CHARGING CONTROL DEVICE, STORAGE MEDIUM AND CHARGING CONTROL METHOD
The charging control device manages private keys in separate memory areas to maintain authentication and charging continuity during certificate updates, addressing the issue of key overwriting in vehicle charging systems.
Patent Information
- Application Number
- DE102024106988
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-18
- Filing Date
- 2024-03-12
- Publication Date
- 2025-06-18
AI Technical Summary
Existing vehicle charging systems do not account for the update of certificates, leading to potential loss of authentication due to overwriting of private keys when new certificates are installed, disrupting charging operations.
A charging control device that stores a first private key corresponding to a first certificate in a first memory area and generates a second private key in a second memory area, allowing the first private key to be retained until the installation of the second certificate is complete, ensuring continuous authentication and charging capability.
Ensures uninterrupted charging operations by maintaining the validity of the first private key during the installation of a new certificate, preventing authentication disruptions and enhancing system stability.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL FIELDThe present disclosure relates to a charge control device, a program, and a charge control method.GENERAL STATE OF THE ARTExamples of a vehicle that can charge a traction battery by connecting an external power supply (also referred to as an electric vehicle) include a battery electric vehicle (BEV) and a plug-in hybrid vehicle (PHV). Examples of a method for authenticating charging of the traction battery mainly include an external authentication means (EIM) and plug-and-charge (PnC).In charging by PnC, a certificate is stored in a vehicle, the stored certificate and a signature generated by a private key corresponding to the certificate are sent from the vehicle to a charging device (also referred to as a charging station) to perform authentication when the vehicle is connected to the charging device, and charging is started when the authentication succeeds. In issuing the certificate, for example, an on-board computer generates an on-board computer public key and an on-board computer private key paired with the on-board computer public key, and issues a request for issuing the certificate concerning the on-board computer public key to a certification authority. The certificate authority then receives the certificate issuance request sent from the onboard computer, signs the onboard computer public dish included in the certificate issuance request, and outputs the certificate to the onboard computer. In this way, the on-board computer acquires the certificate issued from the certificate authority in response to the request for issuing the certificate (see, for example, Japanese Patent Laid-Open No. 2018-19415).However, in the prior art, the case of updating an issued certificate is not considered.For example, once a certificate issued is updated to a new certificate and a new private key is generated in the vehicle, a private key corresponding to the currently available certificate may be overwritten. For this reason, the private key corresponding to the currently available certificate may be lost and the vehicle may not be authenticated by a signature until a new certificate is installed in the vehicle for update. An aspect of an embodiment disclosed in this application is to provide a device or the like that can be further loaded using a certificate even when a new certificate is installed in a vehicle in which a certificate has already been installed.SUMMARY OF THE INVENTIONAn aspect of an embodiment disclosed in this application is illustrated by a charge control device for a vehicle, including a controller configured to communicate with a charging facility for charge authentication. The controller stores a first private key corresponding to a first certificate in a first area of memory. The controller is configured to generate a second private key and a public key in response to a request from a certificate issuer. The controller is configured to store the second private key in a second area of the memory different from the first area. The controller is configured to send the public key to the certificate issuer to obtain a second certificate issued by the certificate issuer. The controller is configured to maintain use of the first private key until completion of installation of the second certificate. The controller is configured to use the second key after completion of installation.In the charging control device, the controller stores a first private key corresponding to a currently valid first certificate and a second private key corresponding to a second certificate that is newly issued based on a request from an issuer at different storage locations. Accordingly, the currently valid first private key is not overwritten with the newly generated second private key. For this reason, the controller may use the first private key until completion of installation of the second certificate. Upon completion of installation of the second certificate, the controller uses the second private key. In this way, the charging control device can continue charging even when a new second certificate is installed in a vehicle in which the first certificate has already been installed, using the first certificate and the first private key corresponding thereto. After completion of the installation of the second certificate, the charging control device may immediately change to a process by the second certificate and the second private key corresponding thereto. That is, even when a new certificate is installed in a vehicle in which a certificate has already been installed, the charging controller may execute control, thereby continuing to charge using the certificate.BRIEF DESCRIPTION OF THE DRAWINGSBased on the following figures, exemplary embodiments of the present disclosure will be described, wherein FIG. 1 shows a vehicle equipped with a charge control device according to a first embodiment; FIG. 2 shows hardware configurations of the vehicle and a charging facility; FIG. 3 shows a process for updating a private key by the charge control device according to the first embodiment; FIG. 4 is a sequence diagram showing a certificate updating process according to the first embodiment; FIG. 5 is a flowchart showing an update process of a pair of a certificate and a key by the charge control device according to the first embodiment; FIG. 6 is a flowchart showing an update process of a pair of a certificate and a key by a charge control device according to a second embodiment; FIG. 7 is a sequence diagram showing a certificate update process according to a third embodiment; and FIG. 8 shows a process flow of a charge control device according to the third embodiment.DESCRIPTION OF EMBODIMENTSHereinafter, a charge control device 10 and a computer program (hereinafter, simply referred to as a program) will be described.First EmbodimentReferring to FIGS. 1 to 5, the charge control device 10, a program, and a charge control method according to a first embodiment will be described.StructuresFIG. 1 shows a vehicle 1 equipped with the charge control device 10 according to the present embodiment. FIG. 1 also shows a charging device (an electric vehicle supply device, EVSE) 2 that supplies electric power to a battery 19 (see FIG. 2, also referred to as a secondary battery or storage battery) of the vehicle 1, and an MO server 5 and an original equipment manufacturing server (OEM server) 6 that exchange information with the vehicle 1 or the charging device 2.The vehicle 1 is referred to as an electric vehicle and can charge the traction battery 19. The vehicle 1 has the charge control device 10 and performs a charge process or charge control with the charging device 2. In the charging process or the like, the charging control device 10 of the vehicle 1 generates a signature as PnC, which is a first authentication process, on the basis of a contract certificate or the like and an encryption key, and the charging device 2 checks the signature. When the authentication succeeds, the vehicle 1 performs the charging with the charging device 2. The operation by PnC is started, for example, when a plug 2B supplying electric power from the charging device 2 is connected to a power receiving unit of the vehicle 1.When charging the vehicle 1, besides the operation by PnC as described above as the second authentication operation, an operation