Communication method and communication apparatus for hydrogen fueling
The bidirectional communication method enhances the efficiency and security of hydrogen fueling by establishing a secure communication channel between mobility and dispensers, addressing inefficiencies and security gaps in conventional technologies, applicable to hydrogen-fueled vehicles and other mobility systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HYUNDAI MOTOR CO LTD
- Filing Date
- 2025-10-29
- Publication Date
- 2026-05-07
AI Technical Summary
Conventional hydrogen fuel supply technologies for hydrogen electric vehicles are inefficient, slow, unsuitable for large-scale operations, and lack security due to the use of low-level communication technology, failing to reflect advancements in Information and Communication Technology (ICT).
A bidirectional communication method and apparatus are introduced to enhance the safety, compatibility, security, and reliability of hydrogen fueling by establishing a secure communication channel between mobility and dispensers, using a handshake protocol with message exchange and session headers, and employing advanced communication media.
The bidirectional communication method improves the efficiency and security of hydrogen fueling processes, ensuring safe and reliable operations across various hydrogen-fueled mobility systems, including vehicles, aerial mobility, industrial trucks, trains, and ships.
Smart Images

Figure KR2025017442_07052026_PF_FP_ABST
Abstract
Description
Communication method and communication device for hydrogen fuel supply
[0001] The present invention relates to a communication method and apparatus for hydrogen fueling from a charging station / dispenser to hydrogen fueled mobility, and more specifically, to a bidirectional communication method and apparatus using the same that can improve the safety, compatibility, security, efficiency, and reliability of hydrogen fueling.
[0002] The content described in this section merely provides background information regarding the present embodiment and does not constitute prior art.
[0003] Hydrogen cars, or hydrogen electric vehicles, refer to zero-emission automobiles that move using electrical energy generated by the interaction of high-pressure hydrogen stored in the vehicle with ambient air. Hydrogen electric vehicles are also known as Fuel Cell Electric Vehicles (FCEVs). Most hydrogen electric vehicles operate by generating electricity using a fuel cell system that utilizes hydrogen as an energy source. Hydrogen electric vehicles are attracting attention as a future eco-friendly mobility solution because they not only emit only pure water (H2O) during the electricity generation process but also possess the capability to remove ultrafine dust from the atmosphere while in operation. Given that hydrogen is an infinite source on Earth and the energy production process is environmentally friendly, this technology is widely recognized for its potential for application across various industries.
[0004] Hydrogen-fueled mobility refers to a type of mobility that uses hydrogen as an energy source or hydrogen as fuel to generate electrical energy and uses this to drive an electric motor. In addition to the hydrogen electric vehicles described above, hydrogen-fueled mobility includes aerial mobility as well as industrial trucks, trains, ships, and aircraft, and may include devices that generate electrical energy using hydrogen as fuel and use this to drive.
[0005] Most hydrogen fuel cell vehicles deliver high-pressure hydrogen, safely stored in a hydrogen fuel storage tank, and oxygen supplied through an air supply system to a fuel cell stack, generating electrical energy through an electrochemical reaction between the hydrogen and oxygen. This generated electrical energy is converted into kinetic energy via a drive motor to power the vehicle, and the vehicle has the advantage of emitting only pure water through its exhaust port while in motion.
[0006] Meanwhile, the concept of a hydrogen fueled car, as opposed to a hydrogen electric vehicle, also refers to a vehicle that uses hydrogen as fuel; a hydrogen fueled car operates by driving an electric motor using heat generated from the direct combustion of hydrogen in an internal combustion engine (ICE). The method of supplying hydrogen for hydrogen fueled cars is not significantly different from that used for hydrogen electric vehicles.
[0007] In a control technique for supplying hydrogen to a vehicle utilizing hydrogen as fuel, the ultimate goal is to control the temperature and pressure of the Compressed Hydrogen Storage System (CHSS) on the fuel cell side to operate under limit temperature and limit pressure conditions for the safety of hydrogen fuel supply.
[0008] The hydrogen fuel supply processes, control techniques, and protocols for conventional hydrogen electric vehicles were defined when wired and wireless communication technologies and computing techniques for control were not yet mature, and thus fail to adequately reflect the achievements of recently attained Information and Communication Technology (ICT). Consequently, conventional hydrogen fuel supply technology for hydrogen electric vehicles is inefficient, slow, and unsuitable for large-scale hydrogen fuel supply.
[0009] In addition, regarding hydrogen fuel supply communication, conventional technology has the problem of weak security due to the application of low-level communication technology.
[0010] To solve the above-mentioned problems, the present invention may propose a hydrogen fueling process for hydrogen fueled mobility and a communication protocol for the process that overcomes the limitations and vulnerabilities of existing unidirectional communication and improves the safety, compatibility, security, efficiency, and reliability of the hydrogen fueling process, a bidirectional communication method for the hydrogen fueling process, and a device utilizing the communication method.
[0011] The present invention may propose a communication method that can appropriately utilize a conventional communication medium or an advanced communication medium to efficiently achieve a hydrogen fueling goal for hydrogen fuel mobility and dispensers.
[0012] The present invention may propose a method for hydrogen fuel mobility and dispensers to exchange information using an improved secure communication environment in order to efficiently achieve a hydrogen fueling goal.
[0013] The present invention can propose and provide a version of a communication method between a hydrogen fuel mobility and a dispenser with improved security.
[0014] A communication method for hydrogen fuel supply according to an embodiment of the present invention for achieving the above objective may include: a step of establishing a secure communication channel between the mobility and the dispenser based on a handshake that exchanges messages with the dispenser that fuels the mobility, which is performed between the communication device of the hydrogen fueled mobility and the communication device of the dispenser that fuels the mobility by means of a communication device of the hydrogen fueled mobility; a step of generating a first message having said session header including a version of the session header based on metadata of a session receiving hydrogen fuel from said dispenser, a schema identifier of the payload, and length information of said payload; and a step of transmitting said first message to said dispenser using said secure communication channel.
[0015] In a communication method for hydrogen fuel mobility for hydrogen fuel supply according to one embodiment of the present invention, the packet containing the first message may include the session header and the payload, and the payload may include a message header and a schema-based encoded message.
[0016] The above message header may include a session identifier, a message identifier, a timestamp of the message, and optional signatures.
[0017] A first session identifier that uniquely identifies the above session may be assigned from the dispenser after a communication protocol negotiation procedure between the mobility and the dispenser, and a fuel supply protocol negotiation procedure.
[0018] A communication method for hydrogen fuel mobility for hydrogen fuel supply according to one embodiment of the present invention may further include the step of obtaining the first session identifier based on a message header included in the first fuel supply parameter response message received from the dispenser.
[0019] In a communication method for hydrogen fuel mobility for hydrogen fuel supply according to one embodiment of the present invention, in the first message prior to the first session identifier being assigned from the dispenser, the session identifier field may be determined as a predetermined value.
[0020] In a communication method for hydrogen fuel mobility for hydrogen fuel supply according to one embodiment of the present invention, in the first message including a first fuel supply parameter request message before the first session identifier is received from the dispenser, the session identifier field may be determined as a predetermined value.
[0021] In a communication method for hydrogen fuel mobility for hydrogen fuel supply according to one embodiment of the present invention, a plurality of second messages within a session after the first session identifier is assigned from the dispenser following the first fuel supply parameter request message may include the first session identifier in the message header.
[0022] A communication device for supplying hydrogen fuel, which is deployed in a hydrogen fuel mobility according to one embodiment of the present invention, may include a memory for storing at least one command; and a processor for executing said at least one command.
[0023] The processor can establish a secure communication channel between the mobility and the dispenser based on a handshake that exchanges messages between the dispenser, which fuels the mobility with hydrogen, and the mobility; can generate a first message having the session header, which includes a version of the session header based on metadata of the session receiving hydrogen fuel from the dispenser, a schema identifier of the payload, and length information of the payload; and the mobility can transmit the first message to the dispenser using the secure communication channel.
[0024] In a communication device for hydrogen fuel mobility according to one embodiment of the present invention, a packet containing the first message may include the session header and the payload, and the payload may include a message header and a schema-based encoded message.
[0025] In a communication device for hydrogen fuel mobility according to one embodiment of the present invention, the message header may include a session identifier, a message identifier, a timestamp of the message, and optional signatures.
[0026] In a communication device for hydrogen fuel mobility according to one embodiment of the present invention, a first session identifier that uniquely identifies the session may be assigned from the dispenser after a communication protocol negotiation procedure between the mobility and the dispenser, and a fuel supply protocol negotiation procedure.
[0027] In a communication device for hydrogen fuel mobility according to one embodiment of the present invention, the processor can obtain the first session identifier based on a message header included in the first fuel supply parameter response message received from the dispenser.
[0028] In a communication device for hydrogen fuel mobility according to one embodiment of the present invention, in the first message prior to the first session identifier being assigned from the dispenser, the session identifier field may be determined to a predetermined value.
[0029] In a communication device for hydrogen fuel mobility according to one embodiment of the present invention, a plurality of second messages within a session after the first session identifier is assigned from the dispenser following the first fuel supply parameter request message may include the first session identifier in the message header.
[0030] A communication method for hydrogen fuel supply according to one embodiment of the present invention is performed between a communication device of hydrogen fueled mobility and a communication device of a dispenser that supplies hydrogen to the mobility, and may include: a step of establishing a secure communication channel between the mobility and the dispenser based on a handshake that exchanges messages between the mobility and the dispenser by the communication device of the dispenser; a step of generating a third message having the session header, which includes a version of the session header based on metadata of the session in which the dispenser supplies hydrogen to the mobility, a schema identifier of the payload, and length information of the payload; and a step of transmitting the third message to the mobility using the secure communication channel.
[0031] In a communication method for a dispenser for hydrogen fuel supply according to one embodiment of the present invention, the packet containing the third message may include the session header and the payload, the payload may include a message header and a schema-based encoded message, and the message header may include a session identifier, a message identifier, a timestamp of the message, and optional signatures.
[0032] A communication method for a dispenser for hydrogen fuel supply according to one embodiment of the present invention may further include a communication protocol negotiation procedure between the mobility and the dispenser, and a step of assigning a first session identifier that uniquely identifies the session to the session after the fuel supply protocol negotiation procedure.
[0033] A communication method for a dispenser for hydrogen fuel supply according to one embodiment of the present invention may further include the step of including the first session identifier in the message header of the first fuel supply parameter response message to be transmitted to the mobility and transmitting it.
[0034] In a communication method for a dispenser for hydrogen fuel supply according to one embodiment of the present invention, in the third message prior to the first session identifier being assigned from the dispenser, the session identifier field may be determined to a predetermined value.
[0035] A plurality of fourth messages within the corresponding session after the first fuel supply parameter request message, after the first session identifier is assigned from the dispenser, may include the first session identifier in the message header.
[0036] A communication device for supplying hydrogen fuel, disposed in a dispenser for supplying hydrogen fuel to a hydrogen fuel mobility according to one embodiment of the present invention, may include a memory for storing at least one command; and a processor for executing said at least one command.
[0037] The processor can establish a secure communication channel between the mobility and the dispenser based on a handshake for exchanging messages with the mobility; generate a third message having the session header, which includes a version of the session header based on metadata of the session in which the dispenser fuels hydrogen to the mobility, a schema identifier of the payload, and length information of the payload; and transmit the third message to the mobility using the secure communication channel.
[0038] According to a communication method for hydrogen fuel supply and a device using the same according to one embodiment of the present invention, namely, a hydrogen fuel supply control device or a communication control device for mobility, the limitations and vulnerabilities of existing unidirectional communication can be overcome in a hydrogen fueling process and a communication protocol for hydrogen fueled mobility including a fuel cell electric vehicle (FCEV) and a hydrogen fuel engine, and the safety, compatibility, security, efficiency, and reliability of hydrogen fuel supply can be improved.
[0039] According to one embodiment of the present invention, a conventional communication medium or an advanced communication medium may be appropriately utilized to efficiently achieve a hydrogen fueling goal through cooperation between mobility and a dispenser.
[0040] According to one embodiment of the present invention, hydrogen fuel mobility and a dispenser can exchange information using an improved secure communication environment to efficiently achieve a hydrogen fueling goal.
[0041] According to one embodiment of the present invention, a version with improved security of a communication method performed between a hydrogen fuel mobility and a dispenser can be provided.
[0042] FIG. 1 is a conceptual diagram illustrating the operation of systems / devices within a hydrogen fuel supply environment in which a hydrogen fuel supply process to which bidirectional communication technology is applied is performed, according to one embodiment of the present invention.
[0043] FIG. 2 is a conceptual diagram illustrating a system / device participating in a hydrogen fuel supply communication method according to an embodiment of the present invention and sub-components within the system / device.
[0044] FIG. 3 is a conceptual diagram illustrating functional blocks corresponding to procedures in a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0045] FIG. 4 is an operation flowchart conceptually illustrating the operation between functional blocks corresponding to procedures in a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0046] FIG. 5 is a diagram conceptually illustrating functional blocks corresponding to procedures in a hydrogen fuel supply communication method according to one embodiment of the present invention on an OSI 7 layer.
[0047] FIG. 6 is an operation flowchart conceptually illustrating a secure communication procedure within a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0048] FIG. 7 is an operation flowchart conceptually illustrating a secure communication procedure within a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0049] FIG. 8 is an operation flowchart conceptually illustrating a part of a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0050] FIG. 9 is an operation flowchart conceptually illustrating a part of a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0051] FIG. 10 is an operation flowchart conceptually illustrating message contents transmitted and received by a hydrogen fuel supply communication method according to an embodiment of the present invention.
[0052] FIG. 11 is a conceptual block diagram of the internal structure of a generalized computing system that can be mounted on a hydrogen fuel mobility, dispenser, and / or fuel supply station as a communication device, communication control device, and / or electronic control device for hydrogen fuel supply according to one embodiment of the present invention.
[0053] In addition to the above objectives, other objectives and features of the present invention will become apparent through the description of embodiments with reference to the accompanying drawings.
[0054] The present invention is capable of various modifications and may have various embodiments, and specific embodiments are illustrated in the drawings and described in detail. However, this is not intended to limit the invention to specific embodiments, and it should be understood that the invention includes all modifications, equivalents, and substitutions that fall within the spirit and scope of the invention.
[0055] Terms such as first, second, A, B, etc., may be used to describe various components, but said components shall not be limited by said terms. These terms are used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of the present invention, the first component may be named the second component, and similarly, the second component may be named the first component. The term "and / or" includes a combination of a plurality of related described items or any of a plurality of related described items.
[0056] In the embodiments of the present application, "at least one of A and B" may mean "at least one of A or B" or "at least one of one or more combinations of A and B". Additionally, in the embodiments of the present application, "at least one of A and B" may mean "at least one of A or B" or "at least one of one or more combinations of A and B".
[0057] When it is stated that one component is "connected" or "connected" to another component, it should be understood that while it may be directly connected or connected to that other component, there may also be other components in between. On the other hand, when it is stated that one component is "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between.
[0058] The terms used in this application are used merely to describe specific embodiments and are not intended to limit the invention. The singular expression includes the plural expression unless the context clearly indicates otherwise. In this application, terms such as "comprising" or "having" are intended to specify the presence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0059] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as generally understood by those skilled in the art to which the present invention pertains. Terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an ideal or overly formal sense unless explicitly defined in this application.
[0060] Some terms used in this specification are defined as follows.
[0061] Hydrogen fueled mobility can refer to all types of mobility, including ICE (internal combustion engine) based mobility that obtains the power required for movement using hydrogen as an energy source, mobility that generates electrical energy using hydrogen as fuel and drives an electric motor using this, and / or hybrid vehicles / mobility equipped with an ICE and an electric motor using hydrogen as an energy source.
[0062] In addition to hydrogen electric vehicles, hydrogen fuel mobility may include aerial mobility, as well as industrial trucks, trains, ships, and aircraft, which use hydrogen as fuel to generate electrical energy and drive them.
[0063] Hydrogen electric vehicles generally refer to fuel cell electric vehicles (FCEVs) that utilize fuel cells, but they can include all mobility vehicles that drive electric motors using hydrogen as an energy source through methods other than fuel cells.
[0064] Even if, for instance, a hydrogen fuel cell vehicle is disclosed as the primary embodiment in the following embodiments, other embodiments of the present invention may be implemented to include ICE-based hydrogen fueled mobility that utilizes hydrogen as fuel, within the scope consistent with the purpose of the invention. Even if a hydrogen fueling protocol and / or a communication protocol for hydrogen fueling is disclosed with a hydrogen fuel cell vehicle as the primary embodiment in the following embodiments, it is obvious to those skilled in the art that, according to other embodiments of the present invention, the hydrogen fueling protocol and / or the communication protocol for hydrogen fueling disclosed in the following embodiments may also be applied to ICE-based hydrogen fueled mobility.
[0065] Hydrogen fuel supply refers to the process of receiving high-pressure hydrogen from a dispenser at a hydrogen station and compressing and storing it in a hydrogen storage tank of a vehicle / mobility. In the sense of supplying hydrogen to hydrogen fuel mobility, hydrogen fuel supply can be briefly used interchangeably with the term "fueling." That is, in this specification, "fueling" may be used to mean fuel supply or hydrogen fuel supply, and "fuel supply" may mean the supply of hydrogen fuel. For example, "fuel supply protocol" may be referred to as "hydrogen fuel supply protocol," "fuel supply session" may be referred to as "hydrogen fuel supply session," and "fuel supply method" may be referred to as "hydrogen fuel supply method."
[0066] Hydrogen fluid fuels may include gaseous hydrogen fuel or liquid hydrogen fuel.
[0067] Hydrogen fuel may include at least one of hydrogen in a gaseous state and hydrogen in a liquid state, and may basically mean compressed hydrogen, but is not limited thereto.
