Method and apparatus for hydrogen refueling
The bidirectional communication method for hydrogen refueling addresses inefficiencies in conventional systems by implementing error detection and emergency protocols, enhancing safety and efficiency in hydrogen fuel supply processes.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- HYUNDAI MOTOR CO LTD
- Filing Date
- 2024-03-07
- Publication Date
- 2026-04-28
AI Technical Summary
Conventional hydrogen refueling technologies for hydrogen-electric vehicles are inefficient, slow, and unsuitable for large-scale refueling due to the limitations of unidirectional communication and outdated control techniques, lacking integration with advanced ICT systems.
A bidirectional communication method for hydrogen fuel supply that includes error detection, classification, and handling, along with emergency protocols, to enhance safety, compatibility, and efficiency in hydrogen refueling processes.
The bidirectional communication method improves the safety, compatibility, and reliability of hydrogen refueling by enabling effective error handling and emergency management, optimizing hydrogen fuel supply protocols based on use cases and ensuring interoperability between mobility and dispensers.
Smart Images

Figure 2026513505000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a communication technology for hydrogen fueling in hydrogen fueled mobility, and more particularly, to a hydrogen fueling process that can improve the safety, compatibility, efficiency, and reliability of hydrogen fueling, error handling for the hydrogen fueling process, and emergency handling methods and devices using the same.
Background Art
[0002] The content described herein simply provides background information for this example and does not provide prior art.
[0003] A hydrogen vehicle or a hydrogen electric vehicle means a pollution-free vehicle that runs on electrical energy generated by the reaction of high-pressure hydrogen stored in the vehicle with air in the atmosphere. A hydrogen electric vehicle is also called a fuel cell electric vehicle (FCEV). Most hydrogen electric vehicles utilize hydrogen as an energy source and use a fuel cell system to produce electricity and move. In a hydrogen electric vehicle, not only pure water (H2O) is emitted during the process of generating electricity, but it also has a function of removing ultrafine dust in the atmosphere during operation, so it is attracting attention as an environmentally friendly future mobility. Hydrogen, as a fuel, is considered to be infinite on Earth, and the energy production process is environmentally friendly, so it has received wide acclaim as a technology with potential for widespread use across industries.
[0004] Hydrogen-fueled mobility refers to a type of mobility that uses hydrogen as an energy source or generates electrical energy from hydrogen fuel, which is then used to drive electric motors. In addition to the aforementioned hydrogen electric vehicles, hydrogen-fueled mobility includes aerial mobility, as well as industrial trucks, trains, ships, and aircraft, and can include devices that generate electrical energy from hydrogen fuel and use it for propulsion.
[0005] Most hydrogen fuel cell vehicles (HEVs) safely store high-pressure hydrogen in hydrogen fuel storage tanks and supply oxygen through an air supply system to a fuel cell stack, where an electrochemical reaction occurs between hydrogen and oxygen to produce electrical energy. The produced electrical energy is converted into kinetic energy through a drive motor to power the HEV, and while driving, HEVs have the advantage of emitting only pure water through an exhaust port.
[0006] On the other hand, while the concept of a hydrogen fueled car (hydrogen-fueled car) is also a vehicle that uses hydrogen as fuel, a hydrogen fueled car uses a system where hydrogen is directly burned in an engine (ICE, Internal Combustion Engine) to generate heat that drives an electric motor. The method of refueling a hydrogen fueled car with hydrogen is not much different from the method of refueling a hydrogen-fueled car with hydrogen.
[0007] Control techniques for supplying hydrogen to vehicles that utilize hydrogen as fuel ultimately aim to control the temperature and pressure of the compressed hydrogen storage system (CHSS) on the fuel cell side to operate under critical temperature and pressure conditions necessary for safe hydrogen refueling.
[0008] Conventional hydrogen refueling processes, control techniques, and protocols for hydrogen-electric vehicles were defined in a time when wired and wireless communication technologies and computing techniques for control were not yet mature, and therefore do not accurately reflect the recent advancements in information and communication technology (ICT). Consequently, conventional hydrogen refueling technologies for hydrogen-electric vehicles are inefficient, slow, and unsuitable for large-scale hydrogen refueling.
[0009] In particular, in the case of hydrogen refueling communication, most hydrogen refueling control devices utilize unidirectional infrared communication devices in the wireless system, and therefore, even wireless-based hydrogen refueling communication still suffers from the limitations and vulnerabilities of unidirectional communication. [Overview of the Initiative] [Problems that the invention aims to solve]
[0010] The object of the present invention, in order to solve the aforementioned problems, is to provide a hydrogen fueling process for hydrogen fueled mobility, a communication protocol for the process, a method for negotiating a communication protocol for the process, a method for negotiating a fueling protocol, a method for negotiating charging parameters, a monitoring and control method, a safety check-in method, a safety check-out method, and an apparatus utilizing the same.
[0011] Another object of the present invention relates to error handling and emergency handling methods and apparatus for a hydrogen refueling process, which handle errors and / or emergencies occurring during communication protocol negotiation, fueling protocol negotiation, charging parameter negotiation, monitoring and control, safety check-in, and safety check-out processes for a hydrogen refueling process.
[0012] Another object of the present invention is to provide a hydrogen refueling communication bidirectional process that can be controlled to determine whether a conventional or advanced communication medium is used to effectively achieve a hydrogen fueling goal, a communication protocol negotiation process that takes bidirectional / unidirectional communication into consideration, and an apparatus that utilizes the same. [Means for solving the problem]
[0013] A communication method for hydrogen fuel supply according to one embodiment of the present invention for achieving the above objective is a communication method for hydrogen fuel supply (fueling) performed by a communication device of a hydrogen fuel mobility, and includes the steps of: detecting an error occurring during a communication process for preparing for hydrogen fuel supply between a dispenser that supplies hydrogen to mobility and mobility, or during the process in which the dispenser supplies hydrogen to mobility; determining whether or not to stop the communication process or the hydrogen fuel supply process in response to the detected error; and performing a subsequent process defined based on the detected error.
[0014] In a communication method for supplying hydrogen fuel performed by a mobility communication device according to one embodiment of the present invention, the step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error may include the step of classifying the detected error as either a safety-critical error or a non-safety-critical error.
[0015] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error may further include a step of classifying the detected error as a communication error, a system error, or a qualitative error, if the detected error is not a safety-critical error.
[0016] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error may include a step of performing an emergency handling process if the detected error is a safely fatal error.
[0017] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error may further include the step of determining whether to replace the first fuel supply protocol of the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol if the detected error is not a safely fatal error.
[0018] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error may include the step of transmitting a message to a dispenser, including whether or not the communication process or the hydrogen fuel supply process has been terminated.
[0019] A communication device for hydrogen fuel mobility according to one embodiment of the present invention includes a memory for storing at least one instruction and a processor for executing at least one instruction, the processor being able to detect errors occurring during the communication process for preparing for hydrogen fuel supply between a dispenser that supplies hydrogen to mobility and mobility, or during the process in which the dispenser supplies hydrogen to mobility, the processor being able to determine whether or not to stop the communication process or the hydrogen fuel supply process in response to the detected error, and the processor being able to perform subsequent processes defined based on the detected error.
[0020] When the processor decides whether to interrupt the communication process or the hydrogen fueling process in response to a detected error, it can classify the detected error as either a safety-critical error or a non-safety-critical error.
[0021] When the processor decides whether to interrupt the communication process or the hydrogen fueling process in response to a detected error, it can classify the detected error as either a communication error, a system error, or a qualitative error, provided that the error is not safely fatal.
[0022] When the processor performs a subsequent process defined based on the detected error, it can perform an emergency handling process if the detected error is a safely fatal error.
[0023] When determining whether to terminate the communication process or the hydrogen fuel supply process for a detected error, if the detected error is not a safety-critical error, the processor can decide whether to replace the first fuel supply protocol of the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol.
[0024] When the processor performs a subsequent process defined based on the detected error, it can transmit a message including whether to terminate the communication process or the hydrogen fuel supply process to the dispenser.
[0025] The communication device of a dispenser for supplying hydrogen fuel to a hydrogen fuel mobility according to an embodiment of the present invention includes a memory storing at least one or more instructions and a processor executing at least one instruction. The processor can detect an error occurring during a communication process for preparing a hydrogen fuel supply between the dispenser and the mobility or a process in which the dispenser supplies hydrogen to the mobility by at least one or more instructions, determine whether to terminate (stop) the communication process or the hydrogen fuel supply process for the detected error, and perform a subsequent process defined based on the detected error.
[0026] A communication method for hydrogen fuel supply (fueling) performed by a communication device of a dispenser for supplying hydrogen fuel to a hydrogen fuel mobility according to an embodiment of the present invention can include a step of detecting an error occurring during a communication process for preparing a hydrogen fuel supply between the dispenser and the mobility or a process in which the dispenser supplies hydrogen to the mobility, a step of determining whether to terminate (stop) the communication process or the hydrogen fuel supply process for the detected error, and a step of performing a subsequent process defined based on the detected error.
[0027] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to an embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process for a detected error may include the step of classifying the detected error into either a safety-critical error or a non-safety-critical error.
[0028] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to an embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process for a detected error may further include the step of classifying the detected error into either a communication error, a system error, or a Qualitative error when the detected error is a non-safety-critical error.
[0029] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to an embodiment of the present invention, the step of performing a subsequent process defined based on the detected error may include the step of performing an emergency handling process when the detected error is a safety-critical error.
[0030] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to an embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process for a detected error may further include the step of determining whether to replace the first fuel supply protocol of the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol when the detected error is a non-safety-critical error.
[0031] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error may include the step of performing a hydrogen fuel supply process based on a second fuel supply protocol when a first fuel supply protocol in the communication process or the hydrogen fuel supply process is replaced by a second fuel supply protocol.
[0032] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error may include the step of transmitting a message to the mobility device, including whether or not the communication process or the hydrogen fuel supply process has been terminated.
[0033] In a communication method for supplying hydrogen fuel performed by a communication device of a dispenser according to one embodiment of the present invention, if a message including whether or not the communication process or the hydrogen fuel supply process is being stopped includes the stopping of the communication process or the hydrogen fuel supply process, the message may further include a reason code corresponding to an appropriate reason for the stop. [Effects of the Invention]
[0034] According to one embodiment of the present invention, a communication method for hydrogen fuel supply and a device utilizing the same, namely a hydrogen refueling control device or communication control device for a vehicle / mobility, the limitations and vulnerabilities of existing unidirectional communication can be overcome in the hydrogen fueling process and communication protocol for hydrogen fueled mobility, including fuel cell electric vehicles (FCEVs) and hydrogen fuel engines, thereby improving the safety, compatibility, efficiency, and reliability of hydrogen refueling.
[0035] Furthermore, according to one embodiment of the present invention, it is possible to provide a communication protocol negotiation for hydrogen fuel supply, a fuel supply protocol negotiation, a parameter exchange method, and a communication protocol fallback rule that select the communication protocol required to execute the protocol for hydrogen fuel supply on a use case basis, taking into account the preference of the mobility or dispenser, while maximizing interoperability between the mobility and dispenser and considering backward compatibility.
[0036] Furthermore, according to one embodiment of the present invention, rules and procedures necessary for negotiating communication protocols, negotiating fuel supply protocols, and exchanging fuel supply parameters can be provided to effectively determine whether to use a conventional or advanced communication medium in order for mobility and dispensers to cooperate to effectively achieve a hydrogen refueling goal.
[0037] Furthermore, according to one embodiment of the present invention, rules and procedures necessary for monitoring and control, safety check-in, and safety check-out can be provided so that mobility and dispensers can cooperate to effectively achieve the fueling goal.
[0038] Furthermore, according to one embodiment of the present invention, rules and procedures necessary for use cases in which the monitoring and control, safety check-in, and safety check-out processes are linked with the negotiation of communication protocols, the negotiation of fuel supply protocols, and the exchange of fuel supply parameters, in order for mobility and dispensers to cooperate to effectively achieve the fueling goal, can be provided.
[0039] Furthermore, according to one embodiment of the present invention, rules and procedures necessary for use cases in which communication protocol negotiation, fueling protocol negotiation, charging parameter negotiation, monitoring and control, error handling for the hydrogen refueling process to handle errors and / or emergencies occurring during the safety check-in and safety check-out processes, and emergency handling processes are linked in order for mobility and a dispenser to cooperate to effectively achieve the fueling goal. [Brief explanation of the drawing]
[0040] [Figure 1] This is a conceptual diagram of a hydrogen refueling system for a fuel cell electric vehicle (FCEV) to which the hydrogen refueling bidirectional communication process according to one embodiment of the present invention can be applied. [Figure 2] Figure 1 is a partially enlarged view illustrating the physical fastening structure between the FCEV and the dispenser in the hydrogen refueling system. [Figure 3] This graph illustrates the changes in the state of hydrogen fuel that occur during the hydrogen refueling process using the hydrogen refueling system shown in Figure 1. [Figure 4] This is a framework for a functional block that performs a series of hydrogen refueling procedures, employing a hydrogen refueling communication bidirectional process according to one embodiment of the present invention. [Figure 5] This diagram illustrates the communication stacks associated with each use case that can be employed in the hydrogen refueling bidirectional communication process according to one embodiment of the present invention, focusing on the OSI (Open Systems Interconnection Reference Model) 7-layer structure. [Figure 6]This is an illustrative diagram illustrating the pairing process of a discovery and pairing procedure that can be used in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention. [Figure 7] This is an illustrative diagram illustrating backward compatibility that can be adopted in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention. [Figure 8] This is an illustrative diagram illustrating backward compatibility that can be adopted in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention. [Figure 9] This is an illustrative diagram illustrating a communication data usage classification that can be adopted in a hydrogen refueling bidirectional communication process according to one embodiment of the present invention, and backward compatibility between the communication data usage classifications. [Figure 10] This is a flowchart illustrating the authentication process of a communication security procedure that can be used in a hydrogen refueling bidirectional communication process according to one embodiment of the present invention. [Figure 11] This is a flowchart illustrating a communication protocol negotiation procedure that can be used in a two-way hydrogen refueling communication process according to one embodiment of the present invention. [Figure 12] This is a flowchart illustrating the fuel supply protocol negotiation procedure in a two-way hydrogen refueling communication process according to one embodiment of the present invention. [Figure 13] This is a flowchart illustrating the fueling parameter exchange / negotiation procedure that can be used in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention. [Figure 14] This is a conceptual diagram illustrating a table of parameters transmitted from the mobility unit to the dispenser side in a fuel supply parameter negotiation / exchange process according to one embodiment of the present invention. [Figure 15]This is a conceptual diagram illustrating a table of parameters transmitted from the dispenser to the mobility side in a fuel supply parameter negotiation / exchange process according to one embodiment of the present invention. [Figure 16] This is a conceptual block diagram of the internal structure of a generalized computing system that can be mounted on hydrogen fuel mobility, dispensers, and / or refueling stations as a communication device, communication control device, and / or electronic control device for hydrogen fuel supply according to one embodiment of the present invention. [Figure 17] This is an operation flowchart illustrating a communication method for supplying hydrogen fuel according to one embodiment of the present invention. [Figure 18] This is an operation flowchart illustrating a communication method for supplying hydrogen fuel according to another embodiment of the present invention. [Modes for carrying out the invention]
[0041] In addition to the aforementioned objectives, other objectives and features of the present invention will be clearly indicated through the description of embodiments with reference to the accompanying drawings. Since the present invention can be modified in various ways and has many different embodiments, we will attempt to illustrate and describe in detail specific embodiments with reference to the drawings. However, this should not be understood as limiting the present invention to specific embodiments, but rather as including all modifications, equivalents, or substitutes that fall within the spirit and technical scope of the present invention.
[0042] Terms such as First, Second, A, and B may be used to describe various components, but the components should not be limited by such terms. The terms are used solely for the purpose of distinguishing one component from another. For example, without departing the scope of the present invention, the First component may be named the Second component, and similarly, the Second component may be named the First component. The term "and / or" includes a combination of multiple related listed items or any of the multiple related listed items.
[0043] In the embodiments of this application, "at least one of A and B" may mean "at least one of A or B" or "at least one of one or more combinations of A and B". Also, in the embodiments of this application, "one or more of A and B" may mean "one or more of A or B" or "one or more of one or more combinations of A and B".
[0044] When it is mentioned that one component is "linked" or "connected" to another component, it should be understood that it may be directly linked or connected to the other component, but there may also be other components in between. Conversely, when it is mentioned that one component is "directly linked" or "directly connected" to another component, it should be understood that there are no other components in between.
[0045] The terminology used in this application is used solely to describe specific embodiments and is not intended to limit the invention. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this application, terms such as “includes” or “having” are intended to specify the existence of features, figures, stages, operations, components, parts, or combinations thereof described in the specification, and should be understood not to preemptively exclude the possibility of the existence or addition of one or more other features, figures, stages, operations, components, parts, or combinations thereof.
[0046] Unless otherwise specified, all terms used herein, including technical or scientific terms, have the same meaning as those generally understood by a person of ordinary skill in the art to which this invention pertains. Terms as defined in commonly used dictionaries should be interpreted as having the meaning consistent with their meaning in the context of the relevant art, and not as ideal or overly formal unless expressly defined herein.
[0047] Some terms used in this specification are defined as follows: Hydrogen electric vehicles generally include all hydrogen fuel cell vehicles (FCEVs) that utilize fuel cells, or ICE (internal combustion engine) based vehicles that use hydrogen as fuel. The hydrogen electric vehicles described below may also be simply referred to as FCEVs.
[0048] Although the following embodiments primarily describe hydrogen fuel cell vehicles, other embodiments of the present invention may include ICE-based hydrogen vehicles that utilize hydrogen as fuel. In the following embodiments, hydrogen fueling protocols and / or communication protocols for hydrogen fuel supply are disclosed, mainly for hydrogen fuel cell vehicles, and according to other embodiments of the present invention, the hydrogen fuel supply protocols and / or communication protocols for hydrogen fuel supply disclosed in the following embodiments may also be applied to ICE-based hydrogen vehicles. Hydrogen fluid fuels can include gaseous hydrogen fuel or liquid hydrogen fuel.
[0049] A Compressed Hydrogen Storage System (CHSS) may include at least one tank mounted on the vehicle and a device coupled to this tank for compressing and storing hydrogen in the tank. A Pressure Relief Device (PRD) is a device located in the CHSS that can isolate the stored hydrogen from the vehicle's hydrogen refueling system and the surrounding environment, and can release the hydrogen to the outside.
[0050] Hydrogen refueling essentially refers to the process of receiving high-pressure hydrogen from a dispenser at a hydrogen station and compressing and storing it in a vehicle's tank. Hydrogen refueling can be used simply as synonymous with fueling in the context of supplying hydrogen fuel to a hydrogen electric vehicle. That is, in this specification, "fueling" can be used to mean fuel supply, hydrogen refueling, or charging, and charging can mean the refueling of hydrogen fuel. For example, a fuel supply protocol may be referred to as a refueling protocol, a fuel supply session may be referred to as a refueling session, and a fuel supply method may be referred to as a hydrogen refueling method or a charging (fueling) method.
[0051] The pressure ramp rate (PRR) is expressed in MPa / min and represents the rate of increase in the CHSS pressure. The Average Pressure Ramp Rate (APRR) represents the average value of the pressure increase rate from the start to the end of hydrogen fueling. Pre-cooling basically refers to the process of cooling hydrogen at a hydrogen refueling station before refueling.
[0052] A dispenser is a component that delivers pre-cooled hydrogen to the CHSS (Hydrogen-Suspended Stabilization System). Dispensers are located at hydrogen refueling stations and can perform hydrogen refueling operations between the hydrogen storage tanks at the refueling station and the CHSS in vehicles. A nozzle is a device connected to a dispenser and coupled to the receptacle of a hydrogen electric vehicle, allowing for the transfer of hydrogen fuel. The term "fueling session" can be used to include communication sessions that take place throughout the entire use case for hydrogen fueling.
