Charging device and charging method

The charging device addresses the challenge of minimizing attack impact during BEV vehicle charging by using a dedicated sandbox task and a handover task to manage battery state and charge amount, effectively suppressing attack propagation and ensuring charging safety and legitimacy.

JP2025080610APending Publication Date: 2025-05-26PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023193876
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-14
Publication Date
2025-05-26

AI Technical Summary

Technical Problem

Existing charging devices for BEV vehicles face challenges in minimizing the impact of attacks during charging, while continuing to manage the battery state and charge amount effectively.

Method used

A charging device with a processor and memory that generates a dedicated sandbox charging task, detects attacks, and transitions to a handover charging task that does not communicate with the charging station, allowing the handover task to acquire battery state and charge information before deleting the original task.

Benefits of technology

This solution effectively suppresses the propagation of attacks while continuously managing the battery state and charge amount, ensuring the safety and legitimacy of the charging process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025080610000001_ABST
    Figure 2025080610000001_ABST
Patent Text Reader

Abstract

To provide a charging device capable of suppressing propagation of an attack while continuing management of a battery state and a charging amount.SOLUTION: A charging device 10 mounted on a vehicle includes a processor 11 and a memory 17. The processor 11 uses the memory 17 to determine whether or not a charging station for charging a battery mounted on the vehicle and the charging device 10 are connected. When determining that the charging station and the charging device 10 are connected, the charging device generates a charging task that functions as a sandbox dedicated to charging the battery, and determines whether or not an attack to the charging device 10 is detected. When determining that the attack to the charging device 10 is detected, the charging device generates a charging task for takeover that does not communicate with the charging station, and allows the charging task for takeover to acquire information that exhibits a battery state and information that exhibits a charging amount to the battery, and thereafter deletes the charging task.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a charging device for charging a battery mounted on a vehicle, etc.

Background Art

[0002] When resources such as memory are insufficient and there is a risk that the system may stop, an OS (Operating System) such as Linux (registered trademark) has a function of forcibly terminating tasks that consume resources to secure resources. However, since important tasks may also be forcibly terminated, Patent Document 1 discloses a method of forcibly terminating unimportant tasks and executing important tasks without forcibly terminating them even when resources are insufficient.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] When a charging device for charging a vehicle such as a BEV (Battery Electric Vehicle) is attacked during charging of the vehicle, it is necessary to minimize the impact of the attack and at the same time continue to manage the state and charge amount of the battery. Since the management of the battery state is related to safety and the management of the charge amount is related to billing, the management of the battery state and charge amount is a very important process. Since the charging task is a task that performs these processes, the charging task is an important task.

[0005] For example, when the method disclosed in Patent Document 1 is applied to a charging device such as a BEV vehicle, even if excessive resource consumption occurs, the charging task, which is an important task, is not forcibly terminated, in other words, not deleted. Therefore, even when the charging device is attacked and malware invades the charging task, resulting in excessive resource consumption due to the malware, the charging task is not deleted, and there is a risk that the attack may spread to the outside of the charging task (for example, other ECUs (Electronic Control Unit)).

[0006] Therefore, the present disclosure provides a charging device and the like that can suppress the propagation of an attack while continuing to manage the state and charge amount of the battery.

Means for Solving the Problem

[0007] The charging device according to the present disclosure is a charging device mounted on a vehicle, comprising a processor and a memory. The processor uses the memory to determine whether a charging station for charging the battery mounted on the vehicle is connected to the charging device. When it is determined that the charging station and the charging device are connected, a charging task that functions as a dedicated sandbox for charging the battery is generated. It is determined whether an attack on the charging device is detected. When it is determined that an attack on the charging device is detected, a handover charging task that does not communicate with the charging station is generated. After causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, the charging task is deleted.

[0008] The charging device according to the present disclosure is a charging device mounted on a charging station for charging a vehicle, and includes a processor and a memory. The processor uses the memory to determine whether the vehicle and the charging device are connected. When it is determined that the vehicle and the charging device are connected, a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle is generated. It is determined whether an attack on the charging device is detected. When it is determined that an attack on the charging device is detected, a handover charging task that does not communicate with the vehicle is generated. After causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, the charging task is deleted.

[0009] The charging method according to the present disclosure is a charging method executed by a charging device mounted on a vehicle. It is determined whether a charging station for charging the vehicle and the charging device are connected. When it is determined that the charging station and the charging device are connected, a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle is generated. It is determined whether an attack on the charging device is detected. When it is determined that an attack on the charging device is detected, a handover charging task that does not communicate with the charging station is generated. After causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, the charging task is deleted.

[0010] The charging method according to the present disclosure is a charging method executed by a charging device mounted on a charging station for charging a vehicle. It is determined whether the vehicle and the charging device are connected. When it is determined that the vehicle and the charging device are connected, a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle is generated. It is determined whether an attack on the charging device is detected. When it is determined that an attack on the charging device is detected, a handover charging task that does not communicate with the vehicle is generated. After causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, the charging task is deleted.

[0011] Note that these general or specific aspects may be implemented in a system, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM, or may be implemented in any combination of a system, method, integrated circuit, computer program, and recording medium.

Advantages of the Invention

[0012] According to a charging device or the like according to one aspect of the present disclosure, it is possible to suppress the propagation of an attack while continuously managing the state and charge amount of a battery.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments will be specifically described with reference to the drawings.

[0015] Note that all the embodiments described below show comprehensive or specific examples. The numerical values, shapes, materials, components, arrangement positions and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are just examples and not the gist for limiting the present disclosure.

