Control device and control method
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- TOYOTA JIDOSHA KK
- Filing Date
- 2023-12-19
- Publication Date
- 2026-08-04
AI Technical Summary
【0013】 本開示によれば、電動車両に対応するルート証明書が電力スタンドに不整合となることに起因して、電動車両と電力スタンドとの間における電力伝送が不成立となるのを抑制することができる。
Smart Images

Figure 0007899812000001 
Figure 0007899812000002 
Figure 0007899812000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a control device and a control method.
Background Art
[0002] International Publication No. 2021 / 1158021 (Patent Document 1) discloses an electric vehicle capable of charging by the PnC method from a charging station. When a contract certificate is stored (installed) in the electric vehicle, the above PnC charging becomes possible.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Here, although not specified in Patent Document 1 above, in order to store (install) a contract certificate in an electric vehicle (vehicle), it is necessary to transmit route certificate information from the electric vehicle to the charging station. However, since the syntax pattern (rule) of the route certificate corresponding to the electric vehicle is not defined by the standard, the route certificate may not match between the electric vehicle and the charging station. In this case, the contract certificate cannot be installed in the electric vehicle, and charging by the PnC method between the electric vehicle and the charging station cannot be performed. For this reason, the charging control (power transmission) by the PnC method between the electric vehicle and the charging stand may not be established.
[0005] This disclosure is made to solve the above-mentioned problems, and its purpose is to provide a control device and control method that can suppress the failure of power transmission between an electric vehicle and a power station due to inconsistencies between the route certificate corresponding to the electric vehicle and the power station. [Means for solving the problem]
[0006] The control device relating to the first aspect of this disclosure is a control device for a vehicle that communicates with a power station capable of power transmission including at least one of charging and discharging, and comprises a communication unit that transmits root certificate information to the power station in order to obtain (request) a contract certificate, and a processor. The processor modifies the root certificate when the communication unit receives an inconsistency notification indicating that the root certificate is incompatible with the power station. The communication unit transmits the modified root certificate information to the power station. The root certificate refers to a certificate created by a root CA (Certificate authority), which is a certification authority for digital certificates, by signing it itself.
[0007] As described above, the control device relating to the first aspect of this disclosure modifies the root certificate when the communication unit receives an inconsistency notification indicating that the root certificate is inconsistent with the power station, and transmits the information of the modified root certificate to the power station. This allows the contract certificate to be requested (re-requested) using the modified root certificate even if the root certificate is inconsistent with the power station. As a result, the failure of power transmission between the power station and the electric vehicle can be suppressed compared to the case where the contract certificate cannot be re-requested. Therefore, the failure of power transmission between the electric vehicle and the power station due to the root certificate corresponding to the electric vehicle being inconsistent with the power station can be suppressed.
[0008] In the control device relating to the first aspect described above, preferably, when the communication unit determines that the modified root certificate is compatible with the power stand, it transmits the modified root certificate information to the power stand during the next power transmission to the power stand, without transmitting the information of the root certificate before the modification to the power stand. With this configuration, it is possible to omit the transmission of information of root certificates that were not compatible with the power stand and transmit information of root certificates that have a proven track record of success to the power stand. As a result, the time required until it is determined that the root certificate is compatible with the power stand during the next power transmission can be shortened.
[0009] In this case, preferably, the control device includes a storage unit that stores a root certificate that matches the power stand and associates it with the power stand. When the communication unit receives a matching notification indicating that the changed root certificate matches the power stand, (i) the processor updates the information in the storage unit, and (ii) the communication unit, during the next power transmission to the power stand, does not send the information of the root certificate before the change to the power stand, but instead sends the information of the changed root certificate based on the updated information in the storage unit to the power stand. With this configuration, unlike when the information of matching root certificates and power stands is stored in an external device, the above information can be obtained without using communication with an external device. As a result, the processing load on the control device can be reduced.