by an external authentication means (EIM) in which an RFID card or the like is presented is also possible. For this reason, the charging device 2 includes an EIM reader 2A. The external authentication means is, for example, an authentication means based on user information obtained from a credit card, a QR code (registered trademark), a radio frequency identification (RFID), or the like via the EIM reader 2A.The charge control device 10 may be connected to the MO server 5, the OEM server 6, and the like via a network N 1. The network N 1 includes a wireless network such as a long term evolution (LTE), a fifth generation mobile communication system (5G), and a sixth generation mobile communication system (6G), or a wired public network such as the Internet.For example, the charging device 5 may transmit the signature transmitted from the vehicle 1 to the MO server 5 to request authentication by a user of the vehicle 1. When the authentication by the MO server 5 is successful, the charging device 2 may charge the battery 19 of the vehicle 1 and charge the user of the vehicle 1. When the vehicle 1 is loaded, the vehicle 1 may request the charging device 2 to install a contract certificate or the like. In this case, the vehicle 1 presents a certificate (such as an OEM provision certificate) issued from an OEM, which is a manufacturer or a seller of the vehicle, to the charging device 2. When the charging device 2 has a valid contract certificate or the like associated with the OEM provision certificate notified from the vehicle, the charging device 2 may provide the contract certificate or the like to the vehicle 1. The charging device 2 can access the MO server 2, acquire the valid contract certificate or the like corresponding to the OEM provision certificate, and install the contract certificate or the like in the vehicle 1.As described above, the certificate (the OEM provision certificate, a vehicle certificate, or the like) issued from the OEM, which is the manufacturer or the seller of the vehicle 1, is installed in the vehicle 1 and stored in a storage 12 (FIG. 2 ) of the charge control device 10. The user of the vehicle 1 previously makes a contract with a service provider (MO) to make the battery 19 of the vehicle 1 charge by the charging device 2. According to this contract, the contract certificate or the like and an encryption key such as a private key are issued from the MO server 5 and installed in the vehicle 1 via, for example, the OEM server 6. The contract certificate and the encryption key may be referred to as certificate data. The certificate data such as the contract certificate may be installed in the vehicle 1 via the charging device 2, for example.Hereinafter, the OEM provision certificate, the vehicle certificate, the contract certificate and the like are collectively referred to as certificates. The certificates are electronic data installed in the vehicle 1, and are issued to the charge control device 10 by an external computer such as a certification authority, the MO server 5, and the OEM server 6. Here, the certification authority refers to a authority authorized to issue a certificate to a company, organization, person, and the like. Besides certification authority belonging to a company such as an OEM, an organization, or the like, the certification authority may be a authority independent of a company such as an OEM, an organization, a person, or the like, and may be referred to as a root certification authority having secure reliability as it is checked.The charging control device 10 may generate an electronic signature (a digital signature) based on a certificate or the like having a private key corresponding to the certificate, and request authentication to an external computer such as the charging device 2, the MO server 5, the OEM server 6, or the certification authority. In the present embodiment, the electronic signature is simply referred to as a signature. An external computer such as the charging device 2, the MO server 5, the OEM server 6, or the certification authority has a public key paired with the private key, and can determine whether authentication is possible by decrypting the signature. The private key and the public key may be an example of pair key information.Specifically, the vehicle 1 is connected to the charging device 2. The charging device 2 is provided with a certificate (C) such as an OEM provision certificate or a vehicle certificate issued from the OEM server 6 and a signature based on a private key (KS) from the vehicle 1. Then, the charging device 2 checks the signature using a public key of a corresponding certificate. In addition, a sequence check may be performed using an OCSP (Online Certificate Status Protocol), a CRL (Certificate Review List), and the like.The certificate may be output to a storage device attached to the charging device 2 and stored therein. The storage device connected to the charging device 2 is, for example, a memory 22 of the charging device 2, an external storage unit 23, or a storage device such as a computer that can be accessed by the charging device 2 via the network N 1.In the present embodiment, an external computer that installs a certificate 1 in the vehicle 1 via the network N 1 is referred to as an issuer. For example, when the contract certificate is issued from the MO server 5 and installed in the vehicle 2 via the OEM server 6 or the charging facility 2, the MO server 5 may be regarded as an issuer. And, for example, when the OEM provision certificate or the vehicle certificate is issued from the OEM server 6 and installed in the vehicle 1, the OEM server 6 may be regarded as an issuer.The present embodiment illustrates a process for updating a certificate C 1 and a private key KS 1 corresponding to the certificate C 1 already installed in the charge control device 10 into a new certificate C 2 and a private key KS 2 corresponding to the certificate C 2. That is, here, it is assumed that the certificate C 1 is updated to the certificate C 2 in the external computer such as the MO server 5, the OEM server 6, or the certificate authority.For example, when the certificate C 1 is updated in the OEM server 6, the OEM server 6 sends a certificate signing request (CSR) generation request to the charge control device 10 of the vehicle 1 to which the certificate C 1 has already been issued (R 1). Then, the charge control device 10 generates a pair of a public key KO2 and the private key KS2, and sends a CSR including the public key KO2 of the generated pair to the OEM server 6 (R2). Then, the OEM server 6 generates the new certificate C2 by itself signing, for example, the received public key KO2 with a private key obtained from the certificate authority. The OEM server 6 may send the CSR to the MO server 5, request generation of the new certificate C 2, and obtain the certificate C 2 from the MO server 5. The OEM server 6 outputs the generated certificate C 2 to the charging control device 10 and installs the certificate C 2 in the charging control device 10, thereby updating the certificate C 1 to the certificate C 2 (R 3).Accordingly, the private key KS1 is modified to the private key KS2. Thereafter, the charge control device 10 generates a signature on the basis of the updated certificate C 2 and the private key KS 2, and requests authentication by the charging device 2 or the like. The charging facility 2, or the MO server 5, the OEM server 6, or the like to which the signature has been sent via the charging facility 2 determines whether the signature is appropriate using the modified public key KO 2, and determines whether to authenticate the charging control device 10.As described below, in the present embodiment, the charge control device 10 updates the certificate C 1 and the private key KS 1 to the new certificate C 2 and the new private key KS 2 in a state where a signature using the existing private key KS 1 is valid. Therefore, in the present embodiment, when the charge controller 10 experiences charging from the charging device 2 by PnC, the charge control device 10 can be stably charged by the charging device 2 regardless of the update of the private key KS 1 to KS 2.The present embodiment describes an example in which a certificate (for example, an OEM provision certificate or a vehicle certificate) is updated according to a generation request from the OEM server 6. In updating a certificate (for example, a contract certificate) according to a generation request from the MO server 5, the MO server 5 may update the certificate of the charge control device 10 in the same manner via the OEM server 