Management Server
The management server manages vehicle and ECU identification to prevent incorrect user authentication by deleting and reissuing certificate data, ensuring accurate billing and user convenience in vehicle services.
Patent Information
- Application Number
- JP2022197270
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2042-12-09
AI Technical Summary
An ECU installed in a first vehicle can be transferred to a second vehicle without deleting its certificate data, leading to incorrect user authentication.
A management server manages certificate data, including vehicle and ECU identification information, and sends deletion commands to the second vehicle to delete the certificate data if the identification information does not match stored records, and requests reissue of the certificate data from a service server.
Prevents incorrect user authentication and ensures accurate billing by deleting and reissuing certificate data without user intervention, enhancing user convenience and service accuracy.
Smart Images

Figure 0007786351000001 
Figure 0007786351000002 
Figure 0007786351000003
Abstract
Description
[Technical Field]
[0001] The technology disclosed in this specification relates to a management server. [Background technology]
[0002] There is known a technology that uses certificate data stored in an ECU of a vehicle to authenticate a user of the vehicle and receive services. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Publication No. 2020-100245 Summary of the Invention [Problem to be solved by the invention]
[0004] An ECU installed in a first vehicle may be removed from the first vehicle and then installed in a second vehicle. In this case, the ECU may be installed in the second vehicle without deleting the certificate data stored in the ECU. If authentication is performed using the certificate data stored in the ECU installed in the second vehicle, the user may be authenticated as a user of the first vehicle, not as a user of the second vehicle.
[0005] This specification provides a technology that can prevent a vehicle user from being authenticated as a user different from the user. [Means for solving the problem]
[0006] A first aspect of the present technology discloses a management server that manages certificate data stored in an ECU of a vehicle. The management server includes a memory that stores a database describing certificate data issued to the vehicle, and at least one processor connected to the memory. The memory stores, in addition to the certificate data, vehicle identification information for identifying the vehicle and ECU identification information for identifying an ECU installed in the vehicle at the time the certificate data was issued. The processor executes an acquisition process that communicates with a specific vehicle in which the ECU is installed to acquire specific vehicle identification information for identifying the specific vehicle and the ECU identification information, and a first transmission process that, in a first case where the combination of the specific vehicle identification information and the ECU identification information acquired from the specific vehicle is not stored in the memory, transmits a first command to the specific vehicle to delete the certificate data stored in the ECU.
[0007] According to the above configuration, in a first case where the combination of specific vehicle identification information and ECU identification information acquired from the specific vehicle is not stored in the memory, the management server transmits a first command to the specific vehicle to delete the certificate data stored in the ECU. When the specific vehicle receives the first command from the management server, it deletes the certificate data in the ECU. This prevents authentication using the certificate data stored in the ECU from being performed. Therefore, it is possible to prevent a user of the specific vehicle from being authenticated as a user different from the user.
[0008] In a second aspect of the present technology, in the above-mentioned first aspect, the processor may further execute a second transmission process to transmit a second command to a service server of a service provider that provides a service to the vehicle using the certificate data, requesting deletion and reissue of the certificate data, in the first case.
[0009] According to the above configuration, the certificate data is reissued without the user having to perform any operation to request the reissue of the certificate data, thereby improving user convenience.
[0010] In a third aspect of the present technology, in the second aspect described above, the processor may further perform an update process to update the database using the reissued certificate data when receiving reissued certificate data from the service server after sending the second command to the service server.
[0011] According to the above configuration, the reissued certificate data can be managed appropriately.
[0012] In a fourth aspect of the present technology, in the second or third aspect, the processor may further execute a third transmission process to transmit the reissued certificate data to the specific vehicle when the processor receives the reissued certificate data from the service server after transmitting the second command to the service server.
[0013] According to the above configuration, the reissued certificate data is stored in the ECU without the user having to perform any operation to store the reissued certificate data in the ECU, thereby improving user convenience.
[0014] In a fifth aspect of the present technology, in any one of the first to fourth aspects, the vehicle may be an electric vehicle equipped with a rechargeable battery, and the service provider may be a business that provides a charging service for the battery.
