Vehicle system, charge control device, and program

The vehicle system uses a dual control device setup with a private key and public key system to verify identification, preventing unauthorized charging of stolen electric vehicles by ensuring only authorized users can initiate charging.

JP2026023029APending Publication Date: 2026-02-13DENSO TEN LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024124719
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-31
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing PnC systems for electric vehicles do not adequately prevent charging when the vehicle itself is stolen, as mutual authentication between the charging ECU and another ECU can still succeed, allowing unauthorized charging.

Method used

A vehicle system with a first control device and a second control device that communicate to verify identification information, preventing charging if the information does not match, using a private key and public key system to generate and verify signature data.

Benefits of technology

Prevents unauthorized charging of stolen electric vehicles by ensuring that only authorized users can initiate charging, thereby safeguarding against theft-related financial losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026023029000001_ABST
    Figure 2026023029000001_ABST
Patent Text Reader

Abstract

To prevent an electric vehicle from being charged when the electric vehicle is stolen.SOLUTION: A vehicle system according to an embodiment controls charging of a battery mounted on an electric vehicle. The vehicle system includes a first control device and a second control device. The second control device is configured to communicate with the first control device. The first control device receives the first identification information, and transmits data including the first identification information to the second control device when the battery is charged. The second control device stores the second identification information in advance, and does not charge the battery when the first identification information received from the first control device does not match the second identification information after detecting the charging start operation of the battery.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a vehicle system, a charge control device, and a program. [Background technology]

[0002] A known technology for charging the battery of an electric vehicle is the PnC (Plug and Charge) method. With PnC, when a charging plug is connected to a charging port of an electric vehicle, authentication, billing, and the start of charging are performed automatically using authentication information such as a contract in the charging ECU (Electronic Control Unit) of the electric vehicle.

[0003] Therefore, if the charging ECU of an electric vehicle is stolen and attached to another electric vehicle, and the other electric vehicle is charged using the PnC system, there is a risk that the user whose charging ECU was stolen will be charged. Therefore, measures against theft are desirable for electric vehicles that can be charged using the PnC system.

[0004] Patent Document 1 discloses a technology in which a master ECU and another general ECU mounted on a vehicle perform mutual authentication processing, and if the authentication fails, the processing is stopped. By using this technology, an electric vehicle can perform authentication processing between a charging ECU and another ECU, and prohibit charging using the PnC method if the authentication fails. In other words, an electric vehicle using the technology of Patent Document 1 can prevent charging using the PnC method if the charging ECU is fraudulently replaced. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2017-79369 Summary of the Invention [Problem to be solved by the invention]

[0006] However, with the above technology, if the electric vehicle itself is stolen, mutual authentication between the charging ECU and another ECU is successful, so there is a risk that charging using the PnC method will be performed on the stolen electric vehicle.

[0007] The present invention has been made in view of the above, and has an object to prevent charging of an electric vehicle when the electric vehicle is stolen. [Means for solving the problem]

[0008] A vehicle system according to one aspect of the embodiment controls charging of a battery mounted on an electric vehicle. The vehicle system includes a first control device and a second control device. The second control device is capable of communicating with the first control device. The first control device receives first identification information, and when the battery is to be charged, transmits data including the first identification information to the second control device. The second control device pre-stores the second identification information, and after detecting a battery charging start operation, does not charge the battery if the first identification information received from the first control device does not match the second identification information. [Effects of the Invention]

[0009] In the vehicle system according to the embodiment, if an electric vehicle is stolen, the first identification information cannot be received from the authorized user of the electric vehicle, and therefore the first identification information and the second identification information do not match. Therefore, if the first identification information and the second identification information do not match, the vehicle system does not charge the battery, thereby preventing charging of the battery if the electric vehicle is stolen. [Brief explanation of the drawings]

[0010] [Figure 1] FIG. 1 is a diagram illustrating battery charging using the PnC method. [Figure 2] FIG. 2 is a block diagram illustrating the vehicle system according to the first embodiment. [Figure 3] FIG. 3 is a flowchart illustrating the signature data generation process executed by the vehicle control device according to the first embodiment. [Figure 4] FIG. 4 is a flowchart illustrating the charge control process executed by the charge control device according to the first embodiment. [Figure 5] FIG. 5 is a flowchart illustrating the signature data generation process according to the second embodiment. [Figure 6] FIG. 6 is a flowchart illustrating a signature data generation process according to a modification of the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0011] Hereinafter, a vehicle system, a charging control device, and a program according to an embodiment will be described in detail with reference to the accompanying drawings. However, the present invention is not limited to the embodiment.

