Charging controller, user interface controller, vehicle and corresponding methods and computer programs
Patent Information
- Application Number
- EP2023789620
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-01-31
- Filing Date
- 2023-10-11
- Publication Date
- 2025-12-10
AI Technical Summary
The existing Plug & Charge standard for electric vehicles restricts users to a single charging contract, limiting their choice of service providers and preventing the widespread adoption of this payment method by restricting competition and flexibility in charging networks.
A charging control device with a cryptographically secured element that can store multiple charging contracts, allowing users to select and manage multiple certificates, enabling the use of different contracts for each charging process through a user interface, independent of the charging station infrastructure.
This solution enhances user flexibility and competition by allowing multiple charging contracts to be stored and selected on the vehicle, enabling secure and efficient charging processes while maintaining compatibility with existing infrastructure, thereby promoting the adoption of the Plug & Charge standard.
Smart Images

Figure EP2023078236_08082024_PF_FP
Abstract
Description
[0001] Charging control unit, user interface control unit, vehicle and corresponding methods and computer programs
[0002] Technical area
[0003] The invention relates to a charging control device, a user interface control device, a vehicle with a charging control device and a user interface control device, as well as to corresponding methods and computer programs.
[0004] background
[0005] Plug & Charge (a charging standard for electric vehicles) is based on the industry standard ISO 15118. Using Plug & Charge (P&C), drivers of electric vehicles, such as battery electric vehicles (BEVs) or hybrid vehicles (PHEVs, plug-in hybrid electric vehicles, a hybrid vehicle whose battery can be charged by the engine and by plugging in a charging connector), can authenticate at public charging stations simply by plugging in the charging cable. Authentication is performed using a digital contract certificate in accordance with the standard. The contract certificate contains, among other things, the contract number.The charging point operator (CPO) can use this number to bill the charging process via existing roaming platforms with the contracted provider (EMP or MO, Electro Mobility Provider or Mobility Operator, often the same as the EMP) or directly with the customer (if the CPO is also a contracted provider). The functionality is described in detail below.
[0006] According to the current version of the standard (ISO 15118-2), the vehicle can only transmit one certificate to the charging station; therefore, in many systems only one certificate is stored on the vehicle. According to the standard, the certificate is usually stored on the charger. Certificates can be installed either via PLC (communication via charging cable) from the charging station or via a backend (i.e. via a server) / telematics connection. Contract certificates are managed in a shared pool (collection) in backends / servers. The certificates are created by the MO and retrieved by the OEM (Original Equipment Manufacturer), for example the vehicle manufacturer. A new version of the standard (ISO 15118-20) describes a procedure for using multiple certificates. However, this standard requires adaptations to the charging controllers and charging stations and will therefore only be supported by future vehicles.Generally, the ISO15118-2 version is used in both charging station infrastructure and vehicles. The vehicle and charging station should be able to communicate using the same version of the ISO standard.
[0007] A publication by Hubject (an aggregator) and Volkswagen, "Plug&Charge Multi-Contract Handling," addresses the use of multiple contracts. It proposes that customers can replace the (only) installed certificate with another, desired certificate. Limiting the number of certificates restricts the customer's choice of charging service provider (who issues the certificate). Currently, P&C works exclusively with the vehicle manufacturers' offerings. This not only restricts the customer (for example, regarding the alternating use of a private contract and a business contract), but also limits competition regarding P&C. This potentially prevents charging networks from offering P&C themselves, thus harming the spread and acceptance of this payment method.
[0008] There is a need for an improved concept for the technical security of the charging process of electric vehicles.
[0009] Summary
[0010] The present invention is based on the realization that support for multiple charging contracts can be created by storing multiple charging contracts / private keys in a cryptographically secured element (i.e., a "secure element") of the charging control unit of the vehicle, instead of storing a single charging contract or a private key of the certificate associated with the charging contract on the charging control unit of the vehicle. In other words, more than one contract certificate, for example, five certificates, can be installed on the vehicle at the same time. While the private key of the respective certificate / charging contract is stored in the cryptographically secured element, the actual certificate and metadata about the certificate can be stored outside the cryptographically secured element, for example for storage space reasons.In addition, the charging control unit stores information about which of the charging contracts should be used when initiating the charging process (via P&C or similar procedures). This selection can be made via a user interface control unit (also known as a “head unit”) of the vehicle. The driver of the vehicle has the option of determining which certificates are installed and which certificate will be used for the next charging process. The vehicle user interface can give the driver the option of selecting a charging certificate from a list of available certificates (e.g., the contracts the customer has already concluded or can conclude). The driver can, for example, install a specific number of charging certificates for use and, if necessary, change the active contract for each charging process. By keeping the certificates in the vehicle, there is no need to download them again when changing.Certificates can be uploaded to the installation via vehicle telematics, making the installation independent of a charging station.
