Charging control apparatus, storage medium, and charging control method
By allocating different storage areas to manage private keys and certificates in the memory of the charging control device, the problem of private keys being rewritten when the vehicle updates the certificate is solved, and the vehicle continuously charge authentication during the certificate update process is realized.
Patent Information
- Application Number
- CN202410324923.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-03-21
- Publication Date
- 2025-06-20
AI Technical Summary
In the prior art, when a vehicle updates a certificate, it may cause the private key corresponding to the currently available certificate to be rewritten, resulting in the authentication failure until a new certificate is installed.
A charging control device is designed to manage different private keys and certificates by allocating different storage areas in the memory. Specifically, the controller stores the first private key corresponding to the first certificate in one area and generates and stores the second private key in another area until the second certificate is installed.
It realizes that even when a new certificate is installed in a vehicle where the certificate has been installed, the certificate can be continued to be used for charging, avoiding authentication failure caused by the rewrite of the private key.
Smart Images

Figure CN120171365A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a charging control device, a program, and a charging control method. Background Art
[0002] Examples of vehicles (also referred to as electric vehicles) capable of charging a drive battery by connecting to an external power source include battery electric vehicles (BEV vehicles) and plug-in hybrid (PHV) vehicles. Examples of methods for authenticating charging of a drive battery mainly include an external authentication method (EIM) and plug and charge (PnC).
[0003] In PnC charging, a certificate is stored in the vehicle, and when the vehicle is connected to a charging facility (also referred to as a charging pile), the stored certificate and a signature generated by a private key corresponding to the certificate are sent from the vehicle to the charging facility to perform authentication, and charging is started when the authentication is successful. For example, when a certificate is issued, an on-board computer generates an on-board computer public key and an on-board computer private key paired with the on-board computer public key, and sends a request to issue a certificate regarding the on-board computer public key to a certificate authority. The certificate authority then receives the certificate issuance request sent by the on-board computer, signs the on-board computer public key included in the certificate issuance request, and issues a certificate to the on-board computer. In this way, the on-board computer obtains the certificate issued by the certificate authority in response to the certificate issuance request (for example, see Japanese Patent Application Laid-Open No. 2018-19415).
[0004] However, in the related art, the case of updating the issued certificate has not been considered.
[0005] For example, when a once-issued certificate is updated to a new certificate and a new private key is generated on the vehicle, the private key corresponding to the currently available certificate may be overwritten. Therefore, the private key corresponding to the currently available certificate may be lost, and authentication by the vehicle using the signature may fail until a new certificate for the update is installed in the vehicle. An aspect of an embodiment disclosed herein is to provide a device or the like that can continuously charge using a certificate even when a new certificate is installed in a vehicle in which a certificate has already been installed. Summary of the Invention
[0006] One aspect of the embodiments disclosed herein is illustrated by a charging control device for a vehicle, the charging control device including: a controller configured to communicate with a charging facility for charging authentication. The controller stores a first private key corresponding to a first certificate in a first area of a memory. The controller is configured to generate a second private key and a public key in response to a request from a certificate issuer. The controller is configured to store the second private key in a second area of the memory different from the first area. The controller is configured to send the public key to the certificate issuer to receive a second certificate issued by the certificate issuer. The controller is configured to: keep using the first private key until the installation of the second certificate is completed. The controller is configured to: use the second private key when the installation is completed.
[0007] In the charging control device, the controller stores a first private key corresponding to a currently valid first certificate and a second private key corresponding to a newly issued second certificate based on a request from an issuer in different storage destinations. Therefore, the currently valid first private key is not overwritten by the newly generated second private key. For this reason, the controller can use the first private key until the installation of the second certificate is completed. When the installation of the second certificate is completed, the controller uses the second private key. In this way, even when a new second certificate is installed in a vehicle in which the first certificate has already been installed, the charging control device can continue charging using the first certificate and the first private key corresponding thereto. When the installation of the second certificate is completed, the charging control device can immediately switch to a process using the second certificate and the second private key corresponding thereto. That is, even when a new certificate is installed in a vehicle in which a certificate has already been installed, the charging control device can perform control to continue charging using the certificate. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Exemplary embodiments of the present disclosure will be described in detail based on the following drawings, in which:
[0009] Figure 1 A vehicle equipped with a charging control device according to a first embodiment is shown;
[0010] Figure 2 The hardware configuration of the vehicle and the charging facility is shown;
[0011] Figure 3 The process of updating the private key of the charging control device according to the first embodiment is shown;
[0012] Figure 4 A sequence diagram showing the process of updating a certificate according to the first embodiment;
[0013] Figure 5 A flowchart showing the process of updating a certificate and a key pair performed by the charging control device according to the first embodiment;
[0014] Figure 6 is a flowchart showing the update process of a certificate and a key pair performed by a charging control device according to a second embodiment;
[0015] Figure 7 is a sequence diagram showing the process of updating a certificate according to a third embodiment; and
[0016] Figure 8 shows the process flow of a charging control device according to a third embodiment. Detailed Description of the Invention
[0017] Hereinafter, a charging control device 10 and a computer program (hereinafter simply referred to as a program) will be described.
[0018] First Embodiment
[0019] will be described with reference to Figures 1 to 5 a charging control device 10, a program, and a charging control method according to a first embodiment.
[0020] Configuration
[0021] Figure 1 shows a vehicle 1 equipped with a charging control device 10 according to the present embodiment. Figure 1 Also shown is a charging facility (Electric Vehicle Supply Equipment (EVSE)) 2 that supplies power to a battery 19 (see Figure 2 , also referred to as a secondary battery or a storage battery) of the vehicle 1, and an MO server 5 and an Original Equipment Manufacturer (OEM) server 6 that exchange information with the vehicle 1 or the charging facility 2.
[0022] The vehicle 1 is called an electric vehicle and can charge a drive battery 19. The vehicle 1 includes a charging control device 10 and performs a charging process or charging control using the charging facility 2. In a charging process or the like, for PnC which is a first authentication process, the charging control device 10 of the vehicle 1 creates a signature based on a contract certificate or the like and an encryption key, and the charging facility 2 verifies the signature. When the authentication is successful, the vehicle 1 performs charging using the charging facility 2. For example, when a plug 2B that supplies power from the charging facility 2 is connected to a power receiving unit of the vehicle 1, the PnC process starts.
[0023] When charging the vehicle 1, in addition to the PnC process described above, a process by an external authentication method (EIM) such as presenting an RFID card or the like as a second authentication process is also possible. For this purpose, the charging facility 2 includes an EIM reader 2A. The external authentication method is, for example, an authentication method based on user information obtained from a credit card, a QR code (registered trademark), radio frequency identification (RFID), or the like via the EIM reader 2A.
