Battery monitoring system
Patent Information
- Application Number
- CN202280083865.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-13
- Filing Date
- 2022-12-20
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-12-20
AI Technical Summary
[0008] The technology described in Patent Document 1 is very useful in improving the reliability of the host device, but it cannot guarantee the reliability of the data provided by the monitoring unit itself, and therefore lacks reliability in this respect.
Smart Images

Figure CN118414648B_ABST
Abstract
Description
[0001] Cross-referencing of relevant applications
[0002] This application is based on Japanese Patent Application No. 2021-212555, filed on December 27, 2021, and Japanese Patent Application No. 2022-198705, filed on December 13, 2022, the contents of which are incorporated herein by reference. Technical Field
[0003] This disclosure relates to battery monitoring systems. Background Technology
[0004] In a battery monitoring system, data obtained by a monitoring unit electrically connected to the battery and monitoring the battery is sent to a host device such as a battery control device or a battery charging device. In this technology, it is known that the host device encrypts the raw data provided from the monitoring unit and the processed data obtained by processing the raw data, and manages it using an autonomous distributed ledger (so-called blockchain) (see, for example, Patent Document 1).
[0005] Existing technical documents
[0006] Patent documents
[0007] Patent Document 1: European Patent Application Publication No. 3570058 Summary of the Invention
[0008] The technology described in Patent Document 1 is very useful in improving the reliability of the host device, but it cannot guarantee the reliability of the data provided by the monitoring unit itself, and therefore lacks reliability in this respect.
[0009] One objective of this disclosure is to provide a battery monitoring system that ensures the reliability of data provided from the monitoring unit to the host device. Other objectives of this disclosure include providing a battery monitoring system that can restore the battery cycle process even in the event of unauthorized access, or providing a battery monitoring system that can prevent battery theft.
[0010] According to one point of view in this disclosure
[0011] The battery monitoring system includes:
[0012] The monitoring unit monitors the rechargeable and dischargeable batteries; and
[0013] The host device is provided with monitoring data obtained through monitoring of the battery by the monitoring unit, and uses blockchain to store at least a portion of the specific information contained in the monitoring data.
[0014] The host computer has the following features:
[0015] The block generation department generates new blocks that contain at least a portion of specific information and a hash value based on the last block in the last link of the blockchain; and
[0016] External communication devices are used to distribute and store new blocks generated by the block generation unit across multiple external devices.
[0017] At least one of the monitoring unit and the host device is provided with a data protection unit to ensure the reliability of the monitoring data.
[0018] Therefore, by using a data protection unit located in at least one of the monitoring unit and the host device to ensure the reliability of the monitoring data, the reliability of the data provided from the monitoring unit to the host device can be ensured.
[0019] According to another point of view in this disclosure
[0020] The battery monitoring system includes:
[0021] The monitoring unit monitors the rechargeable and dischargeable batteries; and
[0022] The host device is provided with monitoring data obtained through the monitoring of the battery by the monitoring unit.
[0023] A data protection unit is set up in the monitoring department to ensure the reliability of the monitoring data.
[0024] The data protection unit includes an access restriction unit and an access deactivation unit. The access restriction unit restricts external access to the monitoring data stored in the storage unit of the monitoring unit. If the access deactivation unit is notified of a pre-set deactivation key from the host device while the access is restricted, the access restriction is lifted.
[0025] Thus, by providing an access restriction unit to the monitoring unit, the reading / tampering of monitoring data caused by unauthorized access can be suppressed. Furthermore, since the monitoring unit is equipped with an access deactivation unit, even in the event of unauthorized access, the process can be restored to battery cycling.
[0026] Moreover, according to another point of view in this disclosure,
[0027] The battery monitoring system includes:
[0028] The monitoring unit monitors the rechargeable and dischargeable batteries; and
[0029] The charger controls the charging of the battery.
[0030] Both the monitoring unit and the charger store a unique ID assigned to the monitoring unit.
[0031] Both the monitoring unit and the charger have data authentication units for mutual authentication of unique IDs.
[0032] If the authentication results from the data authentication department indicate that the unique IDs stored in the charger and the monitoring department are inconsistent, charging of the battery will be prohibited.
[0033] Thus, if the charger is configured to prevent charging of the battery due to a mismatch between the inherent ID in the monitoring unit and the charger, thereby rendering the battery worthless, it can discourage thieves from stealing the battery. This is very useful for preventing battery theft.
[0034] Furthermore, the parenthesized reference numerals in the accompanying drawings that indicate the correspondence between the constituent elements and the specific constituent elements described in the embodiments described later are an example. Attached Figure Description
[0035] Figure 1 This is a schematic diagram of the battery monitoring system according to the first embodiment.
[0036] Figure 2 This is an explanatory diagram used to illustrate lithium-ion batteries.
[0037] Figure 3 This is a schematic diagram of the monitoring unit and battery ECU of the battery monitoring system.
[0038] Figure 4 This is an explanatory diagram used to illustrate the hash value of a new block.
[0039] Figure 5 This is an explanatory diagram used to illustrate blockchain.
[0040] Figure 6 This is an explanatory diagram used to illustrate countermeasures related to impersonation by the monitoring department.
[0041] Figure 7 This is an explanatory diagram used to illustrate countermeasures related to data forgery using signal interference.
[0042] Figure 8 This is an explanatory diagram used to illustrate countermeasures related to intrusion into higher-level devices.
[0043] Figure 9 This is an explanatory diagram used to illustrate countermeasures related to battery theft.
[0044] Figure 10 This is a schematic diagram of the battery monitoring system according to the second embodiment.
[0045] Figure 11 This is an explanatory diagram illustrating a first embodiment of countermeasures related to unauthorized access.
[0046] Figure 12 This is a flowchart illustrating the process of handling countermeasures against unauthorized access by the monitoring department.
[0047] Figure 13 This is an explanatory diagram illustrating a second embodiment of countermeasures related to unauthorized access.
[0048] Figure 14 This is a flowchart illustrating the process of handling countermeasures against unauthorized access by the monitoring department.
[0049] Figure 15 This is an explanatory diagram illustrating a third embodiment of countermeasures related to unauthorized access.
[0050] Figure 16 This is a flowchart illustrating the process of handling countermeasures against unauthorized access by the monitoring department.
[0051] Figure 17 This is an explanatory diagram illustrating a fourth embodiment of countermeasures related to unauthorized access.
[0052] Figure 18 This is a flowchart illustrating the process of handling countermeasures against unauthorized access by the monitoring department. Detailed Implementation
[0053] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. Furthermore, in the following embodiments, sometimes the same reference numerals are used to refer to parts that are the same as or equivalent to those described in previous embodiments, and their descriptions are omitted. Also, in embodiments, where only a portion of the constituent elements is described, other portions of the constituent elements can be applied to the constituent elements described in previous embodiments. The following embodiments can be partially combined with each other, even without explicit explicit description, as long as they do not particularly hinder the combination.