6. That is, the OEM server 6 may transmit a CSR generation request to the vehicle 1 in response to a request from the MO server 5. Then, the OEM server 6 may send a CSR obtained from the charge control device 10 to the MO server 5 and request the issue of a certificate. Further, the OEM server 6 may transmit the updated certificate issued from the MO server 5 to the charge control device 10.FIG. 2 shows hardware structures of the vehicle 1 and the charging device 2. the charge control device 10 of the vehicle 1 and the charging device 2 that charges the battery 19 mounted on the vehicle 1 constitute a charging system. The vehicle 1 includes the charge control device 10 and the battery 19 whose charge is controlled by the charge control device 10.The charge control device 10 includes a CPU 11, a memory 12, and an external device connected to an external interface (I / F), and executes information processing according to a program. Examples of the external device include an external storage unit 13, a display unit 14, an operation unit 15, an external communication unit 16A, and a charge communication unit 16B. The CPU 11 and the memory 12 may be collectively referred to as a control unit. The control unit is also referred to as an electronic control unit (ECU). The control unit is an example of control.The CPU 11 executes a computer program loaded into the memory 12 in an executable manner and provides the functions of the load control device 10. The CPU 11 is also referred to as a processor or a microcontroller unit (MCU). The memory 12 stores computer programs executed by the CPU 11, data processed by the CPU 11, and the like.The memory 12 is a dynamic random access memory (DRAM), a static random access memory (SRAM), a read only memory (ROM), or the like. The external storage unit 13 is used as, for example, a storage area for supporting the memory 12, and stores computer programs executed by the CPU 11, data processed by the CPU 11, and the like. The external storage unit 13 is a hard disk drive, a solid state drive (SSD), or the like.The display unit 14 is, for example, a liquid crystal display or an electroluminescence panel. The operation unit 15 is, for example, a keyboard or a pointing device. The present embodiment illustrates a touch panel having a touch sensor as a pointing device. The display unit 14 and the operation unit 15 function as a user interface available to a user.The external communication unit 16A exchanges data with another device (such as the OEM server 6 in FIG. 1 ) in a public network such as the network N 1 (see FIG. 1 ). For example, the CPU 11 communicates with a computer of an enterpriser via the external communication unit 16A in a public network. The external communication unit 16A may be a wireless communication device that accesses a cellular network. The external communication unit 16A may be a communication device that accesses a wireless local area network (LAN). The external communication unit 16A is referred to as a telematics control unit (TCU), and may perform communication referred to as telematics via the network N 1.The charge communication unit 16B exchanges signals with a charge communication unit 26B. That is, the charging communication unit 16B performs communication with the charging device 2 by, for example, a communication method based on power line communication (PLC) or similar to the PLC. The charging communication unit 16B may perform communication with the charging communication unit 26B through a controller area network (CAN), a wireless LAN, Ethernet, or the like, or through a communication operation based thereon. The charging communication unit 16B may internally include a CPU, a memory, an input / output interface, a communication interface, and the like. In the present embodiment, the charge control device 10 communicates with the charging device 2 via the external communication unit 16A or the charge communication unit 16B, and performs a charge request and an authentication process.The charging device 2 includes a CPU 21, a memory 22, and an external device connected to an external interface (I / F), and executes information processing according to a program. Examples of the external device include an external storage unit 23, a display unit 24, an operation unit 25, an external communication unit 26A, the charge communication unit 26B, and the EIM reader 2A. The charger 2 further includes a power supply circuit 29. The other configurations of the charging device 2 as the EIM reader 2A and the power supply circuit 29 are the same as those of the charge control device 10 of the vehicle 1, and thus the description thereof is omitted.The EIM reader 2A is a card reader that reads information from an IC card such as a credit card by a touch or in a non-contact manner, an image reading device that reads a QR code (registered trademark), an RFID reader, or the like. The power supply circuit 29 supplies power to the battery 19 and charges the battery 19, and in FIG. 2, the charge communication unit 16B and the charge communication unit 26B as well as the battery 19 and the power supply circuit 29 are connected via the connector 2B in FIG. 1.That is, the charge control device 10 of the vehicle 1 communicates with the charging device 2 when the connector 2B is connected to a terminal portion including a power receiving unit of a circuit and a terminal of the charge communication unit 16 in the vehicle 1 of which the battery 19 is charged. The charge control device 10 of the vehicle 1 communicates with the charging facility via the charge communication units 16B and 26B, for example, and performs PnC through TLS authentication and vehicle-to-grid (V2G) communication. The charge control device 10 of the vehicle and the charging device 2 mutually authenticate each other through the TLS authentication and the V2G communication, charge the battery 19 of the vehicle 1, and perform an authentication process related to the charging. The charge control device of the vehicle 1 and the charging device 2 can communicate with each other via the external communication units 16A and 26A when the plug 2B is connected to the terminal portion in the vehicle 1 including the power receiving unit of the circuit and the terminal of the charge communication unit 16B.The MO server 5 and the OEM server 6 have the same configuration as the CPUs 11 and 21, the memories 12 and 22, the external storage units 13 and 23, the display units 14 and 24, the operation units 15 and 25, the external communication units 16A and 26A, and the like. The MO server 5 and the OEM server 6 are general computers. The MO server 5 and the OEM server 6 may be a set of multiple computers called a cloud.The MO server 5 may be referred to as an Enterprise (MO) computer that provides the service to the user for charging the vehicle 1. The charging facility 2 can be managed and operated by an enterprise called a charge point operator (CPO) besides an MO. The OEM server may be referred to as an enterpriser's computer in connection with the manufacture and sale of the vehicle 1,The certificate and private key updating process of FIG. 3 shows a process of updating a private key by the charge control device 10 according to the present embodiment. In FIG. 3, an arrow A in the middle shows a transition from a process with a symbol R 1 to a process with a symbol R 3. The process with the symbol R 1 above the arrow A in FIG. 3 corresponds to the symbol R 1 in FIG. 1. The process with the symbol R 3 under the arrow A in FIG. 3 corresponds to the symbol R 3 in FIG. 1. The process with the symbol R 3 is a process when the charging control device 10 installs the certificate C 2 obtained from the OEM server 6 and stores the certificate C 2 in a security storage in the storage 12 or the external storage unit 13.Here, the charge control device 10 has already stored, for example, the private key KS 1 corresponding to the certificate C 1 in a storage space in the security storage in the memory 12 or the external storage unit 13. In a register of the CPU 11, it is registered that a currently used storage space is SL1. That is, the charge control device 10 stores a first private key (the private key KS 1) corresponding to an installed first certificate (the certificate C 1) in a first area (the storage space SL 1) of the memory 12 or the like. The certificate C 1 is an example of the first certificate, the private key KS 1 is an example of the first private key, and the storage space SL 1 is an example of the first area. Here, the security memory is a storage device which checks the authenticity or legitimacy of the access and