Management device, management system, management method, and recording medium
The management device records the identifier and position information of the battery device, determines the legitimacy of the battery device, outputs authentication invalid information to stop the starting processing, solves the problem of failure caused by the improper battery device in the electric vehicle, and effectively suppresses the improper battery device.
Patent Information
- Application Number
- CN202080071255.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-05-18
- Filing Date
- 2020-12-28
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2040-12-28
AI Technical Summary
In the prior art, improper use of battery devices for electric vehicles may lead to poor vehicle movement or malfunction, making it difficult to effectively suppress the use of improper battery devices.
The management device records the identifier and position information of the battery device multiple times, determines whether the same identifier is associated with the multiple position information, and outputs authentication invalid information when it is determined to be associated, causing the authentication processing of the battery device to fail, thereby aborting the starting processing of the vehicle.
It effectively suppresses the use of improper battery devices, prevents vehicle failures caused by improper battery devices, and improves the safety and reliability of electric vehicles.
Smart Images

Figure CN114514137B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a management device, a management system, a management method and a program. Background Art
[0002] There are vehicles such as electric bicycles and electric vehicles that are equipped with secondary batteries (also referred to as battery devices) and are driven by electric power.
[0003] Conventionally, there is a technology for detecting an abnormal (illegal) charging and discharging device connected to an electric vehicle or the like to prevent the connection of the abnormal (illegal) charging and discharging device (see Patent Document 1).
[0004] Prior art literature
[0005] Patent Document 1: Patent No. 5999566 Summary of the Invention
[0006] Problems to be solved by the invention
[0007] There is a problem that when an improper (illegal) battery device is used instead of a proper (legal) battery device for a vehicle, there is a possibility that the driving of the vehicle may be malfunctioned.
[0008] Therefore, the present invention provides a management device and the like that suppresses inappropriate use of a battery device.
[0009] Means used to solve problems
[0010] A management device according to one technical solution of the present invention is a management device for managing the legitimacy of a battery device used as a power source of a vehicle, and comprises: a management unit, which obtains an identifier of the battery device and location information indicating the location of the battery device multiple times, and maintains management information that records the identifier obtained and the location information by associating them each time; a determination unit, which refers to the management information to determine whether the same identifier is associated with multiple different location information at a time point; and an output unit, which outputs information that invalidates authentication related to the battery device when the determination unit determines that one identifier is associated with multiple location information, and after the information is output, terminates the start-up process of the vehicle based on the fact that authentication failed in the authentication process performed by the vehicle and the battery device.
[0011] In addition, these general or specific technical solutions can be implemented by systems, methods, integrated circuits, computer programs or computer-readable recording media such as CD-ROMs, or by any combination of systems, devices, integrated circuits, computer programs and recording media.
[0012] Effects of the Invention
[0013] The management device of the present invention can suppress improper use of battery devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 It is a block diagram schematically showing the configuration of a management system according to an embodiment.
[0015] Figure 2 This is a block diagram showing the functions of each device constituting the management system according to the embodiment.
[0016] Figure 3 This is an explanatory diagram showing a first example of management information according to the embodiment.
[0017] Figure 4 This is an explanatory diagram showing a second example of management information according to the embodiment.
[0018] Figure 5 It is an explanatory diagram showing a third example of management information according to the embodiment.
[0019] Figure 6 This is an explanatory diagram showing an example of a revocation list according to the embodiment.
[0020] Figure 7 This is a flowchart showing the processing of the vehicle according to the embodiment.
[0021] Figure 8 This is a flowchart showing the first process of the management device according to the embodiment.
[0022] Figure 9 This is a sequence diagram showing the first process of the management system according to the embodiment.
[0023] Figure 10 This is a flowchart showing the second process of the management device according to the embodiment.
[0024] Figure 11 This is a sequence diagram showing the second process of the management system according to the embodiment.
[0025] Figure 12 It is a block diagram schematically showing the configuration of a management device according to a modified example of the embodiment.
[0026] Figure 13 This is a flowchart showing the processing of the management device according to a modified example of the embodiment. DETAILED DESCRIPTION
[0027] (Foundation that forms the basis of the present invention)
[0028] The present inventors have discovered that the following problems may occur with respect to the technologies related to electric vehicles described in the "Background Art" column.
[0029] As one of the transportation tools driven by electric power, there is an electric vehicle (hereinafter, also simply referred to as a vehicle). Hereinafter, a technical solution for using the above transportation tool will be described by taking a vehicle as an example.
[0030] Furthermore, electric vehicles include electric bicycles, electric cars, electric two-wheeled vehicles, electric scooters, etc. Furthermore, vehicles driven by electricity include not only vehicles but also drones that people can ride on.
[0031] One of the vehicle service methods is a service method in which a business operator charges a battery device and rents it to a user. The user connects the battery device and uses the vehicle. After use, the battery device is returned and then recharged by the business operator and rented to the user.
[0032] In this service method, the vehicle is sequentially connected to a number of battery devices. Some of these battery devices are officially manufactured for the vehicle (also known as legitimate battery devices), while others are not (also known as inappropriate battery devices). Using an inappropriate battery device to drive the vehicle may cause malfunction or failure.
[0033] Therefore, in order to prevent improper use of battery devices, it is assumed that an authentication chip is installed in the battery device. When the vehicle is started, the battery device is authenticated during the startup process, and the vehicle starts after confirming that the battery device has a valid authentication chip.
[0034] In this case, if the authentication information stored in the authentication chip of a legitimate battery device is extracted and copied to another battery device, an unauthorized battery device may exist with the same authentication information as the legitimate battery device. If such an unauthorized battery device is connected to a vehicle, the authentication process between the vehicle and the battery device will succeed. As a result, the vehicle may be driven using the unauthorized battery device, which may cause problems or failures.
[0035] Therefore, it is sought to suppress the improper use of battery devices.
[0036] The present invention provides a management device and the like for suppressing inappropriate use of a battery device.
[0037] A management device according to one technical solution of the present invention is a management device for managing the legitimacy of a battery device used as a power source of a vehicle, and comprises: a management unit, which obtains an identifier of the battery device and location information indicating the location of the battery device multiple times, and maintains management information that records the identifier obtained and the location information by associating them each time; a determination unit, which refers to the management information to determine whether the same identifier is associated with multiple different location information at a time point; and an output unit, which outputs information that invalidates authentication related to the battery device when the determination unit determines that one identifier is associated with multiple location information, and after the information is output, terminates the start-up process of the vehicle based on the fact that authentication failed in the authentication process performed by the vehicle and the battery device.
[0038] According to the above technical solution, the management device determines whether the same identifier of a battery device is associated with multiple pieces of location information by referring to the management information, thereby managing whether the inherent information of the battery device has been illegally copied. The battery device identifier is inherent to the battery device, and each battery device is assigned one identifier. Therefore, the reason why the same identifier is associated with multiple pieces of location information is that the inherent information of the battery device has been copied, and the inherent information has become possessed by multiple battery devices. Furthermore, the management device outputs a message that invalidates the authentication of the battery device, thereby terminating the vehicle startup process, thereby helping to prevent the use of the battery device. In this way, the management device can prevent the improper use of battery devices.