[0054] (First Implementation)
[0055] based on Figures 1-9 The first embodiment of this disclosure will be described. The battery monitoring system 1 is a system for monitoring batteries BT that are capable of charging and discharging, such as high-voltage batteries, stationary batteries, and portable batteries installed in automobiles.
[0056] like Figure 1 As shown, the battery monitoring system 1 includes a monitoring unit 20 for monitoring the battery BT and a battery ECU 50 for providing monitoring data obtained by monitoring the battery BT through the monitoring unit 20. The battery ECU 50 is a host device located above the monitoring unit 20. Alternatively, the battery monitoring system 1 may replace the battery ECU 50 with a charger CH capable of controlling the charging of the battery BT. In this case, the charger CH corresponds to the host device. Hereinafter, the battery ECU 50 and the charger CH will sometimes be referred to as host devices.
[0057] The battery BT that is being monitored is a rechargeable battery. A battery BT can consist of a single battery cell or a battery pack consisting of multiple battery cells connected in series. In addition, some battery cells in a battery pack can also be connected in parallel.
[0058] Specifically, the BT battery is composed of lithium-ion batteries. Lithium-ion batteries, for example... Figure 2 As shown, the battery is constructed using lithium iron phosphate (LFP) and nickel / manganese / cobalt (NMC) as the positive electrode agent, and graphite as the negative electrode agent. Furthermore, the current collector on the positive electrode side is made of aluminum, and the current collector on the negative electrode side is made of copper. This type of lithium-ion battery exhibits excellent charge-discharge cycle characteristics, and on the other hand, it has the characteristic that its electrode potential is very close to the lithium deposition potential, making it easy for lithium to be deposited during charging.
[0059] like Figure 3 As shown, the monitoring unit 20 is electrically connected to the battery BT via the connecting member WH. The monitoring unit 20 can be integrally mounted to the battery BT, or it can be detachably mounted relative to the battery BT. In addition, the connecting member WH includes a flexible substrate FPC printed with wiring patterns.
[0060] The monitoring unit 20 includes a sensor unit 21, a storage unit 22, a first data protection unit 24, and a wireless communication device 25. Figure 3 In the diagram, the various components of the monitoring unit 20 are enclosed in square frames, but this is for the purpose of summarizing the various components and does not indicate that the various components are mounted on a single substrate.
[0061] The sensor unit 21 detects the state of the battery BT. The sensor unit 21 includes a temperature sensor 211, a current sensor 212, a voltage sensor 213, a degradation detection unit 214, a SOH inference unit 215, etc.
[0062] Temperature sensor 211 is a sensor for detecting the temperature of a lithium-ion battery. Temperature sensor 211 is, for example, mounted on a flexible substrate (FPC). Alternatively, the battery temperature can also be inferred from the measured internal impedance of the battery (BT). In this case, the unit that infers the battery temperature functions as temperature sensor 211.
[0063] The current sensor 212 is a sensor that detects the output current of the battery BT. The current sensor 212 can be mounted on a flexible printed circuit board (FPC) or on a substrate other than a flexible printed circuit board (FPC).
[0064] Voltage sensor 213 is a sensor that detects the output voltage of battery BT. Voltage sensor 213 can be mounted on a flexible substrate FPC, or on a substrate other than a flexible substrate FPC.
[0065] The degradation detection unit 214 detects the degree of degradation of the battery BT, which is an important indicator in setting the residual value of the battery BT. The degradation detection unit 214 includes a precipitation detection unit 214a and a coating detection unit 214b.
[0066] The deposition detection unit 214a is a device for detecting lithium deposition in a lithium-ion battery. The deposition detection unit 214a infers the amount of lithium deposition based on the correlation between the amount of lithium deposition in the lithium-ion battery and the behavior of the current and voltage when the two ends of the lithium-ion battery are short-circuited. Although not shown, the deposition detection unit 214a includes a short-circuit circuit for discharging the lithium-ion battery by temporarily short-circuiting its two ends, and an arithmetic unit for inferring the amount of lithium deposition based on the behavior of the current and voltage when the lithium-ion battery is short-circuited using the short-circuit circuit. The short-circuit circuit includes a short-circuit switch for short-circuiting the two ends of the lithium-ion battery, a coil, and a capacitor. A self-resonant circuit is formed by the internal resistance of the lithium-ion battery, the coil of the short-circuit circuit, and the capacitor. The arithmetic unit extracts a resistance change component related to the amount of lithium deposition from the signal waveform of at least one of the current and voltage flowing through the short-circuit circuit when the two ends of the lithium-ion battery are short-circuited, and calculates an inferred value of the amount of lithium deposition based on the extracted component.
[0067] This method for estimating lithium deposition is very simple in construction and is very useful in that it allows for the detection of specific battery degradation modes by adjusting the discharge frequency from the lithium-ion battery. Furthermore, the deposition detection unit 214a calculates a correction value as the amount of lithium deposition, obtained by correcting the estimated value using at least one of the battery temperature detected by the temperature sensor 211 and the parasitic resistance value pre-stored in the storage unit 22 (described later). Alternatively, the deposition detection unit 214a can also deduce the amount of lithium deposition using methods other than those described above.
[0068] The coating detection unit 214b detects the thickness of the coating formed at the interface between the negative electrode and the electrolyte during lithium-ion battery charging. This coating is also called the SEI layer. SEI is an abbreviation for Solid Electrolyte Interphase. The thickness of the SEI layer is related to the behavior of the current and voltage when the two ends of the lithium-ion battery are short-circuited using the aforementioned short-circuit circuit. The coating detection unit 214b infers the thickness of the SEI layer based on the behavior of the current and voltage when the two ends of the lithium-ion battery are short-circuited using the short-circuit circuit. Specifically, the coating detection unit 214b extracts components related to the thickness of the SEI layer from the signal waveform of at least one of the current and voltage flowing through the short-circuit circuit when the two ends of the battery BT are short-circuited using the short-circuit circuit, and infers the thickness of the SEI layer based on the extracted components. In addition, when detecting the thickness of the SEI layer, similar to the detection of lithium deposition, it is desirable to use the battery temperature, etc. for correction. Alternatively, the coating detection unit 214b can also infer the thickness of the SEI layer using methods other than those described above.
[0069] Here, the internal resistance of the battery BT and the condition of the positive electrode active material inside the battery BT are physical quantities that directly affect the degradation of the battery BT. Therefore, the degradation detection unit 214 may also include a detection unit for the internal resistance of the battery BT and a detection unit for the condition of the positive electrode active material inside the battery BT.
[0070] The SOH inference unit 215 infers the volumetric efficiency (SOH) of the battery BT based on physical quantities that are highly correlated with the capacity degradation of the battery BT. One reason for the degradation of the battery BT is the increase in its internal resistance. The internal resistance of the battery BT is strongly correlated with physical quantities such as the amount of lithium deposition and the internal resistance of the battery BT itself. In addition, the internal resistance of the battery BT is temperature-dependent and affects the current and voltage of the battery BT. Furthermore, SOH is an abbreviation for State of Health.