[0015] For example, in a charging service, if a vehicle user is authenticated as a user other than the user, the charging fee will be billed to the other user. With the above configuration, it is possible to prevent a specific vehicle user from being authenticated as a user other than the user. Therefore, it is possible to provide the charging service appropriately. [Brief explanation of the drawings]
[0016] [Figure 1] 2 shows the configuration of a charging service system 2. [Figure 2] 2 shows the control configuration of each device in the charging service system 2. [Figure 3] The contents of the management table 118 and the certificate lists 218 and 318 are shown. [Figure 4] 10A and 10B show sequence diagrams of a case A in which charging is performed and a case B in which vehicle information is transmitted from the vehicle 10A to the management server 100. FIG. [Figure 5] 10 shows a sequence diagram of a case B in which vehicle information is transmitted from a vehicle 10B to a management server 100. DETAILED DESCRIPTION OF THE INVENTION
[0017] (Example) (Configuration of charging service system 2; Figure 1) 1, charging service system 2 includes vehicles 10A and 10B, a management server 100, a service server 200, a charging server 300, and a charging station 340. Charging service system 2 is a system for providing a charging service for charging batteries 14A and 14B (see FIG. 2) mounted on vehicles 10A and 10B.
[0018] (Configuration of vehicles 10A and 10B; Figure 2) Vehicles 10A and 10B are electric vehicles, and electric vehicles include battery electric vehicles, hybrid electric vehicles, plug-in hybrid electric vehicles, and fuel cell electric vehicles.
[0019] As shown in FIG. 2, the vehicle 10A includes an electric motor 12A, a rechargeable battery 14A, a vehicle-side connector 16A, a communication device 18A, and an ECU (Electronic Control Unit) 20A. The electric motor 12A is a traction motor that operates using power supplied from the battery 14A. The battery 14A is, for example, a lithium-ion battery. The vehicle-side connector 16A has a shape corresponding to a cable-side connector 340A of a charging station 340. A user can connect the cable-side connector 340A to the vehicle-side connector 16A. By connecting the vehicle-side connector 16A and the cable-side connector 340A, charging power is supplied to the battery 14A. Furthermore, when the vehicle-side connector 16A and the cable-side connector 340A are connected, wired communication is possible between the vehicle 10A and the charging station 340. That is, the vehicle-side connector 16A also functions as a wired I / F. The communication device 18A is a device capable of wireless communication. The communication device 18A is connectable to the Internet 4 (see FIG. 1). That is, the communication device 18A functions as a wireless I / F. A memory (not shown) of the communication device 18A stores communication device identification information CI1 for identifying the communication device 18A. The ECU 20A is a device that controls the operation of the vehicle 10A. A memory (not shown) of the ECU 20A stores ECU identification information EI1 for identifying the ECU 20A and certificate data CD1 used to receive the provision of a charging service. The certificate data CD1 is data generated by the service server 200 and issued to the vehicle 10A. The certificate data CD1 is, for example, a key certificate. Furthermore, a memory (not shown) of the vehicle 10A stores vehicle identification information VI1 for identifying the vehicle 10A.
[0020] The vehicle 10B includes an electric motor 12B, a battery 14B, a vehicle-side connector 16B, a communication device 18B, and an ECU 20B. The electric motor 12B, the battery 14B, and the vehicle-side connector 16B have the same configurations as the electric motor 12A, the battery 14A, and the vehicle-side connector 16A, respectively. The communication device 18B has the same configuration as the communication device 18A, except that communication device identification information CI2 is stored therein. The ECU 20B has the same configuration as the ECU 20A, except that ECU identification information EI2 and certificate data CD2 are stored therein. The certificate data CD2 is data generated by the service server 200 and issued to the vehicle 10B. In addition, vehicle identification information VI2 for identifying the vehicle 10B is stored in a memory (not shown) of the vehicle 10B.
