the one or more authentication information units AT stored in the vehicle storage device 28 as an authentication information unit AT to be deleted. However, the management server 70 does not determine whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
  • the third device 30C shown in FIG. 20 is a device 30 that does not store non-friend key information DKN and is designated as a non-friend device 52 by the series of processes.
  • an operation to request registration of a non-friend key KN for the third device 30C is executed in the friend device 51 (not shown), causing the management system 10 to perform the series of processes shown in Figure 7 to register the non-friend key KN.
  • Step S801 shown in Figure 20 is similar to step S47 shown in Figure 7.
  • the third device 30C performs processing step S802.
  • the processing of step S802 shown in Figure 20 is similar to step S48 shown in Figure 7.
  • the processing of step S803 shown in Figure 20 is similar to step S48 shown in Figure 7.
  • step S803 the management server 70 transmits to the vehicle 20 the authentication package ATP included in the non-friend key information DKN and a storage request D34 for storing the authentication package ATP. After that, when the vehicle 20 receives the authentication package ATP and storage request D34, the vehicle 20 performs the processing of step S804.
  • step S804 the vehicle 20 determines whether the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored. If the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored, the vehicle 20 generates an upper limit notification M111.
  • the upper limit notification M111 comprises a signal indicating that the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
  • the vehicle 20 transmits the upper limit notification M111 to the management server 70.
  • the management server 70 is configured to be able to recognize that the number of one or more authentication information units AT stored in the vehicle 20 has reached the predetermined number that can be stored in the vehicle 20.
  • step S805 the management server 70 performs the same process as step S505 shown in FIG. 14. As a result, the management server 70 selects the authentication information unit AT to be deleted. Thereafter, the management server 70 transmits a replacement request D111 shown in FIG. 10 to the vehicle 20.
  • step S806 The vehicle 20 that has received the replacement request D111 performs the process of step S806.
  • step S806 the vehicle 20 performs the same process as step S105 shown in FIG. 10.
  • step S807 the vehicle 20 proceeds to the process of step S807 shown in FIG. 20.
  • step S807 the vehicle 20 generates a completion notification M112.
  • the completion notification M112 includes a signal indicating that the vehicle 20 has replaced the authentication package ATP included in the non-friend key information DKN of the third device 30C with the authentication information unit AT selected by the management server 70 in step S805 and stored it in the vehicle storage device 28.
  • the completion notification M112 includes information in which the authentication information unit AT selected by the management server 70 in step S805 has been deleted.
  • the vehicle 20 transmits the completion notification M112 to the management server 70. Having received the completion notification M112, the management server 70 performs the process of step S808.
  • step S808 the management server 70 generates a completion notification M113.
  • the completion notification M113 includes a signal indicating that the vehicle 20 has stored the authentication package ATP included in the non-friend key information DKN of the third device 30C in place of one or more authentication information units AT already stored in the vehicle storage device 28.
  • the completion notification M113 includes information that the authentication information unit AT selected by the management server 70 in step S805 has been deleted.
  • the management server 70 transmits the completion notification M113 to the third device 30C.
  • step S809 the third device 30C presents to the device HMI_32 registration completion information indicating that the registration of the third device 30C's non-friend key KN to the vehicle 20 has been completed.
  • the management system 10 then terminates the series of processes for replacing the current authentication information unit AT.
  • ⁇ Sending confirmation notification M121> When the management system 10 selects an authentication information unit AT to be deleted from one or more authentication information units AT stored in the vehicle memory device 28, it may confirm with the user of the owner device 40 whether or not to allow the deletion of the authentication information unit AT.
  • FIG. 21 is an explanatory diagram showing the flow of a series of processes executed by the vehicle 20 after the vehicle 20 selects an authentication information unit AT to be deleted from one or more authentication information units AT stored in the vehicle storage device 28 in the series of processes shown in FIG. 10.
  • the vehicle storage device 28 has already stored a vehicle program PV.
  • the vehicle execution device 27 executes the vehicle program PV stored in the vehicle storage device 28. This causes the vehicle 20 to execute a series of processes.
  • the owner device 40 is a first device 30A that has already stored key information DK indicating the owner key KO through the series of processes shown in FIG. 5.
  • step S104 the vehicle 20 performs the same processing as in step S104 shown in FIG. 10.
  • the vehicle 20 selects the authentication information unit AT to be deleted, the vehicle 20 performs the processing of step S105.
  • step S901 the vehicle 20 generates a confirmation request D121.
  • the confirmation request D121 is a request to the user of the owner device 40 for permission to delete the authentication information unit AT selected by the vehicle 20 in step S104.
  • the vehicle 20 transmits the confirmation request D121 and name information ATP5 to the management server 70.
  • the name information ATP5 is included in the authentication information unit AT selected by the vehicle 20 in step S104.
  • the management server 70 is configured to be able to receive a confirmation request D121 from the vehicle 20.
  • the management server 70 receives the confirmation request D121, it performs the process of step S902.
  • the management server 70 generates a confirmation notification M121, which is a notification requesting permission to delete the authentication information unit AT, in accordance with the confirmation request D121.
  • the confirmation notification M121 includes information for enabling the device 30 to set whether or not to permit the deletion of the authentication information unit AT through operation of the device 30.
  • the management server 70 transmits the name information ATP5 received from the vehicle 20 and the confirmation notification M121 to the owner device 40.
  • the owner device 40 is configured to be able to receive the confirmation notification M121 from the management server 70.
  • the owner device 40 performs the process of step S903.
  • the owner device 40 presents to the device HMI_32 an image that allows the user of the owner device 40 to set whether or not to permit deletion of the authentication information unit AT.
  • Figure 22 is an example of an image presented on the device HMI_32 of the owner device 40 to ask the user of the owner device 40 whether or not to allow the deletion of the authentication information unit AT.
  • the "Name Information” field shown in Figure 22 displays the name information ATP5 that the owner device 40 has received from the management server 70.
  • the user of the owner device 40 follows the instructions presented on the device HMI_32 and selects either "YES” or "NO” using the radio button to indicate whether or not to allow the deletion of the authentication information unit AT.
  • Step S903 If YES> If the user of the owner device 40 selects "YES” using the radio button and then presses "OK” (step S903: YES), the owner device 40 generates a permission notification M122.
  • the permission notification M122 is a notification that permits the deletion of the authentication information unit AT.
  • the owner device 40 transmits the permission notification M122 to the management server 70.
  • step S904 the management server 70 generates a continuation request D122.
  • the continuation request D122 includes a signal for permitting the vehicle 20 to delete the authentication information unit AT.
  • the management server 70 transmits the continuation request D122 to the vehicle 20.
  • step S105 the vehicle 20 performs the same process as step S105 shown in FIG. 10. That is, the vehicle 20 deletes the authentication information unit AT from the vehicle storage device 28. Thereafter, the management system 10 performs the processes from step S106 onwards shown in FIG. 10.
  • Step S93 NO> 21, if the user of the owner device 40 selects "NO” shown in FIG. 22 using the radio button and then presses "OK” (step S903: NO), the owner device 40 generates a rejection notification M123.
  • the rejection notification M123 is a notification that rejects the deletion of the authentication information unit AT.
  • the owner device 40 transmits the rejection notification M123 to the management server 70.
  • step S905 the management server 70 generates a cancellation request D123.
  • the cancellation request D123 requests the vehicle 20 to cancel the deletion of the authentication information unit AT.
  • the management server 70 transmits the cancellation request D123 to the vehicle 20.
  • step S906 the vehicle 20 cancels the deletion of the authentication information unit AT.
  • the management system 10 ends the series of processes without deleting the authentication information unit AT from the vehicle storage device 28. In this case, no new authentication information unit AT is stored in the vehicle storage device 28.
  • the management system 10 is configured to be able to confirm with the user of the owner device 40 whether or not to allow deletion of the authentication information unit.
  • the management server 70 may send a confirmation notification M121 to the share device 50.
  • the management server 70 may send the confirmation notification M121 to the next share device 50.
  • the share device 50 to which the confirmation notification M121 is sent has stored name information ATP that is identical to the name information ATP5 received from the vehicle 20 in step S903.
  • the management server 70 may send the confirmation notification M121 to the owner device 40 and the share device 50.
  • the non-friend device 52 may be able to transmit a request for registering a new non-friend key KN.
  • a share device 50 that has stored a share key KS may transmit a request for registering a new non-friend key KN regardless of whether the share device 50 is a friend device 51 or a non-friend device 52.
  • the management system 10 may register the new non-friend key KN by the series of processes shown in FIG. 7.
  • the third device 30C shown in FIG. 4 is a non-friend device 52 that has stored key information DK indicating the non-friend key KN of the vehicle 20.
  • the third device 30C may send a request to register a new non-friend key KN for the vehicle 20.
  • a new device 30 that has stored key information DK for the new non-friend key KN of the vehicle 20 is registered as a non-friend device 52.
  • the second device 30B that has stored friend key information DKF indicating the friend key KF is a device 30 that has stored key information DK indicating the first digital key (friend key KF).
  • the first digital key is not limited to the owner key KO.
  • the third device 30C has stored non-friend key information DKN that indicates the non-friend key KN to be registered based on the registration request D31 from the second device 30B.
  • the third device 30C is a device 30 that has stored key information DK indicating the second digital key (non-friend key KN).
  • the new device that has stored key information DK indicating the new non-friend key KN to be registered based on a registration request from the third device 30C is the device 30 that has stored key information DK indicating the third digital key (non-friend key KN).
  • the vehicle storage device 28 has already stored an authentication information unit AT for authenticating the friend key KF as the authentication information unit AT for authenticating the first digital key (friend key KF).
  • the vehicle storage device 28 has already stored an authentication information unit AT for authenticating the non-friend key KN as the authentication information unit AT for authenticating the second digital key (non-friend key KN).
  • the vehicle storage device 28 has already stored an authentication information unit AT for authenticating the new non-friend key KN as the authentication information unit AT for authenticating the third digital key (non-friend key KN).
  • the following describes a vehicle 20 in which an authentication information unit AT for authenticating a second digital key (non-friend key KN) and an authentication information unit AT for authenticating a third digital key (non-friend key KN) are stored in the vehicle storage device 28, and the number of one or more authentication information units AT stored in the vehicle storage device 28 has reached the predetermined number that can be stored.
  • the vehicle 20 may select the authentication information unit AT for authenticating the new non-friend key KN stored in the vehicle 20 as the authentication information unit AT to be deleted.
  • the management server 70 receives a request to store a new authentication information unit AT in the vehicle 20, it may send a command to the vehicle 20 to delete the authentication information unit AT that was required to authenticate the new non-friend key KN stored in the vehicle 20.
  • the vehicle 20 does not need to have any of the BLE module 23, the UWB module 24, or the NFC module 25. As long as the vehicle 20 has at least one short-range communication module, it can perform short-range communication with the device 30. Furthermore, the vehicle 20 is not limited to having these communication modules, and it is sufficient that the vehicle 20 has a module that performs short-range communication with the device 30.
  • the vehicle management device 26 is not limited to being an ECU whose primary function is to process digital keys.
  • the vehicle management device 26 may be, for example, a central ECU that manages multiple ECUs in the vehicle 20.
  • the vehicle management device 26 may be configured as a circuit having one or more processors that execute various processes in accordance with a computer program (software) or program product.
  • the vehicle management device 26 may be configured as a circuit having one or more dedicated hardware circuits, such as an application-specific integrated circuit (ASIC), or a combination thereof, that execute at least some of the various processes.
  • the processor includes a CPU and memory such as RAM and ROM.
  • the memory stores program code, programs, program products, or instructions that cause the CPU to execute various processes.
  • the memory i.e., non-transitory computer-readable storage medium, includes any available medium that can be accessed by a general-purpose or dedicated computer. The same applies to the device 30 and the management server 70.
  • the device 30 is not limited to a smartphone. It may also be a smartwatch.
  • the device 30 may also be a specified server.
  • the specified server may include the device 30.
  • the owner device 40 may be included in the specified server.
  • the friend device 51 may be included in the specified server.
  • the multiple digital keys exist in a hierarchy arranged from top to bottom in the order of owner key KO, friend key KF, and non-friend key KN, with the higher the hierarchy, the greater the authority of the digital key. It is not necessary for the higher the hierarchy of the digital key, the greater the authority. For example, the same level of authority may be set for the three hierarchies of owner key KO, friend key KF, and non-friend key KN.
  • a device server 60 does not have to be provided for each type of device 30. It is sufficient that multiple devices 30 and the management server 70 are capable of wireless communication. The device server 60 may be omitted. It is sufficient that multiple devices 30 and the management server 70 are capable of direct wireless communication.
  • the management server 70 may be made up of multiple servers.
  • the management server 70 may be made up of a server portion that stores the database DB and a server portion that executes a server program.
  • the management server 70 may be made up of a server portion that communicates with the vehicle 20 and a server portion that communicates with the device server 60, and these server portions may be able to communicate with each other.
  • the management server 70 does not need to store a database DB.
  • the management server 70 only needs to manage, for at least one digital key in the management system 10, the combination of the key information DK of the device 30 and the authentication information unit AT of the vehicle management device 26.
  • the share device 50 has the function of receiving the share key KS.
  • a device 30 that has the function of receiving a digital key, such as the share device 50, is sometimes called a receiver device.
  • the authentication information unit AT may be any information for authenticating the digital key when the digital key is used, and is not limited to the examples in the above embodiments.
  • the authentication information unit AT may be a common key shared by the vehicle management device 26 and the device 30.
  • the authentication information unit AT may be a common secret key.
  • the configuration of the information contained in the key information DK is not limited to the example in the above embodiment.
  • the owner key information DKO does not have to include slot identification information ST4.
  • the key information DK may include information indicating the type of digital key.
  • the type of digital key is information indicating one of the owner key KO, friend key KF, and non-friend key KN, for example.
  • the database DB may include information indicating the type of device 30.
  • the type of device 30 is information indicating, for example, a smartphone, a smartwatch, or a specified server as in the modified example described above.
  • the structure of the data blocks DA in the database DB is not limited to the examples in the above embodiments.
  • the database DB only needs to contain the information necessary for management by the management server 70 in the management system 10.
  • the series of processes for registering the owner key KO is not limited to the examples in the above embodiments.
  • the owner device 40 may store the owner key information DKO by transmitting and receiving information such as the generated data DC between the vehicle 20 and the first device 30A via the management server 70.
  • the series of processes for registering the owner key KO may be modified as appropriate depending on the structure of the information included in the owner key information DKO and the structure of the information included in the authentication information unit AT.
  • the series of processes for registering the friend key KF is not limited to the examples in the above embodiments.
  • the management server 70 may update the database DB by processing step S29 after sending the authentication package ATP and storage request D24 to the vehicle 20.
  • the series of processes for registering the friend key KF may be modified as appropriate depending on the structure of the information contained in the friend key information DKF and the structure of the information contained in the authentication information unit AT.
  • the series of processes for registering a non-friend key KN is not limited to the examples in the above embodiments.
  • the order of the series of processes for registering a non-friend key KN may be different from the order of the series of processes for registering a friend key KF.
  • the series of processes for registering a non-friend key KN may be changed as appropriate depending on the structure of the information contained in the non-friend key information DKN and the structure of the information contained in the authentication information unit AT.
  • the types of digital keys do not have to include non-friend keys KN.
  • the share keys KS may only be friend keys KF.
  • ⁇ Process for deleting a digital key> the friend device 51 transmits the deletion reservation D41 to the management server 70. However, the transmission does not have to be a reservation. That is, the friend device 51 may transmit a request to delete the non-friend key KN to the management server 70 regardless of the default condition RC. Furthermore, the deletion request is not necessarily issued by the friend device 51.
  • the management server 70 may proceed with the processing from step S62 onward by the owner device 40 issuing a request to delete the non-friend key KN.
  • the non-friend device 52 may send a request to the management server 70 to delete the non-friend key KN registered in the non-friend device 52.
  • the management server 70 receives the deletion request, it generates a request to delete the non-friend key information DKN, similar to step S66 shown in FIG. 8.
  • the management server 70 then sends a request to delete the non-friend key information DKN to the non-friend device 52.
  • the non-friend device 52 that has received the request to delete the non-friend key information DKN then deletes the non-friend key information DKN, similar to step S67 shown in FIG. 8.
  • the non-friend device 52 then sends a notification to the management server 70 indicating that the non-friend key information DKN has been deleted.
  • the management server 70 proceeds with the processing from step S82 onwards shown in FIG. 9.
  • the non-friend device 52 does not need to send a notification to the management server 70 indicating that the non-friend key information DKN has been deleted. In this case, the management server 70 sends a request to the non-friend device 52 to delete the non-friend key information DKN, and then proceeds with the processing from step S82 onwards shown in Figure 9.
  • a deletion reservation may be requested from the management server 70 in both cases where a non-friend key KN is deleted due to operation of the friend device 51 and where a non-friend key KN is deleted due to operation of the non-friend device 52.
  • the owner device 40 and/or the vehicle 20 may request the deletion of the non-friend key KN.
  • the management server 70 may generate a request to delete the non-friend key KN when a predetermined condition is met.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Lock And Its Accessories (AREA)

Abstract

車両管理装置、管理サーバ、および管理システム、が提供される。車両記憶装置(28)は、1つまたは複数のデジタルキー情報単位(AT)を記憶する。デジタルキー情報単位(AT)はデジタルキーに関する情報単位である。車両記憶装置(28)はデジタルキー情報単位(AT)の記憶済数について車両記憶装置(28)に記憶可能な既定数を有している。車両処理回路(27)は、記憶済数が既定数に達している状態で、新たに前記デジタルキー情報単位(AT)を受信したとき、車両記憶装置(28)に記憶済の1つまたは複数のデジタルキー情報単位(AT)のうちのいずれかを削除する(S104、S105)。