[0012] (First embodiment) A vehicle system 1 (see FIG. 2) according to the first embodiment is mounted on an electric vehicle 100 shown in FIG. 1. The electric vehicle 100 is a vehicle that can run using driving force generated by a motor. The electric vehicle 100 includes a plug-in hybrid vehicle. The electric vehicle 100 can charge its battery 101 by receiving power from a charging station 200 and charging equipment installed in a home or the like. FIG. 1 is a diagram illustrating charging of the battery 101 using the PnC system.

[0013] When charging the battery 101 of the electric vehicle 100 at the charging station 200, the charging can be performed by the PnC method. When charging the battery 101 of the electric vehicle 100 by the PnC method, charging starts when a charging plug 201 provided on the charging station 200 is connected to a charging port 102 of the electric vehicle 100.

[0014] Specifically, when charging plug 201 is connected to charging port 102, authentication information such as a Contract document stored in charging control device 3 of electric vehicle 100 is transmitted to charging station 200 via charging port 102, where authentication is performed and charging begins. Information on the fee for charging battery 101 is transmitted together with the authentication information via network N to, for example, server device 300. Then, based on the information stored in server device 300, the fee is billed to the user of electric vehicle 100 identified by the authentication information.

[0015] If the charge control device 3 of the electric vehicle 100 is stolen and attached to another electric vehicle, and charging is performed by the other electric vehicle using the PnC system, a charging fee will be charged based on the authentication information stored in the charge control device 3. Therefore, there is a risk that the user whose charge control device 3 was stolen will be charged the charging fee. Furthermore, if the electric vehicle 100 itself is stolen, there is a risk that the user whose electric vehicle 100 was stolen will be charged the charging fee.

[0016] The vehicle system 1 according to the first embodiment aims to prevent charging by the PnC method when the charge control device 3 or the electric vehicle 100 is stolen. The vehicle system 1 according to the first embodiment will be described in detail below.

[0017] As shown in FIG. 2, the vehicle system 1 includes a vehicle control device 2 (first control device) and a charge control device 3 (second control device) different from the vehicle control device 2. FIG. 2 is a block diagram illustrating the vehicle system 1 according to the first embodiment. The vehicle control device 2 and the charge control device 3 are capable of communicating with each other. The vehicle control device 2 and the charge control device 3 are mounted on an electrically powered vehicle 100 and are capable of communicating with each other via an in-vehicle network. The in-vehicle network includes, for example, a CAN (Controller Area Network) and an AVCLAN (Audio Visual Communication Local Area Network).

[0018] The vehicle control device 2 is capable of communicating with devices external to the electric vehicle 100, such as a mobile terminal. The vehicle control device 2 includes a communication unit 10, a controller 11, and a storage unit 12.

[0019] The communication unit 10 communicates data with, for example, a user's mobile terminal. The communication unit 10 is, for example, an in-vehicle communication module capable of wireless communication. The wireless communication is performed by, for example, Wi-Fi (registered trademark), LTE (Long Term Evolution), BLE (Bluetooth (registered trademark) Low Energy), Zigbee (registered trademark), UWB (Ultra Wide Band), etc.

[0020] The storage unit 12 is realized by a storage device such as a ROM (Read Only Memory), a RAM (Random Access Memory), or a flash memory. The storage unit 12 stores various data and programs. The storage unit 12 stores a hash function. The storage unit 12 includes a secure area. The secure area is, for example, a TPM (Trusted Platform Module) that stores a private key.

[0021] The controller 11 corresponds to a so-called processor. The controller 11 is realized by a CPU (Central Processing Unit), an MPU (Micro Processing Unit), a GPU (Graphical Processing Unit), or the like. The controller 11 executes a program according to an embodiment (not shown) stored in the storage unit 12, using RAM as a work area. The controller 11 can also be realized by an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).

[0022] Controller 11 is capable of generating keys. Specifically, controller 11 generates a private key and a public key. For example, controller 11 can generate a private key and a public key in advance preparations such as a manufacturing process in a factory where electric vehicle 100 is manufactured. For example, controller 11 generates a private key and a public key through a setting operation by an administrator or the like in advance preparations.

[0023] The generated private key is stored in a secure area of ​​the storage unit 12 of the vehicle control device 2. The generated public key is transmitted to the charge control device 3 and stored in a secure area of ​​the storage unit 21 of the charge control device 3. The private key and the public key may be generated by an external device.

[0024] The charge control device 3 includes a controller 20 and a storage unit 21. The charge control device 3 controls charging of the battery 101 (see FIG. 1) of the electric vehicle 100 when the battery 101 is charged by the PnC system.

