control device

The control device on vehicles switches communication modes to prevent power transmission failure by using plaintext communication when encrypted communication fails, ensuring reliable charging and discharging operations.

JP2026077282APending Publication Date: 2026-05-13TOYOTA JIDOSHA KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
TOYOTA JIDOSHA KK
Filing Date
2024-10-25
Publication Date
2026-05-13

AI Technical Summary

Technical Problem

Encrypted communication failure between vehicles and charging equipment can lead to the impossibility of power transmission, as authentication or compatibility issues prevent successful communication.

Method used

A control device on the vehicle switches between encrypted and plaintext communication requests after electrical connection, allowing power transmission to continue via plaintext communication if encrypted communication fails.

Benefits of technology

Prevents power transmission failure by enabling alternative communication methods, ensuring seamless charging and discharging operations while maintaining security through encrypted communication when available.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026077282000001_ABST
    Figure 2026077282000001_ABST
Patent Text Reader

Abstract

The present invention provides a control device capable of preventing the failure of power transmission between a vehicle and a power station due to the failure of establishing encrypted communication. [Solution] The ECU 10 includes a communication unit 13 that communicates with the EVSE 200, and a processor 11 that can switch requests regarding communication between the communication unit 13 and the EVSE 200. The processor 11 can switch between encrypted communication requests that request the execution of encrypted communication and plaintext communication requests that request the execution of plaintext communication after the vehicle 100 and the EVSE 200 are electrically connected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a control device.

Background Art

[0002] Japanese Patent Application Laid-Open No. 2016-101049 (Patent Document 1) discloses a vehicle including an encryption / decryption unit that encrypts communication data transmitted and received between the vehicle and charging equipment.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] Although not specified in the above Patent Document 1, when authentication (matching) fails due to a certificate required for encrypted communication or the compatibility between the vehicle and the charging equipment (power stand), encrypted communication between the vehicle and the charging equipment becomes impossible. In this case, charging (power transmission) may become impossible.

[0005] This disclosure has been made to solve the above problems, and an object thereof is to provide a control device capable of suppressing the impossibility of power transmission between a vehicle and a power stand due to the failure of establishing encrypted communication.

Means for Solving the Problems

[0006] A control device according to one aspect of the present disclosure is a control device mounted on a vehicle that controls power transmission between a power station and the vehicle's battery, and comprises a communication unit that communicates with the power station, and a control unit that can switch requests regarding communication between the communication unit and the power station. The control unit can switch between an encrypted communication request that requests the execution of encrypted communication and a plaintext communication request that requests the execution of plaintext communication after the vehicle and the power station are electrically connected. [Effects of the Invention]

[0007] According to this disclosure, it is possible to suppress the failure of power transmission between the vehicle and the power station due to the failure to establish encrypted communication. [Brief explanation of the drawing]

[0008] [Figure 1] This figure shows the configuration of the charge / discharge system according to the first embodiment. [Figure 2] This is a sequence diagram showing the control between the vehicle and the EVSE according to the first embodiment. [Figure 3] Figure 2 is a sequence diagram showing the details of step S16. [Figure 4] This figure shows the configuration of the charge / discharge system according to the second embodiment. [Figure 5] This figure shows the display screen of a car navigation device according to the second embodiment. [Figure 6] This is a sequence diagram showing the control between the vehicle and the EVSE according to the second embodiment. [Figure 7] This figure shows the configuration of the charge / discharge system according to the third embodiment. [Figure 8] This is a sequence diagram showing the control between the vehicle and the EVSE according to the third embodiment. [Figure 9] This is a sequence diagram showing the control between the vehicle and the EVSE according to the first modified example. [Figure 10] This is a sequence diagram showing the control between the vehicle and EVSE in the second modified example. [Figure 11]This is a sequence diagram showing the control between the vehicle and EVSE according to the third modified example. [Figure 12] This is a sequence diagram showing the control between the vehicle and the EVSE according to the fourth modified example. [Figure 13] This is a sequence diagram showing the control between the vehicle and EVSE according to the fifth modified example. [Modes for carrying out the invention]

[0009] Embodiments of this disclosure will be described with reference to the drawings. In the drawings referred to below, the same or equivalent components are given the same number.

[0010] [First Embodiment] Figure 1 shows the configuration of a charge / discharge system 1 according to the first embodiment. The charge / discharge system 1 comprises a vehicle 100 and an EVSE (Electric Vehicle Supply Equipment) 200. The EVSE 200 is an example of a "power station" as disclosed herein.

