Charging system, charging control unit, and program

The charging system ensures secure communication between vehicles and charging facilities by verifying wireless identification information and implementing TLS handshakes with random number generation and signature verification, addressing security risks in the transition from CAN to wireless LAN communication.

JP2026021922APending Publication Date: 2026-02-12DENSO TEN LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024123171
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-30
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing charging systems for electric vehicles face security risks due to the lack of secure communication protocols, particularly in the transition from Controller Area Network (CAN) to wireless Local Area Network (LAN), where information exchanged via CAN can be tampered with or intercepted, leading to potential information leakage and unauthorized power usage.

Method used

A charging system that includes a charging control unit on the vehicle and an equipment control unit connected via wire, which verifies wireless identification information through a wired path and wireless path to ensure matching parameters, implementing a TLS handshake with random number generation and signature verification to secure encrypted communication.

Benefits of technology

The system effectively prevents unauthorized access and tampering by ensuring that wireless communication is securely established, thereby preventing information leakage and unauthorized charging.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026021922000001_ABST
    Figure 2026021922000001_ABST
Patent Text Reader

Abstract

To charge a vehicle by safely using both wired communication such as CAN and wireless communication such as wireless LAN between the vehicle and a charging facility.SOLUTION: A charging system includes a charging control unit that is mounted on a vehicle and controls charging of the vehicle, a facility control unit that is connected to the charging control unit by wire and controls a charging facility that charges the vehicle, and a wireless device that is wirelessly connected to the charging control unit. The charging control unit acquires, from the facility control unit, at least wireless identification information for connecting to the wireless device. On the other hand, the wireless device includes at least wireless identification information in a parameter to be exchanged when establishing encrypted communication with the charging control unit, and wirelessly transmits the parameter. Then, the charging control unit verifies whether or not the radio identification information acquired from the facility control unit matches the radio identification information included in the parameter, and stops the charging when the radio identification information does not match.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a charging system, a charging control unit, and a program. [Background technology]

[0002] Battery electric vehicles (BEVs) and plug-in hybrid vehicles (PHVs) are known as vehicles (also called electric vehicles) that can be connected to an external power source to charge the driving battery. There are two main authentication methods for charging the driving battery: External Identification Means (EIM) and Plug & Play. A plug and charge (PnC) has been proposed (see, for example, Patent Document 1 below). PnC is a procedure that follows ISO15118, a standard for the communication interface between a power grid (also called a power grid or power system) and a vehicle. In other words, in the use case of (Vehicle-to-Grid) V2G, PnC is used. The application of automatic billing systems is expected.

[0003] In PnC, security is required to ensure security using Transport Layer Security (TLS) because user authentication information is exchanged between the vehicle and the charging equipment that charges the vehicle. However, current charging standards such as CHArge de Move (CHAdeMO) and GB / T communicate between the vehicle and the charging equipment via Controller Area Network (CAN). However, In CAN, the amount of data in the data field sent and received in the data frame is limited, making it difficult to apply CAN to sending and receiving TLS packets. For this reason, Japan is currently proposing to the ISO15118 working group that wireless Local Area Network (LAN) communication and CAN communication be used together. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2019-47216 Summary of the Invention [Problem to be solved by the invention]

[0005] In a wireless LAN, communicating devices must identify the pairing partner. Therefore, for example, it is assumed that a vehicle and a charging facility exchange information for pairing via wireless LAN through CAN communication, and then communicate via wireless LAN based on the information exchanged via CAN communication. However, this method does not take into consideration the security of the information exchanged via CAN communication. For example, if the information exchanged via CAN communication is tampered with or illegally used for wireless LAN communication, there is a risk of information leakage, unauthorized power usage, etc. due to spoofing by an attacker in at least one of the vehicle and the charging facility. An aspect of the disclosed embodiment is to safely use wired communication such as CAN and wireless communication such as wireless LAN between the vehicle and the charging facility, securely establish encrypted wireless communication, and enable charging of the vehicle. [Means for solving the problem]

[0006] One aspect of the disclosed embodiment is exemplified by a charging system including a charging control unit mounted on a vehicle and controlling charging of the vehicle, an equipment control unit connected to the charging control unit by wire and controlling charging equipment that charges the vehicle, and a wireless device connected wirelessly to the charging control unit. Here, the charging control unit acquires at least wireless identification information for connecting to the wireless device from the equipment control unit. Meanwhile, the wireless device wirelessly transmits at least the wireless identification information included in parameters exchanged when establishing encrypted communication with the charging control unit. Then, the charging control unit The wireless identification information acquired from the equipment control unit verifies whether or not it matches the wireless identification information included in the parameters, and if they do not match, stops the charging. [Effects of the Invention]