[0025] The storage unit 21 is realized by a storage device such as a ROM, a RAM, or a flash memory. Various data and programs are stored in the storage unit 21. The storage unit 21 stores a hash function. The hash function stored in the storage unit 21 is the same as the hash function stored in the storage unit 12 of the vehicle control device 2.

[0026] The storage unit 21 includes a secure area. The secure area is, for example, a TPM. The secure area stores a public key received from the vehicle control device 2. The secure area also stores user authentication information (second identification information) of the user. The user authentication information may be stored in a part of the storage unit 21 other than the secure area. The user authentication information is an identifier that identifies the user, for example, a user ID (Identification). The user authentication information is set, for example, when the user signs a contract to enable charging using the PnC method, and is stored in the storage unit 21. Hereinafter, the user authentication information will be referred to as "user identification information." The secure area also stores authentication information such as a contract agreement.

[0027] The controller 20 corresponds to a processor. The controller 20 is realized by a CPU, an MPU, a GPU, or the like. The controller 20 executes a program according to an embodiment (not shown) stored in the storage unit 21, using RAM as a work area. The controller 20 can also be realized by an integrated circuit such as an ASIC or an FPGA.

[0028] When charging by the PnC system, the controller 20 transmits the authentication information stored in the storage unit 21 to the charging station 200 (see FIG. 1) via the charging port 102 (see FIG. 1).

[0029] Next, a description will be given of a method for controlling charging by the PnC system in the vehicle system 1. Note that the vehicle control device 2 stores a private key, and the charging control device 3 stores a public key and user identification information.

[0030] First, the signature data generation process executed by the vehicle control device 2 will be described with reference to Fig. 3. Fig. 3 is a flowchart illustrating the signature data generation process executed by the vehicle control device 2 according to the first embodiment. The signature data generation process is performed at every first processing cycle that is set in advance.

[0031] The controller 11 determines whether or not identification information (first identification information) has been received (S100). The identification information is transmitted, for example, from a mobile terminal of a charger who will be charging the battery 101 of the electric vehicle 100 by the PnC system, as preparation for charging the battery 101 of the electric vehicle 100 by the PnC system. The identification information is transmitted from the mobile terminal of the charger to the vehicle control device 2 when an operation for transmitting the identification information is performed on the mobile terminal of the charger. The identification information is received by the communication unit 10 of the vehicle control device 2. The controller 11 receives the identification information when the battery 101 is being charged. Specifically, the controller 11 receives user identification information from the charger every time the battery 101 is being charged by the PnC system.

[0032] The charger is the authorized user when the authorized user of electric vehicle 100 charges the vehicle. The charger is also the third party when, for example, electric vehicle 100 is stolen and charging is performed by a third party other than the authorized user.

[0033] The identification information may be received from a device other than a mobile terminal. For example, the identification information may be input by a user via a car navigation system installed in the electric vehicle 100.

[0034] If the controller 11 determines that the identification information has not been received (S100: No), the controller 11 ends the current processing.

[0035] When the controller 11 determines that the identification information has been received (S100: Yes), the controller 11 stores the received identification information in the storage unit 12 (S101).

[0036] Next, the controller 11 determines whether a predetermined time has elapsed since receiving the identification information (S102). The predetermined time is a preset time, which is a preparation time for the user to start charging at the charging station 200. The predetermined time is, for example, several minutes.

[0037] When the controller 11 determines that the predetermined time has not elapsed (S102: No), the controller 11 determines whether or not verification data has been received from the charge control device 3 (S103). The verification data is, for example, a random number. Note that the verification data is not limited to a random number, and may be any data that cannot be guessed by a third party other than the authorized user of the electric vehicle 100. When the controller 11 receives the verification data, the controller 11 determines that information regarding the charging start operation of the battery 101 has been received.

[0038] If the controller 11 determines that the verification data has not been received (S103: No), the controller 11 returns to step S102 and repeats the above process. If the verification data has not been received, the controller 11 determines that the information regarding the charging start operation of the battery 101 has not been received.

[0039] When it is determined that the verification data has been received (S103: Yes), the controller 11 generates signature data (S104). Specifically, the controller 11 generates the signature data using a private key from the verification data transmitted from the charging control device 3 and the identification information received from the charger.

[0040] For example, the controller 11 calculates a hash value from the verification data and the identification information using a hash function. Then, the controller 11 encrypts the calculated hash value using a private key to generate signature data. Note that the controller 11 may also generate signature data from the verification data using a private key.

