Data update system, program and method

The data update system ensures secure and efficient vehicle software updates by using a multi-stage authentication process and integrated charging-communication cables, addressing the security gaps in existing methods.

JP7764948B2Active Publication Date: 2025-11-06NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024510799
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-29
Publication Date
2025-11-06
Estimated Expiration
2042-03-29

AI Technical Summary

Technical Problem

Existing methods for updating vehicle software do not adequately consider the importance of the data being downloaded, leading to insufficient security during the update process.

Method used

A data update system involving a user terminal, center server, and charging station, which performs multi-stage authentication using authentication codes and location information to ensure secure data transmission and update, with integrated communication and charging cables to enhance security.

Benefits of technology

The system maintains high security levels during data updates, prevents unauthorized software installation, and ensures uninterrupted updates by integrating charging and data processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007764948000001
    Figure 0007764948000001
  • Figure 0007764948000002
    Figure 0007764948000002
  • Figure 0007764948000003
    Figure 0007764948000003
Patent Text Reader

Abstract

A data updating system according to one embodiment of the present invention carries out, in a user terminal, an authentication request process (S5) for transmitting, to a central server, authentication information including at least an authentication code displayed on a charging stand, user information registered previously, and location information of the charging stand and the user terminal. Said system also carries out, in the central server, an authentication process (S6) for authenticating the validity of the authentication information, and if the authentication process is successful, a distribution process (S10) for causing the charging stand to download software for updating, and carries out, in the charging stand once a charging cable has been connected to a vehicle, an authentication code provision process (S2) for displaying the authentication code, and a data updating process (S11) for updating software in the vehicle to be updated by sending the downloaded software via a communication line to the vehicle to be updated.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a data updating system, its program, and The present invention relates to a data updating system, a program and a method for updating data installed in a vehicle. [Background technology]

[0002] In recent years, the amount of software installed in automobiles (hereinafter referred to as vehicles) has become enormous, and the software responsible for controlling the vehicles has also become more complex. As a result, it has become necessary to update the software installed in the vehicles to address vehicle defects or improve functionality. However, since the software that controls the vehicle is related to the safety of the vehicle, it is necessary to ensure high security when updating the software. Therefore, an example of technology related to updating programs installed in vehicles is disclosed in Patent Document 1.

[0003] In Patent Document 1, for example, Figure 193 and paragraph 0649 disclose that security is ensured by dividing the program storage area depending on the communication method, whether the program is transmitted via wired or wireless. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Publication No. 2020-27626 Summary of the Invention [Problem to be solved by the invention]

[0005] However, the method described in Patent Document 1 does not allow for the storage of data according to the importance of the software to be downloaded to the vehicle or the vehicle body data downloaded from the vehicle, and therefore has the problem of not providing sufficient security.

[0006] In view of the above-mentioned problems, an object of the present invention is to provide a data update system, a program and a method thereof that perform data updates while maintaining a high level of security. [Means for solving the problem]

[0007] A data update system according to one embodiment includes a user terminal operated by a user, a center server that performs authentication processing and data distribution, and a charging station that charges the vehicle, the charging station including a charging cable connected to a vehicle and a communication line that performs data communication with the vehicle. The user terminal performs authentication request processing to transmit authentication information including at least an authentication code provided by the charging station to the center server, and the center server performs authentication processing to confirm the validity of the authentication information and, in response to the authentication processing being successful, transmits the data to the charging station. data The charging station performs a distribution process to download the data from the charging cable to the vehicle, and the charging station performs an authentication code provision process to provide the authentication code in response to the charging cable being connected to the vehicle, and a data update process to update the data of the vehicle to be updated by providing the downloaded data to the vehicle to be updated via the communication line.

[0008] A data update program according to one embodiment is a data update program executed by a calculation unit in each device in a data update system having a center server, a charging station, and a user terminal, wherein a first program executed on the user terminal performs an authentication request process to send authentication information including at least an authentication code displayed on the charging station to the center server, a second program executed on the center server performs an authentication process to confirm the validity of the authentication information and a distribution process to cause the charging station to download data to be updated in response to the authentication process being passed, the charging station includes a charging cable connected to a vehicle and a communication line for data communication with the vehicle, and a third program executed on the charging station performs an authentication code provision process to provide the authentication code in response to the charging cable being connected to the vehicle, and a data update process to provide the downloaded data to the vehicle to be updated via the communication line.