[0053] Interoperability can refer to the state in which components of different systems can work together to perform the intended function of the overall system. Information interoperability can refer to the ability of two or more networks, systems, devices, applications, or components to share and use information securely, effectively, and easily with little or no inconvenience to users.
[0054] Correlation / Association can include the procedure for establishing a relationship between two peer communication entities. Command and control communication may refer to communication between an electric vehicle hydrogen fuel supply system and a hydrogen electric vehicle that exchanges information necessary for starting, controlling, and ending the hydrogen fuel supply process.
[0055] On the other hand, while the following detailed description illustrates embodiments related to hydrogen electric vehicles or fuel cell electric vehicles (FCEVs), it will be obvious to those skilled in the art that the concept of the present invention can be applied to a wide variety of hydrogen-fueled mobility. Hydrogen-fueled mobility refers to a type of mobility that uses hydrogen as an energy source or generates electrical energy using hydrogen as fuel, and uses this to drive an electric motor. In addition to hydrogen electric vehicles, hydrogen-fueled mobility may also include aerial mobility, as well as industrial trucks, trains, ships, and aircraft that produce electrical energy using hydrogen as fuel and use it for propulsion.
[0056] Furthermore, the bidirectional communication process for hydrogen refueling according to the present invention can be partially applied not only to hydrogen fuel mobility but also to buildings or facilities that use hydrogen as an energy source. Furthermore, in the following explanation, hydrogen fuel may include at least one of gaseous hydrogen and liquid hydrogen, and may essentially mean compressed hydrogen, but is not limited to this.
[0057] Furthermore, for the sake of explanation, vehicles utilizing a two-way hydrogen refueling and communication process will primarily be described as fuel cell electric vehicles (FCEVs), but the explanation is not limited to this configuration and can also include hybrid electric vehicles (EVs) and internal combustion engine (ICE) vehicles that use hydrogen as fuel.
[0058] In the following specification, some or all of the processes of communication methods, communication protocol negotiation methods, hydrogen refueling (fueling) protocol negotiation methods, and hydrogen refueling (fueling) parameter negotiation methods performed in hydrogen fuel mobility may be performed by an electronic control unit (ECU), communication device, or communication control device within the hydrogen fuel mobility.
[0059] Some or all of the processes of the communication method, communication protocol negotiation method, hydrogen refueling (fueling) protocol negotiation method, hydrogen refueling (fueling) parameter negotiation method, hydrogen refueling (fueling) method, and hydrogen refueling (fueling) control method performed in the dispenser in the following specification may be performed by the dispenser's controller, electronic control unit, communication device, or communication control device. Furthermore, some of the processes of the said method may be performed by the controller, electronic control unit, communication device, or communication control device of the refueling station associated with the dispenser.
[0060] On the other hand, even technologies that were publicly known before the filing date of this invention may be included as part of the structure of the present invention as necessary, and such will be described herein to the extent that it does not obscure the spirit of the present invention. However, in describing the structure of the present invention, detailed explanations of publicly known technologies that were publicly known before the filing date and that would be obvious to a person skilled in the art may obscure the spirit of the present invention, so overly detailed explanations of publicly known technologies will be omitted. Furthermore, the spirit of this invention is not intended to assert rights over such publicly known technologies, and the content of publicly known technologies may be included as part of the present invention to the extent that it does not depart from the spirit of the present invention.
[0061] For example, IrDA technology can be used for unidirectional communication, short-range wireless communication technologies (Bluetooth®, WLAN, UWB) can be used for bidirectional communication, and wired communication technologies for unidirectional / bidirectional communication can utilize prior art known before the filing of the present invention. At least some of these prior arts can be applied as elemental technologies necessary for carrying out the present invention.
[0062] Preferred embodiments of the present invention will be described in detail below with reference to the attached drawings. Figure 1 is a conceptual diagram of a hydrogen refueling system for a fuel cell electric vehicle (FCEV) to which the hydrogen refueling bidirectional communication process according to one embodiment of the present invention can be applied. Figure 2 is a partially enlarged view illustrating the physical fastening structure between the FCEV and the dispenser in the hydrogen refueling system of Figure 1. Figure 3 is a graph illustrating the state changes of the hydrogen fuel that occur during the hydrogen refueling process using the hydrogen refueling system of Figure 1.
[0063] Referring to Figure 1, the hydrogen refueling system may be configured to include a hydrogen refueling station and a hydrogen electric vehicle 100 in a broad sense. In addition to the mechanical, structural, electrical, electronic, and communication devices that are fundamental to a vehicle, the hydrogen electric vehicle 100 may be equipped with an electronic control device 110 for hydrogen refueling, a vehicle system 120, a vehicle tank 130, and a receptacle 150.
[0064] The electronic control unit 110 can send and receive signals and data via wired or wireless means to and from a hydrogen refueling station or the electronic control unit 210 of the hydrogen refueling station, process this data, and control hydrogen refueling on the vehicle side. The electronic control unit 110 can be configured as at least part of other electronic control units installed in the vehicle, or vice versa, and may be referred to as the first electronic control unit or electronic control unit #1.
[0065] The vehicle system 120 may be connected to a first electronic control unit 110 and configured to control hydrogen filling and hydrogen release of the vehicle tank 130 and monitor the state of the vehicle tank 130 based on signals and commands from the first electronic control unit 110. The vehicle system 120 may be configured to control the operation of the fuel cell system by embodiment, include components that perform such control operations, or be coupled with such components. Such a vehicle system 120 also performs vehicle safety functions and may be referred to as a vehicle safety system in this case.
[0066] The vehicle may be provided with at least one, preferably more than one, vehicle tank 130. The vehicle tank 130 can compress and store hydrogen supplied from the hydrogen refueling station under the control of the vehicle safety system, and can release the stored hydrogen.
[0067] Furthermore, the vehicle tank 130 may correspond to a hydrogen storage system attached to the vehicle. In this case, the hydrogen storage system may consist of a high-pressure hydrogen storage tank, pressure control equipment, high-pressure piping, and an external frame. The high-pressure hydrogen storage tank may have a capacity of several tens to several hundreds of liters and may be configured as a series of smaller storage tanks connected in parallel. A boss unit through which hydrogen fuel can enter and exit may be attached to the high-pressure hydrogen storage tank, and hydrogen filling and release can be controlled through the boss unit. Valves, pressure reduction mechanisms, and sensors for various measurements may be attached to the boss unit. Such a hydrogen storage system is known as a compressed hydrogen storage system (CHSS), and for convenience of explanation, the term "vehicle tank" in this specification may mean a CHSS.
[0068] The aforementioned hydrogen electric vehicle 100 may, but is not limited to, a fuel cell system including a fuel cell stack, and for convenience of explanation, may be simply referred to as "FCEV," "vehicle," or "mobility 100." In the following specification, the subject referred to simply as "vehicle" or "mobility" may be understood to include not only the hydrogen electric vehicle 100 but also other vehicles / mobilities that use hydrogen as fuel (hydrogen fueled vehicle / mobility).
[0069] A hydrogen refueling station may be equipped with a dispenser (200), an electronic control unit (210), a refueling station system (220), a hydrogen tank (230), a station box (240), and a nozzle (250).
[0070] The dispenser 200 can supply hydrogen from the hydrogen tank 230 to the vehicle through a nozzle 250 that is firmly connected to the vehicle's receptacle 150, under the control of the filling station system 220. The dispenser 200 may, but is not limited to, include an electronic control unit 210 inside its housing. The nozzle 250 can essentially be installed at the end of a cable that extends for a certain length outside the housing of the dispenser 200.
[0071] The electronic control unit 210 can transmit and receive signals and data via wired or wireless connection to the vehicle's first electronic control unit 110 for hydrogen refueling, process this data, and control hydrogen refueling at the hydrogen refueling station. The electronic control unit 210 can exchange pre-set signals and data with the refueling station system 220. The electronic control unit 210 may also be referred to as the second electronic control unit or electronic control unit #2.
[0072] The aforementioned first electronic control unit 110 and second electronic control unit 210 may each be composed of multiple electronic control units, and may be configured to operate by matching different electronic control units to each other for each communication protocol. In this case, it may be useful when falling back for backward compatibility, and when bidirectional communication is unavailable and unidirectional communication must be used. It may also be useful when actually performing charging after pairing with NFC, or when using different communication methods in combination, such as when using Wi-Fi.
[0073] The refueling station system 220 can monitor and regulate the pressure, rate, and temperature of hydrogen released from the hydrogen tank 230 based on signals and / or data from the second electronic control unit. To this end, the refueling station system 220 can control the operation of the station box 240 connected to the discharge port and discharge valve of the hydrogen tank 230. The refueling station system 220 may also be referred to as the refueling station safety system.
[0074] In other embodiments of the present invention, the communication entity associated with the dispenser 200 for communicating with the vehicle / mobility 100 may be an electronic control unit 210, a separate communication device mounted on the dispenser 200, or an electronic control unit or separate communication device in the filling station system 220 may communicate with the vehicle / mobility 100 on behalf of the dispenser 200.
[0075] In yet another embodiment of the present invention, the communication control device for communicating with the dispenser 200 side in the vehicle / mobility 100 may be the first electronic control device 110, or it may be a separate communication control device.
[0076] The hydrogen tank 230 stores hydrogen or compressed hydrogen. The hydrogen tank 230 can release the stored hydrogen at a predetermined pressure and rate under the control of a safety management module within the filling station system 220. The hydrogen tank may also be referred to as a hydrogen storage tank.
[0077] The station box 240 may be equipped with an adjustment valve whose inlet is connected to the outlet or discharge valve of the hydrogen tank 230 and whose outlet is connected to the dispenser 200 or a nozzle 250 coupled to the dispenser 200. The station box 240 may be equipped with means for adjusting the pressure, velocity, temperature, etc. of the discharged hydrogen, or components that perform functions corresponding to such means. The station box 240 may also be equipped with sensors for measuring the pressure, velocity, temperature, etc. of the discharged hydrogen.
[0078] The nozzle 250 can be connected to the hydrogen fuel supply system of the dispenser 200 through a conduit or flexible pipe of a predetermined length. The nozzle 250 may have a shape and structure that allows it to interlock tightly and securely with the vehicle's receptacle. As shown in Figure 2, the nozzle 250 can engage with the receptacle 150. At this time, signals and information regarding the engagement state between the nozzle 250 and the receptacle 150 are transmitted to the first electronic control unit and the vehicle safety system, and can also be transmitted to the second electronic control unit and the filling station safety system, via the first sensor 160 installed on the vehicle and the second sensor 260 attached to the nozzle 250.
[0079] The hydrogen fuel, pre-cooled from the aforementioned hydrogen refueling station, is supplied to the hydrogen electric vehicle 100 via the dispenser 200. At this time, the hydrogen refueling process can be described by parameters including the pressure increase rate (PRR) and / or the mean pressure increase rate (APRR).
[0080] The interface between the hydrogen refueling station and the vehicle 100 can be handled by the dispenser 200. The dispenser 200 may be configured to control the target pressure and injection rate for hydrogen refueling by integrating information indirectly obtained from the vehicle tank 130 and fuel supply information from the hydrogen refueling station.
[0081] In existing technology, there are two methods for transmitting information from vehicle 100 to dispenser 200: a communication method and a non-communication method. When using communication, existing technology simply transmits the temperature and pressure values of vehicle tank 130 of vehicle 100 to dispenser 200 in a one-way manner. Dispenser 200 cannot actively utilize this information and uses it only as a safety standard, such as an emergency stop at the limit temperature and pressure. Furthermore, the hydrogen refueling protocol for safe and rapid refueling is managed by dispenser 200, and it has only minimal safety management devices that automatically release hydrogen through a pressure relief device (PRD) without active safety management of vehicle tank 130.
[0082] On the other hand, to address the phenomenon of rising hydrogen gas temperature during hydrogen refueling (see Figure 3), a hydrogen refueling station may be equipped with a precooler. The precooler can lower the temperature of the hydrogen fuel through pre-cooling. The precooler may be installed in or coupled to at least one of the hydrogen tank 230 and the station box 240. Of course, the precooler may also be installed in or coupled to the piping that transports hydrogen at the hydrogen refueling station.
[0083] The dispenser 200 and the second electronic control unit may be equipped with charge control logic, which can be used to control the hydrogen fueling process by utilizing state information such as temperature and pressure of the hydrogen fuel supplied to the vehicle or filled into the vehicle tank 130, and filling state information such as the CHSS filling rate (SOC, State of Charge).
[0084] As mentioned above, the hydrogen refueling process is controlled by a dispenser 200 between the vehicle 100 and the hydrogen refueling station, and such a dispenser 200 may be equipped with a protocol for supplying hydrogen fuel to the vehicle according to a defined procedure. Such a hydrogen refueling protocol may also be installed in the vehicle. The protocols installed in the vehicle and dispenser 200 may include at least a portion of a communication protocol that conforms to SAE standards, ISO standards, etc.
[0085] To meet the minimum safety requirements, simulations can be conducted through thermodynamic modeling under various conditions. The parameters derived from these simulations can then be used to implement table-based or MC-formula-based partial real-time correction methods. These minimum safety requirements may include upper limits on the temperature and pressure conditions of the CHSS (Chemical Heat Storage System) and guidelines for the State of Charge (SOC).
[0086] If the dispenser 200 does not actively control state values related to hydrogen refueling, the conventional table-based method is extremely inefficient and has difficulty responding flexibly to changes in surrounding conditions because it does not utilize the temperature of the pre-cooled hydrogen fuel provided at the gas refueling station or the temperature of the vehicle tank 130 measured by the vehicle 100. Furthermore, although the conventional MC-Formula-based method corrects the temperature of the pre-cooled hydrogen fuel in real time, its calculation and application methods are complex and have limitations in their application, making it difficult to expand. Thus, existing communication protocols have been developed with the safe completion of refueling as their primary goal, and there are no alternatives that can actively control sudden situations such as excessive pre-cooling or overheating of the vehicle tank 130. As a result, problems such as increased operating costs due to overcooling and refueling delays due to overheating may occur.
[0087] For example, when hydrogen fuel is filled into a vehicle tank (see 130 in Figure 1), the internal temperature of the vehicle tank rises due to the heat of compression, which in turn raises the temperature of the hydrogen fuel inside the vehicle tank. The vehicle tank is constructed so that its dome and body are surrounded by carbon fiber, which has low heat transfer efficiency, in order to block heat exchange between the outside atmosphere and the hydrogen fuel stored inside. Therefore, when the temperature of the hydrogen fuel inside the vehicle tank rises during the filling process, the low heat transfer characteristics of the vehicle tank mean that the temperature rise observed on the surface of the vehicle tank may be negligible compared to the internal temperature rise until the filling is completed.
[0088] On the other hand, temperature control during the hydrogen refueling process can aim to control the internal temperature of the vehicle tank 130 to 85°C or lower when the final refueling is completed, after receiving the supply of pre-cooled hydrogen gas. That is, as shown in the characteristic curve for hydrogen temperature during hydrogen refueling in Figure 3, the temperature of the hydrogen fuel decreases at a constant rate in Phase I (P1), which is the pre-cooling stage of the hydrogen refueling station. In Phase II (P2), which is the stage in which hydrogen fuel is supplied from the hydrogen refueling station to hydrogen mobility such as vehicles, the temperature of the hydrogen fuel gradually rises due to the thermal mass of the hydrogen refueling station. In Phase III (P3), which is the stage in which hydrogen fuel is transferred from inside the vehicle to the vehicle tank, the temperature of the hydrogen fuel further gradually rises due to the thermal mass of the vehicle. In Phase IV (P4), which is the stage in which hydrogen fuel is compressed and stored in the vehicle tank, the temperature of the hydrogen fuel may rise rapidly due to the heat of compression.
[0089] Therefore, in this embodiment, the hydrogen refueling procedure can be effectively carried out through active state variable control that reflects real-time measurement data via a bidirectional hydrogen refueling communication process, and a hydrogen refueling protocol can be provided for this purpose.
[0090] Figure 4 shows a framework for a functional block that performs a series of hydrogen refueling procedures, employing a two-way hydrogen refueling communication process according to one embodiment of the present invention (hereinafter referred to as the "hydrogen refueling framework"). Referring to Figure 4, the hydrogen refueling framework consists of use case (UC) functional blocks: discovery and pairing functional block (hereinafter abbreviated as "UC1" or "UC-1"), communication security functional block (UC2 or UC-2), communication protocol negotiation functional block (UC3 or UC-3), fueling protocol negotiation functional block (UC4 or UC-4), fueling parameter negotiation functional block (UC5 or UC-5), safety check-in functional block (UC6 or UC-6), monitoring and control functional block (UC7 or UC-7), safety check-out functional block (UC8 or UC-8), termination functional block (UC9 or UC-9), error handling functional block (UC10 or UC-10), and emergency handling functional block. It may be equipped with a handling function block (UC11 or UC-11).
[0091] The UC1 to UC11 functional blocks can correspond to chronological stages (S401 to S411), as illustrated in Figure 4. In this case, Figure 4 may be understood as an operation flowchart that includes the chronological stages (S401 to S411). UC10 and UC11 may be individually connected to UC3 through UC8, respectively, and configured to perform error handling and / or emergency handling in each use case.
[0092] The aforementioned use cases are functional blocks that collectively provide the entire hydrogen refueling procedure of a hydrogen refueling system in a consistent manner for safe and secure fueling communication. The vehicle and dispenser can sequentially execute each use case in a specific order to achieve the hydrogen refueling objective.
[0093] Furthermore, after the dispenser nozzle is connected to the vehicle receptacle, the vehicle and dispenser can perform fuel supply communication by realizing each use case in the order shown in Figure 4. However, the vehicle and dispenser may omit specific use cases if necessary according to predefined requirements.
[0094] Each of the aforementioned use cases can be realized through communication between a dispenser control system of a dispenser that supplies hydrogen as fuel to a hydrogen fuel vehicle using a fuel supply protocol for hydrogen fuel vehicles, and the hydrogen fuel vehicle itself.
[0095] On the other hand, a hydrogen fuel vehicle (hereinafter simply referred to as "vehicle") and a dispenser that embody the aforementioned use cases can exchange data for vehicle identification using UC-1. For this purpose, the vehicle may be equipped with sensors, an electric control unit (ECU), a transmitter, and a receiver. The receiver may be integrated with the transmitter when bidirectional communication is required.
[0096] The dispenser can be configured to receive specific data from the vehicle. The dispenser can store data specified by the station PLC (programmable logic controller) for data logging or for use in the fuel supply protocol. Data logging can refer to the process of collecting data over a period of time to analyze specific operating states of the hydrogen refueling system or to record data-based events / operations in the system or network environment, or the data collected by this process. In the case of two-way communication, the station is equipped with sensors specified by the fuel supply protocol, and the station PLC or electronic control unit can obtain measurements from the sensors and send these measurements to the vehicle. The aforementioned vehicle and station can use existing communication protocol standards such as infrared, Wi-Fi, and Bluetooth for communication.
[0097] Furthermore, a communication channel can be established between the vehicle and the dispenser, which are physically connected via a vehicle-dispenser interface. The pairing process for establishing such a communication channel can be carried out using wired, optical, or wireless technology.
[0098] The discovery and pairing procedures and pairing processor may have preconditions that the dispenser nozzle is inserted into and firmly coupled to the vehicle fueling receptacle. The vehicle fueling receptacle may be simply referred to as the vehicle receptacle or receptacle.
[0099] Furthermore, the vehicle and dispenser essentially know which communication protocol to follow. Therefore, communications following UC-1 are discovery and pairing procedures or post-conditions of the pairing process, and can only rely on the communication protocol agreed upon for the current use case. If the vehicle or dispenser selects a communication protocol outside the agreed scope, the selected communication will not be performed. In other words, even if the pairing process is successfully completed, approval for fuel or approval for fuel supply may not be granted.
