In-vehicle device and program

The in-vehicle device adjusts the scheduled departure time to precede the shortest authentication deadline, addressing security flaws in ISO15118-20 by ensuring secure charging transactions.

JP2026013042APending Publication Date: 2026-01-28DENSO TEN LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024113187
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-16
Publication Date
2026-01-28

AI Technical Summary

Technical Problem

ISO15118-20 does not specify certificates, authentication processes, or TLS session operation methods, leading to potential security flaws due to expired certificates during charging, which may result in unauthenticated power transactions.

Method used

An in-vehicle device with a controller that adjusts the scheduled departure time to be before the shortest authentication deadline, ensuring secure charging by communicating with the charging facility to complete the transaction before any authentication expires.

Benefits of technology

Ensures secure charging by completing transactions before authentication deadlines, thereby preventing unauthorized power exchanges and maintaining security during charging.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026013042000001_ABST
    Figure 2026013042000001_ABST
Patent Text Reader

Abstract

To improve a defect on security caused by charging and power feeding in a range exceeding an authentication period in charging and power feeding between a vehicle and a charging and power feeding facility.SOLUTION: The vehicle-mounted device includes a controller configured to communicate with the electric power charging and feeding facility and perform charging and feeding of electric power. The charging and power feeding facility controls charging and power feeding to attain a prescribed amount of charge by the expected time of departure of the vehicle. Here, charging and power feeding include at least one of charging of a battery of the vehicle from the outside of the vehicle and power feeding from the battery to the outside of the vehicle. The controller is configured to change the expected departure time to be earlier than or equal to a shortest time limit among time limits related to the one or more authentications between the vehicle and the power charging and feeding facility, when the shortest time limit is earlier than the expected departure time. Then, the controller transmits the changed expected departure time to the power charging and feeding facility.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an in-vehicle device and a program. [Background technology]

[0002] Battery electric vehicles (BEVs) and plug-in hybrid vehicles (PHVs) are well known as vehicles (also called electric vehicles) that can be connected to an external power source to charge the driving battery. There are two main authentication methods for charging the driving battery: External Identification Means (EIM) and Plug & Play. Plug and Charge (PnC) has been proposed (see, for example, Patent Document 1 below). PnC is a procedure that complies with ISO15118, a standard for the communication interface between electric vehicles and the power grid. With PnC, a contract certificate is stored in the vehicle in advance, and user authentication is performed using an encryption key that is paired with the contract certificate.

[0003] Regardless of the authentication method, the vehicle and charging equipment (Electric Vehicle Supply Equipment, EV If the vehicle and EVSE require authentication, after the vehicle and EVSE are connected, the vehicle's certificate (e.g., Vehicle Certificate) is notified to the EVSE, and the EVSE's certificate (e.g., SECC Certificate) is notified to the vehicle. Each certificate is then authenticated by the operator's certificate (e.g., V2G ROOT certificate or OEM ROOT certificate) stored on the peer (EVSE to vehicle, and vehicle to EVSE). This authentication procedure is called Transport Layer Security (TLS) client and server authentication.

[0004] Furthermore, ISO15118-20 assumes V2G and allows infrastructure equipment on the power grid and vehicles to arbitrate V2G power transmission via communication protocols between vehicles / EVSE and between EVSE / infrastructure equipment. This power transmission involves the authentication process described above. For example, a vehicle certificate or SECC certificate is required to connect a TLS session. Authentication is done by document. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2014-225995 Summary of the Invention [Problem to be solved by the invention]

[0006] However, ISO15118-20 does not specify these certificates, authentication processes, or TLS session operation methods. In such a situation, it is possible that the TLS session lifetime may expire while charging is in progress. In addition, there are cases where the Contract certificate, Vehicle certificate, or SECC certificate expires. It is assumed that there may be cases where the authentication is not performed. Or, a combination of these cases may occur. In these cases, there will be a period during which user authentication is not guaranteed. Aspects of the disclosed embodiments improve security flaws in charging between a vehicle and charging equipment, which may occur when charging is performed beyond the authentication expiration date. [Means for solving the problem]

