Server and system
By sending digital certificates with different validity periods between the vehicle and the charging station, the problem of communication interruption caused by invalid vehicle communication equipment protocols is solved, ensuring that a reliable communication connection can still be established even when the protocol is invalid, thus improving the security and reliability of communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2025-10-27
- Publication Date
- 2026-05-01
AI Technical Summary
If the vehicle's onboard communication equipment protocol is invalid, the vehicle cannot establish a communication connection with the charging station, resulting in charging being impossible.
A server system is provided that ensures a communication connection can be established even when the vehicle communication device protocol is invalid by sending two digital certificates (a first digital certificate and a second digital certificate) with different validity periods. The first digital certificate has a short validity period and is used for renewal, while the second digital certificate has a long validity period and is used for long-term security. The server switches the certificate sending according to the protocol status.
This technology enables reliable communication between the vehicle and the charging station even when the vehicle communication equipment protocol is invalid, improving the security and reliability of communication and reducing the risk of communication interruption.
Smart Images

Figure CN121966907A_ABST
Abstract
Description
Servers and systems Technical Field
[0001] This disclosure relates to servers and systems. Background Technology
[0002] Japanese Patent Application Publication No. 2022-527902 discloses a system for authenticating digital certificates sent from EV charging stations in vehicles. In this system, a communication connection is established between the vehicle and the EV charging station based on the digital certificate, after which vehicle charging is performed.
[0003] Although not explicitly stated in Japanese Patent Publication No. 2022-527902, the protocol of the onboard communication device must be valid for the vehicle to receive a digital certificate. If the protocol of the onboard communication device is not valid, the vehicle cannot receive the digital certificate. Without the vehicle receiving the digital certificate, a communication connection between the vehicle and the EV charging station cannot be established. Summary of the Invention
[0004] This disclosure was made to address the aforementioned issues, and its purpose is to provide a server and system that can more reliably establish a communication connection between a vehicle and a charging station even when the protocol of the vehicle communication device is not valid.
[0005] The servers involved in the first aspect of this disclosure are as follows. That is,
[0006] A server that sends a digital certificate for communication between a vehicle and a charging station to the vehicle, wherein the server comprises:
[0007] The communications unit communicates with the vehicle's onboard communications equipment; and
[0008] Control Department.
[0009] Digital certificates include:
[0010] The first digital certificate; and
[0011] The second digital certificate has a longer validity period than the first digital certificate.
[0012] Without requesting the termination of the agreement for the vehicle communication equipment, the control unit sends the first digital certificate to the vehicle communication equipment through the communication unit.
[0013] In the event that the protocol for the vehicle communication device has been terminated, the control unit sends the second digital certificate to the vehicle communication device through the communication unit.
[0014] The system involved in the second aspect of this disclosure has the following features:
[0015] The server mentioned in aspect 1 above; and
[0016] The vehicle includes onboard communication equipment for communicating with the communications department.
[0017] The above and other objects, features, aspects, and advantages of the invention will become clear from the following detailed description in relation to the invention, which is understood in conjunction with the accompanying drawings. Attached Figure Description
[0018] Figure 1 is a diagram showing the structure of the system in this embodiment.
[0019] Figure 2 is the first diagram showing the sequence of the system in this embodiment.
[0020] Figure 3 is the second diagram showing the sequence of the system in this embodiment.
[0021] Figure 4 is a timing diagram showing the system in the first variation of this embodiment.
[0022] Figure 5 is a timing diagram showing the system in the second variation of this embodiment. Detailed Implementation
[0023] Embodiments of this disclosure will be described with reference to the accompanying drawings. Furthermore, in the drawings referred to below, the same or equivalent parts are labeled with the same reference numerals.
[0024] Figure 1 is a diagram showing the structure of system 1 according to this embodiment. System 1 includes a server 100 and a vehicle 200.
[0025] Server 100 includes processor 110, memory 120, and communication unit 130. Furthermore, processor 110 is an example of the "control unit" of this disclosure.