[0041] Next, the controller 11 transmits the generated signature data and the identification information received from the charger to the charging control device 3 (S105). That is, the controller 11 transmits data including the identification information to the charging control device 3 via the in-vehicle network. The controller 11 transmits the identification information to the charging control device 3 via a communication path different from the communication path of the PnC system in the charging station 200.

[0042] The vehicle system 1 can increase the validity of the identification information transmitted to the charging control device 3 by transmitting the identification information to the charging control device 3 via a communication path different from the PnC communication path in the charging station 200. Specifically, the vehicle system 1 can increase the validity of the identification information transmitted to the charging control device 3 by transmitting the identification information to the charging control device 3 via the vehicle control device 2.

[0043] Next, the controller 11 erases the identification information stored in step S101 from the storage unit 12 (S106).

[0044] If the controller 11 determines that the predetermined time has elapsed (S102: Yes), it erases the identification information stored in step S101 from the storage unit 12 (S106). That is, if the controller 11 does not receive verification data within the predetermined time, it erases the identification information from the storage unit 12.

[0045] Next, the charge control process executed by the charge control device 3 will be described with reference to Fig. 4. Fig. 4 is a flowchart illustrating the charge control process executed by the charge control device 3 according to the first embodiment. The charge control process is performed at every second process cycle set in advance.

[0046] The controller 20 determines whether the charging plug 201 of the charging station 200 that performs PnC charging is connected to the charging port 102 of the electric vehicle 100 (S200). The controller 20, for example, detects the type of the connected charging plug 201 and determines whether the charging plug 201 of the charging station 200 that performs PnC charging is connected. When the charging plug 201 of the charging station 200 that performs PnC charging is connected to the charging port 102 of the electric vehicle 100, the controller 20 determines that it has detected an operation to start charging the battery 101. When the charging plug 201 of the charging station 200 that performs PnC charging is not connected to the charging port 102 of the electric vehicle 100, the controller 20 determines that it has not detected an operation to start charging the battery 101.

[0047] When the controller 20 determines that the charging plug 201 of the charging station 200 that performs PnC charging is not connected to the charging port 102 of the electric vehicle 100 (S200: No), the controller 20 ends the current processing.

[0048] When the controller 20 determines that the charging plug 201 of the charging station 200 that performs PnC charging is connected to the charging port 102 of the electric vehicle 100 (S200: Yes), the controller 20 generates verification data (S201). For example, the controller 20 generates a random number and sets the generated random number as the verification data.

[0049] Next, the controller 20 transmits the generated verification data to the vehicle control device 2 (S202). Upon receiving this verification data, the vehicle control device 2 transmits the signature data and the identification information to the charge control device 3 in step S105 of FIG. 3. Next, the controller 20 determines whether or not the signature data and the identification information have been received from the vehicle control device 2 (S203). If the controller 20 determines that the signature data and the identification information have not been received (S203: No), the controller 20 repeats the processing of step S203.

[0050] When the controller 20 determines that the signature data and the identification information have been received (S203: Yes), the controller 20 determines whether the identification information matches (S204). Specifically, the controller 20 determines whether the identification information (first identification information) received from the vehicle control device 2 matches the user identification information (second identification information) stored in the storage unit 21 of the charge control device 3.

[0051] If the electric vehicle 100 is stolen and identification information is sent to the vehicle control device 2 from a third party who is not the authorized user of the electric vehicle 100, the identification information received from the vehicle control device 2 will not match the user identification information stored in the storage unit 21 of the charging control device 3. Therefore, if the controller 20 determines that the identification information does not match (S204: No), the controller 20 determines that the electric vehicle 100 has been stolen. Therefore, if the controller 20 determines that the identification information does not match (S204: No), it does not start charging the battery 101 using the PnC method, issues a notice to the effect that charging using the PnC method will be stopped (S205), and ends the processing. In other words, charging of the battery 101 using the PnC method is prohibited.

[0052] This allows the vehicle system 1 to prevent charging by the PnC method when the electric vehicle 100 is stolen.

[0053] When identification information is transmitted to the vehicle control device 2 from a legitimate user of the electric vehicle 100, the identification information received from the vehicle control device 2 matches the user identification information stored in the storage unit 21 of the charging control device 3. Therefore, when the controller 20 determines that the identification information matches, it determines that the electric vehicle 100 has not been stolen. When the controller 20 determines that the identification information matches (S204: Yes), it verifies the signature data (S206). The controller 20 verifies the signature data using the public key. The controller 20 verifies the signature data using the verification data of the charging control device 3 and the public key.