[0009] A data update method according to one embodiment is a data update method in a data update system having a center server, a charging station, and a user terminal, in which the user terminal performs an authentication request process to send authentication information including at least an authentication code displayed on the charging station to the center server, and the center server performs an authentication process to confirm the validity of the authentication information and a distribution process to cause the charging station to download data to be updated in response to the authentication process being passed, the charging station having a charging cable connected to a vehicle and a communication line for communicating data with the vehicle, and the charging station performs an authentication code provision process to provide the authentication code in response to the charging cable being connected to the vehicle, and a data update process to provide the downloaded data to the vehicle to be updated via the communication line. [Effects of the Invention]

[0010] According to the data update system, program and method thereof of the present invention, data can be updated while maintaining a high level of security. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a block diagram of a data updating system according to a first embodiment. [Figure 2] FIG. 2 is a hardware configuration diagram of a center server according to the first embodiment. [Figure 3] FIG. 2 is a hardware configuration diagram of the charging station according to the first embodiment. [Figure 4] FIG. 2 is a hardware configuration diagram of a user terminal according to the first embodiment. [Figure 5] FIG. 2 is a hardware configuration diagram of a vehicle according to the first embodiment. [Figure 6] FIG. 10 is a sequence diagram illustrating a first example of a data update procedure according to the first embodiment. [Figure 7] FIG. 10 is a sequence diagram illustrating a second example of a data update procedure according to the first embodiment. [Figure 8] FIG. 10 is a sequence diagram illustrating a third example of a data update procedure according to the first embodiment. [Figure 9] FIG. 10 is a sequence diagram illustrating a fourth example of a data update procedure according to the first embodiment. [Figure 10] FIG. 10 is a sequence diagram illustrating an example of a procedure for verifying validity in updating a parameter according to the first embodiment. [Figure 11] FIG. 10 is a sequence diagram illustrating a data update procedure according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] For clarity of explanation, the following description and drawings have been omitted and simplified as appropriate. Furthermore, each element shown in the drawings as a functional block that performs various processes may be configured in terms of hardware by a CPU (Central Processing Unit), memory, and other circuits. In terms of software, they are realized by programs loaded into memory, etc. Therefore, it will be understood by those skilled in the art that these functional blocks can be realized in various forms, such as hardware only, software only, or a combination thereof, and are not limited to any one of these. Note that in each drawing, the same elements are given the same reference numerals, and redundant explanations are omitted as necessary.

[0013] The above-described program can be stored in various types of non-transitory computer-readable media and supplied to a computer. Non-transitory computer-readable media include various types of tangible recording media. Examples of non-transitory computer-readable media include magnetic recording media (e.g., flexible disks, magnetic tapes, hard disk drives), magneto-optical recording media (e.g., magneto-optical disks), CD-ROMs (Read Only Memory), CD-Rs, CD-R / Ws, semiconductor memories (e.g., mask ROMs, PROMs (Programmable ROMs), EPROMs (Erasable PROMs), flash ROMs, and RAMs (Random Access Memory). )). The program may be provided to the computer by various types of temporary computer-readable media. Examples of temporary computer-readable media include electrical signals, optical signals, and electromagnetic waves. The temporary computer-readable media can provide the program to the computer via a wired communication path such as an electrical wire or optical fiber, or via a wireless communication path.

[0014] Embodiment 1 A block diagram of a data updating system 1 according to the first embodiment is shown in FIG. 1. As shown in FIG. 1, the data updating system 1 according to the first embodiment includes a center server 100, a charging station 200, a user terminal 300, and a vehicle 400. Here, the data updating system 1 updates data stored in the vehicle 400, but this data is not limited to software and parameters that control the vehicle, and may include data other than the software and parameters. In the following explanation, an example will be described in which software and parameters are used as the data to be updated. The vehicle 400 is an automobile equipped with software to be updated by the data updating system 1, and is, for example, an electric automobile that requires charging or a plug-in hybrid automobile.

[0015] 1 also shows a USB (Universal Serial Bus: registered trademark) interface 50 and an OTA (Over The Air) interface 60 as interfaces for transferring data to the vehicle 400. Here, the OTA interface 60 is an interface for transferring data using wireless communication, and is a general term for a communication path that combines one or more of various communication standards such as a mobile phone communication network and Wi-Fi. The vehicle 400 is configured to be able to import or read data via these various communication paths.

