WO2025080025A1 - 개선된 안전 체크인 프로세스를 포함하는 수소 연료공급을 위한 양방향 통신 방법 및 장치 - Google Patents
개선된 안전 체크인 프로세스를 포함하는 수소 연료공급을 위한 양방향 통신 방법 및 장치 Download PDFInfo
- Publication number
- WO2025080025A1 WO2025080025A1 PCT/KR2024/015413 KR2024015413W WO2025080025A1 WO 2025080025 A1 WO2025080025 A1 WO 2025080025A1 KR 2024015413 W KR2024015413 W KR 2024015413W WO 2025080025 A1 WO2025080025 A1 WO 2025080025A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- dispenser
- mobility
- fuel supply
- protocol
- communication
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Images
Classifications
-
- F—MECHANICAL ENGINEERING; LIGHTING; HEATING; WEAPONS; BLASTING
- F17—STORING OR DISTRIBUTING GASES OR LIQUIDS
- F17C—VESSELS FOR CONTAINING OR STORING COMPRESSED, LIQUEFIED OR SOLIDIFIED GASES; FIXED-CAPACITY GAS-HOLDERS; FILLING VESSELS WITH, OR DISCHARGING FROM VESSELS, COMPRESSED, LIQUEFIED, OR SOLIDIFIED GASES
- F17C5/00—Methods or apparatus for filling containers with liquefied, solidified, or compressed gases under pressures
- F17C5/06—Methods or apparatus for filling containers with liquefied, solidified, or compressed gases under pressures for filling with compressed gases
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/14—Session management
- H04L67/141—Setup of application sessions
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/24—Negotiation of communication capabilities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/30—Definitions, standards or architectural aspects of layered protocol stacks
- H04L69/32—Architecture of open systems interconnection [OSI] 7-layer type protocol stacks, e.g. the interfaces between the data link level and the physical level
- H04L69/322—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions
- H04L69/323—Intralayer communication protocols among peer entities or protocol data unit [PDU] definitions in the physical layer [OSI layer 1]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W76/00—Connection management
- H04W76/10—Connection setup
Definitions
- the present invention relates to a communication technology for hydrogen fueling from a charging station/dispenser to hydrogen fueled mobility, and more particularly, to a hydrogen fueling process capable of improving the safety, compatibility, efficiency and reliability of hydrogen fueling, a bidirectional communication method for the hydrogen fueling process, and an apparatus using the same ⁇ METHOD AND APPARATUS FOR BIDIRECTIONAL COMMUNICATION FOR HYDROGEN FUELING INCLUDING IMPROVED SAFETY CHECK-IN PROCESS ⁇ .
- Hydrogen cars or hydrogen electric vehicles, are zero-emission vehicles that run on electric energy generated by the combination of high-pressure hydrogen stored in the vehicle and air in the atmosphere. Hydrogen electric vehicles are also called fuel cell electric vehicles (FCEVs). Most hydrogen electric vehicles use hydrogen as an energy source and use a fuel cell system to generate electricity to move. Hydrogen electric vehicles not only emit only pure water ( H2O ) during the electricity generation process, but also have the function of removing ultrafine dust in the atmosphere while in operation, so they are attracting attention as a future eco-friendly mobility. It is widely recognized as a technology with the potential to be utilized across industries, as hydrogen as a fuel is infinite on Earth and the process of producing energy is eco-friendly.
- Hydrogen fueled mobility refers to mobility that uses hydrogen as an energy source or generates electric energy using hydrogen as fuel and uses it to drive an electric motor.
- Hydrogen fueled mobility includes not only the hydrogen electric vehicles described above, but also aerial mobility, industrial trucks, trains, ships, and aircraft, and may include devices that generate electric energy using hydrogen as fuel and use it to drive.
- a hydrogen fueled car directly combusts hydrogen in an engine (ICE, Internal Combustion Engine) and drives an electric motor with the heat generated.
- ICE Internal Combustion Engine
- the method of supplying hydrogen for a hydrogen fueled car is not much different from the method of supplying hydrogen for a hydrogen electric car.
- the control technique for supplying hydrogen to a vehicle that uses hydrogen as fuel ultimately aims to control the temperature and pressure of the Compressed Hydrogen Storage System (CHSS) on the fuel cell side to operate under the limit temperature and limit pressure conditions for the safety of hydrogen fuel supply.
- CHSS Compressed Hydrogen Storage System
- the purpose of the present invention to solve the above problems is to provide a hydrogen fueling process of hydrogen fueled mobility, and a communication protocol for the process, which can overcome the limitations and vulnerabilities of existing one-way communications and improve the safety, compatibility, efficiency and reliability of hydrogen fueling, a hydrogen fueling process, a communication protocol negotiation for the hydrogen fueling process, a fueling protocol negotiation, a fueling parameter negotiation method, a monitoring and control method, a safety check-in method, a safety check-out method and a device using the same.
- Another object of the present invention is to provide an error handling and emergency handling method for a hydrogen fueling process, which handles errors and/or emergencies occurring during communication protocol negotiation, fueling protocol negotiation, fueling parameter negotiation, monitoring and control, safety check-in, and safety check-out processes for a hydrogen fueling process, and a device using the same.
- Another object of the present invention is to provide a hydrogen fueling communication bidirectional process, a communication protocol negotiation process considering bidirectional/unidirectional communication, and a device using the same, which can control hydrogen fuel mobility and dispensers to determine a conventional communication medium or an advanced communication medium to effectively achieve a hydrogen fueling goal.
- Another object of the present invention is to propose and provide an improved version of the Safety Check-In use case performed between hydrogen fuel mobility and a dispenser.
- a communication method for hydrogen fueling is performed by a communication device of hydrogen fueled mobility, and as a communication method for hydrogen fueling, the method may include: a step of exchanging information on a first fueling protocol between the mobility and the dispenser based on a result of a pairing process between a dispenser that supplies hydrogen to the mobility and the mobility; and a step of performing a check of the pairing process between the mobility and the dispenser if a check of the pairing process between the mobility and the dispenser is requested based on the information on the first fueling protocol before a safety check-in process is performed.
- the communication method for hydrogen fuel supply may further include a step of determining whether a check of a pairing process between mobility and a dispenser is required based on information about the first fuel supply protocol.
- a step of determining whether a check of a pairing process between mobility and a dispenser is required based on information about a first fueling protocol may include a step of determining whether information about the first fueling protocol includes information about a safe check-in use case.
- the step of performing a check of a pairing process between the mobility and the dispenser may include a step of performing the pairing process again between the mobility and the dispenser if information on a first fuel supply protocol does not include information on a safe check-in use case.
- pairing information shared between the mobility and the dispenser may include information related to interoperability or compatibility between the mobility and the dispenser.
- the information related to interoperability or compatibility may include information on a fuel supply protocol exchanged between the mobility and the dispenser, and information on whether the fuel supply protocol includes information on a safe check-in use case.
- a communication method for hydrogen fueling performed by a communication device of hydrogen fueled mobility may further include a step of re-negotiating a communication protocol or a fueling protocol for a process of fueling hydrogen to the mobility between the mobility and the dispenser based on a result of a step of re-performing a pairing process.
- a communication method for hydrogen fueling performed by a communication device of hydrogen fueled mobility may further include a step of re-negotiating a second fueling protocol for a process in which the dispenser refuels the mobility with hydrogen, between the mobility and the dispenser, based on a result of a step of re-performing a pairing process.
- information about the second fuel supply protocol may be determined so that the second fuel supply protocol includes information about the safety check-in use case.
- a communication method for hydrogen fueling performed by a communication device of hydrogen fueled mobility may further include a check-in step of checking whether a first necessary safety condition is satisfied between the mobility and the dispenser before a process of the dispenser supplying hydrogen to the mobility after a check of a pairing process is performed; and a check-out step of checking whether a second necessary safety condition is satisfied between the mobility and the dispenser after the process of the dispenser supplying hydrogen to the mobility and before a nozzle is separated from the mobility.
- a communication method for hydrogen fuel supply performed by a communication device of hydrogen fueled mobility may further include a step of detecting and handling a non-safety-critical error based on a check result of a pairing process.
- a communication method for hydrogen fuel supply performed by a communication device of hydrogen fueled mobility may further include a step of detecting and handling an emergency situation in which mutual operation between a dispenser and mobility must be stopped based on a check result of a pairing process.
- the step of renegotiating the second fuel supply protocol may include the steps of renegotiating a communication protocol linked to the second fuel supply protocol between the mobility and the dispenser; renegotiating the second fuel supply protocol between the mobility and the dispenser based on the communication protocol; and renegotiating fuel supply parameters between the mobility and the dispenser based on the second fuel supply protocol.
- the information of the communication protocol or fuel supply protocol transmitted between the dispenser and the mobility may include the protocol name, index, version, priority or preference.
- a communication method for hydrogen fueling performed by a communication device of a dispenser that supplies hydrogen fuel to hydrogen fuel mobility may include a step of exchanging information on a first fueling protocol between the mobility and the dispenser based on a result of a pairing process between the mobility and the dispenser; and a step of performing a check of the pairing process between the mobility and the dispenser if a check of the pairing process between the mobility and the dispenser is requested based on the information on the first fueling protocol before a safety check-in process is performed.
- a communication method for hydrogen fuel supply performed by a communication device of a dispenser that supplies hydrogen to hydrogen fuel mobility may further include a step of determining whether a check of a pairing process between the mobility and the dispenser is required based on information about a first fuel supply protocol.
- a step of determining whether a check of a pairing process between the mobility and the dispenser is required may include a step of determining whether information on a first fuel supply protocol includes information on a safe check-in use case.
- the step of performing a check of a pairing process between the mobility and the dispenser may include a step of performing the pairing process again between the mobility and the dispenser if information on a first fuel supply protocol does not include information on a safe check-in use case.
- pairing information shared between the mobility and the dispenser in a step of re-performing the pairing process may include information related to interoperability or compatibility between the mobility and the dispenser.
- interoperability or compatibility related information may include information about the fueling protocol exchanged between the mobility and the dispenser, information about whether the fueling protocol includes information about a safe check-in use case.
- a communication method for hydrogen fueling performed by a communication device of a dispenser that supplies hydrogen to hydrogen fuel mobility may further include a step of re-negotiating a communication protocol or a fueling protocol for a process of the dispenser supplying hydrogen to the mobility between the mobility and the dispenser based on a result of a step of re-performing a pairing process.
- a communication method for hydrogen fueling performed by a communication device of a dispenser that supplies hydrogen to hydrogen fuel mobility may further include a step of re-negotiating a second fueling protocol for a process in which the dispenser supplies hydrogen to the mobility, between the mobility and the dispenser, based on a result of a step of re-performing a pairing process.
- information about the second fuel supply protocol may be determined so that the second fuel supply protocol includes information about the safety check-in use case.
- a communication device for hydrogen fuel mobility comprises: a memory storing at least one command; and a processor executing at least one command, wherein the processor can exchange information on a first fuel supply protocol between the mobility and the dispenser based on a result of a pairing process between a dispenser that supplies hydrogen to the mobility and the mobility by the at least one command, and can determine whether a check of the pairing process between the mobility and the dispenser is required before performing a safety check-in process, and if the check of the pairing process is required, can perform a check of the pairing process between the mobility and the dispenser.
- the processor can determine whether information about the first fueling protocol includes information about a safe check-in use case when determining whether a check of the pairing process between the mobility and the dispenser is required.
- the processor may perform the pairing process between the mobility and the dispenser again if, when performing the check of the pairing process, the information about the first fueling protocol does not include information about the safety check-in use case, if a check of the pairing process is required.
- the pairing information shared between the mobility and the dispenser may include information related to interoperability or compatibility between the mobility and the dispenser.
- the processor may, based on the results of the step of re-performing the pairing process by at least one command, renegotiate a communication protocol or a fueling protocol between the mobility and the dispenser for the process of refueling the mobility with hydrogen.
- the processor may, based on the results of the step of re-performing the pairing process by at least one command, renegotiate a second fueling protocol between the mobility and the dispenser for the process of refueling the mobility with hydrogen.
- information on the second fuel supply protocol may be determined such that the second fuel supply protocol includes information on a safe check-in use case.
- a communication device of a dispenser supplying hydrogen fuel to hydrogen fuel mobility comprises: a memory storing at least one command; and a processor executing at least one command, wherein the processor can exchange information on a first fuel supply protocol between the mobility and the dispenser based on a result of a pairing process between the mobility and the dispenser by the at least one command, and, before a safety check-in process is performed, if a check of the pairing process between the mobility and the dispenser is requested based on the information on the first fuel supply protocol, the check of the pairing process between the mobility and the dispenser can be performed.
- a communication method for hydrogen fuel supply and a device using the same that is, a hydrogen fuel supply control device or a communication control device for a vehicle/mobility
- FCEV hydrogen electric vehicle
- a hydrogen fuel engine and a communication protocol therefor it is possible to overcome the limitations and vulnerabilities of existing one-way communication in a hydrogen fueling process of hydrogen fueled mobility including a hydrogen electric vehicle (FCEV: fuel cell electric vehicle) and a hydrogen fuel engine and a communication protocol therefor, and to improve the safety, compatibility, efficiency, and reliability of hydrogen fuel supply.
- FCEV hydrogen electric vehicle
- a method for negotiating a communication protocol for hydrogen fueling in which a communication protocol required to execute a protocol for hydrogen fueling is selected according to a use case, while considering priorities according to preferences of the mobility and the dispenser, while maximizing interoperability between the mobility and the dispenser and considering backward compatibility.
- rules and procedures required for communication protocol negotiation, fueling protocol negotiation, and fueling parameter exchange can be provided so that mobility and a dispenser can cooperate to effectively determine a conventional communication medium or an advanced communication medium to effectively achieve a hydrogen fueling goal.
- mobility and dispensers can work together to provide rules and procedures necessary for monitoring and control, safety check-in, and safety check-out to effectively achieve the hydrogen fueling goal.
- the monitoring and control, safety check-in, and safety check-out processes, communication protocol negotiation, fueling protocol negotiation, and fueling parameter exchange processes are linked to provide rules and procedures necessary for a use case in which mobility and a dispenser cooperate to effectively achieve a hydrogen fueling goal.
- the rules and procedures required for a use case in which the mobility and the dispenser cooperate to effectively achieve the hydrogen fueling goal are linked, including communication protocol negotiation, fueling protocol negotiation, fueling parameter negotiation, monitoring and control, error handling for the hydrogen fueling process that handles errors and/or emergencies occurring during the safety check-in and safety check-out processes, and emergency handling processes can be provided.
- FIG. 1 is a conceptual diagram of a hydrogen fuel supply system for a hydrogen electric vehicle (FCEV) to which a two-way hydrogen fuel supply communication process according to one embodiment of the present invention can be applied.
- FCEV hydrogen electric vehicle
- FIG. 2 is a partially enlarged view illustrating the physical connection structure between the FCEV and the dispenser in the hydrogen fuel supply system of Figure 1.
- Figure 3 is a graph for explaining the state changes of hydrogen fuel that occur during the hydrogen fuel supply process by the hydrogen fuel supply system of Figure 1.
- FIG. 4 is a framework for functional blocks performing a series of hydrogen fueling procedures that can employ a hydrogen fueling communication bidirectional process according to one embodiment of the present invention.
- FIG. 5 is an exemplary diagram showing a communication stack related to each use case that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention, centered on the OSI (Open Systems Interconnection reference model) 7 layer.
- OSI Open Systems Interconnection reference model
- FIG. 6 is an exemplary diagram illustrating a pairing process of a discovery and pairing procedure that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention.
- FIG. 8 is an exemplary diagram illustrating backward compatibility that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention.
- FIG. 17 is a flowchart illustrating a communication method for hydrogen fuel supply according to another embodiment of the present invention.
- Hydrogen electric vehicles can generally include both hydrogen fuel cell electric vehicles (FCEVs) that use fuel cells or ICE (internal combustion engine)-based vehicles that use hydrogen as fuel.
- FCEVs hydrogen fuel cell electric vehicles
- ICE internal combustion engine
- Hydrogen fueling basically means the process of supplying high-pressure hydrogen from a dispenser at a hydrogen charging station and compressing and storing it in a tank of a vehicle.
- Hydrogen fueling can be briefly used with the same meaning as fueling in terms of supplying hydrogen fuel to a hydrogen electric vehicle. That is, in this specification, "fueling" can be used to mean fueling, hydrogen fueling, or fueling, and fueling can mean fueling hydrogen fuel.
- a fueling protocol can be referred to as a fueling protocol
- a fueling session can be referred to as a fueling session
- a fueling method can be referred to as a hydrogen fueling method or a fueling method.
- Pressure Ramp Rate is expressed in MPa/min and refers to the pressure increase rate of CHSS.
- Pre-cooling can basically mean the process of cooling hydrogen in a hydrogen charging station before fueling it.
- the vehicle system (120) may be connected to the first electronic control unit (110) and configured to control hydrogen fuel supply or hydrogen discharge of the vehicle tank (130) according to a signal or command of the first electronic control unit (110) and to monitor the state of the vehicle tank (130).
- the vehicle system (120) may include a component that controls the operation of the fuel cell system or performs such control operations, or may be configured to be coupled with such a component, depending on the implementation.
- the vehicle system (120) may also perform a vehicle safety function, in which case it may also be referred to as a vehicle safety system.
- a hydrogen charging station may be equipped with a dispenser (200), an electronic control unit (210), a charging station system (220), a hydrogen tank (230), a station box (240), and a nozzle (250).
- the dispenser (200) can supply hydrogen supplied from a hydrogen tank (230) to a vehicle through a nozzle (250) that is rigidly connected to a receptacle (150) of the vehicle under the control of a charging station system (220).
- the dispenser (200) can have an electronic control device (210) inside the housing, but is not limited thereto.
- the nozzle (250) can basically be installed at the end of a cable that extends to a certain length outside the housing of the dispenser (200).
- the charging station system (220) can monitor or control the pressure, speed, and temperature of hydrogen discharged from the hydrogen tank (230) according to the signal and/or data of the second electronic control unit. To this end, the charging station system (220) can control the operation of the station box (240) connected to the discharge port or discharge valve of the hydrogen tank (230).
- the charging station system (220) may also be referred to as a charging station safety system.
- the station box (240) may be equipped with a control valve having an inlet connected to the discharge port or discharge valve of the hydrogen tank (230) and an outlet connected to the dispenser (200) or a nozzle (250) coupled to the dispenser (200).
- the station box (240) may be equipped with a means for controlling the pressure, speed, temperature, etc. of the hydrogen being discharged, or a component that performs a function corresponding to such means.
- the station box (240) may be equipped with sensors for measuring the pressure, speed, temperature, etc. of the hydrogen being discharged.
- the nozzle (250) can be engaged with the receptacle (150) as shown in Fig. 2. At this time, a signal or information on the engagement status of the nozzle (250) and the receptacle (150) is transmitted to the first electronic control device or the vehicle safety system by the first sensor (160) installed in the vehicle and the second sensor (260) attached to the nozzle (250), and can also be transmitted to the second electronic control device or the charging station safety system.
- Hydrogen fuel pre-cooled from the aforementioned hydrogen charging station is supplied to a hydrogen electric vehicle (100) through a dispenser (200).
- the hydrogen fuel supply process can be described by parameters including a pressure increase rate (PRR) and/or an average pressure increase rate (APRR).
- PRR pressure increase rate
- APRR average pressure increase rate
- the interface between the hydrogen charging station and the vehicle (100) can be handled by the dispenser (200).
- the dispenser (200) can be configured to control target pressure and injection speed for hydrogen fuel supply by synthesizing information indirectly obtained from the vehicle tank (130) and fuel supply information of the hydrogen charging station.
- a communication method In the existing technology, there are two ways to transmit information from the vehicle (100) to the dispenser (200): a communication method and a non-communication method.
- the temperature and pressure values of the vehicle tank (130) of the vehicle (100) are simply transmitted in one direction to the dispenser (200), and the dispenser (200) does not actively utilize the information, but only utilizes it as a safety standard, such as an emergency stop at the limit temperature and pressure.
- the hydrogen fuel supply protocol for safe and rapid fuel supply is managed by the dispenser (200), and only a minimum safety management device is provided to automatically release hydrogen through a pressure relief device (PRD) without active safety management of the vehicle tank (130).
- PRD pressure relief device
- the hydrogen charging station may be equipped with a pre-cooler.
- the pre-cooler may lower the temperature of hydrogen fuel through pre-cooling.
- the pre-cooler may be installed or coupled to at least one of the hydrogen tank (230) and the station box (240).
- the pre-cooler may of course be installed or coupled to a pipe that transports hydrogen in the hydrogen charging station.
- the hydrogen fueling process is controlled between the vehicle (100) and the hydrogen charging station by the dispenser (200), and the dispenser (200) may be equipped with a protocol for supplying hydrogen fuel to the vehicle according to a set procedure.
- This hydrogen fueling protocol may also be equipped in the vehicle.
- the protocol equipped in the vehicle or the dispenser (200) may include at least a part of a communication protocol according to the SAE standard, the ISO standard, etc.
- the internal temperature of the vehicle tank rises due to the compression heat, and thus the temperature of the hydrogen fuel inside the vehicle tank rises.
- the vehicle tank is configured to wrap the dome and body of the vehicle tank with carbon fiber having low heat transfer efficiency in order to block heat exchange between the external atmosphere and the hydrogen fuel stored inside. Therefore, when the temperature of the hydrogen fuel inside the vehicle tank rises during the fuel supply process, the temperature rise revealed on the surface of the vehicle tank may be minimal compared to the internal temperature rise until the fuel supply is completed due to the low heat transfer characteristics of the vehicle tank.
- Phase I Phase I
- P2 Phase II
- P3 Phase III
- P4 Phase IV
- a hydrogen fuel supply procedure can be effectively performed through active state variable control reflecting real-time measurement data through a hydrogen fuel supply communication two-way process, and a hydrogen fuel supply protocol for this can be provided.
- the hydrogen fueling framework is composed of use case (UC)-specific function blocks, including a discovery and pairing function block (hereinafter, simply referred to as 'UC1' or 'UC-1'), a communication security function block (UC2 or UC-2), a communication protocol negotiation function block (UC3 or UC-3), a fueling protocol negotiation function block (UC4 or UC-4), a fueling parameter negotiation function block (UC5 or UC-5), a safety check-in function block (UC6 or UC-6), a monitoring and control function block (UC7 or UC-7), a safety check-out function block (UC8 or UC-8), a termination function block (UC9 or UC-9), an error handling function block (UC10 or UC-10), and an emergency handling function.
- Blocks (UC11 or UC-11) can be equipped.
- the above-described use cases are functional blocks that collectively provide the entire hydrogen fueling procedures of a hydrogen fueling system in a consistent manner for safe and secure fueling communication.
- the vehicle and dispenser can sequentially perform each use case in a specific order to achieve the hydrogen fueling goal.
- the vehicle and the dispenser can perform fuel supply communication by implementing each use case in the order shown in Fig. 4. However, the vehicle and the dispenser can omit specific use cases if necessary according to predefined requirements.
- Each of the use cases described above can be implemented through communication between a dispenser control system of a dispenser that supplies hydrogen as fuel to a hydrogen fuel vehicle according to a fueling protocol for a hydrogen fuel vehicle and the hydrogen fuel vehicle.
- the hydrogen fuel vehicle (hereinafter also referred to simply as “vehicle”) and the dispenser implementing the aforementioned use case can exchange data for vehicle identification in UC-1.
- the vehicle can be equipped with sensors, an electric control unit (ECU), a transmitter, and a receiver.
- the receiver can be integrally coupled with the transmitter in case of two-way communication.
- the dispenser can be configured to receive specific data from the vehicle.
- the dispenser can store data of data logging or store data specified in the charging station PLC (programmable logic controller) for use in the fueling protocol.
- Data logging can refer to a process of collecting data for a certain period of time to analyze a specific operating state of a hydrogen fueling system or to record data-based events/operations of a system or network environment, or data collected by this process.
- the charging station is equipped with a sensor specified by the fueling protocol, and the charging station PLC or electronic control unit can obtain measurements from the sensors and send the measurements to the vehicle.
- the aforementioned vehicle or charging station can use existing communication protocol standards for communication, such as infrared, Wi-Fi, or Bluetooth.
- the discovery and pairing procedure or pairing process may have pre-conditions that the dispenser nozzle is inserted into and firmly connected to a vehicle fueling receptacle.
- the vehicle fueling receptacle may be simply referred to as a vehicle receptacle or receptacle.
- the vehicle and the dispenser know by default which communication protocol to follow. Therefore, subsequent communication after UC-1 can only rely on the communication protocol agreed upon in the current use case, either as a discovery and pairing procedure or as a post-condition of the pairing process. If a communication protocol outside the agreed upon scope is selected by the vehicle or the dispenser, the selected communication will not be performed. That is, even if the pairing process is completed successfully, authorization for fuel or authorization for fuel delivery may not be granted.
- Any method used to pair the vehicle and dispenser shall be configured so as not to increase the risk of ignition or explosion beyond an acceptable level.
- any wired pairing method shall be configured to mitigate or prevent the risk of sparking due to electrostatic discharge.
- any method used to pair the vehicle and the dispenser may be integrated into the vehicle-to-dispenser interface or installed so as to have proximity between the fueling receptacle of the vehicle and the nozzle and hose assembly of the dispenser.
- the interface may refer to something physically integrated into the nozzle and receptacle interface.
- the proximity may be defined by hardware associated with the pairing method.
- the physical geometry used for infrared communication may be specified, including the allowed distance between the transmitter and receiver.
- the physical geometry of the hydrogen fueling hardware may be pre-specified, wherein the proximity does not include a relatively long-range wireless communication technology such as Bluetooth, such as a pairing method that risks pairing a vehicle and dispenser that are not physically connected.
- the infrared communication may be referred to as infrared data association (IrDA) communication, and may include bidirectional infrared (bi-IrDA) communication.
- a communication method for hydrogen fueling is a communication method for hydrogen fueling performed by a communication device of hydrogen fuel mobility, which may include a step of negotiating a communication protocol with a dispenser that fuels hydrogen to mobility (S403); a step of negotiating a fueling protocol for receiving hydrogen from the dispenser with the dispenser (S404); and a step of negotiating a fueling parameter based on the fueling protocol with the dispenser (S405).
- a communication method for hydrogen fueling performed by a dispenser supplying hydrogen fuel to hydrogen fuel mobility may include a step of negotiating a communication protocol with the mobility (S403); a step of negotiating a fueling protocol for supplying hydrogen to the mobility with the mobility (S404); and a step of negotiating a fueling parameter based on the fueling protocol with the mobility (S405).
- the communication stack related to the use case of the hydrogen fueling communication bidirectional process (briefly referred to as the 'hydrogen fueling communication stack') can be expressed as protocol suites corresponding to each of the data link and physical layer, the network layer, the transport layer, the security layer, the session layer, the presentation layer, and the application layer belonging to the OSI 7 layers.
- the hydrogen fuel supply communication stack may include at least one first protocol (510) selected from bidirectional IrDA (bi-IrDA), WLAN, NFC, etc. as a protocol of the data link and physical layers of the OSI 7 layers.
- first protocol selected from bidirectional IrDA (bi-IrDA), WLAN, NFC, etc.
- the hydrogen fuel supply communication stack may include at least one third protocol (530) selected from TCP (transmission control protocol), UDP (user datagram protocol), etc. as a protocol of the transport layer of the OSI 7 layer.
- TCP transmission control protocol
- UDP user datagram protocol
- the hydrogen fueling communication stack may include a JSON-based session protocol (550) as a protocol of the session layer of the OSI 7 layer.
- the JSON-based session protocol (550) may be used when communicating between a vehicle and a dispenser or sending data between an electronic control unit of a vehicle and an electronic control unit of a charging station.
- the hydrogen fueling communication stack may include JSON (JavaScript object notation) (560) as a protocol of the presentation layer of the OSI 7 layer.
- JSON is one of the formats that can be used when sending data from a server to a client.
- protocol messages between a vehicle and a dispenser or between an electronic control unit of a vehicle and an electronic control unit of a charging station can be expressed in JSON.
- the hydrogen fueling communication stack may include fueling protocols (FP) (570) related to hydrogen fueling as a protocol of an application layer of the OSI 7 layer.
- the fueling protocols (570) may include a first fueling protocol (FP1), a second fueling protocol (FP2), and an nth fueling protocol (FPn). n may be any natural number greater than or equal to 3.
- the hydrogen fueling communication stack described above may be configured to utilize protocols such as PLC (programmable logic controller), WLAN, etc. as protocols of the data link and physical layers and the network layer; TCP and/or IPv6 protocols as protocols of the transport layer and the security layer; binary XML (binary extensible markup language) protocol as protocols of the session layer corresponding to the encoding layer; and one of the existing protocols used in electric vehicles as protocols of the presentation layer and the application layer.
- the existing protocols used in electric vehicles may include at least one protocol for direct current (DC) fueling, alternate current (AC) fueling, wireless power transfer (WPT), automatic connection device pantograph (ACDP), etc. of the electric vehicle.
- the use case (UC1) of the discovery and pairing step (S401) of Fig. 4 enables the device to identify a communication counterparty (a communication module of a vehicle or dispenser) responsible for controlling a physically connected receptacle or nozzle.
- UC1 can also define a method for identifying incompatibility and define a safety mechanism.
- the vehicle and the dispenser may attempt to find a common communication technology to execute the fueling protocol.
- the vehicle and the dispenser may discover each other and initiate communication based on discovery mechanisms provided by the underlying data link and physical layers.
- An additional pairing procedure may be required to establish a communication channel with the device connected to the fueling hose assembly. If the communication channel does not guarantee proper pairing, for example, in the case of wireless communication, a separate pairing channel may be required to convey the pairing information. If pairing is implicitly guaranteed, for example, the communication channel integrated with the hose assembly may suffice.
- Table 2 is a table showing the purpose, prerequisites, and follow-up conditions of use case UC1 of the discovery and pairing step (S401) of Fig. 4.
- UC-1 Type Description Use case name UC-1: "Discovery and Pairing" Objectives UC-1 allows devices to identify the communication counterparty (communication module of vehicle or dispenser) that is responsible for the control of the physically connected receptacle or nozzle, respectively. UC-1 also defines how to identify incompatibility and may define a failsafe mechanism. Short Description During this use case, vehicle and dispenser try to find out any common communication technologies to run a fueling protocol. Depending on the discovery mechanism provided by the underlying physical/data-link layer, the vehicle and dispenser discovers each other and start communication. To ensure that the communication channel is established with the devices that are bound to the fueling hose assembly, extra pairing procedure may need to be involved.
- Table 3 is a table showing supported communication technologies and their respective clauses that can be used in use case UC1 of the discovery and pairing step (S401) of FIG. 4.
- FIG. 6 is a flowchart illustrating in detail step (S401) according to one embodiment of the present invention.
- the pairing process is such that when pairing at UCDC level 2 and UCDC level 3, the vehicle and the dispenser can exchange pairing IDs and check the other party's pairing ID.
- a vehicle can broadcast a message (PAIR_ID_ANNOUNCE) containing its pairing ID (PAIR_ID), i.e., the vehicle ID (vehicle_id).
- PAIR_ID_ACK the vehicle ID
- PAIR_ID_CONFIRM the dispenser's message
- the dispenser can broadcast a message (PAIR_ID_ANNOUNCE) containing its pairing ID, i.e., the dispenser ID (dispenser_id).
- the vehicle can send a message (PAIR_ID_ACK) to the dispenser to acknowledge that it has received the dispenser ID.
- the dispenser can send a message (PAIR_ID_CONFIRM) to the vehicle to confirm that it has normally received the ACK message that the vehicle has received the dispenser ID.
- This send-echo-verify method allows vehicles and dispensers to use session-specific randomized pairing IDs. This solves the privacy issue of pairing ID exchange. That is, trust in the pairing process is established by a subsequent process, and for this purpose, the session-specific pairing ID is included in the data used to establish trust.
- the vehicle and the dispenser can ensure that the pairing provides sufficient information to secure the communication channel for any method used to pair the vehicle and the dispenser.
- the pairing may include the exchange of cryptographic keys so that the vehicle and dispenser can secure communications during fueling.
- UCDC Level 1 does not support bidirectional communication, so securing the communication channel may not be possible. Pairing a vehicle and a dispenser at UCDC Level 2 and UCDC Level 3 may be configured to provide sufficient information to secure the communication to meet a particular security level, for example, IEC 62443 Security Level 3. IEC 62443 Security Level 3 may be a security level for actors with appropriate resources and appropriate motivation.
- FIG. 7 is an exemplary diagram illustrating backward compatibility that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention.
- the hydrogen fuel supply device can be made into a compatible device that has backward compatibility with existing devices in consideration of interoperability.
- the hydrogen fuel supply device or its communication device can be classified into Type 0, Type 1, Type 2, and Type 3.
- Type 0 may refer to a device that does not support fueling communications or does not receive such communications messages.
- Type 1 may refer to a device supporting IrDA communication for fuel supply.
- a Type 1 device may fallback to a Type 0 device.
- Type 2 can refer to a device that supports advanced communication (AC). Type 2 devices can fall back to Type 0 devices.
- AC advanced communication
- Type 3 can refer to a device that supports IrDA and advanced communications.
- a Type 3 device can fall back to any of Type 0, Type 1, and Type 2.
- Advanced communication may refer to communication using a medium such as WLAN (wireless local area network), Bluetooth (BT), NFC (near field communication), WiFi, UWB (ultra-wideband), RFID (radio frequency identification), 4G, and 5G, and a specific protocol.
- advanced communication may include bidirectional IrDA, serial communication, automotive Ethernet (ETH), high level communication, etc.
- the specific protocol may include TCT/IP (transmission control protocol/internet protocol), fueling protocol, etc.
- high level communication can process all information exceeding the information handled by command and control communication.
- the data link of high level communication may use PLC (Power line communication), but is not limited thereto.
- advanced communications may include hybrid forms, such as a combination of IrDA and wired or IrDA and wireless.
- hybrid forms such as a combination of IrDA and wired or IrDA and wireless.
- changes to the nozzle and receptacle may be required.
- wireless communication technologies can include various communication means such as 5G, WLAN, BLE, ETH, UWB, RFID, NFC, etc.
- Known protocols such as TCP/IP can be used as protocols for these communication means.
- communication means considered as wireless communication can use Bluetooth, WLAN, Wi-Fi (ISO 15118 for inductive / ACD), UWB (IEC limited consideration for ACD), etc.
- hydrogen fueling devices can be implemented to support communication of different technologies. Accordingly, the hydrogen fueling communication bidirectional process of the present embodiment is configured to maximize interoperability between the devices.
- Type 2 device supporting Specification #2 according to a given standard encounters a Type 0 device or a Type 1 device, the Type 2 device can fall back to a Type 0 device (S620).
- Type 3 device can fall back to a Type 0 device (S630).
- Type 3 device can fall back to a Type 1 device (S640).
- Type 3 device can fall back to a Type 2 device (S650).
- the aforementioned standard #1 may include the SAE (Society of Automotive Engineers) standard, etc.
- the standard #2 may include the ISO 19885-3 standard, etc.
- the hydrogen fueling device may perform a connection compatibility check.
- the hydrogen fueling device may perform a connection compatibility check as in Scenario 1 to Scenario 3 below, depending on whether WLAN, which is one of the advanced communications, is supported.
- the dispenser can be equipped with an access point (AP), which is a wireless router.
- AP access point
- the dispenser can support FCEV fuel station beaconing and fueling methods from xVSE (x-vehicle supply equipment). FCEVs in proximity to the dispenser can scan and find the dispenser, and establish a WLAN link with the found dispenser.
- FCEVs in proximity to the dispenser can scan and find the dispenser, and establish a WLAN link with the found dispenser.
- the dispenser may support IrDA communication but not WLAN communication.
- the dispenser corresponds to a Type 1 device.
- An FCEV in the vicinity of the dispenser is a Type 3 device and cannot find the dispenser, which is a Type 1 device, by scanning.
- IrDA communication can be initiated between the FCEV and the dispenser.
- the dispenser can support WLAN communication and IrDA communication.
- the dispenser corresponds to a Type 3 device.
- An FCEV a Type 1 device, can be parked near the dispenser. The dispenser cannot find any WLAN clients yet.
- IrDA communication can be initiated between the FCEV and the dispenser.
- FIG. 8 is an exemplary diagram illustrating backward compatibility that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention.
- the hydrogen fueling communication bidirectional process of the present embodiment can provide rules and principles for the fueling method and communication protocol to fall back to maximize interoperability without the FCEV and dispenser necessarily selecting the most preferred communication method.
- the device with a relatively higher type or UCDC level can be configured to fall back to the type or level of the device with a relatively lower type or level.
- both devices can maintain their current type or UCDC level.
- one device is a type 1 device and the other device is a type 2 device, both devices can be configured to fall back to a type 0 device.
- one device is a type 3 device and the other device is not a type 3 device, the type 3 device can be configured to fall back to the same type or UCDC level as the other device.
- the aforementioned specification #1 can be a communication protocol of the SAE standard, and specification #2 can be a toe-in protocol of the ISO 19885 standard.
- the vehicle and the dispenser can both support and select the best one among them.
- a device without communication hereinafter referred to as 'no communication device'
- a device supporting unidirectional communication hereinafter referred to as 'unidirectional communication device'
- the two devices can maintain the bidirectional communication method as it is.
- UCDC compatibility can be treated separately.
- a device meets a non-communication device it can rely on no communication. This can be applied to all devices supporting bidirectional communication (hereinafter referred to as 'bidirectional communication devices').
- the above-described two-way communication device can be configured to support a fueling method by one-way communication, regardless of whether one-way communication is available.
- the two-way communication device must be able to determine whether the other party supports two-way communication. If the FCEV or dispenser does not support two-way communication, the two-way communication device can fall back to a one-way communication device that uses a compatible one-way communication method.
- FIG. 9 is an exemplary diagram for explaining a communication data usage classification that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention and backward compatibility in the communication data usage classification.
- UCDC Level 0 (900) may refer to communications that are not used by the fueling protocol for dispensing of hydrogen or related safety functions, or where data is not transmitted or where data is transmitted. UCDC Level 0 (900) does not support communication between the vehicle and the dispenser (no communication), so the dispenser cannot transmit the pairing ID to the vehicle during process control or safety functions.
- the vehicle can transmit the pairing ID to the dispenser. While the data transmitted at UCDC Level 1 (910) is not used for safety functions, the static data transmitted can be used to improve the performance of the fueling protocol, and the dynamic data transmitted can be used to reduce the risk against process deviations within the fueling protocol.
- Static data transmitted at UCDC Level 2 may be used for safety functions. Such static data at UCDC Level 2 (920) may be in addition to the permitted uses for static data and dynamic data defined for UCDC Level 1.
- UCDC Level 3 static and dynamic data can be used for dynamic control within a protocol or safety function.
- This UCDC Level 3 (930) dynamic data may be in addition to the permitted uses for static and dynamic data defined for UCDC Level 2.
- the UCDC levels can have a form where UCDC level 1 is included in UCDC level 2, and UCDC level 2 is included in UCDC level 3, i.e., a higher level includes a lower level.
- a device supporting a specific UCDC level can support a device of a lower UCDC level.
- Devices supporting different UCDC levels can use the highest UCDC level supported by both devices. It can be said that the above-mentioned UCDC levels also easily support UCDC level 0. It can be seen that the UCDC levels are backward compatible. In another embodiment of the present invention, the backward compatibility can be effectively applied to each of Non-Comm, Uni-directional Comm, Bi-directional Comm, and combinations thereof, regardless of the UCDC level.
- interoperability and/or compatibility between a vehicle/mobility and a dispenser can be shared in the discovery and pairing step (S401) of FIG. 4.
- the interoperability and/or compatibility can be utilized in the communication protocol negotiation step (S403), the fuel supply protocol negotiation step (S404), and/or the fuel supply parameter negotiation step (S405) described below.
- information on interoperability and/or compatibility shared between the vehicle/mobility and the dispenser in the discovery and pairing step (S401) of FIG. 4 may be updated or re-shared while going through the communication protocol negotiation step (S403), the fuel supply protocol negotiation step (S404), and/or the fuel supply parameter negotiation step (S405).
- Information on interoperability and/or compatibility may be updated due to changes in the communication environment, changes in parameters affecting the fuel supply process, etc.
- the discovery and pairing step (S401) of FIG. 4 may also be referred to as a Dispenser Discovery Protocol (DDP).
- DDP Dispenser Discovery Protocol
- a DDP may be initiated by a DDP request message [DDPRequest] broadcast by a mobility.
- the DDPRequest may include the mobility's pairing ID "pairing_id".
- a dispenser receives a DDPRequest, and the dispenser can respond to the DDPRequest by sending a DDPResponse.
- the DDPResponse can contain the dispenser's IP address "IPAddr”, the dispenser's TCP port number "TCPPort”, the dispenser's UDP port number “UDPPort”, and the dispenser's pairing ID "pairing_id”.
- FIG. 10 is a flowchart for explaining an authentication process of a communication security procedure (S402) that can be employed in a hydrogen fuel supply communication two-way process according to one embodiment of the present invention.
- the mobility can transmit a message requesting a list of authorization methods to the dispenser (S1010).
- the dispenser can transmit a response message to the request for the list of authorization methods from the mobility to the mobility (S1020).
- the response message can include information on a list of authorization methods related to an external authentication procedure such as an RFID (radio frequency identification), credit cards, or debit cards, or a self-authentication procedure.
- the mobility can transmit an authentication request message including a specific method selected from the list of authentication methods, such as RFID, to the dispenser (S1030).
- the dispenser can transmit a response message to the authentication request of the mobility to the mobility (S1040).
- This response message can include information indicating that the authentication method selected by the mobility is working.
- the mobility can perform authentication using the previously selected authentication method according to the response of the dispenser and transmit a request message for confirmation of authentication performance (Done?) to the dispenser (S1050). If the authentication performance is not confirmed or the authentication is not completed, the above-described series of steps (S1010 to S1050) can be repeatedly performed. If the authentication is completed, the dispenser can transmit an authentication completion (Done (success)) message to the mobility (S1090).
- the dispenser can check whether the mobility is authorized, i.e., whether the user of the mobility is authorized to supply hydrogen fuel, before proceeding further with the hydrogen fueling process.
- the hydrogen fueling device including at least one of the mobility and the dispenser can establish a transport layer, i.e., a TCP connection, after a data link and physical layer connection is established between the mobility and the dispenser, and then perform a TLS handshake for authentication and exchange keys to establish a secure communication channel.
- a transport layer i.e., a TCP connection
- DTLS handshake for authentication and exchange keys to establish a secure communication channel.
- UDP communication protected by DTLS can be used while security-critical information is exchanged.
- the mobility and the dispenser can successfully perform discovery and pairing procedures and establish data link and physical layer connections. Then, credentials required for authentication and key exchange can be prepared. This allows the communication channel between the mobility and the dispenser to be encrypted and integrity protected.
- the dispenser can authenticate the mobility, and optionally, the mobility can authenticate the dispenser.
- dispenser authentication may be required and dispenser authentication may be optional, in which case the dispenser may act as a client and the mobility may act as a server.
- the mobility and the dispenser For TLS handshakes, the mobility and the dispenser must prepare the necessary credentials.
- the mobility and the dispenser can store the certificate chain, the private key corresponding to the certificate, and the trust anchor certificate in a secure repository that protects against unauthorized access.
- the mobility can request client authentication from the dispenser by sending a predefined CertificateRequest message.
- the dispenser can act to send the certificate to the mobility by sending a certificate and CertificateVerify message.
- Mobility When Mobility sends a certificate request message along with a handshake message such as ServerHello, if the dispenser does not send a certificate verification message along with the certificate, it can abort the TLS handshake by sending an alert message with the "certificate_required" alert code.
- a handshake message such as ServerHello
- step (S402) can be illustrated by the following Table 4.
- Type Description Use case name UC-2 “Communication Security” Objectives /Vehicle and Dispenser establish a secure channel over the discovered communication channel to achieve communication security goals including confidentiality, integrity, and privacy.
- Short Description After the physical and data-link layer connection is made between vehicle and dispenser, they setup layer-3 and establish a TCP connection, then perform a TLS handshake to authenticate and exchange keys to establish a secure communication channel.
- Pre-conditions Vehicle and dispenser performed discovery and pairing use case successfully and made a data-link layer connection. Credentials necessary for the authentication and key exchange are prepared.
- Post-conditions Dispenser authenticated the vehicle and the vehicle authenticated dispenser successfully. Communication channel between vehicle and dispenser are encrypted and integrity protected.
- the step of negotiating a communication protocol may include a step of transmitting a message including information on a first communication protocol applicable to the mobility to the dispenser (S1110); and a step of receiving a message including information on a second communication protocol selected from among common communication protocols applicable between the mobility and the dispenser from the dispenser (S1130).
- the dispenser may receive a message including information on a first communication protocol applicable to the mobility from the mobility (S1110), compare the first communication protocol with the communication protocol applicable to the dispenser, select a second communication protocol among common communication protocols applicable between the mobility and the dispenser, and transmit a message including information on the selected second communication protocol to the mobility (S1130).
- a step may further be included before step (S1110) in which the dispenser requests the mobility for information including a list of first communication protocols applicable to the mobility.
- an embodiment may be provided in which the dispenser first transmits a message containing information about its applicable communication protocol to the mobility, the mobility then selects a specific communication protocol among the common communication protocols, and transmits a message containing information about the selected specific communication protocol to the dispenser.
- step (S403) can be illustrated by the following Table 5.
- the contents of the message transmitted and received in step (S1110) can be illustrated by the following Table 6.
- Information about the first communication protocol may include at least one of an index of the first communication protocol, a name of the first communication protocol, a version of the first communication protocol, and a preference for the first communication protocol.
- the contents of the response message transmitted and received in step (S1130) can be illustrated by the following Table 7.
- the above-described communication protocol negotiation procedure is a procedure for identifying a communication protocol to be followed during a fueling session of hydrogen fueling after the vehicle and the dispenser discover and pair each other on a compatible communication channel.
- the dispenser may take the initiative to exchange communication protocols and parameters with the vehicle.
- a communication method can perform the step (S401) of performing a discovery and pairing process with a dispenser using a first communication technology.
- the step of negotiating the fuel supply protocol (S404) and the step of negotiating the fuel supply parameters (S405) described later can be performed using the second communication technology.
- step (S401) of performing the discovery and pairing process may be updated due to changes in the communication environment and changes in environmental variables related to hydrogen fuel supply.
- the communication protocol negotiation procedure can be implemented by all available communication protocols to ensure successful negotiation between different fueling protocols for each communication technology.
- a fueling protocol using a communication technology such as WLAN can use a protocol commonly supported by the vehicle and the dispenser (hereinafter also referred to as a “common protocol”) to determine the communication protocol to be used in the hydrogen fueling communication bidirectional process.
- common protocol a protocol commonly supported by the vehicle and the dispenser
- hydrogen fueling communication-related standards can include SAE J2601 series, ISO 19885-3, ISO 19885-4, etc.
- the communication mode can include No comm., IrDA, XYZ (ISO), etc.
- the fueling method can include a table-based fueling method such as a lookup table, an MC formula-based fueling method, etc.
- the communication level can include UCDC levels, and other parameters can include pressure class, CHSS (compressed hydrogen storage system) category, fueling tables, etc.
- the mobility or dispenser may be configured to further perform a process of falling back to a lower type or lower UCDC level of the other party depending on the mutual type or UCDC level identified in the communication protocol negotiation procedure.
- a common protocol allows the mobility and dispenser to reach agreement on the communication protocol to be used for fueling communication.
- the mobility can prioritize the communication protocols it supports.
- the mobility can provide the prioritized communication protocols to the dispenser.
- An example of the prioritized communication protocols is as shown in Table 8 below.
- Fueling protocol negotiation is the process by which the vehicle and the dispenser find and agree on a fueling protocol to be used for the fueling session. In this step, the vehicle and the dispenser can select the communication protocol that the vehicle prefers the most among the protocols that they both support.
- a hydrogen fueling communication protocol negotiation method is a hydrogen fueling communication protocol negotiation method performed by a communication control device of hydrogen fuel mobility (100), comprising: a step (S1110) of transmitting a first message including a list of at least one first fueling protocol supported by the mobility (100) and a first communication protocol required to execute the at least one first fueling protocol to a communication entity associated with a dispenser (200); and a step (S1130) of receiving a response message including a second communication protocol selected from at least one first communication protocol from the communication entity associated with the dispenser (200).
- the communication entity associated with the dispenser (200) may be an electronic control device (210) of the dispenser (200), a separate communication device mounted on the dispenser (200), or an electronic control device or separate communication device within the charging station system (200) may communicate with the vehicle/mobility (100) in place of the dispenser (200).
- the first message may include priority information based on the preference of mobility (100) as shown in Table 6.
- each message may be defined based on Tables 4 to 6.
- the response message may include a second communication protocol selected from at least one first communication protocol based on priority information based on preference.
- the mobility (100) side or the dispenser (200) side alone or in cooperation with each other may select the second communication protocol based on priority information based on preference.
- the act of finally transmitting an approval message to the other party to finish the protocol negotiation process (finished) may be mainly performed on the mobility (100) side, but may be modified to be performed on the dispenser (200) side.
- the dispenser (200) may first send a list of supported protocols, and the mobility (100) may feed back the selected protocol.
- the response message may include at least one first communication protocol and a second communication protocol selected from among common communication protocols common to the protocols supported by the dispenser (200).
- the No comm. communication standard is selected as shown in FIGS. 7 to 9, and a hydrogen fuel supply protocol according to the No comm. communication standard is selected according to a predetermined rule so that hydrogen can be supplied.
- steps (S404) to (S405) described below may be simplified or omitted.
- FIG. 12 is a flowchart illustrating a fuel supply protocol negotiation step (S404) among a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention.
- a message including information on at least one first fuel supply protocol applicable in mobility as a hydrogen fuel supply protocol supporting the selected second communication protocol can be transmitted to the dispenser (S1210).
- the dispenser may receive a message including information on a first fuel supply protocol applicable to the mobility from the mobility (S1210), compare the first fuel supply protocol with the fuel supply protocol applicable to the dispenser, select a second fuel supply protocol among common fuel supply protocols applicable between the mobility and the dispenser, and transmit a message including information on the selected second fuel supply protocol to the mobility (S1130).
- step (S1210) in which the dispenser requests the mobility for information including a list of first fuel supply protocols applicable to the mobility.
- an embodiment may be provided in which the dispenser first transmits a message containing information about its applicable fueling protocol to the mobility, the mobility then selects a specific fueling protocol from among the common fueling protocols, and transmits a message containing information about the selected specific fueling protocol to the dispenser.
- step (S404) can be illustrated by the following Table 9.
- Type Description Use case name UC-4 “Fueling Protocol Negotiation” Objectives Vehicle and Dispenser determine which fueling protocol to use for the fueling. Short Description Once communication protocol selection is done, the vehicle and the dispenser negotiates on the fuelling protocol to use for the fuelling. The negotiation starts when the vehicle sends a list of its supported protocols and then the dispenser picks a common protocol supported by both and the vehicle prefers the most. Pre-conditions A communication protocol is selected. Post-conditions The vehicle and the dispenser reached an agreement on which fueling protocol to use for their fueling.
- the contents of the message transmitted and received in step (S1210) can be illustrated by the following Table 10.
- FuellingProtocolType Fueling protocols supported by the vehicle FuellingProtocolType idx Unsigned integer Index of the protocol Name String Name of the protocol Ver String Version of the protocol subprot String Optional: Name of the sub-protocol pref Unsigned integer Preference of protocols. Smaller number represents higher preference.
- Information about the first fuel supply protocol may include at least one of an index of the first fuel supply protocol, a name of the first fuel supply protocol, a version of the first fuel supply protocol, a sub-protocol of the first fuel supply protocol, and a preference for the first fuel supply protocol.
- the contents of the response message transmitted and received in step (S1230) can be illustrated by the following Table 11.
- a message containing information about a second fuel supply protocol may further contain information on whether the fuel supply protocol negotiation was successful.
- the content of the message transmitted in step (S1210) according to one embodiment of the present invention can be represented as shown in Table 12 below.
- mobility can provide the dispenser with parameter information in the form of a table, including an arbitrarily assigned name for the supported fuel supply method or fuel supply protocol, information on the revision date (year) or version, information on whether a sub-protocol is available, and preference information.
- the dispenser may proactively exchange its own communication protocol and parameters with the mobility instead of the mobility, and may also provide priority to communication protocols supported by the dispenser to the mobility.
- PRHYDE PROtocol for heavy-duty HYDrogEn refueling
- RTR-HFP is presented by a type of protocol concept that improves fueling efficiency based on real-time communication
- ANN-MPC may be presented by a type of protocol concept that collects and analyzes data from refueling sites and applies predictions to actual refueling situations.
- the dispenser can select the fuel supply protocol corresponding to index 2 and transmit a response message including the result code OK to the mobility.
- the dispenser may send a response message to the mobility containing information indicating that there is no common protocol (e.g., FAIL_NO_COMMON_PROTOCOL) in the ResultCode field.
- Table 13 and Table 14 can be similarly applied in a case where the dispenser responds with mobility by selecting a second communication protocol among the common communication protocols in step (S1130) of FIG. 11.
- FIG. 13 is a flowchart for explaining a fueling parameter exchange/negotiation step (S405) that can be employed in a hydrogen fueling communication bidirectional process according to one embodiment of the present invention.
- the fuel supply parameter exchange/negotiation step (S405) may include a step in which the mobility and the dispenser exchange detailed parameters necessary for executing the fueling protocol.
- the step (S405) of negotiating fuel supply parameters may include a step (S1310) of transmitting a message including information on fuel supply parameters on the mobility side required by the second fuel supply protocol selected as a result of the fuel supply protocol negotiation (S404) to the dispenser; and a step (S1350) of receiving a message including compatibility information on the dispenser side for the fuel supply parameters on the mobility side from the dispenser.
- the step of negotiating the fuel supply parameters may include the step of receiving a message from the dispenser including information on the fuel supply parameters of the dispenser side required by the second fuel supply protocol selected as a result of the fuel supply protocol negotiation (S404) (S1330); and the step of transmitting a message including compatibility information on the mobility side for the fuel supply parameters of the dispenser side to the dispenser (S1370).
- Mobility can transmit a message containing information about fuel supply parameters on the mobility side at step (S1310) to the dispenser while setting the Accepted field for the corresponding parameters to ⁇ pending>.
- the dispenser can transmit a message containing information about fuel supply parameters on the dispenser side at step (S1330) while setting the Accepted field for the corresponding parameters to ⁇ pending> to the mobility.
- Mobility can respond to the dispenser by sending a message including information on fuel supply parameters on the dispenser side as a response message to the message received in step (S1330) and setting the Accepted field for the corresponding parameters to ⁇ OK> or ⁇ true> (S1350).
- the dispenser may respond to the message received in step (S1310) by sending a message including information on fuel supply parameters on the mobility side, while setting the Accepted field for the corresponding parameters to ⁇ OK> or ⁇ true>, to the mobility (S1370).
- the mobility and dispenser can respond by indicating whether each of the fuel supply parameters is Accepted or not.
- the Accepted field of the parameters that are not agreed upon can be marked as ⁇ false>.
- Mobility and dispensers can reach agreement on all parameters by repeatedly sending and receiving messages and responding to those messages.