[0100] All methods used to pair the vehicle with the dispenser are configured not to increase the ignition or explosion hazard beyond an acceptable level. For example, all wired pairing methods are configured to mitigate or eliminate the spark hazard due to electrostatic discharge.
[0101] In terms of the effectiveness of physical pairing, all methods used to pair a vehicle with a dispenser may be integrated into a vehicle-dispenser interface or configured to have proximity between the vehicle's fuel supply receptacle and the dispenser's nozzle and hose assembly. Here, the interface may refer to one that is physically integrated into the nozzle and receptacle interface. Proximity may be defined by the hardware associated with the pairing method. For example, the physical geometry used for infrared communication may be specified, including the allowable distance between the transmitter and receiver. The physical shape of the hydrogen refueling hardware may also be pre-specified, in which case proximity does not include pairing methods that risk pairing a vehicle and dispenser that are not physically connected, such as relatively long-range wireless communication technologies like Bluetooth. Infrared communication may be referred to as IrDA (infrared data association) communication and may include bi-IrDA communication.
[0102] Referring again to Figure 4, a communication method for hydrogen fuel supply according to one embodiment of the present invention is a communication method for hydrogen fuel supply (fueling) performed by a communication device of a hydrogen fuel mobility, and may include the steps of: negotiating a communication protocol with a dispenser that supplies hydrogen fuel to the mobility (S403); negotiating a fuel supply protocol with the dispenser for receiving hydrogen fuel from the dispenser (S404); and negotiating fuel supply parameters based on the fuel supply protocol with the dispenser (S405).
[0103] A communication method for hydrogen fuel supply performed by a dispenser supplying hydrogen fuel to a hydrogen fuel mobility vehicle according to one embodiment of the present invention may include a step of negotiating a communication protocol with the mobility vehicle (S403), a step of negotiating a fuel supply protocol with the mobility vehicle for refueling hydrogen to the mobility vehicle (S404), and a step of negotiating fuel supply parameters with the mobility vehicle based on the fuel supply protocol (S405).
[0104] Figure 5 is an illustrative diagram showing, primarily based on the OSI (Open Systems Interconnection Reference Model) 7 layers, communication stacks related to each use case that can be adopted in the hydrogen refueling communication bidirectional process according to one embodiment of the present invention. As illustrated in Figure 5, the communication stack associated with the use case of a two-way hydrogen refueling communication process (simply put, the "hydrogen refueling communication stack") can be expressed as protocol suites, corresponding to the data link and physical layer, network layer, transport layer, security layer, session layer, presentation layer, and application layer, respectively, which belong to the OSI 7 layers.
[0105] In other words, the hydrogen refueling communication stack may include at least one first protocol 510 selected from bidirectional IrDA (bi-IrDA), WLAN, NFC, etc., as the data link and physical layer protocols of the OSI 7 layer. Furthermore, the hydrogen refueling communication stack can include IPv6 (Internet Protocol Version 6) Protocol 520 as a protocol in the OSI 7-layer network layer.
[0106] Furthermore, the hydrogen refueling communication stack may include at least one third protocol 530 selected from TCP (Transmission Control Protocol), UDP (User Datagram Protocol), etc., as a protocol for the transmission layer of the OSI 7-layer structure. Furthermore, the hydrogen refueling communication stack may include at least one fourth protocol 540 selected from TLS (transport layer security), DTLS (datagram transmission layer security), etc., as a security layer protocol of the OSI 7-layer structure. TLS may include versions such as TLS 1.2 and TLS 1.3, and DTLS may include versions such as DTLS 1.2 and DTLS 1.3.
[0107] TLS is implemented using TCP sockets, while DTLS can be implemented using UDP sockets. Furthermore, the hydrogen refueling communication stack may include a JSON-based session protocol 550 as a session layer protocol in the OSI 7-tier hierarchy. The JSON-based session protocol 550 can be used for communication between a vehicle and a dispenser, or for sending data between the vehicle's electronic control unit and the refueling station's electronic control unit.
[0108] Furthermore, the hydrogen refueling communication stack can include JSON (JavaScript Object Notation) 560 as a protocol in the OSI 7-tier representation layer. JSON is one of the formats that can be used when sending data from a server to a client. Using JSON, protocol messages can be expressed in JSON between a vehicle and a dispenser, or between the vehicle's electronic control unit and the refueling station's electronic control unit.
[0109] Furthermore, the hydrogen refueling communication stack may include hydrogen refueling-related fuel supply protocols (FP) 570 as an application layer protocol of the OSI 7 layer. Fuel supply protocols 570 may include a first fuel supply protocol FP1, a second fuel supply protocol FP2, and an nth fuel supply protocol FPn, where n can be any natural number greater than or equal to 3.
[0110] Furthermore, the aforementioned hydrogen refueling communication stack may be configured in other embodiments to use protocols such as PLC (programmable logic controller) and WLAN as the protocols for the data link and physical and network layers, TCP and / or IPv6 as the protocols for the transmission and security layers, Binary XML (binary extensible markup language) as the protocol for the session layer corresponding to the encoding layer, and one of the existing protocols used in electric vehicles as the protocols for the representation and application layers. The existing protocols used in electric vehicles may include at least one protocol for DC (direct current) charging, AC (alternate current) charging, wireless power transfer (WPT), automatic connection device pantograph (ACDP), etc.
[0111] The general communication data items exchanged between the vehicle and the refueling station via the aforementioned hydrogen refueling communication stack are shown in Table 1 below. [Table 1]
[0112] On the other hand, use case UC1 in the discovery and pairing stage (S401) of Figure 4 allows the device to identify the communication partner (vehicle or dispenser communication module) responsible for controlling the physically connected receptacle or nozzle. UC1 can also define a method for identifying incompatibilities and define safety device mechanisms. In such use case UC1, the vehicle and dispenser can search for common communication technologies to execute the fuel supply protocol. The search mechanism provided by the basic data link and physical layer allows the vehicle and dispenser to find each other and initiate communication. Additional pairing procedures are required for a communication channel to be established with the device connected to the fuel supply hose assembly. If the communication channel does not guarantee correct pairing, for example in the case of wireless communication, a separate pairing channel to transmit pairing information may be required. If pairing is implicitly guaranteed, for example, the communication channel for communication integrated with the hose assembly may be sufficient.
[0113] Table 2 is a table illustrating the objectives, prerequisites, and subsequent conditions for use case UC1 in the discovery and pairing stage (S401) shown in Figure 4. [Table 2]
[0114] Table 3 illustrates the supported communication technologies and their respective clauses that can be used in use case UC1 during the discovery and pairing phase (S401) shown in Figure 4. [Table 3]
[0115] Figure 6 is an operation flowchart illustrating in detail a step (S401) according to one embodiment of the present invention. Referring to Figure 6, in the Discovery and Pairing step (S401) of Figure 4, when pairing at UDC Level 2 and UDC Level 3, the vehicle and dispenser exchange pairing IDs and can confirm the other party's pairing ID.
[0116] For example, a vehicle can broadcast a message (PAIR_ID_ANNOUNCE) containing its pairing ID (PAIR_ID), i.e., its vehicle ID (vehicle_id). A dispenser can then send a message (PAIR_ID_ACK) to the vehicle acknowledging receipt of the vehicle ID. The vehicle can then send a message (PAIR_ID_CONFIRM) to the dispenser confirming that it has successfully received the ACK message indicating that the dispenser has received its vehicle ID.
[0117] Next, the dispenser can broadcast a message (PAIR_ID_ANNOUNCE) containing its pairing ID, or dispenser ID (dispenser_id). The vehicle can then send a message (PAIR_ID_ACK) to the dispenser acknowledging receipt of the dispenser ID. The dispenser can then send a message (PAIR_ID_CONFIRM) to the vehicle confirming that it has successfully received the ACK message indicating that the vehicle has received the dispenser ID.
[0118] Through this transmission-echo-verification method, vehicles and dispensers can use session-specific randomized pairing IDs. This solves the problem of protecting personal information during pairing ID exchange. In other words, trust in the pairing process is established by a subsequent process, and for this purpose, the session-specific pairing ID is included in the data used to establish that trust.
[0119] On the other hand, when supporting secure communication at a specific UCDC level, at least one of the vehicle and dispenser can verify that the pairing provides sufficient information to protect the communication channel for all methods used to pair the vehicle and dispenser. For example, pairing may include the exchange of encryption keys so that the vehicle and dispenser can communicate securely during refueling.
[0120] Incidentally, UCDC Level 1 does not support bidirectional communication, so communication channel security may be impossible. Pairing a vehicle and dispenser with UCDC Level 2 and UCDC Level 3 can be configured to provide sufficient information to protect communications in order to satisfy a specific security level, for example, IEC 62443 Security Level 3. IEC 62443 Security Level 3 may be a security level against actors with appropriate resources and appropriate motives.
[0121] Figure 7 is an illustrative diagram illustrating backward compatibility that can be adopted in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention. Referring to Figure 7, hydrogen refueling systems can be manufactured as compatible devices that are backward compatible with existing devices, taking interoperability into consideration. When devices are classified based on interoperability, hydrogen refueling systems and their communication devices can be classified into Type 0, Type 1, Type 2, and Type 3.
[0122] Type 0 may refer to a device that does not support or receive communication messages for fuel supply. Type 1 may refer to equipment that supports IrDA communication for fuel supply. Type 1 equipment can fall back to Type 0 equipment.
[0123] Type 2 may refer to equipment that supports advanced communication (AC). Type 2 equipment can fall back to Type 0 equipment. Type 3 can refer to equipment that supports IrDA and advanced communications. A Type 3 device can fall back to any one of Type 0, Type 1, or Type 2.
[0124] Advanced communication can refer to communication using mediums (mediums) and specific protocols such as WLAN (wireless local area network), Bluetooth (BT), NFC (near field communication), Wi-Fi (registered trademark), UWB (ultra-wideband), RFID (radio frequency identification), 4G, and 5G. Advanced communication can also include bidirectional IrDA, serial communication, automotive Ethernet (Ethernet, ETH), and high-level communication. Specific protocols can include TCT / IP (transmission control protocol / internet protocol) and fuel supply protocols. High-level communication can process all information exceeding that handled by command and control communication. The data link for high-level communication can use, but is not limited to, PLC (Power Line Communication).
[0125] Furthermore, advanced communication can take a hybrid form, including a combination of IrDA and wired or IrDA and wireless. In the case of a combination of IrDA and wired, modifications to the nozzle and receptacle may be necessary.
[0126] In other words, advanced communication can be a wired / wireless bidirectional communication technology, and wireless communication technologies can include a variety of communication methods such as 5G, WLAN, BLE, ETH, UWB, RFID, and NFC. Known protocols such as TCP / IP can be used as protocols for such communication methods. For example, communication methods considered as wireless communication may include Bluetooth, WLAN, Wi-Fi (ISO 15118 for inductive / ACD), UWB (IEC limited consideration for ACD), etc.
[0127] In practice, hydrogen refueling devices can be implemented to support communication between devices using different technologies. Therefore, the two-way hydrogen refueling communication process in this embodiment is configured to maximize interoperability between devices. In other words, as shown in Figure 7, when a Type 1 device supporting standard #1, which conforms to a predetermined standard, encounters a Type 0 device or a Type 2 device, the Type 1 device can fall back to the Type 0 device (S610).
[0128] Furthermore, if a Type 2 device supporting standard #2, which conforms to a predetermined standard, encounters a Type 0 device or a Type 1 device, the Type 2 device can fall back to the Type 0 device (S620).
[0129] Furthermore, when a Type 3 device supporting standard #2 encounters a Type 0 device, the Type 3 device can fall back to the Type 0 device (S630). When a Type 3 device encounters a Type 1 device, the Type 3 device can fall back to the Type 1 device (S640). Also, when a Type 3 device encounters a Type 2 device, the Type 3 device can fall back to the Type 2 device (S650).
[0130] Standard #1 mentioned above can include SAE (Society of Automotive Engineers) standards, etc. Standard #2 can include ISO 19885-3 standards, etc. Furthermore, to support the aforementioned interoperability, the hydrogen refueling unit can perform a connection compatibility check. For example, depending on whether or not the hydrogen refueling unit supports WLAN, one of the advanced communication technologies, it can perform a connection compatibility check as shown in the following scenarios 1 to 3.
[0131] In Scenario 1, the dispenser can prepare an access point (AP), which is a wireless router. The dispenser can support fuel supply methods at FCEV fuel station beaconing and VSE (vehicle supply equipment). An FCEV in close proximity to the dispenser can scan for it and establish a WLAN link with the dispenser it finds.
[0132] In Scenario 2, the dispenser can support IrDA communication but not WLAN communication. The dispenser corresponds to a Type 1 device. An FCEV adjacent to the dispenser cannot find the dispenser, which is a Type 1 device, by scanning it as a Type 3 device. When the FCEV's receptacle is connected to the nozzle attached to the dispenser's cable, IrDA communication can begin between the FCEV and the dispenser.
[0133] In Scenario 3, the dispenser can support WLAN and IrDA communication. In this case, the dispenser corresponds to a Type 3 device. An FCEV, which is a Type 1 device, may be parked around the dispenser. The dispenser cannot yet find any WLAN clients. When the FCEV's receptacle is connected to the nozzle attached to the dispenser's cable, IrDA communication can begin between the FCEV and the dispenser.
[0134] Figure 8 is an illustrative diagram illustrating backward compatibility that can be adopted in a hydrogen filling communication bidirectional process according to one embodiment of the present invention. Referring to Figure 8, the two-way hydrogen refueling communication process of this embodiment does not necessarily select the communication method preferred by the FCEV and dispenser, but rather provides rules and principles that fall back to maximize interoperability between the fueling method and the communication protocol.
[0135] In other words, when one of the vehicles and dispensers meets another, the device with a relatively higher type or UCDC level may be configured to fall back to the type or level of the device with a relatively lower type or level.
[0136] For example, if a vehicle and a dispenser are of the same type or the same UDC level, both devices can maintain their current type or UDC level. On the other hand, if one device is a type 1 device and the other is a type 2 device, both devices may be configured to fall back to a type 0 device. And if one device is a type 3 device and the other is not a type 3 device, the type 3 device may be configured to fall back to the same level as the other device's type or UDC level.
[0137] The aforementioned standard #1 may be an SAE standard communication protocol, and standard #2 may be an ISO 19885 standard communication protocol.
[0138] According to the configuration described above, if there are two devices with the "same embodiment," the vehicle and the dispenser can both select the best of the two that they support. When a device without communication (hereinafter, "non-communication device") meets a device that supports unidirectional communication (hereinafter, simply referred to as "unidirectional communication device"), the latter can fall back to a no-communication (no comm) device that does not have a communication method to support. Also, when two devices that support bidirectional communication meet, the two devices can maintain their bidirectional communication method. Here, UCDC compatibility may be handled separately. Furthermore, when a device meets a non-communication device, it can rely on non-communication. This can be applied to all devices that support bidirectional communication (hereinafter, simply referred to as "bidirectional communication devices").
[0139] Furthermore, when a unidirectional communication device encounters a bidirectional communication device, if the bidirectional communication device supports both unidirectional and bidirectional communication methods, the bidirectional communication device can fall back to unidirectional communication. If the bidirectional communication device does not support unidirectional communication, the bidirectional communication device can fall back to a no-communication device to rely on no-communication.
[0140] The aforementioned bidirectional communication device may be configured to support a unidirectional fuel supply method, regardless of whether unidirectional communication is available. Such a bidirectional communication device must be able to determine whether the other party supports bidirectional communication. If the FCEV or dispenser does not support bidirectional communication, the bidirectional communication device can fall back to a unidirectional communication device that uses a compatible unidirectional communication method.
[0141] Figure 9 is an illustrative diagram illustrating the communication data usage classifications that can be adopted in a hydrogen refueling bidirectional communication process according to one embodiment of the present invention, and backward compatibility between the communication data usage classifications.
[0142] As shown in Figure 9, vehicles and dispensers can possess pairing identities (IDs), and the requirements for exchanging such identities can be classified by the use classification of communication data (UCDC) level. UCDC levels can include UCDC level 1 (UCDC-1) (910), UCDC level 2 (UCDC-2) (920), and UCDC level 3 (UCDC-3) (930). UCDC levels can further include UCDC level 0 (UCDC-0) (900).
[0143] UCDC Level 0 (900) may refer to communications where data is not transmitted or, if data is transmitted, are not used by fuel supply protocols for hydrogen dispensing or related safety functions. In UCDC Level 0 (900), there is no communication between the vehicle and the dispenser, so the dispenser cannot transmit the pairing ID to the vehicle during process control or safety functions.
[0144] When pairing in UCDC Level 1 (910), the vehicle can transmit a pairing ID to the dispenser. The data transmitted in UCDC Level 1 (910) is not used for safety functions, but the transmitted static data may be used to improve the performance of the fuel supply protocol, and the transmitted dynamic data may be used to reduce the risk against process deviations within the fuel supply protocol.
[0145] Static data transmitted under UCDC Level 2(920) may be used for safety functions. Such UCDC Level 2(920) static data may be additional uses beyond those permitted for static and dynamic data as defined for UCDC Level 1.
[0146] Under UCDC Level 3(930), static and dynamic data may be used for dynamic control within a protocol or safety function. Such dynamic data under UCDC Level 3(930) may be additional uses beyond those permitted for static and dynamic data as defined for UCDC Level 2.
[0147] As mentioned above, UCDC levels can take the form of UCDC level 1 being included in UCDC level 2, and UCDC level 2 being included in UCDC level 3, that is, higher levels can include lower levels. Devices supporting a particular UCDC level can support devices supporting even lower UCDC levels. Devices supporting different UCDC levels can use the highest UCDC level supported by both devices. It can be said that the aforementioned UCDC levels also readily support UCDC level 0. It can be seen that UCDC levels are backward compatible. In other embodiments of the present invention, backward compatibility can be effectively applied to Non-Comm, Uni-directional Comm, Bi-directional Comm, and combinations thereof, regardless of UCDC level.
[0148] Referring to Figures 4 to 8, information regarding interoperability and / or compatibility between the vehicle / mobility and the dispenser may be shared during the discovery and pairing phase (S401) in Figure 4. This interoperability and / or compatibility can then be utilized in the communication protocol negotiation phase (S403), the fuel supply protocol negotiation phase (S404), and / or the fuel supply parameter negotiation phase (S405), which will be described later.
[0149] In another embodiment of the present invention, information regarding interoperability and / or compatibility shared between the vehicle / mobility and the dispenser during the discovery and pairing stage (S401) in Figure 4 may be updated or reshared during the communication protocol negotiation stage (S403), the fuel supply protocol negotiation stage (S404), and / or the fuel supply parameter negotiation stage (S405). Information regarding interoperability and / or compatibility may be updated due to changes in the communication environment, changes in parameters affecting the fuel supply process, etc.
[0150] In another embodiment of the present invention, at least a portion of the discovery and pairing stage (S401) shown in Figure 4 may be referred to as the Dispenser Discovery Protocol (DDP).
[0151] DDP can be initiated by a DDP request message [DDPRequest] broadcast by the mobility. The DDPRequest may include the mobility's pairing ID "pairing_id".
[0152] A dispenser can receive a DDPRequest and send a DDPResponse in response. The DDPResponse may include the dispenser's IP address ("IPAddr"), the dispenser's TCP port number ("TCPPort"), the dispenser's UDP port number ("UDPPort"), and the dispenser's pairing ID ("pairing_id").