[0016] The center server 100 includes an authentication processing unit 11, a distribution processing unit 12, a database 13, a parameter storage unit 14, and a software storage unit 15. The authentication processing unit 11 verifies the validity of authentication information sent from the user terminal 300, and permits the distribution processing unit 12 to distribute data (e.g., software and parameters) to be updated if the authentication information is verified (passed). The authentication processing unit 11 performs authentication using information included in the authentication information. However, the authentication process for identifying a user can be performed using various methods, such as authentication using an ID and password as information to identify the user, or biometric authentication using biometric information preset by the user. If the authentication process is successful, the distribution processing unit 12 downloads the software to be updated to the charging station 200. Furthermore, if the authentication process performed by the authentication processing unit 11 is successful, the distribution processing unit 12 also downloads vehicle control parameters to the charging station 200 or reads parameters from the vehicle 400.

[0017] The database 13 accumulates vehicle body data such as equipment failure diagnosis data, security logs, and driving data stored in the vehicle 400. The vehicle body data is analyzed for validity and content by developers and mechanics at the vehicle manufacturer. The parameter storage unit 14 stores parameters stored in the vehicle 400 and new parameters to be given to the vehicle 400. The parameters are used for drive control and driving control of the vehicle 400, and require a high level of security. The parameters are also updated as instructed by developers and mechanics at the vehicle manufacturer. The software storage unit 15 stores software to be updated. The software stored in the software storage unit 15 is used, for example, to perform drive control and driving control of the vehicle 400, and requires a high level of security.

[0018] The charging stand 200 includes a display unit 21 , an authentication code providing processing unit 22 , an update processing unit 23 , and a communication line interface 24 .

[0019] The display unit 21 displays various information related to charging and data updating to the user. If the display unit 21 is equipped with a touch panel or the like, it also serves as an input unit that accepts instructions from the user. In other words, the display unit 21 is one of the user interfaces that allows the user to use the data updating system 1.

[0020] The authentication code providing processing unit 22 provides an authentication code in response to the connection of a charging cable to the vehicle 400. In the following description, the authentication code is provided by displaying the authentication code on the display unit 21, but the authentication code may also be transmitted via short-range wireless communication, wireless LAN, a public communication network, or the like. The authentication code may be, for example, a one-time password that can be used in the data update system 1. The authentication code may be in the form of multiple numbers, and various formats such as a QR code (registered trademark) may be adopted.

[0021] The update processing unit 23 performs a data update process that updates data (e.g., software and parameters) of the vehicle to be updated by providing the downloaded data to the vehicle to be updated via a communication line. The communication line interface 24 is provided in the charging stand 200 and is an interface circuit for driving a communication line that serves as a communication path between the charging stand 200 and the vehicle 400 to enable communication between the charging stand 200 and the vehicle 400. Although not shown, the charging stand 200 also has a charging cable for charging the vehicle 400. This charging cable may be provided separately from the communication line connected to the vehicle 400 via the communication line interface 24, but an example in which the communication line is provided integrally with the charging cable to reduce user operation will be described below. By utilizing physical communication lines and charging cables in this way, it is possible to prevent access to the vehicle 400 via unauthorized communication lines, thereby increasing the security level.

[0022] The user terminal 300 is a terminal operated by a user, and may be, for example, a mobile information terminal such as a smartphone capable of communicating with the outside world via a mobile phone communication network or Wi-Fi, or a car navigation terminal. The user terminal 300 performs an authentication request process to transmit authentication information to the center server 100, including at least an authentication code provided by the charging station 200. This authentication information may further include pre-registered user information, location information of the charging station and the user terminal, and other information. The user terminal 300 is equipped with a device for acquiring the authentication code generated by the vehicle 400, such as a touch panel, an imaging element such as a camera, or a short-range wireless communication interface. The user terminal 300 also has a display unit that can display information obtained from the center server 100 and the charging station 200, and an interface screen generated by application software running on the user terminal 300.

[0023] Vehicle 400 is a device whose data is to be updated. Vehicle 400 has a first information storage unit (e.g., authentication-free data storage area 41), a second information storage unit (e.g., vehicle body data storage area 42), and a third information storage unit (e.g., authentication-required data storage area 43), each of which has a restricted accessible communication path.

[0024] The authentication-free data storage area 41 is an information storage area that is restricted to access other than via a wired connection (e.g., USB interface 50) using a cable of a standard not managed by the vehicle manufacturer, and via a wireless connection (e.g., OTA interface 60). The authentication-free data storage area 41 stores data that does not require authentication, such as traffic information, weather information, map data, and music data. The data stored in this authentication-free data storage area 41 has little impact on the control of the vehicle 400, and is data that does not pose a problem even if it has a low security level. The USB interface 50 and the OTA interface 60 are set as communication paths that allow access to the authentication-free data storage area 41.