[0007] As described above, the charging control unit of the present charging system verifies whether the wireless identification information acquired from the equipment control unit matches the wireless identification information included in the parameters exchanged when establishing encrypted communication with the wireless device, and stops charging if they do not match. Therefore, in the present charging system, the charging control device acquires wireless identification information via a wired path via the equipment control unit and a wireless path from the wireless device, and can verify whether the two match. As a result, the present charging system can safely establish wireless encrypted communication between the vehicle and the charging facility using both wired communication and wireless communication, and charge the vehicle. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a diagram illustrating the configuration of a charging system according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating a process in a comparative example in which a vehicle is charged using both a wireless LAN and a CAN in a vehicle, a charging facility, and a wireless device. [Figure 3] FIG. 3 is a diagram illustrating a first problem in the process of the comparative example. [Figure 4] FIG. 4 is a diagram illustrating a second problem in the process of the comparative example. [Figure 5] FIG. 5 is a diagram illustrating a third problem in the process of the comparative example. [Figure 6] FIG. 6 is a sequence diagram illustrating the processing of the charging system of this embodiment. [Figure 7] FIG. 7 is a sequence diagram illustrating the processing of the charging system of this embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, a charging system 100 according to one embodiment, a charging control unit 10 included in the charging system 100, and a computer program executed by the charging control unit 10 (hereinafter simply referred to as a program) will be described with reference to FIGS.

[0010] (Application example) 1 to 5 illustrate examples of applications (use cases) to which a charging system 100 according to this embodiment is applied. FIG. 1 is a diagram illustrating the configuration of the charging system 100 according to this embodiment. The charging system 100 includes a vehicle 1, a charging facility 2, and a wireless device 3.

[0011] The vehicle 1 is a BEV and includes a battery 19, a high-voltage circuit 18, a charging control unit 10, a Controller Area Network communication unit (hereinafter referred to as a CAN communication unit 11), and a wireless LAN communication unit (Wireless Local Area Network communication unit; hereinafter referred to as a WLAN communication unit 12). Reference numeral 9 is called a storage battery or secondary battery, and supplies power to the motor and other devices of the vehicle 1. A high-voltage circuit 18 receives power from the charging equipment 2 and charges a battery 19 under the control of the charging control unit 10.

[0012] The charging control unit 10 communicates with the charging facility 2, and performs authentication by PnC or EIM and controls charging of the battery 19. The charging control unit 10 also communicates with the Mobility Operator ( MO servers, Original Equipment Manufacturer (OEM) servers, certificate pools, etc. Access is made via the network to obtain various certificates and the corresponding encryption keys (public key, private key) for each certificate.

[0013] The charging control unit 10 has a CPU, a memory, and an external device connected to an external interface (I / F), and executes information processing by a program. Examples of the external device include an external storage unit, a display unit, an operation unit, and a communication unit. The CPU and memory can be collectively referred to as the control unit. The control unit is also called an Electronic Control Unit (ECU). The control unit is an example of a controller.

[0014] The CAN communication unit 11 accesses a wired CAN network and performs serial communication with devices on the CAN network. In this embodiment, the CAN communication unit 11 communicates with a CAN communication unit 21 of the charging facility 2.

[0015] The WLAN communication unit 12 accesses a wireless LAN network identified by a Service Set Identifier (SSID) and performs wireless communication with devices on the wireless LAN network. In this embodiment, the WLAN communication unit 12 communicates with a WLAN communication unit 22 of the charging facility 2.

[0016] The charging equipment 2 has a high-voltage circuit 28, a high-voltage power supply 27, an equipment control unit 20, a CAN communication unit 21, and a communication unit 23. When the charging equipment 2 is connected to the vehicle 1, it charges the battery 19 of the vehicle 1. In this embodiment, the charging equipment 2 cooperates with the wireless device 3, and performs authentication with the vehicle 1 via the wireless device 3 using PnC or EIM.

[0017] When the battery 19 of the vehicle 1 is charged, the high-voltage circuit 28 is connected to the high-voltage circuit 18 of the vehicle 1 to supply power to the high-voltage circuit 28 and charge the battery 19. The high-voltage power supply 27 is connected to, for example, a commercial power system and supplies power to the high-voltage circuit 28.

[0018] The configuration of the CAN communication unit 21 is the same as that of the CAN communication unit 11 of the vehicle 1. That is, the CAN communication unit 21 communicates with the CAN communication unit 11 of the vehicle 1. The communication unit 23 communicates with the communication unit 33 of the wireless device 3. The communication between the communication unit 23 and the communication unit 33 may be wired communication or wireless communication. For example, the communication unit 23 is an interface for communication using an Inter-Integrated Circuit (I2C), a Serial Peripheral Interface (SPI), or a CAN. However, the communication unit 23 may be a wireless LAN communication interface that accesses a wireless LAN with an SSID different from that of the WLAN communication unit 32 of the wireless device 3. The communication unit 23 may also be a wireless communication interface such as Bluetooth (registered trademark), Bluetooth (registered trademark) Low Energy (BLE), etc. It may also be an interface.