[0153] Figure 10 is a flowchart illustrating the authentication process of a communication security procedure (S402) that can be used in a hydrogen refueling bidirectional communication process according to one embodiment of the present invention. Referring to Figure 10, the mobility device can transmit a message to the dispenser requesting a list of authorization methods (S1010). The dispenser can transmit a response message to the mobility device in response to the request for the list of authorization methods (S1020). The response message may include information on a list of authorization methods related to external authentication procedures such as RFID (radio frequency identification), credit cards, and debit cards, as well as internal authentication procedures.
[0154] Next, the mobility device can transmit an authentication request message to the dispenser, including a specific method selected from the authentication method list, such as RFID (S1030). The dispenser can transmit a response message to the mobility device in response to the authentication request (S1040). This response message may include information indicating that the authentication method selected by the mobility device is working.
[0155] Next, the mobility device performs authentication using the authentication method selected prior to the dispenser's response and can transmit a confirmation (Done?) message to the dispenser regarding the successful completion of authentication (S1050). If confirmation of successful authentication has not been received or authentication is not complete, the aforementioned series of steps (S1010-S1050) may be repeated. Once authentication is complete, the dispenser can transmit a successful authentication (Done(success)) message to the mobility device (S1090).
[0156] According to the configuration described above, the dispenser can verify whether the mobility has been approved, that is, whether the user of the mobility has the authority to refuel with hydrogen, before proceeding further with the hydrogen refueling process.
[0157] For security during the authentication process, a hydrogen refueling system including at least one of a mobility device and a dispenser can perform a TLS handshake to authenticate after establishing a data link and physical layer connection between the mobility device and the dispenser, and after setting up the transmission layer, i.e., a TCP connection, and then exchanging keys to establish a secure communication channel. Furthermore, UDP communication protected by DTLS can be used while security-critical information is being exchanged.
[0158] Furthermore, the mobility and dispenser can successfully perform discovery and pairing procedures and establish data link and physical layer connections. Subsequently, credentials necessary for authentication and key exchange can be prepared. This allows the communication channel between the mobility and dispenser to be encrypted to protect its integrity. The dispenser can authenticate the mobility, and selectively the mobility can authenticate the dispenser.
[0159] On the other hand, during the aforementioned TLS handshake, mobility authentication is mandatory, while dispenser authentication may be optional. In this case, the dispenser can act as the client and mobility can act as the server. For a TLS handshake, the mobility and dispenser must prepare the necessary credentials. The mobility and dispenser can store the certificate chain, the personal key corresponding to the certificate, and the trust anchor certificate in a secure storage location protected from unauthorized access.
[0160] During the TLS handshake, Mobility can request client authentication from the dispenser by transmitting a predefined CertificateRequest message. Upon receiving the CertificateRequest message, the dispenser can then transmit the certificate and CertificateVerify messages to Mobility to transmit the certificate.
[0161] When Mobility sends a certificate request message along with handshake messages such as ServerHello, if the dispenser does not send a certificate confirmation message along with the certificate, it can abort the TLS handshake by sending a warning message containing a "certificate_required" warning code.
[0162] According to another embodiment of the present invention, the objective, prerequisites, and subsequent conditions of step (S402) may be shown in Table 4. [Table 4]
[0163] Figure 11 is a flowchart illustrating a communication protocol negotiation stage (S403) that can be adopted in a hydrogen refueling bidirectional communication process according to one embodiment of the present invention. Referring to Figure 11, the communication protocol negotiation stage (S403) may include a stage of transmitting a message containing information for a first communication protocol applicable to the mobility to the dispenser (S1110), and a stage of receiving a message from the dispenser containing information for a second communication protocol selected from common communication protocols applicable to both the mobility and the dispenser (S1130).
[0164] Referring to the embodiment in Figure 11, the dispenser receives a message from the mobility device containing information about a first communication protocol applicable to the mobility device (S1110), compares the first communication protocol with the communication protocols applicable to the dispenser, selects a second communication protocol from among the common communication protocols applicable to both the mobility device and the dispenser, and transmits a message to the mobility device containing information about the selected second communication protocol (S1130).
[0165] At this point, although not shown in Figure 11, the process may further include a step in which the dispenser requests information from the mobility device, including a list of first communication protocols applicable to the mobility device, prior to step (S1110).
[0166] In another embodiment of the present invention, a dispenser may first transmit a message to the mobility device containing information about its applicable communication protocols, and the mobility device may select a specific communication protocol from among the common communication protocols and transmit a message to the dispenser containing information about the selected specific communication protocol. This could further involve the mobility requesting information from the dispenser, including a list of applicable communication protocols.
[0167] According to one embodiment of the present invention, the objective, prerequisites, and subsequent conditions of step (S403) may be shown in Table 5. [Table 5]
[0168] According to one embodiment of the present invention, the content of the messages transmitted and received in step (S1110) may be shown in Table 6. [Table 6]
[0169] Information regarding the first communication protocol may include at least one of the following: the index of the first communication protocol, the name of the first communication protocol, the version of the first communication protocol, and the preference for the first communication protocol. According to one embodiment of the present invention, the contents of the response message transmitted and received in step (S1130) may be shown in Table 7. [Table 7]
[0170] The response message containing information regarding the second communication protocol may further include information on whether the communication protocol negotiation was successful or not. The aforementioned communication protocol negotiation procedure is a procedure for identifying the communication protocol to follow during the hydrogen refueling session, after the vehicle and dispenser have discovered and paired each other on compatible communication channels. In particular, in this embodiment, the dispenser can take the lead in exchanging the communication protocol and parameters with the vehicle.
[0171] In other words, the communication method according to one embodiment of the present invention can perform the step of discovering and pairing with a dispenser (S401) using the first communication technology.
[0172] If the result of the communication protocol negotiation stage (S403) relates to the second communication technology, the stage of negotiating the fuel supply protocol (S404) and the stage of negotiating the fuel supply parameters (S405), which will be described later, can be carried out using the second communication technology.
[0173] During the discovery and pairing process (S401), information regarding the interoperability and / or compatibility between the mobility and the dispenser may be shared.
[0174] During the process of carrying out steps (S403) to (S405) of the present invention, changes in the communication environment and changes in environmental variables related to hydrogen fuel supply may update the information regarding the interoperability and / or compatibility between mobility and dispensers that was shared in step (S401) of carrying out the discovery and pairing process.
[0175] Communication protocol negotiation procedures can be embodied by all available communication protocols to ensure successful negotiation between different fueling protocols for each communication technology. For example, a fuel supply protocol utilizing a communication technology such as WLAN can use a protocol (hereinafter also referred to as the "common protocol") that is commonly supported by the vehicle and dispenser to determine which communication protocol to use in the two-way hydrogen refueling communication process.
[0176] In practice, various combinations of mobility and dispensers can occur at each site, depending on hydrogen refueling communication standards, communication modes, fuel supply methods, communication levels, and other parameters. Here, hydrogen refueling communication standards can include SAE J2601 series, ISO 19885-3, ISO 19885-4, etc. Communication modes can include no communication (No comm.), IrDA, XYZ (ISO), etc. Fuel supply methods can include table-based refueling methods such as lookup tables, MC formula-based refueling methods, etc. Communication levels can include UCDC levels, and other parameters can include pressure class, CHSS (compressed hydrogen storage system) category, and fueling tables.
[0177] On the other hand, the mobility or dispenser may be configured to further perform a process of falling back to the other party's lower type or lower UDC level based on the mutual type or UDC level confirmed in the communication protocol negotiation procedure.
[0178] Furthermore, in environments where various combinations are possible, if incompatibility is found in parameters exchanged during the negotiation procedures for hydrogen refueling (UC3-UC5), the mobility and dispenser can return to the communication protocol negotiation procedures and resume the negotiation process.
[0179] In one embodiment of the present invention, a communication protocol assigned a priority may include protocols having the priority levels exemplified in Table 6 described later.
[0180] The dispenser will use the specific protocol selected from the protocol list.<selected protocol> A response message including ) can be transmitted to the mobility (S1130). The specific protocol is a common protocol selected by the dispenser that is supported by both the dispenser and the mobility and is the highest priority protocol preferred by the mobility, for example, the ISO 19885-3-2023-UCDC-3 protocol (see Table 6).
[0181] According to the common protocol, mobility and dispensers can reach an agreement on the communication protocol to be used for fueling communication.
[0182] On the other hand, mobility can assign priorities to the communication protocols it supports. Mobility can then provide the dispenser with the assigned priorities for communication protocols. An example of an assigned priorities for communication protocols is shown in Table 8 below. [Table 8]
[0183] Once a communication protocol is selected in the aforementioned communication protocol negotiation use case UC3, the vehicle and dispenser can activate their respective communication protocol implementations and begin fuel supply protocol negotiation. Fuel supply protocol negotiation is a procedure in which the vehicle and dispenser search for and agree on a fuel supply protocol to use for a fuel supply session. At this stage, the vehicle and dispenser can both select the communication protocol that the vehicle prefers most from among the protocols they support. A hydrogen refueling communication protocol negotiation method according to one embodiment of the present invention is a hydrogen refueling communication protocol negotiation method performed by a communication control device of a hydrogen fuel mobility 100, and includes the steps of: transmitting a first message (S1110) to a communication entity associated with a dispenser 200, which includes a list of at least one first fueling protocol and at least one first communication protocol required to perform the fuel supply protocol supported by the mobility 100; and receiving a response message (S1130) from the communication entity associated with the dispenser 200, which includes a second communication protocol selected from at least one first communication protocol. The communication entity associated with the dispenser 200 may be the electronic control unit 210 of the dispenser 200, or a separate communication device mounted on the dispenser 200, or an electronic control unit or separate communication device in the filling station system 220 may communicate with the vehicle / mobility 100 on behalf of the dispenser 200.
[0184] The first message can include priority information based on the preference level of mobility 100, as shown in Table 6. Furthermore, each message can be defined based on Tables 4 through 6.
[0185] At this time, the response message may include a second communication protocol selected from at least one or more first communication protocols based on preference-based priority information. The mobility 100 or the dispenser 200 can select the second communication protocol based on preference-based priority information either individually or in cooperation with each other. Furthermore, the act of finally transmitting an acknowledgment message to the other party to conclude the protocol negotiation process (finished) can be mainly performed by the mobility 100, but it can be modified to be performed by the dispenser 200. In this case, the dispenser 200 may first send a list of supported protocols, and the mobility 100 may provide feedback on the selected protocol.
[0186] The response message may include a second communication protocol selected from at least one first communication protocol and a common communication protocol that is included in the protocols supported by the dispenser 200. The response message may include a second communication protocol, determined by the type of device that falls back from a plurality of first communication protocols required by the control device of the dispenser 200 to execute the first fuel supply protocol, based on interoperability and backward compatibility between the mobility 100 and the dispenser 200.
[0187] In this case, according to one embodiment of the present invention, if a common communication protocol does not exist, as shown in Figures 7 to 9, a No comm. communication standard is selected, and a hydrogen fuel supply protocol in accordance with the No comm. communication standard is selected according to predetermined rules, and hydrogen can be supplied as fuel. In this case, steps (S404) to (S405) described later may be simplified or omitted.
[0188] According to another embodiment of the present invention, if a common communication protocol does not exist, communication between the mobility 100 and the dispenser 200 may be terminated (S409).
[0189] Figure 12 is an operation flowchart illustrating the fuel supply protocol negotiation stage (S404) of the hydrogen refueling communication bidirectional process according to one embodiment of the present invention. Referring to Figure 12, the step of negotiating a fuel supply protocol according to one embodiment of the present invention (S404) may include the step of transmitting a message to the dispenser containing information on a first fuel supply protocol applicable to the mobility based on the results of the communication protocol negotiation (S403) (S1210), and the step of receiving a message from the dispenser containing information on a second fuel supply protocol selected from among fuel supply protocols that are commonly applicable between the mobility and the dispenser (S1230).
[0190] If a second communication protocol is selected as a result of the communication protocol negotiation (S403), a message containing information for at least one or more first fuel supply protocols applicable to mobility may be transmitted to the dispenser as a hydrogen fuel supply protocol supporting the selected second communication protocol (S1210).
[0191] The dispenser can select a hydrogen fuel supply protocol that supports the second communication protocol from among the fuel supply protocols applicable to the dispenser and the first fuel supply protocol that are common to both, and then select a second fuel supply protocol from among the selected common fuel supply protocols. In this case, the second fuel supply protocol may be selected based on interoperability and / or compatibility, or it may be selected based on a preference set by mobility or the dispenser.
[0192] Referring to the embodiment in Figure 12, the dispenser receives a message from the mobility device containing information about a first fuel supply protocol applicable to the mobility device (S1210), compares the first fuel supply protocol with the fuel supply protocols applicable to the dispenser, selects a second fuel supply protocol from among the common fuel supply protocols applicable to both the mobility device and the dispenser, and transmits a message to the mobility device containing information about the selected second fuel supply protocol (S1130).
[0193] At this point, although not shown in Figure 12, the process may further include a step in which the dispenser requests information from the mobility, including a list of first fuel supply protocols applicable to the mobility prior to step (S1210).
[0194] In another embodiment of the present invention, an embodiment may be provided in which the dispenser first transmits a message to the mobility containing information about its applicable fuel supply protocol, the mobility selects a specific fuel supply protocol from among the common fuel supply protocols, and transmits a message to the dispenser containing information about the selected specific fuel supply protocol. This could further involve Mobility requesting information from the dispenser, including a list of applicable fuel supply protocols.
[0195] According to one embodiment of the present invention, the objective, prerequisites, and subsequent conditions of step (S404) may be shown in Table 9. [Table 9]
[0196] According to one embodiment of the present invention, the content of the messages transmitted and received in step (S1210) may be shown in Table 10. [Table 10]
[0197] Information regarding the first fuel supply protocol may include at least one of the following: the index of the first fuel supply protocol, the name of the first fuel supply protocol, the version of the first fuel supply protocol, the sub-protocol of the first fuel supply protocol, and the preference for the first fuel supply protocol. According to one embodiment of the present invention, the contents of the response messages transmitted and received in step (S1230) may be shown in Table 11. [Table 11]
[0198] The message containing information regarding the second fuel supply protocol may further include information on whether the fuel supply protocol negotiations were successful or not. The content of the message transmitted in step (S1210) according to one embodiment of the present invention may be shown in Table 12. [Table 12]
[0199] As shown in Table 12, Mobility can provide the dispenser with parameter information in table format, which includes an arbitrarily assigned name for the assisted fuel supply method or fuel supply protocol, revision date (year) and version information, information on whether or not subprotocols are present, and preference information.
[0200] In another embodiment of the present invention, the dispenser may proactively exchange its own communication protocols and parameters with the mobility instead of the mobility, and may prioritize and provide the mobility with communication protocols supported by the dispenser.
[0201] Table 11 shows that PRHYDE (Protocol for heavy-duty HYDrogEn refueling) is one of the European projects that has been developing heavy-duty vehicle refueling protocols, RTR-HFP is a protocol concept that improves refueling efficiency based on real-time communication, and ANN-MPC is a protocol concept that collects and analyzes data from refueling sites and predicts and applies it to actual refueling conditions.
[0202] Examples of messages transmitted in step (S1230) according to one embodiment of the present invention are shown in Tables 13 and 14 below. [Table 13]
[0203] According to Table 13, the dispenser can select the fuel supply protocol corresponding to index 2 and transmit a response message to the mobility device, including the result code OK. [Table 14]
[0204] According to Table 14, if the dispenser fails to find a compatible protocol in the list of fuel supply protocols supported by the mobility that it receives from the mobility, it can send a response message to the mobility with information indicating that there is no common protocol (e.g., FAIL_NO_COMMON_PROTOCOL) in the ResultCode field. The examples in Tables 13 and 14 can also be applied when the dispenser responds to the mobility by selecting a second communication protocol from the common communication protocols at stage (S1130) in Figure 11.
[0205] Figure 13 is a flowchart illustrating the fueling parameter exchange / negotiation stage (S405) that can be adopted in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention. The fuel supply parameter exchange / negotiation phase (S405) may include a phase in which mobility and dispensers exchange detailed parameters necessary for the implementation of the fueling protocol.
[0206] Referring to Figure 13, the step of negotiating fuel supply parameters (S405) may include the step of transmitting a message to the dispenser containing information on the mobility-side fuel supply parameters required by the second fuel supply protocol selected as a result of the fuel supply protocol negotiation (S404) (S1310), and the step of receiving a message from the dispenser containing compatibility information on the dispenser side for the mobility-side fuel supply parameters (S1350).
[0207] The step of negotiating fuel supply parameters (S405) may include receiving a message from the dispenser (S1330) containing information on the dispenser-side fuel supply parameters required by the second fuel supply protocol selected as a result of the fuel supply protocol negotiation (S404), and transmitting a message to the dispenser (S1370) containing mobility-side compatibility information for the dispenser-side fuel supply parameters.
[0208] In step (S1310), the mobility unit transmits a message containing information about the fuel supply parameters on the mobility side, and the Accepted field for the relevant parameters <pending>The settings can be left in place and transmitted to the dispenser.
[0209] Similarly, in step (S1330), the dispenser transmits a message containing information about the fuel supply parameters on the dispenser side, and the Accepted field for the relevant parameters <pending>It can be transmitted to mobility devices while remaining in that setting.
[0210] In the first stage (S1330), the mobility device transmits a message as a response to the received message, containing information about the fuel supply parameters on the dispenser side, while also setting the Accepted field for the relevant parameters. <ok>or <true>It can be set to respond to the dispenser (S1350).
[0211] The dispenser, as a response message to the message received in step (S1310), transmits a message containing information about the fuel supply parameters on the mobility side, while setting the Accepted field for the relevant parameters. <ok>or <true>It can be set to respond to mobility (S1370). At this time, the mobility and dispenser can respond by displaying whether each fuel supply parameter is Accepted or not. The Accepted field for unagreed parameters is <false>This may be displayed.
[0212] The mobility and dispenser can reach an agreement on all parameters by repeatedly sending and receiving messages and responding to those messages.
[0213] The parameters to be exchanged may include parameters to support fueling method compatibility, parameters for physical characteristics, monitoring parameters, and acceptance-related parameters.
[0214] Here, compatibility support parameters include pressure class, CHSS category, etc., parameters for physical characteristics include maximum allowable CHSS pressure, maximum allowable CHSS temperature, maximum allowable speed, CHSS volume, etc., monitoring parameters include current CHSS pressure, current CHSS temperature, etc., and acceptance-related parameters may include information indicating acceptance or rejection, such as parameters indicating yes (true) or no (false). The aforementioned parameters may each have information for one of the pre-specified levels or settings, and information for different or identical main UCDC levels.
[0215] On the other hand, the dispenser has parameters that can be supported (<DIS’s parameters> (In a simplified way)<DIS’s params> An OK message can be transmitted to the mobility device indicating that information and mobility parameters have been received and accepted (S1330, S1370).
[0216] Secondary parameters related to fuel supply parameter exchange / negotiation may include parameters to support fuel supply method compatibility, parameters for physical characteristics, parameters related to fueling goals, monitoring parameters, and acceptance-related parameters.
[0217] Here, compatibility support-related parameters include fuel delivery temp., selected fueling table, etc., parameters for physical characteristics include maximum fuel delivery pressure, maximum fuel delivery temperature, minimum fuel delivery temperature, maximum fuel delivery velocity, etc., fuel delivery target-related parameters include target SOC, target final CHSS pressure, target final CHSS temperature, target APR, expected fueling duration, etc., monitoring parameters include current fuel delivery temperature, ambient temperature, etc., and acceptance-related parameters may include parameters such as "accepted". The aforementioned parameters may each have information set for one of the pre-set levels or set values, and information for different or identical main UCDC levels.
[0218] In this way, mobility can provide the dispenser with parameters listed in a table format. The listed parameters include FCEV parameters compatible with UCDC levels, which are discussed during the fuel supply protocol negotiation phase.