[0011] The vehicle 100 includes an ECU (Electronic Control Unit) 10, a battery pack 20, a charger / discharger 30, and a car navigation system 40. The ECU 10 and battery pack 20 are examples of the "control device" and "storage battery" as defined in this disclosure, respectively. The navigation system 40 in Figures 1, 4, and 7 corresponds to the car navigation system 40 (hereinafter, it will be referred to as the car navigation system 40 in the detailed description).

[0012] The ECU10 controls the charging and discharging between the battery pack 20 and the EVSE200 by controlling the charger / discharger 30.

[0013] The battery pack 20 is a battery for driving the vehicle 100. The vehicle 100 may be a PHEV (Plug-in Hybrid Electric Vehicle), a BEV (Battery Electric Vehicle), an FCEV (Fuel Cell Electric Vehicle), or the like.

[0014] The vehicle 100 is electrically connected to the EVSE 200 by the cable 201, enabling power transfer between the vehicle 100 and the EVSE 200. Specifically, when the connector 202 provided at the tip of the cable 201 is inserted (connected) into the inlet 50 of the vehicle 100, power transfer between the vehicle 100 and the EVSE 200 becomes possible. The power (charging power) from the EVSE 200 is supplied to a power storage cell (not shown) of the battery pack 20 through the charge / discharge device 30. Thereby, the power storage cell is charged. The power (discharge power) from the battery pack 20 is supplied to the EVSE 200 through the charge / discharge device 30. Thereby, the power storage cell is discharged. The ECU 10 (processor 11) may detect that the connector 202 is connected to the inlet 50 based on a signal from an ECU not shown. The processor 11 is an example of the "control unit" of the present disclosure.

[0015] The power storage cell is a secondary battery, typically a lithium-ion secondary battery. A lithium-ion secondary battery is a battery using lithium as a charge carrier, and may include not only a lithium-ion secondary battery with a liquid electrolyte but also an all-solid-state battery using a solid electrolyte. Note that the power storage cell is not limited to a lithium-ion secondary battery and may be composed of a nickel-metal hydride secondary battery or other secondary batteries.

[0016] The car navigation device 40 can receive various operations by the user of the vehicle 100. The car navigation device 40 can also display information to be transmitted to the user.

[0017] The ECU 10 includes a processor 11, a memory 12, and a communication unit 13. The memory 12 stores the program executed by the processor 11, as well as information used by the program (e.g., maps, formulas, and various parameters). The communication unit 13 includes various communication interfaces. The communication unit 13 communicates with various devices in the vehicle 100 (e.g., a car navigation system 40) via CAN (Controller Area Network) communication. The processor 11 controls the communication unit 13.

[0018] The processor 11 transmits a control signal to the charger / discharger 30 via the communication unit 13. The charger / discharger 30 charges and discharges the battery pack 20 according to the control signal from the processor 11.

[0019] EVSE200 is installed in public facilities, such as shopping malls and theme parks. However, the installation locations of EVSE200 are not limited to the examples above.

[0020] The EVSE200 includes a control unit 210. The control unit 210 includes a processor 211, a memory 212, and a communication unit 213. The memory 212 stores the program executed by the processor 211, as well as information used by the program (e.g., maps, formulas, and various parameters). The communication unit 213 includes various communication interfaces. The processor 211 controls the communication unit 213.

[0021] Each of the processors 11,211 is, for example, a CPU (Central Processing Unit) or an MPU (Micro-Processing Unit). Each processor 11,211 performs various processes by reading system programs and control programs, respectively, loading them into memory 12,212, and executing them. In this specification, "processor" is not limited to processors that execute processing using stored-program methods, but may also include hardwired circuits such as ASICs (Application Specific Integrated Circuits) and FPGAs (Field-Programmable Gate Arrays). Therefore, the term "processor" can also be interpreted as processing circuitry in which processing is predefined by computer-readable code and / or hardwired circuits.

[0022] The communication unit 213 communicates with the communication unit 13 of the ECU 10. This allows various types of information to be exchanged between the ECU 10 (communication unit 13) and the control device 210 (communication unit 213). For example, information on power and various authentication information are exchanged between the ECU 10 and the control device 210. The vehicle 100 may also communicate with the communication unit 213 of the EVSE 200 using a different communication method than the communication unit 13. In this case, the communication unit 13 communicates indirectly with the communication unit 213.