[0039] In addition, it may also be that the authentication process is an authentication process using a public key, and the output unit outputs, as the information, expiration information that invalidates the public key certificate of the battery device to the certification authority. After the expiration information is output to the certification authority, the vehicle uses the expiration information obtained from the certification authority to terminate the start-up process of the vehicle based on the fact that the authentication failed in the authentication process using the public key performed on the vehicle and the battery device.
[0040] According to the above technical solution, the management device uses the output information to determine if the authentication process using the public key between the vehicle and the battery device has failed, thereby terminating the vehicle startup process. This makes it easier for the management device to prevent an improper battery device from being connected to the vehicle and used. This makes it easier for the management device to prevent improper battery device use.
[0041] Furthermore, the management unit may obtain the identifier and the position information provided in the activation process of the vehicle, and the output unit may output information for terminating the activation process to the vehicle as the output of the information.
[0042] According to the above technical solution, the management device obtains the identifier and location information provided during the vehicle startup process. If it determines that the same identifier is associated with multiple pieces of location information, it aborts the ongoing startup process. This prevents vehicles connected to an inappropriate battery device from failing to start. This allows the management device to more effectively prevent the use of inappropriate battery devices.
[0043] Furthermore, the management unit may acquire the identifier and the position information provided when the battery device is connected to a charging device.
[0044] According to the above technical solution, the management device obtains the identifier and location information provided when the battery device is connected to the charging device, and determines that the same identifier is associated with multiple locations. Therefore, the management device can detect improper battery devices when the battery device is connected to the charging device and prevent their subsequent use. Thus, by confirming the legitimacy of the battery device when connected to the charging device, the management device can more effectively prevent the use of improper battery devices.
[0045] Furthermore, the management unit may acquire, as the position information, position information acquired by a position sensor included in a terminal owned by a person riding the transportation vehicle.
[0046] According to the above technical solution, the management device uses the location information of the terminal owned by the person riding in the vehicle as the location information of the battery device. When the person who owns the terminal rides in the vehicle, since the battery device and the user's terminal are located at a close distance (for example, within a few tens of centimeters or about 1 meter), it is considered that it is not a big deal even if the location information obtained by the terminal is used as the location information of the battery device. In addition, generally speaking, most terminals have position sensors. Therefore, when the battery device does not have a position sensor, the management device can use the position sensor of the terminal to replace the location information of the battery device, and can manage the legitimacy of the battery device. Therefore, the management device can suppress the improper use of the battery device even if the battery device does not have a position sensor.
[0047] A management system according to one aspect of the present invention includes the aforementioned management device and the vehicle using the battery device, the legitimacy of which is managed by the management device, as a power source.
[0048] According to the above technical solution, the management system is composed of a management device and a vehicle, and has the same effect as the management device.
[0049] Furthermore, the management system may further include the battery device used as a power source of the vehicle.
[0050] According to the above technical solution, the management system is composed of a management device, a vehicle and a battery device, and has the same effect as the management device.
[0051] A management method according to a technical solution of the present invention is a management method for managing the legitimacy of a battery device used as a power source for a vehicle, comprising: a management step of acquiring an identifier of the battery device and location information indicating the location of the battery device multiple times, and retaining management information that records the identifier acquired and the location information by associating them each time; a determination step of determining, with reference to the management information, whether the same identifier is associated with a plurality of location information that are different from each other at a point in time; and an output step of outputting information that invalidates authentication associated with the battery device when it is determined in the determination step that one identifier is associated with a plurality of location information, and after the information is output, terminating the start-up process of the vehicle based on the fact that authentication failed in the authentication process performed by the vehicle and the battery device.
[0052] According to the above technical solution, the same effect as the above management device is achieved.
[0053] Furthermore, a program according to one aspect of the present invention is a program for causing a computer to execute the above-mentioned management method.
[0054] The above technical solution has the same effect as the above management method.
[0055] In addition, these general or specific technical solutions can be implemented by systems, methods, integrated circuits, computer programs or recording media such as computer-readable CD-ROMs, or by any combination of systems, devices, integrated circuits, computer programs or recording media.
[0056] Hereinafter, embodiments will be described in detail with reference to the drawings.
[0057] In addition, the embodiments described below are all general or specific examples. The numerical values, shapes, materials, components, configuration positions of components, connection methods, steps, and the order of steps shown in the following embodiments are examples and are not intended to limit the present invention. In addition, among the components of the following embodiments, components that are not described in the independent claims representing the most general concepts are described as arbitrary components.
[0058] (Implementation Method)
[0059] In this embodiment, a management device and the like that suppresses inappropriate use of a battery device will be described.
[0060] Figure 1 It is a block diagram schematically showing the configuration of the management system 1 according to the present embodiment.
[0061] like Figure 1 As shown, the management system 1 includes a management device 10 and a vehicle 20. The management system 1 may also include a battery device 30. The management system 1 uses a terminal 40, an authentication authority 50, and a charging device 60 to prevent improper use of the battery device 30.
[0062] The management device 10 is a computer that manages the legitimacy of the battery device 30. At a predetermined timing, the management device 10 obtains the battery device 30 identifier and location information indicating the location of the battery device 30. By determining whether the same identifier is associated with multiple pieces of different location information, the management device 10 determines the legitimacy of the battery device 30 and outputs the result.
[0063] Vehicle 20 is an electric vehicle powered by electricity supplied from battery device 30. Examples of vehicle 20 include electric bicycles, electric cars, electric two-wheeled vehicles, and electric scooters. Furthermore, vehicle 20 can be, more generally, a vehicle powered by electricity or, for example, a passenger-carrying drone. During startup, vehicle 20 transmits the identifier and location information of the connected battery device 30 to management device 10. Furthermore, vehicle 20 is controlled by, for example, certification authority 50 so that it will not start if an inappropriate battery device 30 is connected.
[0064] The battery device 30 is a device that includes a battery used as a power source for the vehicle 20. The battery device 30 includes a secondary battery and is charged by the charging device 60. Alternatively, the battery device 30 may be charged at a facility separate from the charging device 60 (e.g., the home of the user U or a parking lot at a shopping mall).
[0065] The terminal 40 is an information terminal owned by the user U of the vehicle 20, such as a mobile phone, a smartphone, or a tablet. The terminal 40 is connected to the network N via a mobile phone line (3G, 4G, LTE (Long Term Evolution)) or Wi-Fi (registered trademark), and can communicate with each device constituting the management system 1 via the network N. In addition, the terminal 40 can communicate with the vehicle 20 via short-range wireless communication (such as Bluetooth (registered trademark)). When the terminal 40 receives an operation of a start instruction to start the vehicle 20 from the user U, the vehicle 20 performs a start process. During the start process, if the authentication between the vehicle 20 and the battery device 30 is successful, the vehicle 20 starts and can be driven. On the other hand, if the authentication fails, the vehicle 20 does not start.