[0019] The wireless device 3 has a WLAN communication unit 32 and a communication unit 33. The wireless device 3 cooperates with the charging facility 2 to assist in charging the vehicle 1. More specifically, the wireless device 3 communicates with the vehicle 1 via wireless LAN, thereby connecting the charging facility 2 and the vehicle 1 via wireless LAN. That is, the charging facility 2 communicates with the vehicle 1 via wireless LAN via the wireless device 3, and performs user authentication using PnC or EIM, billing the user for charging by the charging facility 2, and the like. The configurations and operations of the WLAN communication unit 32 and the communication unit 33 are similar to those of the WLAN communication unit 12 of the vehicle 1 and the communication unit 23 of the charging facility 2, respectively. Note that although the wireless device 3 is depicted separately from the charging facility 2 in FIG. 1 , the charging facility 2 and the wireless device 3 together can be understood as power facilities that supply power to the vehicle 1.

[0020] 2 illustrates a process in a comparative example in which the vehicle 1 is charged using both a wireless LAN and a CAN in the vehicle 1, the charging facility 2, and the wireless device 3. This process starts, for example, when the plug of the charging facility 2 is connected to the vehicle 1 (S101). When the plug of the charging facility 2 is connected to the vehicle 1, the charging control unit 10 of the vehicle 1 sends a WAKE UP frame to the charging facility 2 via the CAN. The information is transmitted to the equipment control unit 20 of the equipment 2 (S102).

[0021] Thereafter, the charging control unit 10 transmits a charging sequence selection frame to the equipment control unit 20 via the CAN (S105). Upon receiving the charging sequence selection frame, the equipment control unit 20 transmits a charging sequence selection frame response to the charging control unit 10 via the CAN (S106). The charging sequence selection frame response notifies the charging control unit 10 of SSID1, which is the SSID of the wireless LAN, and EVSEID1, which is the identification information of the charging equipment 2. The SSID is a name that identifies the wireless LAN network, and also a name that identifies the wireless LAN. It can also be said to be the identifier of the wireless device 3 that operates as an access point in the above. The above communications from S102 to S106 are executed by the CAN.

[0022] Next, the charging control unit 10 of the vehicle 1 and the wireless device 3 establish a wireless LAN link using SSID1 (S107). Once the wireless LAN link is established, the charging control unit 10 transmits a Session Discovery Protocol Request (SDPReq) to the wireless device 3 via the wireless LAN (S108). In the SDPReq, the identification information (EVSEID1) of the charging facility 2 is notified to the wireless device 3.

[0023] Upon receiving the SDPReq, the wireless device 3 sends a Session Discovery Protocol Response (S The SDPRes is returned to the charging control unit 10 (S109). The SDPRes includes the Internet Protocol (IP) address of the wireless device 3 and the upper application (or The port number that identifies the service is notified.

[0024] Thereafter, the charging control unit 10 accesses the wireless device 3 via wireless LAN using the notified IP address and port number, and establishes a TLS connection (S131). Then, a charging control signal is exchanged between the charging control unit 10 and the wireless device 3 via wireless LAN (S132). The charging control signal is transferred to the charging facility 2 via the wireless device 3, and power is transmitted from the charging facility 2 to the vehicle 1 (S133).

[0025] (First problem) Fig. 3 is a diagram illustrating a first problem in the processing of the comparative example in Fig. 2. Fig. 3 illustrates a case where attackers A1, A2, etc., to the charging system 100 interrupt the CAN communication between the vehicle 1 and the charging facility 2 and perform a man-in-the-middle attack such as obtaining information or tampering with information.

[0026] For example, an attacker A1 may physically insert a device-in-the-middle (MitM50) into the CAN communication line connecting the vehicle 1 and the charging equipment 2, and perform an attack. Alternatively, an attacker A1 may connect the MitM50 to the CAN bus connecting the vehicle 1 and the charging equipment 2, and logically interrupt the communication between the vehicle 1 and the charging equipment 2. Logical interruption means, for example, that the MitM50 acts as the charging equipment 2 with respect to the vehicle 1, and as the vehicle 1 with respect to the charging equipment 2.

[0027] When such a MitM50 is inserted between the vehicle 1 and the charging facility 2, i.e., on the CAN bus, the MitM50 intercepts the SSID (for example, value SSID1) transmitted by the charging facility 2 in the charging sequence selection frame response. Then, for example, the MitM50 tampers with the intercepted value SSID1 to value SSID2 and transmits it to the vehicle 1. As a result, the vehicle 1 connects via wireless LAN to an unauthorized wireless device 53 prepared by the attacker A1 and identified by value SSID2, instead of the legitimate wireless device 3 associated with the charging facility 2 and identified by value SSID1. As a result, there is a risk of information leakage from the vehicle 1 to the wireless device 53.

