Method for ensuring refueling at a trusted fuel supply device

The method employs bidirectional communication and encrypted data transmission to authenticate fuel supply devices, addressing the inadequacies of mechanical barriers and data transmission systems, ensuring secure and compliant refueling of e-fuel vehicles.

DE102024205031B3Active Publication Date: 2025-08-07SCHAEFFLER TECHNOLOGIES AG & CO KG

Patent Information

Application Number
DE102024205031
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-05-29
Publication Date
2025-08-07
Estimated Expiration
2044-05-29

AI Technical Summary

Technical Problem

Existing methods for preventing misfueling of e-fuel vehicles with conventional fuels are inadequate, as mechanical barriers are complex and prone to failure, and existing data transmission systems are susceptible to manipulation.

Method used

A method utilizing bidirectional communication between a vehicle and a fuel supply device, involving a communication device, a data processing device, and a network, to authenticate and ensure the fuel supply device is trusted before allowing refueling, using NFC and encrypted data transmission to prevent unauthorized fueling.

Benefits of technology

Ensures secure and reliable refueling of e-fuel vehicles by preventing misfueling through robust authentication and encryption, reducing the risk of abuse and ensuring compliance with legal regulations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for ensuring a refueling process of a vehicle (1) powered by an internal combustion engine at a trusted fuel supply device (4). The vehicle (1) comprises a first communication device (10), and the fuel supply device (4) comprises a second communication device (11) that can communicate with the first communication device (10). The fuel supply device (4) has a communication connection to a network, via which a connection to a data processing device (6, 23) can be established. Before the refueling process begins, a method is executed that comprises the following steps: ▪ Transmission of a first data packet from the vehicle (1) to the fuel supply device (4), ▪ Forwarding part or all of the first data packet from the fuel supply device (4) to the network (5), ▪ Processing the data packet received from the fuel supply device (4) via the network (5) in the data processing device (6, 23), ▪ Returning the data packet processed in the data processing device (6, 23) via the network (5) to the fuel supply device (4), ▪ Returning the data packet received by the data processing device (6, 23) from the fuel supply device (4) to the vehicle (1). ▪ Approval of the refueling process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical area

[0001] The invention relates to a method for ensuring a refueling process of a vehicle powered by an internal combustion engine at a trustworthy fuel supply device, wherein the vehicle has a first communication device and the fuel supply device has a second communication device, wherein the first communication device and the second communication device are designed such that communication can be generated between the two communication devices, wherein the fuel supply device has a communication connection to a network suitable for data transport, via which a connection to a data processing device can be established. State of the art

[0002] As part of the overall reduction of carbon dioxide (CO2) emissions, a ban on vehicles powered by internal combustion engines is planned within the European Union (EU). According to current status, this ban is scheduled to take effect in 2035. Unless a complete ban on vehicles powered by internal combustion engines is implemented, or if exceptions are granted, internal combustion engine vehicles will likely only be able to be powered by sustainably produced e-fuel. E-fuel is particularly distinguished by the fact that it is very similar to conventional petroleum-derived fuel, but is produced in a CO2-neutral manner.

[0003] While sufficient production of such e-fuels represents a challenge, it is also particularly important to ensure that vehicles marketed as e-fuel vehicles can also be operated exclusively with e-fuels after a certain deadline. To this end, devices must be created to ensure that an e-fuel vehicle cannot be refueled with conventional fuel.

[0004] A disadvantage of previously known devices for preventing misfueling, such as diesel instead of gasoline, is that the mechanical barriers, such as thicker and thinner fuel nozzles, require increased structural complexity, as mechanical components must be provided both on the vehicle and at the filling station to prevent misfueling. Furthermore, the number of different fuels that can be distinguished by such mechanical barriers is very small. Furthermore, misfueling is not completely prevented, as a smaller filler neck can still be inserted into the larger tank opening.

[0005] Furthermore, the methods currently available on the market to prevent misfuelling are more geared towards preventing damage to the vehicle, whereas the corresponding devices and methods to prevent misuse when refuelling with conventional fuel instead of e-fuel must have a higher safety threshold, as misfuelling constitutes a violation of the law that may be punishable depending on the applicable legal situation.