- the parameters being exchanged may include parameters to support fueling method compatibility, parameters for physical characteristics, monitoring parameters, acceptance related parameters, etc.
- the parameters related to compatibility support include pressure class, CHSS category, etc.
- the parameters related to physical characteristics include maximum allowable CHSS pressure, maximum allowable CHSS temperature, maximum allowable speed, CHSS volume, etc.
- the monitoring parameters include current CHSS pressure, current CHSS temperature, etc.
- the parameters related to acceptance may include information indicating whether it is accepted or not, for example, a parameter indicating yes (true) or no (false).
- the above-mentioned parameters may each be set with information on one of the pre-specified levels or set values and information on the main UCDC levels that are different or the same.
- the dispenser can transmit an OK message to the mobility indicating that it has received and accepted information about the supportable parameters ( ⁇ DIS's parameters>) (shortly ⁇ DIS's params>) and the parameters of the mobility (S1330, S1370).
- Secondary parameters related to fuel supply parameter exchange/negotiation may include parameters to support fuel supply method compatibility, parameters regarding physical characteristics, parameters related to fueling goals, monitoring parameters, acceptance related parameters, etc.
- the parameters related to compatibility support include fueling delivery temperature, selected fueling table, etc.
- the parameters related to physical characteristics include maximum fuel delivery pressure, maximum fuel delivery temperature, minimum fuel delivery temperature, maximum fuel delivery speed, etc.
- the parameters related to fueling targets include target SOC, target final CHSS pressure, target final CHSS temperature, target APR, expected fueling duration, etc.
- the monitoring parameters include current fuel delivery temperature, ambient temperature, etc.
- the parameters related to acceptance may include parameters such as accepted.
- the above-mentioned parameters may each be set with information on one of preset levels or set values and information on different or identical main UCDC levels.
- the mobility can provide the dispenser with parameters listed in a table format.
- the listed parameters include FCEV parameters compatible with the UCDC level negotiated during the fuel supply protocol negotiation phase.
- the mobility and the dispenser can exchange various parameters to determine whether they can perform a compatible fueling procedure.
- the information required to perform a safe and efficient fueling procedure can include compatibility parameters, physical characteristics, fueling targets, monitoring parameters, etc.
- Compatibility parameters may include, for example, pressure rating, fuel delivery transmission temperature, etc.
- physical characteristics may include, for example, maximum CHSS pressure, maximum flow rate, etc.
- fuel delivery targets may include target SOC, target CHSS pressure, etc.
- monitoring parameters may include current CHSS temperature, ambient temperature, etc.
- the FCEV may return to the communication protocol negotiation phase to attempt to negotiate another protocol or to stop fueling to the dispenser.
- the FCEV may be configured to propose to the dispenser a set of supported protocols, excluding the protocols that failed in the fueling parameter exchange phase.
- the vehicle and the dispenser can negotiate specific parameters for the fueling protocol, communicate static or dynamic states, and exchange detailed fueling parameters to determine the fueling target.
- the fueling parameter negotiation fails due to incompatibility, it can go back to UC-3 to select another fueling protocol, or it can go back to UC-1 to select another communication protocol, and if these are not performed properly, the current communication can be terminated.
- some fueling protocols can be performed on a Non Comm. basis. Some fueling protocols may require unidirectional IrDA to be performed. Some fueling protocols may require bidirectional communication to be performed. Some fueling protocols may require both bidirectional communication and unidirectional IrDA to be performed.
- a given UCDC level or a higher UCDC level may be required for a certain fueling protocol to be performed.
- At least one fueling protocol may be proposed based on the type or type of the hydrogen fuel cell vehicle and the type or type of the dispenser.
- the proposed fueling protocols may be proposed with different priorities. While considering the priorities of the proposed fueling protocols, the communication protocol and the fueling protocol between the hydrogen fuel cell vehicle and the dispenser may be finally determined based on whether the communication protocol required by the fueling protocol is supported by the hydrogen fuel cell vehicle and/or the dispenser.
- either the mobility or the dispenser may first transmit fuel supply parameters to the other party, and the other party may respond with a message including newly reconfigured fuel supply parameters by keeping parameters it accepts among the received fuel supply parameters and changing parameters it does not accept.
- the mobility and the dispenser may perform parameter negotiation in stages.
- the mobility and the dispenser may first negotiate some of the parameters, and then perform an exchange/negotiation process for sub-parameters of the parameters for which an agreement has been reached.
- each message including fuel supply parameters may be configured to be considered as not reaching an agreement if no response message is received within a preset message processing time.
- Table 15 illustrates the contents of a message including fuel supply parameters on the mobility side according to one embodiment of the present invention.
- Table 16 illustrates the contents of a message including fuel supply parameters on the dispenser side according to one embodiment of the present invention.
- the mobility and the dispenser can generate a message with range/values for the supportable parameters (fueling parameters) and transmit it to the other party.
- Parameters may include physical characteristic related parameters (simply referred to as 'physical parameters'), monitoring parameters, safety policy related parameters, acceptance related parameters, etc.
- the physical parameters include receptacle type, pressure class, CHSS category, CHSS type, CHSS capacity, maximum allowable CHSS pressure, maximum allowable CHSS temperature, maximum allowable speed, etc.
- the monitoring parameters include current CHSS pressure, current CHSS temperature, etc.
- the safety policy related parameters include emergency policy, safety enforcement level, etc.
- the acceptance related parameters may include information indicating whether it is accepted or not, such as a parameter indicating true, false, or pending.
- Parameters relevant to fuel supply parameter negotiation may include physical characteristic related parameters (hereinafter referred to as 'physical parameters'), monitoring parameters, fuel supply target related parameters, safety policy related parameters, and acceptance related parameters.
- 'physical parameters' physical characteristic related parameters
- monitoring parameters fuel supply target related parameters
- safety policy related parameters safety policy related parameters
- acceptance related parameters acceptance related parameters
- the physical parameters include fueling delivery temperature, maximum fuel delivery pressure, maximum fuel delivery temperature, minimum fuel delivery temperature, maximum fuel delivery speed, etc.
- the monitoring parameters include current fuel delivery temperature, ambient temperature, etc.
- the fueling target related parameters include selected fueling table, target SOC, target final CHSS pressure, target final CHSS temperature, target APR, expected fueling time, etc.
- the acceptance related parameters may include parameters such as accepted, etc.
- the above-mentioned parameters may each be set with information on one of preset levels or set values and information on different or identical main UCDC levels.
- FCEV can provide the dispenser with parameters listed in a table format.
- the listed parameters include FCEV parameters compatible with the UCDC level negotiated during the fuel supply protocol negotiation phase.
- the dispenser can respond with its own fuel supply parameters by transmitting a fuel supply parameter negotiation response message with the “result” set to “OK” to the FCEV within a preset message response time.
- the FCEV may indicate the incompatibility to the dispenser by sending an error notification request message with the “reason” set to each predefined error code.
- the use case for safety check-in can be used to verify that all safety conditions are met by the vehicle and the dispenser. This step is optional, but it is recommended to define a dedicated safety check-in procedure in the fuel delivery protocol to ensure the desired safety level in a precise and explicit manner.
- FIG. 14 is a conceptual diagram illustrating a table of parameters transmitted from the mobility side to the dispenser side in a fuel supply parameter negotiation/exchange process according to one embodiment of the present invention.
- FIG. 15 is a conceptual diagram illustrating a table of parameters transmitted from a dispenser to a mobility side in a fuel supply parameter negotiation/exchange process according to one embodiment of the present invention.
- a method for exchanging fuel supply parameters over communication for hydrogen fuel supply is a method for exchanging fuel supply parameters over communication for hydrogen fuel supply performed by a communication control device of hydrogen fuel mobility (100), comprising: a step (S1310) of transmitting a first parameter including at least one or more first hydrogen fueling method compatibility supported by the mobility (100) and at least one or more first physical characteristics to a communication entity related to a dispenser (200); and a step (S1370) of receiving, from the communication entity related to the dispenser (200), a response message including a second parameter including at least one or more second hydrogen fueling method compatibility supported by the dispenser (200), at least one or more second physical characteristics, and a fueling goal.
- the communication entity associated with the dispenser (200) may be an electronic control device (210) of the dispenser (200), a separate communication device mounted on the dispenser (200), or an electronic control device or separate communication device within the charging station system (200) may communicate with the vehicle/mobility (100) in place of the dispenser (200).
- the first parameter may further include a first monitoring parameter supported by the mobility (100).
- the second parameter may further include a second monitoring parameter supported by the dispenser (200).
- a parameter exchange process may be terminated based on an confirmation message (OK message) included in a response message.
- the parameter exchange process may be terminated when the mobility (100) and the dispenser (200) accept all exchanged parameters, or may be terminated when either party does not accept the exchanged parameters.
- the protocol negotiation process may be revisited or the fuel supply session may be terminated by a process to be described later.
- At least one first hydrogen fuel supply method compatibility may include at least one of a pressure class of mobility (100) and a fuel supply tank category (CHSS Category).
- a pressure class of mobility 100
- CHSS Category fuel supply tank category
- the first parameter may further include a parameter related to acceptance of mobility (100).
- the first monitoring parameter may include at least one of current fuel supply tank pressure (Current CHSS Pressure) and current fuel supply tank temperature (Current CHSS Temperature).
- At least one second fuel supply method compatibility may include at least one of a fueling delivery temperature of a dispenser (200) and a selected fueling table.
- the selected fueling table may include a sequence table of a fueling protocol selected during a protocol negotiation process, and may be included in an OK message of S1330.
- the at least one second physical characteristic may include at least one of a maximum fuel delivery pressure (Max Fuel Delivery Pressure), a maximum fuel delivery temperature (Max Fuel Delivery Temperature), a minimum fuel delivery temperature (Min Fuel Delivery Temperature), and a maximum fuel delivery flow rate (Max Fuel Delivery Flow Rate).
- the fuel supply target may include at least one of a target SoC, a target final CHSS pressure, a target final CHSS temperature, a target average fueling rate (APR), and an expected fueling duration.
- the second parameter may further include a parameter related to acceptance of the dispenser (200).
- the second monitoring parameter may include at least one of a current fuel delivery temperature and an ambient temperature.
- Mobility (100) can provide first parameters compatible with the UCDC level negotiated during the protocol negotiation process in the form of a table at step (S1310).
- the mobility (100) may re-perform the protocol negotiation process. Alternatively, if the mobility (100) or the dispenser (200) does not accept the exchanged parameters, the mobility (100) may terminate the fueling session.
- the mobility (100) may propose a set of supported protocols other than the protocols provided in the failed parameter exchange process.
- Table 17 illustrates the contents of a message including fuel supply parameters on the mobility side according to another embodiment of the present invention.
- Table 18 illustrates the contents of a message including fuel supply parameters on the dispenser side according to another embodiment of the present invention.
- a communication method may further include a step of renegotiating at least one of a communication protocol and fuel supply parameters if the fuel supply parameters are incompatible between the mobility and the dispenser as a result of the fuel supply parameter negotiation (S405).
- the renegotiation step may perform steps (S403), (S404), and (S405) again.
- the process may go back to step (S403), perform renegotiation from step (S403), and then perform steps (S404) and (S405) sequentially again.
- the process may go back to step (S404), perform renegotiation from step (S404), and then perform step (S405) sequentially again.
- the renegotiation step may simplify steps (S403), (S404), and (S405) or omit some processes.
- steps (S403) and (S404) may be combined to negotiate the communication protocol and the fuel supply protocol together. For example, based on whether the communication protocol and the fuel supply protocol are mutually supported according to the compatibility and/or interoperability information identified in the preceding step (S401), the communication protocol and the fuel supply protocol may be negotiated together based on a protocol list that includes the communication protocol and the fuel supply protocol.
- the renegotiation step may be performed based on a list of communication protocols and fuel supply protocols other than the communication protocol or fuel supply protocol selected in the previous step (S403) and step (S404).
- a communication method may further include a step of determining a third communication protocol and a third fuel supply protocol based on a predetermined policy if the result of the fuel supply parameter negotiation (S405) determines that the fuel supply parameter is incompatible between the mobility and the dispenser; and a step of supplying hydrogen based on the third communication protocol and the third fuel supply protocol.
- the third fuel supply parameter may be determined based on the third fuel supply protocol, and the step of supplying hydrogen may be performed based on the third fuel supply protocol and the third fuel supply parameter.
- the dispenser can fall back to No Communication and supply hydrogen using a hydrogen fueling protocol based on No Communication.
- a safety check-in step (S406) that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention is illustrated.
- the mobility and/or dispenser can verify that all necessary safety conditions are met before the actual fueling begins.
- the mobility and the dispenser can perform a safety check at step S406 to determine if the fuel supply is safe.
- the safety check can be performed implicitly within the protocol according to the fuel supply protocol, and depending on the implementation, the safety check step (S406) can be omitted.
- the mobility and/or dispenser can check whether the nozzle-receptacle is secured, check for leaks, and check the last-minute status.
- the mobility can initiate the safe check-in step (S406) by transmitting a safe check-in request message to the dispenser within the message sequence setting time.
- the mobility and the dispenser can exchange messages for coupler check.
- the mobility can transmit a message including information indicating the result of its own coupler check (e.g., mobility: OK) to the dispenser, and the dispenser can transmit a message including information indicating the result of its own coupler check (e.g., DP: OK) to the mobility.
- a message including information indicating the result of its own coupler check e.g., mobility: OK
- DP DP: OK
- the mobility and the dispenser can exchange messages related to leak check of gas. While exchanging messages related to leak check, the dispenser can transmit information indicating that it is performing a leak check (ongoing) to the mobility. And the mobility can transmit information indicating that it is waiting for the leak check result of the dispenser (waiting) to the dispenser. When the leak check is completed, the dispenser can transmit a message requesting the measured tank volume together with information indicating that the leak check is completed (Done) to the mobility.
- the dispenser can send a message to the mobility for an immobilized status check, and the mobility can send a message to the dispenser indicating that it is ready for a status check.
- the dispenser can report parameters about the coupler lock status, leak check status, predicted mobility tank capacity, etc. to the mobility.
- fueling can begin.
- the mobility and the dispenser can exchange information to monitor various status parameters to ensure that the fueling is performed safely and efficiently. If necessary, the mobility or the dispenser can send a control message to control the fueling step (S406) or to request the other party to take action in response to a safety-related condition.
- the parameters and commands to be exchanged may vary depending on the actual fueling protocol.
- Step (S407) is a monitoring and control step that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention.
- the mobility and/or dispenser including the mobility can monitor the fuel supply status and control the fuel supply if necessary. If all safety checks are confirmed, the mobility and the dispenser can start supplying fuel according to the selected fuel supply protocol using the given parameters. During the fuel supply, the mobility and the dispenser can exchange various measurement data to determine the fuel supply status and operate to detect the occurrence of safety-critical accidents as quickly as possible.
- the mobility can send specific commands to the dispenser to control the fuel supply step (S407), such as starting and ending the fuel supply.
- the mobility can use UDP with DTLS for communication to support black channel communication.
- Black channel communication can refer to communication that applies the black channel principle, which ensures secure communication despite the output characteristics of the communication channel having unsecured properties or properties that are not related to the application.
- the mobility including the mobility can transmit a message to the dispenser to start fueling control, and in response, the dispenser can transmit a message including confirmation information (e.g., OK) to the mobility.
- confirmation information e.g., OK
- the mobility can send a message to the dispenser containing information about its fueling loop (e.g., x, y, z), and the dispenser can provide the mobility with a message containing information about its fueling loop corresponding to the mobility's fueling loop (e.g., a, b, c).
- the dispenser can provide the mobility with a message containing information about its fueling loop corresponding to the mobility's fueling loop (e.g., a, b, c).
- the mobility may transmit a fueling control request message to the dispenser that includes information to slow down or reduce the amount of fuel supplied, and the dispenser may transmit a response message to the mobility that includes information indicating a decrease in the fueling status (e.g., slowing).
- the mobility can transmit a fuel supply control request message requesting a stop of fuel supply to the dispenser, and the dispenser can transmit a fuel supply status response message including information on stopping or stopping fuel supply (stopping/stopped) to the mobility.
- the mobility and the dispenser can continuously or periodically exchange parameters related to the fuel supply status.
- the mobility can transmit the current tank temperature, the current tank pressure, etc. to the dispenser, and the dispenser can provide the mobility with parameters related to the start, stop, ramping up, ramping down of fuel supply, the current injection pressure, the subsequent fuel supply plan, etc.
- Request messages related to control transmitted from the mobility to the dispenser may include information or parameters regarding start, pause, resume, and terminate of fuel supply. Additionally, messages related to reporting transmitted from the mobility to the dispenser may include information or parameters regarding current tank temperature, current tank pressure, and the like.
- Messages related to reporting transmitted from the dispenser to the mobility may include information or parameters such as status information, current ambient temperature, current pressure ramp rate (PRR [Mbar/min]), deliver fuel flow rate (g/sec]), current fuel delivery temperature, pre-cooling temperature, current fuel delivery pressure, whether in use before full charge (full charge), whether in use of a cooled dispenser, whether in use of a fallback, reason for fueling stop, and current amount of hydrogen delivered.
- PRR current pressure ramp rate
- g/sec deliver fuel flow rate
- messages related to target parameter updates transmitted from the dispenser to the mobility may include information or parameters such as target final tank pressure, target final tank temperature, target fuel delivery APR, target SOC, current SOC, and estimated remaining duration.
- the mobility and the dispenser including the mobility can verify that the quantity and the dispenser each meet all safety conditions via a safety check-out use case.
- This safety check-out step is optional, but it is desirable to define a dedicated safety check step (S407) in the fueling protocol to ensure the desired safety level in a precise and explicit manner.
- a safety check-out step (S408) that can be employed in a hydrogen fuel supply communication two-way process according to one embodiment of the present invention can be performed as follows.
- the mobility and the dispenser including the mobility can confirm, through the safety check-out step (S408), whether all necessary safety conditions are satisfied before separating the nozzle of the dispenser from the outlet.
- the mobility and the dispenser can confirm that it is absolutely safe for a user or worker to separate the nozzle from the mobility after the fuel supply is completed.
- the mobility can initiate safe checkout and perform the safe checkout step (S408) by transmitting a safe checkout request message to the dispenser within a message sequence setting time.
- the mobility can transmit a message including information about the result of a coupler check (e.g., OK) to the dispenser, and the dispenser can transmit a message including information indicating that a coupler check is in progress (e.g., Ongoing) to the mobility.
- a coupler check e.g., OK
- the dispenser can transmit a message including information indicating that a coupler check is in progress (e.g., Ongoing) to the mobility.
- the mobility can transmit a message containing coupler check result information (e.g., OK) back to the dispenser, and the dispenser can transmit a message containing coupler check completion information (e.g., Done) to the mobility.
- coupler check result information e.g., OK
- coupler check completion information e.g., Done
- the report message transmitted from the dispenser to the mobility may include information or parameters regarding the coupler unlock status.
- the coupler unlock status information may include information regarding locked, unlocked, icing, problem, etc.
- the termination use case (UC9) can be performed.
- a termination step (S409) that can be employed in a hydrogen fuel supply communication bidirectional process according to one embodiment of the present invention can be performed as follows.
- the mobility can perform the termination step (S409) by sending a termination request message to the dispenser.
- the mobility including the mobility can transmit a message to the dispenser for querying how much fuel has been supplied.
- the dispenser can transmit a response message including information about the amount of hydrogen supplied (e.g., X grams) to the mobility in response to the query message of the mobility.
- the mobility can transmit a confirmation request message for the completion of fuel supply to the dispenser, and the dispenser can transmit a goodbye message to the mobility as a response message to the confirmation request message.
- the mobility and the dispenser can exchange at least some book-keeping information about the fuel supply session of the hydrogen fuel supply in the termination step (S409).
- the mobility and the dispenser can exchange summary information about the fuel supply session of the hydrogen fuel supply before completing the termination step (S409).
- the ledger information or summary information may include information about how much fuel was dispensed, what reports were generated, etc. Additionally, the reporting message transmitted from the mobility to the dispenser may include information or parameters about the current tank temperature, the current tank pressure, and the reporting message transmitted from the dispenser to the mobility may include information about the final SOC, the final average fueling rate (APR), the final measured tank pressure, the actual fueling time, the actual amount of hydrogen fueled, etc.
- APR final average fueling rate
- the error handling use case (UC10) is a function block for handling a situation in which a non-safety critical error occurs, such as terminating the fuel supply procedure similar to a normal shutdown or suddenly stopping communication.
- the error handling step (S410) may define error conditions related to the fuel supply protocol, provide detection criteria, and include response processes including notification, termination process, and fallback mechanism when detected.
- the mobility may send a TerminateReq message to the dispenser with "action" set to "stop” and “reason” set to an appropriate reason or reason code.
- An appropriate reason or reason code may include a reason such as message is corrupted.
- the error handling step (S410) defines non-safety-critical error conditions and provides exemplary error conditions and possible responses.
- Examples of communication errors may include a loss of communication, unrecognizable received data due to encoding or syntax errors, or received data being out of range.
- System errors may include instances where the dispenser or mobility detects a critical system error on its own.
- qualitative errors may include instances where the quality of communication performance does not meet a required level, or where the quality of data integrity or accuracy does not meet a required level.
- the hydrogen fuel supply communication bidirectional process of the present embodiment can perform the following specific error handling steps (S410) such as (1) to (4) for the above-described error conditions.
- Mobility and Dispenser will immediately stop supplying fuel, but may take safe action and terminate the session by stopping communication.
- the dispenser may first immediately stop fuel supply and send a termination request message to the mobility with “Action” set to “Stop” and “Reason” set to an appropriate reason or reason code.
- the hydrogen fueling communication bidirectional process including the fueling protocol can define error conditions related to the fueling protocol, provide detection criteria, and perform an error handling step (S410) including a notification, a termination step (S410), and a fallback mechanism when an error is detected by the detection criteria.
- S410 error handling step
- S410 a notification, a termination step (S410), and a fallback mechanism when an error is detected by the detection criteria.
- An emergency handling step (S411) that can be employed in a hydrogen fuel supply communication two-way process according to one embodiment of the present invention can be performed as follows.
- the emergency handling step (S411) may define safety critical conditions requiring emergency response during fuel supply and may include response processes to prevent safety critical accidents.
- the emergency handling step (S411) can define safety-critical emergency conditions and possible responses to emergency conditions, and provide critical cases to consider.
- a fueling protocol may define emergency conditions relevant to the protocol, provide detection criteria and performance requirements, and prescribe response steps (S411) to ensure that a hazardous situation is not reached.
- the mobility may transmit a first emergency stop request message including information requesting fuel supply stop due to high pressure (e.g., Emg: Stop (high pressure)) to the dispenser.
- the dispenser may transmit a response message including information indicating that it is processing emergency fuel supply stop (e.g., Emg: Stopping) to the mobility according to the first emergency stop request message.
- the mobility may transmit the first emergency stop request message back to the dispenser.
- the dispenser may transmit a response message to the mobility that includes information indicating that fuel supply has been stopped in an emergency (e.g., Emg: Stopped) according to the first emergency stop request message.
- the dispenser may transmit a second emergency stop request message including information (e.g., Emg: Stopping (leaking)) indicating that it is processing a fuel supply stop due to the leak to the mobility.
- the mobility may transmit a response message including information (e.g., Emg: Confirmed) indicating that it has confirmed the second emergency stop request message to the dispenser.
- the dispenser may transmit a third emergency stop notification message to the mobility, which includes information indicating that it has processed a fuel supply stop due to a leak (e.g., Emg: Stopped (leaking)).
- the mobility may transmit a response message to the dispenser, which includes information indicating that it has confirmed the third emergency stop notification message (e.g., Emg: Confirmed).
- the mobility or dispenser can immediately respond according to the action indicated in the emergency notification message and terminate the communication without undue delay.
- the emergency notification message includes a header and a message that is a body connected to the header, the header includes information indicating that it is an emergency notification, and the message can include values or information or parameters for the class, type, and action of the emergency notification.
- the emergency notification message described above may be transmitted as a TLS or DTLS message, depending on the technology used for communication.
- the fuel supply protocol can perform the safety check-in step (S406).
- the mobility and dispenser can recheck the pairing before dispensing hydrogen during the safety check-in step (S406).
- the mobility and dispenser can recheck the pairing before dispensing hydrogen during the safety check-in step (S406).
- the mobility can transmit a message (e.g. SafetyCheckInReq) indicating the start of the safety check-in step (S406) to the dispenser within a predetermined time interval (e.g. MessageSequenceTimeout).
- a message e.g. FuelParamNegoRes
- the mobility can transmit a message (e.g. SafetyCheckInReq) indicating the start of the safety check-in step (S406) to the dispenser within a predetermined time interval (e.g. MessageSequenceTimeout).
- messages transmitted and received in the safety check-in step (S406) may be defined based on the contents of each fuel supply protocol specified in a standard such as, for example, ISO 19885-3.
- the message transmitted and received in the safety check-in step (S406) may include a result value of processing the request message as a result element.
- the result value that may be provided as the result element may include, for example, 'OK' in case of success, 'FAILED' in case of failure, and 'PENDING' in other cases.
- the dispenser can respond to the mobility with a SafetyCheckInRes message with safety-check parameters within the MessageResponseTimeout time interval.
- the dispenser can send another SafetyCheckInReq message to the mobility within the MessageResponseTimeout time interval.
- the mobility or dispenser When the mobility or dispenser cannot confirm all safety conditions within a given time (e.g. UCSafetyCheckInTimeout), it can send an ErrNotifReq message with the "reason" field set to an appropriate error code.
- UCSafetyCheckInTimeout e.g. UCSafetyCheckInTimeout
- the mobility or dispenser may transmit a request message to the counterpart indicating the start of a safe check-in, and the counterpart may respond with a response message to the request message for a safe check-in within a predetermined time period.
- Type Description Use case name UC-7 “Fuelling control and monitoring” Objectives Vehicle and Dispenser monitors the fueling status and control the fueling if necessary. Short Description Once all the safety checks are confirmed, the vehicle and dispenser starts the fuelling according to the chosen fuelling protocol with given parameters. During the fuelling, vehicle and dispenser exchange various measured data to understand the fuelling status and detect any safety-critical incidents as early as possible. Vehicle can also submit certain commands to dispenser to control the fuelling procedure, such as starting and ending the fuelling.To support black-channel communication, UDP with DTLS is used for the communication. Pre-conditions All the safety checks are confirmed and vehicle and dispenser are ready to fuel. Post-conditions The fuelling is finished successfully.
- the fuel supply protocol can perform the monitoring and control step (S407).
- the mobility may transmit a message (e.g., FuelLoopReq message) to the dispenser requesting the start of the monitoring and control phase (S407) within a predetermined time interval (e.g., MessageSequenceTimeout) after receiving the SafetyCheckInRes message or, in an embodiment where the safety check-in phase (S406) is omitted, after receiving the FuelParamNegoRes message.
- a message e.g., FuelLoopReq message
- S407 e.g., MessageSequenceTimeout
- the mobility (as a client) and the dispenser (as a server) can initiate a DTLS 1.3 handshake following RFC 9147 with session resumption using NewSessionTicket. At this time, the NewSessinTicket can be received from the dispenser.
- the mobility can send a message (e.g. FuelLoopReq message) to the dispenser requesting the start of the monitoring and control phase (S407) within a predefined time interval (e.g. MessageSequenceTimeout).
- a message e.g. FuelLoopReq message
- S407 the start of the monitoring and control phase
- a predefined time interval e.g. MessageSequenceTimeout
- the FuelLoopReq message can be implemented based on the definition of each fueling protocol.
- the fueling protocol can specify static or dynamic data to be included within FuelLoopReq and FuelLoopRes to monitor fueling status and exchange safety-related information.
- the element names included in the message transmitted and received in step S407 may include status, reason, result, etc., and may be illustrated by Table 23 below. Elements not illustrated in the contents of Table 23 below may be specified by each fuel supply protocol standard, such as ISO 19885-3, for example.
- the dispenser can be expected to conduct an action.
- the mobility can send the message with "action" set to the desired action code.
- the action code can be defined by the fueling protocol.
- the dispenser may send a FuelLoopRes message with "result” set to "FAILED” or another appropriate error code if the received FuelLoopReq message was not successfully processed.
- a dispenser may transmit a FuelLoopRes message with "status" set to one of the supported codes specified in Table 23 or the fueling protocol.
- the dispenser may send a FuelLoopRes message with "status" set to "finished” when fueling is complete (done) and the intended fueling goal has been achieved.
- the dispenser can send a FuelLoopRes message with "status” set to "stop_error” and “reason” set to the appropriate reason code if fueling is stopped for any error-related reason.
- a dispenser can send a FuelLoopRes message with "status” set to “stopping” if the most recent FuelLoopReq message had "action” set to "stop” and fueling has not been completely stopped.
- a dispenser can send a FuelLoopRes message with "status” set to "stopped_requested” if the most recent FuelLoopReq message had "action” set to "stop” and fueling has been completely stopped.
- a mobility can send a FuelLoopReq message within a predefined time interval (e.g. MessageSequenceTimeout).
- a predefined time interval e.g. MessageSequenceTimeout
- the mobility or dispenser can immediately send an EmergencyReq message, stop the fueling procedure, and close the communication.
- step S407 has been described focusing on an embodiment in which the mobility requests the start of each step and the dispenser responds, the idea of the present invention is not limited thereto.
- either the mobility or the dispenser can first transmit a message requesting the start of step S407, and the other party can perform step S407 by responding to the message requesting the start of step S407.
- the message transmitted by either the mobility or the dispenser may include a request for monitoring regarding the status of the hydrogen fueling procedure.
- the response message to which the counterpart responds may include information regarding the requested monitoring target status.
- the state and related parameters that can be the target of the monitoring request may include the parameter set exchanged in step (S405).
- the state and related parameters that can be the target of the monitoring request may include the state and parameters of the mobility or the dispenser.
- the state and related parameters that can be the target of the monitoring request may include the fueling state and/or related parameters of the mobility and/or the dispenser that are changed or maintained by the hydrogen fueling procedure.
- the status that may be the subject of the monitoring request may include the status and/or information of the procedure itself in which fueling is performed from the dispenser to the mobility. For example, information may be included such as whether the fueling procedure is ongoing, paused, terminated, and/or, if stopped/terminated, whether it was stopped due to an error or finished due to the achievement of a goal.
- Type Description Use case name UC-8 "Safety Check-out" Objectives Vehicle and Dispenser confirms that all the necessary safety conditions are met before the nozzle can be detached from the receptacle Short Description After the fueling has been finished, the vehicle and dispenser ensure that it is absolutely safe for the user or operator to unplug the nozzle from the vehicle. The vehicle and dispenser repeatedly report their condition until the safety checks are all. This use case may be omitted if the fueling protocol does not require such safety checks at the end. Pre-conditions Fuelling is finished. Post-conditions It is safe to unplug the nozzle from the receptacle.
- a safety checkout step (S408) can be performed to ensure that the mobility and the dispenser meet safety conditions.
- This step (S408) is optional but it is strongly recommended that a dedicated safety checkout procedure be defined by the fueling protocol to ensure the desired level of safety in a precise and explicit manner.
- Information exchange during the safety checkout step can be used for the purpose of diagnosis and determination of responsibility when a safety-related incident occurs.
- the fueling protocol can perform the safety checkout step (S408).
- a fueling protocol compliant with ISO 19885-2 can define a set of safety conditions to be confirmed between the mobility and the dispenser prior to unplugging the nozzle.
- the mobility can send a message (e.g. SafetyCheckOutReq) to the dispenser over the TLS channel requesting the start of the safe checkout step (S408) within a predefined time interval (e.g. MessageSequenceTimeout).
- a message e.g. SafetyCheckOutReq
- the mobility can re-establish the TCP/TLS channel with the dispenser.
- the re-establishment process can be initiated by a TLS-resumption handshake using the NewSessionTicket received before sending the SafetyCheckOutReq message.
- a message requesting the start of step (S408) may be transmitted by either the mobility or the dispenser to the other party.
- the other party may perform step (S408) by responding to the message requesting the start of step (S408).
- messages transmitted and received in the safe check-out step (S408) may be defined based on the contents of each fuel supply protocol specified in a standard such as ISO 19885-3, for example.
- the message transmitted and received in the safe checkout step (S408) may include a result value of processing the request message as a result type.
- the result value that may be provided as the result type may include, for example, 'OK' in case of success, 'FAILED' in case of failure, and 'PENDING' in other cases.
- the dispenser can respond to the mobility with a SafetyCheckOutRes message with safety-check parameters within the MessageResponseTimeout time interval.
- the dispenser confirms that all safety conditions are met when sending a SafetyCheckOutRes message to the mobility, the result value of that message can be set to "OK".
- the mobility can send another SafetyCheckOutReq message to the dispenser within the MessageResponseTimeout time interval.
- the dispenser can send another SafetyCheckOutReq message to the mobility within the MessageResponseTimeout time interval.
- the mobility or dispenser When the mobility or dispenser cannot confirm all safety conditions within a given time (e.g. UCSafetyCheckOutTimeout), it can send an ErrNotifReq message with the "reason" field set to an appropriate error code.
- UCSafetyCheckOutTimeout e.g. UCSafetyCheckOutTimeout
- the fuel supply protocol in the monitoring and control step (S407), if a non-critical error is found and the fuel supply is interrupted before the fuel supply is completed, the fuel supply protocol can define a fallback mechanism that ensures backward compatibility among the mutually compatible mechanisms between the mobility and the dispenser, and can resume and finish the fuel supply based on the fallback mechanism.
- the fallback mechanism at this time could be, for example, a non-communication fueling method.
- Safety conditions along the connection and fuel supply path on both sides may include the nozzle-receptacle mating status - i.e., whether mated, mating condition, leakage condition, etc.
- a plurality of safety elements including the safety elements checked in the safety check-in step (S406), may be monitored and checked in the monitoring and control step (S407).
- the safety elements may be monitored and checked in the monitoring and control step (S407) independently (or independently) of being negotiated and checked in the fuel supply parameter negotiation step (S405).
- Type Description Use case name UC-9 "Termination" Objectives As the last step of fuelling, vehicle and dispenser finalizes the fuelling by exchanging information about fuelling results regarding fuelling performance and methods, and any reasons if the fueling stopped unexpectedly. This use case also handles the house-keeping when a non-safety-critical problem occurred. Short Description After the fuelling has been finished and safety checks are confirmed, vehicle and dispenser exchanges some book-keeping information regarding the fuelling session. When a non-safety-critical problem occurred, this use case allows the vehicle and dispenser to exchange wrap-up information about the fuelling session before leaving. Pre-conditions The fuelling is finished and the nozzle is safe to unplug.Or a non-safety-critical problem occurred during any other use cases. Post-conditions Information about the fueling session is stored and the fueling session is completely finished.
- the mobility can send a termination request message (e.g. "TerminateReq") to the dispenser.
- a termination request message e.g. "TerminateReq
- a mobility or dispenser When a mobility or dispenser receives an EmergencyNotif message, it can immediately respond with the action indicated in the message and close the communication without undue delay.
- the fueling protocol may not be allowed to modify the structure of the EmergencyNotif message.
- Type unsignedByte Emergency reason code by number defined in Table XYZ action unsignedByte Optional:Pre-defined action code necessary or recommended to be performed by the receiving party
- the step of determining whether to stop a communication process or a hydrogen fueling process in response to a detected error may include a step of classifying the detected error as either a safety-critical error or a non-safety-critical error.
- the step of performing a defined follow-up process based on a detected error may include at least a part of a step (S411) of performing an emergency handling process when the detected error is a safety-critical error.
- the step (S2020) of determining whether to stop a communication process or a hydrogen fuel supply process in response to a detected error may further include a step of determining whether to replace a first fuel supply protocol of the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol if the detected error is not a safety-critical error.
- Various types of incidents occurring during the execution of steps S403 to S409 can be detected by the mobility or dispenser (S2010). Incidents detected at this time can be classified as errors if they satisfy certain conditions (S2010 and S2020). If the detected error is a non-safety-critical error, it can be handled by the error handling process of step S410 or a separate subsequent step, and if it is a safety-critical error, it can be handled by the emergency handling process of step S411.
- the criteria for classifying a detected error as a non-safety-critical error or a safety-critical error (emergency) are predefined by the fuel supply protocol of steps S403 to S409, and the error detected can be classified by each step S403 to S409 when the error is detected.
- Step S410 may classify the detected error and determine whether to stop the fuel supply process based on the classification result or the status of the error. If it is determined not to stop the fuel supply process and to continue the fuel supply process by the fallback fuel supply protocol (based on updated interoperability or compatibility information), steps necessary for continuing the fuel supply process among steps S403 to S409 may be performed again as a result of step S410.
- a communication method for hydrogen fueling performed by a communication device of a dispenser for supplying hydrogen fuel to hydrogen fuel mobility comprises: a step (step S2010; which may be performed as a part of steps S403 to S406, or steps S408 to S409) for preparing hydrogen fueling between the dispenser and the mobility or a step (step S407) for supplying hydrogen from the dispenser to the mobility; a step (step S2020; which may be performed as a part of steps S410 or S411) for determining whether to stop the communication step (steps S403 to S406, or steps S408 to S409) or the process of supplying hydrogen (step S407) in response to the detected error; and may include a step of performing a defined follow-up process based on the detected error (performed as part of steps S403 to S411).
- the step of determining whether to stop a communication process or a hydrogen fuel supply process in response to a detected error may include a step of classifying the detected error as either a safety-critical error or a non-safety-critical error.
- the step (S2020) of determining whether to stop a communication process or a hydrogen fuel supply process in response to a detected error may further include a step (which may be performed as a part of step S410) of classifying the detected error as any one of a communication error, a system error, or a qualitative error if the detected error is not a fatal error to safety.
- the step of performing a defined follow-up process based on a detected error may include at least a part of a step (S411) of performing an emergency handling process when the detected error is a safety-critical error.
- the step (S2020) of determining whether to stop a communication process or a hydrogen fuel supply process in response to a detected error may further include a step of determining whether to replace a first fuel supply protocol of the communication process or the hydrogen fuel supply process with a fallback second fuel supply protocol if the detected error is not a safety-critical error.
- the step of performing a defined subsequent process based on a detected error may include a step of the dispenser performing a process of supplying hydrogen fuel based on the second fuel supply protocol when a first fuel supply protocol of the communication process or the process of supplying hydrogen is replaced with a second fuel supply protocol.
- the dispenser side can select the second fuel supply protocol by applying the first fuel supply protocol or a pre-defined fallback according to a pre-defined rule, and supply hydrogen based on the second fuel supply protocol.
- the mobility or dispenser can stop the session if necessary.
- the mobility or dispenser can stop the session if it needs to stop the session.
- the mobility or dispenser can stop the session based on the detected error and send a message to the other party including a stop action and a reason code corresponding to the reason.
- a fallback fueling protocol based on a limited communication protocol or communication environment may be selected based on updated interoperability or compatibility information between the mobility and the dispenser, and hydrogen may be fueled based on the selected fueling protocol.
- a different fueling protocol can be selected while maintaining the communication protocol between the mobility and the dispenser in case of a qualitative error.
- a different communication protocol can be selected while maintaining the fueling protocol between the mobility and the dispenser.
- the mobility and dispenser may perform renegotiation to select a new combination of communication protocol and fuel supply protocol.
- some of steps S403 to S405 may be performed again for renegotiation, or renegotiation may be performed within step S410.
- the communication can be minimized and subsequent steps can be performed.
- the mobility or dispenser can fallback the communication protocol and the fueling protocol.
- the cessation of fuel supply and communications may be performed with the highest priority.
- the step of performing a defined subsequent process based on a detected error may include a step of transmitting a message to mobility including whether to stop the communication process or the process of supplying hydrogen.
- the message when a message including whether to stop a communication process or a process of supplying hydrogen includes a stop of the communication process or the process of supplying hydrogen, the message may further include a reason code corresponding to an appropriate reason for the stop.
- steps S2010, S2020, S410, and/or S411 are related to steps S403 to S409.
- steps S2010 and S2020 can detect all incidents occurring during steps S401 to S409, or during the fuel supply process, determine whether they are errors, and classify the errors.
- the process can return to any one of steps S401 to S409 to perform the subsequent process or to perform the current process and/or the next process if the error is resolved.
- steps S2010 and S2020 can detect incidents occurring in the hydrogen fueling process, such as steps S401 - UC1: Discovery and Pairing, steps S402 - UC2: Communication Security, steps S403 - UC3: Communication Protocol Negotiation, steps S404 - UC4: Fuel Supply Protocol Negotiation, steps S405 - UC5: Fuel Supply Parameter Negotiation, steps S406 - UC6: Safety Check-In, steps S407 - UC7: Monitoring and Control, steps S408 - UC8: Safety Check-Out, steps S409 - UC9: Termination, or in parallel therewith, determine whether the incidents are errors, detect errors, or classify errors.
- steps S401 - UC1 Discovery and Pairing
- steps S402 - UC2 Communication Security
- steps S403 - UC3 Communication Protocol Negotiation
- steps S404 - UC4 Fuel Supply Protocol Negotiation
- steps S405 - UC5 Fuel Supply Parameter Negotiation
- the process can return to steps S401 to S409 or a hydrogen fuel supply process in parallel therewith.
- communications and fueling may be suspended and/or terminated.
- fueling may continue even in the event of a safety-critical error if communications are secured or fueling is available, or if fueling must continue (e.g., to evacuate a hazardous area, transport a patient, etc.).
- communication or fueling may be stopped or continued based on the criticality/severity of the error, available communication environment, available fueling protocol, UCDC level, necessity of communication or fueling, etc.
- the process of constant monitoring of interoperability, updating of interoperability information accordingly, and/or updating of a combination of communication/fuel supply protocols has been disclosed with a focus on an embodiment in which either the mobility or the dispenser performs the process, but the detailed processes of these processes may be performed by either the mobility or the dispenser, and may be performed through mutual cooperation. Furthermore, in an alternative embodiment of the present invention, part of the process of constant monitoring of interoperability, updating of interoperability information accordingly, and/or updating of a combination of communication/fuel supply protocols may be performed proactively by the mobility, and part of the process may be performed proactively by the dispenser.
- error detection can be performed by either the mobility or the dispenser, and the entity that detects the error can transmit a message to the other party that includes the detection of the error, the detected error, the suspension of communication and fuel supply based on the error, or a reason code corresponding to the reason for the suspension.
- FIG. 17 is a flowchart illustrating a communication method for hydrogen fuel supply according to another embodiment of the present invention.
- a communication method for hydrogen fueling is performed by a communication device of hydrogen fueled mobility, and may include the steps of: discovering a dispenser that fuels hydrogen to mobility, sharing pairing information between the mobility and the dispenser, and performing pairing between the mobility and the dispenser (S2100); negotiating a communication protocol or a fueling protocol for a process in which the dispenser fuels hydrogen to the mobility based on information related to interoperability or compatibility between the mobility and the dispenser (S2200); and transmitting information required for monitoring and controlling a process in which the dispenser fuels hydrogen to the mobility based on the fueling protocol to the dispenser (S2300).
- the operation performed in the step (S2100) of performing pairing may include part or all of the operation of step S401 of FIG. 4 and FIG. 16.
- the operation performed for monitoring and control may include part or all of the operation of step S407 of FIG. 4 and FIG. 16.
- the operation that the dispenser can perform in step S407 and/or the operation that the mobility can perform in step S407 may be performed in step S2300.
- a communication method for hydrogen fuel supply may further include, after the step of performing pairing (S2100), a step of establishing a secure channel between mobility and a dispenser to negotiate a communication protocol or a fuel supply protocol (see step S402 of FIG. 4 and FIG. 16).
- a communication method for hydrogen fuel supply may further include a check-in step (see step S406 of FIGS. 4 and 16) for checking whether a first necessary safety condition is satisfied between the mobility and the dispenser before the process of the dispenser supplying hydrogen to the mobility after the step of negotiating a communication protocol or a fuel supply protocol (S2200); and a check-out step (see step S408 of FIGS. 4 and 16) for checking whether a second necessary safety condition is satisfied between the mobility and the dispenser after the process of the dispenser supplying hydrogen to the mobility and before the nozzle is separated from the mobility.
- a check-in step for checking whether a first necessary safety condition is satisfied between the mobility and the dispenser before the process of the dispenser supplying hydrogen to the mobility after the step of negotiating a communication protocol or a fuel supply protocol (S2200)
- a check-out step for checking whether a second necessary safety condition is satisfied between the mobility and the dispenser after the process of the dispenser supplying hydrogen to the mobility and before the nozzle is separated from the mobility.
- the first necessary safety condition and/or the second necessary safety condition may include a connection state between the nozzle and the receptacle, an airtight state of the connection portion, a temperature, a pressure, a remaining charge (SoC) of the hydrogen storage tank on the mobility or dispenser side, etc.
- SoC remaining charge
- a communication method for hydrogen fuel supply may further include a step of detecting and handling a non-safety-critical error that occurs during the step of negotiating a communication protocol or a fuel supply protocol (S2200) or the step of transmitting information required for monitoring and control to the dispenser (S2300) (see steps S2010 and S410 of FIG. 16); and a step of detecting and handling an emergency situation that requires stopping the mutual operation between the dispenser and mobility that occurs during the step of negotiating a communication protocol or a fuel supply protocol (S2200) or the step of transmitting information required for monitoring and control to the dispenser (S2300) (see steps S2020 and S411 of FIG. 16).
- the step (S2200) of negotiating a communication protocol or a fuel supply protocol of a communication method for hydrogen fuel supply may include a step of negotiating a communication protocol between mobility and a dispenser (see step S403 of FIG. 4 and FIG. 16); a step of negotiating a fuel supply protocol between mobility and a dispenser based on the communication protocol (see step S404 of FIG. 4 and FIG. 16); and a step of negotiating a fuel supply parameter between mobility and a dispenser based on the fuel supply protocol (see step S405 of FIG. 4 and FIG. 16).
- information of the communication protocol or fuel supply protocol transmitted between the dispenser and mobility may include a protocol name, index, version, priority, or preference.
- pairing information shared between the mobility and the dispenser may include information related to interoperability or compatibility between the mobility and the dispenser.
- information related to interoperability or compatibility between mobility and a dispenser is updated based on status information when a step (S2200) of negotiating a communication protocol or a fuel supply protocol, or a step (S2300) of transmitting information required for monitoring and control to the dispenser is performed, and the step (S2200) of negotiating a communication protocol or a fuel supply protocol, or a step (S2300) of transmitting information required for monitoring and control to the dispenser may be performed based on the updated interoperability or compatibility-related information.
- a communication method for hydrogen fuel supply may further include a step of re-performing part or all of the step (S2200) of negotiating a communication protocol or a fuel supply protocol if a non-safety-critical error is detected (S2010 and S410 of FIG. 16) during the step (S2200) of negotiating a communication protocol or a fuel supply protocol.
- the information transmitted by the mobility to the dispenser can be determined based on whether the fuel supply protocol allows bidirectional communication between the mobility and the dispenser as a communication protocol.
- a communication method for hydrogen fueling may include a step (S2100) of discovering mobility, sharing pairing information between the mobility and the dispenser, and performing pairing between the mobility and the dispenser; a step (S2200) of negotiating between the mobility and the dispenser a communication protocol or a fueling protocol for a process in which the dispenser supplies hydrogen to the mobility based on information related to interoperability or compatibility between the mobility and the dispenser; and a step (S2300) of monitoring and controlling a process in which the dispenser supplies hydrogen to the mobility based on the fueling protocol.
- a communication method for hydrogen fuel supply performed by a communication device of a dispenser may further include a step (S402) of establishing a secure channel between mobility and the dispenser to negotiate a communication protocol or a fuel supply protocol after the step (S2100) of performing pairing.
- a communication method for hydrogen fuel supply performed by a communication device of a dispenser may further include a check-in step (S406) for checking whether a first necessary safety condition is satisfied between the mobility and the dispenser before a process of the dispenser supplying hydrogen to the mobility after a step (S2200) of negotiating a communication protocol or a fuel supply protocol; and a check-out step (S408) for checking whether a second necessary safety condition is satisfied between the mobility and the dispenser after the process of the dispenser supplying hydrogen to the mobility and before a nozzle is separated from the mobility.
- a check-in step S406 for checking whether a first necessary safety condition is satisfied between the mobility and the dispenser before a process of the dispenser supplying hydrogen to the mobility after a step (S2200) of negotiating a communication protocol or a fuel supply protocol
- S408 for checking whether a second necessary safety condition is satisfied between the mobility and the dispenser after the process of the dispenser supplying hydrogen to the mobility and before a nozzle is separated from the mobility.
- the step (S2200) of negotiating a communication protocol or a fuel supply protocol of a communication method for hydrogen fuel supply performed by a communication device of a dispenser may include a step (S403) of negotiating a communication protocol between mobility and the dispenser; a step (S404) of negotiating a fuel supply protocol between mobility and the dispenser based on the communication protocol; and a step (S405) of negotiating fuel supply parameters between mobility and the dispenser based on the fuel supply protocol.
- a communication method for hydrogen fuel supply may include, as part of step S401 of FIG. 4, step S401 of FIG. 16, and step S2100 of FIG. 17, a step of checking information related to interoperability or compatibility between mobility and a dispenser based on pairing information.
- the method illustrated in FIG. 17 may be performed by the mobility or by the dispenser, or may be performed by mutual cooperation between the mobility and the dispenser.
- APs wireless LAN Access Points
- dispensers some of these APs are assigned to dispensers, while others can participate in communication with mobility without being directly assigned to dispensers.
- Step S2100 may be a process for checking whether there is correct pairing between the mobility and the dispenser.
- the entity performing the pairing check may be both the mobility and the dispenser (station), or may be one of them.
- the dispenser and the mobility can perform subsequent processes related to a communication protocol or a fueling protocol for a process of fueling hydrogen to the mobility by transmitting and receiving at least one message.
- This process can correspond to, for example, step S2200 of FIG. 17, steps S403 to S405 of FIG. 4 and/or FIG. 16.
- the hydrogen fuel mobility and the dispenser/station can discover each other, check compatibility, and verify correct pairing, thereby supporting the start of the hydrogen fueling process and shortening the process up to the start of the hydrogen fueling process.
- a standardized data field such as VSE (Vendor-Specific Element) can be used to provide the functions and communication protocols and/or fuel supply protocols of each hydrogen fuel mobility and dispenser/station to the other party.
- VSE Vehicle-Specific Element
- information such as interoperability and compatibility required in a subsequent process can be shared with the other party, and the process until the start of the hydrogen fuel supply process can be shortened.
- the supported standards in the dispenser or mobility may be known standards, such as ISO 19885, or may include support for specific standards.
- the version of the standard may refer to a specific version of the standard.
- a VSE may indicate that the mobility or dispenser is an ISO 19885 device and may include compatibility information, including a list of supported communication/fueling protocols.
- identifier (ID) information for pairing may be added to the VSE data field.
- the pairing ID may be used for pairing between the mobility and the dispenser in the pairing step (S2100).
- VSE Vehicle Specific Element
- the VSE (Vendor Specific Element) data field may be added to beacon, probe request/response, association request (Assoc Req), and re-association request (Reassoc Req) messages.
- the pairing information may include location or precise positioning information of the dispenser. Additional pairing information may also be performed via a fueling cable between the mobility and the dispenser.
- Pairing information can be exchanged using additional communication technologies other than wireless LAN, such as cables, NFC, RFID, and barcodes.
- additional communication technologies other than wireless LAN, such as cables, NFC, RFID, and barcodes.
- short-range communication technologies can support precise location measurement and positioning.
- the process of checking/verifying pairing can be performed as one-way pairing.
- the mobility can check the dispenser.
- the dispenser can check the mobility, or both can check the other.
- a message may include a list of communication protocols
- the message may include a list of fuel supply protocols or fuel supply parameters. Additionally, the list of communication protocols may be exchanged in association with a list of supported fuel supply protocols.
- the first message may mean a message transmitted based on wireless communication technology by at least one wireless communication entity (2310, 2320, 2330).
- the first message may be transmitted in the form of a beacon message
- wireless LAN-based communication it may be transmitted in the form of a message allowed in wireless LAN communication.
- the communication technology on which the first message depends is not limited to a specific communication medium.
- information related to interoperability or compatibility between a dispenser and a mobility may include whether bidirectional communication between the dispenser and the mobility is supported; whether a function of sharing measurement data through bidirectional communication between the dispenser and the mobility is supported; whether the measurement data can be used to control or manage a process in which the dispenser supplies hydrogen to the mobility; or whether a fallback or alternative protocol of a communication protocol or a fueling protocol can be determined based on a change in a communication environment between the dispenser and the mobility during a process in which the dispenser supplies hydrogen to the mobility.
- the range of fueling protocols commonly supported by the dispenser or mobility may be guided by whether bidirectional communication is supported between the dispenser or mobility, as identified in the list of communication protocols supported by the dispenser or mobility.
- whether real-time measurement data can be utilized in the control or management process of the fueling protocol for the process of hydrogen being supplied from the dispenser to the mobility can be shared as interoperability/compatibility information.
- occurrence of a situation such as UC10 or UC11 may be shared between the mobility and the dispenser based on real-time measurement data.
- whether or not to fallback interoperability/compatibility information may be determined based on whether bidirectional communication is supported, whether real-time measurement data can be shared, whether real-time measurement data can be utilized, etc.
- an alternative communication/fueling protocol or a second-best communication/fueling protocol may be selected and the hydrogen fueling process may be performed or terminated depending on the situation based on the selected protocol.
- the agreement process such as the subsequent protocol negotiation step (S403 to S405) can be supported, and the negotiation process can be shortened secondarily.
- FIG. 18 is a flowchart illustrating an embodiment of step S401 of a communication method for hydrogen fuel supply according to one embodiment of the present invention.
- a communication method for hydrogen fueling is performed by a communication device of hydrogen fueled mobility, and may include the steps of: (S2400) broadcasting a Dispenser Discovery Protocol (DDP) request message via a communication network including a dispenser that supplies hydrogen to mobility; (S2500) receiving a DDP response message including identification information of the dispenser on the communication network from the dispenser; and (S2600) performing authentication for pairing between the mobility and the dispenser using the identification information of the dispenser in the DDP response message.
- DDP Dispenser Discovery Protocol
- a communication method for hydrogen fuel supply performed by a communication device of hydrogen fueled mobility may further include a step of determining an IP address of mobility to be used in a communication network including a dispenser and connecting the mobility to the communication network via a communication channel based on the IP address of the mobility, prior to the step (S2400) of broadcasting a DDP request message.
- the process of determining the IP address of the mobility may be such that the IP address is determined by the communication network and the mobility may be assigned the IP address, and in an alternative embodiment, the mobility may select one of the available IP addresses in the communication network to determine the IP address and assign the IP address to itself.
- the process of determining the IP address of the mobility may be performed through mutual cooperation between the communication network and/or the mobility, and the spirit of the present invention is not limited thereto.
- the mobility when the layer 1/2 connection is established in step S401, can join the network of the dispenser (the network to which the dispenser belongs, or a network under the management of a Fueling Station Operator (FSO) or a Fueling Station Managing System (FSMS) that manages other dispensers around the dispenser, including the dispenser).
- the mobility can join the network by assigning or being assigned an IP address of the mobility.
- the mobility can announce connection information or identification information of the mobility after joining the network.
- the mobility may announce its IP address, TCP/UDP port number, etc. based on the Dispenser Discovery Protocol (DDP).