[0016] (Embodiment) Hereinafter, the charging device according to the embodiment will be described.

[0017] First, an application example of the charging device according to the embodiment will be described with reference to FIG. 1.

[0018] FIG. 1 is a diagram for explaining an application example of the charging device according to the embodiment. FIG. 1 shows a vehicle 100, a charging station 200, and a vehicle management server 300 and a charging station management server 400 that are communicably connected to the vehicle 100 and the charging station 200. The charging device according to the embodiment is mounted on the vehicle 100 or the charging station 200. The charging device 10 is a charging device mounted on the vehicle 100, and the charging device 20 is a charging device mounted on the charging station 200.

[0019] Vehicle 100 is, for example, a BEV vehicle and is equipped with a battery 30 for driving a motor or the like. In addition, sensors such as a GPS (Global Positioning System) 50, a speed sensor 60, and a camera 70 are provided in the vehicle 100. Further, a TCU (Telematics Control Unit) 40 is provided in the vehicle 100, and the vehicle 100 can communicate with a vehicle management server 300 and a charging station management server 400 outside the vehicle 100. The charging device 10 is a device for charging the battery 30 and is, for example, an OBC (On Board Charger). The charging device 10 is connected to a charging station 200 (specifically, the charging device 20 of the charging station 200) and supplies power from the charging station 200 to the battery 30. The charging device 10 has a charging port into which a charging connector provided at the tip of the charging cable of the charging station 200 is inserted.

[0020] The charging station 200 is a device for charging the battery 30 mounted on the vehicle 100, and when connected to the vehicle 100 (specifically, the charging device 10), charges the battery 30 via the charging device 10. In addition, a camera 90 is provided in the charging station 200. Further, a communication IF (InterFace) 80 is provided in the charging station 200, and the charging station 200 can communicate with a vehicle management server 300 and a charging station management server 400 outside the charging station 200. The charging device 20 is a device for charging the battery 30 via the charging device 10. The charging device 20 is connected to the vehicle 100 (specifically, the charging device 10 of the vehicle 100) and supplies power from the charging station 200 to the battery 30 via the charging device 10. The charging device 20 has a charging cable provided with a charging connector at the tip that is inserted into the charging port of the vehicle 100.

[0021] The vehicle management server 300 is a server that manages a plurality of vehicles 100. For example, the vehicle management server 300 acquires and stores position information from each of the plurality of vehicles 100 it manages.

[0022] The charging station management server 400 is a server that manages a plurality of charging stations 200. For example, the charging station management server 400 stores the location information of each of the plurality of charging stations 200 it manages.

[0023] Although FIG. 1 shows a state where a normal charging station 200 is connected to the charging device 10, the charging device 10 may be connected to a device masquerading as a charging station 200, or a charging station invaded by malware. Similarly, although FIG. 1 shows a state where a normal vehicle 100 is connected to the charging device 20, the charging device 20 may be connected to a device masquerading as a vehicle 100, or a vehicle invaded by malware.

[0024] Next, the charging device 10 mounted on the vehicle 100 will be described.

[0025] FIG. 2 is a block diagram showing an example of the charging device 10 of the vehicle 100 according to the embodiment.

[0026] The charging device 10 includes a processor 11 and a memory 17. The memory 17 is, for example, a ROM (Read Only Memory) and a RAM (Random Access Memory), and can store programs executed by the processor 11. The processor 11 includes, as functional components, a connection determination unit 12, a charging task generation unit 13, an attack determination unit 14, a handover charging task generation unit 15, and a charging task deletion unit 16. In other words, the connection determination unit 12, the charging task generation unit 13, the attack determination unit 14, the handover charging task generation unit 15, and the charging task deletion unit 16 are realized by the processor 11 that executes the programs stored in the memory 17. That is, the processor 11 uses the memory 17 to execute the processes performed by the connection determination unit 12, the charging task generation unit 13, the attack determination unit 14, the handover charging task generation unit 15, and the charging task deletion unit 16.

[0027] The connection determination unit 12 determines whether the charging station 200 and the charging device 10 are connected. For example, when it is detected that the charging connector is inserted into the charging port provided in the charging device 10, the connection determination unit 12 determines that the charging station 200 and the charging device 10 are connected.

[0028] When the connection determination unit 12 determines that the charging station 200 and the charging device 10 are connected, the charging task generation unit 13 generates a charging task. The charging task is a VM (Virtual Machine) or a process that functions as a dedicated sandbox for charging. The charging task can only use limited functions (APIs (Application Programming Interfaces)) related to the charging of the vehicle 100. In other words, the charging task cannot use more vehicle 100 functions than necessary to prevent malware intrusion.

[0029] The charging task charges the battery 30 and manages the state and charge amount of the battery 30. The charging task acquires information indicating the state of the battery 30 from the battery 30 or the like and stores it in a memory (shared memory). Note that the memory in which the information indicating the state of the battery 30 is stored may be the memory 17 in which the program is stored, or may be a memory different from the memory 17. The information indicating the state of the battery 30 is, for example, SOC (State Of Charge) and SOH (State Of Health). Also, the charging task stores information indicating the amount of charge to the battery 30 (the amount of electric power charged to the battery 30 since the charging of the battery 30 started) in the memory. Note that the memory in which the information indicating the amount of charge to the battery 30 is stored may be the memory 17 in which the program is stored or the memory in which the information indicating the state of the battery 30 is stored, or may be a memory different from these memories.

[0030] The attack determination unit 14 determines whether an attack on the charging device 10 has been detected. Details of the operation of the attack determination unit 14 will be described later.