[0007] One aspect of the disclosed embodiment is exemplified by an in-vehicle device. The in-vehicle device includes a controller that communicates with a charging facility and executes charging. The charging facility controls charging so that a predetermined amount of charge is achieved by the scheduled departure time of the vehicle. Here, charging is performed by supplying power from outside the vehicle. This includes at least one of charging both batteries and supplying power from the batteries to the outside of the vehicle. If the shortest deadline among the deadlines for one or more authentications between the vehicle and the charging equipment is earlier than the scheduled departure time, the controller changes the scheduled departure time to a time before the shortest deadline. The controller then transmits the changed scheduled departure time to the charging equipment. [Effects of the Invention]

[0008] When the shortest deadline among the deadlines for one or more authentications between the vehicle and the charging equipment is earlier than the scheduled departure time, the controller changes the scheduled departure time to a time before the shortest deadline and transmits the changed scheduled departure time to the charging equipment. Meanwhile, the charging equipment controls charging so that the vehicle will be charged to a predetermined amount by the scheduled departure time.

[0009] Therefore, the controller can transmit the scheduled departure time to the charging equipment so that charging is completed before the shortest possible time limit, thereby improving security flaws caused by charging beyond the authentication deadline. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram illustrating a vehicle equipped with a charging and power control device according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of the hardware configuration of a vehicle and a charging facility. [Figure 3] FIG. 3 is a timing chart showing an application example of an in-vehicle device. [Figure 4] FIG. 4 is a sequence diagram illustrating a scheduled departure time adjustment process performed by an in-vehicle device, an equipment control device, and a user device. [Figure 5] FIG. 5 is a sequence diagram illustrating a scheduled departure time adjustment process performed by an in-vehicle device, an equipment control device, and a user device. DETAILED DESCRIPTION OF THE INVENTION

[0011] An in-vehicle device 10 and a computer program (hereinafter simply referred to as a program) according to an embodiment will be described below with reference to FIGS.

[0012] <Embodiment> (Configuration) FIG. 1 is a diagram illustrating an example of a vehicle 1 equipped with an on-board device 10 according to this embodiment. FIG. 1 also illustrates a charging and supplying facility 2 that supplies power to a battery 19 (see FIG. 2, also called a secondary battery or a storage battery) of the vehicle 1, a Mobility Operator (MO) server 5 that exchanges information with the vehicle 1, an Original Equipment Manufacturer (OEM) server 6, a user device 3 that provides a user interface to a user, and a commercial power system (grid) provided by a power company or the like. It is also assumed that a home power system or a power load may be connected instead of the grid. The on-board device 10 is connected to an Electric Vehicle Communication Controller (EVCC) and The equipment control device 20 is also called a Supply Equipment Communication Controller. Also known as (SECC).

[0013] The vehicle 1 is called an electric vehicle, and can charge a battery 19 for driving. The vehicle 1 has an on-board device 10, and performs a process of charging the battery 19 from a charging and supplying facility 2, or a process of supplying power from the battery 19 to a commercial power grid via the charging and supplying facility 2. In this embodiment, the charging process and the power supply process are called a charging and power supply process. The power supply process can also be called a process of discharging the battery 19.

[0014] The charging and supplying facility 2 has an facility control device 20, and when connected to the on-board device 10 of the vehicle 1, communicates with the on-board device 10 in accordance with a procedure in accordance with ISO15118-20. More specifically, the facility control device 20 establishes a TLS session with the vehicle 1, and supplies power to the vehicle 1 or receives power from the vehicle 1 (i.e., supplies power from the battery 19). It can be said that the power supply equipment 2 performs charging and power supply including at least one of charging the battery 19 of the vehicle 1 from outside the vehicle 1 and supplying power from the battery 19 to outside the vehicle 1. The charging and power supply equipment 2 is an example of something outside the vehicle 1.

[0015] Charging facility 2 is operated by a business called a Charge Point Operator (CPO) in addition to the MO. The charging equipment 2 may be installed in a parking lot where the vehicle 1 is parked, in a facility managed by a CPO, MO, OEM, or the like, or on the premises of a user's home. The charging equipment 2 is connected to, for example, a commercial power grid and serves as an interface for sending and receiving power between the vehicle 1 and the power grid.

[0016] The user of the vehicle 1 concludes a contract with a service provider (MO, etc.) in advance to execute the power receiving and supplying process via the charging and supplying facility 2. According to this contract, a contract certificate, etc. and an encryption key are issued from the MO server 5 and are installed in the vehicle 1 via, for example, the OEM server 6. The contract certificate, etc. and the encryption key can also be referred to as certificate data. Note that the certificate data of the contract certificate, etc. may also be installed in the vehicle 1 via, for example, the charging and supplying facility 2. Note that in a procedure using an external authentication method (EIM) by presenting an RFID card, etc., installation of the contract certificate, etc. and the encryption key is not required.