[0024] The charging control device 10 can be connected to the MO server 5, the OEM server 6, etc. via the network N1. The network N1 includes a wireless network (e.g., Long-Term Evolution (LTE), 5th Generation Mobile Communication System (5G), 6th Generation Mobile Communication System (6G)), and a wired public network (e.g., the Internet).
[0025] For example, the charging facility 2 can transmit the signature sent from the vehicle 1 to the MO server 5 to request authentication of the user of the vehicle 1. When the authentication performed by the MO server 5 is successful, the charging facility 2 can charge the battery 19 of the vehicle 1 and charge the user of the vehicle 1 for the charging. When charging the vehicle 1, the vehicle 1 can request the charging facility 2 to install a contract certificate, etc. In this case, the vehicle 1 presents a certificate (e.g., OEM supply certificate) issued by the OEM (which is the manufacturer or seller of the vehicle 1) to the charging facility 2. When the charging facility 2 has a valid contract certificate, etc. associated with the OEM supply certificate, etc. notified by the vehicle 1, the charging facility 2 can provide the contract certificate, etc. to the vehicle 1. The charging facility 2 can access the MO server 5, obtain a valid contract certificate, etc. corresponding to the OEM supply certificate, and install the contract certificate, etc. in the vehicle 1.
[0026] As described above, certificates (OEM supply certificates, vehicle certificates, etc.) issued by the OEM (which is the manufacturer or seller of the vehicle 1) are installed in the vehicle 1 and stored in the memory 12 of the charging control device 10( Figure 2 ). The user of the vehicle 1 pre-signs a contract with a service provider (MO) to charge the battery 19 of the vehicle 1 through the charging facility 2. According to this contract, a contract certificate, etc. and an encryption key such as a private key are issued from the MO server 5 and installed in the vehicle 1 via, for example, the OEM server 6. The contract certificate and the encryption key can be referred to as certificate data. Certificate data such as a contract certificate can be installed in the vehicle 1 via, for example, the charging facility 2.
[0027] Hereinafter, the OEM supply certificate, the vehicle certificate, the contract certificate, etc. are collectively referred to as certificates. These certificates are electronic data installed in the vehicle 1 and are issued to the charging control device 10 of the vehicle 1 by external computers such as a certificate authority, the MO server 5, and the OEM server 6. Here, the certificate authority refers to an organization authorized to issue certificates to companies, organizations, individuals, etc. In addition to the certificate authority belonging to companies, organizations, etc. such as OEMs, the certificate authority can also be an issuing authority independent of companies, organizations, individuals, etc. such as OEMs and can be referred to as a root certificate authority having security and reliability through acceptance of inspection.
[0028] The charging control device 10 can create an electronic signature (digital signature) based on a certificate or the like and a private key corresponding to the certificate, and request authentication from an external computer such as a charging facility 2, an MO server 5, an OEM server 6, or a certificate authority. In this embodiment, the electronic signature is simply referred to as a signature. An external computer such as a charging facility 2, an MO server 5, an OEM server 6, or a certificate authority has a public key paired with the private key, and can determine whether authentication is possible by decrypting the signature. The private key and the public key can be examples of paired key information.
[0029] More specifically, the vehicle 1 is connected to the charging facility 2. A certificate (C) issued by the OEM server 6 (for example, an OEM supply certificate or a vehicle certificate) and a signature based on the private key (KS) are presented from the vehicle 1 to the charging facility 2. Then, the charging facility 2 verifies the signature using the public key of the corresponding certificate. In addition, validity period verification can be performed using OCSP, CRL, or the like.
[0030] The certificate can be distributed to a storage device accessible from the charging facility 2 and stored in the storage device. A storage device accessible from the charging facility 2 is, for example, a memory 22 of the charging facility 2, an external storage unit 23, or a storage device on the network N1 (for example, a computer accessible by the charging facility 2).
[0031] In this embodiment, an external computer that installs a certificate in the vehicle 1 via the network N1 is called an issuer. For example, when a contract certificate is issued from the MO server 5 and installed in the vehicle 1 via the OEM server 6 or the charging facility 2, the MO server 5 can be regarded as the issuer. In addition, for example, when an OEM supply certificate or a vehicle certificate is issued from the OEM server 6 and installed in the vehicle 1, the OEM server 6 can be regarded as the issuer.
[0032] This embodiment illustrates the process of updating the certificate C1 and the private key KS1 corresponding to the certificate C1 that have been installed in the charging control device 10 to a new certificate C2 and the private key KS2 corresponding to the certificate C2. That is, here, it is assumed that the certificate C1 is updated to the certificate C2 in an external computer such as the MO server 5, the OEM server 6, or the certificate authority.
[0033] For example, when the certificate C1 is updated in the OEM server 6, the OEM server 6 sends a request (R1) to generate a Certificate Signing Request (CSR) to the charging control device 10 of the vehicle 1 that has been distributed with the certificate C1. Then, the charging control device 10 creates a pair of a public key KO2 and a private key KS2, and sends a CSR (R2) including the public key KO2 in the created pair to the OEM server 6. Then, the OEM server 6 creates a new certificate C2, for example, by signing the received public key KO2 with the private key obtained by itself from the certificate authority. The OEM server 6 may transmit the CSR to the MO server 5 to request the creation of a new certificate C2, and receive the certificate C2 from the MO server 5 (R4). The OEM server 6 distributes the created certificate C2 to the charging control device 10 and installs the certificate C2 in the charging control device 10, thereby updating the certificate C1 to the certificate C2 (R3).
[0034] Accordingly, the private key KS1 is modified to the private key KS2. Thereafter, the charging control device 10 creates a signature based on the updated certificate C2 and the private key KS2, and requests authentication from the charging facility 2 or the like. The charging facility 2, or the MO server 5, the OEM server 6, etc. to which the signature is transmitted via the charging facility 2, uses the modified public key KO2 to determine whether the signature is appropriate and determines whether to authenticate the charging control device 10.
[0035] As described below, in this embodiment, the charging control device 10 updates the certificate C1 and the private key KS1 to the new certificate C2 and the new private key KS2 in a state where the signature using the existing private key KS1 is valid. Therefore, in this embodiment, when the charging control device 10 receives charging from the charging facility 2 through PnC, the charging control device 10 can stably charge from the charging facility 2 regardless of whether the private key KS1 is updated to KS2.