[0025] The vehicle body data storage area 42 is an information storage area to which access is restricted other than via the OTA interface 60 and a communication line provided in the charging stand 200. In other words, access to the vehicle body data storage area 42 is restricted other than via a wired connection via a communication line provided in the charging stand 200 and via a connection form other than a wireless connection. The vehicle body data storage area 42 stores vehicle body data generated by the operation of the vehicle 400, such as equipment failure diagnosis data, security logs, and driving data. This vehicle body data is obtained by operating the vehicle 400 and does not affect control, so a low security level is acceptable. However, because this data contains the driver's privacy, a higher security level is required than for data that does not require authentication. Therefore, the OTA interface 60 and a communication line provided in the charging stand 200 are set as the communication path through which access to the vehicle body data storage area 42 is possible.

[0026] The authentication-required data storage area 43 is an information storage area to which access is restricted other than via a communication line provided in the charging stand 200. In other words, access to the authentication-required data storage area 43 is restricted from any connection other than a wired connection via a communication line provided in the charging stand 200. The authentication-required data storage area 43 stores data or programs used for drive control and operation control of the vehicle 400, such as parameters and software. This information is necessary for the safe operation of the vehicle 400 and has a significant impact on control, so a high level of security is required. Therefore, only the communication lines provided in the charging stand 200 are set as communication paths that allow access to the authentication-required data storage area 43.

[0027] Next, an example of detailed hardware configurations of the center server 100, the charging station 200, the user terminal 300, and the vehicle 400 will be described.

[0028] First, FIG. 2 shows a hardware configuration diagram of the center server 100 according to the first embodiment. The center server 100 includes, for example, hardware included in a computer. Specifically, the center server 100 includes a calculation unit 101, a storage unit 102, and a communication interface 103, which are connected via a bus so that they can communicate with each other. The calculation unit 101 executes a second program included in the data update program. The calculation unit 101 that executes this second program performs authentication processing performed by an authentication processing unit 11 and distribution processing performed by a distribution processing unit 12. The storage unit 102 includes a memory, an SSD (Solid State Disk), an HDD (Hard Disk Drive), etc. The computing unit 101 is implemented by a storage device and serves as a database 13, a parameter storage unit 14, and a software storage unit 15. The database 13, the parameter storage unit 14, and the software storage unit 15 may be configured in a housing different from that of the computing unit 101. The communication interface 103 is an interface circuit for communicating with the charging stand 200 and the user terminal 300 via wired or wireless communication.

[0029] Next, FIG. 3 shows a hardware configuration diagram of the charging stand 200 according to the first embodiment. The charging stand 200 can be realized as a computer having a charging function. In the example shown in FIG. 3, the charging stand 200 includes a calculation unit 201, a storage unit 202, a display unit 21, a communication interface 203, a charging interface 205, and a communication line interface 24, which are connected via a bus so as to be able to communicate with each other. The calculation unit 201 executes a third program included in a data update program. The calculation unit 201, which executes this third program, performs an authentication code providing process performed by an authentication code providing processing unit 22 and a data updating process performed by an update processing unit 23. The storage unit 202 is a storage device that stores downloaded software and parameters. The display unit 21 is the display unit 21 described in FIG. 1 and may have not only a display function but also an input function using a touch panel or the like. The communication interface 203 is an interface circuit that communicates with the center server 100 and the user terminal 300, and the communication may be performed wired or wirelessly. The charging interface 205 is an interface circuit to which a charging cable is connected, and passes a charging current to the vehicle 400. The communication line interface 24 is connected to a communication line and communicates with the vehicle 400 via the communication line.

[0030] Next, FIG. 4 shows a hardware configuration diagram of the user terminal 300 according to the first embodiment. The user terminal 300 can be realized as a computer equipped with a photographing function. In the example shown in FIG. 4, the user terminal 300 includes a calculation unit 301, a storage unit 302, a communication interface 303, a display unit 304, and a photographing unit 305, which are connected via a bus so as to be able to communicate with each other. The calculation unit 301 executes a first program included in a data update program. The calculation unit 301 executing this first program performs an authentication request process to transmit authentication information to the center server 100, the authentication information including at least an authentication code displayed on the charging stand 200, pre-registered user information, and location information of the charging stand 200 and the user terminal. The storage unit 302 is a storage device that stores the captured authentication code, location information, etc. The communication interface 303 is an interface circuit that communicates with the center server 100 and the charging stand 200, and the communication may be wired or wireless. For example, the communication interface 303 may have a short-range wireless communication function, and the user terminal 300 and the charging stand 200 may communicate using this short-range wireless communication function to obtain the authentication code. The display unit 304 may have not only a display function but also an input function using a touch panel or the like. A user interface screen generated by a first program executed by the calculation unit 301 is displayed on the display unit 304. The photographing unit 305 is, for example, a camera, and can be configured to receive the authentication code by reading a QR code displayed on the display unit 21 of the charging stand 200.