[0017] In the power receiving process, a TLS session is first established. For example, after the charging equipment 2 and the vehicle 1 are connected via the plug 2B, the SECC certificate of the charging equipment 2 is notified to the vehicle 1. Then, the SECC certificate is authenticated by the V2G ROOT certificate stored on the vehicle 1 side. Next, the vehicle certificate of the vehicle 1 is notified to the charging equipment 2. Then, The Vehicle certificate is authenticated by the V2G ROOT certificate or OEM ROOT certificate stored on the power supply equipment 2 side. Here, the SECC certificate contains the V2G ROOT certificate The Vehicle Certificate contains a hierarchical chain of certificates of the operators associated with the Vehicle Certificate. The certificate includes a hierarchical operator certificate chain linked to a V2G ROOT certificate or an OEM ROOT certificate.

[0018] A certificate chain corresponds to a hierarchy of Certificate Authorities (CAs). A higher-level CA can have a lower-level CA called an intermediate CA (also called a sub-CA). The top-level CA is called a ROOT CA and issues V2G ROOT certificates and OEM ROOT certificates. The CA certificates (sub-certificates) of the lower-level intermediate CAs are signed by the higher-level CA.

[0019] Vehicle 1 authenticates the certificate chain from top to bottom based on the V2G ROOT certificate, and ultimately authenticates the EVSE Leaf certificate (referred to as the SECC certificate). If vehicle 1 successfully authenticates the SECC certificate, it can obtain the private key to use for communication with charging equipment 2, and subsequent communications are encrypted using the private key. This establishes a TLS session.

[0020] After the TLS session is established, V2G communication is performed. In V2G communication, a request from the vehicle 1 and a response from the charging and supply equipment 2 are transmitted to each other, and charging and power supply are performed. In this V2G communication, external authentication is performed using, for example, PnC or an RFID card.

[0021] After the TLS session is established, the on-board device 10 of the vehicle 1 creates a signature based on the Contract certificate and the like and the encryption key, and the charging equipment 2 authenticates this. If the authentication is successful, the vehicle 1 executes a power receiving process using the PnC procedure between the vehicle 1 and the charging equipment 2. In addition to the PnC procedure described above, the power receiving process between the vehicle 1 and the charging equipment 2 can also use an external authentication method (EIM) procedure by presenting an RFID card or the like as a second authentication procedure.

[0022] The in-vehicle device 10 can be connected to an MO server 5, an OEM server 6, and the like via a network N1. The network N1 can be, for example, a wireless network such as Long Term Evolution (LTE), a 5th Generation Mobile Communication System (5G), or a 6th Generation Mobile Communication System (6G), or a wired public network such as the Internet. Includes work.

[0023] For example, the charging and supplying equipment 2 may transfer the signature sent from the vehicle 1 to the MO server 5 and request user authentication of the vehicle 1. Then, when the user authentication by the MO server 5 is successful, the charging and supplying equipment 2 may execute a power receiving process with the battery 19 of the vehicle 1 and a payment process (billing or settlement) with the user of the vehicle 1.

[0024] The user device 3 is a smartphone, a mobile phone, or the like that is connected to the in-vehicle device 10 or the OEM server 6 by wireless communication. Here, the wireless communication is, for example, communication via a wireless access network such as LTE, 5G, or 6G. The wireless communication may also be performed using Bluetooth (registered trademark) or similar. Communication may also be via Bluetooth (registered trademark), Bluetooth low energy (BLE), etc.

[0025] The user device 3 may also be a device connected to the in-vehicle device 10 by wire. The user device 3 may also be incorporated into the in-vehicle device 10, for example, a device corresponding to the display unit 14 and operation unit 15 in FIG. 2. The user device 3 may also have audio, visual, navigation functions, etc. The user device 3 executes processing as an example of a user interface through which a user inputs information.

[0026] FIG. 2 is a diagram illustrating an example of the hardware configuration of the vehicle 1 and the charging and supplying equipment 2. The on-board device 10 of the vehicle 1 and the charging and supplying equipment 2 constitute a charging system. The on-board device 10 has a CPU 11, a memory 12, and external devices connected to an external interface (I / F), and executes information processing by a program. Examples of the external devices include an external storage unit 13, a display unit 14, an operation unit 15, an external communication unit 16A, and a charging and communication unit 16B. The CPU 11 and the memory 12 can be collectively referred to as a control unit. The control unit is an Electronic Control Unit ( The control unit is also called an ECU.