[0011] A first aspect of the present disclosure relates to a charging control unit for a vehicle. The charging control unit comprises at least one interface for communicating with a charging infrastructure. The charging control unit comprises a cryptographically secured element. The charging control unit comprises a control circuit configured to receive a plurality of cryptographically secured charging contracts. The control circuit is configured to store the plurality of charging contracts in the cryptographically secured element. The control circuit is configured to store a selection of one of the plurality of charging contracts. The control circuit is configured to authenticate the charging control unit to the charging infrastructure based on the selected charging contract. This supports the use of multiple charging contracts while maintaining compatibility with existing charging infrastructure.
[0012] In some examples, the at least one interface comprises an interface for communication with a user interface controller of the vehicle. The control circuit can be configured to determine metadata about the plurality of cryptographically secured charging contracts and to provide the metadata to the user interface controller of the vehicle. This enables the display of the available charging contracts and the selection of a charging contract by the driver via the user interface controller. For example, the control circuit can be configured to receive a control signal for selecting a charging contract from the user interface controller and to store the selection based on the control signal. As a result, the selection made by the driver via the user interface controller can be stored and the associated charging contract can be used during the next charging process.
[0013] In addition to the possibility of obtaining charging contracts via the charging station, at least some examples of the present disclosure utilize the possibility of obtaining the charging contracts via a server. For example, the at least one interface can comprise an interface for communicating with a server. The control circuit can be configured to receive the plurality of cryptographically secured charging contracts from the server. This enables the charging contracts to be obtained independently of the charging infrastructure.
[0014] For example, charging contracts and communication with the charging infrastructure can be based on the ISO 15118 standard, and in particular ISO 15118-2. This enables the use of the charging infrastructure within the framework of the standard.
[0015] A further aspect relates to a corresponding method for the charging control unit of the vehicle. The method comprises obtaining the plurality of cryptographically secured charging contracts. The method comprises storing the plurality of charging contracts in the cryptographically secured element of the charging control unit. The method comprises storing the selection of one of the plurality of charging contracts. The method comprises authenticating the charging control unit to the charging infrastructure based on the selected charging contract. A further aspect relates to a corresponding program with program code for carrying out the method when the program code is executed on a computer, a processor, a control module, or a programmable hardware component, for example on the charging control unit.
[0016] Another aspect of the present disclosure relates to a user interface control device for a vehicle. The user interface control device comprises at least one interface for communicating with a charging control device of the vehicle and for communicating with a user interface, such as a user interface of the vehicle or a mobile device of a driver of the vehicle. The user interface control device comprises a control circuit configured to receive metadata about a plurality of charging contracts, which are stored in a cryptographically secured element of the charging control device, from the charging control device. The control circuit is configured to display the plurality of charging contracts via the user interface. The control circuit is configured to provide a selection functionality for selecting a charging contract from the plurality of charging contracts via the user interface.The control circuit is configured to provide a control signal for selecting a charging contract for the charging controller based on the selection of the charging contract. This enables the display of available charging contracts and the selection of a charging contract by the driver via the user interface controller.
[0017] For example, the control circuit can be configured to activate or offer the display of the plurality of charging contracts when the vehicle is located at a charging infrastructure. This can alert the driver that there is a choice between different charging contracts. For example, the driver near a P&C-enabled charging station can be notified of the use of P&C on the screen displayed when the vehicle is parked and given the option to jump directly to the selection screen.
[0018] In some examples, the control circuit can be configured to automatically preselect a charging contract based on the charging infrastructure and display the preselection along with the majority of charging contracts. This enables the use of a charging contract that is particularly advantageous for the respective charging infrastructure, for example, in terms of price. Multiple certificates on the vehicle allow for automated contract selection, for example, by selecting the cheapest contract at the respective charging station.
[0019] A further aspect relates to a corresponding method for the user interface controller. The method comprises obtaining the metadata about the plurality of charging contracts stored in the cryptographically secured element of the charging controller from the charging controller. The method comprises displaying the plurality of charging contracts via the user interface of the vehicle. The method comprises providing the selection functionality for selecting a charging contract from the plurality of charging contracts via the user interface. The method comprises providing the control signal for selecting a charging contract for the charging controller based on the selection of the charging contract.Another aspect relates to a program having program code for performing the method when the program code is executed on a computer, a processor, a control module, or a programmable hardware component, such as the user interface controller.
[0020] Another aspect of the present disclosure relates to a vehicle comprising the charging controller and the user interface controller.
[0021] Short character description
[0022] Some examples of devices and / or methods are explained in more detail below with reference to the accompanying figures. They show:
[0023] Fig. 1a shows a schematic diagram of a charging control device;
[0024] Fig. 1b shows a flowchart of a method for a charging control device;
[0025] Fig. 2a shows a schematic diagram of a user interface controller;
[0026] Fig. 2b shows a flowchart of a method for a user interface controller;
[0027] Fig. 3 shows a schematic diagram of a customer perspective on Plug & Charge;
[0028] Fig. 4 shows a schematic diagram of a technical perspective on Plug & Charge;
[0029] Fig. 5 shows a schematic diagram of a Plug and Charge process from the user perspective;
[0030] Fig. 6 shows a schematic representation of the activation and setting of the Plug & Charge function with multiple charging contracts;
[0031] Fig. 7 shows a simplified representation of the technical infrastructure for the use of Plug & Charge; and Figs. 8a and 8b show a menu navigation within the vehicle.