[0036] This embodiment describes an example of updating a certificate (for example, an OEM supply certificate or a vehicle certificate) according to a generation request from the OEM server 6. When updating a certificate (for example, a contract certificate) according to a generation request from the MO server 5, the MO server 5 can update the certificate of the charging control device 10 in the same manner via the OEM server 6. That is, the OEM server 6 can send a CSR generation request to the vehicle 1 in response to a request from the MO server 5. Then, the OEM server 6 can transmit the CSR received from the charging control device 10 to the MO server 5 and can request the issuance of a certificate. In addition, the OEM server 6 can transmit the updated certificate issued from the MO server 5 to the charging control device 10.
[0037] Figure 2The hardware configurations of the vehicle 1 and the charging facility 2 are shown. The charging control device 10 of the vehicle 1 and the charging facility 2 that charges the battery 19 mounted on the vehicle 1 constitute a charging system. The vehicle 1 includes the charging control device 10 and the battery 19, and the charging of the battery 19 is controlled by the charging control device 10.
[0038] The charging control device 10 includes a CPU 11, a memory 12, and external devices connected to an external interface (I / F), and performs information processing according to a program. Examples of the external devices include an external storage unit 13, a display unit 14, an operation unit 15, an external communication unit 16A, and a charging communication unit 16B. The CPU 11 and the memory 12 may be collectively referred to as a control unit. The control unit is also referred to as an electronic control unit (ECU). The control unit is an example of a controller.
[0039] The CPU 11 executes a computer program loaded in the memory 12 in an executable manner and provides the functions of the charging control device 10. The CPU 11 is also referred to as a processor or a microcontroller unit (MCU). The memory 12 stores the computer program executed by the CPU 11, data processed by the CPU 11, and the like.
[0040] The memory 12 is a dynamic random access memory (DRAM), a static random access memory (SRAM), a read-only memory (ROM), or the like. The external storage unit 13 is used as, for example, a storage area for assisting the memory 12, and stores the computer program executed by the CPU 11, data processed by the CPU 11, and the like. The external storage unit 13 is a hard disk drive, a solid state drive (SSD), or the like.
[0041] The display unit 14 is, for example, a liquid crystal display or an electroluminescent panel. The operation unit 15 is, for example, a keyboard or a pointing device. In this embodiment, a touch panel including a touch sensor is exemplified as the pointing device. The display unit 14 and the operation unit 15 serve as a user interface available to the user.
[0042] The external communication unit 16A exchanges data with another device (for example, the OEM server 6 in Figure 1 ) on a public network such as the network N1 (see Figure 1 ). For example, the CPU 11 communicates with a computer of a commercial carrier on the public network via the external communication unit 16A. The external communication unit 16A may be a wireless communication device accessing a mobile phone network. The external communication unit 16A may be a communication device accessing a wireless local area network (LAN). The external communication unit 16A is referred to as a telematics control unit (TCU) and may perform communication called telematics via the network N1.
[0043] The charging communication unit 16B exchanges signals with the charging communication unit 26B. That is, the charging communication unit 16B performs communication with the charging facility 2 by, for example, a communication method based on power line communication (PLC) or similar to PLC. The charging communication unit 16B can perform communication with the charging communication unit 26B according to Controller Area Network (CAN), Wireless LAN, Ethernet, etc., or according to a communication process based on them. The charging communication unit 16B can internally include a CPU, a memory, an input and output interface, a communication interface, etc. In the present embodiment, the charging control device 10 communicates with the charging facility 2 via the external communication unit 16A or the charging communication unit 16B, and performs a charging request and an authentication process.
[0044] The charging facility 2 includes a CPU 21, a memory 22, and external devices connected to an external interface (I / F), and performs information processing according to a program. Examples of the external devices include an external storage unit 23, a display unit 24, an operation unit 25, an external communication unit 26A, a charging communication unit 26B, and an EIM reader 2A. The charging facility 2 further includes a power supply circuit 29. Except for the EIM reader 2A and the power supply circuit 29, the configuration of the charging facility 2 is the same as that of the charging control device 10 of the vehicle 1, so its description is omitted.
[0045] The EIM reader 2A is a card reader that reads information from an IC card such as a credit card in a contact or non-contact manner, an image reading device that reads a QR code (registered trademark), an RFID reader, etc. The power supply circuit 29 supplies power to the battery 19 and charges the battery 19. In Figure 2 this case, the charging communication unit 16B and the charging communication unit 26B, and the battery 19 and the power supply circuit 29 are connected via Figure 1 the plug 2B in
[0046] That is, when the plug 2B is connected to the connection part in the vehicle 1 that charges the battery 19B (this connection part includes a power receiving unit of the power supply circuit and terminals of the charging communication unit 16B), the charging control device 10 of the vehicle 1 communicates with the charging facility 2. The charging control device 10 of the vehicle 1 communicates with the charging facility 2 via, for example, the charging communication units 16B and 26B, and performs PnC through TLS authentication and vehicle-to-grid (V2G) communication. The charging control device 10 of the vehicle 1 and the charging facility 2 authenticate each other through TLS authentication and V2G communication, charge the battery 19 of the vehicle 1, and perform an authentication process related to charging. When the plug 2B is connected to the connection part in the vehicle 1 (this connection part includes a power receiving unit of the power supply circuit and terminals of the charging communication unit 16B), the charging facility 2 and the charging control device 10 of the vehicle 1 can communicate with each other via the external communication units 16A and 26A.
[0047] The MO server 5 and the OEM server 6 have the same configurations as the CPUs 11 and 21, memories 12 and 22, external storage units 13 and 23, display units 14 and 24, operation units 15 and 25, external communication units 16A and 26A, etc. The MO server 5 and the OEM server 6 are general-purpose computers. The MO server 5 and the OEM server 6 may be a collection of multiple computers called a cloud.
[0048] The MO server 5 may be referred to as a computer of a commercial operator (MO) that provides a service for charging the vehicle 1 to a user. In addition to the MO, the charging facility 2 may also be managed and operated by a commercial operator called a charging station operator (CPO). The OEM server 6 may be referred to as a computer of a commercial operator related to the manufacture or sale of the vehicle 1.
[0049] Process for updating a certificate and a private key
[0050] Figure 3 Shows the process for the charging control device 10 to update the private key according to this embodiment. In Figure 3 , the middle arrow A shows the transition from the process labeled with symbol R1 to the process labeled with symbol R3. Figure 3 The process labeled with symbol R1 above the arrow A in corresponds to Figure 1 the symbol R1 in. The process labeled with symbol R1 is the process when the charging control device 10 receives a CSR generation request. Figure 3 The process labeled with symbol R3 below the arrow A in corresponds to Figure 1 the symbol R3 in. The process labeled with symbol R3 is the process when the charging control device 10 installs the certificate C2 received from the OEM server 6 and stores the certificate C2 in a secure memory in the memory 12 or the external storage unit 13.
