Charging controller, program, and method for controlling charging
The charging control device addresses the challenge of certificate updates by managing private keys in separate memory areas, ensuring continuous charging and authentication during the update process.
Patent Information
- Application Number
- JP2023212694
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-18
- Publication Date
- 2025-06-30
AI Technical Summary
Existing charging control systems for electric vehicles do not adequately manage certificate updates, leading to potential loss of private keys and authentication failures when new certificates are installed.
A charging control device with a controller that stores the first private key in one memory area and generates a second private key in a different area, allowing both keys to be valid sequentially during the certificate update process.
Ensures continuous charging capability using the existing certificate and private key until the new certificate is fully installed, preventing authentication failures and maintaining system stability during updates.
Smart Images

Figure 2025096784000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a charging control device, a program, and a charging control method.
Background Art
[0002] As vehicles (also referred to as electric vehicles) that can be charged from an external power source to a driving battery, battery electric vehicles (BEV vehicles), plug-in hybrids (PHV) vehicles, etc. are known. Also, as an authentication method for charging the driving battery, mainly an external authentication method (EIM (External Identification Means)) and Plug and Charge (PnC) have been proposed.
[0003] In charging by PnC, a certificate is stored in the vehicle, and when connected to a charging facility (also referred to as a stand), authentication is performed by transmitting the stored certificate and a signature generated with the private key corresponding to the certificate from the vehicle to the charging facility. When the authentication is successful, charging is started. By the way, when such a certificate is issued, for example, the in-vehicle computer generates an in-vehicle computer public key and an in-vehicle computer private key that forms a pair with the in-vehicle computer public key, and transmits a certificate issuance request for the in-vehicle computer public key to a certification authority. Then, the certification authority receives the certificate issuance request transmitted by the in-vehicle computer, signs the in-vehicle computer public key included in the certificate issuance request, and issues a certificate to the in-vehicle computer. In this way, the in-vehicle computer acquires the certificate issued by the certification authority in response to the certificate issuance request (for example, see Patent Document 1 below).
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the above conventional technology, no consideration is given to the case where the issued certificate is updated. For example, when a once-issued certificate is updated with a new certificate, if a new private key is generated on the vehicle side, the private key for the currently available certificate may be overwritten. Therefore, the private key corresponding to the currently available certificate may be lost, and there may be a case where the vehicle cannot receive authentication by signature until the new certificate for update is installed in the vehicle. An aspect of the disclosed embodiment is to provide a device or the like that can continue to receive charging using a certificate even when a new certificate is installed in a vehicle in which a certificate has already been installed.
Means for Solving the Problems
[0006] One aspect of the disclosed embodiment is exemplified by a charging control device having a controller that performs charging control with a charging facility based on a certificate. This controller stores the first private key corresponding to the installed first certificate in the first area of the memory. Then, this controller generates a second private key and a public key in response to a request from the certificate issuer. Further, this controller stores the second private key in a second area different from the first area of the memory, transmits the public key to the issuer, and installs the second certificate issued thereby. And this controller makes the first private key valid until the installation of the second certificate is completed, and makes the second private key valid when the installation of the second certificate is completed.
Advantages of the Invention
[0007] This charging control device stores, by the above controller, the first private key for the currently valid first certificate and the second private key for the newly issued second certificate based on the issuer's request in different storage locations respectively. Therefore, the newly generated second private key does not overwrite the currently valid first private key. For this reason, the controller can enable the first private key until the installation of the second certificate is completed. And the controller enables the second private key when the installation of the second certificate is completed. In this way, even when installing a new second certificate in a vehicle in which the first certificate has already been installed, this charging control device can continue to use the charging using the first certificate and the first private key corresponding thereto. And this charging control device can immediately shift to the processing using the second certificate and the second private key corresponding thereto by the completion of the installation of the second certificate. That is, this charging control device can be controlled so that even when installing a new certificate in a vehicle in which a certificate has already been installed, it can continue to receive charging using the certificate.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Embodiments for Carrying Out the Invention
[0009] Hereinafter, the charging control device 10 and the computer program (hereinafter simply referred to as the program) will be described.
[0010] <First Embodiment> With reference to FIGS. 1 to 5, the charging control device 10, the program, and the charging control method according to the first embodiment will be described.
[0011] (Configuration) FIG. 1 is a diagram illustrating a vehicle 1 equipped with the charging control device 10 of the present embodiment. In FIG. 1, a charging facility (Electric Vehicle Supply Equipment, EVSE) 2 that supplies power to the battery 19 (see FIG. 2, also referred to as a secondary battery or a storage battery) of the vehicle 1, the vehicle 1, or a charging MO server 5 that exchanges information with the charging facility 2, and an OEM (Original Equipment Manufacturer) server 6 are also shown.
[0012] The vehicle 1 is called an electric vehicle and can be charged with the traveling battery 19. The vehicle 1 has a charging control device 10 and executes a charging process or charging control with the charging facility 2. In the charging process or the like, as the first authentication procedure PnC, the charging control device 10 of the vehicle 1 creates, for example, a signature based on a Contract certificate or the like and a cryptographic key, and the charging facility 2 verifies this. When the authentication is successful, the vehicle 1 executes charging with the charging facility 2. The procedure by such PnC is activated, for example, when the plug 2B for supplying power from the charging facility 2 is connected to the power receiving unit of the vehicle 1.
[0013] In addition, in the charging of the vehicle 1, in addition to the procedure by PnC as described above, as a second authentication procedure, a procedure of an external authentication method (EIM) by presenting an RFID card or the like is also possible. For this reason, the charging facility 2 has an EIM reader 2A. The external authentication method is, for example, an authentication method based on user information obtained from a credit card, a QR code (registered trademark), RFID (Radio Frequency Identification), etc. via the EIM reader 2A.
[0014] Further, the charge control device 10 can be connected to the MO server 5, the OEM server 6, etc. via the network N1. The network N1 includes, for example, wireless networks such as Long Term Evolution (LTE), 5th Generation Mobile Communication System (5G), 6th Generation Mobile Communication System (6G), and wired public networks such as the Internet. It includes work.
[0015] The charging facility 2 may, for example, transfer the signature transmitted from the vehicle 1 to the MO server 5 and request authentication of the user of the vehicle 1. Then, when the authentication at the MO server 5 is successful, the charging facility 2 may charge the battery 19 of the vehicle 1 and charge the user of the vehicle 1. Further, when receiving charging, the vehicle 1 can also request installation of a Contract certificate or the like from the charging facility 2. In this case, the vehicle 1 presents a certificate (such as an OEM provisioning certificate) issued by the OEM, which is the manufacturer and seller of the vehicle 1, to the charging facility 2. When the charging facility 2 has a valid Contract certificate or the like associated with the OEM provisioning certificate or the like notified from the vehicle 1, it can provide the Contract certificate or the like to the vehicle 1. Further, the charging facility 2 may access the MO server 5 to obtain a valid Contract certificate or the like corresponding to the OEM provisioning certificate and install it in the vehicle 1.