[0071] In this embodiment, the SOH estimation unit 215 takes these factors into account and uses the amount of lithium deposition, the thickness of the SEI layer, the temperature, current, and voltage of the battery BT to apply an estimation model for the SOH of the volumetric capacity to estimate the SOH. The SOH estimation model is, for example, a control mapping or function that defines the relationship between the SOH of the volumetric capacity, the amount of lithium deposition, the thickness of the SEI layer, the temperature, current, and voltage of the battery BT. Alternatively, the SOH estimation unit 215 can also estimate the SOH of the battery BT using methods other than those described above. Furthermore, although not shown, the monitoring unit 20 also includes an estimation unit for estimating the remaining capacity (SOC) of the battery BT.
[0072] The storage unit 22 is composed of a read / write storage medium. The storage unit 22 stores the detection results of the battery BT's state by the sensor unit 21. Specifically, the storage unit 22 stores the battery BT's manufacturing history, including its unique ID set according to each monitoring unit 20, its initial capacity, and its repair history. Additionally, the storage unit 22 stores the battery BT's usage history, such as lithium deposition amount, SEI layer thickness, internal resistance, and volumetric efficiency (SOH). Hereinafter, the unique ID, battery BT manufacturing history, and battery BT usage history will be collectively referred to as "specific information." Furthermore, the storage unit 22 is composed of a non-transitional physical storage medium.
[0073] The monitoring and control unit 23 monitors the detection results of the battery BT's state by the monitoring sensor unit 21, and determines whether the battery BT's state is appropriate based on the monitoring results. In addition, if the monitoring and control unit 23 detects an abnormality in the battery BT, it notifies the upper-level device such as the battery ECU 50 of the abnormality via the wireless communication device 25.
[0074] The first data protection unit 24 is used to ensure the reliability of monitoring data provided from the monitoring unit 20 to higher-level devices such as the battery ECU 50 via the wireless communication device 25. The first data protection unit 24 will be described later.
[0075] The wireless communication device 25 is a device that enables bidirectional communication with a host device such as the battery ECU 50. The monitoring unit 20 receives various signals from the host device such as the battery ECU 50 and sends monitoring data obtained by the monitoring unit 20 through monitoring the battery BT to the host device such as the battery ECU 50. The monitoring data includes specific information such as the unique ID, the manufacturing history of the battery BT, the usage history of the battery BT, and the location information of the battery BT.
[0076] Next, the battery ECU 50 will be described. The battery ECU 50 is the host device of the battery monitoring system 1. Based on monitoring data provided from the monitoring unit 20, the battery ECU 50 performs charge / discharge control of the battery BT and temperature adjustment control of the battery BT by a temperature regulating device. In addition, the battery ECU 50 includes a charge control function for controlling the charging of the battery BT.
[0077] Specifically, the battery ECU 50 includes a microcomputer with a processor, memory 51, I / O, etc., and an internal communication device 52 for bidirectional communication with the monitoring unit 20. The memory 51 is composed of a non-transferable physical storage medium.
[0078] However, with the rapid electrification of automobiles, a large number of decommissioned battery packs (BTs) are expected to be generated in the near future. The manufacturing process of BTs involves significant CO2 emissions and the use of rare metals. Therefore, decommissioned BTs should be reused, rebuilt, or recycled based on their remaining State of Charge (SOC) and State of Hypothesis (SOH), thereby building a battery ecosystem suitable for a circular economy. To build such a battery ecosystem, a traceability system is crucial for linking and managing information such as the value of the BT (SOC, SOH) and its manufacturing / usage history with the BT itself. Imagine users of BTs who wish to access this traceability system, obtain the necessary battery information, and use the BTs at a price commensurate with their value. In such a traceability system, the reliability of the stored battery information is paramount.
[0079] Against this backdrop, the battery monitoring system 1 disclosed herein improves the reliability of the traceability system by applying blockchain technology to the aforementioned traceability system. Furthermore, blockchain technology refers to a database that directly connects terminals on an information communication network and uses encryption technology to decentralizedly process and record the usage history of the battery 10.
[0080] The battery monitoring system 1 disclosed herein is configured to provide reliable and up-to-date data as parameters representing the state of a battery BT used over a long period of time. Specifically, the battery monitoring system 1 encrypts (i.e., hashes) the monitoring data provided by the monitoring unit 20 and the parameters obtained by processing that monitoring data using a host device such as the battery ECU 50 or the charger CH. Then, the host device manages this data in an autonomous distributed ledger (i.e., a blockchain), thereby improving the reliability of the battery monitoring system 1.
[0081] Specifically, the battery monitoring system 1 uses blockchain to store at least a portion of the specific information contained in the monitoring data provided by the monitoring unit 20 to the battery ECU 50. The battery ECU 50 is composed of a block generation unit 53, a storage unit 54, an external communication device 55, and a second data protection unit 56.
[0082] Block generation unit 53, for example, Figure 4 As shown, a new block Bn is generated based on specific information including the unique ID, the manufacturing history of the battery BT, the usage history of the battery BT, and the hash value of the last block Be in the last link of the blockchain.
[0083] The battery ECU 50 stores the new block Bn generated by the block generation unit 53 in its own storage 54, and distributes it to multiple external devices connected via the Internet INT using external communication devices 55. For example... Figure 5The battery monitoring system 1A shown is mutually authenticated with other battery monitoring systems 1B, 1C, 1D, 1E, and 1F connected via the Internet INT, and its data is distributed and stored in the storage 54 of each battery monitoring system 1B, 1C, 1D, 1E, and 1F.
[0084] In this traceability system, the data stored in the storage device 54 using blockchain technology is protected from tampering, thus greatly improving the reliability of the battery monitoring system 1.
[0085] However, while blockchain technology protects data stored in storage 54 from tampering, it cannot guarantee the reliability of the data itself provided from monitoring unit 20 to the upper-level device. Therefore, due to the impersonation of monitoring unit 20 by counterfeit IM devices and interference from electromagnetic shielding ES on the transmission signals of monitoring unit 20, there is a risk that monitoring data different from the actual data may be stored in storage 54. This becomes a factor that compromises the reliability of the traceability system.
[0086] Furthermore, if the upper-level devices such as the battery ECU50 are compromised due to hacking, there is a possibility of intentional manipulation of various information. Specifically, consider situations where control is implemented to cut off communication from the monitoring unit 20, or to prevent updates to the battery BT's volumetric efficiency (SOH), thus leading to the conclusion that the battery BT has not deteriorated. In the event of such a compromise of the upper-level devices, there is also a risk of compromised data reliability.
[0087] Furthermore, in portable battery BTs such as replaceable batteries, even if data is managed through blockchain technology, if stolen, the user loses the value of the battery BT, and a third party enjoys the value. Therefore, countermeasures against theft become a challenge.
[0088] The battery monitoring system 1 takes these factors into consideration and includes a data protection unit to ensure the reliability of the monitoring data. Specifically, the battery monitoring system 1 includes a first data protection unit 24 in the monitoring unit 20 and a second data protection unit 56 in the battery ECU 50.
[0089] More specifically, the monitoring unit 20, as the first data protection unit 24, includes a first information authentication unit 241, a first data authentication unit 242, a diagnostic unit 243, a self-stopping unit 244, and an encrypted communication unit 245.