[0051] Here, for example, the charging control device 10 has stored the private key KS1 corresponding to the certificate C1 in the slot SL1 of the secure memory in the memory 12 or the external storage unit 13. In the register of the CPU 11, it is registered that the currently used slot is SL1. That is, the charging control device 10 stores the first private key (private key KS1) corresponding to the installed first certificate (certificate C1) in the first area (slot SL1) of the memory 12 or the like. The certificate C1 is an example of the first certificate, the private key KS1 is an example of the first private key, and the slot SL1 is an example of the first area. Here, the secure memory is a storage device that checks the authenticity or legality of the access in response to an access request from the CPU 11 and allows access (read or write) when the authenticity or legality is confirmed. For example, the charging control device 10 sends a signature signed with a specific encryption key to the secure memory to request the secure memory to check the authenticity. The slots SL1 and SL2 are storage destinations in the secure memory and are, for example, addresses and register numbers.
[0052] In this state, for example, when a request to update the certificate C1 to a new certificate C2 is generated in the OEM server 6, a CSR generation request is sent from the OEM server 6 to the charging control device 10. When the CSR generation request is received, the charging control device 10 creates a pair of the public key KO2 and the private key KS2, and requests the slot SL2 of the secure memory to store the private key KS2 (also referred to as the generation of information). Accordingly, the new private key KS2 is stored in the slot SL2 while the existing private key KS1 is maintained in the slot SL1. Then, the charging control device 10 generates a CSR including the public key KO2 and sends the CSR to the OEM server 6 ( Figure 1 R2 in).
[0053] Then, in the following process indicated by the symbol R3, for example, the OEM server 6 creates the certificate C2 for the CSR and sends the certificate C2 to the charging control device 10. When the certificate C2 is received, the charging control device 10 changes the currently used slot in the register to SL2 and instructs the secure memory to delete (erase) the private key KS1 in the slot SL1. Accordingly, the private key KS1 in the slot SL1 is deleted (or erased), and a process such as signing with the private key KS2 in the slot SL2 is executed. As described above, in the present embodiment, the charging control device 10 manages one type of key stored in the secure memory using two slots. Therefore, when the number of types of keys to be managed is K (K is an integer), the charging control device 10 can prepare 2 * K slots.
[0054] In Figure 3In this case, the private keys KS1 and KS2 are stored in slots SL1 and SL2 of the secure memory. The charging control device 10 may also store key pairs (i.e., the pair of private key KS1 and public key KO1 or the pair of private key KS2 and public key KO2) in slots SL1 and SL2 of the secure memory. When the private keys KS1 and KS2 are stored in slots SL1 and SL2 of the secure memory, the public keys KO1 and KO2 may be stored in an area of the secure memory different from the memory 12. This is because: compared with the private keys KS1 and KS2, the storage of the public keys KO1 and KO2 does not require or does not greatly require enhanced security.
[0055] Hereinafter, the certificate C1, the public key KO1, and the private key KS1 may be referred to as the first certificate C1, the first public key KO1, and the first private key KS1. The certificate C2, the public key KO2, and the private key KS2 may be referred to as the second certificate C2, the second public key KO2, and the second private key KS2.
[0056] Figure 4 is a sequence diagram showing the process of updating a certificate according to the first embodiment. Figure 4 Illustrates a case where a request to update a certificate occurs in the OEM server 6. When a request to update a certificate occurs in the OEM server 6, the OEM server 6 sends a CSR generation request (P1) to the charging control device 10 of the vehicle 1. The CSR generation request in P1 is an example of a request from a certificate issuer. The OEM server 6 is an example of a certificate issuer. In Figure 4 the example, it is assumed that when the vehicle 1 is connected to the charging facility 2 through the plug 2B ( Figure 1 ), the charging control device 10 receives the CSR generation request. In Figure 4 the sequence diagram, the vertical axis corresponds to the passage of time.
[0057] When the charging control device 10 receives a CSR generation request during the connection of the vehicle 1 to the charging facility 2, the charging control device 10 returns a response (hereinafter referred to as a negative response) to the OEM server 6 indicating that the charging control device 10 does not respond to the CSR generation request (P2). The process of P2 is an example of the following process: when the charging control device 10 is connected to the charging facility 2, once a request is received from the OEM server 6 as the issuer, the request is rejected. Then, the charging control device 10 executes the process during the connection to the charging facility 2, such as the process using the current private key KS1, or continues the process being executed (P3). The process using the current private key KS1 includes, for example, generating a signature and requesting the charging facility 2 to authenticate the signature. For example, the charging control device 10 performs charging control on the charging facility 2 based on the valid private key KS1 and the certificate C1 corresponding to the valid private key KS1. Here, the current private key KS1 is stored in the slot SL1, and the currently used slot is registered as slot SL1 in the register of the charging control device 10.
[0058] Then, the OEM server 6 resends the CSR generation request to the charging control device 10 of the vehicle 1 (P4). The CSR generation request in P4 is also an example of a request from the certificate issuer. When the charging control device 10 receives the CSR generation request again, the vehicle 1 is not connected to the charging facility 2. When the CSR generation request is received in a state where the vehicle 1 is not connected to the charging facility 2, the charging control device 10 executes a key generation process (P5). The key generation process is, for example, as Figure 3 shown. Thus, the charging control device 10 requests the secure memory to store the new private key KS2 in the slot SL2 while maintaining the current private key KS1 in the slot SL1. Therefore, it can be said that the charging control device 10 does not rewrite the private key KS1 as the first private key with the private key KS2 as the second private key.
[0059] The process of P5 is an example of generating a second private key and a public key in response to a request from the certificate issuer. The private key KS2 generated in P5 is an example of the second private key. At this time, a public key KO2 paired with the private key KS2 is also generated. Storing the new private key KS2 in the slot SL2 is an example of storing the second private key in a second area different from the first area such as the memory 12. That is, the slot SL2 is an example of the second area. In addition, maintaining the current private key KS1 in the slot SL1 is an example of using the first private key until the installation of the second certificate is completed. That is, the charging control device 10 performs charging control on the charging facility 2 based on the valid private key KS1 and the certificate C1 corresponding to the valid private key KS1 until the second certificate (certificate C2) corresponding to the public key KO2 is installed.