[0066] The certification authority 50 is a computer that issues and manages the authentication information of each device that constitutes the management system 1. Specifically, the certification authority 50 issues and manages the certificates of the public keys of each device that constitutes the management system 1 (also called public key certificates). In addition, the certification authority 50 manages a revocation list, which indicates the certificates that have expired among the issued public key certificates. When the certification authority 50 receives from the management device 10 the identifier of the battery device 30 that is judged by the management device 10 to be improper (that is, inappropriate), the information that invalidates the public key certificate of the battery device 30 is added to the revocation list. The revocation list to which the information that invalidates the public key certificate of the battery device 30 is added is subsequently obtained by the vehicle 20 and used in the authentication process of the vehicle 20 and the battery device 30. As a result, based on the fact that the public key certificate of the battery device 30 is invalid, the startup process of the vehicle 20 fails.
[0067] The charging device 60 supplies power to the battery device 30 for charging. The charging device 60 is connected to one or more battery devices and supplies power to each of the one or more battery devices 30. When the charging device 60 is connected to a battery device 30, it transmits the identifier of the connected battery device 30 to the management device 10.
[0068] Figure 2 This is a block diagram showing the functions of each device constituting the management system 1 of this embodiment. Figure 2 And explain the structure of each device.
[0069] like Figure 2 As shown, the management device 10 includes an authentication unit 11, a management unit 12, a determination unit 13, and an output unit 14. Each functional unit of the management device 10 is implemented by a CPU (Central Processing Unit) (not shown) of the management device 10 executing a program using a memory.
[0070] The authentication unit 11 is a functional unit that performs authentication processing for the authentication unit 21 of the vehicle 20 and the authentication unit 61 of the charging device 60. The authentication unit 11 stores the private key and public key certificate of the management device 10, as well as the public key of the certification authority 50. The authentication unit 11 performs authentication processing based on an authentication request received from the authentication unit 21 of the vehicle 20 via the terminal 40. Furthermore, the authentication unit 11 performs authentication processing based on an authentication request received from the authentication unit 61 of the charging device 60.
[0071] The management unit 12 is a functional unit that stores management information obtained by associating the battery device 30's identifier with its location information. The management unit 12 obtains the battery device 30's identifier and location information indicating the battery device 30's location multiple times, and stores management information that records the identifier and location information obtained each time. The management unit 12 acquires the battery device 30's identifier and location information, for example, when the vehicle 20 is started while the battery device 30 is connected to the vehicle 20. Another example of this acquisition is when the battery device 30 is connected to the charging device 60, the management unit 12 acquires the identifier and location information provided by the charging device 60 and the charging device 60's identifier. Here, it is assumed that the charging device 60's identifier and location information are associated in a one-to-one manner.
[0072] The determination unit 13 is a functional unit that determines the legitimacy of the battery device 30. The determination unit 13 refers to the management information held by the management unit 12 and determines whether the same identifier is associated with a plurality of different pieces of location information at a time point.
[0073] The output unit 14 is a processing unit that outputs information indicating the result of the determination by the determination unit 13. When the determination unit 13 determines that one identifier is associated with a plurality of pieces of position information, the output unit 14 outputs information indicating that the battery device 30 is unsuitable.
[0074] More specifically, the output unit 14 outputs, as the information, information for invalidating the authentication related to the battery device 30. In this case, after outputting the information, the output unit 14 fails the startup process of the vehicle 20 based on the fact that the authentication process performed between the vehicle 20 and the battery device 30 has failed.
[0075] The authentication process is, for example, an authentication process using a public key. In this case, the output unit 14 outputs, as the above-mentioned information, revocation information that invalidates the public key certificate of the battery device 30 to the authentication authority 50. The output unit 14 uses the revocation information obtained by the vehicle 20 from the authentication authority 50 after the revocation information is output to the authentication authority 50 to fail the startup process of the vehicle 20 based on the fact that the authentication process using the public key performed between the vehicle 20 and the battery device 30 failed.
[0076] Furthermore, the management unit 12 acquires the identifier and position information provided during the activation process of the vehicle 20 , and the output unit 14 may output information for terminating the activation process to the vehicle 20 as output of the above information.
[0077] In addition, if Figure 2 As shown, the vehicle 20 includes: an authentication unit 21, a control unit 22, and a drive unit 23. The various functional units of the vehicle 20 are implemented by executing programs using a memory using a CPU (not shown) of the management device 10. The connection between the vehicle 20 and the battery device 30 includes a connection based on a communication line and an electrical connection that can transfer power. In addition, when the vehicle 20 is started, the vehicle 20 and the terminal 40 can be connected in a communicative manner through short-range wireless communication, and the vehicle 20 can communicate with the management device 10 via the terminal 40. In addition, in the case where the vehicle 20 has a communication interface that is directly connected to the network N, the vehicle 20 can also communicate with the management device 10 without going through the terminal 40.
[0078] The authentication unit 21 is a functional unit that performs authentication processing for the authentication unit 31 of the battery device 30, the authentication unit 41 of the terminal 40, and the authentication unit 11 of the management device 10. The authentication unit 21 holds the private key and public key certificate of the vehicle 20, as well as the public key of the authentication authority 50. When the vehicle 20 receives a start command from the terminal 40, the authentication unit 21 sends an authentication request to the authentication unit 31 of the battery device 30 to perform the authentication process. Furthermore, the authentication unit 21 sends an authentication request to the authentication unit 41 of the terminal 40 to perform the authentication process. Furthermore, the authentication unit 21 sends an authentication request to the authentication unit 11 of the management device 10 via the terminal 40 to perform the authentication process. When performing authentication with the authentication unit 31 of the battery device 30, a revocation list is obtained from the authentication authority 50 via the terminal 40, and the authentication with the battery device 30 recorded in the obtained revocation list is unsuccessful.
[0079] The control unit 22 controls the startup process of the vehicle 20. When the vehicle 20 receives a startup command from the terminal 40, the control unit 22 starts the startup process. During the startup process, the control unit 22 obtains the identifier of the battery device 30 connected to the vehicle 20 through communication.
[0080] Furthermore, the control unit 22 obtains the location information obtained by the terminal 40 as the location information of the battery device 30. This is because, when the vehicle 20 is started, the vehicle 20 and the terminal 40 are within a range that allows for near-field wireless communication (e.g., within a few meters), and the vehicle 20 and the battery device 30 are within a distance that allows for connection (e.g., within a few centimeters). Therefore, it is not a problem to use the location information obtained by the terminal 40 as the location information of the battery device 30. Furthermore, if the vehicle 20 or the battery device 30 is equipped with a position sensor, the location information obtained by the position sensor of the vehicle 20 or the battery device 30 may also be used as the location information of the battery device 30.
[0081] Furthermore, the control unit 22 transmits the acquired identifier and position information of the battery device 30 to the management device 10 .
[0082] Furthermore, during the startup process, the control unit 22 performs authentication of the battery device 30 by the authentication unit 21. If the authentication succeeds, the startup process continues. On the other hand, if the authentication fails, the startup process is terminated, thereby terminating the startup of the drive unit 23.
