Monitoring device and monitoring method

The monitoring device efficiently manages communication status based on attack risk levels, preventing unnecessary interruptions and ensuring safe charging/discharging operations by differentiating between low-risk and high-risk cyber threats.

JP2026091562APending Publication Date: 2026-06-04PANASONIC AUTOMOTIVE SYST CO LTD

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
PANASONIC AUTOMOTIVE SYST CO LTD
Filing Date
2024-11-25
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Existing systems inefficiently handle cyber attacks on vehicles and charging/discharging facilities, leading to unnecessary termination of communication and potential risks such as overcharging or malware infection, without considering the risk level of the attack.

Method used

A monitoring device with an attack detection unit, response determination unit, and communication control unit that assesses the risk level of detected attacks to determine whether to continue or terminate communication between vehicles and charging/discharging facilities.

Benefits of technology

Prevents unnecessary termination of communication during cyber attacks, allowing efficient charging and discharging operations by distinguishing between low-risk and high-risk attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026091562000001_ABST
    Figure 2026091562000001_ABST
Patent Text Reader

Abstract

The system provides monitoring devices that can prevent unnecessary termination of communications when an attack is detected. [Solution] The monitoring device 100 includes an attack detection unit 110 that detects an attack on at least one of a mobile body that uses an electric motor 200 as a driving source, and a charging and discharging facility that charges and discharges the mobile body in conjunction with communication with the mobile body; a response determination unit 120 that determines whether or not to change the communication status between the mobile body and the charging and discharging facility based on the risk level of the detected attack, which is determined based on the type of attack detected; and a communication control unit 130 that changes the communication status between the mobile body and the charging and discharging facility if it is determined that the communication status between the mobile body and the charging and discharging facility should be changed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a monitoring device and a monitoring method.

Background Art

[0002] Conventionally, there is a device that detects a cyber attack (hereinafter, also simply referred to as an attack) and controls the charge and discharge amount (see, for example, Patent Document 1).

[0003] Patent Document 1 discloses an electronic control device that, when receiving an attack such as unauthorized access that falsifies data during automatic driving control, makes at least one of the preset charge limit amount and discharge limit amount of the battery smaller than that during normal control without receiving an attack.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] There is a charge and discharge facility that charges the battery provided in a vehicle and accepts discharge from the battery. When charge and discharge are performed between the vehicle and the charge and discharge facility, communication is performed between the vehicle and the charge and discharge facility.

[0006] When the vehicle or the charge and discharge facility is attacked, risks such as overcharging of the battery occur. In order to cope with such risks, for example, it is conceivable to stop charge and discharge by terminating (cutting off) the communication between the vehicle and the charge and discharge facility.

[0007] On the other hand, if charge and discharge are always stopped by always stopping communication when an attack is detected, it may be inefficient from the perspective of charge and discharge.

[0008] This disclosure provides a monitoring device and the like that can prevent unnecessary termination of communications when an attack is detected. [Means for solving the problem]

[0009] A monitoring device according to one aspect of the present disclosure includes: an attack detection unit that detects an attack against at least one of a mobile body that uses an electric motor as a driving source for travel, and a charging and discharging facility that charges and discharges the mobile body in conjunction with communication with the mobile body; a response determination unit that determines whether or not to change the communication status between the mobile body and the charging and discharging facility based on the risk level of the detected attack determined based on the content of the detected attack; and a communication control unit that changes the communication status between the mobile body and the charging and discharging facility if it is determined that the communication status between the mobile body and the charging and discharging facility should be changed.

[0010] A monitoring method according to one aspect of the present disclosure detects an attack on at least one of a mobile body that uses an electric motor as a driving source and a charging / discharging facility that charges and discharges the mobile body in communication with the mobile body, determines whether to change the communication status between the mobile body and the charging / discharging facility based on the risk level of the detected attack determined based on the content of the detected attack, and if it is determined that the communication status between the mobile body and the charging / discharging facility should be changed, the communication status between the mobile body and the charging / discharging facility is changed. [Effects of the Invention]

[0011] According to this disclosure, it is possible to provide monitoring devices and the like that can prevent unnecessary termination of communications when an attack is detected. [Brief explanation of the drawing]

[0012] [Figure 1] Figure 1 is a block diagram showing the configuration of the charge / discharge system according to Embodiment 1. [Figure 2] Figure 2 shows an example of a risk table. [Figure 3] Figure 3 shows a second example of a risk table. [Figure 4] Figure 4 is a flowchart showing the processing procedure of a vehicle according to Embodiment 1. [Figure 5] Figure 5 is a block diagram showing the charge / discharge system according to Embodiment 2. [Figure 6] Figure 6 shows the first example of a correspondence table. [Figure 7] Figure 7 is a flowchart showing the processing procedure of a vehicle according to Embodiment 2. [Figure 8] Figure 8 shows a third example of a risk table. [Figure 9] Figure 9 shows a fourth example of a risk table. [Figure 10] Figure 10 shows a second example of a correspondence table. [Figure 11] Figure 11 is a flowchart showing a monitoring method according to one aspect of this disclosure. [Modes for carrying out the invention]

[0013] (Knowledge that forms the basis of this disclosure) Battery Electric Vehicles (BEVs) communicate with infrastructure such as charging stations or smart grids for charging control or billing control. There are also use cases where the power stored in a BEV's battery is discharged to the smart grid via discharge stations.

[0014] One threat specific to BEVs is the risk of overcharging due to an attacker hijacking a BEV, resulting in an excessive power supply. This risk is extremely dangerous, as it also carries the risk of fire.

[0015] Furthermore, if a charging / discharging station hijacked by malware communicates with a BEV, there is a risk of personal information leakage and malware infection of the BEV. For example, if a BEV hijacked by an attacker connects to infrastructure, the threat from the BEV could spread to the infrastructure, meaning the BEV could be used as a stepping stone for an attack.