[0031] When the attack determination unit 14 determines that an attack on the charging device 10 has been detected, the handover charging task generation unit 15 generates a handover charging task that does not communicate with the charging station 200. The handover charging task is a VM or process that takes over the management of the state and charge amount of the battery 30 from the charging task. Further, when charging of the battery 30 has been started by the charging task, the handover charging task performs a charging end process. Note that the handover charging task does not necessarily function as a sandbox.

[0032] After causing the handover charging task to acquire information indicating the state of the battery 30 and information indicating the amount of charge to the battery 30, the charging task deletion unit 16 deletes the charging task. Further, when charging of the battery 30 has been started by the charging task, when the attack determination unit 14 determines that an attack on the charging device 10 has been detected, the handover charging task is caused to perform a charging end process.

[0033] Next, the details of the operation of the charging device 10 will be described with reference to FIGS. 3 and 4. First, the operation of the charging device 10 before the start of the charging process will be described with reference to FIG. 3.

[0034] FIG. 3 is a flowchart showing an example of the operation of the charging device 10 of the vehicle 100 according to the embodiment before the start of the charging process.

[0035] First, the connection determination unit 12 determines that the charging device 10 and the charging station 200 are connected, in other words, detects the connection between the charging device 10 and the charging station 200 (step S101).

[0036] Next, the charging task generation unit 13 generates a charging task (step S102).

[0037] Next, the charging task communicates with the charging station 200 to start the charging process (step S103).

[0038] Next, the attack determination unit 14 acquires the position information of the vehicle 100 and the position information of the charging station 200, and checks the consistency between the position information of the vehicle 100 and the position information of the charging station 200 (step S104). For example, the attack determination unit 14 acquires the position information of the vehicle 100 from the GPS 50 and acquires the position information of the charging station 200 from the charging station management server 400. If there is no consistency between the position information of the vehicle 100 and the position information of the charging station 200, it can be determined that an attack on the charging device 10 has been detected because the charging device 10 of the vehicle 100 at a position different from the position of the charging station 200 is connected to a device posing as the charging station 200 and the charging device 10 may be under attack.

[0039] The attack determination unit 14 determines whether there is consistency between the position information of the vehicle 100 and the position information of the charging station 200 (step S105). If there is no problem with the consistency (No in step S105), the charging device 10 starts the charging process. The operation of the charging device 10 after starting the charging process will be described with reference to FIG. 4 below.

[0040] If there is no consistency between the position information of the vehicle 100 and the position information of the charging station 200, that is, if there is a problem with the consistency (Yes in step S105), the attack determination unit 14 determines that an attack on the charging device 10 has been detected, and the processes after step S106 are performed.

[0041] First, the handover charging task generation unit 15 generates a handover charging task (step S106).

[0042] Next, the charging task deletion unit 16 causes the relay charging task to acquire the relay information (step S107). Specifically, the charging task deletion unit 16 causes the relay charging task to acquire the information indicating the state of the battery 30 and the information indicating the amount of charge to the battery 30. The relay charging task acquires the information indicating the state of the battery 30 and the information indicating the amount of charge to the battery 30 stored in the memory by the charging task from the memory. Note that since it is before the start of the charging process, the amount of charge to the battery 30 is 0.

[0043] Then, the charging task deletion unit 16 deletes the charging task (step S108).

[0044] In steps S104 and S105, the attack determination unit 14 may acquire the sensing data of sensors such as the speed sensor 60 or the camera 70 provided in the vehicle 100, and determine whether an attack on the charging device 10 is detected based on the sensing data. When the charging device 10 is attacked, the sensing data of the sensors provided in the vehicle 100 may be different from the normal data, so it is possible to determine whether an attack on the charging device 10 is detected based on the sensing data.

[0045] For example, the attack determination unit 14 acquires, as sensing data, an image captured by the camera 70 provided in the vehicle 100, and if the image does not show that the charging station 200 and the charging device 10 are connected, it may be determined that an attack on the charging device 10 is detected. If the image captured by the camera 70 does not show that the charging station 200 and the charging device 10 are connected, there is a possibility that a device posing as the charging station 200 is connected to the charging device 10, so it can be determined that an attack on the charging device 10 is detected.

[0046] For example, the attack determination unit 14 may acquire, as sensing data, the speed information of the vehicle 100 obtained by the speed sensor 60 provided in the vehicle 100, and when the speed information indicates that the vehicle 100 is moving, it may be determined that an attack on the charging device 10 has been detected. When the speed information indicates that the vehicle 100 is moving, the vehicle 100 is not connected to the charging station 200 during movement, and since there is a possibility that the charging device 10 is being attacked, it can be determined that an attack on the charging device 10 has been detected.

[0047] Next, the operation after the start of the charging process of the charging device 10, which is performed when an attack on the charging device 10 is not detected before the start of the charging process of the charging device 10, will be described with reference to FIG. 4.

[0048] FIG. 4 is a flowchart showing an example of the operation after the start of the charging process of the charging device 10 of the vehicle 100 according to the embodiment.

[0049] The attack determination unit 14 acquires the charging amount information received by the vehicle 100 from the charging station management server 400 and the charging amount information measured by the vehicle 100 (step S111). The charging station 200 transmits charging amount information indicating the charging amount to the battery 30 of the vehicle 100 to the charging station management server 400, and the vehicle 100 can receive the charging amount information from the charging station management server 400 for the charging amount from the charging station 200 to the battery 30 of the vehicle 100. Further, the charging device 10 can measure charging amount information indicating the charging amount from the start of charging the battery 30 until the present. The charging amount information received from the charging station management server 400 and the charging amount information measured by the vehicle 100 are consistent under normal conditions, but when there is no consistency between the charging amount information received from the charging station management server 400 and the charging amount information measured by the vehicle 100, since there is a possibility that the charging device 10 is being attacked, it can be determined that an attack on the charging device 10 has been detected.