[0083] The drive unit 23 is a functional unit that drives the vehicle 20. It includes components related to driving the vehicle 20, such as a motor, brakes, steering, and axles. Furthermore, the drive unit 23 includes terminals for electrical connection to the battery unit 30 and receives power through the terminals. When the battery unit 30 is connected to the vehicle 20 and the startup process performed by the control unit 22 is successful, the drive unit 23 becomes drivable using power supplied from the battery unit 30.
[0084] The vehicle 20 may further include a presentation unit (not shown) that presents information by displaying on a screen or outputting sound, etc. When the startup process of the vehicle 20 is stopped, the presentation unit may present information indicating that the startup process is stopped.
[0085] In addition, if Figure 2 As shown, the battery device 30 includes an authentication unit 31 and a charge / discharge unit 32. Each functional unit of the battery device 30 is implemented by a CPU (not shown) included in the battery device 30 executing a program using a memory.
[0086] The authentication unit 31 is a functional unit that performs authentication processing with the authentication unit 21 of the vehicle 20. The authentication unit 31 holds the private key and public key certificate of the battery device 30 and the public key of the certification authority 50. The authentication unit 31 performs authentication processing in response to an authentication request received from the authentication unit 21 of the vehicle 20.
[0087] The charging and discharging unit 32 is a functional unit that charges and discharges electric power. The charging and discharging unit 32 has terminals for electrical connection to the vehicle 20. The charging and discharging unit 32 includes a storage element that charges and discharges electric power, a charging circuit that charges the storage element with electric power, and a discharging circuit that discharges the electric power from the storage element and supplies it to the vehicle 20. The charging and discharging unit 32 supplies electric power to the vehicle 20 via the terminals.
[0088] In addition, if Figure 2 As shown, terminal 40 includes an authentication unit 41, a position sensor 42, a reception unit 43, a presentation unit 44, and a startup control unit 45. Each functional unit of terminal 40 is implemented by a CPU (not shown) in terminal 40 executing a program using a memory.
[0089] The authentication unit 41 is a functional unit that performs authentication processing with the authentication unit 21 of the vehicle 20. The authentication unit 41 stores the private key and public key certificate of the terminal 40, and the public key of the certification authority 50. The authentication unit 41 performs authentication processing in response to an authentication request received from the authentication unit 21 of the vehicle 20. If the authentication processing is successful, the authentication unit 41 relays communication data between the vehicle 20 and the management device 10, thereby establishing communication between the vehicle 20 and the management device 10.
[0090] The position sensor 42 is a sensor that acquires position information indicating the position of the terminal 40. The position sensor 42 is, for example, a GPS (Global Positioning System) receiver that acquires the position information of the terminal 40. The position information acquired by the position sensor 42 is provided to the vehicle 20.
[0091] The receiving unit 43 is a functional unit that receives various operations from the user U. The receiving unit 43 receives an operation to start the vehicle 20. The receiving unit 43 receives various operations in various ways, such as touch input on an image displayed on the touch-panel display or voice input. In the case of touch input, the user U's operation is determined by identifying the location touched on the display screen by the user U. In the case of voice input, the user U's operation is determined by voice recognition processing that recognizes the voice uttered by the user U.
[0092] The presentation unit 44 is a functional unit that presents information through, for example, a display on a screen or an audio output. It is assumed that the presented information is visually recognized or heard by the user U. If the startup process of the vehicle 20 is aborted, the presentation unit 44 may present information indicating that the startup process has been aborted. Furthermore, if the startup process of the vehicle 20 continues without aborting and the startup is successful, the presentation unit 44 may present information indicating that the startup process was successful.
[0093] The start control unit 45 is a functional unit that controls the control unit 22 of the vehicle 20 to perform a start process of the vehicle 20 when the accepting unit 43 accepts an operation to start the vehicle 20 .
[0094] In addition, if Figure 2 As shown, the certification authority 50 includes an issuing unit 51 and a list management unit 52 .
[0095] The issuing unit 51 is a functional unit that issues public key certificates. Public key certificates are information that verifies that the public keys of the management device 10, vehicle 20, battery device 30, terminal 40, and charging device 60 are genuine. The issuing unit 51 creates public key certificates by appending the electronic signature of the certification authority 50 to information containing the public keys of these devices. The created public key certificates are then provided to these devices in advance.
[0096] The list management unit 52 is a functional unit that manages revocation information indicating revoked public key certificates among the public key certificates issued by the issuing unit 51. When revocation information indicating the revocation of the public key certificate of the battery device 30 is output from the output unit 14 of the management device 10, the list management unit 52 records information indicating the public key certificate of the battery device 30 in the revocation list. The revocation list is then provided to the authentication unit 21 of the vehicle 20 and utilized in the authentication process between the vehicle 20 and the battery device 30.
[0097] In addition, if Figure 2 As shown, the charging device 60 includes an authentication unit 61 , an acquisition unit 62 , and a power supply 63 .
[0098] The authentication unit 61 is a functional unit that performs authentication processing with the authentication unit 11 of the management device 10. The authentication unit 61 holds the private key of the charging device 60, the public key certificate, and the public key of the certification authority 50. The authentication unit 61 performs authentication processing based on an authentication request received from the authentication unit 11 of the management device 10.
[0099] The acquisition unit 62 is a functional unit that acquires the identifier of the battery device 30 connected to the charging device 60. The acquisition unit 62 acquires the identifier of the battery device 30 connected to the charging device 60 from the battery device 30 through communication and provides the acquired identifier to the management device 10.
[0100] Power supply 63 is a functional unit that charges battery device 30 connected to charging device 60 by supplying power. Power supply 63 receives power from a system power supply, power generation equipment, power storage equipment, or the like, and supplies the supplied power to battery device 30.
[0101] Hereinafter, management information held by the management unit 12 of the management device 10 and determination examples performed by the determination unit 13 will be described.
[0102] Figure 3 This is an explanatory diagram showing a first example of management information according to this embodiment. Figure 3 The management information shown is an example of the management information held by the management unit 12 of the management device 10 .
[0103] like Figure 3 As shown, the management information entry includes the following items: battery ID, connection destination, charging device ID, vehicle ID, location information, authentication time, connection start time, and connection end time. Each management information entry is generated when a battery device 30 is connected to a vehicle 20 or charging device 60.
[0104] The battery ID is an identifier for uniquely identifying the battery device 30 associated with the entry.
[0105] The connection destination is information indicating a destination to which the battery device 30 related to the entry is connected, and is information indicating the vehicle 20 or the charging device 60 .
[0106] The charging device ID indicates the identifier of the connected charging device 60 when the battery device 30 associated with the entry is connected to the charging device 60. Furthermore, it is assumed that the charging device ID is previously associated one-to-one with the location information of the location where the charging device 60 is installed. In this case, the charging device ID functions as location information indicating the location of the charging device 60.
[0107] The vehicle ID indicates an identifier of the connected vehicle 20 when the battery device 30 associated with the entry is connected to the vehicle 20 .
