Servers and Systems
The server system addresses the issue of unreliable communication by providing a first and second digital certificate with varying validity periods, ensuring continuous connectivity between vehicles and EV charging stations even when the vehicle communication device contract is invalid.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2024-10-30
- Publication Date
- 2026-05-15
AI Technical Summary
Existing systems fail to reliably establish communication between a vehicle and an EV charging station when the contract of the vehicle communication device is not valid.
A server system that transmits a first digital certificate with a short validity period and a second digital certificate with a longer validity period to a vehicle communication device, ensuring continuous communication connectivity even when the contract is not active.
Ensures a more reliable and secure communication connection between the vehicle and the EV charging station by using a second digital certificate with a longer validity period, preventing interruptions due to contract expiration or cancellation.
Smart Images

Figure 2026079207000001_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a server and a system.
Background Art
[0002] Japanese Patent Application Publication No. 2022-527902 (Patent Document 1) discloses a system in which a digital certificate transmitted from an EV charging station is authenticated in a vehicle. In this system, communication is connected between the vehicle and the EV charging station based on the digital certificate, and then charging of the vehicle is executed.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Although not specified in Patent Document 1 above, in order for a vehicle to receive a digital certificate, it is necessary to activate a contract of the vehicle communication device. If the contract of the vehicle communication device is not valid, the vehicle cannot receive the digital certificate. In a state where the vehicle has not received the digital certificate, a communication connection between the vehicle and the EV charging station cannot be established.
[0005] This disclosure has been made to solve the above problems, and an object thereof is to provide a server and a system capable of more reliably establishing a communication connection between a vehicle and a power stand even when the contract of the vehicle communication device is not valid.
Means for Solving the Problems
[0006] The server relating to the first aspect of this disclosure is a server that transmits a digital certificate used for communication between a vehicle and a power station to a vehicle, and comprises a communication unit that communicates with the vehicle's vehicle communication device, and a control unit. The digital certificate includes a first digital certificate and a second digital certificate having a longer validity period than the first digital certificate. The control unit transmits the first digital certificate to the vehicle communication device via the communication unit if no request for cancellation of the vehicle communication device has been made, and transmits the second digital certificate to the vehicle communication device via the communication unit if a request for cancellation of the vehicle communication device has been made.
[0007] The system relating to the second aspect of this disclosure comprises the server relating to the first aspect described above, and a vehicle including a vehicle communication device that communicates with a communication unit. [Effects of the Invention]
[0008] According to this disclosure, a more reliable communication connection can be established between the vehicle and the power station even if the vehicle communication device contract is not valid. [Brief explanation of the drawing]
[0009] [Figure 1] This is a diagram showing the configuration of the system according to this embodiment. [Figure 2] Figure 1 shows the sequence of the system according to this embodiment. [Figure 3] Figure 2 shows the sequence of the system according to this embodiment. [Figure 4] This is a sequence diagram of a system according to a first modification of this embodiment. [Figure 5] This is a sequence diagram of a system according to a second modification of this embodiment. [Modes for carrying out the invention]
[0010] Embodiments of this disclosure will be described with reference to the drawings. In the drawings referred to below, the same or equivalent components are given the same number.
[0011] Figure 1 shows the configuration of System 1 according to this embodiment. System 1 comprises a server 100 and a vehicle 200.
[0012] The server 100 comprises a processor 110, memory 120, and a communication unit 130. The processor 110 is an example of a "control unit" as described herein.
[0013] Memory 120 stores the program executed by the processor 110, as well as information used by the program (for example, maps, mathematical formulas, and various parameters). The communication unit 130 is controlled by the processor 110.
[0014] The communication unit 130 can communicate with the Data Communication Module (DCM) 230, which will be described later, and the certification authority 400, which will be described later.
[0015] The vehicle 200 includes an ECU (Electronic Control Unit) 210, a battery pack 220, a DCM 230, a car navigation system 240, and an inlet 250. The DCM 230 is an example of the "vehicle communication device" described herein.