[0016] As described above, a certificate (such as an OEM Provisioning certificate or a Vehicle certificate) issued by an OEM, which is the manufacturer and seller of the vehicle 1, is installed in the memory 12 (Fig. 2) of the charging control device 10 of the vehicle 1. Also, the user of the vehicle 1 concludes a contract with a service provider (MO) in advance in order to charge the battery 19 of the vehicle 1 at the charging facility 2. By this contract, a Contract certificate etc. and a cryptographic key such as a private key are issued from the MO server 5 and installed in the vehicle 1 via, for example, the OEM server 6. The Contract certificate etc. and the cryptographic key can also be referred to as certificate data. Note that the certificate data such as the Contract certificate may be installed in the vehicle 1 via the charging facility 2 in some cases. Hereinafter, the OEM Provisioning certificate, the Vehicle certificate, the Contract certificate etc. are collectively referred to as a certificate. The certificate is electronic data installed in the vehicle 1 and is issued by an external computer such as a certification authority, the MO server 5, the OEM server 6, etc. to the charging control device 10 of the vehicle 1. Here, the certification authority refers to an organization having the authority to issue a certificate to a company, an organization, an individual, etc. Among the certification authorities, there is one called a root certification authority whose reliability is ensured by being audited, which is an organization independent of companies, organizations such as OEMs, or individuals, etc.
[0017] As described above, the OEM Provisioning certificate, the Vehicle certificate, the Contract certificate etc. are collectively referred to as a certificate. The charging control device 10 can create an electronic signature (digital signature) for data based on the certificate etc. with the private key corresponding to the certificate and request authentication from an external computer such as the charging facility 2, the MO server 5, the OEM server 6, the certification authority, etc. In this embodiment, the electronic signature is simply called a signature. The external computers such as the charging facility 2, the MO server 5, the OEM server 6, the certification authority, etc. have a public key paired with the private key and can determine the validity of the authentication by decrypting the signature. This private key and public key can be regarded as an example of paired key information.
[0018] The charging control device 10 can create an electronic signature (digital signature) for data based on the certificate etc. with the private key corresponding to the certificate and request authentication from an external computer such as the charging facility 2, the MO server 5, the OEM server 6, the certification authority, etc. In this embodiment, the electronic signature is simply called a signature. The external computers such as the charging facility 2, the MO server 5, the OEM server 6, the certification authority, etc. have a public key paired with the private key and can determine the validity of the authentication by decrypting the signature. This private key and public key can be regarded as an example of paired key information. The external computers such as the charging facility 2, the MO server 5, the OEM server 6, the certification authority, etc. have a public key paired with the private key and can determine the validity of the authentication by decrypting the signature. This private key and public key can be regarded as an example of paired key information.
[0019] More specifically, the vehicle 1 is connected to the charging facility 2, and a signature based on certificates (C) such as an OEM Provisioning certificate and a Vehicle certificate issued from the OEM server 6 and a private key (KS) is presented from the vehicle 1 to the charging facility 2. Then, the charging facility 2 verifies the signature using the public key of the issuing certificate of each certificate. Also, revocation verification may be performed using OCSP, CRL, or the like.
[0020] The issuing certificate may be distributed and stored in a storage device accessible from the charging facility 2. The storage device accessible from the charging facility 2 is, for example, a storage device such as the memory 22 of the charging facility 2, an external storage unit 23, or a computer accessible by the charging facility 2 on the network N1.
[0021] In the present embodiment, an external computer that installs a certificate in the vehicle 1 via the network N1 is called an issuer. However, for example, when a Contract certificate is issued from the MO server 5 and installed in the vehicle 1 via the OEM server 6, both the MO server 5 and the OEM server 6 can be called issuers. Also, for example, when a Contract certificate is issued from the MO server 5 and installed in the vehicle 1 via the charging facility 2, the MO server 5 can be called the issuer.
[0022] In the present embodiment, in the charge control device 10 in which the certificate C1 and the private key KS1 corresponding to the certificate C1 have already been installed, a process of updating to a new certificate C2 and a private key KS2 corresponding to the certificate C2 is illustrated. That is, here, it is assumed that an update from the certificate C1 to the certificate C2 has occurred in an external computer such as the MO server 5, the OEM server 6, or a certification authority.
[0023] For example, in the OEM server 6, when an update of the certificate C1 occurs, the OEM server 6 sends a generation request for a CSR (Certificate Signing Request) to the charging control device 10 of the vehicle 1 where the certificate C1 has already been distributed (R1). Then, the charging control device 10 creates a pair of a public key KO2 and a private key KS2, and sends a CSR including the public key KO2 among the created pair to the OEM server 6 (R2). Then, the OEM server 6 creates a new certificate C2, for example, by signing the received public key KO2 with the private key it obtained from the certification authority. However, the OEM server 6 may transfer the CSR to the MO server 5, request the creation of a new certificate C2, and receive the certificate C2 from the MO server 5 (R4). Then, the OEM server 6 distributes the created certificate C2 to the charging control device 10 and installs it in the charging control device 10 to update from the certificate C1 to the certificate C2 (R3).
[0024] As a result, the private key KS1 is revised to the private key KS2. Thereafter, the charging control device 10 creates a signature with the updated certificate C2 and the private key KS2, and requests authentication from the charging facility 2 or the like. The charging facility 2, or the MO server 5, the OEM server 6, etc. to which the signature is transferred via the charging facility 2, determines the validity of the signature using the revised public key KO2, and decides whether to authenticate the charging control device 10 or not.
[0025] As described below, in this embodiment, the charging control device 10 updates the certificate C1 and the private key KS1 to a new certificate C2 and a private key KS2 while enabling the signature by the existing private key KS1. Therefore, in this embodiment, when the charging control device 10 receives charging from the charging facility 2 according to PnC, regardless of the update of the private key KS1 to KS2, it can stably receive charging from the charging facility 2.