[0028] In this case, a problem occurs when, for example, the charging facility 2 and its backend server are operated without authentication using a Contract certificate or without authentication using EIM such as a Radio Frequency Identification (RFID) card. That is, if the operation is performed in a manner in which the connection destination information of the vehicle 51 is simply sent to the wireless device 3 and the vehicle 51 is charged, the attacker A2's vehicle 51 will be charged by accident. That is, if the operation is performed in a manner in which power is simply supplied from the charging facility 2A identified by the EVSEID2 received by the wireless device 3, power theft will be carried out on the vehicle 51 connected to the charging facility 2A.

[0029] (Second problem) FIG. 4 is a diagram illustrating a second problem in the processing of the comparative example in FIG. 2. FIG. 4 also illustrates a case where an attacker A of the charging system 100 uses the MitM50 to interrupt the CAN communication between the vehicle 1 and the charging facility 2 and conducts a man-in-the-middle attack, such as obtaining or falsifying information. In FIG. 4, the MitM50 intercepts the identification information (e.g., EVSEID1) of the charging facility 2 transmitted by the charging sequence selection frame response (S106 in FIG. 2). The MitM50 then alters the EVSEID1 to EVSEID2 and transmits it to the vehicle 1. However, in FIG. 4, unlike FIG. 3, the MitM50 does not alter the SSID (e.g., the value SSID1) that indicates the wireless device 3 as an access point.

[0030] Then, vehicle 1 mistakenly believes that it is connected to charging facility 2A identified by EVSEID2. As a result, vehicle 1 notifies wireless device 3 by SDPReq (S109 in FIG. 2) that it is connected to charging facility 2A identified by EVSEID2. In this case, if wireless device 3 is not notified of authentic, untampered identification information (EVSEID1 in this case) by charging facility 2, it will be difficult to detect tampering.

[0031] (Third problem) Fig. 5 is a diagram illustrating a third problem in the processing of the comparative example in Fig. 2. Fig. 5 illustrates a case where an attacker A connects a user's vehicle 1 to an unauthorized charging facility 52. ​​Here, the case where the attacker A fraudulently obtains the identification information (EVSEID1) of the charging facility 2 and the SSID (value SSID1) of the wireless device 3 via some route is illustrated. Then, the attacker A rewrites the identification information of the charging facility 52 that the attacker A owns to EVSEID1.

[0032] For example, charging equipment 52 of attacker A notifies vehicle 1 of the illegally obtained identification information (EVSEID1) of charging equipment 2 and SSID1 of wireless device 3 via CAN. Then, charging equipment 52 of attacker A connects vehicle 1 to wireless device 3 identified by SSID1 and performs a TLS handshake. As a result, vehicle 1 connects to charging equipment 52 of attacker A instead of connecting to charging equipment 2 identified by EVSEID1 as it should be, which creates the risk of power theft from vehicle 1 by charging equipment 52 of attacker A.

[0033] (Processing of the embodiment) 6 and 7 are sequence diagrams illustrating the processing of the charging system 100 of this embodiment. In this processing, the processing of S1 and S2 is the same as S101 and S102 in FIG. 2. In this embodiment, when the equipment control unit 20 of the charging equipment 2 receives a WAKE UP frame ( S2), and transmits a start notification to the wireless device 3 (S3).

[0034] When receiving the activation notification, the wireless device 3 generates a random number and responds to the charging facility 2 with the random number as EVSERandom (S4). Furthermore, the charging control unit 10 of the vehicle 1 also generates a random number EVRandom and notifies the facility control unit 20 of the charging facility 2 of the random number EVRandom by a charging sequence selection frame (S5). The processing of S5 is an example of the wireless device 3 generating random number information when the vehicle 1 is connected to the charging facility 2.

[0035] Then, the equipment control unit 20 notifies the charging control unit 10 of the charging sequence selection frame response including EVSERandom in addition to SSID1 of the wireless device 3 and identification information (EVSEID1) of the charging equipment 2 (S6). As a result, the charging control unit 10 acquires at least SSID1, which is wireless identification information for connecting to the wireless device 3, from the equipment control unit 20.

[0036] The processing of S4 and S6 is an example of the wireless device 3 generating random number information when the vehicle 1 is connected to the charging equipment 2 and notifying the generated random number information to the charging control unit 10 via the equipment control unit 20.

[0037] At this time, the equipment control unit 20 may notify the wireless device 3 of the EVRandom notified by the charging control unit 10 in S5 and the identification information (EVSEID1) of the charging equipment 2 notified to the charging control unit 10 in S6 as confirmation information (S7). The equipment identification information (EVSEID1) for identifying the charging equipment 2 notified in S7 is the identification information notified by the equipment control unit 20 to the charging control unit 10 in the processing of S6 when the vehicle 1 was connected to the charging equipment 2.