[0090] The first information authentication unit 241 is an authentication unit that mutually authenticates specific information provided from the monitoring unit 20 to the battery ECU 50. The first information authentication unit 241 determines whether the specific information possessed by the monitoring unit 20 is consistent with the specific information possessed by the battery ECU 50.
[0091] The first data authentication unit 242 is an authentication unit that mutually authenticates the unique ID assigned to the monitoring unit 20 with the battery ECU 50. The first data authentication unit 242 determines whether the unique ID possessed by the monitoring unit 20 is consistent with the unique ID possessed by the battery ECU 50.
[0092] The diagnostic unit 243 diagnoses whether the command signals sent from the host device are appropriate. The diagnostic unit 243 generates a learned model by learning the command signals from the host device, and uses this learned model to diagnose whether the command signals are appropriate. For example, the diagnostic unit 243 learns the trends in the command signals from the host device to generate the learned model.
[0093] The self-stop unit 244 stops the function of the monitoring unit 20. For example, the self-stop unit 244 stops its own function when the diagnostic unit 243 diagnoses that the instruction signal from the upper device is inappropriate. For example, the self-stop unit 244 cuts off the power supply to the IC constituting the monitoring unit 20, thereby stopping the function of the monitoring unit 20.
[0094] The encrypted communication unit 245 encrypts the monitoring data and sends it to the host device. The encrypted communication unit 245 is composed of an encryption processing unit 246 for encrypting the monitoring data and a wireless communication device 25.
[0095] On the other hand, the battery ECU50, as the second data protection unit 56, has a second information authentication unit 561, a second data authentication unit 562, a decryption processing unit 563, and a charging restriction unit 564.
[0096] The second information authentication unit 561 is an authentication unit that mutually authenticates specific information provided by the monitoring unit 20 to the battery ECU 50. The second information authentication unit 561 determines whether the information held by the monitoring unit 20 is consistent with the information held by the battery ECU 50.
[0097] The second data authentication unit 562 is an authentication unit that mutually authenticates the unique ID assigned to the monitoring unit 20 with the monitoring unit 20. The second data authentication unit 562 determines whether the unique ID possessed by the monitoring unit 20 is consistent with the unique ID possessed by the battery ECU 50.
[0098] The decryption processing unit 563 is configured correspondingly to the encrypted communication unit 245 of the monitoring unit 20. The decryption processing unit 563 decrypts the monitoring data encrypted by the encryption processing unit 246 through a prescribed decryption process.
[0099] The charging restriction unit 564 restricts the charging of the battery BT. For example, the charging restriction unit 564 prohibits the charging of the battery BT if the authentication results of the first data authentication unit 242 and the second data authentication unit 562 indicate that the unique IDs stored in the host device and the monitoring unit 20 are inconsistent.
[0100] Here, the charger CH, installed at the charging station CS, etc., together with the battery ECU 50, serves as the host device for the monitoring unit 20 of the battery BT. The charger CH controls the charging of the battery BT. The charger CH is equipped with a data authentication unit AS corresponding to the second data authentication unit 562 and a controller CR corresponding to the charging restriction unit 564.
[0101] The battery monitoring system 1 configured in this way, with the data protection unit located in the monitoring unit 20 and the host device, can effectively counteract impersonation of the monitoring unit 20, data forgery using signal interference, intrusion into the host device, and battery theft. The following describes countermeasures related to impersonation of the monitoring unit 20, data forgery using signal interference, intrusion into the host device, and battery theft.
[0102] [Impersonation by Surveillance Department 20]
[0103] Reference Figure 6 Countermeasures related to impersonation of the monitoring unit 20 will be explained. For example, regarding impersonation of the monitoring unit 20... Figure 6 As shown, consider illegal acts such as replacing the regular monitoring unit 20 with a counterfeit IM and tampering with the monitoring data provided to the host device.
[0104] In contrast, the battery monitoring system 1 enables both the monitoring unit 20 and the battery ECU 50 to possess at least a portion of specific information, including the unique ID, the manufacturing history of the battery BT, and the usage history of the battery BT. This information is then mutually authenticated by the information authentication units 241 and 561 to determine if there are any inconsistencies. For example, if the specific information is consistent between the two information authentication units 241 and 561, it is considered normal; if the specific information is inconsistent between one of the information authentication units 241 and 561, it is determined that the monitoring unit 20 is impersonating the user.
[0105] Data forgery using signal jamming
[0106] Reference Figure 7 This section explains countermeasures related to data forgery using signal interference. Examples of data forgery using signal interference include... Figure 7 As shown, consider illegal activities such as using electromagnetic shielding ES to interfere with the signals generated by the legitimate monitoring unit 20, thereby providing false monitoring data from the counterfeit IM to the host device.
[0107] In contrast, the battery monitoring system 1 provides encrypted monitoring data from the monitoring unit 20 to the host device. In the host device, the second information authentication unit 561 determines whether the monitoring data provided from the monitoring unit 20 is encrypted. The second information authentication unit 561 determines that the monitoring data is normal if it is encrypted, and determines that the monitoring data is forged if it is not encrypted.
[0108] [Hit on host device]
[0109] Reference Figure 8 This section describes countermeasures related to intrusion into higher-level devices. For example, intrusion into higher-level devices... Figure 8 As shown, consider illegal acts such as hacking or other intrusions into the host device, where the monitoring unit 20 requests data that is only beneficial to itself.
[0110] In contrast, the monitoring unit 20 in the battery monitoring system 1 includes a diagnostic unit 243 that diagnoses whether command signals sent from the host device are appropriate. This diagnostic unit 243 generates a learned model by learning the command signals from the host device and uses the learned model to diagnose whether the command signals are appropriate. The diagnostic unit 243 determines that the command signals are normal if they follow past trends, and diagnoses that the host device has been compromised if the command signals do not follow past trends.
[0111] [Battery theft]
[0112] Reference Figure 9 This section explains countermeasures related to battery theft. For example, if a replaceable battery is stolen... Figure 9 As shown, there is a possibility that the battery BT can be charged by a charger CH installed at a charging station CS, etc.
[0113] In contrast, the battery monitoring system 1 assigns a unique ID to both the monitoring unit 20 and the charger CH. These unique IDs are mutually authenticated by the data authentication units 242 and AS to determine if there are any discrepancies. For example, if the unique IDs of the monitoring unit 20 and the charger CH match in either the data authentication units 242 or AS, it is considered normal, and charging is allowed. On the other hand, if the unique IDs of the monitoring unit 20 and the charger CH do not match in either the data authentication units 242 or AS, it is determined to be battery theft. In this case, the charger CH prohibits charging of the battery BT. Alternatively, in the case of battery theft, the monitoring unit 20, battery ECU 50, etc., can also prohibit the discharge of the battery BT. Furthermore, the determination of battery theft can also be made by the user based on the location information of the battery BT, and this information can be transmitted to the monitoring unit 20, battery ECU 50, or charger CH to prohibit charging or discharging.