permits the access (read or write) when the authenticity or legitimacy has been confirmed in response to an access request from the CPU 11. For example, the charge control device 10 sends a signature signed with a certain encryption key to the security storage to request the security storage to check authenticity. The memory locations SL1 and SL2 are memory destinations in the security memory and are, for example, addresses and register numbers.In this state, when a request for updating the certificate C 1 to the new certificate C 2 is generated in the OEM server 6, a CSR generation request is sent from the OEM server 6 to the charging control device 10. Upon receiving the SCR generation request, the charge control device 10 generates a pair of the public key KO 2 and the private key KS 2, and requests the storage space SL 2 of the security storage to store the private key KS 2 (also referred to as generation of information). Thereby, the new private key KS2 is stored in the memory space SL2, while the existing private key KS1 is retained in the memory space SL1. Then, the charging control unit 10 generates a CSR including the public key KO 2, and sends the CSR to the OEM server 6 (R 2 in FIG. 1 ).Then, in the lower process with the symbol R 3, the OEM server 6 generates, for example, the certificate C 2 for the CSR and sends the certificate C 2 to the load control unit 10. Upon receiving the certificate C 2, the load control device 10 changes the currently used storage space in the register to SL 2 and instructs the security storage to remove (delete) the private key KS 1 in the storage space SL 1. Accordingly, the private key KS1 in the storage space SL1 is removed (or deleted), and a process such as a signature is executed by the private key KS2 in the storage space SL2. As described above, in the present embodiment, the charge control device 10 manages a kind of key stored in the security memory having two storage locations. Accordingly, when the number of kinds of keys to be managed is K (K is an integer), the load control device 10 can prepare 2*K storage locations.In FIG. 3, the private keys KS1 and KS2 are stored in the storage locations SL1 and SL2 of the security memory. The load control device 10 may also store in the storage locations SL 1 and SL 2 of the security store a key pair, i.e. a pair of the private key KS 1 and the public key KO 1 or a pair of the private key KS 2 and the public key KO 2. When the private keys KS1 and KS2 are stored in the storage locations SL1 and SL2 of the security store, the public keys KO1 and KO2 may be stored in an area other than the security store of the memory 12. This is because it is not so much necessary or necessary to store the public keys KO1 and KO2 for more security compared with the private keys KS1 and KS2.Hereinafter, the certificate C 1, the public key KO 1, and the private key KS 1 may be referred to as the first certificate C 1, the first public key KO 1, and the first private key KS 1. The certificate C 2, the public key KO 2, and the private key KS 2 may be referred to as a second certificate C 2, a second public key KO 2, and a second private key KS 2.FIG. 4 is a sequence diagram showing a certificate updating process according to the first embodiment. FIG. 4 illustrates a case where a request for updating the certificate occurs in the OEM server 6. When a request for updating the certificate occurs in the OEM server 6, the OEM server 6 sends a CSR generation request to the charge control device 10 of the vehicle 1 (P 1). The CSR generation request at P 1 is an example of a request from a certificate issuer. The OEM server 6 is an example of the certificate issuer. In the example of FIG. 4, it is assumed that the CSR generation request is obtained from the charge control device 10 of the vehicle 1 while the vehicle is connected to the charging device 2 through the connector 2B (FIG. 1 ) (see the dashed frame). In the sequence diagram of FIG. 4, a vertical axis corresponds to the time course.Upon receiving the CSR generation request while the vehicle 1 is connected to the charging device 2, the charge control device 10 sends a response (hereinafter referred to as a negative response) indicating that the charge control device 10 does not respond to the CSR generation request to the OEM server 6 (P 2). The process of P 2 is an example in which, when a request is received from the OEM server 6 constituting the issuer, the request is rejected when the charge control device 10 is connected to the charging device 2. Then, the charge control device 10 executes a process connected to the charging device 2, for example, a process by the current private key KS 1, or continues a process that has been executed (P 3). The process by the current private key KS 1 includes, for example, generating a signature and requesting authentication of the signature by the charging device 2. for example, the charging control device 10 performs charging control with the charging device 2 based on the valid private key KS 1 and the certificate C 1 corresponding to the valid private key KS 1. Here, the current private key KS1 is stored in the storage space SL1, and it is registered in the register of the load control apparatus 10 that the currently used storage space is the storage space SL1.Then, the OEM server 6 again sends a CSR generation request to the charge control device 10 of the vehicle 1 (P 4). The CSR generation request is also an example of a request from the certificate issuer. When the charge control device 10 receives the CSR generation request again, the vehicle 1 is not connected to the charging device 2. Upon receiving the CSR generation request in a state where the vehicle 1 is not connected to the charging device 2, the charge control device 10 executes a key generation process (P 5). The key generation process is performed, for example, as described in FIG. 3. Then, the charge control device 10 requests the security storage to store the new private key KS2 in the storage space SL2 while retaining the current private key KS1 in the storage space SL1. Accordingly, it can be said that the charge control device 10 does not overwrite the private key KS 1, which is the first private key, with the private key KS 2, which is the second private key.The process of P 5 is an example of generating the second private key and the public key in response to a request from the certificate issuer. The private key KS2 generated at P5 is an example of the second private key. In this case, the public key KO2 paired with the private key KS2 is also generated. Storing the new private key KS 2 in the storage space SL 2 is an example of storing the second private key in a second area different from the first area of the memory 12 or the like. That is, the storage space SL 2 is an example of the second area. In addition, keeping the current private key KS 1 in the storage space SL 1 is an example of using the first private key until the installation of the second certificate is completed. That is, the charge control device 10 performs the charge control with the charging device 2 on the basis of the valid private key KS 1 and the certificate C 1 corresponding to the valid private key KS 1 until the second certificate (the certificate C 2) corresponding to the public key KO 2 is installed.Then, the charge control device 10 sends a CSR including the public key KO2 generated as a pair with the private key KS2 to the OEM server 6 (P6). The process of P 6 is an example of sending the public key to the issuer. Upon receiving the CSR including the public key KO 2 from the charge control device 10, the OEM server 6 generates the certificate C 2 based on the public key KO 2 and signs the certificate C 2 using a private key issued from the certification authority. Then, the OEM server 6 outputs the certificate C 2 to the charge control device 10 (P 7).Upon receipt of the certificate C2, the load control apparatus 10 registers in the register that the currently used storage space is the storage space SL2, requests the security memory to remove (also referred to as deletion) the private key KS1 of the storage space SL1, and causes the security memory to perform the removal (deletion) (P8). At P 8, obtaining the certificate C 2 and registering in the registry that the currently used storage space is the storage space SL 2 is an example of installing the second certificate. In this manner, in the charge control apparatus 10, an OEM provision certificate and a vehicle certificate and the like as well as a corresponding private key and the like are changed. For example, the charge control device 