[0031] Next, FIG. 5 shows a hardware configuration diagram of vehicle 400 according to the first embodiment. FIG. 5 illustrates only components of vehicle 400 that are related to paths for externally accessing authentication-free data storage area 41, vehicle body data storage area 42, and authentication-required data storage area 43. Vehicle 400 has authentication-free data storage area 41, vehicle body data storage area 42, and authentication-required data storage area 43, each of which has a restricted access path. Vehicle 400 also has a USB connection port 406, a wireless communication interface 407, and a charging cable connection port 408 as input / output interfaces for the access paths. In vehicle 400, charging cable connection port 408 also serves as a connection port for a communication line that serves as a communication path with charging stand 200. Vehicle 400 also has an access guard unit 401 between USB connection port 406, wireless communication interface 407, charging cable connection port 408, and authentication-free data storage area 41, vehicle body data storage area 42, and authentication-required data storage area 43.

[0032] The access guard unit 401 recognizes the connection type with an external device or medium and controls the access range depending on the connection type. The access guard unit 401 also recognizes at least a wired connection using a communication line provided in the charging stand 200 and a wireless connection as the connection type. More specifically, the access guard unit 401 recognizes the standard of the connected cable and the difference between the wired and wireless connection types, and controls the access range depending on the cable standard and the difference between the connection type. The access control performed by the access guard unit 401 may control either writing or reading to each information storage area, or both writing and reading. More specifically, the access guard unit 401 includes a connection type recognition unit 402 and access control units 403 to 405. The connection type recognition unit 402 recognizes which of the USB connection port 406, the wireless communication interface 407, and the charging cable connection port 408 is enabled, and grants permission to pass to the access control unit corresponding to the enabled port. The access control unit 403 switches between enabling and disabling a path for accessing the authentication-required data storage area 41 via the USB connection port 406 and the wireless communication interface 407. The access control unit 404 switches between enabling and disabling a path for accessing the vehicle body data storage area 42 via the wireless communication interface 407 and the charging cable connection port 408. The access control unit 405 switches between enabling and disabling a path for accessing the authentication-required data storage area 43 via the charging cable connection port 408. In other words, in the vehicle 400, the access guard unit 401 restricts the information storage area that can be accessed for each communication interface.

[0033] Next, the operation of the data update system 1 according to the first embodiment will be described. In the data update system 1 according to the first embodiment, four operation examples are possible depending on whether or not data is updated and whether or not parameters are updated in data updates using the charging station 200. The four operation examples will be described below as the first to fourth examples. In addition, the sequence diagrams shown below will be described assuming that a user uses the user terminal 300 to pre-register user information such as the user's name, the telephone number of the user terminal 300, the license plate number of the vehicle to be used, the chassis number, and identification information (e.g., user ID) in the database 13 of the center server 100. In the following description, an example will be described in which the data to be updated is at least one of software and parameters, but the data to be updated is not limited to software and parameters.

[0034] FIG. 6 is a sequence diagram illustrating a first example of a data update procedure according to the first embodiment. This first example is an example of operation when software is updated while charging. As shown in FIG. 6, in the first example, the operation of the data update system 1 starts when the user connects the charging cable of the charging stand 200 to the vehicle 400 (step S1). When the charging stand 200 recognizes that the charging cable has been connected to the vehicle 400, the charging stand 200 displays an authentication code on the display unit 21 (step S2). Then, the user reads the authentication code displayed on the display unit 21 using the user terminal 300 (step S3). At the same time as the authentication code is read, the user terminal 300 also reads current location information using a GPS function or the like (step S4). In the data update system 1, because the user is within a distance where the user can operate the charging cable of the charging stand 200, the GPS information of the user terminal 300 can be regarded as location information of the user terminal 300 and the charging stand 200. Next, the user terminal 300 generates authentication information including at least the authentication code read in step S3, the location information of the charging station 200 and the user terminal 300 read in step S4, and the pre-registered user information, and transmits the generated authentication information to the center server 100 (step S5).

[0035] Next, the center server 100 performs an authentication process to verify the validity of the received authentication information by referring to the user information stored in the database 13 (step S6). If the authentication process is successful, the distribution processing unit 12 calculates the time required to complete charging and data update as a predicted time (step S7). The center server 100 notifies the charging stand 200 of the time calculated in step S7.