[0006] Another known method is described in EP 1 094 028 A1, which is based on the method of transmitting data from the vehicle to a verification system. While other vehicle refueling systems with automatic vehicle recognition transmit data via a cable connection along the fuel pump hose, this now occurs directly from the vehicle to the verification system, with a fuel pump point identifier located on the fuel pump nozzle being sent to the storage unit in the vehicle. Eliminating a transmission cable along the fuel pump hose significantly reduces the susceptibility of the refueling system to failure. Description of the invention, task, solution, advantages

[0007] Therefore, the object of the present invention is to create a method which prevents the improper filling of a vehicle declared as an e-fuel vehicle with a conventional fuel as safely as possible.

[0008] The problem with regard to the method is solved by a method having the features of claim 1.

[0009] An embodiment of the invention relates to a method for ensuring a refueling process of a vehicle powered by an internal combustion engine at a trustworthy fuel supply device, wherein the vehicle has a first communication device and the fuel supply device has a second communication device, wherein the first communication device and the second communication device are designed such that communication can be generated between the two communication devices, wherein the fuel supply device has a communication connection to a network suitable for data transport, via which a connection to a data processing device can be established, wherein before the start of the refueling process, a method is carried out which has the following steps: ▪ Transmission of a first data packet from the vehicle to the fuel supply device, ▪ Forwarding part or all of the first data packet from the fuel supply device to the network, ▪ Processing the data packet received from the fuel supply device via the network in the data processing device, ▪ Returning the data packet processed in the data processing device to the fuel supply device via the network, ▪ Return of the data packet received by the data processing device from the fuel supply device to the vehicle. ▪ Approval of the refueling process.

[0010] Due to the legislation expected to apply in the future, there will be vehicles with combustion engines that must be fueled with verifiably climate-neutral e-fuels. E-fuels are synthetically produced fuels that, in particular, do not contain fossil fuels. To prevent misuse and prevent the vehicle from running on conventional fuels, it must be ensured that the fuel supply facility, such as a gas station in particular, can only be used if it is trustworthy and if it is guaranteed that the appropriate fuel is being dispensed.

[0011] For this purpose, the vehicle has a communication device via which the vehicle can communicate with the communication device of the fuel supply device, in particular exchanging data packets. NFC (Near Field Communication) devices can be used for this purpose. Since the vehicle must both send data to and receive data from the fuel supply device, communication must be bidirectional.

[0012] A communication process can preferably be initiated by approaching the fuel nozzle to the vehicle's fuel tank. The transmitting and receiving elements, preferably antennas, are preferably arranged in the area of the fuel nozzle and the fuel nozzle. A particular advantage of using NFC technology in conjunction with a suitable antenna arrangement is that it ensures that the fuel nozzle cannot be removed from the vehicle's fuel tank without interrupting the connection. This makes misuse and incorrect refueling of the e-fuel vehicle more difficult. If the connection is interrupted, the vehicle can, for example, interrupt the refueling process.

[0013] The fuel supply device also has the means to establish communication with a data processing device via a suitable network, for example, the Internet, in order to forward the data received from the vehicle and receive it from this data processing device. Preferably, the connection to the network is established in an encrypted manner, for example, via a VPN (virtual private network).

[0014] An advantageous embodiment provides that the fuel supply device communicates with an internal company network, for example a network of the operator of the fuel supply device or a central umbrella organization, which in turn communicates with the data processing device using the Internet.

[0015] In a preferred embodiment, the method begins with the transmission of a first data packet from the vehicle to the fuel supply device. This can occur, for example, when the fuel pump nozzle approaches the vehicle. The data packet is preferably formed by a task that is passed from the vehicle to the fuel supply device. A task is basically defined by the vehicle sending a request, which must be supplemented by a response from the fuel supply device that matches the request. The vehicle alone is not able to solve the task. Tasks can be formed, for example, by a PIN-TAN process, a challenge-response method, or digital certificates. Other tasks are also conceivable, as long as they are issued by the vehicle and cannot be solved independently by the vehicle.

[0016] The fuel supply device is also unable to complete the task independently without assistance from other entities. Preferably, the task is presented in a new form each time a refueling process is started, so that no repetitions occur. This can be achieved, for example, by incorporating a random component into the task.