- DDP Dispenser Discovery Protocol
- an IP address of the mobility can be generated based on a random number.
- the mobility may generate an IPv6 address by a method specified in, for example, RFC 3041, etc., in order to avoid exposure of a MAC address of the mobility, which may be permanent, when the IPv6 address is exposed or shared with a dispenser.
- a mobility can broadcast a DDPRequest message over a communication network that includes the dispenser.
- the DDP request message may or may not include identification information of the mobility, and may be broadcast using predefined information (e.g., TCP port number, UDP port number, etc.).
- predefined information e.g., TCP port number, UDP port number, etc.
- a message might be broadcast using the link-local multicasting address "0xff02::1" on port number 19885.
- the dispenser can open UDP port 19885 and prepare to receive the next message transmitted from the mobility.
- the mobility's pairing ID, etc. may be included in the initial DDP request message.
- DDPResponse ⁇ "IPaddress” : ⁇ dispenser IP address>, "TCPPort”: ⁇ dispenser's TCP port number>, "UDPPort”: ⁇ dispenser's UDP port number> "pairing_id” : ⁇ dispenser's pairing ID> (optional) ⁇
- the pairing ID of the mobility and dispenser, etc. may be shared with the other party using a separate process within the DDP protocol other than the DDP request message or DDP response message and may be used in the authentication process for pairing.
- identification information of mobility included in a DDP request message or a message transmitted in a subsequent process may include an IP address of the mobility (generated to avoid exposure of a MAC address), and identification information of a dispenser included in a DDP response message may include an IP address of the dispenser, a TCP port number of the dispenser, or a UDP port number of the dispenser.
- identification information of mobility included in a DDP request message or a message transmitted in a subsequent process may include a pairing identifier (ID) of the mobility
- identification information of a dispenser included in a DDP response message may include a pairing identifier (ID) of the dispenser.
- authentication for pairing between the mobility and the dispenser can be performed via a pairing channel different from the communication channel through which the mobility is connected to the communication network using the pairing identifier of the mobility and the pairing identifier of the dispenser.
- the step (S2600) of performing authentication for pairing between the mobility and the dispenser may include the steps of: binding a pairing channel for pairing between the mobility and the dispenser to a communication channel using a pairing identifier of the mobility and a pairing identifier of the dispenser; and performing authentication for pairing between the mobility and the dispenser using a pairing identifier of the mobility and a pairing identifier of the dispenser within the pairing channel.
- the communication channel and the pairing channel may be the same channel, in another embodiment, the communication channel and the pairing channel may be different channels of the same type, and in yet another embodiment, the communication channel and the pairing channel may be different types of channels.
- the pairing ID field in the DDP request message and/or DDP response message may be particularly useful when a pairing channel other than the communication channel is used.
- the pairing ID may be used when binding a pairing channel to a communication channel.
- the pairing channel may be implemented as a separate secure channel (e.g., TCP and/or TLS).
- the pairing channel may be established as a heterogeneous communication technology from the communication channel.
- the communication channel may be WLAN and the pairing channel may be UWB, or may be established using short-range communication such as BLE, irDA, RFID, etc.
- mutual authentication may be required between the mobility and the dispenser.
- the mobility may act as a client within TCP/TLS/DTLS and the dispenser may act as a server, the spirit of the present invention is not limited to any particular embodiment.
- a mobility DDP request message may include queries about where a dispenser is, who the dispenser is, etc.
- the dispenser's DDP response message may include information about who it is, where it is, its IP address, or port information.
- a TCP 3-way handshake and/or a TLS 3-way handshake may be performed between the mobility and the dispenser.
- the mobility sends a SYN message
- the dispenser responds with a SYN/ACK message
- the mobility can respond with an ACK message.
- the mobility sends a Client Hello message
- the dispenser responds with a Server Hello message
- the mobility can send a Client finished + First fueling message.
- each of the mobility and the dispenser can prove its own identity using a certificate and a signature.
- the dispenser can request authentication from the client (mobility) at any time.
- the mobility may log this security event in the EVCC of the mobility or an associated database, notify the user of this security event if possible, and stop fueling based on emergency handling (UC11, S411).
- the dispenser can log this security event in the dispenser's SECC or associated database and stop fueling based on emergency handling (UC11, S411).
- the message transmitted by the mobility may include information on a communication protocol or fuel supply protocol supported by the mobility as information related to interoperability or compatibility between the mobility and the dispenser.
- the DDP request message may include information on a communication protocol or fuel supply protocol supported by the mobility as information related to interoperability or compatibility between the mobility and the dispenser.
- information of a communication protocol or fueling protocol supported by the mobility may include a protocol name, an index, a version, a priority, or a preference.
- the message transmitted by the dispenser may include information on a communication protocol or fuel supply protocol supported by the dispenser as information related to interoperability or compatibility between the mobility and the dispenser.
- the DDP response message may include information on a communication protocol or fuel supply protocol supported by the dispenser as information related to interoperability or compatibility between the mobility and the dispenser.
- information of a communication protocol or fuel supply protocol supported by the dispenser may include a protocol name, an index, a version, a priority, or a preference.
- a communication method for hydrogen fuel supply performed by a communication device of hydrogen fueled mobility may further include a step (S403, S404, S405) of negotiating a communication protocol or a fuel supply protocol between the mobility and the dispenser after pairing between the mobility and the dispenser is performed.
- the steps (S403, S404, S405) of negotiating a communication protocol or a fuel supply protocol between the mobility and the dispenser may include: a step (S403) of negotiating a communication protocol between the mobility and the dispenser; a step (S404) of negotiating a fuel supply protocol between the mobility and the dispenser based on the communication protocol; and a step (S405) of negotiating fuel supply parameters between the mobility and the dispenser based on the fuel supply protocol.
- a communication method for hydrogen fueling may include a step of receiving a Dispenser Discovery Protocol (DDP) request message broadcast from a mobility via a communication network including the dispenser (S2400); a step of transmitting a DDP response message including identification information of the dispenser on the communication network to the mobility (S2500); and a step of performing authentication for pairing between the mobility and the dispenser using the identification information of the dispenser in the DDP response message between the mobility and the dispenser (S2600).
- DDP Dispenser Discovery Protocol
- identification information of mobility included in a DDP request message may include a pairing identifier (ID) of the mobility
- identification information of the dispenser included in a DDP response message may include a pairing identifier (ID) of the dispenser.
- a step (S2600) of performing authentication for pairing between mobility and the dispenser can be performed using a pairing identifier of the mobility and a pairing identifier of the dispenser.
- authentication for pairing between the mobility and the dispenser can be performed via a pairing channel different from the communication channel through which the mobility is connected to the communication network using the pairing identifier of the mobility and the pairing identifier of the dispenser.
- identification information of the dispenser included in a DDP response message may include an IP address of the dispenser, a TCP port number of the dispenser, or a UDP port number of the dispenser.
- a communication method for hydrogen fueling may further include a step (S403, S404, S405) of negotiating a communication protocol or a fueling protocol between the mobility and the dispenser after pairing between the mobility and the dispenser is performed; and a step (S407) of monitoring and controlling a process in which the dispenser supplies hydrogen to the mobility based on the fueling protocol.
- a communication method for hydrogen fueling may further include a step (not shown) of the dispenser opening a UDP port of the dispenser based on a UDP port number of a mobility included in a predefined DDP request message.
- authentication for pairing may be performed by requesting or initiating it on the mobility side as needed.
- authentication for pairing may be performed by continuously requesting or initiating the mobility from the dispenser side.
- the dispenser may periodically or continuously request or initiate the process related to authentication for pairing (S2600) from the mobility.
- authentication for pairing can be performed with unilateral authentication.
- authentication for pairing can be performed with mutual authentication.
- an entity performing the role of a server in the authentication process for pairing may transmit a certificate/certificate and signature to the other party.
- an entity performing the role of a server in the authentication process for pairing may transmit a certificate, a signature, a certification/certification request, etc. to the other party.
- the mobility when authentication for pairing (S2600) is performed with mutual authentication, the mobility can act as the server at one time and the dispenser can act as the server at another time.
- a protocol message is expressed or coded as a JSON-based message.
- the protocol message can be generated using various message coding and/or expression techniques, and the protocol message generated using various techniques can be transmitted and received between the mobility, the dispenser, and the charging station.
- FIG. 19 is a flowchart illustrating a communication method for hydrogen fuel supply according to one embodiment of the present invention.
- the mobility and/or dispenser can verify that all necessary safety conditions are met before the actual fuel supply begins.
- the mobility and dispenser can perform a safety status check at step S406 to ensure that the fuel supply is safe.
- a communication method for hydrogen fueling is performed by a communication device of hydrogen fueled mobility, and as a communication method for hydrogen fueling, the method may include: a step (S404, and/or S405) of exchanging information on a first fueling protocol between the mobility and the dispenser based on a result of a pairing process (S401) between a dispenser that supplies hydrogen to the mobility; and a step (S2800) of performing a check of a pairing process between the mobility and the dispenser if a check of the pairing process between the mobility and the dispenser is requested based on the information on the first fueling protocol before a safety check-in process is performed.
- a step (S2800) of performing a check of the pairing process between the mobility and the dispenser can be performed if the first fuel supply protocol and/or fuel supply parameters according to the first fuel supply protocol are successfully negotiated and exchanged in steps S404 and/or S405.
- the communication method for hydrogen fuel supply may further include a step (S2700) of determining whether a check of a pairing process between mobility and a dispenser is required based on information about a first fuel supply protocol.
- a step (S2700) of determining whether a check of a pairing process between mobility and a dispenser is required based on information about a first fuel supply protocol may be performed if the first fuel supply protocol and/or fuel supply parameters according to the first fuel supply protocol are successfully negotiated and exchanged in steps S404 and/or S405, and may be performed before step S2800 is executed.
- a step (S2700) of determining whether a check of a pairing process between mobility and a dispenser is required based on information on a first fuel supply protocol may include a step of determining whether information on the first fuel supply protocol includes information on a safe check-in use case.
- step (S2700) of determining whether a check of a pairing process between mobility and a dispenser is required before performing a safety check-in process (S406) of a communication method for hydrogen fuel supply it can be determined whether the first fuel supply protocol and/or the fuel supply parameters according to the first fuel supply protocol include whether a check of a pairing process is required before the safety check-in process (S406). That is, whether a check of a pairing process is required before the safety check-in process (S406) can be defined in the first fuel supply protocol and/or the fuel supply parameters according to the first fuel supply protocol.
- the step (S2800) of performing a check of a pairing process between mobility and a dispenser in a communication method for supplying hydrogen fuel may include a step of checking a pairing process (S401). At this time, it may be checked whether the pairing process (S401) has been performed validly, and whether the pairing process (S401) is still valid even after steps S404 and/or S405 are performed.
- the result of the pairing process (S401) can be verified.
- the pairing ID of each of the mobility and dispenser can be used.
- step (S2800) of performing a check of a pairing process between mobility and a dispenser in a communication method for hydrogen fuel supply if the already negotiated first fuel supply protocol and/or the fuel supply parameters according to the first fuel supply protocol do not faithfully define the contents of the UC6 safety check-in process, pairing is performed again (S401 is performed again), and if necessary, a new second fuel supply protocol can be negotiated again based on the result of the re-pairing (S403, S404, and/or S405 are performed again).
- FIG. 20 is a flowchart illustrating a communication method for hydrogen fuel supply according to another embodiment of the present invention.
- a step (S2700) of determining whether a check of a pairing process between mobility and a dispenser is required may include a step (S2900) of determining whether information on a first fuel supply protocol includes information on a safe check-in use case.
- a step (S2800) of performing a check of a pairing process between the mobility and the dispenser may include a step (S401 performed again) of performing the pairing process between the mobility and the dispenser again if information on the first fuel supply protocol does not include information on a safe check-in use case.
- pairing information shared between the mobility and the dispenser may include information related to interoperability or compatibility between the mobility and the dispenser.
- the information related to interoperability or compatibility may include information on a fuel supply protocol exchanged between the mobility and the dispenser, and information on whether the fuel supply protocol includes information on a safe check-in use case.
- a communication method for hydrogen fueling performed by a communication device of hydrogen fueled mobility may further include a step of re-negotiating a communication protocol or a fueling protocol for a process in which the dispenser supplies hydrogen to the mobility between the mobility and the dispenser (re-performing S403, S404, and/or S405) based on a result of a step of re-performing a pairing process (re-performing S401).
- a communication method for hydrogen fueling performed by a communication device of hydrogen fueled mobility may further include a step of re-negotiating a second fueling protocol for a process in which the dispenser supplies hydrogen to the mobility between the mobility and the dispenser (re-performing S403, S404, and/or S405) based on a result of a step of re-performing a pairing process (re-performing S401).
- information about the second fuel supply protocol may be determined so that the second fuel supply protocol includes information about the safety check-in use case.
- a communication method for hydrogen fueling performed by a communication device of hydrogen fueled mobility may further include a check-in step (S406) of checking whether a first necessary safety condition is satisfied between the mobility and the dispenser before a process in which the dispenser supplies hydrogen to the mobility after a check of a pairing process is performed (S401 is performed again and/or S2800); and a check-out step (S408) of checking whether a second necessary safety condition is satisfied between the mobility and the dispenser after the process in which the dispenser supplies hydrogen to the mobility and before a nozzle is separated from the mobility.
- a check-in step S406 of checking whether a first necessary safety condition is satisfied between the mobility and the dispenser before a process in which the dispenser supplies hydrogen to the mobility after a check of a pairing process is performed (S401 is performed again and/or S2800)
- S408 of checking whether a second necessary safety condition is satisfied between the mobility and the dispenser after the process in which the dispenser supplies hydrogen to the mobility and before a nozzle is separated from the mobility.
- the pairing result, the pairing information, and/or the pairing verification result if it is determined that part or all of the process performed up to that point (S401 to S405) needs to be performed again, part or all of the process performed up to that point (S401 to S405) can be performed again according to the protocol of step S410.
- the type of error may include a case where the pairing check/verification result is a fail, or a case where the fuel supply protocol does not faithfully define the UC6: safe check-in process.
- a communication method for hydrogen fuel supply performed by a communication device of hydrogen fueled mobility may further include a step (S2010, S2020, S411) of detecting and handling an emergency situation in which mutual operation between a dispenser and mobility must be stopped based on a check result of a pairing process (re-performing S401 and/or S2800).
- the mutual operation between the dispenser and the mobility may be stopped according to the protocol of step S411.
- the types of critical errors may include a case where the pairing check/verification result fails, or the fuel supply protocol does not faithfully define the UC6: safe check-in process.
- the step of renegotiating the second fuel supply protocol may include the step of renegotiating a communication protocol linked to the second fuel supply protocol between the mobility and the dispenser (re-performing S403); the step of renegotiating the second fuel supply protocol between the mobility and the dispenser based on the communication protocol (re-performing S404); and the step of renegotiating fuel supply parameters between the mobility and the dispenser based on the second fuel supply protocol (re-performing S405).
- the information of the communication protocol or fuel supply protocol transmitted between the dispenser and the mobility may include a protocol name, index, version, priority, or preference.
- pairing in a situation where pairing is required in step S406 (safety check-in use case) based on content predefined in the fuel supply protocol, pairing can be performed during the safety check-in process. Even if the content predefined in the fuel supply protocol incompletely defines the safety check-in use case or it is unclear whether pairing is to be performed in the safety check-in use case, in an alternative embodiment of the present invention, a pairing check can be performed before starting step S407 after step S405.
- steps of FIG. 19 and/or FIG. 20 may be performed as preparatory steps before the start of step S406 (safety check-in use case).
- steps S401 to S405 may be optionally re-performed.
- some of steps S401 to S405 that are optionally re-performed may be re-performed based on interoperability/compatibility between the mobility and the dispenser, whether the fueling protocol faithfully defines the safe check-in use case, etc.
- the mobility and/or dispenser can check whether the nozzle-receptacle is fixed, check for leakage, and check the last-minute status.
- the mobility can initiate the safe check-in step (S406) by transmitting a safe check-in request message to the dispenser within the message sequence setting time.
- the mobility and the dispenser can exchange messages for coupler check.
- the mobility can transmit a message including information indicating the result of its own coupler check (e.g., mobility: OK) to the dispenser, and the dispenser can transmit a message including information indicating the result of its own coupler check (e.g., DP: OK) to the mobility.
- a message including information indicating the result of its own coupler check e.g., mobility: OK
- DP DP: OK
- the mobility and the dispenser can exchange messages related to leak check of gas. While exchanging messages related to leak check, the dispenser can transmit information indicating that it is performing a leak check (ongoing) to the mobility. And the mobility can transmit information indicating that it is waiting for the leak check result of the dispenser (waiting) to the dispenser. When the leak check is completed, the dispenser can transmit a message requesting the measured tank volume together with information indicating that the leak check is completed (Done) to the mobility.
- the dispenser can send a message to the mobility for an immobilized status check, and the mobility can send a message to the dispenser indicating that it is ready for a status check.
- fueling can begin.
- the mobility and the dispenser can exchange information to monitor various status parameters to ensure that fueling is performed safely and efficiently (S407). If necessary, the mobility or the dispenser can send a control message to control the fueling step (S406) or to request the other party to take action in response to a safety-related condition.
- the parameters and commands to be exchanged may vary depending on the actual fueling protocol.
- pairing information shared between the mobility and the dispenser may include information related to interoperability or compatibility between the mobility and the dispenser.
- information about the second fuel supply protocol may be determined so that the second fuel supply protocol includes information about the safety check-in use case.
- additional information may be considered in addition to the information considered in the previous steps S401 to S405.
- additional information may include information on whether the fueling protocol satisfying interoperability/compatibility faithfully defines the information of UC6: Safe Check-In Process.
- additional information may include information about whether the negotiated first fueling protocol requires a UC6: Safe Check-In procedure, and whether the current communication and fueling environment, etc., are suitable for faithfully performing the UC6: Safe Check-In procedure defined in the first fueling protocol.
- a processor and a memory are electronically connected to each component, and the operation of each component can be controlled or managed by the processor.
- At least a part of the process of a fuel supply communication method for supplying fuel to an electric vehicle according to one embodiment of the present invention can be executed by the computing system (3000) of FIG. 21.
- the processor (3100) may mean a central processing unit (CPU), a graphics processing unit (GPU), or a dedicated processor on which methods according to embodiments of the present invention are performed.
- CPU central processing unit
- GPU graphics processing unit
- dedicated processor on which methods according to embodiments of the present invention are performed.
- Each of the memory (3200) and the storage device (3400) may be configured with at least one of a volatile storage medium and a nonvolatile storage medium.
- the memory (3200) may be configured with at least one of a read only memory (ROM) and a random access memory (RAM).
- the computing system (3000) may further include a storage device (3400), an input interface (3500), an output interface (3600), etc.
- the processor (3100) can determine whether information about the first fuel supply protocol includes information about a safe check-in use case (S2900).
- the pairing information shared between the mobility and the dispenser may include information related to interoperability or compatibility between the mobility and the dispenser.
- interoperability or compatibility related information may include information about the fueling protocol exchanged between the mobility and the dispenser, information about whether the fueling protocol includes information about a safe check-in use case.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Mechanical Engineering (AREA)
- General Engineering & Computer Science (AREA)
- Filling Or Discharging Of Gas Storage Vessels (AREA)
- Vehicle Cleaning, Maintenance, Repair, Refitting, And Outriggers (AREA)
- Computing Systems (AREA)
Abstract
본 발명의 일 실시예에 따른 방법은, 모빌리티에 수소를 연료공급하는 디스펜서와 모빌리티 간 페어링 과정의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하는 단계; 및 안전 체크인 과정이 수행되기 전에, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행하는 단계를 포함한다.
Description
본 발명은 충전소(station)/디스펜서(dispenser)로부터 수소 연료 모빌리티(hydrogen fueled mobility)로 수소 연료공급 (hydrogen fueling)을 위한 통신 기술에 관한 것으로, 더욱 상세하게는 수소 연료공급의 안전성, 호환성, 효율 및 신뢰성을 향상시킬 수 있는 수소 연료공급 프로세스, 그 수소 연료공급 프로세스를 위한 양방향 통신 방법 및 이를 이용하는 장치{METHOD AND APPARATUS FOR BIDIRECTIONAL COMMUNICATION FOR HYDROGEN FUELING INCLUDING IMPROVED SAFETY CHECK-IN PROCESS}에 관한 것이다.
이 부분에 기술된 내용은 단순히 본 실시예에 대한 배경 정보를 제공할 뿐 종래 기술을 제공하는 것은 아니다.
수소차 또는 수소전기차는 차량에 저장된 고압 수소와 대기 중 공기가 만나 생성된 전기에너지로 움직이는 무공해 자동차를 의미한다. 수소전기차는 연료전지차(FCEV, Fuel Cell Electric Vehicle)이라고 불리기도 한다. 수소전기차 대부분은 수소를 에너지원으로 활용해 연료전지 시스템을 이용하여 전기를 생산해 움직인다. 수소전기차에서는 전기를 만드는 과정에서 순수한 물(H2O)만 배출할 뿐 아니라, 운행 중 대기에 있는 초미세먼지를 제거하는 기능이 있어 미래 친환경 모빌리티로 주목받고 있다. 연료인 수소가 지구상에 무한하다는 점과 에너지를 생산하는 과정이 친환경적이라는 점에서 산업 전반에 활용할 수 있는 잠재력을 갖춘 기술로 널리 각광받고 있다.
수소 연료 모빌리티(hydrogen fueled mobility)는 수소를 에너지원으로 하거나 수소를 연료로 하여 전기 에너지를 생성하고 이를 이용하여 전동기를 구동하는 방식의 모빌리티를 의미한다. 수소 연료 모빌리티는 앞서 설명한 수소전기차 외에 공중 모빌리티(aerial mobility)는 물론, 산업용 트럭, 열차, 선박, 항공기를 포함하고, 수소를 연료로 하여 전기에너지를 생성하고 이를 이용하여 구동하는 장치를 포함할 수 있다.
수소전기차 대부분은 수소연료저장탱크에 안전하게 보관된 고압 수소와 공기공급시스템을 통해 유입된 산소를 연료전지스택에 전달하고, 수소와 산소 간 전기화학 반응을 일으켜 전기에너지를 생산한다. 생산된 전기에너지는 구동모터를 통해 운동에너지로 전환되어 수소전기차를 움직이며, 주행 중인 수소전기차는 배출구를 통해 순수한 물(pure water)만을 배출하는 장점을 가진다.
한편, 수소전기차가 아닌 수소연료차(Hydrogen Fueled Car)의 개념 또한 수소를 연료로 사용하는 차량인데, 수소연료차는 수소를 엔진 (ICE, Internal Combustion Engine)에서 직접 연소하여 발생하는 열로 전동기를 구동하는 방식이다. 수소연료차를 위해서 수소를 연료공급하는 방식은 수소전기차를 위한 수소 연료공급 방식과 크게 다르지 않다.
수소를 연료로 활용하는 차량에 수소를 공급하기 위한 제어 기법에서는, 최종적으로 연료전지 측의 압축수소저장시스템(CHSS, Compressed Hydrogen Storage System)의 온도와 압력을 수소 연료공급의 안전을 위한 한계 온도 및 한계 압력 조건 하에서 동작하도록 제어하는 것을 목표로 한다.
종래의 수소전기차의 수소 연료공급 프로세스, 제어 기법, 및 이를 위한 프로토콜은 과거 유무선 통신 기술이나 제어를 위한 컴퓨팅 기법이 성숙하지 않았을 때 규정된 것이어서 최근 도달한 정보통신기술(ICT)의 성과를 제대로 반영하지 못하고 있다. 따라서 종래의 수소전기차의 수소 연료공급 기술은 비효율적이고 느리며 대용량 수소 연료공급에 적합하지 않다.
특히, 수소 연료공급 통신에 있어서, 무선의 경우, 대부분의 수소 연료공급 제어 장치가 단방향 적외선 통신 장치를 이용하고 있으며, 따라서 무선 기반의 수소 연료공급 통신에 있어서도 단방향 통신의 한계 및 취약점을 여전히 가지고 있다.
상기와 같은 문제점을 해결하기 위한 본 발명의 목적은, 수소 연료 모빌리티(hydrogen fueled mobility)의 수소 연료공급(hydrogen fueling) 프로세스, 및 그 프로세스를 위한 통신 프로토콜에서 기존의 단방향 통신의 한계 및 취약점들을 극복하고 수소 연료공급의 안전성, 호환성, 효율 및 신뢰성을 향상시킬 수 있는 수소 연료공급 프로세스, 그 수소 연료공급 프로세스를 위한 통신 프로토콜 협상, 연료공급 프로토콜(fueling protocol) 협상, 연료공급 파라미터 협상 방법, 모니터링 제어 (Monitoring and Control) 방법, 안전 체크인 (Safety Check-in) 방법, 안전 체크아웃 (Safety Check-out) 방법 및 이를 이용하는 장치를 제공하는 것이다.
본 발명의 다른 목적은 수소 연료공급 프로세스를 위한 통신 프로토콜 협상, 연료공급 프로토콜(fueling protocol) 협상, 연료공급 파라미터 협상, 모니터링 제어 (Monitoring and Control), 안전 체크인 (Safety Check-in), 안전 체크아웃 (Safety Check-out) 과정에서 발생하는 에러 및/또는 이머전시를 핸들링하는 수소 연료공급 프로세스를 위한 에러 핸들링 (error handling), 및 이머전시 핸들링 (emergency handling) 방법 및 이를 이용하는 장치에 관한 것이다.
본 발명의 다른 목적은 수소 연료 모빌리티와 디스펜서가 수소 연료공급 목표(fueling goal)를 효과적으로 달성하기 위해 종래의 통신 매체 또는 어드밴스드(advanced) 통신 매체를 결정하도록 제어할 수 있는 수소 연료공급 통신 양방향 프로세스, 양방향/단방향 통신을 고려하는 통신 프로토콜 협상 프로세스, 및 이를 이용하는 장치를 제공하는데 있다.
본 발명의 다른 목적은 수소 연료 모빌리티와 디스펜서 간에 수행되는 안전 체크인 (Safety Check-In) 유즈 케이스의 개선된 버전을 제안하고 제공하는 데 있다.
상기 목적을 달성하기 위한 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되며, 수소 연료공급(fueling)을 위한 통신 방법으로서, 모빌리티에 수소를 연료공급하는 디스펜서와 모빌리티 간 페어링 과정의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하는 단계; 및 안전 체크인 과정이 수행되기 전에, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계를 포함할 수 있다.
이때 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 모빌리티와 디스펜서 간 페어링 과정을 다시 수행하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정을 다시 수행하는 단계에서 모빌리티와 디스펜서 간 공유되는 페어링 정보는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함할 수 있다. 이때 상호운용성 또는 호환성 관련 정보는, 모빌리티와 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계를 더 포함할 수 있다.
이때, 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 제2 연료공급 프로토콜이 결정될 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정의 체크가 수행된 이후에, 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이전에 모빌리티와 디스펜서 간 제1 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-인 단계; 및 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이후 및 모빌리티에서 노즐이 분리되기 전에, 모빌리티와 디스펜서 간 제2 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-아웃 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정의 체크 결과에 기반하여, 안전에 치명적이지 않은 에러(non-safety-critical error)를 검출하고 핸들링하는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정의 체크 결과에 기반하여, 디스펜서 및 모빌리티 간 상호 동작을 중지해야 하는 긴급상황을 검출하고 핸들링하는 단계를 더 포함할 수 있다.
제2 연료공급 프로토콜을 다시 협상하는 단계는, 모빌리티와 디스펜서 간 제2 연료공급 프로토콜과 연계되는 통신 프로토콜을 다시 협상하는 단계; 통신 프로토콜에 기반하여, 모빌리티와 디스펜서 간 제2 연료공급 프로토콜을 다시 협상하는 단계; 및 제2 연료공급 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 파라미터를 다시 협상하는 단계를 포함할 수 있다.
제2 연료공급 프로토콜을 다시 협상하는 단계에서, 디스펜서 및 모빌리티 간에 전송되는 통신 프로토콜 또는 연료공급 프로토콜의 정보는 프로토콜 이름, 인덱스, 버전, 우선순위 또는 선호도를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급(fueling)을 위한 통신 방법은, 모빌리티와 디스펜서 간 페어링 과정의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하는 단계; 및 안전 체크인 과정이 수행되기 전에, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계를 포함할 수 있다.
이때 본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 모빌리티와 디스펜서 간 페어링 과정을 다시 수행하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정을 다시 수행하는 단계에서 모빌리티와 디스펜서 간 공유되는 페어링 정보는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함할 수 있다.
이때 상호운용성 또는 호환성 관련 정보는, 모빌리티와 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계를 더 포함할 수 있다.
이때 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 제2 연료공급 프로토콜이 결정될 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티의 통신 장치는, 적어도 하나 이상의 명령을 저장하는 메모리(memory); 및 적어도 하나의 명령을 실행하는 프로세서(processor)를 포함하고, 프로세서는 적어도 하나 이상의 명령에 의하여, 모빌리티에 수소를 연료공급하는 디스펜서와 모빌리티 간 페어링 과정의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환할 수 있고, 안전 체크인 과정을 수행하기 전에, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부를 판정할 수 있고, 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행할 수 있다.
이때, 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정될 수 있다.
프로세서는, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정될 때, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정할 수 있다.
프로세서는, 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행할 때, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 모빌리티와 디스펜서 간 페어링 과정을 다시 수행할 수 있다.
프로세서가 페어링 과정을 다시 수행할 때, 모빌리티와 디스펜서 간 공유되는 페어링 정보는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함할 수 있다.
이때 상호운용성 또는 호환성 관련 정보는, 모빌리티와 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함할 수 있다.
프로세서는, 적어도 하나 이상의 명령에 의하여, 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상할 수 있다.
프로세서는, 적어도 하나 이상의 명령에 의하여, 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상할 수 있다.
이때 본 발명의 일 실시예에 따른 수소 연료 모빌리티의 통신 장치에서 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 제2 연료공급 프로토콜이 결정될 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서의 통신 장치는, 적어도 하나 이상의 명령을 저장하는 메모리(memory); 및 적어도 하나의 명령을 실행하는 프로세서(processor)를 포함하고, 프로세서는 적어도 하나 이상의 명령에 의하여, 모빌리티와 디스펜서 간 페어링 과정의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환할 수 있고, 안전 체크인 과정이 수행되기 전에, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행할 수 있다.
이때, 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정될 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법 및 이를 이용하는 장치, 즉, 차량/모빌리티의 수소 연료공급 제어 장치 또는 통신 제어 장치에 의하면, 수소전기차(FCEV: fuel cell electric vehicle) 및 수소 연료 엔진을 포함하는 수소 연료 모빌리티(hydrogen fueled mobility)의 수소 연료공급(hydrogen fueling) 프로세스 및 그를 위한 통신 프로토콜에서 기존의 단방향 통신의 한계 및 취약점들을 극복하고 수소 연료공급의 안전성, 호환성, 효율, 및 신뢰성을 향상시킬 수 있다.
또한, 본 발명의 일 실시예에 따르면, 모빌리티와 디스펜서가 모빌리티 또는 디스펜서의 선호도에 따른 우선 순위를 고려하되 모빌리티와 디스펜서 간의 상호운용성(interoperability)을 극대화하고 하위 호환성 (backward compatibility)을 고려하여 수소 연료공급을 위한 프로토콜을 실행하기 위하여 요구되는 통신 프로토콜을 유즈케이스에 따라 선택하는 수소 연료공급을 위한 통신 프로토콜 협상, 연료공급 프로토콜 협상, 및 파라미터 교환 방법 및 통신 프로토콜 폴백 규칙을 제공할 수 있다.
또한, 본 발명의 일 실시예에 따르면, 모빌리티와 디스펜서가 협력하여 수소 연료공급 목표(fueling goal)를 효과적으로 달성하기 위해 종래의 통신 매체 또는 어드밴스드(advanced) 통신 매체를 효과적으로 결정하도록 통신 프로토콜 협상, 연료공급 프로토콜 협상, 및 연료공급 파라미터 교환에 필요한 규칙과 절차를 제공할 수 있다.
또한, 본 발명의 일 실시예에 따르면, 모빌리티와 디스펜서가 협력하여 수소 연료공급 목표(fueling goal)를 효과적으로 달성하기 위해 모니터링 및 제어 (Monitoring and Control), 안전 체크인 (Safety Check-in), 및 안전 체크아웃 (Safety Check-out)에 필요한 규칙과 절차를 제공할 수 있다.
또한, 본 발명의 일 실시예에 따르면, 모빌리티와 디스펜서가 협력하여 수소 연료공급 목표(fueling goal)를 효과적으로 달성하기 위해 모니터링 및 제어 (Monitoring and Control), 안전 체크인 (Safety Check-in), 및 안전 체크아웃 (Safety Check-out) 과정과 통신 프로토콜 협상, 연료공급 프로토콜 협상, 및 연료공급 파라미터 교환 과정이 연동되는 유즈 케이스에 필요한 규칙과 절차를 제공할 수 있다.
또한, 본 발명의 일 실시예에 따르면, 모빌리티와 디스펜서가 협력하여 수소 연료공급 목표(fueling goal)를 효과적으로 달성하기 위해 통신 프로토콜 협상, 연료공급 프로토콜(fueling protocol) 협상, 연료공급 파라미터 협상, 모니터링 제어 (Monitoring and Control), 안전 체크인 (Safety Check-in), 안전 체크아웃 (Safety Check-out) 과정에서 발생하는 에러 및/또는 이머전시를 핸들링하는 수소 연료공급 프로세스를 위한 에러 핸들링 (error handling), 및 이머전시 핸들링 (emergency handling) 과정이 연동되는 유즈 케이스에 필요한 규칙과 절차를 제공할 수 있다.
또한, 본 발명의 일 실시예에 따르면, 수소 연료 모빌리티와 디스펜서 간에 수행되는 안전 체크인 (Safety Check-In) 유즈 케이스의 개선된 버전을 구현하는 데 필요한 규칙과 절차를 제공할 수 있다.
도 1은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스를 적용할 수 있는 수소전기차(FCEV, fuel cell electric vehicle) 수소 연료공급 시스템에 대한 개념도이다.
도 2는 도 1의 수소 연료공급 시스템에서 FCEV와 디스펜서 간의 물리적인 체결 구조를 설명하기 위한 부분 확대도이다.
도 3은 도 1의 수소 연료공급 시스템에 의한 수소 연료공급 과정에서 나타나는 수소 연료의 상태 변화를 설명하기 위한 그래프이다.
도 4는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스를 채용할 수 있는 일련의 수소 연료공급 절차를 수행하는 기능 블록들에 대한 프레임워크이다.
도 5는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 각 유즈케이스와 관련된 통신 스택에 대해 OSI(Open Systems Interconnection reference model) 7 계층을 중심으로 나타낸 예시도이다.
도 6은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 발견 및 페어링(discovery and pairing) 절차의 페어링 과정을 설명하기 위한 예시도이다.
도 7은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 하위 호환성(backward compatibility)을 설명하기 위한 예시도이다.
도 8은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 하위 호환성(backward compatibility)을 설명하기 위한 예시도이다.
도 9는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 통신 데이터 사용 분류와 통신 데이터 사용 분류에서 하위 호환성(backward compatibility)을 설명하기 위한 예시도이다.
도 10은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 통신 보안 절차의 인증 과정을 설명하기 위한 흐름도이다.
도 11은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 통신 프로토콜 협상(communication protocol negotiation) 절차를 설명하기 위한 흐름도이다.
도 12는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스 중 연료공급 프로토콜 협상 절차를 설명하기 위한 흐름도이다.
도 13은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 연료공급 파라미터 교환/협상 (fueling parameter exchange/negotiation) 절차를 설명하기 위한 흐름도이다.
도 14는 본 발명의 일 실시예에 따른 연료공급 파라미터 협상/교환 프로세스에서 모빌리티로부터 디스펜서 측으로 전달되는 파라미터의 테이블을 도시하는 개념도이다.
도 15는 본 발명의 일 실시예에 따른 연료공급 파라미터 협상/교환 프로세스에서 디스펜서로부터 모빌리티 측으로 전달되는 파라미터의 테이블을 도시하는 개념도이다.
도 16은 도 4의 대안적 실시예 중 하나를 도시하는 동작 흐름도이다.
도 17은 본 발명의 다른 일 실시예에 따른 수소 연료공급을 위한 통신 방법을 도시하는 동작 흐름도이다.
도 18은 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 단계 S401의 일 실시예를 도시하는 동작 흐름도이다.
도 19는 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법을 도시하는 동작 흐름도이다.
도 20은 본 발명의 다른 일 실시예에 따른 수소 연료공급을 위한 통신 방법을 도시하는 동작 흐름도이다.
도 21은 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 장치, 통신 제어 장치, 및/또는 전자 제어 장치로서 수소 연료 모빌리티, 디스펜서, 및/또는 연료공급 스테이션에 탑재될 수 있는 일반화된 컴퓨팅 시스템의 내부 구조에 대한 개념적인 블록도이다.
상기 목적 외에 본 발명의 다른 목적 및 특징들은 첨부 도면을 참조한 실시예에 대한 설명을 통하여 명백히 드러나게 될 것이다.
본 발명은 다양한 변경을 가할 수 있고 여러 가지 실시예를 가질 수 있는 바, 특정 실시예들을 도면에 예시하고 상세하게 설명하고자 한다. 그러나, 이는 본 발명을 특정한 실시 형태에 대해 한정하려는 것이 아니며, 본 발명의 사상 및 기술 범위에 포함되는 모든 변경, 균등물 내지 대체물을 포함하는 것으로 이해되어야 한다.
제1, 제2, A, B 등의 용어는 다양한 구성요소들을 설명하는 데 사용될 수 있지만, 상기 구성요소들은 상기 용어들에 의해 한정되어서는 안 된다. 상기 용어들은 하나의 구성요소를 다른 구성요소로부터 구별하는 목적으로만 사용된다. 예를 들어, 본 발명의 권리 범위를 벗어나지 않으면서 제1 구성요소는 제2 구성요소로 명명될 수 있고, 유사하게 제2 구성요소도 제1 구성요소로 명명될 수 있다. "및/또는"이라는 용어는 복수의 관련된 기재된 항목들의 조합 또는 복수의 관련된 기재된 항목들 중의 어느 항목을 포함한다.
본 출원의 실시예들에서, "A 및 B 중에서 적어도 하나"는 "A 또는 B 중에서 적어도 하나" 또는 "A 및 B 중 하나 이상의 조합들 중에서 적어도 하나"를 의미할 수 있다. 또한, 본 출원의 실시예들에서, "A 및 B 중에서 하나 이상"은 "A 또는 B 중에서 하나 이상" 또는 "A 및 B 중 하나 이상의 조합들 중에서 하나 이상"을 의미할 수 있다.
어떤 구성요소가 다른 구성요소에 "연결되어" 있다거나 "접속되어" 있다고 언급된 때에는, 그 다른 구성요소에 직접적으로 연결되어 있거나 또는 접속되어 있을 수도 있지만, 중간에 다른 구성요소가 존재할 수도 있다고 이해되어야 할 것이다. 반면에, 어떤 구성요소가 다른 구성요소에 "직접 연결되어" 있다거나 "직접 접속되어" 있다고 언급된 때에는, 중간에 다른 구성요소가 존재하지 않는 것으로 이해되어야 할 것이다.
본 출원에서 사용한 용어는 단지 특정한 실시예를 설명하기 위해 사용된 것으로, 본 발명을 한정하려는 의도가 아니다. 단수의 표현은 문맥상 명백하게 다르게 뜻하지 않는 한, 복수의 표현을 포함한다. 본 출원에서, "포함하다" 또는 "가지다" 등의 용어는 명세서상에 기재된 특징, 숫자, 단계, 동작, 구성요소, 부품 또는 이들을 조합한 것이 존재함을 지정하려는 것이지, 하나 또는 그 이상의 다른 특징들이나 숫자, 단계, 동작, 구성요소, 부품 또는 이들을 조합한 것들의 존재 또는 부가 가능성을 미리 배제하지 않는 것으로 이해되어야 한다.
다르게 정의되지 않는 한, 기술적이거나 과학적인 용어를 포함해서 여기서 사용되는 모든 용어들은 본 발명이 속하는 기술 분야에서 통상의 지식을 가진 자에 의해 일반적으로 이해되는 것과 동일한 의미를 가지고 있다. 일반적으로 사용되는 사전에 정의되어 있는 것과 같은 용어들은 관련 기술의 문맥 상 가지는 의미와 일치하는 의미를 가지는 것으로 해석되어야 하며, 본 출원에서 명백하게 정의하지 않는 한, 이상적이거나 과도하게 형식적인 의미로 해석되지 않는다.
본 명세서에 사용되는 일부 용어를 정의하면 다음과 같다.
수소전기차는 일반적으로 연료전지를 이용하는 수소연료전지차(FCEV, fuel cell electric vehicle) 또는 수소를 연료로 이용하는 ICE(internal combustion engine) 기반 차량을 모두 포함할 수 있다. 이하에서 설명하는 수소전기차는 간략히 FCEV로도 지칭될 수 있다.
이하의 실시예에서는 수소연료전지차를 주된 실시예로 기재하였으나, 본 발명의 다른 실시예는 수소를 연료로 이용하는 ICE 기반 수소전기차를 포함할 수 있다. 이하의 실시예에서 수소연료전지차를 중심으로 수소 연료공급(fueling) 프로토콜 및/또는 수소 연료공급을 위한 통신 프로토콜이 개시되며, 본 발명의 다른 실시예에 의하면 ICE 기반 수소전기차에서도 이하의 실시예에서 개시된 수소 연료공급 프로토콜 및/또는 수소 연료공급을 위한 통신 프로토콜이 적용될 수 있다.
수소 유체 연료는 기체 수소 연료 또는 액체 수소 연료를 포함할 수 있다.
압축수소저장시스템(CHSS, Compressed Hydrogen Storage System)은 차량 측에 탑재되는 적어도 하나의 탱크와 이 탱크에 결합하여 탱크에 수소를 압축하여 저장하는 장치를 포함할 수 있다.
압력 배출 장치(PRD, Pressure Relief Device)는 CHSS에 배치되며 저장된 수소를 차량의 수소 연료공급 시스템 및 주변 환경으로부터 고립시킬(isolate) 수 있고, 수소를 외부로 배출시킬 수 있는 장치를 의미할 수 있다.
수소 연료공급은 기본적으로 수소 충전소(Hydrogen Station)의 디스펜서로부터 고압 수소를 공급받아 차량의 탱크에 압축 저장하는 과정을 의미한다. 수소 연료공급은 수소전기차에 수소 연료 공급하는 측면에서 간략히 연료공급(fueling)과 동일한 의미로 사용될 수 있다. 즉, 본 명세서에서 "fueling"은 연료공급이나 수소 연료공급 또는 연료공급의 의미로 사용될 수 있고, 연료공급은 수소 연료의 연료공급을 의미할 수 있다. 예를 들어, 연료공급 프로토콜은 연료공급 프로토콜로 지칭될 수 있고, 연료공급 세션은 연료공급 세션으로 지칭될 수 있고, 연료공급 방법은 수소연료공급 방법 또는 연료공급(fueling) 방법으로 지칭될 수 있다.
압력 증가율(PRR, Pressure Ramp Rate)은 MPa/min 으로 나타내어지며 CHSS의 압력의 증가율을 의미한다.
평균 압력 증가율(APRR, Average Pressure Ramp Rate)은 수소 연료공급(fueling)의 시작부터 끝까지 압력 증가율의 평균값을 의미한다.
예냉(pre-cooling)은 기본적으로 수소 충전소의 수소를 연료공급 전에 미리 냉각시키는 과정을 의미할 수 있다.
디스펜서(dispenser)는 예냉된 수소를 CHSS로 전달하는 콤포넌트이다. 디스펜서는 수소 충전소에 배치되고 수소 충전소의 수소 저장 탱크와 차량의 CHSS 사이에서 수소 연료공급 동작을 수행할 수 있다.
노즐(nozzle)은 디스펜서에 연결되며 수소전기차의 리셉터클(receptacle)에 결합하고 수소 연료의 전달을 허용하는 장치를 의미한다.
연료공급 세션(fueling session)은 수소 연료공급(hydrogen fueling)을 위한 유즈케이스(use cases) 전체에 걸쳐 이루어지는 통신 세션들을 포함하는 의미로 사용될 수 있다.
상호운용성(Interoperabilty)은 서로 상대적인 시스템의 성분들이 전체 시스템의 목적하는 동작을 수행하기 위해 함께 작동할 수 있는 상태를 지칭할 수 있다. 정보 상호운용성(Information interoperability)은 두 개 이상의 네트워크들, 시스템들, 디바이스들, 애플리케이션들 또는 성분들이 사용자가 거의 또는 전혀 불편함 없이 안전하고 효과적으로 정보를 공유하고 쉽게 사용할 수 있는 능력을 지칭할 수 있다.
연관(Correlation/Association)은 두 피어(peer) 통신 실체들 사이의 관계 성립 절차를 포함할 수 있다.
명령 및 제어 통신(Command and control communication)은 수소 연료 공급 프로세스의 시작, 제어 및 종료에 필요한 정보를 교환하는 전기차 수소연료 공급장치와 수소전기차 사이의 통신을 지칭할 수 있다.
한편, 이하의 상세한 설명에서는 수소전기차 또는 연료전지전기차(fuel cell electric vehicle, FCEV)와 관련된 실시예가 도시되지만 본 발명의 사상은 다양한 종류의 수소 연료 모빌리티(hydrogen fueled mobility)에 적용될 수 있는 것임은 당업자에게 자명하다. 수소 연료 모빌리티는 수소를 에너지원으로 하거나 수소를 연료로 하여 전기 에너지를 생성하고 이를 이용하여 전동기를 구동하는 방식의 모빌리티를 의미한다. 수소 연료 모빌리티에는 수소전기차 외에 공중 모빌리티(Aerial Mobility)는 물론, 산업용 트럭, 열차, 선박, 항공기 또한 수소를 연료로 하여 전기에너지를 생산하고 이를 이용하여 구동하는 장치가 포함될 수 있다.
또한, 본 발명의 수소 연료공급을 위한 양방향 통신 프로세스는 수소 연료 모빌리티 뿐만 아니라 수소를 에너지원으로 하는 건축물, 또는 시설물에도 부분적으로 적용될 수 있다.
또한, 이하의 설명에서, 수소 연료는 가스 상태의 수소 및 액체 상태의 수소 중 적어도 하나를 포함할 수 있고, 기본적으로 압축된 수소를 의미할 수 있으나 이에 한정되지는 아니한다.
아울러 수소 연료공급 통신 양방향 프로세스를 이용하는 차량은 설명의 편의상 수소전기차(FCEV)를 중심으로 설명하지만, 이러한 구성으로 한정되지 않고, 수소를 연료로 사용하는 하이브리드 형태의 EV(electric vehicle) 차량, ICE(internal combustion engine) 차량 등도 포함할 수 있다.
이하의 명세서에서 수소 연료 모빌리티에서 수행되는 통신 방법, 통신 프로토콜 협상 방법, 수소 연료공급(연료 공급, fueling) 프로토콜 협상 방법, 및 수소 연료공급(연료 공급, fueling) 파라미터 협상 방법의 일부 또는 전부 과정은 수소 연료 모빌리티 내의 전자제어장치(ECU), 통신 장치, 또는 통신 제어 장치에 의하여 수행될 수 있다.
이하의 명세서에서 디스펜서에서 수행되는 통신 방법, 통신 프로토콜 협상 방법, 수소 연료공급(연료 공급, fueling) 프로토콜 협상 방법, 수소 연료공급(연료 공급, fueling) 파라미터 협상 방법, 수소 연료공급(연료 공급, fueling) 방법, 및 수소 연료공급(연료 공급, fueling) 제어 방법의 일부 또는 전부 과정은 디스펜서의 컨트롤러, 전자제어장치, 통신 장치, 또는 통신 제어 장치에 의하여 수행될 수 있다. 또한 디스펜서와 연관되는 연료공급 스테이션의 컨트롤러, 전자제어장치, 통신 장치, 또는 통신 제어 장치에 의하여 상기 방법의 일부 과정이 수행될 수도 있다.
한편 본 발명의 출원일 전에 공지된 기술이라 하더라도 필요 시 본 출원 발명의 구성의 일부로서 포함될 수 있으며, 이에 대해서는 본 발명의 취지를 흐리지 않는 범위 내에서 본 명세서에서 설명한다. 다만 본 출원 발명의 구성을 설명함에 있어, 본 출원일 전에 공지된 기술로서 당업자가 자명하게 이해할 수 있는 사항에 대한 자세한 설명은 본 발명의 취지를 흐릴 수 있으므로, 공지 기술에 대한 지나치게 자세한 사항의 설명은 생략한다. 또한, 본 발명의 취지는 이들 공지 기술에 대한 권리를 주장하고자 하는 것이 아니며 공지 기술의 내용은 본 발명의 취지에 벗어나지 않는 범위 내에서 본 발명의 일부로서 포함될 수 있다.
예를 들어, 단방향 통신의 경우 IrDA 기술을 이용하거나, 양방향 통신의 경우 근거리 무선 통신 기술 (블루투스, WLAN, UWB)을 이용하거나, 단방향/양방향 통신을 위한 유선 통신 기술 등은 본 발명의 출원 전 공지 기술을 이용할 수 있으며, 이들 공지 기술들 중 적어도 일부는 본 발명을 실시하는 데에 필요한 요소 기술로서 적용될 수 있다.
이하, 본 발명에 따른 바람직한 실시예를 첨부된 도면을 참조하여 상세하게 설명한다.
도 1은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스를 적용할 수 있는 수소전기차(FCEV)용 수소 연료공급 시스템에 대한 개념도이다. 도 2는 도 1의 수소 연료공급 시스템에서 FCEV와 디스펜서 간의 물리적인 체결 구조를 설명하기 위한 부분 확대도이다. 그리고 도 3은 도 1의 수소 연료공급 시스템에 의한 수소 연료공급 과정에서 나타나는 수소 연료의 상태 변화를 설명하기 위한 그래프이다.
도 1을 참조하면, 수소 연료공급 시스템은 넓은 의미에서 수소 충전소와 수소전기차(100)를 포함하도록 구성될 수 있다.
수소전기차(100)는 차량에 기본적으로 필요한 기계 장치, 기구 장치, 전기 장치, 전자 장치, 통신 장치 이외에 수소 연료공급을 위한 전자제어장치(110), 차량 시스템(120), 차량 탱크(130) 및 리셉터클(150)을 구비할 수 있다.
전자제어장치(110)는 수소 연료공급을 위해 수소 충전소나 수소 충전소의 전자제어장치(210)와 유선 또는 무선으로 신호와 데이터를 송수신하고 이를 처리하여 차량측에서의 수소 연료공급을 제어할 수 있다. 전자제어장치(110)는 차량에 탑재되는 다른 전자제어장치의 적어도 일부분으로 구성되거나 그 역도 가능하며, 제1 전자제어장치 또는 전자제어장치#1으로 지칭될 수 있다.
차량 시스템(120)은 제1 전자제어장치(110)에 연결되고 제1 전자제어장치(110)의 신호나 명령에 따라 차량 탱크(130)의 수소 연료공급이나 수소 방출을 제어하고, 차량 탱크(130)의 상태를 모니터링하도록 구성될 수 있다. 차량 시스템(120)은 구현에 따라서 연료전지 시스템의 동작을 제어하거나 이러한 제어 동작을 수행하는 구성부를 포함하거나 해당 구성부와 결합하도록 구성될 수 있다. 이러한 차량 시스템(120)은 차량 안전 기능도 수행하며, 이 경우 차량 안전 시스템으로도 지칭될 수 있다.
차량 탱크(130)는 적어도 하나 이상, 바람직하게는 복수개가 구비될 수 있다. 차량 탱크(130)는 차량 안전 시스템의 제어에 따라 수소 충전소 측으로부터 공급되는 수소를 압축 저장하고, 저장된 수소를 방출할 수 있다.
또한, 차량 탱크(130)는 차량에 부착된 수소저장시스템에 대응될 수 있다. 이 경우, 수소저장시스템은 고압수소저장탱크, 압력제어기구, 고압배관 및 외부 프레임으로 구성될 수 있다. 고압수소저장탱크는 수십 내지 수백 리터의 용량을 가질 수 있고, 소형 저장탱크를 병렬로 연결한 형태를 구비할 수 있다. 고압수소저장탱크에는 수소 연료가 출입할 수 있는 보스부(boss unit)가 결합될 수 있고, 보스부를 통해 수소 연료공급 및 수소 방출을 제어할 수 있다. 보스부에는 밸브, 감압기구 및 각종 측정을 위한 센서들이 부착될 수 있다. 이러한 수소저장시스템은 압축수소저장시스템(CHSS)으로 알려져 있으며, 본 명세서에서 "차량 탱크"라는 표현은 설명의 편의상 CHSS를 의미할 수 있다.
전술한 수소전기차(100)는 연료전지 스택을 포함한 연료전지 시스템을 구비할 수 있으나, 이에 한정되지 않으며, 설명의 편의상 간략히 'FCEV', '차량' 또는 모빌리티(100)라고 지칭될 수 있다. 이하의 명세서에서 차량 또는 모빌리티라고 간단히 지칭되는 대상은 수소전기차(100) 외에 수소를 연료로서 이용하는 차량/모빌리티(hydrogen fueled vehicle/mobility)를 포함하는 것으로 이해될 수 있다.
수소 충전소는 디스펜서(dispenser, 200), 전자제어장치(210), 충전소 시스템(220), 수소 탱크(230), 스테이션 박스(240) 및 노즐(250)을 구비할 수 있다.
디스펜서(200)는 충전소 시스템(220)의 제어에 따라 수소 탱크(230)에서 공급되는 수소를 차량의 리셉터클(150)에 견고하게 연결된 노즐(250)을 통해 차량으로 공급할 수 있다. 디스펜서(200)는 전자제어장치(210)를 하우징 내부에 구비할 수 있으나, 이에 한정되지는 않는다. 노즐(250)는 기본적으로 디스펜서(200)의 하우징 외부에 일정 길이로 연장되는 케이블의 말단부에 설치될 수 있다.
전자제어장치(210)는 수소 연료공급을 위해 차량의 제1 전자제어장치(110)와 유선 또는 무선으로 신호와 데이터를 송수신하고 이를 처리하여 수소 충전소측에서의 수소 연료공급을 제어할 수 있다. 전자제어장치(210)는 충전소 시스템(220)과 기설정된 신호 및 데이터를 교환할 수 있다. 전자제어장치(210)는 제2 전자제어장치 또는 전자제어장치#2로도 지칭될 수 있다.
전술한 제1 전자제어장치(110)과 제2 전자제어장치(210) 각각은 복수의 전자제어장치들로 구성될 수 있고, 통신 프로토콜마다 서로 다른 전자제어장치들이 매칭되어 동작하도록 구성될 있다. 이 경우, 하위 호환성(backward compatibility)을 위해 폴백할 때, 그리고 양방향 통신을 사용하지 못하고 단방향 통신을 사용해야 하는 경우에 유용할 수 있다. 또한, NFC로 페어링을 한 후에 실제 연료공급을 수행할 때는 WiFi를 쓰는 경우와 같이 서로 다른 통신 방식을 조합하여 이용할 때 유용할 수 있다.