[0068] A Compressed Hydrogen Storage System (CHSS) may include at least one tank mounted on the mobility side and a device coupled to the tank to compress and store hydrogen in the tank.
[0069] A Pressure Relief Device (PRD) is a device deployed in the CHSS that can isolate stored hydrogen from the mobility's hydrogen fuel supply system and the surrounding environment, and can discharge the hydrogen to the outside.
[0070] Pressure Ramp Rate (PRR) is expressed in MPa / min and represents the rate of increase in pressure of CHSS.
[0071] The Average Pressure Ramp Rate (APRR) refers to the average value of the pressure increase rate from the beginning to the end of hydrogen fueling.
[0072] Pre-cooling basically refers to the process of cooling the hydrogen at a hydrogen refueling station in advance before supplying fuel.
[0073] The dispenser is a component that delivers pre-cooled hydrogen to the CHSS. The dispenser is placed at a hydrogen refueling station and can perform hydrogen fuel supply operations between the hydrogen storage tank of the hydrogen refueling station and the CHSS of the mobility.
[0074] A nozzle refers to a device that connects to a dispenser, connects to the receptacle of a hydrogen electric vehicle, and allows for the delivery of hydrogen fuel.
[0075] A fueling session can be used to mean communication sessions that take place throughout the entire use case for hydrogen fueling.
[0076] Interoperability can refer to the state in which components of relative systems can work together to perform the intended operation of the entire system. Information interoperability can refer to the ability of two or more networks, systems, devices, applications, or components to safely and effectively share and easily use information with little to no inconvenience to users.
[0077] Correlation / Association may include the procedure for establishing a relationship between two peer communication entities.
[0078] Command and control communication may refer to communication between a hydrogen fuel supply device and a hydrogen fuel mobility device that exchanges information necessary for the start, control, and termination of the hydrogen fuel supply process.
[0079] In addition, the bidirectional communication process for hydrogen fuel supply of the present invention can be partially applied not only to hydrogen fuel mobility but also to buildings or facilities that use hydrogen as an energy source.
[0080] In the following specification, some or all of the processes of the communication method, communication protocol negotiation method, hydrogen fuel supply (fueling) protocol negotiation method, and hydrogen fuel supply (fueling) parameter negotiation method performed in hydrogen fuel mobility may be performed by an electronic control unit (ECU), a communication device, or a communication control device within the hydrogen fuel mobility.
[0081] In the following specification, some or all of the processes of the communication method, communication protocol negotiation method, hydrogen fuel supply (fueling) protocol negotiation method, hydrogen fuel supply (fueling) parameter negotiation method, hydrogen fuel supply (fueling) method, and hydrogen fuel supply (fueling) control method performed in the dispenser may be performed by the controller, electronic control unit, communication device, or communication control device of the dispenser. Additionally, some of the processes of the above methods may be performed by the controller, electronic control unit, communication device, or communication control device of the fuel supply station associated with the dispenser.
[0082] Meanwhile, even if technology was known prior to the filing date of the present invention, it may be included as part of the composition of the present invention if necessary, and such details are described in this specification to the extent that they do not obscure the spirit of the present invention. However, in describing the composition of the present invention, detailed descriptions of matters that are known prior to the filing date and are obvious to those skilled in the art may obscure the spirit of the present invention; therefore, overly detailed descriptions of known technology are omitted. Furthermore, the purpose of the present invention is not to claim rights regarding these known technologies, and the content of the known technologies may be included as part of the present invention to the extent that it does not deviate from the spirit of the present invention.
[0083] For example, for unidirectional communication, IrDA technology may be used; for bidirectional communication, short-range wireless communication technology (Bluetooth, WLAN, UWB) may be used; or wired communication technology for unidirectional / bidirectional communication may be used, etc., which are known technologies prior to the filing of the present invention, and at least some of these known technologies may be applied as elemental technologies necessary for implementing the present invention.
[0084] Hereinafter, preferred embodiments according to the present invention will be described in detail with reference to the attached drawings.
[0085] FIG. 1 is a conceptual diagram illustrating the operation of systems / devices within a hydrogen fuel supply environment in which a hydrogen fuel supply process to which bidirectional communication technology is applied is performed, according to one embodiment of the present invention.
[0086] Referring to FIG. 1, pre-cooled hydrogen gas from a hydrogen refueling station (Station, 300) is supplied to a hydrogen fueled mobility (100) via a dispenser (200). At this time, the hydrogen fuel supply process can be described and controlled by parameters including a pressure ramp rate (PRR) or an average pressure ramp rate (APRR). The pressure ramp rate may refer to a concept applied to a relatively short time interval, while the average pressure ramp rate may refer to a concept applied to a time interval longer than the pressure ramp rate.
[0087] The mobility (100) may include hydrogen storage (102). The hydrogen storage (102) may be implemented by connecting one or more compressed hydrogen storage systems (CHSS) or commonly referred to as "tank" in parallel.
[0088] A pressure relief device (PRD, 104) is a device capable of discharging hydrogen fuel stored in a CHSS to the outside. Generally, hydrogen injection and discharge into the CHSS do not proceed simultaneously, and sensors capable of measuring state information such as the pressure and temperature of the hydrogen inside the CHSS may be attached.
[0089] The pressure of hydrogen stored on the mobility (100) side is also referred to as the State of Charge (SoC), which is analogous to the charging process of a battery.
[0090] A dispenser (200) is positioned as an interface between a hydrogen charging station (300) and a hydrogen fuel mobility (100), and the dispenser (200) can control the target pressure of hydrogen stored in the mobility (100) and the injection speed of hydrogen fuel supplied to the mobility (100) based on measurement data such as the temperature and pressure of hydrogen on the mobility (100) side and fuel supply information of the charging station (300). An example of a control logic currently in use is a control logic that follows the SAE J2601 (2020-05) standard.
[0091] For example, the target pressure of hydrogen is the goal of fuel supply, and the range of PRR or APRR can be determined based on the target time and target pressure. In this case, to ensure safety and reliability, the range of PRR or APRR may be adjusted or determined based on constraints such as the temperature rise caused by the increase in pressure during the fuel supply process and the temperature limit when the temperature rises.
[0092] The control logic that controls the hydrogen fuel supply process of the dispenser (200) may be referred to as a hydrogen fuel supply protocol (210). The hydrogen fuel supply protocol (210) illustrated in FIG. 1 may refer to a plurality of control logics possessed by the dispenser (200), and among these, one of the control logics is determined based on, for example, the SAE J2601 (2020-05) standard, or target information and environmental information, and the determined control logic may be executed by the elements of the hydrogen fuel supply protocol (210).
[0093] Regarding minimum safety requirements, simulations can be performed through thermodynamic modeling for various situations. Based on parameters derived from the simulation, a table-based single injection method and / or an MC-formula-based partial real-time correction method may be utilized.
[0094] Minimum safety requirements may include upper limits for the temperature and pressure conditions of hydrogen within the CHSS and guidelines for the State of Charge (SoC). Simulations may be performed through thermodynamic modeling using boundary conditions covering Best to Worst Cases.
[0095] The hydrogen refueling station (300) may include a hydrogen storage (302) and a pre-cooler (304). The hydrogen storage (302) on the side of the refueling station (300) may generally be a tank that stores high-pressure hydrogen. The pre-cooler (304) can supply hydrogen to the mobility (100) via the dispenser (200) with the temperature of the hydrogen gas lowered through pre-cooling.
[0096] Since the pressure and temperature of hydrogen may increase simultaneously during the hydrogen fuel supply process, pre-cooling may be performed for the safety and efficiency of the fuel supply. However, excessive pre-cooling may be a factor in causing excessive energy costs and operating costs. A method may be provided in which hydrogen status information (temperature, pressure, etc.) from the charging station (300) is transmitted to the dispenser (200) and considered together in the control logic of the hydrogen fuel supply protocol (210), thereby allowing the charging station (300) to control or optimize pre-cooling.
[0097] FIG. 2 is a conceptual diagram illustrating a system / device participating in a hydrogen fuel supply communication method according to an embodiment of the present invention and sub-components within the system / device.
[0098] Referring to FIG. 2, the dispenser (200) may include a controller (202) and a sensor (206). The controller (202) may generally be implemented as a Programmable Logic Controller (PLC) or by a device including electrical / electronic logic.
[0099] The controller (202) may include the aforementioned hydrogen fuel supply protocol (210) elements and communication device (204).
[0100] The sensor (206) on the dispenser (200) side can measure and detect the state information of the hydrogen supplied as fuel from the dispenser (200).
[0101] The mobility (100) may include an electronic control unit (ECU, 110) of a fuel supply system. The electronic control unit (110) may be connected to a hydrogen storage (102) on the mobility (100) side. The electronic control unit (110) may communicate with a communication device (114) and / or a sensor (116) on the mobility (100) side via an in-vehicle network.
[0102] The communication device (204) and the communication device (114) may be equipped with and operate communication software. A portion of the communication software may be implemented by being installed in the controller (202) of the dispenser (200) or in the network system and electronic control unit (110) of the mobility (100).
[0103] While the primary purpose of the communication software is network traffic management, it may also include a function to provide mobility data related to the hydrogen fuel supply process.
[0104] Data obtained from the sensor (116), etc. can be converted into a form suitable for transmission to the dispenser (200). Data obtained from the sensor (116), etc. can be transmitted to the dispenser (200) and used to control the hydrogen fuel supply process by the hydrogen fuel supply protocol (210) as shown in FIG. 1, and can also be used as a safety standard such as an emergency stop in emergency situations such as exceeding a limit temperature.
[0105] For active and efficient control, real-time measurement data obtained from the sensor (116) can be transmitted to the dispenser (200).
[0106] In this case, real-time measurement and / or real-time communication data can be classified into static data and dynamic data. Static data may include the capacity, configuration, or type of equipment of a storage tank that does not change over time, while dynamic data may refer to data such as temperature or pressure that may change during the fuel supply process.
[0107] Static data may include, for example, the volume of the tank of the mobility (100) or charging station (300), pressure rating, maximum allowable pressure, type of tank, number of tanks, size of tank, serial number of tank, manufacturer of tank, usage data of tank, permissible temperature range of hydrogen fluid in tank, etc.
[0108] Dynamic data may include, for example, fuel supply commands (e.g., start, stop, pause, abandon, increase flow rate, decrease flow rate, tank change commands, etc.), control parameters for fuel supply (e.g., Average Pressure Ramp Rate (APRR), Pressure Ramp Rate, etc.), real-time measurements of pressure and / or temperature within the tank, including fluctuations in temperature and / or pressure within the tank (which may indicate leakage and / or imminent failure), the State of Charge (SOC) of the tank at the filling station or mobility side, the ambient temperature outside the tank, and / or real-time measurements of the flow rate of hydrogen fluid entering the tank.
[0109] The communication process performed between the communication device (204) and the communication device (114) using communication software, etc., may include an embodiment for exchanging information about the following situations.
[0110] (1) No communication situation: When the mobility (100) or charging station (300) is not equipped with a communication function, or the communication function is broken, or communication is impossible because the communication function is broken during fuel supply.
[0111] (2) Communication error: Although communication with the mobility (100) or charging station (300) is possible, if parts, sensors, or equipment operate abnormally and some of the data is missing or an error occurs
[0112] (3) Uncertified equipment, parts, or mobility: When communication with mobility (100) or charging station (300) is possible and data is collected normally, but the reliability of the transmitted data is low and verification is required or limited use is required.
[0113] (4) Communication protocol not certified: In cases where communication with mobility (100) or charging station (300) is possible but the communication method is not specified in the standard or is not certified in the relevant country, and thus safety, reliability, and stability are not ensured
[0114] In one embodiment of the present invention, an artificial neural network model is placed in a dispenser (200), and the hydrogen fuel supply process may be controlled based on static data and / or dynamic data using the artificial neural network model to improve the performance and efficiency of the hydrogen fuel supply process. The artificial neural network model may cooperate with the hydrogen fuel supply protocol (210) or assist in the control operation of the hydrogen fuel supply protocol (210).
[0115] FIG. 3 is a conceptual diagram illustrating functional blocks corresponding to procedures in a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0116] Referring to FIG. 3, the communication procedure for the hydrogen fuel supply process may include four procedure groups.
[0117] "UC" shown in Fig. 3 can be understood as an abbreviation for Use Case.
[0118] The connecting group (S400) may be a procedure group that includes communication connection operations between the mobility and the dispenser.
[0119] The connecting group (S400) may include a UC1-discovery and pairing procedure (S410), a UC3-communication security procedure (S420), and a UC5-communication protocol negotiation procedure (S430).
[0120] The initializing group (S500) may be a procedure group that includes operations for initialization and preparation processes before fueling hydrogen to the mobility from the dispenser.
[0121] The initialization group (S500) may include a UC6-fuel supply protocol negotiation procedure (S540) and a UC7-fuel supply parameter exchange procedure (S550).
[0122] The fueling group (S600) may be a procedure group that includes operations highly relevant to the process of fueling hydrogen to the mobility from a dispenser.
[0123] The fueling group (S600) may include UC8-safety check-in procedure (S660), UC10-monitoring and control procedure (S670), and UC11-safety check-out procedure (S680).
[0124] The closing group (S700) may be a procedure group that includes operations related to the cessation of hydrogen fuel supply or the termination of communication between the mobility and the dispenser.
[0125] The closing group (S700) may include UC12-termination procedure (S710), UC13-error handling procedure (S720), and UC14-emergency handling procedure (S730).
[0126] In the UC1-Discovery and Pairing Procedure (S410), a discovery and pairing operation may be included to enable the mobility and the dispenser to discover and identify each other. The mobility and the dispenser may exchange pairing messages containing information about each other, and the information exchanged between them included in the pairing messages may be utilized for the mobility and the dispenser to recognize each other's interoperability and / or compatibility. The information exchanged between them may be used in the UC5-Communication Protocol Negotiation Procedure (S430), UC6-Fuel Supply Protocol Negotiation Procedure (S540), UC7-Fuel Supply Parameter Exchange Procedure (S550), UC8-Safety Check-in Procedure (S660), UC10-Monitoring and Control Procedure (S670), and / or UC11-Safety Check-out Procedure (S680), etc. The information included in the pairing message and exchanged with each other can be reconfirmed in a subsequent procedure if necessary.
[0127] Pairing information may include a pairing ID. The pairing ID may be set independently on both the mobility (100) and the dispenser (200). In one embodiment of the present invention, the pairing ID may be generated for a single fueling session. A fueling session may refer to a series of processes in which communication is initiated as preparation for fueling, fueling proceeds, and communication is terminated when fueling is finished.
[0128] In one embodiment of the present invention, the pairing ID of the mobility (100) and / or dispenser (200) may be generated individually for each fuel supply session.
[0129] In an alternative embodiment of the present invention, the pairing ID of the mobility (100) and / or dispenser (200) may be maintained for a certain period of time and maintained for a plurality of fuel supply sessions.
[0130] In the UC3-communication security procedure (S420), a communication channel with enhanced security features between the mobility and the dispenser can be established. In one embodiment of the present invention, subsequent communication procedures can be performed via the secure communication channel.
[0131] In the UC5-communication protocol negotiation procedure (S430), the communication protocol to be used for communication can be determined through negotiation between the mobility and the dispenser.
[0132] In the UC6-fuel supply protocol negotiation procedure (S540), a fuel supply protocol for the hydrogen fuel supply process can be determined through negotiation between the mobility and the dispenser.
[0133] In the UC7-fuel supply parameter exchange procedure (S550), detailed parameters under the fuel supply protocol can be exchanged and determined through negotiation between the mobility and the dispenser.
[0134] In the negotiation or exchange process of the UC5-communication protocol negotiation procedure (S430), the UC6-fuel supply protocol negotiation procedure (S540), and / or the UC7-fuel supply parameter exchange procedure (S550), the mobility and / or dispenser exchange negotiation request and / or response messages including a list of available or supportable protocols, and any one of the protocols in the list may be determined based on interoperability and / or compatibility.
[0135] At this time, the mobility and / or dispenser may transmit a list of protocols or parameters including preferences or priorities, and preferences or priorities may be considered when determining the protocol.
[0136] Preferences or priorities can be determined based on the safety, efficiency, and performance of the fuel supply process, user / mobility needs, the surrounding environment, constraints of the fuel supply process, etc.
[0137] In the UC8-Safety Check-in Procedure (S660), the contents of a predetermined checklist for safety may be checked before the hydrogen fuel supply process begins, including checking the coupling between the nozzle and receptacle between the dispenser and the mobility. At this time, information provided by sensors on the dispenser and / or mobility side may be used for the safety check-in.
[0138] In the UC10-monitoring and control procedure (S670), information for monitoring may be exchanged between the mobility and the dispenser while the hydrogen fuel supply process is in progress. The information exchanged may include information regarding whether the hydrogen fuel supply process is proceeding smoothly or as planned, and information that must be checked for safety between the mobility and the dispenser.
[0139] Recognition and determination of the state in which the hydrogen fuel supply is finished when the target charge rate (SoC) is achieved as a result of the hydrogen fuel supply process can also be performed in the UC10-monitoring and control procedure (S670).
[0140] In the UC11-Safety Check-out Procedure (S680), the contents of a predetermined checklist for safety may be checked before the physical separation process between the mobility and the dispenser after the hydrogen fuel supply process has been terminated.
[0141] The UC12-termination procedure (S710) may perform an operation for the termination of the hydrogen fuel supply process and / or communication channel when the target SoC is achieved by hydrogen fuel supply or when the hydrogen fuel supply process needs to be terminated for other reasons.