10 performs the charge control with the charging device 2 on the basis of the valid private key KS 2 and the certificate C 2 corresponding to the valid private key KS 2. That is, when the installation of the second certificate (certificate C 2) corresponding to the private key KL 2 is completed, the charge control device 10 deletes the private key KS 1 that is the first private key. Then, the charge control device 10 performs charge control with the charging device 2 on the basis of the valid private key (the private key KS 2) and the second certificate (the certificate C 2). In the charge control apparatus 10, an operation for changing a private key corresponding to a contract certificate is the same as the operation of Fig. 4 except that both the OEM server 6 and the MO server 5 are involved.In addition, in FIG. 4, the private keys KS1 and KS2 are stored in the storage locations SL1 and SL2 of the security memory. The charge control device 10 may also store in the storage locations SL 1 and SL 2 of the security store a key pair, i.e. a pair of the private key KS 1 and the public key KO 1 or a pair of the private key KS 2 and the public key KO 2. When the private keys KS1 and KS2 are stored in the storage locations SL1 and SL2 of the security memory, the public keys KO1 and KO2 may be stored in an area other than the security memory of the memory 12 or the external storage unit 13.FIG. 5 is a flowchart showing an update process of a pair of a certificate and a key by the charge control device 10 according to the first embodiment. The process starts, for example, when the charge control device 10 receives a request from an external device such as the OEM server 6 via the external communication unit 16A. It is assumed that at the time of the start, the currently used private key is the private key KS1 and the certificate C1 is valid.In the process of FIG. 5, the charge control device 10 determines whether the vehicle 1 is currently connected to the charging device 2 (S 1). Such connection of the vehicle 1 to the charging device 2 means, for example, a state in which the plug 2B (FIG. 1 ) of the charging device 2 is connected to the terminal portion of the vehicle 1 having the power receiving unit connected to the battery 19 and a communication terminal. When the connector 2B of the charging device 2 is connected to the terminal portion of the vehicle 2, for example, the charging communication unit 26B (FIG. 2 ) transmits a pulse signal or the like defined by specifications or standards of the device to the charging communication unit 16B. For this reason, the charge control device 10 can acquire the connection with the charging device 2 via the charge communication unit 16B.When the vehicle 1 is currently connected to the charging device 2 (YES in S 1), the charging control device 10 sends a negative response to the OEM server 6 (S 2). Then, the charge control device 10 ends the process.On the other hand, when the vehicle 1 is not currently connected to the charging device 2 (NO in S 1), the charging control device 10 determines the type of request obtained via the external communication unit 16A (S 3). When the type of the received request is a CSR generation request (SCR at S 3), the load control device 10 reads a storage location number of the currently used storage location from the register and determines a storage location number of the currently used storage location (S 4).When it is determined at S 4 that the currently used storage space is SL 1, the charge control device 10 generates a pair of the public key KO 2 and the private key KS 2 (S 5) in the storage space SL 2. The charge control device 10 may generate the pair of the public key KO 2 and the private key KS 2 in the memory 12 or the external storage unit 13, and request the security memory to store both in the storage space SL 2. The charge control device 10 may request the security storage to store only the private key KS 2 of the generated key pair in the storage space SL 2. This is because it is desired that the private key KS2 is kept secret to secure security. In addition, the pair of the public key KO2 and the private key KS2 may be generated in the security memory.In any case, the charge control device 10 stores the private key KS 1 corresponding to the currently valid certificate C 1 and the private key KS 2 corresponding to the certificate C 2 to be newly obtained in the future in different storage locations SL 1 and SL 2, respectively, by the process of S 5. The charging control device 10 determines the private key KS 1 to be valid until the installation of the new certificate C 2 is completed, and determines the private key KS 2 to be valid when the installation of the new certificate C 2 is completed.On the other hand, if it is determined at S4 that the currently used storage space is SL2, a pair of the public key KO2 and the private key KS2 is generated in the storage space SL1 (S6). The process of S 6 is the same as the process of S 5, and thus the description thereof is omitted. After the process of S 5 or the process of S 6, the charge control device 10 sends a CSR including the public key KO 2 generated in the process S 5 or the process S 6 to the OEM server 6 (S 7).When it is determined at S 3 that the request is an issue of a certificate (certificate issue at S 3), the load control device 10 refers to the number of the currently used storage space from the register and determines the number of the currently used storage space (S 8). When it is determined at S8 that the currently used storage space is SL1, the load control device 10 inverts the storage space number of the currently used storage space of the register to SL2 (S9).Then, the charge control device 10 removes the key of the storage space SL 1 (SL 10). In the process of S 10, when the key pair is stored in the storage space SL 1, the charge control device 10 may remove the key pair. On the other hand, when only the private key KS 1 is stored in the storage space SL 1, the charge control device 10 may remove the stored private key KS 1.On the other hand, when it is determined at S8 that the currently used storage space is SL2, the load control device 10 inverts the storage space number of the currently used storage space of the register to SL1 (S11). Then, the charge control device 10 removes the key of the storage space SL 2 (SL 12).The process of S 12 is the same as that of S 10, and thus the description thereof is omitted.Effects of the First EmbodimentAs described above, in response to a request from an external device such as the OEM server 6, which is a certificate issuer, the charge control device 10 generates pair key information regarding the first private key KS 1 and the first public key KO 1. Then, the charge control device 10 sends a CSR including the first public key KO 1 to the issuer and installs the issued first certificate C 1. Then, the charge control device 10 generates a signature based on the installed first certificate CS 1 and the first private key KS 1, and performs charge control with the charging device 2.In the present embodiment, in a state in which the existing first private key KS 1 is installed, the charge control device 10 receives a CSR generation request from the OEM server 6 or the like. Then, the charge control device 10 generates a new pair of the second public key KO 2 and the second private key KS 2, and sends a CSR including the second public key KO 2 to the OEM server 6 or the like. Then, the charge control device 10 acquires and installs the new second certificate C 2. At this time, the load control device 10 stores the first private key KS1 corresponding to the currently valid first certificate C1 and the second private key KS2 corresponding to the new second certificate C2 issued on the basis of a request from the OEM server 6 in the storage locations SL1 and SL2 which are different storage locations.The charging control device 10 determines the first private key KS 1 to be valid until the installation of the second certificate C 2 is completed, and determines the second private key KS 2 to be valid when the installation of the second certificate C 2 is completed. Accordingly, the charging control device 10 may execute a process by the first private key KS 1 from the generation of the pair of the second public key KO 2 and the second private key KS 2 until completion of installation of the second certificate C 2. That is, the charge control device 10 may generate a signature using the first private key KS 1 corresponding to the previously valid first certificate C 1 and request an external device such as the charging device 