[0016] The ECU210 comprises a processor 211, a memory 212, and a communication unit 213. The memory 212 stores the program executed by the processor 211, as well as information used by the program (for example, maps, formulas, and various parameters). The communication unit 213 is controlled by the processor 211. The communication unit 213 can communicate with the DCM 230 and the car navigation device 240, etc., via CAN (Controller Area Network) communication or the like.
[0017] The battery pack 220 is a battery for driving the vehicle 200. The vehicle 200 may be a PHEV (Plug-in Hybrid Electric Vehicle), a BEV (Battery Electric Vehicle), an FCEV (Fuel Cell Electric Vehicle), etc.
[0018] The vehicle 200 is electrically connected to the EVSE 300 by the cable 301, enabling power transfer between the vehicle 200 and the EVSE 300. Specifically, when the connector 302 provided at the tip of the cable 301 is inserted (connected) into the inlet 250 of the vehicle 200, power transfer between the vehicle 200 and the EVSE 300 becomes possible. The power (charging power) from the EVSE 300 is supplied to the power storage cells (not shown) of the battery pack 220 through a charger (not shown) of the vehicle 200. Thereby, the power storage cells are charged. The power (discharge power) from the battery pack 220 is supplied to the EVSE 300 through the above-mentioned charger. Thereby, the power storage cells are discharged. The power storage cells are secondary batteries, typically lithium-ion secondary batteries. A lithium-ion secondary battery is a battery that uses lithium as a charge carrier and may include not only a lithium-ion secondary battery with a liquid electrolyte but also an all-solid-state battery using a solid electrolyte. The power storage cells are not limited to lithium-ion secondary batteries and may be composed of nickel-metal hydride secondary batteries or other secondary batteries. Also, the EVSE 300 is an example of the "power stand" of the present disclosure.
[0019] In a state where the vehicle 200 and the EVSE 300 are connected by the cable 301, the ECU 210 (communication unit 213) communicates with the EVSE 300. The ECU that communicates with the EVSE 300 may be different from the ECU 210.
[0020] The ECU 210 and the EVSE 300 communicate with each other, for example, by TLS (Transport Layer Security) communication. TLS is a protocol for performing highly secure communication. Digital certificates are used for TLS communication. Based on the digital certificates, information can be safely exchanged between the vehicle 200 and the EVSE 300. After the communication connection between the vehicle 200 and the EVSE 300 is established, the authentication data from the vehicle 200 is transmitted to the EVSE 300 in an encrypted form. When the authentication based on the authentication data is completed, charging from the EVSE 300 to the vehicle 200 and discharging from the vehicle 200 to the EVSE 300 become possible. In the case of PnC (Plug and Charge), when the authentication is completed, the charging (discharging) process and the billing process are automatically started. The digital certificate becomes valid by being written into the ECU 210 (memory 212) of the vehicle 200. The vehicle 200 may be a vehicle capable of PnC charging (billing).
[0021] For example, the EVSE 300 or the server 100 etc. performs a process of checking the expiration period (validity period) of the digital certificate written in the ECU 210. When the digital certificate is valid because the current time is before the expiration period, the establishment of the communication connection between the vehicle 200 and the EVSE 300 is permitted. As a result, the power transfer between the vehicle 200 and the EVSE 300 becomes possible.
[0022] The digital certificate is issued by the certification authority 400. The digital certificate includes a first digital certificate and a second digital certificate. The expiration period of the first digital certificate is, for example, 5 years from the issuance. The expiration period of the second digital certificate is, for example, 20 years from the issuance. That is, the expiration period of the second digital certificate is longer than the expiration period of the first digital certificate. Thereby, the security of the communication by the first digital certificate is higher than the security of the communication by the second digital certificate. The expiration periods of the first digital certificate and the second digital certificate are not limited to the above examples.
[0023] In addition to being able to communicate with the communication unit 130 of the server 100 as described above, the DCM230 can also communicate with the certification authority 400.