[0026] In addition to the program executed by the processor 110, the memory 120 also stores information used in the program (such as mappings, formulas, and various parameters). The communication unit 130 is controlled by the processor 110.
[0027] The communication unit 130 is capable of communicating with the DCM (Data Communication Module) 230 (described later) and the certification authority 400 (described later).
[0028] Vehicle 200 includes an ECU (Electronic Control Unit) 210, a battery pack 220, a DCM 230, a vehicle navigation device 240, and a connector 250. Furthermore, the DCM 230 is an example of the "vehicle communication equipment" disclosed herein.
[0029] The ECU 210 includes a processor 211, a memory 212, and a communication unit 213. The memory 212 stores, in addition to the program executed by the processor 211, information used in the program (such as mappings, formulas, and various parameters). The communication unit 213 is controlled by the processor 211. The communication unit 213 can communicate with the DCM 230 and the vehicle navigation device 240 via CAN (Controller Area Network) or other means.
[0030] Battery pack 220 is the battery used for driving vehicle 200. Vehicle 200 can be PHEV (Plug-in Hybrid Electric Vehicle), BEV (Battery Electric Vehicle), or FCEV (Fuel Cell Electric Vehicle), etc.
[0031] Vehicle 200 is electrically connected to EVSE 300 via cable 301, thereby enabling power exchange between the two vehicles. Specifically, power exchange between vehicle 200 and EVSE 300 is achieved by inserting (connecting) a connector 302 located at the front end of cable 301 into (connecting to) port 250 of vehicle 200. Power (charging power) from EVSE 300 is supplied to individual batteries (not shown) in battery pack 220 via a charger / discharger (not shown) of vehicle 200, thereby charging the individual batteries. Power (discharging power) from battery pack 220 is supplied to EVSE 300 via the same charger / discharger, thereby discharging the individual batteries. Furthermore, the individual batteries are secondary batteries, typically lithium-ion secondary batteries. Lithium-ion secondary batteries use lithium as a charge carrier; in addition to lithium-ion secondary batteries with a liquid electrolyte, they can also include all-solid-state batteries using a solid electrolyte. Furthermore, the single battery is not limited to lithium-ion secondary batteries, but can also be composed of nickel-metal hydride secondary batteries or other secondary batteries. Additionally, the EVSE300 is one example of the "charging station" disclosed herein.
[0032] With the vehicle 200 and EVSE300 connected by cable 301, ECU 210 (communication unit 213) communicates with EVSE300. Furthermore, the ECU communicating with EVSE300 may be different from ECU 210.
[0033] ECU210 and EVSE300 communicate, for example, via TLS (Transport Layer Security). TLS is a protocol for highly secure communication. Digital certificates can be used in TLS communication. Based on the digital certificate, information can be securely exchanged between vehicle 200 and EVSE300. Afterwards, if a communication connection is established between vehicle 200 and EVSE300, authentication data from vehicle 200 is sent to EVSE300 in encrypted form. If authentication based on the authentication data is successful, charging from EVSE300 to vehicle 200 and discharging from vehicle 200 to EVSE300 can be performed. Furthermore, in PnC (Plug and Charge), if authentication is successful, billing and charging (discharging) processes automatically begin. Additionally, the digital certificate becomes valid by being written into ECU210 (memory 212) of vehicle 200. Vehicle 200 can also be a vehicle capable of PnC charging (billing).
[0034] For example, the EVSE300 or server 100 performs a process to verify the validity period (expiration date) of the digital certificate written to the ECU210. If the digital certificate is valid before its expiration date, a communication connection between the vehicle 200 and the EVSE300 can be established. As a result, power exchange between the vehicle 200 and the EVSE300 becomes possible.
[0035] Digital certificates are issued by a certification authority (CPA). A digital certificate includes a first digital certificate and a second digital certificate. The validity period of the first digital certificate is, for example, 5 years after issuance. The validity period of the second digital certificate is, for example, 20 years after issuance. That is, the validity period of the second digital certificate is longer than that of the first digital certificate. Therefore, communication based on the first digital certificate is more secure than communication based on the second digital certificate. Furthermore, the validity periods of the first and second digital certificates are not limited to the examples mentioned above.