[0050] The attack determination unit 14 determines whether there is consistency between the charge amount information received from the charging station management server 400 and the charge amount information measured by the vehicle 100, that is, whether there is a difference in each charge amount (step S112).

[0051] If there is no consistency between the charge amount information received from the charging station management server 400 and the charge amount information measured by the vehicle 100, that is, if there is a difference in each charge amount (Yes in step S112), the attack determination unit 14 determines that an attack on the charging device 10 has been detected, and the processing after step S116 is performed.

[0052] If there is consistency between the charge amount information received from the charging station management server 400 and the charge amount information measured by the vehicle 100, that is, if there is no difference in each charge amount (No in step S112), the attack determination unit 14 monitors the communication between the charging device 10 and the charging station 200 (step S113). If the communication volume between the charging device 10 and the charging station 200 is larger than a predetermined communication volume, it can be determined that the charging device 10 has been attacked, so it is determined that an attack on the charging device 10 has been detected.

[0053] The attack determination unit 14 determines whether the communication volume of the communication between the charging device 10 and the charging station 200 is larger than a predetermined communication volume, that is, whether the communication volume is abnormal (step S114).

[0054] If the communication volume of the communication between the charging device 10 and the charging station 200 is larger than a predetermined communication volume, that is, if the communication volume is abnormal (Yes in step S114), the attack determination unit 14 determines that an attack on the charging device 10 has been detected, and the processing after step S116 is performed.

[0055] When the communication volume between the charging device 10 and the charging station 200 is less than a predetermined communication volume, that is, when the communication volume is normal (No in step S114), the charging task determines whether charging has been completed (step S115). If charging has not been completed (No in step S115), the processing from step S111 is repeated until charging is completed. If charging has been completed (Yes in step S115), the charging task performs charging end processing and the charging process ends.

[0056] Note that the order in which step S111 and step S112, and step S113 and step S114 are performed may be reversed. Also, either one of step S111 and step S112, and step S113 and step S114 may not be performed.

[0057] When Yes in step S112 or Yes in step S114, the handover charging task generation unit 15 generates a handover charging task (step S116).

[0058] Next, the charging task deletion unit 16 causes the handover charging task to acquire handover information (step S117). Specifically, the charging task deletion unit 16 causes the handover charging task to acquire information indicating the state of the battery 30 and information indicating the amount of charge to the battery 30. The handover charging task acquires information indicating the state of the battery 30 and information indicating the amount of charge to the battery 30 stored in the memory by the charging task from the memory. For example, the charging task deletion unit 16 causes the handover charging task to calculate the amount of charge charged to the battery 30 since the start of the charging process.

[0059] Next, the charging task deletion unit 16 causes the handover charging task to perform a charging end process to the battery 30 (step S118). Thereby, even when an attack on the charging device 10 is detected and the charging task is deleted, charging can be ended by the handover charging task instead of the charging task.

[0060] Then, the charging task deletion unit 16 deletes the charging task (step S119).

[0061] Note that the determination of an attack on the charging device 10 by the attack determination unit 14 may be performed only before the start of the charging process, or may be performed only after the start of the charging process. For example, at least one of an attack determination using position information, an attack determination using an image captured by the camera 70, an attack determination using speed information obtained by the speed sensor 60, an attack determination using charge amount information, and an attack determination using the communication volume of communication between the charging device 10 and the charging station 200 may be performed.

[0062] As described above, when an attack on the charging device 10 is detected, a handover charging task is generated, and information indicating the state of the battery 30 and information indicating the amount of charge to the battery 30 are handed over to the handover charging task before the charging task is deleted. Therefore, the management of the state and charge amount of the battery 30 can be continued. Further, when it is determined that the charging device 10 is connected to the charging station 200 and an attack on the charging device 10 is detected, there is a possibility that malware has invaded the charging station 200 or a device masquerading as the charging station 200 is connected to the charging device 10 and the malware has invaded the dedicated charging task. However, since the charging task is deleted, the propagation of the attack can be suppressed. In addition, since the newly generated handover charging task does not communicate with the charging station 200, there is no possibility that malware will invade the handover charging task. Therefore, while continuing the management of the state and charge amount of the battery 30, the propagation of the attack can be suppressed. That is, the safety of the vehicle 100 and the legitimacy of charging can be ensured.

[0063] Next, the charging device 20 mounted on the charging station 200 will be described.

[0064] FIG. 5 is a block diagram showing an example of the charging device 20 of the charging station 200 according to the embodiment.

[0065] The charging device 20 includes a processor 21 and a memory 27. The memory 27 is, for example, a ROM and a RAM, and can store programs executed by the processor 21. The processor 21 includes, as functional components, a connection determination unit 22, a charging task generation unit 23, an attack determination unit 24, a handover charging task generation unit 25, and a charging task deletion unit 26. In other words, the connection determination unit 22, the charging task generation unit 23, the attack determination unit 24, the handover charging task generation unit 25, and the charging task deletion unit 26 are realized by the processor 21 that executes programs stored in the memory 27. That is, the processor 21 uses the memory 27 to execute the processes performed by the connection determination unit 22, the charging task generation unit 23, the attack determination unit 24, the handover charging task generation unit 25, and the charging task deletion unit 26.