[0026] Note that in this embodiment, an example of the update of a certificate (for example, an OEM Provisioning certificate, a Vehicle certificate) due to a generation request from the OEM server 6 is illustrated. However, the MO ser When updating the certificate (e.g., Contract certificate) due to the generation request from the MO server 5, the MO server 5 may similarly update the certificate of the charging control device 10 via the OEM server 6. That is, the OEM server 6 may receive the request from the MO server 5 and send a CSR generation request to the vehicle 1. Then, the OEM server 6 may transfer the CSR received from the charging control device 10 to the MO server 5 and request the issuance of the certificate. Further, the OEM server 6 may transfer the updated certificate issued from the MO server 5 to the charging control device 10. Figure 2 is a diagram illustrating the hardware configuration of the vehicle 1 and the charging facility 2. The charging control device 10 of the vehicle 1 and the charging facility 2 that charges the battery 19 mounted on the vehicle 1 constitute a charging system. The vehicle 1 has a charging control device 10 and a battery 19 whose charging is controlled by the charging control device 10.
[0027] The charging control device 10 has a CPU 11, a memory 12, and external devices connected to an external interface (I / F), and executes information processing by a program. Examples of the external devices include an external storage unit 13, a display unit 14, an operation unit 15, an external communication unit 16A, and a charging communication unit 16B. The CPU 11 and the memory 12 together can be called a control unit. The control unit is also called an Electronic Control Unit (ECU). The control unit is an example of a controller is.
[0028] The CPU 11 executes a computer program developed executable in the memory 12 and provides the functions of the charging control device 10. The CPU 11 is also called a processor or a MCU (Micro Controller Unit). The memory 12 stores the computer program executed by the CPU 11 and the data processed by the CPU 11, etc.
[0029] The memory 12 is a Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Read Only Memory (ROM), etc. The external storage unit 13 is used, for example, as a storage area that supplements the memory 12, and stores computer programs executed by the CPU 11, data processed by the CPU 11, etc. The external storage unit 13 is a hard disk drive, Solid State Drive (SSD), etc.
[0030] The display unit 14 is, for example, a liquid crystal display, an electroluminescence panel, etc. The operation unit 15 is, for example, a keyboard, a pointing device, etc. In the present embodiment, a touch panel having a touch sensor as a pointing device is exemplified. The display unit 14 and the operation unit 15 act as a user interface available to the user.
[0031] The external communication unit 16A exchanges data with other devices (such as the OEM server 6 in FIG. 1) on a public network such as the network N1 (see FIG. 1). For example, the CPU 11 communicates with a computer of a service provider on the public network through the external communication unit 16A. The external communication unit 16A may be a wireless communication device that accesses a mobile phone network. Also, the external communication unit 16A may be a communication device that accesses a wireless LAN (Local Area Network). The external communication unit 16A is called a TCU (Telematics Control Unit) and may execute communication called telematics via the network N1 as well.
[0032] The charging communication unit 16B transmits and receives signals to and from the charging communication unit 26B. That is, the charging communication unit 16B is based on, for example, PLC (Power Line Communications) with the charging facility 2 or execute communication using a communication method similar to that of a PLC. However, the charging communication unit 16B may communicate with the charging communication unit 26B using communication such as CAN (Controller Area Network), wireless LAN, Ethernet, etc., or a communication procedure based on these. Note that the charging communication unit 16B may have a CPU, a memory, an input / output interface, a communication interface, etc. inside. In the present embodiment, the charging control device 10 communicates with the charging facility 2 via the external communication unit 16A or the charging communication unit 16B, and executes a charging request and authentication process. Accordingly, it may execute communication using communication similar to CAN (Controller Area Network), wireless LAN, Ethernet, etc., or a communication procedure based on these. Note that the charging communication unit 16B may have a CPU, a memory, an input / output interface, a communication interface, etc. inside. In the present embodiment, the charging control device 10 communicates with the charging facility 2 via the external communication unit 16A or the charging communication unit 16B, and executes a charging request and authentication process.
[0033] The charging facility 2 includes a CPU 21, a memory 22, and external devices connected to an external interface (I / F), and executes information processing by a program. Examples of the external devices include an external storage unit 23, a display unit 24, an operation unit 25, an external communication unit 26A, a charging communication unit 26B, and an EIM reader 2A. Further, the charging facility 2 has a power supply circuit 29. Among the charging facility 2, the configurations other than the EIM reader 2A and the power supply circuit 29 are the same as those of the charging control device 10 of the vehicle 1, and thus the description thereof is omitted.
[0034] The EIM reader 2A is a card reader that reads information in contact or non-contact from an IC card such as a credit card, an image reader that reads a QR code (registered trademark), an RFID reader, etc. The power supply circuit 29 supplies power to the battery 19 and charges the battery 19. Note that in FIG. 2, both between the charging communication unit 16B and the charging communication unit 26B and between the battery 19 and the power supply circuit 29 are connected via the plug 2B of FIG. 1.
[0035] That is, when the charging control device 10 of the vehicle 1 and the charging facility 2 are connected to a connection part including the power receiving part of the power circuit in the vehicle 1 where the plug 2B charges the battery 19 and the terminals of the charging communication part 16B, they communicate with each other. The charging control device 10 of the vehicle 1 and the charging facility 2 communicate with each other, for example, through the charging communication parts 16B and 26B, and execute PnC through TLS authentication and Vehicle-to-Grid (V2G) communication. The charging control device 10 of the vehicle 1 and the charging facility 2 authenticate each other through TLS authentication and V2G communication, and execute charging of the battery 19 of the vehicle 1 and authentication processing for the charging. However, the charging control device 10 of the vehicle 1 and the charging facility 2 may communicate with each other via the external communication parts 16A and 26A when the plug 2B is connected to a connection part including the power receiving part of the power circuit in the vehicle 1 and the terminals of the charging communication part 16B.
[0036] The MO server 5 and the OEM server 6 have the same configuration as the CPU 11, 21, memory 12, 22, external storage part 13, 23, display part 14, 24, operation part 15, 25, external communication parts 16A, 26A, etc. The MO server 5 and the OEM server 6 are general computers. Note that the MO server 5 and the OEM server 6 may be a set of a plurality of computers called a cloud.
[0037] The MO server 5 can be said to be a computer of an operator (MO) that provides a charging service for the vehicle 1 to the user. Note that the charging facility 2 may be managed and operated by an operator called a CPO (Charge Point Operator) in addition to the MO. Also, the OEM server 6 can be said to be a computer of an operator related to the manufacture or sale of the vehicle 1.
[0038] (Certificate and Private Key Update Procedure) FIG. 3 is a diagram illustrating a secret key update procedure by the charging control device 10 in the present embodiment. In FIG. 3, the central arrow A illustrates the transition from the process with symbol R1 attached to the process with symbol R3 attached. In FIG. 3, the process with symbol R1 attached on the upper side with respect to arrow A corresponds to symbol R1 in FIG. 1. The process with symbol R1 attached is the process when the charging control device 10 receives a CSR generation request. In FIG. 3, the process with symbol R3 attached on the lower side with respect to arrow A corresponds to symbol R3 in FIG. 1. The process with symbol R3 attached is the process when the charging control device 10 installs the certificate C2 received from the OEM server 6 and stores it in the secure memory in the memory 12 or the external storage unit 13.