충전소 시스템(220)은 제2 전자제어장치의 신호 및/또는 데이터에 따라 수소 탱크(230)에서 방출되는 수소의 압력, 속도, 온도를 모니터링하거나 조절할 수 있다. 이를 위해 충전소 시스템(220)은 수소 탱크(230)의 방출구나 방출밸브에 연결되는 스테이션 박스(240)의 동작을 제어할 수 있다. 충전소 시스템(220)은 충전소 안전 시스템으로도 지칭될 수 있다.
본 발명의 다른 실시예에서는 차량/모빌리티(100)와 통신하기 위한 디스펜서(200)와 관련되는 통신 엔티티는 전자제어장치(210)일 수도 있고, 디스펜서(200)에 탑재되는 별도의 통신 장치일 수도 있으며, 충전소 시스템(220) 내의 전자제어장치 또는 별도의 통신 장치가 디스펜서(200)를 대신하여 차량/모빌리티(100)와 통신할 수도 있다.
본 발명의 또 다른 실시예에서는 차량/모빌리티(100)에서 디스펜서(200) 측과 통신하기 위한 통신 제어 장치는 제1 전자제어장치(110)일 수도 있고, 별도의 통신 제어 장치일 수도 있다.
수소 탱크(230)는 수소 또는 압축 수소를 저장한다. 수소 탱크(230)는 충전소 시스템(220) 내의 안전 관리 모듈의 제어에 따라 저장된 수소를 소정의 압력이나 속도로 방출할 수 있다. 수소 탱크는 수소 저장 탱크로도 지칭될 수 있다.
스테이션 박스(240)는 수소 탱크(230)의 방출구나 방출밸브에 유입구가 연결되고, 유출구가 디스펜서(200) 또는 디스펜서(200)에 결합된 노즐(250)에 연결되는 조절밸브를 구비할 수 있다. 스테이션 박스(240)는 방출되는 수소의 압력, 속도, 온도 등을 조정하기 위한 수단이나 이러한 수단에 대응하는 기능을 수행하는 구성부를 구비할 수 있다. 또한, 스테이션 박스(240)는 방출되는 수소의 압력, 속도, 온도 등을 측정하기 위한 센서들을 구비할 수 있다.
노즐(250)은 소정 길이의 도관이나 유연한 파이프를 통해 디스펜서(200)의 수소 연료 공급 시스템에 연결될 수 있다. 노즐(250)은 차량의 리셉터클과 기밀하고 견고하게 맞물리는 형상과 구조를 구비할 수 있다.
노즐(250)은 도 2에 나타낸 바와 같이 리셉터클(150)에 맞물릴 수 있다. 이때, 차량에 설치된 제1 센서(160)와 노즐(250)에 부착되는 제2 센서(260)에 의해 노즐(250)과 리셉터클(150)의 체결 상태에 대한 신호나 정보가 제1 전자제어장치나 차량 안전 시스템으로 전달되고, 또한 제2 전자제어장치나 충전소 안전 시스템으로 전달될 수 있다.
전술한 수소 충전소로부터 예냉된 수소 연료는 디스펜서(200)를 거쳐 수소전기차(100)로 공급된다. 이때 수소 연료공급 과정은 압력 증가율(PRR) 및/또는 평균 압력 증가율(APRR)을 포함하는 파라미터에 의하여 기술될 수 있다.
수소 충전소와 차량(100)의 인터페이스는 디스펜서(200)에서 담당할 수 있다. 디스펜서(200)는 차량 탱크(130)로부터 간접적으로 획득한 정보와 수소 충전소의 연료공급 정보를 종합해서 수소 연료공급에 대한 타겟 압력과 주입속도 등을 제어하도록 구성될 수 있다.
기존 기술에 있어서 차량(100)에서 디스펜서(200)로 정보를 전달하는 방식은 통신(communication) 방식과 무통신(Non-communication) 방식이 있다. 통신을 이용하는 경우, 기존 기술에서는 차량(100)의 차량 탱크(130)의 온도 및 압력 값들이 단순히 단방향으로 디스펜서(200)로 전달될 뿐이며, 디스펜서(200)에서도 해당 정보를 적극적으로 활용하지 못하고, 단지 한계 온도 압력에서의 비상 정지와 같은 안전 기준으로 활용하고 있다. 또한, 안전하고 신속한 연료공급을 위한 수소 연료공급 프로토콜은 디스펜서(200)에서 관리하고 있으며, 차량 탱크(130)에 대한 능동적인 안전 관리 없이, 압력 방출 장치(PRD: pressure relief device)를 통해 자동으로 수소를 방출하는 최소한의 안전관리 장치만을 가지고 있다.
한편, 수소 연료공급이 진행되는 동안 수소 가스의 온도가 상승하는 현상(도 3 참조)에 대응하기 위해, 수소 충전소는 프리-쿨러를 구비할 수 있다. 프리-쿨러는 예냉(pre-cooling)을 통해 수소 연료의 온도를 낮출 수 있다. 프리-쿨러는 수소 탱크(230) 및 스테이션 박스(240) 중 적어도 어느 하나에 설치되거나 결합될 수 있다. 또한, 프리-쿨러는 수소 충전소에서 수소를 운송하는 배관에 설치되거나 결합될 수 있음은 물론이다.
디스펜서(200) 내부나 제2 전자제어장치에는 연료공급 제어 로직이 탑재될 수 있고, 연료공급 제어 로직은 차량으로 공급되거나 차량 탱크(130)에 연료공급되는 수소 연료의 온도, 압력 등의 상태 정보, CHSS의 충전율(SOC, State of Charge) 등의 연료공급 상태 정보를 활용하여 수소 연료공급(hydrogen fueling) 과정을 제어하는데 이용될 수 있다.
전술한 바와 같이 수소 연료공급 프로세스는 차량(100)과 수소 충전소 간의 제어를 디스펜서(200)가 담당하고, 이러한 디스펜서(200)에는 정해진 절차에 따라서 수소 연료를 차량에 공급하는 프로토콜이 탑재될 수 있다. 이러한 수소 연료공급(fueling) 프로토콜은 차량에도 탑재될 수 있다. 차량이나 디스펜서(200)에 탑재되는 프로토콜은 SAE 표준, ISO 표준 등에 따른 통신 프로토콜의 적어도 일부를 포함할 수 있다.
안전을 위한 최소 요구사항(requirements)에 대해서, 다양한 상황에 대해서 열역학적인 모델링을 통한 시뮬레이션을 진행하고, 이를 통해 도출한 파라미터 등을 활용하여 테이블 기반(Table-based) 방식이나 MC-formula 기반의 부분적인 실시간 보정(Partial Real-Time Correction) 방식이 이용될 수 있다. 여기서 안전을 위한 최소 요구사항은 CHSS의 온도 및 압력 조건의 상한과, 충전율(SOC)에 대한 가이드라인을 포함할 수 있다.
디스펜서(200)에서 수소 연료공급과 관련된 상태 값을 능동적으로 제어하지 않는 경우, 종래 기술의 테이블 기반 방식은 가스 충전소에서 제공되는 예냉 수소 연료의 온도나, 차량(100)에서 측정되는 차량 탱크(130)의 온도 등이 활용되지 않아 효율성이 매우 낮으며 주변 상황 변화에 유연하게 대처하기 어렵다. 또한, 종래 기술의 MC-Formula 기반 방식은 예냉 수소 연료의 온도를 실시간으로 보정하지만 계산 및 적용 방식이 복잡하고 적용에 한계가 있어 확장이 어렵다. 이와 같이 기존의 통신 프로토콜이 안전한 연료공급 완료를 주요 목표로 개발되어 과도한 예냉이나 차량 탱크(130)의 과열 등 돌발적 상황에 대해 적극적으로 제어할 수 있는 대안이 없고, 이로 인하여 과냉각에 의한 운영 비용 상승, 과열에 의한 연료공급 지연 등의 문제가 발생할 수 있다.
예를 들어, 차량 탱크(도 1의 130 참조)에 수소 연료가 연료공급될 때, 압축열에 의해 차량 탱크의 내부 온도가 상승하고, 이로 인해 차량 탱크 내부의 수소 연료의 온도가 상승한다. 차량 탱크는, 외부 대기와 내부 저장된 수소 연료 간의 열교환을 차단하기 위하여, 차량 탱크의 돔과 바디를 열전달 효율이 낮은 탄소섬유로 감싸도록 구성된다. 따라서 연료공급 과정에서 차량 탱크 내부의 수소 연료의 온도가 상승할 때, 차량 탱크의 낮은 열전달 특성으로 인하여 연료공급이 완료되는 시점까지 내부의 온도 상승에 비해 차량 탱크의 표면에 드러나는 온도 상승은 미미할 수 있다.
한편, 수소 연료공급 과정의 온도 제어는 예냉 수소 가스를 공급받아 최종 연료공급 완료 시점에서, 차량 탱크(130)의 내부 온도가 85℃ 이하가 되도록 제어하는 것으로 목표로 할 수 있다. 즉, 도 3에 나타낸 수소 연료공급 시의 수소 온도에 대한 특성 곡선과 같이, 수소 연료의 온도는 수소 충전소의 예냉 단계인 페이즈(Phase) I(P1)에서 수소 온도가 일정 속도로 감소하고, 수소 충전소에서 차량 등의 수소 모빌리티로 수소 연료를 공급하는 단계인 페이즈 Ⅱ(P2)에서 수소 충전소의 열질량으로 인해 수소 연료의 온도가 서서히 올라가고, 차량 내부에서 차량 탱크로 수소 연료를 이송하는 단계인 페이즈 Ⅲ(P3)에서 차량의 열질량으로 인해 수소 연료의 온도가 추가로 서서히 올라가고, 차량 탱크에 수소 연료를 압축 저장하는 단계인 페이즈 Ⅳ(P4)에서 압축 열로 인해 수소 연료의 온도가 급격히 상승할 수 있다.
이에 본 실시예에서는 수소 연료공급 통신 양방향 프로세스를 통해 실시간 측정 데이터를 반영한 능동적인 상태 변수 제어를 통해 효과적으로 수소 연료공급 절차를 수행할 수 있고, 이를 위한 수소 연료공급 프로토콜을 제공할 수 있다.
도 4는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스를 채용할 수 있는 일련의 수소 연료공급 절차를 수행하는 기능 블록들에 대한 프레임워크(이하 '수소 연료공급 프레임워크'라고 한다)이다.
도 4를 참조하면, 수소 연료공급 프레임워크는, 유즈케이스(use case, UC)별 기능 블록들로서, 발견 및 페어링(discovery and pairing) 기능 블록(이하 간략히 'UC1' 또는 'UC-1'), 통신 보안(communication security) 기능 블록(UC2 또는 UC-2), 통신 프로토콜 협상(communication protocol negotiation) 기능 블록(UC3 또는 UC-3), 연료공급 프로토콜 협상(fueling protocol negotiation) 기능 블록(UC4 또는 UC-4), 연료공급 파라미터 협상(fueling parameter negotiation) 기능 블록(UC5 또는 UC-5), 안전 체크인(safety check-in) 기능 블록(UC6 또는 UC-6), 모니터링 및 제어(monitoring and control) 기능 블록(UC7 또는 UC-7), 안전 체크아웃(safety check-out) 기능 블록(UC8 또는 UC-8), 종료(termination) 기능 블록(UC9 또는 UC-9), 오류 처리(error handling) 기능 블록(UC10 또는 UC-10), 긴급 처리(emergency handling) 기능 블록(UC11 또는 UC-11)을 구비할 수 있다.
UC1 내지 UC11 기능 블록 각각은 도 4에 도시된 것처럼 시계열적인 단계들(S401 내지 S411)에 대응할 수 있다. 이때 도 4는 시계열적인 단계들(S401 내지 S411)을 포함하는 동작 흐름도로 이해될 수도 있다.
UC10 및 UC11은 UC3 내지 UC8에 각각 개별적으로 연결되어 각 유즈케이스에서의 오류 처리 및/또는 긴급 처리를 수행하도록 구성될 수 있다.
전술한 유즈케이스는 안전 및 보안의 연료공급(fueling) 통신을 위해 수소 연료공급 시스템의 전체 수소 연료공급 절차(fueling procedures)를 일관된 방식으로 집합적으로 제공하는 기능 블록이다. 차량과 디스펜서는 수소 연료공급 목표를 달성하기 위해 특정 순서로 각 유즈케이스를 차례대로 수행할 수 있다.
또한, 디스펜서 노즐이 차량 리셉터클에 연결된 후, 해당 차량과 디스펜서는 도 4에 표시된 순서대로 각 유즈케이스를 구현하여 연료공급 통신을 수행할 수 있다. 다만, 차량과 디스펜서는 미리 정의된 요구사항에 따라 필요한 경우 특정 유즈케이스를 생략할 수 있다.
전술한 각 유즈케이스는 수소 연료 차량을 위한 연료공급 프로토콜에 따라 수소 연료 차량에 수소를 연료로 공급하는 디스펜서의 디스펜서 제어 시스템과 수소 연료 차량과의 통신을 통해 구현될 수 있다.
한편, 전술한 유즈케이스를 구현하는 수소 연료 차량(이하 간략히 '차량'이라고도 한다)과 디스펜서는 UC-1에서 차량 식별을 위한 데이터 교환을 수행할 수 있다. 이를 위해 차량은 센서(sensors), 전자제어장치(electric control unit, ECU), 송신기(transmitter) 및 수신기(receiver)를 구비할 수 있다. 수신기는 양방향 통신을 하는 경우, 송신기와 일체로 결합될 수 있다.
그리고, 디스펜서는 차량으로부터 특정 데이터를 받을 수 있도록 구성될 수 있다. 디스펜서는 데이터 로깅(data logging)의 데이터를 저장하거나 연료공급 프로토콜에 사용하기 위해 충전소 PLC(programmable logic controller)에 지정된 데이터를 저장할 수 있다. 데이터 로깅은, 수소 연료공급 시스템의 특정 동작 상태를 분석하거나 시스템 또는 네트워크 환경의 데이터 기반 이벤트/동작을 기록하기 위해 일정 기간 동안 데이터를 수집하는 프로세스 또는 이 프로세스에 의해 수집된 데이터를 지칭할 수 있다. 양방향 통신의 경우, 충전소(station)에는 연료공급 프로토콜에 의해 지정된 센서가 구비되고, 충전소 PLC 또는 전자제어장치는 센서로부터 측정값을 획득하고 이 측정값을 차량으로 보낼 수 있다. 전술한 차량이나 충전소는 적외선, 와이파이, 블루투스 등의 통신을 위해 기존의 통신 프로토콜 표준을 사용할 수 있다.
또한, 차량과 디스펜서는 차량-디스펜서 인터페이스에서 물리적으로 연결된 차량과 디스펜서 사이에 통신 채널을 설정할 수 있다. 이러한 통신 채널을 설정하는 페어링 프로세스는 유선, 광학 또는 무선 기술을 사용하여 수행될 수 있다.
발견 및 페어링 절차나 페어링 프로세서는 디스펜서 노즐이 차량 연료공급 리셉터클(vehicle fueling receptacle)에 삽입되어 견고하고 연결되는 전제 조건(pre-conditions)을 가질 수 있다. 차량 연료공급 리셉터클은 간략히 차량 리셉터클 또는 리셉터클로 지칭될 수 있다.
또한, 차량과 디스펜서는 기본적으로 어떤 통신 프로토콜에 따를지를 알고 있다. 따라서 UC-1 이후에 이어지는 통신은, 발견 및 페어링 절차나 페어링 프로세스의 사후 조건(post-conditions)으로서, 현재의 유즈케이스에서 합의된 통신 프로토콜에만 의존할 수 있다. 차량이나 디스펜서에 의해 합의 범위를 벗어난 통신 프로토콜이 선택되는 경우, 선택된 통신은 수행되지 않는다. 즉, 페어링 프로세스가 성공적으로 완료되더라도, 연료에 대한 승인이나 연료공급에 대한 승인은 부여되지 않을 수 있다.
차량과 디스펜서를 페어링하는 데 사용되는 모든 방법은 허용가능한 수준 이상으로 점화 또는 폭발 위험을 증가시키지 않도록 설정된다. 예를 들어, 모든 유선 페어링 방법은 정전기 방전으로 인한 스파크 위험을 완화하거나 차단하도록 구성된다.
물리적 페어링의 유효성 측면에서, 차량과 디스펜서를 페어링하는 데 사용되는 모든 방법은, 차량-디스펜서 인터페이스에 통합되거나, 차량의 연료공급 리셉터클과 디스펜서의 노즐 및 호스(hose) 어셈블리 간에 근접성(proximity)를 갖도록 설치될 수 있다. 여기서, 인터페이스는 노즐과 리셉터클 인터페이스에 물리적으로 통합된 것을 지칭할 수 있다. 그리고 근접성은 페어링 방법과 관련된 하드웨어에 의해 정의될 수 있다. 예를 들어, 송신기와 수신기 사이의 허용된 거리를 포함하여 적외선 통신에 사용되는 물리적 기하학 구조(geometry)를 지정할 수 있다. 또한, 수소 연료공급 하드웨어의 물리적 형상이 미리 지정될 수 있는데, 이때 근접성은 물리적으로 연결되지 않은 차량과 디스펜서를 페어링할 위험이 있는 페어링 방법 예를 들어 블루투스 등과 같은 상대적으로 장거리 무선 통신 기술을 포함하지 않는다. 적외선 통신은 IrDA(infrared data association) 통신으로 지칭될 수 있고, 양방향 적외선(bi-IrDA) 통신을 포함할 수 있다.
다시 도 4를 참조하면, 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 수소 연료 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급(fueling)을 위한 통신 방법으로서, 모빌리티에 수소를 연료공급하는 디스펜서와 통신 프로토콜을 협상하는 단계(S403); 디스펜서로부터 수소를 연료공급받기 위한 연료공급 프로토콜을 디스펜서와 협상하는 단계(S404); 및 연료공급 프로토콜에 기반하는 연료공급 파라미터를 디스펜서와 협상하는 단계(S405)를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서에 의하여 수행되는 수소 연료공급(fueling)을 위한 통신 방법은, 모빌리티와 통신 프로토콜을 협상하는 단계(S403); 모빌리티로 수소를 연료공급하기 위한 연료공급 프로토콜을 모빌리티와 협상하는 단계(S404); 및 연료공급 프로토콜에 기반하는 연료공급 파라미터를 모빌리티와 협상하는 단계(S405)를 포함할 수 있다.
도 5는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 각 유즈케이스와 관련된 통신 스택에 대해 OSI(Open Systems Interconnection reference model) 7 계층을 중심으로 나타낸 예시도이다.
도 5에 예시한 바와 같이, 수소 연료공급 통신 양방향 프로세스의 유즈케이스와 관련된 통신 스택(간략히 '수소 연료공급 통신 스택')은 OSI 7 계층에 속한 데이터 링크 및 물리(data link and physical) 계층, 네트워크(network) 계층, 전송(transport) 계층, 보안(security) 계층, 세션(session) 계층, 표현(presentation) 계층 및 응용(application) 계층 각각에 대응하여 프로토콜 모음(protocol suites)으로 표현될 수 있다.
즉, 수소 연료공급 통신 스택은 OSI 7 계층의 데이터 링크 및 물리 계층의 프로토콜로서 양방향 IrDA(bi-IrDA), WLAN, NFC 등에서 선택되는 적어도 하나의 제1 프로토콜(510)을 포함할 수 있다.
또한, 수소 연료공급 통신 스택은 OSI 7 계층의 네트워크 계층의 프로토콜로서 IPv6(internet protocol version 6) 프로토콜(520)을 포함할 수 있다.
또한, 수소 연료공급 통신 스택은 OSI 7 계층의 전송 계층의 프로토콜로서, TCP(transmission control protocol), UDP(user datagram protocol) 등에서 선택되는 적어도 하나의 제3 프로토콜(530)을 포함할 수 있다.
또한, 수소 연료공급 통신 스택은 OSI 7 계층의 보안 계층의 프로토콜로서, TLS(transport layer security), DTLS(datagram transmission layer security) 등에 선택되는 적어도 하나의 제4 프로토콜(540)을 포함할 수 있다. TLS는 TLS 1.2, TLS 1.3 등의 버전들을 포함하고, DTLS는 DTLS 1.2, DTLS 1.3 등의 버전들을 포함할 수 있다. TLS는 TCP 소켓에서 구현되고, DTLS는 UDP 소켓에서 구현될 수 잇다.
또한, 수소 연료공급 통신 스택은 OSI 7 계층의 세션 계층의 프로토콜로서, JSON 기반 세션 프로토콜(JSON-based session protocol)(550)을 포함할 수 있다. JSON 기반 세션 프로토콜(550)은 차량과 디스펜서와의 통신 또는 차량의 전자제어장치와 충전소의 전자제어장치 간에 데이터를 보낼 때 사용될 수 있다.
또한, 수소 연료공급 통신 스택은 OSI 7 계층의 표현 계층의 프로토콜로서, JSON(JavaScript object notation)(560)을 포함할 수 있다. JSON은 서버에서 클라이언트로 데이터를 보낼 때 사용할 수 있는 양식 중 하나이다. JSON을 이용하면, 차량과 디스펜서 간에 또는 차량의 전자제어장치와 충전소의 전자제어장치 간에 프로토콜 메시지를 JSON으로 표기할 수 있다.
또한, 수소 연료공급 통신 스택은 OSI 7 계층의 응용 계층의 프로토콜로서, 수소 연료공급 관련 연료공급 프로토콜들(fueling protocols, FP)(570)을 포함할 수 있다. 연료공급 프로토콜들(570)은 제1 연료공급 프로토콜(FP1), 제2 연료공급 프로토콜(FP2), 제n 연료공급 프로토콜(FPn)을 포함할 수 있다. n은 3 이상의 임의의 자연수일 수 있다.
또한, 전술한 수소 연료공급 통신 스택은, 또 다른 실시예에서, 데이터 링크 및 물리 계층과 네트워크 계층의 프로토콜로서, PLC(programmable logic controller), WLAN 등의 프로토콜을 사용하고; 전송 계층과 보안 계층의 프로토콜로서, TCP 및/또는 IPv6 프로토콜을 사용하고; 인코딩 계층에 대응하는 세션 계층의 프로토콜로서, 이진 XML(binary extensible markup language) 프로토콜을 사용하고; 표현 계층과 응용 계층의 프로토콜로서, 전기차에 사용되는 기존 프로토콜들 중 하나를 활용하도록 구성될 수 있다. 전기차에 사용되는 기존 프로토콜은 전기차의 직류(DC: direct current) 연료공급, 교류(AC: alternate current) 연료공급, 무선전력전송(WPT: wireless power transfer), 자동 연결장치 펜터그래프(ACDP: automatic connection device pantograph) 등을 위한 적어도 하나의 프로토콜을 포함할 수 있다.
전술한 수소 연료공급 통신 스택을 통해 차량과 충전소 간에 주고받는 전반적인 통신 데이터 항목을 나타내면 다음의 표 1과 같다.
| 구분 | 충전소 → 차량 | 차량 → 충전소 |
| 통신데이터항목 | - 공급 수소압력 - 공급 수소온도 - 공급 수소유량 - 최대공급 수소압력 - 최대공급 수소온도 - 최소공급 수소온도 - 최대공급 수소유량 - 대기온도 - 통신가능 여부 (comm/non-comm) - 목표값 - 연료공급 진행 여부 - 긴급정지 여부 - 수소 연료공급 프로토콜 카테고리 - 공급수소량 - 수소 연료공급 예상완료 시간 |
- 리셉터클 타입 - 리셉터클 사용압력 - 탱크볼륨 - 탱크압력 - 탱크온도 - 최대사용 압력 - 최대사용 온도 |
한편, 도 4의 발견 및 페어링(discovery and pairing) 단계(S401)의 유즈케이스(UC1)는 장치가 물리적으로 연결된 리셉터클 또는 노즐의 제어를 담당하는 통신 상대방(차량 또는 디스펜서의 통신 모듈)을 식별할 수 있도록 한다. 또한 UC1은 비호환성을 식별하는 방법을 정의하고 안전 장치 메커니즘을 정의할 수 있다.
이러한 유즈케이스(UC1)에서 차량과 디스펜서는 연료공급 프로토콜을 실행하기 위해 일반적인 통신 기술을 찾으려고 할 수 있다. 기본 데이터 링크 및 물리 계층에서 제공하는 검색 메커니즘에 따라 차량과 디스펜서가 서로를 검색하고 통신을 시작할 수 있다. 연료공급 호스 어셈블리에 연결된 장치와 통신 채널이 설정되도록 하려면 추가 페어링 절차가 필요하다. 통신 채널이 올바른 페어링을 보장하지 않는 경우 예컨대 무선 통신의 경우, 페어링 정보를 전달하는 별도의 페어링 채널이 필요할 수 있다. 페어링이 암묵적으로 보장되는 경우 예컨대 호스 어셈블리와 통합된 통신의 통신 채널만으로 충분할 수 있다.
표 2는 도 4의 발견 및 페어링 단계(S401)의 유즈케이스 UC1의 목적, 선결조건, 후속조건을 도시하는 표이다.
| Type | Description |
| Use case name | UC-1: "Discovery and Pairing" |
| Objectives | UC-1 allows devices to identify the communication counterparty (communication module of vehicle or dispenser) that is responsible for the control of the physically connected receptacle or nozzle, respectively. UC-1 also defines how to identify incompatibility and may define a failsafe mechanism. |
| Short Description | During this use case, vehicle and dispenser try to find out any common communication technologies to run a fuelling protocol. Depending on the discovery mechanism provided by the underlying physical/data-link layer, the vehicle and dispenser discovers each other and start communication. To ensure that the communication channel is established with the devices that are bound to the fuelling hose assembly, extra pairing procedure may need to be involved. When communication channel does not guarantee the correct pairing (e.g., wireless communication), we may need an extra pairing channel that delivers pairing information. When pairing is implicitly guaranteed (e.g., communication integrated with hose assembly), only communication channel should be sufficient. |
| Pre-conditions | The dispenser nozzle is securely connected to the vehicle receptacle |
| Post-conditions | Vehicle and Dispenser knows what communication medium to use for the communication. After this use case, subsequent communication solely depends on the communication protocol that was agreed on in this use case. If an out-of-scope communication protocol is chosen, no further ISO 19985 communication is performed. |
표 3은 도 4의 발견 및 페어링 단계(S401)의 유즈케이스 UC1에서 이용될 수 있는 지원되는 통신 기술(supported communication technologies) 및 각각의 clauses를 도시하는 표이다.
| Clause | Communication Technology | Communication Channel | Pairing Channel |
| Annex P.1 | Unidirectional irDA | (irDA references) | N/A |
| Annex P.2 | Bidirectional IrDA | (irDA references) | N/A |
| Annex P.3 | WLAN with NFC | IEEE 802.11 | NFC Forum Specifications |
도 6은 본 발명의 일 실시예에 따른 단계(S401)를 상세히 도시하는 동작 흐름도이다.
도 6을 참조하면, 도 4의 발견 및 페어링(Discovery and Pairing) 단계(S401)에서 페어링 과정은, UCDC 레벨2 및 UCDC 레벨3에서 페어링할 때 차량과 디스펜서는 페어링 ID를 교환하고 상대방의 페어링 ID를 확인할 수 있다.
일례로, 차량(vehicle)은 자신의 페어링 ID(PAIR_ID) 즉, 차량 ID(vehicle_id)를 담은 메시지(PAIR_ID_ANNOUNCE)를 브로드캐스트할 수 있다. 디스펜서(dispenser)는 차량으로부터 차량 ID를 받았음을 회신하는 메시지(PAIR_ID_ACK)를 차량으로 전달할 수 있다. 차량은 디스펜서가 차량 ID를 받았다는 ACK 메시지를 정상적으로 수신하였음을 확인하는 메시지(PAIR_ID_CONFIRM)를 디스펜서로 전달할 수 있다.
다음, 디스펜서(dispenser)는 자신의 페어링 ID 즉, 디스펜서 ID(dispenser_id)를 담은 메시지(PAIR_ID_ANNOUNCE)를 브로드캐스트할 수 있다. 차량(vehicle)은 디스펜서로부터 디스펜서 ID를 받았음을 회신하는 메시지(PAIR_ID_ACK)를 디스펜서로 전달할 수 있다. 디스펜서는 차량이 디스펜서 ID를 받았다는 ACK 메시지를 정상적으로 수신하였음을 확인하는 메시지(PAIR_ID_CONFIRM)를 차량으로 전달할 수 있다.
이러한 전송-에코-검증 방법을 통해 차량과 디스펜서가 세션별 무작위(session-specific randomized) 페어링 ID를 사용할 수 있다. 이에 의하면, 페어링 ID 교환에 대한 개인 정보 보호 문제를 해결할 수 있다. 즉, 페어링 과정에 대한 신뢰는 후속 프로세스에 의해 설정되며, 이를 위해 세션별 페어링 ID는 신뢰를 설정하는 데 사용되는 데이터에 포함된다.
한편, 특정 UCDC 레벨에서 보안 통신을 지원하는 경우, 차량 및 디스펜서 중 적어도 하나는 차량과 디스펜서를 페어링하는 데 사용되는 모든 방법에 대해 페어링이 통신 채널을 보호하기에 충분한 정보를 제공하는지 확인할 수 있다. 예를 들어, 페어링은 차량 및 디스펜서가 연료공급 동안에 통신을 보안할 수 있도록 암호화 키의 교환을 포함할 수 있다.
참고로, UCDC 레벨1은 양방향 통신을 지원하지 않으므로 통신 채널 보안이 불가능할 수 있다. UCDC 레벨2 및 UCDC 레벨3에서 차량과 디스펜서를 페어링하는 것은 특정 보안 레벨 예컨대, IEC 62443 보안 레벨 3을 충족하기 위해 통신을 보호하기 위한 충분한 정보를 제공하도록 구성될 수 있다. IEC 62443 보안 레벨 3은 적당한 리소스와 적당한 동기를 가진 행위자(actors)에 대한 보안 레벨일 수 있다.
도 7은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 하위 호환성(backward compatibility)을 설명하기 위한 예시도이다.
도 7을 참조하면, 수소 연료공급 장치는 상호운용성을 고려하여 기존 장치들과 하위 호환성(backward compatibility)을 가지는 호환성 장치로 만들어질 수 있다. 상호운용성을 기준으로 장치를 구분하면, 수소 연료공급 장치나 그 통신 장치는 타입0(Type 0), 타입1(Type 1), 타입2(Type 2), 및 타입3(Type 3)으로 분류될 수 있다.
타입0(Type 0)은 연료공급(fueling)을 위한 통신을 지원하지 않거나 해당 통신 메시지를 받지 못하는 장치를 지칭할 수 있다.
타입1(Type 1)은 연료공급을 위한 IrDA 통신을 지원하는 장치를 지칭할 수 있다. 타입1 장치는 타입0 장치로 폴백(fallback)할 수 있다.
타입2(Type 2)는 어드밴스드 통신(advanced communication, AC)을 지원하는 장치를 지칭할 수 있다. 타입2 장치는 타입0 장치로 폴백할 수 있다.
타입3(Type 3)은 IrDA와 어드밴스드 통신을 지원하는 장치를 지칭할 수 있다. 타입3 장치는 타입0, 타입1 및 타입2 중 어느 하나로 폴백할 수 있다.
어드밴스드 통신은 WLAN(wireless local area network), 블루투스(Bluetooth, BT), NFC(near field communication), 와이파이(WiFi), UWB(ultra-wideband), RFID(radio frequency identification), 4G, 5G 등의 매체(medium)와 특정 프로토콜을 사용하는 통신을 지칭할 수 있다. 또한, 어드밴스드 통신은 양방향 IrDA, 시리얼 통신, 차량용 이더넷(ethernet, ETH), 하이 레벨 통신(high level communication) 등을 포함할 수 있다. 여기서 특정 프로토콜은 TCT/IP(transmission control protocol/internet protocol), 연료공급(fueling) 프로토콜 등을 포함할 수 있다. 그리고 하이 레벨 통신은 명령 및 제어 통신에서 담당하는 정보를 초과하는 모든 정보를 처리할 수 있다. 하이 레벨 통신의 데이터 링크는 PLC(Power line communication)을 사용할 수 있으나, 이에 한정되지는 않는다.
또한, 어드밴스드 통신은, 하이브리드 형태로서, IrDA와 유선(wired)을 조합한 형태나 IrDA와 무선(wireless)을 조합한 형태를 포함할 수 있다. IrDA와 유선(wired)을 조합한 형태의 경우, 노즐과 리셉터클에 대한 변경이 필요할 수 있다.
즉, 어드밴스드 통신은 유선/무선 양방향 통신 기술일 수 있으며, 무선 통신 기술로는 5G, WLAN, BLE, ETH, UWB, RFID , NFC 등 다양한 통신 수단을 포함할 수 있다. 이러한 통신 수단을 위한 프로토콜로서 TCP/IP 등의 알려진 프로토콜을 사용할 수 있다. 예를 들어, 무선 통신으로서 고려되는 통신 수단은 Bluetooth, WLAN, Wi-Fi(ISO 15118 for inductive / ACD), UWB(IEC limited consideration for ACD) 등이 이용될 수 있다.
실제로 수소 연료공급 장치들은 서로 다른 기술의 통신을 지원하도록 구현될 수 있다. 이에 본 실시예의 수소 연료공급 통신 양방향 프로세스는 장치들 간의 상호운용성을 최대화할 수 있도록 구성된다.
다시 말해서, 도 7에 나타낸 바와 같이, 소정의 표준에 따른 규격#1을 지원하는 타입1 장치가 타입0 장치 또는 타입2 장치를 만나면, 타입1 장치는 타입0 장치로 폴백할 수 있다(S610).
또한, 소정의 표준에 따른 규격#2를 지원하는 타입2 장치가 타입0 장치 또는 타입1 장치를 만나면, 타입2 장치는 타입0 장치로 폴백할 수 있다(S620).
그리고 규격#2를 지원하는 타입3 장치가 타입0 장치를 만나면, 타입3 장치는 타입0 장치로 폴백할 수 있다(S630). 타입3 장치가 타입1 장치를 만나면, 타입3 장치는 타입1 장치로 폴백할 수 있다(S640). 또한, 타입3 장치가 타입2 장치를 만나면, 타입3 장치는 타입2 장치로 폴백할 수 있다(S650).
전술한 규격#1은 SAE(Society of Automotive Engineers) 표준 등을 포함할 수 있다. 규격#2는 ISO 19885-3 표준 등을 포함할 수 있다.
또한, 전술한 상호운용성을 지원하기 위해, 수소 연료공급 장치는 연결 호환성 체크를 수행할 수 있다. 예를 들어, 수소 연료공급 장치는 어드밴스드 통신 중 하나인 WLAN의 지원 여부에 따라 다음의 시나리오 1 내지 시나리오 3에서와 같이 연결 호환성 체크를 수행할 수 있다.
시나리오 1에서, 디스펜서는 무선 라우터인 액세스 포인트(access point, AP)를 준비할 수 있다. 디스펜서는 FCEV 가스충전소(fuel station) 비커닝 (beaconing)과 xVSE(x-vehicle supply equipment)에서의 연료공급 방법을 지원할 수 있다. 디스펜서에 근접한 FCEV는 디스펜서를 스캔하여 찾고, 찾은 디스펜서와 WLAN 링크를 설정할 수 있다.
시나리오 2에서, 디스펜서는 WLAN 통신을 지원하지 않고 IrDA 통신을 지원할 수 있다. 디스펜서는 타입1(Type 1) 장치에 대응된다. 디스펜서 근접한 FCEV는 타입3(Type 3) 장치로서 스캔으로 타입1 장치인 디스펜서를 찾을 수 없다. FCEV의 리셉터클이 디스펜서의 케이블에 달린 노즐과 연결될 때, FCEV와 디스펜서 간에 IrDA 통신이 시작될 수 있다.
시나리오 3에서 디스펜서는 WLAN 통신 및 IrDA 통신을 지원할 수 있다. 이 경우, 디스펜서는 타입3(Type 3) 장치에 대응된다. 타입1 장치인 FCEV는 디스펜서 주변에 주차될 수 있다. 디스펜서는 아직 어떠한 WLAN 클라이언트도 찾을 수 없다. FCEV의 리셉터클이 디스펜서의 케이블에 달린 노즐과 연결될 때, FCEV와 디스펜서 간에 IrDA 통신이 시작될 수 있다.
도 8은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 하위 호환성(backward compatibility)을 설명하기 위한 예시도이다.
도 8을 참조하면, 본 실시예의 수소 연료공급 통신 양방향 프로세스는, FCEV 및 디스펜서가 반드시 가장 선호하는 통신 방법을 선택하지 않고, 상호운용성을 극대화하기 위해 연료공급 방법(fueling method)과 통신 프로토콜이 상호운용성을 최대화하도록 폴백하는 규칙 및 원리를 제공할 수 있다.
즉, 차량 및 디스펜서 중 하나가 다른 하나를 만나면, 상대적으로 높은 타입(Type)이나 UCDC 레벨을 가진 장치가 상대적으로 낮은 타입이나 레벨을 가진 장치의 타입이나 레벨에 맞추어 폴백하도록 구성될 수 있다.
예를 들어, 차량 및 디스펜서가 동일한 타입 또는 동일한 UCDC 레벨이면, 두 장치들 모두 현재의 타입 또는 UCDC 레벨을 유지할 수 있다. 한편, 하나의 장치가 타입1 장치이고 다른 하나의 장치가 타입2 장치인 경우, 두 장치들 모두 타입0 장치로 폴백하도록 설정될 수 있다. 그리고, 하나의 장치가 타입3 장치이고, 다른 하나의 장치가 타입 3 장치가 아닌 경우, 타입3 장치는 다른 하나의 장치의 타입이나 UCDC 레벨과 동일한 레벨로 폴백하도록 구성될 수 있다.
전술한 규격#1은 SAE 표준의 통신 프로토콜일 수 있고, 규격#2는 ISO 19885 표준의 토인 프로토콜일 수 있다.
전술한 구성에 의하면, "동일한 구현"을 가진 두 개의 장치가 있는 경우, 차량과 디스펜서는 둘 다 지원하는 것과 그 중 가장 좋은 것을 선택할 수 있다. 통신이 없는 장치(이하 '무통신 장치')가 단방향 통신을 지원하는 장치(이하 간략히 '단방향 통신 장치')와 만나는 경우, 후자는 지원하는 통신 방식이 없는 무통신(no communication, No comm) 장치로 폴백할 수 있다. 또한, 양방향 통신을 지원하는 두 장치들이 만나는 경우, 두 장치들은 그대로 양방향 통신 방법을 유지할 수 있다. 여기서 UCDC 호환성은 별도로 취급될 수 있다. 또한, 어떤 장치가 무통신 장치를 만나면 무통신에 의존할 수 있다. 이는 모든 양방향 통신을 지원하는 장치(이하 간략히 '양방향 통신 장치')에 적용될 수 있다.
또한, 단방향 통신 장치가 양방향 통신 장치와 만날 때, 양방향 통신 장치가 단방향 통신 방식과 양방향 통신 방식을 모두 지원하는 경우, 양방향 통신 장치는 단방향 통신 방식으로 폴백할 수 있다. 그리고, 양방향 통신 장치가 단방향 통신을 지원하지 않는 경우, 양방향 통신 장치는 무통신(No comm)에 의지하도록 무통신 장치로 폴백할 수 있다.
전술한 양방향 통신 장치는 단방향 통신의 유무에 관계없이 단방향 통신에 의한 연료공급 방법을 지원하도록 구성될 수 있다. 이러한 양방향 통신 장치는 상대방이 양방향 통신을 지원하는지 확인할 수 있어야 한다. FCEV 또는 디스펜서가 양방향 통신을 지원하지 않는 경우, 양방향 통신 장치는 호환가능한 단방향 통신 방법을 사용하는 단방향 통신 장치로 폴백할 수 있다.
도 9는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 통신 데이터 사용 분류와 통신 데이터 사용 분류에서 하위 호환성(backward compatibility)을 설명하기 위한 예시도이다.
도 9에 나타낸 바와 같이, 차량과 디스펜서는 페어링 신원(ID: identity/identification)을 보유할 수 있는데, 이러한 신원을 주고받기 위한 요구사항은 통신 데이터 사용 분류(UCDC: use classification of communication data) 레벨에 의해 분류될 수 있다. UCDC 레벨은 UCDC 레벨1(UCDC-1)(910), UCDC 레벨2(UCDC-2)(920) 및 UCDC 레벨3(UCDC-3)(930)을 가질 수 있다. UCDC 레벨은 UCDC 레벨0(UCDC-0)(900)을 더 가질 수 있다.
UCDC 레벨0(900)은 데이터가 전달되지 않거나 데이터가 전달되는 경우에 수소 공급(dispensing of hydrogen)이나 관련 안전 기능을 위한 연료공급 프로토콜에 의해 사용되지 않는 통신을 지칭할 수 있다. UCDC 레벨0(900)에서는 차량과 디스펜서 간의 통신을 지원하지 않으므로(no communication), 디스펜서는 프로세스 제어(process control) 또는 안전 기능(safety functions) 과정에서 페어링 ID를 차량에 전달할 수 없다.
UCDC 레벨1(910)에서 페어링할 때, 차량은 페어링 ID를 디스펜서로 전달할 수 있다. UCDC 레벨1(910)에서 전달된 데이터는 안전 기능(safety functions)에 사용되지는 않지만, 전달된 정적 데이터(static data)는 연료공급 프로토콜의 성능을 개선하는데 사용될 수 있고, 전달된 동적 데이터(dynamic data)는 연료공급 프로토콜 내에서 프로세스 편차에 대한 위험 (risk against process deviations)을 줄이는데 사용될 수 있다.
UCDC 레벨2(920)에서 전달된 정적 데이터는 안전 기능(safety functions)에 사용될 수 있다. 이러한 UCDC 레벨2(920)의 정적 데이터는 UCDC 레벨1에 대해 정의된 정적 데이터와 동적 데이터에 대하여 허용된 용도에 더하여 추가된 것일 수 있다.
UCDC 레벨3(930)에서 정적 데이터와 동적 데이터는 프로토콜 또는 안전 기능 내에서 동적 제어를 위해 사용될 수 있다. 이러한 UCDC 레벨3(930)의 동적 데이터는 UCDC 레벨2에 대해 정의된 정적 데이터와 동적 데이터에 대하여 허용된 용도에 더하여 추가된 것일 수 있다.
전술한 바와 같이, UCDC 레벨은, UCDC 레벨1이 UCDC 레벨2에 포함되고, UCDC 레벨2가 UCDC 레벨3에 포함되는, 즉 상위 레벨이 하위 레벨을 포함하는 형태를 가질 수 있다. 특정 UCDC 레벨을 지원하는 장치는 더 낮은 UCDC 레벨의 장치를 지원할 수 있다. 서로 다른 UCDC 레벨들을 지원하는 장치는 두 장치에서 지원하는 가장 높은 UCDC 레벨을 사용할 수 있다. 전술한 UCDC 레벨은 UCDC 레벨0도 쉽게 지원한다고 말할 수 있다. UCDC 레벨은 backward compatible함을 알 수 있다. 본 발명의 다른 실시예에서는 backward compatibility는 UCDC 레벨과 무관하게 Non-Comm, Uni-directional Comm, Bi-directional Comm 각각과 그 조합에 대해서도 유효하게 적용될 수 있다.
도 4 내지 도 8을 함께 참조하면, 도 4의 발견 및 페어링 단계(S401)에서 차량/모빌리티와 디스펜서 간의 상호운용성(interoperability), 및/또는 호환성(compatibility)에 대한 정보가 공유될 수 있다. 이때 상호운용성 및/또는 호환성은 후술할 통신 프로토콜 협상 단계(S403), 연료공급 프로토콜 협상 단계(S404), 및/또는 연료공급 파라미터 협상 단계(S405)에서 활용될 수 있다.
본 발명의 다른 일 실시예에서는, 도 4의 발견 및 페어링 단계(S401)에서 차량/모빌리티와 디스펜서 간에 공유된 상호운용성(interoperability), 및/또는 호환성(compatibility)에 대한 정보가, 통신 프로토콜 협상 단계(S403), 연료공급 프로토콜 협상 단계(S404), 및/또는 연료공급 파라미터 협상 단계(S405)를 거치면서 업데이트되거나 재공유될 수도 있다. 통신 환경의 변화, 연료공급 과정에 영향을 미치는 파라미터의 변화 등으로 인하여 상호운용성(interoperability), 및/또는 호환성(compatibility)에 대한 정보가 업데이트될 수도 있다.
본 발명의 다른 일 실시예에서는 도 4의 발견 및 페어링 단계(S401)는 디스펜서 발견 프로토콜(DDP, Dispenser Discovery Protocol)로 지칭될 수도 있다.
DDP는 모빌리티에 의하여 브로드캐스트되는 DDP 요청 메시지 [DDPRequest]에 의하여 개시될 수 있다. DDPRequest는 모빌리티의 페어링 ID "pairing_id"를 포함할 수 있다.
디스펜서가 DDPRequest를 수신하고, 디스펜서가 DDPRequest에 응답하여 DDPResponse를 전송할 수 있다. DDPResponse는 디스펜서의 IP 주소 "IPAddr", 디스펜서의 TCP포트넘버 "TCPPort", 디스펜서의 UDP 포트넘버 "UDPPort", 디스펜서의 페어링 ID "pairing_id"를 포함할 수 있다.
도 10은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 통신 보안 절차(S402)의 인증 과정을 설명하기 위한 흐름도이다.
도 10을 참조하면, 모빌리티는 디스펜서(dispenser)에 인증 방법(authorization method)에 대한 리스트를 요청하는 메시지를 전달할 수 있다(S1010). 디스펜서는 모빌리티의 인증 방법 리스트 요청에 대한 응답 메시지를 모빌리티로 전달할 수 있다(S1020). 응답 메시지에는 RFID(radio frequency identification), 신용카드(credit cards), 직불카드(debit cards) 등의 외부 인증 절차나 자체 인증 절차와 관련된 인증 방법 리스트 정보가 포함될 수 있다.
다음, 모빌리티는 인증 방법 리스트에서 선택한 특정 방법 예컨대 RFID를 포함하는 인증 요청 메시지를 디스펜서로 전달할 수 있다(S1030). 디스펜서는 모빌리티의 인증 요청에 대한 응답 메시지를 모빌리티로 전달할 수 있다(S1040). 이 응답 메시지에는 모빌리티에서 선택된 인증 방법에 작동 중(working)임을 알리는 정보가 포함될 수 있다.
다음, 모빌리티는 디스펜서의 응답에 따라 앞서 선택한 인증 방법으로 인증을 수행하고 인증 수행에 대한 확인(Done?) 요청 메시지를 디스펜서로 전달할 수 있다(S1050). 인증 수행을 확인받지 못했거나 인증이 완료되지 않은 경우, 전술한 일련의 단계들(S1010 내지 S1050)이 반복 수행될 수 있다. 인증이 완료되면, 디스펜서는 인증 완료(Done(success)) 메시지를 모빌리티로 전송할 수 있다(S1090).
전술한 구성에 의하면, 디스펜서는 수소 연료공급 프로세스를 더 진행하기 전에 모빌리티가 승인되었는지 즉, 모빌리티의 사용자에게 수소 연료공급에 대한 권한이 있는지를 확인할 수 있다.
인증 과정의 보안을 위해, 모빌리티 및 디스펜서 중 적어도 하나를 포함하는 수소 연료공급 장치는, 모빌리티와 디스펜서 간에 데이터 링크 및 물리 계층 연결이 이루어진 후 전달 계층 즉, TCP 연결을 설정한 다음 TLS 핸드셰이크를 수행하여 인증하고, 키를 교환하여 보안 통신 채널을 설정할 수 있다. 또한, 보안에 중요한 정보가 교환되는 동안, DTLS로 보호되는 UDP 통신을 사용할 수 있다.
또한, 모빌리티 및 디스펜서는 발견 및 페어링 절차를 성공적으로 수행하고 데이터 링크 및 물리 계층의 연결을 설정할 수 있다. 그런 다음, 인증 및 키 교환에 필요한 자격 증명이 준비될 수 있다. 이에 의해 모빌리티와 디스펜서 간의 통신 채널은 암호화되고 무결성 보호될 수 있다. 디스펜서가 모빌리티를 인증하고, 선택적으로 모빌리티가 디스펜서를 인증할 수 있다.
한편, 전술한 TLS 핸드셰이크 시, 모빌리티 인증은 필수이고 디스펜서 인증은 선택 사항일 수 있으며, 이 경우 디스펜서는 클라이언트 역할을 하고 모빌리티는 서버 역할을 할 수 있다.
TLS 핸드셰이크의 경우, 모빌리티와 디스펜서는 필요한 자격 증명을 준비해야 한다. 모빌리티와 디스펜서는 인증서 체인, 인증서에 해당하는 개인 키 및 신뢰 앵커 인증서를 무단 액세스로부터 보호하는 안전한 저장소에 저장할 수 있다.
TLS 핸드셰이크 동안, 모빌리티는 미리 정의된 인증서요청(CertificateRequest) 메시지를 전송하여 클라이언트 인증을 디스펜서에 요청할 수 있다. 인증서요청 메시지를 수신한 경우, 디스펜서는 인증서 및 인증서확인(CertificateVerify) 메시지를 전송하여 모빌리티로 인증서를 전송하도록 동작할 수 있다.
모빌리티는 ServerHello 등의 핸드쉐이크 메시지와 함께 인증서요청 메시지를 보냈을 때, 디스펜서가 인증서와 함께 인증서확인 메시지를 보내지 않으면, "요구된 인증서(certificate_required)" 경고 코드가 포함된 경고 메시지를 보내서 TLS 핸드셰이크를 중지할 수 있다.
본 발명의 다른 일 실시예에 따르면, 단계(S402)의 목적, 선결조건, 및 후속조건은 다음의 표 4에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-2: "Communication Security" |
| Objectives | /Vehicle and Dispenser establish a secure channel over the discovered communication channel to achieve communication security goals including confidentiality, integrity, and privacy. |
| Short Description | After the physical and data-link layer connection is made between vehicle and dispenser, they setup layer-3 and establish a TCP connection, then perform a TLS handshake to authenticate and exchange keys to establish a secure communication channel. |
| Pre-conditions | Vehicle and dispenser performed discovery and pairing use case successfully and made a data-link layer connection. Credentials necessary for the authentication and key exchange are prepared. |
| Post-conditions | Dispenser authenticated the vehicle and the vehicle authenticated dispenser successfully. Communication channel between vehicle and dispenser are encrypted and integrity protected. |
도 11은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 통신 프로토콜 협상(communication protocol negotiation) 단계(S403)를 설명하기 위한 흐름도이다.
도 11을 참조하면, 통신 프로토콜을 협상하는 단계(S403)는, 모빌리티에서 적용 가능한 제1 통신 프로토콜에 대한 정보를 포함하는 메시지를 디스펜서로 전송하는 단계(S1110); 및 모빌리티와 디스펜서 간 공통적으로 적용 가능한 공통 통신 프로토콜 중 선택된 제2 통신 프로토콜에 대한 정보를 포함하는 메시지를 디스펜서로부터 수신하는 단계(S1130)를 포함할 수 있다.
도 11의 실시예를 참고하면, 디스펜서는 모빌리티에서 적용 가능한 제1 통신 프로토콜에 대한 정보를 포함하는 메시지를 모빌리티로부터 수신하고(S1110), 제1 통신 프로토콜과 디스펜서에서 적용 가능한 통신 프로토콜을 비교하며, 모빌리티와 디스펜서 간 공통적으로 적용 가능한 공통 통신 프로토콜 중 제2 통신 프로토콜을 선택하고, 선택된 제2 통신 프로토콜에 대한 정보를 포함하는 메시지를 모빌리티로 전송할 수 있다(S1130).
이때 도 11에 도시되지는 않았지만, 단계(S1110) 전에 모빌리티에서 적용 가능한 제1 통신 프로토콜의 리스트를 포함하는 정보를 디스펜서가 모빌리티로 요청하는 단계가 더 포함될 수 있다.
본 발명의 다른 일 실시예에서는 디스펜서가 먼저 자신의 적용 가능한 통신 프로토콜에 대한 정보를 포함하는 메시지를 모빌리티로 전송하고, 모빌리티가 공통 통신 프로토콜 중 특정한 통신 프로토콜을 선택하며, 선택된 특정 통신 프로토콜에 대한 정보를 포함하는 메시지를 디스펜서로 전송하는 실시예도 제공될 수 있다.
이때 디스펜서에서 적용 가능한 통신 프로토콜의 리스트를 포함하는 정보를 모빌리티가 디스펜서로 요청하는 단계가 더 포함될 수 있다.
본 발명의 일 실시예에 따르면, 단계(S403)의 목적, 선결조건, 및 후속조건은 다음의 표 5에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-3: "Communication Protocol Negotiation" |
| Objectives | Vehicle and Dispenser determine which communication protocol to use throughout the fueling. |
| Short Description | Once TLS handshake is successfully finished, the vehicle and the dispenser negotiates on the communication protocol to use throughout the fuelling session. The negotiation starts when the vehicle sends a list of its supported protocols and then the dispenser picks a common protocol supported by both and the vehicle prefers the most. |
| Pre-conditions | A secure authenticated communication channel is established using TLS 1.3. |
| Post-conditions | The vehicle and the dispenser reached an agreement on which communication protocol to use for their fuelling communication. |
본 발명의 일 실시예에 따르면, 단계(S1110)에서 전송 및 수신되는 메시지의 내용은 다음의 표 6에 의하여 도시될 수 있다.
| Element Name | Type | Semantics |
| protocols | CommProtocolType | Communication protocols supported by the vehicle |
| CommProtocolType | ||
| Index | Unsigned integer | Index of the protocol |
| Name | String | Name of the protocol |
| Ver | String | Version of the protocol |
| pref | Unsigned integer | Preference of protocols. Smaller number represents higher preference. |
제1 통신 프로토콜에 대한 정보는, 제1 통신 프로토콜의 인덱스, 제1 통신 프로토콜의 명칭, 제1 통신 프로토콜의 버전, 및 제1 통신 프로토콜에 대한 선호도 중 적어도 하나 이상을 포함할 수 있다.
본 발명의 일 실시예에 따르면, 단계(S1130)에서 전송 및 수신되는 응답 메시지의 내용은 다음의 표 7에 의하여 도시될 수 있다.
| Element Name | Type | Semantics |
| Index | Unsigned integer | Optional:Index of chosen protocol |
| Result | resultType | Result of the protocol negotiation. 'OK' if successful. 'FAILED_INCOMPAT' otherwise. |
제2 통신 프로토콜에 대한 정보를 포함하는 응답 메시지는, 통신 프로토콜 협상의 결과로서 성공 여부의 정보를 더 포함할 수 있다.
전술한 통신 프로토콜 협상 절차는. 차량과 디스펜서가 호환되는 통신 채널에서 서로를 발견하고 페어링한 후 먼저 수소 연료공급의 연료공급 세션(fueling session) 동안에 따를 통신 프로토콜을 식별하기 위한 절차이다. 특히, 본 실시예에서는 디스펜서가 주도하여 통신 프로토콜과 파라미터를 차량과 주고받을 수 있다.
즉, 본 발명의 일 실시예에 따른 통신 방법은, 디스펜서와 발견 및 페어링 과정을 수행하는 단계(S401)를 제1 통신 기술을 이용하여 수행할 수 있다.