[0016] Here, for charging or discharging of a BEV, communication between the BEV and a charging / discharging stand (e.g., an EVSE (Electric Vehicle Supply Equipment)) is essential. Therefore, when an attack on the BEV occurs, that is, when an abnormality occurs in the BEV, if the communication is interrupted (ended) without question, the BEV will be unable to charge and discharge.

[0017] There are various types of attacks, and even if a BEV is attacked, it does not necessarily immediately pose a highly dangerous risk such as overcharging. Therefore, immediately ending the communication at the initial stage of an attack may be inefficient considering the charging and discharging of the BEV.

[0018] In view of such problems, the inventors of the present application have created the present disclosure.

[0019] Hereinafter, each embodiment will be specifically described with reference to the drawings.

[0020] Note that each of the embodiments described below shows comprehensive or specific examples. Numerical values, shapes, materials, components, arrangement positions and connection forms of components, steps, the order of steps, etc. shown in each of the following embodiments are merely examples and are not intended to limit the present disclosure. Also, among the components in each of the following embodiments, components not described in the independent claims of the present disclosure are described as optional components. Also, each figure is not necessarily drawn precisely. In each figure, substantially the same configuration is denoted by the same reference numeral, and duplicate descriptions may be omitted or simplified.

[0021] Also, in this specification, for example, when described in comparison with more than a threshold value or below a threshold value, it means being distinguished based on the threshold value, and may respectively mean greater than or equal to the threshold value and less than the threshold value.

[0022] Furthermore, the numerical values ​​such as thresholds in this embodiment are merely examples, and other numerical values ​​may be used.

[0023] (Embodiment 1) [composition] Figure 1 is a block diagram showing the configuration of the charge / discharge system 10 according to Embodiment 1.

[0024] The charging and discharging system 10 is a system in which a vehicle 20 and a charging and discharging station 30 perform charging and discharging. For example, the charging and discharging station 30 is located at a station (charging and discharging station) where charging and discharging takes place. The charging and discharging station 30 charges (supplies power to) the vehicle 20 and accepts discharge from the vehicle 20.

[0025] Furthermore, the act of the charging / discharging station 30 charging the vehicle 20 and accepting discharge from the vehicle 20 is also referred to simply as charging / discharging the vehicle 20.

[0026] The charging and discharging system 10 comprises a vehicle 20 and a charging and discharging station 30.

[0027] Vehicle 20 is an electric vehicle, such as an electric vehicle (EV). For example, vehicle 20 is driven using a battery 210 and an electric motor 200, such as a motor powered by electricity from the battery 210, as its driving power source.

[0028] Vehicle 20 can be any electric mobile device, such as a motorcycle or a mobile robot. Vehicle 20 is just one example of a mobile device.

[0029] The charging / discharging station 30 is an EV charger / discharger that communicates with the vehicle 20 and charges the vehicle 20 (specifically, the battery 210 installed in the vehicle 20) or accepts discharge from the vehicle 20 (specifically, the battery 210). When the charging / discharging station 30 performs charging / discharging with the vehicle 20, it does so while communicating with the vehicle 20. In other words, charging and discharging between the vehicle 20 and the charging / discharging station 30 is accompanied by communication. The charging / discharging station 30 can, for example, supply power to the vehicle 20 from an external commercial power source (not shown) owned by a power company, or supply power from the vehicle 20 to the external commercial power source. This allows for transactions such as buying or selling electricity between the owner (user) of the vehicle 20 and the management company that manages the charging / discharging station 30.

[0030] The charging / discharging stand 30 may, for example, have a function for charging and a function for discharging, but it is sufficient to have either one of these functions; it does not need to have a charging function or a discharging function.

[0031] Furthermore, the charging / discharging stand 30 may be placed in a station, for example, but it may also be placed in a home or other location.

[0032] For example, when charging and discharging occur between the vehicle 20 and the charging / discharging station 30, charge / discharge information (e.g., information indicating the amount of charge or discharge) showing the result of charging and discharging at the charging / discharging station 30 is transmitted to the station server that manages the station. In this case, the charge / discharge information from the vehicle 20 is also transmitted to the vehicle management server that manages the vehicle 20, and / or to a terminal such as a PC (Personal Computer) used by the user of the vehicle 20. Servers such as the vehicle management server and the station server are implemented by computers that include, for example, a communication interface, non-volatile memory where programs are stored, volatile memory which is a temporary storage area for executing programs, input / output ports for sending and receiving signals, and a processor for executing programs.

[0033] Vehicle 20 comprises a monitoring device 100, an electric motor 200, a battery 210, a vehicle control unit 220, and a communication unit 230. Although not shown in the figures, vehicle 20 also has ports to which power lines and the like are connected for charging and discharging between vehicle 20 and the charging / discharging station 30, as well as other mechanisms that are typical of electric vehicles.

[0034] The monitoring device 100 is a computer that monitors at least one of the vehicle 20 and the charging / discharging station 30. Specifically, the monitoring device 100 detects attacks on at least one of the vehicle 20 and the charging / discharging station 30 while charging / discharging is in progress and communication is ongoing. In other words, the monitoring device 100 determines whether at least one of the vehicle 20 and the charging / discharging station 30 has been attacked. If the monitoring device 100 detects an attack, that is, if it determines that at least one of the vehicle 20 and the charging / discharging station 30 has been attacked, it performs a process to change the communication status between the vehicle 20 and the charging / discharging station 30 according to the risk level of the detected attack.

[0035] The monitoring device 100 includes an attack detection unit 110, a response determination unit 120, a communication control unit 130, and a risk table storage unit 140.