[0027] The CPU 11 executes a computer program deployed in an executable manner in the memory 12, and provides the functions of the in-vehicle device 10. The CPU 11 is also called a processor. The CPU 11 is not limited to a single processor. The CPU 11 may be a plurality of processors of the same type operating in parallel. The CPU 11 may also include one or more dedicated processors suitable for calculations according to the processing target, such as a GPU (Graphics Processing Unit) or a DSP (Digital Signal Processor). The CPU 11 may also execute processing in cooperation with other processors of the same type, such as a GPU or a DSP.

[0028] The memory 12 stores computer programs executed by the CPU 11, data processed by the CPU 11, etc. The memory 12 is a dynamic random access memory (DRAM), a static random access memory (SRAM), a read only memory (ROM), etc. The external storage unit 13 is used, for example, as a storage area that supplements the memory 12, and stores computer programs executed by the CPU 11, data processed by the CPU 11, etc. The external storage unit 13 is a hard disk drive, a solid state drive (SSD), etc.

[0029] The display unit 14 is, for example, a liquid crystal display, an electroluminescence panel, etc. The operation unit 15 is, for example, a keyboard, a pointing device, etc. In this embodiment, a touch panel equipped with a touch sensor is exemplified as the pointing device. The display unit 14 and the operation unit 15 act as a user interface that can be used by the user.

[0030] The external communication unit 16A exchanges data with other devices (such as the OEM server 6 in FIG. 1) on a public network such as the network N1 (see FIG. 1). For example, the CPU 11 communicates with a computer of a carrier on the public network through the external communication unit 16A. The external communication unit 16A may be a wireless communication device that accesses a mobile phone network. The external communication unit 16A may also be a communication device that accesses a wireless LAN (Local Area Network). The external communication unit 16A is called a TCU (Telematics Control Unit), and is used to communicate with the network N1. It may also be a device that performs communication called telematics via the Internet.

[0031] The charging communication unit 16B transmits and receives signals to and from the charging communication unit 26B. That is, the charging communication unit 16B communicates with the charging and power supply equipment 2, for example, based on PLC (Power Line Communications). However, the charging communication unit 16B may communicate with the charging communication unit 26B via a CAN (Controller Area Network), a wireless LAN, an Ethernet, or the like. Communication may be performed according to the above or a communication procedure based on these.

[0032] The charging and supplying equipment 2 has an equipment control device 20 and a power supply circuit 29. The equipment control device 20 has a CPU 21, a memory 22, and external devices connected to an external interface (I / F), and executes information processing using a program. Examples of the external devices include an external storage unit 23, an external communication unit 26A, a charging and communication unit 26B, and an EIM reader 2A. The configuration of the charging and supplying equipment 2, other than the EIM reader 2A and the power supply circuit 29, is the same as that of the on-board device 10 of the vehicle 1, and therefore a description thereof will be omitted.

[0033] The EIM reader 2A is a card reader that reads information from an IC card such as a credit card by contact or contactless, an image reader that reads a QR code (registered trademark), an RFID reader, etc. The power supply circuit 29 is connected to a commercial power grid and charges the battery 19 or receives power from the battery 19.

[0034] The MO server 5 and the OEM server 6 have the same configuration as the CPUs 11 and 21, memories 12 and 22, external storage units 13 and 23, display unit 14, operation unit 15, and external communication units 16A and 26A. The MO server 5 and the OEM server 6 are general-purpose computers. The MO server 5 and the OEM server 6 may be a collection of multiple computers called a cloud.

[0035] 3 is a timing chart showing an application example of the in-vehicle device 10. In this embodiment, when the vehicle 1 is connected to the charging facility 2 and charging is performed, the in-vehicle device 10 transmits the scheduled departure time (DepartureTime) of the vehicle 1 to the charging facility 2 in a ScheduleExchangeReq message. The charging facility 2, or a Home Energy Management System (HEMS) system connected to the charging facility 2 via a network N1 or the like, or a back-end aggregator calculates the amount of power to be charged based on the scheduled departure time received from the vehicle 1 and the charge amount of the battery 19 requested at the scheduled departure time.