Description

車両管理装置、管理サーバ、および管理システム
 この開示は車両管理装置、管理サーバ、および管理システム、に関する。
 特許文献1には、スマートフォン等のデバイスを、車両のキーとするデジタルキーシステムの技術が開示されている。デジタルキーシステムは、車両に、デジタルキーに関する情報を記憶させる。デジタルキーシステムは、デバイスに、デジタルキー情報を記憶させる。これによって、物理的なキーを必要とせずに、デジタルキーとして登録されたデバイスを用いて、車両を使用できるようになる。さらにデジタルキーシステムは、デジタルキー情報を記憶済のデバイスと、他人のデバイスと、の通信を通じることで、他人のデバイスをデジタルキーとして機能させるための登録要求を行なう。これによって、デジタルキーシステムは、前記他人のデバイスをデジタルキーとして車両に登録できるよう構成されている。すなわちデジタルキーは、新たに別のデジタルキーを生成することが可能である。デジタルキーシステムは、物理的なキーの受け渡しを必要とせずに、他人に車両を貸し出すことができる。
特開2023-184349号公報
 車両が記憶することが可能に構成されているデジタルキー情報単位の数には、限りがありうる。
 本開示の一側面によれば、車両に搭載される車両管理装置が提供される。前記車両管理装置は、車両処理回路と、1つまたは複数のデジタルキー情報単位を記憶するように構成されている車両記憶装置と、を備えている。前記デジタルキー情報単位はデジタルキーに関する情報単位である。前記車両記憶装置は前記デジタルキー情報単位の記憶済数について前記車両記憶装置に記憶可能な既定数を有している。前記車両処理回路は、前記記憶済数が前記既定数に達している状態で、新たに前記デジタルキー情報単位を受信したとき、前記車両記憶装置に記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを、削除するように構成されている。
 本開示の別の側面によれば、サーバ処理回路を備えている管理サーバが提供される。前記サーバ処理回路は、1つまたは複数のデジタルキーを管理するべく、1つまたは複数のデジタルキー情報単位を車両に記憶させるための記憶要求を受信する。1つまたは複数のデジタルキー情報単位は、1つまたは複数の前記デジタルキーに関する情報単位である。サーバ処理回路は、前記車両が記憶済の前記デジタルキー情報単位の数としての記憶済数が、前記車両が記憶可能な前記デジタルキー情報単位の既定数に達しているか否かを把握する。サーバ処理回路は、前記記憶済数が前記既定数に達している前記車両に対する前記記憶要求を受信したとき、前記車両に、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除させるための命令を送信する。
 本開示のさらに別の側面によれば、管理システムが提供される。前記管理システムは、車両に搭載される車両管理装置と、サーバ処理回路を備えている管理サーバと、を備えている。車両管理装置は、車両処理回路と車両記憶装置とを備えている。サーバ処理回路は、1つまたは複数のデジタルキーを管理する。前記車両記憶装置は、1つまたは複数の前記デジタルキーに関する情報単位としての1つまたは複数のデジタルキー情報単位を記憶する。前記車両記憶装置は、記憶可能な前記デジタルキー情報単位の数の既定数を有している。前記車両処理回路または前記サーバ処理回路のうちの少なくとも一方は、前記車両記憶装置に記憶済の前記デジタルキー情報単位の前記数が前記既定数に達している状態で、新たに前記デジタルキー情報単位を受信したとき、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除するように構成されている。
 上記の車両管理装置によれば、車両が記憶済のデジタルキー情報単位のなかから、どのデジタルキー情報単位を削除するのかをユーザが選択しなくてよくなる。よって、ユーザにかかる負担が軽減される。
 上記の管理サーバによれば、車両が記憶済のデジタルキー情報単位のなかから、どのデジタルキー情報単位を削除するのかをユーザが選択しなくてよくなる。よって、ユーザにかかる負担が軽減される。
 上記の管理システムによれば、車両が記憶済のデジタルキー情報単位のなかから、どのデジタルキー情報単位を削除するのかをユーザが選択しなくてよくなる。よって、ユーザにかかる負担が軽減される。
 さて、車両が記憶することが可能に構成されているデジタルキー情報単位の数には、限りがある。車両に記憶済のデジタルキー情報単位の数が、記憶可能な既定数に達しているときに、新たにデジタルキー情報単位を車両に記憶させるには、次のことが必要である。すなわち、車両のユーザは、車両が記憶済のデジタルキー情報単位のなかから、どれを削除するのかを選択する必要がある。上記の各種構成は、この要求に答える。
図1は、第1実施形態の管理システムを示す概略図である。 図2は、第1実施形態のオーナーキー情報を示す概略図である。 図3は、第1実施形態のシェアキー情報を示す概略図である。 図4は、第1実施形態のデータベースにおけるデータを示す概略図である。 図5は、第1実施形態のオーナーキーの登録が行なわれる際に管理システムが行なう一連の処理を示す説明図である。 図6は、第1実施形態のフレンドキーの登録が行なわれる際に管理システムが行なう一連の処理を示す説明図である。 図7は、第1実施形態のノンフレンドキーの登録が行なわれる際に管理システムが行なう一連の処理を示す説明図である。 図8は、第1実施形態のフレンドデバイスからの要求によってノンフレンドキーが削除される際に管理システムが行なう一連の処理を示す説明図である。 図9は、第1実施形態のノンフレンドデバイスからの要求によってノンフレンドキーが削除される際に管理システムが行なう一連の処理を示す説明図である。 図10は、第1実施形態の車両管理装置を備えている車両と、管理サーバと、を備えている管理システムが行なう一連の処理を示す説明図である。 図11は、図10と、図12と、において車両管理装置が実行する処理の流れを示すフローチャートである。 図12は、第2実施形態の車両管理装置を備えている車両と、管理サーバと、を備えている管理システムが行なう一連の処理を示す説明図である。 図13は、図12の処理の続きを示す説明図である。 図14は、第3実施形態の車両管理装置を備えている車両と、管理サーバと、を備えている管理システムが行なう一連の処理を示す説明図である。 図15は、図14と、図16と、図18と、図20と、において管理サーバが実行する処理の流れを示すフローチャートである。 図16は、第4実施形態の車両管理装置を備えている車両と、管理サーバと、を備えている管理システムが行なう一連の処理を示す説明図である。 図17は、図16の処理の続きを示す説明図である。 図18は、第5実施形態の車両管理装置を備えている車両と、管理サーバと、を備えている管理システムが行なう一連の処理を示す説明図である。 図19は、図18の処理の続きを示す説明図である。 図20は、変更例の車両管理装置を備えている車両と、管理サーバと、を備えている管理システムが行なう一連の処理を示す説明図である。 図21は、デジタルキー情報単位の削除を許可するか否かをユーザに選択させる一連の処理を示す説明図である。 図22は、デジタルキー情報単位の削除を許可するか否かをユーザに選択させるべく提示される画像の表示例を示す図である。
 図1~図11は、管理サーバ、設定方法、設定処理、プログラム、およびプログラム製品、の第1実施形態を説明する。
 <管理システム10の概略>
 図1に示すように、管理サーバ70は、管理システム10を構成する複数の装置のうちの1つである。管理システム10は、車両20、複数のデバイス30、デバイスサーバ60、および管理サーバ70、を備えている。管理サーバ70は、デジタルキーを管理するサーバである。デジタルキーに関して、CCC(Car_Connectivity_Consortium)の規格が存在する。本実施形態のデジタルキーに関する事項は、CCCに準拠している。
 車両20は、通信モジュール21、車両HMI_22、BLEモジュール23、UWBモジュール24、NFCモジュール25、および車両管理装置26、を有している。HMIは、Human_Machine_Interfaceの略である。BLEは、Bluetooth(登録商標)_Low_Energyの略である。UWBは、Ultra_Wide_Bandの略である。NFCは、Near_Field_Communicationの略である。
 通信モジュール21は、無線通信回線網を介して管理サーバ70との通信を行なう。車両HMI_22は、車両20のユーザの操作を受け付ける入力装置と、画像および音声などによってユーザに情報を提示する提示装置と、を備えている。提示装置は、例えば、モニタおよびスピーカである。
 BLEモジュール23は、BLE通信によってデバイス30との近距離通信を行なう。UWBモジュール24は、UWB通信によってデバイス30に通信する。UWBモジュール24は、デバイス30と車両20との距離を計測する。NFCモジュール25は、NFC通信によってデバイス30との近距離通信を行なう。
 車両管理装置26は、車両20に搭載されている。車両管理装置26は、車両20のデジタルキーに関する管理を行なう。車両管理装置26は、例えば、デジタルキーECUを有している車両制御回路である。車両管理装置26は、車両実行装置27と、車両記憶装置28と、を有している。車両記憶装置28は、車両プログラムPVと、認証情報単位ATと、を記憶済である。車両プログラムPVは、車両実行装置27に実行させることで、車両実行装置27に認証情報単位ATの記憶、削除、および置き換え、を行なわせる。認証情報単位ATは、デジタルキーを認証するための情報である。よって、デジタルキーが使用される際に、デジタルキーによる車両20の制御が可能とされる。認証情報単位ATは、認証されるデジタルキーごとに設けられている。車両実行装置27は、CPUを有している車両処理回路である。車両実行装置27は、車両プログラムPVを実行することで、認証情報単位ATの記憶、削除、および置き換え、に関する処理を実行する。
 デジタルキーを認証する、とは、デジタルキーによって車両20が制御されることを可能にすることである。例えば、車両管理装置26がデジタルキーを認証すると、車両管理装置26は、デジタルキーによる車両20の開錠を可能にする。また例えば、車両管理装置26がデジタルキーを認証すると、車両管理装置26は、デジタルキーによる車両20の始動を可能にする。
 デバイス30は、スマートフォンなどの携帯情報端末である。デバイス30は、通信モジュール31、デバイスHMI_32、BLEモジュール33、UWBモジュール34、NFCモジュール35、デバイス実行装置36、およびデバイス記憶装置37、を有している。
 通信モジュール31は、無線通信回線を介してデバイスサーバ60との通信を行なう。デバイスHMI_32は、デバイス30のユーザによる操作を受け付ける入力装置と、画像および音声などによってユーザに情報を提示する提示装置と、を備えている。提示装置は、例えば、モニタおよびスピーカである。
 BLEモジュール33は、BLE通信によって車両20との近距離通信を行なう。UWBモジュール34は、UWB通信によって車両20に通信する。NFCモジュール35は、NFC通信によって車両20との近距離通信を行なう。
 デバイス記憶装置37は、デバイスプログラムPDと、キー情報DKと、を記憶済である。デバイスプログラムPDは、種々のデバイス処理をデバイス実行装置36に実行させることで、デバイス実行装置36にキー情報DKの記憶および削除を行なわせる。キー情報DKは、デジタルキーを示す情報である。
 デバイスプログラムPDは、例えば、デバイスアプリケーションおよびデジタルキーフレームワークを備えている。デバイスアプリケーションは、キー情報DKの記憶および削除を行なうためのアプリケーションである。デジタルキーフレームワークは、OSに用意されたAPIを利用してデバイス30のペアリング、およびデジタルキーのシェアリング、の機能を提供するプログラムである。デバイス実行装置36は、デバイスプログラムPDを実行することで、キー情報DKの記憶および削除に関する処理を実行するデバイス処理回路である。
 複数のデバイス30は、オーナーデバイス40と、複数のシェアデバイス50と、を備えている。オーナーデバイス40は、キー情報DKとして、オーナーキーKOを示すオーナーキー情報DKOを記憶済である。オーナーキーKOは、1つの車両20に対して1つのみ登録可能に構成されている。よって、オーナーキーKOは、1つの車両20に対して1つのみ存在する。
 図2に示すように、オーナーキー情報DKOは、オーナーキー構造情報STOを有している。オーナーキー構造情報STOは、車両識別情報ST1、デバイス内キー識別情報ST2、デジタルキー識別情報ST3、およびスロット識別情報ST4、を備えている。オーナーキー構造情報STOはさらに、証明書情報ST5、デバイス公開鍵情報ST6、車両公開鍵情報ST7、および許可公開鍵情報ST8、を備えている。
 車両識別情報ST1は、1つまたは複数のデジタルキーが設定される対象である車両20を識別する情報である。例えば、車両識別情報ST1は車両20のIDである。
 デバイス内キー識別情報ST2は、デバイス30内におけるデジタルキーの管理に用いられる。デバイス内キー識別情報ST2は、デバイス30のアプリケーション内において、デジタルキーを識別できるための情報である。
 デジタルキー識別情報ST3は、管理サーバ70内におけるデジタルキーの管理に用いられる。スロット識別情報ST4は、デバイス30のローカル上で、デジタルキーを識別できるための情報である。
 証明書情報ST5は、デジタルキーを証明する証明書を示す。デバイス公開鍵情報ST6は、デバイス30の公開鍵であるデバイス公開鍵PKDを示す。オーナーキー情報DKOにおけるデバイス公開鍵PKDは、オーナーデバイス40の公開鍵を示す。車両公開鍵情報ST7は、車両20の公開鍵である車両公開鍵PKVを示す。許可公開鍵情報ST8は、既に許可された車両公開鍵PKVを示す。
 図1に示すように、シェアデバイス50は、キー情報DKとして、シェアキーKSを示すシェアキー情報DKSを記憶済である。シェアキーKSは、デジタルキーを使用可能とするべくデジタルキーを登録するうえで1つの車両20に対して複数登録可能なデジタルキーである。すなわち、シェアキーKSは、1つの車両20に対して複数存在できる。
 複数のシェアデバイス50は、1つまたは複数のフレンドデバイス51と、1つまたは複数のノンフレンドデバイス52と、を備えている。フレンドデバイス51は、シェアキー情報DKSとして、フレンドキーKFを示すフレンドキー情報DKFを記憶済である。ノンフレンドデバイス52は、シェアキー情報DKSとして、ノンフレンドキーKNを示すノンフレンドキー情報DKNを記憶済である。つまり、シェアキーKSの種類は、フレンドキーKFと、ノンフレンドキーKNと、を備えている。フレンドキーKFは、後述するようにオーナーデバイス40から直接の登録要求D21に基づき登録済のシェアキーKSである。登録要求D21は、デバイス30に、キー情報DKであるフレンドキー情報DKFを記憶することを要求する。ノンフレンドキーKNは、後述するようにフレンドデバイス51からの登録要求D31に基づき登録済のシェアキーKSである。すなわち、登録要求D31は、デバイス30に、キー情報DKであるノンフレンドキー情報DKNを記憶させるための要求である。ノンフレンドキーKNは、オーナーデバイス40とは別のデバイス30であるシェアデバイス50からの登録要求に基づき、登録されたシェアキーKSである。シェアデバイス50からの登録要求は、いわゆる間接の登録要求である。
 デジタルキーが登録されている状態は、デジタルキーを使用可能となっている状態である。すなわち、デジタルキーが登録されている状態では、車両20は認証情報単位ATを記憶しており、かつデバイス30はキー情報DKを記憶済である。認証情報単位ATは、デジタルキーに関する情報単位としてのデジタルキー情報単位である。すなわち、デジタルキーが登録されている状態では、車両20はデジタルキー情報単位を記憶済である。キー情報DKは、デジタルキー情報単位である。すなわち、デジタルキーが登録されている状態では、デバイス30はデジタルキー情報単位を記憶済である。
 図3に示すように、シェアキー情報DKSは、シェアキー構造情報STSと、認証パッケージATPと、を有している。シェアキー構造情報STSは、車両識別情報ST1、デバイス内キー識別情報ST2、デジタルキー識別情報ST3、およびスロット識別情報ST4、を備えている。シェアキー構造情報STSはさらに、証明書情報ST5、車両公開鍵情報ST7、および許可公開鍵情報ST8、を備えている。つまりシェアキー構造情報STSは、オーナーキー構造情報STOから、デバイス公開鍵情報ST6を除いた情報である。
 認証パッケージATPは、署名情報ATP1、パスワード情報ATP2、有効開始時情報ATP3、有効期限情報ATP4、ネーム情報ATP5、およびデバイス公開鍵情報ATP6、を含んでいる。
 署名情報ATP1は、シェアデバイス50が、デジタルキーをシェアされる正規の対象であることを示す。例えば、シェアデバイス50がフレンドデバイス51の場合、署名情報ATP1はオーナーデバイス40による署名を示す。オーナー署名情報は、デバイス公開鍵情報ATP6で示されるフレンドデバイス51のデバイス公開鍵PKDに、オーナーデバイス40が署名したことを示す。また例えば、シェアデバイス50がノンフレンドデバイス52の場合、署名情報ATP1はフレンドデバイス51による署名を示す。フレンド署名情報は、デバイス公開鍵情報ATP6で示されるノンフレンドデバイス52のデバイス公開鍵PKDに、フレンドデバイス51が署名したことを示す。
 パスワード情報ATP2は、車両20とオーナーデバイス40とがペアリングする際に、セキュアチャネルを確立する際に用いられたペアリングパスワードPASを示す。有効開始時情報ATP3は、シェアキーKSを使用できる最も早い日時を示す。有効期限情報ATP4は、シェアキーKSを使用できる最も遅い日時を示す。ネーム情報ATP5は、シェアキーKSを識別する名称を示す。例えばネーム情報ATP5は、オーナーデバイス40からの操作によって、シェアデバイス50毎に、識別可能な名称として設定される。
 図1に示すように、デバイスサーバ60は、デバイス30と、管理サーバ70と、の通信を中継する。デバイスサーバ60は、デバイス30の種別ごとに設けられている。すなわち、第1種別のデバイス30が通信するデバイスサーバ60と、第2種別のデバイス30が通信するデバイスサーバ60と、は異なっている。例えば、デバイス30の種別とは、デバイス30の機種のことであり、デバイスサーバ60は、デバイス30の機種ごとに設けられている。例えば、デバイス30の種別とは、デバイス30が用いる通信回線のことであり、デバイスサーバ60は、デバイス30が用いる通信回線ごとに設けられている。いずれのデバイスサーバ60も、管理サーバ70との通信を中継するので、異なる種別のデバイス30は、デバイスサーバ60を介して管理サーバ70と通信できる。図1では、デバイスサーバ60を1つのみ図示する。
 <管理サーバ70>
 管理サーバ70は、車両20および複数のデバイス30に通信可能に構成されている。管理サーバ70は、サーバ実行装置71、サーバ記憶装置72、および通信モジュール73、を備えている。通信モジュール73は、無線通信回線を介してデバイスサーバ60に通信を行なう。また通信モジュール73は、車両20の通信モジュール21に無線通信可能に構成されている。サーバ記憶装置72はサーバプログラムPS、置き換えプログラムPM、およびデータベースDB、を記憶済である。サーバプログラムPSは、各種のサーバ処理をサーバ実行装置71に実行させることでサーバ実行装置71に、データベースDBにおけるデジタルキーの登録と、データベースDBにおけるデジタルキーの削除と、を行なわせる。置き換えプログラムPMは、各種のサーバ処理をサーバ実行装置71に実行させることでサーバ実行装置71に、認証情報単位ATの置き換えを車両記憶装置28に行なわせる命令を送信させる。サーバ実行装置71は、置き換えプログラムPMを実行することで、認証情報単位ATの置き換えに関する処理を実行する。サーバ実行装置71は、サーバ処理回路を備えている。
 データベースDBは、車両20毎にデータブロックDAに区切られている。デジタルキーが登録されている状態では、管理サーバ70は、データブロックDAに、前記デジタルキーを示すキー情報DKを記憶するデバイス30を示す情報を記憶済である。
 図4に示すように、1つの車両20のデータブロックDAは、前記車両20に登録されたデジタルキーの種類と、登録されたデバイス30と、登録されたデバイス30同士間の関係と、を含んでいる。デジタルキーの種類によって、デジタルキーの階層に優劣が定められている。デジタルキーの階層の上から順番に、オーナーキーKO、フレンドキーKF、ノンフレンドキーKNと並んでいる。
 デジタルキーの権限は、例えば、シェアキーKSの登録を要求できる数、デジタルキーの認証によって可能な車両20の制御範囲、などである。デジタルキーの階層が高いほどデジタルキーの権限が大きいので、例えば、デジタルキーが登録を要求できるシェアキーKSの数は多くなる。より具体的には、例えば、オーナーデバイス40が登録を要求できるフレンドキーKFの数は、フレンドデバイス51が登録を要求できるノンフレンドキーKNの数より多い。
 また例えば、デジタルキーの階層が高いほどデジタルキーの権限が大きいので、デジタルキーが制御可能な車両20の制御範囲は広くなる。制御可能な車両20の制御範囲は、例えば、(a)車両20のエンジンの始動制御と、(b)車両20の電源のオン制御と、(c)車両20のドアの開錠制御および施錠制御と、のうち可能な制御を示す。例えば、制御可能な車両20の制御範囲が上述の3つの制御である場合は、制御可能な車両20の制御範囲が(c)車両20のドアの開錠制御および施錠制御の1つのみの場合よりも、制御可能な車両20の制御範囲は広い。より具体的には、フレンドキーKFが制御可能な車両20の制御範囲は、上述の3つの制御である。一方で、ノンフレンドキーKNが制御可能な車両20の制御範囲は、(c)車両20のドアの開錠制御および施錠制御、の1つのみである。
 1つの車両20について、7つのデバイス30に対してデジタルキーが登録された状態を説明する。7つのデバイス30は、第1デバイス30A、第2デバイス30B、第3デバイス30C、第4デバイス30D、第5デバイス30E、第6デバイス30F、および第7デバイス30G、である。第1デバイス30Aに登録されたデジタルキーを第1デジタルキーとする。第2デバイス30Bに登録されたデジタルキーを第2デジタルキーとする。第3デバイス30Cに登録されたデジタルキーを第3デジタルキーとする。第4デバイス30Dに登録されたデジタルキーを第4デジタルキーとする。第5デバイス30Eに登録されたデジタルキーを第5デジタルキーとする。第6デバイス30Fに登録されたデジタルキーを第6デジタルキーとする。第7デバイス30Gに登録されたデジタルキーを第7デジタルキーとする。
 データブロックDAでは、デジタルキーの種類がオーナーキーKOとして登録されたデバイス30は、第1デバイス30Aである。すなわち、第1デバイス30Aは、オーナーデバイス40である。つまり、第1デジタルキーはオーナーキーKOである。
 データブロックDAでは、デジタルキーの種類がシェアキーKSとして登録されたデバイス30は、第2デバイス30B、第3デバイス30C、第4デバイス30D、第5デバイス30E、第6デバイス30F、および第7デバイス30Gである。すなわち、第2デバイス30B、第3デバイス30C、第4デバイス30D、第5デバイス30E、第6デバイス30F、および第7デバイス30Gは、シェアデバイス50である。第2デジタルキー、第3デジタルキー、第4デジタルキー、第5デジタルキー、第6デジタルキー、および第7デジタルキー、は全てシェアキーKSである。
 さらに詳細には、データブロックDAでは、デジタルキーの種類がフレンドキーKFとして登録されたデバイス30は、第2デバイス30Bおよび第5デバイス30Eである。すなわち、第2デバイス30Bおよび第5デバイス30Eは、フレンドデバイス51である。
 データブロックDAでは、デジタルキーの種類がノンフレンドキーKNとして登録されたデバイス30は、第3デバイス30C、第4デバイス30D、第6デバイス30F、および第7デバイス30G、である。すなわち、第3デバイス30C、第4デバイス30D、第6デバイス30F、および第7デバイス30Gは、ノンフレンドデバイス52である。
 データブロックDAでは、第2デバイス30Bと第1デバイス30Aとの関係は、第1デバイス30Aからの登録の要求に基づき、第2デバイス30BにフレンドキーKFが登録されている関係である。つまり、第2デジタルキーは、第1デジタルキーに基づき生成されている。
 データブロックDAでは、第5デバイス30Eと第1デバイス30Aとの関係は、第1デバイス30Aからの登録の要求に基づき、第5デバイス30EにフレンドキーKFが登録されている関係である。つまり、第5デジタルキーは、第1デジタルキーに基づき生成されている。
 データブロックDAでは、第3デバイス30Cと第2デバイス30Bとの関係は、第2デバイス30Bからの登録の要求に基づき、第3デバイス30CにノンフレンドキーKNが登録されている関係である。つまり、第3デジタルキーは、第2デジタルキーに基づき生成されている。
 データブロックDAでは、第4デバイス30Dと第2デバイス30Bとの関係は、第2デバイス30Bからの登録の要求に基づき、第4デバイス30DにノンフレンドキーKNが登録されている関係である。つまり、第4デジタルキーは、第2デジタルキーに基づき生成されている。
 データブロックDAでは、第6デバイス30Fと第5デバイス30Eとの関係は、第5デバイス30Eからの登録の要求に基づき、第6デバイス30FにノンフレンドキーKNが登録されている関係である。つまり、第6デジタルキーは、第5デジタルキーに基づき生成されている。
 データブロックDAでは、第7デバイス30Gと第5デバイス30Eとの関係は、第5デバイス30Eからの登録の要求に基づき、第7デバイス30GにノンフレンドキーKNが登録されている関係である。つまり、第7デジタルキーは、第5デジタルキーに基づき生成されている。
 このように、データブロックDAには、デジタルキーとして登録されたデバイス30が記憶済である。またデバイス30が登録された際に、登録の起因となった要求をしたデバイス30を示す情報が、デジタルキーに紐づけられている。またデータブロックDAには、各デジタルキーが、どのデジタルキーに基づき生成されているかを示す情報も含まれている。
 <デジタルキーの登録>
 次に、管理システム10における、デジタルキーの登録を行なうための一連の処理を説明する。管理システム10は、デジタルキーの登録として、オーナーキーKOの登録、フレンドキーKFの登録、およびノンフレンドキーKNの登録、を行なう。以下では、各デジタルキーが登録されていない状態から、デジタルキーが登録されている状態へと移行するまでの一連の流れを説明する。以下の説明では、車両管理装置26の車両実行装置27が実行する処理を、車両20が実行する処理として説明する。同様に以下の説明では、デバイス実行装置36が実行する処理をデバイス30が実行する処理として説明する。以下の説明では、サーバ実行装置71が実行する処理を管理サーバ70が実行する処理として説明する。
 <オーナーキーの登録>
 図5に示すように、管理システム10は、オーナーキーKOの登録を行なうべく、一連の処理を行なう。オーナーキーKOを示すキー情報DKを記憶していないデバイス30のうち、オーナーデバイス40として登録されることになるデバイス30を、第1デバイス30Aと表記する。
 管理システム10は、オーナーキーKOを登録するべく、第1デバイス30Aには、オーナーキーKOを示すキー情報DKを記憶する。管理システム10は、オーナーキーKOの登録によって、車両20には、オーナーキーKOを認証するための認証情報単位ATを記憶する。これによって、第1デバイス30Aは、オーナーデバイス40となる。オーナーキーKOの登録を行なうに際して、第1デバイス30Aには、必要なアプリケーションがインストールされていることを前提としている。
 管理サーバ70が第1デバイス30AなどからオーナーキーKOの登録要求D11を取得すると、管理サーバ70は、まず、ステップS11の処理を行なう。ステップS11では、管理サーバ70は、ペアリングパスワードPASを生成する。その後、管理サーバ70は、ペアリングパスワードPASを示す情報を、車両20および第1デバイス30Aへ送信する。
 その後、車両20は、ペアリングパスワードPASを受信する。車両20がペアリングパスワードPASを受信後、車両HMI_22を介して車両20がペアリングモードに設定されると、第1デバイス30Aからのパスワードを受信できる状態で待機する。その後、車両20は、処理をステップS12へ進める。
 ステップS12では、車両20は、第1デバイス30Aとのペアリングを行なう。ペアリングが行なわれると、車両20は、データ通信を行なうためのセキュアチャネルを、第1デバイス30Aとの間で確立する。ペアリングは、管理サーバ70から車両20と第1デバイス30Aとへ送信されたペアリングパスワードPASを用いて行なわれる。ペアリングが完了すると、車両20は、処理をステップS13へ進める。
 ステップS13では、車両20は、車両20の公開鍵である車両公開鍵PKVと、車両20の秘密鍵である車両秘密鍵SKVと、を生成する。その後、車両20は、セキュアチャネルを介して、オーナーキーKOを生成するための生成データDCを、第1デバイス30Aへ送信する。生成データDCは、車両識別情報ST1と、車両公開鍵PKVを示す車両公開鍵情報と、を備えている。その後、第1デバイス30Aは、生成データDCを受信する。その後、第1デバイス30Aは、処理をステップS14へ進める。
 ステップS14では、第1デバイス30Aは、オーナーキーKOを示すオーナーキー情報DKOを生成する。その後、第1デバイス30Aは、処理をステップS15へ進める。
 ステップS15では、第1デバイス30Aは、オーナーキー情報DKOを記憶する。これによって、第1デバイス30Aは、オーナーデバイス40となる。すなわち、登録要求D11は、デバイス30にキー情報DKとしてのオーナーキー情報DKOを記憶させるための要求である。その後、第1デバイス30Aは、オーナーキーKOに関する証明書情報ST5と、デバイス公開鍵PKDを示すデバイス公開鍵情報ST6と、を車両20へ送信する。
 その後、車両20が証明書情報ST5と、デバイス公開鍵情報ST6と、を受信すると、車両20は、ステップS16の処理を行なう。ステップS16では、車両20は、証明書情報ST5を検証する。証明書情報ST5の検証が完了すると、車両20は、処理をステップS17へ進める。
 ステップS17では、車両20は、デバイス公開鍵PKDを示すデバイス公開鍵情報ST6を、認証情報単位ATとして記憶する。その後、車両20は、認証情報単位ATの記憶が完了したことを示す完了通知M11を、第1デバイス30Aへ送信する。
 その後、第1デバイス30Aが完了通知M11を受信すると、第1デバイス30Aは、ステップS18の処理を行なう。ステップS18では、第1デバイス30Aは、オーナーキーKOのキートラック要求D12を生成する。キートラック要求D12は、管理サーバ70に対して、データベースDBの更新を要求するための信号である。第1デバイス30Aは、デバイスサーバ60を介して、オーナーキーKOのキートラック要求D12を管理サーバ70へ送信する。
 その後、管理サーバ70は、キートラック要求D12を受信すると、ステップS19の処理を行なう。ステップS19では、管理サーバ70は、オーナーキーKOの登録管理を行なう。具体的には管理サーバ70は、データベースDBにおける車両20のデータブロックDAに、オーナーキーKOとして登録されたデバイス30として、第1デバイス30Aを記憶する。これによって、管理システム10は、オーナーキーKOの登録の一連の処理を終了する。
 <フレンドキーKFの登録>
 図6に示すように、管理システム10は、フレンドキーKFの登録を行なうべく、一連の処理を行なう。フレンドキー情報DKFを記憶していないデバイス30のうち、当該一連の処理によってフレンドデバイス51として登録されることになるデバイス30を、第2デバイス30Bと表記する。
 オーナーデバイス40において、フレンドキーKFの登録を要求する操作が実行されることによって、まず、オーナーデバイス40は、ステップS21の処理を行なう。ステップS21では、オーナーデバイス40は、フレンドキーKFの登録要求D21を、図示を省略するリレーサーバへ送信する。その後、オーナーデバイス40は、処理をステップS22へ進める。
 ステップS22では、オーナーデバイス40は、デジタルキーをシェアするための招待情報IV1を、リレーサーバから取得する。招待情報IV1は、例えば、URLリンクである。URLリンクには、デジタルキーをシェアするべく必要なシェア情報SH1が格納されている。その後、オーナーデバイス40は、招待情報IV1を第2デバイス30Bへ送信する。
 その後、第2デバイス30Bは、招待情報IV1を受信すると、ステップS23の処理を行なう。ステップS23では、第2デバイス30Bは、招待情報IV1に基づき、シェア情報SH1を取得する。具体的には、第2デバイス30Bは、URLリンクのリンク元から、シェア情報SH1をダウンロードする。
 シェア情報SH1は、例えば、シェアキー構造情報STS、パスワード情報ATP2、有効開始時情報ATP3、有効期限情報ATP4、およびネーム情報ATP5、を含んでいる。有効開始時情報ATP3、有効期限情報ATP4、およびネーム情報ATP5、はオーナーデバイス40によって設定される。その後、第2デバイス30Bは、処理をステップS24へ進める。
 ステップS24では、第2デバイス30Bは、シェア情報SH1を用いて署名なしフレンドキー情報DKFNを生成する。署名なしフレンドキー情報DKFNは、署名情報ATP1を有しないフレンドキー情報DKFである。具体的には、第2デバイス30Bは、取得済のシェア情報SH1に含まれる各情報を、署名なしフレンドキー情報DKFNの各情報として生成する。その後、第2デバイス30Bは、生成した署名なしフレンドキー情報DKFNをURLリンクにアップロード完了したことを示す完了通知M21と、署名を要求する署名要求D22と、をオーナーデバイス40へ送信する。
 その後、オーナーデバイス40は、第2デバイス30Bから、完了通知M21と、署名要求D22と、を受信する。オーナーデバイス40は、完了通知M21を受信すると、署名なしフレンドキー情報DKFNを取得する。オーナーデバイス40は、署名要求D22を受信すると、オーナーデバイス40が操作されることによってステップS25の処理を行なう。
 ステップS25では、オーナーデバイス40は、署名情報ATP1を生成する。詳細には、オーナーデバイス40は、取得済の署名なしフレンドキー情報DKFNを、デバイスHMI_32に提示させるとともに、オーナーデバイス40のユーザがフレンドキーKFの登録に同意することを示す操作を受け付ける。同意操作が行なわれると、オーナーデバイス40は、同意操作が行なわれたことに基づき署名を取得する。その後、オーナーデバイス40は、処理をステップS26へ進める。