[0108] The location information includes the location information of the battery device 30 associated with the entry when the vehicle 20 is started. Furthermore, the location information is not necessarily required when the battery device 30 associated with the entry is connected to the charging device 60. In this case, the location information may be set to the predetermined location information of the charging device 60.
[0109] The authentication time is information indicating the time when the battery device 30 related to the entry is connected to the vehicle 20 and the authentication process between the battery device 30 and the vehicle 20 is successful.
[0110] The connection start time is information indicating the time at which the connection is started when the battery device 30 associated with the entry is connected to the charging device 60 .
[0111] The connection end time is information indicating the time when the battery device 30 associated with this entry was connected to the charging device 60 and the connection was completed. For a battery device 30 connected to the charging device 60, the connection end time is not set, so the time is not displayed. In this case, for example, "(Connecting)" may be displayed.
[0112] In this manner, the battery ID of the battery device 30 is associated with the location information and recorded in the management information. When the battery device 30 is connected to the vehicle 20, the location information of the battery device 30 is used. When the battery device 30 is connected to the charging device 60, the location information of the charging device 60 is used, which is associated one-to-one with the charging device ID.
[0113] Figure 3 The first row of the entry E1 shows that the battery device 30 with the battery ID B01345 is connected to the vehicle 20 with the vehicle ID "H224." Furthermore, the location information of the vehicle 20 at the time of startup is "35 degrees 40 minutes 8.4 seconds north latitude, 139 degrees 46 minutes 40.8 seconds east longitude," and the time when the authentication between the vehicle 20 and the battery device 30 was successful is "January 20, 2020, 7:45."
[0114] in addition, Figure 3 The entry E2 in the second row shows that the battery device 30 with the battery ID B97143 is connected to the charging device 60 with the charging device ID "ST221." It also shows that the connection with the charging device 60 started at "7:50 on January 20, 2020," and ended at "3:02 on January 20, 2020."
[0115] in addition, Figure 3 The entry E4 in the fourth row shows that the battery device 30 with the battery ID B74522 is connected to the charging device 60 with the charging device ID "ST003." Furthermore, the connection with the charging device 60 was started at 2:54 PM on January 20, 2020, indicating that the connection is in progress (i.e., not yet completed).
[0116] in addition, Figure 3 The fifth row of the entry E5 shows that the battery device 30 with the battery ID B97143 is connected to the vehicle 20 with the vehicle ID "H340." Furthermore, the location information of the vehicle 20 at the time of startup is "34 degrees 41 minutes 13.4 seconds north latitude, 135 degrees 31 minutes 31.7 seconds east longitude," and the time when the authentication between the vehicle 20 and the battery device 30 was successful is "January 20, 2020, 12:45."
[0117] That is, in Figure 3 In the management information shown, the battery device 30 with the battery ID B97143 is associated with the position information of the charging device 60 at the time of "12:45 on January 20, 2020" (see entry E2) and is also associated with the position information of the vehicle 20 (see entry E5).
[0118] In this manner, the determination unit 13 refers to the management information and determines that the same battery device ID is associated with a plurality of different pieces of position information at one point in time.
[0119] Figure 4 : is an explanatory diagram showing a second example of management information according to this embodiment. Figure 4 The management information shown is another example of the management information held by the management unit 12 of the management device 10. The items included in each entry of the management information are the same as Figure 3 The management information is the same as shown in the following table. Figure 3 Same as shown.
[0120] Figure 4 Item E6 in row 5 shows that battery device 30, whose battery ID is B01345, is connected to vehicle 20, whose vehicle ID is "H340." Furthermore, the location information of vehicle 20 at startup is "34 degrees 41 minutes 13.4 seconds north latitude, 135 degrees 31 minutes 31.7 seconds east longitude," and the time when authentication between vehicle 20 and battery device 30 was successful is "January 20, 2020, 7:45."
[0121] That is to say, in Figure 4 In the management information shown, the battery device 30 with battery ID B01345 is associated with the location information of the vehicle 20 with vehicle ID H224 at the time point of "7:45 on January 20, 2020" (see entry E1), and is also associated with the location information of the vehicle 20 with vehicle ID H340 (see entry E6).
[0122] In this manner, the determination unit 13 refers to the management information and determines that the same battery device ID is associated with a plurality of different pieces of position information at one point in time.
[0123] Figure 5 This is an explanatory diagram showing a third example of management information according to this embodiment. Figure 5 The management information shown is another example of the management information held by the management unit 12 of the management device 10. The items included in each entry of the management information are the same as Figure 3 The management information is the same as shown in the following table. Figure 3 Same as shown.
[0124] Figure 5 The fifth row, entry E7, shows that battery device 30, whose battery ID is B74522, is connected to charging device 60, whose charging device ID is "ST009." Furthermore, the connection with charging device 60 is shown to have started at 3:32 PM on January 20, 2020, and ended at 5:42 PM on January 20, 2020.
[0125] That is to say, in Figure 5 In the management information shown, the battery device 30 with battery ID B74522 is associated with the location information of the charging device 60 with charging device ID ST0003 at a time point after "15:32 on January 20, 2020" (see entry E4), and is associated with the location information of the charging device 60 with charging device ID ST0009 (see entry E7).
[0126] In this manner, the determination unit 13 refers to the management information and determines that the same battery device ID is associated with a plurality of different pieces of position information at one point in time.
[0127] Figure 6 This is an explanatory diagram showing an example of a revocation list according to this embodiment.
[0128] Figure 6 The revocation list shown is a list showing revoked public key certificates issued by the certification authority 50 .
[0129] One entry in the revocation list corresponds to one expired certificate and includes the expired certificate number, the date and time when the certificate expires.
[0130] For example, Figure 6 The entry in the first row of the revocation list shown shows that the public key certificate with certificate number 23534 expired at the time of "January 20, 2020, 12:45."
[0131] Figure 6 The entries in the revocation list shown are, for example, Figure 3 The management information shown is an example of an entry generated by the certification authority 50 when the battery device 30 having the battery ID B97143 is associated with a plurality of pieces of location information at a time point.
[0132] when Figure 6 When the revocation list shown is provided to the vehicle 20 , the authentication process of the battery device 30 corresponding to the certificate number 23534 by the vehicle 20 fails, and the startup process of the vehicle 20 can be stopped.
[0133] The processing in the management system 1 configured as above will be described.
[0134] Hereinafter, the processing of the management system 1 at (1) the timing when the vehicle 20 connected to the battery device 30 is started and (2) the timing when the battery device 30 is connected to the charging device 60 will be described.
[0135] (1) Timing of starting the vehicle 20 connected to the battery device 30
[0136] Figure 7 This is a flowchart showing the processing of the vehicle 20 according to the present embodiment. Figure 8 This is a flowchart showing the first process of the management device 10 according to this embodiment. Figure 9 1 is a sequence diagram showing the first process of the management system 1 of this embodiment. Figure 7 、 Figure 8 as well as Figure 9 Next, the processing of the management system 1 at the timing of starting the vehicle 20 connected to the battery device 30 will be described.