[0010] In the control device relating to the first aspect described above, preferably, the power station is configured to enable charging of the vehicle based on the PnC (Plug and Charge) charging method and the EIM (External Identification Means) charging method, respectively. When performing charging based on the PnC charging method, the processor repeatedly modifies the root certificate until the modified root certificate matches the power station, and when the number of root certificate modifications reaches a predetermined number, it switches the charging method from the PnC charging method to the EIM charging method. With this configuration, if the charging sequence based on the PnC charging method does not start properly even after the root certificate has been modified a predetermined number of times, the execution of the PnC charging method can be abandoned and the system can switch to a charging sequence based on the EIM charging method. As a result, charging can be started more quickly compared to continuing to modify the root certificate.
[0011] A control method relating to the second aspect of this disclosure is a control method by a vehicle control device that communicates with a power station capable of power transmission including at least one of charging and discharging, comprising: a first transmission step of transmitting route certificate information to the power station in order to obtain a contract certificate; a receiving step of receiving an inconsistency notice after the first transmission step indicating that the route certificate is not compatible with the power station; a modification step of modifying the route certificate after the receiving step; and a second transmission step of transmitting the modified route certificate information to the power station.
[0012] In the control method relating to the second aspect of this disclosure, as described above, when the communication unit receives an inconsistency notification indicating that the root certificate is not compatible with the power station, the root certificate is changed, and information about the changed root certificate is transmitted to the power station. This provides a control method that can suppress the failure of power transmission between the electric vehicle and the power station due to the root certificate corresponding to the electric vehicle being incompatible with the power station. [Effects of the Invention]
[0013] According to this disclosure, it is possible to prevent power transmission failures between electric vehicles and power stations caused by inconsistencies between the route certificate corresponding to the electric vehicle and the power station. [Brief explanation of the drawing]
[0014] [Figure 1] This figure shows the configuration of a charging system according to one embodiment. [Figure 2] This diagram shows the structure of the root certificate. [Figure 3] This is a sequence diagram showing the control in a charging system according to one embodiment. [Modes for carrying out the invention]
[0015] Embodiments of this disclosure will be described in detail below with reference to the drawings. In the drawings, the same or corresponding parts are denoted by the same reference numerals and their descriptions will not be repeated.
[0016] <Charging system configuration> Figure 1 shows the configuration of the charging system 200 according to this embodiment. The charging system 200 comprises an electric vehicle 10 equipped with an ECU 100 and an EVSE (Electric Vehicle Supply Equipment) 20. The electric vehicle 10 and EVSE 20 are examples of the "vehicle" and "power station" as disclosed herein. The ECU 100 is an example of the "control device" as disclosed herein.
[0017] The electric vehicle 10 includes, for example, a PHEV (Plug-in Hybrid Electric Vehicle), a BEV (Battery Electric Vehicle), or an FCEV (Fuel Cell Electric Vehicle).
[0018] EVSE20 means vehicle power supply equipment. The electric vehicle 10 is configured to be electrically connected to the EVSE20. The EVSE20 includes a cable 20b to which a connector 20a is attached. When the connector 20a is connected to an inlet (not shown) of the electric vehicle 10, power is supplied (charged) from the EVSE20 to the electric vehicle 10. Note that charging is an example of "power transmission" in the present disclosure.
[0019] The EVSE20 is configured to be able to charge an electric vehicle based on each of the PnC (Plug and Charge) charging method and the EIM (External Identification Means) charging method. The PnC charging method refers to a charging method in which by simply connecting the connector 20a of the EVSE20 to the electric vehicle 10, processes such as billing authentication and charging are automatically executed. The EIM charging method refers to a charging method in which a user of the electric vehicle 10 makes a payment at the installation location of the EVSE20 or on the EVSE20 main body using cash, electronic money, or the like.
[0020] The electric vehicle 10 includes an ECU (Electric Control Unit) 100, a battery pack 1, a GPS (Global Positioning System) module 2, and a DCM (Data Communication Module) 3.