[0060] Then, the charging control device 10 sends a CSR (P6) including the public key KO2 created in pair with the private key KS2 to the OEM server 6. The process of P6 is an example of sending a public key to the issuer. When receiving the CSR including the public key KO2 from the charging control device 10, the OEM server 6 creates a certificate C2 based on the public key KO2 and signs the certificate C2 using the private key issued by the certificate authority. Then, the OEM server 6 distributes the certificate C2 to the charging control device 10 (P7).
[0061] When receiving the certificate C2, the charging control device 10 registers that the currently used slot in the register is slot SL2, requests the secure memory to delete (also referred to as erase) the private key KS1 of slot SL1, and causes the secure memory to perform the deletion (erase) (P8). In P8, receiving the certificate C2 and registering the currently used slot in the register as slot SL2 is an example of installing the second certificate. In this way, in the charging control device 10, the OEM supply certificate, vehicle certificate, etc. and the corresponding private keys, etc. are modified. For example, the charging control device 10 performs charging control with the charging facility 2 based on the valid private key KS2 and the certificate C2 corresponding to the valid private key KS2. That is, when the installation of the second certificate (certificate C2) corresponding to the private key KS2 is completed, the charging control device 10 erases the private key KS1 as the first private key. Then, the charging control device 10 performs charging control with the charging facility 2 based on the valid second private key (private key KS2) and the second certificate (certificate C2). In the charging control device 10, the process for modifying the private key corresponding to the contract certificate is the same as that of Figure 4 except that both the OEM server 6 and the MO server 5 are involved.
[0062] Similarly in Figure 4 the private keys KS1 and KS2 are stored in slots SL1 and SL2 of the secure memory. The charging control device 10 can also store key pairs (i.e., the pair of the private key KS1 and the public key KO1 or the pair of the private key KS2 and the public key KO2) in slots SL1 and SL2 of the secure memory. When the private keys KS1 and KS2 are stored in slots SL1 and SL2 of the secure memory, the public keys KO1 and KO2 can be stored in an area of the secure memory different from the memory 12 or the external storage unit 13.
[0063] Figure 5 is a flowchart showing the update process of the certificate and key pair executed by the charging control device 10 according to the first embodiment. This process starts, for example, when the charging control device 10 receives a request from an external device such as the OEM server 6 via the external communication unit 16A. At the start, it is assumed that the currently used private key is the private key KS1 and the certificate C1 is valid.
[0064] During Figure 5 the process, the charging control device 10 determines whether the vehicle 1 is currently connected to the charging facility 2 (S1). The vehicle 1 being connected to the charging facility 2 means, for example, the following state: the plug 2B ( Figure 1 ) of the charging facility 2 is connected to the connection part of the vehicle 1 (the connection part includes a power receiving unit and a communication terminal connected to the battery 19). For example, when the plug 2B of the charging facility 2 is connected to this connection part of the vehicle 1, the charging communication unit 26B ( Figure 2 ) sends a pulse signal or the like defined by the specifications or standards of the device to the charging communication unit 16B. Therefore, the charging control device 10 can detect the connection to the charging facility 2 via the charging communication unit 16B.
[0065] When the vehicle 1 is currently connected to the charging facility 2 (\"Yes\" in S1), the charging control device 10 sends a negative response to the OEM server 6 (S2). Then, the charging control device 10 ends the process.
[0066] On the other hand, when the vehicle 1 is not currently connected to the charging facility 2 (\"No\" in S1), the charging control device 10 determines the type of the received request via the external communication unit 16A (S3). When the type of the received request is a CSR generation request (CSR in S3), the charging control device 10 reads the slot number of the currently used slot from the register and determines the slot number of the currently used slot (S4).
[0067] When it is determined in S4 that the currently used slot is SL1, the charging control device 10 generates a pair of a public key KO2 and a private key KS2 in the slot SL2 (S5). The charging control device 10 can generate the pair of the public key KO2 and the private key KS2 in the memory 12 or the external storage unit 13 and request the secure memory to register both of them in the slot SL2. The charging control device 10 can request the secure memory to register only the private key KS2 of the generated key pair in the slot SL2. This is because it is desired to keep the private key KS2 confidential while ensuring security. In addition, the pair of the public key KO2 and the private key KS2 can be generated in the secure memory.
[0068] In any case, through the process of S5, the charging control device 10 stores the private key KS1 corresponding to the currently valid certificate C1 and the private key KS2 corresponding to the newly obtained future certificate C2 in different slots SL1 and SL2 respectively. The charging control device 10 makes the private key KS1 valid until the installation of the new certificate C2 is completed, and makes the private key KS2 valid when the installation of the new certificate C2 is completed.
[0069] On the other hand, when it is determined in S4 that the currently used slot is SL2, a pair of a public key KO2 and a private key KS2 is generated in slot SL1 (S6). The process of S6 is the same as that of S5, so its description is omitted. After the process of S5 or S6, the charging control device 10 sends a CSR including the public key KO2 generated in the process of S5 or S6 to the OEM server 6 (S7).
[0070] When it is determined in S3 that the request is for certificate distribution (distribution certificate in S3), the charging control device 10 looks up the number of the currently used slot from the register and determines the slot number of the currently used slot (S8). When it is determined in S8 that the currently used slot is SL1, the charging control device 10 reverses the slot number of the currently used slot in the register to SL2 (S9).
[0071] Then, the charging control device 10 deletes the key of slot SL1 (S10). In the process of S10, when the key pair is stored in slot SL1, the charging control device 10 can delete the key pair. On the other hand, when only the private key KS1 is stored in slot SL1, the charging control device 10 can delete the stored private key KS1.
[0072] On the other hand, when it is determined in S8 that the currently used slot is SL2, the charging control device 10 reverses the slot number of the currently used slot in the register to SL1 (S11). Then, the charging control device 10 deletes the key of slot SL2 (S12). The process of S12 is the same as that of S10, so its description is omitted.
[0073] Effects of the First Embodiment
[0074] As described above, the charging control device 10 generates pairing key information regarding the first private key KS1 and the first public key KO1 in response to a request from an external device (e.g., the OEM server 6 as the certificate issuer). Then, the charging control device 10 sends a CSR including the first public key KO1 to the issuer and installs the issued first certificate C1. Then, the charging control device 10 creates a signature based on the installed first certificate C1 and the first private key KS1 and performs charging control with the charging facility 2.