[0137] In addition, Figure 7 、 Figure 8 as well as Figure 9 The same number is used to mark the same process. Figure 9 , a case where the determination in step S204 described later is “Yes” and the determination in step S107 is “No” is shown.
[0138] First, refer to Figure 7 as well as Figure 9 , the processing of the vehicle 20 and the processing of the management system 1 at the timing of starting the vehicle 20 connected to the battery device 30 will be described.
[0139] like Figure 7 As shown, in step S101, the authentication unit 21 obtains the start command and location information. The start command and location information obtained by the authentication unit 21 are sent from the terminal 40. The start command is sent by the terminal 40 based on the fact that the terminal 40 receives the start instruction from the user U through the acceptance unit 43 ( Figure 9 Steps S221~S222).
[0140] Furthermore, the authentication unit 21 may perform authentication processing with the authentication unit 41 of the terminal 40 before or after receiving the activation command. Furthermore, the information representing the activation command may be accompanied by an electronic signature of the terminal 40. In this case, the authentication unit 21 can verify the electronic signature to confirm that the activation command was indeed sent from the terminal 40.
[0141] Furthermore, the vehicle 20 may be configured to execute subsequent steps only when receiving a start command from a predetermined terminal 40. For example, the vehicle 20 may be configured to execute subsequent steps only when receiving a start command from a user U who has the right to use the vehicle 20, and not execute subsequent steps when receiving a start command from a user U who does not have such right.
[0142] In step S102, the authentication unit 21 performs authentication and sharing of a common key with the authentication unit 11 of the management device 10. The authentication process can employ public key authentication. The sharing process can employ existing techniques for performing encrypted communication using private and public keys (e.g., the sharing of a common key performed prior to SSL (Secure Sockets Layer) encrypted communication).
[0143] In step S103, the authentication unit 21 obtains a revocation list from the authentication authority 50. When the battery ID of an inappropriate battery device is added to the revocation list in step S241 described later, the authentication unit 21 obtains the added revocation list.
[0144] In step S104, the authentication unit 21 performs authentication processing with the authentication unit 31 of the battery device 30 connected to the vehicle 20 ( Figure 9 During the authentication process, the authentication unit 21 obtains the battery ID of the battery device 30. If the authentication process is successful ("Yes" in step S104), the process proceeds to step S105. Otherwise ("No" in step S104), the process proceeds to step S111. If the battery device 30 has an inappropriate battery ID, the authentication process fails.
[0145] In step S105, the authentication unit 21 transmits the battery ID of the battery device 30 acquired in step S104 and the location information acquired in step S101 to the management device 10. The battery ID and location information are encrypted using the common key shared in step S102.
[0146] In step S106 , the control unit 22 obtains activation permission information from the management device 10 .
[0147] In step S107, the control unit 22 determines whether the start permission information acquired in step S106 is information that permits the start of the vehicle 20. If it is determined that the start of the vehicle 20 is permitted ("YES" in step S107), the process proceeds to step S108; otherwise ("NO" in step S107), the process proceeds to step S111.
[0148] In step S108 , the control unit 22 continues the startup process. As a result, the control unit 22 starts the vehicle 20 .
[0149] In step S109, if the control unit 22 continues the startup process in step S108 and the startup of the vehicle 20 is successful, a notification indicating that the startup is completed is sent to the terminal 40. Based on the sent notification, the terminal 40 prompts the content of the notification through the prompt unit 44 so that the user can recognize it. In addition, step S109 is not a necessary process. If step S109 is completed, the process ends. Figure 7 A series of processing shown.
[0150] In step S111, the control unit 22 stops the startup process. As a result, the control unit 22 stops the startup of the vehicle 20.
[0151] In step S112, when the vehicle 20 fails to start due to the fact that the start process is stopped in step S111, the control unit 22 sends a notification indicating that the start has failed to the terminal 40. Based on the sent notification, the terminal 40 displays the content of the notification through the display unit 44 so that the user can recognize it ( Figure 9 Step S223). In addition, step S112 is not a necessary process. If step S112 is completed, then the process ends. Figure 7 A series of processing shown.
[0152] Next, refer to Figure 8 as well as Figure 9 Next, the processing of the management device 10 and the processing of the management system 1 at the timing of starting the vehicle 20 connected to the battery device 30 will be described.
[0153] like Figure 8 As shown, in step S201, the authentication unit 11 performs authentication processing and sharing processing of sharing a common key with the authentication unit 21 of the vehicle 20. Figure 7 The authentication process and sharing process are the same.
[0154] In step S202, the management unit 12 obtains the battery ID and location information of the battery device 30 connected to the vehicle 20. The obtained battery ID and location information are sent from the vehicle 20 ( Figure 7 The communication to obtain the battery ID and location information is encrypted using the common key shared in step S201.
[0155] In step S203 , the management unit 12 associates the battery ID and position information acquired in step S202 and records them in the management information.
[0156] In step S204, the management unit 12 determines whether the same battery ID is associated with multiple pieces of location information in the management information. If it is determined that the same battery ID is associated with multiple pieces of location information ("Yes" in step S204), the process proceeds to step S205; otherwise ("No" in step S204), the process proceeds to step S211.
[0157] In step S205, the management unit 12 notifies the certification authority 50 of the battery ID associated with the plurality of location information as the battery ID of an inappropriate battery device. The certification authority 50 that receives the notification adds the notified battery ID to the invalidation list (step S241). Thereafter, when a request for the invalidation list is made from the vehicle 20, the certification authority 50 sends the invalidation list to which the battery ID is added to the vehicle 20. As a result, the authentication process between the vehicle 20 that receives the invalidation list and the battery device 30 whose battery ID is recorded in the invalidation list fails, and the startup process of the vehicle 20 is terminated (in step S241). Figure 7 "No" in step S104, step S111).
[0158] In step S206, the management unit 12 transmits the start permission information indicating that the start of the vehicle 20 is suspended to the vehicle 20. Thus, the start processing of the vehicle 20 is continued, and as a result, the vehicle 20 is started ( Figure 7 In addition, step S206 is not a necessary process.
[0159] In step S211, the management unit 12 transmits start permission information indicating that the start of the vehicle 20 is permitted to the vehicle 20. As a result, the start processing of the vehicle 20 is stopped. As a result, the start processing of the vehicle 20 is stopped and the start fails ( Figure 7 In addition, step S211 is not a necessary process.
[0160] If step S206 or S211 is completed, then the Figure 8 A series of processing shown.
[0161] In this manner, the management device 10 can suppress improper use of the battery device 30 by using the battery ID and position information acquired when the vehicle 20 connected to the battery device 30 starts.
[0162] Furthermore, if step S206 is not executed, the vehicle 20 may be started using an inappropriate battery device 30 . However, in this case, after the startup, information to stop the operation of the vehicle 20 may be transmitted from the management device 10 to the vehicle 20 .