[0023] The ECU 10 can switch requests regarding communication between the communication unit 13 and the EVSE 200 (communication unit 213). Specifically, the ECU 10 can switch whether to use encrypted communication or plaintext communication when communicating with the EVSE 200. Encrypted communication is a communication method in which communication data is encrypted before being sent and received. Plaintext communication is a communication method in which communication data is sent and received without encryption. In the first embodiment, the vehicle 100 (ECU 10) is assumed to support only one encryption protocol (for example, TLS (Transport Layer Security)). However, the encryption protocols supported by the vehicle 100 are not limited to the above example.

[0024] When the encrypted communication request sent from the ECU10 to the EVSE200 is authenticated (approved) by the EVSE200, encrypted communication becomes possible between the vehicle 100 and the EVSE200.

[0025] In conventional control systems, if authentication (matching) fails due to issues such as certificates required for encrypted communication or incompatibility between the vehicle and the EVSE, encrypted communication between the vehicle and the EVSE becomes impossible. In this case, charging (power transmission) may become impossible.

[0026] Therefore, in the first embodiment, the ECU 10 can switch between an encrypted communication request, which requests the execution of encrypted communication, and a plaintext communication request, which requests the execution of plaintext communication, after the vehicle 100 and the EVSE 200 are electrically connected. This makes it possible to communicate between the vehicle 100 and the EVSE 200 via plaintext communication even if encrypted communication fails, and enables power transmission (charging) between the vehicle and the EVSE. Details will be explained using the following sequence diagram.

[0027] <Sequence control> Figure 2 shows an example of sequence control between the vehicle 100 and the EVSE 200. The processing of the vehicle 100 shown in Figure 2 is executed by the ECU 10 (processor 11). The processing of the EVSE 200 shown in Figure 2 is executed by the control device 210 (processor 211). Steps S1 and S17 below indicate user operation steps.

[0028] In step S1, the connector 202 is connected to the inlet 50 of the vehicle 100. This allows the ECU 10 to detect that the connector 202 has been connected to the inlet 50. Subsequently, the charge-discharge sequence between the vehicle 100 and the EVSE 200 is initiated.

[0029] In step S2, the ECU 10 determines whether the establishment of encrypted communication failed last time. "Previous failure" means a failure in step S1 or later, and does not mean a failure in the previous charge / discharge sequence (previous plug-in period). Therefore, the first determination in step S2 is always No. If the establishment of encrypted communication did not fail last time (No in S2), the process proceeds to step S3. If the establishment of encrypted communication failed last time (Yes in S2), the process proceeds to step S4.

[0030] In step S3, the ECU 10 transmits a signal indicating an encrypted communication request (SeccDiscoveryReqMesseage) to the control device 210 via the communication unit 13. The signal indicating an encrypted communication request will be simply referred to as the encrypted communication request below. Next, the process proceeds to step S9.

[0031] In step S4, the ECU 10 transmits a signal indicating a plaintext communication request (SeccDiscoveryReqMesseage) to the control device 210 through the communication unit 13. The signal indicating a plaintext communication request will be simply referred to as a plaintext communication request below. Next, the process proceeds to step S12.

[0032] In step S5, the control device 210 determines whether or not it has received an encrypted communication request from the ECU 10. If an encrypted communication request has been received (Yes in S5), the process proceeds to step S6. If an encrypted communication request has not been received (No in S5), the process proceeds to step S7.

[0033] In step S6, the control device 210 responds to the ECU 10 regarding whether or not it can establish encrypted communication based on the encrypted communication request. Specifically, the control device 210 sends a signal (SeccDiscoveryResMesseage) to the ECU 10 through the communication unit 213 indicating whether or not it can establish encrypted communication. For example, if the encrypted communication request in step S3 was a request for encrypted communication using TLS, the control device 210 determines that it can establish encrypted communication if it supports TLS. Conversely, the control device 210 determines that it cannot establish encrypted communication if it does not support TLS. Next, the process proceeds to step S7.

[0034] In step S7, the control device 210 determines whether or not it has received a plaintext communication request from the ECU 10. If a plaintext communication request has been received (Yes in S7), the process proceeds to step S8. If a plaintext communication request has not been received (No in S7), the process proceeds to step S14.

[0035] In step S8, the control device 210 responds to the ECU 10 via the communication unit 213 that plaintext communication can be established. Next, the process proceeds to step S14. Steps S7 and S8 may be omitted.