[0036] The DCM230 can communicate with the communication unit 130 of the server 100 as described above, and can also communicate with the certification authority 400.
[0037] Furthermore, processors 110 and 211 are, for example, CPUs (Central Processing Units) or MPUs (Micro-Processing Units). Processors 110 and 211 respectively implement various processes by reading system programs and control programs, expanding them in memories 120 and 212, and executing them. In this specification, "processor" is not limited to the narrow definition of a processor that executes processing in a stored-program manner, but can include hard-wired circuits such as ASICs (Application Specific Integrated Circuits) and FPGAs (Field-Programmable Gate Arrays). Therefore, the term "processor" can also be understood as a processing circuitry that predefines processing through computer-readable code and / or hard-wired circuitry.
[0038] The vehicle navigation device 240 is configured to display various information related to the vehicle 200. For example, the vehicle navigation device 240 can also display the protocol status and validity period of the DCM 230, as well as the type and validity period of the digital certificate written to the ECU 210. In addition, the above-mentioned information can also be displayed on a user terminal (such as a smartphone or tablet).
[0039] Here, the vehicle needs the DCM protocol to be valid when receiving a digital certificate. If the DCM protocol is not valid, the vehicle cannot receive the digital certificate. Without the vehicle receiving the digital certificate, a communication connection between the vehicle and the EVSE cannot be established.
[0040] Therefore, in this embodiment, if the user of vehicle 200 does not request the termination of the DCM230 protocol, processor 110 sends the first digital certificate to DCM230 via communication unit 130. On the other hand, if the user requests the termination of the DCM230 protocol, processor 110 sends the second digital certificate to DCM230 via communication unit 130.
[0041] Therefore, compared to sending the first digital certificate to vehicle 200 when the DCM230 protocol is terminated, it is possible to set the validity period of the digital certificate more reliably and for a longer period after the DCM230 protocol expires.
[0042] (System sequence control)
[0043] Next, the sequential control in System 1 will be described with reference to Figures 2 and 3. Furthermore, the processing of the server 100 in Figures 2 and 3 is performed by the processor 110. Additionally, the processing of the vehicle 200 in Figures 2 and 3 is performed by the ECU 210 (processor 211).
[0044] In step S1, the certification authority 400 issues a second digital certificate. The second digital certificate issued by the certification authority 400 is sent to the DCM 230 of the vehicle 200.
[0045] In step S2, the second digital certificate issued in step S1 is written to the ECU 210 of vehicle 200. That is, the second digital certificate is initially written to ECU 210. Specifically, the second digital certificate is written to ECU 210 before vehicle 200 leaves the factory.
[0046] Therefore, even in the initial state of vehicle 200 where the DCM230 protocol is not valid, a communication connection between EVSE300 and vehicle 200 can be established using the second digital certificate.
[0047] In step S3, the user performs an operation related to the protocol of DCM230 on the vehicle navigation device 240 or the aforementioned user terminal. As a result, a signal indicating the content of the operation in step S3 is sent to the server 100.
[0048] In step S4, server 100 determines whether the signal sent to server 100 based on the operation in step S3 contains information about the protocol application of DCM230. If the signal contains information about the protocol application of DCM230 (yes in S4), the process proceeds to step S5. If the signal does not contain information about the protocol application of DCM230 (no in S4), the process of server 100 ends. Furthermore, the process in step S4 can also be performed based on server 100 receiving the signal. Additionally, server 100 can also perform the process in step S4 if it receives the signal even when it has not received a write notification (described later) indicating that the first digital certificate has been written to ECU210.
[0049] In step S5, server 100 sends an instruction signal to vehicle 200 (DCM230) to enable the protocol flag of DCM230 via communication unit 130. As a result, the protocol flag in vehicle 200 is enabled. When the protocol flag is enabled, DCM230 can receive a digital certificate from server 100 (communication unit 130). Conversely, when the protocol flag is disabled, DCM230 cannot receive a digital certificate from server 100 (communication unit 130). Next, server 100's processing proceeds to step S6. Furthermore, enabling the protocol flag is an example of the "protocol of the vehicle communication device being valid" in this disclosure. Disabling the protocol flag is an example of the "protocol of the vehicle communication device not being valid" in this disclosure.
