Why this environment matters
At a public charger, payment success and permission to energise a connector are different decisions. A charger may need to authenticate a driver, communicate with an operator and coordinate power electronics during the same session. This proposal separates those responsibilities so a fault in the commercial interface has less authority over charging hardware.
The security challenge
A driver could begin with a card, an app or a vehicle credential. Each path introduces different messages and backend dependencies. A deployment concept would normalise these into a short-lived session record containing the authorised connector, spending or energy limit, and expiry. It would avoid giving the payment interface a general hardware-control capability.
How the capsule model could help
The control side would independently check connector state and the manufacturer’s electrical conditions before acting on an authorised energy request. NØNOS capsules could separate the user interface, operator protocol client and device adapter, provided the required hardware support exists. The electrical protection chain would remain responsible for unsafe physical conditions. Loss of connectivity during a session creates a business decision as well as a technical one. The operator might permit a bounded offline allowance or require a controlled stop. That choice should be explicit and testable; a network timeout must not accidentally become unlimited charging or an unexplained locked connector. Metering events would need durable reconciliation outside temporary process memory. After reconnecting, the system should distinguish a resent receipt from a new charge and should retain enough evidence to resolve a disputed session. A RAM-resident operating model is not a substitute for a billing ledger.
Deployment requirements
This is an architecture study for charger manufacturers and operators. Connector interoperability, electrical safety, metrology and payment compliance require their own evidence. A secure operating-system component alone would not establish them. Evaluation requirements: Disconnect the operator service during an active session and verify the documented offline allowance or controlled-stop behavior. Replay a payment approval against a different connector; it should not authorise that connector. Restart the interface between metering and receipt upload, then reconcile the session without duplicate billing or missing energy records.
Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.
Follow one charging session from payment to contactor
A driver could begin with a card, an app or a vehicle credential. Each path introduces different messages and backend dependencies. A deployment concept would normalise these into a short-lived session record containing the authorised connector, spending or energy limit, and expiry. It would avoid giving the payment interface a general hardware-control capability.
The control side would independently check connector state and the manufacturer’s electrical conditions before acting on an authorised energy request. NØNOS capsules could separate the user interface, operator protocol client and device adapter, provided the required hardware support exists. The electrical protection chain would remain responsible for unsafe physical conditions.
What happens when the cloud disappears?
Loss of connectivity during a session creates a business decision as well as a technical one. The operator might permit a bounded offline allowance or require a controlled stop. That choice should be explicit and testable; a network timeout must not accidentally become unlimited charging or an unexplained locked connector.
Metering events would need durable reconciliation outside temporary process memory. After reconnecting, the system should distinguish a resent receipt from a new charge and should retain enough evidence to resolve a disputed session. A RAM-resident operating model is not a substitute for a billing ledger.
Who could buy or integrate it?
- Charger manufacturers integrating controller software
- Charge-point operators procuring managed charging hardware
- Fleet depot integrators configuring charger and site controls
Industry examples: ChargePoint, ABB. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.