[0036] In step S9, the ECU 10 determines, based on the response in step S6, whether or not the establishment of encrypted communication based on the encrypted communication request was successful. If the establishment of encrypted communication is successful (Yes in S9), the process proceeds to step S10. If the establishment of encrypted communication fails (No in S9), the process returns to step S2. Note that the control in this disclosure is not limited to the ECU 10 determining the success or failure of the establishment of encrypted communication based on the response from the control device 210. For example, if the control device 210 determines that the establishment of encrypted communication is not possible, it may send a command signal (retry command) to the ECU 10 to return the process to step S2.

[0037] In step S10, the ECU 10 sends an encrypted communication handshake signal to the EVSE 200 through the communication unit 13. The process then proceeds to step S11.

[0038] In step S11, the ECU 10 sends a signal to the control device 210 via the communication unit 13 to request a PnC (Plug and Charge) charge. Next, the process proceeds to step S16. Note that the processes in steps S10 and S11 may be performed in the reverse order of the example above, or they may be performed simultaneously.

[0039] In step S12, the ECU 10 transmits a plaintext communication handshake signal to the EVSE 200 through the communication unit 13. Note that the processing in step S12 may be performed in response to the ECU 10 receiving the response in step S8. Next, the process proceeds to step S13.

[0040] In step S13, the ECU 10 sends a signal to the control device 210 via the communication unit 13 to request an EIM (External Identification Means) charge. Next, the process proceeds to step S16. Note that the processes in steps S12 and S13 may be performed in the reverse order of the example above, or simultaneously.

[0041] In step S14, the control device 210 determines whether it has received the encrypted communication handshake signal from step S10 or the plaintext communication handshake signal from step S12. If the control device 210 has received either handshake signal (Yes in S14), the process proceeds to step S15. If the control device 210 has not received either handshake signal (No in S14), the process returns to step S5.

[0042] In step S15, the control device 210 transmits a response signal to the ECU 10 via the communication unit 213 that authorizes the charge requested in step S11 or step S13. The process then proceeds to step S16. The ECU 10 may, for example, transmit a command signal to the car navigation device 40 or a terminal held by the user (e.g., a smartphone or tablet) to display a message indicating that the EIM charge has been authorized, if the EIM charge is authorized.

[0043] Furthermore, in step S2, after it is determined in step S9 that the establishment of encrypted communication has failed, it is determined that the previous attempt to establish encrypted communication failed, and the process proceeds to step S4. In other words, when the establishment of encrypted communication based on an encrypted communication request fails, the ECU 10 switches from an encrypted communication request to a plaintext communication request.

[0044] This prevents repeated encrypted communication requests (infinite retries) from being made to the EVSE200, which does not support encrypted communication. This prevents the charging sequence from continuing without the battery pack 20 actually being charged. It also prevents the auxiliary battery (not shown) of the vehicle 100 from running out due to the charging sequence continuing for a long time.

[0045] In step S16, process A is executed. Details of process A will be described later. Then, in step S17, connector 202 is disconnected from inlet 50 of vehicle 100. This disconnects the electrical connection between vehicle 100 and EVSE200.

[0046] Figure 3 is a sequence diagram showing the details of step S16 in Figure 2. Step S16 includes steps S16A to S16H. In step S16A, the ECU 10 determines whether or not encrypted communication has been successfully established. If encrypted communication has been successfully established (Yes in S16A), the process proceeds to step S16B. If plaintext communication has been successfully established (No in S16A), the process proceeds to step S16C.

[0047] In step S16B, the ECU 10 sends a signal to the control device 210 via the communication unit 13 that permits charging and discharging of the battery pack 20 between the vehicle 100 and the EVSE 200. The process then proceeds to step S16F.

[0048] In step S16C, the ECU 10 sends a signal to the control device 210 via the communication unit 13 that permits charging from the EVSE 200 to the battery pack 20 and prohibits discharging from the battery pack 20 to the EVSE 200. Next, the process proceeds to step S16F.

[0049] In step S16D, the control device 210 determines whether or not it has received the signal in step S16B or step S16C. If the above signal has been received (Yes in S16D), the process proceeds to step S16E. If the above signal has not been received (No in S16D), the process in step S16D is repeated.

[0050] In step S16E, the control device 210 transmits a response (acknowledgment) signal to the vehicle 100 via the communication unit 213 in response to the signal in step S16B or step S16C. The process then proceeds to step S16G.

[0051] In step S16F, the ECU 10 determines whether or not it has received the response signal from step S16E. If the response signal has been received (Yes in S16F), the process proceeds to step S16G. If the response signal has not been received (No in S16F), the process in step S16F is repeated.