 ステップS26では、オーナーデバイス40は、署名なしフレンドキー情報DKFNに、署名情報ATP1を加える。これによって、オーナーデバイス40は、フレンドキー情報DKFを生成する。その後、オーナーデバイス40は、生成したフレンドキー情報DKFを、招待情報IV1であるURLリンクへアップロードする。オーナーデバイス40は、完成したフレンドキー情報DKFをURLリンクにアップロード完了したことを示す完了通知M22を、第2デバイス30Bへ送信する。
 その後、第2デバイス30Bは、完了通知M22を取得する。その後、第2デバイス30Bは、ステップS27の処理を行なう。ステップS27では、第2デバイス30Bは、フレンドキー情報DKFをダウンロードするとともに記憶する。これによって、第2デバイス30Bは、フレンドデバイス51となる。その後、第2デバイス30Bは、処理をステップS28へ進める。
 ステップS28では、第2デバイス30Bは、フレンドキーKFのキートラック要求D23を生成する。第2デバイス30Bは、フレンドキー情報DKFと、フレンドキーKFのキートラック要求D23と、を管理サーバ70へ送信する。
 その後、管理サーバ70がフレンドキーKFのキートラック要求D23を受信すると、管理サーバ70は、ステップS29の処理を行なう。ステップS29では、管理サーバ70は、フレンドキーKFの登録管理を行なう。キートラック要求D23は、新たな認証情報単位ATを車両20に記憶させるための要求である。
 具体的には登録管理として、管理サーバ70は、キートラック要求D23の対象であるフレンドキーKFが、拒否リストに掲載されていないことを確認する。拒否リストは、既に削除要求を受信済のフレンドキーKFおよびノンフレンドキーKNを備えているシェアキーKSを示すリストである。フレンドキーKFが拒否リストに掲載されている場合、管理サーバ70は、キートラック要求D23には応えられない通知を、第2デバイス30Bへ送信する。
 一方で、キートラック要求D23を受信済のフレンドキーKFが拒否リストに掲載されていない場合、管理サーバ70は、キートラック要求D23を受信済のフレンドキーKFを、データベースDBに登録する。詳細には、管理サーバ70は、データベースDBにおける車両20のデータブロックDAに、フレンドデバイス51として登録されたデバイス30として、第2デバイス30Bを記憶する。管理サーバ70は、取得済のフレンドキー情報DKFを参照して、第2デバイス30Bとオーナーデバイス40との関係を記憶する。
 その後、管理サーバ70は、フレンドキー情報DKFに含まれる認証パッケージATPと、前記認証パッケージATPの記憶を要求するための記憶要求D24と、を車両20へ送信する。すなわち、管理サーバ70は、フレンドデバイス51のデバイス公開鍵PKDを示すデバイス公開鍵情報ST6を、車両20へ送信する。また管理サーバ70は、前記デバイス公開鍵PKDにオーナーデバイス40の署名がされていることを、車両20へ通知する。
 その後、車両20は、管理サーバ70から、記憶要求D24および認証パッケージATPを受信すると、ステップS30の処理を行なう。ステップS30では、車両20は、受信済の認証パッケージATPを、フレンドキーKFを認証するための認証情報単位ATとして記憶する。
 また管理サーバ70は、登録管理が完了した後、キートラックの完了通知M23を第2デバイス30Bへ送信する。
 その後、第2デバイス30Bは、キートラックの完了通知M23を受信すると、ステップS31の処理を行なう。ステップS31の処理では、第2デバイス30Bは、フレンドキーKFの登録完了を示す情報を、デバイスHMI_32に提示する。例えば、第2デバイス30Bは、フレンドキーKFの登録完了を示す画像を、デバイスHMI_32に表示する。これによって、管理システム10は、フレンドキーKFの登録の一連の処理を終了する。
 <ノンフレンドキーKNの登録>
 図7に示すように、管理システム10は、ノンフレンドキーKNの登録を行なうべく、一連の処理を行なう。ノンフレンドキー情報DKNを記憶していないデバイス30のうち、当該一連の処理によってノンフレンドデバイス52として登録されることになるデバイス30を、第3デバイス30Cと表記する。
 フレンドデバイス51においてノンフレンドキーKNの登録を要求する操作が実行されることによって、まず、フレンドデバイス51は、ステップS41の処理を行なう。ステップS41では、フレンドデバイス51は、ノンフレンドキーKNの登録要求D31を、図示を省略するリレーサーバへ送信する。その後、フレンドデバイス51は、処理をステップS42へ進める。
 ステップS42では、フレンドデバイス51は、デジタルキーをシェアするための招待情報IV2を、リレーサーバから取得する。招待情報IV2は、例えば、URLリンクである。URLリンクには、デジタルキーをシェアするべく必要なシェア情報SH2が格納されている。その後、フレンドデバイス51は、招待情報IV2を第3デバイス30Cへ送信する。
 その後、第3デバイス30Cは、招待情報IV2を受信すると、ステップS43の処理を行なう。ステップS43では、第3デバイス30Cは、招待情報IV2に基づき、シェア情報SH2を取得する。具体的には、第2デバイス30Bは、URLリンクから、シェア情報SH2をダウンロードする。
 シェア情報SH2は、例えば、シェアキー構造情報STS、パスワード情報ATP2、有効開始時情報ATP3、有効期限情報ATP4、およびネーム情報ATP5、を含んでいる。有効開始時情報ATP3、有効期限情報ATP4、およびネーム情報ATP5、はフレンドデバイス51によって設定される。その後、第3デバイス30Cは、処理をステップS44へ進める。
 ステップS44では、第3デバイス30Cは、シェア情報SH2を用いて署名なしノンフレンドキー情報DKNNを生成する。署名なしノンフレンドキー情報DKNNは、署名情報ATP1を有しないノンフレンドキー情報DKNである。具体的には、第3デバイス30Cは、取得済のシェア情報SH2に含まれる各情報を、署名なしノンフレンドキー情報DKNNの各情報として生成する。その後、第3デバイス30Cは、生成した署名なしノンフレンドキー情報DKNNをURLリンクにアップロード完了したことを示す完了通知M31と、署名を要求する署名要求D32と、をフレンドデバイス51へ送信する。
 その後、フレンドデバイス51は、第3デバイス30Cから、完了通知M31と、署名要求D32と、を受信する。フレンドデバイス51は、完了通知M31を受信すると、署名なしノンフレンドキー情報DKNNを取得する。フレンドデバイス51は、署名要求D32を受信すると、フレンドデバイス51が操作されることによってステップS45の処理を行なう。
 ステップS45では、フレンドデバイス51は、署名情報ATP1を生成する。詳細には、フレンドデバイス51は、取得済の署名なしノンフレンドキー情報DKNNを、デバイスHMI_32に提示させるとともに、フレンドデバイス51のユーザがノンフレンドキーKNの生成に同意することを示す操作を受け付ける。同意操作が行なわれると、フレンドデバイス51は、同意操作が行なわれたことに基づき署名を取得する。その後、フレンドデバイス51は、処理をステップS46へ進める。
 ステップS46では、フレンドデバイス51は、署名なしノンフレンドキー情報DKNNに、署名情報ATP1を加える。これによって、フレンドデバイス51は、ノンフレンドキー情報DKNを生成する。その後、フレンドデバイス51は、生成したノンフレンドキー情報DKNを、招待情報IV2であるURLリンクへアップロードする。フレンドデバイス51は、完成したノンフレンドキー情報DKNをURLリンクにアップロード完了したことを示す完了通知M32を、第3デバイス30Cへ送信する。
 その後、第3デバイス30Cは、完了通知M32を取得する。その後、第3デバイス30Cは、ステップS47の処理を行なう。ステップS47では、第3デバイス30Cは、ノンフレンドキー情報DKNをダウンロードして記憶する。これによって、第3デバイス30Cは、ノンフレンドデバイス52となる。その後、第3デバイス30Cは、処理をステップS48へ進める。
 ステップS48では、第3デバイス30Cは、ノンフレンドキーKNのキートラック要求D33を生成する。第3デバイス30Cは、ノンフレンドキー情報DKNと、ノンフレンドキーKNのキートラック要求D33と、を管理サーバ70へ送信する。
 その後、管理サーバ70がノンフレンドキーKNのキートラック要求D33を受信すると、管理サーバ70は、ステップS49の処理を行なう。ステップS49では、管理サーバ70は、ノンフレンドキーKNの登録管理を行なう。
 具体的には登録管理として、管理サーバ70は、キートラック要求D33の対象であるノンフレンドキーKNが、拒否リストに掲載されていないことを確認する。ノンフレンドキーKNが拒否リストに掲載されている場合、管理サーバ70は、キートラック要求D33には応えられない通知、を第3デバイス30Cへ送信する。
 一方で、ノンフレンドキーKNが拒否リストに掲載されていない場合、管理サーバ70は、キートラック要求D33の対象であるノンフレンドキーKNを、データベースDBに登録する。詳細には、管理サーバ70は、データベースDBにおける車両20のデータブロックDAに、ノンフレンドデバイス52として登録されたデバイス30として、第3デバイス30Cを記憶する。管理サーバ70は、取得済のノンフレンドキー情報DKNを参照して、第3デバイス30Cとフレンドデバイス51との関係を記憶する。具体的には、管理サーバ70は、第3デバイス30Cを、第2デバイス30Bからの登録要求D31によって登録されたノンフレンドキーKNを有しているデバイス30として記憶する。
 その後、管理サーバ70は、ノンフレンドキー情報DKNに含まれる認証パッケージATPと、前記認証パッケージATPの記憶を要求するための記憶要求D34と、を車両20へ送信する。すなわち、管理サーバ70は、ノンフレンドデバイス52のデバイス公開鍵PKDを示すデバイス公開鍵情報ST6を、車両20へ送信する。また管理サーバ70は、前記デバイス公開鍵PKDにフレンドデバイス51の署名がされていることを、車両20へ通知する。
 その後、車両20が、認証パッケージATPおよび記憶要求D34を受信すると、ステップS50の処理を行なう。ステップS50では、車両20は、受信済の認証パッケージATPを記憶する。すなわち、車両20は、認証パッケージATPを、ノンフレンドキーKNを認証するための認証情報単位ATとして記憶する。
 また管理サーバ70は、登録管理が完了した後、キートラックの完了通知M33を第2デバイス30Bへ送信する。
 その後、第2デバイス30Bは、キートラックの完了通知M33を受信すると、ステップS51の処理を行なう。ステップS51の処理では、第3デバイス30Cは、ノンフレンドキーKNの登録完了を示す情報を、デバイスHMI_32に提示する。例えば、第3デバイス30Cは、ノンフレンドキーKNの登録完了を示す画像を、デバイスHMI_32に表示する。これによって、管理システム10は、ノンフレンドキーKNの登録の一連の処理を終了する。
 <ノンフレンドキーKNの削除>
 次に、管理システム10における、ノンフレンドキーKNを削除するための一連の処理を説明する。以下では、ノンフレンドキーKNが登録されている状態から、ノンフレンドキーKNが登録されていない状態へと移行するまでの一連の流れを説明する。以下の説明では、車両実行装置27が実行する処理を、車両20が実行する処理として説明する.同様に、デバイス実行装置36が実行する処理を、デバイス30が実行する処理として、サーバ実行装置71が実行する処理を、管理サーバ70が実行する処理として、各々説明する。
 <フレンドデバイス51からの削除予約D41によるノンフレンドキーKNの削除>
 図8に示すように、管理システム10は、フレンドデバイス51からの削除予約D41に基づきノンフレンドキーKNを削除するべく、一連の処理を行なう。
 フレンドデバイス51においてノンフレンドキーKNの削除を要求する操作が実行されることによって、まず、フレンドデバイス51は、ステップS61の処理を行なう。ステップS61では、ノンフレンドキーKNの削除予約D41を生成する。削除予約D41は、ノンフレンドキーKNの削除を予約するための指令である。
 削除予約D41は、ノンフレンドキーKNの削除を要求するための信号、ノンフレンドキーKNを示すデジタルキー識別情報ST3、および既定条件RCを示す情報、を備えている。既定条件RCは、削除予約D41を受信後にノンフレンドキーKNの削除を始めるべく必要な条件である。既定条件RCは、予め定められている。既定条件RCは、例えば、削除予約D41を受信してから予め定められたフェードアウト期間を経過したことである。フレンドデバイス51は、ノンフレンドキーKNの削除予約D41を管理サーバ70へ送信する。
 その後、管理サーバ70は、ノンフレンドキーKNの削除予約D41を受信すると、ステップS62の処理を行なう。ステップS62では、管理サーバ70は、削除予約D41にしたがって保留中通知M41を生成する。管理サーバ70は、保留中通知M41をフレンドデバイス51へ送信する。
 その後、フレンドデバイス51が保留中通知M41を受信すると、フレンドデバイス51は、ステップS63の処理を行なう。ステップS63では、フレンドデバイス51は、削除予約D41の対象であるノンフレンドキーKNの削除を保留中であることを示す情報を、デバイスHMI_32に提示する。
 ステップS62の処理の後、管理サーバ70は、ステップS64の処理を行なう。ステップS64では、管理サーバ70は、データベースDBにおいて、削除予約D41の対象であるノンフレンドキーKNの状態をフェードアウト状態として記憶する。フェードアウト状態は、削除予約D41を受信しているものの、まだ削除の実行を保留している状態である。その後、管理サーバ70は、処理をステップS65へ進める。
 ステップS65では、管理サーバ70は、既定条件RCを満たすことを確認する。管理サーバ70が既定条件RCを満たすことを確認すると、管理サーバ70は、処理をステップS66へ進める。
 ステップS66では、管理サーバ70は、削除予約D41の対象であるノンフレンドキーKNを示すノンフレンドキー情報DKNを削除するための削除要求D42を生成する。管理サーバ70は、削除要求D42をノンフレンドデバイス52へ送信する。
 その後、ノンフレンドデバイス52が削除要求D42を受信すると、ステップS67の処理を行なう。ステップS67では、ノンフレンドデバイス52は、削除要求D42にしたがって、ノンフレンドキー情報DKNを削除する。ノンフレンドデバイス52は、削除要求D42にしたがった削除が完了したことを示す削除完了通知M42を、管理サーバ70へ送信する。
 その後、管理サーバ70が完了通知M42を受信すると、管理サーバ70は、ステップS68の処理を行なう。ステップS68では、管理サーバ70は、ノンフレンドデバイス52におけるノンフレンドキー情報DKNを削除した履歴を記憶する。その後、管理サーバ70は、処理をステップS69へ進める。
 ステップS69では、管理サーバ70は、認証情報単位ATの削除要求D43を生成する。認証情報単位ATの削除要求D43は、削除予約D41の対象であるノンフレンドキーKNが認証されるときに必要であった認証情報単位ATを、削除する要求を示す。管理サーバ70は、削除要求D43を車両20へ送信する。
 その後、車両20が削除要求D43を受信すると、車両20は、ステップS70の処理を行なう。ステップS70では、車両20は、削除要求D43にしたがって、削除予約D41の対象であるノンフレンドキーKNが認証されるときに必要であった認証情報単位ATを、削除する。すなわち、車両20は、ノンフレンドキーKNの認証パッケージATPを削除する。その後、車両20は、削除要求D43にしたがった認証情報単位ATの削除が完了したことを示す削除完了通知M43を、管理サーバ70へ送信する。
 その後、管理サーバ70が完了通知M43を受信すると、管理サーバ70は、ステップS71の処理を行なう。ステップS71では、管理サーバ70は、車両20における今回の一連の削除に関する処理で削除される対象であるノンフレンドキーKNが認証されるときに必要であった認証情報単位ATを、削除した履歴を記憶する。その後、管理サーバ70は、処理をステップS72へ進める。
 ステップS72では、管理サーバ70は、データベースDBを更新する。具体的には、管理サーバ70は、データベースDBにおける車両20のデータブロックDAから、今回の一連の処理の削除対象であるノンフレンドキーKNを有しているノンフレンドデバイス52を、削除する。その後、管理サーバ70は、削除予約D41にしたがったノンフレンドキーKNの一連の削除が完了したことを示す削除完了通知M44を、フレンドデバイス51へ送信する。
 その後、フレンドデバイス51が完了通知M44を受信すると、フレンドデバイス51は、ステップS73の処理を行なう。ステップS73では、フレンドデバイス51は、削除予約D41の対象であるノンフレンドキーKNの削除が完了したことを示す情報を、デバイスHMI_32に提示する。例えば、フレンドデバイス51は、ノンフレンドキーKNの削除完了を示す画像を、デバイスHMI_32に表示する。その後、管理システム10は、今回のノンフレンドキーKNの削除についての一連の処理を終了する。
 <ノンフレンドデバイス52における削除起因によるノンフレンドキーKNの削除>
 図9に示すように、管理システム10は、ノンフレンドデバイス52における削除操作に起因して、前記ノンフレンドデバイス52が記憶中のノンフレンドキー情報DKNが示すノンフレンドキーKNを削除するべく一連の処理を行なう。
 ノンフレンドデバイス52においてノンフレンドキーKNの削除を要求する所定操作が実行されることによって、まず、ノンフレンドデバイス52は、ステップS81の処理を行なう。ステップS81では、ノンフレンドデバイス52は、所定操作にしたがって、ノンフレンドキー情報DKNを削除する。その後、ノンフレンドデバイス52は、ノンフレンドキー情報DKNが削除されたことを示す削除完了通知M51を、管理サーバ70へ送信する。
 その後、管理サーバ70が完了通知M51を受信すると、管理サーバ70は、ステップS82の処理を行なう。ステップS82では、管理サーバ70は、ノンフレンドデバイス52におけるノンフレンドキー情報DKNを削除した履歴を記憶する。その後、管理サーバ70は、ノンフレンドキー情報DKNが削除されたことを示す削除完了通知M52を、フレンドデバイス51へ送信する。
 その後、フレンドデバイス51が完了通知M52を受信すると、フレンドデバイス51は、ステップS83の処理を行なう。ステップS83では、フレンドデバイス51は、ノンフレンドデバイス52のノンフレンドキー情報DKNの削除が完了したことを示す情報を、デバイスHMI_32に提示する。例えば、フレンドデバイス51は、ノンフレンドキーKNの削除完了を示す画像を、デバイスHMI_32に表示する。
 ステップS82の処理の後、管理サーバ70は、ステップS84の処理を行なう。ステップS84では、管理サーバ70は、ステップS81で削除完了済のノンフレンドキー情報DKNが認証されるときに必要であった認証情報単位ATを、削除するための削除要求D51を生成する。管理サーバ70は、削除要求D51を車両20へ送信する。
 その後、車両20が削除要求D51を受信すると、車両20は、ステップS85の処理を行なう。ステップS85では、車両20は、削除要求D51にしたがって、ステップS81で削除完了済のノンフレンドキー情報DKNが認証されるときに必要であった認証情報単位ATを、削除する。車両20は、削除要求D51にしたがった認証情報単位ATの削除が完了したことを示す完了通知M53を、管理サーバ70へ送信する。
 その後、管理サーバ70が完了通知M53を受信すると、管理サーバ70は、ステップS86の処理を行なう。ステップS86では、管理サーバ70は、ステップS81で削除完了済のノンフレンドキー情報DKNが認証されるときに必要であった認証情報単位ATを、削除した履歴を記憶する。その後、管理サーバ70は、処理をステップS87へ進める。
 ステップS87では、管理サーバ70は、データベースDBを更新する。具体的には、管理サーバ70は、データベースDBにおける車両20のデータブロックDAから、今回の一連の処理の削除対象であるノンフレンドキーKNを有しているノンフレンドデバイス52を削除する。これによって、管理システム10は、今回のノンフレンドキーKNの削除についての一連の処理を終了する。
 <車両管理装置26による認証情報単位ATの置き換え>
 さて、車両記憶装置28が記憶することが可能に構成されている認証情報単位ATの数には、限りがある。換言すれば、車両記憶装置28が記憶可能な認証情報量には、上限がある。車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATを受信したとき、次の処理を行なう。つまり車両20は、新たな認証情報単位ATを、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかの代わりに記憶する。
 具体的には、車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たに認証情報単位ATが受信されたとき、次の処理を行なう。つまり車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを、削除する。その後、車両20は、受信済の新たな認証情報単位ATを、車両記憶装置28に記憶する。
 <車両20が実行する一連の処理>
 図10は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATを受信したとき、管理システム10における車両20が実行する一連の処理の流れを示す説明図である。
 図1に示すように、車両20において、車両記憶装置28は、車両プログラムPVを記憶済である。車両実行装置27は、車両記憶装置28に記憶済の車両プログラムPVを実行する。これによって、車両20は一連の処理を実行する。
 図10に示す第3デバイス30Cは、ノンフレンドキー情報DKNを記憶していない1つまたは複数のデバイス30のうち、当該一連の処理によってノンフレンドデバイス52とされるデバイス30である。図示しないフレンドデバイス51において、第3デバイス30Cに対するノンフレンドキーKNの登録要求操作が実行されることによって、管理システム10は、ノンフレンドキーKNの登録を行なうべく、図7に示す一連の処理を行なう。
 図10に示すステップS101は、図7に示すステップS47とで同様である。ステップS101の処理の後、第3デバイス30Cは、ステップS102の処理を行なう。図10に示すステップS102の処理は、図7に示すステップS48とで同様である。第3デバイス30Cは、管理サーバ70へ、ノンフレンドキー情報DKNと、ノンフレンドキーKNのキートラック要求D33と、を送信する。
 その後、管理サーバ70がノンフレンドキーKNのキートラック要求D33を受信すると、管理サーバ70は、ステップS103の処理を行なう。ステップS103では、図7に示すステップS49とで同様に、管理サーバ70は、ノンフレンドキーKNの登録管理を行なう。ステップS103の処理として、管理サーバ70は、ノンフレンドキー情報DKNに含まれる認証パッケージATPと、前記認証パッケージATPを記憶するための記憶要求D34と、を車両20へ送信する。加えて、管理サーバ70は、車両20についてのデータベースDBにおいてフェードアウト状態として記憶済のデジタルキーが存在する場合、フェードアウト状態となっているデジタルキーの情報を車両20へと送信する。車両20についてのデータベースDBにおいてフェードアウト状態として記憶済のデジタルキーが存在する場合というのは、削除予約D41が未執行のまま残っている状態である。
 その後、車両20が、認証パッケージATPと、記憶要求D34と、を受信すると、車両20はステップS104の処理を行なう。このとき、車両20は、車両20についてのデータベースDBにおいてフェードアウト状態として記憶済のデジタルキーが存在する場合、フェードアウト状態となっているデジタルキーの情報を受信する。
 <削除されるべき認証情報単位ATの選択>
 ステップS104では、車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかから、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPによって置き換えられるべき認証情報単位ATを選択する。すなわち、ステップS104では、車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかから、削除されるべき認証情報単位ATを選択する。車両20が前記認証情報単位ATを選択する処理については後述する。車両20が第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPによって置き換えられるべき認証情報単位ATを選択すると、車両20はステップS105の処理を行なう。
 図11は、ステップS104において車両20が行なう、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPによって置き換えられるべき認証情報単位ATを選択する処理を示すフローチャートである。車両20は、ステップS104の処理として、この一連の処理を行なう。
 <フェードアウト状態の判定>
 図11に示すように、この一連の処理を開始すると、車両20は、ステップS200において、削除予約D41が残っているかを判定する。車両20は、車両記憶装置28がフェードアウト状態の1つまたは複数のデジタルキーの認証情報単位ATを記憶済の場合、削除予約D41が残っていると判定する。削除予約D41が残っている場合(ステップS200:YES)、車両20は、処理をステップS210に進める。
 ステップS210では、車両20は、複数の削除予約D41が残っているか否かを判定する。車両20は、車両記憶装置28がフェードアウト状態の複数のデジタルキーの認証情報単位ATを記憶済の場合、複数の削除予約D41が残っていると判定する。複数の削除予約D41が残っている場合(ステップS210:YES)、車両20は、処理をステップS220へ進める。
 ステップS220では、車両20は、車両記憶装置28が記憶済のフェードアウト状態の複数のデジタルキーの認証情報単位ATを全て削除する。これによって、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数は、記憶可能な既定数未満となる。その後、車両20は、図11に示す一連の処理を終了する。車両20は、図11に示す一連の処理を終了した後、図10に示すステップS105の処理を行なう。
 車両記憶装置28がフェードアウト状態のデジタルキーの認証情報単位ATを1つのみ記憶済の場合、すなわち残っている削除予約D41が複数ではない場合(ステップS210:NO)、車両管理装置26は、処理をステップS230へ進める。
 ステップS230では、車両管理装置26は、前記フェードアウト状態のデジタルキーの認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、車両20は、図11に示す一連の処理を終了する。車両20は、図11に示す一連の処理を終了した後、図10に示すステップS105の処理を行なう。
 ステップS200の処理では、削除予約D41が残っていない場合(ステップS200:NO)、車両20は、処理をステップS240に進める。
 <プロテクト対象として選択済の認証情報単位ATが存在するか否かの判定>
 車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうち、プロテクト対象にされる認証情報単位ATを選択することが可能に構成されている。例えば、車両20のユーザは、車両20の車両HMI_22を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATをプロテクト対象として選択することができる。例えば、車両20のユーザは、オーナーデバイス40のデバイスHMI_32を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATをプロテクト対象として選択することができる。例えば、車両20のユーザは、フレンドデバイス51のデバイスHMI_32を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATをプロテクト対象として選択することができる。例えば、車両20のユーザは、ノンフレンドデバイス52のデバイスHMI_32を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATをプロテクト対象として選択することができる。
 ステップS240では、車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかに、プロテクト対象として選択済の認証情報単位ATが存在するか否かを判定する。プロテクト対象として選択済の認証情報単位ATが存在する場合(ステップS240:YES)、車両20は、処理をステップS250に進める。ステップS250では、車両20は、以降の処理において、プロテクト対象としては未選択の認証情報単位ATのなかから、削除されるべき認証情報単位ATを選択することを決定する。その後、車両20は、処理をステップS260に進める。プロテクト対象として選択済の認証情報単位ATが存在しない場合(ステップS240:NO)、車両20は、処理をステップS260に進める。
 <認証情報単位ATに優先順位が設定されているか否かの判定>
 車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定可能に構成されている。例えば、車両20のユーザは、車両20の車両HMI_22を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できる。例えば、車両20のユーザは、オーナーデバイス40のデバイスHMI_32を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できる。例えば、車両20のユーザは、フレンドデバイス51のデバイスHMI_32を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できる。例えば、車両20のユーザは、ノンフレンドデバイス52のデバイスHMI_32を介して、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できる。
 ステップS260では、車両20は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATに対して、優先順位が設定されているか否かを判定する。車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATに対して、優先順位が設定されている場合(ステップS260:YES)、車両20は処理をステップS270に進める。
 ステップS270では、車両20は、車両記憶装置28が、優先順位が異なる複数の認証情報単位ATを記憶済か否かを判定する。車両記憶装置28が、優先順位が異なる複数の認証情報単位ATを記憶済の場合(ステップS270:YES)、車両20は処理をステップS280に進める。
 ステップS280では、車両20は、優先順位に基づき、削除されるべき認証情報単位ATを選択する。例えば、車両20は、優先順位が最も低い認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、車両20は、図11に示す一連の処理を終了する。車両20は、図11に示す一連の処理を終了した後、図10に示すステップS105の処理を行なう。
 図11に示すステップS260の処理では、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATに対して、優先順位が設定されていない場合(ステップS260:NO)、車両20は処理をステップS290に進める。ステップS270の処理では、車両記憶装置28が、優先順位が異なる複数の認証情報単位ATを記憶していない場合(ステップS270:NO)、車両20は処理をステップS290に進める。
 <ノンフレンドキーKNの認証情報単位ATを記憶済か否かの判定>
 ステップS290では、車両20は、車両記憶装置28がノンフレンドキーKNの認証情報単位ATを記憶済か否かを判定する。車両記憶装置28がノンフレンドキーKNの認証情報単位ATを記憶済の場合(ステップS290:YES)、車両20は処理をステップS300に進める。
 ステップS300では、車両管理装置26は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATのうち、ノンフレンドキー情報DKNに対応する認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、車両20は、図11に示す一連の処理を終了する。車両20は、図11に示す一連の処理を終了した後、図10に示すステップS105の処理を行なう。
 ステップS290では、車両記憶装置28がノンフレンドキーKNの認証情報単位ATを記憶していない場合(ステップS290:NO)、車両20は処理をステップS310に進める。ステップS310では、車両20は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATのうち、最後に使用された日付が最も古いシェアキー情報DKSに対応する認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、車両20は、図11に示す一連の処理を終了する。車両20は、図11に示す一連の処理を終了した後、図10に示すステップS105の処理を行なう。
 <認証情報単位ATの置き換え>
 図10に示すステップS105では、車両20は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの代わりに記憶する。具体的には、車両20は、ステップS105において選択済の認証情報単位ATを、車両記憶装置28から削除する。その後、車両20は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、第3デバイス30CのノンフレンドキーKNを認証するための認証情報単位ATとして記憶する。
 ステップS220の処理を行なった場合、車両20は、車両記憶装置28が記憶済のフェードアウト状態の複数のデジタルキーの認証情報単位ATを、全て削除する。これによって、ステップS104において、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数は、記憶可能な既定数未満となる。ステップS105の処理時に、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達していない場合、ステップS105では、車両20は、認証情報単位ATを車両記憶装置28から削除しない。この場合、車両20は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、第3デバイス30CのノンフレンドキーKNを認証するための認証情報単位ATとして記憶する。