[0017] After receiving the task in the form of a data packet, the fuel supply device forwards the entire data packet, or at least the task to be solved. To do this, the fuel supply device can contact a network. This network can, for example, be formed by an internal network operated by the operator of the fuel supply device, which is set up, for example, in the form of a virtual private network (VPN), or directly via the Internet. From the operator's VPN, the Internet can also preferably be contacted in order to be able to forward the data packet to the desired destination. The advantage of using an intermediate VPN network is that it is secured by suitable encryption, thus ensuring the transmission of data that cannot be changed externally from the fuel supply device to the Internet and back.

[0018] The data packet is then forwarded via the internet to a data processing device. This device is capable of solving the task using the information available to it. The data processing device can be a cloud storage system, a database, or another suitable system capable of receiving data from the internet, processing it, and sending a response back to the data sender. Particularly advantageously, the data processing device could be a cloud storage system belonging to the vehicle manufacturer, or a cloud storage system independent of the specific manufacturer and operated by a reputable organization, such as the Central Association of the Petrol Station Industry (ZTG) or a government agency.

[0019] A key prerequisite for this is that the fuel supply device must identify itself to the data processing device using a known authentication method. This is necessary to ensure that the requesting fuel supply device is trustworthy. Since refueling e-fuel vehicles with e-fuel will be a legally regulated process, it is necessary to ensure that refueling cannot be carried out by dubious fuel supply devices. At the very least, the goal is to keep the costs of intentionally misfueling as low as possible.

[0020] Only if the fuel supply device can successfully identify itself will the data processing device solve the transmitted task and send it back to the fuel supply device.

[0021] Once the task is solved, the response in the form of the processed data packet is sent back via the network used directly to the fuel supply device or via the internal VPN network.

[0022] The fuel supply device then returns the received solution to the vehicle, which can then evaluate whether the filling station is trustworthy, which is the case if the solution is correct, or untrustworthy, which is the case if the solution is incorrect. Depending on this, the vehicle can authorize the refueling process and accept fuel, or abort the refueling process and refuse fueling using suitable blocking devices. One possible solution here would be a locking flap in the fuel filler neck that cannot be manipulated from the outside and is only opened when proof of a trustworthy fuel supply device can be provided.

[0023] A major advantage of the method described here is that only the fuel supply device actually needs to be connected to the internet. This can be ensured with greater security in a fixed structure than in a mobile vehicle. This allows for secure refueling even in regions with weak mobile network coverage.

[0024] It is particularly advantageous if the first data packet contains a task that must be completed, whereby the vehicle only authorizes the refueling process if the task has been correctly completed and returned to the vehicle. The task can be performed using PIN-TAN procedures, challenge-response methods, digital certificates, or similar methods.

[0025] It is also advantageous if the transmitted task can be solved by the data processing device. In particular, the task can be solved exclusively by the data processing device and not by the fuel supply device itself, the vehicle itself, or the network used for transmission. In this way, misuse can be prevented or significantly made more difficult, since local intervention is not possible to misuse the task.

[0026] A preferred embodiment is characterized in that the data processing device comprises or is connected to a database containing a complete list of all vehicles eligible for refueling. This is necessary to ensure that vehicles approved as e-fuel vehicles are reliably identified and can be refueled with certified e-fuel by trusted fuel supply devices.

[0027] Each e-fuel vehicle can be registered in a database and assigned a unique identifier, ensuring that each e-fuel vehicle is known with certainty and can be identified during a query. The database can also contain information that is preferably not available outside the database and serves to solve the tasks transmitted by fuel supply devices.

[0028] It is also preferable for the data processing device to access at least one vehicle-specific value from the database to solve the task transmitted to it by the fuel supply device via the data packet. This is advantageous in order to make external manipulation more difficult. Furthermore, it ensures that only vehicles stored in the database, i.e., registered vehicles, can be refueled.

[0029] Furthermore, it is advantageous if the data processing device is formed by a cloud storage device that has access to the database containing the vehicles and on which a processing routine designed to solve the assigned task can be executed. This is advantageous to ensure that the fuel supply devices can be supplied with solutions for the transmitted tasks at any time.