[0036] Next, the charging stand 200 displays on the display unit 21 the estimated time calculated as the time required to complete the received charging and data update (step S8). The user checks the estimated time displayed on the display unit 21 and instructs the charging stand 200 to charge and update the data (step S9). The instruction in step S9 may be given using the user terminal 300 or via the display unit 21 of the charging stand 200.

[0037] Then, in response to the instruction in step S9, the charging stand 200 downloads the software to be updated from the center server 100 (step S10). Thereafter, the charging stand performs charging and data update in parallel (step S11). In step S11, the software to be updated that the charging stand 200 downloaded from the center server 100 in step S10 is provided to the vehicle 400. By performing charging and data update simultaneously in this way, it is possible to prevent the data update from being stopped midway due to insufficient power supply capacity during the data update. Thereafter, in response to the completion of both charging and data update, the charging stand 200 notifies the user that both charging and data update processing have been completed (step S12). The notification in step S12 may be sent to the user terminal 300, or may be displayed on the display unit 21.

[0038] Thereafter, in response to the user removing the charging cable from the vehicle 400 (step S13), a message requesting the user to enter payment information is displayed on the display unit 21 of the charging stand 200, and in response to the payment information being entered on the display unit 21 (step S14), the center server 100 executes payment processing (step S15). Note that the timing of the payment information entry procedure can be changed as appropriate according to the system specifications, such as entering the payment information in step S14 before issuing the charging and software update instructions in step S9.

[0039] Next, a second example of the operation of the data update system 1 will be described. The second example is an example of operation in which a software update request is notified to the user, but the software update is delayed due to time constraints of the user. Fig. 7 shows a sequence diagram illustrating a second example of the data update procedure according to the first embodiment.

[0040] 7, in the second example, steps S9 to S12 in the first example are replaced with steps S21 to S23. In step S21, the user instructs charging only without selecting data update. As a result, the charging stand 200 performs only charging (step S22) and, upon completion of charging, notifies the user that charging has been completed (step S23).

[0041] Next, a third example of the operation of the data update system 1 will be described. The third example is an example of operation when there is no software to be updated and only charging is performed. Fig. 8 shows a sequence diagram for explaining the third example of the data update procedure according to the first embodiment.

[0042] 8, in the third operation example, steps S7 and S8 in the second operation example are replaced with steps S31 and S32. In the third example, since there is no data update, the predicted time is calculated based only on charging (step S31). Also, in the third example, the predicted time displayed on the display unit 21 is only the predicted time required to complete charging (step S32).

[0043] Next, a fourth example of the operation of the data update system 1 will be described. The fourth example is an example of operation in which both parameters and software are updated along with charging. FIG. 9 is a sequence diagram illustrating a fourth example of the data update procedure according to the first embodiment. As shown in FIG. 9, the fourth example is obtained by replacing steps S7 to S12 of the first example with steps S41 to S45. Note that parameter updates may be performed remotely by a mechanic via the center server 100.

[0044] In step S41, the center server 100 calculates the predicted time required for charging, data update, and parameter update. Then, the center server 100 causes the display unit 21 of the charging stand 200 to display the predicted time calculated in step S41 (step S42). Next, the user instructs the charging stand 200 to perform charging, parameter update, and data update (step S43). In response to this instruction from the user, the charging stand 200 performs charging and updates the parameters and software (step S44). Then, when all of the processing in step S44 is complete, the charging stand 200 notifies the user that the processing is complete (step S45).

[0045] Here, in the parameter and data update in step S44, the validity of the updated state can be verified. Fig. 10 shows a sequence diagram for explaining an example of a procedure for validating the update of parameters according to the first embodiment.

[0046] The example shown in Fig. 10 is the processing performed in step S44. As shown in Fig. 10, in step S44, the charging stand 200 first downloads software to be updated from the center server 100 (step S50). Then, while charging the vehicle 400, the charging stand 200 provides the downloaded software to the vehicle 400 to perform a data update (step S51). Then, in response to completion of this update (step S52), the charging stand 200 reads vehicle body data from the vehicle 400 and transmits the current vehicle body data to the center server 100 (step S53). A mechanic or the like determines parameter setting values ​​while referring to the vehicle body data downloaded from the vehicle 400 (step S54). Thereafter, the parameters to be updated are downloaded from the center server 100 to the charging stand 200. Thereafter, the charging stand 200 transmits the downloaded parameters to the vehicle 400, and the vehicle 400 updates the parameters (step S55). Thereafter, the vehicle 400 transmits the vehicle body data including at least the equipment failure diagnosis data to the center server 100 (step S56).