[0142] In the UC13-Error Handling Procedure (S720), non-critical errors may be handled. Based on the type and state of the error, it may be determined whether the hydrogen fuel supply process will be stopped and transitioned to the UC12-Termination Procedure (S710), or whether the hydrogen fuel supply process will be resumed after performing other logic.
[0143] In the UC14-Emergency Handling Procedure (S730), a critical error or emergency situation may be handled. In this case, the hydrogen fuel supply process may be stopped and transition to the UC12-Termination Procedure (S710).
[0144] In one embodiment of the present invention, interoperability and / or compatibility between mobility and dispenser may be determined based on detailed information included in pairing-related information exchanged in the UC1-Discovery and Pairing Procedure (S410).
[0145] In an alternative embodiment of the present invention, information for determining or updating interoperability and / or compatibility between mobility and dispenser may be additionally exchanged or supplemented in the UC5-communication protocol negotiation procedure (S430), UC6-fuel supply protocol negotiation procedure (S540), UC7-fuel supply parameter exchange procedure (S550), and / or UC8-safety check-in procedure (S660), etc.
[0146] For example, if renegotiation or re-determination is required due to changes in the communication environment, changes / errors in the performance and function of the communication channel, changes in the surrounding environment, changes in parameters affecting the fuel supply process, etc., pairing may be performed again or protocols / parameters may be renegotiated or determined in the UC5-communication protocol negotiation procedure (S430), UC6-fuel supply protocol negotiation procedure (S540), UC7-fuel supply parameter exchange procedure (S550), and / or UC8-safety check-in procedure (S660).
[0147] At this time, some procedures of the UC13-Error Handling Procedure (S720) may be used in the renegotiation / redecision process.
[0148] For example, communication protocols and fuel supply protocols are determined based on communication compatibility between mobility and dispenser, but if a state in which the performance or reliability of the communication channel is temporarily degraded is detected during the safety check-in step immediately before the hydrogen fuel supply process or during the hydrogen fuel supply process, the communication protocol and fuel supply protocol with backward compatibility within the previously exchanged list may fall back to, or alternative communication / fuel supply protocols may be negotiated / determined.
[0149] In one alternative embodiment of the present invention, when the previously selected best / most preferred protocol combination becomes incompatible or unusable in the combination of interoperable available protocols between mobility and dispenser, when determining an alternative next-best / next-best protocol combination, a combination in which the fuel supply protocol is changed while maintaining the same communication protocol as the existing best / most preferred protocol combination may be searched, or a combination in which the communication protocol is changed while maintaining the fuel supply protocol may be searched.
[0150] In one alternative embodiment of the present invention, when generating first interoperability information by searching for available protocol combinations in the UC1-Discovery and Pairing Procedure (S410), a priority can be determined in advance to prioritize cases where the communication protocol and the fuel supply protocol each match. For example, if a combination of communication protocol A1 and fuel supply protocol B1 is determined as the highest priority / best preference combination, combinations of fuel supply protocols B2, B3, ..., which can coexist with communication protocol A1 while maintaining communication protocol A1, can be designated in advance with high priority as alternative combinations for the highest priority / best preference combination. Alternatively, combinations of communication protocols A2, A3, ..., which can coexist with fuel supply protocol B1 while maintaining fuel supply protocol B1, can be designated in advance with high priority as alternative combinations for the highest priority / best preference combination.
[0151] As an alternative embodiment, for example, in the UC10-monitoring and control procedure (S670), if a change in the communication environment and a change in the fuel supply infrastructure are detected as a non-safety-critical error and the fuel supply is interrupted before the fuel supply is completed, the mobility and dispenser may re-perform some or all of the UC5-communication protocol negotiation procedure (S430), the UC6-fuel supply protocol negotiation procedure (S540), and / or the UC7-fuel supply parameter exchange procedure (S550).
[0152] Changes in the communication environment may include cases where the communication channel is disconnected.
[0153] Changes in the communication environment may include cases where the received data is not recognized, and cases where the received data is in an unacceptable range.
[0154] Changes in the communication environment may include cases where the quality of communication performance does not meet the required level.
[0155] Changes in the communication environment may include cases where the integrity or precision of data exchanged via communication does not meet the required level.
[0156] Changes in the fuel supply infrastructure may include cases where the fuel supply parameters on the mobility side change or remain in a state based on the control parameters for fuel supply on the dispenser side, but the level required for the change or maintenance of the fuel supply-related parameters on the mobility side is not met.
[0157] In one embodiment of the present invention, when the communication protocol or fuel supply protocol combination A falls back to combination B due to a temporary failure, the communication protocol or fuel supply protocol combination A can be restored.
[0158] In one embodiment of the present invention, the preference or priority of mobility or dispenser may be added to the list of fuel supply protocols. Available communication protocols may be added to the list of fuel supply protocols. Or, supported fuel supply protocols may be added to the list of communication protocols.
[0159] In the negotiation process of the communication protocol, the communication protocol may be determined based on the preference or priority of the fuel supply protocol, information on communication protocols supporting the fuel supply protocol, etc.
[0160] In an alternative embodiment of the present invention, some of the items to be checked in the UC8-Safety Check-in Procedure (S660) may be checked in the UC7-Fuel Supply Parameter Exchange Procedure (S550).
[0161] FIG. 4 is an operation flowchart conceptually illustrating the operation between functional blocks corresponding to procedures in a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0162] FIG. 5 is a diagram conceptually illustrating functional blocks corresponding to procedures in a hydrogen fuel supply communication method according to one embodiment of the present invention on an OSI 7 layer.
[0163] Referring to FIG. 4, the linkage or combination between function blocks corresponding to each procedure shown in FIG. 3 is illustrated.
[0164] Referring to FIG. 5, it is conceptually illustrated which layer of the OSI 7 layer each procedure illustrated in FIG. 4 is performed on.
[0165] Table 1 discloses the purpose, preconditions, and subsequent conditions of the UC1-Discovery and Pairing Procedure (S410).
[0166] TypeDescriptionUse case nameUC-1: "Discovery and Pairing"ObjectivesUC-1 allows devices to identify the communication counterparty (communication module of vehicle or dispenser) that is responsible for the control of the physically connected receptacle or nozzle, respectively. UC-1 also defines how to identify incompatibility and may define a failsafe mechanism.Short DescriptionDuring this use case, vehicle and dispenser try to find out any common communication technologies to run a fuelling protocol. Depending on the discovery mechanism provided by the underlying physical / data-link layer, the vehicle and dispenser discovers each other and start communication. To ensure that the communication channel is established with the devices that are bound to the fuelling hose assembly, extra pairing procedure may need to be involved. When communication channel does not guarantee the correct pairing (e.g., wireless communication), we may need an extra pairing channel that delivers pairing information. When pairing is implicitly guaranteed (e.g., communication integrated with hose assembly), only communication channel should be sufficient.Pre-conditionsThe dispenser nozzle is securely connected to the vehicle receptaclePost-conditionsVehicle and Dispenser knows what communication medium to use for the communication. After this use case, subsequent communication solely depends on the communication protocol that was agreed on in this use case. If an out-of-scope communication protocol is chosen, no further ISO 19985 communication is performed.
[0167] 표 2는 UC1-디스커버리 및 페어링 프로시져(S410)에서 이용될 수 있는, 지원되는 통신 기술(supported communication technologies) 및 각각의 clauses를 개시한다.
[0168] ClauseCommunication TechnologyCommunication ChannelPairing ChannelAnnex P.1Unidirectional irDA(irDA references)N / AAnnex P.2Bidirectional IrDA(irDA references)N / AAnnex P.3WLAN with NFCIEEE 802.11NFC Forum Specifications
[0169] Referring to FIGS. 4 and 5, the UC1-discovery and pairing procedure (S410) can be performed at the data link and physical layers.
[0170] In the UC1-Discovery and Pairing Procedure (S410), the mobility and the dispenser can exchange pairing IDs with each other and check or identify the other party's pairing ID.
[0171] The side initiating the pairing procedure among the mobility and the dispenser may broadcast a pairing request message containing its first pairing ID. The other party may send an acknowledgment for the pairing ID and its own second pairing ID as a pairing response message.
[0172] A list of supported fuel supply protocols and a list of communication protocols may be transmitted separately from, or together with, the pairing ID.
[0173] A session-specific randomized pairing ID can be used as the pairing ID included in the initial broadcast message. This approach resolves privacy concerns regarding the exchange of pairing IDs. In other words, trust in the pairing process is established by subsequent processes, and to this end, the session-specific pairing ID can be included in the data used to establish trust. This method is also referred to as the transmit-echo-verify method.
[0174] If secure communication is supported at a specific Use Classification of Communicated Data (UCDC) level, at least one of the mobility and / or dispenser can verify that for all methods used to pair the mobility and the dispenser, the pairing provides sufficient information to secure the communication channel. For example, the pairing may include the exchange of encryption keys so that the mobility and the dispenser can secure communication during refueling.
[0175] Since UCDC Level 1 does not support bidirectional communication, communication channel security may not be possible. Pairing mobility and dispensers at UCDC Level 2 and UCDC Level 3 may be implemented to provide sufficient information to protect communication in order to meet a specific security level, e.g., IEC 62443 Security Level 3. IEC 62443 Security Level 3 may be a security level for actors with appropriate resources and appropriate motives.
[0176] Table 3 discloses the purpose, preconditions, and subsequent conditions of the UC2-communication setup procedure (S415) of FIG. 4.
[0177] TypeDescriptionUse case nameUC-2: "Communication Setup"ObjectivesUC-2 allows the vehicle / mobility to setup the communication link with dispenser in network and transport layer. This includes IP address assignment, Dispenser's IP / port discovery and TCP link establishment.Vehicle / mobility sets up its IP address, obtain the IP address and port number of Dispenser, and establish a TCP connection with Dispenser.During this process, a paired status is also checked and / or confirmed.Short DescriptionAfter data-link is established, the vehicle / mobility first self-assigns its IP address according to SLAAC mechanism defined in IPv6. Once IP address is assigned, the vehicle / mobility broadcasts an inquiry message, which is replied by the dispenser with its connection information. The connection information includes the IP address and TCP & UDP port number of the dispenser.These inquiry and response messages also contain pairing IDs so that the vehicle / mobility and dispenser can confirm that they are talking to paired entities. Then vehicle / mobility initiates TCP handshake to make a reliable connection with the dispenser.Pre-conditionsData-link between vehicle / mobility and the dispenser is active.Post-conditionsPaired vehicle / mobility and dispenser established a TCP connection and the vehicle / mobility is ready to send a UDP packet when needed.
[0178] The pre-conditions of the UC2-communication setup procedure (S415) may include 1) that the physical & data link connection among the OSI-7 layers is completed, and 2) that initialized pairing is performed at the data link level, and 3) that the initialized pairing refers to the pairing between the communication module / device of the mobility (100) and the dispenser (200), respectively.
[0179] Referring to FIGS. 4 and FIGS. 5 together, the UC2-communication setup procedure (S415) can be performed at the network layer and the transport layer.
[0180] In one embodiment of the present invention, the process of obtaining network connection information including an IP address, etc., in the UC2-communication setup procedure (S415) may be performed at the physical layer, data link layer, etc., among the OSI layers.
[0181] In an alternative embodiment of the present invention, the process of obtaining network connection information including an IP address, etc., in the UC2-communication setup procedure (S415) can be performed by cooperation between the physical layer, data link layer, etc., among the OSI layers and a higher layer, for example, the application layer.
[0182] For example, DDP (Dispenser Discovery Protocol) request messages and / or DDP response messages may include IP addresses, pairing information, port information, etc., which can be exchanged and shared between the mobility (100) and the dispenser (200). In one embodiment, the DDP request message and / or DDP response message are generated based on the network layer and the transport layer, but the payload included in the DDP request message and / or DDP response message may include content defined or used at the application layer. In this case, the DDP request message and / or DDP response message may be understood as messages exchanged at the application layer.
[0183] In one embodiment of the present invention, the DDP request message and the DDP response message may be transmitted as UDP packets.
[0184] In one embodiment of the present invention, the DDP request message may include a pairing ID of the mobility (100). The mobility (100) may set a pairing ID to be included in the DDP request message. At this time, the pairing ID of the mobility (100) to be included in the DDP request message may be the same as the pairing ID (#1) determined in the UC1-Discovery and pairing procedure (S410), or it may be set as a new pairing ID (#2) based on the pairing ID (#1) determined in the UC1-Discovery and pairing procedure (S410).
[0185] In an alternative embodiment of the present invention, the DDP request message may further include network connection information such as the IP address of the mobility (100), UDP port number, and TCP port information.
[0186] Mobility (100) can send a DDP request message to the dispenser (200). As a response to the DDP request message, the dispenser (200) can send a DDP response message to the mobility (100).
[0187] The DDP response message may include the IP address of the dispenser (200) (e.g., IPv6 address), TCP port number, UDP port number, pairing ID of the dispenser (200), DDP result, etc.
[0188] The DDP result included in the DDP response message may include a verification result for the pairing ID of the mobility (100) included in the DDP request message. At this time, the pairing ID included in the DDP request message may be compared with the pairing ID (#1) that is determined in the UC1-Discovery and Pairing Procedure (S410) and provided to the dispenser (200) prior to the DDP request message. If the two pairing IDs obtained from the mobility (100) match as a result of the comparison, the pairing result may be indicated as OK.
[0189] In an alternative embodiment, the pairing ID (#2) of the DDP request message may be a pairing ID generated based on a predetermined rule using the pairing ID (#1) provided to the dispenser (200) prior to the DDP request message, which is determined in the UC1-Discovery and pairing procedure (S410). In this case, the dispenser (200) may verify whether the pairing ID (#2) of the DDP request message is a pairing ID generated based on a predetermined rule using the previously received pairing ID (#1), and include the result as a DDP result in the DDP response message.
[0190] The exchange of DDP request messages and DDP response messages may be a process distinct from the pairing confirmation process. However, in an alternative embodiment of the present invention, a role similar to pairing confirmation may be performed by the exchange of DDP request messages and DDP response messages.
[0191] In the UC2-communication setup procedure (S415), a communication pattern between the mobility (100) and the dispenser (200) can be defined.
[0192] As an example of a communication pattern, a synchronous communication pattern may be used in which a message transmitted by the mobility (100) is defined as a request message and a message transmitted by the dispenser (200) is defined as a response message, and the request message and the response message are exchanged with each other by a handshake. Under a synchronous communication pattern, the operation of the mobility (100) may be defined to wait for a response message until an appropriate response message for the request message is received.
[0193] Another example of a communication pattern is an asynchronous communication pattern in which either the mobility (100) or the dispenser (200) transmits the next message regardless of whether there is a response to the previously transmitted message.
[0194] Synchronous communication patterns can be used for operations such as negotiation, exchange, determination, and sharing of protocols, policies, parameters, or information.
[0195] Asynchronous communication patterns may be applied under limited conditions, such as transmitting status information during the fuel supply process periodically or non-periodically, or notifying the occurrence of an error.
[0196] The exchange of messages between the mobility (100) and the dispenser (200) can basically follow a synchronous communication pattern.
[0197] Mobility (100) and dispenser (200) can determine whether an asynchronous communication pattern is supported and available by exchanging messages with each other, or by logical determination of each entity regardless of message exchange. For example, whether an asynchronous communication pattern is supported and available can be determined based on information exchanged in the UC1-Discovery and Pairing Procedure (S410). Alternatively, whether an asynchronous communication pattern is supported and available can be determined based on matters defined in the communication protocol or fuel supply protocol determined by the UC5-Communication Protocol Negotiation Procedure (S430) or the UC6-Fuel Supply Protocol Negotiation Procedure (S540) to be described later.
[0198] In an alternative embodiment of the present invention, information regarding the communication pattern supported between the mobility (100) and the dispenser (200), the policy, conditions, environment, etc. determined in the UC2-communication setup procedure (S415), may be predefined or predetermined by the certificate, authentication information, pairing information, communication protocol, fuel supply protocol, etc. shared between the mobility (100) and the dispenser (200).
[0199] The purpose, preconditions, and subsequent conditions of the UC3-communication security procedure (S420) may be disclosed according to the following Table 4.
[0200] TypeDescriptionUse case nameUC-3: "Communication Security"ObjectivesVehicle / mobility and Dispenser establish a secure channel over the discovered communication channel to achieve communication security goals including confidentiality, integrity, and privacy.Short DescriptionAfter the physical and data-link layer connection is made between vehicle / mobility and dispenser, they setup layer-3 and establish a TCP connection (in UC-2), then perform a TLS handshake to authenticate and exchange keys to establish a secure communication channel. Then a DTLS handshake may be performed with binding to the established TLS session.Pre-conditionsVehicle and dispenser performed discovery and pairing use case successfully and made a data-link layer connection. Vehicle knows the connection information of Dispenser. Credentials necessary for the authentication and key exchange are prepared.Post-conditionsDispenser authenticated the vehicle and the vehicle authenticated dispenser successfully.Communication channel (both TCP and UDP comm. channel) between vehicle and dispenser are authenticated, encrypted and integrity protected.
[0201] Referring to FIGS. 4 and FIGS. 5 together, the UC3-communication security procedure (S420) can be performed at the security layer.
[0202] In the UC3-communication security procedure (S420), a TLS link can be established between the mobility (100) and the dispenser (200).
[0203] In one embodiment of the present invention, a DTLS channel may be further established based on a TLS link.
[0204] Mobility (100) can use UDP with DTLS for communication to support black channel communication. Black channel communication may refer to communication that applies the black channel principle, which ensures secure communication despite the output characteristics of a communication channel having unsecured attributes or attributes not related to the application.
[0205] The communication channel prior to and after the UC3-communication security procedure (S420) may be established using different communication technologies. For example, the UC1-discovery and pairing procedure (S410) may be performed via a first communication channel based on a first communication technology having a relatively wide range, including WLAN.