[0036] The attack detection unit 110 is a processing unit that detects attacks against at least one of the vehicle 20 and the charging / discharging station 30, which performs charging or discharging (charging or discharging) of the vehicle 20 in conjunction with communication with the vehicle 20. Specifically, the attack detection unit 110 performs detection processing to detect an attack against at least one of the vehicle 20 and the charging / discharging station 30 when the vehicle 20 and the charging / discharging station 30 are communicating and charging / discharging is taking place. The attack detection unit 110 detects attacks against the vehicle 20 and the charging / discharging station 30 based, for example, on data input / output in the ECU (Electronic Control Unit) of the vehicle 20, data transmitted and received via the communication unit 230, and data transmitted and received by the charging / discharging station 30.

[0037] Furthermore, the attack detection unit 110 determines the nature of the detected attack. The nature of the attack includes, for example, the type of attack, the source of the attack, and the target of the attack. The attack detection unit 110 detects the nature of the attack based on, for example, data input and output from the ECU of the vehicle 20, data transmitted and received via the communication unit 230, and data transmitted and received by the charging and discharging stand 30.

[0038] The attack detection method and the method for determining the content of an attack by the attack detection unit 110 are not particularly limited. The attack detection unit 110 may be implemented, for example, by an IDS (Intrusion Detection System). Alternatively, the monitoring device 100 may store rule information in advance that indicates rules for detecting an attack and determining the content of an attack. In this case, the attack detection unit 110 may detect an attack and determine the content of an attack based on the rule information.

[0039] The response determination unit 120 is a processing unit that determines whether or not to change the communication status between the vehicle 20 and the charging / discharging station 30 based on the risk level of the detected attack, which is determined based on the content of the attack detected by the attack detection unit 110. Specifically, the response determination unit 120 determines whether to continue or terminate communication between the vehicle 20 and the charging / discharging station 30 based on the risk level.

[0040] For example, the response determination unit 120 identifies the type of attack detected by the attack detection unit 110 and determines (calculates) the risk level of the detected attack based on the type of attack detected. The type of attack is an example of the content of the attack. Also, for example, the response determination unit 120 identifies the victim who was attacked by the attack detection unit 110 and determines the risk level of the detected attack based on the victim. The victim is another example of the content of the attack. Also, for example, the response determination unit 120 identifies the source of the detected attack and determines the risk level of the detected attack based on the victim and the source of the attack. The source of the attack is another example of the content of the attack.

[0041] The response determination unit 120 determines, for example, the risk level of the detected attack based on a risk table.

[0042] Figures 2 and 3 show specific examples of risk tables.

[0043] The first example of a risk table shown in Figure 2 is a table that shows the correspondence between attack types and risk levels. Specifically, in this example, the risk table contains information that links attack types with risk levels.

[0044] In this example, examples of attack types include "port scanning," "brute force," "firmware tampering," and "power input exceeding a specified amount." The specified amount, which is the amount of power input to battery 210, can be arbitrarily determined in advance and is not particularly limited.

[0045] In this example, the risk levels are set to "low" and "high". For example, "port scan" and "brute force" are set to a "low" risk level. In this example, "firmware tampering" and "power input exceeding the specified amount" are set to a "high" risk level.

[0046] The response determination unit 120, for example, if the type of attack detected by the attack detection unit 110 is a "port scan", determines the risk level of the detected attack to be "low".

[0047] The second example of a risk table shown in Figure 3 is a table that shows the correspondence between the detected attack and the risk level. Specifically, in this example, the risk table contains information that links the detected attack with the risk level.

[0048] The targets of attack detection are those that the attack detection unit 110 detects as either the source of the attack or the target of the attack. The attack detection unit 110 detects an attack, for example, by analyzing the data input and output at the target of the attack detection.

[0049] In this example, examples of targets for attack detection include "connection ports," "ECUs inside the vehicle," "charging / discharging stations," "battery control ECUs," "ECUs near entry points," and "ECUs involved in vehicle control." Vehicle 20 is equipped with multiple ECUs. ECUs may be connected in a daisy-chain fashion, for example, to a communication unit 230 that communicates with an external communication device. For example, an "ECU near an entry point" is an ECU that is relatively close to the communication unit 230, such as being in the first or second position relative to the communication unit 230, while an "ECU inside the vehicle" is an ECU that is relatively far from the communication unit 230, such as being in the third or fourth position relative to the communication unit 230. A "connection port" is, for example, a wireless communication circuit provided by the communication unit 230. For example, a "battery control ECU" is an ECU that controls the battery 210 provided by vehicle 20. For example, an "ECU involved in vehicle control" is an ECU that controls the engine and other components provided by vehicle 20 to control the vehicle's movement. Each of the above ECUs may be housed in a physical enclosure. Alternatively, multiple ECUs may be housed in a single enclosure using virtualization technology such as a hypervisor.

[0050] In this example, the risk levels included in the risk table are set according to the attack source and the victim being targeted by the attack. The attack source, in this context, refers to a device such as a processor that, when attacked by an external third party, transmits unintended data to a device in the vehicle 20 or the charging / discharging station 30, thereby disrupting the processing of the device or causing the device to perform unintended processing (i.e., carrying out an attack).

[0051] In this example, the risk level is set to "low" when the source of the attack is a "connection port" and the target of the attack is an "ECU near the entry point." In this example, the risk level is set to "high" when the source of the attack is an "ECU inside the vehicle," a "charging / discharging station," or a "battery control ECU," and the target of the attack is an "ECU involved in vehicle control," a "battery control ECU," or a "charging / discharging station."

[0052] The response determination unit 120 determines the risk level of the detected attack to be "low" if, for example, the type of attack detected by the attack detection unit 110 is a "port scan". Also, for example, the response determination unit 120 determines the risk level of the detected attack to be "high" if, for example, the target of the attack detected by the attack detection unit 110 is a "battery control ECU" and the source of the attack is an "internal vehicle ECU".

[0053] As described above, the response determination unit 120 determines the risk level of a detected attack based, for example, on risk table information (also simply called a risk table) that shows the correspondence between the content of the attack and the risk level.