[0032] Description
[0033] Some examples will now be described in more detail with reference to the accompanying figures. However, other possible examples are not limited to the features of these detailed embodiments. These may include modifications of the features, as well as equivalents and alternatives to the features. Furthermore, the terminology used herein to describe specific examples is not intended to be limiting of other possible examples.
[0034] Throughout the description of the figures, identical or similar reference numerals refer to identical or similar elements or features, which may be implemented identically or in a modified form while providing the same or a similar function. Furthermore, the thickness of lines, layers, and / or regions in the figures may be exaggerated for clarity.
[0035] When two elements A and B are combined using "or," this is to be understood as disclosing all possible combinations, i.e., only A, only B, and both A and B, unless explicitly defined otherwise in the individual case. Alternative wording for the same combinations may be "at least one of A and B" or "A and / or B." This applies equivalently to combinations of more than two elements.
[0036] If a singular form is used, such as "a," "an," and "the," and the use of only a single element is neither explicitly nor implicitly defined as mandatory, further examples may also use multiple elements to implement the same function. If a function is described below as being implemented using multiple elements, further examples may implement the same function using a single element or a single processing entity.It is further understood that the terms "comprises", "comprising", "comprises" and / or "having" when used herein describe the presence of the specified features, integers, steps, operations, processes, elements, components and / or a group thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, processes, elements, components and / or a group thereof.
[0037] Fig. 1a shows a schematic diagram of a charging control unit 10 for a vehicle 100, wherein the charging control unit 10 is part of the vehicle 100. The charging control unit comprises at least one interface 12 for communication with a charging infrastructure 105 (such as a charging station), for example via power line communication. In some examples, the at least one interface 12 comprises an interface for communication with a user interface control unit 20 of the vehicle 100 and / or at least one interface for communication with a server (not shown), for example via a telematics connection / mobile radio connection. The charging control unit 10 comprises a cryptographically secured element 14, such as a so-called "secure element" or "trusted execution environment". The charging control unit 10 comprises a control circuit 16 coupled to the cryptographically secured element 14 and the at least one interface 12.For example, the cryptographically secured element can be part of the control circuit 16 or a separate component. The control circuit 16 is configured to receive a plurality of cryptographically secured charging contracts. The control circuit 16 is configured to store the plurality of charging contracts in the cryptographically secured element 14. The control circuit 16 is configured to store a selection of a charging contract from the plurality of charging contracts. The control circuit 16 is configured to authenticate the charging control device 10 to the charging infrastructure 105 based on the selected charging contract.
[0038] Fig. 1b shows a flowchart of a corresponding method for the charging control unit 16. The method includes obtaining 110 the plurality of cryptographically secured charging contracts. The method includes storing 120 the plurality of charging contracts in the cryptographically secured element 14 of the charging control unit 10. The method includes storing 130 the selection of a charging contract from the plurality of charging contracts. The method includes authenticating 140 the charging control unit to the charging infrastructure based on the selected charging contract.
[0039] The charging control unit, the corresponding method, and a corresponding computer program are described below with reference to the charging control unit. Features that can be described in connection with the charging control unit also apply to the corresponding method or computer program.
[0040] The proposed concept is based on the fact that not just one cryptographically secured charging contract (i.e., a cryptographically secured certificate of the charging contract, i.e., a contract with a mobility operator or charging infrastructure operator) is stored on the charging control unit in the cryptographically secured element 14 of the charging control unit, but several. For example, up to a predetermined number (e.g., up to 4, up to 5, up to 8) of charging contracts (i.e., the private keys of the corresponding certificates of the charging contracts) can be stored on the charging control unit. At least the private key of the respective certificate of the charging contract is stored within a storage device of the cryptographically secured element.Remaining components of the respective charging contract certificate can be stored, for example together with metadata, within the storage device of the cryptographically secured element or outside the cryptographically secured element, for example in a so-called NVRAM (non-volatile random access memory) of the charging control unit. The charging contracts can be obtained from a server, for example a server of the vehicle manufacturer, or from the charging infrastructure (via powerline communication). In other words, the control circuit can be configured to receive the plurality of cryptographically secured charging contracts from the server (for example via the user interface control unit) and / or from the charging infrastructure.