[0163] (2) Timing of connecting the battery device 30 to the charging device 60
[0164] Figure 10 This is a flowchart showing the second process of the management device 10 according to this embodiment. Figure 11 : is a sequence diagram showing the second process of the management system 1 of this embodiment. Figure 10 as well as Figure 11 , the processing of the management system 1 when the battery device 30 is connected to the charging device 60 is described. Figure 10 as well as Figure 11 The same number is used to mark the same process.
[0165] Here, the processing of the management system 1 when the battery device used in the vehicle 20 (also called a used battery) is removed from the vehicle 20 and connected to the charging device 60, and the battery device removed from the charging device 60 (also called a charged battery) is connected to the vehicle 20 is described (steps S321 and S322).
[0166] At this time, the terminal 40 obtains the used battery ID (step S331) and transmits the user ID of the user U to the charging device 60 along with the obtained used battery ID (step S332). There are various methods for the terminal 40 to obtain the used battery ID. For example, there are methods in which the terminal 40 reads a code (barcode or QR code, etc.) displayed on the housing of the used battery device by photographing the used battery device, or methods in which the user U visually reads information such as the serial number displayed on the housing of the used battery device and inputs it to the terminal 40.
[0167] In step S301, the authentication unit 11 performs authentication processing and sharing processing of sharing a common key with the authentication unit 61 of the charging device 60 ( Figure 11 Step S341). As for the authentication process and the shared process, Figure 7 The authentication process and sharing process are the same.
[0168] In step S302, the management unit 12 obtains the battery ID (also referred to as the used battery ID) of the battery device 30 connected to the charging device 60, the battery ID (also referred to as the charged battery ID) of the battery device 30 removed from the charging device 60, and the charging device ID of the charging device 60. The obtained used battery ID, charged battery ID, and charging device ID are sent from the charging device 60 ( Figure 11 In the communication for obtaining the used battery ID, the charged battery ID, and the charging device ID, encryption is performed using the common key shared in step S301.
[0169] In step S303, the management unit 12 associates the used battery ID and the charging device ID acquired in step S302 and records them in the management information. In addition, the management unit 12 records the connection start time for the recorded used battery ID.
[0170] In step S304 , the management unit 12 records the connection end time for the charged battery ID acquired in step S302 .
[0171] In step S305, the management unit 12 determines whether the same battery ID is associated with multiple location information in the management information. If it is determined that the same battery ID is associated with multiple location information ("Yes" in step S305), the process proceeds to step S306. Otherwise ("No" in step S305), the process ends. Figure 10 A series of processing shown.
[0172] In step S306, the management unit 12 notifies the certification authority 50 of the battery ID determined to be associated with multiple pieces of location information as the battery ID of an inappropriate battery device. The certification authority 50 that receives the notification adds the notified battery ID to the revocation list (step S351). Figure 8 The processing is the same as that in step S205.
[0173] As described above, the management device 10 can suppress improper use of the battery device by using the battery ID and position information acquired when the battery device 30 is connected to the charging device 60 .
[0174] In the above description, the determination unit 13 of the management device 10 determines that the same battery device ID is associated with a plurality of different pieces of location information at one point in time. However, “one point in time” may be a concept having a certain time width.
[0175] For example, a predetermined time width of several minutes to several tens of minutes may be used as “one time point”.
[0176] Alternatively, "one point in time" can be determined based on the distance between two locations. Specifically, the time required for vehicle 20 to move between two locations can be defined as "one point in time." For example, if two locations are 60 km apart, and the vehicle 20 is moving at 60 km / h, a time span of one hour can be defined as "one point in time." Assuming that a battery device ID is associated with a single battery device 30, there can be no battery with the same battery device ID at two different locations during that time. In other words, the presence of a battery with the same battery device ID at two different locations during that time is likely due to a high probability that the battery device ID was illegally copied.
[0177] Alternatively, instead of determining that the same battery device ID is associated with a plurality of different pieces of location information at a single point in time, the determination unit 13 may determine based on the number of vehicles 20 connected to the battery device 30. Specifically, the determination unit 13 may determine whether a single battery device ID is connected to a predetermined number or more of vehicles 20 within a predetermined period of time (e.g., a single day). If so, the output unit 14 may output information indicating that the battery device 30 is inappropriate.
[0178] Alternatively, the determination unit 13 may determine based on the distance that the vehicle 20 can travel from a fully charged state. Specifically, after completing the start process for the vehicle 20, the determination unit 13 may determine whether the next start process for the vehicle 20 has been performed at a location that exceeds the distance that the vehicle 20 can travel on a single charge (e.g., approximately 300 km for an electric vehicle or approximately 30 km for an electric two-wheeled vehicle). If this is the case, the output unit 14 may output information indicating that the battery device 30 is unsuitable.
[0179] Furthermore, the determination unit 13 may also perform a determination based on the remaining battery level of the battery device 30. Specifically, the determination unit 13 may determine whether the remaining battery level is higher than a predetermined value or more than the remaining battery level when the vehicle 20 connected to the battery device 30 was last started, or when the battery device 30 was removed from the charging device 60. If so, the output unit 14 may output information indicating that the battery device 30 is faulty.
[0180] (Modification of the embodiment)
[0181] Figure 12 It is a block diagram schematically showing the configuration of a management device 10A according to this modification.
[0182] The management device 10A is a management device that manages the legitimacy of a battery device used as a power source for a vehicle.
[0183] like Figure 12 As shown, the management device 10A includes a management unit 12A, a determination unit 13A, and an output unit 14A.
[0184] The management unit 12A acquires the identifier of the battery device and the position information indicating the position of the battery device multiple times, and holds management information in which the acquired identifier and position information are associated and recorded each time the battery device is acquired.
[0185] The determination unit 13A refers to the management information and determines whether the same identifier is associated with a plurality of different pieces of position information at one point in time.
[0186] When the determination unit 13A determines that one identifier is associated with multiple location information, the output unit 14A will output information that invalidates the authentication related to the battery device. After the above information is output, the start-up process of the vehicle is terminated based on the fact that the authentication failed in the authentication process performed by the vehicle and the battery device.
[0187] Figure 13 This is a flowchart showing the processing of the management device 10A according to this modification.
[0188] like Figure 13 As shown, in step S1 (management step), the identifier of the battery device and the position information indicating the position of the battery device are acquired multiple times, and management information is stored in which the acquired identifier and position information are associated and recorded each time.
[0189] In step S2 (determination step), the management information is referred to and it is determined whether the same identifier is associated with a plurality of different position information at one point in time.
[0190] In step S3 (output step), when the determination step determines that one identifier is associated with multiple location information, information that invalidates the authentication related to the battery device will be output. After the above information is output, based on the fact that the authentication failed in the authentication process performed by the vehicle and the battery device, the start-up process of the vehicle is terminated.
[0191] Thereby, the management device 10A can suppress the inappropriate use of the battery device.