[0021] (Configuration of management server 100; Figure 2) The management server 100 is provided on the Internet 4 (see FIG. 1), for example, by a business that sells vehicles. The management server 100 manages information used for charging services. The management server 100 includes a control unit 110. The control unit 110 includes a CPU 112 and a memory 114. The CPU 112 executes various processes in accordance with a program 116 stored in the memory 114. The memory 114 is configured by a volatile memory, a non-volatile memory, etc.
[0022] The memory 114 further stores a management table 118. As shown in FIG. 3, the management table 118 stores ECU identification information, vehicle identification information, communication device identification information, user information, and certificate data in association with each other. The user information includes user identification information for identifying a user who receives a charging service, credit card information, and the like. Hereinafter, the ECU identification information, vehicle identification information, and communication device identification information will be collectively referred to as "vehicle information." Hereinafter, the ECU identification information, vehicle identification information, communication device identification information, user information, and certificate data will be collectively referred to as "management information."
[0023] (Configuration of service server 200; Figure 2) Service server 200 in FIG. 2 is provided on Internet 4 (see FIG. 1) by, for example, a service provider that provides services to vehicles using certificate data. Service server 200 includes control unit 210. Control unit 210 includes CPU 212 and memory 214. CPU 212 executes various processes in accordance with program 216 stored in memory 214. For example, control unit 210 issues certificate data. That is, service server 200 also functions as a certification authority. Memory 214 includes volatile memory, non-volatile memory, etc. Memory 214 further stores certificate list 218. As shown in FIG. 3, certificate list 218 includes one or more certificate data. In a modified example, vehicle identification information, user information, and certificate data may be stored in association with each other in certificate list 218.
[0024] (Configuration of charging server 300; Figure 2) 2 is provided on the Internet 4 (see FIG. 1 ) by, for example, a business operator that operates a charging station 340. Charging server 300 includes a control unit 310. Control unit 310 includes a CPU 312 and a memory 314. CPU 312 executes various processes in accordance with a program 316 stored in memory 314. Memory 314 also stores a certificate list 318. Certificate list 318 is similar to certificate list 218 of service server 200.
[0025] (Specific cases: Figures 4 to 6) Specific cases A to C executed by the charging service system 2 of this embodiment will be described with reference to FIGS.
[0026] (Case A; Figure 4) Referring to Figure 4, case A will be described in which battery 14A mounted on vehicle 10A is recharged. In the initial state of case A, ECU identification information EI1, vehicle identification information VI1, communication device identification information CI1, user information U1, and certificate data CD1 are stored in association with each other in management table 118, and ECU identification information EI2, vehicle identification information VI2, communication device identification information CI2, user information U2, and certificate data CD2 are also stored in association with each other (see Figure 3). Furthermore, certificate lists 218 and 318 store certificate data CD1 and CD2. Furthermore, ECU 20A of vehicle 10A and ECU 20B of vehicle 10B store certificate data CD1 and CD2, respectively.
[0027] At T10, the user of vehicle 10A performs a connector connection operation to connect cable-side connector 340A of charging station 340 to vehicle-side connector 16A of vehicle 10A. By connecting vehicle-side connector 16A to cable-side connector 340A, vehicle 10A becomes capable of communicating with charging server 300 via charging station 340 and the Internet 4.
[0028] At T12, vehicle 10A transmits certificate data CD1 to charging server 300 using encrypted communication (for example, TLS communication).
[0029] When the charging server 300 receives the certificate data CD1 from the vehicle 10A at T12, at T14, the charging server 300 performs authentication using the received certificate data CD1, and the authentication is successful. Although not shown in the figure, the charging server 300 transmits information indicating successful authentication to the charging station 340. The charging station 340 starts supplying charging power to the vehicle 10A. Then, when the supply of charging power to the vehicle 10A is completed, the charging station 340 transmits fee information indicating the charging fee to the charging server 300. The charging server 300 transmits the certificate data CD1 and the fee information to the management server 100 via the service server 200. The management server 100 identifies the user information U1 associated with the received certificate data CD1 in the management table 118 and executes a process of settling the charging fee using the credit card information indicated by the identified user information U1. In this way, simply by the user performing the connector connection operation, authentication, charging of the battery 14A, and payment of the charging fee are automatically performed.