[0021] The battery pack 1 stores, for example, the power used for the running of the electric vehicle 10. It is possible to increase the power storage amount of the battery pack 1 by charging from the EVSE20.
[0022] The GPS module 2 receives GPS signals transmitted from three or more (preferably four or more) satellites above the electric vehicle 10 and determines the position of the electric vehicle 10 (the vehicle itself). The position information of the electric vehicle 10 determined by the GPS module 2 is transmitted to the DCM module 3 by CAN communication or the like. Note that the GPS module 2 may be built into a car navigation device (not shown) or the like.
[0023] The DCM3 is configured to access external communication servers and the internet. This allows the electric vehicle 10 to acquire various types of information from external sources through the DCM3.
[0024] The ECU 100 transmits and receives information between itself and the battery pack 1, GPS module 2, and DCM 3, etc., via CAN communication by the communication unit 130 described later. The ECU 100 is also configured to control each of the above-mentioned devices.
[0025] The ECU 100 includes a processor 110, a memory 120, and a communication unit 130. The memory 120 stores a program executed by the processor 110, as well as information used by the program (for example, maps, formulas, and various parameters). Note that the memory 120 is an example of a "storage unit" as described herein.
[0026] Memory 120 stores the root certificates shown in Figure 2. In the example shown in Figure 2, memory 120 stores three root certificates, Root Certificates 1 to 3. A root certificate refers to a certificate signed and created by the root CA, which is the certification authority for digital certificates.
[0027] Memory 120 stores root certificates that are consistent with EVSE20, associating them with EVSE20. When processor 110 determines that a root certificate is consistent with EVSE20, it stores the root certificate and EVSE20 together in memory 120 (updating the information in memory 120).
[0028] The communication unit 130 sends root certificate information to the EVSE 20 in order to obtain (request) a contract certificate. When the processor 110 obtains a contract certificate via the EVSE 20, it creates a list of root certificates based on the root certificate profile stored in memory 120. For example, the processor 110 creates a list based on the root certificate profile in which information is set for at least one of the following items: "SerialNumber", "CommonName", "Country", "Organization", "Organization Unit", and "Domain Component". The processor 110 then sends the created list to the EVSE 20 via the communication unit 130. In the following, the pattern of items in which information is set will be referred to as a "syntax pattern".
[0029] When the connector 20a is connected to the electric vehicle 10, the communication unit 130 transmits and receives information with the EVSE 20 (communication unit 23, described later) via the cable 20b.
[0030] The EVSE20 includes a processor 21, a memory 22, and a communication unit 23. The memory 22 stores programs executed by the processor 21, as well as information used by the programs (for example, maps, mathematical formulas, and various parameters).
[0031] Here, in order to store (install) the contract certificate in the electric vehicle, it is necessary to send the root certificate information from the electric vehicle to the EVSE. However, since the syntax pattern (rules) of the root certificate corresponding to the electric vehicle is not defined by the standard, there may be cases where the root certificates are incompatible between the electric vehicle and the EVSE. In this case, the contract certificate cannot be installed in the electric vehicle, and PnC charging between the electric vehicle and the EVSE cannot be performed. Therefore, PnC charging control between the electric vehicle and the EVSE may fail.
[0032] Therefore, in this embodiment, the processor 110 modifies the root certificate when the communication unit 130 receives an inconsistency notification indicating that the root certificate does not match the EVSE 20. Specifically, the processor 110 modifies the root certificate by changing the items in which information is set in the root certificate. The communication unit 130 then transmits the information of the modified root certificate to the EVSE 20. Details will be explained with reference to Figure 3.
[0033] <Sequence control of the charging system> Figure 3 shows the sequence control (S2 to S19 described later) corresponding to the control method by the charging system 200. Note that each process of the electric vehicle 10 shown in Figure 3 is executed by the ECU 100 (processor 110). Each process of the EVSE 20 is executed by the processor 21.