[0219] As mentioned above, once the communication link is established and the communication and fuel supply protocols are selected during the protocol negotiation phase, the mobility and dispenser can exchange various parameters to verify whether they can perform mutually compatible fuel supply procedures. Here, the information necessary to perform safe and efficient fuel supply procedures may include compatibility parameters, physical characteristics, fuel supply targets, and monitoring parameters.
[0220] Compatibility parameters may include, for example, pressure class and fuel supply transmission temperature; physical characteristics may include, for example, maximum CHSS pressure and maximum flow rate; fuel supply targets may include target SOC and target CHSS pressure; and monitoring parameters may include current CHSS temperature and ambient temperature.
[0221] If a compatible parameter cannot be found and fuel delivery cannot proceed, the FCEV can return to the communication protocol negotiation phase to attempt other protocol negotiations or to halt fuel delivery to the dispenser. Then, upon returning to the communication protocol negotiation phase due to the failure of the fuel delivery parameter exchange phase, the FCEV may be configured to propose to the dispenser a suite of supported protocols, excluding the protocol that failed in the fuel delivery parameter exchange phase.
[0222] Once a fuel supply protocol is negotiated using the aforementioned use case (UC-4), the vehicle and dispenser can negotiate specific parameters for the fuel supply protocol, communicate static or dynamic states, and exchange detailed fuel supply parameters to determine fuel supply targets. If fuel supply parameter negotiation fails due to incompatibility, they can return to UC-3 to select another fuel supply protocol or UC-1 to select another communication protocol, and if these are not successfully performed, the current communication can be terminated.
[0223] According to the configuration described above, certain fueling protocols can be implemented on a non-communication basis. Unidirectional IrDA may be required for certain fueling protocols to be implemented. Bidirectional communication may be required for certain fueling protocols to be implemented. Both bidirectional communication and unidirectional IrDA may be required for certain fueling protocols to be implemented.
[0224] A certain fuel supply protocol may require a predetermined UCDC level or a higher UCDC level to be implemented. Based on the type or type of hydrogen electric vehicle and the type or type of dispenser, at least one fuel supply protocol may be proposed. The proposed fuel supply protocols may be proposed with different priorities. Taking into account the priorities of the proposed fuel supply protocols, the final communication protocol and fuel supply protocol between the hydrogen electric vehicle and the dispenser may be determined based on whether the communication protocol required by the fuel supply protocol is supported by the hydrogen electric vehicle and / or the dispenser.
[0225] In another embodiment of the present invention, either the mobility or the dispenser may first transmit fuel supply parameters to the other party, and the other party may respond with a message containing newly reconfigured fuel supply parameters, retaining the parameters it accepts and modifying the parameters it does not accept.
[0226] In another embodiment of the present invention, the mobility and dispenser may perform parameter negotiations in stages. The mobility and dispenser may negotiate some of the parameters first and then perform an exchange / negotiation process for the sub-parameters of the parameters to which agreement has been reached.
[0227] In another embodiment of the present invention, messages containing fuel supply parameters may be configured such that an agreement is not reached if a response message is not received within a predetermined message processing time.
[0228] Table 15 below shows the content of a message including fuel supply parameters on the mobility side according to one embodiment of the present invention. [Table 15]
[0229] Table 16 below shows the contents of a message including fuel supply parameters on the dispenser side according to one embodiment of the present invention. [Table 16]
[0230] During the fuel supply parameter negotiation phase (S405), mobility and dispensers can generate and communicate messages to the other party containing ranges / values for fueling parameters. These parameters may include physical properties parameters (simply called "physical parameters"), monitoring parameters, safety policy parameters, and acceptance parameters.
[0231] Here, physical parameters include receptacle type, pressure class, CHSS category, CHSS type, CHSS capacity, maximum allowable CHSS pressure, maximum allowable CHSS temperature, and maximum allowable speed; monitoring parameters include current CHSS pressure and current CHSS temperature; safety policy-related parameters include emergency policy and safety enforcement level; and acceptance-related parameters may include information indicating acceptance or rejection, such as yes, false, or pending.
[0232] Parameters related to fuel supply parameter negotiations may include physical characteristics-related parameters (simply put, "physical parameters"), monitoring parameters, fuel supply target-related parameters, safety policy-related parameters, and acceptance-related parameters.
[0233] Here, physical parameters include fuel delivery temp., maximum fuel delivery pressure, maximum fuel delivery temperature, minimum fuel delivery temperature, and maximum fuel delivery velocity; monitoring parameters include current fuel delivery temperature and ambient temperature; fuel delivery target-related parameters include selected fueling table, target SOC, target final CHSS pressure, target final CHSS temperature, target APR, and expected fuel delivery time; and acceptance-related parameters may include parameters such as "accepted." The aforementioned parameters may each have information set for one of the pre-set levels or set values, as well as information for different or identical main UCDC levels.
[0234] In this way, FCEV can provide the dispenser with parameters listed in a table format. The listed parameters include FCEV parameters that are compatible with UCDC levels discussed during the fuel supply protocol negotiation phase.
[0235] On the other hand, after receiving a fuel supply parameter negotiation request message, if the received fuel supply parameters are compatible with the dispenser, the dispenser can respond to its own fuel supply parameters by transmitting a fuel supply parameter negotiation response message to the FCEV with the "Result" set to "OK" within a pre-set message response time.
[0236] Furthermore, after receiving a fuel supply parameter negotiation request message, if the dispenser discovers that it is incompatible with the vehicle's fuel supply parameters, the dispenser can respond by sending a fuel supply parameter negotiation response message to the FCEV in question, with the "Result" set to "Failure" to indicate incompatibility with the FCEV. The result indicates the value and information contained in the resultcode field, while failure is a failure at a specific time and may be expressed as an expression indicating incompatibility, such as "fail_incompat".
[0237] Furthermore, after receiving a fuel supply parameter negotiation request message, if the FCEV discovers that the fuel supply mediation variables of the dispenser are incompatible, the FCEV can send an error notification request message to the dispenser, along with the "reason" set for each predefined error code, to indicate the incompatibility to the dispenser.
[0238] On the other hand, before commencing fuel supply, the vehicle and dispenser can be verified to ensure all safety conditions are met through a use case (UC6) for safety check-in. While this step is optional, it is preferable to define a dedicated safety check-in procedure in the fuel supply protocol to ensure the desired level of safety in a precise and explicit manner.
[0239] Figure 14 is a conceptual diagram illustrating a table of parameters transmitted from mobility to the dispenser side in a fuel supply parameter negotiation / exchange process according to one embodiment of the present invention. Figure 15 is a conceptual diagram illustrating a table of parameters transmitted from the dispenser to the mobility side in a fuel supply parameter negotiation / exchange process according to one embodiment of the present invention.
[0240] Referring together to Figures 13 and 15, a communication-based fuel supply parameter exchange method for hydrogen refueling according to one embodiment of the present invention is a communication-based parameter exchange method for hydrogen refueling performed by a communication control device of a hydrogen fuel mobility 100, and includes the steps of: transmitting a first parameter (S1310) to a communication entity associated with a dispenser 200, the first parameter including at least one of at least one of at least one first hydrogen refueling method compatibility and at least one of at least one first physical characteristics supported by the mobility 100; and receiving a response message (S1370) from the communication entity associated with the dispenser 200, the second parameter including at least one of at least one second hydrogen refueling method compatibility, at least one of at least one second physical characteristics, and a fueling goal supported by the dispenser 200.
[0241] The communication entity associated with the dispenser 200 may be the electronic control unit 210 of the dispenser 200, or a separate communication device mounted on the dispenser 200, or an electronic control unit or separate communication device in the filling station system 220 may communicate with the vehicle / mobility 100 on behalf of the dispenser 200. In this case, the first parameter may further include a first monitoring parameter supported by mobility 100. The second parameter may further include a second monitoring parameter supported by dispenser 200.
[0242] In the communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, the parameter exchange process can be terminated based on a confirmation message (OK message) included in the response message. The parameter exchange process can be terminated when both the mobility 100 and the dispenser 200 accept all the exchanged parameters, and can also be terminated when either one does not accept the exchanged parameters. If not accepted, the protocol negotiation process may be revisited or the filling session may be terminated by the process described later.
[0243] In the communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, at least one or more first hydrogen filling method compatibilities can include at least one or more of the pressure class of the mobility 100 and the filling tank category (CHSS Category).
[0244] In the communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, at least one or more first physical characteristics can include at least one or more of the maximum allowable filling tank pressure, the maximum allowable filling tank temperature, the maximum allowable flow rate, and the filling tank volume (CHSS volume).
[0245] In the communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, the first parameter can further include parameters related to the acceptance of the mobility 100.
[0246] In a communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, the first monitoring parameter can include at least one or more of the current filling tank pressure (Current CHSS Pressure) and the current filling tank temperature (Current CHSS Temperature).
[0247] In a communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, at least one or more of the second filling method compatibilities can include at least one or more of the fueling delivery temperature (Fueling Delivery Temperature) of the dispenser 200 and the selected fueling table (Selected Fueling Table). The selected fueling table can include the sequence table of the selected fueling protocol in the protocol negotiation process and can be included in the OK message of S1330.
[0248] In a communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, at least one or more of the second physical characteristics can include at least one or more of the maximum fuel delivery pressure (Max Fuel Delivery Pressure), the maximum fuel delivery temperature (Max Fuel Delivery Temperature), the minimum fuel delivery temperature (Min Fuel Delivery Temperature), and the maximum fuel delivery flow rate (Max Fuel Delivery Flow Rate).
[0249] In a communication parameter exchange method for hydrogen filling according to an embodiment of the present invention, the filling target can include at least one or more of the target state of charge (Target SoC), the target final filling tank pressure (Target Final CHSS Pressure), the target final filling tank temperature (Target Final CHSS Temperature), the target average filling rate (Target APR:Average Fueling Rate), and the expected fueling duration (Expected Fueling Duration).
[0250] In one embodiment of the present invention, a method for exchanging communication parameters for hydrogen refueling, the second parameter may further include acceptance-related parameters of the dispenser 200.
[0251] In one embodiment of the present invention, a communication parameter exchange method for hydrogen refueling may include at least one of the following: current fuel delivery temperature and ambient temperature.
[0252] Mobility 100 can provide first parameters compatible with the UCDC level negotiated during the protocol negotiation process in a table format in stages (S1310). Dispenser 200 can provide a second set of parameters in a table format, in stages (S1330), that are compatible with the UCDC levels negotiated during the protocol negotiation process. At this time, the second set of parameters may include a message indicating acceptance of the first set of parameters provided in stage (S1310).
[0253] If Mobility 100 or Dispenser 200 does not accept the exchanged parameters, Mobility 100 may resume the protocol negotiation process. Alternatively, if Mobility 100 or Dispenser 200 does not accept the exchanged parameters, Mobility 100 may terminate the filling session.
[0254] In a protocol negotiation process that is performed again by a parameter exchange process that failed because mobility 100 or dispenser 200 did not accept the exchanged parameters, mobility 100 may propose a supported protocol suite other than the protocol provided in the failed parameter exchange process.
[0255] Table 17 shows the contents of a message including fuel supply parameters on the mobility side according to another embodiment of the present invention. [Table 17]
[0256] Table 18 shows the contents of a message including fuel supply parameters on the dispenser side according to another embodiment of the present invention. [Table 18]
[0257] A communication method according to one embodiment of the present invention may further include a step of renegotiating at least one of the communication protocol and fuel supply parameters if, as a result of fuel supply parameter negotiation (S405), the fuel supply parameters are incompatible between the mobility and the dispenser. In this case, the renegotiating step in the communication method according to one embodiment of the present invention can be performed again in steps (S403), (S404), and (S405). For example, one can go back to step (S403) and perform the renegotiation from step (S403), and then perform steps (S404) and (S405) in sequence. In yet another embodiment, one can go back to step (S404) and perform the renegotiation from step (S404), and then perform steps (S405) in sequence.
[0258] The step of renegotiating using a communication method according to another embodiment of the present invention may simplify steps (S403), (S404), and (S405) or omit some processes. Alternatively, steps (S403) and (S404) may be combined to negotiate both the communication protocol and the fuel supply protocol.
[0259] The step of renegotiating using a communication method according to another embodiment of the present invention may be carried out based on the remaining list of communication protocols and fuel supply protocols, excluding the communication protocol or fuel supply protocol selected in steps (S403) and (S404). For example, based on the compatibility and / or interoperability information obtained in step (S401), the communication protocol and fuel supply protocol may be negotiated together based on a protocol list that includes both the communication protocol and the fuel supply protocol, depending on whether or not they support each other.
[0260] A communication method according to one embodiment of the present invention may further include the steps of determining a third communication protocol and a third fuel supply protocol based on a predetermined policy if, as a result of fuel supply parameter negotiation (S405), the fuel supply parameters are incompatible between the mobility and the dispenser, and supplying hydrogen based on the third communication protocol and the third fuel supply protocol. In this case, the third fuel supply parameters may be determined based on the third fuel supply protocol, and the step of supplying hydrogen may be carried out based on the third fuel supply protocol and the third fuel supply parameters.
[0261] For example, if communication between the mobility device and the dispenser becomes impossible due to changes in the communication environment, the dispenser can fall back to a "No Communication" state and supply hydrogen fuel using a hydrogen fuel supply protocol based on "No Communication."
[0262] In one embodiment of the present invention, if the fuel supply parameters are incompatible between the mobility and the dispenser as a result of fuel supply parameter negotiation, the communication method can perform the step of terminating communication between the dispenser and the mobility (S409).
[0263] Referring back to FIG. 4, a safety check-in step (S406) that can be employed in the hydrogen filling communication two-way process according to an embodiment of the present invention is illustrated. In the safety check-in step (S406), the mobility and dispenser including mobility can confirm whether all necessary safety conditions are satisfied before the actual fuel supply starts.
[0264] When the fuel supply parameters are exchanged and the mobility and dispenser are considered to be compatible, the mobility and dispenser can perform a safety status inspection to confirm whether the fuel supply is safe. According to the fuel supply protocol, the safety inspection can be implicitly performed within the protocol, and depending on the implementation, the safety check-in step (S406) can be omitted.
[0265] Also, in the safety check-in step (S406), the mobility and / or dispenser can inspect whether the nozzle-receptacle is fixed, check for leaks, and check the last-minute status.
[0266] Also, after receiving a fuel supply parameter negotiation response message from the dispenser, if the fuel supply protocol supports a safety check-in, the mobility can transmit a safety check-in request message to the dispenser within the message sequence setting time to start the safety check-in step (S406).
[0267] The mobility and dispenser can exchange messages for a coupler check. A message including information indicating the mobility's own coupler check result (e.g., Mobility: OK) can be transmitted to the dispenser, and the dispenser can transmit a message including information indicating its own coupler check result (e.g., DP: OK) to the mobility.
[0268] Furthermore, the mobility unit and the dispenser can exchange messages related to gas leak checks. During the exchange of leak check-related messages, the dispenser can transmit information to the mobility unit indicating that the leak check is in progress (ongoing). The mobility unit can then transmit information to the dispenser unit indicating that it is waiting for the leak check results (waiting). Once the leak check is complete, the dispenser can transmit a message to the mobility unit indicating that the leak check is complete (Done) and requesting the measured tank volume.
[0269] Furthermore, the dispenser can transmit messages to the mobility unit for immobilized status checks, and the mobility unit can transmit messages to the dispenser indicating that it is ready for a status check.
[0270] In this way, when a mobility device reports parameters such as its current state or immobilization status to the dispenser, the dispenser can report parameters such as the coupler lock status, leak check status, and predicted mobility tank capacity to the mobility device.
[0271] Once the aforementioned safety check-in phase (S406) is completed, fuel supply may begin. During fuel supply, the mobility and dispenser can exchange information and monitor various state parameters to ensure that fuel supply is performed safely and efficiently. If necessary, the mobility or dispenser can send control messages to control the fuel supply phase (S406) or request the other party to take action to address safety-related conditions. The parameters and commands exchanged may vary depending on the actual fuel supply protocol.
[0272] Step (S407) is a monitoring and control step that can be adopted in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention.
[0273] During the monitoring and control phase (S407), the mobility and / or dispenser can monitor the fuel supply status and control fuel supply as needed. Once all safety checks are confirmed, the mobility and dispenser can begin fuel supply using the selected fuel supply protocol with the given parameters. While fueling, the mobility and dispenser exchange various measurement data to understand the fuel supply status and can act to detect critical accidents as quickly and safely as possible.
[0274] Furthermore, the mobility can transmit specific commands to the dispenser to control fuel supply stages (S407), such as starting and ending fuel supply. In this case, the mobility can use UDP with DTLS to support black channel communication. Black channel communication may refer to communication that applies the black channel principle, where secure communication must be guaranteed despite the output characteristics of the communication channel having unsecured attributes or attributes unrelated to the application.
[0275] To describe the monitoring and control phase (S407) in more detail, for example, a mobility unit, including the mobility unit itself, can transmit a message to the dispenser to start fuel supply control, and in response, the dispenser can transmit a message to the mobility unit including confirmation information (e.g., OK).
[0276] Furthermore, the mobility can transmit a message to the dispenser containing information about its own fuel supply loop (e.g., x, y, z), and the dispenser can provide the mobility with a message containing information about its own fuel supply loop corresponding to the mobility's fuel supply loop (e.g., a, b, c).
[0277] Furthermore, the mobility unit can transmit fuel control request messages to the dispenser, which may contain information to slow down or reduce the amount of fuel supplied. The dispenser can then transmit response messages to the mobility unit, which may contain information indicating a decrease in the fuel status (e.g., slowing).
[0278] Furthermore, the mobility unit can transmit a fuel supply control request message to the dispenser requesting a halt (stop) in fuel supply, and the dispenser can transmit a fuel supply status response message to the mobility unit that includes information indicating whether or not fuel supply has been stopped (stopping / stopped).
[0279] Thus, during the monitoring and control phase (S407), the mobility and dispenser can continuously or periodically exchange parameters related to the fuel supply status. The mobility transmits the current tank temperature, current tank pressure, etc., to the dispenser, and the dispenser can provide the mobility with parameters related to fuel supply start, stop, increase (ramping up), decrease (ramping down), current injection pressure, subsequent fuel supply plan, etc.
[0280] Control-related request messages transmitted from the mobility unit to the dispenser may include information and parameters regarding fuel supply, such as start, pause, resume, and terminate. Reporting-related messages transmitted from the mobility unit to the dispenser may also include information and parameters regarding the current tank temperature, current tank pressure, etc.
[0281] Messages related to reporting transmitted from the dispenser to the mobility unit may include information and parameters such as status information, current ambient temperature, current pressure ramp rate (PRR [Mbar / min]), deliver fuel flow rate (g / sec], current fuel delivery temperature, pre-cooling temperature, current fuel delivery pressure, whether the unit is fully charged, whether the cooling dispenser is in use, whether fallback is in use, reason for fuel supply interruption, and the current amount of hydrogen delivered.
[0282] Furthermore, messages related to target parameter updates transmitted from the dispenser to the mobility unit may include information and parameters regarding target final tank pressure, target final tank temperature, target fuel supply APR, target SOC, current SOC, estimated remaining duration, etc.
[0283] On the other hand, when TCP is used in the aforementioned monitoring and control phase (S407), if the safety check-in phase using a safety check-in response message or fuel supply protocol is omitted, the mobility unit can transmit a fueling loop request message to the dispenser within the message sequence setting time after receiving a fuel supply parameter negotiation response message from the dispenser. Request and response messages related to the fueling loop can be transmitted as DTLS messages.
[0284] After completing the hydrogen fuel supply through the aforementioned monitoring and control phase (S407), and before ending the session and separating the nozzle from the mobility, the mobility and dispenser can verify through a safety check-out use case that the quantity and dispenser each meet all safety requirements. While such a safety check-out phase is optional, it is preferable to define a dedicated safety check phase (S407) in the fuel supply protocol to ensure the desired level of safety in a precise and explicit manner.