[0041] The cryptographically secured charging contract is based on a so-called provisioning certificate of the vehicle or the charging control unit. A private part of the provisioning certificate is stored in cryptographically secured element 14, and a public part of the provisioning certificate is made available to the other participants, for example, via one or more aggregators, as shown in Fig. 7. The public part can then be used to encrypt the cryptographically secured charging contracts or to restrict their use so that they can only be used using the private part of the provisioning certificate, with commissioning taking place within the cryptographically secured element.During the authentication of the charging controller, at least the certificate of the charging contract is used to cryptographically secure communication with the charging infrastructure 105 and to identify the charging controller to the charging infrastructure. The charging contracts and communication with the charging infrastructure can be based on the ISO 15118 standard, and in particular on the ISO 15118-2 standard.
[0042] Which of the charging contracts (i.e., which of the certificates) is used for this depends on the selection of the charging contract. A preselection can be made by default, for example, a selection of the first installed charging contract. This preselection can then be changed via the user interface device. For example, the control circuit can be configured to determine metadata about the plurality of cryptographically secured charging contracts and to provide the metadata to the user interface control device of the vehicle. This metadata can include, for example, an identifier of the charging contract, a validity period of the charging contract, and / or an operator who issued the charging contract. Based on this metadata, the driver of the vehicle can then be enabled to select a charging contract via the user interface control device.In response to the provided metadata, the control circuit can receive a control signal for selecting a charging contract from the user interface controller. This control signal can, for example, contain an indicator indicating which charging contract should be selected. The control circuit can be configured to store the selection based on the control signal. This can be done, for example, by storing a so-called pointer in a data structure, for example, within the cryptographically secured element with the aid of the cryptographically secured element or outside the cryptographically secured element.
[0043] The at least one interface 12 may, for example, correspond to one or more inputs and / or one or more outputs for receiving and / or transmitting information, for example in digital bit values, based on a code, within a module, between modules, or between modules of different entities.
[0044] In embodiments, the control circuit 16 can correspond to any controller or processor or a programmable hardware component. For example, the control circuit 16 can also be implemented as software programmed for a corresponding hardware component. In this respect, the control circuit 16 can be implemented as programmable hardware with appropriately adapted software. Any processors, such as digital signal processors (DSPs), can be used. Embodiments are not limited to a specific type of processor. Any processor or even multiple processors are conceivable for implementation. In some examples, the control circuit 16 can include the cryptographically secured element 14.
[0045] More details and aspects of the charging controller, the corresponding method, and the computer program are mentioned in connection with the concept or examples described below (e.g., Figs. 2 to 8b). The charging controller, the corresponding method, and the computer program may include one or more additional optional features corresponding to one or more aspects of the proposed concept or the described examples, as described before or after.
[0046] Fig. 2a shows a schematic diagram of a user interface controller 20 (also called a "head unit") for a vehicle. The user interface controller 20 comprises at least one interface 22 for communication with a charging controller 10 (shown in Fig. 1a) of the vehicle and for communication with a user interface, such as a touch-sensitive screen or a combination of screen and haptic input device, of the vehicle (not shown) or outside the vehicle (such as a user interface of a mobile device of a driver of the vehicle, via a mobile application). The user interface controller comprises a control circuit 24 coupled to the at least one interface 22.The control circuit 24 is configured to receive metadata about a plurality of charging contracts stored in a cryptographically secured element of the charging controller from the charging controller. The control circuit 24 is configured to display the plurality of charging contracts via the user interface. The control circuit 24 is configured to provide a selection functionality for selecting a charging contract from the plurality of charging contracts via the user interface. The control circuit 24 is configured to provide a control signal for selecting a charging contract for the charging controller based on the selection of the charging contract.
[0047] Fig. 2b shows a flowchart of a corresponding method for the user interface controller 24. The method includes obtaining 210 the metadata about the plurality of charging contracts stored in the cryptographically secured element of a charging controller from the charging controller. The method includes displaying 220 the plurality of charging contracts via the user interface. The method includes providing 230 the selection functionality for selecting a charging contract from the plurality of charging contracts via the user interface. The method includes providing 240 the control signal for selecting a charging contract for the charging controller based on the selection of the charging contract.
[0048] The user interface control device, the corresponding method, and a corresponding computer program are described below with reference to the user interface control device. Features that can be described in connection with the user interface control device also apply to the corresponding method or computer program.
[0049] In the proposed concept, the user interface controller is used to display and select existing contracts. This is shown, for example, in Fig. 6, where three charging contracts are displayed (DE123456789, DE987654321, and DE555555555), two of which are already installed and one (DE555555555) is available for download. Consequently, the control circuit can be configured to display, in addition to the plurality of charging contracts stored in a cryptographically secured element of the charging controller, one or more charging contracts available for download (e.g., from a vehicle manufacturer's server) and to retrieve corresponding information from a server (e.g., by querying the identifiers of new contract certificates, as shown in Fig. 7, where the user interface controller 710 and the server 740 are shown).The charging contracts available on the charging controller can be displayed based on the metadata that the user interface controller receives from the charging controller. The control circuit can also retrieve additional information about these charging contracts from the server (740 in Fig. 7), as shown in Fig. 7, for example, based on the identifiers of the charging contracts. This additional information can include information about the prices of charging sessions, staggered by time, by charging station provider, etc., information about the contracting party of the charging contract, etc.