[0206] The sequence following the UC3-communication security procedure (S420) may be performed via a second communication channel based on a second communication technology that has a relatively narrow range but is strong in local communication.
[0207] The sequence following the UC3-communication security procedure (S420) may be performed partially via the first communication channel and / or the second communication channel based on shared information or required functions.
[0208] As illustrated in FIG. 4, the sequence following the UC3-communication security procedure (S420) can be performed by relying on the security communication channel set up / established in the UC3-communication security procedure (S420).
[0209] Referring to FIGS. 4 and FIGS. 5 together, the sequence following the UC3-communication security procedure (S420) performed at a higher layer above the security layer can be performed by relying on the security communication channel set up / established in the UC3-communication security procedure (S420).
[0210] The UC4-encoding and session management procedure (S425) can provide a method for managing the type and schema of application payloads / messages exchanged between the mobility (100) and the dispenser (200) so as to distinguish various fuel supply sessions and manage messages in a chronological order.
[0211] Table 5 discloses the purpose, preconditions, and subsequent conditions of the UC4-encoding and session management procedure (S425) of FIG. 4.
[0212] TypeDescriptionUse case nameUC-4: "Encoding and Session Management"ObjectivesUC-4 allows the vehicle / mobility and dispenser to exchange application payload in a coherent format, effectively switch between different types of messaging schema, and manage a fueling session so that different fueling sessions are distinguished and messages are managed in a chronical order.Short DescriptionOnce a secure communication channel is established, the vehicle / mobility and dispenser can exchange message payloads. To handle diverse nature of application messages, we use ASN.1 schemas with COER encoding rules to coherently express information in a modular way. The messages are encapsulated with a common message header so that devices can efficiently allocate resources to handle messages, and can distinguish different schemas. With session ID and time stamps in the session header, different sessions can be managed separately and chronical order of the messages are preserved.Pre-conditionsAn authenticated and encrypted communication link is established.Post-conditionsVehicle / mobility and dispenser can exchange application payloads using different ASN.1 schemas with session management and messaging time preservation.
[0213] Referring to FIGS. 4 and FIGS. 5 together, the UC4-encoding and session management procedure (S425) can be performed at the session layer and the presentation layer.
[0214] The UC4-encoding and session management procedure (S425) may propose a format including a header and message payload of an application payload / message exchanged between the mobility (100) and the dispenser (200), and provide a procedure for encoding a message to include the header and message payload.
[0215] In the UC4-encoding and session management procedure (S425), the mobility (100) and the dispenser (200) can determine the encoding technique of the message by exchanging messages with each other or by logical judgment of each entity regardless of message exchange.
[0216] For example, a policy determining which encoding scheme or encoding rules to use for which type of message may be determined based on information exchanged in the aforementioned UC1-Discovery and Pairing Procedure (S410). Alternatively, a policy determining which encoding scheme or encoding rules to use for which type of message may be determined based on matters defined in the communication protocol or fuel supply protocol determined by the UC5-Communication Protocol Negotiation Procedure (S430) or the UC6-Fuel Supply Protocol Negotiation Procedure (S540) described later.
[0217] In an alternative embodiment of the present invention, information for determining an encoding scheme / encoding rule according to the type or condition of a message supported between the mobility (100) and the dispenser (200) may be predefined or predetermined by a certificate, authentication information, pairing information, communication protocol, fuel supply protocol, etc. shared between the mobility (100) and the dispenser (200).
[0218] The encoding rules determined in the UC4-encoding and session management procedure (S425) can be defined based on a schema.
[0219] In the UC4-encoding and session management procedure (S425), encoding rules can be determined based on a schema that is predefined according to the message type.
[0220] Messages exchanged between the mobility (100) and the dispenser (200) in the UC5-communication protocol negotiation procedure (S430), UC6-fuel supply protocol negotiation procedure (S540), UC7-fuel supply parameter exchange procedure (S550), UC8-safety check-in procedure (S660), UC10-monitoring and control procedure (S670), UC11-safety check-out procedure (S680), UC13-error handling procedure (S720), and / or UC14-emergency handling procedure (S730) can be encoded according to the encoding rule determined in the UC4-encoding and session management procedure (S425).
[0221] Referring to FIGS. 4 and FIGS. 5 together, the messages exchanged between the mobility (100) and the dispenser (200) in the UC5-communication protocol negotiation procedure (S430), UC6-fuel supply protocol negotiation procedure (S540), UC7-fuel supply parameter exchange procedure (S550), UC8-safety check-in procedure (S660), UC10-monitoring and control procedure (S670), UC11-safety check-out procedure (S680), UC13-error handling procedure (S720), and / or UC14-emergency handling procedure (S730) described below are messages transmitted at the application layer. Messages transmitted from these application layers can be encoded according to encoding rules determined by the UC4-encoding and session management procedure (S425) implemented in the session layer and presentation layer.
[0222] A session identifier for identifying a fueling session may be assigned by the dispenser (200). The session identifier may be assigned after the communication protocol and the fueling protocol are determined by negotiation.
[0223] The message header may include a session identifier, a message identifier, a timestamp, and a signature information list.
[0224] In the UC5-communication protocol negotiation procedure (S430), an application layer protocol can be initiated and a communication protocol can be negotiated.
[0225] The purpose, preconditions, and subsequent conditions of the UC5-communication protocol negotiation procedure (S430) may be disclosed by the following Table 6.
[0226] TypeDescriptionUse case nameUC-5: "Communication Protocol Negotiation"ObjectivesVehicle and Dispenser determine which communication protocol to use throughout the fueling.Short DescriptionOnce TLS handshake is successfully finished, the vehicle and the dispenser negotiates on the communication protocol to use throughout the fuelling session. The negotiation starts when the vehicle sends a list of its supported protocols and then the dispenser picks a common protocol supported by both and the vehicle prefers the most.Pre-conditionsA secure authenticated communication channel is established using TLS 1.3.Post-conditionsThe vehicle and the dispenser reached an agreement on which communication protocol to use for their communication for fuelling session.
[0227] UC5-통신 프로토콜 협상 프로시져(S430)에서 협상 요청을 위하여 전송 및 수신되는 메시지의 내용은 다음의 표 7에 의하여 개시될 수 있다.
[0228] Element NameTypeSemanticsprotocolsCommProtocolTypeCommunication protocols supported by the vehicleCommProtocolTypeIndexUnsigned integerIndex of the protocolNameStringName of the protocolVerStringVersion of the protocolprefUnsigned integerPreference of protocols. Smaller number represents higher preference.
[0229] Information regarding the communication protocol may include at least one of the index of the communication protocol, the name of the communication protocol, the version of the communication protocol, and the preference for the communication protocol.
[0230] The content of the response message to the negotiation request message in the UC5-communication protocol negotiation procedure (S430) can be disclosed according to the following Table 8.
[0231] Element NameTypeSemanticsIndexUnsigned integerOptional:Index of chosen protocolResultresultTypeResult of the protocol negotiation. 'OK' if successful. 'FAILED_INCOMPAT' otherwise.
[0232] The response message may further include information on whether the communication protocol negotiation was successful.
[0233] A communication protocol negotiation request message may include a list of communication protocols supported by the mobility (100), and a communication protocol negotiation response message may include information designating the result of the protocol negotiation and / or the protocol selected by the communication protocol negotiation. In this case, the information designating the selected protocol may be an index or ID of the selected protocol.
[0234] If a common communication protocol exists as a result of the communication protocol negotiation and a selected protocol exists, the result of the communication protocol negotiation may be included in the response message, such as 'OK', indicating success.
[0235] If, as a result of the communication protocol negotiation, no common communication protocol exists or no selected protocol exists, the result of the communication protocol negotiation may be included in the response message, such as 'Fail', indicating failure.
[0236] Mobility (100) and dispenser (200) can interact with each other based on various combinations according to hydrogen fuel supply communication standards, communication modes, fuel supply methods, communication levels, other parameters, etc.
[0237] Standards related to hydrogen fuel supply communication may include the SAE J2601 series, ISO 19885-3, ISO 19885-4, etc. Communication modes may include no comm., IrDA, XYZ (ISO), etc. Fuel supply methods may include table-based fuel supply methods such as lookup tables, MC formula-based fuel supply methods, etc. Communication levels may include UCDC levels, and other parameters may include pressure class, CHSS (compressed hydrogen storage system) category, hydrogen fuel supply tables, etc.
[0238] The mobility (100) or dispenser (200) may further perform a process of falling back to the other party's lower type or lower UCDC level according to the mutual type or UCDC level confirmed in the communication protocol negotiation procedure.
[0239] In an alternative embodiment, if incompatibility is detected in the parameters exchanged while the mobility (100) and the dispenser (200) are performing negotiation procedures (UC5 to UC7) for hydrogen fuel supply, they may return to the communication protocol negotiation procedure and perform the negotiation procedures again.
[0240] Mobility (100) can assign priority to the communication protocols it supports. Mobility (100) can provide the communication protocols assigned priority to the dispenser (200). An example of the communication protocols assigned priority is shown in Table 9 below.
[0241] Protocol IDPrioritySAE J2601 - No comm.7SAE J2799 - IrDA6SAE J2601 - IrDA5ISO 19885-3-2023-UCDC-04ISO 19885-3-2023-UCDC-13ISO 19885-3-2023-UCDC-22ISO 19885-3-2023-UCDC-31
[0242] The dispenser (200) selects a specific protocol (<selected protocol> A response message including ) can be transmitted to the mobility (100). The specific protocol may be a common protocol selected by the dispenser (200), which is supported by both the dispenser (200) and the mobility (100) and is the highest priority protocol preferred by the mobility (200), such as the ISO 19885-3-2023-UCDC-3 protocol (see Table 9).
[0243] By using a common protocol, the mobility (100) and the dispenser (200) can reach an agreement on the communication protocol to be used for fueling communication.
[0244] When a communication protocol is selected in the UC5-communication protocol negotiation procedure (S430), the mobility (100) and the dispenser (200) can activate their respective communication protocol implementations and start the UC6-fuel supply protocol negotiation procedure (S540). The UC6-fuel supply protocol negotiation procedure (S540) is a procedure in which the mobility (100) and the dispenser (200) find and agree on a fuel supply protocol to use in a fuel supply session. In these steps, the mobility (100) and the dispenser (200) can select the communication protocol most preferred by the mobility (100) from among the protocols that both support.
[0245] That is, in the process of negotiating communication protocols and / or fuel supply protocols, if there are multiple protocols that are commonly supported by the mobility (100) and the dispenser (200), the dispenser (200) can select the protocol that the mobility (100) has designated as having the highest priority or preference.
[0246] The purpose, preconditions, and subsequent conditions of the UC6-Fuel Supply Protocol Negotiation Procedure (S540) may be disclosed by the following Table 10.
[0247] TypeDescriptionUse case nameUC-6: "Fueling Protocol Negotiation"ObjectivesVehicle and Dispenser determine which fueling protocol to use for the fuelling.Short DescriptionOnce communication protocol selection is done, the vehicle and the dispenser negotiates on the fueling protocol to use for the fuelling. The negotiation starts when the vehicle sends a list of its supported protocols and then the dispenser picks a common protocol supported by both and the vehicle prefers the most.Pre-conditionsA communication protocol specification is selected.Post-conditionsThe vehicle and the dispenser reached an agreement on which fueling protocol to use for their fuelling.
[0248] The content of the message transmitted and received as a negotiation request message in the UC6-Fuel Supply Protocol Negotiation Procedure (S540) may be disclosed according to the following Table 11.
[0249] Element NameTypeSemanticsfuelProtsFuellingProtocolTypeFuelling protocols supported by the vehicleFuellingProtocolTypeidxUnsigned integerIndex of the protocolNameStringName of the protocolVerStringVersion of the protocolsubprotStringOptional: Name of the sub-protocolprefUnsigned integerPreference of protocols. Smaller number represents higher preference.
[0250] Information regarding the fuel supply protocol may include at least one of the index of the fuel supply protocol, the name of the fuel supply protocol, the version of the fuel supply protocol, the sub-protocol of the fuel supply protocol, and / or preference for the fuel supply protocol.
[0251] The contents of the response messages transmitted and received as negotiation response messages in response to a negotiation request in the UC6-fuel supply protocol negotiation procedure (S540) may be disclosed according to the following Table 12.
[0252] Element NameTypeSemanticsIndexUnsigned integerOptional:Index of chosen protocolResultEnumerationResult of the protocol negotiation. 'OK' if successful. 'FAILED_INCOMPAT' otherwise.
[0253] The response message may further include information on whether the fuel supply protocol negotiation was successful.
[0254] In another embodiment of the present invention, the content of the message transmitted as a negotiation request message in the UC6-fuel supply protocol negotiation procedure (S540) may be disclosed as shown in Table 13 below.
[0255] IndexNameRevisionSub-protocolPreference1PRHYDE2023TYPE3-T-initial42PRHYDE2024TYPE3-T-Special33RTR-HFP24ANN-MPC55HMC-FAST1.01
[0256] As shown in Table 13, mobility (100) can provide the dispenser (200) with parameter information in the form of a table, which includes a name arbitrarily assigned to a supported fuel supply method or fuel supply protocol, revision time (year) or version information, information on whether a sub-protocol is provided, and preference information.
[0257] A fuel supply protocol negotiation request message may include a list of fuel supply protocols supported by the mobility (100), and a fuel supply protocol negotiation response message may include information designating the result of the protocol negotiation and / or the protocol selected by the fuel supply protocol negotiation. In this case, the information designating the selected protocol may be an index or ID of the selected protocol.
[0258] If, as a result of the fuel supply protocol negotiation, a common fuel supply protocol exists and a selected protocol exists, the result of the fuel supply protocol negotiation may be included in the response message, such as 'OK', indicating success.
[0259] If, as a result of the fuel supply protocol negotiation, no common fuel supply protocol exists or no selected protocol exists, the result of the fuel supply protocol negotiation may be included in the response message, such as 'Fail', indicating failure.
[0260] In another embodiment of the present invention, the dispenser (200) may proactively exchange its communication protocols and parameters with the mobility (100) on behalf of the mobility (100), and may provide the communication protocols supported by the dispenser (200) to the mobility (100) by giving priority to them.
[0261] In Table 13, PRHYDE (PRotocol for heavy-duty HYDrogEn refueling) may be presented by one of the European projects that has been developing a heavy-duty mobility refueling protocol, RTR-HFP may be presented by a protocol concept that improves refueling efficiency based on real-time communication, and ANN-MPC may be presented by a protocol concept that collects and analyzes data from the refueling site and predicts and applies it to the actual refueling situation.
[0262] Certain fueling protocols can be performed on a non-communicative basis. Unidirectional IrDA may be required for other fueling protocols to be executed. Bidirectional communication may be required for yet another fueling protocol to be executed. Both bidirectional communication and unidirectional IrDA may be required for yet another fueling protocol to be executed.
[0263] In order for a specific fuel supply protocol to be executed, a certain UCDC level or a higher UCDC level may be required in relation to the communication protocol. At least one fuel supply protocol may be proposed based on the type or class of the mobility (100) and the type or class of the dispenser (200). The proposed fuel supply protocols may be proposed with different priorities. Considering the priorities of the proposed fuel supply protocols, the communication protocol and fuel supply protocol between the hydrogen mobility (100) and the dispenser (200) may ultimately be determined based on whether the communication protocol required by the fuel supply protocol is supported by the hydrogen mobility (100) and / or the dispenser (200).
[0264] Tables 14 through 17 disclose parameters included in messages exchanged between mobility (100) and dispenser (200) in the UC7-fuel supply parameter exchange procedure (S550).
[0265] Table 14 is an example of parameters for the mobility (100) side.
[0266] NameUnitPrecisionRange / ValuesTypeSemanticsPressure ClassN / AN / A{H35, H70}StaticPressure classof the tankCHSS VolumeLiter2 decimalsPositive, No-maxStaticVolumeof the tankCHSS PressureMPa2 decimalsPositive, No-maxDynamicCurrent pressureof the tankEmergency PolicyN / AN / A{Terminate,Fallback}StaticEmergency handling policy
[0267] Table 15 is an example of parameters for the dispenser (200).
[0268] NameUnitPrecisionRange / ValuesTypeSemanticsFueling Delivery TemperatureN / AN / A{H35, H70}Static...FuelingTemperatureMPa2 decimalsPositive, No-maxDynamicCurrent pressureof the tankEmergency PolicyN / AN / A{Terminate,Fallback}StaticEmergency handling policy
[0269] Table 16 is another example of parameters on the mobility (100) side.
[0270] Physical ParametersReceptacle Type?Pressure ClassH35 / H70CHSS CategoryA / B / C / DCHSS Type1 / 2 / 3 / 4CHSS Volume? LMaximum allowed CHSS Pressure? MPaMaximum allowed BHSS temp.? ℃Maximum allowed flow rate? g / sMonitoring ParametersCurrent CHSS Pressure? MPaCurrent CHSS Temp.? ℃Safety PolicyEmergency Policy?Safety Enforcement Level?AcceptanceAcceptedTRUE / FALSE / PENDING
[0271] Table 17 is another example of parameters on the dispenser (200) side.
[0272] Physical ParametersFueling Delivery temp.T30Max Fuel Delivery Pressure? MPaMax Fuel Delivery Temp.? ℃Min Fuel Delivery Temp.? ℃Mas Fuel Delivery Flow Rate? g / sMonitoring ParametersCurrent Fuel Delivery Temp.? ℃Ambient Temperature? ℃Fueling GoalSelected Fueling TableD1Target SoC? %Target Final CHSS Pressure? MPaTarget Final CHSS Temperature? ℃Target APR? MPa / sAllowed Temperature? ℃Expected Fueling Duration? sSafety PolicyAcceptanceAcceptedTRUE / FALSE / PENDING
[0273] In the UC7-fuel supply parameter exchange procedure (S550), the mobility (100) and the dispenser (200) can generate a message with ranges / values for fueling parameters and transmit it to the other party.