[0054] Specifically, the controller 20 decrypts the received signature data using the public key. If the controller 20 can decrypt the received signature data using the public key, the controller 20 calculates a hash value using a hash function from the verification data generated in step S201 and the user identification information stored in the storage unit 21 of the charging control device 3. Then, the controller 20 verifies the signature data by comparing the hash value obtained by decryption with the calculated hash value. Note that the controller 20 may verify the signature data depending on whether the signature data can be decrypted using the public key.

[0055] Next, the controller 20 determines whether the signature data is correct (S207). If the hash value obtained by decryption matches the calculated hash value, the controller 20 determines that the signature data is correct. Specifically, if the hash value obtained by decryption matches the calculated hash value, the controller 20 determines that the charging control device 3 has not been stolen or replaced. If the hash value obtained by decryption matches the calculated hash value, the controller 20 may determine that the vehicle control device 2 has not been stolen or replaced. Note that the controller 20 may determine that the signature data is correct if the signature data can be decrypted using the public key.

[0056] If the controller 20 determines that the hash value obtained by decryption does not match the calculated hash value, the controller 20 determines that the signature data is incorrect. Specifically, if the hash value obtained by decryption does not match the calculated hash value, the controller 20 determines that the charging control device 3 has been stolen and replaced. If the hash value obtained by decryption does not match the calculated hash value, the controller 20 may determine that the vehicle control device 2 has been stolen and replaced. Note that the controller 20 may also determine that the signature data is incorrect if the signature data cannot be decrypted using the public key.

[0057] If the controller 20 determines that the signature data is incorrect (S207: No), the controller 20 does not charge the battery 101 by the PnC method, and proceeds to step S205.

[0058] If the signature data is incorrect, the vehicle system 1 does not charge the battery 101 by the PnC method, in other words, prohibits the charging of the battery 101 by the PnC method. This allows the vehicle system 1 to prevent charging by the PnC method in another electric vehicle to which the charge control device 3 has been replaced.

[0059] When the controller 20 determines that the signature data is correct (S207: Yes), it charges the battery 101 by the PnC method (S208). In other words, it permits charging of the battery 101 by the PnC method. That is, when the identification information received from the vehicle control device 2 matches the user identification information stored in the storage unit 21 of the charging control device 3 (S204: Yes) and the signature data is correct (S207: Yes), the controller 20 charges the battery 101 by the PnC method.

[0060] This allows the authorized user of the electric vehicle 100 to charge the battery 101 using the PnC system.

[0061] If the electric vehicle 100 is stolen by a third party who is not the authorized user of the electric vehicle 100 and the third party attempts to charge the battery 101 using the PnC method but is unable to transmit the identification information, the controller 11 terminates the process without generating signature data. In this case, the electric vehicle 100 is not charged using the PnC method. In this way, the controller 11 can determine whether the electric vehicle 100 has been stolen by receiving the identification information when the battery 101 is being charged. Therefore, the vehicle system 1 can prevent charging using the PnC method when the electric vehicle 100 has been stolen.

[0062] Furthermore, if a third party transmits identification information that differs from the user identification information of a legitimate user, the transmitted identification information will not match the user identification information stored in the storage unit 21 of the charging control device 3. In this case, charging by the PnC method is not performed in the electric vehicle 100. Therefore, the vehicle system 1 can prevent charging by the PnC method when the electric vehicle 100 is stolen.

[0063] The vehicle system 1 can determine whether the signature data transmitted from the vehicle control device 2 is valid by using the verification data and the public key of the charge control device 3. Therefore, if the charge control device 3 is stolen and replaced with another electric vehicle, the vehicle system 1 can detect the replacement of the charge control device 3.

[0064] Next, a vehicle system 1 according to a modified example will be described.

[0065] The private key and the public key may be hash functions. In this case, the controller 11 of the vehicle control device 2 generates, as signature data, a hash value calculated using the private key from the verification data and the received identification information, for example.

[0066] Furthermore, the controller 20 of the charge control device 3 calculates a hash value using the public key from the verification data and the user identification information stored in the storage unit 21. The controller 20 verifies the signature data by comparing the hash value received as the signature data with the hash value calculated using the public key.

[0067] Then, if the hash value received as the signature data matches the hash value calculated using the public key, the controller 20 determines that the signature data is correct. On the other hand, if the hash value received as the signature data does not match the hash value calculated using the public key, the controller 20 determines that the signature data is incorrect. The vehicle system 1 may determine the authenticity of the signature data in this manner.

[0068] When the charging control device 3 determines that the received identification information does not match the stored user identification information a predetermined first predetermined number of times, the charging control device 3 may delete the public key stored in the storage unit 21. When the charging control device 3 determines that the received identification information does not match the stored user identification information a predetermined number of times in succession, the charging control device 3 may delete the public key stored in the storage unit 21. As a result, the signature data cannot be verified in the electric vehicle 100 having the charging control device 3 from which the public key has been deleted, and charging of the battery 101 by the PnC method is completely prevented.