[0114] The countermeasures related to the aforementioned battery theft can be implemented not only between the monitoring unit 20 and the charger CH, but also between the monitoring unit 20 and the battery ECU 50. That is, the battery monitoring system 1 can also enable both the monitoring unit 20 and the battery ECU 50 to hold the unique ID of the monitoring unit 20, and mutually authenticate these unique IDs through the data authentication units 242 and 562 to determine whether there is a contradiction.
[0115] In the battery monitoring system 1 described above, monitoring data obtained by monitoring the battery BT through the monitoring unit 20 is provided to the host device, and the host device uses blockchain to store at least a portion of the specific information contained in the monitoring data. This ensures the reliability of the battery monitoring system 1.
[0116] Furthermore, at least one of the monitoring unit 20 and the host device is provided with a data protection unit to ensure the reliability of the monitoring data. Therefore, by using the data protection unit provided in at least one of the monitoring unit 20 and the host device to ensure the reliability of the monitoring data, the reliability of the data provided from the monitoring unit 20 to the host device can be ensured.
[0117] In addition, if the authentication result from the data authentication unit indicates a discrepancy between the unique ID stored in the host device and the monitoring unit 20, charging of the battery BT will be prohibited. Thus, if the battery BT is prevented from charging due to a discrepancy between the unique ID in the monitoring unit 20 and the host device, thereby rendering the battery BT worthless, it can discourage thieves from stealing it. This is very useful for preventing theft of battery BTs.
[0118] In addition, the battery monitoring system 1 can achieve the following effects.
[0119] (1) Both the monitoring unit 20 and the host device have information authentication units for mutual authentication of specific information as data protection units. Therefore, for example, it is possible to detect illegal acts such as replacing the legitimate monitoring unit 20 with a counterfeit IM to tamper with the monitoring data provided to the host device. As a result, it is possible to prevent tampering of monitoring data caused by the impersonation of the monitoring unit 20.
[0120] (2) The monitoring unit 20, as a data protection unit, has an encrypted communication unit 245 that encrypts the monitoring data before sending it to the host device. Thus, if the monitoring data provided from the monitoring unit 20 to the host device is encrypted, illegal acts such as interfering with signals from the legitimate monitoring unit 20 and providing false monitoring data to the host device can be detected on the host device side. As a result, the forgery of monitoring data can be prevented.
[0121] (3) The monitoring unit 20, as a data protection unit, has a diagnostic unit 243 that diagnoses whether the instruction signals sent from the host device are appropriate. Therefore, for example, illegal acts such as impersonating the host device and requesting only data beneficial to itself from the monitoring unit 20 can be detected at the monitoring unit 20 side. As a result, tampering with monitoring data caused by impersonation of the host device can be prevented.
[0122] (4) The diagnostic unit 243 generates a learned model by learning instruction signals from the host device, and uses the learned model to diagnose whether the instruction signals are appropriate. As a result, the trend of instruction signals from the host device only requesting data that is beneficial to itself can be reflected in the learned model, thereby improving the detection accuracy of intrusions from the host device.
[0123] (5) The monitoring unit 20, as a data protection unit, has a self-stopping unit 244 that can stop itself when the diagnostic unit 243 diagnoses that the command signal is inappropriate. Accordingly, it is possible to suppress the expansion of damage caused by illegal acts such as impersonating a higher-level device and requesting only data that is beneficial to itself from the monitoring unit 20.
[0124] (Second Implementation)
[0125] Next, refer to Figures 10-18 The second embodiment will be described. In this embodiment, the differences from the first embodiment will be mainly described.
[0126] In recent years, in order to achieve a circular economy, there has been a growing trend towards the safe and sustainable use of battery resources until their depletion. It is predicted that in the near future, a society will emerge that can appropriately control the cycle of "battery BT manufacturing" → "temporary use" → "secondary use" → "recycling". In this future battery circular society, it is believed that the following system is needed: capable of monitoring data on the number of batteries in each process of battery utilization and their health status in the cloud, predicting when and what type of battery BT to supply for each process, and optimizing production planning.
[0127] To realize this circular society, the reliability of monitoring data, including sensing information such as the health status of the battery BT, is crucial, and countermeasures against unauthorized access to systems containing the battery BT are necessary. As a countermeasure against unauthorized access, one consideration is deleting the monitoring data stored in the storage unit 22 of the monitoring unit 20 upon the occurrence of unauthorized access. Furthermore, unauthorized access refers to access without legitimate access rights. For example, in the event of unauthorized access caused by intrusion into a higher-level device, there are concerns about the leakage / disclosure, unauthorized use, or tampering of monitoring data from the monitoring unit 20.
[0128] However, if the monitoring data stored in the storage unit 22 of the monitoring unit 20 is deleted as a countermeasure against unauthorized access, the health status of the battery BT will become unclear. In this case, it is impossible to determine whether it can be used for "reuse", resulting in a cycle of "temporary use" → "recycling", which makes it impossible to achieve effective use of the battery BT.
[0129] In view of these circumstances, this embodiment proposes a battery monitoring system 1 that takes countermeasures against unauthorized access that leads to the reading / tampering of monitoring data, and can restore the battery cycle process even in the event of unauthorized access.
[0130] like Figure 10 As shown, in this embodiment, the battery monitoring system 1 adds an access restriction unit 247 and an access deactivation unit 248 to the first data protection unit 24 of the monitoring unit 20. Furthermore, in Figure 10 For convenience, the illustrations of the first information authentication unit 241, the first data authentication unit 242, the diagnostic unit 243, the self-stop unit 244, and the encrypted communication unit 245 of the first data protection unit 24 are omitted.
[0131] Access restriction unit 247 restricts external access to monitoring data stored in storage unit 22 of monitoring unit 20. For example, access restriction unit 247 restricts external access to monitoring data when unauthorized access is detected or predicted.
[0132] Access deactivation unit 248 removes the restriction on access to monitoring data stored in storage unit 22 when access is restricted by access restriction unit 247. For example, access deactivation unit 248 removes the restriction on access to monitoring data when it is notified of a deactivation key from a host device with legitimate access rights.
[0133] In other respects, it is the same as the first embodiment. The battery monitoring system 1 of this embodiment can achieve the same effects as the first embodiment by having the same configuration or equivalent configuration.
[0134] The following describes specific embodiments of the countermeasures against unauthorized access in the monitoring unit 20. Furthermore, the first to fourth embodiments shown below can be partially combined with each other, even without explicit description, as long as they do not cause particular obstacles in the combination.
[0135] [First Embodiment]
[0136] First, refer to Figure 11 , Figure 12 The first embodiment will be described. The monitoring unit 20, for example, is designed for... Figure 11 Countermeasures for unauthorized access caused by intrusion into a host device, as shown, and implementation. Figure 12 The processing is shown. Figure 12 The processing shown is performed periodically or irregularly by the monitoring unit 20.
[0137] like Figure 12 As shown, in step S100, the monitoring unit 20 determines whether it detects or predicts unauthorized access to the monitoring data stored in the storage unit 22.