[0036] That is, the amount of power to be charged is determined, for example, so that the battery 19 has a predetermined charge level at the scheduled departure time. There are no limitations on the predetermined charge level. For example, the predetermined charge level is a full charge. The predetermined charge level may be a value set as a parameter in the in-vehicle device 10, the charging facility 2, the HEMS system, or the back-end aggregator. The back-end aggregator is an institutional computer that adjusts the power exchanged between the commercial power grid and the vehicle 1, the charging facility 2, the HEMS system, or the like.

[0037] The timing chart in Fig. 3 illustrates the relationship between the respective deadlines for multiple authentications between the vehicle 1 and the charging facility 2 and the scheduled departure time of the vehicle 1. Multiple certifications between the parties, such as Contract Certificate, Vehicle Certificate, SECC Certificate, etc. The expiration dates for each authentication are the expiration date of the Contract certificate (T1), the expiration time of the TLS session lifetime (T2), the expiration date of the Vehicle certificate (T3), and the expiration date of the SECC certificate (T4). T1, T3 , T4 and the expiration time T2 are examples of respective deadlines related to one or more authentications between the vehicle 1 and the charging equipment 2.

[0038] In FIG. 3, Tk (k is an integer) exemplifies time. The time is calculated by the operating system (OS) of a computer and includes, for example, year, month, day, hour, minute, and second. However, the time may be corrected using time information acquired by a Global Navigation Satellite System (GNSS) receiver. The time may also be time information acquired by a GNSS receiver. GNSS is also known as the Global Positioning System (GPS). However, in this embodiment, the validity period for authentication between the vehicle 1 and the power charging equipment 2 is not limited to the example shown in FIG.

[0039] To exchange power between vehicle 1 and charging equipment 2, the user connects plug 2B of charging equipment 2 to a connector including a power receiving unit connected to battery 19 of vehicle 1 and a terminal connected to charging communication unit 16B (T5). Then, on-board device 10 of vehicle 1 accepts the setting of the scheduled departure time (DepartureTime) from the user through the user interface, and (T6). The in-vehicle device 10 may obtain the scheduled departure time from the user's schedule information stored in the memory 12. Alternatively, the in-vehicle device 10 may obtain the scheduled departure time from the user's schedule information stored in a wirelessly accessible user device 3 (see FIG. 1 ).

[0040] If the acquired scheduled departure time is later than any of the above-mentioned authentication-related deadlines (T1 to T4), the in-vehicle device 10 updates the scheduled departure time to the shortest deadline or to a time before the deadline (T7). In Fig. 3, the expiration date (T1) of the Contract certificate is exemplified as the shortest deadline. In Fig. 3, the expiration date (T1) of the Contract certificate is exemplified as the case where the expiration date (T1) of the Contract certificate is earlier than the scheduled departure time (T5).

[0041] 3 illustrates a case where the shortest deadline among the deadlines for one or more authentications between the vehicle 1 and the charging equipment 2 is earlier than the scheduled departure time. However, the shortest deadline is not limited to the expiration date (T1) of the Contract certificate. In other words, any of the deadlines (T1 to T4) for the above authentications can be the shortest deadline. Then, the on-board device 10 sets the scheduled departure time (DepartureTime) in a message called ScheduleExchangeReq and transmits the message to the charging equipment 2.

[0042] (Processing flow) 4 and 5 are sequence diagrams illustrating an example of a scheduled departure time adjustment process performed by the in-vehicle device 10, the equipment control device 20, and the user device 3. The CPU 11 and memory 12 of the in-vehicle device 10, as an example of a controller, cooperate with the equipment control device 20 and the user device 3 according to a program on the memory 12 to execute the following process.

[0043] This process starts, for example, when the user connects plug 2B of charging and supplying equipment 2 to a connector of vehicle 1. In this process, first, the user inputs a planned departure time through user device 3, which is an example of a user interface (S40). However, the process of S40 may be executed as, for example, input of the user's schedule information before the user connects plug 2B of charging and supplying equipment 2 to a connector of vehicle 1.

[0044] The in-vehicle device 10 receives the scheduled departure time from the user device 3 (S41). After the user connects the plug 2B of the charging equipment 2 to the connector of the vehicle 1, the on-vehicle device 10 acquires the scheduled departure time when the scheduled departure time is input to the user device 3 in the process of S40. However, the on-vehicle device 10 may acquire the scheduled departure time regardless of the process of S40.