[0024] Each of the processors 110 and 211 is, for example, a CPU (Central Processing Unit) or an MPU (Micro-Processing Unit). Processors 110 and 211 perform various processes by reading system programs and control programs, respectively, loading them into memories 120 and 212, and executing them. In this specification, "processor" is not limited to processors in the narrow sense that execute processing using stored programs, but may also include hardwired circuits such as ASICs (Application Specific Integrated Circuits) and FPGAs (Field-Programmable Gate Arrays). Therefore, the term "processor" can also be interpreted as processing circuitry in which processing is predefined by computer-readable code and / or hardwired circuits.
[0025] The car navigation system 240 is configured to display various information about the vehicle 200. For example, the car navigation system 240 may display the contract status and validity period of the DCM 230, and the type and validity period of the digital certificate written to the ECU 210. The above information may also be displayed on a user terminal (for example, a smartphone or tablet) owned by the user.
[0026] In this case, the DCM contract must be active for the vehicle to receive the digital certificate; if the DCM contract is not active, the vehicle cannot receive the digital certificate. If the vehicle has not received the digital certificate, a communication connection cannot be established between the vehicle and the EVSE.
[0027] Therefore, in this embodiment, if the cancellation of the DCM230 has not been requested by the user of the vehicle 200, the processor 110 transmits a first digital certificate to the DCM230 via the communication unit 130. On the other hand, if the cancellation of the DCM230 has been requested by the user, the processor 110 transmits a second digital certificate to the DCM230 via the communication unit 130.
[0028] This allows for a more reliable and longer period during which the digital certificate remains valid after the DCM230 contract has ceased to be valid, compared to the case where the first digital certificate is sent to the vehicle 200 when a cancellation of the DCM230 is requested.
[0029] (System sequence control) Next, the sequence control by System 1 will be explained with reference to Figures 2 and 3. Note that the processing of Server 100 in Figures 2 and 3 is executed by Processor 110. Also, the processing of Vehicle 200 in Figures 2 and 3 is executed by ECU 210 (Processor 211).
[0030] In step S1, the certification authority 400 issues a second digital certificate. The second digital certificate issued by the certification authority 400 is sent to the DCM230 of the vehicle 200.
[0031] In step S2, the second digital certificate issued in step S1 is written to the ECU 210 of vehicle 200. In other words, the second digital certificate is written to the ECU 210 first. Specifically, the second digital certificate is written to the ECU 210 before vehicle 200 leaves the factory.
[0032] This allows a communication connection between EVSE300 and vehicle 200 to be established using the second digital certificate, even in the initial state of vehicle 200 where the DCM230 contract is not yet active.
[0033] In step S3, the user performs an operation related to the contract for the DCM230 on the car navigation device 240 or the user terminal. As a result, a signal indicating the content of the operation in step S3 is sent to the server 100.
[0034] In step S4, the server 100 determines whether the signal sent to the server 100 based on the operation in step S3 contains information about the DCM230 contract application. If the signal contains information about the DCM230 contract application (Yes in S4), the process proceeds to step S5. If the signal does not contain information about the DCM230 contract application (No in S4), the server 100's processing ends. Note that the processing in step S4 may be performed in response to the server 100 receiving the signal. Alternatively, the server 100 may perform the processing in step S4 in response to receiving the signal before receiving a write notification (described later) indicating that the first digital certificate has been written to the ECU210.
[0035] In step S5, the server 100 sends a command signal to the vehicle 200 (DCM230) via the communication unit 130 to turn on the contract flag of the DCM230. This turns on the contract flag in the vehicle 200. When the contract flag is on, the DCM230 can receive a digital certificate from the server 100 (communication unit 130). On the other hand, when the contract flag is off, the DCM230 cannot receive a digital certificate from the server 100 (communication unit 130). Next, the server 100 proceeds to step S6. Note that "the contract flag is on" is an example of "when the vehicle communication device contract is valid" in this disclosure. Also, "the contract flag is off" is an example of "when the vehicle communication device contract is invalid" in this disclosure.