[0138] The monitoring unit 20 may detect unauthorized access, for example, based on the diagnostic results of the diagnostic unit 243 on the command signal. Alternatively, the monitoring unit 20 may determine unauthorized access not based on the diagnostic results of the diagnostic unit 243, but in cases where the authentication key is inconsistent or the password is repeatedly incorrect when accessing the monitoring unit 20.
[0139] Furthermore, the monitoring unit 20 predicts unauthorized access based on whether similar behavior has been performed, even if it cannot be determined to be unauthorized access. For example, the monitoring unit 20 determines that unauthorized access has been predicted if the order or number of requests for various parameters indicating the state of the battery BT is different from usual, or even if the password is wrong only once.
[0140] The monitoring unit 20 stands still until unauthorized access is detected or predicted. If unauthorized access is detected or predicted, it proceeds to step S110. In step S110, the monitoring unit 20 stores the monitoring data stored in the storage unit 22 as backup data on an external storage device 60 such as a cloud server. The backup data is expected to be encrypted so that it cannot be identified from the outside.
[0141] The external storage device 60 is located outside the monitoring unit 20. Data communication between the external storage device 60 and the monitoring unit 20 is conducted via wireless communication based on OTA or wired communication via communication cables. OTA is an abbreviation for Over The Air.
[0142] Next, the monitoring unit 20 deletes the monitoring data stored in the storage unit 22 in step S120. Thus, access to the monitoring data stored in the storage unit 22 is restricted. The aforementioned steps S110 and S120 are performed by the access restriction unit 247.
[0143] Next, in step S130, the monitoring unit 20 determines whether a host device with legitimate access rights, such as the regular battery ECU 50, has been notified of the unlock key to remove the access restriction.
[0144] The monitoring unit 20 waits until it is notified to remove the key. If it is notified to remove the key from the host device, it proceeds to step S140. In step S140, the monitoring unit 20 retrieves backup data from the external storage device 60 and restores the monitoring data to the storage unit 22 based on the backup data. This removes the restriction on access to the monitoring data. The aforementioned step S140 is processed by the access removal unit 248.
[0145] The unauthorized access countermeasures described above in the first embodiment can prevent the reading / tampering of monitoring data caused by unauthorized access. In particular, in this example, the monitoring data is restored to the storage unit 22 based on the backup data stored in the external storage device 60, so even in the event of unauthorized access, the process can be restored to battery cycle.
[0146] [Modifications of the First Embodiment]
[0147] In the first embodiment, access to the monitoring data is restricted upon detection or prediction of unauthorized access, but this is not a limitation. The monitoring unit 20 may, for example, periodically restrict access to the monitoring data, or restrict access based on command signals from a host device. This is also true in subsequent embodiments.
[0148] Furthermore, the backup of monitoring data to external storage device 60 is not limited to detecting or predicting unauthorized access to the monitoring data; it can also be performed periodically. Additionally, when the backup of monitoring data to external storage device 60 is performed periodically, if unauthorized access to the monitoring data is detected or predicted, the backup may not be performed, and the monitoring data may be deleted from storage unit 22 instead.
[0149] [Second Embodiment]
[0150] Next, refer to Figure 13 , Figure 14 The second embodiment will be described. The monitoring unit 20, for example, is designed for... Figure 13 Countermeasures for unauthorized access caused by intrusion into a host device, as shown, and implementation. Figure 14 The processing is shown. Figure 14 The processing shown is performed periodically or irregularly by the monitoring unit 20.
[0151] like Figure 14 As shown, in step S200, the monitoring unit 20 determines whether it has detected or predicted unauthorized access to the monitoring data stored in the storage unit 22. This determination process is the same as in the first embodiment, so its description is omitted.
[0152] If unauthorized access is detected or predicted, the monitoring unit 20 prohibits information access to the storage unit 22 in step S210. The monitoring unit 20 may, for example, interrupt external communication with the storage unit 22 by disabling the function of the wireless communication device 25, or set it to be unable to read monitoring data, thereby prohibiting information access to the storage unit 22. This restricts access to the monitoring data stored in the storage unit 22. The aforementioned step S210 is implemented by the access restriction unit 247.
[0153] Next, in step S220, the monitoring unit 20 determines whether a release key for removing access restrictions has been notified from a host device with legitimate access rights, such as a regular battery ECU 50.
[0154] If the host device notifies the release of the key, the monitoring unit 20 performs a process in step S230 that enables information access to the storage unit 22, allowing access to the information in the storage unit 22. Thus, the access restriction on the monitoring data is lifted. The aforementioned step S230 is performed by the access release unit 248.
[0155] The unauthorized access countermeasures of the second embodiment described above can prevent the reading / tampering of monitoring data caused by unauthorized access. In particular, the unauthorized access countermeasures of this example have the advantage of being able to achieve this through a simple process of switching between prohibiting and allowing information access to the storage unit 22.
[0156] [Third Embodiment]
[0157] Next, refer to Figure 15 , Figure 16 The third embodiment will be described. The monitoring unit 20, for example, is designed for... Figure 15 Countermeasures for unauthorized access caused by intrusion into a host device, as shown, and implementation. Figure 16 The processing is shown. Figure 16 The processing shown is performed periodically or irregularly by the monitoring unit 20.
[0158] like Figure 16 As shown, in step S300, the monitoring unit 20 determines whether it has detected or predicted unauthorized access to the monitoring data stored in the storage unit 22. This determination process is the same as in the first embodiment, so its description is omitted.
[0159] If unauthorized access is detected or predicted, the monitoring unit 20 encrypts the monitoring data stored in the storage unit 22 in step S310. Examples of encryption methods include public-key encryption. This restricts access to the monitoring data stored in the storage unit 22. The aforementioned step S310 is implemented by the access restriction unit 247.
[0160] Next, in step S320, the monitoring unit 20 determines whether a host device with legitimate access rights, such as the regular battery ECU 50, has been notified of the unlock key to remove the access restriction.
[0161] If the host device notifies the release of the key, the monitoring unit 20 decrypts the encrypted monitoring data in step S330. This removes the access restriction on the monitoring data. The aforementioned step S330 is processed by the access release unit 248.
[0162] The unauthorized access countermeasures described in the third embodiment above can prevent the reading / tampering of surveillance data caused by unauthorized access. In particular, in this example, there is the advantage of being able to implement countermeasures against unauthorized access through simple encryption and decryption of surveillance data.
[0163] [Fourth Embodiment]
[0164] Reference Figure 17 , Figure 18 The fourth embodiment will be described. The monitoring unit 20, for example, is designed for... Figure 17 Countermeasures for unauthorized access caused by intrusion into a host device, as shown, and implementation. Figure 18 The processing is shown. Figure 18 The processing shown is performed periodically or irregularly by the monitoring unit 20.
[0165] like Figure 18 As shown, in step S400, the monitoring unit 20 determines whether it has detected or predicted unauthorized access to the monitoring data stored in the storage unit 22. This determination process is the same as in the first embodiment, so its description is omitted.