[0050] In step S6, server 100 sends the issuance request for the first digital certificate to certification authority 400 via communication unit 130. Next, server 100 proceeds to step S10.
[0051] In step S7, the certification authority 400 determines whether it has received a request to issue the first digital certificate. If a request to issue the first digital certificate has been received (yes in S7), the process proceeds to step S8. If no request to issue the first digital certificate has been received (no in S7), the certification authority 400's process ends. Furthermore, the process in step S7 can also be executed according to a predetermined cycle.
[0052] In step S8, the certification authority 400 issues the first digital certificate. Next, in step S9, the certification authority 400 sends the first digital certificate issued in step S8 to the server 100. Afterwards, the processing by the certification authority 400 ends.
[0053] In step S10, the server 100 determines whether the first digital certificate has been received by the communication unit 130. If the first digital certificate has been received (yes in S10), the process proceeds to step S11. If the first digital certificate has not been received (no in S10), step S10 is repeated.
[0054] In step S11, server 100 sends the first digital certificate, which was sent from certification authority 400 in step S9, to vehicle 200 (DCM230) via communication unit 130. That is, server 100 sends the first digital certificate to DCM230 when the user of vehicle 200 has performed the protocol operation of applying for DCM230 (yes in S4).
[0055] Here, a digital certificate can be easily obtained through communication during the validity period of the DCM230 protocol. Therefore, even if a first digital certificate with a relatively short validity period is sent to the DCM230, the vehicle 200 can easily update the first digital certificate due to the DCM230 protocol. Thus, the security of communication between the vehicle 200 and the EVSE300 can be improved through the first digital certificate, and interruptions during the period when the vehicle 200 possesses the first digital certificate can be suppressed.
[0056] In step S12, vehicle 200 determines whether the protocol flag of DCM230 is on. If the protocol flag of DCM230 is on (yes in S12), the process proceeds to step S13. If the protocol flag of DCM230 is off (no in S12), the processing of vehicle 200 ends. Alternatively, after vehicle 200 has left the factory, the processing can be performed according to a predetermined cycle in step S12.
[0057] In step S13, vehicle 200 determines whether a digital certificate has been received. If a digital certificate has been received (yes in S13), the process proceeds to step S14. If no digital certificate has been received (no in S13), the process of vehicle 200 ends.
[0058] In step S14, the vehicle 200 writes the received digital certificate into the ECU 210 (memory 212). Next, the processing of the vehicle 200 proceeds to step S15.
[0059] In step S15, vehicle 200 sends a notification to server 100 indicating that a digital certificate was written in step S14. This notification may include, for example, information such as the type of digital certificate written (first digital certificate or second digital certificate), the date and time of writing, etc. Afterwards, the processing of vehicle 200 ends.
[0060] Figure 3 follows the sequence in Figure 2, indicating the sequence in which the DCM230 protocol termination application was submitted.
[0061] In step S16, the server 100 determines whether the communication unit 130 has received a write notification indicating that the first digital certificate has been written to the ECU 210. If the write notification has been received (yes in S16), the process proceeds to step S17. If the write notification has not been received (no in S16), the server 100's process ends. Furthermore, the process in step S16 can also be executed according to a predetermined cycle.
[0062] Here, the information (signal) from step S3 above is sent to server 100.
[0063] In step S17, server 100 determines whether the signal sent to server 100 based on the operation in step S3 contains information about a protocol termination request from DCM230, and whether a protocol termination request from DCM230 existed three months prior to the expiration date of the first digital certificate (the last day of the validity period) (the signal was sent to server 100 three months prior to the expiration date). If yes in step S17, the process proceeds to step S18. If no in step S17, the process of server 100 ends. Furthermore, the signal containing information about a protocol termination request from DCM230 is an example of a "protocol termination signal" in this disclosure. Alternatively, server 100 may also perform the process in step S17 if it receives the signal while in a state where it has received a write notification indicating that the first digital certificate has been written to ECU210 (the notification in S15). Furthermore, three months is an example of a "prescribed period" in this disclosure.