[0052] In step S16G, the power transmission desired by the user (charging the battery pack 20 or discharging from the battery pack 20) ​​is performed between the vehicle 100 and the EVSE 200. However, if the process in step S16C is being executed, discharging cannot be performed.

[0053] Then, in step S16H, the charging or discharging that was started in step S16G is terminated, for example, when the exchange of the amount of power desired by the user has been completed.

[0054] As described above, in the first embodiment, the ECU 10 can switch between encrypted communication requests and plaintext communication requests after the vehicle 100 and the EVSE 200 are electrically connected. This allows power transmission between the vehicle 100 and the EVSE 200 to be performed by plaintext communication even if encrypted communication fails. Therefore, it is possible to prevent power transmission between the vehicle and the power station from becoming impossible due to the failure to establish encrypted communication.

[0055] Furthermore, in the first embodiment, the ECU 10 requests power transmission based on PnC from the EVSE 200 when encrypted communication is successfully established, and requests power transmission based on EIM from the EVSE 200 when plaintext communication is successfully established. This makes it possible to perform PnC-based power transmission, which requires encrypted communication, using encrypted communication. As a result, payments based on power transmission are made automatically, improving user convenience. Alternatively, power transmission based on EIM, which does not require encrypted communication, can be performed using plaintext communication. This prevents security problems such as the leakage of the user's personal information (account information, etc.), unlike when PnC-based power transmission is performed using plaintext communication.

[0056] Furthermore, in the first embodiment, the ECU 10 permits charging and discharging of the battery pack 20 with the EVSE 200 when encrypted communication is successfully established, and prohibits discharging from the battery pack 20 to the EVSE 200 and permits charging from the EVSE 200 to the battery pack 20 when plaintext communication is successfully established. This allows charging and discharging of the battery pack 20 to be performed using encrypted communication. As a result, payments based on charging and discharging are made automatically, improving user convenience. In addition, charging of the battery pack 20 can be performed using plaintext communication. In addition, discharging from the battery pack 20 can be prohibited using plaintext communication. This makes it possible to make the use of encrypted communication a requirement for discharging. Therefore, payments (rewards) to the user based on discharging can be automatically paid into the user's account.

[0057] [Second Embodiment] A second embodiment of this disclosure will be described with reference to Figures 4 to 6. In the second embodiment, unlike the first embodiment which switches to plaintext communication when the previous encrypted communication fails to establish, the switch from encrypted communication to plaintext communication is performed based on the PnC billing setting in the vehicle. The same components and processes as in the first embodiment are denoted by the same reference numerals as in the first embodiment, and repeated explanations may be omitted.

[0058] Figure 4 shows the configuration of the charge / discharge system 2 according to the second embodiment. The charge / discharge system 2 comprises a vehicle 101 and an EVSE 300. The EVSE 300 is an example of a "power station" as disclosed herein.

[0059] Vehicle 101 differs from vehicle 100 of the first embodiment in that it is equipped with an ECU 110 instead of an ECU 10. Note that the ECU 110 is an example of a "control device" as disclosed herein.

[0060] The ECU 110 includes a processor 111, a memory 112, and a communication unit 113. The memory 112 stores the program executed by the processor 111, as well as information used by the program (e.g., maps, formulas, and various parameters). The processor 111 controls the communication unit 113. The processor 111 is an example of a "control unit" as described herein.

[0061] The EVSE300 includes a control unit 310. The control unit 310 includes a processor 311, a memory 312, and a communication unit 313. The memory 312 stores the program executed by the processor 311, as well as information used by the program (for example, maps, formulas, and various parameters). The processor 311 controls the communication unit 313.

[0062] Figure 5 shows the display screen 41 of the car navigation device 40. The display screen 41 shows a selection button 42 for turning on the PnC billing setting and a selection button 43 for turning off the PnC billing setting. When the user selects selection button 42, the ECU 110 receives a signal from the car navigation device 40 indicating that the PnC billing setting has been turned on. When the user selects selection button 43, the ECU 110 receives a signal from the car navigation device 40 indicating that the PnC billing setting has been turned off. Note that the above switching of the PnC billing setting may be performed on the user's terminal (for example, a smartphone or tablet). Also, the PnC billing setting may be turned on in the initial state of the vehicle 101.

[0063] <Sequence control> Figure 6 shows an example of a sequence diagram illustrating control between the vehicle 101 and the EVSE 300. The processing of the vehicle 101 shown in Figure 6 is performed by the ECU 110 (processor 111). The processing of the EVSE 300 shown in Figure 6 is performed by the control device 310 (processor 311).