[0030] Furthermore, it is advantageous if an authentication process is performed, whereby the fuel supply device must identify itself to the data processing device using the authentication method in order to communicate with the data processing device. This serves to ensure that the fuel supply device is trustworthy and thus the vehicle can expect to be supplied with certified e-fuel.

[0031] It is also expedient if the task transmitted to the data processing device is only carried out once the fuel supply device has successfully authenticated itself to the data processing device. This prevents improperly transmitted requests from being ignored, thus preventing refueling by the vehicle from being refused.

[0032] Furthermore, it is advantageous if the data packet is transmitted from the vehicle to the fuel supply device via a bidirectional NFC connection, a Wi-Fi connection, a Bluetooth connection, or a UWB (Ultra Wideband) connection. This is advantageous to ensure that data can be sent from the vehicle to the fuel supply device as well as received from the vehicle. Various known communication standards can be used for this purpose.

[0033] Furthermore, it is preferable if an instance is provided downstream of the fuel supply device and upstream of the data processing device, which has a secure communication option with the fuel supply device and serves as a gateway to the data processing device. This can preferably be implemented using a virtual private network (VPN). The advantage of using a VPN network is that secure communication between the respective fuel supply devices and this instance can be ensured, thereby reducing the susceptibility to manipulation.

[0034] In principle, the timing and frequency of the gas station's authentication with the data processing device can vary; for example, queries can be performed before refueling, after refueling, or continuously at intervals. The time before refueling allows refueling to be prevented via an intermediary valve installed between the fuel nozzle and the tank. Authentication after refueling enables the transmission of additional data, such as information about the refueling (amount, duration, etc.), to the data processing device. This could be used, for example, to compile statistics. Alternatively, queries can be performed at intervals during refueling, ensuring continuous gas station authentication.

[0035] It is also advantageous if the refueling process is continuously monitored. This allows, in particular, the continued existence of the communication connection to be verified. Furthermore, the amount of fuel refueled can be documented, for example, for statistical purposes.

[0036] Furthermore, it is preferable if the uninterrupted existence of the communication connection between the vehicle and the fuel supply device is continuously monitored during the refueling process. In particular, queries can be carried out at regular intervals to ensure that the fuel nozzle is still correctly inserted into the vehicle's fuel filler neck. If the communication connection is interrupted for a certain period of time, refueling can be interrupted, as an interruption could indicate an attempted tampering. If an interruption occurs, for example, an error log can be written to or a message can be sent to the data processing device or another control authority. To make the monitoring system more robust, tolerable interruption times can be defined so that an error message is only generated once the interruption time is exceeded.

[0037] Advantageous further developments of the present invention are described in the subclaims and in the following description of the figures. Short description of the drawings

[0038] The invention is explained in detail below using exemplary embodiments with reference to the drawings. In the drawings: Fig. 1 a schematic view of how the process can be implemented, Fig. 2 a schematic view of the authentication steps within the procedure, and Fig. 3 a flow chart of the procedure. Preferred embodiment of the invention

[0039] The Fig. Figure 1 shows an overview of the method and its implementation. Reference numeral 1 indicates a vehicle with an internal combustion engine that is to be powered by e-fuel. Due to the expected legal framework, the vehicle must be refueled with e-fuel if it was sold as such. The vehicle 1 has a fuel filler neck 2, with a communication device 10 arranged on the vehicle 1 directly adjacent to the fuel filler neck 2. The fuel filler nozzle 3, which also has a communication device 11, is inserted into the fuel filler neck.

[0040] The communication devices 10 and 11 are designed such that bidirectional communication 7 can be established between the fuel supply device 4, to which the fuel nozzle 3 belongs, and the vehicle 1. Common communication methods can be used for this purpose. Near Field Communication (NFC) is particularly advantageous for this bidirectional communication. Advantageously, the antennas on the vehicle 1 and the fuel supply device 4, or the fuel nozzle 3, are arranged such that the connection is interrupted when the fuel nozzle 3 is removed.

[0041] The fuel supply device 4, which can be a conventional gas station, can dispense certified e-fuel to the vehicle 1 via the fuel pump nozzle 3, provided the vehicle 1 has recognized the fuel supply device 4 as a trusted fuel source. Otherwise, the vehicle 1 aborts the refueling process, for example, by sending a corresponding signal to the fuel supply device 4 or by preventing the fuel flow using a suitable means, such as a valve.