[0069] Furthermore, when it is determined that the received identification information does not match the stored user identification information a first predetermined number of times, the charging control device 3 may transmit information related to the theft notification to the vehicle control device 2. The vehicle control device 2 transmits the information related to the theft notification via the communication unit 10 to an external management device that manages the theft information.

[0070] Furthermore, if the charge control device 3 determines that the signature data is incorrect a preset second predetermined number of times, it may delete the public key stored in the storage unit 21. If the charge control device 3 determines that the signature data is incorrect a second predetermined number of times in succession, it may delete the public key stored in the storage unit 21. As a result, in an electric vehicle 100 having a charge control device 3 from which the public key has been deleted, it is not possible to verify the signature data, and charging of the battery 101 by the PnC method is completely prevented. The second predetermined number of times and the first predetermined number of times may be the same value or different values.

[0071] Furthermore, if the charging control device 3 determines that the signature data is incorrect a second predetermined number of times, the charging control device 3 may transmit information related to the theft notification to the vehicle control device 2. The vehicle control device 2 transmits the information related to the theft notification via the communication unit 10 to an external management device that manages theft information.

[0072] (Second embodiment) In the first embodiment described above, the user needs to transmit identification information (first identification information) to the vehicle control device 2 every time charging is performed using the PnC method. This may be bothersome to the user. Therefore, in the second embodiment, user identification information (first identification information) that is the same data as the user identification information (second identification information) that is pre-stored in the charging control device 3 is pre-stored in the vehicle control device 2, and when charging is performed using the PnC method, the vehicle control device 2 transmits the user identification information together with signature data to the charging control device 3. For example, when storing the user identification information, the charging control device 3 receives the user identification information from the user's mobile terminal or the like and stores the received user identification information.

[0073] This eliminates the inconvenience to the user when the user charges, because the user identification information is automatically transmitted from the vehicle control device 2 to the charge control device 3. However, in this case, if the electric vehicle 100 is stolen, the thief will be allowed to charge the vehicle using the PnC system.

[0074] Therefore, in the second embodiment, the vehicle control device 2 pre-stores user identification information that is the same data as the user identification information stored in the charge control device 3, and when charging by the PnC system is performed, the vehicle control device 2 transmits the user identification information to the charge control device 3 together with signature data. Then, when the vehicle control device 2 detects that the electric vehicle 100 has been stolen, it rewrites the stored user identification information to other identification information (third identification information) that is different from the user identification information. There are no particular limitations on the method for detecting theft of the electric vehicle 100, and for example, the vehicle control device 2 may detect the theft of the electric vehicle 100 when it receives a notification from the user that the electric vehicle 100 has been stolen. Alternatively, if an anti-theft device is installed in the electric vehicle 100, the anti-theft device may notify the vehicle control device 2 of the vehicle theft when it detects the theft of the electric vehicle 100.

[0075] This configuration can eliminate the inconvenience to the user and prevent the thief from charging the electric vehicle 100 by the PnC system if the vehicle is stolen.

[0076] The signature data generation process executed by the vehicle control device 2 according to the second embodiment will be described with reference to Fig. 5. Fig. 5 is a flowchart illustrating the signature data generation process according to the second embodiment. Here, the process that differs from the first embodiment will be described, and a description of the process that is the same as the first embodiment will be omitted.

[0077] The controller 11 determines whether or not the electric vehicle 100 has been stolen (S300). For example, when the controller 11 receives a notification from the user that the electric vehicle 100 has been stolen, the controller 11 determines that the electric vehicle 100 has been stolen. When the controller 11 does not receive a notification from the user that the electric vehicle 100 has been stolen, the controller 11 determines that the electric vehicle 100 has not been stolen.

[0078] If the controller 11 determines that the electric vehicle 100 has not been stolen (S300: No), the process proceeds to step S302. If the controller 11 determines that the electric vehicle 100 has been stolen (S300: Yes), the controller 11 rewrites the user identification information stored in the vehicle control device 2 to other identification information (S301).

[0079] After rewriting the identification information to other identification information, the controller 11 skips the processes of steps S300 and S301.

[0080] Next, the controller 11 determines whether or not the charging plug 201 of the charging station 200 that performs charging according to the PnC system is connected to the charging port 102 of the electric vehicle 100 (S302).