[0075] In this embodiment, the charging control device 10 receives a CSR generation request from an OEM server 6 or the like while the existing first private key KS1 is installed. Then, the charging control device 10 newly creates a pair of a second public key KO2 and a second private key KS2, and sends a CSR including the second public key KO2 to the OEM server 6 or the like. Then, the charging control device 10 newly acquires and installs a second certificate C2. At this time, the charging control device 10 stores the first private key KS1 corresponding to the currently valid first certificate C1 and the second private key KS2 corresponding to the new second certificate C2 issued based on a request from the OEM server 6 or the like in different storage destinations, namely, slots SL1 and SL2.
[0076] The charging control device 10 keeps the first private key KS1 valid until the installation of the second certificate C2 is completed, and makes the second private key KS2 valid when the installation of the second certificate C2 is completed. Therefore, from the time when the pair of the second public key KO2 and the second private key KS2 is created until the installation of the second certificate C2 is completed, the charging control device 10 can execute a process using the first private key KS1. That is, the charging control device 10 can create a signature using the first private key KS1 corresponding to the first certificate C1 that has been valid until then, and request an external device such as a charging facility 2 to perform authentication.
[0077] When the installation of the second certificate C2 is completed, the charging control device 10 erases the first private key KS1. Therefore, the charging control device 10 can effectively use the secure memory in a less wasteful manner.
[0078] In addition, when the charging control device 10 is connected to the charging facility 2 and receives a request from the OEM server 6 or the like as an issuer, the charging control device 10 rejects the request by returning a negative response. Therefore, the charging control device 10 can execute a process with a smaller load by reducing the number of parallel processes in the process of requesting to create a certificate and the process of authenticating a signature request.
[0079] Second Embodiment
[0080] Hereinafter, reference will be made to Figure 6Describe the charging control device 10 and the program according to the second embodiment. In the first embodiment, when the charging control device 10 receives a request from an external device such as the OEM server 6 and the vehicle 1 is connected to the charging facility 2, the charging control device 10 returns a negative response and ends the process. However, instead of returning a negative response, the charging control device 10 can wait while the vehicle 1 is connected to the charging facility 2. In the second embodiment, the processes other than the process in which the charging control device 10 waits while the vehicle 1 is connected to the charging facility 2 are the same as those in the first embodiment. Here, the configuration and process of the charging control device 10 according to the first embodiment are appropriately referred to and applied to this embodiment as well.
[0081] Figure 6 FIG. is a flowchart showing the process of updating the certificate and key executed by the charging control device 10 according to the second embodiment. As in the first embodiment, the process starts, for example, when the charging control device 10 receives a request from the OEM server 6 or the like via the external communication unit 16A. In this process, as in the first embodiment, the charging control device 10 determines whether the vehicle 1 is currently connected to the charging facility 2 (S1).
[0082] When the vehicle 1 is currently connected to the charging facility 2, the charging control device 10 waits (S2A). This waiting can be waiting for a time until a timer timeout occurs. The charging control device 10 can also wait until the disconnection of the connection to the charging facility 2 is detected via the external communication unit 16A. During the waiting period, the charging control device 10 can execute the process using the current key shown in P3 in another parallel process. Figure 4 as shown in P3.
[0083] After the waiting, when the vehicle 1 is not connected to the charging facility 2, the charging control device 10 executes the process of S3 and subsequent steps. Figure 6 The process of S3 and subsequent steps in Figure 5 is the same as the process in
[0084] As described above, in the present embodiment, when a request from an external device such as the OEM server 6 is received during the connection between the vehicle 1 and the charging facility 2, the charging control device 10 waits without performing the process of generating the CSR and the process of sending the CSR. After waiting, when the vehicle 1 is not connected to the charging facility 2, the charging control device 10 executes the process of S3 and subsequent processes. For this reason, even when the charging control device 10 receives a CSR generation request, the charging control device 10 can create a signature using the currently used private key KS1 and request authentication from an external device such as the charging facility 2. In addition, when the vehicle 1 is not connected to the charging facility 2 after waiting, the charging control device 10 executes the process of S3 and subsequent processes, so that the number of parallel processes can be reduced and the load can be alleviated.
[0085] Third Embodiment
[0086] Hereinafter, with reference to Figure 7 and Figure 8 the charging control device 10 and the program according to the third embodiment will be described. In the first embodiment, when a request from an external device such as the OEM server 6 is received and the vehicle 1 is connected to the charging facility 2, the charging control device 10 returns a negative response and ends the process. In the second embodiment, the charging control device 10 waits without returning a negative response.
[0087] In the present embodiment, the charging control device 10 parallelly executes the process of requesting authentication by signature using the currently used private key KS1 and the process of updating the private key KS1 to the private key KS2 using the CSR. In the third embodiment, in addition to parallelly executing the process of requesting authentication by signature and the like and the process of updating the private key KS1 to the private key KS2 using the CSR, the configuration and process of the charging control device 10 are the same as those according to the first embodiment and the second embodiment. Here, the configuration and process of the charging control device 10 according to the first embodiment and the second embodiment are appropriately referred to and applied to the present embodiment.
[0088] Figure 7 is a sequence diagram showing the process of updating the certificate according to the third embodiment. Similar to Figure 4 for example, when a request to update the current certificate C1 occurs in the OEM server 6, the OEM server 6 sends a CSR generation request (P11) to the charging control device 10 of the vehicle 1. Here, the vehicle 1 is currently connected to the charging facility 2. In this case, for example, the charging control device 10 may be executing a process (P12) using the current private key KS1. The process using the private key KS1 includes, for example, creating a signature using the private key KS1 and requesting authentication from the charging facility 2.
[0089] In this way, even when the vehicle 1 is being connected to the charging facility 2, the charging control device 10 performs the key generation process (P13) regardless of whether it is connected to the charging facility 2. The process in P13 is the same as the Figure 4 key generation process in. That is, the charging control device 10 requests the secure memory to store the new private key KS2 in the slot SL2 while maintaining the current private key KS1 in the slot SL1. That is, in the process of P13, when the vehicle 1 is connected to the charging facility 2 authorized based on the first private key (private key KS1) and the first certificate (certificate C1) corresponding to the first private key, upon receiving a request from the OEM server 6 as the issuer, the charging control device 10 stores the second private key (private key KS2).
[0090] Figure 7 FIG. shows an example in which the charging control device 10 performs the key generation process in P13 after the process using the current private key KS1 in P12. However, the charging control device 10 may perform the process using the current private key KS1 in P12 and the key generation process in P13 in parallel. Then, the charging control device 10 sends a CSR (P14) including the public key KO2 created in pair with the private key KS2 to the OEM server 6. Through the processes of P13 and P14, the charging control device 10 requests the OEM server 6 to install the second certificate (certificate C2) corresponding to the private key KS2, and uses the first private key (private key KS1) at least during the connection between the charging control device 10 and the charging facility 2. That is, the charging control device 10 performs charging control with the charging facility 2 based on the valid private key KS1 and the certificate C1 corresponding to the private key KS1.