[0034] In step S1, the connector 20a of the EVSE20 is connected to the electric vehicle 10. This makes the electric vehicle 10 ready for PnC charging.
[0035] In step S2, the electric vehicle 10 determines whether the EVSE 20 connected in step S1 is an EVSE that has been connected to the electric vehicle 10 for the first time. The electric vehicle 10 makes the above determination based on, for example, the charging history information stored in the memory 120 (location information where PnC charging was performed or ID information of the EVSE on which PnC charging was performed). If it is the first time to connect to the EVSE 20 (Yes in S2), the process proceeds to step S3. If it has been connected to the EVSE 20 in the past (No in S2), the process proceeds to step S4. Note that being connected to the EVSE 20 in the past means that PnC charging has been performed with the EVSE 20 in the past. Conversely, being connected to the EVSE 20 for the first time means that there is no history of PnC charging with the EVSE 20.
[0036] In step S3, the electric vehicle 10 creates a list based on syntax patterns that have a high success rate in PnC charging at EVSEs installed in each region. This performance information is stored, for example, in an external server (not shown) that can communicate with the DCM3.
[0037] In step S4, the electric vehicle 10 creates a list based on syntax patterns that have a history of successful PnC charging in the EVSE 20. The above information on past performance is stored in the memory 120 of the electric vehicle 10. The above information on past performance may also be stored in an external server (not shown) that can communicate with the DCM 3. If there are multiple syntax patterns with a history of success, a syntax pattern may be selected randomly from among the multiple syntax patterns with a history of success, or the syntax pattern with the highest priority based on a predetermined condition (for example, in order of the fewest number of items set) may be selected.
[0038] In step S5, the electric vehicle 10 transmits root certificate information based on the list created in step S3 or S4 to the EVSE 20 via the communication unit 130 in order to obtain (request) a contract certificate. For example, suppose that root certificate information based on a syntax pattern in which information is set in the two items "SerialNumber" and "CommonName" as shown in Figure 2 is transmitted to the EVSE 20.
[0039] In step S6, the EVSE20 determines whether it has received the root certificate information transmitted from the electric vehicle 10 in step S5. If it has received the root certificate information (Yes in S6), the process proceeds to step S7. If it has not received the root certificate information (No in S6), the process in step S7 is repeated.
[0040] In step S7, EVSE20 determines, based on the information received in step S6, whether the root certificate corresponding to the electric vehicle 10 is compatible with EVSE20 (itself). If the root certificate is compatible with EVSE20 (Yes in S7), the process proceeds to step S8. If the root certificate is not compatible with EVSE20 (No in S7), the process proceeds to step S9.
[0041] In step S8, the EVSE20 transmits the contract certificate issued by the PKI (Public Key Infrastructure) provider to the electric vehicle 10 via the communication unit 23.
[0042] In step S9, the EVSE 20 transmits to the electric vehicle 10 via the communication unit 23 that the route certificate based on the information received in step S6 does not match the EVSE 20.
[0043] In step S10, the electric vehicle 10 determines whether or not it has received the inconsistency notification in step S9. If it has not received the inconsistency notification (No in S10), the process proceeds to step S11. If it has received the inconsistency notification (Yes in S10), the process proceeds to step S14.
[0044] In step S11, the electric vehicle 10 receives the contract certificate sent from EVSE 20 in step S8.
[0045] In step S12, pairs of mutually compatible root certificates and EVSE20 (the pairs of root certificates and EVSE20 from S5) are recorded in memory 120 (the information in memory 120 is updated).
[0046] In step S13, the electric vehicle 10 starts a charging session (PnC session) based on the PnC charging method.
[0047] In step S14, the electric vehicle 10 determines whether the number of changes to the root certificate (syntax pattern) has reached two. If the number of changes to the root certificate has reached two (Yes in S14), the process proceeds to step S15. If the number of changes to the root certificate is less than two (No in S14), the process proceeds to step S16.