[0038] 2 , the charging control unit 10 of the vehicle 1 and the wireless device 3 establish a wireless LAN link using SSID1 (S8). When the wireless LAN link is established, the charging control unit 10 transmits a Session Discovery Protocol Request (SDPReq) to the wireless device 3 via the wireless LAN (S9). However, in this embodiment, the SDPReq notifies the wireless device 3 of the EVRandom together with the identification information (EVSEID1) of the charging facility 2. The processing of S9 is an example of wirelessly transmitting the facility identification information (EVSEID1) received from the facility control unit 20 to the wireless device 3.

[0039] Next, the wireless device 3 may verify whether the confirmation information (EVRandom and identification information (EVSEID1) of the charging facility 2) notified in S7 matches that notified in S9 (S10). If at least one of the two does not match and the verification fails (NO in S11), the wireless device 3 may execute error processing and terminate communication with the charging control unit 10 of the vehicle 1. Note that the processing in S7, S10, and S11 may be omitted.

[0040] The process of S10 is an example of wireless device 3 verifying whether or not the facility identification information (EVSEID1) notified by facility control unit 20 matches the facility identification information (EVSEID1) notified by charging control unit 10.

[0041] On the other hand, if the two match and the verification is successful (YES in S11), the wireless device 3 proceeds to the process of S12. Then, similar to S109 in Fig. 2, upon receiving the SDPReq, the wireless device 3 returns the SDPRes to the charging control unit 10 (S12).

[0042] In this embodiment, after returning SDPRes to the charging control unit 10, the wireless device 3 notifies the equipment control unit 20 of an EVRandom request (S13). Then, the equipment control unit 20 notifies the wireless device 3 of EVRandom by means of an EVRandom response (S14). The processing of S14 is an example of the equipment control unit 20 notifying the wireless device 3 of random number information generated by the charging control unit 10. The processing of S14 is also an example of the wireless device 3 acquiring the random number information generated by the charging control unit 10. The sequence of FIG. 6 continues to FIG. 7 by symbols A1, B1, and C1.

[0043] Next, a TLS handshake is performed between the charging control unit 10 of the vehicle 1 and the wireless device 3 via the wireless LAN. In the TLS handshake, first, the charging control unit 10 notifies the wireless device 3 of ClientHello (S21). Upon receiving ClientHello, the wireless device 3 returns ServerHello to the charging control unit 10. Through these processes, key exchange is performed, and thereafter, Encrypted communication is implemented.

[0044] After the ServerHello, wireless device 3 sends an EncryptedExtension message. The wireless device 3 notifies the charging control unit 10 of the obtained parameters of the wireless device 3 (S22). Here, the parameters included in the EncryptedExtension include, for example, SSID1, EVSEID1, and RandomID. The processing of S22 is not limited to processing using the EncryptedExtension message defined in TLS1.3. For example, the wireless device 3 may use, in the processing of S22, an Extension message of ServerHello defined in TLS1.2 instead of the EncryptedExtension message. The EncryptedExtension may be, for example, a combination of these bit strings. The RandomID may be, for example, EVSERandom. The RandomID may be, for example, The ID may include at least one of EVRandom and EVSERandom. Furthermore, the RandomID may be, for example, a combination of bit strings of EVRandom and EVSERandom. The EncryptedExtension message is an example of a TLS extension message.

[0045] That is, in the process of S22, the wireless device 3 includes at least SSID1, which is wireless identification information, in parameters exchanged when establishing encrypted communication with the charging control unit 10 and transmits the parameters via the wireless LAN. It can also be said that the wireless device 3 includes random number information generated by the charging control unit 10 in the parameters and transmits the parameters via the wireless LAN. It can also be said that the wireless device 3 includes random number information notified to the charging control unit 10 via the equipment control unit 20 in the parameters and transmits the random number information via the wireless LAN.

[0046] Then, the wireless device 3 transmits the SECCLeaf certificate to the charging control unit 100 via a Certificate message. The SECC Leaf certificate includes the SECC public key. After a series of TLS handshake procedures, the wireless device 3 sends a CertificateVerify message to the wireless device 10 to verify the signature. The signature is then notified to the power control unit 10 (S24). Here, the signature is a series of messages exchanged in the TLS handshake encrypted with the SECC private key.

[0047] Upon receiving the signature, the charging control unit 10 performs signature verification and additional verification using the SECC public key included in the SECCLeaf certificate (S25). In the signature verification, for example, a digest value of a series of messages in the TLS handshake to be signed is calculated, and it is verified whether the signature attached to the message is signed with the correct SECC private key for the digest value. Therefore, it is confirmed whether the charging facility 2 possesses the SECC private key.

[0048] If the signature verification and additional verification are successful (YES in S26), a TLS connection, i.e., an encrypted communication session, is established between the charging control unit 10 of the vehicle 1 and the wireless device 3 (S31). Then, the vehicle 1 and the charging facility 2 exchange a charging control signal via the wireless device 3 (S32). As a result, for example, power is transmitted from the charging facility 2 to the vehicle 1, and the battery 19 of the vehicle 1 is charged (S33).