[0274] The parameters may include physical characteristic-related parameters (briefly 'physical parameters'), monitoring parameters, safety policy-related parameters, acceptance-related parameters, etc. The aforementioned parameters may each be configured with information regarding one of the preset levels or set values and information regarding different or identical main UCDC levels.
[0275] The negotiation process of the UC5-communication protocol negotiation procedure (S430), the UC6-fuel supply protocol negotiation procedure (S540), and / or the UC7-fuel supply parameter exchange procedure (S550) may not be completed with a single message exchange, but may be completed by repeatedly exchanging messages multiple times.
[0276] At this time, for the protocols / parameters / items for which negotiation has been completed, in the transmitted message <accepted> , <true>, or <ok>Mark with , and for parameters / items currently under negotiation <pending>By indicating the above, the negotiation can be reached sequentially.
[0277] Parameters / items that are rejected or unusable during negotiation <rejected>, or <false>It can be excluded from the negotiation process by being marked as such.
[0278] Mobility (100) and dispenser (200) can reach an agreement on all parameters by repeatedly sending and receiving messages and responding to the messages.
[0279] In another embodiment of the present invention, each message including fuel supply parameters may be configured to be considered as not having reached an agreement if a response message is not received within a preset message processing time.
[0280] The purpose, preconditions, and subsequent conditions of the UC8-Safety Check-in Procedure (S660) may be disclosed by the following Table 18.
[0281] TypeDescriptionUse case nameUC-8: "Safety Check-in"ObjectivesVehicle and Dispenser confirms that all the necessary safety conditions are met and the communication link is correctly paired with the pairing channel before actual fuelling is started.Short DescriptionOnce fuelling parameters are exchanged and vehicle and dispenser are considered compatible, vehicle and dispenser performs safety condition checks and pairing checks to make sure the fuelling is safe and the communication is reliable. Depending on the fuelling protocol and the communication physical layer, the safety checks can be implicitly done within the protocol or physical association and this step may be omitted.Before starting the fueling, Vehicle and Dispenser verify safety conditions and pairing status to make sure the fuelling is safe and the communication is reliable.Pre-conditionsNecessary fuelling parameters are exchanged.Post-conditionsThe vehicle and the dispenser confirmed all the safety conditions and correctness of the pairing, and ready to begin fueling.
[0282] Before the hydrogen fuel supply process begins, the UC8-Safety Check-in Procedure (S660) may be performed to check whether all safety conditions of the mobility (100) and dispenser (200) are met. This step may be optional. Whether the UC8-Safety Check-in Procedure (S660) is mandatory may be defined by the fuel supply protocol. A dedicated safety check-in procedure may be defined in the fuel supply protocol to ensure the desired level of safety in an accurate and explicit manner.
[0283] If the UC5-communication protocol negotiation procedure (S430), the UC6-fuel supply protocol negotiation procedure (S540), and / or the UC7-fuel supply parameter negotiation procedure (S550) are successfully performed, the fuel supply protocol may perform the UC8-safety check-in procedure (S660).
[0284] In the UC8-Safety Check-in Procedure (S660), safety check-in is performed, and pairing can be performed again.
[0285] In this case, if the physical layer for communication is specified to require a pairing procedure, the mobility (100) and the dispenser (200) can re-check the pairing before dispensing hydrogen in the UC8-safety check-in procedure (S660).
[0286] Even if the physical layer for communication is not specified to require a pairing procedure, the mobility (100) and the dispenser (200) can re-check the pairing before dispensing hydrogen in the UC8-safety check-in procedure (S660).
[0287] When fuel supply parameters are exchanged and mobility (100) and dispenser (200) are considered compatible, at step S660, mobility (100) and dispenser (200) can perform a safety status check to verify whether the fuel supply is safe. In an alternative embodiment of the present invention, the safety check may be performed implicitly within the protocol according to the fuel supply protocol, and depending on the implementation, the explicit safety check step (S660) may be omitted.
[0288] Mobility (100) or dispenser (200) can send a request message to the other party signifying the initiation of a safety check-in, and the other party can respond with a response message to the safety check-in request message within a predetermined time interval.
[0289] In the safety check-in step (S660), the mobility (100) and / or dispenser (200) can check whether the nozzle-receptacle is secured (this may be referred to as a coupler check), check for leaks, and check the last-minute status.
[0290] In the safety check-in step (S660), the mobility (100) and / or dispenser (200) may exchange messages containing information indicating the inspection target (e.g., coupler, leakage, the last-minute status), the inspection result / status (OK / DONE / pending / ongoing / waiting / FAIL), and the inspector (mobility (100) or dispenser (200)). Here, "waiting" may refer to a state of waiting for an inspection result from the other party.
[0291] Depending on the inspection target, additional information may be included in the message or additional information may be requested. For example, when the leak inspection is completed, the dispenser (200) may send a message to the mobility (100) requesting the measured tank volume along with the leak inspection completion information (Done).
[0292] Additionally, the dispenser (200) can transmit a message for an immobilized status check to the mobility (100), and the mobility (100) can transmit a message to the dispenser (200) indicating that it is ready for a status check.
[0293] In this way, when the mobility (100) reports parameters regarding the current state or immobilization status of the mobility (100) to the dispenser (200), the dispenser (200) can report parameters regarding the coupler lock status, leak check status, predicted mobility tank capacity, etc. to the mobility (100).
[0294] In the UC8-Safety Check-in Procedure (S660), the pairing information exchanged between the mobility (100) and the dispenser (200) in the preceding step (S410) can be confirmed.
[0295] At this time, it can be verified whether the fuel supply channel connected to the nozzle and the receptacle, the pairing channel where pairing information is shared (which may include a near-field communication medium such as RFID or NFC), and the pairing information shared via a wireless communication channel all match.
[0296] In the aforementioned step (S410), pairing information can be shared by at least one of the fuel supply channel, pairing channel, or wireless communication channel, and whether the pairing information matches can be verified.
[0297] In the UC8-Safety Check-in Procedure (S660), whether the pairing information shared in the aforementioned step (S410) matches can be confirmed once again via at least one of the fuel supply channel, the pairing channel, or the wireless communication channel.
[0298] At this time, the pairing information confirmed in the UC8-Safety Check-in Procedure (S660) may be exactly the same as the pairing information verified in the aforementioned step (S410), or additional proofs may be included for verification. That is, the pairing ID and pairing proofs that are the subject of verification may be exchanged as pairing information, and the pairing proofs are generated based on the pairing ID and may be used to confirm the pairing ID.
[0299] According to one embodiment of the present invention, physical pairing based on the physical properties of hydrogen supplied via a fuel supply channel in the UC8-safety check-in procedure (S660) may be utilized. For physical pairing, hydrogen may be injected into the fuel supply channel to form a pressure greater than a predetermined threshold. This process of forming pressure by hydrogen injection may be referred to as pressurization, and pressurization may be performed by injecting hydrogen from the dispenser (200) into the mobility (100) for the UC8-safety check-in procedure (S660) prior to hydrogen fuel supply.
[0300] The UC9-safety-critical communication procedure (S665) can provide a communication environment for transmitting and receiving safety-critical dynamic data using a black channel, etc., after confirming that safety conditions are met before hydrogen fuel supply begins.
[0301] Table 19 discloses the purpose, preconditions, and subsequent conditions of the UC9-safety-critical communication procedure (S665) of FIG. 4.
[0302] TypeDescriptionUse case nameUC-9: "Safety-critical Communication"ObjectivesAfter vehicle / mobility and dispenser is ready for fueling, if the fueling communication contains safety-critical dynamic data to be exchanged (e.g., UCDC-3), this use case achieves a reliable communication using a safety-critical messaging (communication) layer with black-channel assumption. This use case is optional and only applies to UCDC-3.Short DescriptionSince the delivery failure of the safety-critical dynamic data (e.g., temperature and pressure) with the UCDC-3 communication can lead to safety-critical incidents, vehicle / mobility and dispenser enables safety communication layer for safety-critical data.Vehicle / mobility and dispenser switches to UDP / DTLS and achieve reliable communication by Safety-critical Messaging Protocol (SMP) or the safety communication layer that resides between security layer and session layer.The SMP or safety communication layer addresses various reliability concerns such as corruption, loss, reordering, delay, redundancy, insertion, masquerade, and wrong addressing.Pre-conditionsVehicle / mobility and dispenser are ready to begin fueling in a safe status.Post-conditionsVehicle / mobility and dispenser can exchange their fueling messages in a secure and reliable manner.
[0303] The UC9-safety-critical communication procedure (S665) may provide a sequence that can switch to or utilize the UDP / DTLS protocol to implement the Safety-critical Messaging Protocol (SMP) or safety communication layer between the security layer and the session layer. Referring to FIGS. 4 and FIGS. 5 together, the UC9-safety-critical communication procedure (S665) may establish a safety communication layer dedicated to safety-critical communication between the security layer and the session layer.
[0304] If the communication protocol supports the UCDC-3 level, the UC10-monitoring and control procedure (S670) can be performed through an application layer implemented based on the safety communication layer established in the UC9-safety-critical communication procedure (S665). In this case, the UC10-monitoring and control procedure (S670) can transmit and receive messages containing status information and data on the mobility (100) and / or dispenser (200) side related to the hydrogen fuel supply process.
[0305] In the UC10-monitoring and control procedure (S670), the mobility (100) and / or dispenser (200) can monitor the fuel supply status and control the fuel supply as needed. Once all safety checks are verified, the mobility (100) and the dispenser (200) can start fueling according to a selected fuel supply protocol using given parameters. While fueling, the mobility (100) and the dispenser (200) can operate to determine the fuel supply status by exchanging various measurement data and to detect the occurrence of a safety-critical accident as quickly as possible.
[0306] The purpose, prerequisites, and subsequent conditions of the UC10-monitoring and control procedure (S670) may be disclosed by the following Table 20.
[0307] TypeDescriptionUse case nameUC-10: "Fuelling control and monitoring"ObjectivesVehicle and Dispenser monitors the fuelling status and control the fuelling if necessary.Short DescriptionOnce all the safety checks are confirmed, the vehicle and dispenser starts the fuelling according to the chosen fuelling protocol with given parameters. During the fuelling, vehicle and dispenser exchange various measured data to understand the fuelling status and detect any safety-critical incidents as early as possible. Vehicle can also submit certain commands to dispenser to control the fuelling procedure, such as starting and ending the fuelling.To support black-channel communication, UDP with DTLS is used for the communication.Pre-conditionsAll the safety checks are confirmed and vehicle and dispenser are ready to fuel.Post-conditionsThe fuelling is finished successfully.
[0308] UC8-세이프티 체크 인 프로시져(S660)가 성공적으로 수행되면, 연료공급 프로토콜에 기반하여 UC10-모니터링 및 제어 프로시져(S670)가 수행될 수 있다.
[0309] If the UC8-Safety Check-in Procedure (S660) is omitted, and the UC7-Fuel Supply Parameter Exchange Procedure (S550) is successfully executed, the UC10-Monitoring and Control Procedure (S670) can be executed based on the fuel supply protocol.
[0310] While the UC10-monitoring and control procedure (S670) is being performed, the dispenser (200) can perform all necessary steps to fuel hydrogen to the mobility (100).
[0311] Additionally, the mobility (100) can transmit specific commands to the dispenser (200) to control fuel supply processes, such as starting and stopping fuel supply. At this time, the mobility (100) can use the aforementioned black channel communication.
[0312] Static data or dynamic data included in the message to be transmitted from the UC10-monitoring and control procedure (S670) based on the fuel supply protocol may be specified. In this case, the static data or dynamic data may be defined to monitor the fuel supply status and exchange safety-related information.
[0313] In the UC10-monitoring and control procedure (S670), a DTLS protocol can be set up if necessary.
[0314] The contents of the messages transmitted and received in the UC10-monitoring and control procedure (S670) may be disclosed according to the following Tables 21 and 22.
[0315] Element NameTypeSemanticsactionactionTypeOptional:Action that Vehicle requests to Dispenser.- start- stop- (Any custom actions defined by fuelling protocol)reasonreasonTypeOptional:Reason for why the "action" is requested.
[0316] Element NameTypeSemanticstatusstatusTypeOptional: - preparing- precooling- fuelling- standby- faulted- ramping-up- ramping-down- stopping- finished- stopped_error- stopped_requested- stopped_unknown- (Any custom status codes defined by fuelling protocol)reasonreasonTypeOptional:Reason for stopping when the fuelling is stopped abnormallyresultresultTypeResult of processing the request message. 'OK' if successful. 'FAILED' otherwise. See Table XYZ for the list of result codes.
[0317] Static and dynamic data transmitted from the UC10-monitoring and control procedure (S670) can be used to generate control information for the fuel supply process and to control the fuel supply process.
[0318] The dispenser (200) can send a message with the "status" set to "finished" when the fuel supply is completed (done) and the intended fuel supply goal is achieved.
[0319] The dispenser (200) can send a message in which, if fuel supply is stopped due to a reason related to an error, "status" is set to "stop_error" and "reason" is set to an appropriate reason code.
[0320] The dispenser (200) can send a message with the “status” set to “stopping” if the “action” of the most recent message sent from the mobility (100) is set to “stop” and the fuel supply has not been completely stopped.
[0321] The dispenser (200) can send a message with the “status” set to “stopped_requested” when the “action” of the most recent message sent from the mobility (100) is set to “stop” and the fuel supply has been completely stopped.
[0322] When Mobility (100) sends a FuelLoopReq message with "action" set to "stop" and receives a FuelLoopRes message with "status" set to "stopping", Mobility (100) can send a FuelLoopRes message with "action" set to "stop".
[0323] If a fatal safety incident occurs, the mobility (100) or dispenser (200) can immediately send an EmergencyReq message, stop the fuel supply procedure, and close the communication.
[0324] In one embodiment of the present invention, mobility (100) may request the start of step S670 and the dispenser may respond, but the concept of the present invention is not limited thereto. In an alternative embodiment of the present invention, either mobility (100) or the dispenser (200) may first transmit a message requesting the start of step S670, and the other party may respond to the message requesting the start of step S670, thereby performing step S670.
[0325] In step S670, a message transmitted by either the mobility (100) or the dispenser (200) may include a request for monitoring regarding the status of the hydrogen fuel supply procedure. A response message sent by the other party may include the requested monitoring target status information.
[0326] At this time, the state and related parameters that may be subject to a monitoring request may include a set of parameters exchanged in step S550. The state and related parameters that may be subject to a monitoring request may include the state and parameters of the mobility (100) or the dispenser (200). The state and related parameters that may be subject to a monitoring request may include the fuel supply state and / or related parameters of the mobility (100) and / or the dispenser (200) that are changed or maintained by a hydrogen fuel supply procedure.
[0327] Additionally, the status that may be subject to a monitoring request may include the status and / or information of the procedure itself in which fuel is supplied from the dispenser (200) to the mobility (100). For example, information may be included such as whether the fuel supply procedure is ongoing, paused, or terminated, and / or if it is stopped / terminated, whether it was stopped due to an error or finished due to the achievement of a goal.
[0328] Additionally, the mobility (100) can transmit a fueling control request message containing information to slow down the fuel supply or reduce the amount of fuel supplied to the dispenser (200), and the dispenser (200) can transmit a response message containing information indicating a decrease in the fueling status (e.g., slowing) to the mobility (100).
[0329] Additionally, the mobility (100) can transmit a fuel supply control request message requesting a stop to the dispenser (200), and the dispenser (200) can transmit a fuel supply status response message to the mobility (100) that includes information on stopping or stopping the fuel supply.
[0330] In step S670, the mobility (100) and the dispenser (200) may continuously or periodically exchange parameters related to the fuel supply status. The mobility (100) transmits the current tank temperature, current tank pressure, etc. to the dispenser (200), and the dispenser (200) may provide the mobility (100) with parameters related to fuel supply start, stop, ramping up, ramping down, current injection pressure, subsequent fuel supply plan, etc.
[0331] A request message related to control transmitted from the mobility (100) to the dispenser (200) may include information or parameters regarding the start, pause, resume, termination, etc. of the fuel supply. Additionally, a message related to reporting transmitted from the mobility (100) to the dispenser (200) may include information or parameters regarding the current tank temperature, current tank pressure, etc.
[0332] Messages related to reporting transmitted from the dispenser (200) to the mobility (100) may include information or parameters regarding status information, current ambient temperature, current pressure ramp rate (PRR [Mbar / min]), deliver fuel flow rate (g / sec]), current fuel delivery temperature, pre-cooling temperature, current fuel delivery pressure, whether in use before full charge (buffering), whether cooling dispenser is in use, whether fallback is in use, reason for fuel supply interruption, amount of currently fueled hydrogen, etc.
[0333] And, the message related to the target parameter update transmitted from the dispenser (200) to the mobility (100) may include information or parameters such as the target final tank pressure, target final tank temperature, target fuel supply APR, target SOC, current SOC, estimated remaining duration, etc.
[0334] According to one embodiment of the present invention, when a non-safety-critical error is detected in the UC10-monitoring and control procedure (S670) and the fuel supply is interrupted before the fuel supply is completed, the fuel supply protocol defines a fallback mechanism that ensures backward compatibility among mutually compatible mechanisms between the mobility (100) and the dispenser (200), and can resume and complete the fuel supply based on the fallback mechanism.
[0335] In this case, the fallback mechanism can be, for example, a non-communication fueling method.