 <認証情報単位ATを置き換えた後の処理>
 車両20は、ステップS105の処理を行なった後、処理をステップS106に進める。ステップS106では、車両20は完了通知M61を生成する。完了通知M61は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPが、ステップS104において車両管理装置26が選択した認証情報単位ATであるとともに車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの代わりに、記憶されたことを示す信号を備えている。車両管理装置26は、完了通知M61を管理サーバ70へ送信する。
 管理サーバ70が完了通知M61を受信すると、管理サーバ70は、ステップS107の処理を行なう。ステップS107では、管理サーバ70は、完了通知M62を生成する。完了通知M62は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、第3デバイス30CのノンフレンドキーKNを認証するための認証情報単位ATとして車両記憶装置28が記憶したことを示す情報を備えている。管理サーバ70は、完了通知M62を第3デバイス30Cに向けて送信する。
 第3デバイス30Cが完了通知M62を受信すると、第3デバイス30CはステップS108の処理を行なう。ステップS108では、ノンフレンドデバイス52は、車両20への第3デバイス30CのノンフレンドキーKNの登録が完了したことを示す登録完了の情報を、デバイスHMI_32に提示する。その後、管理システム10は、今回の認証情報単位ATの置き換えについての一連の処理を終了する。
 <第1実施形態の作用>
 車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が既定数に達している状態で、新たに認証情報単位ATが受信されたとき、ユーザによる介入無しに、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除する。認証情報単位ATは、デジタルキー情報単位である。
 <第1実施形態の効果>
 (1-1)上記の車両管理装置26によれば、新たな認証情報単位ATが記憶されるときに、前記車両20が記憶済の1つまたは複数の認証情報単位ATのなかから、どの認証情報単位ATを削除するのかを車両20のユーザが選択しなくてよくなる。すなわち、車両管理装置26は、車両20のユーザの負担を軽減することが可能に構成されている。
 (1-2)以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているとともに、既定条件RCが成立したときに、1つまたは複数の削除予約D41が未執行のまま残っている場合を説明する。削除予約D41は、対象情報である認証情報単位ATの削除を執行するための指令である。この場合、車両管理装置26は、新たな認証情報単位ATを受信したとき、未執行の削除予約D41の対象である認証情報単位ATを、車両記憶装置28から削除する。その後、車両管理装置26は、新たな認証情報単位ATを車両記憶装置28に記憶させる。つまり、車両管理装置26は、削除される認証情報として、削除されることが予定されているデジタルキーを認証するための認証情報単位ATを選択する。これによって、車両管理装置26は、削除されることが予定されていないデジタルキーを認証するための認証情報単位ATを記憶したまま、新たな認証情報単位ATを記憶することが可能に構成されている。
 (1-3)以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているとともに、複数の削除予約D41が未執行のまま残っている場合を説明する。この場合、車両管理装置26は、新たな認証情報単位ATを受信したとき、未執行のまま残っている削除予約D41の対象である認証情報単位ATを全て削除する。その後、車両管理装置26は、新たな認証情報単位ATを車両記憶装置28に記憶させる。これによって、車両管理装置26は、受信済の新たな認証情報単位ATを記憶するとともにさらに別の認証情報単位ATを記憶するための記憶容量を、車両記憶装置28に確保することが可能に構成されている。
 (1-4)車両管理装置26は、車両20のユーザによって車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに対して、優先順位を設定可能に構成されている。車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATを受信したとき、設定済の優先順位に基づき、車両記憶装置28から削除されるべき認証情報単位ATを選択する。これによって、車両管理装置26は、優先順位を設定したユーザの意向を反映して、車両記憶装置28から削除されるべき認証情報単位ATを選択することが可能に構成されている。
 (1-5)車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうち、プロテクト対象にされる認証情報単位ATを選択することが可能に構成されている。車両管理装置26は、新たな認証情報単位ATを受信したとき、プロテクト対象としては未選択の1つまたは複数の認証情報単位ATのうちのいずれかを削除する。車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに対して、プロテクト対象になっている認証情報単位ATと、プロテクト対象になっていない認証情報単位ATと、の2段階の優先順位を設定することが可能に構成されている。車両管理装置26は、プロテクト対象に設定済の認証情報単位ATが削除されることを防ぐことによって、車両20のユーザの意図を反映させることができる。
 (1-6)複数のデジタルキーは、第1デジタルキー、第1デジタルキーに基づき生成される第2デジタルキー、および第2デジタルキーに基づき生成される第3デジタルキー、を備えている。第1デジタルキーは、オーナーキーKOである。第2デジタルキーは、フレンドキーKFである。第3デジタルキーは、ノンフレンドキーKNである。以下は、車両記憶装置28に、第2デジタルキーであるフレンドキーKFを認証するための認証情報単位ATと、第3デジタルキーであるノンフレンドキーKNを認証するための認証情報単位ATと、が記憶されており、且つ車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している場合を説明する。この場合、車両管理装置26は、新たな認証情報単位ATを受信したとき、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうち、第3デジタルキーであるノンフレンドキーKNに対応する認証情報単位ATを削除する。これによって、車両管理装置26は、オーナーキーKOに基づき登録済のフレンドキーKFに対応する認証情報単位ATを保護することが可能に構成されている。これによって、例えば、フレンドキーKFに対応する認証情報単位ATが新たな認証情報単位ATによって置き換えられてしまうことで、再度オーナーがフレンドキーKFを登録し直す、という事態の頻度を低減することが可能に構成されている。
 (1-7)管理システム10は、車両20に搭載される車両管理装置26と、デジタルキーを管理する管理サーバ70と、を備えている。車両20は車両記憶装置28を備えている。管理システム10は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たに認証情報単位ATが受信されたとき、車両記憶装置28が記憶済の認証情報単位のうちのいずれかを削除する。上記の管理システム10によれば、車両記憶装置28が新たな認証情報単位ATを記憶するときに、前記車両20が記憶済の1つまたは複数の認証情報単位ATのなかから、どの認証情報単位ATを削除するのかを車両20のユーザが選択しなくてよくなる。すなわち、管理システム10は、車両20のユーザの負担を軽減することが可能に構成されている。
 <第1実施形態の変更例>
 上記第1実施形態は、以下のように変更して実施することが可能に構成されている。上記第1実施形態および以下の第1実施形態についての変更例は、技術的に矛盾しない範囲で互いに組合せて実施することが可能に構成されている。
 ・以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、車両20が新たな認証情報単位ATが受信された場合を説明する。この場合、車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除することが可能であればよい。車両管理装置26は、新たな認証情報単位ATを車両記憶装置28に記憶させなくてもよい。
 ・以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、車両20が新たな認証情報単位ATが受信された場合を説明する。この場合、車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除することが可能であればよい。車両管理装置26は、削除されるべき認証情報単位ATを選択しなくてもよい。例えば、車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATを、ランダムに削除してもよい。
 ・以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATが受信された場合を説明する。この場合、車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除することができればよい。車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATをプロテクト対象として選択できない構成でもよい。
 ・以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATが受信された場合を説明する。この場合、車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除することができればよい。車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できない構成でもよい。
 ・以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATが受信された場合を説明する。この場合、車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除することができればよい。車両管理装置26は、未執行の削除予約D41の対象になっている1つまたは複数の認証情報単位ATを全て削除することに限られない。
 ・以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATが受信された場合を説明する。この場合、車両管理装置26は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除できれよい。車両管理装置26は、未執行の削除予約D41の対象となっている認証情報単位ATを、削除しなくてもよい。
 ・以下は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATが受信された場合を説明する。この場合、車両管理装置26は、第2デジタルキーであるフレンドキーKFに対応する認証情報単位ATと、第3デジタルキーであるノンフレンドキーKNに対応する認証情報単位ATと、のうち、第2デジタルキーであるフレンドキーKFに対応する認証情報単位ATを削除してもよい。
 ・車両管理装置26は、車両記憶装置28に記憶済の未執行の削除予約D41の対象となっている認証情報単位ATに対して、優先順位を設定可能に構成されてもよい。例えば、車両管理装置26は、残りのフェードアウト期間が短い認証情報単位ATほど、この認証情報単位ATに低い優先順位を設定するように構成されてもよい。例えば、車両管理装置26は、フェードアウト状態に入った時期が早い認証情報単位ATほど、この認証情報単位ATに低い優先順位を設定するように構成されてもよい。
 ・車両実行装置27が車両プログラムPVを実行することで、認証情報単位ATの置き換えに関する処理を実行する場合、管理サーバ70のサーバ実行装置71は、置き換えプログラムPMを実行しなくてもよい。車両実行装置27が車両プログラムPVを実行することで、認証情報単位ATの置き換えに関する処理を実行する場合、管理サーバ70のサーバ記憶装置72は、置き換えプログラムPMを記憶していなくてもよい。
 図7、図12、および図13、は第2実施形態に係る車両管理装置26および管理サーバ70を説明する。第2実施形態については、第1実施形態との相違点を中心に説明する。
 以下は、車両管理装置26が、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、新たな認証情報単位ATを受信したときを説明する。このとき、第2実施形態における車両管理装置26は、前記新たな認証情報単位ATに対応するキー情報DKをデバイス30に記憶させるための登録要求D31を行なったデバイス30による別の登録要求D31に基づき、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATを削除する。つまり車両管理装置26は、新たな認証情報単位ATに対応するキー情報DKをデバイス30に記憶させるための登録要求D31を行なったデバイス30が、過去も登録要求D31を行なっていた場合、過去の登録要求D31に対応する認証情報単位ATを車両記憶装置28から削除する。
 <車両20が実行する一連の処理>
 図12は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、車両20が新たな認証情報単位ATを受信したとき、管理システム10における車両20が実行する一連の処理の流れを示す説明図である。
 第2デバイス30Bは、オーナーデバイス40による登録要求D21に基づき、フレンドキーKFが登録されたフレンドデバイス51である。第4デバイス30Dは、第2デバイス30B(フレンドデバイス51)による登録要求D31に基づき、ノンフレンドキーKNが登録されたノンフレンドデバイス52である。第3デバイス30Cは、ノンフレンドキー情報DKNを記憶していないデバイス30のうち、本一連の処理によってノンフレンドデバイス52とされるデバイス30である。
 フレンドデバイス51である第2デバイス30Bにおいて、第3デバイス30Cに対するノンフレンドキーKNの登録要求操作が実行されることによって、管理システム10は、第3デバイス30Cに対するノンフレンドキーKNの登録を行なうべく、図7に示す一連の処理を行なう。
 図7に示すステップS49の処理として、管理サーバ70は、ノンフレンドキー情報DKNに含まれる認証パッケージATPと、前記認証パッケージATPを記憶するための記憶要求D34と、を車両20へ送信する。その後、車両20が、認証パッケージATPおよび記憶要求D34を受信すると、車両20は図12に示すステップS104の処理を行なう。
 <削除されるべき認証情報単位ATの選択と、認証情報単位ATの置き換え>
 ステップS104では、第1実施形態とで同様に、車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかから、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを選択する。その後、車両20はステップS401の処理を行なう。
 ステップS401では、車両20は、第3デバイス30Cに認証情報単位ATを記憶させるための登録要求D31を行なった第2デバイス30B(フレンドデバイス51)による別の(すなわち過去の)登録要求D31に基づく認証情報単位ATを記憶済の場合、前記認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。ステップS401において車両20が行なう選択の結果は、ステップS102において車両20が行なう選択の結果よりも優先される。
 第4デバイス30Dは、第2デバイス30B(フレンドデバイス51)による登録要求D31に基づきノンフレンドキーKNが登録されたノンフレンドデバイス52である。つまり第2デバイス30B(フレンドデバイス51)は、今回新たに第3デバイス30CにノンフレンドキーKNを登録させるための登録要求D31を行なっただけでなく、過去も、第4デバイス30DにノンフレンドキーKNを登録させるための登録要求D31を行なっていた。車両20は、第4デバイス30DのノンフレンドキーKNを示すノンフレンドキー情報DKNに対応する認証情報単位ATを削除する。その後、車両20は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを記憶する。
 すなわち、車両20は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、第4デバイス30DのノンフレンドキーKNの認証情報単位ATの代わりに記憶する。換言すれば、車両20は、第3デバイス30Cのノンフレンドキー情報DKNの認証パッケージATPを記憶するに際して、第4デバイス30DのノンフレンドキーKNの認証情報単位ATと置き換えて第3デバイス30Cのノンフレンドキー情報DKNの認証パッケージATPを記憶する。その後、車両20はステップS402の処理を行なう。
 <認証情報単位ATを置き換えた後の処理>
 ステップS402では、車両管理装置26は完了通知M71を生成する。完了通知M71は、第3デバイス30CのノンフレンドキーKNの認証情報単位ATが、第4デバイス30DのノンフレンドキーKNの認証情報単位ATの代わりに記憶済であることを示す信号を備えている。完了通知M71は、車両記憶装置28が第3デバイス30CのノンフレンドキーKNの認証情報単位ATを記憶したことを示す信号を、管理サーバ70が第3デバイス30Cに向けて送信するようにさせるための信号を備えている。完了通知M71は、車両記憶装置28が第3デバイス30CのノンフレンドキーKNの認証情報単位ATを記憶したことを示す信号を、管理サーバ70が第4デバイス30D(ノンフレンドデバイス52)、第2デバイス30B(フレンドデバイス51)、およびオーナーデバイス40、に向けて送信するようにさせるための信号を備えている。車両管理装置26は、完了通知M71を管理サーバ70に向けて送信する。
 管理サーバ70が完了通知M71を受信すると、管理サーバ70は、ステップS403の処理を実行する。ステップS403では、管理サーバ70は、完了通知M72を生成する。完了通知M72は、第3デバイス30CのノンフレンドキーKNの認証情報単位ATを、車両記憶装置28が記憶したことを示す信号を備えている。管理サーバ70は、完了通知M72を第3デバイス30Cへ送信する。
 ステップS403の処理の後、管理サーバ70は、ステップS404の処理を実行する。ステップS404では、管理サーバ70は、置き換え通知M73、置き換え通知M74、および置き換え通知M75、を生成する。置き換え通知M73、置き換え通知M74、および置き換え通知M75、は各々、第3デバイス30CのノンフレンドキーKNの認証情報単位ATが、第4デバイス30DのノンフレンドキーKNの認証情報単位ATの代わりに記憶されたことを示す信号を備えている。管理サーバ70は、置き換え通知M73を第4デバイス30D(ノンフレンドデバイス52)に向けて送信する。管理サーバ70は、置き換え通知M74を第2デバイス30B(フレンドデバイス51)に向けて送信する。管理サーバ70は、オーナーデバイス40に向けて置き換え通知M75を送信する。処理は図14へ続く。
 図13に示すように、第3デバイス30Cが完了通知M72を受信すると、第3デバイス30CはステップS405の処理を行なう。ステップS405では、第3デバイス30Cは、車両20において第3デバイス30CのノンフレンドキーKNの登録が完了したことを示す情報を、デバイスHMI_32に提示する。
 第4デバイス30D(ノンフレンドデバイス52)が置き換え通知M73を受信すると、第4デバイス30DはステップS406の処理を行なう。ステップS406では、第4デバイス30Dは、車両記憶装置28において、第3デバイス30CのノンフレンドキーKNの認証情報単位ATが、第4デバイス30DのノンフレンドキーKNの認証情報単位ATの代わりに記憶されたことを示す情報を、デバイスHMI_32に提示する。
 第2デバイス30B(フレンドデバイス51)が置き換え通知M74を受信すると、第2デバイス30BはステップS407の処理を行なう。ステップS407では、第2デバイス30Bは、車両記憶装置28において、第3デバイス30CのノンフレンドキーKNの認証情報単位ATが、第4デバイス30DのノンフレンドキーKNの認証情報単位ATの代わりに記憶されたことを示す情報を、デバイスHMI_32に提示する。
 オーナーデバイス40が置き換え通知M75を受信すると、オーナーデバイス40はステップS408の処理を行なう。ステップS408では、オーナーデバイス40は、車両記憶装置28において、第3デバイス30CのノンフレンドキーKNの認証情報単位ATが、第4デバイス30DのノンフレンドキーKNの認証情報単位ATの代わりに記憶されたことを示す情報を、デバイスHMI_32に提示する。その後、管理システム10は、今回の認証情報単位ATの置き換えについての一連の処理を終了する。
 <第2実施形態の作用>
 車両管理装置26は、第3デバイス30Cのキー情報DKに対応する認証情報単位ATを受信済の場合、第3デバイス30Cのキー情報DKに対応する認証情報単位ATに対応する登録要求D31を行なった第2デバイス30B(フレンドデバイス51)による別の登録要求D31に基づき、車両記憶装置28に記憶済の第3デバイス30Cのキー情報DKに対応する認証情報単位ATを削除する。換言すれば車両管理装置26は、今回の登録要求D31を行なった第2デバイス30B(フレンドデバイス51)による過去の登録要求D31に対応する認証情報単位ATを、車両記憶装置28から削除する。よって、第2デバイス30B(フレンドデバイス51)以外による登録要求D31に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATと、オーナーデバイス40による登録要求D21に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATと、は削除されない。
 <第2実施形態の効果>
 (2-1)車両管理装置26は、第2デバイス30B(フレンドデバイス51)以外による登録要求D31に基づき既に車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATが、第2デバイス30B(フレンドデバイス51)による登録要求D31に起因して削除されてしまうことを防ぐことができる。車両管理装置26は、オーナーデバイス40による登録要求D21に基づき既に車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATが、第2デバイス30B(フレンドデバイス51)による登録要求D31に起因して削除されてしまうことを防ぐことができる。
 <第2実施形態の変更例>
 上記第2実施形態は、以下のように変更して実施することが可能に構成されている。上記第2実施形態および以下の第2実施形態についての変更例は、技術的に矛盾しない範囲で互いに組合せて実施することが可能に構成されている。
 ・以下は、車両管理装置26が、新たな認証情報単位ATが受信された場合、前記新たな認証情報単位ATに対応する登録要求D31を行なったデバイス30による別(すなわち過去)の登録要求D31に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATを削除する場合を説明する。この場合、車両管理装置26は、第3デバイス30CのノンフレンドキーKNの認証情報単位ATを車両記憶装置28が記憶したことを示す信号を生成しなくてもよい。同様に、車両管理装置26は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、第4デバイス30DのノンフレンドキーKNの認証情報単位ATの代わりに記憶したことを示す信号を生成しなくてもよい。
 ・車両管理装置26は、新たな認証情報単位ATに対応する登録要求D21を行なったオーナーデバイス40による別の登録要求D21に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATを削除してもよい。すなわちオーナーデバイス40による過去の登録要求D21に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATは、オーナーデバイス40が新たな登録要求D21を行なった場合、削除される。
 図1、図7、図14、および図15、は第3実施形態に係る車両管理装置26および管理サーバ70を説明する。以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を、管理サーバ70が受信したときを説明する。このとき、第3実施形態の管理サーバ70は、新たな認証情報単位ATを、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかの代わりに記憶させるための命令を、車両20に向けて送信する。
 具体的には、管理サーバ70は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したとき、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除する。その後、管理サーバ70は、受信済の認証情報単位ATを車両記憶装置28に記憶させる。
 <管理サーバ70が実行する一連の処理>
 図14は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、車両20に対する新たな認証情報単位ATを管理サーバ70が受信したとき、管理システム10における管理サーバ70が実行する一連の処理の流れを示す説明図である。
 図1に示すように、管理サーバ70において、サーバ記憶装置72は、置き換えプログラムPMを記憶済である。サーバ実行装置71は、サーバ記憶装置72に記憶済の置き換えプログラムPMを実行する。これによって、管理サーバ70は一連の処理を実行する。
 図14に示す第3デバイス30Cは、ノンフレンドキー情報DKNを記憶していないデバイス30のうち、当該一連の処理によってノンフレンドデバイス52とされるデバイス30である。図示しないフレンドデバイス51において、第3デバイス30Cに対するノンフレンドキーKNの登録要求操作が実行されることによって、管理システム10は、第3デバイス30Cに対するノンフレンドキーKNの登録を行なうべく、図7に示す一連の処理を行なう。
 図14に示すステップS501は、図7に示すステップS47とで同様である。ステップS501の処理の後、第3デバイス30Cは、ステップS502の処理を行なう。図14に示すステップS502の処理は、図7に示すステップS48とで同様である。ステップS502の処理として、第3デバイス30Cは、管理サーバ70へ、ノンフレンドキー情報DKNと、ノンフレンドキーKNのキートラック要求D33と、を送信する。キートラック要求D33は、新たな認証情報単位ATを車両20に記憶させるための要求である。
 その後、管理サーバ70がノンフレンドキーKNのキートラック要求D33を受信すると、管理サーバ70は、ステップS503の処理を行なう。
 ステップS503の処理として、管理サーバ70は、ノンフレンドキーKNの登録管理を行なう。具体的には、管理サーバ70は、キートラック要求D33の対象であるノンフレンドキーKNが、拒否リストに掲載されていないことを確認する。ノンフレンドキーKNが拒否リストに掲載されている場合、管理サーバ70は、第3デバイス30Cへ、キートラック要求D33には応えられない通知を送信する。
 一方で、ノンフレンドキーKNが拒否リストに掲載されていない場合、管理サーバ70は、キートラック要求D33の対象であるノンフレンドキーKNを、データベースDBに登録する。詳細には、管理サーバ70は、データベースDBにおける車両20のデータブロックDAに、ノンフレンドデバイス52として登録されたデバイス30として、第3デバイス30Cを記憶する。管理サーバ70は、取得済のノンフレンドキー情報DKNを参照して、第3デバイス30Cとフレンドデバイス51との関係を記憶する。具体的には、管理サーバ70は、第3デバイス30Cを、第2デバイス30B(フレンドデバイス51)からの登録要求D31によって登録されたノンフレンドキーKNを有しているデバイス30として記憶する。その後、管理サーバ70はステップS504の処理を行なう。
 第3実施形態の管理サーバ70は、データベースDBにおける車両20のデータブロックDAとして、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数と、車両記憶装置28が記憶可能な認証情報単位ATの数と、を記憶済である。すなわち、管理サーバ70は、車両20が記憶済の1つまたは複数の認証情報単位ATの数が、車両20が記憶可能な既定数に達しているか否かを把握可能に構成されている。ステップS504では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているか否かを判定する。
 管理サーバ70が、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、車両記憶装置28が記憶可能な既定数に達していないと判定した場合、管理サーバ70は、認証パッケージATPと、認証パッケージATPを記憶するための記憶要求D34と、を車両20へ送信する。その後、管理システム10は図7に示すステップS50以降の処理を行なう。
 管理サーバ70が、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、前記車両記憶装置28が記憶可能な既定数に達していると判定した場合、管理サーバ70はステップS505の処理を行なう。
 <削除されるべき認証情報単位ATの選択>
 ステップS505では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATのなかから、削除されるべき認証情報単位ATを選択する。
 図15は、ステップS505において管理サーバ70が行なう、削除されるべき認証情報単位ATを選択する処理を示すフローチャートである。管理サーバ70は、ステップS505の処理として、この一連の処理を行なう。
 <フェードアウト状態の判定>
 図15に示すように、この一連の処理を開始すると、ステップS510において、管理サーバ70は、削除予約D41が未執行のまま残っているか否かを判定する。管理サーバ70は、車両記憶装置28に、フェードアウト状態の1つまたは複数のデジタルキーの認証情報単位ATが記憶済の場合、削除予約D41が未執行のまま残っていると判定する。削除予約D41が未執行のまま残っている場合(ステップS510:YES)、管理サーバ70は、処理をステップS511に進める。
 ステップS511では、管理サーバ70は、複数の削除予約D41が未執行のまま残っている状態か否かを判定する。管理サーバ70は、車両記憶装置28に、フェードアウト状態の複数のデジタルキーの認証情報単位ATが記憶済の場合、複数の削除予約D41が未執行のまま残っていると判定する。複数の削除予約D41が未執行のまま残っている場合(ステップS511:YES)、管理サーバ70は、処理をステップS512へ進める。
 ステップS512では、管理サーバ70は、車両20に、車両記憶装置28が記憶済のフェードアウト状態の複数のデジタルキーの認証情報単位ATを全て削除させるための信号を生成する。すなわち、管理サーバ70は、未執行のまま残っている削除予約D41の対象になっている複数の認証情報単位ATを、車両20によって、車両記憶装置28から全て削除させるための信号を生成する。その後、前記信号を車両20に向けて送信する。その後、管理サーバ70は図15に示す一連の処理を終了する。車両20は、前記信号にしたがって、車両記憶装置28が記憶済のフェードアウト状態の複数のデジタルキーの認証情報単位ATを全て削除する。これによって、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数は、記憶可能な既定数未満となる。
 その後、管理サーバ70は、ノンフレンドキー情報DKNに含まれる認証パッケージATPと、この認証パッケージATPを記憶するための記憶要求D34と、を車両20に向けて送信する。管理サーバ70は、キートラックの完了通知M33を、第3デバイス30Cに向けて送信する。ノンフレンドキー情報DKNに含まれる認証パッケージATPと、前記認証パッケージATPを記憶するための記憶要求D34と、を受信済の車両20は、図7に示すステップS50の処理を行なう。キートラックの完了通知M33を受信済の第3デバイス30Cは、図7に示すステップS51の処理を行なう。これによって、管理システム10は、一連の処理を終了する。
 車両記憶装置28が、フェードアウト状態のデジタルキーの認証情報単位ATを1つのみ記憶済の場合、すなわち残っている削除予約D41が複数ではない場合(ステップS511:NO)、管理サーバ70は、処理をステップS513へ進める。
 ステップS513では、管理サーバ70は、フェードアウト状態のデジタルキーの認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、管理サーバ70は、図15に示す一連の処理を終了する。
 ステップS510の処理では、削除予約D41が残っていない場合(ステップS510:NO)、管理サーバ70は、処理をステップS514に進める。
 <プロテクト対象として選択済の認証情報単位ATが存在するか否かの判定>
 管理サーバ70は、データベースDBに記憶済の1つまたは複数の認証情報単位ATをプロテクト対象として選択することが可能に構成されている。例えば、車両20のユーザは、オーナーデバイス40のデバイスHMI_32を介して、データベースDBに記憶済の1つまたは複数の認証情報単位ATの各々を、プロテクト対象として選択することが可能に構成されている。例えば、車両20のユーザは、フレンドデバイス51のデバイスHMI_32を介して、データベースDBに記憶済の1つまたは複数の認証情報単位ATの各々を、プロテクト対象として選択することができる。例えば、車両20のユーザは、ノンフレンドデバイス52のデバイスHMI_32を介して、データベースDBに記憶済の1つまたは複数の認証情報単位ATの各々を、プロテクト対象として選択することができる。