[0049] On the other hand, if at least one of the signature verification and the additional verification in S25 fails (NO in S26), the charging control unit 10 detects fraud and executes error processing. For example, the charging control unit 10 displays the failure of the signature verification on a display device or the like and terminates the TLS communication. In this embodiment, the charging control unit 10 verifies parameters notified by the EncryptedExtension message, the ServerHello Extension message, and the like as additional verification, simultaneously with the signature verification, as follows. Note that the additional verification using these parameters is merely an example, and the following additional verification may be appropriately selected and performed in accordance with system requirements. For example, the charging control unit 10 verifies whether the SSID, which is the wireless identification information received from the equipment control unit 20 in S6, matches the SSID, which is the wireless identification information included in the parameters of the EncryptedExtension message, the ServerHello Extension message, and the like in S22. If the two do not match, the charging control unit 10 stops charging.

[0050] The charging control unit 10 also verifies whether the EVRandom notified in the charging sequence selection frame in S5 matches the EVRandom included in the RandomID included in the parameters of the EncryptedExtension, ServerHello Extension message, etc. in S22. If the two do not match, the charging control unit 10 stops charging. Similarly, the charging control unit 10 verifies whether the EVSERandom received from the equipment control unit 20 in S6 matches the EVSERandom included in the RandomID included in the parameters of the EncryptedExtension, ServerHello Extension message, etc. in S22. If the two do not match, the charging control unit 10 stops charging.

[0051] (Solution to the first problem) In this embodiment, in the TLS handshake, the wireless device 3 notifies the charging control unit 10 of the vehicle 1 of the SSID (e.g., SSID1) of the wireless LAN network formed by the wireless device 3 using an EncryptedExtension, ServerHello Extension message, or the like (S22 in FIG. 7). Next, the wireless device 3 notifies the charging control unit 10 of a signature created by encrypting the series of messages exchanged in the TLS handshake with the SECC private key (S24 in the same figure). Then, the charging control unit 10 verifies the signature with the SECC public key.

[0052] Therefore, even if an attacker A1 tampers with SSID1 of the authorized wireless device 3 in CAN communication to SSID2 of the unauthorized wireless device 53 of the attacker A1 as shown in Figure 3, the wireless device 53 cannot create a signature encrypted with the SECC private key. Therefore, if tampering by the attacker A1 occurs, the signature verification of S25 fails and the TLS communication ends. As a result, no information leakage occurs as shown in Figure 3. Similarly, even if tampering by the attacker A2 occurs, the signature verification of S25 fails and the attacker A2 cannot steal electricity.

[0053] (Solution to the second problem) The equipment control unit 20 notifies the wireless device 3 of the EVRandom received from the charging control unit 10 in the charging sequence selection frame of S5 and the EVSEID already notified to the vehicle 1 in the charging sequence selection frame response of S6 by notifying the wireless device 3 of the confirmation information of S7. Therefore, it can be said that the wireless device 3 has acquired this information in advance from the equipment control unit 20. Meanwhile, the wireless device 3 acquires the EVSEID and EVRandom already notified to the vehicle 1 from the charging equipment 2 in the charging sequence selection frame response of S6 from the vehicle 1 by the SDPReq of S9.

[0054] Here, as shown in Figure 4, attacker A uses MitM50 to intercept the identification information of charging equipment 2 (e.g., EVSEID1) sent by charging equipment 2 in the charging sequence selection frame response, and Assume that the user tampers with the ID into EVSEID2 and sends it to vehicle 1. Vehicle 1 then uses SDPReq to Even if the wireless device 3 is notified of the falsified EVSEID 2, the wireless device 3 will notify the charging facility 2. The notified identification information of the charging facility 2 (for example, EVSEID1) is stored. The device 3 can detect tampering with the identification information (for example, EVSEID1) of the charging facility 2.

[0055] (Solution to the third problem) During the TLS handshake, the wireless device 3 notifies the charging control unit 10 of the vehicle 1 of the RandomID by using an EncryptedExtension, ServerHello Extension message, or the like (S22 in FIG. 7). The RandomID includes an EVRandom that is updated with each TLS handshake. The RandomID may also include both an EVRandom and an EVSERandom. Here, it is assumed that the attacker A has somehow obtained the SSID1 of the wireless device 3 and the identification information (EVSEID1) of the charging facility 2, as shown in FIG. 5. Then, it is assumed that the charging facility 52 of the attacker A has notified the vehicle 1 of the SSID1 of the wireless device 3 and the identification information (EVSEID1) of the charging facility 2 through CAN communication, as shown in FIG. 5.