[0285] A safety check-out step (S408) that can be adopted in a hydrogen refueling bidirectional communication process according to one embodiment of the present invention can be carried out as follows: The mobility and dispenser, including the mobility, can verify through the safety check-out step (S408) that all necessary safety conditions have been met before separating the dispenser nozzle from the outlet. In other words, the mobility and dispenser can verify that it is absolutely safe for the user or operator to separate the nozzle from the mobility after fuel supply is complete.
[0286] For example, after Mobility receives a fuel supply loop response message from the dispenser where “result” is set to “OK,” “status” is set to “finished,” or the prefix is “stopped,” if the hydrogen refueling protocol supports safe checkout, Mobility can initiate safe checkout and transmit a safe checkout request message to the dispenser within the message sequence setting time to perform the safe checkout stage (S408).
[0287] The mobility and dispenser can repeatedly report their respective statuses to each other until all safety checks are confirmed. If the two-way hydrogen refueling communication process does not require such safety checks at the end, the use case for safety checks may be omitted.
[0288] To elaborate on the aforementioned safety checkout stage (S408), for example, the mobility unit can transmit a message to the dispenser containing information about the coupler check result (e.g., OK), and the dispenser can transmit a message to the mobility unit containing information indicating that the coupler check is in progress (e.g., Ongoing).
[0289] Furthermore, the mobility unit can transmit a message containing coupler inspection result information (e.g., OK) back to the dispenser, and the dispenser can transmit a message containing coupler inspection completion information (e.g., Done) back to the mobility unit. Once the aforementioned coupler inspection completion information is confirmed to be successfully completed, the dispenser nozzle can be separated from the mobility receptacle by the user or operator.
[0290] During the aforementioned safe checkout phase (S408), the report message transmitted by the dispenser to the mobility may include information and parameters regarding the coupler unlock status. Coupler unlock status information may include information regarding locked, unlocked, icing, problem, etc.
[0291] The termination use case (UC9) can be performed if fuel delivery is completed and the nozzle is safely separated according to the hydrogen refueling protocol described above, or if a non-safely critical issue occurs during another use case.
[0292] A termination step (S409) that can be used in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention can be carried out as follows. The termination stage (S409) is the final stage of fuel supply, in which the mobility, including the mobility, and the dispenser can exchange information on fuel supply results regarding fuel supply performance and methods, and / or information on the reasons for any unexpected interruption of fuel supply, thereby completing all stages (S409) of hydrogen refueling. The termination use case may also be configured to handle any issues that are not safety-critical if they occur.
[0293] For example, after the mobility receives a safety checkout response message from the dispenser with the "result" set to "DONE," or a fuel supply loop response message with the "status" set to "finished" or prefixed with "stopped," the mobility can transmit a termination request message to the dispenser to complete the termination phase (S409).
[0294] To explain the final stage (S409) in more detail, for example, a mobility device can transmit a message to the dispenser inquiring about how much fuel has been supplied. The dispenser can then transmit a response message to the mobility device in response to the mobility device's inquiry message, which includes information (e.g., an X gram) about the amount of hydrogen supplied as fuel.
[0295] Furthermore, the mobility unit can transmit a confirmation request message to the dispenser regarding the completion of fuel supply, and the dispenser can transmit a goodbye message to the mobility unit as a response to the confirmation request message.
[0296] On the other hand, after fuel supply is complete and safety checks are confirmed, the mobility and dispenser may exchange at least some book-keeping information for the hydrogen refueling session at the end stage (S409). The mobility and dispenser may exchange summary information for the hydrogen refueling session before completing the end stage (S409).
[0297] Book-keeping information may include all information related to hydrogen refueling that is recorded in the mobility and dispenser in accordance with existing rules and policies, across all fueling sessions for hydrogen refueling and prior to the completion of the termination phase (S409) of Use Case 9 (UC9).
[0298] Bookkeeping or summary information may include information on how much fuel was supplied and what kind of reports were created. Report messages transmitted from mobility to dispensers may include information and parameters on the current tank temperature and current tank pressure, while report messages transmitted from dispensers to mobility may include information on the final SOC, final average fueling rate (APR), final measured tank pressure, actual fuel supply time, and actual amount of hydrogen supplied. Once all the necessary information for the fuel supply session has been saved, the fuel supply session can be completely terminated.
[0299] Table 19 shows examples of communication data from some of the use cases mentioned above (UC5 to UC9). [Table 19]
[0300] On the other hand, the error handling use case (UC10) is a functional block for handling situations where a non-fatal error has occurred, such as terminating the fuel supply procedure or abruptly interrupting communication, similar to normal termination. An error handling step (S410) that can be adopted in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention can be carried out as follows.
[0301] The error handling stage (S410) may define error conditions related to the fuel supply protocol and provide detection criteria, and if detected, may include a response process that includes notification, termination process, and fallback mechanism.
[0302] The error handling phase (S410) may be applied when a non-safe, non-fatal error occurs and further communication is impossible. In other words, the mobility and dispenser, including the mobility, can handle a non-safe, fatal error occurring at any time during fuel supply in the error handling phase (S410). In other words, the mobility and dispenser can immediately interrupt fuel supply and move to the termination use case (UC9) after pausing the previously operating use case.
[0303] If a mobility unit detects an event related to a non-safe fatal error, it can notify the dispenser of the reason for termination via a terminate request (TerminateReq) message and stop the current fuel supply or communication session. The dispenser can respond to the terminate request message by terminating the current communication session. If further communication is not possible, the current session may be terminated without further notification.
[0304] Furthermore, if a non-safety-critical error is detected by the mobility and the communication channel continues to operate, the mobility can send a TerminateReq message to the dispenser with its "action" set to "stop" and its "reason" set to an appropriate reason or reason code. An appropriate reason or reason code may include reasons such as "message is corrupted."
[0305] The aforementioned termination request message may be transmitted in the event of non-critical communication errors, system errors, and qualitative errors, except in cases where recovery is not possible.
[0306] In other words, for successful fuel supply, communication must exhibit the behavior expected by the protocol, and fuel supply operation must be within the acceptable range of the fuel supply protocol. However, in reality, a variety of abnormal events can occur. Among these, some errors are minor and can be easily handled, while others are irrecoverable and prevent fuel supply from proceeding. Therefore, the error handling stage (S410) defines error conditions that are not critical to safety and provides exemplary error conditions and possible responses.
[0307] Communication errors may include situations where communication is interrupted, or where received data cannot be recognized due to encoding or syntax errors, or where received data is within an unacceptable range. System errors may include situations where the dispenser or mobility device independently detects a significant system error. Qualitative errors may include situations where the quality of communication performance fails to meet the required standards, or where the quality of data integrity or precision fails to meet the required standards.
[0308] The hydrogen refueling communication bidirectional process of this embodiment can perform the following specific error handling steps (S410) in response to the aforementioned error conditions: (1) to (4).
[0309] If a non-critical error occurs that makes further communication impossible, the mobility and dispensers will immediately cease fuel supply, but may take safe measures to terminate communication and end the session.
[0310] If a non-critical error occurs that interrupts the fuel supply and prevents the fuel supply from being completed, the fuel supply protocol can define a fallback mechanism, for example, by defining a non-communication fuel supply method.
[0311] If a non-safety-critical error is detected by the mobility device and the communication channel remains operational, the mobility device can send a termination request message to the dispenser with the "action" set to "stop" and the "reason" set to an appropriate reason code.
[0312] If a non-safety-critical error is detected by the dispenser and the communication channel remains operational, the dispenser may first immediately cease fuel supply and transmit a termination request message to the mobility with the "Operation" set to "Aborted" and the "Reason" set to an appropriate reason or reason code.
[0313] As described above, the hydrogen refueling communication bidirectional process, including the fuel supply protocol, defines error conditions related to the fuel supply protocol, provides detection criteria, and if an error is detected by the detection criteria, an error handling stage (S410) including notification, termination stage (S410), and fallback mechanism can be performed.
[0314] On the other hand, a critical safety issue could occur during the fuel supply process in a hydrogen refueling system, requiring an emergency response. An emergency handling step (S411) that can be used in a hydrogen refueling communication bidirectional process according to one embodiment of the present invention can be carried out as follows.
[0315] The emergency response phase (S411) defines essential safety conditions requiring emergency response during refueling and may include response processes to prevent essential safety accidents.
[0316] For safe fuel supply, communications must indicate the expected behavior according to the protocol, and fuel supply operations must remain within the safe limits of the fuel supply protocol. However, problems may occur during fuel supply, potentially leading the fuel supply system (or hydrogen refueling system) to reach a critical state that must be avoided at any cost. Therefore, the emergency handling phase (S411) can provide critical cases where safety-critical emergency conditions and possible responses to those emergency conditions must be defined and considered.
[0317] The fuel supply protocol may define emergency conditions related to the protocol, provide sensing criteria and performance requirements, and specify response stages (S411) to ensure that no hazardous situation is encountered. Specifically, if the mobility system detects a high-pressure condition exceeding a previously set threshold during the hydrogen refueling phase (S411), the mobility system can transmit a first emergency stop request message to the dispenser, which includes information requesting the cessation of fuel supply due to the high pressure (e.g., Emg:Stop(high pressure)). The dispenser can then transmit a response message to the mobility system, which includes information indicating that it is processing an emergency fuel supply cessation in response to the first emergency stop request message (e.g., Emg:Stopping).
[0318] Furthermore, immediately after receiving the response message, or after a predetermined period of time has elapsed, the mobility can transmit the first emergency stop request message back to the dispenser. The dispenser can then transmit a response message to the mobility that includes information indicating that the fuel supply has been emergency stopped by the first emergency stop request message (e.g., Emg:Stopped).
[0319] On the other hand, if the dispenser detects a hydrogen fuel leak (leaking) during the hydrogen refueling phase (S411), the dispenser can transmit a second emergency stop request message to the mobility vehicle, which includes information indicating that it is handling the cessation of fuel supply due to the leak (e.g., Emg:Stopping(leaking)). The mobility vehicle can transmit a response message to the dispenser, which includes information indicating that it has received the second emergency stop request message (e.g., Emg:Confirmed).
[0320] Furthermore, the dispenser can transmit a third emergency stop notification message to the mobility unit, which includes information indicating that it has handled a fuel supply interruption due to a leak (e.g., Emg:Stopped(leaking)). The mobility unit can transmit a response message to the dispenser, which includes information indicating that it has acknowledged the third emergency stop notification message (e.g., Emg:Confirmed).
[0321] According to the configuration described above, if a critical situation affecting safety in mobility or a dispenser is detected, it can immediately take necessary measures to prevent a disaster, and, where possible, transmit an emergency notification message containing information about the situation to the other party and cut off communication.
[0322] When an emergency notification message is received, the mobility or dispenser can respond immediately with the action indicated in the emergency notification message, and the communication can be terminated without excessive delay. An emergency notification message consists of a header and a body attached to the header. The header contains information indicating that it is an emergency notification, and the message may contain values, information, or parameters for the class, type, and action of the emergency notification. The aforementioned emergency notification message can be transmitted via TLS or DTLS messages, depending on the technology used for communication.
[0323] Referring again to Figure 4, the objectives, prerequisites, and subsequent conditions for the safety check-in stage (S406) can be shown in Table 20. [Table 20]
[0324] As previously mentioned, once the fuel supply parameter negotiation phase (S405) is successfully completed, the fuel supply protocol can proceed to the safety check-in phase (S406). If the communication physical layer is specified to require a pairing procedure, the mobility and dispenser can re-check the pairing before dispensing hydrogen during the safety check-in phase (S406).
[0325] Even if the communication physical layer is not specified to require a pairing procedure, the mobility and dispenser can re-check the pairing before dispensing hydrogen during the safety check-in phase (S406).
[0326] After receiving a message from the dispenser indicating the completion of stage (S405) (e.g., FuelParamNegoRes), if the fuel supply protocol assists with the safety check-in stage (S406), the mobility can transmit a message to the dispenser within a predetermined time interval (e.g., MessageSequenceTimeout) indicating the start of the safety check-in stage (S406) (e.g., SafetyCheckInReq).
[0327] As an alternative embodiment, if a message indicating the completion of stage (S405) is transmitted to the other party by either the mobility device or the dispenser, either party may transmit a message indicating the start of the safety check-in stage (S406).
[0328] According to one embodiment of the present invention, the messages transmitted and received during the safety check-in phase (S406) may be defined based on the content of each fuel supply protocol as specified in a standard such as ISO 19885-3.
[0329] According to one embodiment of the present invention, the messages transmitted and received during the security check-in phase (S406) may include a result element containing the result value obtained by processing the request message. The result value provided by the result element may include, for example, "OK" if successful, "FAILED" if unsuccessful, and "PENDING" otherwise.
[0330] If all safety conditions are met when the mobility device transmits the SafetyCheckInReq message to the dispenser, the result value of that message may be set to "OK".
[0331] If, when Mobility transmits a SafetyCheckInReq message to the dispenser, several safety conditions have not yet been met, the result value of that message may be set to "PENDING".
[0332] After the dispenser receives the SafetyCheckInReq message, it can respond to the mobility with a SafetyCheckInRes message along with safety-check parameters within the MessageResponseTimeout time interval.
[0333] If, by any chance, all safety conditions are met when the dispenser transmits the SafetyCheckInRes message to the mobility device, the result value of that message may be set to "OK".
[0334] If, when the dispenser transmits a SafetyCheckInRes message to the mobility device, several safety conditions have not yet been met, the result value of that message may be set to "PENDING".
[0335] If a SafetyCheckInRes message with a result value set to "PENDING" is received, Mobility can transmit other SafetyCheckInReq messages to the dispenser within the MessageResponseTimeout time interval.
[0336] If a SafetyCheckInReq message with a result value set to "PENDING" is received, the dispenser can transmit other SafetyCheckInReq messages to the mobility within the MessageResponseTimeout time interval.
[0337] If a mobility device or dispenser fails to confirm all safety conditions within a specified time (e.g., UCSafetyCheckInTimeout), it may transmit an ErrNotifReq message with the "reason" field set to the appropriate error code.
[0338] As an alternative implementation, a mobility device or dispenser can transmit a request message to the other party indicating the start of a safety check-in, and the other party can respond with a response message to the safety check-in request message within a predetermined time interval.
[0339] Referring again to Figure 4, the objectives, prerequisites, and subsequent conditions for the monitoring and control phase (S407) can be shown in Table 21. [Table 21]
[0340] As previously mentioned, once the safety check-in phase (S406) is successfully completed, the fuel supply protocol can proceed to the monitoring and control phase (S407). If the safety check-in phase (S406) is omitted, and the fuel supply parameter negotiation phase (S405) is successfully completed, the fuel supply protocol can proceed to the monitoring and control phase (S407).
[0341] While the monitoring and control phase (S407) is being performed, the dispenser can carry out all the necessary steps to refuel the mobility.
[0342] When the TCP standard is used in fuel supply control and monitoring use cases, the mobility can receive a SafetyCheckInRes message or, in embodiments where the safety check-in phase (S406) is omitted, after receiving a FuelParamNegoRes message, it can transmit a message (e.g., a FuelLoopReq message) to the dispenser requesting the start of the monitoring and control phase (S407) within a predetermined time interval (e.g., MessageSequenceTimeout).
[0343] In embodiments where the aforementioned black channel is used, and the SafetyCheckInRes message is transmitted or the security check-in phase (S406) is omitted, after transmitting the FuelParamNegoRes message, the mobility (as the client) and the dispenser (as the server) can initiate a DTLS 1.3 handshake in accordance with RFC 9147 with a session resumption using NewSessionTicket. At this time, NewSessionTicket may be received from the dispenser.
[0344] After the DTLS 1.3 handshake has been successfully completed (finished), the mobility can transmit a message (e.g., a FuelLoopReq message) to the dispenser requesting the start of the monitoring and control phase (S407) within a predetermined time interval (e.g., MessageSequenceTimeout).
[0345] In this case, 0-RTT does not need to be used for DTLS session resumption.
[0346] FuelLoopReq messages and their response messages (e.g., FuelLoopRes messages) can all be transmitted in accordance with the DTLS message standard. Additional requirements may be necessary for black channel methods.
[0347] The FuelLoopReq message can be implemented based on the definition of each fuel supply protocol. The fuel supply protocol can identify static or dynamic data contained within FuelLoopReq and FuelLoopRes, which can be used to monitor the fuel supply status and exchange safety-related information.
[0348] The element names included in the FuelLoopReq message may include action, reason, etc., and may be shown in Table 22 below. Elements not shown in Table 22 below may be identified by their respective fuel supply protocol standards, such as ISO 19885-3. [Table 22]
[0349] The element names included in the messages sent and received in stage S407 (e.g., FuelLoopRes messages) may include status, reason, result, etc., and may be shown in Table 23 below. Elements not shown in Table 23 below may be identified by their respective fuel supply protocol standards, such as ISO 19885-3. [Table 23]
[0350] When a mobility device transmits a FeulLoopReq message, the dispenser may be expected to perform an action. The mobility device can transmit the message with the desired action code, which may be defined by the fuel supply protocol.
[0351] After receiving a FuelLoopReq message (for example, with "action" set to "start"), when the dispenser is ready to begin, it can use the negotiated method to initiate the fuel supply procedure and respond with a FuelLoopRes message with "result" set to "OK".
[0352] If the dispenser is not ready to start after receiving a FuelLoopReq message (for example, with "action" set to "start"), the dispenser can respond with a FuelLoopRes message with "result" set to "pending".
[0353] After receiving a FuelLoopReq message (for example, with "action" set to "stop"), if the dispenser is ready to abort, it can abort the fuel supply procedure as defined in the fuel supply protocol and respond with a FuelLoopRes message with "result" set to "ONGOING".
[0354] After receiving a FuelLoopReq message (for example, with "action" set to "stop"), if the dispenser is ready to abort, it can immediately abort the fuel supply procedure and respond with a FuelLoopRes message with "result" set to "OK".
[0355] After receiving a FuelLoopReq message, the dispenser can respond with a FuelLoopRes message within a predetermined time interval (e.g., MessageSequenceTimeout).
[0356] If the dispenser has successfully processed the received FuelLoopReq message, it can transmit a FuelLoopRes message with "result" set to "OK". If the dispenser has not successfully processed the received FuelLoopReq message, it may transmit a FuelLoopRes message with "result" set to "FAILED" or another appropriate error code.
[0357] The dispenser can transmit FuelLoopRes messages where "status" is set using one of the supported codes specified in Table 23 or the fuel supply protocol. The dispenser can transmit a FuelLoopRes message with "status" set to "finished" once fuel delivery is complete (done) and the intended fuel delivery target has been achieved.
[0358] The dispenser can transmit a FuelLoopRes message when fuel supply is interrupted due to an error, with "status" set to "stop_error" and "reason" set to the appropriate reason code. The dispenser can transmit a FuelLoopRes message with the status set to "stopping" if the "action" of the most recent FuelLoopReq message is set to "stop" and the fuel supply has not been completely stopped.
[0359] The dispenser can transmit a FuelLoopRes message with the status set to "stopped_requested" if the "action" of the most recent FuelLoopReq message is set to "stop" and the fuel supply has been completely stopped.
[0360] When a mobility device transmits a FuelLoopReq message with "action" set to "stop" and receives a FuelLoopRes message with "status" set to "stopping", the mobility device can transmit a FuelLoopRes message with "action" set to "stop".
[0361] If a mobility device receives a FuelLoopRes message and fuel supply is not finished, the mobility device can transmit a FuelLoopReq message within a predetermined time interval (e.g., MessageSequenceTimeout).
[0362] In the event of a safety-critical incident, the mobility or dispenser can immediately transmit an EmergencyReq message, halting the fuel supply procedure and closing communications.