[0064] In the next step S21 following step S1, the ECU110 determines whether the PnC billing setting is turned on or off. If the PnC billing setting is turned on (Yes in S21), the process proceeds to step S3. If the PnC billing setting is turned off (No in S21), the process proceeds to step S4.

[0065] In the next step S22 following step S6, the control device 310 determines whether or not encrypted communication can be established. If it is determined in step S6 that encrypted communication can be established (Yes in S22), the process proceeds to step S15. If it is determined in step S6 that encrypted communication cannot be established (No in S22), the sequence proceeds to step S17, and the processing by the control device 310 ends.

[0066] In the next step S23 following step S3, ECU110 determines, based on the response in step S6, whether the establishment of encrypted communication based on the encrypted communication request was successful. If the establishment of encrypted communication is successful (Yes in S23), the process proceeds to step S10. If the establishment of encrypted communication fails (No in S23), the sequence proceeds to step S17, and the processing of ECU110 ends.

[0067] Note that in the sequence shown in Figure 6, step S14 (Figure 2) of the first embodiment is not executed. Also, the processes in steps S10 and S12 may not be executed in the second embodiment. The other configurations and processes are the same as in the first embodiment, so a repeated explanation will not be given.

[0068] As described above, in the second embodiment, when the PnC setting is turned on by the user, the ECU 110 makes an encrypted communication request and, when the establishment of encrypted communication is successful, requests power transmission based on PnC from the EVSE 300. Furthermore, when the PnC setting is turned off by the user, the ECU 110 makes a plaintext communication request and, when the establishment of plaintext communication is successful, requests power transmission based on EIM from the EVSE 300. This allows the on / off setting of PnC billing to be linked to the switching between encrypted communication requests and plaintext communication requests. As a result, the user can switch between encrypted communication requests and plaintext communication requests simply by switching the PnC billing setting, without having to perform the complicated setting operation of switching between encrypted communication requests and plaintext communication requests.

[0069] [Third Embodiment] A third embodiment of this disclosure will be described with reference to Figures 7 and 8. In the third embodiment, unlike the second embodiment which switches between encrypted communication requests and plaintext communication requests based on the PnC billing setting, the third embodiment switches between encrypted communication requests and plaintext communication requests based on the operation of connecting cable 201 to a vehicle. The same components and processes as in the second embodiment are denoted by the same reference numerals as in the second embodiment and their repeated descriptions may be omitted.

[0070] Figure 7 shows the configuration of the charge / discharge system 3 according to the third embodiment. The charge / discharge system 3 comprises a vehicle 102 and an EVSE 300.

[0071] Vehicle 102 differs from vehicle 101 of the second embodiment in that it is equipped with an ECU 410 instead of an ECU 110. Note that the ECU 410 is an example of a "control device" as disclosed herein.

[0072] The ECU 410 includes a processor 411, a memory 412, and a communication unit 413. The memory 412 stores the program executed by the processor 411, as well as information used by the program (e.g., maps, formulas, and various parameters). The processor 411 controls the communication unit 413. The processor 411 is an example of a "control unit" as described herein.

[0073] <Sequence control> Figure 8 shows an example of a sequence diagram illustrating control between the vehicle 102 and the EVSE 300. The processing of the vehicle 102 shown in Figure 8 is performed by the ECU 410 (processor 411). The sequence shown in Figure 8 differs from the sequence of the second embodiment described above only in that step S31 is executed instead of step S21 (Figure 6).

[0074] In step S31, the ECU 410 determines whether the connector 202 has been continuously connected to the inlet 50. Specifically, the ECU 410 determines whether the connector 202 has been reconnected to the inlet 50 within a predetermined time (for example, 10 seconds) after step S1. The time when the connector 202 was connected in step S1 is defined as time t1, the time when the connector 202 was then removed from the inlet 50 is defined as time t2, and the time when the connector 202 was then reconnected to the inlet 50 is defined as time t3. The ECU 410 determines whether the difference between time t3 and time t1 is less than or equal to the predetermined time. The ECU 410 may also lock the connector 202 from the inlet 50 after time t3 (or after a predetermined time after time t3) to prevent it from being removed. If the connector 202 has been continuously connected to the inlet 50 (Yes in S31), the process proceeds to step S4. If connector 202 is not continuously connected to inlet 50 (No in S31), the process proceeds to step S3.