[0336] After the hydrogen fuel supply process and the UC10-monitoring and control procedure (S670) are finished, and before terminating the session and unplugging the nozzle from the mobility (100), the mobility (100) and the dispenser (200) can verify through the UC11-safety check-out procedure (S680) that each of the mobility (100) and the dispenser (200) meets all safety conditions. The UC11-safety check-out procedure (S680) may be optional.
[0337] It is strongly recommended that the fuel supply protocol define a dedicated UC11-Safety Checkout Procedure (S680) to ensure the desired safety level in an accurate and explicit manner.
[0338] The purpose, preconditions, and subsequent conditions of the UC11-Safety Check Out Procedure (S680) may be disclosed by the following Table 23.
[0339] TypeDescriptionUse case nameUC-11: "Safety Check-out"ObjectivesVehicle and Dispenser confirms that all the necessary safety conditions are met before the nozzle can be detached from the receptacleShort DescriptionAfter the fueling has been finished, the vehicle and dispenser ensure that it is absolutely safe for the user or operator to unplug the nozzle from the vehicle. The vehicle and dispenser repeatedly report their condition until the safety checks are all. This use case may be omitted if the fueling protocol does not require such safety checks at the end.Pre-conditionsFuelling is finished.Post-conditionsIt is safe to unplug the nozzle from the receptacle.
[0340] The message transmitted and received between the mobility (100) and the dispenser (200) in the UC11-safety check-out procedure (S680) may be implemented by borrowing the content of a message that includes information indicating the inspection target (e.g., coupler, leakage, the last-minute status), inspection result / status (OK / DONE / pending / ongoing / waiting / FAIL), and the inspection subject (mobility (100) or dispenser (200)) initiated in the aforementioned UC8-safety check-in procedure (S660).
[0341] Mobility (100) and dispenser (200) can repeatedly report their respective status to each other until all safety checks are confirmed. If the hydrogen fuel supply communication bidirectional process does not require such safety confirmation at the end, the use case for safety checkout may be omitted.
[0342] When the coupler inspection completion information is confirmed to be successfully completed, the nozzle of the dispenser (200) can be separated from the receptacle of the mobility (100) by a user or operator.
[0343] In the UC11-safety check-out procedure (S680), the report message transmitted by the dispenser (200) to the mobility (100) may include information or parameters regarding the coupler unlock status. The coupler unlock status information may include information regarding locked, unlocked, icing, problem, etc.
[0344] The information exchange used in the UC11-Safety Check Out Procedure (S680) can be used for the purpose of diagnosing and identifying responsibility when a safety-related incident occurs.
[0345] Either the mobility (100) or the dispenser (200) may send a request message to the other party indicating the start of step S680, and the other party may respond with a response message to the request message for safe checkout within a predetermined time interval.
[0346] When fueling is successfully finished and optionally all safety conditions are confirmed, the mobility (100) and the dispenser (200) can perform the UC12-termination procedure (S710).
[0347] The purpose, preconditions, and subsequent conditions of the UC12-termination procedure (S710) may be disclosed by the following Table 24.
[0348] TypeDescriptionUse case nameUC-12: "Termination"ObjectivesAs the last step of fuelling, vehicle and dispenser finalizes the fuelling by exchanging information about fuelling results regarding fuelling performance and methods, and any reasons if the fuelling stopped unexpectedly. This use case also handles the house-keeping when a non-safety-critical problem occurred.Short DescriptionAfter the fuelling has been finished and safety checks are confirmed, vehicle and dispenser exchanges some book-keeping information regarding the fuelling session.When a non-safety-critical problem occurred, this use case allows the vehicle and dispenser to exchange wrap-up information about the fuelling session before leaving.Pre-conditionsThe fuelling is finished and the nozzle is safe to unplug.Or a non-safety-critical problem occurred during any other use cases.Post-conditionsInformation about the fuelling session is stored and the fuelling session is completely finished.
[0349] A message requesting the start of the UC12-termination procedure (S710) may include the contents disclosed in the following Table 25.
[0350] Element NameTypeSemanticstank_pressFinal tank pressuretank_tempFinal tank temperatureamountOptional:The amount of hydrogen that is fuelled.socOptional:The final state of charge from vehicle's measurementreasonTypeReason for termination from Vehicle's point of view. “finished” if dispenser indicated so. "stopped_user" if the user requested to stop. “complete” if the fueling goal is achieved. "unknown" otherwise. Other reason code can be defined by fueling protocol.
[0351] The content of the Terminate Res message responding to the Terminate Req message of Table 25 may be disclosed according to the following Table 26.
[0352] Element NameTypeSemanticsaprrOptional:Average Pressure Ramping RatedurationOptional:Duration of the fuellingamountOptional:The amount of hydrogen that is fuelled.socOptional:The final state of charge from dispenser's measurementresultresultType
[0353] In step S710, the mobility (100) may send a message to the dispenser (200) inquiring how much fuel has been supplied. The dispenser (200) may send a response message to the mobility (100) containing information about the amount of hydrogen supplied (e.g., X gram) in response to the query message of the mobility (100).
[0354] Mobility (100) can transmit a confirmed request message for the completion of fuel supply to the dispenser (200), and the dispenser (200) can transmit a good bye message to the mobility (100) as a response message to the confirmed request message.
[0355] After the fuel supply is completed and the safety check is confirmed, the mobility (100) and the dispenser (200) may exchange at least some book-keeping information regarding the fuel supply session of the hydrogen fuel supply at the termination step (S409). The mobility (100) and the dispenser (200) may exchange summary information regarding the fuel supply session of the hydrogen fuel supply before completing step S409.
[0356] Book-keeping information may include all information related to hydrogen fuel supply that is recorded in the mobility (100) or dispenser (200) according to preset rules or policies prior to completing step S409 over all fueling sessions for hydrogen fuel supply.
[0357] Ledger information or summary information may include information such as how much fuel has been supplied and what reports have been produced. Additionally, a report message transmitted from the mobility (100) to the dispenser (200) may include information or parameters regarding the current tank temperature and current tank pressure, and a report message transmitted from the dispenser (200) to the mobility (100) may include information regarding the final SOC, the final average fueling rate (APR), the final measured tank pressure, the actual fuel supply time, the actual amount of hydrogen supplied, etc.
[0358] Once all necessary information for the fuel supply session is saved, the fuel supply session can be completely terminated.
[0359] For successful refueling, communication must provide expected behaviors according to the protocol. Refueling behavior must remain within an acceptable range based on the refueling protocol. However, in reality, various abnormal events can occur. Some errors are minor and can be easily handled. However, errors that are unrecoverable and prevent the continuation of refueling may also occur.
[0360] In this specification, 'error' or 'error' may refer to an incident occurring during UC1 to UC9 or hydrogen fueling that can interrupt the ongoing process.
[0361] In the UC13-Error Handling Procedure (S720), non-critical errors may be handled. In this case, conditions for non-critical errors, exemplary error conditions, and responses may be specified.
[0362] The purpose, preconditions, and subsequent conditions of the UC13-Error Handling Procedure (S720) may be disclosed by the following Table 27.
[0363] TypeDescriptionUse case nameUC-13: "Error Handling"ObjectivesThis use case handles the situation when a non-safety-critical error occurred by terminating the fuelling procedure similar to normal terminations or abruptly stopping the communication.Short DescriptionAt any time during the fuelling, a non-safety critical error can occur. In this case, vehicle and dispenser stops the use case at the moment and then move to Termination use case (UC-9) to finish the fuelling procedure with both ends informed about the termination reasons. If further communication is not possible, the communication channel is dropped without further notification.Pre-conditionsA non-safety critical error occurred and fuelling cannot be performed further.Post-conditionsVehicle and dispenser is informed about the error and stopped the fuelling.
[0364] 안전에 치명적이지 않지만 수소 연료공급 프로세스에 영향을 줄 수 있는 non-safety-critical error 조건은 예를 들어 다음을 포함할 수 있다.
[0365] As a communication error, it may include 1) when communication is disconnected, 2) when the received data cannot be recognized due to an encoding or syntactic error, or 3) when the received data is in an unacceptable range.
[0366] As a system error, it may include cases where the dispenser or mobility detects its own critical system error.
[0367] Qualitative errors may include 1) cases where communication performance fails to meet the required level, and 2) cases where the quality of data integrity or precision fails to meet the required level.
[0368] When a non-safety-critical error occurs and further communication is impossible, the mobility and dispenser immediately stop the fueling and take safe steps, stop the communication, and end the session.
[0369] When a non-safety-critical error occurs and fuel supply is interrupted while far from completion, the fuel supply protocol can define a fallback mechanism, for example, by defining a non-communication fueling method.
[0370] When a non-safety-critical error is detected by the mobility and the communication channel is still operating, the mobility can send a TerminateReq message in which "action" is set to "stop" and "reason" is set to an appropriate reason code.
[0371] When a non-safety-critical error is detected by the dispenser and the communication channel is still operating, the dispenser may first immediately stop the fuel supply and send a TerminateReq message in which "action" is set to "stop" and "reason" is set to an appropriate reason code.
[0372] The fuel supply protocol can define error conditions according to the protocol and can provide detection criteria, and prescribe response procedures including notification, termination procedure, and fallback mechanism.
[0373] Step S720 defines error conditions related to the fuel supply protocol and provides detection criteria, and may include a response process including notification, termination process, and fallback mechanism when detected.
[0374] Step S720 may be applied in cases where a non-safety fatal error occurs and further communication is impossible. That is, the mobility and dispenser can handle a non-safety fatal error that may occur at any time during fuel supply in Step S720. In other words, the mobility and dispenser can immediately stop fuel supply, pause the previously operating use case, and then proceed to the termination use case (UC9, Step S710).
[0375] In step S720 according to an embodiment of the present invention, specific operations can be performed as follows (1) to (4) regarding the aforementioned error conditions.
[0376] (1) If a non-critical error occurs and further communication is impossible, the mobility and dispenser may immediately stop fuel supply, but take safe measures and stop communication to terminate the session.
[0377] (2) If a non-critical safety error occurs and the fuel supply is interrupted and the fuel supply is not completed, the fuel supply protocol may define a fallback mechanism, for example, by defining a non-communication fuel supply method.
[0378] (3) If a non-safety error is detected in the mobility and the communication channel is still operating, the mobility can send a termination request message to the dispenser with the “action” set to “stop” and the “reason” set to an appropriate reason code.
[0379] (4) If a non-safety error is detected by the dispenser and the communication channel is still operating, the dispenser may first immediately stop the fuel supply and send a termination request message to the mobility with "Operation" set to "Stop" and "Reason" set to an appropriate reason or reason code.
[0380] The purpose, prerequisites, and subsequent conditions of the UC14-Emergency Handling Procedure (S730) may be disclosed by the following Table 28.
[0381] TypeDescriptionUse case nameUC-14: "Emergency Handling"ObjectivesDefine safety-critical conditions that warrant an urgent response and prescribe the response procedure to avoid safety-critical incidents.Short DescriptionFor safe fueling, communication must exhibit expected behaviors according to the protocol and the fueling behavior must stay within the safe range of the fueling protocol. However, it is possible that something goes wrong and the fueling system approaches a critical condition that the system must avoid at all cost. In this use case, we define safety-critical emergency conditions and possible reactions, and provide exemplary cases to consider.Pre-conditionsA safety-critical problem occurred during any moment of fuelling and an urgent response is necessary.Post-conditionsSafety-critical incidents are avoided or minimized, and the fuelling session has been stopped completely.
[0382] The fuel supply protocol can define emergency conditions according to the protocol and can provide prescribe response procedures to avoid entering a detrimental situation by all means, including detection criteria, notification, termination procedure, and fallback mechanism.
[0383] When a mobility device or dispenser detects a safety-critical situation, necessary actions to prevent a catastrophic event can be performed immediately. Additionally, if possible, a message notifying of the emergency along with information about the event can be transmitted, and communication can be closed.
[0384] When the mobility or dispenser receives a message notifying of an emergency, it may immediately respond to the action instructed in the message and close the communication without undue delay.
[0385] For the criticality of the message and the efficiency of delivery, the fuel supply protocol may not be permitted to modify the structure of the message notifying of the emergency.
[0386] The names of elements included in the message notifying an emergency may include class, type, action, etc., and may be disclosed according to Table 29 below. Elements not shown in Table 29 below may be specified by each fuel supply protocol standard, such as, for example, ISO 19885-3. For example, additional emergency reason codes and action codes may be specified for each protocol.
[0387] Element NameTypeSemanticsclassunsignedByteOptional:Severity class of this emergency, from 1 to 5 with decreasing severity.typeunsignedByteEmergency reason code by number defined in Table XYZactionunsignedByteOptional:Pre-defined action code necessary or recommended to be performed by the receiving party
[0388] For safe fuel supply, communication must exhibit expected behavior according to the protocol, and the fuel supply operation must remain within the safe range of the fuel supply protocol. However, there is a possibility that a problem may occur during fuel supply, causing the fuel supply system (or hydrogen fuel supply system) to reach a critical state that must be avoided at all costs. Therefore, step S730 may define safety-critical emergency conditions and possible responses to such emergency conditions, and provide critical cases to be considered.
[0389] The fuel supply protocol may define emergency conditions related to the protocol, provide detection criteria and performance requirements, and define step S730 for responding to ensure that hazardous situations are not entered.
[0390] For example, if a high pressure condition exceeding a preset threshold is detected by the mobility while hydrogen fuel supply is in progress, the mobility can send an emergency request message to the dispenser requesting the suspension of fuel supply due to the high pressure.
[0391] In addition, for example, if a hydrogen fuel leak is detected by the dispenser, the dispenser can send an emergency request message to the mobility requesting the cessation of fuel supply due to the leak.
[0392] The content of the response message to the emergency request message can refer to the content defined in the emergency request message.
[0393] In each step of FIG. 4 that proceeds sequentially, when a preceding step is completed, a message indicating the initiation of a subsequent step may be transmitted within a predetermined time interval. For example, when a message indicating the completion of the UC7-fuel supply parameter exchange procedure (S550) is exchanged between the mobility and the dispenser, a message indicating the initiation of the UC8-safety check-in procedure (S660) may be transmitted from the mobility to the dispenser, or from the dispenser to the mobility, within a predetermined time interval.
[0394] FIG. 6 is an operation flowchart conceptually illustrating a secure communication procedure within a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0395] In the secure communication method illustrated in FIG. 6, the operation of the mobility (100) can be performed by the communication device (114) of the mobility (100), and the operation of the dispenser (200) can be performed by the communication device (204) of the dispenser (200).
[0396] Referring to FIG. 6, a communication method for hydrogen fuel supply according to an embodiment of the present invention is performed between a communication device (114) of a hydrogen fueled mobility (100) and a communication device (204) of a dispenser (200) that supplies hydrogen to the mobility (100), and comprises: a discovery and pairing step (UC1, S410) in which the mobility (100) and the dispenser (200) discover and pair each other; and a step (S1300) of performing authentication or authorization between the mobility (100) and the dispenser (200) based on dispenser authentication information transmitted from a hydrogen fueling operator (HFO) (350) associated with the dispenser (200) and provided from the dispenser (200) to the mobility (100), and mobility authentication information provided from the mobility (100). and may include a step (S1400) of establishing a secure communication channel between the mobility (100) and the dispenser (200) based on the result of authentication or authorization between the mobility (100) and the dispenser (200).
[0397] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, the step (S1300) of performing authentication or authorization between the mobility (100) and the dispenser (200) and the step (S1400) of establishing a secure communication channel between the mobility (100) and the dispenser (200) may be performed as part of a transport layer security (TLS) handshake procedure between the mobility (100) and the dispenser (200). In this case, the TLS handshake procedure may be performed as part of the aforementioned step S420.
[0398] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, the step (1300) of performing authentication or authorization between the mobility (100) and the dispenser (200) and the step (1400) of establishing a secure communication channel between the mobility (100) and the dispenser (200) may be performed using a security algorithm of a predetermined security level or higher.
[0399] At this time, the predetermined Security Level is 256 bits (>10 77 It may be. The security algorithm may use the ECC curve: sep521r1 as the public key algorithm. The signature algorithm may be the ECDSA algorithm. The certificate format may be X.509. The key exchange algorithm may be ECDHE. The encryption / integrity algorithm may be AES-256-GCM. The hash algorithm may be SHA256, SHA384, or SHA512, etc.
[0400] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, the dispenser authentication information may be distributed from the hydrogen fuel supply business operator (HFO) (350) to the dispenser (200) (S1140).
[0401] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, the dispenser authentication information may be generated by a trusted service provider associated with the hydrogen fuel supply business operator (HFO) (350) and transmitted to the dispenser (200) via the hydrogen fuel supply business operator (HFO) (350).
[0402] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, the mobility authentication information is transmitted from the original equipment manufacturer (OEM) (150) of the mobility (100) (S1120) and can be provided from the mobility (100) to the dispenser (200).
[0403] A communication method for supplying hydrogen fuel according to one embodiment of the present invention may perform at least one of steps S430, S540, S550, S660, S670, S680, S710, S720, and / or S730 based on the secure communication channel established in step S420 based on the result of authentication or authorization between the mobility (100) and the dispenser (200).
[0404] A communication method for hydrogen fuel supply according to one embodiment of the present invention may further include a step (S430, S540, or S550) of negotiating a communication protocol, a fuel supply protocol, or fuel supply parameters between the mobility (100) and the dispenser (200) based on the secure communication channel established in step S420 based on the result of authentication or authorization between the mobility (100) and the dispenser (200).
[0405] A communication method for hydrogen fuel supply according to one embodiment of the present invention may further include a step (S660) of checking in safety requirements before a hydrogen fuel supply process is started between the mobility (100) and the dispenser (200), based on the secure communication channel established in step S420 based on the result of authentication or authorization between the mobility (100) and the dispenser (200).