[0039] Here, for example, the charging control device 10 already stores the secret key KS1 corresponding to the certificate C1 in the slot SL1 in the secure memory in the memory 12 or the external storage unit 13. Also, it is registered in the register of the CPU 11 that the currently used slot is SL1. That is, the charging control device 10 stores the first secret key (secret key KS1) corresponding to the installed first certificate (certificate C1) in the first area (slot SL1) such as the memory 12. The certificate C1 is an example of the first certificate, the secret key KS1 is an example of the first secret key, and the slot SL1 is an example of the first area. Here, the secure memory is a storage device that checks the authenticity or legitimacy of access in response to an access request from the CPU 11 and permits access (reading, writing) when the authenticity or legitimacy can be confirmed. For example, the charging control device 10 requests an authenticity check by sending a signature signed with a specific cryptographic key to the secure memory. The slots SL1 and SL2 are storage destinations in the secure memory, for example, addresses, register numbers, etc.
[0040] In this state, for example, when a request to update the certificate C1 to a new certificate C2 occurs in the OEM server 6, a CSR generation request is sent from the OEM server 6 to the charge control device 10. When the charge control device 10 receives the CSR generation request, it creates a pair of public key KO2 and private key KS2, and requests the secure memory to store (also referred to as information generation) the private key KS2 in the slot SL2. Therefore, with the existing private key KS1 maintained in the slot SL1, a new private key KS2 is stored in the slot SL2. Then, the charge control device 10 generates a CSR including the public key KO2 and sends it to the OEM server 6 (R2 in FIG. 1).
[0041] Then, in the process indicated by the symbol R3 in the lower part, for example, the OEM server 6 creates a certificate C2 for the CSR and sends it to the charge control device 10. When the charge control device 10 receives the certificate C2, it changes the currently used slot to SL2 in the register and instructs the secure memory to delete (erase request) the private key KS1 in the slot SL1. As a result, the private key KS1 in the slot SL1 is deleted (or erased), and processes such as signature using the private key KS2 in the slot SL2 are executed. As described above, in this embodiment, the charge control device 10 manages one type of key stored in the secure memory using two slots. Therefore, when the number of key types to be managed is K types (K is an integer), the charge control device 10 may prepare 2*K slots.
[0042] Note that in FIG. 3, it has been described that the private keys KS1 and KS2 are stored in the slots SL1 and SL2 of the secure memory. However, the charge control device 10 may store a key pair, that is, a pair of the private key KS1 and the public key KO1, or a pair of the private key KS2 and the public key KO2, in the slots SL1 and SL2 of the secure memory. Also, when the private keys KS1 and KS2 are stored in the slots SL1 and SL2 of the secure memory, the public keys KO1 and KO2 may be stored in an area other than the secure memory of the memory 12. This is because compared with the private keys KS1 and KS2, there is less requirement or necessity to enhance the security of storing the public keys KO1 and KO2.
[0043] Hereinafter, the certificate C1, public key KO1, and private key KS1 may be referred to as the first certificate C1, the first public key KO1, and the first private key KS1. Also, the certificate C2, public key KO2, and private key KS2 may be referred to as the second certificate C2, the second public key KO2, and the second private key KS2.
[0044] FIG. 4 is a sequence diagram illustrating the processing at the time of certificate update in the first embodiment. In the example of FIG. 4, the case where a request for certificate update occurs in the OEM server 6 is illustrated. When a request for certificate update occurs in the OEM server 6, the OEM server 6 transmits a CSR generation request to the charge control device 10 of the vehicle 1 (P1). The CSR generation request in P1 is an example of a request from the certificate issuer. Also, the OEM server 6 is an example of the certificate issuer. In the example of FIG. 4, it is assumed that the CSR generation request is received by the charge control device 10 while the vehicle 1 is connected to the charging facility 2 by the plug 2B (see the dotted line frame in FIG. 1). Note that in the sequence diagram of FIG. 4, the vertical axis corresponds to the passage of time.
[0045] When the CSR generation request is received by the charge control device 10 while the vehicle 1 is connected to the charging facility 2, the charge control device 10 returns a response indicating that it does not respond to the CSR generation request (hereinafter referred to as a negative response) to the OEM server 6 (P2). The process of P2 is an example of rejecting the request from the OEM server 6, which is the issuer, when the charge control device 10 is connected to the charging facility 2. Then, the charge control device 10 executes the processing while connected to the charging facility 2, for example, the processing using the current private key KS1, or continues the processing being executed (P3). The processing using the current private key KS1 includes, for example, creating a signature and requesting the charging facility 2 to authenticate the signature. Also, for example, the charge control device 10 performs charge control with the charging facility 2 based on the valid private key KS1 and the certificate C1 corresponding to the valid private key KS1. Here, the current private key KS1 is stored in the slot SL1, and it is registered in the register of the charge control device 10 that the currently used slot is the slot SL1.
[0046] Therefore, the OEM server 6 resends the CSR generation request to the charging control device 10 of the vehicle 1 (P4). The CSR generation request at P4 is also an example of a request from the certificate issuer. When the charging control device 10 receives the CSR generation request again, the vehicle 1 is not connected to the charging facility 2. When the charging control device 10 receives the CSR generation request while the vehicle 1 is not connected to the charging facility 2, the charging control device 10 executes a key generation process (P5). The key generation process is, for example, as described in FIG. 3. Then, the charging control device 10 requests the secure memory to store a new secret key KS2 in the slot SL2 while maintaining the current secret key KS1 in the slot SL1. Therefore, it can be said that the charging control device 10 does not overwrite the secret key KS1 as the first secret key with the secret key KS2 as the second secret key.
[0047] The process of P5 is an example of generating a second secret key and a public key in response to a request from the certificate issuer. The secret key KS2 generated at P5 is an example of the second secret key. At this time, a public key KO2 is also generated as a pair with the secret key KS2. Further, storing the new secret key KS2 in the slot SL2 is an example of storing the second secret key in a second area different from the first area such as the memory 12. That is, the slot SL2 is an example of the second area. Further, maintaining the current secret key KS1 in the slot SL1 is an example of making the first secret key valid until the installation of the second certificate is completed. That is, until the second certificate (certificate C2) corresponding to the public key KO2 is installed, the charging control device 10 performs charging control with the charging facility 2 based on the valid secret key KS1 and the certificate C1 corresponding to the valid secret key KS1.