[0192] As described above, the management device of this embodiment refers to the management information to determine whether the same identifier of the battery device is associated with multiple pieces of location information, thereby managing whether the inherent information of the battery device has been abnormally (illegally) copied. The identifier of the battery device is originally information inherent to the battery device, and one battery device is assigned one identifier. Therefore, the association of the same identifier with multiple pieces of location information means that the inherent information of the battery device has been copied, resulting in a state where multiple battery devices have the inherent information. Moreover, the management device outputs information that invalidates the authentication of the battery device, thereby terminating the start-up process of the vehicle, thereby suppressing the use of the battery device. In this way, the management device can suppress the improper use of battery devices.
[0193] Furthermore, the management device uses the output information to cause the authentication process using the public key of the vehicle and battery device to fail, thereby terminating the vehicle startup process. This makes it easier for the management device to prevent an inappropriate battery device from being connected to and used in the vehicle. This makes it easier for the management device to prevent inappropriate battery device use.
[0194] Furthermore, the management device obtains the identifier and location information provided during the vehicle startup process. If it determines that the same identifier is associated with multiple pieces of location information, it aborts the ongoing startup process. This prevents a vehicle with an inappropriate battery device connected from failing to start. This allows the management device to more effectively prevent the use of inappropriate battery devices.
[0195] Furthermore, the management device obtains the identifier and location information provided when the battery device is connected to the charging device, and determines that the same identifier is associated with multiple locations. This allows the management device to detect inappropriate battery devices when they are connected to the charging device and prevent their subsequent use. Thus, by confirming the legitimacy of the battery device when connected to the charging device, the management device can more effectively prevent the use of inappropriate battery devices.
[0196] In addition, the management device uses the location information of the terminal owned by the person riding in the vehicle as the location information of the battery device. When the person who owns the terminal rides in the vehicle, since the battery device and the user's terminal are located at a close distance (for example, within a few tens of centimeters or about 1 meter), it is considered that it is not a big deal even if the location information obtained by the terminal is used as the location information of the battery device. In addition, most terminals generally have location sensors. Therefore, when the battery device does not have a location sensor, the management device can use the location sensor of the terminal to replace the location information of the battery device, and can manage the legitimacy of the battery device. Thus, the management device can suppress the improper use of the battery device even if the battery device does not have a location sensor.
[0197] In addition, the management system of this embodiment has the same effects as the above-mentioned management device.
[0198] In addition, the management method of this embodiment has the same effects as the above-mentioned management device.
[0199] Furthermore, in the above-described embodiments, each component may be constructed from dedicated hardware or implemented by executing a software program suitable for each component. Alternatively, each component may be implemented by a program execution unit, such as a CPU or processor, reading and executing a software program stored on a recording medium, such as a hard disk or semiconductor memory. The software that implements the management device, etc., of the above-described embodiments is the following program.
[0200] That is, the program is a program that causes a computer to execute a management method for managing the legitimacy of a battery device used as a power source for a vehicle, the management method including: a management step of acquiring an identifier of the battery device and location information indicating the location of the battery device multiple times, and retaining management information that records the identifier acquired and the location information by associating them each time; a determination step of determining, with reference to the management information, whether the same identifier is associated with a plurality of location information that are different from each other at a point in time; and an output step of outputting information that invalidates authentication related to the battery device when it is determined in the determination step that one identifier is associated with a plurality of location information, and after the information is output, terminating the start-up process of the vehicle based on the fact that authentication failed in the authentication process performed by the vehicle and the battery device.
[0201] While the management devices and management systems of one or more technical solutions have been described above based on implementations, the present invention is not limited to these implementations. Various modifications of these implementations that would be conceivable to those skilled in the art, as well as configurations combining components from different implementations, are encompassed within the scope of the one or more technical solutions, provided they do not depart from the spirit of the present invention.
[0202] Industrial applicability
[0203] The present invention can be utilized in a management device for managing battery devices used in vehicles.
[0204] Description of labels
[0205] 1 Management System
[0206] 10.10A Management Device
[0207] 11, 21, 31, 41, 61 Certification Department
[0208] 12.12A Management Department
[0209] 13.13A Judgment Unit
[0210] 14, 14A output
[0211] 20 vehicles
[0212] 22 Control Unit
[0213] 23. Drive unit
[0214] 30 battery device
[0215] 32. Charge and discharge unit
[0216] 40 Terminal
[0217] 42 Position Sensor
[0218] 43 Reception Department
[0219] 44 Tips
[0220] 45 Start control unit
[0221] 50 Certification Bureau
[0222] 51 Distribution Department
[0223] 52 List Management Department
[0224] 60 Charging device
[0225] 62 Acquisition Department
[0226] 63 Power Supply
[0227] E1, E2, E4, E5, E6, E7 entries
[0228] N Network
[0229] U User
Claims
1. A management device for managing the legitimacy of a battery device used as a power source for a vehicle, comprising: a management unit that acquires the identifier of the battery device and the location information indicating the location of the battery device multiple times, and holds management information that associates and records the identifier and the location information acquired each time; a determination unit that refers to the management information and determines whether the same identifier is associated with a plurality of different pieces of location information at a time point; as well as The output unit outputs, when the determination unit determines that one identifier is associated with a plurality of the location information, revocation information that invalidates the public key certificate of the battery device to the certification authority. After the revocation information is output to the certification authority, the vehicle uses the revocation information obtained from the certification authority to terminate the start-up process of the vehicle based on the fact that authentication failed in the authentication process using the public key performed on the vehicle and the battery device.
2. The management device according to claim 1, The management department, acquiring the identifier and the position information provided in the activation process of the vehicle, The output portion, As the output of the failure information, information for suspending the activation process is also output to the vehicle.
3. The management device according to claim 1, The management department, The identifier and the position information provided when the battery device is connected to a charging device are acquired.
4. The management device according to claim 1, The management department, As the position information, position information acquired by a position sensor included in a terminal owned by a person riding the transportation means is acquired.
5. A management system comprising: The management device according to any one of claims 1 to 4; and The vehicle uses the battery device whose legitimacy is managed by the management device as a power source.
6. The management system according to claim 5, further comprising: The battery device is used as a power source for the vehicle.
7. A method for managing the legitimacy of battery devices used as power sources for vehicles, comprising: a management step of acquiring the identifier of the battery device and location information indicating the location of the battery device multiple times, and retaining management information in which the identifier and location information acquired each time are associated and recorded; a determination step of determining, with reference to the management information, whether the same identifier is associated with a plurality of different pieces of location information at a time point; as well as An output step, in which, when it is determined in the determination step that one of the identifiers is associated with a plurality of the location information, expiration information for invalidating the public key certificate of the battery device is output to the certification authority; after the expiration information is output to the certification authority, the vehicle uses the expiration information obtained from the certification authority to terminate the start-up process of the vehicle based on the fact that authentication failed in the authentication process using the public key performed on the vehicle and the battery device.
8. A program recording medium for causing a computer to execute the management method according to claim 7.
Citation Information
Patent Citations
Matching method and system for battery modules of electric automobile
CN106696730A
Battery encryption system based on asymmetric cryptographic algorithm and method thereof
CN108808136A
Unauthorized connection detecting device, unauthorized connection detecting system, and unauthorized connection detecting method
US20140059350A1