[0075] Furthermore, the other configurations and processes are the same as those of the second embodiment described above, so no further explanation will be given.

[0076] As described above, in the third embodiment, the ECU 410 switches from encrypted communication requests to plaintext communication requests based on the user's operation of connecting and disconnecting the connector 202 to the inlet 50. Specifically, the ECU 410 switches from encrypted communication requests to plaintext communication requests when the connector 202 is connected to the inlet 50 multiple times in succession. Specifically, by disconnecting the connector 202 connected to the inlet 50 while the charging indicator (not shown) is flashing at a normal speed, and then immediately reconnecting it, it is possible to switch from encrypted communication requests to plaintext communication requests. This is just one example, but it is desirable to switch from encrypted communication requests to plaintext communication requests by reconnecting the connector 202 within one minute of disconnecting it. This allows the user to switch from encrypted communication requests to plaintext communication requests simply by connecting and disconnecting the connector 202. As a result, user convenience can be improved.

[0077] <Variation> Figure 9 shows a sequence combining the first and second embodiments described above. As shown in Figure 9, if the previous encrypted communication failed to be established in step S2 (Yes in S2), the process proceeds to step S41. If the previous encrypted communication was successfully established (No in S2), the process proceeds to step S21.

[0078] In step S41, the ECU switches the PnC billing setting from on to off. If the PnC billing setting is already off, the off setting for PnC billing is maintained. The process then proceeds to step S21.

[0079] If it is determined in step S21 that the PnC billing setting is turned on (Yes in S21), the process proceeds to step S3. If it is determined that the PnC billing setting is turned off (No in S21), the process proceeds to step S4.

[0080] The subsequent sequence is the same as in the first embodiment described above. In step S2, after it is determined that the establishment of encrypted communication failed in step S9 (No in S9), it is determined that the previous establishment of encrypted communication failed, so the process proceeds to step S41. Therefore, in this modified example, the ECU switches the PnC setting from on to off when the establishment of encrypted communication fails.

[0081] This automatically switches off the PnC billing setting if the establishment of encrypted communication fails. Therefore, it eliminates the need for the user to manually disable the PnC billing setting.

[0082] Figure 10 is a modified version of Figure 9. In the example shown in Figure 10, the order of steps S2 and S21 in Figure 9 is reversed. In this case, the process in step S41 in Figure 9 is not executed, and if the answer in step S2 is Yes, the process proceeds to step S4.

[0083] Figure 11 shows a sequence combining the first embodiment and the third embodiment. As shown in Figure 11, if it is determined in the next step S31 of step S1 that the connector 202 is continuously connected to the inlet 50 (Yes in S31), the process proceeds to step S4. If it is determined in step S31 that the connector 202 is not continuously connected to the inlet 50 (No in S31), the process proceeds to step S2. The subsequent sequence is the same as in the first embodiment.

[0084] Figure 12 is a modified version of Figure 11. In the example shown in Figure 12, the order of steps S2 and S31 in Figure 11 is reversed.

[0085] The above embodiment shows an example where the vehicle supports only a single encryption protocol, but the disclosure is not limited thereto. The vehicle may support multiple encryption protocols. An example of such a sequence is shown in Figure 13.

[0086] As shown in Figure 13, in the next step S51 following step S1, the ECU 10 determines whether or not the establishment of encrypted communication has failed for all of the multiple encryption protocols that the vehicle supports. If the establishment of encrypted communication has failed for all encryption protocols (Yes in S51), the process proceeds to step S4. If there are still encryption protocols for which the establishment of encrypted communication has not failed (No in S51), the process proceeds to step S52.

[0087] In step S52, the ECU 10 requests encrypted communication using the encryption protocol with the highest priority among the untried encryption protocols. Next, the process proceeds to step S9. If the answer in step S9 is No, the process returns to step S51.

[0088] Figure 13 shows an example where untried encryption protocols are tried in order of priority, but this disclosure is not limited to this example. For example, in step S51, untried encryption protocols may be tried in order of newest version, or untried encryption protocols may be tried in order of highest number of successful encrypted communication establishments (or success rate).

[0089] The above embodiment shows an example where charging and discharging are permitted only when encrypted communication is successfully established, but the disclosure is not limited thereto. For example, even if encrypted communication is successfully established, only charging may be permitted. Alternatively, charging and discharging may be permitted only when plaintext communication is successfully established.