[0091] Next, for example, the charging control device 10 receives the modified certificate distributed from the OEM server 6 (P15). Once the modified certificate is received, the charging control device 10 replaces the current private key KS1 with the new private key KS2. That is, the charging control device 10 registers in the register that the currently used slot is the slot SL2, requests the secure memory to delete (erase) the private key KS1 in the slot SL1, and causes the secure memory to perform the deletion (erase) (P16). That is, when the installation of the second certificate (certificate C2) corresponding to the private key KS2 is completed, the charging control device 10 erases the private key KS1, and performs charging control with the charging facility 2 based on the valid private key KS2 and the second certificate.
[0092] Figure 8 FIG. shows the process flow of the charging control device 10 according to the third embodiment. Similar to the Figure 5 process, for example, when the charging control device 10 receives a request from an external device (e.g., the OEM server 6) via the external communication unit 16A, the Figure 8 process is activated. AsFigure 5 As in [the previous case], it is assumed that the currently used private key at activation is private key KS1 and certificate C1 is valid.
[0093] Unlike Figure 5 In the process of Figure 8 the charging control device 10 determines whether the vehicle 1 is connected to the charging facility 2 and does not execute the processes when the vehicle 1 is connected to the charging facility 2 ([the determination of S1 and the process of S2 in [the previous case]]). That is, the charging control device 10 determines the type of the received request via the external communication unit 16A regardless of whether the vehicle 1 is connected to the charging facility 2 (S23). When the type of the received request is a CSR generation request (CSR in S23), the charging control device 10 executes the processes from S24 to S27. The processes from S24 to S27 are the same as the processes from S4 to S7 in Figure 5 [[the previous case]] and their description is omitted. In the process from Figure 5 to S27, the charging control device 10 stores the second private key KS2 and requests the OEM server 6, etc. as the certificate issuer to install the second certificate C2. S24
[0094] On the other hand, when it is determined in S23 that the request is a distributed certificate (distributed certificate in S23), the charging control device 10 determines whether the vehicle 1 is currently connected to the charging facility 2 (S1B). When the vehicle 1 is currently connected to the charging facility 2, the charging control device 10 waits (S2B). The waiting method is the same as S2A in Figure 6 [[the previous case]].
[0095] During the waiting period, the charging control device 10 can execute a process using the current key, for example, in another parallel process. According to the determination in S1B and the waiting in S2B, when the charging control device 10 receives a request from the OEM server 6, etc. as the issuer, it can be said that the first private key KS1 is valid at least during the connection between the vehicle 1 and the charging facility 2. It can also be said that the charging control device 10 does not use the key generated during charging during the charging session.
[0096] After waiting, when the vehicle 1 is not connected to the charging facility 2, the charging control device 10 executes the processes from S28 to S32. The processes from S28 to S32 are the same as Figure 5 The processes of S8 to S12 are the same, so their descriptions are omitted. That is, the charging control device 10 stores the private key KS1 corresponding to the currently valid certificate C1 and the private key KS2 corresponding to the newly obtained future certificate C2 in different slots SL1 and SL2 respectively. The private key KS1 is valid until the installation of the new certificate C2 is completed, and the private key KS2 is valid when the installation of the new certificate C2 is completed. That is, when the charging control device 10 receives a certificate from the OEM during a charging session, the charging control device 10 does not immediately switch the currently used key, but switches the currently used key after the charging session ends.
[0097] As described above, when the vehicle 1 is connected to the charging facility 2 authorized by the first certificate C1 and the first private key KS1, even when receiving a CSR generation request from the OEM server 6 or the like as the certificate issuer, the charging control device 10 does not perform a negative response or wait. That is, the charging control device 10 newly creates a pair of the public key KO2 and the private key KS2, and stores at least the private key K2 in the slot SL2.
[0098] Then, the charging control device 10 sends a CSR to the OEM server 6 or the like as the issuer of the CSR generation request, and requests the issuance (and installation) of the second certificate C2. The charging control device 10 makes the first private key KS1 valid at least during the connection between the vehicle 1 and the charging facility 2. Therefore, when the vehicle 1 is connected to the charging facility 2, even when the charging control device 10 receives a CSR generation request, the charging control device 10 continues the process using the private key KS1 as the current key. In parallel with this process, the charging control device 10 can request the OEM server 6 or the like to issue (and install) the second certificate C2. In this case, the private key KS1 as the current key is not overwritten by the new private key KS2. In addition, the creation of the signature, the request for authentication to the charging facility 2, etc. are not interrupted until the issuance (and installation) of the second certificate C2 is completed.
[0099] When the charging control device 10 waits as in S1B and S2B, the first private key KS1 is valid at least during the connection between the vehicle 1 and the charging facility 2. Regardless of whether the vehicle 1 is connected to the charging facility 2, when receiving a request from the OEM server 6 as the certificate issuer, the charging control device 10 newly stores the second private key KS2 in the slot SL2, and requests the OEM server 6 to install the second certificate C2. However, thereafter, when also receiving the second certificate C2 from the OEM server 6 during the connection to the charging facility 2, the charging control device 10 waits and makes the first private key KS1 valid at least during the connection to the charging facility 2. Therefore, the charging control device 10 can continue the process using the first private key KS1 that is currently being processed, and can obtain authentication through the signature.
[0100] When the installation of the second certificate C2 is completed, the charging control device 10 activates the second private key KS2. Therefore, the charging control device 10 can smoothly transition from the process using the first certificate C1 and the first private key KS1 to the process using the second certificate C2 and the second private key KS2 without interruption. That is, the charging control device 10 can continuously execute the process of authenticating through certificate requests. After the charging control device 10 generates the key of the certificate to be verified, the charging control device 10 can perform PnC charging without stopping the service until the OEM server 6 issues the certificate and installs the certificate in the charging control device 10.
[0101] Computer-readable recording medium
[0102] A program that causes a computer or another machine or device (hereinafter referred to as a computer, etc.) to implement one of the above functions can be recorded on a computer-readable recording medium. This function can be provided by causing the computer, etc. to read and execute the program on the recording medium.
[0103] Here, a computer-readable recording medium refers to a recording medium that stores information such as data and programs through electrical, magnetic, optical, mechanical, or chemical operations and can be read by a computer, etc. Among such recording media, removable media from a computer, etc. include, for example, memory cards such as floppy disks, magneto-optical disks, CD-ROMs, CD-R / Ws, DVDs, Blu-ray discs, and flash memories. Recording media fixed in a computer, etc. include hard disks, read-only memories (ROMs), etc. Solid-state drives (SSDs) can be used as removable recording media from a computer, etc., or as recording media fixed to a computer, etc.