[0045] For example, the in-vehicle device 10 may acquire the scheduled departure time from the user device 3 having schedule information in which the scheduled departure time has already been set. Alternatively, the in-vehicle device 10 may acquire the scheduled departure time from the memory 12 or the like in which the scheduled departure time has already been stored. When the in-vehicle device 10 acquires the scheduled departure time independently of the processing of S40, the processing of S40 after the plug 2B is connected to the connector of the vehicle 1 may be omitted. The processing of S41 is an example of acquiring the scheduled departure time.

[0046] 3 is earlier than the scheduled departure time (S42). If the determination in S42 is YES, the on-board device 10 changes the scheduled departure time to a time before the shortest deadline (S43). If the determination in S42 is NO, the on-board device 10 proceeds to the process of S44 without executing the process of S43. If the determination in S42 is YES, this is an example of a case where the shortest deadline among the deadlines for one or more authentications between the vehicle 1 and the charging equipment 2 is earlier than the scheduled departure time.

[0047] Next, the on-board device 10 transmits the maximum charging power and the maximum feed power to the equipment control device 20 (S44). There is no restriction on the timing at which the process of S44 is executed. Next, the equipment control device 20 receives the maximum charging power and the maximum feed power. In this embodiment, the charging and feeding process in the equipment control device 20 is executed in dynamic control mode. The dynamic control mode is a mode in which power is exchanged between the vehicle 1 and the charging equipment 2 within the range of the maximum charging power and the maximum feed power received in advance from the vehicle 1.

[0048] Furthermore, the vehicle-mounted device 10 notifies the vehicle of the scheduled departure time by the ScheduleExchangeReq message. The charging and supplying equipment 2 transmits the ScheduleExchangeReq message to the control device 20 (S45). The process of S45 after the process of S43 is an example of transmitting the changed scheduled departure time to the power charging facility 2.

[0049] Then, the equipment control device 20, the HEMS system linked with the charging equipment 2, or the back-end aggregator adjusts the power plan (S46). Here, in the power plan, the charging equipment 2 determines the amount of power to be charged so that the battery 19 has a predetermined charge level, for example, at the vehicle departure time. Furthermore, since the equipment control device 20 operates in dynamic control mode, the power to be charged at each time in the power plan is set within a range that does not exceed the maximum charging power or maximum power supply power notified in advance by the vehicle 1.

[0050] Then, the on-board device 10 and the equipment control device 20 execute a charging process (S47, S48). That is, the vehicle 1 and the charging equipment 2 charge the battery 19 of the vehicle 1 from the charging equipment 2 or supply power from the battery 19 to the charging equipment 2 according to the power adjusted in S46, within a range that does not exceed the maximum charging power or the maximum supply power. While the charging process of S47 and S48 is being executed, the user can update the departure time by notifying the equipment control device 20 of an update request from the user device 3 (S49). The process of FIG. 5 is continued in FIG. 5 by symbols A1 and B1. Hereinafter, the description will be continued according to FIG. 5.

[0051] The on-board device 10 determines whether or not an update request for the scheduled departure time has been received (S51). If the determination in S51 is YES, this is an example of a case where an update request for updating the scheduled departure time has been received from the user interface while power is being charged between the vehicle 1 and the power charging equipment 2. If the determination in S51 is YES, the on-board device 10 determines whether or not the scheduled departure time updated by the update request is earlier than any of the deadlines illustrated in FIG. 3 (S52).

[0052] If the determination in S52 is NO, the in-vehicle device 10 changes the scheduled departure time to the shortest deadline, and sets it as the new scheduled departure time (S53). If the determination in S52 is YES, the in-vehicle device 10 does not execute the process of S53, and proceeds to the determination in S54. If the determination in S52 is NO, this is an example of a case where the shortest deadline is earlier than the updated scheduled departure time. If the determination in S52 is YES, this is an example of a case where the updated scheduled departure time is earlier than the shortest deadline.

[0053] The in-vehicle device 10 then determines whether the scheduled departure time updated in the update request of S49 or the new scheduled departure time changed in the processing of S53 is acceptable (S54). Here, acceptable refers to a case where the battery 19 is unlikely to reach a predetermined charge level by the scheduled departure time, within a range that does not exceed the maximum charging power or the maximum power supply power. A NO determination in S54 is an example of a case where charging cannot be performed to reach the predetermined charge level by the updated scheduled departure time.