[0030] (Case B; Figure 4) 4, a case B will be described in which the vehicle information transmitted from the vehicle 10A to the management server 100 matches the vehicle information stored in the management server 100. The initial state of the case B is the same as the initial state of the case A.
[0031] At T110, the user of vehicle 10A turns on the ignition switch. In this case, at T112, ECU 20A and the like mounted on vehicle 10A are started. At T114, vehicle 10A transmits vehicle information including ECU identification information EI1, vehicle identification information VI1, and communication device identification information CI1 to management server 100.
[0032] When the management server 100 receives the vehicle information from the vehicle 10A at T114, the management server 100 determines that the combination of the received ECU identification information EI1, vehicle identification information VI1, and communication device identification information CI1 matches the received ECU identification information EI1, vehicle identification information VI1, and communication device identification information CI1 in the management table 118. That is, the management server 100 determines that vehicle information matching the received vehicle information is stored in the management table 118. In this case, the management server 100 does not update the management table 118. Note that the vehicle 10A is configured to periodically transmit the vehicle information to the management server 100. Therefore, even if transmission of the vehicle information to the management server 100 fails immediately after the ECU 20A or the like installed in the vehicle 10A is started, the vehicle information can be reliably transmitted to the management server 100.
[0033] (Case C; Figure 5) 5, a case C will be described in which the vehicle information transmitted from vehicle 10B to management server 100 does not match the vehicle information stored in management server 100. The initial state of case C is the same as the initial state of case A in Fig. 4. In this case, a situation is assumed in which ECUs 20A and 20B fail.
[0034] At T110, an operator (e.g., a service technician at a vehicle dealership) removes ECU 20A from vehicle 10A. Next, the operator repairs ECU 20A. In this case, it is assumed that the operator forgets to delete certificate data CD1 stored in ECU 20A. Although not shown in the figure, the operator installs an ECU different from ECU 20A in vehicle 10B.
[0035] At T220, the worker removes the ECU 20B from the vehicle 10B, and at T222, installs the ECU 20A, in which the certificate data CD1 is stored, into the vehicle 10B. At T230, the worker turns on the ignition switch. In this case, at T232, the ECU 20A and the like installed in the vehicle 10B are started. At T234, the vehicle 10B transmits vehicle information including the ECU identification information EI1, vehicle identification information VI2, and communication device identification information CI2 to the management server 100.
[0036] When the management server 100 receives vehicle information from the vehicle 10B in T234, it determines in T240 that vehicle information matching the received vehicle information (ECU identification information EI1, vehicle identification information VI2, and communication device identification information CI2) is not stored in the management table 118. In this case, the management server 100 identifies, in the management table 118, the certificate data CD1 associated with the received ECU identification information EI1 and the certificate data CD2 associated with the received vehicle identification information VI2. Next, in T150, the management server 100 transmits a first deletion command including the identified certificate data CD1 and CD2 and a reissue command to the service server 200. The deletion command is a signal requesting deletion of the certificate data included in the command. The reissue command is a signal requesting the creation of new certificate data.
[0037] When service server 200 receives a first deletion command and a reissue command from management server 100 in T250, service server 200 updates certificate list 218 in T252. Specifically, service server 200 deletes certificate data CD1 and CD2 included in the first deletion command from certificate list 218. Service server 200 also generates new certificate data CD3 and stores the generated certificate data CD3 in certificate list 218. Next, service server 200 transmits a first update command including certificate data CD3 to management server 100 in T260. Note that, although not shown in the figure, service server 200 deletes certificate data CD1 and CD2 and transmits a command to charging server 300 to store certificate data CD3. In this case, charging server 300 deletes certificate data CD1 and CD2 from certificate list 318 and stores certificate data CD3 in certificate list 318.