[0054] The response determination unit 120 may determine the risk level using both the risk table for the first example and the risk table for the second example. In this case, the response determination unit 120 will, for example, determine the risk level of an attack to be "high" if the risk level were "high" using either of the risk tables, and determine the risk level of an attack to be "low" if the risk level were "low" using both risk tables.

[0055] Furthermore, the type of attack, the target of attack detection, and the risk level associated with each of the attack type and target of attack detection can be arbitrarily determined in advance and are not particularly limited.

[0056] Furthermore, the risk table may include only the attack source or only the attacked party as targets for attack detection.

[0057] Furthermore, the attack detection unit 110 may detect an attack against at least one of the targets based on attack information received from an external device regarding an attack against at least one of the targets. Attack information is, for example, information indicating the content of the attack. The response determination unit 120 determines the risk level of the detected attack based on, for example, the content of the attack indicated by the attack information. The response determination unit 120 may also acquire risk level information indicating the risk level of the detected attack from an external device. Thus, the detection of an attack (specifically, the determination of the content of the attack) and / or the determination of the risk level may be performed by an external device such as a computer with an attack detection function, such as an IDS. The monitoring device 100 may acquire information indicating the results of these detections and / or determinations by the external device and perform attack detection and / or determination of the content of the attack based on the acquired information.

[0058] Furthermore, the response determination unit 120 determines, for example, whether to continue or terminate communication between the vehicle 20 and the charging / discharging station 30 based on the risk level determined as described above. For example, if the risk level is "low", the response determination unit 120 determines to continue communication between the vehicle 20 and the charging / discharging station 30. On the other hand, if the risk level is "high", the response determination unit 120 determines to terminate communication between the vehicle 20 and the charging / discharging station 30. The response determination unit 120 outputs instructions (instruction information) corresponding to the risk level to the communication control unit 130. For example, if the response determination unit 120 determines to terminate communication between the vehicle 20 and the charging / discharging station 30, it outputs an instruction to the communication control unit 130 to terminate communication between the vehicle 20 and the charging / discharging station 30.

[0059] The communication control unit 130 is a processing unit that controls the communication status between the vehicle 20 and the charging / discharging station 30. Specifically, if the correspondence determination unit 120 determines that the communication status between the vehicle 20 and the charging / discharging station 30 should be changed, the communication control unit 130 terminates communication between the vehicle control unit 220 and the charging / discharging station 30 via the communication unit 230. For example, if the communication control unit 130 receives an instruction to terminate communication between the vehicle 20 and the charging / discharging station 30, it terminates communication between the vehicle control unit 220 and the charging / discharging station 30 by forwarding the instruction to the vehicle control unit 220. The communication control unit 130 may also terminate communication between the vehicle control unit 220 and the charging / discharging station 30 by controlling the communication unit 230. In this way, for example, the communication control unit 130 communicates with the charging / discharging station 30, controls the start and end of charging or discharging, and controls the amount of charging and discharging of the battery 210.

[0060] Furthermore, for example, the communication control unit 130 controls communication between the vehicle 20 and external communication devices such as external devices or terminals via the communication unit 230. For example, if the response determination unit 120 determines, based on the detected attack risk level, that communication between the vehicle 20 and the charging / discharging station 30 should be terminated, it outputs notification information indicating that communication between the vehicle 20 and the charging / discharging station 30 should be terminated. This notification information is transmitted, for example, via the communication unit 230 to a terminal used by the user of the vehicle 20. As a result, the user is notified of the content of the notification information, for example, by outputting images and audio based on the notification information to the terminal.

[0061] Notification information is sent, for example, to a terminal used by a mobile user.

[0062] The risk table storage unit 140 is a storage device that stores the risk table.

[0063] The electric motor 200 is a device such as a motor that is powered by electricity from the battery 210.

[0064] Battery 210 is a battery that supplies power to the electric motor 200, stores power from the charging / discharging stand 30, and discharges power to the charging / discharging stand 30.

[0065] The vehicle control unit 220 is a processing unit that controls the operation of the vehicle 20. For example, the vehicle control unit 220 controls communication with the charging / discharging stand 30 and external communication devices via the communication unit 230, controls the movement of the vehicle 20 by controlling the electric motor 200 provided in the vehicle 20, and controls the charging and discharging of the vehicle 20 and the charging / discharging stand 30 by controlling the battery 210 provided in the vehicle 20 and the port connected to the battery 210.

[0066] The communication unit 230 is a communication interface for communicating with the charging / discharging stand 30 and external communication devices. The vehicle control unit 220 controls communication between the vehicle 20 and the charging / discharging stand 30 and external communication devices, for example, by controlling the communication unit 230.

[0067] The monitoring device 100 communicates with an external communication device via, for example, the communication unit 230 provided in the vehicle 20. However, it may also have a separate communication interface and communicate with an external communication device via that interface.

[0068] Alternatively, the communication control unit 130 may control the communication unit 230 to control communication between the monitoring device 100 and the charging / discharging stand 30 and / or an external communication device.

[0069] Furthermore, if an attack is detected by the attack detection unit 110, for example, the communication control unit 130 may send alert information, including information indicating the nature of the detected attack, via the communication unit 230 to the user of the vehicle 20 and / or the charging / discharging station 30, and / or to a computer used in the SOC (Security Operation Center).

[0070] The processing units, such as the attack detection unit 110, the response determination unit 120, the communication control unit 130, and the vehicle control unit 220, are implemented by, for example, one or more processors such as an ECU or CPU (Central Processing Unit), and one or more memories that store control programs executed by the one or more processors.

[0071] The risk table storage unit 140 is implemented by one or more storage devices, such as an HDD (Hard Disk Drive) or semiconductor memory.