[0363] The embodiments related to step S407 described above have mainly focused on embodiments in which the mobility device requests the start of each step and the dispenser responds, but the concept of the present invention is not limited thereto. In alternative embodiments of the present invention, either the mobility device or the dispenser can transmit a message requesting the start of step S407 first, and the other party can perform step S407 by responding to the message requesting the start of step S407.
[0364] In stage S407, a message transmitted by either the mobility unit or the dispenser may include a monitoring request regarding the status of the hydrogen fuel supply procedure. The response message sent by the other party may include the requested monitoring status information.
[0365] At this time, the conditions and related parameters that may be subject to a monitoring request may include a set of parameters that are exchanged in stage (S405). The conditions and related parameters that may be subject to a monitoring request may include the conditions and parameters of the mobility or dispenser. The conditions and related parameters that may be subject to a monitoring request may include the fuel supply conditions and / or related parameters of the mobility and / or dispenser that are changed or maintained by the hydrogen fuel supply procedure.
[0366] Furthermore, the conditions that may be subject to monitoring requests may include the status and / or information of the procedure itself in which fuel is supplied from the dispenser to the mobility. For example, this may include information such as whether the fuel supply procedure is ongoing, paused, or terminated, and / or, if stopped / terminated, whether it was stopped due to an error or finished due to achieving the target.
[0367] Referring again to Figure 4, the objectives, prerequisites, and subsequent conditions of the safe checkout stage (S408) can be shown in Table 24. [Table 24]
[0368] A safety checkout stage (S408) may be performed to ensure that the mobility and dispenser meet safety conditions before terminating the session and unplugging the nozzle from the mobility after the fuel supply has finished. Although this stage (S408) is optional, it is strongly recommended that a dedicated safety checkout procedure be defined by the fuel supply protocol to ensure the desired level of safety in a precise and explicit manner.
[0369] The information exchange used in the safety checkout step may be used for the purpose of diagnosis and accountability in the event of a safety-related incident.
[0370] As previously mentioned, once the monitoring and control phase (S407) and associated fuel supply procedures are successfully completed (finished), the fuel supply protocol can proceed to the safe checkout phase (S408).
[0371] Regardless of whether a safe checkout is performed, a fuel supply protocol compliant with ISO 19885-2 can define a set of safety conditions that are confirmed between the mobility and the dispenser before the nozzle is unplugged.
[0372] After receiving a FuelLoopRes message with "Result" set to "OK" and "status" set to a prefixed value of "finished" or "stopped", if the fuel supply protocol assists with safe checkout, Mobility may transmit a message (e.g., a SafetyCheckOutReq message) to the dispenser via the TLS channel requesting the start of the safe checkout phase (S408) within a predetermined time interval (e.g., MessageSequenceTimeout).
[0373] At this time, if the TCP / TLS channel connection is broken, the mobility can re-establish the TCP / TLS channel with the dispenser. The re-establishment process can be initiated by a TLS-resumption handshake using a NewSessionTicket received before transmitting the SafetyCheckOutReq message.
[0374] As an alternative embodiment, a message requesting the commencement of stage (S408) may be transmitted to the other party by either the mobility device or the dispenser. In this case, stage (S408) may be performed by the other party responding to the message requesting the commencement of stage (S408).
[0375] According to one embodiment of the present invention, the messages transmitted and received during the safe checkout phase (S408) may be defined based on the content of the respective fuel supply protocol as specified in a standard such as ISO 19885-3.
[0376] According to one embodiment of the present invention, the message transmitted and received in the secure checkout stage (S408) may include the result value of processing the request message in the result type. The result value that may be provided in the result type may include, for example, "OK" if successful, "FAILED" if unsuccessful, and "PENDING" otherwise.
[0377] If, by any chance, the mobility device transmits a SafetyCheckOutReq message to the dispenser, the result value of that message may be set to "OK" if the mobility device confirms that all safety conditions are met. If, by any chance, Mobility transmits a SafetyCheckOutReq message to the dispenser, and several safety conditions have not yet been met, the result value of that message may be set to "PENDING".
[0378] After the dispenser receives the SafetyCheckOutReq message, it can respond to the mobility with a SafetyCheckOutRes message along with safety-check parameters within the MessageResponseTimeout time interval.
[0379] If the dispenser confirms that all safety conditions are met when it transmits the SafetyCheckOutRes message to the mobility device, the result value of that message may be set to "OK".
[0380] If, by any chance, the dispenser transmits a SafetyCheckOutRes message to the mobility device, and several safety conditions have not yet been met, the result value of that message may be set to "PENDING".
[0381] If a SafetyCheckOutRes message with a result value set to "PENDING" is received, Mobility can then transmit other SafetyCheckOutReq messages to the dispenser within the MessageResponseTimeout time interval.
[0382] If a SafetyCheckOutReq message with a result value set to "PENDING" is received, the dispenser can transmit other SafetyCheckOutReq messages to the mobility within the MessageResponseTimeout time interval.
[0383] If a mobility device or dispenser fails to confirm all safety conditions within a specified time (e.g., UCSafetyCheckOutTimeout), it may transmit an ErrNotifReq message with the "reason" field set to the appropriate error code.
[0384] As an alternative implementation, either the mobility device or the dispenser can transmit a request message to the other party indicating the start of a secure checkout, and the other party can respond with a response message to the secure checkout request message within a predetermined time interval.
[0385] According to one embodiment of the present invention, if a non-fatal error is detected during the monitoring and control phase (S407) and the fuel supply is interrupted before the fuel supply is completed, the fuel supply protocol defines a fallback mechanism that ensures backward compatibility among mutually compatible mechanisms between the mobility and the dispenser, and the fuel supply can be resumed and terminated based on the fallback mechanism. In this case, the fallback mechanism could be, for example, a non-communication fueling method.
[0386] As an alternative embodiment, if a non-fatal error is detected in the monitoring and control phase (S407) and fuel supply is interrupted before fuel supply is completed, the mobility and dispenser may repeat some or all of the communication protocol negotiation phase (S403), fuel supply protocol negotiation phase (S404), and fuel supply parameter negotiation phase (S405).
[0387] As an alternative embodiment, the mobility and dispenser can use the interoperability information obtained in the discovery and pairing phase (S401) to reduce the amount of information exchanged during the process of repeating some or all of the communication protocol negotiation phase (S403), fuel supply protocol negotiation phase (S404), and fuel supply parameter negotiation phase (S405). For example, if a communication or fuel supply condition is identified where negotiation has already been completed and the selected protocol cannot be maintained, some or all of the communication protocol negotiation phase (S403), fuel supply protocol negotiation phase (S404), and fuel supply parameter negotiation phase (S405) may be repeated, excluding the previously selected protocol.
[0388] As an alternative embodiment, if a change in the communication environment and a change in the fuel supply infrastructure are detected as a safely non-fatal error during the monitoring and control phase (S407), and fuel supply is interrupted before fuel supply is completed, the mobility and dispenser may restart some or all of the communication protocol negotiation phase (S403), fuel supply protocol negotiation phase (S404), and fuel supply parameter negotiation phase (S405).
[0389] Changes in the communication environment can include situations where the communication channel connection is broken (disconnected). Changes in the communication environment may include cases where the received data cannot be recognized, or where the received data is in an unacceptable range.
[0390] Changes in the communication environment may include situations where the required level of communication performance cannot be met. Changes in the communication environment may include situations where the integrity or precision of data exchanged through communication cannot meet the required standards.
[0391] Changes in the fuel supply infrastructure may result in changes to or maintenance of fuel supply parameters on the mobility side based on control parameters for fuel supply on the dispenser side, but this may include cases where the required level of change or maintenance of fuel supply-related parameters on the mobility side is not met.
[0392] Some of the safety conditions checked or monitored in the safety check-in phase (S406), monitoring and control phase (S407), and safety check-out phase (S408) are shown in Table 19 above, but the following may be considered in addition or in addition to the above:
[0393] Safety conditions may include safety-related elements on both sides of the mobility for hydrogen refueling (fuel supply) and the hydrogen refueling machine or dispenser, and / or the fastening condition of the nozzles and receptacles on both sides for initiating hydrogen fuel supply.
[0394] On the hydrogen mobility side, factors such as the pressure and temperature inside the hydrogen tank may also be included. At the hydrogen refueling station, this could include factors such as cylinder temperature, refueling pressure, and ambient temperature. Safety conditions on both sides of the connection and fuel supply path may include the nozzle-receptacle connection status—that is, whether or not it is connected, the state of the connection, and the leakage status.
[0395] The nozzle-receptacle connection status may include information on whether it is suitable and / or sufficient for carrying out the hydrogen fuel supply procedure.
[0396] In one alternative embodiment shown in Figure 4, if the safety check-in stage (S406) performs minimal condition checks, i.e., checks of safety elements including whether or not the nozzle-receptacle is fastened and the fastening status, the safety check-in stage (S406) may be performed prior to the fuel supply parameter negotiation stage (S405).
[0397] In one alternative embodiment shown in Figure 4, if the safety check-in stage (S406) performs minimal condition checks, i.e., checks of safety elements including whether or not the nozzle-receptacle is fastened and the fastening status, then any remaining safety elements not checked in the safety check-in stage (S406) can be negotiated and checked in the fuel supply parameter negotiation stage (S405).
[0398] In one alternative embodiment shown in Figure 4, when the safety check-in stage (S406) performs minimal condition checks, i.e., checks of safety elements including whether or not there is a connection between the nozzle and the receptacle, and the condition of the connection, any remaining safety elements not checked in the safety check-in stage (S406) can be monitored and checked in the monitoring and control stage (S407). In this case, the safety elements can be monitored and checked in the monitoring and control stage (S407) independently of (or regardless of) being negotiated and checked in the fuel supply parameter negotiation stage (S405).
[0399] In one alternative embodiment shown in Figure 4, multiple safety elements, including those checked in the safety check-in stage (S406), can be negotiated and checked in the fuel supply parameter negotiation stage (S405).
[0400] In one alternative embodiment shown in Figure 4, multiple safety elements, including those checked in the safety check-in phase (S406), may be monitored and checked in the monitoring and control phase (S407). In this case, the safety elements may be monitored and checked in the monitoring and control phase (S407) independently of (or regardless of) those negotiated and checked in the fuel supply parameter negotiation phase (S405).
[0401] Referring again to Figure 4, once fueling is successfully finished and all safety conditions are optionally confirmed, the mobility and dispenser termination use cases can be performed.
[0402] The objectives, prerequisites, and subsequent conditions of the termination stage (S409) may be shown in Table 25. [Table 25]
[0403] If a safety check-out use case is omitted after receiving a SafetyCheckOutRes message with "Result" set to "DONE" or a FuelLoopRes message with "status" set to a prefixed value of "finished" or "stopped", the mobility can transmit a termination request message (e.g., a "TerminateReq message") to the dispenser.
[0404] Details regarding termination request messages (e.g., "TerminateReq messages") may be defined in the respective fuel supply protocol specifications. For example, parameters included in the TerminateReq message and exchanged between mobility and dispensers may be defined separately for each individual fuel supply protocol.
[0405] The element names included in the TerminateReq message may include tank_press, tank_temp, amount, soc, reason, etc., and may be shown in Table 26 below. Elements not shown in Table 26 below may be identified by their respective fuel supply protocol standards, such as ISO 19885-3. [Table 26]
[0406] When a dispenser receives a TerminateReq message from a mobility device, the dispenser can respond with a termination response message (e.g., TerminateRes) within a predetermined time interval (e.g., MessageResponseTimeout).
[0407] Details regarding termination response messages (e.g., "TerminateRes messages") may be defined in the respective fuel supply protocol specifications. For example, parameters included in the TerminateRes message and exchanged between mobility and dispensers may be defined separately for each individual fuel supply protocol.
[0408] The element names included in the TerminateRes message may include aprr, duration, amount, soc, result, etc., and may be shown in Table 27 below. Elements not listed in Table 27 below may be identified by their respective fuel supply protocol standards, such as ISO 19885-3. [Table 27]
[0409] As an alternative embodiment, a message requesting the commencement of the termination phase (S409) may be transmitted to the other party by either the mobility or the dispenser. In this case, the other party may perform the termination phase (S409) by responding to the message requesting the commencement of the termination phase (S409).
[0410] For successful refueling, communications must provide expected behaviors according to the protocol. Refueling actions must remain within the limits accommodating the refueling protocol. However, in reality, a variety of unusual events can occur. Some errors may be minor and easily handled. However, errors that cannot be recovered from and prevent the continuation of refueling may also occur.
[0411] In this specification, “failure” or “error” may refer to any incidents occurring during UC1-UC9 (S401-S409) or hydrogen fueling that can interrupt the ongoing process.
[0412] In stage (S410), the conditions for a non-safety critical error, exemplary error conditions, and their responses may be specified.
[0413] Referring again to Figure 4, the purpose, prerequisites, and subsequent conditions of the error handling stage (S410) can be shown in Table 28. [Table 28]
[0414] Non-safety critical error conditions can include, for example, the following: Communication errors may include: 1) communication being disconnected; 2) the received data being unrecognizable due to encoding or syntactic error; and 3) the received data being in an unacceptable range.
[0415] System errors may include cases where the dispenser or mobility device detects its own critical system error.
[0416] Qualitative errors may include: 1) failure to meet the required level of communication performance, and 2) failure to meet the required level of data integrity or precision.
[0417] If a non-safety-critical error occurs and further communication is impossible, the mobility and dispenser will immediately stop the fueling and take safe steps, and stop the communication to end the session.
[0418] When a non-safety-critical error occurs and fuel supply is interrupted far from completion, the fuel supply protocol can define a fallback mechanism, for example, by defining a non-communication fuelling method.
[0419] When a non-safety-critical error is detected by the mobility device and the communication channel is still operational, the mobility device can transmit a TerminateReq message with "action" set to "stop" and "reason" set to the appropriate reason code.
[0420] When a non-safety-critical error is detected by the dispenser and the communication channel is still operational, the dispenser can first immediately stop the fuel supply and then transmit a TerminateReq message with "action" set to "stop" and "reason" set to the appropriate reason code.
[0421] A fuel supply protocol can define error conditions by protocol and provide detection criteria, as well as pre-prescribed response procedures, including notification, termination procedures, and fallback mechanisms.
[0422] Referring again to Figure 4, the objectives, prerequisites, and subsequent conditions of the emergency handling stage (S411) can be shown in Table 29 below. [Table 29]
[0423] A fuel supply protocol can define emergency conditions by protocol and provide pre-prescribed response procedures, including detection criteria, notification, termination procedures, and fallback mechanisms, to avoid entering a detrimental situation by all means.
[0424] When a mobility or dispenser detects a safety-critical situation, necessary actions to prevent a catastrophic incident can be taken immediately. If possible, an EmergencyNotif message may be transmitted along with information about the incident, and communication can be closed.
[0425] When a mobility or dispenser receives an EmergencyNotif message, it can immediately respond to the action instructed in the message and immediately close the communication without undue delay. EmergencyNotif messages can be TLS or DTLS messages, depending on the communication technology used.
[0426] For the sake of message criticality and delivery efficiency, fuel supply protocols may not permit modifications to the structure of EmergencyNotif messages.
[0427] The element names included in an EmergencyNotification message may include class, type, action, etc., and may be shown in Table 30 below. Elements not shown in Table 30 below may be identified by each fuel supply protocol standard, such as ISO 19885-3. For example, additional emergency reason codes and action codes may be identified by each protocol. [Table 30]
[0428] Figure 17 is an operation flowchart illustrating a communication method for supplying hydrogen fuel according to one embodiment of the present invention. Figure 18 is an operation flowchart illustrating a communication method for hydrogen fuel supply according to another embodiment of the present invention. Referring to Figure 18, the relationship between stages S401-S409 in Figure 4 and stages S2010-S2030 in Figure 17 is illustrated.
[0429] Referring to Figures 4, 17, and 18, a communication method for hydrogen fuel supply (fueling) performed by a communication device for hydrogen fuel mobility according to one embodiment of the present invention includes a step (S2010, S400) for detecting an error that occurs during the communication process (steps S403-S406, or steps S408-S409) for preparing for hydrogen fuel supply between a dispenser that supplies hydrogen to a mobility or during the process of the dispenser supplying hydrogen to the mobility (step S407). The process may include: a step (S2020: which may be performed as part of steps S410 or S411) to determine whether to stop the communication process (steps S403 to S406, or steps S408 to S409) or the hydrogen fueling process (step S407) in response to the detected error; and a step (S2030: which may be performed as part of steps S403 to S411) to perform a subsequent process defined based on the detected error.
[0430] The following embodiments may be carried out based on interoperability or compatibility information shared between the mobility and the dispenser in step S401 of Figure 4. In particular, the process in which the communication protocol, fuel supply protocol, and fuel supply parameters are negotiated and determined in steps S403 to S405 may be carried out within the scope of the interoperability or compatibility information.
[0431] Interoperability or compatibility information is identified and shared in stage S410, but may be re-identified and shared in an updated state to suit the current situation in subsequent processes.
[0432] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error (step S2020: which may be performed as part of step S410 or S411) may include the step of classifying the detected error as either a safety-critical error or a non-safety-critical error.
[0433] At this point, the step of classifying the detected errors as safety-critical errors may be performed by step S2020 in Figures 17 and 18, or by part of step S411 in Figure 4. Once the detected errors are classified as safety-critical errors, the subsequent steps may be performed by step S2030 in Figures 17 and 18, or by part of step S411 in Figure 4. At this point, errors classified as safety-critical errors may be treated as emergencies.
[0434] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error (S2020) may further include a step of classifying the detected error as one of a communication error, a system error, or a qualitative error (performed as part of step S410), if the detected error is not a safety-critical error.
[0435] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error (S2030) may include at least a portion of the step of performing an emergency handling process (S411) if the detected error is a safely fatal error.
[0436] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step (S2020) of determining whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error may further include a step of determining whether to replace the first fuel supply protocol of the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol if the detected error is not a safely fatal error.
[0437] In a communication method for hydrogen fuel supply performed by a mobility communication device according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error (S2030) may include the step of transmitting a message to a dispenser including whether or not the communication process or the hydrogen fuel supply process has been terminated.
[0438] Various types of incidents that occur during steps S403 to S409 may be detected by the mobility or dispenser (S2010). At this time, the detected incidents may be classified as errors if they satisfy certain conditions (S2010 and S2020). If the detected error is a non-safety-critical error, it may be processed in the error handling process of step S410 or in step S2030; if it is a safety-critical error, it may be processed in the emergency handling process of step S411 or in step S2030.
[0439] In one embodiment of the present invention, the criteria for classifying a detected error as either a non-safety-critical error or a safety-critical error (emergency) are predetermined by the fuel supply protocol in stages S403 to S409, and the detected error can be classified according to each stage S403 to S409 when an error is detected.
[0440] In an alternative embodiment of the present invention, an error is transmitted to the processes of steps S410 and / or S411 after detection, and steps S410 and / or S411 can classify whether the detected error is a non-safety-critical error or a safety-critical error (emergency). That is, step S410 can classify whether the error is a non-safety-critical error and, if it is a non-safety-critical error, whether it is a communication error, a system error, or a qualitative error. Step S411 can classify whether the error is a safety-critical error.
[0441] Stage S410 classifies the detected error and can decide whether to abort the fuel supply process based on the classification result or the error status. If it is decided to continue the fuel supply process without aborting it (based on updated interoperability or compatibility information) using the fallback fuel supply protocol, then as a result of stage S410, the necessary stages from stages S403 to S409 to continue the fuel supply process may be performed again.
[0442] Furthermore, if the cause of the error is removed and the system is restored to a normal state in stage S410 or S411, the mobility or dispenser may, individually or in cooperation with each other, return to any one of stages S403 to S409 that was being performed before the error occurred, or to the next stage, and continue to perform the hydrogen fuel supply process and the communication process.