[0064] Alternatively, if step S17 is not successful, server 100 may also send a request for the issuance of an updated version of the first digital certificate to certification authority 400. This issuance request may, for example, be sent to certification authority 400 three months prior to the aforementioned validity period.
[0065] Furthermore, the aforementioned 3 months is just one example; periods other than 3 months (such as 1 day, 1 week, and 1 month) can also be used as the basis for the determination in step S17. In addition, the aforementioned period can also be set as the period required for the issuance of the second digital certificate.
[0066] In step S18, server 100 sends a request for the issuance of the second digital certificate to certification authority 400 via communication unit 130. Furthermore, server 100 can adjust the timing of executing step S18 based on the protocol period of DCM 230. For example, server 100 may execute step S18 before the specified period of the DCM 230's validity period (e.g., one month in advance). This specified period can also be set to the period required for the issuance of the second digital certificate. Next, server 100's processing proceeds to step S22.
[0067] In step S19, the certification authority 400 determines whether it has received a request to issue a second digital certificate. If a request to issue a second digital certificate has been received (yes in S19), the process proceeds to step S20. If no request to issue a second digital certificate has been received (no in S19), the certification authority 400's process ends. Furthermore, the process in step S19 can also be executed according to a predetermined cycle.
[0068] In step S20, the certification authority 400 issues a second digital certificate. Next, in step S21, the certification authority 400 sends the second digital certificate issued in step S20 to the server 100. Afterwards, the processing by the certification authority 400 ends.
[0069] In step S22, the server 100 determines whether it has received the second digital certificate through the communication unit 130. If the second digital certificate has been received (yes in S22), the process proceeds to step S23. If the second digital certificate has not been received (no in S22), step S22 is repeated.
[0070] In step S23, the server 100 sends the second digital certificate, which was sent from the certification authority 400 in step S21, to the vehicle 200 (DCM230) via the communication unit 130.
[0071] After the processing in step S23, the second digital certificate is written to the ECU 210 through the processing in step S14 of the vehicle 200. Then, the write notification indicating that the second digital certificate has been written to the ECU 210 is sent to the server 100 through the processing in step S15 of the vehicle 200.
[0072] In step S24, the server 100 determines whether it has received a write notification for the second digital certificate through the communication unit 130. If a write notification for the second digital certificate has been received (yes in S24), the process proceeds to step S25. If no write notification for the second digital certificate has been received (no in S24), step S24 is repeated.
[0073] In step S25, server 100 sends a command signal to vehicle 200 (DCM230) via communication unit 130 to disconnect the protocol flag of DCM230. As a result, the protocol flag of DCM230 in vehicle 200 is disconnected. Consequently, DCM230 cannot receive the digital certificate from server 100. Alternatively, server 100 may execute step S25, for example, on the last day of the DCM230's protocol period.
[0074] As can be seen from steps S17, S24, and S25 above, if the server 100 applies for the termination of the DCM230 protocol three months before the expiration date of the first digital certificate, and the communication unit 130 receives a signal from the DCM230 indicating that the second digital certificate has been written to the ECU210, the DCM230 protocol is switched from valid to invalid. Therefore, it is possible to prevent the DCM230 protocol from being switched to invalid before the vehicle 200 receives the second digital certificate.
[0075] As described above, in this embodiment, server 100 sends the first digital certificate to DCM230 via communication unit 130 without requesting the termination of the DCM230 protocol (e.g., even if the DCM230 protocol has been requested). Server 100 sends the second digital certificate to DCM230 via communication unit 130 when the DCM230 protocol has been requested to be terminated. Therefore, even after the DCM230 protocol changes from valid to invalid, a communication connection between vehicle 200 and EVSE300 can be established using the second digital certificate, which has a longer validity period. That is, even when the DCM230 protocol is not valid, a more reliable communication connection between vehicle 200 and EVSE300 can still be established.