[0050] The charging contracts (already installed and, if applicable, available) are displayed via the user interface. An input modality of the user interface (such as a touchscreen or a haptic input device) can be used to provide the selection functionality in conjunction with the control circuit. For example, the selection functionality can be provided such that the driver can make the selection by tapping or selecting a menu item via the haptic input device. If the user selects a charging contract that is not available on the charging control unit, the control circuit can be configured to retrieve the charging contract from the server as a cryptographically secured charging contract and forward it to the charging control unit.
[0051] Various measures can be taken to support the selection of the charging contract. For example, the control circuit can be designed to activate or offer the display of the plurality of charging contracts (e.g. by request or indication on a screen displayed when the driver parks the vehicle) when the vehicle is located at a charging infrastructure. For this purpose, the control circuit can be designed, for example, to recognize that the vehicle is located at a charging infrastructure based on a map with positions of charging infrastructure and based on the position of the vehicle. Alternatively or additionally, the control circuit can be designed to recognize that the vehicle is located at a charging infrastructure based on a short-range radio signal emitted by the charging infrastructure.
[0052] But the actual selection can also be supported. For example, the control circuit can be configured to automatically preselect a charging contract based on the charging infrastructure and display the preselection along with the majority of charging contracts. Various criteria can be taken into account during the preselection, such as the operator of the charging infrastructure, the expected price of the respective charging contracts at the charging infrastructure, whether the trip is private or business, etc.
[0053] Once the selection is made (or a selection is made that differs from the previously selected selection), the control signal for selecting the charging contract is provided to the charging controller. If a charging contract that has not yet been installed is selected, the control signal can also include the charging contract and / or an instruction to install and select the charging contract.
[0054] The at least one interface 22 may, for example, correspond to one or more inputs and / or one or more outputs for receiving and / or transmitting information, for example in digital bit values, based on a code, within a module, between modules, or between modules of different entities.
[0055] In exemplary embodiments, the control circuit 24 can correspond to any controller or processor or a programmable hardware component. For example, the control circuit 24 can also be implemented as software programmed for a corresponding hardware component. In this respect, the control circuit 24 can be implemented as programmable hardware with appropriately adapted software. Any processors, such as digital signal processors (DSPs), can be used. Exemplary embodiments are not limited to a specific type of processor. Any processor or even multiple processors are conceivable for implementation.
[0056] More details and aspects of the user interface controller, the corresponding method, and the computer program are mentioned in connection with the concept or examples described below (e.g., Figs. 1a to 1b, 3 to 8b). The user interface controller, the corresponding method, and the computer program may include one or more additional optional features corresponding to one or more aspects of the proposed concept or the described examples, as described before or after.
[0057] This disclosure relates to the use of multiple contracts (i.e., contracts) in the use of charging infrastructure, such as the “Plug & Charge” charging standard for electric vehicles.
[0058] Plug & Charge enables electric vehicle (BEV and PHEV) drivers to automatically authenticate themselves at public charging stations simply by plugging in the charging cable. The feature is based on the ISO 15118 standard: charging stations, vehicles, and charging contracts that support this standard can offer Plug & Charge. The list of vehicles, charging station operators, and contract providers that support Plug & Charge is growing.
[0059] In a simplified representation, Plug & Charge comprises three components. First, Plug & Charge comprises a private contract in which the contract provider asks the customer for a specific vehicle identification number (e.g., the vehicle-specific so-called PCID, Provisioning Certificate ID, which can be identical to the VIN, Vehicle Identification Number) in order to create a digital contract certificate in a backend system. This is followed by downloading and activating the contract. The customer can then download the charging contract certificate to the vehicle with the corresponding identification number in the vehicle user interface. The vehicle can then be charged using Plug & Charge. The next time the vehicle is plugged into a compatible charging station, the vehicle transmits the contract certificate via so-called powerline communication (i.e.Communication via the charging cable) to the station. The charging station can now check the contract ID for charging.
[0060] According to the present disclosure, vehicles may offer the ability to manage more than one contract: The customer can load multiple contracts onto the vehicle. One contract is selected in the user interface as the active contract for subsequent loading sessions.
[0061] Plug & Charge enables a fully automated and secure charging experience through EV-to-charging station authentication technology (according to ISO 15118). Fig. 3 shows a schematic diagram of a customer perspective on Plug & Charge. Without Plug & Charge, the charging process includes "plugging in," "manually authenticating" (e.g., via a smart card or mobile application), "waiting for charging indicator," and "locking and leaving the car." With Plug & Charge, the second step, "manually authenticating," is no longer necessary.