[0406] A communication method for hydrogen fuel supply according to one embodiment of the present invention may further include a monitoring step (S670) in which status information of the mobility side based on the hydrogen fuel supply process is provided while the hydrogen fuel supply process is performed between the mobility (100) and the dispenser (200), based on the secure communication channel established in step S420 based on the result of authentication or authorization between the mobility (100) and the dispenser (200).
[0407] FIG. 7 is an operation flowchart conceptually illustrating a secure communication method for hydrogen fuel supply according to one embodiment of the present invention.
[0408] Referring to FIG. 7, a communication method for hydrogen fuel supply according to one embodiment of the present invention may include a process of requesting and responding to authentication-related information of the other party between the mobility (100) or the dispenser (200).
[0409] A communication method for hydrogen fuel supply according to one embodiment of the present invention may further include the step (S1120) in which a first entity, which is either the mobility (100) or the dispenser (200), requests authentication-related information from a second entity, which is the counterpart, in order to establish the secure communication channel.
[0410] At this time, the step (S1120) of requesting authentication-related information of the second entity may be performed as part of a transport layer security (TLS) handshake procedure between the mobility (100) and the dispenser (200).
[0411] A communication method for hydrogen fuel supply according to one embodiment of the present invention may further include the step (S1160) in which the second entity requests authentication-related information of the first entity while responding with authentication-related information of the second entity (S1140).
[0412] At this time, the step (S1160) of requesting authentication-related information of the first entity can be performed as part of a transport layer security (TLS) handshake procedure between the mobility (100) and the dispenser (200).
[0413] In the embodiment of FIG. 7, an embodiment is shown in which the first entity is mobility (100) and the second entity is dispenser (200), but in an alternative embodiment of the present invention, the first entity may be dispenser (200) and the second entity may be mobility (100) as needed.
[0414] In one embodiment of the present invention, in order to respond in step S1140 to the authentication-related information of the second entity requested in step S1120, the second entity may provide the authentication-related information of the second entity, which is stored in advance, to the first entity in step S1140.
[0415] In an alternative embodiment of the present invention, in order to respond in step S1140 with the authentication information of the second entity requested in step S1120, the second entity may provide the authentication information of the second entity to the first entity in step S1140 through additional handshake communication with the OEM (150).
[0416] In one embodiment of the present invention, in order to respond in step S1180 with authentication-related information of the first entity requested in step S1160, the first entity may provide prior-stored authentication-related information of the first entity to the second entity in step S1180.
[0417] In an alternative embodiment of the present invention, in order to respond in step S1180 with the authentication-related information of the first entity requested in step S1160, the first entity may provide the authentication-related information of the first entity to the second entity in step S1180 through additional handshake communication with the HFO (350).
[0418] In the embodiments of FIGS. 6 and 7, HFO (350), dispenser (200), mobility (100), and OEM (150) may be part of an ecosystem for hydrogen fuel supply.
[0419] Certification information for authentication between the dispenser (200) and the mobility (100) in the ecosystem for hydrogen fuel supply can be generated by a trusted service provider. The trusted service provider may be an HFO (350) or an OEM (150), etc., or a specialized organization that handles certification information (certificates) as a third party.
[0420] Public and private keys may be used to generate and process authentication / authorization information. Authentication / authorization information may be generated, signed, and managed based on a hierarchical structure by one or more entities included within the ecosystem.
[0421] Information related to authentication / authorization can be classified into higher-level certificates and leaf certificates based on a hierarchical structure.
[0422] Information regarding the certification / authorization of the mobility (100) may have a specified validity period or life.
[0423] The process of generating, processing, and managing authentication / authorization-related information can be implemented based on the security provided by the Public Key Infrastructure (PKI).
[0424] PKI-based authentication / authorization / certification information provided by an ecosystem including HFO (350), dispenser (200), mobility (100), and OEM (150) can be used to establish a secure communication channel between mobility (100) and dispenser (200).
[0425] PKI-based authentication / authorization / proof information provided by an ecosystem including HFO (350), dispenser (200), mobility (100), and OEM (150) can be used in a separate authentication / authorization / verification process after the pairing step (S410).
[0426] FIG. 8 is an operation flowchart conceptually illustrating a part of a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0427] Referring to FIG. 8, the mobility (100) and the dispenser (200) can perform the UC1-discovery and pairing procedure (S410) by exchanging messages with each other.
[0428] The mobility (100) and dispenser (200) can perform the UC2-communication setup procedure (S415) after the UC1-discovery and pairing procedure (S410).
[0429] The mobility (100) and the dispenser (200) can perform the UC3-communication security procedure (S420) by exchanging messages with each other.
[0430] The UC1-Discovery and Pairing Procedure (S410), UC2-Communication Setup Procedure (S415), and UC3-Communication Security Procedure (S420) can be performed with reference to the embodiments of FIGS. 4 and 5. If necessary, the mobility (100) can transmit a request message for a predefined operation, and the dispenser (200) can transmit a response message to the request message.
[0431] The mobility (100) and the dispenser (200) can perform a communication step (S1500) for hydrogen fuel supply. At this time, the step (S1500) can be performed using a secure communication channel established in the UC3-communication security procedure (S420).
[0432] The mobility (100) and the dispenser (200) can perform a communication step (S1500) for hydrogen fuel supply by performing a step (S1600) of transmitting and receiving an encoded message.
[0433] The process of determining encoding rules based on the type of message, communication protocol, or fuel supply protocol, etc., can be performed by the UC4-encoding and session management procedure (S425) illustrated in FIGS. 4 and 5. At this time, the UC4-encoding and session management procedure (S425) can be performed in the session layer and presentation layer among the OSI layers.
[0434] Encoding rules can be defined as schema-based encoding.
[0435] The schema can be modularized into a common schema and a schema differentiated by hydrogen fuel supply protocol. In another embodiment, the schema can be modularized into a common schema and a schema differentiated by message type.
[0436] In another embodiment, the schema may be modularized into schemas differentiated by the type of content, payload, or data within the message.
[0437] The UC5-communication protocol negotiation procedure (S430), UC6-fuel supply protocol negotiation procedure (S540), UC7-fuel supply parameter exchange procedure (S550), UC8-safety check-in procedure (S660), UC10-monitoring and control procedure (S670), UC11-safety check-out procedure (S680), UC12-termination procedure (S710), UC13-error handling procedure (S720), and / or UC14-emergency handling procedure (S730), etc., illustrated in FIGS. 4 and 5, may be performed at the application layer depending on step (S1600).
[0438] FIG. 9 is an operation flowchart conceptually illustrating a part of a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0439] Referring together to FIG. 8 and FIG. 9, a communication method for hydrogen fuel supply according to one embodiment of the present invention is performed between a communication device (114) of a hydrogen fueled mobility (100) and a communication device (204) of a dispenser (200) that supplies hydrogen to the mobility (100), and comprises the steps of: establishing a secure communication channel between the mobility (100) and the dispenser (200) (S420); and generating a first message (request message) by schema-based encoding the payload and header of a message to be transmitted to the dispenser (200) (S1620) based on a schema determined according to the type of message to be transmitted to the dispenser (200) (SS1630). And the mobility (100) may include the step (S1640) of transmitting the first message (request message) to the dispenser (200) using the secure communication channel.
[0440] A communication method for hydrogen fuel supply according to another embodiment of the present invention is performed between a communication device (114) of a hydrogen fueled mobility (100) and a communication device (204) of a dispenser (200) that supplies hydrogen fuel to the mobility (100), wherein the dispenser (200) establishes a secure communication channel between the mobility (100) and the dispenser (200) (S420); and the dispenser (200) generates a response message for a first message by schema-based encoding the payload and header of a message to be transmitted to the mobility (100) based on a schema determined according to the type of message to be transmitted to the mobility (100) (S1660) (SS1670). and the dispenser (200) may include the step (S1680) of transmitting the response message to the mobility (100) using the secure communication channel.
[0441] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, the schema-based encoding (S1620, S1660) may be performed based on a schema determined based on a fuel supply protocol applied to the process of supplying hydrogen to the mobility and a type of message to be transmitted to the dispenser.
[0442] At this time, schema-based encoding (S1620, S1660) can be performed by a schema-based encoding rule defined or determined in the aforementioned UC4-encoding and session management procedure (S425).
[0443] In this case, message encoding rules support schema-based encoding and can be defined in a modular manner to ensure interoperability, extensibility, and message validation.
[0444] Message encoding rules can be defined, for example, based on Abstract Syntax Notation One (ASN.1) and may include encoding rules such as basic encoding rules (BER), distinguished encoding rules (DER), octet encoding rules (OER), packed encoding rules (PER), and canonical octet encoding rules (COER).
[0445] For example, if the message encoding rule is COER, the mobility or dispenser can encode the message based on COER and then transmit it.
[0446] Message encoding rules can be determined in advance based on the size of the message after encoding, the performance of communication based on the encoded message, etc.
[0447] Mobility (100) and dispenser (200) may share encoding rules and decoding rules based on a specific module (which may refer to encoding rules individually predefined for message types, fuel supply protocols, etc.). That is, a message is transmitted by an encoding rule defined in the encoding rule module to which the message belongs, and the receiving entity can decode the received message by a decoding rule defined in the encoding rule module.
[0448] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, whether a schema for a DDP message type is applied to the encoding of the first message and / or response message may be determined based on whether the type of message to be transmitted to the dispenser is a message for the Dispenser Discovery Protocol (DDP).
[0449] Schemas for message encoding rules can be defined individually or in a modular fashion depending on the message type. For example, a schema defined for messages of the DDP protocol can be applied to DDP request messages or DDP response messages and can have invariant-over-time characteristics.
[0450] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, whether a schema for a protocol negotiation message type is applied to the encoding of the first message and / or response message may be determined based on whether the type of message to be transmitted to the dispenser is a message for communication protocol negotiation or fuel supply protocol negotiation.
[0451] For example, a schema defined for a protocol negotiation message can be applied to communication protocol negotiation request messages, communication protocol negotiation response messages, fuel supply protocol negotiation request messages, fuel supply protocol negotiation response messages, etc., and can have the characteristic of being invariant over time.
[0452] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, whether a schema for a common or base message type is applied to the encoding of the first message and / or response message may be determined based on whether the type of message to be transmitted to the dispenser is a common or base message.
[0453] For example, a schema defined for common data type messages can be applied to common type messages, base message types, data messages such as temperature and pressure, etc., and can be defined based on conditions such as infrequent updates.
[0454] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, whether a schema for a signature message type is applied to the encoding of the first message and / or response message may be determined based on whether the type of message to be transmitted to the dispenser is a data signature message for end-to-end security.
[0455] For example, a schema defined for a data signature message can be applied to end-to-end security or data signature messages, etc., and can be defined based on conditions such as infrequent updates.
[0456] In one embodiment of the present invention, schemas and message encoding rules may be modularized and defined for each message type according to individual fuel supply protocols. Individual fuel supply protocols may refer, for example, to MC Formula High Flow [MCF-HF], Medium Flow-Twin-Lookup Table Method [MF-Twin-LF], Real-Time Responding Hydrogen Fuel Supply Protocol [RTR-HFP], Artificial Neural Network-based Model Predictive Control (ANN-MPC) Fuel Supply Protocol [ANN-MPC], Protocol for heavy-duty HYdrogEn refueling [PRHYDE], etc.
[0457] A communication method for hydrogen fuel supply according to one embodiment of the present invention may further include the step (S1680) in which the mobility receives the response message corresponding to the first message from the dispenser using the secure communication channel.
[0458] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, the process of supplying hydrogen to the mobility based on the exchange of the first message and the response message between the mobility and the dispenser may be prepared, monitored, controlled, or terminated.
[0459] A communication procedure for preparing, monitoring, controlling, or terminating the process of fueling hydrogen to mobility may refer to the aforementioned step (1500) and may be implemented by performing step (1600).
[0460] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, a schema for the protocol negotiation message type may be applied to the encoding of the first message when the first message is a message for communication protocol negotiation or fuel supply protocol negotiation.
[0461] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, a schema for the common or base message type may be applied to the encoding of the first message when the first message is a message for safety check-in, monitoring and control, safety check-out, termination, error notification, or emergency notification.
[0462] In a communication method for hydrogen fuel supply according to one embodiment of the present invention, a schema for the signature message type may be applied to the encoding of the first message when the first message is a message related to safety-critical static data in the process of fueling hydrogen to the mobility.
[0463] FIG. 10 is an operation flowchart conceptually illustrating a hydrogen fuel supply communication method according to one embodiment of the present invention.
[0464] In the present disclosure, various encoding techniques including binary encoding are proposed to improve communication performance (see Table 5 and FIG. 8-9).
[0465] Such message encoding is performed based on a modularized schema separated by message type, and for such modularized encoding, it is necessary to indicate that the separated schema is specific within the message. In this disclosure, an index or field indicating the schema applied within the message is proposed.
[0466] In addition, while compression performance can be improved by binary encoding the message, a method is proposed to indicate the size of the message itself or the size of the payload in the message to overcome the constraints on memory utilization for storing the message.
[0467] Referring together to FIGS. 8 to 10, a communication method for hydrogen fuel supply according to one embodiment of the present invention is performed between a communication device (114) of a hydrogen fueled mobility (100) and a communication device (204) of a dispenser (200) that supplies hydrogen fuel to the mobility (100), by means of a communication device (114) of a hydrogen fueled mobility (100), and includes the step (S420, S2100) of establishing a secure communication channel between the mobility (100) and the dispenser (200) based on TCP / TLS handshake that exchanges messages with the dispenser (200) that supplies hydrogen fuel to the mobility (100); The method may include the steps of: generating a message header and a session header based on metadata including a session identifier for uniquely identifying a session in which the mobility (100) receives hydrogen fuel from the dispenser (200), and a schema identifier of a schema determined according to the type of message to be transmitted to the dispenser (200) (S1610); generating a payload including a schema-based encoded first message and a message header to be transmitted to the dispenser (200) (S1620), and generating a packet of the first message including the payload and the session header (S1630); and transmitting the first message (packet) to the dispenser (200) using a secure communication channel (S1640).
[0468] In a communication method for hydrogen fuel mobility (100) for hydrogen fuel supply according to one embodiment of the present invention, the session header may include a version of the session header, a schema identifier of the payload, and a length of the payload.
[0469] A fueling message may be initiated with a session header. The session header may follow the order and byte lengths such as the session header version (1 byte), schema identifier (2 bytes), and payload length (4 bytes), but the spirit of the invention is not limited by specific embodiments.
[0470] The length of the payload can be expressed in Big Endian format.
[0471] A schema identifier may be a field that designates the schema of the payload. The schema identifier may be defined to be identified for each modularized schema based on the type of message, the type of payload, etc., distinguished by the aforementioned embodiment.
[0472] For example, in a DDP message, the schema identifier may be Ox2000, and in a negotiation message, the schema identifier may be Ox3000. If the payload contains a fuel supply communication protocol message, the schema identifier of the message may be Ox8000 or higher.
[0473] For example, depending on the type of fuel supply (communication) protocol, schema identifiers may be classified into Ox8000 (ISO 19885-MCF-HF-G), Ox8001 (ISO 19885-MF-TWIN-LT), Ox8002 (ISO 19885-ANN-MPC), Ox8003 (ISO 19885-PRHYDE), Ox8004 (ISO 19885-RTR-HF), Ox8005 (ISO 19885-TDSW), etc.
[0474] The schema identifier may be a field that identifies which of the modularized and separated schemas it is associated with for encoding the aforementioned ASN.1 schema.
[0475] The message header may include a session identifier, a message identifier, a timestamp of the message, and optional signatures.
[0476] Session information representing a single session may include time, session ID, message type, etc. The time in the session information may refer to a timestamp. The message type may include a message ID and other information.
[0477] A first session identifier that uniquely identifies the session may be assigned from the dispenser (200) after the UC5-communication protocol negotiation procedure (S430) and the UC6-fuel supply protocol negotiation procedure (S540) between the mobility (100) and the dispenser (200) (S2240).
[0478] The session identifier is assigned by the dispenser (200) (S2240) and may be a locally unique octet string. The session identifier may be generated to uniquely identify a fuel supply session within a given time in relation to a specific dispenser (200). The given time may be one week, one month, etc., and may be determined by the fueling operator, HFO (350), etc.
[0479] A communication method for hydrogen fuel mobility (100) for hydrogen fuel supply according to one embodiment of the present invention may further include the step of obtaining a first session identifier based on a message header included in an initial fuel supply parameter response message received from a dispenser (200) (S2250).
[0480] In a communication method of a hydrogen fuel mobility (100) for hydrogen fuel supply according to one embodiment of the present invention, in a first message before a first session identifier is assigned from a dispenser (200), the session identifier field may be determined as a predetermined value (S2010, S2210, S2230).
[0481] In this case, the predetermined value can be, for example, a value where all bits are assigned as '0'.
[0482] The first message before the first session identifier is assigned from the dispenser (200) may include, for example, a DDP request message (S2010), a communication protocol negotiation request message (S2210), a fuel supply protocol negotiation request message (S2230), etc.
[0483] In a communication method of a hydrogen fuel mobility (100) for hydrogen fuel supply according to one embodiment of the present invention, before the first session identifier is received from the dispenser (200), in a first message including a first fuel supply parameter request message, the session identifier field may be determined to a predetermined value.
[0484] At this time, the predetermined value of the session identifier field may include, for example, Ox00..00, and the session identifier field of this value may be used to inform the dispenser (200) that the session identifier has not yet been assigned.
[0485] In a communication method of a hydrogen fuel mobility (100) for hydrogen fuel supply according to one embodiment of the present invention, a plurality of second messages within a session after a first session identifier is assigned from a dispenser (200) following an initial fuel supply parameter request message may include the first session identifier in a message header.