통신 프로토콜 협상 단계(S403)의 결과가 제2 통신 기술과 관련되는 경우, 후술할 연료공급 프로토콜을 협상하는 단계(S404) 및 연료공급 파라미터를 협상하는 단계(S405)는 제2 통신 기술을 이용하여 수행될 수 있다.
발견 및 페어링 과정을 수행하는 단계(S401)에서는, 모빌리티와 디스펜서 간의 상호운용성(interoperability) 및/또는 호환성(compatibility)에 대한 정보가 공유될 수 있다.
본 발명의 단계(S403) 내지 단계(S405)를 수행하는 과정에서 통신 환경의 변화, 수소 연료공급과 관련된 환경 변수의 변화로 인하여, 발견 및 페어링 과정을 수행하는 단계(S401)에서 공유되었던 모빌리티와 디스펜서 간의 상호운용성 (interoperability) 및/또는 호환성(compatibility)에 대한 정보가 업데이트될 수 있다.
통신 프로토콜 협상 절차는 각 통신 기술에 대한 서로 다른 연료공급 프로토콜들(fueling protocols) 간의 성공적인 협상을 보장하기 위해 모든 이용가능한 통신 프로토콜에 의해 구현될 수 있다. 예를 들어, WLAN 등의 통신 기술을 이용하는 연료공급 프로토콜은 수소 연료공급 통신 양방향 프로세스에서 사용하고자 하는 통신 프로토콜을 결정하기 위해 차량과 디스펜서가 공통으로 지원하는 프로토콜(이하 '공통 프로토콜'이라고도 한다)을 사용할 수 있다.
실제로 각 현장에서 모빌리티 및 디스펜서는 수소 연료공급 통신 관련 표준, 통신 모드, 연료공급 방법, 통신 레벨, 기타 파라미터 등에 따른 다양한 조합이 발생할 수 있다. 여기서, 수소 연료공급 통신 관련 표준은 SAE J2601 시리즈, ISO 19885-3, ISO 19885-4 등을 포함할 수 있다. 통신 모드는 무통신(No comm.), IrDA, XYZ(ISO) 등을 포함할 수 있다. 연료공급 방법은, 룩업테이블(lookup table) 등의 테이블 기반(table-based) 연료공급방식, MC formula 기반 연료공급방식 등을 포함할 수 있다. 그리고 통신 레벨은 UCDC 레벨들을 포함할 수 있고, 기타 파라미터로는 압력 등급(pressure class), CHSS(compressed hydrogen storage system) 카테고리, 수소연료공급 테이블들(fueling tables) 등을 포함할 수 있다.
한편, 모빌리티 또는 디스펜서는 통신 프로토콜 협상 절차에서 확인된 상호 간의 타입 또는 UCDC 레벨에 따라 상대방의 낮은 타입 또는 낮은 UCDC 레벨로 폴백하는 과정을 더 수행하도록 구성될 수 있다.
또한, 다양한 조합의 발생가능한 환경에서, 모빌리티와 디스펜서는 수소 연료공급을 위한 협상 절차들(UC3 내지 UC5)을 수행하는 중에 교환되는 파라미터에서 비호환성이 확인되면, 통신 프로토콜 협상 절차로 되돌아가서 협상 절차들을 다시 수행할 수 있다.
본 발명의 일 실시예에서, 우선순위가 부여된 통신 프로토콜들은 후술할 표 6에 예시한 우선순위(priority)를 가진 프로토콜들을 포함할 수 있다.
디스펜서는 프로토콜 리스트에서 선택한 특정 프로토콜(<selected protocol>)을 포함하는 응답 메시지를 모빌리티로 전달할 수 있다(S1130). 특정 프로토콜은, 디스펜서에 의해 선택된 공통 프로토콜로서, 디스펜서와 모빌리티 모두에서 지원하고 모빌리티가 선호하는 우선순위가 가장 높은 프로토콜 예컨대, ISO 19885-3-2023-UCDC-3 프로토콜일 수 있다(표 6 참조).
공통 프로토콜에 의하면, 모빌리티와 디스펜서는 연료공급 통신(fueling communication)에 사용할 통신 프로토콜에 대해 합의에 도달할 수 있다.
한편, 모빌리티는 자신이 지원하는 통신 프로토콜들에 우선순위를 부여할 수 있다. 모빌리티는 우선순위가 부여된 통신 프로토콜들을 디스펜서에 제공할 수 있다. 우선순위가 부여된 통신 프로토콜들의 일 실시예를 예시하면 다음의 표 8과 같다.
| Protocol ID | Priority |
| SAE J2601 - No comm. | 7 |
| SAE J2799 - IrDA | 6 |
| SAE J2601 - IrDA | 5 |
| ISO 19885-3-2023-UCDC-0 | 4 |
| ISO 19885-3-2023-UCDC-1 | 3 |
| ISO 19885-3-2023-UCDC-2 | 2 |
| ISO 19885-3-2023-UCDC-3 | 1 |
전술한 통신 프로토콜 협상 유즈케이스(UC3)에서 통신 프로토콜이 선택되면, 차량과 디스펜서는 각각의 통신 프로토콜 구현을 활성화하고 연료공급 프로토콜 협상을 시작할 수 있다. 연료공급 프로토콜 협상은 차량과 디스펜서가 연료공급 세션에 사용할 연료공급 프로토콜을 찾아 합의하는 절차이다. 이 단계에서 차량과 디스펜서는 둘 다 지원하는 프로토콜들 중에서 차량이 가장 선호하는 통신 프로토콜을 선택할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급 통신 프로토콜 협상 방법은, 수소 연료 모빌리티(100)의 통신 제어 장치에 의하여 수행되는 수소 연료공급 통신 프로토콜 협상 방법으로서, 모빌리티(100)에서 지원되는 적어도 하나 이상의 제1 연료공급 프로토콜(fueling protocol) 및 적어도 하나 이상의 제1 연료공급 프로토콜을 실행하기 위하여 요구되는 제1 통신 프로토콜(communication protocol)에 대한 리스트를 포함하는 제1 메시지를 디스펜서(200)와 관련되는 통신 엔티티로 전송하는 단계(S1110); 및 디스펜서(200)와 관련되는 통신 엔티티로부터 적어도 하나 이상의 제1 통신 프로토콜 중 선택된 제2 통신 프로토콜을 포함하는 응답 메시지를 수신하는 단계(S1130)를 포함한다.
디스펜서(200)와 관련되는 통신 엔티티는, 디스펜서(200)의 전자 제어장치(210)일 수도 있고, 디스펜서(200)에 탑재되는 별도의 통신 장치일 수도 있으며, 충전소 시스템(200) 내의 전자제어장치 또는 별도의 통신 장치가 디스펜서(200)를 대신하여 차량/모빌리티(100)와 통신할 수도 있다.
제1 메시지는 표 6에 도시된 것처럼 모빌리티(100)의 선호도에 기반한 우선 순위 정보를 포함할 수 있다. 또한 표 4 내지 표 6에 기반하여 각 메시지가 정의될 수 있다.
이때 응답 메시지는, 선호도에 기반한 우선 순위 정보에 기반하여 적어도 하나 이상의 제1 통신 프로토콜 중 선택된 제2 통신 프로토콜을 포함할 수 있다. 모빌리티(100) 측 또는 디스펜서(200) 측 단독으로, 또는 상호 협력하여 선호도에 기반한 우선 순위 정보에 기반하여 제2 통신 프로토콜을 선택할 수 있다. 또한 최종적으로 승인 메시지를 상대방에게 전송하여 프로토콜 협상 과정을 마무리하는 (finished) 행위는 모빌리티(100) 측에서 주로 수행될 수 있지만, 디스펜서(200) 측에서 수행될 수 있도록 변형될 수 있다. 이 경우 디스펜서(200)가 먼저 지원되는 프로토콜 리스트를 송부하고, 모빌리티(100)가 선택된 프로토콜을 피드백할 수도 있다.
응답 메시지는, 적어도 하나 이상의 제1 통신 프로토콜 및 디스펜서(200)에서 지원되는 프로토콜에 공통으로 포함되는 공통 통신 프로토콜 중에서 선택된 제2 통신 프로토콜을 포함할 수 있다.
응답 메시지는, 디스펜서(200)의 제어 장치에 의하여 제1 연료공급 프로토콜을 실행하기 위하여 요구되는 복수의 제1 통신 프로토콜들 중 모빌리티(100)와 디스펜서(200) 간의 상호운용성(interoperability) 및 하위 호환성(backward compatibility)에 기반하여 폴백(fall back)된 장치 타입에 따라 결정되는 제2 통신 프로토콜을 포함할 수 있다.
이때 본 발명의 일 실시예에 따르면 공통 통신 프로토콜이 존재하지 않는 경우, 상기 도 7 내지 도 9에 도시된 것처럼 No comm. 통신 규격이 선택되고, 미리 결정된 규칙에 따라 No comm 통신 규격에 따른 수소 연료공급 프로토콜이 선택되어 수소가 연료공급될 수 있다. 이때 후술할 단계(S404) 내지 단계(S405)는 간략화되거나 생략될 수 있다.
본 발명의 다른 일 실시예에 따르면 공통 통신 프로토콜이 존재하지 않는 경우, 모빌리티(100)와 디스펜서(200) 간의 통신이 종료될(S409) 수도 있다.
도 12는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스 중 연료공급 프로토콜 협상 단계(S404)를 설명하기 위한 동작 흐름도이다.
도 12를 참조하면, 본 발명의 일 실시예에 따른 연료공급 프로토콜을 협상하는 단계(S404)는, 통신 프로토콜 협상(S403)의 결과에 기반하여 모빌리티에서 적용 가능한 제1 연료공급 프로토콜에 대한 정보를 포함하는 메시지를 디스펜서로 전송하는 단계(S1210); 및 모빌리티와 디스펜서 간 공통적으로 적용 가능한 연료공급 프로토콜 중 선택된 제2 연료공급 프로토콜에 대한 정보를 포함하는 메시지를 디스펜서로부터 수신하는 단계(S1230)를 포함할 수 있다.
통신 프로토콜 협상(S403)의 결과로 제2 통신 프로토콜이 선택되면, 선택된 제2 통신 프로토콜을 지원하는 수소 연료공급 프로토콜로서, 모빌리티에서 적용 가능한 적어도 하나 이상의 제1 연료공급 프로토콜에 대한 정보를 포함하는 메시지가 디스펜서로 전송될 수 있다(S1210).
디스펜서는 제2 통신 프로토콜을 지원하는 수소 연료공급 프로토콜로서, 디스펜서에서 적용 가능한 연료공급 프로토콜과 상기 제1 연료공급 프로토콜 중 공통되는 프로토콜들을 선별하고, 선별된 공통 연료공급 프로토콜 중에서 제2 연료공급 프로토콜을 선택할 수 있다. 이때 상호운용성 및/또는 호환성에 의하여 제2 연료공급 프로토콜이 선택될 수 있고, 모빌리티 또는 디스펜서가 설정한 선호도가 적용되어 제2 연료공급 프로토콜이 선택될 수 있다.
도 12의 실시예를 참고하면, 디스펜서는 모빌리티에서 적용 가능한 제1 연료공급 프로토콜에 대한 정보를 포함하는 메시지를 모빌리티로부터 수신하고(S1210), 제1 연료공급 프로토콜과 디스펜서에서 적용 가능한 연료공급 프로토콜을 비교하며, 모빌리티와 디스펜서 간 공통적으로 적용 가능한 공통 연료공급 프로토콜 중 제2 연료공급 프로토콜을 선택하고, 선택된 제2 연료공급 프로토콜에 대한 정보를 포함하는 메시지를 모빌리티로 전송할 수 있다(S1130).
이때 도 12에 도시되지는 않았지만, 단계(S1210) 전에 모빌리티에서 적용 가능한 제1 연료공급 프로토콜의 리스트를 포함하는 정보를 디스펜서가 모빌리티로 요청하는 단계가 더 포함될 수 있다.
본 발명의 다른 일 실시예에서는 디스펜서가 먼저 자신의 적용 가능한 연료공급 프로토콜에 대한 정보를 포함하는 메시지를 모빌리티로 전송하고, 모빌리티가 공통 연료공급 프로토콜 중 특정한 연료공급 프로토콜을 선택하며, 선택된 특정 연료공급 프로토콜에 대한 정보를 포함하는 메시지를 디스펜서로 전송하는 실시예도 제공될 수 있다.
이때 디스펜서에서 적용 가능한 연료공급 프로토콜의 리스트를 포함하는 정보를 모빌리티가 디스펜서로 요청하는 단계가 더 포함될 수 있다.
본 발명의 일 실시예에 따르면, 단계(S404)의 목적, 선결조건, 및 후속조건은 다음의 표 9에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-4: "Fueling Protocol Negotiation" |
| Objectives | Vehicle and Dispenser determine which fuelling protocol to use for the fuelling. |
| Short Description | Once communication protocol selection is done, the vehicle and the dispenser negotiates on the fuelling protocol to use for the fuelling. The negotiation starts when the vehicle sends a list of its supported protocols and then the dispenser picks a common protocol supported by both and the vehicle prefers the most. |
| Pre-conditions | A communication protocol is selected. |
| Post-conditions | The vehicle and the dispenser reached an agreement on which fuelling protocol to use for their fuelling. |
본 발명의 일 실시예에 따르면, 단계(S1210)에서 전송 및 수신되는 메시지의 내용은 다음의 표 10에 의하여 도시될 수 있다.
| Element Name | Type | Semantics |
| fuelProts | FuellingProtocolType | Fuelling protocols supported by the vehicle |
| FuellingProtocolType | ||
| idx | Unsigned integer | Index of the protocol |
| Name | String | Name of the protocol |
| Ver | String | Version of the protocol |
| subprot | String | Optional: Name of the sub-protocol |
| pref | Unsigned integer | Preference of protocols. Smaller number represents higher preference. |
제1 연료공급 프로토콜에 대한 정보는, 제1 연료공급 프로토콜의 인덱스, 제1 연료공급 프로토콜의 명칭, 제1 연료공급 프로토콜의 버전, 제1 연료공급 프로토콜의 하위 프로토콜(sub-protocol), 및 제1 연료공급 프로토콜에 대한 선호도 중 적어도 하나 이상을 포함할 수 있다.
본 발명의 일 실시예에 따르면, 단계(S1230)에서 전송 및 수신되는 응답 메시지의 내용은 다음의 표 11에 의하여 도시될 수 있다.
| Element Name | Type | Semantics |
| Index | Unsigned integer | Optional:Index of chosen protocol |
| Result | Enumeration | Result of the protocol negotiation. 'OK' if successful. 'FAILED_INCOMPAT' otherwise. |
제2 연료공급 프로토콜에 대한 정보를 포함하는 메시지는, 연료공급 프로토콜 협상의 결과로서 성공 여부의 정보를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 단계(S1210)에서 전송되는 메시지의 내용은 다음의 표 12와 같이 나타내어질 수 있다.
| Index | Name | Revision | Sub-protocol | Preference |
| 1 | PRHYDE | 2023 | TYPE3-T-initial | 4 |
| 2 | PRHYDE | 2024 | TYPE3-T-Special | 3 |
| 3 | RTR-HFP | 2 | ||
| 4 | ANN-MPC | 5 | ||
| 5 | HMC-FAST | 1.0 | 1 |
표 12에 나타낸 바와 같이, 모빌리티는 지원가능한 연료공급 방법이나 연료공급 프로토콜에 대하여 임의로 부여된 이름(name), 갱신(revision) 시기(연도)나 버전 정보, 서브 프로토콜 구비 여부에 대한 정보, 그리고 우선순위 (preference) 정보를 구비한 테이블 형태의 파라미터 정보를 디스펜서에 제공할 수 있다.
본 발명의 다른 일 실시예에서는 모빌리티를 대신하여 디스펜서가 주도적으로 자신의 통신 프로토콜과 파라미터를 모빌리티와 주고받을 수 있고, 디스펜서가 지원하는 통신 프로토콜들에 우선순위를 부여하여 모빌리티에 제공할 수도 있다.
표 11에서, PRHYDE(PRotocol for heavy-duty HYDrogEn refueling)는 헤비듀티 차량 연료공급 프로토콜을 개발해 온 유럽의 프로젝트 중 하나에서 제시한 것이고, RTR-HFP는 실시간 통신을 기반으로 연료공급 효율을 높이는 프로토콜 컨셉의 일종에서 제시한 것이고, ANN-MPC는 연료공급 현장의 데이터를 수집, 분석해 실 연료공급 상황에 예측 적용하는 프로토콜 컨셉의 일종에서 제시된 것일 수 있다.
본 발명의 일 실시예에 따른 단계(S1230)에서 전송되는 메시지의 일 예가 다음의 표 13 및 표 14에 도시된다.
| Fueling Protocol ID | ResultCode |
| 2 | OK |
표 13에 따르면 디스펜서는 인덱스(index) 2번에 대응하는 연료공급 프로토콜을 선택하고 그 결과코드(resultcode)인 OK를 포함하는 응답 메시지를 모빌리티로 전달할 수 있다.
| Fueling Protocol ID | ResultCode |
| FAIL_NO_COMMON_PROTOCOL |
표 14에 따르면 디스펜서는 모빌리티로부터 받은 모빌리티에 의하여 지원되는 연료공급 프로토콜 리스트에서 호환가능한 프로토콜을 찾는데 실패한(fail) 경우, 결과코드(ResultCode) 필드에 공통 프로토콜이 없음을 나타내는 정보(예컨대, FAIL_NO_COMMON_PROTOCOL)를 담은 응답 메시지를 모빌리티로 전달할 수 있다.
표 13 및 표 14의 예시는 도 11의 단계(S1130)에서 공통 통신 프로토콜 중 제2 통신 프로토콜을 선택하여 디스펜서가 모빌리티로 응답하는 경우에도 유사하게 적용될 수 있다.
도 13은 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 연료공급 파라미터 교환/협상 (fueling parameter exchange/negotiation) 단계(S405)를 설명하기 위한 흐름도이다.
연료공급 파라미터 교환/협상 단계(S405)는 모빌리티 및 디스펜서가 연료공급 프로토콜 (fueling protocol)을 이행하는데 필요한 상세 파라미터들(detailed parameters)을 서로 교환하는 단계를 포함할 수 있다.
도 13을 참조하면, 연료공급 파라미터를 협상하는 단계(S405)는, 연료공급 프로토콜 협상(S404)의 결과로서 선택된 제2 연료공급 프로토콜에 의하여 요구되는 모빌리티 측의 연료공급 파라미터에 대한 정보를 포함하는 메시지를 디스펜서로 전송하는 단계(S1310); 및 모빌리티 측의 연료공급 파라미터에 대한 디스펜서 측의 호환성 정보를 포함하는 메시지를 디스펜서로부터 수신하는 단계(S1350)를 포함할 수 있다.
연료공급 파라미터를 협상하는 단계(S405)는, 연료공급 프로토콜 협상(S404)의 결과로서 선택된 제2 연료공급 프로토콜에 의하여 요구되는 디스펜서 측의 연료공급 파라미터에 대한 정보를 포함하는 메시지를 디스펜서로부터 수신하는 단계(S1330); 및 디스펜서 측의 연료공급 파라미터에 대한 모빌리티 측의 호환성 정보를 포함하는 메시지를 디스펜서로 전송하는 단계(S1370)를 포함할 수 있다.
모빌리티는 단계(S1310)에서 모빌리티 측의 연료공급 파라미터에 대한 정보를 포함하는 메시지를 전송하면서, 해당 파라미터들에 대한 Accepted 필드를 <pending>으로 설정해 둔 채로 디스펜서로 전송할 수 있다.
마찬가지로 디스펜서는 단계(S1330)에서 디스펜서 측의 연료공급 파라미터에 대한 정보를 포함하는 메시지를 전송하면서, 해당 파라미터들에 대한 Accepted 필드를 <pending>으로 설정해 둔 채로 모빌리티로 전송할 수 있다.
모빌리티는 단계(S1330)에서 수신된 메시지에 대한 응답 메시지로서, 디스펜서 측의 연료공급 파라미터에 대한 정보를 포함하는 메시지를 전송하면서, 해당 파라미터들에 대한 Accepted 필드를 <OK> 또는 <true>로 설정하여 디스펜서로 응답할 수 있다(S1350).
디스펜서는 단계(S1310)에서 수신된 메시지에 대한 응답 메시지로서, 모빌리티 측의 연료공급 파라미터에 대한 정보를 포함하는 메시지를 전송하면서, 해당 파라미터들에 대한 Accepted 필드를 <OK> 또는 <true>로 설정하여 모빌리티로 응답할 수 있다(S1370).
이때 모빌리티와 디스펜서는 연료공급 파라미터들 각각에 대하여 Accepted 여부를 표시하여 응답할 수 있다. 합의되지 않은 파라미터의 Accepted 필드는 <false>로 표시될 수 있다.
모빌리티와 디스펜서는 메시지를 여러 번 반복적으로 송수신하고 그 메시지에 응답함으로써 모든 파라미터들에 대하여 합의를 도출할 수 있다.
교환되는 파라미터들은 연료공급 방법 호환성(fueling method compatibility)을 지원하기 위한 파라미터들, 물리적 특성(physical characteristics)에 대한 파라미터들, 모니터링 파라미터들(monitoring parameters), 수락(acceptance) 관련 파라미터 등을 포함할 수 있다.
여기서 호환성 지원 관련 파라미터들은 압력 등급(pressure class), CHSS 카테고리 등을 포함하고, 물리적 특성에 대한 파라미터들은 최대 허용 CHSS 압력, 최대 허용 CHSS 온도, 최대 허용 속도, CHSS 용량(volume) 등을 포함하고, 모니터링 파라미터들은 현재 CHSS 압력, 현재 CHSS 온도 등을 포함하고, 그리고 수락 관련 파라미터는 수락됨(accepted)이나 그렇지 아니함을 표시하는 정보 예컨대 예(true) 또는 아니오(false)를 지칭하는 파라미터를 포함할 수 있다. 전술한 파라미터들에는 미리 지정된 레벨들이나 설정값들 중 하나에 대한 정보와 서로 다르거나 동일한 메인 UCDC 레벨들에 대한 정보가 각각 설정될 수 있다.
한편, 디스펜서는 지원가능한 파라미터들(<DIS's parameters>)(간략히 <DIS's params>)에 대한 정보와 모빌리티의 파라미터들을 수신 완료 및 수락하였다는 OK 메시지를 모빌리티로 전달할 수 있다(S1330, S1370).
연료공급 파라미터 교환/협상과 관련된 제2 파라미터들은, 연료공급 방법 호환성을 지원하기 위한 파라미터들, 물리적 특성에 대한 파라미터들, 연료공급 목표(fueling goal)와 관련된 파라미터들, 모니터링 파라미터들, 수락 관련 파라미터 등을 포함할 수 있다.
여기서 호환성 지원 관련 파라미터들은 연료공급 전달 온도(fueling delivery temp.), 선택 연료공급 테이블(selected fueling table) 등을 포함하고, 물리적 특성에 대한 파라미터들은 최대 연료 전달 압력, 최대 연료 전달 온도, 최소 연료 전달 온도, 최대 연료 전달 속도 등을 포함하고, 연료공급 목표 관련 파라미터는 타겟 SOC, 타겟 최종 CHSS 압력, 타겟 최종 CHSS 온도, 타겟 APR, 예상 연료공급 시간(expected fueling duration) 등을 포함하고, 모니터링 파라미터들은 현재 연료 전달 온도, 대기 온도 등을 포함하고, 그리고 수락 관련 파라미터는 수락됨(accepted) 등의 파라미터를 포함할 수 있다. 전술한 파라미터들에는 기설정된 레벨들이나 설정값들 중 하나에 대한 정보와 서로 다르거나 동일한 메인 UCDC 레벨들에 대한 정보가 각각 설정될 수 있다.
이와 같이 모빌리티는 테이블 형태로 리스트된 파라미터들을 디스펜서에 제공할 수 있다. 리스트된 파라미터들은 연료공급 프로토콜 협상 단계에서 협의되는 UCDC 레벨과 호환가능한 FCEV 파라미터들을 포함한다.
전술한 바와 같이, 통신 링크가 설정되고 프로토콜 협상 단계에서 통신 및 연료공급 프로토콜이 선택되면, 모빌리티와 디스펜서(dispenser)는 다양한 파라미터들을 교환하여 서로 호환되는 연료공급 절차를 실행할 수 있는지 확인할 수 있다. 여기서, 안전하고 효율적인 연료공급 절차를 수행하기 위해 필요한 정보는, 호환성 파라미터, 물리적 특성, 연료공급 목표, 모니터링 파라미터 등을 포함할 수 있다.
호환성 파라미터는 예를 들어 압력 등급, 연료공급 전송 온도 등을 포함하고, 물리적 특성은 예를 들어 최대 CHSS 압력, 최대 유량 등을 포함하고, 연료 공급 목표는 목표 SOC, 목표 CHSS 압력 등을 포함하고, 그리고 모니터링 파라미터는 현재 CHSS 온도, 주변 온도 등을 포함할 수 있다.
호환 가능한 매개변수를 찾을 수 없고 연료 공급을 진행할 수 없는 경우 FCEV는 통신 프로토콜 협상 단계로 돌아가서 다른 프로토콜 협상을 시도하거나 디스펜서로 연료공급을 중지하도록 동작할 수 있다. 그리고, 연료공급 파라미터 교환 단계의 실패로 인한 되돌아가는 통신 프로토콜 협상 단계에서, FCEV는 연료공급 파라미터 교환 단계에서 실패한 프로토콜을 제외하고 지원되는 프로토콜 집합을 디스펜서에 제안하도록 구성될 수 있다.
전술한 유즈케이스(UC-4)에 의해 연료공급 프로토콜이 협상되면, 차량과 디스펜서는 연료공급 프로토콜에 대한 특정 파라미터를 협상하고, 정적 상태 또는 동적 상태를 알리고, 연료공급 목표를 결정하기 위해 자세한 연료공급 파라미터를 교환할 수 있다. 여기서, 비호환성으로 인해 연료공급 파라미터 협상이 실패하면, UC-3으로 돌아가서 다른 연료공급 프로토콜을 선택하거나 UC-1로 돌아가서 다른 통신 프로토콜을 선택할 수 있고, 이것들이 정상적으로 수행되지 않으면 현재의 통신을 종료할 수 있다.
전술한 구성에 의하면, 어떤 연료공급 프로토콜(fueling protocols)은 무통신(Non Comm.) 기반으로 수행될 수 있다. 어떤 연료공급 프로토콜이 수행되기 위해서는 단방향 IrDA가 요구될 수 있다. 어떤 연료공급 프로토콜이 수행되기 위해서는 양방향 통신이 요구될 수 있다. 어떤 연료공급 프로토콜이 수행되기 위해서는 양방향 통신 및 단방향 IrDA가 모두 요구될 수도 있다.
어떤 연료공급 프로토콜이 수행되기 위해서는 소정의 UCDC 레벨 또는 더 높은 UCDC 레벨이 요구될 수 있다. 수소전기차의 종류 또는 타입, 디스펜서의 종류 또는 타입에 기반하여 적어도 하나 이상의 연료공급 프로토콜이 제안될 수 있다. 제안되는 연료공급 프로토콜은 서로 다른 우선순위(priority)를 가지고 제안될 수도 있다. 제안되는 연료공급 프로토콜의 우선순위를 고려하면서 연료공급 프로토콜에 의하여 요구되는 통신 프로토콜이 수소전기차 및/또는 디스펜서에 의하여 지원되는지 여부에 기반하여 최종적으로 수소전기차 및 디스펜서 간의 통신 프로토콜과 연료공급 프로토콜이 결정될 수 있다.
본 발명의 다른 일 실시예에서는, 모빌리티 또는 디스펜서 중 어느 한 쪽이 먼저 연료공급 파라미터를 상대방으로 전송하고, 상대방은 수신된 연료공급 파라미터들 중 수락하는 파라미터는 유지하고, 수락하지 않는 파라미터는 변경하여 새롭게 재구성된 연료공급 파라미터들을 포함하는 메시지를 응답할 수도 있다.
본 발명의 다른 일 실시예에서는, 모빌리티 및 디스펜서는 파라미터 협상을 단계적으로 수행할 수도 있다. 모빌리티 및 디스펜서는 파라미터의 일부를 먼저 협상하고, 합의가 도출된 파라미터들의 서브-파라미터들에 대한 교환/협상 과정을 수행할 수도 있다.
본 발명의 다른 일 실시예에서는, 연료공급 파라미터를 포함하는 메시지 각각은 미리 설정된 메시지 처리 시간 내에 응답 메시지를 수신하지 못하면 합의에 이르지 못한 것으로 간주되도록 설정될 수도 있다.
아래의 표 15는 본 발명의 일 실시예에 따른 모빌리티 측의 연료공급 파라미터들을 포함하는 메시지의 내용을 도시한다.
| Name | Unit | Precision | Range/Values | Type | Semantics |
| Pressure Class | N/A | N/A | {H35, H70} | Static | Pressure classof the tank |
| CHSS Volume | Liter | 2 decimals | Positive, No-max | Static | Volumeof the tank |
| CHSS Pressure | MPa | 2 decimals | Positive, No-max | Dynamic | Current pressureof the tank |
| Emergency Policy | N/A | N/A | {Terminate,Fallback} | Static | Emergency handling policy |
아래의 표 16은 본 발명의 일 실시예에 따른 디스펜서 측의 연료공급 파라미터들을 포함하는 메시지의 내용을 도시한다.`
| Name | Unit | Precision | Range/Values | Type | Semantics |
| Fueling Delivery Temperature | N/A | N/A | {H35, H70} | Static | ... |
| FuelingTemperature | MPa | 2 decimals | Positive, No-max | Dynamic | Current pressure of the tank |
| Emergency Policy | N/A | N/A | {Terminate,Fallback} | Static | Emergency handling policy |
연료공급 파라미터 협상 단계(S405)에서, 모빌리티 및 디스펜서는 지원가능한 파라미터들(fueling parameters)에 대한 범위/값(range/values)을 가진 메시지를 생성하여 상대방에게 전달할 수 있다.
파라미터들은 물리적 특성 관련 파라미터들(간략히 '물리적 파라미터들(physical parameters)), 모니터링 파라미터들(monitoring parameters), 안전 정책(safety policy) 관련 파라미터들, 수락(acceptance) 관련 파라미터 등을 포함할 수 있다.
여기서 물리적 파라미터들은 리셉터클 타입(receptacle type), 압력 등급(pressure class), CHSS 카테고리, CHSS 타입, CHSS 용량, 최대 허용 CHSS 압력, 최대 허용 CHSS 온도, 최대 허용 속도 등을 포함하고, 모니터링 파라미터들은 현재 CHSS 압력, 현재 CHSS 온도 등을 포함하고, 안전 정책 관련 파라미터들은 긴급 정책(emergency policy), 안전 강화 레벨(safety enforcement level) 등을 포함하고, 그리고 수락 관련 파라미터는 수락됨(accepted)이나 그렇지 아니함을 표시하는 정보 예컨대 예(true), 아니오(false) 또는 처리 중(pending)을 지칭하는 파라미터를 포함할 수 있다.
연료공급 파라미터 협상과 관련된 파라미터들은, 물리적 특성 관련 파라미터들(간략히 '물리적 파라미터들'), 모니터링 파라미터들, 연료공급 목표 관련 파라미터들, 안전 정책 관련 파라미터들, 그리고 수락 관련 파라미터 등을 포함할 수 있다.
여기서 물리적 파라미터들은 연료공급 전달 온도(fueling delivery temp.), 최대 연료 전달 압력, 최대 연료 전달 온도, 최소 연료 전달 온도, 최대 연료 전달 속도 등을 포함하고, 모니터링 파라미터들은 현재 연료 전달 온도, 대기 온도(ambient temperature) 등을 포함하고, 연료공급 목표 관련 파라미터들은 선택 연료공급 테이블(selected fueling table), 타겟 SOC, 타겟 최종 CHSS 압력, 타겟 최종 CHSS 온도, 타겟 APR, 예상 연료공급 시간 등을 포함하고, 그리고 수락 관련 파라미터는 수락됨(accepted) 등의 파라미터를 포함할 수 있다. 전술한 파라미터들에는 기설정된 레벨들이나 설정값들 중 하나에 대한 정보와 서로 다르거나 동일한 메인 UCDC 레벨들에 대한 정보가 각각 설정될 수 있다.
이와 같이 FCEV는 테이블 형태로 리스트된 파라미터들을 디스펜서에 제공할 수 있다. 리스트된 파라미터들은 연료공급 프로토콜 협상 단계에서 협의되는 UCDC 레벨과 호환가능한 FCEV 파라미터들을 포함한다.
한편, 연료공급 파라미터 협상 요청 메시지를 수신한 후 수신된 연료공급 파라미터가 디스펜서와 호환되는 경우, 디스펜서는 기설정된 메시지 응답 시간 내에서 "결과"가 "OK"로 설정된 연료공급 파라미터 협상 응답 메시지를 FCEV로 전송하여 자체 연료공급 파라미터로 응답할 수 있다.
또한, 연료공급 파라미터 협상 요청 메시지를 수신한 후 디스펜서가 차량의 연료공급 파라미터와 호환되지 않는 것을 발견하면, 디스펜서는 해당 차량인 FCEV에 대한 비호환성을 나타내기 위해 "결과"가 "실패"로 설정된 연료공급 파라미터 협상 응답 메시지를 FCEV로 전송하여 응답할 수 있다. 결과는 결과코드(resultcode) 필드에 담기는 값이나 정보를 나타내고, 실패는 특정 시기의 실패(fail)로서 비호환성을 나타내는 표현 예컨대 'fail_incompat' 등으로 표현될 수 있다.
또한, 연료공급 파라미터 협상 요청 메시지를 수신한 후 FCEV가 디스펜서의 연료 공급 매개변수가 호환되지 않는 것을 발견하면, FCEV는 미리 정의된 각각의 오류 코드로 설정된 "이유"와 함께 오류 통지 요청 메시지를 디스펜서로 전송하여 디스펜서에 비호환성을 표시할 수 있다.
한편, 연료 공급을 시작하기 전에, 안전 체크인(safety check-in)에 대한 유즈케이스(UC6)를 통해 차량 및 디스펜서가 모든 안전 조건이 충족되었는지 확인할 수 있다. 이 단계는 선택 사항이지만 정확하고 명시적인 방식으로 원하는 안전 수준을 보장하기 위해 연료공급 프로토콜에서 전용의 안전 체크인 절차를 정의하는 것이 바람직하다.
도 14는 본 발명의 일 실시예에 따른 연료공급 파라미터 협상/교환 프로세스에서 모빌리티로부터 디스펜서 측으로 전달되는 파라미터의 테이블을 도시하는 개념도이다.
도 15는 본 발명의 일 실시예에 따른 연료공급 파라미터 협상/교환 프로세스에서 디스펜서로부터 모빌리티 측으로 전달되는 파라미터의 테이블을 도시하는 개념도이다.
도 13 및 도 15를 함께 참조하면, 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 연료공급 파라미터 교환 방법은, 수소 연료 모빌리티(100)의 통신 제어 장치에 의하여 수행되는 수소 연료공급을 위한 통신 상의 파라미터 교환 방법으로서, 모빌리티(100)에서 지원되는 적어도 하나 이상의 제1 수소 연료공급 방법 호환성(Fueling Method Compatibility), 및 적어도 하나 이상의 제1 물리적 특성(Physical Characteristics) 중 적어도 하나 이상을 포함하는 제1 파라미터를 디스펜서(200)와 관련되는 통신 엔티티로 전송하는 단계(S1310); 및 디스펜서(200)와 관련되는 통신 엔티티로부터 디스펜서(200)에서 지원되는 적어도 하나 이상의 제2 수소 연료공급 방법 호환성, 적어도 하나 이상의 제2 물리적 특성, 및 연료공급 목표(Fueling Goal) 중 적어도 하나 이상을 포함하는 제2 파라미터를 포함하는 응답 메시지를 수신하는 단계(S1370)를 포함한다.
디스펜서(200)와 관련되는 통신 엔티티는, 디스펜서(200)의 전자 제어장치(210)일 수도 있고, 디스펜서(200)에 탑재되는 별도의 통신 장치일 수도 있으며, 충전소 시스템(200) 내의 전자제어장치 또는 별도의 통신 장치가 디스펜서(200)를 대신하여 차량/모빌리티(100)와 통신할 수도 있다.
이때 제1 파라미터는 모빌리티(100)에서 지원되는 제1 모니터링 파라미터를 더 포함할 수 있다. 제2 파라미터는 디스펜서(200)에서 지원되는 제2 모니터링 파라미터를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 응답 메시지에 포함되는 확인 메시지(OK 메시지)에 기반하여 파라미터 교환 프로세스가 종료될 수 있다. 파라미터 교환 프로세스는 모빌리티(100)와 디스펜서(200)가 모든 교환된 파라미터를 수락하는(accept) 경우 종료될 수 있고, 어느 한 쪽이 교환된 파라미터를 수락하지 않는 경우에도 종료될 수 있다. 수락하지 않는 경우에는 후술할 과정에 의하여 프로토콜 협상 과정이 revisit되거나 연료공급 세션이 종결될(terminate) 수도 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 적어도 하나 이상의 제1 수소 연료공급 방법 호환성은, 모빌리티(100)의 압력 클래스(Pressure Class), 및 연료공급 탱크 카테고리(CHSS Category) 중 적어도 하나 이상을 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 적어도 하나 이상의 제1 물리적 특성은, 최대 허용 연료공급 탱크 압력(Maximum allowed CHSS Pressure), 최대 허용 연료공급 탱크 온도(Maximum allowed CHSS Temperature), 최대 허용 유량(Maximum allowed flow rate), 및 연료공급 탱크 부피(CHSS volume) 중 적어도 하나 이상을 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 제1 파라미터는 모빌리티(100)의 수락(acceptance) 관련 파라미터를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 제1 모니터링 파라미터는, 현재 연료공급 탱크 압력(Current CHSS Pressure), 및 현재 연료공급 탱크 온도(Current CHSS Temperature) 중 적어도 하나 이상을 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 적어도 하나 이상의 제2 연료공급 방법 호환성은, 디스펜서(200)의 연료공급 딜리버리 온도(Fueling Delivery Temperature) 및 선택된 연료공급 테이블(Selected Fueling Table) 중 적어도 하나 이상을 포함할 수 있다. 선택된 연료공급 테이블은 프로토콜 협상 과정에서 선택된 연료공급 프로토콜의 시퀀스 테이블을 포함할 수 있으며, S1330의 OK 메시지에 포함될 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 적어도 하나 이상의 제2 물리적 특성은, 최대 연료공급 딜리버리 압력(Max Fuel Delivery Pressure), 최대 연료공급 딜리버리 온도(Max Fuel Delivery Temperature), 최소 연료공급 딜리버리 온도(Min Fuel Delivery Temperature), 및 최대 연료공급 딜리버리 유량(Max Fuel Delivery Flow Rate) 중 적어도 하나 이상을 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 연료공급 목표는, 타겟 충전율(Target SoC), 타겟 최종 연료공급 탱크 압력(Target Final CHSS Pressure), 타겟 최종 연료공급 탱크 온도(Target Final CHSS Temperature), 타겟 평균 연료공급 속도(Target APR: Average Fueling Rate), 기대 연료공급 시간(Expected Fueling Duration) 중 적어도 하나 이상을 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 제2 파라미터는 디스펜서(200)의 수락(acceptance) 관련 파라미터를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 상의 파라미터 교환 방법에서는, 제2 모니터링 파라미터는, 현재 연료공급 딜리버리 온도(Current Fuel Delivery Temperature) 및 대기 온도(ambient temperature) 중 적어도 하나 이상을 포함할 수 있다.
모빌리티(100)는 프로토콜 협상 과정에서 협상된 UCDC 레벨과 호환 가능한 제1 파라미터들을 테이블 형태로 단계(S1310)에서 제공할 수 있다.
디스펜서(200)는 프로토콜 협상 과정에서 협상된 UCDC 레벨과 호환 가능한 제2 파라미터들을 테이블 형태로 단계(S1330)에서 제공할 수 있다. 이때 제2 파라미터들은 단계(S1310)에서 제공된 제1 파라미터들에 대한 수락을 나타내는 메시지를 포함하여 제공될 수 있다.
만일 모빌리티(100) 또는 디스펜서(200)가 교환된 파라미터들을 수락하지 않는 경우 모빌리티(100)는 프로토콜 협상 과정을 다시 수행할 수 있다. 또는 모빌리티(100) 또는 디스펜서(200)가 교환된 파라미터들을 수락하지 않는 경우 모빌리티(100)는 연료공급 세션을 종결할(terminate) 수 있다.
모빌리티(100) 또는 디스펜서(200)가 교환된 파라미터들을 수락하지 않아 실패한 파라미터 교환 과정에 의하여 다시 수행된 프로토콜 협상 과정에서 모빌리티(100)는 실패한 파라미터 교환 과정에서 제공되었던 프로토콜 이외의 지원되는 프로토콜 집합을 제안할 수 있다.
표 17은 본 발명의 다른 일 실시예에 따른 모빌리티 측의 연료공급 파라미터들을 포함하는 메시지의 내용을 도시한다.
| Physical Parameters | |
| Receptacle Type | ? |
| Pressure Class | H35/H70 |
| CHSS Category | A/B/C/D |
| CHSS Type | 1/2/3/4 |
| CHSS Volume | ? L |
| Maximum allowed CHSS Pressure | ? MPa |
| Maximum allowed BHSS temp. | ? ℃ |
| Maximum allowed flow rate | ? g/s |
| Monitoring Parameters | |
| Current CHSS Pressure | ? MPa |
| Current CHSS Temp. | ? ℃ |
| Safety Policy | |
| Emergency Policy | ? |
| Safety Enforcement Level | ? |
| Acceptance | |
| Accepted | TRUE/FALSE/PENDING |
표 18은 본 발명의 다른 일 실시예에 따른 디스펜서 측의 연료공급 파라미터들을 포함하는 메시지의 내용을 도시한다.
| Physical Parameters | |
| Fueling Delivery temp. | T30 |
| Max Fuel Delivery Pressure | ? MPa |
| Max Fuel Delivery Temp. | ? ℃ |
| Min Fuel Delivery Temp. | ? ℃ |
| Mas Fuel Delivery Flow Rate | ? g/s |
| Monitoring Parameters | |
| Current Fuel Delivery Temp. | ? ℃ |
| Ambient Temperature | ? ℃ |
| Fueling Goal | |
| Selected Fueling Table | D1 |
| Target SoC | ? % |
| Target Final CHSS Pressure | ? MPa |
| Target Final CHSS Temperature | ? ℃ |
| Target APR | ? MPa/s |
| Expected Fueling Duration | ? ℃ |
| Safety Policy | ? s |
| Acceptance | |
| Accepted | TRUE/FALSE/PENDING |
본 발명의 일 실시예에 따른 통신 방법은, 연료공급 파라미터 협상(S405)의 결과 연료공급 파라미터가 모빌리티와 디스펜서 간에 비호환되는(incompatible) 경우, 통신 프로토콜 및 연료공급 파라미터 중 적어도 하나 이상을 재협상하는 단계를 더 포함할 수 있다.
이때 본 발명의 일 실시예에 따른 통신 방법에서 재협상하는 단계는, 단계(S403), 단계(S404), 및 단계(S405)를 다시 수행할 수 있다. 예를 들어, 단계(S403)로 go back하여 단계(S403)부터 재협상을 수행하고, 단계(S404) 및 단계(S405)를 순차적으로 다시 수행할 수 있다. 또 다른 실시예로는, 단계(S404)로 go back하여 단계(S404)부터 재협상을 수행하고, 단계(S405)를 순차적으로 다시 수행할 수도 있다.
본 발명의 다른 일 실시예에 따른 통신 방법에서 재협상하는 단계는, 단계(S403), 단계(S404), 및 단계(S405)를 간략화하거나 일부 과정을 생략할 수 있다. 또는 단계(S403), 및 단계(S404)를 결합하여 통신 프로토콜과 연료공급 프로토콜을 함께 협상할 수도 있다. 예를 들어 앞선 단계(S401)에서 파악된 호환성 및/또는 상호운용성 정보에 따라 통신 프로토콜과 연료공급 프로토콜의 상호 지원여부에 기반하여 통신 프로토콜과 연료공급 프로토콜이 함께 포함된 프로토콜 리스트에 기반하여 통신 프로토콜과 연료공급 프로토콜이 함께 협상될 수도 있다.
본 발명의 다른 일 실시예에 따른 통신 방법에서 재협상하는 단계는, 앞선 단계(S403), 및 단계(S404)에서 선택되었던 통신 프로토콜 또는 연료공급 프로토콜을 제외한 나머지 통신 프로토콜 및 연료공급 프로토콜 리스트에 기반하여 수행될 수 있다.
본 발명의 일 실시예에 따른 통신 방법은, 연료공급 파라미터 협상(S405)의 결과 연료공급 파라미터가 모빌리티와 디스펜서 간에 비호환되는(incompatible) 경우, 미리 결정된 정책에 기반하여 제3 통신 프로토콜 및 제3 연료공급 프로토콜을 결정하는 단계; 및 제3 통신 프로토콜 및 제3 연료공급 프로토콜에 기반하여 수소가 연료공급되는 단계를 더 포함할 수 있다. 이때 제3 연료공급 프로토콜에 기반하여 제3 연료공급 파라미터가 결정될 수 있고, 수소가 연료공급되는 단계는 제3 연료공급 프로토콜 및 제3 연료공급 파라미터에 기반하여 수행될 수 있다.
예를 들어 통신 환경의 변화 등으로 인하여 모빌리티와 디스펜서 간의 통신이 불가능한 경우, 디스펜서는 No Communication으로 fall back하여, No Communication에 기반한 수소 연료공급 프로토콜로 수소를 연료공급할 수 있다.
본 발명의 일 실시예에 따른 통신 방법은, 연료공급 파라미터 협상의 결과 연료공급 파라미터가 모빌리티와 디스펜서 간에 비호환되는(incompatible) 경우, 디스펜서와 모빌리티 간의 통신을 종료하는 단계(S409)를 수행할 수 있다.
다시 도 4를 참조하면, 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 안전 체크인(safety check-in) 단계(S406)가 도시된다.
안전 체크인 단계(S406)에서, 모빌리티 및/또는 디스펜서(dispenser)는 실제 연료공급이 시작되기 전에 필요한 모든 안전 조건이 충족되었는지 확인할 수 있다.
연료공급 파라미터들이 교환되고 모빌리티와 디스펜서가 호환되는 것으로 간주되면, 단계 S406에서 모빌리티와 디스펜서가 안전 상태 점검을 수행하여 연료공급이 안전한지 확인할 수 있다. 본 발명의 대안적 실시예에서는 연료공급 프로토콜에 따라 안전 점검은 프로토콜 내에서 암시적으로 수행될 수 있으며, 구현에 따라 안전 체크인 단계(S406)는 생략될 수 있다.
또한, 안전 체크인 단계(S406)에서, 모빌리티 및/또는 디스펜서는 노즐-리셉터클이 고정되었는지를 점검하고, 누설을 점검하고, 마지막 상태(the last-minute status)를 점검할 수 있다.
또한, 디스펜서로부터 연료공급 파라미터 협상 응답 메시지를 수신한 후 연료공급 프로토콜이 안전 체크인을 지원하는 경우, 모빌리티는 메시지 시퀀스 설정시간 내에 디스펜서로 안전 체크인 요청 메시지를 전송하여 안전 체크인 단계(S406)를 시작할 수 있다.
모빌리티와 디스펜서는 커플러 점검(coupler check)을 위한 메시지들을 주고받을 수 있다. 모빌리티의 자신의 커플러 점검 결과를 나타내는 정보(예컨대 모빌리티: OK)를 포함한 메시지를 디스펜서로 전달하고, 디스펜서는 자신의 커플러 점검 결과를 나타내는 정보(예컨대 DP: OK)를 포함한 메시지를 모빌리티로 전달할 수 있다.
또한, 모빌리티와 디스펜서는 가스의 누설 점검(leak check)과 관련된 메시지들을 주고받을 수 있다. 누설 점검 관련 메시지들을 주고받는 중에, 디스펜서는 누설 점검 중임을 나타내는 정보(ongoing)를 모빌리티로 전달할 수 있다. 그리고 모빌리티는 디스펜서의 누설 점검 결과를 기다리고 있음을 나타내는 정보(waiting)를 디스펜서로 전달할 수 있다. 누설 점검이 완료되면, 디스펜서는 누설점검완료 정보(Done)와 함께 측정된 탱크 용량(measured tank volume)을 요청하는 메시지를 모빌리티로 전달할 수 있다.
또한, 디스펜서는 고정된(immobilized) 상태 점검(status check)을 위한 메시지를 모빌리티로 전달할 수 있고, 모빌리티는 상태 점검을 위해 준비되어 있음(ready)을 알리는 메시지를 디스펜서로 전달할 수 있다.
이와 같이, 모빌리티가 디스펜서에 모빌리티의 현재 상태 또는 고정 상태(immobilization status)에 대한 파라미터들을 보고(reporting)하면, 디스펜서는 커플러 고정 상태(coupler lock status), 누설 점검 상태(leak check status), 예측된 모빌리티 탱크 용량 등에 대한 파라미터들을 모빌리티로 보고할 수 있다.
전술한 안전 체크인 단계(S406)를 통과하면 연료공급이 시작될 수 있다. 연료공급 중에, 모빌리티와 디스펜서는 정보를 교환하여 연료공급이 안전하고 효율적으로 수행되도록 다양한 상태 파라미터들을 모니터링할 수 있다. 필요한 경우, 모빌리티 또는 디스펜서는 연료공급 단계(S406)를 제어하거나 안전 관련 조건에 대응하기 위해 상대방의 조치를 요청하는 제어 메시지를 보낼 수 있다. 교환할 파라미터들과 명령은 실제 연료공급 프로토콜에 따라 다를 수 있다.
단계(S407)는 본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 모니터링 및 제어(monitoring and control) 단계이다.
모니터링 및 제어 단계(S407)에서, 모빌리티를 포함하는 모빌리티 및/또는 디스펜서(dispenser)는 연료공급 상태를 모니터링하고 필요 시 연료공급을 제어할 수 있다. 모든 안전 점검이 확인되면, 모빌리티와 디스펜서는 주어진 파라미터들을 사용하여 선택한 연료공급 프로토콜에 따라 연료공급을 시작할 수 있다. 연료를 공급하는 동안, 모빌리티와 디스펜서는 다양한 측정 데이터를 교환하여 연료공급 상태를 파악하고 가능한 한 빠르게 안전에 중요한 사고 발생을 감지하도록 동작할 수 있다.
또한, 모빌리티는 연료공급 시작 및 종료와 같은 연료공급 단계(S407)를 제어하기 위해 디스펜서에 특정 명령을 전달할 수 있다. 이때 모빌리티는 블랙 채널 통신을 지원하기 위해 DTLS가 있는 UDP를 통신에 사용할 수 있다. 블랙 채널 통신은 보안되지 않은 속성이나 애플리케이션과 관련되지 않은 속성을 가진 통신 채널의 출력 특성에도 불구하고 안전한 통신이 보장되어야 하는 블랙채널 원리를 적용한 통신을 지칭할 수 있다.
모니터링 및 제어 단계(S407)를 예를 들어 좀더 구체적으로 설명하면, 모빌리티를 포함한 모빌리티는 디스펜서(dispenser)로 연료공급 제어(fueling control)를 시작(start)하기 위한 메시지를 전달할 수 있고, 이에 응답하여 디스펜서는 확인 정보(예컨대 OK)를 포함하는 메시지를 모빌리티로 전달할 수 있다.
또한, 모빌리티는 자신의 연료공급 경로(fueling loop)에 대한 정보(예컨대 x, y, z)를 포함하는 메시지를 디스펜서로 전달하고, 디스펜서는 모빌리티의 연료공급 경로에 대응하는 자신의 연료공급 경로에 대한 정보(예컨대 a, b, c)를 포함하는 메시지를 모빌리티에 제공할 수 있다.
또한, 모빌리티는 연료공급을 늦추거나(slower) 연료공급량을 줄이기 위한 정보를 포함하는 연료공급 제어(fueling control) 요청 메시지를 디스펜서로 전달하고, 디스펜서는 연료공급 상태(fueling status)의 감소를 나타내는 정보(예컨대 slowing)를 포함한 응답 메시지를 모빌리티로 전달할 수 있다.
또한, 모빌리티는 연료공급의 중단(stop)을 요청하는 연료공급 제어 요청 메시지를 디스펜서로 전달하고, 디스펜서는 연료공급을 중단하고 있거나 중단한 정보(stopping/stopped)를 포함하는 연료공급 상태 응답 메시지를 모빌리티로 전달할 수 있다.
이와 같이, 모니터링 및 제어 단계(S407)에서 모빌리티와 디스펜서는 연료공급 상태와 관련된 파라미터들을 연속적으로 또는 주기적으로 교환할 수 있다. 모빌리티는 현재 탱크 온도, 현재 탱크 압력 등을 디스펜서로 전달하고, 디스펜서는 연료공급 시작, 중지, 증가(ramping up), 감소(ramping down), 현재 주입 압력, 이후의 연료공급 계획 등과 관련된 파라미터들을 모빌리티에 제공할 수 있다.
모빌리티에서 디스펜서로 전달되는 제어(control)와 관련된 요청 메시지는 연료공급에 대한 시작(start), 멈춤(pause), 재개(resume), 종료(terminate) 등에 대한 정보나 파라미터를 포함할 수 있다. 또한, 모빌리티에서 디스펜서로 전달되는 보고(reporting)와 관련된 메시지는, 현재 탱크 온도, 현재 탱크 압력 등에 대한 정보나 파라미터를 포함할 수 있다.
디스펜서에서 모빌리티로 전달되는 보고(reporting)와 관련된 메시지는, 상태 정보, 현재 대기 온도, 현재 압력 상승율(pressure ramp rate, PRR [Mbar/min]), 전달 연료 유속(deliver fuel flow rate [g/sec]), 현재 연료 전달 온도, 사전 냉각 온도, 현재 연료 전달 압력, 만충(완충)전 사용중 여부, 냉각 디스펜서 사용중 여부, 폴백 사용중 여부, 연료공급 중지 이유, 현재 연료공급된 수소양 등에 대한 정보나 파라미터를 포함할 수 있다.
그리고, 디스펜서에서 모빌리티로 전달되는 타겟 파라미터 업데이트와 관련된 메시지는, 타겟 최종 탱크 압력, 타겟 최종 탱크 온도, 타겟 연료공급 APR, 타겟 SOC, 현재 SOC, 예측된 잔류 시간(estimated remaining duration) 등에 대한 정보나 파라미터를 포함할 수 있다.
한편, 전술한 모니터링 및 제어 단계(S407)에서 TCP가 사용될 때, 안전 체크인 응답 메시지 또는 연료공급 프로토콜에 의한 안전 체크인 단계가 생략된 경우, 모빌리티는 디스펜서로부터 연료공급 파라미터 협상 응답 메시지를 수신한 후, 메시지 시퀀스 설정시간 내에 연료공급 경로(fueling loop) 요청 메시지를 디스펜서로 전송할 수 있다. 연료공급 경로와 관련된 요청 메시지나 응답 메시지는 DTLS 메시지로 전송될 수 있다.