[0076] Furthermore, in this embodiment, if server 100 applies for the termination of the DCM230 agreement three months before the expiration of the first digital certificate, the second digital certificate is sent to DCM230 before the termination of the DCM230 agreement. This ensures that the issuance period for the second digital certificate is approximately three months. Consequently, it is easy to send the second digital certificate to DCM230 before the expiration of the first digital certificate.
[0077] Furthermore, in this embodiment, when the communication unit 130 receives a signal indicating that the user of vehicle 200 has requested the termination of the protocol of DCM 230, the server 100 sends the second digital certificate to DCM 230 via the communication unit 130. Thus, the server 100 can use the aforementioned signal as a trigger condition to execute the process of sending the second digital certificate to DCM 230.
[0078] <Variation Example>
[0079] Figure 4 shows a variation of Figure 3. In step S3, if the user performs an operation related to the DCM230 protocol, the DCM230 protocol information is updated. Furthermore, the aforementioned protocol information may be stored, for example, in the memory 120 of the server 100. Alternatively, the aforementioned protocol information may also be stored in the cloud.
[0080] In step S31, when the IG power supply of vehicle 200 is turned on, vehicle 200 notifies server 100 that the IG power supply has been turned on via DCM230.
[0081] If the condition is yes in step S16, proceed to step S32. In step S32, server 100 determines whether the IG power supply of vehicle 200 is turned on. If server 100 receives the notification from communication unit 130 in step S31, it determines that the IG power supply is turned on. If the notification is received (yes in S32), the process proceeds to step S33. If the notification is not received (no in S32), the process of server 100 ends.
[0082] In step S33, server 100 confirms the protocol information of DCM 230 stored in memory 120. Next, the process proceeds to step S34.
[0083] In step S34, server 100 determines, based on protocol information, whether a protocol termination request for DCM230 exists and whether such a request was made three months prior to the expiration date of the first digital certificate. If the result is yes in step S34, the process proceeds to step S18. If the result is no in step S34, the process of server 100 ends. Furthermore, since the steps after step S18 are the same as those in Figure 3, they will not be described again.
[0084] As described above, in the modified example shown in Figure 4, server 100 performs a process to confirm the protocol information of DCM230, and determines whether a request to terminate the DCM230 protocol has been made based on the aforementioned protocol information. Therefore, even without receiving signals from vehicle navigation device 240, user terminal, etc., server 100 can detect whether a request to terminate the DCM230 protocol has been made.
[0085] Furthermore, in the variant shown in Figure 4, the server 100 performs the process of confirming the aforementioned protocol information based on whether the vehicle 200's IG power is turned on. Therefore, since the protocol information is confirmed whenever the vehicle 200's IG power is turned on, the delay in issuing the second digital certificate after the protocol termination request can be suppressed.
[0086] Figure 5 shows a variation of the sequence in Figures 2 and 3. As shown in Figure 5, in step S1, the second digital certificate issued by the certification authority 400 is sent not only to the vehicle 200 but also to the server 100. Furthermore, the vehicle 200 can also send the second digital certificate received from the certification authority 400 to the server 100. Additionally, the server 100 can also send the second digital certificate received from the certification authority 400 to the vehicle 200. Furthermore, the certification authority 400 can also send the second digital certificate to the server 100 based on a sending request from the server 100.
[0087] In step S41, server 100 stores the second digital certificate sent from certification authority 400 in memory 120. In this case, memory 120 is an example of the "storage unit" of this disclosure.
[0088] In the example shown in Figure 5, if the condition is yes in step S17, the process proceeds to step S42. In step S42, the server 100 sends the second digital certificate stored in the memory 120 in step S41 to the vehicle 200 via the communication unit 130. Furthermore, since other processes are the same as in the above embodiment, they will not be described again.