 ステップS514では、管理サーバ70は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかに、プロテクト対象として選択済の認証情報単位ATが存在するか否かを判定する。プロテクト対象として選択済の認証情報単位ATが存在する場合(ステップS514:YES)、管理サーバ70は、以降の処理において、プロテクト対象でない認証情報単位ATのなかから、削除されるべき認証情報単位ATを選択する。その後、管理サーバ70は、処理をステップS516に進める。車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかに、プロテクト対象として選択済の認証情報単位ATが存在しない場合(ステップS514:NO)、管理サーバ70は処理をステップS516に進める。
 <認証情報単位ATに優先順位が設定されているか否かの判定>
 管理サーバ70は、データベースDBに記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定可能に構成されている。例えば、車両20のユーザは、オーナーデバイス40のデバイスHMI_32を介して、データベースDBに記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できる。例えば、車両20のユーザは、フレンドデバイス51のデバイスHMI_32を介して、データベースDBに記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できる。例えば、車両20のユーザは、ノンフレンドデバイス52のデバイスHMI_32を介して、データベースDBに記憶済の1つまたは複数の認証情報単位ATに、優先順位を設定できる。
 ステップS516では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATに対して、優先順位が設定されているか否かを判定する。車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATに対して、優先順位が設定されている場合(ステップS516:YES)、管理サーバ70は処理をステップS517に進める。
 ステップS517では、管理サーバ70は、車両記憶装置28が、優先順位が異なる複数の認証情報単位ATを記憶済か否かを判定する。車両記憶装置28が、優先順位が異なる複数の認証情報単位ATを記憶済の場合(ステップS517:YES)、管理サーバ70は処理をステップS518に進める。
 ステップS518では、管理サーバ70は、優先順位に基づき、削除されるべき認証情報単位ATを選択する。例えば、管理サーバ70は、優先順位が最も低い認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、管理サーバ70は、図15に示す一連の処理を終了する。
 ステップS516では、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATに対して、優先順位が設定されていない場合(ステップS516:NO)、管理サーバ70は処理をステップS519に進める。ステップS517では、車両記憶装置28が、優先順位が異なる複数の認証情報単位ATを記憶していない場合(ステップS517:NO)、管理サーバ70は処理をステップS519に進める。
 <ノンフレンドキーKNの認証情報単位ATを記憶済か否かの判定>
 ステップS519では、管理サーバ70は、車両記憶装置28がノンフレンドキーKNの認証情報単位ATを記憶済か否かを判定する。車両記憶装置28がノンフレンドキーKNの認証情報単位ATを記憶済の場合(ステップS519:YES)、管理サーバ70は処理をステップS520に進める。
 ステップS520では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATのうち、ノンフレンドキーKNの認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、管理サーバ70は、図15に示す一連の処理を終了する。
 ステップS519では、車両記憶装置28がノンフレンドキーKNの認証情報単位ATを記憶していない場合(ステップS519:NO)、管理サーバ70は処理をステップS521に進める。ステップS521では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATのうち、最後に使用された日付が最も古いシェアキーKSの認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。その後、管理サーバ70は、図15に示す一連の処理を終了する。
 <認証情報単位ATの置き換え>
 図14に示すように、ステップS505の後、管理サーバ70は、認証パッケージATPと、置き換え要求D81と、を車両20へ送信する。置き換え要求D81は、認証パッケージATPを、ステップS505において管理サーバ70が選択済の認証情報単位ATの代わりに記憶させるための要求である。置き換え要求D81は、車両20に、ステップS505において管理サーバ70が選択済の認証情報単位ATを車両記憶装置28から削除させるための命令と、車両20に、認証パッケージATPを、第3デバイス30CのノンフレンドキーKNを認証するための認証情報単位ATとして記憶させるための命令と、を備えている。
 認証パッケージATPと、置き換え要求D81と、を受信済の車両20は、ステップS506の処理を行なう。ステップS506では、車両20は、認証パッケージATPを、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの代わりに記憶する。具体的には、管理サーバ70は、ステップS505において管理サーバ70が選択済の認証情報単位ATを、車両記憶装置28から削除する。その後、車両20は、認証パッケージATPを、第3デバイス30CのノンフレンドキーKNを認証するための認証情報単位ATとして記憶する。
 管理サーバ70は、ステップS505の処理を行なった後、処理をステップS507に進める。ステップS507では、管理サーバ70は完了通知M81を生成する。完了通知M81は、車両20が、認証パッケージATPを、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの代わりに記憶したことを示す信号を備えている。管理サーバ70は、完了通知M81を第3デバイス30Cへ送信する。
 第3デバイス30Cが完了通知M81を受信すると、第3デバイス30CはステップS508の処理を行なう。ステップS508では、第3デバイス30Cは、ノンフレンドキーKNの登録が完了したことを示す登録完了の情報を、デバイスHMI_32に提示する。その後、管理システム10は、今回の認証情報単位ATの置き換えについての一連の処理を終了する。
 <第3実施形態の作用>
 管理サーバ70は、車両20が記憶済の1つまたは複数の認証情報単位ATの数が既定数に達している状態で、新たに認証情報単位ATが受信されたとき、ユーザによる介入無しに、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令を送信する。認証情報単位ATは、デジタルキーに関する情報の取り扱い単位である。
 <第3実施形態の効果>
 (3-1)管理サーバ70によれば、新たな認証情報単位ATを車両20に記憶させるときに、車両20が記憶済の1つまたは複数の認証情報単位ATのなかから、どの認証情報単位ATを削除するのかを、車両20のユーザは選択しなくてよい。すなわち、管理サーバ70は、車両20のユーザの負担を軽減することが可能に構成されている。
 (3-2)管理サーバ70は、削除予約D41を受信可能に構成されている。削除予約D41は、既定条件RCが成立したときに、対象情報である認証情報単位ATの削除を車両20に執行させるための指令である。管理サーバ70は、車両20についてのデータベースDBに削除予約D41が未執行のまま残っているか否かを記憶済である。以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。すなわち車両20についてのデータベースDBには、削除予約D41が未執行のまま残っている。このとき、管理サーバ70は、車両20に、未執行の削除予約D41の対象になっている1つまたは複数の認証情報単位ATのうちの1つまたは複数を削除させるための命令を送信する。これによって、管理サーバ70は、車両20に、未執行の削除予約D41の対象になっている1つまたは複数の認証情報単位ATを、新たな認証情報単位ATに置き換えることによって、新たな認証情報単位ATを記憶させる。つまり、管理サーバ70は、新たな認証情報単位ATによって置き換えられる認証情報として、削除されることが予定されている認証情報単位ATを選択する。換言すれば管理サーバ70は、削除されることが予定されていない認証情報単位ATを記憶させたまま、新たな認証情報単位ATを記憶させることができる。
 (3-3)以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。車両20には、複数の削除予約D41が未執行のまま残っている。このとき、管理サーバ70は、車両20に、認証情報単位ATと、次の命令と、を送信する。すなわちこの命令は、削除予約D41の対象になっている複数の認証情報単位ATを全て削除させることで、前記記憶要求に対応する新たな認証情報単位ATを記憶させるための命令である。管理サーバ70は、削除予約D41の対象になっている複数の認証情報単位ATを、車両20に全て削除させる。管理サーバ70は、新たな認証情報単位ATを車両20に記憶させるとともに認証情報単位ATを記憶するための記憶容量を、車両20に確保させることができる。
 (3-4)管理サーバ70は、車両20に記憶済の1つまたは複数の認証情報単位ATに対して、車両20のユーザによって優先順位を設定可能に構成されている。管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している車両20に対する新たな認証情報単位ATを登録させる要求を受信したとき、設定済の優先順位に基づき、削除されるべき認証情報単位ATを選択する。管理サーバ70は、車両20に、管理サーバ70が選択済の認証情報単位ATを削除させるための命令を送信する。管理サーバ70は、既に記憶済の優先順位に従って、削除されるべき認証情報単位ATを選択する。管理サーバ70は、優先順位を設定したユーザの意向を反映して、削除されるべき認証情報単位ATを選択することが可能に構成されている。
 (3-5)管理サーバ70は、車両20に記憶済の1つまたは複数の認証情報単位ATのうち、車両20のユーザによってプロテクト対象に設定される認証情報単位ATを選択することが可能に構成されている。管理サーバ70は、プロテクト対象としては未選択の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令を、車両20に送信する。管理サーバ70は、車両20に記憶済の1つまたは複数の認証情報単位ATに対して、プロテクト対象になっている認証情報単位ATと、プロテクト対象になっていない認証情報単位ATと、の2段階の優先順位を設定することが可能に構成されている。管理サーバ70は、プロテクト対象に設定済の認証情報単位ATが削除されることを防ぐことによって、ユーザの意図を反映させることができる。
 (3-6)以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。車両記憶装置28は、フレンドキーKFを認証するための認証情報単位ATと、ノンフレンドキーKNを認証するための認証情報単位ATと、を記憶済である。このとき、管理サーバ70は、ノンフレンドキーKNが認証されるときに必要であった認証情報単位ATを、削除させるための命令を車両20へ送信する。管理サーバ70は、車両20のオーナーが登録したフレンドキーKFを認証するための認証情報単位ATを保護することが可能に構成されている。これによって、例えば、フレンドキーKFの認証に必要な認証情報単位ATが削除されてしまうことで、再度オーナーがフレンドキーKFを登録し直す、という事態の頻度を低減することが可能に構成されている。
 <第3実施形態の変更例>
 第3実施形態は、以下のように変更して実施することが可能に構成されている。第3実施形態および以下の変更例は、技術的に矛盾しない範囲で互いに組合せて実施することが可能に構成されている。
 ・以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。このとき、管理サーバ70は、車両20に、車両20が記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させることができれよい。管理サーバ70は、車両20が記憶済の1つまたは複数の認証情報単位ATのなかから、削除されるべき認証情報単位ATを選択しなくてもよい。例えば、管理サーバ70は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを、ランダムに削除する命令を車両20に向けて送信してもよい。
 ・以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。このとき、管理サーバ70は、車両20に、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令を送信できれよい。管理サーバ70は、認証情報単位ATをプロテクト対象として選択できなくてもよい。
 ・以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。このとき、管理サーバ70は、車両20に、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令を送信できれよい。管理サーバ70は、認証情報単位ATに優先順位を設定できなくてもよい。
 ・以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。このとき、管理サーバ70は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令を、車両20に送信できればよい。管理サーバ70は、未執行の削除予約D41の対象になっている1つまたは複数の認証情報単位ATを、車両20に削除させなくてもよい。
 ・以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。このとき、管理サーバ70は、車両20に、未執行の削除予約D41の対象になっている1つまたは複数の認証情報単位AT以外の認証情報単位ATを削除させてもよい。
 ・以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。車両記憶装置28には、フレンドキーKFを認証するための認証情報単位ATと、ノンフレンドキーKNを認証するための認証情報単位ATと、が記憶済である。このとき、管理サーバ70は、車両20に、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうち、フレンドキーKFが認証されるときに必要であった認証情報単位ATを、削除させてもよい。
 ・管理サーバ70は、車両20についてのデータベースDBに記憶済の未執行の削除予約D41の対象となっている複数の認証情報単位ATに対して、優先順位を設定可能に構成されてもよい。例えば、管理サーバ70は、残りのフェードアウト期間が短い認証情報単位ATほど、この認証情報単位ATに低い優先順位を設定するように構成されてもよい。例えば、管理サーバ70は、フェードアウト状態に入った時期が早い認証情報単位ATほど、この認証情報単位ATに低い優先順位を設定するように構成されてもよい。
 図7および図14~図17は、第4実施形態に係る車両管理装置26および管理サーバ70を説明する。第4実施形態については、第3実施形態との相違点を中心に説明する。
 以下は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、前記車両20に対する新たな認証情報単位ATの記憶要求を管理サーバ70が受信したときを説明する。このとき、管理サーバ70は、前記新たな認証情報単位ATを、前記新たな認証情報単位ATに対応するキー情報DKをデバイス30に記憶させるための登録要求D31を行なったデバイス30による別の登録要求D31に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATを削除させるための命令を、車両20に向けて送信する。つまり管理サーバ70は、新たな認証情報単位ATに対応するキー情報DKをデバイス30に記憶させるための登録要求D31を行なったデバイス30が、過去も登録要求D31を行なっていた場合、過去の登録要求D31に対応する認証情報単位ATを車両記憶装置28から削除させる。
 <管理サーバ70が実行する一連の処理>
 図16は、車両20についてのデータベースDBに記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している状態で、管理サーバ70が車両20に対する新たな認証情報単位ATの記憶要求を受信したとき、管理システム10における管理サーバ70が実行する一連の処理の流れを示す説明図である。
 第2デバイス30Bは、オーナーデバイス40による登録要求D21に基づき、フレンドキーKFが登録されたフレンドデバイス51である。第2デバイス30B(フレンドデバイス51)は、フレンドキー情報DKFを記憶済である。第4デバイス30Dは、フレンドデバイス51である第2デバイス30Bによる登録要求D31に基づき、ノンフレンドキーKNが登録されたノンフレンドデバイス52である。第4デバイス30D(ノンフレンドデバイス52)は、ノンフレンドキー情報DKNを記憶済である。第3デバイス30Cは、ノンフレンドキー情報DKNを記憶していないデバイス30のうち、本一連の処理によって新たにノンフレンドデバイス52とされるデバイス30である。
 フレンドデバイス51である第2デバイス30Bにおいて、第3デバイス30Cに対するノンフレンドキーKNの登録要求操作が実行されることによって、管理システム10は、ノンフレンドキーKNの登録を行なうべく、図7に示す一連の処理を行なう。
 図7に示すステップS48では、第3デバイス30Cは、ノンフレンドキーKNのキートラック要求D33を生成する。第3デバイス30Cは、管理サーバ70へ、ノンフレンドキー情報DKNと、ノンフレンドキーKNのキートラック要求D33と、を送信する。
 管理サーバ70がノンフレンドキーKNのキートラック要求D33を受信すると、管理サーバ70は、図14に示すステップS503の処理を行なう。ステップS503で管理サーバ70が実行する処理は、第3実施形態とで同様である。その後、管理サーバ70は図16に示すステップS504の処理を行なう。ステップS504で管理サーバ70が実行する処理は、第3実施形態とで同様である。
 管理サーバ70は、データベースDBにおける車両20のデータブロックDAとして、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数と、車両記憶装置28が記憶可能な認証情報単位ATの数と、を記憶済である。ステップS504では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているか否かを判定する。
 以下は、管理サーバ70が、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、前記車両記憶装置28が記憶可能な既定数に達していないと判定した場合を説明する。この場合、管理サーバ70は第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPと、前記認証パッケージATPを記憶するための記憶要求D34と、を車両20へ送信する。その後、管理システム10は図7に示すステップS50以降の処理を行なう。
 以下は、管理サーバ70が、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、前記車両記憶装置28が記憶可能な既定数に達していると判定した場合を説明する。この場合、管理サーバ70は図16に示すステップS601以降の処理を行なう。
 ステップS601では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATのなかから、認証パッケージATPによって置き換えられるべき認証情報単位ATを選択する。
 図15は、ステップS601において管理サーバ70が行なう、認証パッケージATPによって置き換えられるべき認証情報単位ATを選択する処理を示すフローチャートである。管理サーバ70は、第3実施形態におけるステップS505とで同様に、ステップS601の処理として図15に示す一連の処理を行なう。
 管理サーバ70は、図15に示す一連の処理を行なった後、第3デバイス30Cにキー情報DKを記憶させるための登録要求D31を行なった第2デバイス30B(フレンドデバイス51)による別の登録要求D31に基づく認証情報単位ATを、車両記憶装置28が記憶済か否かを判定する。換言すれば管理サーバ70は、今回の登録要求D31を行なった第2デバイス30B(フレンドデバイス51)による過去の登録要求D31に対応する認証情報単位ATを、車両記憶装置28が記憶済か判定する。管理サーバ70は、車両記憶装置28が別(過去)の登録要求D31に対応する認証情報単位ATを記憶済の場合、前記認証情報単位ATを、削除されるべき認証情報単位ATとして選択する。前記選択の結果は、図15に示す一連の処理による選択の結果よりも優先される。
 第4デバイス30Dは、第2デバイス30B(フレンドデバイス51)による登録要求D31に基づき、ノンフレンドキーKNを示すノンフレンドキー情報DKNが記憶済のノンフレンドデバイス52である。車両記憶装置28は、第4デバイス30D(ノンフレンドデバイス52)に記憶済のノンフレンドキー情報DKNに対応する認証情報単位ATを記憶済である。管理サーバ70は、置き換えられるべき認証情報単位ATとして、第4デバイス30D(ノンフレンドデバイス52)に記憶済のノンフレンドキー情報DKNに対応する認証情報単位ATを選択する。
 管理サーバ70は、認証パッケージATPと、置き換え要求D91と、を車両20へ送信する。置き換え要求D91は、認証パッケージATPを、第4デバイス30D(ノンフレンドデバイス52)が記憶済のノンフレンドキー情報DKNに対応する認証情報単位ATの代わりに記憶させるための命令である。置き換え要求D91は、第4デバイス30D(ノンフレンドデバイス52)に記憶済のノンフレンドキー情報DKNに対応する認証情報単位ATを削除させるための命令を備えている。置き換え要求D91は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを記憶させるための命令を備えている。
 認証パッケージATPと、置き換え要求D91と、を受信済の車両20は、ステップS602の処理を行なう。ステップS602では、車両20は、第4デバイス30D(ノンフレンドデバイス52)に記憶済のノンフレンドキー情報DKNに対応する認証情報単位ATを削除する。その後、車両20は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを記憶する。すなわち、車両20は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、第4デバイス30D(ノンフレンドデバイス52)に記憶済のノンフレンドキー情報DKNに対応する認証情報単位ATの代わりに記憶する。
 <車両20が認証情報単位ATを記憶した後の処理>
 管理サーバ70は、ステップS601の処理の後、ステップS603の処理を実行する。ステップS603では、管理サーバ70は、完了通知M92を生成する。完了通知M92は、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証情報単位ATを、車両記憶装置28に記憶させたことを示す信号を備えている。管理サーバ70は、完了通知M92を第3デバイス30Cへ送信する。
 ステップS603の処理の後、管理サーバ70は、ステップS604の処理を実行する。ステップS604では、管理サーバ70は、置き換え通知M93、置き換え通知M94、および置き換え通知M95、を生成する。置き換え通知M93、置き換え通知M94、および置き換え通知M95、は第4デバイス30D(ノンフレンドデバイス52)のキー情報DKに対応する認証情報単位ATが、第3デバイス30Cのキー情報DKに含まれる認証パッケージATPによって置き換えられたことを示す信号を備えている。管理サーバ70は、置き換え通知M93を第4デバイス30D(ノンフレンドデバイス52)に向けて送信する。管理サーバ70は、置き換え通知M94を第2デバイス30B(フレンドデバイス51)に向けて送信する。管理サーバ70は、置き換え通知M95をオーナーデバイス40に向けて送信する。その後、処理は図17へ続く。
 図17に示すように、第3デバイス30Cは、完了通知M92を受信するとステップS605の処理を行なう。ステップS605では、第3デバイス30Cは、第3デバイス30Cのキー情報DKに含まれる認証パッケージATPが、認証情報単位ATとして車両20に登録されたことを示す登録完了を、デバイスHMI_32に提示する。
 第4デバイス30D(ノンフレンドデバイス52)は、置き換え通知M93を受信するとステップS606の処理を行なう。ステップS606では、第4デバイス30D(ノンフレンドデバイス52)は、第4デバイス30D(ノンフレンドデバイス52)のキー情報DKに対応する認証情報単位ATが、第3デバイス30Cのキー情報DKに含まれる認証パッケージATPによって置き換えられたことを示す情報を、デバイスHMI_32に提示する。
 第2デバイス30B(フレンドデバイス51)は、置き換え通知M94を受信するとステップS607の処理を行なう。ステップS607では、第2デバイス30B(フレンドデバイス51)は、第4デバイス30D(ノンフレンドデバイス52)のキー情報DKに対応する認証情報単位ATが、第3デバイス30Cのキー情報DKに含まれる認証パッケージATPによって置き換えられたことを示す情報を、デバイスHMI_32に提示する。
 オーナーデバイス40は、置き換え通知M95を受信するとステップS608の処理を行なう。ステップS608では、オーナーデバイス40は、第4デバイス30D(ノンフレンドデバイス52)のキー情報DKに対応する認証情報単位ATが、第3デバイス30Cのキー情報DKに含まれる認証パッケージATPによって置き換えられたことを示す情報を、デバイスHMI_32に提示する。その後、管理システム10は、今回の認証情報単位ATの置き換えについての一連の処理を終了する。
 <第4実施形態の作用>
 管理サーバ70は、新たな認証情報単位ATが受信された場合、新たな認証情報単位ATに対応する登録要求D31を行なった第2デバイス30B(フレンドデバイス51)による別(すなわち過去)の登録要求D31に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATを削除させるための命令を、車両20に送信する。すなわち、新たな認証情報単位ATに対応する登録要求D31を行なった第2デバイス30B(フレンドデバイス51)による過去の登録要求D31に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATは、削除される。よって、第2デバイス30B(フレンドデバイス51)以外による登録要求D31に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATと、オーナーデバイス40による登録要求D21に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATと、は削除されない。
 <第4実施形態の効果>
 (4-1)管理サーバ70は、第2デバイス30B(フレンドデバイス51)以外による登録要求D31に基づき既に車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATが、第2デバイス30B(フレンドデバイス51)による登録要求D31に起因して削除されてしまうことを防ぐことができる。管理サーバ70は、オーナーデバイス40による登録要求D21に基づき既に車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATが、第2デバイス30B(フレンドデバイス51)による登録要求D31に起因して削除されてしまうことを防ぐことができる。
 (4-2)以下は、管理サーバ70が、車両20に、新たな認証情報単位ATと、次の命令と、を送信したときを説明する。すなわちこの命令は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令である。このとき、管理サーバ70は、オーナーデバイス40に向けて、車両20から認証情報単位ATが削除されたことを通知する。これによって、管理サーバ70は、車両20のオーナーに、車両20に記憶されていた認証情報単位ATのうちの1つが削除されたことを把握させることができる。
 (4-3)以下は、管理サーバ70が、車両20に、新たな認証情報単位ATと、次の命令と、を送信したときを説明する。すなわちこの命令は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令である。このとき、管理サーバ70は、削除されるべき認証情報単位ATに対応する登録要求D31を行なったシェアデバイス50に向けて、認証情報単位ATが削除されたことを通知する。これによって、管理サーバ70は、削除された認証情報単位ATに対応する登録要求D31を行なったシェアデバイス50のユーザに、認証情報単位ATが削除されたことを把握させることができる。
 (4-4)以下は、管理サーバ70が、車両20に、新たな認証情報単位ATと、次の命令と、を送信するときを説明する。すなわちこの命令は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを削除させるための命令である。このとき、管理サーバ70は、削除された認証情報単位ATに対応するキー情報DKを記憶済のシェアデバイス50に向けて、認証情報単位ATが削除されたことを通知する。削除された認証情報単位ATに対応するキー情報DKを記憶済のデバイス30は、車両20を使用することができなくなる。すなわち管理サーバ70は、シェアデバイス50のユーザに対して、前記シェアデバイス50に登録されているデジタルキーが使用不能になったことを通知することが可能に構成されている。これによって、ユーザは、実際に車両20の使用を試みる前に、デジタルキーがもはや使用不可能であることに気づくことができる。
 <第4実施形態の変更例>
 上記第4実施形態は、以下のように変更して実施することが可能に構成されている。上記第4実施形態および以下の第4実施形態についての変更例は、技術的に矛盾しない範囲で互いに組合せて実施することが可能に構成されている。
 ・管理サーバ70は、オーナーデバイス40に向けて、削除された認証情報単位ATのみを通知してもよい。管理サーバ70は、オーナーデバイス40に向けて通知を送信しなくてもよい。これらの場合であっても、管理サーバ70は、前記車両20のユーザによる介入無しに、認証情報単位ATを削除させることができる。よって、管理サーバ70は、ユーザの負担を軽減することが可能に構成されている。
 ・管理サーバ70は、認証情報単位ATを削除したときに、前記認証情報単位ATに対応するデジタルキーの登録要求を行なったシェアデバイス50に向けて、通知を送信しなくてもよい。その場合であっても、管理サーバ70は、前記車両20のユーザによる介入無しに、認証情報単位ATを削除させることができる。よって、管理サーバ70は、ユーザの負担を軽減することが可能に構成されている。
 ・管理サーバ70は、認証情報単位ATが置き換えられるシェアデバイス50に向けて、通知を送信しなくてもよい。その場合であっても、管理サーバ70は、前記車両20のユーザによる介入無しに、認証情報単位ATを削除させることができる。よって、管理サーバ70は、ユーザの負担を軽減することが可能に構成されている。
 ・管理サーバ70は、新たな認証情報単位ATが受信された場合、前記認証情報単位ATに対応する登録要求D21を行なったオーナーデバイス40による別の登録要求D21に基づき車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATを、削除させるための命令を車両20に送信してもよい。
 図7、図15、図18、および図19、は第5実施形態に係る車両管理装置26および管理サーバ70を説明する。第5実施形態については、第3実施形態との相違点を中心に説明する。第5実施形態では、車両20についてのデータベースDBに、フェードアウト状態として記憶済のデジタルキーが複数存在する。第5実施形態の管理サーバ70は、車両20に、削除予約D41の対象になっている複数の認証情報単位ATを全て削除させるための命令、新たな認証情報単位AT、および新たな認証情報単位ATを記憶させるための命令、を送信する。このとき、管理サーバ70は、削除予約D41の対象になっている複数の認証情報単位ATに対応するキー情報DKを記憶済の複数のシェアデバイスに向けて、キー情報DKに対応する認証情報単位ATが削除されたことを通知する。
 <管理サーバ70が実行する一連の処理>
 図18に示すように、ステップS700において、管理サーバ70は、第5デバイス30Eが記憶済のフレンドキー情報DKFによって示されるフレンドキーKFが、フェードアウト状態であることを記憶済である。管理サーバ70は、第6デバイス30Fが記憶済のノンフレンドキー情報DKNによって示されるノンフレンドキーKNが、フェードアウト状態であることを記憶済である。つまりステップS700における管理サーバ70は、複数の削除予約D41が未執行のまま残っている状態である。
 図18に示す第3デバイス30Cは、ノンフレンドキー情報DKNを記憶していないデバイス30のうち、当該一連の処理によってノンフレンドデバイス52とされるデバイス30である。図示しないフレンドデバイス51である第2デバイス30Bにおいて、第3デバイス30Cに対するノンフレンドキーKNの登録要求操作が実行されることによって、管理システム10は、図7に示す一連の処理を行なう。
 図18に示すステップS701は、図7に示すステップS47とで同様である。ステップS701の処理の後、第3デバイス30Cは、ステップS702の処理を行なう。図18に示すステップS702の処理は、図7に示すステップS48とで同様である。ステップS702の処理として、第3デバイス30Cは、管理サーバ70へ、ノンフレンドキー情報DKNと、ノンフレンドキーKNのキートラック要求D33と、を送信する。