[0054] If the scheduled departure time updated in the update request of S49 is earlier than any of the deadlines (YES in S52) and the updated scheduled departure time is not acceptable (NO in S54), the in-vehicle device 10 maintains the scheduled departure time. In this case, the in-vehicle device 10 does not transmit the updated scheduled departure time to the equipment control device 20 (S56). Also, if any of the deadlines is earlier than the scheduled departure time updated in the update request of S49 (NO in S52) and the new scheduled departure time changed in the processing of S53 is not acceptable (NO in S54), the in-vehicle device 10 maintains the scheduled departure time. In this case, the in-vehicle device 10 does not transmit the new scheduled departure time to the equipment control device 20 (S56).

[0055] In these cases, the power plan of S46 is maintained, and the charging process continues (S58, S59). If the scheduled departure time updated in the update request of S49 or the new scheduled departure time changed in S53 is not acceptable, the in-vehicle device 10 may notify the user to that effect. For example, the in-vehicle device 10 may notify the user device 3 that the scheduled departure time or the like updated in the update request of S49 is not acceptable, or may display a message on the display unit 14 or output it by voice.

[0056] On the other hand, if the scheduled departure time updated in the update request of S49 is acceptable (YES in S54), the in-vehicle device 10 transmits the updated scheduled departure time to the equipment control device 20 (S55). Also, if the new scheduled departure time changed in S53 is acceptable (YES in S54), the in-vehicle device 10 transmits the new scheduled departure time to the equipment control device 20 (S55). Then, the charging and supplying equipment 2 receives the scheduled departure time updated in the update request of S49 or the new scheduled departure time changed in S53. Then, the equipment control device 20, the HEMS system linked to the charging and supplying equipment 2, or the backend aggregator adjusts the power plan again (S57).

[0057] Then, the in-vehicle device 10 and the equipment control device 20 execute the power charging process (S58, S59). That is, the in-vehicle device 10 and the equipment control device 20 execute the power charging process in accordance with the power plan readjusted in S57.

[0058] (Effects of the embodiment) 4 and 5, the on-board device 10 communicates with the equipment control device 20 of the charging equipment 2 and executes charging using the CPU 11 and memory 12, which are an example of a controller. Here, the equipment control device 20 controls charging so that a predetermined amount of charge is achieved by the scheduled departure time of the vehicle 1, as in S47, S48, S58, and S59 above. That is, the charging equipment 2 controls charging, which includes at least one of charging the battery 19 of the vehicle 1 from outside the vehicle 1 and feeding power from the battery 19 to outside the vehicle 1, within a maximum power range specified by the vehicle 1. Controlled by.

[0059] Then, the on-vehicle device 10 acquires the scheduled departure time from the user device 3, etc. Furthermore, if the shortest deadline among the deadlines for one or more authentications between the vehicle 1 and the power charging facility 2 is earlier than the scheduled departure time, the on-vehicle device 10 changes the scheduled departure time to a time before the shortest deadline. Then, the on-vehicle device 10 transmits the changed scheduled departure time to the facility control device 20 of the power charging facility 2.

[0060] Therefore, the in-vehicle device 10 and the facility control device 20 can complete the charging before the deadline for authentication between the vehicle 1 and the charging facility 2. As a result, the in-vehicle device 10 can improve security flaws associated with charging between the vehicle 1 and the charging facility 2.

[0061] When the on-board device 10 receives an update request from the user device 3 to update the scheduled departure time while charging is being performed between the vehicle 1 and the charging facility 2, the on-board device 10 handles the case where the shortest deadline is earlier than the scheduled departure time updated by the update request. That is, if the shortest deadline is earlier than the scheduled departure time updated by the update request, the on-board device 10 changes the updated scheduled departure time to a new scheduled departure time that is earlier than the shortest deadline. Therefore, even when the scheduled departure time is updated during charging and is further changed to a new scheduled departure time that is earlier than the shortest deadline, the on-board device 10 can improve security flaws associated with charging between the vehicle 1 and the charging facility 2.

[0062] The in-vehicle device 10 handles cases where the scheduled departure time updated by the update request is earlier than the shortest deadline among T1 to T4 and where charging cannot be performed to achieve the specified charge amount by the updated scheduled departure time. In this case, the in-vehicle device 10 discards the updated scheduled departure time and maintains the scheduled departure time before receiving the update request. Therefore, even when the scheduled departure time is updated during charging, the in-vehicle device 10 can maintain security and manage charging to achieve the specified charge amount.