[0038] In T260, upon receiving a first update command from service server 200, management server 100 updates management table 118. Specifically, management server 100 identifies user information U2 associated with received vehicle identification information VI2 in management table 118. Next, management server 100 stores management information including received ECU identification information EI1, received vehicle identification information VI2, received communication device identification information CI2, identified user information U2, and received certificate data CD3 in management table 118. Furthermore, management server 100 deletes management information including certificate data CD1 and management information including certificate data CD2 from management table 118. Next, in T270, management server 100 transmits a second deletion instruction including certificate data CD1 and a second update command including certificate data CD3 to vehicle 10B.
[0039] When vehicle 10B receives the second deletion command and the second update command from management server 100 at T270, it deletes certificate data CD1 stored in ECU 20A and stores certificate data CD3 in ECU 20A. Thereafter, when the user of vehicle 10B performs a connector connection operation to connect cable-side connector 340A of charging station 340 with vehicle-side connector 16B of vehicle 10B, communication using certificate data CD3 is performed between vehicle 10B and charging server 300. In this case, the charging fee required to charge battery 14B of vehicle 10B is billed to the user of vehicle 10B.
[0040] As described above, the management server 100 includes a memory 114 that stores a management table 118 (an example of a "database") that describes certificate data CD1 issued to the vehicle 10A, and a CPU 112 (an example of a "processor"). In addition to the certificate data CD1, the memory 114 stores vehicle identification information VI1 for identifying the vehicle 10A and ECU identification information EI1 for identifying the ECU 20A that was mounted on the vehicle 10A at the time the certificate data CD1 was issued. The management server 100 communicates with a vehicle 10B (an example of a "specific vehicle") in which the ECU 20A is mounted, and acquires vehicle identification information VI2 (an example of "specific vehicle identification information") for identifying the vehicle 10B and the ECU identification information EI1 (T234 in FIG. 5). In the first case (case C in Figure 5) in which the combination of vehicle identification information VI2 and ECU identification information EI1 obtained from vehicle 10B is not stored in memory 114, the management server 100 sends a second deletion command (an example of a "first command") to vehicle 10B to delete the certificate data CD1 stored in ECU 20A (T270 in Figure 5).
[0041] According to the above configuration, when the vehicle 10B receives the second deletion command from the management server 100, the vehicle 10B deletes the certificate data CD1 in the ECU 20A (T272 in FIG. 5). As a result, authentication using the certificate data CD1 stored in the ECU 20A is no longer performed. Therefore, it is possible to prevent the user of the vehicle 10A from being authenticated as a user different from the user.
[0042] Furthermore, in the first case (case C in FIG. 5), the management server 100 further transmits a first deletion command and a reissue command (an example of a "second command") to the service server 200 (T250 in FIG. 5).
[0043] According to the above configuration, the certificate data is reissued without the user having to perform any operation to request the reissue of the certificate data, thereby improving user convenience.
[0044] Furthermore, when the management server 100 receives certificate data CD3 (an example of "certificate data after reissue") from the service server 200 (T260 in FIG. 5) after sending the first deletion command and reissue command to the service server 200, the management server 100 updates the management table 118 using the certificate data CD3 (T262 in FIG. 5).
[0045] According to the above configuration, the certificate data CD3 can be managed appropriately.
[0046] Furthermore, after sending the first deletion command and reissue command to the service server 200, when the management server 100 receives the certificate data CD3 from the service server 200 (T260 in Figure 5), the management server 100 transmits the certificate data CD3 to the vehicle 10B (T270 in Figure 5).
[0047] According to the above configuration, the certificate data CD3 is stored in the ECU 20A without the user having to perform any operation to store the certificate data CD3 in the ECU 20A, thereby improving user convenience.
[0048] Furthermore, vehicle 10B is an electric vehicle equipped with a rechargeable battery 14B. The service provider is a business that provides a battery charging service.
[0049] In a charging service, if a user of a vehicle is authenticated as a user different from the user, the charging fee will be billed to the user different from the user. With the above configuration, it is possible to prevent the user of vehicle 10B from being authenticated as a user different from the user. Therefore, it is possible to provide the charging service appropriately.