[0066] The connection determination unit 22 determines whether the vehicle 100 and the charging device 20 are connected. For example, when it is detected that the charging connector of the charging cable provided in the charging device 20 is inserted into the charging port provided in the charging device 10, the connection determination unit 22 determines that the vehicle 100 and the charging device 20 are connected.

[0067] When the connection determination unit 22 determines that the vehicle 100 and the charging device 20 are connected, the charging task generation unit 23 generates a charging task. The charging task is a VM or a process that functions as a dedicated sandbox for charging. The charging task can only use limited functions (APIs) related to the charging of the charging station 200. In other words, the charging task cannot use functions of the charging station 200 that are more than necessary in preparation for malware intrusion.

[0068] The charging task performs charging of the battery 30 via the charging device 10 and manages the state and charge amount of the battery 30. The charging task acquires information indicating the state of the battery 30 from the vehicle 100 and stores it in the memory. Note that the memory in which the information indicating the state of the battery 30 is stored may be the memory 27 in which the program is stored, or may be a memory different from the memory 27. The information indicating the state of the battery 30 is, for example, SOC and SOH, etc. Also, the charging task stores information indicating the charge amount to the battery 30 (the amount of electric power charged to the battery 30 since the charging of the battery 30 was started) in the memory. Note that the memory in which the information indicating the charge amount to the battery 30 is stored may be the memory 27 in which the program is stored or the memory in which the information indicating the state of the battery 30 is stored, or may be a memory different from these memories.

[0069] The attack determination unit 24 determines whether an attack on the charging device 20 has been detected.

[0070] For example, the attack determination unit 24 acquires the position information of the vehicle 100 and the position information of the charging station 200, and determines that an attack on the charging device 20 has been detected when there is no consistency between the position information of the vehicle 100 and the position information of the charging station 200. For example, the attack determination unit 24 acquires the position information of the vehicle 100 from the vehicle management server 300 and acquires the position information of the charging station 200 from the charging station management server 400. When there is no consistency between the position information of the vehicle 100 and the position information of the charging station 200, the charging device 20 of the charging station 200 at a position different from the position of the vehicle 100 is connected to the device posing as the vehicle 100, and since there is a possibility that the charging device 20 is being attacked, it can be determined that an attack on the charging device 20 has been detected.

[0071] For example, when the attack determination unit 24 acquires an image captured by the camera 90 provided in the charging station 200 and the image does not show that the vehicle 100 and the charging device 20 are connected, it determines that an attack on the charging device 20 has been detected. When the image captured by the camera 90 does not show that the vehicle 100 and the charging device 20 are connected, there is a possibility that a device posing as the vehicle 100 is connected to the charging device 20, so it can be determined that an attack on the charging device 20 has been detected.

[0072] For example, the attack determination unit 24 monitors the communication between the charging device 20 and the vehicle 100, and when the communication volume of the communication is greater than a predetermined communication volume, it determines that an attack on the charging device 20 has been detected. When the communication volume of the communication between the charging device 20 and the vehicle 100 is greater than a predetermined communication volume, there is a possibility that the charging device 20 is under attack, so it can be determined that an attack on the charging device 20 has been detected.

[0073] Note that in the charging device 20, attack determination using the speed information of the vehicle 100 and attack determination using the charge amount information are not performed.

[0074] When the handover charging task generation unit 25 determines that the attack determination unit 24 has detected an attack on the charging device 20, it generates a handover charging task that does not communicate with the vehicle 100. The handover charging task is a VM or process that takes over the management of the state and charge amount of the battery 30 from the charging task. Also, when charging of the battery 30 has been started by the charging task, the handover charging task performs a charging end process. Note that the handover charging task does not have to function as a sandbox.

[0075] After causing the inheritance charging task to acquire the information indicating the state of the battery 30 and the information indicating the amount of charge to the battery 30, the charging task deletion unit 26 deletes the charging task. Further, when charging of the battery 30 has been started by the charging task, if the attack determination unit 24 determines that an attack on the charging device 20 has been detected, the inheritance charging task is caused to perform a charging end process.

[0076] Regarding the details of the operation of the charging device 20, since it is basically similar to the operation of the charging device 10 except that the charging device 20 is mounted on the charging station 200 and the communication partner is the vehicle 100, the description thereof is omitted.

[0077] As described above, when an attack on the charging device 20 is detected, an inheritance charging task is generated, and the information indicating the state of the battery 30 and the information indicating the amount of charge to the battery 30 are taken over by the inheritance charging task before the charging task is deleted. Therefore, the state and charge amount of the battery 30 can be continuously managed. Further, when it is determined that the charging device 20 is connected to the vehicle 100 and an attack on the charging device 20 is detected, there is a possibility that malware has invaded the vehicle 100 or a device posing as the vehicle 100 is connected to the charging device 20 and the malware has invaded the dedicated charging task for charging. However, since the charging task is deleted, the propagation of the attack can be suppressed. Further, since the newly generated inheritance charging task does not communicate with the vehicle 100, there is no possibility that malware will invade the inheritance charging task. Therefore, while continuously managing the state and charge amount of the battery 30, the propagation of the attack can be suppressed. That is, the safety of the vehicle 100 and the charging station 200 and the legitimacy of charging can be ensured.

[0078] (Other Embodiments) As described above, embodiments have been described as examples of the technology according to the present disclosure. However, the technology according to the present disclosure is not limited thereto, and is also applicable to embodiments in which appropriate changes, replacements, additions, omissions, etc. are made. For example, the following modifications are also included in one embodiment of the present disclosure.

[0079] For example, the present disclosure can be implemented not only as the charging devices 10 and 20, but also as a charging method including steps (processes) performed by the components constituting the charging devices 10 and 20.