[0072] Furthermore, the above-mentioned communication interface, such as the communication unit 230, is implemented, for example, by an antenna and a wireless communication circuit, and / or a connector to which a communication line is connected, so that wireless communication is possible. Also, for example, PLC (Power Line Communication) may be used for communication between each device, such as the vehicle 20 and the charging / discharging station 30. Each device may be provided with a configuration such as a circuit for performing PLC as a communication interface. The communication standard used for the communication interface may be arbitrarily determined and is not particularly limited.

[0073] [Processing Procedure] Figure 4 is a flowchart showing the processing procedure of the vehicle 20 according to Embodiment 1.

[0074] First, suppose the vehicle 20 starts communicating with the charging / discharging station 30 and begins charging or discharging (S110). The vehicle control unit 220, for example, starts communicating with the charging / discharging station 30 when a power line is connected to the port and outputs start information to the monitoring device 100 indicating that charging or discharging of the vehicle 20 has started. The monitoring device 100, for example, determines that charging or discharging of the vehicle 20 has started when it receives the start information.

[0075] The monitoring device 100 may acquire information indicating the amount of power detected by a power meter or other device that detects the receiving and / or supply of power via a port provided by the vehicle 20, and determine whether or not charging or discharging of the vehicle 20 has started based on the detection results and the acquired information.

[0076] Next, the monitoring device 100 determines whether an attack on at least one of the vehicle 20 and the charging / discharging station 30 has been detected (S120). For example, if charging or discharging of the vehicle 20 is started, the monitoring device 100 starts a detection process to detect an attack on at least one of the vehicle 20 and the charging / discharging station 30. For example, the monitoring device 100 continues to perform the detection process while charging or discharging of the vehicle 20 is taking place.

[0077] The monitoring device 100 may perform detection processing when the vehicle 20 and the charging / discharging station 30 are communicating, or it may perform detection processing continuously while the engine of the vehicle 20 is on.

[0078] If the monitoring device 100 determines that an attack has been detected (Yes in S120), it determines the risk level of the detected attack based on the risk table (S130).

[0079] Next, the monitoring device 100 determines whether to continue charging or discharging the vehicle 20 (S140). If step S140 is performed after step S130, for example, the monitoring device 100 determines whether to continue charging or discharging the vehicle 20 based on the detected risk level of the attack. Alternatively, for example, the monitoring device 100 may determine whether to continue charging or discharging the vehicle 20 based on the amount of energy in the battery 210, the amount of energy supplied to the battery 210, or the amount of energy released from the battery 210. In other words, the monitoring device 100 makes, for example, a determination to continue charging or discharging the vehicle 20 based on the risk level, and a determination to determine whether the vehicle 20 has been charged or discharged by a predetermined amount of energy (i.e., the planned amount of energy). Furthermore, if the monitoring device 100 determines, for example, that no attack has been detected (No in S120), in step S140 it does not determine whether to continue charging or discharging the vehicle 20 based on the risk level, but rather determines whether the vehicle 20 has been charged or discharged by a predetermined amount of power (i.e., the planned amount of power).

[0080] The predetermined amount of power can be arbitrarily determined and is not particularly limited. For example, the predetermined amount of power is set by the user of the vehicle 20. The predetermined amount of power is, for example, the amount of power that fully charges the battery 210, or the amount of power that causes the battery 210 to have zero remaining power. The monitoring device 100 determines, for example, whether the battery 210 is fully charged when the vehicle 20 is being charged. The monitoring device 100 also determines, for example, whether the battery 210 has zero remaining power when the vehicle 20 is being discharged. For example, when the vehicle 20 is being charged, if the monitoring device 100 determines that the battery 210 is not fully charged, it proceeds to Yes in step S140, and if it determines that the battery 210 is fully charged, it proceeds to No in step S140. Furthermore, the monitoring device 100, for example, when the vehicle 20 is discharging, will proceed to Yes in step S140 if it determines that the remaining power of the battery 210 is not 0, and will proceed to No in step S140 if it determines that the remaining power of the battery 210 is 0.

[0081] If the monitoring device 100 determines that charging or discharging of the vehicle 20 should continue (Yes in S140), it returns to step S120 and continues the detection process.

[0082] On the other hand, if the monitoring device 100 determines that it will not continue charging or discharging the vehicle 20 (No in S140), it terminates the charging or discharging of the vehicle 20 (S150). For example, the monitoring device 100 outputs an instruction to the communication control unit 130 to terminate communication between the vehicle 20 and the charging / discharging station 30, thereby causing the vehicle control unit 220 to terminate communication with the charging / discharging station 30 and to stop charging or discharging the vehicle 20.

[0083] For example, the vehicle control unit 220 may determine whether to continue charging or discharging the vehicle 20 based on the amount of energy in the battery 210, the amount of energy supplied to the battery 210, or the amount of energy released from the battery 210, and may continue or terminate the charging or discharging of the vehicle 20 based on the determination result. In other words, the vehicle control unit 220 may determine whether the vehicle 20 has been charged or discharged by a predetermined amount of energy without being attacked. In this case, for example, the monitoring device 100 does not need to determine in step S140 whether the vehicle 20 has been charged or discharged by a predetermined amount of energy.

[0084] [Effects, etc.] As described above, when the monitoring device 100 detects an attack (cyberattack) against the vehicle 20 or the charging / discharging station 30, it determines whether or not to communicate with the charging / discharging station 30 based on the risk level (risk value) of the attack. Here, for example, if the risk level is low, the monitoring device 100 will continue communication between the vehicle 20 and the charging / discharging station 30, and if the risk level is high, it will cut off communication between the vehicle 20 and the charging / discharging station 30 (stop charging or discharging).

[0085] For example, an attack that is considered to have little impact on vehicle 20 (e.g., an attack that does not immediately endanger human lives) will be assigned a low risk level. On the other hand, an attack that is considered to have a significant impact on vehicle 20 (e.g., an attack that could immediately endanger human lives) will be assigned a high risk level.

[0086] The risk level is determined (calculated) using, for example, one or more of the attack type and the targets of the attack detection.