[0048] In step S15, the electric vehicle 10 abandons PnC charging and starts a charging session (EIM session) based on the EIM charging method. Next, the process proceeds to step S17.
[0049] In step S16, the electric vehicle 10 modifies the syntax pattern of the root certificate. For example, the electric vehicle 10 modifies the syntax pattern by adding one more item to which information is set (for example, by adding information to the item corresponding to "Country"). Note that the method of modifying the syntax pattern is not limited to the above example. Next, the process returns to step S5. That is, in step S5, the modified syntax pattern of the root certificate is sent to EVSE20.
[0050] In step S7, after the process returns to step S5, it is determined that the root certificate with the modified syntax pattern is compatible with EVSE20. Subsequently, in step S11, the electric vehicle 10 receives the contract certificate from step S8 (corresponding to "receiving a compatibility notification" in this disclosure). In this case, in step S12, the electric vehicle 10 (processor 110) updates the information in memory 120 so that the root certificate with the modified syntax pattern and EVSE20 are associated with each other. At the next time the electric vehicle 10 charges EVSE20 (the next step S4), it does not send the information of the root certificate before the modification to EVSE20, but instead sends the information of the modified root certificate based on the updated information in memory 120 to EVSE20.
[0051] In step S17, billing authentication is performed between the electric vehicle 10 and the EVSE 20. In step S18, charging begins between the electric vehicle 10 and the EVSE 20. In step S19, charging ends. In step S20, the connection between the connector 20a of the EVSE 20 and the electric vehicle 10 is released.
[0052] As described above, in this embodiment, the processor 110 modifies the root certificate when the communication unit 130 receives an inconsistency notification indicating that the root certificate does not match the EVSE 20. The communication unit 130 sends the information of the modified root certificate to the EVSE 20. This allows the processor to modify the root certificate and attempt to connect to PnC charging again, even if the root certificate does not match the EVSE 20. As a result, it is possible to prevent PnC charging from ending unsuccessfully (transitioning to EIM charging).
[0053] The above embodiment shows an example in which control is performed to change the root certificate during charging control of the electric vehicle 10, but the disclosure is not limited thereto. Control to change the root certificate may also be performed during discharging control of the electric vehicle 10. Furthermore, control to change the root certificate may be performed both during charging control and discharging control of the electric vehicle 10.
[0054] In the above embodiment, an example was shown in which, when it is determined that the modified root certificate is compatible with EVSE20, the information of the root certificate before modification is not sent to EVSE20 during the next charge, and the information of the modified root certificate is sent to EVSE20. However, this disclosure is not limited to this example. Regardless of the determination made during the previous charge, the electric vehicle may initially send the root certificate before modification (the default root certificate) to EVSE20.
[0055] In the above embodiment, an example was shown in which the system switches to an EIM session when the number of root certificate changes reaches a predetermined number (2 times in the above embodiment), but this disclosure is not limited thereto. The charging control itself may be terminated when the number of root certificate changes reaches a predetermined number.
[0056] The above embodiment shows an example where the system switches to an EIM session when the number of root certificate changes reaches two, but this disclosure is not limited to this. The upper limit on the number of root certificate changes may be other than two. For example, the electric vehicle 10 may be able to change the root certificate until information is set for all items of the syntax pattern shown in Figure 2. This will be explained in detail. Assume that when the electric vehicle 10 changes the root certificate, it is possible to increase the number of items (see Figure 2) for which information is set one by one. For example, the electric vehicle 10 changes the root certificate by setting information for "Country" from the state in Figure 2. Therefore, the electric vehicle 10 can change the root certificate four times, as it is possible to add information to each of the "Country", "Organization", "Organization Unit", and "Domain Component" items from the state in Figure 2. Note that the method of changing the root certificate is not limited to the example above.
[0057] In the above embodiment, an example was shown in which the consistency between the root certificate and EVSE20 is determined by EVSE20, but this disclosure is not limited thereto. For example, the determination may be performed by an external server different from EVSE20. Furthermore, the results of the determination (inconsistency notification and consistency notification) may be transmitted from the external server to the electric vehicle 10.