 その後、管理サーバ70がノンフレンドキーKNのキートラック要求D33を受信すると、管理サーバ70は、ステップS703の処理を行なう。
 ステップS703の処理として、管理サーバ70は、ノンフレンドキーKNの登録管理を行なう。具体的には、管理サーバ70は、キートラック要求D33の対象であるノンフレンドキーKNが、拒否リストに掲載されていないことを確認する。ノンフレンドキーKNが拒否リストに掲載されている場合、管理サーバ70は、第3デバイス30Cへ、キートラック要求D33には応えられない通知を送信する。
 一方で、ノンフレンドキーKNが拒否リストに掲載されていない場合、管理サーバ70は、キートラック要求D33の対象であるノンフレンドキーKNを、データベースDBに登録する。詳細には、管理サーバ70は、データベースDBにおける車両20のデータブロックDAに、ノンフレンドデバイス52として登録されたデバイス30として、第3デバイス30Cを記憶する。管理サーバ70は、取得済のノンフレンドキー情報DKNを参照して、第3デバイス30Cとフレンドデバイス51との関係を記憶する。具体的には、管理サーバ70は、第3デバイス30Cを、第2デバイス30B(フレンドデバイス51)からの登録要求D31によって登録されたノンフレンドキーKNを有しているデバイス30として記憶する。その後、管理サーバ70はステップS704の処理を行なう。
 管理サーバ70は、データベースDBにおける車両20のデータブロックDAとして、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数と、車両記憶装置28が記憶可能な認証情報単位ATの数と、を記憶済である。ステップS704では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているか否かを判定する。
 管理サーバ70が、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、前記車両記憶装置28が記憶可能な既定数に達していないと判定した場合、管理サーバ70は認証パッケージATPと、記憶要求D34と、を車両20へ送信する。その後、管理システム10は図7に示すステップS50以降の処理を行なう。
 管理サーバ70が、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、前記車両記憶装置28が記憶可能な既定数に達していると判定した場合、管理サーバ70はステップS705の処理を行なう。
 ステップS705では、管理サーバ70は、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATのなかから、認証パッケージATPによって置き換えられるべき認証情報単位ATを選択する。
 図15は、ステップS705において管理サーバ70が行なう、認証パッケージATPによって置き換えられるべき認証情報単位ATを選択する処理を示すフローチャートである。管理サーバ70は、ステップS705の処理として、この一連の処理を行なう。
 図15に示すように、この一連の処理を開始すると、ステップS510において、管理サーバ70は、1つまたは複数の削除予約D41が未執行のまま残っているか否かを判定する。管理サーバ70は、車両記憶装置28に、フェードアウト状態の1つまたは複数のデジタルキーの認証情報単位ATが記憶済の場合、1つまたは複数の削除予約D41が未執行のまま残っていると判定する。車両記憶装置28には、フェードアウト状態のデジタルキーとして、フレンドデバイス51である第5デバイス30EのフレンドキーKFと、ノンフレンドデバイス52である第6デバイス30FのノンフレンドキーKNと、が記憶済である。すなわち、少なくとも1つの削除予約D41が未執行のまま残っている(ステップS510:YES)。よって、管理サーバ70は、処理をステップS511に進める。
 ステップS511では、管理サーバ70は、複数の削除予約D41が未執行のまま残っている状態か否かを判定する。管理サーバ70は、車両記憶装置28に、フェードアウト状態の複数のデジタルキーの認証情報単位ATが記憶済の場合、複数の削除予約D41が未執行のまま残っていると判定する。車両記憶装置28には、フェードアウト状態の複数のデジタルキーの認証情報単位ATとして、第5デバイス30EのフレンドキーKFの認証情報単位ATと、第6デバイス30FのノンフレンドキーKNの認証情報単位ATと、が記憶済である。すなわち、複数の削除予約D41が未執行のまま残っている(ステップS511:YES)。よって、管理サーバ70は、処理をステップS512へ進める。
 ステップS512では、管理サーバ70は、車両20に、車両記憶装置28が記憶済のフェードアウト状態の複数のデジタルキーの認証情報単位ATを全て削除させるための信号を生成する。すなわち、管理サーバ70は、未執行のまま残っている削除予約D41の対象になっている複数の認証情報単位ATを、車両20に、車両記憶装置28から全て削除させるための信号を生成する。管理サーバ70は、前記信号として図18に示す削除要求D101を生成する。その後、管理サーバ70は、削除要求D101を車両20に向けて送信する。その後、管理サーバ70は図15に示す一連の処理を終了する。
 図15に示す一連の処理を終了した後、図18に示すステップS705において、管理サーバ70は、記憶要求D102を生成する。記憶要求D102は、認証パッケージATPを車両記憶装置28に記憶させるための信号である。管理サーバ70は、記憶要求D102と、認証パッケージATPと、を車両20に向けて送信する。
 車両20は、削除要求D101を受信するとステップS706の処理を行なう。ステップS706では、車両20は、削除要求D101にしたがって、車両記憶装置28が記憶済のフェードアウト状態の複数のデジタルキーの認証情報単位ATを全て削除する。これによって、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数は、記憶可能な既定数未満となる。その後、車両20は、図19に示すステップS707の処理を行なう。
 ステップS707では、車両20は、記憶要求D102にしたがって、受信済の認証パッケージATPを記憶する。すなわち、車両20は、認証パッケージATPを、ノンフレンドキーKNを認証するための認証情報単位ATとして記憶する。
 <車両20が認証情報単位ATを記憶した後の処理>
 管理サーバ70は、ステップS705の処理の後、ステップS708の処理として、キートラックの完了通知M101を生成する。管理サーバ70は、第3デバイス30Cへ、キートラックの完了通知M101を送信する。
 第3デバイス30Cは、キートラックの完了通知M101を受信すると、ステップS709の処理を行なう。ステップS709の処理では、第3デバイス30Cは、ノンフレンドキーKNの登録完了を示す情報を、デバイスHMI_32に提示する。例えば、第3デバイス30Cは、ノンフレンドキーKNの登録完了を示す画像を、デバイスHMI_32に提示する。
 管理サーバ70は、ステップS708の処理の後、ステップS710の処理として削除通知M102と、削除通知M103と、を生成する。削除通知M102は、車両20から第6デバイス30Fのノンフレンドキー情報DKNに対応する認証情報単位ATが削除されたことを示す通知である。削除通知M103は、車両20から第5デバイス30Eのフレンドキー情報DKFに対応する認証情報単位ATと、第6デバイス30Fのノンフレンドキー情報DKNに対応する認証情報単位ATと、が削除されたことを示す通知である。管理サーバ70は、削除通知M102を第6デバイス30Fに向けて送信する。管理サーバ70は、削除通知M103を第5デバイス30Eに向けて送信する。
 第6デバイス30Fが削除通知M102を受信すると、第6デバイス30Fは削除通知M102にしたがってステップS711の処理を実行する。ステップS711では、第6デバイス30Fは、第6デバイス30Fのデバイス記憶装置37から、車両20によって削除された認証情報単位ATに対応するノンフレンドキー情報DKNを削除する。
 ステップS711では、第6デバイス30Fは、ノンフレンドキー情報DKNが削除されたことを示す情報を、デバイスHMI_32に提示する。第6デバイス30Fは、第6デバイス30Fのノンフレンドキー情報DKNに含まれる認証情報単位ATが車両記憶装置28から削除されたことを示す情報を、デバイスHMI_32に提示する。
 第5デバイス30Eが削除通知M103を受信すると、第5デバイス30Eは削除通知M103にしたがってステップS712の処理を実行する。ステップS712では、第5デバイス30Eは、第5デバイス30Eのデバイス記憶装置37から、車両20によって削除された認証情報単位ATに対応するノンフレンドキー情報DKNを削除する。第5デバイス30Eは、第5デバイス30Eのデバイス記憶装置37から、車両20によって削除された認証情報単位ATに対応するノンフレンドキー情報DKNが削除されたことを示す情報を、デバイスHMI_32に提示する。
 ステップS712では、第5デバイス30Eは、第5デバイス30Eのフレンドキー情報DKFに対応する認証情報単位ATが車両20から削除されたことを示す情報を、デバイスHMI_32に提示する。第5デバイス30Eは、第6デバイス30Fのノンフレンドキー情報DKNに対応する認証情報単位ATが車両20から削除されたことを示す情報を、デバイスHMI_32に提示する。その後、管理システム10は、一連の処理を終了する。
 <第5実施形態の作用>
 削除された認証情報単位ATに対応するキー情報DKを記憶済のシェアデバイス50は、車両20を使用することができなくなる。
 <第5実施形態の効果>
 (5-1)管理サーバ70は、シェアデバイス50のユーザに対して、シェアデバイス50に登録されているデジタルキーが使用できなくなったことを通知することが可能に構成されている。これによって、シェアデバイス50のユーザは、実際に車両の使用を試みる前に、デジタルキーがもはや使用不可能であることを気づくことができる。
 <第5実施形態の変更例>
 上記第5実施形態は、以下のように変更して実施することが可能に構成されている。上記第5実施形態および以下の第5実施形態についての変更例は、技術的に矛盾しない範囲で互いに組合せて実施することが可能に構成されている。
 ・管理サーバ70のサーバ実行装置71が置き換えプログラムPMを実行することで、認証情報単位ATの置き換えに関する処理を実行する場合、車両管理装置26のサーバ実行装置71は、車両プログラムPVにおける認証情報単位ATの置き換えに関する処理を実行しなくてもよい。管理サーバ70のサーバ実行装置71が置き換えプログラムPMを実行することで、認証情報単位ATの置き換えに関する処理を実行する場合、車両記憶装置28は、車両プログラムPVとして、認証情報単位ATの置き換えに関する処理を記憶していなくてもよい。
 <その他の変更例>
 その他、上記各実施形態に共通して変更可能な要素としては次のようなものがある。以下の変更例は、技術的に矛盾しない範囲で互いに組合せて実施することが可能に構成されている。
 ・上記各実施形態におけるデジタルキーに関する事項は、CCCに準拠していなくてもよい。
 ・車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している場合に認証情報単位ATを削除する処理を備えている一連の処理は、上記各実施形態の例に限られない。例えば、図20に示す管理サーバ70は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうちのいずれかを、削除されるべき認証情報単位ATとして選択するように構成されている。ただし、管理サーバ70は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているか否かを判定しない。図20に示す車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているか否かを判定するように構成されている。ただし、車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのうち、削除されるべき認証情報単位ATを選択しない。図20に示す第3デバイス30Cは、ノンフレンドキー情報DKNを記憶していないデバイス30のうち、当該一連の処理によってノンフレンドデバイス52とされるデバイス30である。
 図20の例を引き続き説明する。図示しないフレンドデバイス51において、第3デバイス30Cに対するノンフレンドキーKNの登録要求操作が実行されることによって、管理システム10は、ノンフレンドキーKNの登録を行なうべく、図7に示す一連の処理を行なう。図20に示すステップS801は、図7に示すステップS47とで同様である。ステップS801の処理の後、第3デバイス30Cは、ステップS802の処理を行なう。図20に示すステップS802の処理は、図7に示すステップS48とで同様である。図20に示すステップS803の処理は、図7に示すステップS48とで同様である。
 ステップS803の処理として、管理サーバ70は、ノンフレンドキー情報DKNに含まれる認証パッケージATPと、認証パッケージATPを記憶するための記憶要求D34と、を車両20へ送信する。その後、車両20が、認証パッケージATPおよび記憶要求D34を受信すると、車両20はステップS804の処理を行なう。
 ステップS804では、車両20は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達しているか否かを判定する。車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している場合、車両20は上限通知M111を生成する。上限通知M111は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達していることを示す信号を備えている。車両20は上限通知M111を管理サーバ70に向けて送信する。管理サーバ70は、上限通知M111を受信することによって、車両20が記憶済の1つまたは複数の認証情報単位ATの数が、車両20が記憶可能な既定数に達していることを把握可能に構成されている。
 上限通知M111を受信済の管理サーバ70は、ステップS805の処理を実行する。ステップS805では、管理サーバ70は、図14に示すステップS505とで同様の処理を行なう。これによって、管理サーバ70は、削除されるべき認証情報単位ATを選択する。その後、管理サーバ70は、図10に示す置き換え要求D111を車両20に向けて送信する。
 置き換え要求D111を受信済の車両20は、ステップS806の処理を行なう。ステップS806の処理では、車両20は、図10に示すステップS105とで同様の処理を行なう。車両20は、ステップS806の処理を行なった後、処理を図20に示すステップS807に進める。
 ステップS807では、車両20は完了通知M112を生成する。完了通知M112は、車両20が、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、ステップS805において管理サーバ70が選択済の認証情報単位ATと置き換えて車両記憶装置28に記憶したことを示す信号を備えている。すなわち、完了通知M112は、ステップS805において管理サーバ70が選択済の認証情報単位ATが削除された情報を備えている。車両20は、完了通知M112を管理サーバ70へ送信する。完了通知M112を受信済の管理サーバ70は、ステップS808の処理を行なう。
 ステップS808では、管理サーバ70は完了通知M113を生成する。完了通知M113は、車両20が、第3デバイス30Cのノンフレンドキー情報DKNに含まれる認証パッケージATPを、車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの代わりに記憶したことを示す信号を備えている。すなわち、完了通知M113は、ステップS805において管理サーバ70が選択済の認証情報単位ATが削除された情報を備えている。管理サーバ70は、完了通知M113を第3デバイス30Cへ送信する。
 第3デバイス30Cが完了通知M113を受信すると、第3デバイス30CはステップS809の処理を行なう。ステップS809では、第3デバイス30Cは、車両20への第3デバイス30CのノンフレンドキーKNの登録が完了したことを示す登録完了の情報を、デバイスHMI_32に提示する。その後、管理システム10は、今回の認証情報単位ATの置き換えについての一連の処理を終了する。
 <確認通知M121の送信>
 ・管理システム10は、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかから、削除されるべき認証情報単位ATを選択した場合、認証情報単位ATの削除を許可するか否かをオーナーデバイス40のユーザに確認してもよい。
 図21は、図10に示す一連の処理において、車両記憶装置28に記憶済の1つまたは複数の認証情報単位ATのなかから、削除されるべき認証情報単位ATを車両20が選択した後に、前記車両20が実行する一連の処理の流れを示す説明図である。図1に示すように、車両20において、車両記憶装置28は、車両プログラムPVを記憶済である。車両実行装置27は、車両記憶装置28に記憶済の車両プログラムPVを実行する。これによって、車両20は一連の処理を実行する。オーナーデバイス40は、図5に示す一連の処理によってオーナーキーKOを示すキー情報DKを記憶済の第1デバイス30Aである。
 ステップS104では、車両20は、図10に示すステップS104とで同様の処理を行なう。車両20が、削除されるべき認証情報単位ATを選択すると、車両20はステップS105の処理を行なう。
 ステップS901では、車両20は、確認要求D121を生成する。確認要求D121は、ステップS104において車両20が選択済の認証情報単位ATを削除するための許可を、オーナーデバイス40のユーザに求める要求である。車両20は、確認要求D121と、ネーム情報ATP5と、を管理サーバ70に向けて送信する。ネーム情報ATP5は、ステップS104において車両20が選択済の認証情報単位ATに含まれる。
 管理サーバ70は、確認要求D121を車両20から受信可能に構成されている。管理サーバ70は、確認要求D121を受信すると、ステップS902の処理を行なう。ステップS902では、管理サーバ70は、確認要求D121にしたがって、前記認証情報単位ATを削除するための許可を求める通知である確認通知M121を生成する。確認通知M121は、デバイス30の操作を通じて前記認証情報単位ATの削除を許可するか否かが設定されるようにするための情報を備えている。管理サーバ70は、車両20から受信済のネーム情報ATP5と、確認通知M121と、をオーナーデバイス40に向けて送信する。
 <確認通知M121を受信後にオーナーデバイス40が行なう処理>
 オーナーデバイス40は、確認通知M121を管理サーバ70から受信可能に構成されている。オーナーデバイス40が確認通知M121を受信すると、オーナーデバイス40は、ステップS903の処理を行なう。ステップS903では、オーナーデバイス40は、前記認証情報単位ATの削除を許可するか否かをオーナーデバイス40のユーザに設定させるための画像を、デバイスHMI_32に提示する。
 図22は、オーナーデバイス40のデバイスHMI_32に提示される、前記認証情報単位ATの削除を許可するか否かをオーナーデバイス40のユーザに確認する画像の一例である。図22に示す「ネーム情報」の欄には、オーナーデバイス40が管理サーバ70から受信済のネーム情報ATP5が表示される。オーナーデバイス40のユーザは、デバイスHMI_32に提示されている案内に従って、前記認証情報単位ATの削除を許可するか否かについて、ラジオボタンによって「YES」、または「NO」のうちのいずれか1つを選択する。
 <ステップS903:YESの場合>
 オーナーデバイス40のユーザが、ラジオボタンによって「YES」を選択した後、「決定」を押した場合(ステップS903:YES)、オーナーデバイス40は、許可通知M122を生成する。許可通知M122は、認証情報単位ATの削除を許可する通知である。オーナーデバイス40は、管理サーバ70に向けて許可通知M122を送信する。
 <許可通知M122を受信後に管理システム10が行なう処理>
 管理サーバ70は、許可通知M122を受信すると、ステップS904の処理を行なう。ステップS904では、管理サーバ70は、継続要求D122を生成する。継続要求D122は、車両20に対して認証情報単位ATの削除を許可するための信号を備えている。管理サーバ70は、継続要求D122を車両20に向けて送信する。
 車両20は、継続要求D122を受信すると、ステップS105の処理を行なう。ステップS105では、車両20は、図10に示すステップS105とで同様の処理を行なう。すなわち、車両20は、車両記憶装置28から認証情報単位ATを削除する。その後、管理システム10は、図10に示すステップS106以降の処理を行なう。
 <ステップS93:NOの場合>
 図21に示すステップS903において、オーナーデバイス40のユーザが、ラジオボタンによって図22に示す「NO」を選択した後、「決定」を押した場合(ステップS903:NO)、オーナーデバイス40は、拒否通知M123を生成する。拒否通知M123は、前記認証情報単位ATの削除を拒否する通知である。オーナーデバイス40は、拒否通知M123を管理サーバ70に向けて送信する。
 <拒否通知M123を受信後に管理システム10が行なう処理>
 管理サーバ70は、拒否通知M123を受信すると、ステップS905の処理を行なう。ステップS905では、管理サーバ70は中止要求D123を生成する。中止要求D123は、車両20に、前記認証情報単位ATの削除を中止することを要求する。管理サーバ70は、中止要求D123を車両20に向けて送信する。
 車両20は、中止要求D123を受信すると、ステップS906の処理を行なう。ステップS906では、車両20は、前記認証情報単位ATの削除を中止する。その後、管理システム10は、車両記憶装置28から前記認証情報単位ATを削除しないまま、一連の処理を終了する。この場合、車両記憶装置28には新たな認証情報単位ATは記憶されない。
 管理システム10は、当該一連の処理を実行することによって、当認証情報単位の削除を許可するか否かを、オーナーデバイス40のユーザに確認することが可能に構成されている。
 管理サーバ70は、確認通知M121をシェアデバイス50に送信してもよい。例えば、管理サーバ70は、確認通知M121を、次のシェアデバイス50に向けて送信してもよい。すなわち確認通知M121の送信先のシェアデバイス50は、ステップS903において車両20から受信済のネーム情報ATP5と同一のネーム情報ATPを記憶済である。管理サーバ70は、確認通知M121をオーナーデバイス40と、シェアデバイス50と、に向けて送信してもよい。
 <ノンフレンドデバイス52による新たなノンフレンドキーKNの登録>
 ・ノンフレンドデバイス52は、新たなノンフレンドキーKNが登録されるための要求を送信できてもよい。つまり、シェアキーKSを記憶済のシェアデバイス50は、このシェアデバイス50がフレンドデバイス51であるかノンフレンドデバイス52であるかにかかわらず、新たなノンフレンドキーKNが登録されるための要求を送信してもよい。この場合、管理システム10は、図7に示す一連の処理によって、新たなノンフレンドキーKNについて登録すればよい。
 例えば、図4に示す第3デバイス30Cは、車両20のノンフレンドキーKNを示すキー情報DKを記憶済のノンフレンドデバイス52である。第3デバイス30Cは、車両20の新たなノンフレンドキーKNが登録されるための要求を送信してもよい。その結果、車両20の新たなノンフレンドキーKNのキー情報DKを記憶済の新たなデバイス30が、ノンフレンドデバイス52として登録される。この場合、フレンドキーKFを示すフレンドキー情報DKFを記憶済の第2デバイス30Bは、第1デジタルキー(フレンドキーKF)を示すキー情報DKを記憶済のデバイス30である。すなわち、第1デジタルキーはオーナーキーKOに限らない。第3デバイス30Cは、第2デバイス30Bからの登録要求D31に基づき登録されるノンフレンドキーKNを示すノンフレンドキー情報DKNを記憶済である。第3デバイス30Cは、第2デジタルキー(ノンフレンドキーKN)を示すキー情報DKを記憶済のデバイス30である。第3デバイス30Cからの登録要求に基づき登録される新たなノンフレンドキーKNを示すキー情報DKを記憶済の新たなデバイスは、第3デジタルキー(ノンフレンドキーKN)を示すキー情報DKを記憶済のデバイス30である。
 この場合、車両記憶装置28は、第1デジタルキー(フレンドキーKF)を認証するための認証情報単位ATとして、フレンドキーKFを認証するための認証情報単位ATを記憶済である。車両記憶装置28は、第2デジタルキー(ノンフレンドキーKN)を認証するための認証情報単位ATとして、ノンフレンドキーKNを認証するための認証情報単位ATを記憶済である。車両記憶装置28は、第3デジタルキー(ノンフレンドキーKN)を認証するための認証情報単位ATとして、前記新たなノンフレンドキーKNを認証するための認証情報単位ATを記憶済である。
 以下は、車両記憶装置28に、第2デジタルキー(ノンフレンドキーKN)を認証するための認証情報単位ATと、第3デジタルキー(ノンフレンドキーKN)を認証するための認証情報単位ATと、が記憶されており、且つ車両記憶装置28が記憶済の1つまたは複数の認証情報単位ATの数が、記憶可能な既定数に達している車両20を説明する。車両20は、さらに新たな認証情報単位ATを受信したとき、車両20に記憶済の前記新たなノンフレンドキーKNを認証するための認証情報単位ATを、削除されるべき認証情報単位ATとして選択してもよい。同様に管理サーバ70は、さらに新たな認証情報単位ATを車両20に記憶させるための要求を受信したとき、車両20に記憶済の前記新たなノンフレンドキーKNが認証されるときに必要であった認証情報単位ATを、削除させるための命令を、車両20に向けて送信してもよい。
 <管理システム10>
 ・車両20は、BLEモジュール23、UWBモジュール24、またはNFCモジュール25、の一部を有していなくてもよい。車両20は、少なくとも1つの近距離通信モジュールを有していれば、デバイス30との近距離通信を行なうことができる。また車両20は、これらの通信モジュールを有していることに限られず、デバイス30との近距離通信を行なうモジュールを有していればよい。
 ・車両管理装置26は、デジタルキーの処理を主とするECUであることに限られない。車両管理装置26は、例えば、車両20が有している複数のECUを統括して管理するセントラルECUであってもよい。
 ・車両管理装置26は、コンピュータプログラム(ソフトウェア)またはプログラム製品に従って各種処理を実行する1つ以上のプロセッサを備えている回路(circuitry)として構成してもよい。車両管理装置26は、各種処理のうち少なくとも一部の処理を実行する、特定用途向け集積回路(ASIC)等の1つ以上の専用のハードウェア回路、またはそれらの組合せ、を備えている回路として構成してもよい。プロセッサは、CPUと、RAMならびにROM等のメモリと、を備えている。メモリは、各種処理をCPUに実行させるように構成されたプログラムコード、プログラム、プログラム製品、または指令、を格納している。メモリすなわち非一時的なコンピュータ読取可能な記憶媒体は、汎用または専用のコンピュータでアクセスできるあらゆる利用可能な媒体を備えている。この点、デバイス30および管理サーバ70についても同様である。
 ・デバイス30は、スマートフォンに限られない。スマートウォッチであってもよい。またデバイス30は、所定サーバであってもよい。この場合、所定サーバに、デバイス30が含まれてもよい。例えば、レンタル事業者および/またはシェアリング事業者が車両20のオーナーである場合、オーナーデバイス40は、所定サーバに含まれてもよい。また例えば、フレンドデバイス51は、所定サーバに含まれてもよい。
 ・上記各実施形態において、複数のデジタルキーには、オーナーキーKO、フレンドキーKF、ノンフレンドキーKN、の順に上から下に並んだ階層が存在しており、階層が高いほどデジタルキーの権限が大きく設定されている。デジタルキーの階層が高いほど権限が大きく設定されていなくてもよい。例えば、オーナーキーKO、フレンドキーKF、ノンフレンドキーKN、の3つの階層について同じ大きさの権限が設定されてもよい。
 ・デバイスサーバ60は、デバイス30の種別ごとに設けられていなくてもよい。複数のデバイス30と、管理サーバ70と、が無線通信可能となっていればよい。デバイスサーバ60が省かれてもよい。複数のデバイス30と、管理サーバ70と、が直接無線通信可能であればよい。
 ・管理サーバ70は、複数のサーバによって構成されてもよい。例えば、データベースDBを記憶するサーバ部分と、サーバプログラムを実行するサーバ部分と、で管理サーバ70が構成されてもよい。また例えば、車両20に通信するサーバ部分と、デバイスサーバ60に通信するサーバ部分と、で管理サーバ70が構成されるとともに、これらのサーバ部分同士が互いに通信可能となってもよい。
 ・管理サーバ70は、データベースDBを記憶していなくてもよい。管理サーバ70は、少なくとも、管理システム10における1つのデジタルキーについて、デバイス30のキー情報DKと、車両管理装置26の認証情報単位ATと、の組合せを管理していればよい。
 ・シェアデバイス50は、上記実施形態のように、シェアキーKSを受け取る機能を有している。シェアデバイス50のように、デジタルキーを受け取る機能を有しているデバイス30は、レシーバーデバイスと呼ばれることがある。
 <各種情報について>
 ・認証情報単位ATは、デジタルキーが使用される際に前記デジタルキーが認証されるための情報であればよく、上記各実施形態の例に限られない。例えば、認証情報単位ATは、車両管理装置26とデバイス30とで共通の共通鍵であってもよい。また例えば、認証情報単位ATは、共通秘密鍵であってもよい。
 ・キー情報DKに含まれる情報の構成は、上記実施形態の例に限られない。例えば、オーナーキー情報DKOは、スロット識別情報ST4を有していなくてもよい。また例えば、キー情報DKは、デジタルキーの種別を示す情報を有してもよい。デジタルキーの種別は、例えば、オーナーキーKO、フレンドキーKF、およびノンフレンドキーKN、のうちの1つを示す情報である。
 ・データベースDBは、デバイス30の種別を示す情報を含んでいてもよい。デバイス30の種別は、例えば、スマートフォン、スマートウォッチ、および上述の変更例のような所定サーバ、などのうちのいずれかを示す情報である。
 ・データベースDBにおけるデータブロックDAの構造は、上記各実施形態の例に限られない。データベースDBは、管理システム10において管理サーバ70が管理するべく必要な情報を含んでいればよい。
 <デジタルキーを登録する一連の処理>
 ・オーナーキーKOを登録する一連の処理は、上記各実施形態の例に限られない。例えば、ステップS12の処理によるペアリングがなされなくても、車両20と、第1デバイス30Aと、が管理サーバ70を介して生成データDCなどの情報を送受信することで、オーナーデバイス40はオーナーキー情報DKOを記憶してもよい。オーナーキーKOを登録する一連の処理は、オーナーキー情報DKOに含まれる情報の構造および認証情報単位ATに含まれる情報の構造に応じて、適宜変更されればよい。
 ・フレンドキーKFを登録する一連の処理は、上記各実施形態の例に限られない。例えば、管理サーバ70は、認証パッケージATPおよび記憶要求D24を車両20に送信した後に、ステップS29の処理によって、データベースDBを更新してもよい。フレンドキーKFを登録する一連の処理は、フレンドキー情報DKFに含まれる情報の構造と、認証情報単位ATに含まれる情報の構造と、に応じて適宜変更されればよい。
 ・ノンフレンドキーKNを登録する一連の処理は、上記各実施形態の例に限られない。ノンフレンドキーKNを登録する一連の処理の順番は、フレンドキーKFを登録する一連の処理の順番とは、異なってもかまわない。ノンフレンドキーKNを登録する一連の処理は、ノンフレンドキー情報DKNに含まれる情報の構造と、認証情報単位ATに含まれる情報の構造と、に応じて適宜変更されればよい。
 ・デジタルキーの種類に、ノンフレンドキーKNが含まれていなくてもよい。つまり、管理システム10において、シェアキーKSは、フレンドキーKFのみであってもよい。
 <デジタルキーを削除する一連の処理>
 ・上記各実施形態では、フレンドデバイス51は、ノンフレンドキーKNを削除する際に、削除予約D41を管理サーバ70へ送信しているが、送信されるのは予約でなくてもよい。すなわち、フレンドデバイス51は、既定条件RCにかかわらずノンフレンドキーKNを削除する要求を管理サーバ70へ送信してもよい。またフレンドデバイス51が削除要求を発することに限らず、オーナーデバイス40がノンフレンドキーKNを削除する要求を発することによって、管理サーバ70は、ステップS62以降の処理を進めてもよい。
 ・以下、ノンフレンドデバイス52においてノンフレンドキーKNの削除を要求する操作が実行される場合を説明する。この場合、ノンフレンドデバイス52は、図9のステップS81における処理に代えて、前記ノンフレンドデバイス52に登録されているノンフレンドキーKNを削除する要求を管理サーバ70へ送信してもよい。管理サーバ70は、削除要求を受信すると、図8に示すステップS66とで同様に、ノンフレンドキー情報DKNを削除する要求を生成する。その後、管理サーバ70は、前記ノンフレンドデバイス52に向けてノンフレンドキー情報DKNを削除する要求を送信する。ノンフレンドキー情報DKNを削除する要求を受信済の前記ノンフレンドデバイス52は、図8に示すステップS67とで同様に、ノンフレンドキー情報DKNを削除する。その後、前記ノンフレンドデバイス52は、管理サーバ70へ、ノンフレンドキー情報DKNが削除されたことを示す通知を送信する。管理サーバ70は、前記ノンフレンドデバイス52においてノンフレンドキー情報DKNが削除されたことを示す通知を受信後、図9に示すステップS82以降の処理を進める。前記ノンフレンドデバイス52は、管理サーバ70へ、ノンフレンドキー情報DKNが削除されたことを示す通知を送信しなくてもよい。この場合、管理サーバ70は、前記ノンフレンドデバイス52に向けてノンフレンドキー情報DKNを削除する要求を送信した後、図9に示すステップS82以降の処理を進める。
 ・フレンドデバイス51の操作に起因してノンフレンドキーKNを削除する場合と、ノンフレンドデバイス52の操作に起因してノンフレンドキーKNを削除する場合と、のいずれでも削除予約が管理サーバ70に要求されてもよい。
 ・オーナーデバイス40および/または車両20が、ノンフレンドキーKNの削除を要求してもよい。また例えば、管理サーバ70が、所定条件が満たされたときに、ノンフレンドキーKNの削除要求を生成してもよい。