[0443] A communication method for hydrogen fueling performed by a communication device of a dispenser supplying hydrogen fuel to a hydrogen fuel mobility vehicle according to one embodiment of the present invention may include a step of detecting an error occurring during a communication process for preparing hydrogen fueling between the dispenser and the mobility vehicle (steps S403-S406, or steps S408-S409) or during the process in which the dispenser fuels the mobility vehicle with hydrogen (step S407) (step S2010, which may be performed as part of steps S403-S409); a step of determining whether to stop the communication process (steps S403-S406, or steps S408-S409) or the hydrogen fueling process (step S407) in response to the detected error (step S2020, which may be performed as part of steps S410 or S411); and a step of performing a subsequent process defined based on the detected error (step S2030, which is performed as part of steps S403-S411).
[0444] In a communication method for supplying hydrogen fuel performed by a communication device of a dispenser according to one embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error (which may be performed as part of step S2020, step S410, or S411) may include the step of classifying the detected error as either a safety-critical error or a non-safety-critical error.
[0445] In a communication method for supplying hydrogen fuel performed by a communication device of a dispenser according to one embodiment of the present invention, the step of determining whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error (S2020) may further include a step of classifying the detected error as a communication error, a system error, or a qualitative error (which may be performed as part of step S410) if the detected error is not a safety-critical error.
[0446] In a communication method for supplying hydrogen fuel performed by a communication device of a dispenser according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error (S2030) may include at least a portion of the step of performing an emergency handling process (S411) if the detected error is a safely fatal error.
[0447] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to one embodiment of the present invention, the step (S2020) of determining whether to suspend the communication process or the hydrogen fuel supply process in response to a detected error may further include a step of determining whether to replace the first fuel supply protocol of the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol if the detected error is not a safely fatal error.
[0448] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error may include a step in which the dispenser performs a hydrogen fuel supply process based on a second fuel supply protocol when a first fuel supply protocol in the communication process or the hydrogen fuel supply process is replaced by a second fuel supply protocol.
[0449] In the event of a communication error, the dispenser can select the second fuel supply protocol by applying a pre-defined fallback according to the first fuel supply protocol or a pre-defined rule, and then supply hydrogen fuel based on the second fuel supply protocol. In the event of a communication error, the mobility or dispenser may terminate the session if necessary.
[0450] In the event of a system error, the mobility or dispenser may terminate the session if necessary. At this time, the mobility or dispenser may terminate the session based on the detected error and transmit a message to the other party containing the stop action and a reason code corresponding to the reason.
[0451] In an alternative embodiment, in the event of a qualitative error, a fallback fuel supply protocol can be selected based on a restricted communication protocol or communication environment based on updated interoperability or compatibility information between the mobility and the dispenser, and hydrogen can be supplied based on the selected fuel supply protocol.
[0452] In an alternative embodiment, in the case of a qualitative error, another fuel supply protocol can be selected while maintaining the communication protocol between the mobility and the dispenser. In yet another alternative embodiment, another communication protocol can be selected while maintaining the fuel supply protocol between the mobility and the dispenser.
[0453] In an alternative embodiment, if the error is qualitative, the mobility and dispenser may reconsider to select a new communication protocol and fuel supply protocol combination. In this case, some of steps S403 to S405 may be performed again for the reconsideration, or the reconsideration may be performed within step S410.
[0454] In an alternative embodiment, if communication is still active even in an emergency, communication can be minimized and subsequent processes can be carried out. The mobility or dispenser can fall back the communication protocol and fuel supply protocol.
[0455] In an alternative implementation, if an emergency occurs, suspending fuel supply and communications may be given top priority.
[0456] In a communication method for hydrogen fuel supply performed by a communication device of a dispenser according to one embodiment of the present invention, the step of performing a subsequent process defined based on a detected error may include the step of transmitting a message to the mobility device, including whether or not the communication process or the hydrogen fuel supply process has been terminated.
[0457] In a communication method for supplying hydrogen fuel performed by a communication device of a dispenser according to one embodiment of the present invention, if a message including whether or not the communication process or the hydrogen fuel supply process is being stopped includes the stopping of the communication process or the hydrogen fuel supply process, the message may further include a reason code corresponding to an appropriate reason for the stop.
[0458] In a communication method for hydrogen fuel supply performed by a mobility and / or dispenser communication device according to one of the alternative embodiments of the present invention, the criticality of an error may be determined based on the UCDC level of available communication or fuel supply process in relation to the detected error. Furthermore, a decision may be made based on the UCDC level whether or not to discontinue fuel supply. In this case, the process of determining the severity of the error and / or whether or not to discontinue fuel supply based on the UCDC level may be applied when the error is a qualitative error. However, the scope of the present invention is not limited by such embodiments.
[0459] In the embodiments shown in Figures 4 and 18, examples are illustrated in which steps S2010, S2020, S410, and / or S411 relate to steps S403 to S409. In one of the alternative embodiments of the present invention, steps S2010 and S2020 can detect all incidents occurring in steps S401 to S409, or during the fuel supply process, determine whether they are errors, and classify the errors. In another alternative embodiment of the present invention, after passing through steps S410 and S411 as part of steps S2010, S2020, and S2030, it is possible to return to any one of steps S401 to S409 to perform the existing process and / or the next process if the subsequent process is carried out or if the error is resolved.
[0460] Specifically, stages S2010 and S2020 can detect incidents occurring in stages such as stage S401-UC1: discovery and pairing, stage S402-UC2: communication security, stage S403-UC3: communication protocol negotiation, stage S404-UC4: fuel supply protocol negotiation, stage S405-UC5: fuel supply parameter negotiation, stage S406-UC6: safety check-in, stage S407-UC7: monitoring and control, stage S408-UC8: safety check-out, and stage S409-UC9: termination or parallel hydrogen fuel supply processes, determine whether the incidents are errors, detect errors, or classify errors.
[0461] Furthermore, after an error has been classified and its handling has been carried out in stages S2030, S410, or S411, the system can return to stages S401-S409 or the parallel hydrogen fuel supply process.
[0462] Furthermore, after the error has been processed and resolved, the system can return to steps S401-S409 or the parallel hydrogen fuel supply process to carry out the process that was being performed before the error occurred or the next stage.
[0463] In one of the alternative embodiments, a criterion for determining whether an error is safely fatal may be whether it could cause damage to the facility and / or human life, or induce fire, explosion, leak, etc., as an incident that may occur before, during, or after hydrogen fuel supply.
[0464] In the event of a safety-critical error, communications and fuel supply may be interrupted and / or terminated. In alternative embodiments, even in the event of a safety-critical error, fuel supply may continue if communications are maintained, fuel supply is possible, or if fuel supply must continue (for reasons such as escaping a hazardous area or transporting patients).
[0465] In the event of a non-safety-critical error, communication or fuel supply may be suspended or continued based on the criticality / severity of the error, available communication environment, available fuel supply protocols, UCDC level, and the need for communication or fuel supply.
[0466] In the embodiments described above, the processes of continuous interoperability monitoring, resulting interoperability information updates, and / or communication / fuel supply protocol combination updates were primarily disclosed in which either mobility or dispenser performed the process. However, the detailed processes of these processes can, of course, be performed by either mobility or dispenser, or they can be performed through mutual cooperation. In alternative embodiments of the present invention, some parts of the processes of continuous interoperability monitoring, resulting interoperability information updates, and / or communication / fuel supply protocol combination updates may be primarily performed by mobility, while other parts may be primarily performed by dispenser.
[0467] Furthermore, error detection may be performed by either the mobility or the dispenser, and the entity that detected the error may transmit a message to the other party including the detection of the error, the detected error, the termination of communication and fuel supply based on the error, or a reason code corresponding to the reason for the termination.
[0468] Figure 16 is a conceptual block diagram of the internal structure of a generalized computing system that can be mounted on a hydrogen fuel mobility vehicle, dispenser, and / or refueling station as a communication device, communication control device, and / or electronic control device for hydrogen refueling according to one embodiment of the present invention.
[0469] Although not shown in the drawings in the embodiments of Figures 1 to 15, the processor and memory are electronically connected to each component, and the operation of each component can be controlled or managed by the processor.
[0470] At least a portion of the charging communication method for electric vehicle charging according to one embodiment of the present invention can be performed by the computing system 3000 shown in Figure 16.
[0471] A computing system 3000 according to one embodiment of the present invention may include at least one processor 3100 and a memory 3200 that stores instructions that the at least one processor 3100 perform at least one step. At least some steps of the method according to one embodiment of the present invention may be performed by the at least one processor 3100 loading and executing instructions from the memory 3200.
[0472] The processor 3100 may mean a central processing unit (CPU), a graphics processing unit (GPU), or a dedicated processor on which the method according to an embodiment of the present invention is performed.
[0473] The memory 3200 and the storage device 3400 may each consist of at least one of a volatile storage medium and a non-volatile storage medium. For example, the memory 3200 may consist of at least one of a read-only memory (ROM) and a random access memory (RAM).
[0474] Furthermore, the computing system 3000 may include a communication interface 3300 that performs communication over a wireless network. Furthermore, the computing system 3000 may further include a storage device 3400, an input interface 3500, an output interface 3600, and the like. Furthermore, each component included in the computing system 3000 can be connected by the bus 3700 to perform communication.
[0475] An apparatus including the processor 3100 according to one embodiment of the present invention may be, for example, a communication-enabled desktop computer, laptop computer, notebook computer, smartphone, tablet PC, mobile phone, smart watch, smart glasses, e-book reader, PMP (portable multimedia player), portable game console, navigation device, digital camera, DMB (digital multimedia broadcasting) player, digital audio recorder, digital audio player, digital video recorder, digital video player, PDA (Personal Digital Assistant), etc.
[0476] A communication device for supplying hydrogen fuel according to one embodiment of the present invention is a device mounted on a hydrogen fuel mobility and / or dispenser that performs communication between the hydrogen fuel mobility and the dispenser, and includes a processor 3100 that receives and executes at least one instruction from a memory 3200.
[0477] A communication control device for a hydrogen fuel mobility 100 according to one embodiment of the present invention may include a memory 3200 for storing at least one instruction, and a processor 3100 for executing at least one instruction. The processor 3100 can detect errors occurring during the communication process for preparing for hydrogen fuel supply between a dispenser that supplies hydrogen to the mobility and the mobility, or during the process in which the dispenser supplies hydrogen to the mobility, based on at least one instruction, can determine whether or not to stop the communication process or the hydrogen fuel supply process in response to the detected error, and can perform subsequent processes defined based on the detected error.
[0478] When the processor 3100 decides whether to abort the communication process or the hydrogen fuel supply process in response to a detected error, it can classify the detected error as either a safety-critical error or a non-safety-critical error.
[0479] When the processor 3100 decides whether to interrupt the communication process or the hydrogen fuel supply process in response to a detected error, it can classify the detected error as a communication error, a system error, or a qualitative error if the error is not safely fatal.
[0480] When the processor 3100 performs a subsequent process defined based on the detected error, it can perform an emergency handling process if the detected error is a safely fatal error.
[0481] When the processor 3100 decides whether to abort the communication process or the hydrogen refueling process in response to a detected error, it can decide whether to replace the first refueling protocol of the communication process or the hydrogen refueling process with a fallback second refueling protocol if the detected error is not a safely fatal error.
[0482] When the processor 3100 performs a subsequent process defined based on the detected error, it can transmit a message to the dispenser, including whether or not to abort the communication process or the hydrogen fueling process.
[0483] A communication device for a dispenser that supplies hydrogen fuel to a hydrogen fuel mobility vehicle according to one embodiment of the present invention includes a memory 3200 for storing at least one instruction and a processor 3100 for executing at least one instruction, wherein the processor 3100 can detect errors occurring during the communication process for preparing for hydrogen fuel supply between the dispenser and mobility or during the process in which the dispenser supplies hydrogen fuel to mobility, can determine whether or not to stop the communication process or the hydrogen fuel supply process in response to the detected error, and can perform subsequent processes defined based on the detected error.
[0484] On the other hand, while most of the embodiments described above have focused on a method in which the communication protocol and parameters of the hydrogen fuel mobility are transmitted from the hydrogen fuel mobility to the dispenser first, the present invention is not limited to specific embodiments, and it is of course possible to configure the system so that the communication protocol and parameters of the dispenser are transmitted from the dispenser to the hydrogen fuel mobility first. In this case, it is obvious that the only difference is that the sender becomes the receiver and the receiver becomes the sender in the relevant embodiment, and that the system has substantially the same characteristics.
[0485] The operation of the method according to the embodiment of the present invention can be embodied in a computer-readable program or code on a computer-readable recording medium. The computer-readable recording medium includes all types of recording devices that store information that can be read by a computer system. Furthermore, the computer-readable recording medium can be distributed across a network of computer systems, allowing computer-readable programs or code to be stored and executed in a distributed manner.
[0486] Furthermore, computer-readable recording media can include hardware devices specially configured to store and execute program instructions, such as ROM, RAM, and flash memory. Program instructions can include not only machine code generated by a compiler, but also high-level language code that can be executed by a computer using an interpreter or the like.
[0487] Some aspects of the present invention have been described in the context of apparatus, but they can also be described by corresponding methods, where blocks or apparatus correspond to method steps or features of method steps. Similarly, aspects described in the context of methods can also be described by corresponding blocks or items or features of corresponding apparatus. Some or all of the method steps may be carried out by (or utilizing) hardware devices such as, for example, a microprocessor, a programmable computer, or an electronic circuit. In some embodiments, at least one or more of the most important method steps may be carried out by such devices.
[0488] In embodiments, a programmable logic device (e.g., a field-programmable gate array) may be used to perform some or all of the functions of the methods described herein. In embodiments, a field-programmable gate array may operate in conjunction with a microprocessor to perform one of the methods described herein. Generally, it is preferable that the methods be performed by some hardware device.
[0489] While preferred embodiments of the present invention have been described above with reference to the present invention, those skilled in the art will understand that the present invention can be modified and altered in various ways without departing from the spirit and scope of the invention as described in the following claims. [Explanation of Symbols]
[0490] 100 Hydrogen Electric Vehicles 110, 210 Electronic control unit 120 Vehicle Systems 130 Vehicle Tank 150 receptacles 160 First Sensor 200 dispensers 220 Filling Station System 230 hydrogen tanks 240 Station Box 250 nozzles 260 Second Sensor 900 UCDC Level 0 910 UCDC Level 1 920 UCDC Level 2 930 UCDC Level 3 3000 Computing Systems 3100 processor 3200 memory 3300 Communication Interface 3400 storage device 3500 Input Interfaces 3600 Output Interface 3700 bus< / false> < / true> < / ok> < / true> < / ok> < / pending> < / pending>
Claims
1. A communication method for hydrogen fuel supply (fueling) carried out by hydrogen fuel mobility, A step of detecting an error that occurs during the communication process for preparing for hydrogen fuel supply between a dispenser that supplies hydrogen to the mobility, or during the process in which the dispenser supplies hydrogen to the mobility. A step of determining whether or not to stop the communication process or the hydrogen fuel supply process in response to the detected error, and A communication method for supplying hydrogen fuel, characterized by including a step of performing a subsequent process defined based on the detected error.
2. The step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to the detected error is: The communication method for supplying hydrogen fuel according to claim 1, further comprising the step of classifying the detected error into either a safety-critical error or a non-safety-critical error.
3. The step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to the detected error is: The communication method for supplying hydrogen fuel according to claim 2, further comprising the step of classifying the detected error as one of the following: a communication error, a system error, or a qualitative error, if the detected error is not a safely fatal error.
4. The step of carrying out a subsequent process defined based on the detected error is: The communication method for supplying hydrogen fuel according to claim 2, further comprising the step of performing an emergency handling process if the detected error is a safely fatal error.
5. The step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to the detected error is: The communication method for hydrogen fuel supply according to claim 2, further comprising the step of determining whether to replace the first fuel supply protocol in the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol if the detected error is not a safely fatal error.
6. The step of carrying out a subsequent process defined based on the detected error is: A communication method for supplying hydrogen fuel according to claim 1, characterized by comprising the step of transmitting a message to the dispenser including whether or not the communication process or the hydrogen fuel supply process has been discontinued.
7. A communication device for supplying hydrogen fuel to a hydrogen fuel mobility vehicle, Memory for storing at least one instruction, Includes a processor that executes at least one of the aforementioned instructions, The processor, by at least one instruction, The system detects errors that occur during the communication process between a dispenser that supplies hydrogen fuel to the mobility and the mobility, or during the process in which the dispenser supplies hydrogen fuel to the mobility. In response to the detected error, a decision is made as to whether or not to stop the communication process or the hydrogen fuel supply process. A communication device characterized by performing a subsequent process defined based on the detected error.
8. When the processor determines whether to terminate the communication process or the hydrogen fuel supply process in response to the detected error, The communication device according to claim 7, characterized in that it classifies the detected error into either a safety-critical error or a non-safety-critical error.
9. When the processor determines whether to terminate the communication process or the hydrogen fuel supply process in response to the detected error, The communication device according to claim 8, characterized in that, if the detected error is not a safely fatal error, the detected error is classified as one of the following: a communication error, a system error, or a qualitative error.
10. The communication device according to claim 8, characterized in that when the processor performs a subsequent process defined based on the detected error, it performs an emergency handling process if the detected error is a safely fatal error.
11. When the processor determines whether to terminate the communication process or the hydrogen fuel supply process in response to the detected error, The communication device according to claim 8, characterized in that, if the detected error is not a safely fatal error, it determines whether to replace the first fuel supply protocol in the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol.
12. When the processor performs a subsequent process defined based on the detected error, The communication device according to claim 7, characterized in that it transmits a message to the dispenser including whether or not the communication process or the hydrogen fuel supply process has been discontinued.
13. A communication method for hydrogen fueling performed by a communication device of a dispenser that supplies hydrogen to hydrogen fuel mobility, A communication process for preparing hydrogen fuel supply between the dispenser and the mobility, or a step of detecting an error that occurs during the process of the dispenser supplying hydrogen fuel to the mobility. A step of determining whether or not to stop the communication process or the hydrogen fuel supply process in response to the detected error, and A communication method for supplying hydrogen fuel, characterized by including a step of performing a subsequent process defined based on the detected error.
14. The step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to the detected error is: The communication method for supplying hydrogen fuel according to claim 13, further comprising the step of classifying the detected error into either a safety-critical error or a non-safety-critical error.
15. The step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to the detected error is: The communication method for supplying hydrogen fuel according to claim 14, further comprising the step of classifying the detected error as a communication error, a system error, or a qualitative error, if the detected error is not a safely fatal error.
16. The step of carrying out a subsequent process defined based on the detected error is: A communication method for hydrogen fuel supply according to claim 14, further comprising the step of performing an emergency handling process if the detected error is a safely fatal error.
17. The step of deciding whether to suspend the communication process or the hydrogen fuel supply process in response to the detected error is: A communication method for hydrogen fuel supply according to claim 14, further comprising the step of determining whether to replace the first fuel supply protocol in the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol if the detected error is not a safely fatal error.
18. The step of carrying out a subsequent process defined based on the detected error is: A communication method for hydrogen fuel supply according to claim 17, characterized in that, when the first fuel supply protocol of the communication process or the hydrogen fuel supply process is replaced by the second fuel supply protocol, the process of supplying hydrogen fuel is carried out based on the second fuel supply protocol.
19. The step of carrying out a subsequent process defined based on the detected error is: A communication method for supplying hydrogen fuel according to claim 13, comprising the step of transmitting a message to the mobility device including whether or not the communication process or the hydrogen fuel supply process has been discontinued.
20. The communication method for supplying hydrogen fuel according to claim 19, wherein if a message including whether or not the communication process or the hydrogen fuel supply process is terminated includes the termination of the communication process or the hydrogen fuel supply process, the message further includes a code corresponding to the reason for the termination.