[0048] Then, the charging control device 10 transmits a CSR including the public key KO2 created as a pair with the private key KS2 to the OEM server 6 (P6). The process of P6 is an example of transmitting the public key to the issuer. When the OEM server 6 receives the CSR including the public key KO2 from the charging control device 10, it creates a certificate C2 based on the public key KO2 using the private key issued by the certification authority. Then, the OEM server 6 distributes the certificate C2 to the charging control device 10 (P7).
[0049] When the charging control device 10 receives the certificate C2, it registers in the register that the currently used slot is slot SL2, requests the secure memory to delete (also referred to as erase) the private key KS1 of slot SL1, and causes the deletion (erasure) to be executed (P8). In P8, receiving the certificate C2 and registering in the register that the currently used slot is slot SL2 is an example of installing the second certificate. In this way, in the charging control device 10, the OEM Provisioning certificate, the Vehicle certificate, etc., and the corresponding private keys, etc. are revised. Also, for example, the charging control device 10 performs charging control with the charging facility 2 based on the valid private key KS2 and the certificate C2 corresponding to the valid private key KS2. That is, when the installation of the second certificate (certificate C2) corresponding to the private key KS2 is completed, the charging control device 10 erases the private key KS1 as the first private key. Then, it performs charging control with the charging facility 2 based on the valid second private key (private key KS2) and the second certificate (certificate C2). Note that the procedure for revising the private key corresponding to the Contract certificate in the charging control device 10 is the same as the process of FIG. 4 except that both the OEM server 6 and the MO server 5 are involved. In the charging control device 10, the OEM Provisioning certificate, the Vehicle certificate, etc., and the corresponding private keys, etc. are revised. Also, for example, the charging control device 10 performs charging control with the charging facility 2 based on the valid private key KS2 and the certificate C2 corresponding to the valid private key KS2. That is, when the installation of the second certificate (certificate C2) corresponding to the private key KS2 is completed, the charging control device 10 erases the private key KS1 as the first private key. Then, it performs charging control with the charging facility 2 based on the valid second private key (private key KS2) and the second certificate (certificate C2). Note that the procedure for revising the private key corresponding to the Contract certificate in the charging control device 10 is the same as the process of FIG. 4 except that both the OEM server 6 and the MO server 5 are involved.
[0050] Also, in FIG. 4 as well, it was described that the secure memory slots SL1 and SL2 store the secret keys KS1 and KS2. However, the charge control device 10 may store a key pair, that is, a pair of the secret key KS1 and the public key KO1, or a pair of the secret key KS2 and the public key KO2, in the secure memory slots SL1 and SL2. However, when the secret keys KS1 and KS2 are stored in the secure memory slots SL1 and SL2, the public keys KO1 and KO2 may be stored in an area other than the secure memory of the memory 12 or the external storage unit 13.
[0051] FIG. 5 is a flowchart illustrating the update process of the certificate and the key pair by the charge control device 10 of the first embodiment. This process is started, for example, when the charge control device 10 receives a request from an external device, such as the OEM server 6 or the like, via the external communication unit 16A. At the time of this startup, it is assumed that the currently used secret key is the secret key KS1 and the certificate C1 is valid.
[0052] In the process of FIG. 5, the charge control device 10 determines whether the vehicle 1 is currently connected to the charging facility 2 (S1). Whether the vehicle 1 is connected to the charging facility 2 means, for example, a state in which the plug 2B (FIG. 1) of the charging facility 2 is connected to a connection portion including a power receiving portion and a communication terminal connected to the battery 19 of the vehicle 1. When the plug 2B of the charging facility 2 is connected to the connection portion of the vehicle 1, for example, the charging communication unit 26B (FIG. 2) transmits a pulse signal or the like defined by the specifications or standards of the device to the charging communication unit 16B. Therefore, the charge control device 10 can detect the connection to the charging facility 2 via the charging communication unit 16B.
[0053] If the vehicle 1 is currently connected to the charging facility 2 (YES in S1), the charge control device 10 transmits a negative response to the OEM server 6 (S2). Then, the charge control device 10 ends the process.
[0054] On the one hand, when the vehicle 1 is not currently connected to the charging facility 2 (NO in S1), the charging control device 10 determines the type of the request received via the external communication unit 16A (S3). When the type of the received request is a CSR generation request (CSR in S3), the charging control device 10 reads the number of the currently used slot from the register and determines the number of the currently used slot (S4).
[0055] If the currently used slot is SL1 in the determination of S4, the charging control device 10 generates a pair of a public key KO2 and a private key KS2 in the slot SL2 (S5). Note that the charging control device 10 may generate a pair of the public key KO2 and the private key KS2 in the memory 12 or the external storage unit 13 and request the secure memory to register both of them in the slot SL2. However, the charging control device 10 may request the secure memory to register only the private key KS2 among the generated key pair in the slot SL2. This is because the private key KS2 is desired to ensure security and be kept secret. Also, a pair of the public key KO2 and the private key KS2 may be generated within the secure memory.
[0056] In any case, by the process of S5, the charging control device 10 stores the private key KS1 for the currently valid certificate C1 and the private key KS2 for the newly acquired certificate C2 in different slots SL1 and SL2, respectively. Then, until the installation of the new certificate C2 is completed, the charging control device 10 enables the private key KS1, and when the installation of the new certificate C2 is completed, enables the private key KS2.
[0057] On the other hand, if the currently used slot is SL2 in the determination of S4, a pair of the public key KO2 and the private key KS2 is generated in the slot SL1 (S6). Since the process of S6 is the same as the process of S5, the description thereof is omitted. Then, after the process of S5 or after the process of S6, the charging control device 10 transmits a CSR including the public key KO2 generated in the process of S5 or S6 to the OEM server 6 (S7).
[0058] Also, in the determination of S3, when the request is for the distribution of a certificate (certificate distribution in S3), the charging control device 10 refers to the number of the currently used slot from the register and determines the number of the currently used slot (S8). If, in the determination of S8, the currently used slot is SL1, the charging control device 10 reverses the number of the currently used slot in the register to SL2 (S9).
[0059] Then, the charging control device 10 deletes the key of slot SL1 (S10). In the process of S10, if a key pair is stored in slot SL1, the charging control device 10 may delete the key pair. On the other hand, if only the secret key KS1 is stored in slot SL1, the charging control device 10 may delete the stored secret key KS1.