Claims (19)

  1.  車両に搭載される車両管理装置であって、前記車両管理装置は、
     車両処理回路と、
     1つまたは複数のデジタルキー情報単位を記憶するように構成されている車両記憶装置であって、前記デジタルキー情報単位はデジタルキーに関する情報単位であり、前記車両記憶装置は前記デジタルキー情報単位の記憶済数について前記車両記憶装置に記憶可能な既定数を有している、前記車両記憶装置と、
     を備えており、
     前記車両処理回路は、前記記憶済数が前記既定数に達している状態で、新たに前記デジタルキー情報単位を受信したとき、前記車両記憶装置に記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを、削除するように構成されている、
     車両管理装置。
  2.  1つまたは複数の削除予約は、対応する既定条件が成立したときに、削除対象である前記デジタルキー情報単位の削除を執行するための指令であり、
     前記車両処理回路は、前記記憶済数が前記既定数に達しているとともに1つまたは複数の前記削除予約が未執行のまま残っている状態で、新たに前記デジタルキー情報単位を受信したとき、未執行の前記削除予約の対象になっている前記デジタルキー情報単位を削除するように構成されている、
     請求項1に記載の車両管理装置。
  3.  1つまたは複数の削除予約は、対応する既定条件が成立したときに、削除対象である前記デジタルキー情報単位の削除を執行するための指令であり、
     前記車両処理回路は、前記記憶済数が前記既定数に達しているとともに複数の前記削除予約が未執行のまま残っている状態で、新たに前記デジタルキー情報単位を受信したとき、未執行のまま残っている複数の前記削除予約の対象になっている前記デジタルキー情報単位を全て削除するように構成されている、
     請求項1または2に記載の車両管理装置。
  4.  前記車両処理回路は、前記車両記憶装置に記憶済の1つまたは複数の前記デジタルキー情報単位に対して、前記車両のユーザが優先順位を設定することを許容するように構成されており、
     前記車両処理回路は、前記記憶済数が前記既定数に達している状態で、新たに前記デジタルキー情報単位を受信したとき、
     設定済の前記優先順位に基づき、削除対象である前記デジタルキー情報単位を選択するように構成されている、
     請求項1~3のいずれか1項に記載の車両管理装置。
  5.  前記車両処理回路は、
     前記車両記憶装置に記憶済の複数の前記デジタルキー情報単位のうち、プロテクト対象にされる前記デジタルキー情報単位が選択されていることを把握することと、
     新たに前記デジタルキー情報単位を受信したとき、前記プロテクト対象としては未選択の複数の前記デジタルキー情報単位のうちのいずれかを削除することと、
     を行なうように構成されている、
     請求項1~4のいずれか1項に記載の車両管理装置。
  6.  前記デジタルキーは、第1デジタルキー、前記第1デジタルキーに基づき生成される第2デジタルキー、および前記第2デジタルキーに基づき生成される第3デジタルキー、を備えており、
     前記車両処理回路は、前記車両記憶装置が前記第2デジタルキーに対応する前記デジタルキー情報単位と、前記第3デジタルキーに対応する前記デジタルキー情報単位と、を記憶しているとともに、前記記憶済数が前記既定数に達している状態で、新たに前記デジタルキー情報単位を受信したとき、前記第3デジタルキーに対応する前記デジタルキー情報単位を削除するように構成されている、
     請求項1~5のいずれか1項に記載の車両管理装置。
  7.  前記車両処理回路は、前記記憶済数が前記既定数に達している状態で、新たに前記デジタルキー情報単位を受信したとき、新たに受信済の前記デジタルキー情報単位に対応する登録要求を行なったデバイスによる別の登録要求に基づき、前記車両記憶装置に記憶済の1つまたは複数の前記デジタルキー情報単位を削除するように構成されている、
     請求項1~6のいずれか1項に記載の車両管理装置。
  8.  サーバ処理回路を備えている管理サーバであって、前記サーバ処理回路は、
     1つまたは複数のデジタルキーを管理するべく、1つまたは複数の前記デジタルキーに関する情報単位としての1つまたは複数のデジタルキー情報単位を車両に記憶させるための記憶要求を受信することと、
     前記車両が記憶済の前記デジタルキー情報単位の数としての記憶済数が、前記車両が記憶可能な前記デジタルキー情報単位の既定数に達しているか否かを把握することと、
     前記記憶済数が前記既定数に達している前記車両に対する前記記憶要求を受信したとき、前記車両に、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除させるための命令を送信することと、
     を行なうように構成されている、
     管理サーバ。
  9.  1つまたは複数の削除予約は、対応する前記デジタルキー情報単位の削除を、既定条件が成立したときに前記車両に執行させるための指令であり、
     前記サーバ処理回路は、
     1つまたは複数の前記削除予約が、前記車両に未執行のまま残っているか否かを把握することと、
     前記記憶済数が前記既定数に達しているとともに1つまたは複数の前記削除予約が未執行のまま残っている前記車両に対する前記記憶要求を受信したとき、前記車両に、未執行の前記削除予約の対象になっている1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除させるための命令を送信することと、
     を行なうように構成されている、
     請求項8に記載の管理サーバ。
  10.  1つまたは複数の削除予約は、対応する前記デジタルキー情報単位の削除を、既定条件が成立したときに前記車両に執行させるための指令であり、
     前記サーバ処理回路は、
     1つまたは複数の前記削除予約が、前記車両に未執行のまま残っているか否かを把握することと、
     前記記憶済数が前記既定数に達しているとともに複数の前記削除予約が未執行のまま残っている前記車両に対する前記記憶要求を受信したとき、前記車両に、複数の前記削除予約の対象になっている前記デジタルキー情報単位を全て削除させるための命令を送信することと、
     を行なうように構成されている、
     請求項8または9に記載の管理サーバ。
  11.  前記サーバ処理回路は、
     前記車両に記憶済の1つまたは複数の前記デジタルキー情報単位を把握することと、
     前記車両に記憶済の1つまたは複数の前記デジタルキー情報単位の優先順位を把握することであって、前記優先順位は前記車両のユーザによって設定される、前記優先順位を把握することと、
     前記記憶済数が前記既定数に達している前記車両に対する前記記憶要求を受信したとき、前記車両に、前記優先順位に基づき、削除対象である前記デジタルキー情報単位を選択させるための命令を送信することと、
     を行なうように構成されている、
     請求項8~10のいずれか1項に記載の管理サーバ。
  12.  前記サーバ処理回路は、
     前記車両に記憶済の複数の前記デジタルキー情報単位のうち、プロテクト対象にされる前記デジタルキー情報単位が選択されたことを把握することと、
     記憶済の1つまたは複数の前記デジタルキー情報単位の前記数が前記既定数に達している前記車両に対する前記記憶要求を受信したとき、前記車両に、前記プロテクト対象としては未選択の複数の前記デジタルキー情報単位のうちのいずれかを削除させるための命令を送信することと、
     を行なうように構成されている、
     請求項8~11のいずれか1項に記載の管理サーバ。
  13.  複数の前記デジタルキーは、第1デジタルキーと、前記第1デジタルキーに基づき生成される第2デジタルキーと、前記第2デジタルキーに基づき生成される第3デジタルキーと、を備えており、
     前記サーバ処理回路は、
     前記第2デジタルキーに対応する前記デジタルキー情報単位と、前記第3デジタルキーに対応する前記デジタルキー情報単位と、を前記車両が記憶しているとともに、前記記憶済数が前記既定数に達している前記車両に対して、前記記憶要求を受信したとき、前記車両に、前記車両に記憶済の前記第3デジタルキーに対応する前記デジタルキー情報単位を削除させるための命令を送信するように構成されている、
     請求項8~12のいずれか1項に記載の管理サーバ。
  14.  前記サーバ処理回路は、
     前記記憶済数が前記既定数に達している前記車両に対する前記記憶要求を受信したとき、前記車両に、前記記憶要求に対応する前記デジタルキー情報単位に対応する登録要求を行なったデバイスによる別の登録要求に基づき記憶済の1つまたは複数の前記デジタルキー情報単位を削除させるための命令を送信するように構成されている、
     請求項8~13のいずれか1項に記載の管理サーバ。
  15.  複数の前記デジタルキーは第1デジタルキーを備えており、前記第1デジタルキーは前記車両に対して1つのみ存在する前記デジタルキーであり、
     前記サーバ処理回路は、
     前記車両に向けて、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除させるための命令が送信されたとき、前記第1デジタルキーに対応するデジタルキー情報単位を記憶済のデバイスに向けて、前記車両から、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかが削除されることを通知するように構成されている、
     請求項8~14のいずれか1項に記載の管理サーバ。
  16.  前記サーバ処理回路は、前記車両に向けて、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除させるための命令が送信されたとき、削除される前記デジタルキー情報単位に対応する登録要求を行なったデバイスに向けて、前記デジタルキー情報単位が削除されることを通知するように構成されている、
     請求項8~15のいずれか1項に記載の管理サーバ。
  17.  前記サーバ処理回路は、前記車両に向けて、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除させるための命令が送信されたとき、削除される前記デジタルキー情報単位に対応するデジタルキー情報単位を記憶済のデバイスに向けて、前記デジタルキー情報単位が削除されることを通知するように構成されている、
     請求項8~16のいずれか1項に記載の管理サーバ。
  18.  前記サーバ処理回路は、前記車両に、複数の削除予約の対象になっている前記デジタルキー情報単位を全て削除させるための命令が送信されたとき、複数の前記削除予約の対象になっている前記デジタルキー情報単位に対応するデジタルキー情報単位を記憶済の複数のデバイスに向けて、前記削除予約の対象になっている前記デジタルキー情報単位が削除されることを通知するように構成されている、
     請求項8~17のいずれか1項に記載の管理サーバ。
  19.  管理システムであって、前記管理システムは、
     車両に搭載される車両管理装置であって、車両処理回路と車両記憶装置とを備えている前記車両管理装置と、
     1つまたは複数のデジタルキーを管理するためのサーバ処理回路を備えている管理サーバと、
     を備えており、
     前記車両記憶装置は、1つまたは複数のデジタルキー情報単位を記憶するように構成されており、1つまたは複数の前記デジタルキー情報単位は1つまたは複数の前記デジタルキーに関する情報単位であり、前記車両記憶装置は、記憶可能な前記デジタルキー情報単位の数の既定数を有しており、
     前記車両処理回路または前記サーバ処理回路のうちの少なくとも一方は、前記車両記憶装置に記憶済の前記デジタルキー情報単位の前記数が前記既定数に達している状態で、新たに前記デジタルキー情報単位を受信したとき、前記車両が記憶済の1つまたは複数の前記デジタルキー情報単位のうちのいずれかを削除するように構成されている、
     管理システム。
PCT/JP2025/019473 2024-07-12 2025-05-29 車両管理装置、管理サーバ、および管理システム Pending WO2026014100A1 (ja)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2024-112946 2024-07-12
JP2024112946A JP2026011934A (ja) 2024-07-12 2024-07-12 車両管理装置、管理サーバ及び管理システム