[0050] While specific examples of the technology disclosed in this specification have been described in detail above, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and alterations of the specific examples exemplified above.
[0051] (First Modification) When the combination of vehicle identification information VI2 and ECU identification information EI1 acquired from vehicle 10B is not stored in memory 114, management server 100 does not have to transmit the first deletion command and reissue command to service server 200. In this modification, T250 to T262 and T274 in case C of Fig. 5 can be omitted. In this modification, the "second transmission process," "update process," and "third transmission process" can be omitted.
[0052] (Second Modification) In T262 of Case C in Fig. 5, the management server 100 does not have to store the management information including the certificate data CD3 in the management table 118. In this modification, when the management server 100 receives a command to update the management table 118 from the vehicle 10B, it may store the management information including the certificate data CD3 in the management table 118.
[0053] (Third Modification) The management server 100 does not need to send the second update command in T270 of Case C in Fig. 5. In this modification, when the management server 100 receives a command from the vehicle 10B requesting transmission of the certificate data CD3, the management server 100 may send the second update command to the vehicle 10B.
[0054] Furthermore, the technical elements described in this specification or drawings may exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. The technologies illustrated in this specification or drawings can achieve multiple objectives simultaneously, and achieving one of these objectives is itself technically useful. [Explanation of symbols]
[0055] 2: Charging service system, 4: Internet, 10A: Vehicle, 10B: Vehicle, 12A: Electric motor, 12B: Electric motor, 14A: Battery, 14B: Battery, 16A: Vehicle side connector, 16B: Vehicle side connector, 18A: Communication device, 18B: Communication device, 20A: ECU, 20B: ECU, 100: Management server, 110: Control unit, 112: CPU, 114: Memory, 116: Program, 118: Management table, 200: Service server, 210: Control unit, 212: CPU, 214: Memory, 216: Program, 218: Certificate list, 300: Charging server, 310: Control unit, 312: CPU, 314: Memory, 316: Program, 318: Certificate list, 340: Charging station, 340A: Cable side connector
Claims
1. A management server that manages certificate data stored in an ECU of a vehicle, a memory storing a database describing certificate data issued to said vehicle; at least one processor coupled to the memory; the memory stores, in addition to the certificate data, vehicle identification information for identifying the vehicle and ECU identification information for identifying an ECU that was installed in the vehicle at the time of issuance of the certificate data; The processor: an acquisition process of communicating with a specific vehicle equipped with the ECU to acquire specific vehicle identification information for identifying the specific vehicle and the ECU identification information; a first transmission process of transmitting, to the specific vehicle, a first command to delete the certificate data stored in the ECU in a first case where a combination of the specific vehicle identification information and the ECU identification information acquired from the specific vehicle is not stored in the memory; The management server that runs
2. The processor further comprises:
2. The management server according to claim 1, wherein, in the first case, a second transmission process is executed to transmit a second command to a service server of a service provider that provides a service to the vehicle using the certificate data, requesting deletion and reissue of the certificate data.
3. The processor further comprises:
3. The management server according to claim 2, wherein, after transmitting the second command to the service server, when reissued certificate data is received from the service server, an update process is executed to update the database using the reissued certificate data.
4. The processor further comprises:
3. The management server according to claim 2, wherein, when reissued certificate data is received from the service server after transmitting the second command to the service server, a third transmission process is executed to transmit the reissued certificate data to the specific vehicle.
5. The vehicle is an electric vehicle equipped with a rechargeable battery, The management server according to claim 2 , wherein the service provider is a business that provides a charging service for the battery.
Citation Information
Patent Citations
Authentication-authorization system, and authentication-authorization method
JP2009205230A
Charging system, charge controller, charging device, and charging method
JP2013045360A
Management system of vehicle identification information
JP2020100245A
Communication system and communication control method
JP2021196820A
Charging authentication device, vehicle charging system, and charging authentication method
JP2022061185A