[0036] In step S6, the server 100 sends a request for issuance of the first digital certificate to the certification authority 400 via the communication unit 130. Next, the server 100 proceeds to step S10.
[0037] In step S7, the certification authority 400 determines whether or not it has received a request to issue the first digital certificate. If it has received a request to issue the first digital certificate (Yes in S7), the process proceeds to step S8. If it has not received a request to issue the first digital certificate (No in S7), the processing of the certification authority 400 ends. Note that the processing in step S7 may be performed at predetermined intervals.
[0038] In step S8, the Certificate Authority 400 issues the first digital certificate. Next, in step S9, the Certificate Authority 400 sends the first digital certificate issued in step S8 to the server 100. After that, the processing of the Certificate Authority 400 is completed.
[0039] In step S10, the server 100 determines whether the first digital certificate has been received by the communication unit 130. If the first digital certificate has been received (Yes in S10), the process proceeds to step S11. If the first digital certificate has not been received (No in S10), the process in step S10 is repeated.
[0040] In step S11, the server 100 transmits the first digital certificate sent from the certification authority 400 in step S9 to the vehicle 200 (DCM230) via the communication unit 130. That is, the server 100 transmits the first digital certificate to the DCM230 when the user of the vehicle 200 applies for a contract with the DCM230 (Yes in S4).
[0041] Here, during the period that the DCM230 contract is valid, the digital certificate can be easily obtained via communication. Therefore, even if the first digital certificate, which has a relatively short validity period, is sent to the DCM230, the vehicle 200 can easily renew the first digital certificate because the DCM230 contract is in place. This enhances the security of communication between the vehicle 200 and the EVSE300 through the first digital certificate, while preventing any interruption in the period during which the vehicle 200 possesses the first digital certificate.
[0042] In step S12, the vehicle 200 determines whether the contract flag of the DCM230 is on or off. If the contract flag of the DCM230 is on (Yes in S12), the process proceeds to step S13. If the contract flag of the DCM230 is off (No in S12), the processing of the vehicle 200 ends. Note that after the vehicle 200 has been shipped from the factory, the process in step S12 may be executed at predetermined intervals.
[0043] In step S13, vehicle 200 determines whether or not it has received a digital certificate. If it has received a digital certificate (Yes in S13), the process proceeds to step S14. If it has not received a digital certificate (No in S13), the process of vehicle 200 ends.
[0044] In step SS14, vehicle 200 writes the received digital certificate to ECU 210 (memory 212). Next, vehicle 200 proceeds to step S15.
[0045] In step S15, the vehicle 200 sends a notification to the server 100 indicating that it wrote the digital certificate in step S14. This notification may include information such as the type of digital certificate written (first digital certificate or second digital certificate) and the date and time it was written. After that, the processing of the vehicle 200 is completed.
[0046] Figure 3 shows the sequence that follows the sequence in Figure 2, and illustrates the sequence when a cancellation request for DCM230 is made.
[0047] In step S16, the server 100 determines whether the communication unit 130 has received a write notification indicating that the first digital certificate has been written to the ECU 210. If the write notification has been received (Yes in S16), the process proceeds to step S17. If the write notification has not been received (No in S16), the server 100's process ends. Note that the process in step S16 may be executed at predetermined intervals.
[0048] Now, let's assume that the information (signal) from step S3 above has been sent to server 100.
[0049] In step S17, the server 100 determines whether the signal sent to the server 100 based on the operation in step S3 contains information about a DCM230 cancellation request, and whether the DCM230 cancellation request was made (the signal was sent to the server 100) three months before the expiration date (end of the validity period) of the first digital certificate. If the answer in step S17 is Yes, the process proceeds to step S18. If the answer in step S17 is No, the server 100's processing ends. The signal containing information about a DCM230 cancellation request is an example of a "cancellation signal" in this disclosure. The server 100 may also perform the processing in step S17 in response to receiving the signal while it has received a write notification (notification in S15) indicating that the first digital certificate has been written to the ECU210. Three months is an example of a "specified period" in this disclosure.