[0062] Fig. 4 shows a schematic diagram of a technical perspective on Plug & Charge. First (1.), the vehicle manufacturer (depicted as an OEM in Fig. 4) provides a provisioning certificate to an aggregator. Then, the vehicle user concludes a charging contract with the mobility operator (MO). As part of concluding the charging contract, the vehicle user provides the vehicle identification number (e.g., the PCID), which can be done, for example, by the vehicle manufacturer. The mobility operator creates a contract certificate (3.) for the specified vehicle identification number, which is also provided to the aggregator. The aggregator notifies the OEM (4.) that it has received a contract certificate and optionally forwards it to them (or the contract certificate is retrieved from the OEM as needed). The customer instructs the vehicle manufacturer, and in particular the vehicle, to download and install the contract certificate (5.).During the charging process, (6) the vehicle manufacturer or the vehicle communicates via ISO 15118 with the charging point operator (CPO), which in turn can contact the mobility operator via the aggregator and / or a roaming platform regarding payment for the charging process.
[0063] Charging via Plug & Charge and similar protocols offers the advantage that RFID (radio frequency identification) cards and mobile devices are not required for the charging process. Handling the EVSE ID (electric vehicle supply facility identifier) or a QR code (quick response code) is also not required. Likewise, the use of a smartphone app to initiate the charging process, which is sometimes common today, is no longer necessary. Managing multiple contracts allows the use of the same, and thus the use of different contracts (e.g., through the vehicle manufacturer or other mobility operators).
[0064] Fig. 5 shows a schematic diagram of a Plug and Charge process from the user's perspective. It distinguishes between the sections "Setting" (or setup), "Search and find", "Charging session", "Paying", and "Resetting". The "Setting" section includes logging into the charging contract and activating Plug and Charge using a mobile device, and activating and setting the function in the vehicle. The "Search and find" section includes searching for a charging station, parking and exiting, plugging in the charging connector (no manual authentication required), waiting for the charging indicator, locking and leaving the car, and unplugging the charging connector. The "Paying" section includes providing payment and charging history information on a mobile device. The "Resetting" section involves resetting the vehicle. Once the function is set up, the customer does not need to perform any authentication activity.The configuration is integrated into existing elements: contract management, charging menu and reset to factory settings.
[0065] Setting up the system includes, for example, a Plug & Charge registration process. This can involve logging into the vehicle manufacturer's user interface (e.g., via an internet browser) to log in and activate the Plug & Charge option. There, the Plug & Charge settings can be accessed via vehicle management, for example, and Plug & Charge can be activated. Furthermore, a contract can be selected to activate Plug & Charge. For example, all Plug & Charge-enabled electric vehicles (BEV and PHEV) can receive a vehicle manufacturer-based charging contract with Plug & Charge functionality. A simple check of the vehicle identification number allows the user to check whether the vehicle is Plug & Charge-enabled. The vehicle manufacturer-based charging contract can be activated for the Plug & Charge functionality once the vehicle is enabled.
[0066] Fig. 6 shows a schematic representation of the activation and configuration of the Plug & Charge function with multiple charging contracts, and in particular the charging contract activation in the vehicle. Fig. 6 shows three screens that emerge from one another. The top screen shows the main Plug & Charge contract selection screen. This includes a switch for activating Plug & Charge and a display of the available charging contracts, along with an indicator showing which charging contract is currently selected. For example, the user interface shows a list of all available contracts (e.g., from the vehicle manufacturer or other sources). In this case, two installed charging contracts are displayed, of which the top one is selected, and one charging contract that is ready for installation. In the middle, a context menu is also shown, which is called up when one of the charging contracts is tapped.This shows an identification number for the charging contract as well as buttons for accessing further screens. The buttons include Contract Details, Activate Contract, Download Contract (grayed out because the selected contract is already selected), and Delete Contract. Below is a screen displaying the contract details. This includes a button for deleting the contract, as well as an information display with the identification number of the charging contract, information about the contract's expiration date, and information about whether a cost estimate is available for the contract. The user interface enables user-specific installation, activation, selection, and configuration of charging contracts. For example, a distinction can be made between primary and secondary users. The installation, selection, and configuration of multiple Plug & Charge contracts from the vehicle manufacturer or others is possible.
[0067] Plug & Charge is offered via so-called aggregators, whereby the aggregators ensure that one contract can be used in multiple countries, or multiple contracts can be used per country. In China, a similar approach is pursued with Easy Charge. The present invention is adapted to also be used with Easy Charge. Fig. 7 shows a simplified representation of the technical infrastructure for using Plug & Charge. Fig. 7 shows a charging control unit 710, which can correspond to the charging control unit 10 of Fig. 1a, a user interface control unit 720, which can correspond to the user interface control unit 20 of Figs. 1a and 1b, an intermediary 730 (which can be used in the vehicle or during vehicle production), a Plug & Charge coordinator 740 (on the part of the vehicle manufacturer), an aggregator 750, a mobility service provider 760, a charging station operator 770, and the charging station 780.The charging control unit 710 is configured for communication according to ISO 15118 and is responsible for certificate storage and handling (including diagnostic requests). The intermediary is the vehicle manufacturer's root certificate authority and provides commission certificates.