[0087] Examples of attacks to which a low risk level is set include reconnaissance attacks such as port scanning, or brute-force attacks that bypass authentication, which are considered to have little impact on the vehicle 20. On the other hand, examples of attacks to which a high risk level is set include attacks that are considered to have a significant impact on the vehicle 20, such as firmware tampering or power input exceeding the specified amount.

[0088] Furthermore, examples of attacks that are detected with a low risk level include attacks from the source to the target, such as attacks from external communication equipment on the vehicle 20 to a wireless communication connection port (e.g., communication unit 230) on the vehicle 20 that communicates with the external communication equipment, or attacks from that connection port to an ECU near that connection port (e.g., the "ECU near the entry point" mentioned above).

[0089] Furthermore, specific examples of attacks that are detected with a high risk level include attacks from the attack source to the target, such as attacks from an ECU far from the connection port (for example, the "ECU inside the vehicle" mentioned above) to a part directly involved in the control of the vehicle 20 (for example, the "ECU involved in vehicle control" mentioned above), attacks from the charging / discharging stand 30 to the ECU that controls the battery 210, and attacks from the ECU that controls the battery 210 to the charging / discharging stand 30.

[0090] Such a monitoring device 100 can prevent unnecessary termination of communication when an attack on the vehicle 20 or the charging / discharging station 30 is detected. Specifically, even when an attack occurs, it is possible to prevent the spread of the attack by allowing charging or discharging in the case of a low-risk attack, while blocking communication in the case of a high-risk attack. Therefore, the charging and discharging of the vehicle 20 can be controlled efficiently.

[0091] (Embodiment 2) Next, a monitoring device according to Embodiment 2 will be described. In describing Embodiment 2, the differences from Embodiment 1 will be the main focus, and substantially similar configurations and processes will be denoted by the same reference numerals, and their descriptions may be omitted or simplified.

[0092] [composition] Figure 5 is a block diagram showing the configuration of the charge / discharge system 11 according to Embodiment 2.

[0093] The charging and discharging system 11 is a system in which the vehicle 21 and the charging and discharging station 30 perform charging and discharging.

[0094] The charging and discharging system 11 comprises a vehicle 21 and a charging and discharging station 30.

[0095] Vehicle 21 is an electric vehicle, for example. Specifically, vehicle 21 uses a battery 210 and an electric motor 200, such as a motor powered by electricity from the battery 210, as its driving power source.

[0096] Vehicle 21 can be any electric mobile device, such as a motorcycle or a mobile robot. Vehicle 21 is just one example of a mobile device.

[0097] Vehicle 21 comprises a monitoring device 101, an electric motor 200, a battery 210, a vehicle control unit 220, and a communication unit 230. Although not shown in the figures, vehicle 21 also has ports to which power lines and the like are connected for charging and discharging between vehicle 21 and the charging / discharging station 30, as well as other mechanisms that are typical of electric vehicles.

[0098] The monitoring device 101 is a computer that monitors at least one of the vehicle 21 and the charging / discharging station 30.

[0099] The monitoring device 101 includes an attack detection unit 110, a response determination unit 121, a communication control unit 130, a risk table storage unit 140, a power remaining monitoring unit 150, and a response table storage unit 160.

[0100] The response determination unit 121 is a processing unit that determines whether or not to change the communication status between the vehicle 21 and the charging / discharging station 30 based on the risk level of the detected attack, which is determined based on the content of the attack detected by the attack detection unit 110. Specifically, the response determination unit 121 determines whether to continue or terminate communication between the vehicle 21 and the charging / discharging station 30 based on the risk level.

[0101] For example, the response determination unit 121 identifies the type of attack detected by the attack detection unit 110 and determines the risk level of the detected attack based on the type of attack detected. Also, for example, the response determination unit 121 identifies the victim who was attacked by the attack detection unit 110 and determines the risk level of the detected attack based on the victim. Also, for example, the response determination unit 121 identifies the attack source that carried out the detected attack and determines the risk level of the detected attack based on the victim and the attack source. The response determination unit 121 determines the risk level of the detected attack based on the risk table described above, for example. The response determination unit 121 may also acquire risk level information indicating the risk level of the detected attack from an external device, similar to the response determination unit 120.

[0102] Furthermore, the response determination unit 121 determines whether or not to change the communication status between the vehicle 21 and the charging / discharging station 30 based on the remaining power of the battery 210 in the vehicle 21, which has been monitored (detected) by the remaining power monitoring unit 150, and the risk level of the attack detected by the attack detection unit 110.

[0103] The power level monitoring unit 150 is a processing unit that monitors the remaining power of the battery 210 provided in the vehicle 21. The power level monitoring unit 150 monitors the remaining power of the battery 210 by acquiring information indicating the amount of power related to the battery 210, such as the amount of power stored in the battery 210 (current power level) and / or the amount of power input and output to the battery 210, as detected by a power sensor (not shown). The power level monitoring unit 150 outputs power level information related to the remaining power of the battery 210 to the correspondence determination unit 121, for example.

[0104] The remaining power information is, for example, information indicating what percentage of the maximum capacity of the battery 210 is charged. The remaining power information can be any information relating to the remaining power of the battery 210, and may also be information that directly indicates the amount of energy stored in the battery 210.

[0105] The response determination unit 121 determines whether or not to change the communication status between the vehicle 21 and the charging / discharging station 30, based on, for example, the risk level of the attack detected by the attack detection unit 110, the remaining power amount indicated by the power information, and the response table information (also simply called the response table).

[0106] Figure 6 shows a specific example of a correspondence table.

[0107] The first example of the correspondence table shown in Figure 6 illustrates the relationship between risk level, remaining power, and response method ("Response" shown in Figure 6). The information indicating the response method included in the correspondence table is information that shows what processing the monitoring device 101 will perform.