[0050] Furthermore, if the answer in step S17 is No, the server 100 may send a request to the certification authority 400 for the issuance of an updated version of the first digital certificate. This request may be sent to the certification authority 400, for example, three months before the expiration date.
[0051] The above example of March is merely an illustration, and other periods (for example, one day, one week, and one month) may be used as the criteria for the determination in step S17. Furthermore, the above period may be set to the period required for the issuance of the second digital certificate.
[0052] In step S18, the server 100 sends a request for issuance of a second digital certificate to the certification authority 400 via the communication unit 130. The server 100 may adjust the timing of executing the process in step S18 based on the contract period of the DCM 230. For example, the server 100 may execute the process in step S18 a predetermined period before the expiration of the DCM 230 (for example, one month before). The predetermined period may be set to the period required for issuance of the second digital certificate. Next, the server 100 proceeds to step S22.
[0053] In step S19, the certification authority 400 determines whether or not it has received a request for the issuance of a second digital certificate. If it has received a request for the issuance of a second digital certificate (Yes in S19), the process proceeds to step S20. If it has not received a request for the issuance of a second digital certificate (No in S19), the processing of the certification authority 400 ends. Note that the processing in step S19 may be executed at predetermined intervals.
[0054] In step S20, the Certificate Authority 400 issues a second digital certificate. Next, in step S21, the Certificate Authority 400 sends the second digital certificate issued in step S20 to the server 100. After that, the processing of the Certificate Authority 400 is completed.
[0055] In step S22, the server 100 determines whether the second digital certificate has been received by the communication unit 130. If the second digital certificate has been received (Yes in S22), the process proceeds to step S23. If the second digital certificate has not been received (No in S22), the process in step S22 is repeated.
[0056] In step S23, the server 100 transmits the second digital certificate, which was sent from the certification authority 400 in step S21, to the vehicle 200 (DCM230) via the communication unit 130.
[0057] After the processing in step S23, the second digital certificate is written to the ECU 210 by the processing in step S14 in the vehicle 200. Then, by the processing in step S15 in the vehicle 200, a write notification is sent to the server 100 indicating that the second digital certificate has been written to the ECU 210.
[0058] In step S24, the server 100 determines whether or not a write notification for the second digital certificate has been received by the communication unit 130. If a write notification for the second digital certificate has been received (Yes in S24), the process proceeds to step S25. If a write notification for the second digital certificate has not been received (No in S24), the process in step S24 is repeated.
[0059] In step S25, the server 100 sends a command signal to the vehicle 200 (DCM230) via the communication unit 130 to turn off the contract flag of the DCM230. This turns off the contract flag of the DCM230 in the vehicle 200. As a result, the DCM230 is unable to receive digital certificates from the server 100. The server 100 may, for example, execute the process in step S25 on the last day of the contract period for the DCM230.
[0060] As can be seen from steps S17, S24, and S25 above, if the cancellation of DCM230 is requested three months before the expiration date of the first digital certificate, the server 100 switches the DCM230 contract from active to inactive after the communication unit 130 receives a signal from DCM230 indicating that the second digital certificate has been written to ECU210. This prevents the DCM230 contract from being switched to inactive before the second digital certificate is received by the vehicle 200.
[0061] As described above, in this embodiment, if the cancellation of the DCM230 contract has not been requested (for example, if the DCM230 contract has been requested), the server 100 sends the first digital certificate to the DCM230 via the communication unit 130. If the cancellation of the DCM230 contract has been requested, the server 100 sends the second digital certificate to the DCM230 via the communication unit 130. This allows the communication connection between the vehicle 200 and the EVSE300 to be established using the second digital certificate, which has a relatively long validity period, even after the DCM230 contract has been switched from active to inactive. In other words, the communication connection between the vehicle 200 and the EVSE300 can be established more reliably even when the DCM230 contract is not active.