[0166] If unauthorized access is detected or predicted, the monitoring unit 20 prohibits at least one of reading or modifying the monitoring data in step S410. For example, the monitoring unit 20 sets the access rights of the folder storing the monitoring data to be unreadable or unmodifiable, thereby prohibiting at least one of reading or modifying the monitoring data. This restricts access to the monitoring data stored in the storage unit 22. The aforementioned step S410 is implemented by the access restriction unit 247.
[0167] Next, in step S420, the monitoring unit 20 determines whether the access restriction removal key has been notified from a host device with legitimate access rights, such as the regular battery ECU 50.
[0168] If the host device notifies the removal of the key, the monitoring unit 20 allows the reading and rewriting of the monitoring data located in the storage unit 22 in step S430. This removes the access restriction on the monitoring data. The aforementioned step S430 is processed by the access removal unit 248.
[0169] The unauthorized access countermeasures described in the fourth embodiment above can prevent the reading or tampering of surveillance data caused by unauthorized access. In particular, in this example, there is the advantage of being able to implement countermeasures against unauthorized access through a simple process such as changing the access rights settings of the folder where the surveillance data is stored.
[0170] (Other implementation methods)
[0171] While the above describes representative embodiments of the present disclosure, the present disclosure is not limited to the above embodiments, and various modifications can be made as follows.
[0172] As described in the above embodiments, the battery monitoring system 1 is preferably configured to respond to "impersonation of the monitoring unit 20", "data forgery using signal interference", "intrusion into the host device", "battery theft", and "unauthorized access", but is not limited thereto. The battery monitoring system 1 may also be configured to respond to some of the above-mentioned illegal acts, or to respond to other illegal acts besides those described above.
[0173] As described above, the host device preferably uses blockchain to store at least a portion of the specific information contained in the monitoring data, but this is not always the case.
[0174] As described in the above embodiment, the sensor unit 21 of the monitoring unit 20 preferably includes a temperature sensor 211, a current sensor 212, a voltage sensor 213, a degradation detection unit 214, and a SOH inference unit 215, but it is not limited to this. For example, the sensor unit 21 of the monitoring unit 20 may not include the degradation detection unit 214 and the SOH inference unit 215.
[0175] As described in the above embodiments, the first data protection unit 24 preferably includes a first information authentication unit 241, a first data authentication unit 242, a diagnostic unit 243, a self-stopping unit 244, an encrypted communication unit 245, an access restriction unit 247, and an access deactivation unit 248, but it is not limited to this. For example, the first data protection unit 24 may also omit a portion of the first information authentication unit 241, the first data authentication unit 242, the diagnostic unit 243, the self-stopping unit 244, the encrypted communication unit 245, the access restriction unit 247, and the access deactivation unit 248.
[0176] As described in the above embodiment, the second data protection unit 56 of the battery ECU 50 preferably includes a second information authentication unit 561, a second data authentication unit 562, a decryption processing unit 563, and a charging restriction unit 564, but it is not limited to this. For example, the second data authentication unit 562 may not include a portion of the second information authentication unit 561, the second data authentication unit 562, the decryption processing unit 563, and the charging restriction unit 564.
[0177] In the above embodiments, the connecting member WH is illustrated to include a flexible substrate FPC, but it is not limited thereto, and the connecting member WH may not include a flexible substrate FPC.
[0178] In the above embodiments, the battery ECU 50 and the charger CH are exemplified as the host devices of the monitoring unit 20, but the host device may also be composed of devices different from the battery ECU 50 and the charger CH.
[0179] Battery monitoring system 1 monitors lithium-ion batteries, but is not limited to this. The monitoring object of battery monitoring system 1 can also be a battery other than lithium-ion batteries. Battery monitoring system 1 can also be configured such that the monitoring unit 20 is connected to the host device via a wired connection instead of wirelessly. Furthermore, battery monitoring system 1 is not limited to being completely identical to the battery monitoring system described above, and may differ from it in some aspects.
[0180] In the above embodiments, the elements constituting the embodiments are not necessarily required, except where they are specifically stated to be necessary or are obviously considered necessary in principle.
[0181] In the above embodiments, when referring to the number, value, quantity, range, or other numerical values of the constituent elements of the embodiments, the references are not limited to those specific numbers, except where they are specifically stated to be necessary or where they are clearly limited to a specific number in principle.
[0182] In the above embodiments, when referring to the shape, positional relationship, etc. of constituent elements, etc., the references are not limited to that shape, positional relationship, etc., except as specifically stated or as limited in principle to a specific shape, positional relationship, etc.
[0183] The control unit and method of this disclosure can also be implemented using a dedicated computer, which is provided by comprising a processor programmed to perform one or more functions embodied in a computer program and a memory. The control unit and method of this disclosure can also be implemented using a dedicated computer, which is provided by comprising a processor composed of one or more dedicated hardware logic circuits. The control unit and method of this disclosure can also be implemented using more than one dedicated computer, which is constructed by combining a processor programmed to perform one or more functions and a memory with a processor composed of one or more hardware logic circuits. Alternatively, the computer program can also be stored as instructions to be executed by the computer on a computer-readable non-transitional tangible recording medium.
[0184] [This is a public statement]
[0185] [First Viewpoint]
[0186] A battery monitoring system, characterized in that it comprises:
[0187] The monitoring unit monitors the rechargeable and dischargeable batteries; and
[0188] The host device is provided with monitoring data obtained through monitoring of the battery by the monitoring unit, and uses blockchain to store at least a portion of the specific information contained in the monitoring data.
[0189] The host device has:
[0190] A block generation unit generates a new block containing at least a portion of the specific information and a hash value based on the last block in the last link of the blockchain; and
[0191] External communication devices are used to distribute and store the new blocks generated by the block generation unit across multiple external devices.
[0192] At least one of the monitoring unit and the host device is provided with a data protection unit to ensure the reliability of the monitoring data.
[0193] [Second Viewpoint]
[0194] According to the battery monitoring system described in the first viewpoint, the monitoring unit and the host device each have an information authentication unit for mutually authenticating the specific information as the data protection unit.
[0195] [Third Viewpoint]
[0196] According to the battery monitoring system described in the first or second viewpoint, the monitoring unit has an encrypted communication unit that encrypts the monitoring data and sends it to the host device as a data protection unit.
[0197] [Fourth viewpoint]
[0198] According to any one of the first to third viewpoints, the battery monitoring system wherein the monitoring unit has a diagnostic unit as the data protection unit for diagnosing whether the instruction signal sent from the host device is appropriate.
[0199] [Fifth Viewpoint]
[0200] According to the battery monitoring system described in the fourth viewpoint, the diagnostic unit generates a learned model by learning the instruction signal from the host device, and uses the learned model to diagnose whether the instruction signal is appropriate.
[0201] [Sixth Viewpoint]
[0202] According to the battery monitoring system described in the fourth or fifth viewpoint, the monitoring unit has a self-stopping unit as the data protection unit that stops itself when the diagnostic unit diagnoses the command signal as inappropriate.
[0203] [Seventh Viewpoint]
[0204] According to any one of the first to sixth viewpoints, in the battery monitoring system, the host device includes a charging control function for controlling the charging of the battery.