[0068] To install a new contract in the vehicle, and in particular in the charging control unit, the following steps can be performed. To enable the installation of charging contracts (or the corresponding certificates), a so-called commission certificate is required. In the present example, this is performed by the intermediary 740. The intermediary receives a certificate signing request (CSR) from the charging control unit and provides a private key of the certificate to the charging control unit 730 and a public key to the Plug & Charge coordinator 740. The coordinator publishes the commission certificate (i.e., its public key) to the aggregator 750. The commission certificate contains a cryptographically secured identification code for the vehicle (e.g., the chassis number).
[0069] When a customer signs a charging contract, they provide the vehicle's identification code to the mobility service provider 750 as part of the contract. The mobility service provider creates a new contract certificate. The contract certificate can then be encrypted using the commission certificate (i.e., the public key) so that it can only be decrypted by the vehicle's charging control unit. The appropriate commission certificate is determined using the identification code. The aggregator 750 receives the encrypted contract certificate and informs the Plug & Charge coordinator 740. The coordinator can then receive the contract certificate and provide it to the charging control unit, for example, via a telematics connection. Alternatively, the contract certificate can be exchanged via powerline communication between the charging station 780 and the charging control unit 710.If the charging controller has a corresponding contract certificate, it can identify itself via the contract certificate within the framework of a two-way TLS (Transport Layer Security) communication. The charging station identifies itself via a leaf certificate derived from a V2G (Vehicle-to-Grid) root certificate. Authorization of the charging session takes place between the charging station 780, the charging station operator 770, and the aggregator 750, whereby the charging station operator 770 can determine the mobility service provider 760 via the aggregator 750. Payment is then made, in accordance with the contract, to the mobility service provider 760 via an e-mobility identifier.
[0070] The user interface control unit comprises a system for a graphical user interface, which can be based, for example, on a graphical operating system for mobile devices and can enable on-board user guidance, vehicle configuration, and Plug & Charge functionality, as well as the actual control unit functionality. The latter communicates with the charging control unit 710 and receives information about certificates stored there from the charging control unit 710. The system for the graphical user interface can then provide an option to select one of the stored certificates, with the selection being communicated to the charging control unit. The user interface control unit 720 also requests identifiers of new contract certificates (and V2G root certificates) from the Plug & Charge coordinator 740 in order to be able to offer the installation of the contract certificates.If the installation is initiated, the user interface control unit 720 requests the relevant certificates for installation from the Plug & Charge coordinator. These certificates are then forwarded to the charging control unit. For communication between the user interface control unit 720 and the charging control unit 710, diagnostic communication and / or status / configuration communication can be used, for example.
[0071] In many cases, the driver will select a charging contract via the vehicle's user interface. Alternatively, or in addition, this selection is also possible via a mobile application from the vehicle manufacturer. This can be used as an alternative to the vehicle's user interface to perform configuration and provide notifications.
[0072] Figures 8a and 8b show menu navigation within the vehicle. Figure 8a shows the case where Plug & Charge is not supported. In this case, the charging costs are displayed under the "Charging" item in the menu structure. A contract can be selected to estimate the charging costs. This corresponds, for example, to the status quo. Figure 8b shows the case where Plug & Charge is activated. In this case, the "Plug & Charge" item is displayed under the "Charging" item in the menu structure, with the option to select a Plug & Charge contract. This contract is then used to charge the vehicle.
[0073] In the present invention, the charger (i.e. the charging control unit) and the user interface control unit (head unit) basically exchange the following information. The charging control unit provides the user interface control unit with metadata of the installed contracts and information about which contract is currently active. The user interface control unit provides the charging control unit with information about which contract should be activated. Only the activated contract is transmitted for authentication when plugged into the charging station. The active contract can be selected using various mechanisms via the user interface / user interface control unit. This can, for example, be done manually via user input, whereby the input is saved. When parking the vehicle at a Plug & Charge charging station, the user interface can inform the user about the option of selecting a contract.The selection can, for example, be partially automated using rules defined by the user, such as location / GPS (Global Positioning System)-based or dependent on the operator of the charging station, or fully automated, for example in which the user interface control unit uses a database to determine which installed contracts are compatible with the corresponding charging station (roaming) or which contract is the cheapest when the vehicle is parked.
[0074] The aspects and features described in connection with a particular one of the previous examples may also be combined with one or more of the further examples to replace an identical or similar feature of that further example or to additionally introduce the feature into the further example.