[0062] Furthermore, in this embodiment, if a request for cancellation of DCM230 is made three months before the expiration date of the first digital certificate, the server 100 sends the second digital certificate to DCM230 before DCM230 is cancelled. This ensures that there is approximately three months to issue the second digital certificate. As a result, the second digital certificate can be easily sent to DCM230 before the first digital certificate expires.
[0063] Furthermore, in this embodiment, when the communication unit 130 receives a signal indicating that the user of the vehicle 200 has requested cancellation of the DCM 230, the server 100 transmits a second digital certificate to the DCM 230 via the communication unit 130. This allows the server 100 to execute a process to transmit the second digital certificate to the DCM 230, triggered by the above signal.
[0064] <Variation> Figure 4 shows a modified version of Figure 3. If the user performs an operation related to the DCM230 contract in step S3, the DCM230 contract information is updated. This contract information is stored, for example, in the memory 120 of server 100. This contract information may also be stored in the cloud.
[0065] In step S31, if the IG power of vehicle 200 is turned on, vehicle 200 notifies server 100 via DCM230 that the IG power has been turned on.
[0066] If the answer in step S16 is Yes, the process in step S32 is performed. In step S32, the server 100 determines whether or not the IG power of the vehicle 200 has been turned on. If the notification in step S31 has been received by the communication unit 130, the server 100 determines that the IG power has been turned on. If the above notification has been received (Yes in S32), the process proceeds to step S33. If the above notification has not been received (No in S32), the server 100's process ends.
[0067] In step S33, the server 100 checks the contract information for the DCM230 stored in memory 120. Next, the process proceeds to step S34.
[0068] In step S34, the server 100 determines, based on the contract information, whether a cancellation request for DCM230 has been made and whether the cancellation request was made before 3 months prior to the expiration date of the first digital certificate. If the answer in step S34 is Yes, the process proceeds to step S18. If the answer in step S34 is No, the server 100's process ends. Note that steps S18 onward are the same as in Figure 3, so no repeated explanation will be given.
[0069] As described above, in the modified example shown in Figure 4, the server 100 executes a process to check the contract information of the DCM230 and determines whether or not a cancellation request for the DCM230 has been made based on the above contract information. As a result, the server 100 can detect whether or not a cancellation request for the DCM230 has been made without receiving signals from the car navigation device 240 or the user terminal.
[0070] Furthermore, in the modified example shown in Figure 4, the server 100 executes a process to verify the contract information in response to the vehicle 200's IG power being turned on. As a result, the contract information is verified each time the vehicle 200's IG power is turned on, which helps to suppress delays in the issuance of the second digital certificate after a cancellation request has been submitted.
[0071] Figure 5 shows a modified version of the sequence of events in Figures 2 and 3. As shown in Figure 5, the second digital certificate issued by the certification authority 400 in step S1 is transmitted not only to the vehicle 200 but also to the server 100. The vehicle 200 may also transmit the second digital certificate received from the certification authority 400 to the server 100. The server 100 may also transmit the second digital certificate received from the certification authority 400 to the vehicle 200. Furthermore, the certification authority 400 may transmit the second digital certificate to the server 100 in response to a request from the server 100 to transmit the second digital certificate.
[0072] In step S41, the server 100 stores the second digital certificate sent from the certification authority 400 in memory 120. In this case, memory 120 is an example of the “storage unit” of this disclosure.
[0073] In the example shown in Figure 5, if the answer in step S17 is Yes, the process proceeds to step S42. In step S42, the server 100 transmits the second digital certificate, which was stored in memory 120 in step S41, to the vehicle 200 via the communication unit 130. Note that the other processes are the same as in the above embodiment, so a repeated explanation will not be given.
[0074] With this configuration, the server 100 can send the second digital certificate to the vehicle 200 without requesting the issuance of the second digital certificate from the certification authority 400. As a result, by eliminating the need to request issuance from the certification authority 400, the second digital certificate can be sent to the vehicle 200 more quickly after the cancellation of the DCM230 is requested, and the processing load on the server 100 can be reduced.