[0108] In this example, when the vehicle 21 is charging (as shown in Figure 6 as "Charging"), if the risk level of the detected attack is determined to be "High", the response determination unit 121 terminates the charging of the vehicle 21 regardless of the remaining power of the battery 210 (as shown in Figure 6 as "Regardless") (as shown in Figure 6 as "Charging Stop").

[0109] In this example, the response determination unit 121 terminates the charging of the vehicle 21 when the vehicle 21 is charging, the risk level of the detected attack is determined to be "low", and the remaining power of the battery 210 is 50% or more of the maximum capacity of the battery 210 (as shown in Figure 6 as "50% or more capacity").

[0110] On the other hand, in this example, when the vehicle 21 is charging, the response determination unit 121 determines that the risk level of the detected attack is "low" and the remaining power of the battery 210 is less than 50% of the maximum capacity of the battery 210 (shown as "less than 50% capacity" in Figure 6), and it continues to charge the vehicle 21 (shown as "continue charging" in Figure 6). In other words, in this case, for example, the response determination unit 121 does not perform the process of ending the charging of the vehicle 21, the vehicle 21 continues to charge, and the attack detection unit 110 continues to perform the attack detection process.

[0111] In this example, if the vehicle 21 is discharging (as shown in Figure 6 as "Discharging"), and the risk level of the detected attack is determined to be "High", the response determination unit 121 will terminate the discharge of the vehicle 21 regardless of the remaining power of the battery 210 (as shown in Figure 6 as "Discharge Stop").

[0112] In this example, the response determination unit 121 continues discharging the vehicle 21 when the vehicle 21 is discharging, the risk level of the detected attack is determined to be "low", and the remaining power of the battery 210 is 50% or more of the maximum capacity of the battery 210 (shown as "continued discharge" in Figure 6).

[0113] On the other hand, in this example, the response determination unit 121 terminates the discharge of the vehicle 21 when the vehicle 21 is discharging, the detected risk level of the attack is determined to be "low", and the remaining power of the battery 210 is less than 50% of the maximum capacity of the battery 210.

[0114] Thus, in this example, if the risk level of the detected attack is "low," a decision is made based on the remaining power of the battery 210 to determine whether to continue charging or discharging.

[0115] The specific numerical value of the remaining power used in the determination can be determined arbitrarily.

[0116] Furthermore, information indicating the maximum capacity of the battery 210 may be pre-stored in a storage device such as an HDD or semiconductor memory provided by the monitoring device 101.

[0117] The correspondence table storage unit 160 is a storage device that stores the correspondence table.

[0118] The processing units, such as the attack detection unit 110, the response determination unit 121, the communication control unit 130, the remaining power monitoring unit 150, and the vehicle control unit 220, are implemented by, for example, one or more processors such as an ECU or CPU, and one or more memories that store control programs executed by the one or more processors.

[0119] The risk table storage unit 140 and the corresponding table storage unit 160 are implemented by one or more storage devices, such as an HDD or semiconductor memory.

[0120] [Processing Procedure] Figure 7 is a flowchart showing the processing procedure of the vehicle 21 according to Embodiment 2.

[0121] First, suppose that the vehicle 21 starts communicating with the charging / discharging station 30 and starts charging or discharging (S110). The vehicle control unit 220 starts communicating with the charging / discharging station 30 when, for example, a power line is connected to the port, and outputs start information to the monitoring device 101 indicating that charging or discharging of the vehicle 21 has started. The monitoring device 101, for example, determines that charging or discharging of the vehicle 21 has started when it receives the start information.

[0122] Next, the monitoring device 101 determines whether or not an attack has been detected against at least one of the vehicle 21 and the charging / discharging stand 30 (S120).

[0123] If the monitoring device 101 determines that an attack has been detected (Yes in S120), it determines the risk level of the detected attack based on the risk table (S130).

[0124] Next, the monitoring device 101 acquires power level information indicating the remaining power of the battery 210 (S160). Specifically, the correspondence determination unit 121 acquires power level information indicating the amount of power in the battery 210 from the power level monitoring unit 150.

[0125] Next, the monitoring device 101 refers to the correspondence table (S170). Specifically, the monitoring device 101 uses the correspondence table stored in the correspondence table storage unit 160 to execute the next step S141.

[0126] Next, the monitoring device 101 determines whether to continue charging or discharging the vehicle 21 (S141). If step S141 is performed after step S160, for example, the monitoring device 101 determines whether to continue charging or discharging the vehicle 21 based on the detected attack risk level and the remaining power information. If the monitoring device 100 determines, for example, that no attack has been detected (No in S120), in step S141 it does not make a determination to continue charging or discharging the vehicle 21 based on the risk level, but instead makes a determination, for example, based on the remaining power information, whether the vehicle 21 has been charged or discharged by a predetermined amount of power (i.e., the planned amount of power). Note that even if No is obtained in step S120, only step S160 of steps S130, S160, and S170 may be performed, and step S141 may be performed after step S160.

[0127] If the monitoring device 101 determines that charging or discharging of the vehicle 21 should continue (Yes in S141), it returns to step S120 and continues the detection process.

[0128] On the other hand, if the monitoring device 101 determines that it will not continue charging or discharging the vehicle 21 (No in S141), it terminates the charging or discharging of the vehicle 21 (S150).

[0129] [Effects, etc.] As described above, the monitoring device 101 determines whether or not to communicate with the charging / discharging station 30 based on the risk level of the attack and the remaining power of the battery 210. For example, even if the risk level is low, the monitoring device 101 will terminate communication if charging exceeds a threshold (50% capacity in the above example). Similarly, even if the risk level is low, the monitoring device 101 will terminate communication if discharging falls below a threshold. Even if the risk level is low, there is still a possibility that an attack has infiltrated the vehicle 21, even if it has not been detected, so the monitoring device 101 will, for example, only allow a minimum amount of charging or discharging.