[0058] In the above embodiment, an example was shown in which it is determined whether or not the connection between the electric vehicle 10 and the EVSE 20 is being made for the first time after the connector 20a has been connected, but the disclosure is not limited thereto. For example, it may be determined whether or not the connection between the electric vehicle 10 and the EVSE 20 is being made for the first time depending on whether or not the EVSE 20 has been found by the car navigation system, or whether or not the electric vehicle 10 has stopped near the EVSE 20.
[0059] The above embodiment shows an example in which the root certificate information (list of syntax patterns) initially sent to the EVSE 20 is adjusted depending on whether or not it is the first time the electric vehicle 10 and the EVSE 20 are connected (see S3 and S4 in Figure 3), but the disclosure is not limited thereto. Regardless of whether or not it is the first time the electric vehicle 10 and the EVSE 20 are connected, the root certificate information initially sent to the EVSE 20 may be constant (for example, the default root certificate information).
[0060] Furthermore, the control of the above embodiments and the various modifications described above may be performed in combination with each other.
[0061] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of this disclosure is indicated by the claims rather than by the description of the embodiments above, and all modifications within the meaning and scope equivalent to the claims are intended to be included. [Explanation of Symbols]
[0062] 10 Electric vehicles (vehicles), 20 EVSE (electric charging stations), 100 ECU (control unit), 110 Processor, 120 Memory (storage unit), 130 Communication unit.
Claims
1. A vehicle control device that communicates with a power station capable of power transmission including at least one of charging and discharging, A communication unit transmits information about a root certificate, which includes multiple items for which setting information can be configured for each item, to the power station in order to obtain a contract certificate. Equipped with a processor, When the communication unit receives an inconsistency notification indicating that the root certificate is incompatible with the power stand, the processor modifies the setting item among the multiple items in the root certificate that is the item in which the setting information is set. The communication unit is a control device that transmits information about the root certificate whose settings have been changed to the power station.
2. The control device according to claim 1, wherein, when the communication unit determines that the root certificate with the changed setting items is compatible with the power stand, it transmits to the power stand, during the next power transmission to the power stand, the information of the root certificate with the changed setting items, instead of transmitting to the power stand the information of the root certificate before the setting items were changed.
3. The system further includes a storage unit that stores the root certificate, which is consistent with the power stand, in association with the power stand. When the communication unit receives a consistency notification indicating that the root certificate with the changed settings is compatible with the power station, The processor updates the information in the memory unit, The control device according to claim 2, wherein the communication unit, during the next power transmission to the power stand, does not transmit to the power stand the information of the root certificate before the setting items were changed, but instead transmits to the power stand the information of the root certificate with the setting items changed, based on the updated information of the storage unit.
4. The aforementioned charging station is configured to enable charging of the vehicle based on the PnC (Plug and Charge) charging method and the EIM (External Identification Means) charging method, respectively. The aforementioned processor, When performing charging based on the PnC charging method, the setting items are repeatedly changed until the root certificate with the changed setting items is compatible with the power station. The control device according to any one of claims 1 to 3, wherein when the number of changes to the setting item reaches a predetermined number, the charging method is switched from the PnC charging method to the EIM charging method.
5. A control method by a vehicle control device that communicates with a power station capable of power transmission including at least one of charging and discharging, A first transmission step involves transmitting information of a root certificate, which includes multiple items for which setting information can be configured for each item, to the power station in order to obtain a contract certificate. A receiving step, which follows the first transmission step, is to receive a notification of inconsistency indicating that the root certificate is not compatible with the power station, Following the reception step, a modification step is performed to modify a setting item among the multiple items in the root certificate that is the item in which the setting information is set, A control method comprising: a second transmission step of transmitting information of the root certificate whose setting items have been changed in the modification step to the power station.