[0075] In the above embodiment, an example was shown in which the second digital certificate received from the certification authority 400 is written to the ECU 210 before the vehicle 200 leaves the factory, but the disclosure is not limited thereto. The second digital certificate may be written to the ECU 210 during its manufacture (design).
[0076] The modified example shown in Figure 4 illustrates how contract information is verified when the IG power is turned on, but this disclosure is not limited to this. Contract information may also be verified at times other than when the IG power is turned on (for example, when the connector 302 is plugged into the vehicle 200).
[0077] The configurations (controls) of each of the above embodiments and each modified example may be combined with each other.
[0078] It should be noted that the embodiments disclosed herein are illustrative in all respects and not restrictive. The scope of this disclosure is defined by the claims rather than the description of the embodiments above, and includes all modifications within the meaning and scope equivalent to the claims. [Explanation of Symbols]
[0079] 1 System, 100 Servers, 110 Processors (control units), 120 Memory (storage units), 130 Communication units, 200 Vehicles, 210 ECUs, 220 Battery packs, 230 DCM (Vehicle Communication Modules), 240 Car navigation systems, 300 EVSE (Electric Power Stations), 400 Certification authorities.
Claims
1. A server that transmits a digital certificate used for communication between the vehicle and the power station to the vehicle, A communication unit that communicates with the vehicle's communication device, It comprises a control unit and, The digital certificate includes a first digital certificate and a second digital certificate having a longer validity period than the first digital certificate. The control unit, If the cancellation of the vehicle communication device has not been requested, the first digital certificate is transmitted to the vehicle communication device via the communication unit. A server that, when a request for cancellation of the vehicle communication device is received, transmits the second digital certificate to the vehicle communication device via the communication unit.
2. The server according to claim 1, wherein the control unit transmits the first digital certificate to the vehicle communication device via the communication unit when the user of the vehicle performs an operation to apply for a contract for the vehicle communication device.
3. The control unit, The process of checking the contract information of the vehicle communication device is executed, The server according to claim 1 or 2, which determines whether or not an application for cancellation of the vehicle communication device has been submitted based on the aforementioned contract information.
4. The server according to claim 3, wherein the control unit performs the process of confirming the contract information in response to the vehicle's IG power being turned on.
5. The server according to claim 1 or 2, wherein the control unit transmits the second digital certificate to the vehicle communication device via the communication unit when the communication unit receives a cancellation signal indicating that the user of the vehicle has performed an operation to request cancellation of the vehicle communication device.
6. The server according to claim 1 or 2, wherein if a request for cancellation of the vehicle communication device is made prior to a predetermined period before the expiration date of the first digital certificate, the control unit transmits the second digital certificate to the vehicle communication device via the communication unit before the vehicle communication device is cancelled.
7. The vehicle communication device is capable of receiving the digital certificate from the communication unit when the vehicle communication device contract is valid, and is not capable of receiving the digital certificate from the communication unit when the vehicle communication device contract is invalid. The server according to claim 6, wherein if a request for cancellation of the vehicle communication device is made before the expiration date, the control unit switches the contract of the vehicle communication device from active to inactive after the communication unit receives a signal from the vehicle communication device indicating that the second digital certificate has been written to the vehicle's ECU.
8. The server according to claim 1 or 2, A system comprising a vehicle including a vehicle communication device that communicates with the aforementioned communication unit.
9. The vehicle is equipped with an ECU capable of writing the first digital certificate and the second digital certificate, The system according to claim 8, wherein the second digital certificate is first written to the ECU.
10. The vehicle communication device is capable of communicating with the certification authorities that issue the first digital certificate and the second digital certificate, respectively. The aforementioned server, It includes a storage unit that stores the second digital certificate transmitted from the certification authority to the vehicle communication device and initially written to the ECU, The system according to claim 9, wherein when a request for cancellation of the vehicle communication device is made, the system transmits the second digital certificate stored in the storage unit to the vehicle communication device via the communication unit.