[0060] On the other hand, if, in the determination of S8, the currently used slot is SL2, the charging control device 10 reverses the number of the currently used slot in the register to SL1 (S11). Then, the charging control device 10 deletes the key of slot SL2 (S12). Since the process of S12 is the same as that of S10, the description thereof is omitted.
[0061] (Effect of the First Embodiment) As described above, the charging control device 10 generates key pair information of the first secret key KS1 and the first public key KO1 in response to a request from an external device such as the OEM server 6 which is the issuer of the certificate. Then, the charging control device 10 transmits the CSR including the first public key KO1 to the issuer and installs the issued first certificate C1. Then, the charging control device 10 creates a signature based on the installed first certificate C1 and the first secret key KS1 and performs charging control with the charging facility 2.
[0062] In this embodiment, with such an existing first secret key KS1 installed, the charging control device 10 receives a CSR generation request from the OEM server 6 or the like. Then, the charging control device 10 newly creates a pair of a second public key KO2 and a second secret key KS2, and sends a CSR including the second public key KO2 to the OEM server 6 or the like. Then, the charging control device 10 newly acquires and installs a second certificate C2. At this time, the charging control device 10 stores the first secret key KS1 for the currently valid first certificate C1 and the second secret key KS2 for the newly issued second certificate C2 based on the request of the OEM server 6 or the like in different storage locations, slots SL1 and SL2.
[0063] Then, until the installation of the second certificate C2 is completed, the charging control device 10 enables the first secret key KS1, and enables the second secret key KS2 when the installation of the second certificate C2 is completed. Therefore, from the time when the pair of the second public key KO2 and the second secret key KS2 is created until the installation of the second certificate C2 is completed, the charging control device 10 can execute processing using the first secret key KS1. That is, the charging control device 10 can create a signature using the first secret key KS1 for the first certificate C1 that has been valid until then, and request authentication from an external device, for example, the charging facility 2 or the like.
[0064] In addition, when the installation of the second certificate C2 is completed, the charging control device 10 deletes the first secret key KS1. Therefore, the charging control device 10 can effectively use the secure memory with less waste.
[0065] Furthermore, when the charging control device 10 receives a request from the OEM server 6 or the like, which is the issuer, while being connected to the charging facility 2, it rejects the request by returning a negative response. Therefore, the charging control device 10 can reduce the parallel processes in the process of requesting certificate creation and the process of requesting authentication by signature, and execute processing with less load.
[0066] <Second Embodiment> Hereinafter, with reference to FIG. 6, the charging control device 10 and the program according to the second embodiment will be described. In the first embodiment described above, when the vehicle 1 is connected to the charging facility 2 when the charging control device 10 receives a request from an external device such as the OEM server 6, the charging control device 10 returns a negative response and ends the process. However, instead of returning a negative response, the charging control device 10 may wait while the vehicle 1 is connected to the charging facility 2. In the second embodiment, processes other than the process in which the charging control device 10 waits while connected to the charging facility 2 are the same as those in the first embodiment. Therefore, the configuration and process of the charging control device 10 in the first embodiment are appropriately referred to and also applied to this embodiment.
[0067] FIG. 6 is a flowchart illustrating the process of updating the certificate and key pair by the charging control device 10 in the second embodiment. This process is started, for example, when the charging control device 10 receives a request from the OEM server 6 or the like via the external communication unit 16A, similar to the first embodiment. Also in this process, similar to the first embodiment, the charging control device 10 determines whether the vehicle 1 is currently connected to the charging facility 2 (S1).
[0068] And if the vehicle 1 is currently connected to the charging facility 2, the charging control device 10 waits as it is (S2A). The waiting may be a wait for a time until it times out by a timer. Also, the charging control device 10 may wait until it detects that the connection to the charging facility 2 has been interrupted via the external communication unit 16A. During this waiting period, the charging control device 10 may execute the process using the current key illustrated in P3 of FIG. 4 in another parallel process.
[0069] And after the waiting, when the vehicle 1 is no longer connected to the charging facility 2, the charging control device 10 executes the processes after S3. Since the processes after S3 in FIG. 6 are the same as those in FIG. 5, the description thereof is omitted.
[0070] As described above, in the present embodiment, when the vehicle 1 is connected to the charging facility 2 when the charging control device 10 receives a request from an external device such as the OEM server 6, the charging control device 10 waits without executing the process of generating the CSR and the process of transmitting the CSR. Then, after waiting, when the vehicle 1 is no longer connected to the charging facility 2, the charging control device 10 executes the processes after S3. For this reason, even when the charging control device 10 receives a CSR generation request, it can create a signature using the currently used private key KS1 and execute an authentication request to an external device, for example, the charging facility 2. In addition, after waiting, when the vehicle 1 is no longer connected to the charging facility 2, the charging control device 10 executes the processes after S3, so that the number of parallel processes can be reduced and the load can be reduced.
[0071] <Third Embodiment> Hereinafter, with reference to FIGS. 7 and 8, the charging control device 10 and the program according to the third embodiment will be described. In the first embodiment, when the vehicle 1 is connected to the charging facility 2 when the charging control device 10 receives a request from an external device such as the OEM server 6, the charging control device 10 returns a negative response and ends the process. Also, in the second embodiment, the charging control device 10 waits without returning a negative response.
[0072] In the present embodiment, the charging control device 10 executes in parallel the process of authentication request and the like by signature using the currently used private key KS1 and the process of updating to the private key KS2 by the CSR. In the third embodiment, the configuration and process of the charging control device 10 other than executing in parallel the process of authentication request and the like by signature and the process of updating to the private key KS2 by the CSR are the same as those in the first embodiment and the second embodiment. Therefore, the configuration and process of the charging control device 10 in the first embodiment and the second embodiment are appropriately referred to and applied to the present embodiment.
[0073] FIG. 7 is a sequence diagram illustrating the process at the time of certificate update in the third embodiment. Similar to FIG. 4, for example, when a request to update the current certificate C1 occurs in the OEM server 6, the OEM server 6 transmits a CSR generation request to the charge control device 10 of the vehicle 1 (P11). Here, the vehicle 1 is currently connected to the charging facility 2. Also, in this case, for example, the charge control device 10 may be executing processing using the current private key KS1 (P12). The processing using the private key KS1 is, for example, the creation of a signature using the private key KS1 and a request for authentication to the charging facility 2.
[0074] In this way, even when the vehicle 1 is connected to the charging facility 2, the charge control device 10 executes key generation processing regardless of the connection to the charging facility 2 (P13). The processing of P13 is the same as the key generation processing of FIG. 4. That is, the charge control device 10 requests the secure memory to store the new private key KS2 in the slot SL2 while maintaining the current private key KS1 in the slot SL1. That is, in the processing of P13, when receiving a request from the OEM server 6 as the issuer while connected to the charging facility 2 based on the first certificate (certificate C1) and the first private key corresponding to the first private key (private key KS1), the second private key (private key KS2) is saved.