[0205] Both the monitoring unit and the host device store a unique ID assigned to the monitoring unit.
[0206] The monitoring unit and the host device each have a data authentication unit for mutually authenticating the inherent ID.
[0207] The host device prohibits charging the battery if the authentication result from the data authentication department indicates that the unique IDs stored in the host device and the monitoring department are inconsistent.
[0208] [Eighth Viewpoint]
[0209] According to any one of the first to fifth viewpoints, the battery monitoring system includes an access restriction unit and an access deactivation unit as the data protection unit. The access restriction unit restricts external access to the monitoring data stored in the storage unit of the monitoring unit. If the access deactivation unit is notified of a pre-set deactivation key from the host device while the access is restricted, the access restriction is lifted.
[0210] [Ninth Viewpoint]
[0211] A battery monitoring system, characterized in that it comprises:
[0212] The monitoring unit monitors the rechargeable and dischargeable batteries; and
[0213] The host device is provided with monitoring data obtained through the monitoring of the battery by the monitoring unit.
[0214] A data protection unit is provided in the monitoring unit to ensure the reliability of the monitoring data.
[0215] The data protection unit includes an access restriction unit and an access deactivation unit. The access restriction unit restricts external access to the monitoring data stored in the storage unit of the monitoring unit. If the access is restricted and a pre-set deactivation key is notified from the host device, the access deactivation unit removes the access restriction.
[0216] [Tenth Viewpoint]
[0217] According to the battery monitoring system described in the eighth or ninth viewpoint, the access restriction unit, after storing the monitoring data as backup data in an external storage device located outside the monitoring unit, deletes the monitoring data from the storage device, thereby restricting access.
[0218] If the access release unit is notified of the release key, it uses the backup data stored in the external storage device to restore the monitoring data to the storage unit, thereby releasing the access restriction.
[0219] [Eleventh Viewpoint]
[0220] According to the battery monitoring system described in the eighth or ninth viewpoint, the access restriction unit restricts access by prohibiting access to information in the storage unit.
[0221] If the access release unit is notified of the release key, it allows access to the information, thereby removing the access restriction.
[0222] [Twelfth Viewpoint]
[0223] According to the battery monitoring system described in the eighth or ninth viewpoint, the access restriction unit restricts access by encrypting the monitoring data located in the storage unit.
[0224] If the access release unit is notified of the release key, it will decrypt the encrypted monitoring data, thereby releasing the access restriction.
[0225] [Thirteenth Viewpoint]
[0226] According to the battery monitoring system described in the eighth or ninth viewpoint, the access restriction unit restricts access by prohibiting at least one of reading and rewriting the monitoring data located in the storage unit.
[0227] If the access release unit is notified of the release key, it allows the reading and rewriting of the monitoring data located in the storage unit, thereby removing the access restriction.
[0228] [Fourteenth Viewpoint]
[0229] A battery monitoring system, characterized in that it comprises:
[0230] The monitoring unit monitors the rechargeable and dischargeable batteries; and
[0231] The charger controls the charging of the battery.
[0232] Both the monitoring unit and the charger store a unique ID assigned to the monitoring unit.
[0233] The monitoring unit and the charger each have a data authentication unit for mutually authenticating the inherent ID.
[0234] If the authentication result from the data authentication unit indicates that the inherent ID stored in the charger and the monitoring unit are inconsistent, the charger will prohibit charging of the battery.
[0235] [Fifteenth Viewpoint]
[0236] According to any one of the eighth to thirteenth viewpoints, in the battery monitoring system, if the access restriction unit detects or predicts the illegal access, it restricts external access to the monitoring data.
Claims
1. A battery monitoring system, characterized in that, have: The monitoring department monitors batteries that can be charged and discharged. as well as The host device is provided with monitoring data obtained through monitoring of the battery by the monitoring unit, and uses blockchain to store at least a portion of the specific information contained in the monitoring data. The host device has: The block generation unit generates a new block that contains at least a portion of the specific information and the hash value of the last block in the last link of the blockchain. as well as External communication devices are used to distribute and store the new blocks generated by the block generation unit across multiple external devices. At least one of the monitoring unit and the host device is provided with a data protection unit to ensure the reliability of the monitoring data. The monitoring unit includes a diagnostic unit that diagnoses whether the command signals sent from the host device are appropriate, which serves as the data protection unit. The diagnostic unit generates a learned model by learning the tendencies of command signals sent from the host device, and uses the learned model to diagnose the received command signals. If the command signal follows the past tendencies of the learned model, the diagnosis is appropriate.
2. The battery monitoring system according to claim 1, characterized in that, The monitoring unit and the host device each have an information authentication unit for mutually authenticating the specific information as the data protection unit.
3. The battery monitoring system according to claim 1 or 2, characterized in that, The monitoring unit includes an encrypted communication unit that encrypts the monitoring data and sends it to the host device as a data protection unit.
4. The battery monitoring system according to claim 1 or 2, characterized in that, The monitoring unit has a self-stopping unit that stops itself when the diagnostic unit diagnoses the command signal as inappropriate, which serves as the data protection unit.
5. The battery monitoring system according to claim 1 or 2, characterized in that, The host device includes a charging control function to control the charging of the battery. Both the monitoring unit and the host device store a unique ID assigned to the monitoring unit. The monitoring unit and the host device each have a data authentication unit for mutually authenticating the inherent ID. The host device prohibits charging the battery if the authentication result from the data authentication department indicates that the unique IDs stored in the host device and the monitoring department are inconsistent.
6. The battery monitoring system according to claim 1, characterized in that, The monitoring unit includes an access restriction unit and an access deactivation unit as the data protection unit. The access restriction unit restricts external access to the monitoring data stored in the storage unit of the monitoring unit. If the access deactivation unit is notified of a pre-set deactivation key from the host device while the access is restricted, the access restriction is lifted.
7. The battery monitoring system according to claim 6, characterized in that, The access restriction unit restricts access by storing the monitoring data as backup data on an external storage device located outside the monitoring unit, and then deleting the monitoring data from the storage device. If the access release unit is notified of the release key, it uses the backup data stored in the external storage device to restore the monitoring data to the storage unit, thereby releasing the access restriction.
8. The battery monitoring system according to claim 6 or 7, characterized in that, The access restriction unit restricts access by prohibiting access to information in the storage unit. If the access release unit is notified of the release key, it allows access to the information, thereby removing the access restriction.
9. The battery monitoring system according to claim 6 or 7, characterized in that, The access restriction unit restricts access by encrypting the monitoring data located in the storage unit. If the access release unit is notified of the release key, it will decrypt the encrypted monitoring data, thereby releasing the access restriction.
10. The battery monitoring system according to claim 6 or 7, characterized in that, The access restriction unit restricts access by prohibiting at least one of reading or rewriting the monitoring data located in the storage unit. If the access release unit is notified of the release key, it allows the reading and rewriting of the monitoring data located in the storage unit, thereby removing the access restriction.
Citation Information
Patent Citations
Battery monitor
WO2020025943A1