전술한 모니터링 및 제어 단계(S407)를 통해 수소 연료 공급을 마친 후, 세션을 종료하고 모빌리티에서 노즐을 분리하기 전에, 모빌리티를 포함하는 모빌리티와 디스펜서(dispenser)는 안전 체크아웃(safety check-out) 유즈케이스를 통해 량과 디스펜서 각자가 모든 안전 조건을 충족하는지 확인할 수 있다. 이러한 안전 체크아웃 단계는 선택 사항이지만 정확하고 명시적인 방식으로 원하는 안전 수준을 보장하기 위해 연료공급 프로토콜에서 전용의 안전 점검 단계(S407)를 정의하는 것이 바람직하다.
본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 안전 체크아웃(safety check-out) 단계(S408)는 다음과 같이 수행될 수 있다. 모빌리티를 포함하는 모빌리티 및 디스펜서(dispenser)는, 안전 체크아웃 단계(S408)를 통해 디스펜서의 노즐을 콘센트에서 분리하기 전에 필요한 모든 안전 조건이 충족되었는지 확인할 수 있다. 다시 말해서, 모빌리티 및 디스펜서는 연료공급이 완료된 후 사용자 또는 작업자가 모빌리티에서 노즐을 분리하는 것이 절대적으로 안전한지 확인할 수 있다.
예를 들어, 모빌리티가 디스펜서로부터 "결과(result)"가 "OK"로 설정되거나, "상태(status)"가 "마침(finished)"으로 설정되거나 접두사가 "중지됨(stopped)"인 연료공급 루프 응답 메시지를 수신한 후, 수소 연료공급 프로토콜이 안전 체크아웃을 지원하는 경우, 모빌리티는 안전 체크아웃을 시작할 수 있고, 메시지 시퀀스 설정시간 내에 디스펜서로 안전 체크아웃 요청 메시지를 전송하여 안전 체크아웃 단계(S408)를 수행할 수 있다.
모빌리티와 디스펜서는 안전 점검이 모두 확인될 때까지 각자의 상태를 상대방에게 반복적으로 보고할 수 있다. 수소 연료공급 통신 양방향 프로세스가 마지막에 이러한 안전 확인을 요구하지 않는 경우, 안전 체크아웃에 대한 유즈케이스는 생략될 수 있다.
전술한 안전 체크아웃 단계(S408)에 대하여 예를 들어 좀더 상세히 설명하면, 모빌리티는 커플러 점검(coupler check) 결과에 대한 정보(예컨대 OK)를 포함하는 메시지를 디스펜서(dispenser)로 전달할 수 있고, 디스펜서는 커플러 점검을 진행 중임을 나타내는 정보(예컨대 Ongoing)를 포함하는 메시지를 모빌리티로 전달할 수 있다.
또한, 모빌리티는 커플러 점검 결과 정보(예컨대 OK)를 포함하는 메시지를 다시 디스펜서(dispenser)로 전달할 수 있고, 디스펜서는 커플러 점검 완료 정보(예컨대 Done)를 포함하는 메시지를 모빌리티로 전달할 수 있다.
전술한 커플러 점검 완료 정보가 정상적으로 완료된 것으로 확인되면, 사용자 또는 작업자에 의해, 디스펜서의 노즐은 모빌리티의 리셉터클로부터 분리될 수 있다.
전술한 안전 체크아웃 단계(S408)에서, 디스펜서가 모빌리티로 전달하는 보고 메시지에는 커플러 풀림 상태(coupler unlock status)에 대한 정보나 파라미터가 포함될 수 있다. 커플러 풀림 상태 정보는 잠김(locked), 풀림(unlocked), 아이싱(icing), 문제(problem) 등에 대한 정보를 포함할 수 있다.
전술한 수소 연료공급 프로토콜에 따라 연료공급이 완료되고 노즐을 안전하게 분리한 경우이거나 또는 다른 유즈케이스 중에 안전에 중요하지 않은 문제가 발생한 경우, 종료(termination) 유즈케이스(UC9)를 수행할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 종료(termination) 단계(S409)는 다음과 같이 수행될 수 있다.
종료 단계(S409)는 연료공급의 마지막 단계로, 모빌리티를 포함하는 모빌리티와 디스펜서(dispenser)는 연료공급 성능 및 방법에 관한 연료공급 결과에 대한 정보, 및/또는 연료공급을 예기치 않게 중단한 경우의 이유에 대한 정보를 교환하여 수소 연료공급에 대한 모든 단계(S409)를 완료할 수 있다. 종료 유즈케이스는 안전에 중요하지 않은 문제가 발생한 경우, 이와 관련된 작업도 처리하도록 구성될 수 있다.
예를 들어, 모빌리티가 디스펜서로부터 "결과(result)"가 "완료(DONE)"로 설정된 안전 체크아웃 응답 메시지를 수신하거나, "상태(status)"가 "마침(finished)"로 설정되거나 접두사가 "중지됨(stopped)"인 연료공급 루프 응답 메시지를 수신한 후, 모빌리티는 디스펜서로 종료 요청 메시지를 전송하여 종료 단계(S409)를 수행할 수 있다.
종료 단계(S409)에 대하여 예를 들어 좀더 상세히 설명하면, 모빌리티를 포함하는 모빌리티는 얼마나 많은 연료공급이 이루어졌는지를 질의하는 메시지를 디스펜서(dispenser)로 전달할 수 있다. 디스펜서는 모빌리티의 질의 메시지에 대응하여 연료공급된 수소량에 대한 정보(예컨대 X gram)를 포함하는 응답 메시지를 모빌리티로 전달할 수 있다.
또한, 모빌리티는 연료공급 완료에 대한 확인(confirmed) 요청 메시지를 디스펜서로 전달할 수 있고, 디스펜서는 확인 요청 메시지에 대한 응답 메시지로서 굿바이(good bye) 메시지를 모빌리티로 전달할 수 있다.
한편, 연료공급이 완료되고 안전 점검이 확인된 후, 모빌리티와 디스펜서는 종료 단계(S409)에서 수소 연료공급의 연료공급 세션에 대한 적어도 일부의 장부 정보(book-keeping information)를 서로 교환할 수 있다. 모빌리티와 디스펜서는 종료 단계(S409)를 완료하기 전에 수소 연료공급의 연료공급 세션에 대한 요약 정보를 교환할 수 있다.
장부 정보(book-keeping information)는 수소 연료공급을 위한 모든 연료공급 세션(fueling session)에 걸쳐 그리고 유즈케이스9(UC9)의 종료(termination) 단계(S409)를 완료하기에 앞서, 기설정 규칙이나 정책에 따라 모빌리티나 디스펜서에 기록되는 수소 연료공급과 관련된 모든 정보를 포함할 수 있다.
장부 정보 또는 요약 정보는 연료가 얼마나 공급되었는지, 어떠한 보고서가 만들어졌는지 등에 대한 정보를 포함할 수 있다. 또한, 모빌리티에서 디스펜서로 전달되는 보고 메시지는 현재 탱크 온도, 현재 탱크 압력에 대한 정보나 파라미터가 포함될 수 있고, 디스펜서에서 모빌리티로 전달되는 보고 메시지는 최종 SOC, 최종적인 평균 연료공급 속도(APR: average fueling rate), 최종적으로 측정된 탱크 압력, 실제 연료공급 시간, 실제 연료공급된 수소량 등에 대한 정보를 포함할 수 있다.
연료공급 세션에 대한 필요한 정보가 모두 저장되면, 연료공급 세션은 완전히 종료될 수 있다.
전술한 유즈케이스들 중 일부(UC5 내지 UC9)의 통신 데이터를 예시하면 다음의 표 19와 같다.
| UC 구분 | 충전소 → 차량 | 차량 → 충전소 |
| FuelingParameter Negotiation |
통신 전달여부 체크 연료공급 프로토콜 수소 공급(냉각) 온도 목표 연료공급 압력 목표 연료공급 후 예상(기대) 탱크 온도 목표 연료공급량 (SOC %) 목표 연료공급 시간 대기온도 |
통신 전달여부 체크 최대사용압력 최대사용온도 최대사용유량 탱크온도 탱크압력 탱크부피 차량연료공급압력(350/700 등) |
| SafetyCheck-in | 노즐-리셉터클 체결 여부 수소저장시스템 누설 체크 결과 충전소 예측 차량 탱크 부피 (사용맵 적합성 확인) |
탱크온도 탱크압력 탱크부피 |
| Monitoring andControl | 수소 공급(냉각) 온도 목표 연료공급 압력 목표 연료공급 후 예상(기대) 탱크 온도 목표 연료공급량 (SOC %) 대기온도 목표 연료공급 속도 실제 연료공급 속도 목표 연료공급 시간 실제 연료공급 시간 연료공급 유량 연료공급 상태(시작/연료공급중/중단/일시정지) 통신 상태 연료공급 중단시 사유 (정상종료/충전소압력부족/통신이상) 만연료공급(Top-off) 여부 콜드 디스펜서 여부 폴백 진행 여부 |
탱크온도 탱크압력 탱크부피 연료공급 중단요청 |
| SafetyCheck-out | 노즐-리셉터클 분리가능 여부 (분리가능/아이싱 등) |
탱크온도 탱크압력 탱크부피 |
| Termination | 목표 연료공급량실제 연료공급량 목표연료공급속도 실제연료공급속도 목표연료공급압력 실제연료공급압력 목표탱크온도 실제탱크온도 목표연료공급시간 실제연료공급시간 |
한편, 오류 처리 유즈케이스(UC10)는 정상적인 종료와 유사하게 연료공급 절차를 종료하거나 갑자기 통신을 중단하여 안전에 치명적이지 않은 오류가 발생한 상황을 처리하기 위한 기능 블록이다.
본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 오류 처리(error handling) 단계(S410)는 다음과 같이 수행될 수 있다.
오류 처리 단계(S410)는 연료공급 프로토콜과 관련된 오류 조건을 정의하고 검출 기준을 제공하고, 검출되는 경우 알림, 종료 과정 및 폴백 메커니즘을 포함한 대응 과정을 포함할 수 있다.
오류 처리 단계(S410)는 안전에 치명적이지 않은 오류가 발생하고 더 이상의 통신이 불가능한 경우에 적용될 수 있다. 즉, 모빌리티를 포함하는 모빌리티와 디스펜서(dispenser)는 오류 처리 단계(S410)에서 연료공급 중 언제라도 비안전 치명적 오류가 발생하는 것을 처리할 수 있다. 다시 말해서, 모빌리티와 디스펜서는 연료공급을 즉시 중단하고, 이전에 작동 중인 유즈케이스를 일시 멈춘 후에 종료 유즈케이스(UC9)로 이동할 수 있다.
비안전 치명적 오류에 대한 이벤트를 모빌리티에서 감지한 경우, 모빌리티는 종료 요청(terminate request, TerminateReq) 메시지를 통해 종료 사유를 디스펜서에 알리고 현재의 연료공급 세션이나 통신(the comm.) 세션을 중지 (stop)할 수 있다. 디스펜서는 종료 요청 메시지에 응답하여 현재의 통신 세션을 종료할 수 있다. 추가적인 통신이 불가능한 경우, 추가적인 알림 없이 현재 세션이 종료될 수 있다.
또한, 안전에 중요하지 않은 오류가 모빌리티에서 감지되고 통신 채널이 계속 작동하는 경우, 모빌리티는 "동작(action)"이 "중지(stop)"로 설정되고 "이유"가 적절한(appropriate) 이유나 이유 코드로 설정된 종료 요청(TerminateReq) 메시지를 디스펜서로 전송할 수 있다. 적절한 이유 또는 이유 코드는 메시지가 손상되었다(message is corrupted) 등과 같은 이유를 포함할 수 있다.
전술한 종료 요청 메시지는 복구할 수 없는 경우를 제외한 안전에 치명적이지 않은 통신 오류, 시스템 오류 및 질적 오류(qualitative error)의 오류 상황에서 전송될 수 있다.
즉, 성공적인 연료공급을 위해 통신은 프로토콜에 따라 예상되는 동작을 보여야 하며 연료공급 동작은 연료공급 프로토콜의 허용 가능한 범위 내에 있어야 한다. 하지만 실제로는 다양한 비정상적인 사건이 발생할 수 있다. 그 중에 일부 오류는 사소하고 쉽게 처리될 수 있으나 일부 다른 오류는 복구할 수 없고, 연료공급을 진행할 수 없게 한다. 따라서, 오류 처리 단계(S410)에서는 안전에 중요하지 않은 오류 조건을 정의하고 예시적인 오류 조건과 가능한 응답을 제공한다.
통신 오류의 일례로는, 통신이 끊어지거나, 인코딩 오류나 구문 오류로 인해 수신된 데이터를 인식할 수 없거나, 수신된 데이터가 허용되지 않는 범위에 있는 경우를 포함할 수 있다. 시스템 오류는 디스펜서 또는 모빌리티가 자체적으로 중요한 시스템 오류를 감지한 경우를 포함할 수 있다. 그리고, 질적 오류는 통신 성능의 품질이 요구 수준을 충족하지 못하거나, 데이터 무결성 또는 정밀도의 품질이 요구 수준을 충족하지 못하는 경우를 포함할 수 있다.
본 실시예의 수소 연료공급 통신 양방향 프로세스는 전술한 오류 조건에 대한 다음의 (1) 내지 (4)와 같은 구체적인 오류 처리 단계(S410)를 수행할 수 있다.
(1) 안전에 치명적이지 않은 오류가 발생하고 더 이상의 통신이 불가능한 경우, 모빌리티 및 디스펜서는 연료공급을 즉시 중지하지만 안전한 조치를 취하고 통신을 중지하여 세션을 종료할 수 있다.
(2) 안전에 치명적이지 않은 오류가 발생하고 연료공급이 중단되어 연료공급이 완료되지 않은 경우, 연료공급 프로토콜은 예를 들어 비통신 연료공급 방법을 정의하여 폴백 메커니즘을 정의할 수 있다.
(3) 안전에 중요하지 않은 오류가 모빌리티에서 감지되고 통신 채널이 여전히 작동 중인 경우, 모빌리티는 "동작(action)"이 "중지(stop)"로 설정되고 "이유(reason)"가 적절한 이유 코드로 설정된 종료 요청 메시지를 디스펜서로 전송할 수 있다.
(4) 안전에 중요하지 않은 오류가 디스펜서에 의해 감지되고 통신 채널이 여전히 작동 중인 경우, 디스펜서는 먼저 연료공급을 즉시 중지하고 "동작"이 "중지"로 설정되고, "이유"가 적절한 이유 또는 이유 코드로 설정된 종료 요청 메시지를 모빌리티로 전송할 수 있다.
전술한 바와 같이, 연료공급 프로토콜을 포함하는 수소 연료공급 통신 양방향 프로세스는 연료공급 프로토콜과 관련된 오류 조건을 정의하고, 탐지 기준을 제공하고, 탐지 기준에 의해 오류가 탐지되는 경우 알림, 종료 단계(S410) 및 폴백 메커니즘을 포함한 오류 처리 단계(S410)를 수행할 수 있다.
한편, 수소 연료공급 시스템에서의 연료공급 도중에 안전에 중요한 문제가 발생하여 긴급한 대응이 필요할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급 통신 양방향 프로세스에 채용할 수 있는 긴급 처리(emergency handling) 단계(S411)는 다음과 같이 수행될 수 있다.
긴급 처리 단계(S411)는 연료연료공급 중에 긴급 대응이 필요한 안전 필수 조건을 정의하고 안전 필수 사고를 방지하기 위한 대응 과정을 포함할 수 있다.
안전한 연료공급을 위해 통신은 프로토콜에 따라 예상되는 동작을 보여야 하며 연료공급 동작은 연료공급 프로토콜의 안전한 범위 내에 있어야 한다. 하지만, 연료공급 도중에 문제가 발생하여 연료공급 시스템(또는 수소 연료공급 시스템)이 어떤 대가를 치르더라도 피해야 하는 임계 상태에 도달할 가능성이 있다. 따라서, 긴급 처리 단계(S411)에서는 안전에 중요한 비상 조건과 비상 조건에 대해 가능한 대응을 정의하고 고려해야 할 중요 케이스를 제공할 수 있다.
연료공급 프로토콜은 프로토콜과 관련된 비상 조건을 정의하고 감지 기준 및 성능 요구 사항을 제공하고, 반드시 유해한 상황에 진입하지 않도록 대응 단계(S411)를 규정할 수 있다.
구체적으로, 수소 연료공급 단계(S411)를 진행하는 도중, 모빌리티에 의해, 기설정 기준치를 초과하는 고압(high pressure) 상태가 검출되면, 모빌리티는 고압에 따른 연료공급 중지를 요청하는 정보(예컨대 Emg: Stop (high pressure))를 포함하는 제1 긴급 중지 요청 메시지를 디스펜서(dispenser)로 전달할 수 있다. 디스펜서는 제1 긴급 중지 요청 메시지에 따라 긴급 연료공급 중지를 처리중임을 나타내는 정보(예컨대 Emg: Stopping)를 포함하는 응답 메시지를 모빌리티로 전달할 수 있다.
또한, 응답 메시지를 수신한 후 즉시 또는 기설정된 시간이 경과한 후에, 모빌리티는 제1 긴급 중지 요청 메시지를 다시 디스펜서로 전달할 수 있다. 디스펜서는 제1 긴급 중지 요청 메시지에 따라 연료공급이 긴급 중지되었음을 나타내는 정보(예컨대 Emg: Stopped)를 포함하는 응답 메시지를 모빌리티로 전달할 수 있다.
한편, 수소 연료공급 단계(S411)를 진행하는 도중, 디스펜서에 의해, 수소 연료의 누설(leaking)이 검출되면, 디스펜서는 누설에 따른 연료공급 중지를 처리 중임을 알리는 정보(예컨대 Emg: Stopping (leaking))를 포함하는 제2 긴급 중지 요청 메시지를 모빌리티로 전달할 수 있다. 모빌리티는 제2 긴급 중지 요청 메시지를 확인했음을 알리는 정보(예컨대 Emg: Confirmed)를 포함하는 응답 메시지를 디스펜서로 전달할 수 있다.
또한, 디스펜서는 누설에 따른 연료공급 중지를 처리했음을 알리는 정보(예컨대 Emg: Stopped (leaking))를 포함하는 제3 긴급 중지 통지 메시지를 모빌리티로 전달할 수 있다. 모빌리티는 제3 긴급 중지 통지 메시지를 확인했음을 알리는 정보(예컨대 Emg: Confirmed)를 포함하는 응답 메시지를 디스펜서로 전달할 수 있다.
전술한 구성에 의하면, 모빌리티를 포함하는 모빌리티 또는 디스펜서(dispenser)에서 안전에 영향을 미치는 중대한 상황이 감지되면, 즉시 필요한 조치를 취하여 재난이 발생하지 않도록 동작할 수 있으며, 가능한 경우 상황에 대한 정보가 포함된 긴급 통지 메시지를 상대방에게 전송하고 통신을 차단할 수 있다.
긴급 통지 메시지가 수신되면, 모빌리티 또는 디스펜서는 긴급 통지 메시지에 표시된 동작(action)에 따라 즉시 응답하고 과도한 지연 없이 통신을 종료할 수 있다. 긴급 통지 메시지는 헤더(header)와 헤더에 연결되는 바디(body)인 메시지를 포함하고, 헤더에는 긴급 통지임을 나타내는 정보가 포함되고, 메시지에는 긴급 통지에 대한 등급(class), 타입(type) 및 동작(action)에 대한 값이나 정보 또는 파라미터가 포함될 수 있다.
전술한 긴급 통지 메시지는 통신에 사용되는 기술에 따라 TLS 또는 DTLS 메시지로 전송될 수 있다.
다시 도 4를 참조하여 안전 체크인 단계 (S406)의 목적, 선결조건, 및 후속조건은 다음의 표 20에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-6: "Safety Check-in" |
| Objectives | Vehicle and Dispenser confirms that all the necessary safety conditions are met and the communication link is correctly paired with the pairing channel before actual fuelling is started. |
| Short Description | Once fuelling parameters are exchanged and vehicle and dispenser are considered compatible, vehicle and dispenser performs safety condition checks and pairing checks to make sure the fuelling is safe and the communication is reliable. Depending on the fuelling protocol and the communication physical layer, the safety checks can be implicitly done within the protocol or physical association and this step may be omitted. |
| Pre-conditions | Necessary fuelling parameters are exchanged. |
| Post-conditions | The vehicle and the dispenser confirmed all the safety conditions and correctness of the pairing, and ready to begin fuelling. |
연료공급 파라미터 협상 단계(S405)가 성공적으로 수행되면, 연료공급 프로토콜은 안전 체크인 단계 (S406)를 수행할 수 있음은 전술한 바와 같다.
이때 통신 물리 계층이 페어링 절차 (pairing procedure)를 요구하도록 규정된 경우에, 모빌리티와 디스펜서는 안전 체크인 단계 (S406)에서 수소를 디스펜싱하기 전에 페어링을 다시 체크할 수 있다.
이때 통신 물리 계층이 페어링 절차 (pairing procedure)를 요구하도록 규정되지 않은 경우에도, 모빌리티와 디스펜서는 안전 체크인 단계 (S406)에서 수소를 디스펜싱하기 전에 페어링을 다시 체크할 수 있다.
단계 (S405)의 완료를 알리는 메시지 (예를 들어 FuelParamNegoRes)를 디스펜서로부터 수신한 후에, 만일 연료공급 프로토콜이 안전 체크인 단계(S406)를 지원하면, 모빌리티는 안전 체크인 단계 (S406)의 시작을 의미하는 메시지 (예를 들어 SafetyCheckInReq)를 미리 결정된 시간 구간 (예를 들어 MessageSequenceTimeout) 내에 디스펜서로 전송할 수 있다.
대안적 실시예로서, 단계 (S405)의 완료를 알리는 메시지가 모빌리티와 디스펜서 중 일방에 의하여 상대방에게 전송된 경우, 그 일방 또는 상대방은 안전 체크인 단계 (S406)의 시작을 의미하는 메시지를 전송할 수 있다.
본 발명의 일 실시예에 따르면 안전 체크인 단계 (S406)에서 전송 및 수신되는 메시지는 예를 들어 ISO 19885-3 과 같은 규격에서 규정되는 각각의 연료공급 프로토콜의 내용에 기반하여 정의될 수 있다.
본 발명의 일 실시예에 따르면 안전 체크인 단계 (S406)에서 전송 및 수신되는 메시지는 요청 메시지를 처리한 결과 값을 result element로 포함할 수 있다. 이때 result element로 제공될 수 있는 결과 값은 예를 들어 성공한 경우 'OK', 실패한 경우 'FAILED'를 포함할 수 있고, 이외의 경우에 'PENDING'을 포함할 수 있다.
만일 모빌리티가 디스펜서로 SafetyCheckInReq 메시지를 전송할 때 모든 안전 조건이 충족된다면 그 메시지의 결과 값은 "OK"로 설정될 수 있다.
만일 모빌리티가 디스펜서로 SafetyCheckInReq 메시지를 전송할 때 몇몇 안전 조건이 아직 충족되지 않았다면 그 메시지의 결과 값은 "PENDING"으로 설정될 수 있다.
디스펜서가 SafetyCheckInReq 메시지를 수신한 후 MessageResponseTimeout 시간 구간 내에 디스펜서가 안전-체크 파라미터와 함께 SafetyCheckInRes 메시지를 모빌리티로 응답할 수 있다.
만일 디스펜서가 모빌리티로 SafetyCheckInRes 메시지를 전송할 때 모든 안전 조건이 충족된다면 그 메시지의 결과 값은 "OK"로 설정될 수 있다.
만일 디스펜서가 모빌리티로 SafetyCheckInRes 메시지를 전송할 때 몇몇 안전 조건이 아직 충족되지 않았다면 그 메시지의 결과 값은 "PENDING"으로 설정될 수 있다.
만일 result 값이 "PENDING"으로 세팅된 SafetyCheckInRes 메시지를 수신한 경우, 모빌리티는 또 다른 SafetyCheckInReq 메시지를 MessageResponseTimeout 시간 구간 내에 디스펜서로 전송할 수 있다.
만일 result 값이 "PENDING"으로 세팅된 SafetyCheckInReq 메시지를 수신한 경우, 디스펜서는 또 다른 SafetyCheckInReq 메시지를 MessageResponseTimeout 시간 구간 내에 모빌리티로 전송할 수 있다.
모빌리티 또는 디스펜서는 모든 안전 조건을 소정의 시간 (예를 들어 UCSafetyCheckInTimeout) 내에 컨펌할 수 없을 때, "reason" 항목을 적절한 에러 코드로 설정한 ErrNotifReq 메시지를 전송할 수 있다.
대안적 실시예로서, 모빌리티 또는 디스펜서는 안전 체크인의 시작을 의미하는 요청 메시지를 상대방에게 전송할 수 있고, 상대방은 소정의 시간 구간 내에 안전 체크인의 요청 메시지에 대한 응답 메시지를 응답할 수 있다.
다시 도 4를 참조하여 모니터링 및 제어 단계 (S407)의 목적, 선결조건, 및 후속조건은 다음의 표 21에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-7: "Fuelling control and monitoring" |
| Objectives | Vehicle and Dispenser monitors the fuelling status and control the fuelling if necessary. |
| Short Description | Once all the safety checks are confirmed, the vehicle and dispenser starts the fuelling according to the chosen fuelling protocol with given parameters. During the fuelling, vehicle and dispenser exchange various measured data to understand the fuelling status and detect any safety-critical incidents as early as possible. Vehicle can also submit certain commands to dispenser to control the fuelling procedure, such as starting and ending the fuelling.To support black-channel communication, UDP with DTLS is used for the communication. |
| Pre-conditions | All the safety checks are confirmed and vehicle and dispenser are ready to fuel. |
| Post-conditions | The fuelling is finished successfully. |
안전 체크인 단계(S406)가 성공적으로 수행되면, 연료공급 프로토콜은 모니터링 및 제어 단계 (S407)를 수행할 수 있음은 전술한 바와 같다.
안전 체크인 단계(S406)가 생략되는 경우에는 연료공급 파라미터 협상 단계(S405)가 성공적으로 수행되면, 연료공급 프로토콜은 모니터링 및 제어 단계 (S407)를 수행할 수 있다.
모니터링 및 제어 단계 (S407)가 수행되는 동안 디스펜서는 모빌리티로 연료공급하기 위하여 모든 필요한 스텝들을 수행할 수 있다.
TCP 규격이 연료공급 제어 및 모니터링 유즈 케이스에서 이용될 때, 모빌리티는 SafetyCheckInRes 메시지를 수신하거나 안전 체크인 단계 (S406)이 생략되는 실시예에서는 FuelParamNegoRes 메시지를 수신한 후에, 미리 정해진 시간 구간 (예를 들어 MessageSequenceTimeout) 내에 모니터링 및 제어 단계(S407)의 시작을 요구하는 메시지 (예를 들어 FuelLoopReq 메시지)를 디스펜서로 전송할 수 있다.
전술한 블랙 채널이 이용될 때 SafetyCheckInRes 메시지를 전송하거나 안전 체크인 단계 (S406)이 생략되는 실시예에서는 FuelParamNegoRes 메시지를 전송한 후에, 모빌리티 (클라이언트로서) 및 디스펜서 (서버로서)는 NewSessionTicket을 이용한 session resumption과 함께 RFC 9147을 따르는 DTLS 1.3 핸드셰이크를 개시할 수 있다. 이때 NewSessinTicket은 디스펜서로부터 수신될 수 있다.
DTLS 1.3 핸드셰이크가 성공적으로 마무리된 (finished) 후에, 모빌리티는 미리 정해진 시간 구간 (예를 들어 MessageSequenceTimeout) 내에 모니터링 및 제어 단계(S407)의 시작을 요구하는 메시지 (예를 들어 FuelLoopReq 메시지)를 디스펜서로 전송할 수 있다.
이때 0-RTT는 DTLS session resumption을 위해 사용되지 않을 수 있다.
FuelLoopReq 및 그에 대한 응답 메시지 (예를 들어 FuelLoopRes 메시지)는 모두 DTLS 메시지 규격을 따르도록 전송될 수 있다.
이 외에 블랙 채널 방법을 위해 필요한 요건들이 추가될 수 있다.
FuelLoopReq 메시지는 연료공급 프로토콜 각각의 정의에 기반하여 구현될 수 있다.
연료공급 프로토콜은 FuelLoopReq 및 FuelLoopRes 내에 포함될 정적 또는 동적 데이터를 정적 또는 동적 데이터는 연료공급 상태를 모니터하고 안전 관련 정보를 교환할 수 있도록 특정할 수 있다.
FuelLoopReq 메시지에 포함되는 엘리먼트 이름은 action, reason 등을 포함할 수 있으며, 아래 표 22에 의하여 도시될 수 있다. 아래 표 22의 내용에 도시되지 않은 엘리먼트들은 예를 들어 ISO 19885-3과 같은 연료공급 프로토콜 규격 각각에 의하여 특정될 수 있다.
| Element Name | Type | Semantics |
| action | actionType | Optional:Action that Vehicle requests to Dispenser. - start - stop - (Any custom actions defined by fuelling protocol) |
| reason | reasonType | Optional:Reason for why the "action" is requested. |
단계 S407에서 송수신되는 메시지 (예를 들어 FuelLoopRes 메시지)에 포함되는 엘리먼트 이름은 status, reason, result 등을 포함할 수 있으며, 아래 표 23에 의하여 도시될 수 있다. 아래 표 23의 내용에 도시되지 않은 엘리먼트들은 예를 들어 ISO 19885-3과 같은 연료공급 프로토콜 규격 각각에 의하여 특정될 수 있다.
| Element Name | Type | Semantics |
| status | statusType | Optional: - preparing - precooling - fuelling - standby - faulted - ramping-up - ramping-down - stopping - finished - stopped_error - stopped_requested - stopped_unknown - (Any custom status codes defined by fuelling protocol) |
| reason | reasonType | Optional:Reason for stopping when the fuelling is stopped abnormally |
| result | resultType | Result of processing the request message. 'OK' if successful. ‘FAILED' otherwise. See Table XYZ for the list of result codes. |
모빌리티가 FeulLoopReq 메시지를 전송할 때 디스펜서는 action을 수행할(conduct) 것이 기대될 수 있다. 모빌리티는 "action"을 원하는 action code로 설정하여 메시지를 전송할 수 있다. 이때 action code는 연료공급 프로토콜에 의하여 정의될 수 있다.
FuelLoopReq (예를 들어 "action"이 "start"로 설정된) 메시지를 수신한 후에, 디스펜서가 시작할 준비가 되면, 디스펜서는 협상된 방법을 이용하여 연료공급 프로시져를 시작하고 "result"가 "OK"로 설정된 FuelLoopRes 메시지를 응답할 수 있다.
FuelLoopReq (예를 들어 "action"이 "start"로 설정된) 메시지를 수신한 후에, 디스펜서가 시작할 준비가 되지 않으면, 디스펜서는 "result"가 "pending"으로 설정된 FuelLoopRes 메시지를 응답할 수 있다.
FuelLoopReq (예를 들어 "action"이 "stop"으로 설정된) 메시지를 수신한 후에, 디스펜서가 중지할 준비가 되면, 디스펜서는 연료공급 프로토콜에 정의된 대로 연료공급 프로시져를 중지하고 "result"가 "ONGOING"으로 설정된 FuelLoopRes 메시지를 응답할 수 있다.
FuelLoopReq (예를 들어 "action"이 "stop"으로 설정된) 메시지를 수신한 후에, 디스펜서가 중지할 준비가 되면, 디스펜서는 연료공급 프로시져를 즉각 (immediately) 중지하고 "result"가 "OK"로 설정된 FuelLoopRes 메시지를 응답할 수 있다.
FuelLoopReq 메시지를 수신한 후에, 디스펜서는 미리 정해진 시간 구간 (예를 들어 MessageSequenceTimeout) 내에 FuelLoopRes 메시지를 응답할 수 있다.
디스펜서는 수신된 FuelLoopReq 메시가 성공적으로 처리되었으면 "result"가 "OK"로 설정된 FuelLoopRes 메시지를 전송할 수 있다.
디스펜서는 수신된 FuelLoopReq 메시가 성공적으로 처리되지 않았으면 "result"가 "FAILED" 또는 다른 적절한 에러 코드로 설정된 FuelLoopRes 메시지를 전송할 수 있다.
디스펜서는, "status"가 표 23 또는 연료공급 프로토콜에 특정된 지원되는 코드 중 하나를 이용하여 설정된 FuelLoopRes 메시지를 전송할 수 있다.
디스펜서는, 연료공급이 완료되고(done) 의도된 연료공급 목표가 달성되면 "status"가 "finished"로 설정된 FuelLoopRes 메시지를 전송할 수 있다.
디스펜서는, 에러에 관련된 이유로 연료공급이 중지되면 "status"가 "stop_error"로 설정되고 "reason"이 적절한 reason code로 설정된 FuelLoopRes 메시지를 전송할 수 있다.
디스펜서는, 가장 최근의 FuelLoopReq 메시지의 "action"이 "stop"으로 설정되고 연료공급이 완전히 중지되지 않으면(has not been completely stopped), "status"가 "stopping"으로 설정된 FuelLoopRes 메시지를 전송할 수 있다.
디스펜서는, 가장 최근의 FuelLoopReq 메시지의 "action"이 "stop"으로 설정되고 연료공급이 완전히 중지되면(has been completely stopped), "status"가 "stopped_requested"로 설정된 FuelLoopRes 메시지를 전송할 수 있다.
모빌리티가 "action"이 "stop"으로 설정된 FuelLoopReq 메시지를 전송하였고 "status"가 "stopping"으로 설정된 FuelLoopRes 메시지를 수신하면, 모빌리티는 "action"이 "stop"으로 설정된 FuelLoopRes 메시지를 전송할 수 있다.
모빌리티가 FuelLoopRes 메시지를 수신하고 연료공급이 마무리되지 않았으면(not finished), 모빌리티는 미리 정해진 시간 구간 (예를 들어 MessageSequenceTimeout) 내에 FuelLoopReq 메시지를 전송할 수 있다.
안전에 치명적인 사건이 발생하면, 모빌리티 또는 디스펜서는 즉각 EmergencyReq 메시지를 전송할 수 있고, 연료공급 프로시져를 중지하며 통신을 폐쇄할 수 있다.
이상의 단계 S407과 관련된 실시예는 모빌리티가 각 단계의 시작을 요청하고 디스펜서가 응답하는 실시예를 중심으로 설명되었으나, 본 발명의 사상은 이에 한정되지 않는다. 본 발명의 대안적 실시예에서는 모빌리티 또는 디스펜서 어느 쪽이라도 먼저 단계 S407의 시작을 요청하는 메시지를 전송할 수 있고, 그 상대방은 단계 S407의 시작을 요청하는 메시지에 응답함으로써 단계 S407이 수행될 수 있다.
단계 S407에서 모빌리티 또는 디스펜서 중 일방이 전송하는 메시지는 수소의 연료공급 프로시져의 상태에 관한 모니터링 요청을 포함할 수 있다. 그 상대방이 응답하는 응답 메시지는 요청된 모니터링 대상 상태 정보를 포함할 수 있다.
이때 모니터링 요청의 대상이 될 수 있는 상태 및 관련 파라미터는 단계 (S405)에서 교환되는 파라미터 셋을 포함할 수 있다. 모니터링 요청의 대상이 될 수 있는 상태 및 관련 파라미터는 모빌리티 또는 디스펜서의 상태 및 파라미터를 포함할 수 있다. 모니터링 요청의 대상이 될 수 있는 상태 및 관련 파라미터는 수소 연료공급 프로시져에 의하여 변화하거나 유지되는 모빌리티 및/또는 디스펜서의 연료공급 상태 및/또는 관련 파라미터를 포함할 수 있다.
또한 모니터링 요청의 대상이 될 수 있는 상태는 디스펜서로부터 모빌리티로 연료공급이 진행되는 프로시져 자체의 상태 및/또는 정보를 포함할 수 있다. 예를 들어, 연료공급 프로시져가 진행 중(ongoing)인지, 일시 중지인지, 완전히 종료된(terminated) 상태인지, 및/또는 중지(stop)/종료(terminated)되었다면 에러에 의한 중지인지 또는 목표 달성에 의한 마침(finished)인지 등의 정보가 포함될 수 있다.
다시 도 4를 참조하여 안전 체크아웃 단계 (S408)의 목적, 선결조건, 및 후속조건은 다음의 표 24에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-8: "Safety Check-out" |
| Objectives | Vehicle and Dispenser confirms that all the necessary safety conditions are met before the nozzle can be detached from the receptacle |
| Short Description | After the fuelling has been finished, the vehicle and dispenser ensure that it is absolutely safe for the user or operator to unplug the nozzle from the vehicle. The vehicle and dispenser repeatedly report their condition until the safety checks are all confirmed. This use case may be omitted if the fuelling protocol does not require such safety checks at the end. |
| Pre-conditions | Fuelling is finished. |
| Post-conditions | It is safe to unplug the nozzle from the receptacle. |
연료공급이 마무리된 (finished) 후에 세션을 종료하고 (terminating the session) 모빌리티로부터 노즐을 언플러그하기 전에, 모빌리티 및 디스펜서가 안전 조건이 충족되는 지를 확실히 하기(ensure)할 수 있도록 안전 체크아웃 단계 (S408)가 수행될 수 있다. 이 단계 (S408)은 옵셔널이지만 정확하고 명시적인 방법으로 원하는 안전 레벨을 ensure하기 위하여 dedicated 안전 체크 아웃 프로시져가 연료공급 프로토콜에 의하여 정의될 것이 강하게 추천될 수 있다.
안전 체크아웃 스텝에서 이용되는 정보 교환은 안전 관련 사건이 발생할 때 진단 및 책임을 확인하기 위한 목적으로 이용될 수 있다.
모니터링 및 제어 단계 (S407) 및 관련 연료공급 프로시져가 성공적으로 마무리되면 (finished), 연료공급 프로토콜은 안전 체크아웃 단계 (S408)를 수행할 수 있음은 전술한 바와 같다.
안전 체크아웃이 수행되는 지 여부와 무관하게, ISO 19885-2를 준수하는 연료공급 프로토콜은 노즐을 언플러그하기 전에 모빌리티와 디스펜서 간에 컨펌될 안전 조건의 집합을 정의할 수 있다.
"Result"가 "OK"로, "status"가 "finished" 또는 "stopped" 접두사가 붙은 (prefixed) 값으로 설정된 FuelLoopRes 메시지를 수신한 후 연료공급 프로토콜이 안전 체크아웃을 지원하면, 모빌리티는 미리 정해진 시간 구간 내에 (예를 들어 MessageSequenceTimeout) 안전 체크아웃 단계 (S408)의 시작을 요청하는 메시지 (예를 들어 SafetyCheckOutReq) 메시지를 TLS 채널을 경유하여 디스펜서로 전송할 수 있다.
이때 TCP/TLS 채널의 연결이 해제되면 모빌리티는 디스펜서와 TCP/TLS 채널을 재수립할 수 있다. 재수립 과정은 SafetyCheckOutReq 메시지를 전송하기 전에 수신되는 NewSessionTicket 를 이용한 TLS-resumption 핸드셰이크에 의하여 개시될 수 있다.
대안적 실시예로서, 단계 (S408)의 시작을 요청하는 메시지는 모빌리티와 디스펜서 중 어느 일방에 의하여 상대방에게 전송될 수 있다. 이때 그 상대방은 단계 (S408)의 시작을 요청하는 메시지에 응답함으로써 단계 (S408)이 수행될 수 있다.
본 발명의 일 실시예에 따르면 안전 체크아웃 단계 (S408)에서 전송 및 수신되는 메시지는 예를 들어 ISO 19885-3 과 같은 규격에서 규정되는 각각의 연료공급 프로토콜의 내용에 기반하여 정의될 수 있다.
본 발명의 일 실시예에 따르면 안전 체크아웃 단계 (S408)에서 전송 및 수신되는 메시지는 요청 메시지를 처리한 결과 값을 result type으로 포함할 수 있다. 이때 result type으로 제공될 수 있는 결과 값은 예를 들어 성공한 경우 'OK', 실패한 경우 'FAILED'를 포함할 수 있고, 이외의 경우에 'PENDING'을 포함할 수 있다.
만일 모빌리티가 디스펜서로 SafetyCheckOutReq 메시지를 전송할 때 모빌리티가 모든 안전 조건이 충족됨을 컨펌한다면 그 메시지의 결과 값은 "OK"로 설정될 수 있다.
만일 모빌리티가 디스펜서로 SafetyCheckOutReq 메시지를 전송할 때 몇몇 안전 조건이 아직 충족되지 않았다면 그 메시지의 결과 값은 "PENDING"으로 설정될 수 있다.
디스펜서가 SafetyCheckOutReq 메시지를 수신한 후 MessageResponseTimeout 시간 구간 내에 디스펜서가 안전-체크 파라미터와 함께 SafetyCheckOutRes 메시지를 모빌리티로 응답할 수 있다.
만일 디스펜서가 모빌리티로 SafetyCheckOutRes 메시지를 전송할 때 모든 안전 조건이 충족됨을 디스펜서가 컨펌한다면 그 메시지의 결과 값은 "OK"로 설정될 수 있다.
만일 디스펜서가 모빌리티로 SafetyCheckOutRes 메시지를 전송할 때 몇몇 안전 조건이 아직 충족되지 않았다면 그 메시지의 결과 값은 "PENDING"으로 설정될 수 있다.
만일 result 값이 "PENDING"으로 세팅된 SafetyCheckOutRes 메시지를 수신한 경우, 모빌리티는 또 다른 SafetyCheckOutReq 메시지를 MessageResponseTimeout 시간 구간 내에 디스펜서로 전송할 수 있다.
만일 result 값이 "PENDING"으로 세팅된 SafetyCheckOutReq 메시지를 수신한 경우, 디스펜서는 또 다른 SafetyCheckOutReq 메시지를 MessageResponseTimeout 시간 구간 내에 모빌리티로 전송할 수 있다.
모빌리티 또는 디스펜서는 모든 안전 조건을 소정의 시간 (예를 들어 UCSafetyCheckOutTimeout) 내에 컨펌할 수 없을 때, "reason" 항목을 적절한 에러 코드로 설정한 ErrNotifReq 메시지를 전송할 수 있다.
대안적 실시예로서, 모빌리티 또는 디스펜서 중 어느 일방은 안전 체크아웃의 시작을 의미하는 요청 메시지를 상대방에게 전송할 수 있고, 그 상대방은 소정의 시간 구간 내에 안전 체크아웃의 요청 메시지에 대한 응답 메시지를 응답할 수 있다.
본 발명의 일 실시예에 따르면, 모니터링 및 제어 단계 (S407)에서 안전에 치명적이지 않은 에러가 발견되고 연료공급이 인터럽트되어 연료공급이 완료되기 전인 경우에, 연료공급 프로토콜은 모빌리티와 디스펜서 간 상호 호환되는 메커니즘 중 하위 호환성을 확보하는 폴백 메커니즘을 정의하고 폴백 메커니즘에 기반하여 연료공급을 재개하여 마무리할 수 있다.
이때 폴백 메커니즘은, 예를 들어 non-communication fueling method일 수 있다.
대안적 실시예로서, 모니터링 및 제어 단계 (S407)에서 안전에 치명적이지 않은 에러가 발견되고 연료공급이 인터럽트되어 연료공급이 완료되기 전인 경우에, 모빌리티와 디스펜서는 통신 프로토콜 협상 단계 (S403), 연료공급 프로토콜 협상 단계 (S404), 및 연료공급 파라미터 협상 단계 (S405) 중 일부 또는 전부를 다시 수행할 수 있다.
대안적 실시예로서, 모빌리티와 디스펜서는 디스커버리 및 페어링 단계 (S401)에서 얻어진 상호운용성 정보를 이용하여 통신 프로토콜 협상 단계 (S403), 연료공급 프로토콜 협상 단계 (S404), 및 연료공급 파라미터 협상 단계 (S405) 중 일부 또는 전부를 다시 수행하는 과정에서 교환되는 정보를 감축할 수 있다. 예를 들어 이미 협상 완료되고 선택된 프로토콜을 유지할 수 없는 통신 상태 또는 연료공급 상태가 확인된 경우에는, 이전에 선택되었던 프로토콜을 제외하고 통신 프로토콜 협상 단계 (S403), 연료공급 프로토콜 협상 단계 (S404), 및 연료공급 파라미터 협상 단계 (S405) 중 일부 또는 전부를 다시 수행할 수도 있다.
대안적 실시예로서, 모니터링 및 제어 단계 (S407)에서 안전에 치명적이지 않은 에러로서 통신 환경의 변화 및 연료공급 인프라의 변화가 감지되고, 연료공급이 인터럽트되어 연료공급이 완료되기 전인 경우에, 모빌리티와 디스펜서는 통신 프로토콜 협상 단계 (S403), 연료공급 프로토콜 협상 단계 (S404), 및 연료공급 파라미터 협상 단계 (S405) 중 일부 또는 전부를 다시 수행할 수 있다.
통신 환경의 변화는 통신 채널의 연결이 끊어지는 (disconnected) 경우를 포함할 수 있다.
통신 환경의 변화는 수신되는 데이터가 인식되지 못하는 경우를 포함할 수 있고, 수신되는 데이터가 수용불가능한 범위 (in an unacceptable range)인 경우를 포함할 수 있다.
통신 환경의 변화는 통신 성능의 품질이 요구되는 수준을 충족하지 못하는 경우를 포함할 수 있다.
통신 환경의 변화는 통신에 의하여 교환되는 데이터의 integrity 또는 precision이 요구되는 수준을 충족하지 못하는 경우를 포함할 수 있다.
연료공급 인프라의 변화는 디스펜서 측의 연료공급을 위한 제어 파라미터에 기반하여 모빌리티 측의 연료공급 파라미터가 변화하거나 상태를 유지하지만, 모빌리티 측의 연료공급 관련 파라미터의 변화 또는 상태 유지가 요구되는 수준을 충족하지 못하는 경우를 포함할 수 있다.
안전 체크-인 단계 (S406), 모니터링 및 제어 단계 (S407), 및 안전 체크-아웃 단계 (S408)에서 체크되거나 모니터링되는 안전 조건의 일부가 상기 표 19에서 도시되지만, 다음의 사항이 추가되거나 보완적으로 고려될 수 있다.
안전 조건은 수소 연료공급(연료공급)을 위한 모빌리티와 수소 연료공급이기 또는 디스펜서 양 측의 안전과 관련한 요소 및/또는 수소 연료공급을 개시하기 위한 양 측의 노즐, 리셉터클의 체결 상태 등을 포함할 수 있다.
수소 모빌리티 측에서는 수소 탱크 내 압력, 온도 등이 더 포함될 수 있다.
수소 충전소 측에서는 실린더 내 온도, 연료공급 압력, 주변 온도 등이 포함될 수 있다.
양 측의 연결 및 연료공급 경로 상의 안전 조건으로는 노즐-리셉터클 체결 상태 - 즉, 체결 여부, 체결 상태, 리키지(누출) 상태 등이 포함될 수 있다.
노즐-리셉터클 체결 상태는 수소 연료공급 프로시져를 수행하기에 적합한 및/또는 충분한 상태인지 여부에 대한 정보를 포함할 수 있다.
도 4의 대안적 실시예의 하나에서는, 안전 체크-인 단계 (S406)가 최소한의 상태 확인, 즉, 노즐-리셉터클 간 체결 여부, 체결 상태 등을 포함하는 안전 요소의 체크를 수행하는 경우에, 안전 체크-인 단계 (S406)가 연료공급 파라미터 협상 단계 (S405)에 앞서 실행될 수 있다.
도 4의 대안적 실시예의 하나에서는, 안전 체크-인 단계 (S406)가 최소한의 상태 확인, 즉, 노즐-리셉터클 간 체결 여부, 체결 상태 등을 포함하는 안전 요소의 체크를 수행하는 경우에, 안전 체크-인 단계 (S406)에서 체크되지 않은 나머지 안전 요소들이 연료공급 파라미터 협상 단계 (S405)에서 협상 및 체크될 수 있다.
도 4의 대안적 실시예의 하나에서는, 안전 체크-인 단계 (S406)가 최소한의 상태 확인, 즉, 노즐-리셉터클 간 체결 여부, 체결 상태 등을 포함하는 안전 요소의 체크를 수행하는 경우에, 안전 체크-인 단계 (S406)에서 체크되지 않은 나머지 안전 요소들이 모니터링 및 제어 단계 (S407)에서 모니터링 및 체크될 수 있다. 이때 안전 요소들은 연료공급 파라미터 협상 단계 (S405)에서 협상 및 체크되는 것과 무관하게 (또는 독립적으로) 모니터링 및 제어 단계 (S407)에서 모니터링 및 체크될 수 있다.
도 4의 대안적 실시예의 하나에서는, 안전 체크-인 단계 (S406)에서 체크되는 안전 요소를 포함한 복수의 안전 요소들이, 연료공급 파라미터 협상 단계 (S405)에서 협상 및 체크될 수 있다.
도 4의 대안적 실시예의 하나에서는, 안전 체크-인 단계 (S406)에서 체크되는 안전 요소를 포함한 복수의 안전 요소들이, 모니터링 및 제어 단계 (S407)에서 모니터링 및 체크될 수 있다. 이때 안전 요소들은 연료공급 파라미터 협상 단계 (S405)에서 협상 및 체크되는 것과 무관하게 (또는 독립적으로) 모니터링 및 제어 단계 (S407)에서 모니터링 및 체크될 수 있다.
도 4의 대안적 실시예의 하나에서는, 상호운용성 (interoperability) 및/또는 호환성 (compatibility)의 공유, 식별, 모니터링, 업데이트 및/또는 활용이 전 프로세스에 걸쳐 수행될 수 있다.
예를 들어, 발견 및 페어링 단계 (S401)에서 모빌리티와 디스펜서/충전소 간에 공유되는 상호운용성 관련 정보가 이후의 단계들 (S402~S411)에서 각 상황에 맞게 체크될 수 있고, 각 단계에서 가용한 상호운용성 정보로 업데이트되거나 다시 컨펌되는 실시예가 제시될 수 있다.
예를 들어, 단계 (S401)에서 파악된 모빌리티-디스펜서 간 상호운용 가용 프로토콜의 조합 (통신 프로토콜, 연료공급 프로토콜의 조합)들이 10개일 때, 이후의 단계에서 통신/시스템 오류, 통신/시스템 환경 변화, 또는 연료공급 환경의 변화 등에 의하여 10개의 프로토콜들 중 일부가 비호환되거나 사용 불가능하여, 가용 프로토콜 조합이 10개 미만으로 줄어들 수 있다. 이러한 상황을 각 Use Case에 대응하는 단계들 (S402~S411)에서 체크하고 그 결과로서 상호운용성 정보가 가용한 상호운용성 정보로 업데이트되며 업데이트된 상호운용성 정보에 기반하여 각 단계가 수행될 수 있다.
또한, 예를 들어, 도중의 단계에서 일시적으로 특정한 가용 상호운용 프로토콜 조합 A가 비호환되거나 사용 불가능한 것으로 파악되는 경우, 다른 상호운용 프로토콜로 대체되거나 fall back되어 해당 단계가 수행될 수 있다.
예를 들어 단계 S401 내지 S403에서 복수개의 가용 상호운용 프로토콜 조합들이 파악되고, 이들 중 선호도 및 우선 순위에 기반하여 상호운용 프로토콜 조합 A가 통신 프로토콜 협상의 결과로 선택된 이후, 단계 S404에서 통신/시스템 환경 변화, 오류, 및/또는 연료공급 환경의 변화로 상호운용 프로토콜 조합 A가 사용 불가능하다고 파악되는 경우, 선호도 및 우선 순위에 기반하여 선택되거나 fall back되는 다른 상호운용 프로토콜 조합 B가 연료공급 프로토콜 협상의 결과로 결정되어 단계 S404 및 그 이후의 단계가 수행될 수 있다.
유사한 다른 실시예로, 단계 S401 내지 S404에서 복수개의 가용 상호운용 프로토콜 조합들이 파악되고, 이들 중 선호도 및 우선 순위에 기반하여 상호운용 프로토콜 조합 A가 연료공급 프로토콜 협상의 결과로 선택된 이후, 단계 S405에서 통신/시스템 환경 변화, 오류, 및/또는 연료공급 환경의 변화로 상호운용 프로토콜 조합 A가 사용 불가능하다고 파악되는 경우, 선호도 및 우선 순위에 기반하여 선택되거나 fall back되는 다른 상호운용 프로토콜 조합 B를 통신 프로토콜 협상 및 연료공급 프로토콜 협상의 결과로 대체한 후, 단계 S405 및 그 이후의 단계가 수행될 수 있다.
유사한 다른 실시예로, 단계 S401 내지 S406에서 복수개의 가용 상호운용 프로토콜 조합들이 파악되고, 이들 중 선호도 및 우선 순위에 기반하여 상호운용 프로토콜 조합 A가 통신 프로토콜 협상, 연료공급 프로토콜 협상, 및 연료공급 파라미터 협상의 결과로 선택된 이후, 단계 S407에서 통신/시스템 환경 변화, 오류, 및/또는 연료공급 환경의 변화로 상호운용 프로토콜 조합 A가 사용 불가능하다고 파악되는 경우, 선호도 및 우선 순위에 기반하여 선택되거나 fall back되는 다른 상호운용 프로토콜 조합 B를 통신 프로토콜 협상, 연료공급 프로토콜 협상, 및 연료공급 파라미터 협상의 결과로 대체한 후, 단계 S407에 따르는 수소 연료공급 및 그 이후의 단계가 수행될 수 있다.
다른 대안적 실시예로, 예를 들어, 도중의 단계에서 일시적으로 특정한 가용 상호운용 프로토콜 조합 A가 사용 불가능하게 되고 다른 상호운용 프로토콜로 대체되거나 fall back되어 해당 단계가 수행된 이후, 후속 단계에서 다시 상호운용 프로토콜 조합 A가 사용 가능하게 되었을 때, 후속 단계에서 재협상 또는 미리 결정된 정책에 기반하여 상호운용 프로토콜 조합 A를 채택하여 후속 단계가 수행될 수도 있다.
예를 들어, 단계 S401 내지 S406에서 복수개의 가용 상호운용 프로토콜 조합들 중 선호도 및 우선 순위에 기반하여 상호운용 프로토콜 조합 A가 통신 프로토콜 협상, 연료공급 프로토콜 협상, 및 연료공급 파라미터 협상의 결과로 선택된 이후, 단계 S407에서 통신/시스템 환경 변화, 오류, 및/또는 연료공급 환경의 변화로 상호운용 프로토콜 조합 A가 사용 불가능하다고 파악된 이후 선택되거나 fall back된 다른 상호운용 프로토콜 조합 B에 기반하여 단계 S407에 따르는 수소 연료공급 및 그 이후의 단계가 수행되는 경우를 가정한다. 이때, 통신/시스템 환경 변화, 오류, 및/또는 연료공급 환경의 변화로 상호운용 프로토콜 조합 A가 다시 사용 가능하다고 판정되는 경우, 모빌리티와 디스펜서/충전소 간의 재협상 또는 미리 결정된 복원 프로세스에 의하여 상호운용 프로토콜 조합 A가 복원될 수 있다.