[0486] In an alternative embodiment of the present invention illustrated in FIG. 10, the dispenser (200) may assign a session identifier to the current session during the fuel supply protocol negotiation procedure (S2240).
[0487] At this time, the dispenser (200) can send a fuel supply protocol negotiation response message to the mobility (100) including a session identifier (e.g., Ox123..123) (S2250).
[0488] Mobility (100) can recognize the session identifier of a message and obtain the session identifier of the current session (S2260).
[0489] After obtaining the session identifier, the mobility (100) can transmit all messages of the session including the session identifier (S2270).
[0490] At this time, in one embodiment of the present invention, a session identifier may be assigned and transmitted in a fuel supply protocol negotiation response message of any one of the fuel supply protocol negotiation procedures and in subsequent messages.
[0491] In another embodiment of the present invention, after the fuel supply protocol negotiation procedure is completely finished, a session identifier may be assigned and transmitted in the first fuel supply parameter exchange response message and subsequent messages.
[0492] In another embodiment of the present invention, when a session identifier is not yet assigned in a fuel supply parameter exchange request message, a session identifier may be assigned and transmitted in a fuel supply parameter exchange response message of the dispenser (200) and subsequent messages.
[0493] The dispenser (200) may assign a sequential number, a random number, or a specific number as a session identifier.
[0494] The uniqueness of a session identifier may depend on the provider's policy. For example, one policy may require the session identifier to be unique within the charging station for a specific period, while another policy may require it to be unique for a single day within the charging station.
[0495] Message identifiers can maintain uniqueness within the messages of the entity creating the message. For example, the first message may have a message identifier of all zeros, and subsequent messages may be provided with message identifiers that increase by 1.
[0496] At this time, since each message contains information about the entity that creates and transmits the message, even if the message identifiers of the message of the mobility (100) and the message of the dispenser (100) are the same, the message can be distinguished without confusion as to whose message it is. That is, each message may include a message identifier implemented to be uniquely identified within the message of a specific entity.
[0497] A communication method for hydrogen fuel supply according to another embodiment of the present invention is performed between a communication device (114) of a hydrogen fueled mobility (100) and a communication device (204) of a dispenser (200) that supplies hydrogen fuel to the mobility (100), and by means of the communication device (204) of the dispenser (200), establishes a secure communication channel between the mobility (100) and the dispenser (200) based on a handshake that exchanges messages between the mobility (100) and the dispenser (200); The method may include the step (S1650) of generating a message header and a session header based on metadata including a session identifier of a session in which a dispenser (200) fuels hydrogen to the mobility (100), and a schema identifier of a schema determined according to the type of message to be transmitted to the mobility (100); the step (S1670) of generating a payload including a third message and a message header that is schema-based encoded (S1660) of a message to be transmitted to the mobility (100), and generating a third message packet including the payload and the session header; and the step (S1680) of transmitting the third message (packet) to the mobility (100) using a secure communication channel.
[0498] In a communication method of a dispenser (200) for hydrogen fuel supply according to one embodiment of the present invention, the session header may include a version of the session header, a schema identifier of the payload, and a length of the payload, and the message header may include a session identifier, a message identifier, a timestamp of the message, and optional signatures.
[0499] A communication method for a dispenser (200) for hydrogen fuel supply according to one embodiment of the present invention may further include a step (S2240) of assigning a first session identifier that uniquely identifies the session to the session after a UC-5 communication protocol negotiation procedure (S430) between mobility (100) and dispenser (200) and a UC6-fuel supply protocol negotiation procedure (S540).
[0500] A communication method of a dispenser (200) for hydrogen fuel supply according to one embodiment of the present invention may further include the step of including a first session identifier in the message header of an initial fuel supply parameter response message to be transmitted to the mobility (100).
[0501] In an alternative embodiment, the first session identifier may be transmitted by being included in the message header of any one of the fuel supply protocol negotiation response messages (S2250).
[0502] In a communication method of a dispenser (200) for hydrogen fuel supply according to one embodiment of the present invention, in a third message before a first session identifier is assigned from the dispenser (200), the session identifier field may be determined as a predetermined value (S2020, S2220).
[0503] A plurality of fourth messages within the session after the first fuel supply parameter request message or after the first session identifier is assigned from the dispenser (200) may include the first session identifier in the message header (S2250).
[0504] FIG. 11 is a conceptual block diagram of the internal structure of a generalized computing system that can be mounted on a hydrogen fuel mobility, dispenser, and / or fuel supply station as a communication device, communication control device, and / or electronic control device for hydrogen fuel supply according to one embodiment of the present invention.
[0505] Although omitted in the drawings of the embodiments of FIGS. 1 to 10, each component and functional element of the embodiments of FIGS. 1 to 10 may be electronically connected to a processor and memory, and the operation of each component may be controlled or managed by a processor that loads and executes program instructions stored in memory.
[0506] At least some of the processes of a fuel supply communication method for supplying hydrogen to a hydrogen fuel mobility according to one embodiment of the present invention can be executed by the computing system (3000) of FIG. 11.
[0507] A computing system (3000) according to one embodiment of the present invention may include at least one processor (3100) and a memory (3200) that stores instructions instructing the at least one processor (3100) to perform at least one step. At least some steps of a method according to one embodiment of the present invention may be performed by the at least one processor (3100) loading instructions from the memory (3200) and executing them.
[0508] The processor (3100) may mean a central processing unit (CPU), a graphics processing unit (GPU), or a dedicated processor on which methods according to embodiments of the present invention are performed.
[0509] Each of the memory (3200) and the storage device (3400) may be composed of at least one of a volatile storage medium and a non-volatile storage medium. For example, the memory (3200) may be composed of at least one of read-only memory (ROM) and random access memory (RAM).
[0510] Additionally, the computing system (3000) may include a communication interface (3300) that performs communication through a wired / wireless network.
[0511] Additionally, the computing system (3000) may further include a storage device (3400), an input interface (3500), an output interface (3600), etc.
[0512] Additionally, each component included in the computing system (3000) can communicate with each other by being connected by a bus (3700).
[0513] An artificial neural network model (3800) may be used to implement the embodiments of FIGS. 1 to 10. As shown in FIG. 11, the artificial neural network model (3800) may electronically communicate with other components, including a processor (3100) and a memory (3200), via a bus (3700).
[0514] A device including a processor (3100) according to one embodiment of the present invention may be, for example, a communicable desktop computer, laptop computer, notebook, smartphone, tablet PC, mobile phone, smart watch, smart glass, e-book reader, PMP (portable multimedia player), portable game console, navigation device, digital camera, DMB (digital multimedia broadcasting) player, digital audio recorder, digital audio player, digital video recorder, digital video player, PDA (Personal Digital Assistant), etc.
[0515] A communication device for hydrogen fuel supply according to one embodiment of the present invention is a device mounted on a hydrogen fuel mobility and / or dispenser and performing communication between the hydrogen fuel mobility and the dispenser, and includes a processor (3100) that receives and executes at least one command from a memory (3200).
[0516] A communication device (114) or communication control device disposed in a hydrogen fuel mobility (100) according to one embodiment of the present invention may include a memory (3200) storing at least one command; and a processor (3100) executing at least one command. The processor (3100) may perform the following process by executing at least one command.
[0517] The processor (3100) can establish a secure communication channel between the mobility (100) and the dispenser (200) based on TLS handshakes that exchange messages between the dispenser (200) that fuels hydrogen to the mobility (100) and the mobility (100) (S420, S2100); and can generate a message header and a session header based on metadata including a session identifier of a session that receives hydrogen fuel from the dispenser (200), and a schema identifier of a schema determined according to the type of message to be transmitted to the dispenser (200) (S1610); The mobility (100) can generate a payload (message header + message) including a schema-based encoded first message (S1620) and the message header to be transmitted to the dispenser (200), and can generate a first message packet (session header + payload) including the payload and the session header (S1630); and the mobility (100) can transmit the first message (or first message packet) to the dispenser (200) using the secure communication channel.
[0518] In a communication device (114) of a hydrogen fuel mobility (100) according to one embodiment of the present invention, the session header may include a version of the session header, a schema identifier of the payload, and a length of the payload.
[0519] In a communication device (114) of a hydrogen fuel mobility (100) according to one embodiment of the present invention, the message header may include a session identifier, a message identifier, a timestamp of the message, and optional signatures.
[0520] In a communication device (114) of a hydrogen fuel mobility (100) according to one embodiment of the present invention, a first session identifier that uniquely identifies the session may be assigned from the dispenser (200) after a communication protocol negotiation procedure between the mobility (100) and the dispenser (200), and a fuel supply protocol negotiation procedure (S2240).
[0521] In a communication device (114) of a hydrogen fuel mobility (100) according to one embodiment of the present invention, the processor (3100) can obtain the first session identifier based on a message header included in the first fuel supply parameter response message received from the dispenser (200) (S2250) (S2260).
[0522] In a communication device (114) of a hydrogen fuel mobility (100) according to one embodiment of the present invention, in the first message before the first session identifier is assigned from the dispenser (200), the session identifier field may be determined as a predetermined value (S2010, S2210, S2230).
[0523] In a communication device (114) of a hydrogen fuel mobility (100) according to one embodiment of the present invention, a plurality of second messages within a corresponding session after the first session identifier is assigned from the dispenser (200) following the first fuel supply parameter request message (S2240) may include the first session identifier in the message header (S2270). A communication device (204) or a communication control device disposed in a dispenser that supplies hydrogen to the hydrogen fuel mobility according to one embodiment of the present invention may include a memory (3200) that stores at least one command; and a processor (3100) that executes at least one command. The processor (3100) may perform the following process by executing at least one command.
[0524] The processor (3100) can establish a secure communication channel between the mobility (100) and the dispenser (200) based on a handshake for exchanging messages with the mobility (100) (S420, S2100); and can generate a message header and a session header based on metadata including a session identifier of a session in which the dispenser (200) fuels hydrogen to the mobility (100), and a schema identifier of a schema determined according to the type of message to be transmitted to the mobility (100) (S1650); A payload (message header + message) including a schema-based encoded third message (S1660) and the message header of the message to be transmitted to the mobility (100) can be generated, and a packet (session header + payload) of the third message (response message) including the payload and the session header can be generated (S1670); and the third message (response message, or response message packet) can be transmitted to the mobility (100) using the secure communication channel (S1680).
[0525] The processor (3100) may assign a first session identifier that uniquely identifies the session to the session after a communication protocol negotiation procedure between the mobility (100) and the dispenser (200) and a fuel supply protocol negotiation procedure (S2240).
[0526] The processor (3100) may include the first session identifier in the message header of the first fuel supply parameter response message to be transmitted to the mobility (100). In the communication device (204) of the dispenser (200) according to one embodiment of the present invention, in the third message before the first session identifier is assigned from the dispenser (200), the session identifier field may be determined as a predetermined value (S2020, S2220).
[0527] In a communication device (204) of a dispenser (200) according to one embodiment of the present invention, a plurality of fourth messages within a corresponding session after the first fuel supply parameter request message or after the first session identifier is assigned from the dispenser (200) (S2240) may include the first session identifier in the message header (S2250).
[0528] Meanwhile, although most of the aforementioned embodiments have focused on a method of first transmitting the communication protocol or parameters of the hydrogen fuel mobility from the hydrogen fuel mobility to the dispenser, the present invention is not limited to specific embodiments and can be configured to first transmit the communication protocol or parameters of the dispenser from the hydrogen fuel mobility. In this case, it is obvious that the invention has substantially the same features, except that the sender becomes the receiver and the receiver becomes the sender in the corresponding embodiment.
[0529] The operation of the method according to an embodiment of the present invention can be implemented as a computer-readable program or code on a computer-readable recording medium. A computer-readable recording medium includes all types of recording devices in which information that can be read by a computer system is stored. Additionally, the computer-readable recording medium may be distributed across networked computer systems, allowing computer-readable programs or code to be stored and executed in a distributed manner.
[0530] In addition, computer-readable recording media may include hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Program instructions may include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc.
[0531] Some aspects of the invention have been described in the context of a device, but may also be described according to a corresponding method, wherein a block or device corresponds to a method step or a feature of a method step. Similarly, aspects described in the context of a method may also be described according to a corresponding block or item or a feature of a corresponding device. Some or all of the method steps may be performed by (or using) a hardware device, such as, for example, a microprocessor, a programmable computer, or an electronic circuit. In some embodiments, at least one of the most important method steps may be performed by such a device.
[0532] In the embodiments, a programmable logic device (e.g., a field-programmable gate array) may be used to perform some or all of the functions of the methods described herein. In the embodiments, a field-programmable gate array may operate with a microprocessor to perform one of the methods described herein. Generally, it is preferable that the methods be performed by some hardware device.
[0533] Although the present invention has been described with reference to preferred embodiments, those skilled in the art will understand that various modifications and changes can be made to the invention without departing from the spirit and scope of the invention as described in the following claims.< / false> < / rejected> < / pending> < / ok> < / true> < / accepted>
Claims
As a communication method for hydrogen fueled mobility, A step of establishing a secure communication channel between the mobility and the dispenser based on a handshake in which the mobility exchanges messages with the dispenser that supplies hydrogen fuel to the mobility; The above mobility generates a first message having a session header including a version of the session header based on metadata of a session receiving hydrogen fuel from the dispenser, a schema identifier of the payload, and length information of the payload; and The above mobility transmits the first message to the dispenser using the above secure communication channel; including, Communication method for hydrogen fuel mobility. In paragraph 1, The packet containing the first message above includes the session header and the payload, and The above payload includes a message header and a schema-based encoded message, Communication method for hydrogen fuel mobility. In paragraph 2, The above message header is, including a session identifier, a message identifier, a message timestamp, and optional signatures, Communication method for hydrogen fuel mobility. In paragraph 1, A first session identifier that uniquely identifies the above session is assigned from the dispenser after the communication protocol negotiation procedure between the mobility and the dispenser, and the fuel supply protocol negotiation procedure, Communication method for hydrogen fuel mobility. In paragraph 4, The above mobility acquires the first session identifier based on a message header included in a first fuel supply parameter response message received from the dispenser; including, Communication method for hydrogen fuel mobility. In paragraph 4, In the first message prior to the first session identifier being assigned from the dispenser, the session identifier field is determined to a predetermined value, Communication method for hydrogen fuel mobility. In paragraph 4, In the first message including the first fuel supply parameter request message prior to the first session identifier being received from the dispenser, the session identifier field is determined to a predetermined value. Communication method for hydrogen fuel mobility. In paragraph 4, A plurality of second messages within the corresponding session after the first fuel supply parameter request message, after the first session identifier is assigned from the dispenser, include the first session identifier in the message header. Communication method for hydrogen fuel mobility. As a communication device for hydrogen fuel supply deployed in hydrogen fuel mobility, It includes a processor that executes at least one of the above instructions, The above processor is, Establish a secure communication channel between the mobility and the dispenser based on a handshake that exchanges messages with the dispenser that supplies hydrogen fuel to the mobility; Generating a first message having the session header, which includes a version of the session header based on metadata of the session receiving hydrogen fuel from the dispenser, a schema identifier of the payload, and length information of the payload; The above mobility transmits the first message to the dispenser using the above secure communication channel; Communication device. In Paragraph 9, The packet containing the first message above includes the session header and the payload, and The above payload includes a message header and a schema-based encoded message, Communication device. In Paragraph 10, The above message header is, including a session identifier, a message identifier, a message timestamp, and optional signatures, Communication device. In Paragraph 9, A first session identifier that uniquely identifies the above session is assigned from the dispenser after the communication protocol negotiation procedure between the mobility and the dispenser, and the fuel supply protocol negotiation procedure, Communication device. In Paragraph 12, The above processor is, Obtaining the first session identifier based on a message header included in a first fuel supply parameter response message received from the dispenser, Communication device. In Paragraph 12, In the first message prior to the first session identifier being assigned from the dispenser, the session identifier field is determined to a predetermined value, Communication device. In Paragraph 12, A plurality of second messages within the corresponding session after the first fuel supply parameter request message, after the first session identifier is assigned from the dispenser, include the first session identifier in the message header. Communication device. As a communication method for a dispenser that supplies hydrogen fuel to hydrogen fuel mobility, A step of establishing a secure communication channel between the mobility and the dispenser based on a handshake for exchanging messages with the mobility; The step of generating a third message having the session header, which includes a version of the session header based on metadata of the session in which the dispenser fuels hydrogen to the mobility, a schema identifier of the payload, and length information of the payload; and A step of transmitting the third message to the mobility using the above secure communication channel; including, Dispenser communication method. In Paragraph 16, The packet containing the third message above includes the session header and the payload, and The above payload includes a message header and a schema-based encoded message, and The above message header is, including a session identifier, a message identifier, a message timestamp, and optional signatures, Dispenser communication method. In Paragraph 16, A step of assigning a first session identifier that uniquely identifies the session to the session after a communication protocol negotiation procedure between the mobility and the dispenser, and a fuel supply protocol negotiation procedure; including, Dispenser communication method. In Paragraph 18, A step of including the first session identifier in the message header of a first fuel supply parameter response message to be transmitted to the mobility and transmitting it; including, Dispenser communication method. In Paragraph 18, In the third message prior to the first session identifier being assigned from the dispenser, the session identifier field is determined to a predetermined value, and A plurality of fourth messages within the corresponding session after the first fuel supply parameter request message, after the first session identifier is assigned from the dispenser, include the first session identifier in the message header. Dispenser communication method.
Citation Information
Patent Citations
Apparatus and method for changing charge protocol of electric vehicle
KR101437375B1
Device for spraying fluid
KR1020220153880A
Nonaqueous electrolyte for lithium secondary battery and lithium secondary battery employing the same
KR1020230077708A
Communication systems and methods for hydrogen fueling and electric charging
US20210371269A1
KR20240044376A