[0042] To start the refueling process, the vehicle 1 sends a task in the form of a data packet to the fuel supply device 4 as soon as the fuel nozzle 3 is approached or inserted into the fuel nozzle 2. This task serves as a secure means for the vehicle 1 to identify a trusted fuel source.

[0043] The task reaches the fuel supply device 4, which, however, cannot solve the task independently. The fuel supply device 4 forwards the task to an internal network 5 via a communication link 8. This can, for example, be a VPN network operated by the operator of the fuel supply device 4, which is suitable for establishing an internal connection to a company server that is protected from external access. The intermediate step of the internal network 5 is advantageous, but ultimately not absolutely necessary. Particularly with a view to the everyday implementation of the method at a large number of filling stations, it is advantageous if the individual fuel supply devices of an operator first communicate with an internal network instance, for example a central server, and only from this is the request transmitted to the downstream data processing device 6.

[0044] The data processing device 6 finally receives the task sent by the vehicle 1. Only the data processing device 6 is able to solve the task and return the correct solution.

[0045] The data processing device 6, which can be formed, for example, by a central cloud storage, can be contacted via the general internet. The data processing device 6 is either a database itself or has access to a database in which all vehicles 1 to be refueled with e-fuel are listed. For this purpose, it is necessary that each e-fuel vehicle 1 is centrally registered in this database or a comparable medium, enabling unique identification of the respective vehicle 1. This is preferably done by the manufacturer of the vehicles 1 during production or upon sale of the corresponding vehicle 1.

[0046] The data processing device 6 solves the transmitted task with the aid of the vehicle-specific data from the database and sends the solution back via the Internet to the internal network 5, if such a network is interposed, or directly to the fuel supply device 4. The fuel supply device 4 sends the solution on to the vehicle 1, which finally releases the refueling process if the solution is correct and aborts the refueling process if the solution is incorrect.

[0047] If necessary, the process can be repeated if an incorrect solution is received to ensure that no communication error occurred. If an incorrect solution is received, an entry can also be made in the memory of vehicle 1 to document the aborted refueling process. It would also be conceivable to store geodata from the navigation system or the communication module, if present in vehicle 1, in order to identify potentially corrupted fuel supply devices 4. Such data could be read out during a workshop visit or sent to a central location via the communication interface of vehicle 1 to make misuse more difficult.

[0048] Communication via the communication link 9 in the case of an upstream internal network 5, or via direct communication between the fuel supply device 4 and the data processing device 6, only occurs after successful authentication of the fuel supply device 4 with the data processing device 6. For this purpose, for example, a method with a public key and a private key can be used. Alternative authentication methods can also be used, as long as it is ensured that the fuel supply device 4 or the intermediate internal network 5 are among the permitted and trustworthy partners and thus have access to the data processing device 6.

[0049] This ensures that the data processing device 6 trusts the fuel supply device 4 or its intermediate internal network 5, and that the vehicle 1 also trusts the fuel supply device 4. If both are ensured and the task is solved correctly, a safe refueling process can be carried out.

[0050] Fig. 2 schematically shows a database 24 or cloud, for example, of the vehicle manufacturer. From this database 24, information uniquely describing the vehicle is sent to the so-called authentication authority 22. This occurs, for example, when the vehicle is registered in the database 24. The authentication authority 22 can be the authority previously described as a database, which the data processing device 23 accesses. Reference numeral 21 denotes a so-called certification authority, with which the fuel supply device must register and identify itself directly or via the downstream internal network 20. As described above, a public key and a private key can be used for this purpose. Other authentication methods are also conceivable.

[0051] The certification authority 21 and the authentication authority 22 together form the data processing device 23 with its database.

[0052] Fig. 3 shows a flowchart of the method. In step 30, the fuel nozzle is approached or inserted. In step 31, the vehicle transmits the task to the fuel supply device. In step 32, the fuel supply device forwards the task to an internal company network. In step 33, the internal company network contacts the data processing device and transmits an identification element. In step 34, the data processing device responds to the internal company network if a positive verification has taken place. In step 35, the internal company network transmits the task to the data processing device. In step 36, the data processing device solves the task and sends the solution back to the internal company network in step 37. In step 38, the internal company network forwards the solution to the fuel supply device, which transmits the solution to the vehicle in step 39.In step 40, the vehicle checks the solution and releases the refueling process in step 41 or aborts the refueling process.