[0080] FIG. 6 and FIG. 7 are flowcharts showing an example of a charging method according to other embodiments.

[0081] The charging method is a charging method executed by a charging device 10 mounted on a vehicle 100. As shown in FIG. 6, it is determined whether a charging station 200 for charging the vehicle 100 and the charging device 10 are connected (step S11). When it is determined that the charging station 200 and the charging device 10 are connected (Yes in step S11), a charging task that functions as a dedicated sandbox for charging the battery 30 mounted on the vehicle 100 is generated (step S12). It is determined whether an attack on the charging device 10 is detected (step S13). When it is determined that an attack on the charging device 10 is detected (Yes in step S13), a handover charging task that does not communicate with the charging station 200 is generated (step S14). After causing the handover charging task to acquire information indicating the state of the battery 30 and information indicating the amount of charge to the battery 30 (step S15), the charging task is deleted (step S16). The process includes this.

[0082] The charging method is a charging method executed by a charging device 20 mounted on a charging station 200 that charges the vehicle 100. As shown in FIG. 7, it is determined whether the vehicle 100 and the charging device 20 are connected (step S21). When it is determined that the vehicle 100 and the charging device 20 are connected (Yes in step S21), a charging task is generated that functions as a dedicated sandbox for charging the battery 30 mounted on the vehicle 100 (step S22). It is determined whether an attack on the charging device 20 is detected (step S23). When it is determined that an attack on the charging device 20 is detected (Yes in step S23), a handover charging task that does not communicate with the vehicle 100 is generated (step S24). After causing the handover charging task to acquire information indicating the state of the battery 30 and information indicating the amount of charge to the battery 30 (step S25), the charging task is deleted (step S26). The process includes this.

[0083] For example, the present disclosure can be realized as a program for causing a computer (processor) to execute the steps included in the charging method. Furthermore, the present disclosure can be realized as a non-transitory computer-readable recording medium such as a CD-ROM on which the program is recorded.

[0084] For example, when the present disclosure is realized by a program (software), each step is executed by the program being executed using hardware resources such as a CPU, memory, and input / output circuit of a computer. That is, each step is executed by the CPU acquiring data from the memory or input / output circuit etc. and performing calculations, or outputting the calculation result to the memory or input / output circuit etc.

[0085] In the above-described embodiments, each component included in the charging devices 10 and 20 may be configured by dedicated hardware or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory.

[0086] Some or all of the functions of the charging devices 10 and 20 according to the above-described embodiments are typically realized as an LSI, which is an integrated circuit. These may be individually integrated into one chip, or may be integrated into one chip so as to include some or all of them. Further, the integration into an integrated circuit is not limited to an LSI, and it may be realized by a dedicated circuit or a general-purpose processor. An FPGA (Field Programmable Gate Array) that can be programmed after LSI manufacturing, or a reconfigurable processor that can reconfigure the connection and setting of circuit cells inside the LSI may be used.

[0087] Furthermore, if a technology for integrating into an integrated circuit that replaces an LSI appears due to the progress of semiconductor technology or another derived technology, naturally, each component included in the charging devices 10 and 20 may be integrated using that technology.

[0088] In addition, forms obtained by applying various modifications that can be conceived by those skilled in the art to the embodiments, and forms realized by arbitrarily combining the components and functions in each embodiment without departing from the spirit of the present disclosure are also included in the present disclosure.

[0089] (Supplementary Note) From the description of the above embodiments, the following technology is disclosed.

[0090] (Technology 1) A charging device mounted on a vehicle, comprising a processor and a memory, wherein the processor uses the memory to determine whether a charging station for charging a battery mounted on the vehicle is connected to the charging device, and when it is determined that the charging station and the charging device are connected, generates a charging task that functions as a sandbox dedicated to charging the battery, determines whether an attack on the charging device is detected, and when it is determined that an attack on the charging device is detected, generates a handover charging task that does not communicate with the charging station, and after causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, deletes the charging task. Charging device.

[0091] According to this, when an attack on the charging device is detected, a handover charging task is generated, and information indicating the state of the battery and information indicating the amount of charge to the battery are handed over to the handover charging task before the charging task is deleted, so that the state of the battery and the management of the charge amount can be continued. In addition, when it is determined that the charging device is connected to the charging station and an attack on the charging device is detected, there is a possibility that malware has invaded the charging station or a device posing as the charging station is connected to the charging device and malware has invaded the dedicated charging task. However, since the charging task is deleted, the propagation of the attack can be suppressed. In addition, since the newly generated handover charging task does not communicate with the charging station, there is no possibility that malware will invade the handover charging task. Therefore, while continuing to manage the state of the battery and the charge amount, the propagation of the attack can be suppressed. That is, the safety of the vehicle and the legitimacy of charging can be ensured.

[0092] (Technology 2) The charging device according to Technology 1, wherein the processor acquires the position information of the vehicle and the position information of the charging station, and when there is no consistency between the position information of the vehicle and the position information of the charging station, determines that an attack on the charging device is detected.

[0093] According to this, when there is no consistency between the position information of the vehicle and the position information of the charging station, the charging device of the vehicle located at a position different from the position of the charging station is connected to the device posing as the charging station, and since there is a possibility that the charging device is being attacked, it can be determined that an attack on the charging device has been detected.

[0094] (Technology 3) The processor acquires sensing data of a sensor provided in the vehicle, and determines whether an attack on the charging device has been detected based on the sensing data, for the charging device according to Technology 1 or 2.

[0095] According to this, when the charging device is attacked, the sensing data of the sensor provided in the vehicle may become data different from normal, so it can be determined whether an attack on the charging device has been detected based on the sensing data.