[0081] If the controller 11 determines that the charging plug 201 is not connected to the charging port 102 of the electric vehicle 100 (S302: No), the controller 11 ends the current processing.

[0082] When the controller 11 determines that the charging plug 201 is connected to the charging port 102 of the electric vehicle 100 (S302: Yes), the controller 11 determines whether a predetermined time has elapsed since the charging plug 201 was connected to the charging port 102 (S303).

[0083] When it is determined that the predetermined time has not elapsed (S303: No), the controller 11 determines whether or not verification data has been received from the charge control device 3 (S103).

[0084] If the controller 11 determines that the predetermined time has elapsed (S303: Yes), it ends the current processing.

[0085] When generating the signature data in step S104, the controller 11 generates the signature data from the verification data transmitted from the charging control device 3 and the identification information stored in the vehicle control device 2 using a private key.

[0086] Therefore, if the identification information stored in the vehicle control device 2 is user identification information, the controller 11 generates signature data using a private key from the verification data and the user identification information. Also, if the identification information stored in the vehicle control device 2 is other identification information than user identification information, the controller 11 generates signature data using a private key from the verification data and the other identification information. Therefore, if it is determined that the electric vehicle 100 has been stolen, signature data different from the signature data generated using the user identification information is generated.

[0087] After step S104, the controller 11 transmits the generated signature data and identification information to the charging control device 3 (S304). If the identification information stored in the vehicle control device 2 is user identification information, the controller 11 transmits the signature data and the user identification information to the charging control device 3. If the identification information stored in the vehicle control device 2 is other identification information than user identification information, the controller 11 transmits the signature data and other identification information to the charging control device 3. In other words, if it is determined that the electric vehicle 100 has been stolen, the controller 11 transmits other identification information different from the user identification information to the charging control device 3.

[0088] After transmitting the signature data and the identification information to the charge control device 3, the controller 11 ends the process.

[0089] The vehicle control device 2 stores user identification information, and when charging by the PnC method, transmits the stored user identification information together with signature data to the charging control device 3. This allows the user of the electric vehicle 100 to easily charge by the PnC method without having to transmit user identification information to the vehicle control device 2 every time charging is performed by the PnC method.

[0090] If the electric vehicle 100 is stolen, the vehicle control device 2 rewrites the stored user identification information to other identification information, and when charging by the PnC method is to be performed, transmits the other identification information to the charging control device 3. As a result, the user identification information stored in the charging control device 3 does not match the other identification information transmitted from the vehicle control device 2, and charging by the PnC method is not performed. In other words, if the electric vehicle 100 is stolen, by rewriting the user identification information to other identification information, it is possible to prevent charging by the PnC method in the stolen electric vehicle 100.

[0091] As a modified example, when the user notices that the electric vehicle 100 has been stolen, the user may issue an instruction from a mobile terminal or the like to rewrite the user identification information (first identification information) to other identification information (third identification information) different from the user identification information. This also eliminates the inconvenience to the user and makes it possible to prevent the thief from charging the vehicle by the PnC system if the vehicle is stolen.

[0092] A signature data generation process according to a modified example of the second embodiment will be described with reference to Fig. 6. Fig. 6 is a flowchart illustrating the signature data generation process according to a modified example of the second embodiment. Here, the process that differs from the first embodiment or the second embodiment will be described, and a description of the process that is the same as the first embodiment or the second embodiment will be omitted.

[0093] The controller 11 determines whether or not an instruction to rewrite the user identification information stored in the vehicle control device 2 to other identification information has been received from the user's mobile terminal or the like (S400). Specifically, the controller 11 determines whether or not other identification information has been received from the user's mobile terminal or the like. When the controller 11 receives other identification information from the user's mobile terminal or the like, the controller 11 determines that an instruction to rewrite the user identification information stored in the vehicle control device 2 to other identification information has been received. When the controller 11 does not receive other identification information from the user's mobile terminal or the like, the controller 11 determines that an instruction to rewrite the user identification information stored in the vehicle control device 2 to other identification information has not been received.

[0094] If the controller 11 has not received an instruction from the user's mobile terminal or the like to rewrite the user identification information stored in the vehicle control device 2 with other identification information (S400: No), the controller 11 proceeds to the process of step S302.

[0095] When the controller 11 receives an instruction from a user's mobile terminal or the like to rewrite the user identification information stored in the vehicle control device 2 with other identification information (S400: Yes), the controller 11 rewrites the user identification information stored in the vehicle control device 2 with the received other identification information (S401).

[0096] The controller 11 receives an instruction from a user's mobile terminal or the like to rewrite the user identification information stored in the vehicle control device 2 with other identification information, and if the other identification information is received, in step S304, the controller 11 transmits the other identification information to the charging control device 3.