[0047] Thereafter, in the center server 100, a program executed by the calculation unit 101 performs a validity diagnosis process to verify the validity of the parameter settings (step S57). Here, one example of a means for verifying the validity is for a diagnostician to check the vehicle state (vehicle drive motor noise) after the parameters have been changed. If there is no problem with the validity of the parameter settings, the center server 100 notifies the charging stand 200 that the verification of the validity of the parameter settings has been completed (step S58), and the charging stand 200 notifies the user of the completion of the process in step S45. By verifying the validity of the parameter settings in this way, the validity of the data update can be confirmed.

[0048] As explained above, the data update system 1 according to the first embodiment can perform multi-stage authentication using the authentication code displayed on the charging station 200 and the user information and location information generated within the user terminal 300, thereby preventing the installation of illegitimate software with a low security level on the vehicle 400. For example, it is possible to prevent vehicle body data from being updated when the center server 100 is accessed from a user terminal of an unauthorized user. It is also possible to prevent vehicle body data from being updated when the center server 100 is accessed from a location other than the charging station. In other words, by using the data update system 1, it is possible to improve the security level of the software installed on the vehicle 400.

[0049] Furthermore, in the data update system 1, by updating the software while charging, it is possible to prevent the data update from being stopped due to insufficient charging.

[0050] Furthermore, in vehicle 400, the information storage area that can be accessed is limited depending on the connection route, so the security level of the software stored in authentication-required data storage area 43 can be increased.

[0051] Furthermore, by integrating the communication line and charging cable in the data update system 1, the user only needs to handle one cable, which increases convenience. Furthermore, the data update system 1 displays the time required for the software update and allows the user to choose whether or not to perform the software update, which prevents the data update from being performed at a time when the vehicle is not being used and is insufficient for the data update, thereby preventing the user from feeling inconvenienced.

[0052] Embodiment 2 In the second embodiment, an example will be described in which data to be updated (for example, software) is downloaded in advance to the charging station 200. Fig. 11 shows a sequence diagram illustrating a data update procedure according to the second embodiment.

[0053] As shown in FIG. 11, in the second embodiment, steps S61 to S63 are added before step S1 in the first example shown in FIG. 6. Furthermore, in the second embodiment, the download process of step S10 in the first example shown in FIG. 6 is not performed. The center server 100 notifies the user terminal 300 used by the user that a data update is available (step S61). Then, the user makes a reservation for a data update with the charging stand 200 based on the content notified to the user terminal 300 (step S62). Then, the charging stand 200 downloads the software to be updated from the center server 100 based on the reservation made in step S62 (step S63).

[0054] In this way, by downloading the software to be updated to the charging stand 200 in advance, the time required for data update can be reduced. In the second embodiment, it is preferable that the charging stand 200 for which the data update is to be reserved can be identified in advance. In particular, if there is a charging stand installed at home, it is easy to identify the charging stand 200 for which the software is to be downloaded in advance in this way, and the example of the second embodiment is particularly useful in a data update system 1 that has a charging stand 200 installed at home.

[0055] The present invention is not limited to the above-described embodiment, and can be modified as appropriate within the scope of the invention. [Explanation of symbols]

[0056] 1. Data update system 100 central server 11 Authentication processing section 12 Distribution processing section 13 Database 14 Parameter storage section 15 Software storage section 101 Arithmetic section 102 Storage section 103 Communication Interface 200 charging stations 21 Display section 22 Authentication code provision processing unit 23 Update processing section 24 Communication Line Interface 201 Arithmetic section 202 Storage section 203 Communication Interface 205 Charging Interface 300 User terminal 301 Arithmetic section 302 Storage section 303 Communication Interface 304 Display section 305 Filming Department 400 vehicles 41 Authentication-free data storage area 42 Vehicle body data storage area 43 Authentication required data storage area 401 Access Guard Department 402 Connection type recognition unit 403 Access control section 404 Access Control 405 Access control section 406 USB port 407 Wireless Communication Interface 408 Charging cable port 50 USB interface 60 OTA interface

Claims

1. A user terminal operated by a user; a center server that performs authentication processing and data distribution; a charging station that charges the vehicle, the charging station including a charging cable connected to the vehicle and a communication line that performs data communication with the vehicle; and The user terminal performing an authentication request process to transmit authentication information including at least an authentication code provided by the charging station to the center server; The center server an authentication process for verifying the authenticity of the authentication information; performing a distribution process of downloading the data to be updated to the charging station in response to passing the authentication process; The charging station is an authentication code providing process for providing the authentication code in response to the charging cable being connected to the vehicle; a data update process for updating the data of the vehicle to be updated by providing the downloaded data to the vehicle to be updated via the communication line; A data updating system in which the authentication code is a one-time password updated by the center server.