2 for authentication.When the installation of the second certificate C 2 is completed, the charging control device 10 deletes the first private key KS 1. Accordingly, the charge control device 10 can effectively use the safety storage with less waste.And when the charge control device 10 is connected to the charging device 2 and receives a request from the OEM server 6 or the like, which is an issuer, the charge control device 10 rejects the request by returning a negative response. Accordingly, the charge control device 10 can execute a process with a lower load by reducing the number of parallel processes in the certificate generation requesting process and the signature authentication requesting process.Second EmbodimentWith reference to FIG. 6, the charge control device 10 and a program according to a second embodiment will be described below. In the first embodiment, the charge control device 10 returns a negative response and ends the process when the charge control device 10 receives a request from an external device such as the OEM server 6 and the vehicle 1 is connected to the charging device 2. However, instead of returning a negative response, the charge control device 10 may wait while the vehicle 1 is connected to the charging device 2. In the second embodiment, the processes other than the process in which the charge control device 10 waits while the vehicle 1 is connected to the charging device 2 are the same as those in the first embodiment. Here, structures and processes of the charge control device 10 according to the first embodiment are appropriately referred to, and also applied to the present embodiment.FIG. 6 is a flowchart showing an update process of a certificate and a key pair by the charge control device 10 according to the second embodiment. As in the first embodiment, the process is started, for example, when the charge control device 10 receives a request from the OEM server 6 or the like via the external communication unit 16A. In the process, as in the first embodiment, the charge control device 10 determines whether the vehicle 1 is currently connected to the charging device 2 (S 1).When the vehicle 1 is currently connected to the charging device 2, the charge control device 10 waits (S 2A). The waiting may be waiting for a time period until a timer expires. The charge control device 10 may also wait until it detects, via the external communication unit 16A, that the connection with the charging device 2 has been disconnected. During the waiting period, in another parallel process, the charge control device 10 may execute a process by a current key shown at P 3 in FIG. 4.When the vehicle 1 is not connected to the charging device 2 after waiting, the charge controller 10 executes the processes of S 3 and later. The processes of S 3 and later in FIG. 6 are the same as those in FIG. 5, and thus their descriptions are omitted.As described above, in the present embodiment, upon receiving a request from an external device such as the OEM server 6 while the vehicle is connected to the charging facility 2, the charge control device 10 waits without executing the process of generating a CSR and the process of transmitting the CSR. When the vehicle 1 is not connected to the charging device 2 after waiting, the charge control device 10 executes the processes of S 3 and later. For this reason, even when a CSR generation request is received by the charge control device 10, the charge control device 10 may generate a signature using the currently used private key KS 1 and request authentication from an external device such as the charging device 2. And when the vehicle 1 is not connected to the charging device 2 after waiting, the charging control device 10 executes the processes of S 3 and later, whereby the number of parallel processes can be reduced and the load can be reduced.Third EmbodimentWith reference to FIGS. 7 and 8, the charge control device 10 and a program according to a third embodiment will be described below. In the first embodiment, upon receiving a request from an external device such as the OEM server 6, the charge control device 10 returns a negative response and ends the process when the vehicle 1 is connected to the charging device 2. In the second embodiment, the charge control device 10 waits without returning a negative response.In the present embodiment, the charge control device 10 executes in parallel a process of requesting authentication by a signature using the currently used key KS 1 and a process of updating the private key KS 1 to the private key KS 2 using a CSR. In the third embodiment, the configurations and processes of the charge control device 10 are the same as those according to the first embodiment and the second embodiment, except that the process of requesting the authentication or the like by the signature and the process of updating the private key KS 1 to the private key KS 2 by the CSR are executed in parallel. Here, structures and processes of the charge control device 10 according to the first embodiment and the second embodiment are appropriately referred to, and also applied to the present embodiment.FIG. 7 is a sequence diagram showing a certificate updating process according to the third embodiment. As in FIG. 4, for example, upon occurrence of a request for updating the current certificate C 1 in the OEM server 6, the OEM server 6 sends a CSR generation request to the charge control device 10 of the vehicle 1 (P 11). Here, the vehicle 1 is currently connected to the charging device 2. In this case, the charge control device 10 may execute a process by the current private key KS 1 (P 12), for example. The process by the private key KS 1 includes, for example, generating a signature by the private key KS and a request for authentication to the charging device 2.In this way, even when the vehicle 1 is connected to the charging facility 2, the charge control device 10 executes a key generation process without considering the connection to the charging facility 2 (P 13). The process at P 13 is the same as the key generation process in FIG. 4. That is, in the process of P 13, the charge control device 10 stores the second private key (the private key KS 2) upon receiving the request from the OEM server 6, which is an issuer, while the vehicle 1 is connected to the charging device 2, which performs authorization on the basis of the first certificate (the certificate C 1) corresponding to the first private key (the private key KS 1) and the first private key.FIG. 7 shows an example in which the charge control device 10 executes the key generation process at P 13 after the process by the current private key KS 1 at P 12. However, the charge control device 10 may execute the process by the current private key KS 1 at P 12 and the key generation process at P 13 in parallel. Then, the charge control device 10 sends a CSR including the public key K02 generated as a pair with the private key KS2 to the OEM server 6 (P14). Through the processes of P 13 and P 14, the charging control device 10 requests the OEM server 6 to install the second certificate (the certificate C 2) corresponding to the private key KS 2, and uses the first private key (the private key KS 1) at least during the connection of the charging control device 10 to the charging device 2. That is, the charge control device 10 performs the charge with the charging device 2 that authorizes based on the valid private key KS 2 and the certificate C 1 corresponding to the private key KS 1.Next, the charge control device 10 obtains, for example, the output of a changed certificate from the OEM server 6 (P 15). Upon receipt of the changed certificate, the charge control device 10 replaces the current private key KS 1 with the new private key KS 2. That is, the load control device 10 registers in a register that the currently used storage space is the storage space SL 2, requests the security memory to remove (delete) the private key KS 1 of the storage space SL 1, and causes the security memory to perform the removal (deletion) (P 16). That is, when the installation of the second certificate (certificate C 2) corresponding to the private key KS 2 is completed, the charge control device 10 deletes the private key KS 1 and performs the charge control with the charging device 2 on the basis of the valid private key KS 2 and the second certificate C 2.FIG. 8 shows a process flow of the charge control device 10 according to the third embodiment. As with the process of FIG. 5, the process of FIG. 8 is activated, for example, when the charge control device 10 receives a request from an external