[0056] However, the charging equipment 52 of the attacker A is not connected to the wireless device 3. Therefore, the charging equipment 52 of the attacker A cannot receive the EVRandom notified in the charging sequence selection frame from the vehicle 1 (charging control unit 10) to the charging equipment 2 (equipment control unit 20). Therefore, the charging equipment 52 of the attacker A cannot hand over the EVRandom received from the vehicle 1 to the wireless device 3 in the EVRandom response of S14. Furthermore, the charging equipment 52 of the attacker A cannot receive the updated EVSERandom from the wireless device 3, and cannot hand it over to the vehicle 1 in the charging sequence selection frame response of S6. Therefore, the signature verification between the wireless device 3 and the charging control unit 10 of the vehicle 1 fails.

[0057] Therefore, as shown in Figure 5, the charging equipment 52 of the attacker A disguises itself as the legitimate charging equipment 2. Even if the vehicle 1 is connected via CAN communication, signature verification between the charging control unit 10 of the vehicle 1 and the wireless device 3 will not be successful. In other words, the signature verification in S25 will fail due to a mismatch in the EVRandom or EVSERandom included in the RandomID. Therefore, the attacker A will not be able to steal electricity using charging equipment 52 disguised as legitimate charging equipment 2, as shown in FIG. 5.

[0058] (Effects of the embodiment) The charging control unit 10 acquires at least the SSID, which is wireless identification information for connecting to the wireless device 3, from the equipment control unit 20. Then, the wireless device 3 includes at least the SSID in parameters exchanged when establishing TLS as an example of encrypted communication with the charging control unit 10, and transmits the parameters via wireless LAN. The charging control unit 10 then verifies whether the SSID acquired from the equipment control unit 20 matches the SSID included in the parameters, and stops charging if they do not match.

[0059] Therefore, the charging system 100 prevents an unauthorized attacker A or the like from tampering with the SSID in CAN communication, which is an example of wired communication, and connecting the vehicle 1 to an access point identified by a fake SSID. As a result, the charging system 100 can prevent acts such as leaking information using an existing EVSEID and SSID or stealing electricity. In other words, the charging system 100 can safely use both wired communication and wireless LAN communication between the vehicle 1 and the charging facility 2 and safely establish encrypted communication (TLS) via wireless communication.

[0060] Furthermore, the wireless device 3 generates random number information (EVSERandom) when the vehicle 1 is connected to the charging facility 2. The wireless device 3 then notifies the generated random number information to the charging control unit 10 via the facility control unit 20, and transmits the random number information to the charging control unit 10 via wireless LAN, with the random number information included in a parameter. Meanwhile, the charging control unit 10 verifies whether the random number information notified via the facility control unit 20 matches the random number information included in the parameter, and if the verification fails, stops the charging. Therefore, the charging system 100 can safely use both wired communication and wireless LAN communication between the vehicle 1 and the charging facility 2, and can eliminate unauthorized charging.

[0061] Furthermore, the charging control unit 10 generates random number information (EVRandom) when the vehicle 1 is connected to the charging facility 2. Then, the facility control unit 20 notifies the wireless device 3 of the random number information (EVRandom) generated by the charging control unit 10. Meanwhile, the wireless device 3 acquires the random number information generated by the charging control unit 10, includes the acquired random number information in parameters, and transmits the parameters to the charging control unit 10 via wireless LAN. The charging control unit 10 then verifies whether the random number information notified to the wireless device 3 via the facility control unit 20 matches the random number information included in the parameters, and stops charging if the verification fails. Therefore, the charging system 100 can safely use both wired communication and wireless LAN communication between the vehicle 1 and the charging facility 2 and eliminate unauthorized charging.

[0062] Furthermore, when the vehicle 1 is connected to the charging facility 2, the facility control unit 20 notifies the charging control unit 10 of facility identification information (EVSEID) that identifies the charging facility 2, and notifies the wireless device 3 of the facility identification information (EVSEID). Then, when connecting to the wireless device 3, the charging control unit 10 wirelessly transmits the facility identification information received from the facility control unit 20 to the wireless device 3. Meanwhile, the wireless device 3 verifies whether the facility identification information notified from the facility control unit 20 matches the facility identification information transmitted from the charging control unit 10, and if the verification fails, stops communication with the charging control unit 10. Therefore, the charging system 100 can safely use both wired communication and wireless LAN communication between the vehicle 1 and the charging facility 2.

[0063] In this embodiment, encrypted communication follows the TLS procedure, and parameters exchanged when establishing TLS are transmitted by TLS extension messages. That is, the charging system 100 can safely use both wired communication and wireless LAN communication by utilizing the TLS mechanism.

[0064] For example, the wireless device 3 creates a signature by encrypting information including parameters to be exchanged to establish TLS with a private key. Meanwhile, the charging control unit 10 verifies the signature with a public key corresponding to the private key. Therefore, the charging system 100 can safely establish TLS by utilizing the signature and control charging through V2G communication.