[0089] According to this structure, server 100 can send the second digital certificate to vehicle 200 without requesting the issuing authority of the second digital certificate from certification authority 400. As a result, since there is no need to request issuance from certification authority 400, the second digital certificate can be sent to vehicle 200 more quickly from the date of termination of the DCM230 agreement, and the processing load on server 100 can be reduced.
[0090] In the above embodiment, an example is shown where the second digital certificate received from the certification authority 400 is written into the ECU 210 before the vehicle 200 leaves the factory, but this disclosure is not limited thereto. The second digital certificate may also be written into the ECU 210 during manufacturing (design time).
[0091] In the variation shown in Figure 4, an example is illustrated where protocol information is confirmed upon IG power being switched on, but this disclosure is not limited thereto. Protocol information can also be confirmed at times other than when IG power is switched on (e.g., when connector 302 is inserted into vehicle 200).
[0092] The structures (controls) of the above-described embodiments and variations can also be combined with each other.
[0093] Embodiments of the present invention have been described, but the embodiments disclosed herein should be considered illustrative in all respects and not restrictive. The scope of the present invention is shown by the technical solutions and is intended to include all modifications within the meaning and scope of equivalent technical solutions.
Claims
1. A server that sends a digital certificate for communication between a vehicle and a charging station to the vehicle, wherein, The device includes: a communication unit for communicating with the vehicle's in-vehicle communication equipment; and a control unit, wherein the digital certificate includes a first digital certificate and a second digital certificate with a validity period longer than the first digital certificate; if no protocol termination request is made for the in-vehicle communication equipment, the control unit sends the first digital certificate to the in-vehicle communication equipment via the communication unit; and if a protocol termination request is made for the in-vehicle communication equipment, the control unit sends the second digital certificate to the in-vehicle communication equipment via the communication unit.
2. The server according to claim 1, wherein, When the user of the vehicle performs the operation of applying for the protocol of the vehicle communication device, the control unit sends the first digital certificate to the vehicle communication device through the communication unit.
3. The server according to claim 1 or 2, wherein, The control unit performs a process to confirm the protocol information of the vehicle communication device, and the control unit determines whether a request has been made to terminate the protocol of the vehicle communication device based on the protocol information.
4. The server according to claim 3, wherein, The control unit performs the process of confirming the protocol information based on the fact that the vehicle's IG power supply is turned on.
5. The server according to claim 1 or 2, wherein, When the communication unit receives a protocol termination signal indicating that the user of the vehicle has performed an operation to terminate the protocol of the vehicle communication device, the control unit sends the second digital certificate to the vehicle communication device through the communication unit.
6. The server according to claim 1 or 2, wherein, If the protocol termination of the vehicle communication device is requested before the specified period of the validity of the first digital certificate, the control unit, through the communication unit, sends the second digital certificate to the vehicle communication device before the protocol of the vehicle communication device is terminated.
7. The server according to claim 6, wherein, When the vehicle communication device's protocol is valid, it can receive the digital certificate from the communication unit; when the vehicle communication device's protocol is invalid, it cannot receive the digital certificate from the communication unit; and when the vehicle communication device's protocol is terminated before the specified period of validity, after the communication unit receives a signal from the vehicle communication device indicating that the second digital certificate has been written to the vehicle's ECU, the control unit switches the vehicle communication device's protocol from valid to invalid.
8. A system in which, The device comprises: the server as described in claim 1 or 2; and a vehicle including an in-vehicle communication device that communicates with the communication unit.
9. The system according to claim 8, wherein, The vehicle has an ECU capable of writing the first digital certificate and the second digital certificate, and the second digital certificate is initially written to the ECU.
10. The system according to claim 9, wherein, The vehicle communication device is capable of communicating with the certification authority that issued the first digital certificate and the second digital certificate, respectively. The server includes a storage unit that stores the second digital certificate sent from the certification authority to the vehicle communication device and initially written to the ECU. In the event of a request to terminate the protocol of the vehicle communication device, the server sends the second digital certificate stored in the storage unit to the vehicle communication device through the communication unit.
Citation Information
Patent Citations
Electric Vehicle Charging Station System
JP2022527902A