device, for example, the OEM server 6, via the external communication unit 16A. As in FIG. 5, it is assumed that the currently used private key is the private key KS 1 and the certificate C 1 is valid at the time of activation.In the process of FIG. 8, unlike FIG. 5, the charge control device 10 determines whether the vehicle 1 is connected to the charging device 2, and does not execute the process (the determination of S 1 and the process of S 2 in FIG. 5 ) when the vehicle 1 is connected to the charge control device 2. That is, the charge control device 10 determines the type of request obtained via the external communication unit 16A regardless of whether the vehicle 1 is connected to the charging device 2 (S 23). When the type of the received request is a CSR generation request, the charge control device 10 executes the processes from S 24 to S 27. The processes from S 24 to S 27 are the same as the processes from S 4 to S 7 in FIG. 5, and thus their descriptions are omitted. In the processes from S 24 to S 27, the charging control device 10 stores the second private key KS 2, and requests the OEM server 6 or the like, which is a certificate issuer, to install the second certificate C 2.On the other hand, when it is determined at S 23 that the request is the issue of a certificate (certificate issue at S 23), the charge control device 10 determines whether the vehicle is currently connected to the charging device 2 (S 1B). When the vehicle 10 is currently connected to the charging device 2, the charge control device 10 waits (S 2B). The waiting procedure is the same as that of S2A in Fig. 6.During the waiting period, in another parallel process, the charge control device 10 may execute a process by the current key, for example. According to the determination at S 1B and the waiting at S 2B, when the charge control device 10 receives the request from the OEM server 6 or the like, which is an issuer, it can be said that the first private key KS 1 is valid at least during the connection of the vehicle 1 to the charging device 2. It can also be said that the charging control device 10 does not use the key generated during a charging session during the charging session.When the vehicle 1 is not connected to the charging device 2 after waiting, the charge controller 10 executes the processes from S 28 to S 32. The processes from S 28 to S 32 are the same as those from S 8 to S 12 in FIG. 5, and thus descriptions thereof are omitted. That is, the charge control device 10 stores the private key KS 1 corresponding to the currently valid certificate C 1 and the private key KS 2 corresponding to the certificate C 2 to be newly obtained in the future, respectively, in different storage locations SL 1 and SL 2. The private key KS1 is valid until the installation of the new certificate C2 is completed, and the private key KS2 is valid when the installation of the new certificate C2 is completed. That is, when the charge control device 10 acquires the certificate from the OEM during the charge session, the charge control device 10 does not immediately change the currently used key but changes the currently used key after the charge session has ended.As described above, when the vehicle 1 is connected to the charging device 2 that performs authorization based on the first certificate C 1 and the first private key KS 1, the charging control device 10 does not make a negative response or wait upon receiving the CSR generation request from the OEM server 6 or the like that is a certificate issuer. That is, the charge control device generates a new pair of the public key KO2 and the private key KS2, and stores at least the private key KS2 in the storage space SL2.Then, the charging control device 10 sends a CSR to the OEM server 6 or the like from which the CSR generation request has been issued, and requests the issue (and installation) of the second certificate C 2. The charge control device 10 determines the first key KS 1 to be valid at least during the connection of the vehicle 1 to the charging device 2. For this reason, the charge control device 10 continues the process by the private key KS, which is the current key, even when the charge control device 10 receives the CSR generation request while the vehicle 1 is connected to the charging device 2. In parallel with this process, the charge control device 10 may request the OEM server 6 or the like to issue (and install) the second certificate C 2. In this case, the private key KS1, which is the current key, would not be overwritten with the new private key KS2. In addition, generation of a signature, a request for authentication to the charging device 2, and the like would not be interrupted before the issue (and installation) of the second certificate C 2 is completed.When the charge control device 10 waits as in S 1B and S 2B, at least during the connection of the vehicle 1 to the charging device 2, the private key KS 1 is valid. Upon receiving a request from the OEM server 6, which is a certificate issuer, the charging control device 10 newly stores the second private key KS 2 in the storage space SL 2 regardless of whether the vehicle 1 is connected to the charging device 2, and requests the OEM server 6 to install the second certificate C 2. However, if the second certificate C 2 is thereafter further obtained from the OEM server 6 during the connection with the charging device 2, the charging control device 10 waits and determines the first private key KS 1 to be valid at least during the connection with the charging device 2. Accordingly, the charge control device 10 may continue the process by the first private key KS 1 being currently processed and receive the authentication by a signature.When the installation of the second certificate C 2 is completed, the charging control device 10 determines the second private key KS 2 as valid. Accordingly, the charge control device 10 can smoothly transition from the process by the first certificate C 1 and the first key KS 1 to the process by the second certificate C 2 and the second key KS 2. That is, the charge control device 10 can continuously execute the process of requesting authentication by a certificate. The charging control device 10 can perform the PnC charging after the generation of the key of a certificate to be checked by the charging control device 10 without stopping the service until the OEM server 6 issues the certificate and installs the certificate in the charging control device 10,The computer-readable recording mediumA computer readable recording medium may have recorded thereon a program for causing a computer or other machine or device (hereinafter referred to as a computer or the like) to implement any of the above functions. The function can be provided by causing the computer or the like to read and execute the program on the recording medium.Here, the computer-readable recording medium refers to a recording medium that stores information such as data or programs by an electrical, magnetic, optical, mechanical, or chemical operation and can be read by a computer or the like. Among such recording media, a medium that can be taken out from the computer or the like includes, for example, a memory card such as a floppy disk, a magneto-optical disk, a CD-ROM, a CR-R / W, a DVD, a Blu-ray disk, and a flash memory. A recording medium fixedly installed in a computer or the like includes a hard disk, a read only memory (ROM), or the like. A solid state drive (SSD) may be used as a recording medium that can be moved away from a computer or the like, or as a recording medium fixedly mounted on a computer or the like.Otherwise,The present embodiments have the following aspects (hereinafter referred to as appendages):Appendix 1A charging control apparatus for a vehicle, comprising a controller configured to communicate with a charging facility for charging authentication, the controller storing a first key corresponding to a first certificate in a first area of a memory, the controller configured to generate a second private key and a public key in response to a request from a certificate issuer; store the second private key in a second area of the memory different from the first area; transmit the public key to the certificate issuer to obtain a second certificate issued by the certificate issuer; maintain use of the first private key until completion of installation of the second certificate; and use the second key after completion of installation.Appendix 2The charging control device of Appendix 1, wherein the controller is configured not to override the first private key by the second private key.Appendix 