[0075] Note that in FIG. 7, the charge control device 10 is illustrated as executing the key generation processing of P13 after the processing using the current private key KS1 by P12. However, the charge control device 10 may execute the processing using the current private key KS1 by P12 and the key generation processing of P13 in parallel processes. Then, the charge control device 10 transmits a CSR including the public key KO2 created as a pair with the private key KS2 to the OEM server 6 (P14). By the processing of P13 and P14, the charge control device 10 requests the OEM server 6 to install the second certificate (certificate C2) corresponding to the private key KS2, and makes the first private key (private key KS1) valid at least while connected to the charging facility 2. That is, the charge control device 10 performs charge control with the charging facility 2 based on the valid private key KS1 and the certificate C1 corresponding to the private key KS1.
[0076] Next, the charging control device 10 receives the distribution of the revised certificate from, for example, the OEM server 6 (P15). When the charging control device 10 receives the revised certificate, it replaces the current private key KS1 with a new private key KS2. That is, the charging control device 10 registers in the register that the currently used slot is slot SL2, requests the secure memory to delete (erase) the private key KS1 in slot SL1, and causes the deletion (erasure) to be executed (P16). That is, when the installation of the second certificate (certificate C2) corresponding to the private key KS2 is completed, the charging control device 10 deletes the private key KS1 and performs charging control with the charging facility 2 based on the valid private key KS2 and the second certificate.
[0077] FIG. 8 is a diagram illustrating a processing flow of the charging control device 10 in the third embodiment. The processing in FIG. 8 is started when, for example, the charging control device 10 receives a request from an external device, such as the OEM server 6, via the external communication unit 16A, similar to the processing in FIG. 5. Note that, similar to FIG. 5, at the time of this activation, it is assumed that the currently used private key is the private key KS1 and the certificate C1 is valid.
[0078] In the processing of FIG. 8, different from FIG. 5, the charging control device 10 determines whether or not it is connected to the charging facility 2, and does not execute the determination in S1 and the processing in S2 of FIG. 5 to end the processing when connected. That is, regardless of whether or not the charging control device 10 is connected to the charging facility 2, it determines the type of the request received via the external communication unit 16A (S23). When the type of the received request is a CSR generation request (CSR in S23), the charging control device 10 executes the processing from S24 to S27. The processing from S24 to S27 is the same as the processing from S4 to S7 in FIG. 5, so the description thereof is omitted. Note that through the processing from S23 to S27, the charging control device 10 stores the second private key KS2 and requests the OEM server 6 or the like, which is the issuer of the certificate, to install the second certificate C2.
[0079] On the other hand, in the determination of S23, when the request is for the distribution of a certificate (certificate distribution in S23), the charging control device 10 determines whether the vehicle 1 is currently connected to the charging facility 2 (S1B). And when the vehicle 1 is currently connected to the charging facility 2, the charging control device 10 simply waits (S2B). The waiting method is the same as S2A in FIG. 6.
[0080] During this waiting period, the charging control device 10 may execute other parallel processes, for example, processes using the current key. Through the determination of S1B and the waiting of S2B, it can be said that when the charging control device 10 receives a request from the issuing source such as the OEM server 6, it enables the first secret key KS1 at least while connected to the charging facility 2. Also, it can be said that the keys generated during the charging session are not used during that session by the charging control device 10.
[0081] After the waiting, when the vehicle 1 is no longer connected to the charging facility 2, the charging control device 10 executes the processes from S28 to S32. Since the processes from S28 to S32 are the same as S8 to S12 in FIG. 5, the description thereof is omitted. That is, the charging control device 10 stores the secret key KS1 for the currently valid certificate C1 and the secret key KS2 for the newly acquired certificate C2 in different slots SL1 and SL2 respectively. And until the installation of the new certificate C2 is completed, the secret key KS1 is enabled, and when the installation of the new certificate C2 is completed, the secret key KS2 is enabled. That is, it can also be said that when the charging control device 10 receives a certificate from the OEM during the charging session, it does not immediately switch the currently used key but switches it after the charging session ends.
[0082] As described above, when the charging control device 10 is connected to the charging facility 2 based on the first certificate C1 and the first secret key KS1 and receives a CSR generation request from the certificate issuing source such as the OEM server 6, it does not execute either a negative response or waiting. That is, the charging control device 10 newly creates a pair of the public key KO2 and the secret key KS2 and stores at least the secret key K2 in the slot SL2.
[0083] Then, the charging control device 10 transmits the CSR to the OEM server 6 or the like that is the issuer of the CSR generation request, and requests the issuance (and installation) of the second certificate C2. Then, the charging control device 10 enables the first private key KS1 at least while the vehicle 1 is connected to the charging facility 2. For this reason, even when the charging control device 10 receives a CSR generation request while the vehicle 1 is connected to the charging facility 2, it continues the process using the current key, the private key KS1. Also, in parallel with this process, the charging control device 10 can request the OEM server 6 or the like to issue (and install) the second certificate C2. In this case, there is no risk that the current key, the private key KS1, will be overwritten by the new private key KS2. Also, until the issuance (and installation) of the second certificate C2 is completed, processes such as signature creation and authentication request to the charging facility 2 are not interrupted.
[0084] However, the charging control device 10 enables the first private key KS1 at least while it is connected to the charging facility 2 by waiting as in S1B and S2B above. Therefore, regardless of whether it is connected to the charging facility 2 or not, when the charging control device 10 receives a request from the OEM server 6 that is the issuer of the certificate, it newly stores the second private key KS2 in the slot SL2 and requests the OEM server 6 to install the second certificate C2. However, thereafter, when the second certificate C2 is further received from the OEM server 6 while connected to the charging facility 2, the charging control device 10 waits, so that the first private key KS1 is enabled at least while it is connected to the charging facility 2. Therefore, the charging control device 10 can continue the process using the currently processed first private key KS1 and obtain authentication by signature.
[0085] Further, when the installation of the second certificate C2 is completed, the charging control device 10 enables the second private key KS2. Therefore, the charging control device 10 can smoothly and continuously transition from the processing using the first certificate C1 and the first private key KS1 to the processing using the second certificate C2 and the second private key KS2. That is, the charging control device 10 can continuously perform the process of requesting authentication by the certificate. Between the time when the charging control device 10 generates the key of the revised certificate and the time when the OEM server 6 issues the certificate and installs it in the charging control device 10, the charging control device 10 can perform PnC charging without stopping the service.