[0065] (Computer-readable recording medium) A program that causes a computer or other machine or device (hereinafter referred to as a computer, etc.) to realize any of the above functions can be recorded on a computer-readable recording medium. Then, by having the computer, etc. read and execute the program from this recording medium, the function can be provided.

[0066] Here, a computer-readable recording medium refers to a recording medium that stores information such as data and programs electrically, magnetically, optically, mechanically, or chemically and can be read by a computer. Among such recording media, those that can be removed from a computer include, for example, flexible disks, magneto-optical disks, CD-ROMs, CD-R / Ws, DVDs, Blu-ray disks, and memory cards such as flash memory. Furthermore, recording media that are fixed to a computer include hard disks and ROMs (read-only memories). Furthermore, SSDs (Solid State Drives) are The recording medium can be used as a recording medium that can be removed from a computer or the like, or as a recording medium that is fixed to a computer or the like. [Explanation of symbols]

[0067] 1 vehicle 2 Charging equipment 3 Radio equipment 10 Charging control unit 11 CAN communication section 12 WLAN communication unit 18 High-voltage circuit 19 Battery 20 Equipment Control Section 21 CAN communication section 23 Communications Department 27 High voltage power supply 28 High-voltage circuit 32 WLAN communication unit 33 Communications Department

Claims

1. A charging system including: a charging control unit mounted on a vehicle and controlling charging of the vehicle; an equipment control unit connected to the charging control unit by a wire and controlling charging equipment that charges the vehicle; and a wireless device connected wirelessly to the charging control unit, the charging control unit acquires, from the facility control unit, at least wireless identification information for connecting to the wireless device; the wireless device wirelessly transmits the wireless identification information included in parameters exchanged when establishing encrypted communication with the charging control unit; The charging control unit verifies whether the wireless identification information acquired from the equipment control unit matches the wireless identification information included in the parameters, and stops the charging if they do not match.

2. the wireless device generates random number information when the vehicle is connected to the charging facility, notifies the charging control unit via the facility control unit of the generated random number information, and includes the random number information in the parameter and transmits the parameter to the charging control unit wirelessly; 2. The charging system according to claim 1, wherein the charging control unit verifies whether the random number information notified via the equipment control unit matches the random number information included in the parameter, and if the verification fails, stops the charging.

3. the charging control unit generates random number information when the vehicle is connected to the charging facility; the facility control unit notifies the wireless device of the random number information generated by the charging control unit; the wireless device acquires the random number information generated by the charging control unit, includes the acquired random number information in the parameter, and transmits the parameter to the charging control unit wirelessly; 2. The charging system of claim 1, wherein the charging control unit verifies whether the random number information notified to the wireless device via the equipment control unit matches the random number information included in the parameters, and if the verification fails, stops the charging.

4. the facility control unit notifies the charging control unit of facility identification information that identifies the charging facility when the vehicle is connected to the charging facility, and notifies the wireless device of the facility identification information; the charging control unit wirelessly transmits the equipment identification information received from the equipment control unit to the wireless device; 2. The charging system according to claim 1, wherein the wireless device verifies whether the equipment identification information notified from the equipment control unit matches the equipment identification information transmitted from the charging control unit, and if the verification fails, stops communication with the charging control unit.

5. The encrypted communication follows the Transport Layer Security (TLS) procedure; The charging system according to claim 1 , wherein the parameter is transmitted by an extension message of the TLS.

6. the wireless device creates a signature by encrypting information including the parameters exchanged to establish the encrypted communication with a private key; The charging system according to claim 1 , wherein the charging control unit verifies the signature using a public key corresponding to the private key.

7. A charging control unit controls charging of a vehicle from a charging facility including an equipment control unit connected by wire to a charging control unit mounted on the vehicle and a wireless device connected wirelessly to the charging control unit. So, acquiring wireless identification information for connecting to the wireless device from the equipment control unit and connecting to the wireless device; When establishing encrypted communication with the wireless device, the encrypted communication is established by exchanging parameters including at least the wireless identification information with the wireless device; A charging control unit including a controller that verifies whether the wireless identification information received from the equipment control unit matches the wireless identification information included in the parameters, and stops controlling the charging if they do not match.

8. a controller that controls charging of the vehicle from a charging facility including an equipment control unit that is connected by wire to a charging control unit mounted on the vehicle and a wireless device that is connected wirelessly to the charging control unit; acquiring wireless identification information for connecting to the wireless device from the equipment control unit and connecting to the wireless device; When establishing encrypted communication with the wireless device, the encrypted communication is established by exchanging parameters including at least the wireless identification information with the wireless device; A program for verifying whether the wireless identification information received from the equipment control unit matches the wireless identification information included in the parameters, and for stopping control of the charging if they do not match.

Citation Information

Patent Citations

  • Wired / wireless composite communication system and wired / wireless composite communication method

    JP2019047216A