[0063] The in-vehicle device 10 also handles cases where the updated scheduled departure time is changed to a new scheduled departure time because the shortest expiration date is earlier than the updated scheduled departure time in the update request, and where charging cannot be performed to achieve the specified amount of charge by the new scheduled departure time. In this case, the in-vehicle device 10 discards the new scheduled departure time and maintains the scheduled departure time before receiving the update request. Therefore, even when the in-vehicle device 10 receives a request to update the scheduled departure time and further changes the updated scheduled departure time to a time before the shortest expiration date, it can maintain security and manage charging to achieve the specified amount of charge. (Other variations) In the above embodiment, the charging equipment 2 performs charging in the dynamic control mode. However, the processing of the in-vehicle device 10 illustrated in Fig. 4 and Fig. 5 is not limited to charging with the charging equipment 2 that performs charging in the dynamic control mode. For example, before starting charging, the in-vehicle device 10 and the charging equipment 2 arbitrate a power schedule, and the in-vehicle device 10 can also perform the processing illustrated in Fig. 4 and Fig. 5 for the charging equipment 2 that operates in a schedule control mode in which charging is performed in accordance with the arbitrated power schedule.

[0064] (Computer-readable recording medium) A program that causes a computer or other machine or device (hereinafter referred to as a computer, etc.) to realize any of the above functions can be recorded on a computer-readable recording medium. Then, by having the computer, etc. read and execute the program from this recording medium, the function can be provided.

[0065] Here, the computer-readable recording medium is information such as data and programs. It refers to a recording medium that stores information electrically, magnetically, optically, mechanically, or chemically and can be read by a computer, etc. Among such recording media, those that can be removed from a computer, etc. include flexible disks, magneto-optical disks, CD-ROMs, CD-R / Ws, DVDs, Blu-ray disks, and memory cards such as flash memory. In addition, recording media that are fixed to a computer, etc. include hard disks and ROMs (read-only memories). Furthermore, SSDs (Solid State Drives) are The recording medium can be used as a recording medium that can be removed from a computer or the like, or as a recording medium that is fixed to a computer or the like. [Explanation of symbols]

[0066] 1 vehicle 2 Charging power supply equipment 10 Onboard equipment 11, 21 CPUs 12, 22 memory 13, 23 External memory unit 14 Display section 15 Control section 16A, 26A external communication section 16B, 26B Charging communication section 19 Battery 29 Power circuit

Claims

1. An in-vehicle device including a controller that communicates with a charging facility that controls charging, including at least one of charging a battery of the vehicle from outside the vehicle and supplying power from the battery to outside the vehicle, so that a predetermined charge amount is reached by a scheduled departure time of the vehicle, and that executes the charging, the controller comprising: If the shortest deadline among the deadlines for one or more authentications between the vehicle and the charging facility is earlier than the scheduled departure time, the scheduled departure time is changed to a time before the shortest deadline, and the changed scheduled departure time is transmitted to the charging facility. In-vehicle device.

2. 2. The in-vehicle device according to claim 1, wherein, when the controller receives an update request to update the scheduled departure time while the charging is being performed between the vehicle and the charging facility, if the shortest deadline is earlier than the updated scheduled departure time, the controller changes the updated scheduled departure time to a new scheduled departure time that is earlier than the shortest deadline.

3. 3. The in-vehicle device according to claim 2, wherein, when the updated scheduled departure time is earlier than the shortest deadline and the charging cannot be performed so that the predetermined charge amount is reached by the updated scheduled departure time, the controller discards the updated scheduled departure time and maintains the scheduled departure time before receiving the update request.

4. 3. The in-vehicle device according to claim 2, wherein the controller, when the shortest deadline is earlier than the updated scheduled departure time and when the charging cannot be performed so as to achieve the predetermined charge amount by the new scheduled departure time, discards the new scheduled departure time and maintains the scheduled departure time before receiving the update request.

5. a computer that communicates with a charging facility that controls charging and supplying power, including at least one of charging a battery of the vehicle from outside the vehicle and supplying power from the battery to outside the vehicle, so that a predetermined charge amount is reached by a scheduled departure time of the vehicle; When the shortest deadline among deadlines related to one or more authentications between the vehicle and the charging equipment is earlier than the scheduled departure time, the scheduled departure time is changed to a time before the shortest deadline and the changed scheduled departure time is transmitted to the charging equipment. program.

Citation Information

Patent Citations

  • Charging / discharging control device

    JP2014225995A