[0086] <Computer-readable recording medium> A program for causing a computer or other machine, device (hereinafter referred to as a computer or the like) to realize any of the above functions can be recorded on a computer-readable recording medium. Then, by causing the computer or the like to read and execute the program of this recording medium, the function can be provided.
[0087] Here, the computer-readable recording medium refers to a recording medium that accumulates information such as data and programs by an electrical, magnetic, optical, mechanical, or chemical action and can be read by a computer or the like. Among such recording media, removable ones from a computer or the like include, for example, flexible disks, magneto-optical disks, CD-ROMs, CD-R / Ws, DVDs, Blu-ray disks, memory cards such as flash memories, etc. Also, recording media fixed to a computer or the like include hard disks, ROMs (read-only memories), etc. Further, an SSD (Solid State Drive) can be used as both a removable recording medium from a computer or the like and a recording medium fixed to a computer or the like. Moreover, an SSD can be used as both a removable recording medium from a computer or the like and a recording medium fixed to a computer or the like.
[0088] (Other) Furthermore, the present embodiment includes the following embodiments (hereinafter referred to as supplementary notes). [Supplementary Note 1] It has a controller that performs charging equipment and charging control based on a certificate, The controller is, Save the first private key corresponding to the installed first certificate in the first area of the memory, Generate a second private key and a public key in response to a request from the certificate issuer, Save the second private key in a second area different from the first area of the memory, Send the public key to the issuer and install the second certificate issued, Until the installation of the second certificate is completed, the first private key is made valid, Enable the second private key upon completion of the installation of the second certificate Charging control device. [Appendix 2] The controller does not overwrite the first private key with the second private key The charging control device according to Appendix 1. [Appendix 3] The controller performs charging equipment and charging control based on the valid private key and the certificate corresponding to the valid private key. The charging control device according to Appendix 1. [Appendix 4] The controller deletes the first private key when the installation of the second certificate is completed. The charging control device according to Appendix 1. [Appendix 5] When the controller is connected to the charging equipment and receives a request from the issuer, it rejects the request. The charging control device according to Appendix 1. [Appendix 6] When the controller is connected to the charging equipment based on the first certificate and the first private key and receives a request from the issuer, it saves the second private key, requests the issuer to install the second certificate, and keeps the first private key valid at least while connected to the charging equipment. The charging control device according to Appendix 1. [Appendix 7] The controller is a charging control device described in Supplementary Note 6 that performs charging facility and charging control based on the valid first private key and the certificate corresponding to the first private key. [Supplementary Note 8] The controller is a charging control device described in Supplementary Note 6 that enables the second private key when the installation of the second certificate is completed. [Supplementary Note 9] The controller is a charging control device described in Supplementary Note 8 that, when the installation of the second certificate is completed, deletes the first private key and performs charging facility and charging control based on the valid second private key and the second certificate. [Supplementary Note 10] For a controller that performs charging facility and charging control based on a certificate, Save the first private key corresponding to the installed first certificate in the first area of the memory, Generate a second private key and a public key in response to a request from the issuer of the certificate, Save the second private key in a second area different from the first area of the memory, Send the public key to the issuer and install the second certificate issued, Until the installation of the second certificate is completed, enable the first private key, A program for executing a process of enabling the second private key when the installation of the second certificate is completed. [Supplementary Note 11] For a controller that performs charging facility and charging control based on a certificate, Save the first private key corresponding to the installed first certificate in the first area of the memory, Generate a second private key and a public key in response to a request from the issuer of the certificate, Save the second private key in a second area different from the first area of the memory, Send the public key to the issuer and install the second certificate issued, Until the installation of the second certificate is completed, enable the first private key, Enable the second private key upon completion of installation of the second certificate Charging control method
Explanation of symbols
[0089] 1 Vehicle 2 Charging facility 5 MO server 6 OEM server 10 Charging control device 11, 21 CPU 12, 22 Memory 13, 23 External storage unit 14 Display unit 15 Operation unit 16A, 26A External communication unit 16B, 26B Charging communication unit 19 Battery 29 Power supply circuit 2A EIM reader 2B Plug
Claims
1. A charging control device having a controller that performs charging equipment and charging control based on a certificate, wherein the controller, stores a first private key corresponding to the installed first certificate in a first area of the memory, generates a second private key and a public key in response to a request from the certificate issuer, stores the second private key in a second area different from the first area of the memory, sends the public key to the issuer and installs the second certificate issued thereby, enables the first private key until the installation of the second certificate is completed, and enables the second private key upon completion of the installation of the second certificate charging control device.
2. The controller does not overwrite the first private key with the second private key The charging control device according to claim 1.
3. The charging control device according to claim 1, wherein the controller performs charging equipment and charging control based on the valid private key and the certificate corresponding to the valid private key.
4. The charging control device according to claim 1, wherein the controller deletes the first private key when the installation of the second certificate is completed.
5. The charging control device according to claim 1, wherein when the controller receives a request from the issuer while being connected to the charging equipment, the controller rejects the request.
6. The charging control device according to claim 1, wherein when the controller receives a request from the issuer while being connected to the charging equipment based on the first certificate and the first private key, the controller stores the second private key, requests the issuer to install the second certificate, and enables the first private key at least while being connected to the charging equipment.
7. The charging control device according to claim 6, wherein the controller performs charging equipment and charging control based on the valid first private key and the certificate corresponding to the first private key.
8. The charging control device according to claim 6, wherein the controller enables the second private key when the installation of the second certificate is completed.
9. The charging control device according to claim 8, wherein when the installation of the second certificate is completed, the controller deletes the first private key and performs charging equipment and charging control based on the valid second private key and the second certificate.
10. In a controller that performs charging equipment and charging control based on a certificate, Save the first private key corresponding to the installed first certificate in the first area of the memory, Generate a second private key and a public key in response to a request from the certificate issuer, Save the second private key in a second area different from the first area of the memory, Send the public key to the issuer and install the second certificate issued, Until the installation of the second certificate is completed, enable the first private key, For executing a process of enabling the second private key upon completion of the installation of the second certificate Program.
11. A controller that performs charging control with a charging facility based on a certificate Save the first private key corresponding to the installed first certificate in the first area of the memory, Generate a second private key and a public key in response to a request from the certificate issuer, Save the second private key in a second area different from the first area of the memory, Send the public key to the issuer and install the second certificate issued, Until the installation of the second certificate is completed, enable the first private key, Enable the second private key upon completion of the installation of the second certificate Charging control method.
Citation Information
Patent Citations
System, authentication station, on-vehicle computer, public key certificate issuing method, and program
JP2018019415A