도 4의 대안적 실시예 중 하나에서는, 모빌리티와 디스펜서 간 상호운용 가용 프로토콜의 조합에서 기존에 선택된 최선호/최우선 프로토콜 조합이 비호환, 또는 사용 불가능하게 될 경우, 대체 가능한 차선호/차우선 프로토콜 조합을 결정할 때 기존의 최선호/최우선 프로토콜 조합과 동일한 통신 프로토콜을 유지한 채 연료공급 프로토콜이 변경된 조합을 탐색하거나, 연료공급 프로토콜을 유지한 채 통신 프로토콜이 변경된 조합을 탐색할 수 있다.
도 4의 대안적 실시예 중 하나에서는, 발견 및 페어링 (discovery and pairing) 프로세스 (단계 S401)에서 가용 프로토콜 조합을 탐색하여 제1 상호운용성 정보를 생성할 때, 통신 프로토콜과 연료공급 프로토콜이 각각 일치하는 경우를 우선하도록 우선 순위를 미리 결정할 수 있다. 예를 들어, 통신 프토토콜 A1과 연료공급 프로토콜 B1의 조합이 최우선/최선호 조합으로 결정된 경우, 통신 프토토콜 A1을 유지하면서 통신 프토토콜 A1과 공존할 수 있는 연료공급 프로토콜 B2, B3, ... 등의 조합을 최우선/최선호 조합에 대한 대체 조합으로서 높은 우선 순위를 부여하여 미리 지정할 수 있다. 또는 연료공급 프로토콜 B1을 유지하면서 연료공급 프로토콜 B1과 공존할 수 있는 통신 프로토콜 A2, A3, ... 등의 조합을 최우선/최선호 조합에 대한 대체 조합으로서 높은 우선 순위를 부여하여 미리 지정할 수 있다.
도 4의 대안적 실시예 중 하나에서는, 단계 S403 내지 S409가 수행되는 동안 최우선/최선호 상호운용 프로토콜 조합에 대한 업데이트 과정은 단계 S403 내지 S405 과정의 일부 또는 전부를 재협상함으로써 수행될 수 있다.
도 4의 대안적 실시예 중 하나에서는, 단계 S403 내지 S409가 수행되는 동안 최우선/최선호 상호운용 프로토콜 조합에 대한 업데이트 과정은 단계 S410 또는 S411 과정의 일부 또는 전부에 의하여 수행될 수 있다.
도 4의 대안적 실시예 중 하나에서는, 단계 S403 내지 S409가 수행되는 동안 최우선/최선호 상호운용 프로토콜 조합에 대한 업데이트 과정은 단계 S410 또는 S411 과정의 일부 또는 전부를 경유하되, 단계 S403 내지 S405 과정의 일부 또는 전부를 재협상함으로써 수행될 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 모빌리티가, 또는 디스펜서가, 또는 모빌리티와 디스펜서가 상호협력하여 단계 S401에서 최우선/최선호 상호운용 프로토콜 조합을 결정한 후, 단계 S403 내지 S409가 수행되는 동안 (단계 S410 및 S411의 도움을 받아) 최우선/최선호 상호운용 프로토콜 조합을 결정할 수 있다. 이때, 제1 통신 프로토콜 및 제1 연료공급 프로토콜에 기반하여 제1 프로세스 및 제1 프로세스의 후속 프로세스 중 적어도 하나를 수행하는 단계를 더 포함할 수 있다. 이때, 업데이트된 상호운용성 정보에 기반하여 결정되는 상호운용 통신 프로토콜 및 연료공급 프로토콜은 모빌리티 측의 기능을 일부 제한하거나, 모빌리티-디스펜서 간 통신 기능을 일부 제한할 수 있으므로, 경우에 따라서는 디스펜서가 단독으로, 또는 디스펜서가 주도적으로 수소 연료공급 프로세스 또는 그 후속 프로세스를 수행할 수도 있다. 즉, 상호운용성이 다운그레이드되거나 fall back되는 경우 디스펜서가 모빌리티에 비하여 더 많은 역할을 수행할 수 있다.
다시 도 4를 참조하면 연료공급(fueling)이 성공적으로 마무리되고(finished) 옵셔널하게 모든 안전 조건들이 컨펌되면 모빌리티와 디스펜서 종료 (termination) 유즈 케이스를 수행할 수 있다.
종료 (termination) 단계 (S409)의 목적, 선결조건, 및 후속조건은 다음의 표 25에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-9: "Termination" |
| Objectives | As the last step of fuelling, vehicle and dispenser finalizes the fuelling by exchanging information about fuelling results regarding fuelling performance and methods, and any reasons if the fuelling stopped unexpectedly. This use case also handles the house-keeping when a non-safety-critical problem occurred. |
| Short Description | After the fuelling has been finished and safety checks are confirmed, vehicle and dispenser exchanges some book-keeping information regarding the fuelling session.When a non-safety-critical problem occurred, this use case allows the vehicle and dispenser to exchange wrap-up information about the fuelling session before leaving. |
| Pre-conditions | The fuelling is finished and the nozzle is safe to unplug.Or a non-safety-critical problem occurred during any other use cases. |
| Post-conditions | Information about the fuelling session is stored and the fuelling session is completely finished. |
"Result"가 "DONE"으로 세팅된 SafetyCheckOutRes 메시지를 수신하거나 "status"가 "finished" 또는 "stopped" 접두사가 붙은 (prefixed) 값으로 설정된 FuelLoopRes 메시지를 수신한 후 안전 체크-아웃 유즈 케이스가 생략되면, 모빌리티는 종료 요청 메시지 (예를 들어 "TerminateReq) 메시지를 디스펜서로 전송할 수 있다.
종료 요청 메시지 (예를 들어 "TerminateReq) 메시지에 대한 상세한 사항은 각각의 연료공급 프로토콜 사양서에서 정의될 수 있다. 예를 들어 TerminateReq 메시지 내에 포함되어 모빌리티와 디스펜서 간 교환(exchange)되는 파라미터는 개별적인 연료공급 프로토콜마다 달리 정의될 수 있다.
TerminateReq 메시지에 포함되는 엘리먼트 이름은 tank_press, tank_temp, amount, soc, reason 등을 포함할 수 있으며, 아래 표 26에 의하여 도시될 수 있다. 아래 표 26의 내용에 도시되지 않은 엘리먼트들은 예를 들어 ISO 19885-3과 같은 연료공급 프로토콜 규격 각각에 의하여 특정될 수 있다.
| Element Name | Type | Semantics |
| tank_press | Final tank pressure | |
| tank_temp | Final tank temperature | |
| amount | Optional:The amount of hydrogen that is fuelled. | |
| soc | Optional:The final state of charge from vehicle's measurement | |
| reason | reasonType | Reason for termination from Vehicle's point of view. "finished" if dispenser indicated so. "stopped_user" if the user requested to stop. "complete" if the fuelling goal is achieved. "unknown" otherwise. Other reason code can be defined by fuelling protocol. |
모빌리티로부터 TerminateReq 메시지를 디스펜서가 수신하면, 디스펜서는 소정의 시간 구간 (예를 들어 MessageResponseTimeout) 내에 종료 응답 메시지 (예를 들어 TerminateRes)와 함께 응답할 수 있다.
종료 응답 메시지 (예를 들어 "TerminateRes) 메시지에 대한 상세한 사항은 각각의 연료공급 프로토콜 사양서에서 정의될 수 있다. 예를 들어 TerminateRes 메시지 내에 포함되어 모빌리티와 디스펜서 간 교환(exchange)되는 파라미터는 개별적인 연료공급 프로토콜마다 달리 정의될 수 있다.
TerminateRes 메시지에 포함되는 엘리먼트 이름은 aprr, duration, amount, soc, result 등을 포함할 수 있으며, 아래 표 27에 의하여 도시될 수 있다. 아래 표 27의 내용에 도시되지 않은 엘리먼트들은 예를 들어 ISO 19885-3과 같은 연료공급 프로토콜 규격 각각에 의하여 특정될 수 있다.
| Element Name | Type | Semantics |
| aprr | Optional:Average Pressure Ramping Rate | |
| duration | Optional:Duration of the fuelling | |
| amount | Optional:The amount of hydrogen that is fuelled. | |
| soc | Optional:The final state of charge from dispenser's measurement | |
| result | resultType |
대안적 실시예로서, 종료 (termination) 단계 (S409)의 시작을 요청하는 메시지는 모빌리티와 디스펜서 중 어느 일방에 의하여 상대방에게 전송될 수 있다. 이때 그 상대방은 종료 (termination) 단계 (S409)의 시작을 요청하는 메시지에 응답함으로써 종료 (termination) 단계 (S409)가 수행될 수 있다.
성공적인 연료공급을 위해서, 통신은 프로토콜에 따라서 기대되는 행동(behaviours)을 제공해야 한다. 연료공급 행동은 연료공급 프로토콜에 따라 수용 가능한 범위 내에 머물러야 한다. 그러나 실제로는 다양한 비정상적인 사건들이 발생할 수 있다. 어떤 에러는 마이너하고 쉽게 처리될 수 있다. 그러나 복구될 수 없고 연료공급을 속행할 수 없는 에러도 발생할 수 있다.
본 명세서에서 '오류' 또는 '에러'는 UC1 내지 UC9 (S401 내지 S409) 또는 수소 연료공급 (fueling) 중 발생하는 incidents 중에서, 해당 진행 중인 과정을 interrupt할 수 있는 경우를 지칭할 수 있다.
단계 (S410)에서는 non-safety critical error의 조건, 예시적인 에러 조건과 그 응답에 대해서 규정될 수 있다.
다시 도 4를 참조하면 에러 핸들링 (error handling) 단계 (S410)의 목적, 선결조건, 및 후속조건은 다음의 표 28에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-10: "Error Handling" |
| Objectives | This use case handles the situation when a non-safety-critical error occurred by terminating the fuelling procedure similar to normal terminations or abruptly stopping the communication. |
| Short Description | At any time during the fuelling, a non-safety critical error can occur. In this case, vehicle and dispenser stops the use case at the moment and then move to Termination use case (UC-9) to finish the fuelling procedure with both ends informed about the termination reasons. If further communication is not possible, the communication channel is dropped without further notification. |
| Pre-conditions | A non-safety critical error occurred and fuelling cannot be performed further. |
| Post-conditions | Vehicle and dispenser is informed about the error and stopped the fuelling. |
non-safety critical error 조건은 예를 들어 다음을 포함할 수 있다.
통신 에러로서, 1) 통신이 디스커넥트되는 경우, 2) 수신되는 데이터가 인코딩 또는 syntactic error로 인하여 인식될 수 없는 경우, 3) 수신된 데이터가 수용 불가능한 범위 (in an unacceptable range)인 경우를 포함할 수 있다.
시스템 에러로서, 디스펜서 또는 모빌리티가 그 자신의 critical한 system error를 검출하는 경우를 포함할 수 있다.
Qualitative error로서, 1) 통신 성능이 요구되는 레벨을 충족하는 데 실패한 경우, 2) data integrity 또는 precision의 품질이 요구되는 레벨을 충족하는 데 실패한 경우를 포함할 수 있다.
Non-safety-critical error가 발생하고 더 이상의 통신이 불가능할 때, 모빌리티와 디스펜서는 연료공급을 즉각 중지하고 안전한 단계를 취하며 (stops the fuelling immediately but taking safe steps), 통신을 중지하고 세션을 종료한다 (and stops the communication to end the session).
Non-safety-critical error가 발생하고 연료공급 완료와는 거리가 먼 상태에서 연료공급이 interrupted된 때, 연료공급 프로토콜은 예를 들어, non-communication fuelling method를 정의함으로써 fallback 메커니즘을 정의할 수 있다.
Non-safety-critical error가 모빌리티에 의하여 검출되고 통신 채널이 여전히 동작할 때, 모빌리티는 "action"이 "stop"으로 설정되고 reason"이 적절한 reason code로 설정된 TerminateReq 메시지를 전송할 수 있다.
Non-safety-critical error가 디스펜서에 의하여 검출되고 통신 채널이 여전히 동작할 때, 디스펜서는 먼저 연료공급을 즉각 중지하고, "action"이 "stop"으로 설정되고 reason"이 적절한 reason code로 설정된 TerminateReq 메시지를 전송할 수 있다.
연료공급 프로토콜은 프로토콜에 따른 에러 조건을 정의할 수 있고, 검출 기준 (detection criteria), 및 통지, 종료 절차 (termination procedure), 및 fallback 메커니즘을 포함하는 사전 처방된 응답 절차 (prescribe response procedures)를 제공할 수 있다.
다시 도 4를 참조하면 이머전시 핸들링 (emergency handling) 단계 (S411)의 목적, 선결조건, 및 후속조건은 다음의 표 29에 의하여 도시될 수 있다.
| Type | Description |
| Use case name | UC-11: "Emergency Handling" |
| Objectives | Define safety-critical conditions that warrant an urgent response and prescribe the response procedure to avoid safety-critical incidents. |
| Short Description | For safe fueling, communication must exhibit expected behaviors according to the protocol and the fueling behavior must stay within the safe range of the fueling protocol. However, it is possible that something goes wrong and the fueling system approaches a critical condition that the system must avoid at all cost. In this use case, we define safety-critical emergency conditions and possible reactions, and provide exemplary cases to consider. |
| Pre-conditions | A safety-critical problem occurred during any moment of fuelling and an urgent response is necessary. |
| Post-conditions | Safety-critical incidents are avoided or minimized, and the fuelling session has been stopped completely. |
연료공급 프로토콜은 프로토콜에 따른 이머전시 조건을 정의할 수 있고, 검출 기준 (detection criteria), 및 통지, 종료 절차 (termination procedure), 및 fallback 메커니즘을 포함하는, 위험한 상황에 진입을 회피할 수 있는 (to avoid entering detrimental situation by all means) 사전 처방된 응답 절차 (prescribe response procedures)를 제공할 수 있다.
모빌리티 또는 디스펜서가 safety-critical 상황을 검출한 때, 재난적 사건을 방지하기 위한 필요한 액션이 즉각 수행될 수 있다. 또한 가능하다면 사건에 대한 정보와 함께 EmergencyNotif 메시지가 전송될 수 있고, 통신을 폐쇄할 (close) 수 있다.
모빌리티 또는 디스펜서가 EmergencyNotif 메시지를 수신한 때, 메시지 내에 지시된 액션에 즉각 응답하고, 지체 없이 통신을 폐쇄할 수 있다 (close the communication without undue delay).
EmergencyNotif 메시지는 사용되는 통신 기술에 의존하는 TLS 또는 DTLS 메시지일 수 있다.
메시지의 criticality 및 전달의 효율 (efficiency of delivery)을 위하여 연료공급 프로토콜은 EmergencyNotif 메시지의 구조를 수정하는 것이 허락되지 않을 수 있다.
EmergencyNofit 메시지에 포함되는 엘리먼트 이름은 class, type, action 등을 포함할 수 있으며, 아래 표 30에 의하여 도시될 수 있다. 아래 표 30의 내용에 도시되지 않은 엘리먼트들은 예를 들어 ISO 19885-3과 같은 연료공급 프로토콜 규격 각각에 의하여 특정될 수 있다. 예를 들어 부가적인 emergency reason code 및 action code가 각각의 프로토콜 별로 특정될 수 있다.
| Element Name | Type | Semantics |
| class | unsignedByte | Optional:Severity class of this emergency, from 1 to 5 with decreasing severity. |
| type | unsignedByte | Emergency reason code by number defined in Table XYZ |
| action | unsignedByte | Optional:Pre-defined action code necessary or recommended to be performed by the receiving party |
도 16은 도 4의 대안적 실시예 중 하나를 도시하는 동작 흐름도이다.
도 16을 참조하면, 도 4의 단계 S401 내지 S409에 부가되는 S2010 및 S2020 간의 관계가 도시된다.
도 4, 및 도 16을 함께 참조하면, 본 발명의 일 실시예에 따른 수소 연료 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급(fueling)을 위한 통신 방법은, 모빌리티에 수소를 연료공급하는 디스펜서와 모빌리티 간 수소 연료공급을 준비하기 위한 통신 과정 (단계 S403 내지 S406, 또는 단계 S408 내지 S409) 중 또는 디스펜서가 모빌리티로 수소를 연료공급하는 과정 (단계 S407) 중 발생하는 에러를 검출하는 단계 (단계 S2010; 단계 S403 내지 S409의 일부로서 수행될 수도 있음); 검출된 에러에 대하여 통신 과정 (단계 S403 내지 S406, 또는 단계 S408 내지 S409) 또는 수소를 연료공급하는 과정 (단계 S407)의 중지 (stop) 여부를 결정하는 단계 (단계 S2020: 단계 S410 또는 S411의 일부로서 수행될 수도 있음); 및 검출된 에러에 기반하여 정의된 후속 과정을 수행하는 단계 (별도의 단계로 도시되지는 않음: 단계 S403 내지 S411의 일부로서 수행됨)를 포함할 수 있다.
이하의 실시예는 도 4의 단계 S401에서 모빌리티와 디스펜서 간에 공유되는 상호운용성 (interoperability) 또는 호환성 (compatibility) 정보에 기반하여 수행될 수 있다. 특히 단계 S403 내지 S405에서 통신 프로토콜, 연료공급 프로토콜, 및 연료공급 파라미터가 협상되고 결정되는 과정은 상호운용성 또는 호환성 정보의 범위 내에서 수행될 수 있다.
상호운용성 또는 호환성 정보는 단계 S401에서 식별되고 공유되지만, 이후의 과정에서 현재 상황에 맞게 다시 식별될 수 있고 업데이트된 상태로 공유될 수도 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 대하여 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 결정하는 단계 (단계 S2020: 단계 S410 또는 S411의 일부로서 수행될 수도 있음)는, 검출된 에러를 안전에 치명적인 에러 (safety-critical error) 또는 안전에 치명적이지 않은 에러 (non-safety-critical error) 중 어느 하나로 분류하는 단계를 포함할 수 있다.
이때 검출된 에러를 safety-critical error로 분류하는 과정은, 단계 S2020에 의하여 수행될 수도 있으며, 도 4의 단계 S411의 일부에 의하여 수행될 수 있고, 검출된 에러가 safety-critical error로 분류되면 후속 과정을 수행하는 단계는 별도의 단계(S403~S409)에 의하여 수행될 수 있고, 도 4의 단계 S411의 일부에 의하여 수행될 수도 있다. 이때 safety-critical error로 분류된 에러는 emergency로 취급될 수 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 대하여 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 결정하는 단계(S2020)는, 검출된 에러가 안전에 치명적이지 않은 에러인 경우에, 검출된 에러를 통신 에러 (communication error), 시스템 에러 (system error), 또는 정성적 에러 (Qualitative error) 중 어느 하나로 분류하는 단계 (단계 S410의 일부로서 수행됨)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 기반하여 정의된 후속 과정을 수행하는 단계는, 검출된 에러가 안전에 치명적인 에러인 경우에, 이머전시 핸들링 과정을 수행하는 단계 (S411)의 적어도 일부를 포함할 수 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 대하여 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 결정하는 단계(S2020)는, 검출된 에러가 안전에 치명적이지 않은 에러인 경우에 통신 과정 또는 수소를 연료공급하는 과정의 제1 연료공급 프로토콜을 폴백(fallback)된 제2 연료공급 프로토콜로 대체할 지 여부를 결정하는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 기반하여 정의된 후속 과정을 수행하는 단계는, 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 포함하는 메시지를 디스펜서로 전송하는 단계를 포함할 수 있다.
단계 S403 내지 S409가 수행되는 동안 발생하는 다양한 형태의 incidents가 모빌리티 또는 디스펜서에 의하여 검출될 수 있다(S2010). 이때 검출되는 incidents는 소정의 조건을 충족하면 error로 분류될 수 있다(S2010 및 S2020). 검출된 error는 non-safety-critical error이면 단계 S410의 error handling 과정 또는 별도의 후속 단계에서, safety-critical error이면 단계 S411의 emergency handling 과정에 의하여 처리될 수 있다.
본 발명의 일 실시예에서는 검출된 error를 non-safety-critical error로 분류할 지 safety-critical error (emergency)로 분류할 지의 기준이 단계 S403 내지 S409의 연료공급 프로토콜에 의하여 미리 정의되고, error가 검출되는 때의 각 단계 S403 내지 S409에 의하여 검출된 error가 분류될 수 있다.
본 발명의 대안적 실시예에서는, error는 검출된 후 단계 S410 및/또는 S411의 과정으로 전달되고, 단계 S410 및/또는 S411 각각은 검출된 error가 non-safety-critical error인지 또는 safety-critical error (emergency)인지를 분류할 수 있다. 즉, 단계 S410은 error가 non-safety-critical error인지 여부 및 non-safety-critical error이면 communication error, system error, 또는 qualitative error 중 어느 것인지를 분류할 수 있다. 단계 S411은 error가 safety-critical error인지 여부를 분류할 수 있다.
단계 S410은 검출된 error를 분류하고, 분류 결과 또는 error의 상태에 기반하여 연료공급 과정을 중지할 지 여부를 결정할 수 있다. 만일 연료공급 과정을 중지하지 않고 (업데이트된 상호운용성 또는 호환성 정보에 기반하여) fallback 연료공급 프로토콜에 의하여 연료공급 과정을 계속 수행하도록 결정되면, 단계 S410의 결과로서 다시 단계 S403 내지 S409 중 연료공급 과정의 계속 수행에 필요한 단계가 수행될 수 있다.
또한 단계 S410 또는 S411에서, error가 발생한 요인이 제거되고 정상적인 상태로 복원되었을 때, 모빌리티 또는 디스펜서는 단독으로 또는 상호 협력하여 error가 발생하기 전에 수행 중이던 단계 S403 내지 S409 중 어느 하나로, 또는 그 다음 단계로 복귀하여 수소 연료공급 과정 및 통신 과정을 계속 수행할 수도 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급(fueling)을 위한 통신 방법은, 디스펜서와 모빌리티 간 수소 연료공급을 준비하기 위한 통신 과정 (단계 S403 내지 S406, 또는 단계 S408 내지 S409) 중 또는 디스펜서가 모빌리티로 수소를 연료공급하는 과정 (단계 S407) 중 발생하는 에러를 검출하는 단계 (단계 S2010; 단계 S403 내지 S409의 일부로서 수행될 수도 있음); 검출된 에러에 대하여 통신 과정 (단계 S403 내지 S406, 또는 단계 S408 내지 S409) 또는 수소를 연료공급하는 과정 (단계 S407)의 중지 (stop) 여부를 결정하는 단계 (단계 S2020: 단계 S410 또는 S411의 일부로서 수행될 수도 있음); 및 검출된 에러에 기반하여 정의된 후속 과정을 수행하는 단계 (단계 S403 내지 S411의 일부로서 수행됨)를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 대하여 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 결정하는 단계 (단계 S2020: 단계 S410 또는 S411의 일부로서 수행될 수도 있음)는, 검출된 에러를 안전에 치명적인 에러 (safety-critical error) 또는 안전에 치명적이지 않은 에러 (non-safety-critical error) 중 어느 하나로 분류하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 대하여 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 결정하는 단계(S2020)는, 검출된 에러가 안전에 치명적이지 않은 에러인 경우에, 검출된 에러를 통신 에러 (communication error), 시스템 에러 (system error), 또는 정성적 에러 (Qualitative error) 중 어느 하나로 분류하는 단계 (단계 S410의 일부로서 수행될 수도 있음)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 기반하여 정의된 후속 과정을 수행하는 단계는, 검출된 에러가 안전에 치명적인 에러인 경우에, 이머전시 핸들링 과정을 수행하는 단계 (S411)의 적어도 일부를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 대하여 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 결정하는 단계(S2020)는, 검출된 에러가 안전에 치명적이지 않은 에러인 경우에 통신 과정 또는 수소를 연료공급하는 과정의 제1 연료공급 프로토콜을 폴백(fallback)된 제2 연료공급 프로토콜로 대체할 지 여부를 결정하는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 기반하여 정의된 후속 과정을 수행하는 단계는, 통신 과정 또는 수소를 연료공급하는 과정의 제1 연료공급 프로토콜이 제2 연료공급 프로토콜로 대체되는 경우에, 디스펜서가 제2 연료공급 프로토콜에 기반하여 수소를 연료공급하는 과정을 수행하는 단계를 포함할 수 있다.
통신 에러인 경우에 디스펜서 측에서 제1 연료공급 프로토콜 또는 미리 정의된 규칙에 따른 pre-defined fallback을 적용하여 제2 연료공급 프로토콜을 선택하고, 제2 연료공급 프로토콜에 기반하여 수소를 연료공급할 수 있다.
통신 에러인 경우에 모빌리티 또는 디스펜서는, 세션을 중지해야 하는 경우에 세션을 중지할 수 있다.
시스템 에러인 경우에 모빌리티 또는 디스펜서는 세션을 중지해야 하는 경우에 세션을 중지할 수 있다. 이때 모빌리티 또는 디스펜서는, 검출된 에러에 기반하여 세션을 중지하고 상대방에게 stop action 및 그 이유에 대응하는 reason code를 포함하는 메시지를 전송할 수 있다.
대안적 실시예에서는 정성적 에러 (qualitative error)인 경우에 모빌리티 및 디스펜서 간 업데이트된 상호운용성 또는 호환성 정보에 기반하여 제한된 통신 프로토콜 또는 통신 환경에 기반한 fallback 연료공급 프로토콜을 선택하고, 선택된 연료공급 프로토콜에 기반하여 수소를 연료공급할 수 있다.
대안적 실시예에서는 정성적 에러 (qualitative error)인 경우에 모빌리티 및 디스펜서 간 통신 프로토콜을 유지하면서 다른 연료공급 프로토콜을 선택할 수 있다. 또 다른 대안적 실시예에서는 모빌리티 및 디스펜서 간 연료공급 프로토콜을 유지하면서 다른 통신 프로토콜을 선택할 수 있다.
대안적 실시예에서는 정성적 에러인 경우에 모빌리티 및 디스펜서가 새로운 통신 프로토콜 및 연료공급 프로토콜 조합을 선택하기 위하여 재협상을 수행할 수 있다. 이때 재협상을 위하여 단계 S403 내지 S405의 일부가 다시 수행될 수도 있고, 단계 S410 내에서 재협상이 수행될 수도 있다.
대안적 실시예에서는 emergency인 경우에도 통신이 살아있는 경우 통신을 최소화하고 후속 과정을 수행할 수 있다. 모빌리티 또는 디스펜서가 통신 프로토콜 및 연료공급 프로토콜을 fallback할 수 있다.
대안적 실시예에서는 emergency인 경우에는 연료공급 및 통신의 중지를 최우선으로 수행할 수도 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러에 기반하여 정의된 후속 과정을 수행하는 단계는, 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 포함하는 메시지를 모빌리티로 전송하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 통신 과정 또는 수소를 연료공급하는 과정의 중지 여부를 포함하는 메시지가 통신 과정 또는 수소를 연료공급하는 과정의 중지를 포함하는 경우에, 메시지는 중지 (stop)의 적절한 이유 (appropriate reason)에 대응하는 코드 (reason code)를 더 포함할 수 있다.
본 발명의 대안적 실시예 중 하나에 따른 모빌리티 및/또는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 검출된 에러와 관련하여 가용한 (available) 통신 또는 연료공급 과정의 UCDC 레벨에 기반하여 에러의 심각도 (criticality)가 판정될 수 있다. 또한 UCDC 레벨에 기반하여 연료공급의 중지 여부가 결정될 수 있다. 이때 UCDC 레벨에 기반하여 에러의 심각도 및/또는 연료공급의 중지 여부가 결정되는 과정은 에러가 정성적 에러일 경우에 적용될 수 있다. 다만 이러한 실시예에 의하여 본 발명의 범위가 국한되는 것은 아니다.
도 4 및 도 16의 실시예에서는 단계 S2010, S2020, S410, 및/또는 S411이 단계 S403 내지 S409와 관련되는 실시예가 도시되었다. 본 발명의 대안적 실시예 중 하나에서는, 단계 S2010 및 S2020는 단계 S401 내지 S409, 또는 연료공급 과정 중 발생하는 모든 incidents를 검출하고 error인지 여부를 판정하며 error를 분류할 수 있다. 또한 본 발명의 대안적 실시예에서는 단계 S2010, S2020, 및 별도의 후속 단계의 일부로서 단계 S410 및 S411을 경유한 후에, 후속 과정을 수행하거나 error가 해소된 경우에 기존 과정 및/또는 다음 과정을 수행하기 위하여 단계 S401 내지 S409 중 어느 하나로 복귀할 수 있다.
즉, 단계 S2010 및 S2020는 단계 S401 - UC1: 디스커버리 및 페어링, 단계 S402 - UC2: 통신 보안, 단계 S403 - UC3: 통신 프로토콜 협상, 단계 S404 - UC4: 연료공급 프로토콜 협상, 단계 S405 - UC5: 연료공급 파라미터 협상, 단계 S406 - UC6: 안전 체크-인, 단계 S407 - UC7: 모니터링 및 제어, 단계 S408 - UC8: 안전 체크-아웃, 단계 S409 - UC9: Termination 또는 이와 병행되는 수소 연료공급 과정 등에서 발생하는 incidents를 검출, incidents가 error인지 판정, error를 검출, 또는 error를 분류할 수 있다.
또한, error가 분류되고 그에 대한 handling이 S410 또는 S411에서 수행된 이후에 단계 S401 내지 S409 또는 그와 병행되는 수소 연료공급 과정 등으로 복귀할 수 있다.
또한, error가 처리되고 error가 해소된 이후에 error 발생 이전에 수행되던 과정 또는 그 다음 단계의 수행을 위하여 단계 S401 내지 S409 또는 그와 병행되는 수소 연료공급 과정 등으로 복귀할 수 있다.
대안적 실시예 중 하나에서, 에러가 안전에 치명적인 지 여부를 판정하는 기준으로서, 수소 연료공급 전/중/후에 발생할 수 있는 incidents로서 시설 및/또는 인명에 피해를 주거나, 화재, 폭발, 누출 등을 유발할 수 있는 지가 고려될 수 있다.
안전에 치명적인 에러 (safety-critical error)의 경우 통신 및 연료공급이 중지 및/또는 종료되는 경우가 있을 수 있다. 대안적 실시예에서는 안전에 치명적인 에러인 경우에도 통신이 확보되거나 연료공급이 가능한 경우, 또는 연료공급이 계속 수행되어야 하는 경우 (위험 현장으로부터 탈출, 환자의 이송 등의 이유)에 연료공급이 계속 수행될 수 있다.
안전에 치명적이지 않은 에러 (non-safety-critical error)의 경우 에러의 심각도 (criticality / severity), 가용한 통신 환경, 가용한 연료공급 프로토콜, UCDC 레벨, 통신 또는 연료공급의 필요성 등에 기반하여 통신 또는 연료공급을 중지할 수도 있고, 계속 수행할 수도 있다.
이상의 실시예에서 상호운용성의 상시 모니터링, 그에 따른 상호운용성 정보 업데이트, 및/또는 통신/연료공급 프로토콜 조합의 업데이트 과정은 모빌리티 또는 디스펜서 중 어느 한 쪽에 의하여 수행되는 실시예를 중심으로 개시되었으나, 이들 과정의 세부적인 과정은 모빌리티 또는 디스펜서 어느 한 쪽에 의하여 수행될 수 있음은 물론, 상호 협력에 의하여 수행될 수 있다. 또한 본 발명의 대안적 실시예에서는 상호운용성의 상시 모니터링, 그에 따른 상호운용성 정보 업데이트, 및/또는 통신/연료공급 프로토콜 조합의 업데이트 과정의 일부는 모빌리티가, 또 다른 일부는 디스펜서가 주도적으로 수행할 수도 있다.
또한 에러의 검출은 모빌리티 또는 디스펜서 중 어느 한 쪽에 의하여 수행될 수 있으며, 에러를 검출한 엔티티는 상대방에 에러의 검출, 검출된 에러, 에러에 기반한 통신 및 연료공급의 중지, 또는 중지의 이유에 대응하는 reason code 등을 포함하는 메시지를 전송할 수 있다.
도 17은 본 발명의 다른 일 실시예에 따른 수소 연료공급을 위한 통신 방법을 도시하는 동작 흐름도이다.
도 16과 도 17을 함께 참조하면, 본 발명의 일 실시예에 따른 수소 연료공급(fueling)을 위한 통신 방법은, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되며, 모빌리티에 수소를 연료공급하는 디스펜서를 발견하고, 모빌리티와 디스펜서 간 페어링 정보를 공유하고, 모빌리티와 디스펜서 간 페어링을 수행하는 단계(S2100); 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 협상하는 단계(S2200); 및 연료공급 프로토콜에 기반하여 수행되는, 디스펜서가 모빌리티로 수소를 연료공급하는 과정의 모니터링 및 제어를 위하여 요구되는 정보를 디스펜서로 전송하는 단계(S2300)를 포함할 수 있다. 이때 페어링을 수행하는 단계(S2100)에서 수행되는 동작은 도 4 및 도 16의 단계 S401의 동작의 일부 또는 전부를 포함할 수 있다. 모니터링 및 제어를 위하여 수행되는 동작은, 도 4 및 도 16의 단계 S407의 동작의 일부 또는 전부를 포함할 수 있다. 단계 S407에서 디스펜서가 수행할 수 있는 동작 및/또는 단계 S407에서 모빌리티가 수행할 수 있는 동작이 단계 S2300에서 수행될 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 페어링을 수행하는 단계(S2100) 이후에, 통신 프로토콜 또는 연료공급 프로토콜을 협상하기 위하여 모빌리티와 디스펜서 간 보안 채널(secure channel)을 설립(establish)하는 단계(도 4와 도 16의 단계 S402를 참조)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200) 이후에, 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이전에 모빌리티와 디스펜서 간 제1 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-인 단계(도 4 및 도 16의 단계 S406을 참조); 및 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이후 및 모빌리티에서 노즐이 분리되기 전에, 모빌리티와 디스펜서 간 제2 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-아웃 단계(도 4 및 도 16의 단계 S408을 참조)를 더 포함할 수 있다.
본 발명의 대안적 실시예에 따르면, 제1 필요 안전 조건 및/또는 제2 필요 안전 조건은 노즐과 리셉터클 간의 체결 상태, 체결 부위의 기밀 상태, 모빌리티 또는 디스펜서 측의 수소 저장 탱크의 온도, 압력, 잔존 충전량(SoC) 등을 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200) 또는 모니터링 및 제어를 위하여 요구되는 정보를 디스펜서로 전송하는 단계(S2300)가 수행되는 동안 발생하는 안전에 치명적이지 않은 에러(non-safety-critical error)를 검출하고 핸들링하는 단계(도 16의 단계 S2010, S410을 참조); 및 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200) 또는 모니터링 및 제어를 위하여 요구되는 정보를 디스펜서로 전송하는 단계(S2300)가 수행되는 동안 발생하는, 디스펜서 및 모빌리티 간 상호 동작을 중지해야 하는 긴급상황을 검출하고 핸들링하는 단계(도 16의 단계 S2020 및 S411을 참조)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200)는, 모빌리티와 디스펜서 간 통신 프로토콜을 협상하는 단계(도 4 및 도 16의 단계 S403을 참조); 통신 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 프로토콜을 협상하는 단계(도 4 및 도 16의 단계 S404를 참조); 및 연료공급 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 파라미터를 협상하는 단계(도 4 및 도 16의 단계 S405를 참조)를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200)에서, 디스펜서 및 모빌리티 간에 전송되는 통신 프로토콜 또는 연료공급 프로토콜의 정보는 프로토콜 이름, 인덱스, 버전, 우선순위 또는 선호도를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법에서, 페어링을 수행하는 단계(S2100)에서 모빌리티와 디스펜서 간 공유되는 페어링 정보는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법에서, 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보는, 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200), 또는 모니터링 및 제어를 위하여 요구되는 정보를 디스펜서로 전송하는 단계(S2300)가 수행될 때의 상태 정보에 기반하여 업데이트되고, 업데이트된 상호운용성 또는 호환성 관련 정보에 기반하여 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200), 또는 모니터링 및 제어를 위하여 요구되는 정보를 디스펜서로 전송하는 단계(S2300)가 수행될 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200)가 수행되는 동안 발생하는 안전에 치명적이지 않은 에러(non-safety-critical error)가 검출되면(도 16의 S2010 및 S410), 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200)의 일부 또는 전부를 다시 수행하는 단계를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 모니터링 및 제어를 위하여 요구되는 정보를 디스펜서로 전송하는 단계(S407)에서, 연료공급 프로토콜이 모빌리티와 디스펜서 간 양방향 통신을 통신 프로토콜로서 허용하는 지 여부에 기반하여, 모빌리티가 디스펜서로 전송하는 정보가 결정될 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법은, 모빌리티를 발견하고, 모빌리티와 디스펜서 간 페어링 정보를 공유하고, 모빌리티와 디스펜서 간 페어링을 수행하는 단계(S2100); 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 협상하는 단계(S2200); 및 연료공급 프로토콜에 기반하여 수행되는, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 모니터링하고 제어하는 단계(S2300)를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링을 수행하는 단계(S2100) 이후에, 통신 프로토콜 또는 연료공급 프로토콜을 협상하기 위하여 모빌리티와 디스펜서 간 보안 채널(secure channel)을 설립(establish)하는 단계(S402)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200) 이후에, 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이전에 모빌리티와 디스펜서 간 제1 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-인 단계(S406); 및 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이후 및 모빌리티에서 노즐이 분리되기 전에, 모빌리티와 디스펜서 간 제2 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-아웃 단계(S408)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200) 또는 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 모니터링하게 제어하는 단계(S2300, S407)가 수행되는 동안 발생하는 안전에 치명적이지 않은 에러(non-safety-critical error)를 검출하고 핸들링하는 단계(S2010 및 S410); 및 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계 또는 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 모니터링하게 제어하는 단계(S2300, S407)가 수행되는 동안 발생하는, 디스펜서 및 모빌리티 간 상호 동작을 중지해야 하는 긴급상황을 검출하고 핸들링하는 단계(S2020 및 S411)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법의 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S2200)는, 모빌리티와 디스펜서 간 통신 프로토콜을 협상하는 단계(S403); 통신 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 프로토콜을 협상하는 단계(S404); 및 연료공급 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 파라미터를 협상하는 단계(S405)를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 도 4의 단계 S401, 도 16의 단계 S401, 및 도 17의 단계 S2100의 일부로서, 페어링 정보에 기반하여 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 서로 간에 체크하는 단계를 포함할 수 있다.
도 17에 도시된 방법은, 모빌리티에 의하여 또는 디스펜서에 의하여 수행될 수도 있고, 모빌리티와 디스펜서 간의 상호 협력에 의하여 수행될 수도 있다.
도 17의 실시예에서 모빌리티와 통신하는 엔티티가 디스펜서로 기재되었으나, 디스펜서 또는 스테이션의 통신 장치가 단독으로 또는 협력하여 모빌리티와 통신할 수 있다.
예를 들어 스테이션의 복수개의 무선랜 AP (Access Point)가 배치되며, 이들 중 어떤 AP는 디스펜서에 할당되지만 어떤 AP는 디스펜서에 직접적으로 할당되지는 않은 채로 모빌리티와의 통신에 참여할 수 있다.
단계 S2100는 모빌리티와 디스펜서 (또는 스테이션) 간에 무선 통신을 이용하여 페어링에 관한 정보를 공유하고, 이를 이용하여 서로 상대방의 존재를 발견하는 과정을 포함할 수 있다.
단계 S2100는 모빌리티와 디스펜서 간에 적확한 페어링 여부를 확인하는 과정일 수 있다. 이때 페어링 체크를 수행하는 엔티티는 모빌리티와 디스펜서(스테이션) 양쪽 모두일 수도 있고, 어느 한 쪽일 수도 있다.
단계 S2100 및 이후 페어링 정보에 기반하여 (페어링 정보 내의 상호운용성 및 호환성 정보에 기반하여) 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜에 관련되는 후속 과정을 디스펜서와 모빌리티가 적어도 하나 이상의 메시지를 송수신함으로써 수행할 수 있다. 이 과정은 예를 들어, 도 17의 단계 S2200, 도 4 및/또는 도 16의 단계 S403 내지 S405에 대응할 수 있다.
본 발명의 일 실시예에 따르면, 수소 연료 모빌리티와 디스펜서/스테이션이 상대방을 발견하고 호환성을 체크하며 적확한 페어링 여부를 검증함으로써, 수소 연료공급 프로세스의 시작을 지원하고 수소 연료공급 프로세스 시작까지의 과정을 단축할 수 있다.
또한, 본 발명의 일 실시예에 따르면, 디스커버리 및 페어링 과정에서 VSE (Vendor-Specific Element)와 같은 규격화된 데이터 필드를 이용하여 수소 연료 모빌리티와 디스펜서/스테이션 각각이 가지고 있는 기능과 통신 프로토콜 및/또는 연료공급 프로토콜을 상대방에게 제공할 수 있다.
이때 본 발명의 일 실시예에 따르면, 후속 과정에서 요구되는 상호운용성과 호환성 등의 정보를 상대방과 공유하고 수소 연료공급 프로세스 시작까지의 과정을 단축할 수 있다.
디스펜서를 발견하는 단계(S2100)에서, 디스펜서와 모빌리티 간에 송수신되는 메시지는 VSE (Vendor Specific Element) 데이터 필드를 포함할 수 있고, VSE 데이터 필드는, 페어링에 관한 정보의 적어도 일부를 포함할 수 있다.
VSE 데이터 필드는, 페어링에 관한 정보의 적어도 일부로서, 디스펜서 또는 모빌리티에서 지원되는 규격; 규격의 버전 (version); 디스펜서 또는 모빌리티에서 지원되는 연료공급 프로토콜; 디스펜서 또는 모빌리티에서 지원되는 통신 프로토콜; 또는 디스펜서 또는 모빌리티의 페어링을 위한 식별 정보를 포함할 수 있다.
디스펜서 또는 모빌리티에서 지원되는 규격은 예를 들어 ISO 19885와 같은 알려진 표준 규격일 수 있고, 또는 특정한 표준 규격의 지원 여부를 포함할 수도 있다. 규격의 버전은, 특정한 표준 규격의 버전을 지칭할 수 있다.
예를 들어 VSE는 모빌리티 또는 디스펜서가 ISO 19885 디바이스임을 지칭할 수 있고, 지원되는 통신/연료공급 프로토콜 리스트를 포함하여 호환성 정보를 포함할 수 있다.
또한 VSE 데이터 필드에 페어링을 위한 식별자 (ID, identifier) 정보가 부가될 수 있다. 페어링 ID는 페어링 단계(S2100)에서 모빌리티와 디스펜서 간 페어링을 위하여 이용될 수 있다.
VSE (Vendor Specific Element) 데이터 필드는 비콘, 프로브 요청/응답, 연관 요청 (Assoc Req), 재연관 요청 (Reassoc Req) 메시지 등에 부가될 수 있다.
단계 S2100 및 S2200에서는 무선 랜 (WLAN)과 같은 무선 통신 기술이 이용될 수 있다. 모빌리티와 디스펜서/스테이션 간에는 VSE (Vendor Specific Element) 데이터 필드를 이용하여 페어링 정보 및/또는 상호운용성/호환성 정보가 공유될 수 있다.
페어링 정보는 디스펜서의 위치 또는 정밀 포지셔닝 정보를 포함할 수 있다. 한편 부가적인 페어링 정보는 모빌리티와 디스펜서 간의 연료공급 케이블 (fueling cable)을 경유하여 수행될 수도 있다.
페어링 정보는 케이블, NFC, RFID, Barcode 등 무선 랜이 아닌 추가적인 통신 기술을 이용하여 교환될 수 있다. 이때 근거리 통신 기술은 정밀한 위치 측정 및 포지셔닝을 지원할 수 있다.
페어링을 체크/검증하는 과정은 one-way 페어링으로 수행될 수 있다. 이때 one-way 페어링의 일 실시예에서는 모빌리티가 디스펜서를 체크할 수 있다. 실시예에 따라서는 디스펜서가 모빌리티를 체크할 수도 있고, 양쪽 모두가 상대방을 체크할 수도 있다.
상기의 실시예에서 메시지가 통신 프로토콜 리스트를 포함하는 실시예가 도시되었으나, 본 발명의 다른 실시예에서는 메시지가 연료공급 프로토콜 리스트 또는 연료공급 파라미터를 포함할 수 있다. 또한 통신 프로토콜 리스트는 지원되는 연료공급 프로토콜 리스트와 함께 연관되어 교환될 수 있다.
이때 제1 메시지는 적어도 하나 이상의 무선 통신 엔티티(2310, 2320, 2330)에 의하여 무선 통신 기술에 기반하여 전송되는 메시지를 의미할 수 있다. 예를 들어 블루투스 기반 통신의 경우 비콘(beacon) 메시지의 형식으로 전송될 수 있고, 무선 랜 기반 통신의 경우 무선 랜 통신에서 허용되는 메시지의 형식으로 전송될 수 있다. 이때 본 발명의 실시예들에서는 제1 메시지가 의존하는 통신 기술은 특정한 통신 매체로 한정되지 아니한다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티의 통신 장치에 의하여 수행되는 수소 연료공급(fueling)을 위한 통신 방법에 있어서, 디스펜서와 모빌리티 간 상호운용성 또는 호환성 관련 정보는, 디스펜서와 모빌리티 간 양방향 통신이 지원되는 지 여부; 디스펜서와 모빌리티 간 양방향 통신을 통한 측정 데이터의 공유 기능이 지원되는 지 여부; 측정 데이터가 디스펜서가 모빌리티로 수소를 연료공급하는 과정의 제어 또는 관리에 이용될 수 있는 지 여부; 또는 디스펜서가 모빌리티로 수소를 연료공급하는 과정 도중 디스펜서와 모빌리티 간 통신 환경의 변화에 기반하여 통신 프로토콜 또는 연료공급 프로토콜의 폴백(fallback) 또는 대안 프로토콜이 결정될 수 있는 지 여부를 포함할 수 있다.
도 17의 대안적 실시예 중 하나에서는, 디스펜서 또는 모빌리티에서 지원되는 통신 프로토콜 리스트에 식별되는 아이템으로서, 디스펜서 또는 모빌리티 간에 양방향 통신이 지원되는 지 여부에 따라서 디스펜서 또는 모빌리티에서 공통적으로 지원되는 연료공급 프로토콜의 범위가 가이드될 수 있다.
도 17의 대안적 실시예 중 하나에서는, 양방향 통신을 이용하여 디스펜서와 모빌리티 간 실시간 측정 데이터(디스펜서 측 또는 모빌리티 측의 실측 데이터)의 공유 기능이 지원되는 지 여부가 상호운용성/호환성 정보로서 공유될 수 있다.
도 17의 대안적 실시예 중 하나에서는, 실시간 측정 데이터를 디스펜서로부터 모빌리티로 수소가 연료공급되는 과정을 위한 연료공급 프로토콜의 제어 또는 관리 과정에 활용할 수 있는 지 여부가 상호운용성/호환성 정보로서 공유될 수 있다.
도 17의 대안적 실시예 중 하나에서는, 실시간 측정 데이터에 기반하여 UC10 또는 UC11과 같은 상황의 발생 여부가 모빌리티와 디스펜서 간에 공유될 수 있다. 이때 양방향 통신 지원 여부, 실시간 측정 데이터의 공유 가능 여부, 실시간 측정 데이터의 활용 가능 여부 등에 기반하여 상호운용성/호환성 정보의 fallback 여부가 결정될 수 있다. 이때 fallback 외에도 대안적 통신/연료공급 프로토콜 또는 차선의 통신/연료공급 프로토콜이 선택되고 선택된 프로토콜에 기반하여 수소 연료공급 프로세스가 수행되거나, 상황에 따라서는 종료될 수 있다.
본 발명의 일 실시예에서는, 수소 연료공급 프로토콜의 구체적인 사항을 페어링 및 디스커버리 단계(S401)에서 사전에 탐색함으로써, 이후의 프로토콜 협상 단계(S403 내지 S405) 등 합의 과정을 지원하고, 부차적으로 협상 과정을 단축할 수 있다.
본 발명의 일 실시예에서는, UC10 또는 UC11에 해당하는 상황이 발생했을 때, S401에서 공유된 상호운용성/호환성 정보를 이용하여 대응 과정을 신속하고 효율적으로 처리함으로써 전체적인 수소 연료공급 프로세스의 성공 가능성을 향상시키고, 수소 연료공급 프로세스에 요구되는 시간을 단축할 수 있다.
도 18은 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 단계 S401의 일 실시예를 도시하는 동작 흐름도이다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되며, 수소 연료공급(fueling)을 위한 통신 방법으로서, 모빌리티에 수소를 연료공급하는 디스펜서가 포함되는 통신 네트워크를 경유하여, 디스펜서 디스커버리 프로토콜 (DDP, Dispenser Discovery Protocol) 요청 메시지를 브로드캐스팅하는 단계(S2400); 디스펜서로부터 통신 네트워크 상의 디스펜서의 식별 정보를 포함하는 DDP 응답 메시지를 수신하는 단계(S2500); 및 모빌리티와 디스펜서 간에, DDP 응답 메시지 내의 디스펜서의 식별 정보를 이용하여 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계(S2600)를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, DDP 요청 메시지를 브로드캐스팅하는 단계(S2400) 이전에, 디스펜서가 포함되는 통신 네트워크에서 사용될 모빌리티의 IP 주소가 결정되고, 모빌리티가 모빌리티의 IP 주소에 기반한 통신 채널을 경유하여 통신 네트워크에 연결되는 단계를 더 포함할 수 있다.
이때, 모빌리티의 IP 주소가 결정되는 과정은, 통신 네트워크에 의하여 IP 주소가 결정되고 모빌리티가 IP 주소를 할당받을 수 있으며, 대안적 실시예에서는 통신 네트워크에서 사용 가능한 (available) IP 주소들 중 모빌리티가 어느 하나를 선택하여 IP 주소를 결정하고, 스스로에게 IP 주소를 할당할 수도 있다. 이때 모빌리티의 IP 주소를 결정하는 과정은 통신 네트워크 측 및/또는 모빌리티가 상호 협력하여 수행될 수도 있으며 이로 인하여 본 발명의 사상이 한정되지 아니한다.
본 발명의 대안적 실시예에서, 단계 S401에서 레이어 1/2 연결이 설립되면(established), 모빌리티는 디스펜서의 네트워크(디스펜서가 소속되는 네트워크, 또는 디스펜서를 포함하여 디스펜서 주변의 다른 디스펜서들을 관리하는 FSO (Fueling Station Operator) 또는 FSMS (Fueling Station Managing System)의 관리 하에 있는 네트워크)에 참여(join)할 수 있다. 이때 모빌리티는 모빌리티의 IP 주소를 할당하거나 할당받음으로써 네트워크에 참여할 수 있다. 본 발명의 대안적 실시예에서, 모빌리티는 네트워크에 참여한 후에 모빌리티의 연결 정보(connection information) 또는 식별 정보(identification information)를 어나운스할 수 있다.
모빌리티 및 디스펜서는 IEFT RFC 8200 및 8504에서 정의된 바와 같이 IPv6를 지원할 수 있다.
모빌리티가, 디스펜서가 소속된 네트워크와의 데이터-링크가 활성화된 후에, (통신 채널이 성공적으로 발견되고, 연결되고, 페어링된, communication channel is successfully discovered, connected, and paired), 모빌리티는 IEFT RFC 4291, 4861, 4862, 4429, 및 7527에서 정의된 바와 같이 IP 주소를 통신 네트워크로부터 할당받거나 스스로에게 할당함으로써 네트워크에 참여할 수 있다. 이때 모빌리티가 통신 네트워크에 연결되거나 페어링되는 과정은 모빌리티와 디스펜서 간의 페어링 과정과는 다른 과정을 의미할 수 있다.
본 발명의 대안적 실시예에서, 모빌리티가 IPv6 주소를 할당받은 후에, 모빌리티는 모빌리티의 IP 주소, 및 TCP/UDP 포트 넘버 등을 디스펜서 디스커버리 프로토콜 (DDP. Dispenser Discovery Protocol)에 기반하여 어나운스할 수 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, 모빌리티의 IP 주소는, 랜덤 넘버에 기반하여 생성될 수 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, 모빌리티는 IPv6 주소가 노출되거나 디스펜서로 공유될 때 모빌리티의 영구적일(permanent) 수 있는 MAC 주소의 노출을 회피하기 위하여, 예를 들면 RFC 3041 등에 규정된 방법으로 IPv6 주소를 생성할 수 있다.
본 발명의 일 실시예에 따른 모빌리티의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, 모빌리티는 IPv6 주소가 노출되거나 디스펜서로 공유될 때 모빌리티의 영구적일(permanent) 수 있는 MAC 주소의 노출을 회피하기 위하여, 예를 들면 RFC 3041 등에 규정된 방법으로 랜덤 넘버에 기반하여 IPv6 주소를 생성할 수 있다.
DDP 프로토콜을 수행하기 위하여, 모빌리티는 DDP 요청 메시지 (DDPRequest message)를, 디스펜서가 포함되는 통신 네트워크를 경유하여 브로드캐스트할 수 있다.
이때 DDP 요청 메시지는 모빌리티의 식별 정보를 포함하거나 포함하지 않을 수 있고, 미리 규정된 정보 (예를 들어 TCP 포트 넘버, UDP 포트 넘버 등)를 이용하여 브로드캐스트될 수 있다.
예를 들어, 메시지는 링크-로컬 멀티캐스팅 주소 "0xff02::1"를 이용하며 포트 넘버 19885 상으로 브로드캐스트될 수 있다.
DDP 요청 메시지가 xml 등에 기반하여 구현되는 실시예가 아래의 표 31에 의하여 개시될 수 있다.
| DDPRequest = { "pairing_id" : <vehicle's pairing ID> (optional) } |
디스펜서는 UDP port 19885를 오픈하고, 모빌리티로부터 전송되는 다음 메시지를 수신하기 위하여 준비할 수 있다. 이때 모빌리티의 페어링 ID 등은 최초의 DDP 요청 메시지 내에 포함될 수도 있다.
DDP 응답 메시지가 xml 등에 기반하여 구현되는 실시예가 아래의 표 32에 의하여 개시될 수 있다.
| DDPResponse = { "IPaddress" : <dispenser IP address>, "TCPPort": <dispenser's TCP port number>, "UDPPort": <dispenser's UDP port number> "pairing_id" : <dispenser's pairing ID> (optional) } |
대안적 실시예에서는 모빌리티 및 디스펜서의 페어링 ID 등은 DDP 요청 메시지 또는 DDP 응답 메시지 이외의 DDP 프로토콜 내의 별도의 과정을 이용하여 상대방과 공유되고 페어링을 위한 인증 과정에 이용될 수 있다.
본 발명의 대안적 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, DDP 요청 메시지 또는 이후의 과정에서 전송되는 메시지에 포함되는 모빌리티의 식별 정보는, 모빌리티의 IP 주소(MAC 주소의 노출을 회피하기 위해 생성된)를 포함할 수 있고, DDP 응답 메시지에 포함되는 디스펜서의 식별 정보는, 디스펜서의 IP 주소, 디스펜서의 TCP 포트 넘버, 또는 디스펜서의 UDP 포트 넘버를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, DDP 요청 메시지 또는 이후의 과정에서 전송되는 메시지에 포함되는 모빌리티의 식별 정보는, 모빌리티의 페어링 식별자(ID, Identification)를 포함할 수 있고, DDP 응답 메시지에 포함되는 디스펜서의 식별 정보는, 디스펜서의 페어링 식별자(ID, Identification)를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계(S2600)는, 모빌리티의 페어링 식별자 및 디스펜서의 페어링 식별자를 이용하여 수행될 수 있다.