[0104] Other content
[0105] This embodiment includes the following aspects (hereinafter referred to as appendices).
[0106] Appendix 1:
[0107] A charging control device for a vehicle, comprising:
[0108] A controller configured to communicate with a charging facility for charging authentication, the controller storing a first private key corresponding to a first certificate in a first area of a memory, wherein the controller is configured to:
[0109] Generate a second private key and a public key in response to a request from a certificate issuer;
[0110] Store the second private key in a second area of the memory different from the first area;
[0111] Send the public key to the certificate issuer to receive a second certificate issued by the certificate issuer;
[0112] Keep using the first private key until the installation of the second certificate is completed; and
[0113] When the installation is completed, use the second private key.
[0114] Appendix 2:
[0115] The charging control device according to Appendix 1, wherein the controller is configured not to rewrite the first private key with the second private key.
[0116] Appendix 3:
[0117] The charging control device according to Appendix 1, wherein the controller is configured to communicate with the charging facility for the charging authentication based on a valid first private key or second private key and a certificate corresponding to the valid first private key or second private key.
[0118] Appendix 4:
[0119] The charging control device according to Appendix 1, wherein the controller is configured to erase the first private key when the installation of the second certificate is completed.
[0120] Appendix 5:
[0121] The charging control device according to Appendix 1, wherein the controller is configured to reject a request from the certificate issuer when the request is received during connection to the charging facility.
[0122] Appendix 6:
[0123] The charging control device according to Appendix 1, wherein when a request from the certificate issuer is received during connection to the charging facility based on the first certificate and the first private key, the controller is configured to store the second private key, request the certificate issuer to install the second certificate, and use the first private key at least during connection to the charging facility.
[0124] Appendix 7:
[0125] The charging control device according to Appendix 6, wherein the controller is configured to communicate with the charging facility for the charging authentication based on a valid first private key and a first certificate corresponding to the first private key.
[0126] Appendix 8:
[0127] A charging control device according to Appendix 6, wherein the controller is configured to: use the second private key when the installation of the second certificate is completed.
[0128] Appendix 9:
[0129] A charging control device according to Appendix 8, wherein the controller is configured to: erase the first private key when the installation of the second certificate is completed, and communicate with the charging facility for the charging authentication based on the valid second private key and the second certificate.
[0130] Appendix 10:
[0131] A program for causing a controller to execute a process, the controller being configured to communicate with a charging facility for charging authentication, the controller storing a first private key corresponding to a first certificate in a first area of a memory, the process including:
[0132] Generating a second private key and a public key in response to a request from a certificate issuer;
[0133] Storing the second private key in a second area of the memory different from the first area;
[0134] Sending the public key to the certificate issuer to receive a second certificate issued by the certificate issuer;
[0135] Continuing to use the first private key until the installation of the second certificate is completed; and
[0136] Using the second private key when the installation is completed.
[0137] Appendix 11:
[0138] A charging control method for a controller, the controller being configured to communicate with a charging facility for charging authentication, the controller storing a first private key corresponding to a first certificate in a first area of a memory, the charging control method including:
[0139] Generating a second private key and a public key in response to a request from a certificate issuer;
[0140] Storing the second private key in a second area of the memory different from the first area;
[0141] Sending the public key to the certificate issuer to receive a second certificate issued by the certificate issuer;
[0142] Continuing to use the first private key until the installation of the second certificate is completed; and
[0143] At the completion of the installation, use the second private key.
Claims
1. A charging control device for a vehicle, comprising: A controller is configured to communicate with a charging facility to perform charging authentication, wherein the controller stores a first private key corresponding to a first certificate in a first area of a memory, wherein the controller is configured to: generating a second private key and a public key in response to a request from a certificate issuer; storing the second private key in a second area of the memory different from the first area; Sending the public key to the certificate issuer to receive a second certificate issued by the certificate issuer; Keep using the first private key until the installation of the second certificate is completed; and When the installation is completed, the second private key is used.
2. The charging control device according to claim 1, wherein: The controller is configured not to overwrite the first private key with the second private key.
3. The charging control device according to claim 1, wherein: The controller is configured to communicate with the charging facility to perform the charging authentication based on a valid first private key or a valid second private key and a certificate corresponding to the valid first private key or the valid second private key.
4. The charging control device according to claim 1, wherein: The controller is configured to erase the first private key when the installation of the second certificate is completed.
5. The charging control device according to claim 1, wherein: The controller is configured to, when receiving a request from the certificate issuer during connection to the charging facility, deny the request.
6. The charging control device according to claim 1, wherein: The controller is configured to: when a request is received from the certificate issuer during connection to the charging facility based on the first certificate and the first private key, store the second private key, request the certificate issuer to install the second certificate, and use the first private key at least during connection to the charging facility.
7. The charging control device according to claim 6, wherein: The controller is configured to communicate with the charging facility to perform the charging authentication based on a valid first private key and a first certificate corresponding to the first private key.
8. The charging control device according to claim 6, wherein: The controller is configured to use the second private key when installation of the second certificate is completed.
9. The charging control device according to claim 8, wherein: The controller is configured to: when the installation of the second certificate is completed, erase the first private key, and communicate with the charging facility to perform the charging authentication based on the valid second private key and the second certificate.
10. A non-transitory computer-readable storage medium storing a program, the program causing a controller to execute a process, the controller being configured to communicate with a charging facility for charging authentication, the controller storing a first private key corresponding to a first certificate in a first area of a memory, the process comprising: generating a second private key and a public key in response to a request from a certificate issuer; storing the second private key in a second area of the memory different from the first area; Sending the public key to the certificate issuer to receive a second certificate issued by the certificate issuer; Keep using the first private key until the installation of the second certificate is completed; as well as When the installation is completed, the second private key is used.
11. A charging control method of a controller, the controller being configured to communicate with a charging facility for charging authentication, the controller storing a first private key corresponding to a first certificate in a first area of a memory, the charging control method comprising: generating a second private key and a public key in response to a request from a certificate issuer; storing the second private key in a second area of the memory different from the first area; Sending the public key to the certificate issuer to receive a second certificate issued by the certificate issuer; Keep using the first private key until the installation of the second certificate is completed; as well as When the installation is completed, the second private key is used.
Citation Information
Patent Citations
System, authentication station, on-vehicle computer, public key certificate issuing method, and program
JP2018019415A