[0090] The first embodiment and its modifications described above show examples in which the success or failure of the previous encrypted communication during the current plug-in period is determined, but the disclosure is not limited thereto. For example, if the last encrypted communication during the previous plug-in period failed to be established, the first determination (determination S2) during the current plug-in period may determine that the previous encrypted communication was not established. This modification may only be applicable when the same EVSE and vehicle are connected as in the previous plug-in.

[0091] In the above embodiment, an example was shown in which a single ECU (10, 110, 410) controls the switching between encrypted communication requests and plaintext communication requests, but the disclosure is not limited thereto. The ECU (10, 110, 410) may be composed of multiple ECUs, each having different functions with respect to the above switching.

[0092] In the third embodiment described above, an example was shown in which the request is switched from encrypted communication to plaintext communication by attaching or detaching the connector 202, but the disclosure is not limited thereto. For example, the request may be switched from encrypted communication to plaintext communication by operating the monitor of the car navigation device 40 or EVSE, or by operating a button provided on the connector.

[0093] In the above embodiments and modifications, examples were shown in which the switching between encrypted communication requests and plaintext communication requests is automatically performed by the ECU according to the determination results of each determination step (S2 and S21, etc.), but the disclosure is not limited thereto. For example, the switching between encrypted communication requests and plaintext communication requests may be performed by user operations on the car navigation device 40, the vehicle's meter, and the user's terminal, etc.

[0094] The embodiments and modifications described above illustrate examples in which the vehicle is capable of charging and discharging, but the disclosure is not limited thereto. For example, the vehicle may be capable of charging only.

[0095] The above embodiment shows an example where EIM charges are requested instead of PnC charges if the establishment of encrypted communication fails, but the disclosure is not limited thereto. Alternatively / in addition, if the establishment of encrypted communication fails, a request to change the communication standard to an older version may be sent from the vehicle to the EVSE.

[0096] It should be noted that the embodiments disclosed herein are illustrative in all respects and not restrictive. The scope of this disclosure is defined by the claims rather than the description of the embodiments above, and includes all modifications within the meaning and scope equivalent to the claims. [Explanation of Symbols]

[0097] 10,110,410 ECU (control unit), 11,111,411 Processor (control unit), 13,113,413 Communication unit, 20 Battery pack (storage battery), 50 Inlet, 100,101,102 Vehicle, 200,300 EVSE (power station), 202 Connector.

Claims

1. A control device that is mounted on a vehicle and controls the power transmission between a power station and the vehicle's battery, A communication unit that communicates with the aforementioned power stand, The system includes a control unit capable of switching requests regarding communication between the communication unit and the power stand, The control unit is a control device that can switch between an encrypted communication request, which requests the execution of encrypted communication, and a plaintext communication request, which requests the execution of plaintext communication, after the vehicle and the power stand are electrically connected.

2. The control device according to claim 1, wherein the control unit switches from the encrypted communication request to the plaintext communication request if the establishment of the encrypted communication based on the encrypted communication request fails.

3. The control unit, If the establishment of the encrypted communication based on the encrypted communication request is successful, the power station is requested to transmit the power based on PnC. The control device according to claim 1 or 2, wherein, upon successful establishment of the plaintext communication based on the plaintext communication request, the control device requests the power stand to transmit power based on EIM.

4. The control unit, If the establishment of the encrypted communication based on the encrypted communication request is successful, charging and discharging of the storage battery between the power stand and the storage battery shall be permitted. The control device according to claim 1 or 2, which, when the establishment of the plaintext communication based on the plaintext communication request is successful, prohibits discharge from the storage battery to the power stand and permits charging from the power stand to the storage battery.

5. The control unit, When the user turns on the PnC setting for performing the power transmission based on PnC, the encrypted communication request is made, and when the establishment of the encrypted communication based on the encrypted communication request is successful, the power stand is requested to perform the power transmission based on PnC. The control device according to claim 1 or 2, wherein if the PnC setting is turned off by the user, it makes the plaintext communication request, and when the establishment of the plaintext communication based on the plaintext communication request is successful, it requests the power stand to transmit the power based on EIM.

6. The control device according to claim 5, wherein the control unit switches the PnC setting from on to off when the establishment of the encrypted communication based on the encrypted communication request fails.

7. The control device according to claim 1 or 2, wherein the control unit switches from an encrypted communication request to a plaintext communication request based on a user operation of attaching or detaching the connector of the power stand to the inlet of the vehicle.

8. The control device according to claim 7, wherein the control unit switches from the encrypted communication request to the plaintext communication request when the connector is connected to the inlet multiple times in succession.