모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계(S2600)에서는, 모빌리티의 페어링 식별자 및 디스펜서의 페어링 식별자를 이용하여, 모빌리티가 통신 네트워크에 연결된 통신 채널과 다른 페어링 채널을 경유하여 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행할 수 있다.
모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계(S2600)는, 모빌리티의 페어링 식별자 및 디스펜서의 페어링 식별자를 이용하여 모빌리티와 디스펜서 간의 페어링을 위한 페어링 채널을 통신 채널과 바인딩하는 단계; 및 페어링 채널 내에서 모빌리티의 페어링 식별자 및 디스펜서의 페어링 식별자를 이용하여 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계; 를 포함할 수 있다.
본 발명의 일 실시예에서, 통신 채널과 페어링 채널은 같은 채널일 수 있고, 다른 일 실시예에서는 통신 채널과 페어링 채널은 같은 종류의 서로 다른 채널일 수도 있으며, 또 다른 일 실시예에서는 통신 채널과 페어링 채널은 서로 다른 종류의 채널일 수도 있다.
DDP 요청 메시지 및/또는 DDP 응답 메시지의 페어링 ID 필드는, 통신 채널과 다른 페어링 채널이 이용되는 경우에 특히 유용할 수 있다. 예를 들어, 페어링 ID는 페어링 채널을 통신 채널과 바인딩할 때 이용될 수 있다.
페어링 채널은 별도의 보안 채널(예를 들어 TCP 및/또는 TLS)로서 구현될 수도 있다. 대안적 실시에서는, 페어링 채널은 통신 채널과 서로 이종 통신 기술로 설정될 수도 있다. 예를 들어, 통신 채널은 WLAN이고 페어링 채널은 UWB일 수도 있고, 또는 BLE, irDA, RFID 등의 근거리 통신을 이용하여 설정될 수도 있다.
본 발명의 일 실시예에 따른 모빌리티 및/또는 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, 모빌리티 및 디스펜서 간에는 상호 인증 (mutual authentication)이 요구될 수 있다.
모빌리티가 TCP/TLS/DTLS 내에서 클라이언트의 역할을, 디스펜서가 서버의 역할일 수 있지만 본 발명의 사상이 특정한 실시예에 의하여 한정되는 것은 아니다.
모빌리티의 DDP 요청 메시지는 디스펜서가 어디에 있는지, 또는 디스펜서가 누구인지, 등을 문의하는 내용을 포함할 수 있다.
디스펜서의 DDP 응답 메시지는 자신이 누구인지, 어디에 있는지, IP주소, 또는 포트 정보를 포함할 수 있다.
DDP 요청 메시지와 DDP 응답 메시가 교환된 후, 모빌리티와 디스펜서 간에 TCP 3-way handshake 및/또는 TLS 3-way handshake 등이 수행될 수 있다.
TCP 3-way handshake에서는, 모빌리티가 SYN 메시지를 전송하고, 디스펜서가 SYN/ACK 메시지를 응답하며, 모빌리티가 ACK 메시지를 응답할 수 있다.
TLS 3-way handshake 에서는, 모빌리티가 Client Hello 메시지를 전송하고, 디스펜서가 Server Hello 메시지를 응답하며, 모빌리티가 Client finished + First fueling 메시지를 전송할 수 있다.
본 발명의 일 실시예에 따른 모빌리티 및/또는 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, 모빌리티 및 디스펜서 간 상호 인증 (mutual authentication) 시에는 모빌리티 및 디스펜서 각각은 인증서/증명서 (certificate) 및 서명 (signature)를 이용하여 자신의 identity를 prove할 수 있다.
디스펜서가 서버의 역할인 경우, 디스펜서는 언제든지 클라이언트 (모빌리티)의 인증을 요청할 수 있다.
디스펜서 인증이 실패한 경우, 모빌리티는 이러한 시큐리티 이벤트를 모빌리티의 EVCC 또는 연관된 데이터베이스 내에 기록할 수 있고, 가능하면 사용자에게 이러한 시큐리티 이벤트를 통지할 수 있으며, 이머전시 핸들링 (UC11, S411)에 기반하여 연료공급(fueling)을 중단(stop)할 수 있다.
모빌리티 인증이 실패한 경우, 디스펜서는 이러한 시큐리티 이벤트를 디스펜서의 SECC 또는 연관된 데이터베이스 내에 기록할 수 있고, 이머전시 핸들링 (UC11, S411)에 기반하여 연료공급(fueling)을 중단(stop)할 수 있다.
대안적 실시예의 단계(S401) 내에서, DDP 요청 메시지를 브로드캐스팅하는 단계(S2400) 이후에 모빌리티와 디스펜서 간 페어링을 위한 정보를 공유하는 과정에서, 모빌리티가 전송하는 메시지는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보로서 모빌리티가 지원하는 통신 프로토콜 또는 연료공급 프로토콜의 정보를 포함할 수 있다.
대안적 실시예에서, DDP 요청 메시지를 브로드캐스팅하는 단계(S2400)에서 DDP 요청 메시지는, 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보로서 모빌리티가 지원하는 통신 프로토콜 또는 연료공급 프로토콜의 정보를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 모빌리티가 지원하는 통신 프로토콜 또는 연료공급 프로토콜의 정보는, 프로토콜 이름, 인덱스, 버전, 우선순위 또는 선호도를 포함할 수 있다.
대안적 실시예의 단계(S401) 내에서, DDP 응답 메시지를 전송/수신하는 단계(S2500) 이후에 모빌리티와 디스펜서 간 페어링을 위한 정보를 공유하는 과정에서, 디스펜서가 전송하는 메시지는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보로서 디스펜서가 지원하는 통신 프로토콜 또는 연료공급 프로토콜의 정보를 포함할 수 있다.
대안적 실시예에서, DDP 응답 메시지를 전송/수신하는 단계(S2500)에서 DDP 응답 메시지는, 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보로서 디스펜서가 지원하는 통신 프로토콜 또는 연료공급 프로토콜의 정보를 포함할 수 있다.
본 발명의 일 실시예에 따른, 모빌리티 및/또는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 디스펜서가 지원하는 통신 프로토콜 또는 연료공급 프로토콜의 정보는, 프로토콜 이름, 인덱스, 버전, 우선순위 또는 선호도를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 모빌리티와 디스펜서 간의 페어링이 수행된 이후에, 모빌리티와 디스펜서 간 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S403, S404, S405)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 모빌리티와 디스펜서 간의 페어링이 수행된 이후에, 모빌리티와 디스펜서 간 통신 프로토콜 또는 연료공급 프로토콜을 협상하기 위하여 모빌리티와 디스펜서 간 보안 채널(secure channel)을 설립(establish)하는 단계(S402)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 모빌리티와 디스펜서 간 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S403, S404, S405)는, 모빌리티와 디스펜서 간 통신 프로토콜을 협상하는 단계(S403); 통신 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 프로토콜을 협상하는 단계(S404); 및 연료공급 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 파라미터를 협상하는 단계(S405)를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법은, 디스펜서가 포함되는 통신 네트워크를 경유하여 모빌리티로부터 브로드캐스팅되는 디스펜서 디스커버리 프로토콜 (DDP, Dispenser Discovery Protocol) 요청 메시지를 수신하는 단계(S2400); 통신 네트워크 상의 디스펜서의 식별 정보를 포함하는 DDP 응답 메시지를 모빌리티로 전송하는 단계(S2500); 및 모빌리티와 디스펜서 간에, DDP 응답 메시지 내의 디스펜서의 식별 정보를 이용하여 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계(S2600)를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, DDP 요청 메시지에 포함되는 모빌리티의 식별 정보는, 모빌리티의 페어링 식별자(ID, Identification)를 포함할 수 있고, DDP 응답 메시지에 포함되는 디스펜서의 식별 정보는, 디스펜서의 페어링 식별자(ID, Identification)를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계(S2600)는, 모빌리티의 페어링 식별자 및 디스펜서의 페어링 식별자를 이용하여 수행될 수 있다.
모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행하는 단계에서는, 모빌리티의 페어링 식별자 및 디스펜서의 페어링 식별자를 이용하여, 모빌리티가 통신 네트워크에 연결된 통신 채널과 다른 페어링 채널을 경유하여 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법에서, DDP 응답 메시지에 포함되는 디스펜서의 식별 정보는, 디스펜서의 IP 주소, 디스펜서의 TCP 포트 넘버, 또는 디스펜서의 UDP 포트 넘버를 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법은, 모빌리티와 디스펜서 간의 페어링이 수행된 이후에, 모빌리티와 디스펜서 간 통신 프로토콜 또는 연료공급 프로토콜을 협상하는 단계(S403, S404, S405); 및 연료공급 프로토콜에 기반하여 수행되는, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 모니터링하고 제어하는 단계(S407)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법은, 디스펜서가, 미리 규정된 DDP 요청 메시지에 포함되는 모빌리티의 UDP 포트 넘버에 기반하여 디스펜서의 UDP 포트를 오픈하는 단계(도시되지 않음)를 더 포함할 수 있다.
대안적 실시예에서, 페어링을 위한 인증 (S2600)은 필요에 따라 모빌리티 측에서 요청하거나 시작함으로써 수행될 수 있다.
대안적 실시예에서, 페어링을 위한 인증 (S2600)은 디스펜서 측에서 지속적으로 모빌리티에 요청하거나 시작함으로써 수행될 수 있다. 특히 수소의 연료공급이 시작된 이후 수소를 연료공급하는 과정을 모니터링하고 제어하는 단계(S407)를 수행하기 위하여 디스펜서는 주기적으로 또는 연속적으로 페어링을 위한 인증(S2600)과 관련된 프로세스를 모빌리티에 요청하거나 시작할 수 있다.
대안적 실시예에서, 페어링을 위한 인증 (S2600)은 unilateral authentication으로 실행될 수 있다.
대안적 실시예에서, 페어링을 위한 인증 (S2600)은 mutual authentication으로 실행될 수 있다.
대안적 실시예에서, 페어링을 위한 인증 (S2600) 과정에서 서버의 역할을 수행하는 엔티티는 인증서/증명서(certificate), 서명(signature)를 상대방에게 전송할 수 있다.
대안적 실시예에서, 페어링을 위한 인증 (S2600) 과정에서 서버의 역할을 수행하는 엔티티는 인증서/증명서(certificate), 서명(signature), 인증/증명 요청 (cert request) 등을 상대방에게 전송할 수 있다.
대안적 실시예에서, 페어링을 위한 인증 (S2600)이 mutual authentication으로 실행될 때에는 한번은 모빌리티가, 다른 한번은 디스펜서가 서버의 역할을 수행할 수 있다.
본 발명의 일 실시예에서 설명의 편의상 프로토콜 메시지를 JSON 기반의 메시지로 표현하거나 코딩하는 실시예가 도시되었다. 본 발명의 대안적 실시예에서는 다양한 메시지 코딩 및/또는 표현 기술을 이용하여 프로토콜 메시지를 생성할 수 있고, 다양한 기술을 이용하여 생성된 프로토콜 메시지가 모빌리티, 디스펜서, 충전소 간에 송수신될 수 있다.
도 19는 본 발명의 일 실시예에 따른, 수소 연료공급을 위한 통신 방법을 도시하는 동작 흐름도이다.
전술한 바와 같이, 안전 체크인 단계(S406)에서, 모빌리티 및/또는 디스펜서(dispenser)는 실제 연료공급이 시작되기 전에 필요한 모든 안전 조건이 충족되었는지 확인할 수 있다.
연료공급 파라미터들이 교환되고 모빌리티와 디스펜서가 호환되는 것으로 간주되면, 단계 S406에서 모빌리티와 디스펜서가 안전 상태 점검을 수행하여 연료공급이 안전한지 확인할 수 있다.
도 19를 참조하면, 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되며, 수소 연료공급(fueling)을 위한 통신 방법으로서, 모빌리티에 수소를 연료공급하는 디스펜서와 모빌리티 간 페어링 과정(S401)의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하는 단계(S404, 및/또는 S405); 및 안전 체크인 과정이 수행되기 전에, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 안전 체크인 과정이 수행되기 전에, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)는, 단계 S404 및/또는 S405에서 제1 연료공급 프로토콜 및/또는 제1 연료공급 프로토콜에 따른 연료공급 파라미터가 성공적으로 협상되고 교환되면 수행될 수 있다.
이때 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법은, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계(S2700)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계(S2700)는, 단계 S404 및/또는 S405에서 제1 연료공급 프로토콜 및/또는 제1 연료공급 프로토콜에 따른 연료공급 파라미터가 성공적으로 협상되고 교환되면 수행될 수 있고, 단계 S2800이 실행되기 전에 수행될 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계(S2700)는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하는 단계를 포함할 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 안전 체크인 과정(S406)을 수행하기 전에 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부를 판정하는 단계(S2700)에서는, 제1 연료공급 프로토콜 및/또는 제1 연료공급 프로토콜에 따른 연료공급 파라미터에 안전 체크인 과정(S406) 전에 페어링 과정의 체크가 요구되는 지 여부가 포함되는 지가 판정될 수 있다. 즉, 안전 체크인 과정(S406) 전에 페어링 과정의 체크가 요구되는 지 여부는 제1 연료공급 프로토콜 및/또는 제1 연료공급 프로토콜에 따른 연료공급 파라미터에서 정의될 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)는, 페어링 과정(S401)을 체크하는 단계를 포함할 수 있다. 이때 페어링 과정(S401)이 유효하게 수행되었는지, 단계 S404 및/또는 S405가 수행된 이후에도 여전히 페어링 과정(S401)이 유효한 지가 체크될 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)에서는, 페어링 과정(S401)의 결과를 검증할 수 있다. 이때 페어링 과정(S401)의 결과를 검증할 때에는 모빌리티와 디스펜서 각각의 페어링 ID가 이용될 수 있다.
본 발명의 다른 일 실시예에 따른 수소 연료공급을 위한 통신 방법의 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)에서는, 이미 협상된 제1 연료공급 프로토콜 및/또는 제1 연료공급 프로토콜에 따른 연료공급 파라미터가 UC6 안전 체크인 과정의 내용을 충실히 정의하지 못하는 경우에 페어링을 다시 수행하고(S401을 다시 수행), 페어링을 다시 수행한 결과에 따라 필요하면 새로운 제2 연료공급 프로토콜을 다시 협상할 수 있다(S403, S404, 및/또는 S405를 다시 수행).
도 20은 본 발명의 다른 일 실시예에 따른 수소 연료공급을 위한 통신 방법을 도시하는 동작 흐름도이다.
도 20을 참조하면, 본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부를 판정하는 단계(S2700)는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하는 단계(S2900)를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 모빌리티와 디스펜서 간 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)에서 모빌리티와 디스펜서 간 공유되는 페어링 정보는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함할 수 있다. 이때 상호운용성 또는 호환성 관련 정보는, 모빌리티와 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계(S403, S404, 및/또는 S405를 다시 수행)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계(S403, S404, 및/또는 S405를 다시 수행)를 더 포함할 수 있다.
이때, 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 제2 연료공급 프로토콜이 결정될 수 있다.
도 19와 도 20을 함께 참조하면, 본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정의 체크가 수행된 이후에(S401을 다시 수행, 및/또는 S2800), 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이전에 모빌리티와 디스펜서 간 제1 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-인 단계(S406); 및 디스펜서가 모빌리티로 수소를 연료공급하는 과정 이후 및 모빌리티에서 노즐이 분리되기 전에, 모빌리티와 디스펜서 간 제2 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-아웃 단계(S408)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정의 체크 결과(S401을 다시 수행, 및/또는 S2800)에 기반하여, 안전에 치명적이지 않은 에러(non-safety-critical error)를 검출하고 핸들링하는 단계(S2010, S2020, S410)를 더 포함할 수 있다.
이때 페어링 과정의 체크 결과(S401을 다시 수행, 및/또는 S2800), 페어링 결과, 페어링 정보, 및/또는 페어링 검증 결과 등에서 에러가 검출된 경우, 이전까지 수행된 과정의 일부 또는 전부 (S401 내지 S405)를 다시 수행할 것이 요구되는 것으로 판정되면 단계 S410의 프로토콜에 따라 이전까지 수행된 과정의 일부 또는 전부 (S401 내지 S405)를 다시 수행할 수 있다. 예를 들어, 에러의 종류로는 페어링 체크/검증 결과가 fail이거나, 연료공급 프로토콜이 UC6: 안전 체크인 과정을 충실히 정의하지 않는 경우 등을 들 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티(hydrogen fueled mobility)의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정의 체크 결과(S401을 다시 수행, 및/또는 S2800)에 기반하여, 디스펜서 및 모빌리티 간 상호 동작을 중지해야 하는 긴급상황을 검출하고 핸들링하는 단계(S2010, S2020, S411)를 더 포함할 수 있다.
이때 페어링 과정의 체크 결과(S401을 다시 수행, 및/또는 S2800), 페어링 결과, 페어링 정보, 및/또는 페어링 검증 결과 등에서 크리티컬 에러가 검출된 경우, 단계 S411의 프로토콜에 따라 디스펜서 및 모빌리티 간 상호 동작을 중지할 수 있다. 예를 들어, 크리티컬 에러의 종류로는 페어링 체크/검증 결과가 fail이거나, 연료공급 프로토콜이 UC6: 안전 체크인 과정을 충실히 정의하지 않는 경우 등을 들 수 있다.
다시 도 20을 참조하면, 제2 연료공급 프로토콜을 다시 협상하는 단계는, 모빌리티와 디스펜서 간 제2 연료공급 프로토콜과 연계되는 통신 프로토콜을 다시 협상하는 단계(S403을 다시 수행); 통신 프로토콜에 기반하여, 모빌리티와 디스펜서 간 제2 연료공급 프로토콜을 다시 협상하는 단계(S404를 다시 수행); 및 제2 연료공급 프로토콜에 기반하여, 모빌리티와 디스펜서 간 연료공급 파라미터를 다시 협상하는 단계(S405를 다시 수행)를 포함할 수 있다.
제2 연료공급 프로토콜을 다시 협상하는 단계(S403, S404, 및/또는 S405를 다시 수행)에서, 디스펜서 및 모빌리티 간에 전송되는 통신 프로토콜 또는 연료공급 프로토콜의 정보는 프로토콜 이름, 인덱스, 버전, 우선순위 또는 선호도를 포함할 수 있다.
본 발명의 일 실시예에서, 연료공급 프로토콜에 미리 정의된 내용에 기반하여 단계 S406 (안전 체크-인 유즈 케이스) 내에서 페어링이 요구되는 상황에서는, 안전 체크-인 과정에서 페어링을 수행할 수 있다. 만일 연료공급 프로토콜에 미리 정의된 내용이 안전 체크-인 유즈 케이스를 불완전하게 정의하거나, 안전 체크-인 유즈 케이스 내에서 페어링을 수행할 지 여부가 불명확하게 정의된 경우에도 본 발명의 대안적 실시예에서는 단계 S405 이후 단계 S407을 시작하기 전에 페어링 체크를 수행할 수 있다.
본 발명의 일 실시예에서는, 통신 프로토콜과 연료공급 프로토콜 협상 과정 (S403, S404)에서 결정되는 프로토콜의 내용에 기반하여, 안전 체크인이 수행되어야 하는 지 생략되어도 무방한지, 페어링은 어떻게 수행되는 지 등이 정의될 수 있다. 이러한 사항은 모빌리티와 디스펜서 양방이 모두 인지하고 있다고 가정할 수 있다. 따라서 안전 체크인이 정의되어 있는지, 안전 체크인 내에서 페어링 체크 여부가 정의되어 있는지에 대한 판정은 모빌리티와 디스펜서 각각이 프로토콜에 정의된 내용에 기반하여 수행할 수 있다. 대안적 실시예에 따라서는 이러한 판정은 모빌리티와 디스펜서 간의 상호 협력에 의하여 수행될 수도 있다.
본 발명의 일 실시예에서, 도 19 및/또는 도 20의 단계들은 단계 S406 (안전 체크-인 유즈 케이스)의 일부로서 수행될 수 있다.
본 발명의 다른 일 실시예에서, 도 19 및/또는 도 20의 단계들은 단계 S406 (안전 체크-인 유즈 케이스)의 시작 전에 준비 단계로서 수행될 수 있다.
본 발명의 대안적 실시예에서, 단계 S401 내지 S405의 일부만이 선택적으로 다시 수행될 수도 있다. 이때 선택적으로 다시 수행되는 단계 S401 내지 S405의 일부는 모빌티티와 디스펜서 간의 상호운용성/호환성, 연료공급 프로토콜이 안전 체크인 유즈 케이스를 충실히 정의하는 지 여부 등에 기반하여 다시 수행될 수 있다.
또한, 전술한 바와 같이 본 발명의 일 실시예에서는 안전 체크인 단계(S406)에서, 모빌리티 및/또는 디스펜서는 노즐-리셉터클이 고정되었는지를 점검하고, 누설을 점검하고, 마지막 상태(the last-minute status)를 점검할 수 있다.
또한, 전술한 바와 같이 본 발명의 일 실시예에서는 디스펜서로부터 연료공급 파라미터 협상 응답 메시지를 수신한 후 연료공급 프로토콜이 안전 체크인을 지원하는 경우, 모빌리티는 메시지 시퀀스 설정시간 내에 디스펜서로 안전 체크인 요청 메시지를 전송하여 안전 체크인 단계(S406)를 시작할 수 있다.
모빌리티와 디스펜서는 커플러 점검(coupler check)을 위한 메시지들을 주고받을 수 있다. 모빌리티의 자신의 커플러 점검 결과를 나타내는 정보(예컨대 모빌리티: OK)를 포함한 메시지를 디스펜서로 전달하고, 디스펜서는 자신의 커플러 점검 결과를 나타내는 정보(예컨대 DP: OK)를 포함한 메시지를 모빌리티로 전달할 수 있다.
또한, 모빌리티와 디스펜서는 가스의 누설 점검(leak check)과 관련된 메시지들을 주고받을 수 있다. 누설 점검 관련 메시지들을 주고받는 중에, 디스펜서는 누설 점검 중임을 나타내는 정보(ongoing)를 모빌리티로 전달할 수 있다. 그리고 모빌리티는 디스펜서의 누설 점검 결과를 기다리고 있음을 나타내는 정보(waiting)를 디스펜서로 전달할 수 있다. 누설 점검이 완료되면, 디스펜서는 누설점검완료 정보(Done)와 함께 측정된 탱크 용량(measured tank volume)을 요청하는 메시지를 모빌리티로 전달할 수 있다.
또한, 디스펜서는 고정된(immobilized) 상태 점검(status check)을 위한 메시지를 모빌리티로 전달할 수 있고, 모빌리티는 상태 점검을 위해 준비되어 있음(ready)을 알리는 메시지를 디스펜서로 전달할 수 있다.
이와 같이, 모빌리티가 디스펜서에 모빌리티의 현재 상태 또는 고정 상태(immobilization status)에 대한 파라미터들을 보고(reporting)하면, 디스펜서는 커플러 고정 상태(coupler lock status), 누설 점검 상태(leak check status), 예측된 모빌리티 탱크 용량 등에 대한 파라미터들을 모빌리티로 보고할 수 있다.
전술한 안전 체크인 단계(S406)를 통과하면 연료공급이 시작될 수 있다. 연료공급 중에, 모빌리티와 디스펜서는 정보를 교환하여 연료공급이 안전하고 효율적으로 수행되도록 다양한 상태 파라미터들을 모니터링할 수 있다(S407). 필요한 경우, 모빌리티 또는 디스펜서는 연료공급 단계(S406)를 제어하거나 안전 관련 조건에 대응하기 위해 상대방의 조치를 요청하는 제어 메시지를 보낼 수 있다. 교환할 파라미터들과 명령은 실제 연료공급 프로토콜에 따라 다를 수 있다.
이상의 실시예는 모빌리티 측(또는 모빌리티 측의 통신 장치)에서 수행되는 수소 연료공급을 위한 통신 방법을 설명하였다. 본 발명의 다른 일 실시예는 디스펜서 측(또는 디스펜서 측의 통신 장치)에서 수소 연료공급을 위한 통신 방법을 개시할 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급(fueling)을 위한 통신 방법은, 모빌리티와 디스펜서 간 페어링 과정의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하는 단계(S404 및/또는 S405); 및 안전 체크인 과정이 수행되기 전에, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)를 포함할 수 있다.
이때 본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계(S2700)를 더 포함할 수 있다.
제1 연료공급 프로토콜에 대한 정보에 기반하여 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계(S2700)는, 단계 S404 및/또는 S405에서 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하는 단계(S2900)를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행하는 단계(S2800)는, 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 모빌리티와 디스펜서 간 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법에서, 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)에서 모빌리티와 디스펜서 간 공유되는 페어링 정보는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함할 수 있다.
이때 상호운용성 또는 호환성 관련 정보는, 모빌리티와 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계(S403, S404, 및/또는 S405를 다시 수행)를 더 포함할 수 있다.
본 발명의 일 실시예에 따른, 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는 수소 연료공급을 위한 통신 방법은, 페어링 과정을 다시 수행하는 단계의 결과(S401을 다시 수행)에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상하는 단계(S403, S404, 및/또는 S405를 다시 수행)를 더 포함할 수 있다.
이때 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 제2 연료공급 프로토콜이 결정될 수 있다.
이상의 실시예에서, 본 발명의 각 단계들이 모빌리티 또는 디스펜서 중 어느 한 쪽에 의하여 수행되는 실시예가 도시되었으나, 본 발명의 사상은 이에 한정되지 않는다. 도 19 및 도 20의 각 단계들 및 그에 앞서거나 뒤따르는 단계들 중 적어도 일부는 모빌리티 및 디스펜서 중 적어도 하나 이상의 참여 또는 상호 간의 협력에 의하여 수행될 수 있다.
예를 들어, 단계 S2700 및/또는 S2900에서 포함되는 판정 과정은 모빌리티 및 디스펜서 간 상호 교환되는 정보에 기반하여 수행될 수 있으며, 단계 S401에서 수행된 페어링의 결과에 기반하여 단계 S403 내지 S405 중 적어도 하나 이상에서 결정되는 제1 연료공급 프로토콜의 내용에 기반하여 수행될 수 있다.
안전 체크인 과정 내에서 또는 안전 체크인 과정 이전에 페어링의 체크가 요구되는 지 여부는 제1 연료공급 프로토콜에 정의된 내용에 기반하여 정의, 결정 또는 판정될 수 있으며, 모빌리티 또는 디스펜서가 제1 연료공급 프로토콜의 내용을 참조하여 페어링의 체크가 요구되는 지 여부를 인식할 수 있다. 본 발명의 일 실시예에서는 페어링의 체크가 요구되는 지 여부를 인식하는 과정에 모빌리티 또는 디스펜서 중 어느 하나가 참여할 수 있다. 본 발명의 대안적 실시예에서는 모빌리티 및 디스펜서가 각각 페어링의 체크가 요구되는 지 여부를 인식하는 과정에 참여할 수 있다. 본 발명의 다른 대안적 실시예에서는 페어링의 체크가 요구되는 지 여부를 인식하는 과정을 모빌리티 및 디스펜서가 각각 수행하고, 서로의 인식 또는 판정 결과가 교차 검증될 수 있다.
본 발명의 대안적 실시예에서는, 도 19 및 도 20의 각 단계들에 뒤따르는 단계들은 도 19 및 도 20의 각 단계들에 앞서는 단계들의 과정의 전부를 그대로 수행하거나, 일부를 수행하고 나머지 일부는 필요에 따라 변형될 수 있다. 예를 들어, 단계 S2700, S2800, S2900 이전의 단계 S401 내지 S405는 모빌리티 측에서 주도하여 수행되고, 단계 S2700, S2800, S2900 이후에 뒤따르는 단계 S401 내지 S405의 적어도 일부의 재 수행 시에는 디스펜서 측에서 주도하여 수행되거나, 모빌리티와 디스펜서 간 상호 교차 검증을 통하여 수행될 수도 있다.
본 발명의 대안적 실시예에서는, 단계 S2700, S2800, S2900 이후에 뒤따르는 단계 S401 내지 S405의 적어도 일부의 재 수행 시에는 이전의 단계 S401 내지 S405에서 고려된 정보에 부가적인 정보가 더 고려될 수 있다. 부가적인 정보의 예로는, 상호운용성/호환성을 만족하는 연료공급 프로토콜이 UC6: 안전 체크인 과정의 정보를 충실히 정의하고 있는 지 여부에 대한 정보를 포함할 수 있다.
부가적인 정보의 다른 예로는, 협상에 의하여 도출된 제1 연료공급 프로토콜이 UC6: 안전 체크인 과정을 필수적으로 요구하는 지 여부, 및 제1 연료공급 프로토콜이 UC6: 안전 체크인 과정의 정보를 충실히 정의하고 있는 지 여부에 대한 정보를 포함할 수 있다.
부가적인 정보의 또 다른 예로는, 협상에 의하여 도출된 제1 연료공급 프로토콜이 UC6: 안전 체크인 과정을 필수적으로 요구하는 지 여부, 및 현재 통신 및 연료공급 환경 등이 제1 연료공급 프로토콜에서 정의된 UC6: 안전 체크인 과정을 충실히 수행하기에 적합한 지 여부에 대한 정보를 포함할 수 있다.
도 21은 본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 장치, 통신 제어 장치, 및/또는 전자 제어 장치로서 수소 연료 모빌리티, 디스펜서, 및/또는 연료공급 스테이션에 탑재될 수 있는 일반화된 컴퓨팅 시스템의 내부 구조에 대한 개념적인 블록도이다.
도 1 내지 도 20의 실시예에서 도면 상으로는 생략되었으나 프로세서, 및 메모리가 전자적으로 각 구성 요소와 연결되고, 프로세서에 의하여 각 구성 요소의 동작이 제어되거나 관리될 수 있다.
본 발명의 일 실시예에 따른 전기차 연료공급을 위한 연료공급 통신 방법의 적어도 일부의 과정은 도 21의 컴퓨팅 시스템(3000)에 의하여 실행될 수 있다.
본 발명의 일 실시예에 따른 컴퓨팅 시스템(3000)은, 적어도 하나의 프로세서(processor)(3100) 및 상기 적어도 하나의 프로세서(3100)가 적어도 하나의 단계를 수행하도록 지시하는 명령어들(instructions)을 저장하는 메모리(memory)(3200)를 포함할 수 있다. 본 발명의 일 실시예에 따른 방법의 적어도 일부의 단계는 상기 적어도 하나의 프로세서(3100)가 상기 메모리(3200)로부터 명령어들을 로드하여 실행함으로써 수행될 수 있다.
프로세서(3100)는 중앙 처리 장치(central processing unit, CPU), 그래픽 처리 장치(graphics processing unit, GPU), 또는 본 발명의 실시예들에 따른 방법들이 수행되는 전용의 프로세서를 의미할 수 있다.
메모리(3200) 및 저장 장치(3400) 각각은 휘발성 저장 매체 및 비휘발성 저장 매체 중에서 적어도 하나로 구성될 수 있다. 예를 들어, 메모리(3200)는 읽기 전용 메모리(read only memory, ROM) 및 랜덤 액세스 메모리(random access memory, RAM) 중에서 적어도 하나로 구성될 수 있다.
또한, 컴퓨팅 시스템(3000)은, 유선/무선 네트워크를 통해 통신을 수행하는 통신 인터페이스(3300)를 포함할 수 있다.
또한, 컴퓨팅 시스템(3000)은, 저장 장치(3400), 입력 인터페이스(3500), 출력 인터페이스(3600) 등을 더 포함할 수 있다.
또한, 컴퓨팅 시스템(3000)에 포함된 각각의 구성 요소들은 버스(bus)(3700)에 의해 연결되어 서로 통신을 수행할 수 있다.
본 발명의 일 실시예에 따른 프로세서(3100)를 포함하는 장치는 예를 들어 통신 가능한 데스크탑 컴퓨터(desktop computer), 랩탑 컴퓨터(laptop computer), 노트북(notebook), 스마트폰(smart phone), 태블릿 PC(tablet PC), 모바일폰(mobile phone), 스마트 워치(smart watch), 스마트 글래스(smart glass), e-book 리더기, PMP(portable multimedia player), 휴대용 게임기, 네비게이션(navigation) 장치, 디지털 카메라(digital camera), DMB(digital multimedia broadcasting) 재생기, 디지털 음성 녹음기(digital audio recorder), 디지털 음성 재생기(digital audio player), 디지털 동영상 녹화기(digital video recorder), 디지털 동영상 재생기(digital video player), PDA(Personal Digital Assistant) 등일 수 있다.
본 발명의 일 실시예에 따른 수소 연료공급을 위한 통신 장치는 수소 연료 모빌리티 및/또는 디스펜서에 탑재되며 수소 연료 모빌리티 및 디스펜서 간의 통신을 수행하는 장치로서, 적어도 하나 이상의 명령을 메모리(memory)(3200)로부터 수신하여 실행하는 프로세서(processor)(3100)를 포함한다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티(100)의 통신 장치 또는 통신 제어 장치는, 적어도 하나 이상의 명령을 저장하는 메모리(3200); 및 적어도 하나의 명령을 실행하는 프로세서(3100)를 포함할 수 있다. 프로세서(3100)는, 적어도 하나 이상의 명령에 의하여, 모빌리티에 수소를 연료공급하는 디스펜서가 포함되는 통신 네트워크를 경유하여, 디스펜서 디스커버리 프로토콜 (DDP, Dispenser Discovery Protocol) 요청 메시지를 브로드캐스팅할 수 있고(S2400), 디스펜서로부터 통신 네트워크 상의 디스펜서의 식별 정보를 포함하는 DDP 응답 메시지를 수신할 수 있고(S2500), 본 발명의 일 실시예에 따른 수소 연료 모빌리티의 통신 장치에서, 모빌리티와 디스펜서 간에, DDP 응답 메시지 내의 디스펜서의 식별 정보를 이용하여 모빌리티와 디스펜서 간의 페어링을 위한 인증이 수행될 수 있다(S2600).
본 발명의 일 실시예에 따른 수소 연료 모빌리티의 통신 장치는, 적어도 하나 이상의 명령을 저장하는 메모리(memory)(3200); 및 적어도 하나의 명령을 실행하는 프로세서(processor)(3100)를 포함하고, 프로세서(3100)는 적어도 하나 이상의 명령에 의하여, 모빌리티에 수소를 연료공급하는 디스펜서와 모빌리티 간 페어링 과정(S401)의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환할 수 있고(S404 및/또는 S405), 안전 체크인 과정이 수행되기 전에, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행할 수 있다(S2800).
이때, 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정될 수 있다(S2700).
즉, 안전 체크인 과정(S406)을 수행하기 전에, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부를 판정할 수 있고(S2700), 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행할 수 있다(S2800).
프로세서(3100)는, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부가 판정될 때(S2700), 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정할 수 있다(S2900).
프로세서(3100)는, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부를 판정할 때(S2700), 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정할 수 있다(S2900).
프로세서(3100)는, 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행할 때(S2800), 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 모빌리티와 디스펜서 간 페어링 과정을 다시 수행할 수 있다(S401를 다시 수행).
프로세서(3100)가 페어링 과정을 다시 수행할 때(S401), 모빌리티와 디스펜서 간 공유되는 페어링 정보는 모빌리티와 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함할 수 있다.
이때 상호운용성 또는 호환성 관련 정보는, 모빌리티와 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함할 수 있다.
프로세서(3100)는, 적어도 하나 이상의 명령에 의하여, 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상할 수 있다(S403, S404, 및/또는 S405를 다시 수행).
프로세서(3100)는, 적어도 하나 이상의 명령에 의하여, 페어링 과정을 다시 수행하는 단계(S401을 다시 수행)의 결과에 기반하여, 디스펜서가 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 모빌리티와 디스펜서 간에 다시 협상할 수 있다(S403, S404, 및/또는 S405를 다시 수행).
이때 본 발명의 일 실시예에 따른 수소 연료 모빌리티의 통신 장치에서 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 제2 연료공급 프로토콜이 결정될 수 있다.
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치 또는 통신 제어 장치는, 적어도 하나 이상의 명령을 저장하는 메모리(3200); 및 적어도 하나의 명령을 실행하는 프로세서(3100)를 포함하고, 프로세서(3100)는 적어도 하나 이상의 명령에 의하여, 디스펜서가 포함되는 통신 네트워크를 경유하여 모빌리티로부터 브로드캐스팅되는 디스펜서 디스커버리 프로토콜 (DDP, Dispenser Discovery Protocol) 요청 메시지를 수신할 수 있고(S2400), 통신 네트워크 상의 디스펜서의 식별 정보를 포함하는 DDP 응답 메시지를 모빌리티로 전송할 수 있고(S2500), 모빌리티와 디스펜서 간에, DDP 응답 메시지 내의 디스펜서의 식별 정보를 이용하여 모빌리티와 디스펜서 간의 페어링을 위한 인증을 수행할 수 있다(S2600).
본 발명의 일 실시예에 따른 수소 연료 모빌리티에 수소 연료를 공급하는 디스펜서의 통신 장치는, 적어도 하나 이상의 명령을 저장하는 메모리(memory)(3200); 및 적어도 하나의 명령을 실행하는 프로세서(processor)(3100)를 포함하고, 프로세서(3100)는 적어도 하나 이상의 명령에 의하여, 모빌리티와 디스펜서 간 페어링 과정(S401)의 결과에 기반하여, 모빌리티와 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환할 수 있고(S404 및/또는 S405), 안전 체크인 과정이 수행되기 전에, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행할 수 있다(S2800).
이때, 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정될 수 있다(S2700).
즉, 안전 체크인 과정(S406)을 수행하기 전에, 모빌리티와 디스펜서 간 페어링 과정의 체크가 요구되는 지 여부를 판정할 수 있고(S2700), 페어링 과정의 체크가 요구되면, 모빌리티와 디스펜서 간 페어링 과정의 체크를 수행할 수 있다(S2800).
한편, 전술한 대부분의 실시예들에서는 수소 연료 모빌리티에서 디스펜서로 수소 연료 모빌리티의 통신 프로토콜이나 파라미터를 먼저 전송하는 방식을 중심으로 설명하였지만, 본 발명은 특정한 실시예에 한정되지 않고 디스펜서에서 수소 연료 모빌리티로 디스펜서의 통신 프로토콜이나 파라미터를 먼저 전송하도록 구성될 수 있음은 물론이다. 이 경우, 해당 실시예에서 송신자가 수신자가 되고, 수신자가 송신자가 되는 형태를 가질 뿐 실질적으로 동일한 특징을 가지고 있음은 자명하다.
본 발명의 실시예에 따른 방법의 동작은 컴퓨터로 읽을 수 있는 기록매체에 컴퓨터가 읽을 수 있는 프로그램 또는 코드로서 구현하는 것이 가능하다. 컴퓨터가 읽을 수 있는 기록매체는 컴퓨터 시스템에 의해 읽힐 수 있는 정보가 저장되는 모든 종류의 기록장치를 포함한다. 또한 컴퓨터가 읽을 수 있는 기록매체는 네트워크로 연결된 컴퓨터 시스템에 분산되어 분산 방식으로 컴퓨터로 읽을 수 있는 프로그램 또는 코드가 저장되고 실행될 수 있다.
또한, 컴퓨터가 읽을 수 있는 기록매체는 롬(rom), 램(ram), 플래시 메모리(flash memory) 등과 같이 프로그램 명령을 저장하고 수행하도록 특별히 구성된 하드웨어 장치를 포함할 수 있다. 프로그램 명령은 컴파일러(compiler)에 의해 만들어지는 것과 같은 기계어 코드뿐만 아니라 인터프리터(interpreter) 등을 사용해서 컴퓨터에 의해 실행될 수 있는 고급 언어 코드를 포함할 수 있다.
본 발명의 일부 측면들은 장치의 문맥에서 설명되었으나, 그것은 상응하는 방법에 따른 설명 또한 나타낼 수 있고, 여기서 블록 또는 장치는 방법 단계 또는 방법 단계의 특징에 상응한다. 유사하게, 방법의 문맥에서 설명된 측면들은 또한 상응하는 블록 또는 아이템 또는 상응하는 장치의 특징으로 나타낼 수 있다. 방법 단계들의 몇몇 또는 전부는 예를 들어, 마이크로프로세서, 프로그램 가능한 컴퓨터 또는 전자 회로와 같은 하드웨어 장치에 의해(또는 이용하여) 수행될 수 있다. 몇몇의 실시 예에서, 가장 중요한 방법 단계들의 적어도 하나 이상은 이와 같은 장치에 의해 수행될 수 있다.
실시예들에서, 프로그램 가능한 로직 장치(예를 들어, 필드 프로그래머블 게이트 어레이)가 여기서 설명된 방법들의 기능의 일부 또는 전부를 수행하기 위해 사용될 수 있다. 실시예들에서, 필드 프로그래머블 게이트 어레이(field-programmable gate array)는 여기서 설명된 방법들 중 하나를 수행하기 위한 마이크로프로세서(microprocessor)와 함께 작동할 수 있다. 일반적으로, 방법들은 어떤 하드웨어 장치에 의해 수행되는 것이 바람직하다.
이상 본 발명의 바람직한 실시 예를 참조하여 설명하였지만, 해당 기술 분야의 숙련된 당업자는 하기의 특허 청구의 범위에 기재된 본 발명의 사상 및 영역으로부터 벗어나지 않는 범위 내에서 본 발명을 다양하게 수정 및 변경시킬 수 있음을 이해할 수 있을 것이다.
Claims (20)
- 수소 연료 모빌리티(hydrogen fueled mobility)에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법으로서,상기 모빌리티에 수소를 연료공급하는 디스펜서와 상기 모빌리티 간 페어링 과정의 결과에 기반하여, 상기 모빌리티와 상기 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하는 단계; 및안전 체크인 과정이 수행되기 전에, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행하는 단계;를 포함하는, 수소 연료공급을 위한 통신 방법.
- 제1항에 있어서,상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계;를 더 포함하고,상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계는,상기 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하는 단계;를 포함하고,상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행하는 단계는,상기 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 상기 모빌리티와 상기 디스펜서 간 페어링 과정을 다시 수행하는 단계;를 포함하는, 수소 연료공급을 위한 통신 방법.
- 제2항에 있어서,상기 페어링 과정을 다시 수행하는 단계에서 상기 모빌리티와 상기 디스펜서 간 공유되는 페어링 정보는 상기 모빌리티와 상기 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함하고,상기 상호운용성 또는 호환성 관련 정보는,상기 모빌리티와 상기 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 상기 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함하는,수소 연료공급을 위한 통신 방법.
- 제2항에 있어서,상기 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 상기 모빌리티와 상기 디스펜서 간에 다시 협상하는 단계;를 더 포함하는,수소 연료공급을 위한 통신 방법.
- 제2항에 있어서,상기 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 상기 모빌리티와 상기 디스펜서 간에 다시 협상하는 단계;를 더 포함하고,상기 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 상기 제2 연료공급 프로토콜이 결정되는,수소 연료공급을 위한 통신 방법.
- 제1항에 있어서,상기 페어링 과정의 체크가 수행된 이후에, 상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정 이전에 상기 모빌리티와 상기 디스펜서 간 제1 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-인 단계; 및상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정 이후 및 모빌리티에서 노즐이 분리되기 전에, 상기 모빌리티와 상기 디스펜서 간 제2 필요 안전 조건(necessary safety condition)이 충족되는지 여부를 체크하는 체크-아웃 단계;를 더 포함하는,수소 연료공급을 위한 통신 방법.
- 제1항에 있어서,상기 페어링 과정의 체크 결과에 기반하여, 안전에 치명적이지 않은 에러(non-safety-critical error)를 검출하고 핸들링하는 단계;를 더 포함하는,수소 연료공급을 위한 통신 방법.
- 제1항에 있어서,상기 페어링 과정의 체크 결과에 기반하여, 상기 디스펜서 및 상기 모빌리티 간 상호 동작을 중지해야 하는 긴급상황을 검출하고 핸들링하는 단계;를 더 포함하는,수소 연료공급을 위한 통신 방법.
- 제5항에 있어서,상기 제2 연료공급 프로토콜을 다시 협상하는 단계는,상기 모빌리티와 상기 디스펜서 간 상기 제2 연료공급 프로토콜과 연계되는 통신 프로토콜을 다시 협상하는 단계;상기 통신 프로토콜에 기반하여, 상기 모빌리티와 상기 디스펜서 간 상기 제2 연료공급 프로토콜을 다시 협상하는 단계; 및상기 제2 연료공급 프로토콜에 기반하여, 상기 모빌리티와 상기 디스펜서 간 연료공급 파라미터를 다시 협상하는 단계;를 포함하는,수소 연료공급을 위한 통신 방법.
- 제5항에 있어서,상기 제2 연료공급 프로토콜을 다시 협상하는 단계에서,상기 디스펜서 및 상기 모빌리티 간에 전송되는 통신 프로토콜 또는 연료공급 프로토콜의 정보는 프로토콜 이름, 인덱스, 버전, 우선순위 또는 선호도를 포함하는,수소 연료공급을 위한 통신 방법.
- 수소 연료 모빌리티에 수소를 연료공급하는 디스펜서의 통신 장치에 의하여 수행되는, 수소 연료공급(fueling)을 위한 통신 방법으로서,상기 모빌리티와 상기 디스펜서 간 페어링 과정의 결과에 기반하여, 상기 모빌리티와 상기 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하는 단계; 및안전 체크인 과정이 수행되기 전에, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행하는 단계;를 포함하는, 수소 연료공급을 위한 통신 방법.
- 제11항에 있어서,상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계;를 더 포함하고,상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정되는 단계는,상기 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하는 단계;를 포함하고,상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행하는 단계는,상기 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 상기 모빌리티와 상기 디스펜서 간 페어링 과정을 다시 수행하는 단계;를 포함하는, 수소 연료공급을 위한 통신 방법.
- 제12항에 있어서,상기 페어링 과정을 다시 수행하는 단계에서 상기 모빌리티와 상기 디스펜서 간 공유되는 페어링 정보는 상기 모빌리티와 상기 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함하고,상기 상호운용성 또는 호환성 관련 정보는,상기 모빌리티와 상기 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 상기 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함하는,수소 연료공급을 위한 통신 방법.
- 제12항에 있어서,상기 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 상기 모빌리티와 상기 디스펜서 간에 다시 협상하는 단계;를 더 포함하는,수소 연료공급을 위한 통신 방법.
- 제12항에 있어서,상기 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 상기 모빌리티와 상기 디스펜서 간에 다시 협상하는 단계;를 더 포함하고,상기 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 상기 제2 연료공급 프로토콜이 결정되는,수소 연료공급을 위한 통신 방법.
- 수소 연료 모빌리티에 배치되는, 수소 연료공급을 위한 통신 장치로서,적어도 하나 이상의 명령을 저장하는 메모리; 및상기 적어도 하나의 명령을 실행하는 프로세서를 포함하고,상기 프로세서는, 상기 적어도 하나 이상의 명령에 의하여,상기 모빌리티에 수소를 연료공급하는 디스펜서와 상기 모빌리티 간 페어링 과정의 결과에 기반하여, 상기 모빌리티와 상기 디스펜서 간 제1 연료공급 프로토콜에 대한 정보를 교환하고,안전 체크인 과정이 수행되기 전에, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행하는, 통신 장치.
- 제16항에 있어서,상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정되고,상기 프로세서는, 상기 제1 연료공급 프로토콜에 대한 정보에 기반하여 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크가 요구되는 지 여부가 판정될 때,상기 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부를 판정하고,상기 프로세서는, 상기 페어링 과정의 체크가 요구되면, 상기 모빌리티와 상기 디스펜서 간 상기 페어링 과정의 체크를 수행할 때,상기 제1 연료공급 프로토콜에 대한 정보가 안전 체크인 유즈 케이스에 대한 정보를 포함하지 않으면, 상기 모빌리티와 상기 디스펜서 간 페어링 과정을 다시 수행하는,통신 장치.
- 제17항에 있어서,상기 프로세서가 상기 페어링 과정을 다시 수행할 때,상기 모빌리티와 상기 디스펜서 간 공유되는 페어링 정보는 상기 모빌리티와 상기 디스펜서 간 상호운용성 또는 호환성 관련 정보를 포함하고,상기 상호운용성 또는 호환성 관련 정보는, 상기 모빌리티와 상기 디스펜서 간 교환되는 연료공급 프로토콜에 대한 정보가, 상기 연료공급 프로토콜이 안전 체크인 유즈 케이스에 대한 정보를 포함하는 지 여부에 대한 정보를 포함하는,통신 장치.
- 제17항에 있어서,상기 프로세서는, 상기 적어도 하나 이상의 명령에 의하여,상기 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정을 위한 통신 프로토콜 또는 연료공급 프로토콜을, 상기 모빌리티와 상기 디스펜서 간에 다시 협상하는,통신 장치.
- 제17항에 있어서,상기 프로세서는, 상기 적어도 하나 이상의 명령에 의하여,상기 페어링 과정을 다시 수행하는 단계의 결과에 기반하여, 상기 디스펜서가 상기 모빌리티로 수소를 연료공급하는 과정을 위한 제2 연료공급 프로토콜을, 상기 모빌리티와 상기 디스펜서 간에 다시 협상하고,상기 제2 연료공급 프로토콜에 대한 정보는 안전 체크인 유즈 케이스에 대한 정보를 포함하도록 상기 제2 연료공급 프로토콜이 결정되는,통신 장치.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR20230136536 | 2023-10-13 | ||
| KR10-2023-0136536 | 2023-10-13 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025080025A1 true WO2025080025A1 (ko) | 2025-04-17 |
Family
ID=95396043
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2024/015413 Pending WO2025080025A1 (ko) | 2023-10-13 | 2024-10-11 | 개선된 안전 체크인 프로세스를 포함하는 수소 연료공급을 위한 양방향 통신 방법 및 장치 |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR20250053755A (ko) |
| WO (1) | WO2025080025A1 (ko) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2011033068A (ja) * | 2009-07-30 | 2011-02-17 | Toyota Motor Corp | ガス充填システム |
| KR20150048725A (ko) * | 2012-08-29 | 2015-05-07 | 실버레이크 모빌리티 에코시스템 에스디엔 비에이치디 | 모바일 디바이스들을 페어링하는 방법 |
| JP2019002515A (ja) * | 2017-06-16 | 2019-01-10 | 株式会社タツノ | 水素充填装置 |
| KR20210130193A (ko) * | 2019-02-18 | 2021-10-29 | 니콜라 코퍼레이션 | 수소 연료보급 및 전기 충전을 위한 통신 시스템들 및 방법들 |
| KR20230051193A (ko) * | 2020-07-13 | 2023-04-17 | 아이비스 인크. | 수소 연료공급 시스템 및 방법 |
-
2024
- 2024-10-11 KR KR1020240138726A patent/KR20250053755A/ko active Pending
- 2024-10-11 WO PCT/KR2024/015413 patent/WO2025080025A1/ko active Pending
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2011033068A (ja) * | 2009-07-30 | 2011-02-17 | Toyota Motor Corp | ガス充填システム |
| KR20150048725A (ko) * | 2012-08-29 | 2015-05-07 | 실버레이크 모빌리티 에코시스템 에스디엔 비에이치디 | 모바일 디바이스들을 페어링하는 방법 |
| JP2019002515A (ja) * | 2017-06-16 | 2019-01-10 | 株式会社タツノ | 水素充填装置 |
| KR20210130193A (ko) * | 2019-02-18 | 2021-10-29 | 니콜라 코퍼레이션 | 수소 연료보급 및 전기 충전을 위한 통신 시스템들 및 방법들 |
| KR20230051193A (ko) * | 2020-07-13 | 2023-04-17 | 아이비스 인크. | 수소 연료공급 시스템 및 방법 |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20250053755A (ko) | 2025-04-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020197267A1 (ko) | 무선전력 전송 시스템에서 전력 보정을 수행하는 장치 및 방법 | |
| WO2024072193A1 (ko) | 수소 충전을 위한 통신 상의 파라미터 교환 방법 및 이를 이용하는 장치 | |
| WO2023282548A1 (ko) | 무선 전력 전송 시스템에서 mpp와의 호환성을 제공하는 방법 및 장치 | |
| WO2022030960A1 (en) | Apparatus and methods for linkage of or profile transfer between devices | |
| WO2021010696A1 (ko) | 무선전력 전송장치와 무선전력 수신장치 사이의 상호 인증 및 재인증 방법 및 이를 이용한 무선전력 전송장치와 무선전력 수신장치 | |
| WO2024005604A1 (ko) | 전기차 충전을 위한 무선랜 기반의 충전 통신 장치 및 방법 | |
| WO2024019543A1 (ko) | 수소 충전 통신 양방향 프로세스 및 이를 이용하는 장치 | |
| WO2023277671A1 (ko) | 무선 전력 전송 시스템에서 프로파일 간 호환성 확보 방법 및 장치 | |
| WO2023075570A1 (ko) | 무선 전력 전송 시스템에서 인증 방법 및 장치 | |
| WO2024167286A1 (ko) | 수소 충전을 위한 통신 방법 및 장치 | |
| WO2025080025A1 (ko) | 개선된 안전 체크인 프로세스를 포함하는 수소 연료공급을 위한 양방향 통신 방법 및 장치 | |
| WO2024075967A1 (ko) | 무선 전력 전송 시스템에서 빠른 인증을 통해 고전력 모드에서 무선 재충전을 수행하는 방법 및 장치 | |
| WO2025058350A1 (ko) | 수소 연료공급을 위한 양방향 통신 방법 및 장치 | |
| WO2025023689A1 (ko) | 수소 연료공급을 위한 양방향 통신 방법 및 장치 | |
| WO2024253489A1 (ko) | 수소 연료공급을 위한 양방향 통신 방법 및 장치 | |
| WO2024242512A1 (ko) | 수소 연료공급 프로토콜을 부트스트랩핑하는 방법 및 장치 | |
| WO2024186152A1 (ko) | 에러 및 이머전시를 핸들링하는 수소 충전을 위한 통신 방법 및 장치 | |
| WO2024181826A1 (ko) | 상호운용성에 기반한 수소 충전을 위한 통신 방법 및 장치 | |
| WO2024172634A1 (ko) | 수소 충전의 모니터링 및 제어를 위한 통신 방법 및 장치 | |
| WO2023090849A1 (ko) | 무선 전력 전송 시스템에서 슬롯 생성 방법 및 장치 | |
| WO2022220660A1 (ko) | 무선 전력 전송 시스템에서 품질 인자를 측정하는 방법 및 장치 | |
| WO2025005721A1 (ko) | 수소 연료공급 양방향 통신 방법 및 장치 | |
| WO2025239633A1 (ko) | 수소 연료공급을 위한 보안 통신 방법 및 통신 장치 | |
| WO2021054808A1 (ko) | 기기 간 번들 이동 후 번들의 상태를 설정하는 방법 및 장치 | |
| WO2026071652A1 (ko) | 수소 연료공급을 위한 통신 방법 및 통신 장치 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24877560 Country of ref document: EP Kind code of ref document: A1 |