[0075] Examples may further be or relate to a (computer) program with program code for carrying out one or more of the above methods when the program is executed on a computer, a processor, or other programmable hardware component. Steps, operations, or processes of various of the methods described above may therefore also be carried out by programmed computers, processors, or other programmable hardware components. Examples may also cover program storage devices, e.g., digital data storage media, that are machine-, processor-, or computer-readable and encode or contain machine-executable, processor-executable, or computer-executable programs and instructions. The program storage devices may, for example,Digital storage, magnetic storage media such as magnetic disks and magnetic tapes, hard disk drives or optically readable digital data storage media may include or be computers, processors, control units, field-programmable logic arrays ((F)PLAs = (Field) Programmable Logic Arrays), field-programmable gate arrays ((F)PGA = (Field) Programmable Gate Arrays), graphics processors (GPU = Graphics Processor Unit), application-specific integrated circuits (ASIC = application-specific integrated circuit), integrated circuits (IC = Integrated Circuit) or one-chip systems (SoC = System-on-a-Chip) programmed to carry out the steps of the methods described above.
[0076] It is further understood that the disclosure of multiple steps, processes, operations, or functions disclosed in the specification or claims should not be construed as necessarily being in the described order, unless explicitly stated in the individual case or technically required. Therefore, the foregoing description does not limit the performance of multiple steps or functions to any particular order. Furthermore, in further examples, a single step, function, process, or operation may include and / or be broken down into multiple sub-steps, functions, processes, or operations.
[0077] Where some aspects in the preceding sections have been described in the context of a device or system, these aspects are also to be understood as a description of the corresponding method. For example, a block, device, or functional aspect of the device or system may correspond to a feature, such as a method step, of the corresponding method. Accordingly, aspects described in the context of a method are also to be understood as a description of a corresponding block, element, property, or functional feature of a corresponding device or system. The following claims are hereby incorporated into the Detailed Description, and each claim may stand on its own as a separate example.It should also be noted that, although a dependent claim refers to a particular combination with one or more other claims in the claims, other examples may also include a combination of the dependent claim with the subject matter of any other dependent or independent claim. Such combinations are hereby explicitly suggested unless it is stated in the individual case that a particular combination is not intended. Furthermore, features of a claim for any other independent claim are also intended to be included, even if that claim is not directly defined as dependent on that other independent claim.
Claims
Patent claims 1. A charging control device for a vehicle, the charging control device comprising: at least one interface for communication with a charging infrastructure; a cryptographically secured element; and a control circuit designed to: Obtaining multiple cryptographically secured charging contracts, Storing the plurality of charging contracts in the cryptographically secured element, storing a selection of a charging contract from the plurality of charging contracts, and authenticating the charging controller to the charging infrastructure based on the selected charging contract.
2. The charging control device according to claim 1, wherein the at least one interface comprises an interface for communication with a user interface control device of the vehicle, wherein the control circuit is configured to determine metadata about the plurality of cryptographically secured charging contracts, and to provide the metadata to the user interface control device of the vehicle.
3. The charging controller according to claim 2, wherein the control circuit is configured to receive a control signal for selecting a charging contract from the user interface controller, and to store the selection based on the control signal.
4. The charging control device according to one of claims 1 to 3, wherein the at least one interface comprises an interface for communication with a server, wherein the control circuit is configured to receive the plurality of cryptographically secured charging contracts from the server.
5. The charging control device according to one of claims 1 to 4, wherein the charging contracts and communication with the charging infrastructure are based on the ISO 15118 standard.
6. A user interface control device for a vehicle, comprising: at least one interface for communication with a charging control unit of the vehicle and for communication with a user interface; a control circuit designed to: Obtaining metadata about a plurality of charging contracts stored in a cryptographically secured element of the charging controller from the charging controller; Displaying the majority of charging contracts via the user interface; Providing a selection functionality for selecting a charging contract from the plurality of charging contracts via the user interface; and Providing a control signal for selecting a charging contract for the charging controller based on the selection of the charging contract.
7. The user interface controller according to claim 6, wherein the control circuit is configured to activate or offer the display of the plurality of charging contracts when the vehicle is located at a charging infrastructure.
8. The user interface control device according to claim 7, wherein the control circuit is configured to automatically preselect a charging contract depending on the charging infrastructure and to display the preselection together with the plurality of charging contracts.
9. A vehicle comprising the charging controller according to any one of claims 1 to 5 and the user interface controller according to any one of claims 6 to 8.
10. A method for a charging controller of a vehicle, the method comprising: obtaining a plurality of cryptographically secured charging contracts; Storing the multiple charging contracts in a cryptographically secured element of the charging control unit; Storing a selection of a charging contract from the plurality of charging contracts; and authenticating the charging controller to the charging infrastructure based on the selected charging contract.
11. A method for a user interface controller for a vehicle, comprising: Obtaining metadata about a plurality of charging contracts stored in a cryptographically secured element of a charging controller from the charging controller; Displaying the plurality of charging contracts via a user interface; Providing a selection functionality for selecting a charging contract from the majority of charging contracts via the user interface; and Providing a control signal for selecting a charging contract for the charging control unit based on the selection of the charging contract.
12. A program comprising program code for performing the method according to claim 10 or the method of claim 11, when the program code is executed on a computer, a processor, a control module, or a programmable hardware component.