3The charge control device according to Appendix 1, wherein the controller is configured to communicate with the charging device for charge authentication based on the first or second private key that is valid and a certificate corresponding to the first or second private key that is valid.Appendix 4The charging control device of Appendix 1, wherein the controller is configured to delete the first private key after completion of installation of the second certificate.Appendix 5The charging control apparatus of Appendix 1, wherein the controller is configured to reject the request upon receipt of the request from the certificate issuer during connection to the charging facility.Appendix 6The charging control apparatus according to Appendix 1, wherein the controller is configured to, upon receiving the request from the certificate issuer during connection with the charging facility, store the second private key based on the first certificate and the first private key, request the certificate issuer to install the second certificate, and use the first private key at least during connection with the charging facility.Appendix 7The charging controller of Appendix 6, wherein the controller is configured to communicate with the charging device for charging authentication based on the first private key that is valid and the first certificate corresponding to the first private key.Appendix 8The load control device of Appendix 6, wherein the controller is configured to use the second private key upon completion of installation of the second certificate.Appendix 9The charging control device according to Appendix 8, wherein the controller is configured to delete the first private key after completion of installation of the second certificate, and to communicate with the charging device for charging authentication based on the second private key that is valid and the second certificate.Appendix 10A program for causing a controller to perform a process, the controller being configured to communicate with a charging facility for charge authentication, the controller storing a first private key corresponding to a first certificate in a first area of a memory, the process comprising generating a second private key and a public key in response to a request from a certificate issuer; storing the second private key in a second area of the memory different from the first area; sending the public key to the certificate issuer to obtain a second certificate issued by the certificate issuer; maintaining use of the first private key until completion of installation of the second certificate; and using the second private key after completion of the installation.Appendix 11A charging control method for a controller configured to communicate with a charging facility for charging authentication, the controller controlling a first private key corresponding to a first certificate in a first area of a memory, the charging control method comprising generating a second private key and a public key in response to a request from a certificate issuer; storing the second private key in a second area of the memory different from the first area; sending the public key to the certificate issuer to obtain a second certificate issued by the certificate issuer; maintaining use of the first private key until completion of installation of the second certificate; and using the second private key after completion of installation.References included in the specificationThis list of documents cited by the applicant has been produced in an automated manner and is only included for the better information of the reader. The list is not part of the German patent application or utility model application. The DPMA does not take any adhesion for any faults or omissions.Patent Literature citedJP 2018-19415
[0003]
Claims
A charging control apparatus for a vehicle, comprising a controller configured to communicate with a charging facility for charging authentication, wherein the controller stores a first key corresponding to a first certificate in a first area of a memory, wherein the controller is configured to generate a second private key and a public key in response to a request from a certificate issuer; store the second private key in a second area of the memory different from the first area; transmit the public key to the certificate issuer to obtain a second certificate issued by the certificate issuer; maintain use of the first private key until completion of installation of the second certificate; and use the second key after completion of installation.The charging control device according to claim 1, wherein the controller is configured not to override the first private key by the second private key.The charge control device according to claim 1, wherein the controller is configured to communicate with the charging device for charge authentication based on the first or second private key that is valid and a certificate corresponding to the first or second private key that is valid.The charging control device according to claim 1, wherein the controller is configured to delete the first private key after completion of installation of the second certificate.The charging control apparatus according to claim 1, wherein the controller is configured to reject the request upon receiving the request from the certificate issuer during connection with the charging facility.The charging control apparatus according to claim 1, wherein the controller is configured to, upon receiving the request from the certificate issuer during connection with the charging facility, store the second private key based on the first certificate and the first private key, request the certificate issuer to install the second certificate, and use the first private key at least during connection with the charging facility.The charging control device according to claim 6, wherein the controller is configured to communicate with the charging device for charging authentication based on the first private key that is valid and the first certificate corresponding to the first private key.The charging control device according to claim 6, wherein the controller is configured to use the second private key after completion of installation of the second certificate.The charging control device according to claim 8, wherein the controller is configured to delete the first private key after completion of installation of the second certificate, and communicate with the charging device for charging authentication based on the second private key that is valid and the second certificate.A non-transitory computer readable storage medium storing a program that causes a controller to perform a process, the controller being configured to communicate with a charging device for charge authentication, the controller storing a first private key corresponding to a first certificate in a first area of a memory, the process comprising generating a second private key and a public key in response to a request from a certificate issuer; storing the second private key in a second area of the memory different from the first area; sending the public key to the certificate issuer to obtain a second certificate issued by the certificate issuer; maintaining use of the first private key until completion of installation of the second certificate; and using the second private key after completion of the installation.A charging control method for a controller configured to communicate with a charging facility for charging authentication, the controller controlling a first private key corresponding to a first certificate in a first area of a memory, the charging control method comprising generating a second private key and a public key in response to a request from a certificate issuer; storing the second private key in a second area of the memory different from the first area; sending the public key to the certificate issuer to obtain a second certificate issued by the certificate issuer; maintaining use of the first private key until completion of installation of the second certificate; and using the second private key after completion of installation.
Citation Information
Patent Citations
Device, method and computer program for managing digital certificates
DE602004012485T2
System, authentication station, on-vehicle computer, public key certificate issuing method, and program
JP2018019415A
Dynamic certificate generation on a certificate authority cloud
US20220150238A1
System and method for authenticating communications between a vehicle, a charging station and a charging station management server
WO2021031061A1
JP002018019415A