[0096] (Technology 4) The processor acquires, as the sensing data, an image captured by a camera provided in the vehicle, and when the image does not show that the charging station and the charging device are connected, determines that an attack on the charging device has been detected, for the charging device according to Technology 3.

[0097] According to this, when the image captured by the camera does not show that the charging station and the charging device are connected, there is a possibility that the device posing as the charging station is connected to the charging device, so it can be determined that an attack on the charging device has been detected.

[0098] (Technology 5) The processor acquires, as the sensing data, the speed information of the vehicle obtained by a speed sensor provided in the vehicle, and when the speed information indicates that the vehicle is moving, determines that an attack on the charging device has been detected, for the charging device according to Technology 3 or 4.

[0099] According to this, when the speed information indicates that the vehicle is moving, the vehicle is not connected to the charging station during movement, and since there is a possibility that the charging device is being attacked, it can be determined that an attack on the charging device has been detected.

[0100] (Technology 6) The processor acquires the charge amount information received from a charging station management server that manages the charging station by the vehicle and the charge amount information measured by the vehicle, and when there is no consistency between the charge amount information received from the charging station management server and the charge amount information measured by the vehicle, it determines that an attack on the charging device has been detected, the charging device according to any one of Technologies 1 to 5.

[0101] According to this, when there is no consistency between the charge amount information received from the charging station management server and the charge amount information measured by the vehicle, since there is a possibility that the charging device is being attacked, it can be determined that an attack on the charging device has been detected.

[0102] (Technology 7) The processor monitors the communication between the charging device and the charging station, and when the communication volume of the communication is larger than a predetermined communication volume, it determines that an attack on the charging device has been detected, the charging device according to any one of Technologies 1 to 6.

[0103] According to this, when the communication volume of the communication between the charging device and the charging station is larger than a predetermined communication volume, since there is a possibility that the charging device is being attacked, it can be determined that an attack on the charging device has been detected.

[0104] (Technology 8) When the processor determines that an attack on the charging device has been detected when charging of the battery is started by the charging task, it causes the transfer charging task to perform a charge completion process, the charging device according to any one of Technologies 1 to 7.

[0105] According to this, even when an attack on the charging device is detected and the charging task is deleted, charging can be terminated by a relay charging task instead of the charging task.

[0106] (Technical 9) A charging device mounted on a charging station for charging a vehicle, comprising a processor and a memory, wherein the processor uses the memory to determine whether the vehicle and the charging device are connected, and when it is determined that the vehicle and the charging device are connected, generates a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle, determines whether an attack on the charging device is detected, and when it is determined that an attack on the charging device is detected, generates a relay charging task that does not communicate with the vehicle, and after causing the relay charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, deletes the charging task. Charging device.

[0107] According to this, when an attack on the charging device is detected, a relay charging task is generated, and information indicating the state of the battery and information indicating the amount of charge to the battery are transferred to the relay charging task before the charging task is deleted, so that the management of the state and charge amount of the battery can be continued. In addition, when it is determined that the charging device is connected to the vehicle and an attack on the charging device is detected, there is a possibility that malware has invaded the vehicle or a device posing as a vehicle is connected to the charging device and malware has invaded the dedicated charging task. However, since the charging task is deleted, the propagation of the attack can be suppressed. In addition, since the newly generated relay charging task does not communicate with the vehicle, there is no possibility of malware invading the relay charging task. Therefore, the propagation of the attack can be suppressed while continuing to manage the state and charge amount of the battery. That is, the safety of the vehicle and the charging station and the legitimacy of charging can be ensured.

[0108] (Technique 10) The processor acquires the position information of the vehicle and the position information of the charging station, and when there is no consistency between the position information of the vehicle and the position information of the charging station, determines that an attack on the charging device has been detected, the charging device according to Technique 9.

[0109] According to this, when there is no consistency between the position information of the vehicle and the position information of the charging station, the charging device of the charging station at a position different from the position of the vehicle is connected to the device posing as the vehicle, and since there is a possibility that the charging device is being attacked, it can be determined that an attack on the charging device has been detected.

[0110] (Technique 11) The processor acquires an image captured by a camera provided at the charging station, and when the image does not show that the vehicle and the charging device are connected, determines that an attack on the charging device has been detected, the charging device according to Technique 9 or 10.

[0111] According to this, when the image captured by the camera does not show that the vehicle and the charging device are connected, since there is a possibility that the device posing as the vehicle is connected to the charging device, it can be determined that an attack on the charging device has been detected.

[0112] (Technique 12) The processor monitors the communication between the charging device and the vehicle, and when the communication volume of the communication is greater than a predetermined communication volume, determines that an attack on the charging device has been detected, the charging device according to any one of Techniques 9 to 11.

[0113] According to this, when the communication volume of the communication between the charging device and the vehicle is greater than a predetermined communication volume, since there is a possibility that the charging device is being attacked, it can be determined that an attack on the charging device has been detected.

[0114] (Technique 13) The charging device according to any one of Techniques 9 to 12, wherein when charging of the battery is started by the charging task, the processor causes the handover charging task to perform charging end processing.

[0115] According to this, even when an attack on the charging device is detected and the charging task is deleted, charging can be ended by the handover charging task instead of the charging task.

[0116] (Technique 14) A charging method executed by a charging device mounted on a vehicle, the method including: determining whether a charging station for charging the vehicle and the charging device are connected; generating a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle when it is determined that the charging station and the charging device are connected; determining whether an attack on the charging device is detected; generating a handover charging task that does not communicate with the charging station when it is determined that an attack on the charging device is detected; causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery; and then deleting the charging task.