[0097] When other identification information different from the user identification information is transmitted from the user's mobile terminal or the like, the vehicle control device 2 rewrites the stored user identification information with the other identification information, and when charging by the PnC method is to be performed, transmits the other identification information to the charging control device 3. As a result, the user identification information stored in the charging control device 3 does not match the other identification information transmitted from the vehicle control device 2, and charging by the PnC method is not performed. In other words, when the electric vehicle 100 is stolen, the user identification information is rewritten with the other identification information, thereby making it possible to prevent charging by the PnC method in the stolen electric vehicle 100.

[0098] The vehicle system 1 may be capable of generating a key in the charge control device 3.

[0099] The vehicle control device 2 may store the public key, and the charging control device 3 may store the private key. In this case, the charging control device 3 performs the signature data generation process, and the vehicle control device 2 performs the charging control process. The vehicle control device 2 transmits information regarding whether charging by the PnC method is possible to the charging control device 3. Then, the charging control device 3 determines whether or not to perform charging by the PnC method based on the received information regarding whether charging by the PnC method is possible.

[0100] In the above embodiment, for example, if the electric vehicle 100 is stolen, the vehicle system 1 does not charge using the PnC method. However, charging using methods other than the PnC method may also be prevented. For example, if the identification information does not match, the vehicle system 1 may not charge the battery 101 at all. In this way, for example, if the electric vehicle 100 is stolen, the vehicle system 1 can completely prevent charging the battery 101.

[0101] Further advantages and modifications will readily occur to those skilled in the art. Therefore, the invention in its broader aspects is not limited to the specific details and representative embodiments shown and described above. Accordingly, various modifications may be made without departing from the spirit or scope of the general inventive concept as defined by the appended claims and their equivalents. [Explanation of symbols]

[0102] 1 Vehicle Systems 2. Vehicle control device (first control device) 3. Charging control device (second control device) 10. Communications Department 11 Controller 12 Storage section 20 Controller 21 Memory section 100 Electric Vehicles 101 Battery 102 Charging port 200 charging stations 201 Charging plug 300 Server device

Claims

1. A vehicle system that controls charging of a battery mounted on an electric vehicle, a first control device; a second control device capable of communicating with the first control device; Equipped with The first control device receiving first identification information; When receiving information regarding a charging start operation of the battery, transmitting data including the first identification information to the second control device; The second control device is Second identification information is stored in advance; The vehicle system detects the charging start operation of the battery, and does not charge the battery if the first identification information received from the first control device does not match the second identification information.

2. The vehicle system of claim 1 , wherein the first control unit receives the first identification information when the battery is being charged.

3. The first control device storing in advance the first identification information that is the same data as the second identification information; When the charging start operation of the battery is detected, data including the stored first identification information is transmitted to the second control device; The vehicle system according to claim 1 , wherein, when theft of the electric vehicle is detected, the stored first identification information is rewritten to third identification information different from the first identification information.

4. The first control device storing in advance the first identification information that is the same data as the second identification information; When the charging start operation of the battery is detected, data including the stored first identification information is transmitted to the second control device; The vehicle system according to claim 1 , wherein when third identification information different from the first identification information is received from the user, the third identification information is transmitted to the second control device.

5. one of the first control device and the second control device generates signature data using a private key and transmits the generated signature data to the other of the first control device and the second control device; The other control device verifies the signature data using a public key; The vehicle system according to claim 1 , wherein the second control device does not charge the battery if the signature data is incorrect.

6. the one control device generates the signature data using the verification data transmitted from the other control device and the private key; The vehicle system according to claim 5 , wherein the other control device verifies the signature data using the verification data and the public key of the other control device.

7. The vehicle system according to claim 1 , wherein the first control device transmits the first identification information to the second control device via a communication path different from a communication path for plug-and-charge.

8. A charge control device that controls charging of a battery mounted on an electric vehicle, receiving data including first identification information received by another control device of the electric vehicle from the other control device; A charge control device that detects an operation to start charging the battery, and does not charge the battery if the first identification information does not match pre-stored second identification information.

9. a process in which a first control device of the electric vehicle receives first identification information; a process of transmitting data including the first identification information from the first control device to a second control device of the electric vehicle when the first control device receives information regarding a charging start operation of a battery mounted on the electric vehicle; a process of detecting the charging start operation of the battery in the second control device, and not charging the battery if the first identification information does not match second identification information stored in advance in the second control device; A program that causes a computer to execute the following.

Citation Information

Patent Citations

  • Vehicle system and authentication method

    JP2017079369A