[0053] The examples of the Fig. 1 to 3 are not restrictive in nature and serve to clarify the inventive concept. List of reference symbols 1 vehicle 2 fuel filler necks 3 fuel nozzle 4 Fuel supply device 5 internal network 6 Data processing device 7 bidirectional communication path 8 Communication route 9 Communication route 10 Communication device 11 Communication device 20 Internal network 21 Certification Body 22 Authentication authority 23 Data processing device 24 Database 30 process steps 31 process step 32 process steps 33 Process step 34 process steps 35 process steps 36 process steps 37 Process step 38 process steps 39 Process step 40 process steps 41 Process step

Claims

[1] Method for ensuring a refueling process of a vehicle (1) powered by an internal combustion engine at a trustworthy fuel supply device (4), wherein the vehicle (1) has a first communication device (10) and the fuel supply device (4) has a second communication device (11), wherein the first communication device (10) and the second communication device (11) are designed such that communication can be generated between the two communication devices (10, 11), wherein the fuel supply device (4) has a communication connection to a network suitable for data transport, via which a connection to a data processing device (6, 23) can be established, characterized by that before the refueling process begins, a procedure is carried out which includes the following steps: ▪ Transmission of a first data packet from the vehicle (1) to the fuel supply device (4), ▪ Forwarding part or all of the first data packet from the fuel supply device (4) to the network (5), ▪ Processing the data packet received from the fuel supply device (4) via the network (5) in the data processing device (6, 23), ▪ Returning the data packet processed in the data processing device (6, 23) via the network (5) to the fuel supply device (4), ▪ Returning the data packet received by the data processing device (6, 23) from the fuel supply device (4) to the vehicle (1). ▪ Approval of the refueling process. [2] Method according to claim 1, characterized bythat the first data packet contains a task to be solved, whereby the refueling process is only released by the vehicle (1) if the task has been correctly solved and returned to the vehicle (1). [3] Method according to claim 2, characterized by that the transmitted task can be solved by the data processing device (6, 23). [4] Method according to one of the preceding claims, characterized by that the data processing device (6) has a database or is connected to a database which has a complete list of all vehicles (1) which are eligible for refueling. [5] Method according to claim 4, characterized by that the data processing device (6, 23) accesses at least one vehicle-specific value from the database in order to solve the task transmitted to it by the fuel supply device (4) by means of the data packet. [6] Method according to one of the preceding claims, characterized by that the data processing device (6, 23) is formed by a cloud storage which has access to the database comprising the vehicles (1) and on which a processing routine designed to solve the task at hand can be executed. [7] Method according to one of the preceding claims, characterized by that an authentication process is carried out, wherein the fuel supply device (4) must identify itself to the data processing device (6, 23) by means of the authentication method in order to communicate with the data processing device (6, 23). [8] Method according to claim 7, characterized by that the solution of the task transmitted to the data processing device (6, 23) is only carried out when the authentication of the fuel supply device (4) at the data processing device (6, 23) was successful. [9] Method according to one of the preceding claims, characterized by that the transmission of the data packet from the vehicle (1) to the fuel supply device (4) takes place by means of a bidirectionally communicating NFC connection, a WIFI connection, a Bluetooth connection or a UWB (Ultra Wideband) connection. [10] Method according to one of the preceding claims, characterized by that an instance (5) is provided downstream of the fuel supply device (4) and upstream of the data processing device (6, 2§), which instance has a secure communication option with the fuel supply device (4) and serves as a gateway to the data processing device (6, 23). [11] Method according to one of the preceding claims, characterized by that the refueling process is continuously monitored. [12] Method according to claim 11, characterized bythat the uninterrupted existence of the communication connection between the vehicle (1) and the fuel supply device (4) is continuously monitored during the refueling process.

Citation Information

Patent Citations

  • Method and device for identifying automatically vehicles for fueling purposes

    EP1094028A1

Cited By

  • Method and vehicle with device for preventing misfuelling of a vehicle designed exclusively for use with carbon-neutral fuel

    DE102025135092A1