[0117] According to this, it is possible to provide a charging method capable of suppressing the propagation of an attack while continuing to manage the state and charge amount of the battery.

[0118] (Technique 15) A charging method executed by a charging device mounted on a charging station for charging a vehicle, the method including: determining whether the vehicle and the charging device are connected; generating a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle when it is determined that the vehicle and the charging device are connected; determining whether an attack on the charging device is detected; generating a handover charging task that does not communicate with the vehicle when it is determined that an attack on the charging device is detected; causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery; and then deleting the charging task.

[0119] According to this, while continuously managing the state and charge amount of the battery, it is possible to provide a charging method capable of suppressing the propagation of an attack.

Industrial Applicability

[0120] The present disclosure can be applied to a charging device for charging a battery mounted on a vehicle and the like.

Explanation of Signs

[0121] 10, 20 Charging device 11, 21 Processor 12, 22 Connection determination unit 13, 23 Charging task generation unit 14, 24 Attack determination unit 15, 25 Handover charging task generation unit 16, 26 Charging task deletion unit 17, 27 Memory 30 Battery 40 TCU 50 GPS 60 Speed sensor 70, 90 Camera 80 Communication IF 100 Vehicle 200 Charging station 300 Vehicle management server 400 Charging station management server

Claims

1. A charging device mounted on a vehicle, comprising: a processor and a memory; using the memory, the processor determines whether a charging station for charging a battery mounted on the vehicle is connected to the charging device; when it is determined that the charging station is connected to the charging device, generates a charging task that functions as a dedicated sandbox for charging the battery; determines whether an attack on the charging device is detected; when it is determined that an attack on the charging device is detected, generates a handover charging task that does not communicate with the charging station; after causing the handover charging task to obtain information indicating the state of the battery and information indicating the amount of charge to the battery, deletes the charging task. Charging device.

2. The processor acquires the position information of the vehicle and the position information of the charging station; when there is no consistency between the position information of the vehicle and the position information of the charging station, determines that an attack on the charging device is detected. The charging device according to claim 1.

3. The processor acquires sensing data of a sensor provided on the vehicle, and determines whether an attack on the charging device is detected based on the sensing data. The charging device according to claim 1.

4. The processor acquires, as the sensing data, an image captured by a camera provided on the vehicle, and when the image does not show that the charging station and the charging device are connected, determines that an attack on the charging device is detected. The charging device according to claim 3.

5. The processor acquires, as the sensing data, the speed information of the vehicle obtained by a speed sensor provided on the vehicle, and when the speed information indicates that the vehicle is moving, determines that an attack on the charging device is detected. The charging device according to claim 3.

6. The processor acquires the charge amount information received from a charging station management server that manages the charging station by the vehicle and the charge amount information measured by the vehicle, and when there is no consistency between the charge amount information received from the charging station management server and the charge amount information measured by the vehicle, determines that an attack on the charging device is detected. The charging device according to claim 1.

7. The processor monitors communication between the charging device and the charging station, and when the communication volume of the communication is greater than a predetermined communication volume, determines that an attack on the charging device has been detected. The charging device according to claim 1.

8. When the processor determines that an attack on the charging device has been detected when charging of the battery has started by the charging task, the processor causes the handover charging task to perform a charging end process. The charging device according to any one of claims 1 to 7.

9. A charging device mounted on a charging station that charges a vehicle, comprising a processor and a memory, wherein the processor uses the memory to determine whether the vehicle and the charging device are connected, and when it is determined that the vehicle and the charging device are connected, generates a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle, determine whether an attack on the charging device has been detected, and when it is determined that an attack on the charging device has been detected, generates a handover charging task that does not communicate with the vehicle, acquires information indicating the state of the battery and information indicating the amount of charge to the battery in the handover charging task, and then deletes the charging task. Charging device.

10. The processor acquires the position information of the vehicle and the position information of the charging station, and when there is no consistency between the position information of the vehicle and the position information of the charging station, determines that an attack on the charging device has been detected. The charging device according to claim 9.

11. The processor acquires an image captured by a camera provided at the charging station, and when the image does not show that the vehicle and the charging device are connected, determines that an attack on the charging device has been detected. The charging device according to claim 9.

12. The processor monitors communication between the charging device and the vehicle, and when the communication volume of the communication is greater than a predetermined communication volume, determines that an attack on the charging device has been detected. The charging device according to claim 9.

13. When the charging of the battery has started by the charging task, the processor causes the handover charging task to perform a charging end process. The charging device according to any one of claims 9 to 12.

14. A charging method executed by a charging device mounted on a vehicle, Determine whether a charging station for charging the vehicle and the charging device are connected, When it is determined that the charging station and the charging device are connected, generate a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle, Determine whether an attack on the charging device is detected, When it is determined that an attack on the charging device is detected, generate a handover charging task that does not communicate with the charging station, After causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, delete the charging task, Charging method.

15. A charging method executed by a charging device mounted on a charging station for charging a vehicle, comprising: Determine whether the vehicle and the charging device are connected, When it is determined that the vehicle and the charging device are connected, generate a charging task that functions as a dedicated sandbox for charging the battery mounted on the vehicle, Determine whether an attack on the charging device is detected, When it is determined that an attack on the charging device is detected, generate a handover charging task that does not communicate with the vehicle, After causing the handover charging task to acquire information indicating the state of the battery and information indicating the amount of charge to the battery, delete the charging task, Charging method.

Citation Information

Patent Citations

  • JP1973092260A