Publications (1)

Publication Number Publication Date
WO2026014100A1 true WO2026014100A1 (ja) 2026-01-15

Family

ID=98386594

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2025/019473 Pending WO2026014100A1 (ja) 2024-07-12 2025-05-29 車両管理装置、管理サーバ、および管理システム

Country Status (2)

Country Link
JP (1) JP2026011934A (ja)
WO (1) WO2026014100A1 (ja)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001084175A (ja) * 1999-09-10 2001-03-30 Fuji Xerox Co Ltd 文書セキュリテイ管理装置および文書セキュリティ管理方法
JP2006031097A (ja) * 2004-07-12 2006-02-02 Matsushita Electric Ind Co Ltd 通信システムならびにそれに用いられる通信端末、認証情報管理方法、認証情報管理プログラムおよび認証情報管理プログラムを格納する記録媒体
JP2011256561A (ja) * 2010-06-07 2011-12-22 Toyota Infotechnology Center Co Ltd 鍵装置、錠制御装置、制御用プログラムおよび制御方法
JP2018005353A (ja) * 2016-06-28 2018-01-11 トヨタ自動車株式会社 施解錠システム、サーバ、方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001084175A (ja) * 1999-09-10 2001-03-30 Fuji Xerox Co Ltd 文書セキュリテイ管理装置および文書セキュリティ管理方法
JP2006031097A (ja) * 2004-07-12 2006-02-02 Matsushita Electric Ind Co Ltd 通信システムならびにそれに用いられる通信端末、認証情報管理方法、認証情報管理プログラムおよび認証情報管理プログラムを格納する記録媒体
JP2011256561A (ja) * 2010-06-07 2011-12-22 Toyota Infotechnology Center Co Ltd 鍵装置、錠制御装置、制御用プログラムおよび制御方法
JP2018005353A (ja) * 2016-06-28 2018-01-11 トヨタ自動車株式会社 施解錠システム、サーバ、方法

Also Published As

Publication number Publication date
JP2026011934A (ja) 2026-01-23

Similar Documents

Publication Publication Date Title
WO2016189796A1 (ja) 車両用通信システム、車載装置及び鍵発行装置
JP2020119458A (ja) 管理装置およびその制御方法
JP2001197054A (ja) 認証書管理装置及び認証書管理方法及びコンピュータ読み取り可能な記録媒体
JP2026011934A (ja) 車両管理装置、管理サーバ及び管理システム
JP5988841B2 (ja) 通信装置、通信システム、情報処理方法及びプログラム
WO2013140684A1 (ja) 通信装置、通信用識別情報管理サーバ、通信用識別情報取得方法、通信用識別情報提供方法および記録媒体
WO2026014099A1 (ja) サーバ、設定方法、およびプログラム
JP2009237662A (ja) ファイル管理システム
JP2024125667A (ja) 通信制御装置、通信制御方法、及びデジタルキーシステム
JP6365594B2 (ja) 無線通信装置
JP2026023256A (ja) 管理サーバ、管理方法、及びプログラム
WO2026014106A1 (ja) サーバ、設定方法、プログラム、およびシステム
JP2026023258A (ja) 管理サーバ、管理方法、及びプログラム
JP2026023259A (ja) 管理サーバ、管理方法、及びプログラム
WO2026014105A1 (ja) システム、管理サーバ、車両管理装置、管理方法、及びプログラム
WO2026014082A1 (ja) 管理システム、デバイス、管理サーバ、車両
JP2026011941A (ja) 車両管理装置、管理方法、管理プログラム、管理システム
JP2026011942A (ja) 管理サーバ、管理方法、管理プログラム、管理システム
JP2026011940A (ja) 管理サーバ、車両
US20260034962A1 (en) Vehicle and management server
JP2026023260A (ja) サーバ及び通知プログラム
WO2026014074A1 (ja) サーバ、車載装置、車両、システム、サーバの管理方法、サーバのプログラム、車載装置の管理方法、及び車載装置のプログラム
JP2026011939A (ja) サーバ、デバイス、システム、サーバの管理方法、サーバのプログラム、デバイスの管理方法、及びデバイスのプログラム
US20260040064A1 (en) Management server, management system, deletion method, and non-transitory computer-readable storage medium storing deletion program
WO2026014077A1 (ja) 管理システム、管理サーバ、車両管理装置、及びデバイス

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 25835176

Country of ref document: EP

Kind code of ref document: A1