2. A user terminal operated by a user; a center server that performs authentication processing and data distribution; a charging station that charges the vehicle, the charging station including a charging cable connected to the vehicle and a communication line that performs data communication with the vehicle; and The user terminal performing an authentication request process to transmit authentication information including at least an authentication code provided by the charging station to the center server; The center server an authentication process for verifying the authenticity of the authentication information; performing a distribution process of downloading the data to be updated to the charging station in response to passing the authentication process; The charging station is an authentication code providing process for providing the authentication code in response to the charging cable being connected to the vehicle; a data update process for updating the data of the vehicle to be updated by providing the downloaded data to the vehicle to be updated via the communication line; The charging station is When the user terminal is notified that the data needs to be updated, the data is downloaded from the center server in advance; A data update system that provides the downloaded data to the vehicle when the communication line is connected to the vehicle to be updated and the authentication process is successful.

3. The data updating system according to claim 1 or 2, wherein the charging cable and the communication line are integrated.

4. 3. The data update system according to claim 1, wherein the center server calculates, in response to the authentication process being successful, a predicted time required for the data update and a predicted time required for the charging process in which the charging station charges the vehicle, and displays the predicted time on a display unit of the charging station or the user terminal.

5. 3. The data update system according to claim 1, wherein the charging station provides the data to the vehicle when the user selects to execute the data update process from a selection screen displayed on the user terminal or a display unit provided at the charging station.

6. The data update system according to claim 1, wherein the center server acquires vehicle body data generated by the operation of the vehicle after the data update and performs a normality diagnosis process to verify the validity of the state after the data update.

7. The vehicle is 3. The data updating system according to claim 1, further comprising an access guard unit that recognizes the connection type with an external device or medium and controls the access range depending on the difference in the connection type.

8. A data update program executed by a calculation unit in each device in a data update system having a center server, a charging station, and a user terminal, comprising: a first program executed on the user terminal, performing an authentication request process of transmitting authentication information including at least an authentication code displayed at the charging station to the center server; The second program executed by the center server includes: an authentication process for verifying the authenticity of the authentication information; a distribution process for downloading the data to be updated to the charging station in response to the authentication process being successful; The charging station is a charging cable connected to a vehicle and a communication line for performing data communication with the vehicle; a third program executed at the charging station, an authentication code providing process for providing the authentication code in response to the charging cable being connected to the vehicle; a data update process for providing the downloaded data to the vehicle to be updated via the communication line; A data update program in which the authentication code is a one-time password updated by the center server.

9. In a data update system having a center server, a charging station, and a user terminal, a data update program executed by a calculation unit in each device, comprising: a first program executed on the user terminal, performing an authentication request process of transmitting authentication information including at least an authentication code displayed at the charging station to the center server; The second program executed by the center server includes: an authentication process for verifying the authenticity of the authentication information; a distribution process for downloading the data to be updated to the charging station in response to the authentication process being successful; The charging station is a charging cable connected to a vehicle and a communication line for performing data communication with the vehicle; a third program executed at the charging station, an authentication code providing process for providing the authentication code in response to the charging cable being connected to the vehicle; a data update process for providing the downloaded data to the vehicle to be updated via the communication line; The charging station is When the user terminal is notified that the data needs to be updated, the data is downloaded from the center server in advance; a data update program that provides the downloaded data to the vehicle when the communication line is connected to the vehicle to be updated and the authentication process is successful;

10. A data update method in a data update system having a center server, a charging station, and a user terminal, comprising: In the user terminal, performing an authentication request process to transmit authentication information including at least an authentication code displayed at the charging station to the center server; In the center server, an authentication process for verifying the authenticity of the authentication information; a distribution process for downloading the data to be updated to the charging station in response to the authentication process being successful; The charging station is a charging cable connected to a vehicle and a communication line for performing data communication with the vehicle; In the charging station, an authentication code providing process for providing the authentication code in response to the charging cable being connected to the vehicle; a data update process for providing the downloaded data to the vehicle to be updated via the communication line; A data updating method in which the authentication code is a one-time password updated by the center server.

Citation Information

Patent Citations

  • Data communication method and data communication system between a service provider and a vehicle.

    JP2012526409A

  • Electric mobile body charging system; electric mobile body charging device, portable communication terminal, and server device included in the same; and electric mobile body charging method

    JP2013034322A

  • Vehicle information communication system

    JP2020027626A

  • Charging system, charge setting device and charging method

    JP2020167777A

  • JPP6526300B