[0130] In this way, even when an attack occurs, a minimum amount of charging or discharging is permitted, and if the risk level is high, communication between the vehicle 21 and the charging / discharging station 30 is cut off, thereby preventing the attack from spreading.

[0131] (modified version) The risk table and corresponding table may be defined as desired. Furthermore, the risk level to be determined may be selected from a classification of three or more levels, rather than just two.

[0132] Figures 8 and 9 show specific examples of risk tables related to modified versions.

[0133] The third example of a risk table shown in Figure 8 is a table that shows the correspondence between attack types and risk levels. Specifically, in this example, the risk table contains information that links attack types with risk levels.

[0134] In this example, the risk levels are set to "low," "medium," and "high." In this example, "sending malicious messages" and "downloading malware" are set to a risk level of "medium." The response determination unit 121, for example, if the type of attack detected by the attack detection unit 110 is "sending malicious messages," determines the risk level of the detected attack to be "medium."

[0135] The fourth example of a risk table shown in Figure 9 is a table that shows the correspondence between the detected attack targets and their risk levels. Specifically, in this example, the risk table contains information that links the detected attack targets with their risk levels.

[0136] In this example, when the source of the attack is an "ECU near the entry point" and the target of the attack is an "ECU related to body system functions," the risk level is set to "medium." For example, the response determination unit 121 determines the risk level of the detected attack to be "medium" if, for example, the target of the attack detected by the attack detection unit 110 is an "ECU related to body system functions" and the source of the attack is an "ECU near the entry point." Body system functions refer to functions that provide convenience and / or comfort to the occupants of a vehicle, such as the operation of wipers, power windows, or LED headlights.

[0137] Figure 10 shows a specific example of a correspondence table.

[0138] The second example of the correspondence table shown in Figure 10 illustrates the relationship between risk level, remaining power, and response method.

[0139] In this example, if the vehicle 21 is charging and the risk level of the detected attack is determined to be "high", the response determination unit 121 terminates the charging of the vehicle 21 regardless of the remaining power of the battery 210, and outputs alert information to the computer used in the SOC (SOC notification shown in Figure 10). For example, the response determination unit 121 outputs alert information to the vehicle control unit 220, causing the computer used in the SOC to send the alert information via the communication unit 230. The response determination unit 121 may also send the alert information to the computer used in the SOC via the communication unit 230 without going through the vehicle control unit 220.

[0140] In this example, the response determination unit 121 terminates charging of the vehicle 21 and outputs alert information to the computer used in the SOC when the vehicle 21 is charging, the risk level of the detected attack is determined to be "medium", and the remaining power of the battery 210 is 50% or more of the maximum capacity of the battery 210. On the other hand, in this example, the response determination unit 121 continues charging of the vehicle 21 and outputs alert information to the computer used in the SOC when the vehicle 21 is charging, the risk level of the detected attack is determined to be "medium", and the remaining power of the battery 210 is less than 50% of the maximum capacity of the battery 210.

[0141] In this example, if the vehicle 21 is discharging and the risk level of the detected attack is determined to be "high," the response determination unit 121 terminates the discharge of the vehicle 21 regardless of the remaining power of the battery 210, and outputs alert information to the computer used in the SOC.

[0142] In this example, the response determination unit 121 continues discharging the vehicle 21 and outputs alert information to the computer used in the SOC when the vehicle 21 is discharging, the risk level of the detected attack is determined to be "medium", and the remaining power of the battery 210 is 50% or more of the maximum capacity of the battery 210. On the other hand, in this example, the response determination unit 121 terminates charging the vehicle 21 and outputs alert information to the computer used in the SOC when the vehicle 21 is discharging, the risk level of the detected attack is determined to be "medium", and the remaining power of the battery 210 is less than 50% of the maximum capacity of the battery 210.

[0143] Thus, in this example, if the risk level of the detected attack is "medium," a decision is made based on the remaining power of the battery 210 to determine whether to continue charging or discharging, and regardless of the remaining power of the battery 210, alert information is output to the computer used in the SOC.

[0144] The risk table relating to this modified example may also be used in the monitoring device 100 (specifically, the response determination unit 120). For example, if the risk level is "high", the response determination unit 120 stops charging or discharging the vehicle 20 and outputs alert information to the SOC. Alternatively, if the risk level is "medium", the response determination unit 120 continues charging or discharging the vehicle 20 and outputs alert information to the SOC. Alternatively, if the risk level is "low", the response determination unit 120 continues charging or discharging the vehicle 20 and does not output alert information to the SOC.

[0145] (Representative example) Figure 11 is a flowchart of a monitoring method according to one aspect of the present disclosure. For example, monitoring device 100 or monitoring device 101 includes a processor and memory, and the processor uses the memory to perform the following processing. The following description will be given as processing performed by monitoring device 100.

[0146] First, the monitoring device 100 detects an attack on at least one of the mobile unit that uses the electric motor 200 as a driving source, and the charging and discharging equipment that charges and discharges the mobile unit in conjunction with communication with the mobile unit (S10).

[0147] The electric motor 200 is, for example, a motor installed in a mobile body, which is driven by a battery installed in the mobile body. The vehicles 20 and 21 described above are specific examples of mobile bodies. The charging and discharging station 30 described above is a specific example of charging and discharging equipment.

[0148] Next, the monitoring device 100 determines whether or not to change the communication status between the mobile unit and the charging / discharging equipment based on the risk level of the detected attack, which is determined based on the content of the detected attack (S20).

[0149] The nature of the attack includes, for example, the type of attack described above, and / or the target of detection for the attack described above.

[0150] If the monitoring device 100 determines that the communication status between the mobile unit and the charging / discharging equipment should be changed (Yes in S30), it changes the communication status between the mobile unit and the charging / discharging equipment (S40).

[0151] If the monitoring device 100 determines that the communication status between the mobile body and the charging / discharging equipment needs to be changed, it will stop the charging and discharging between the mobile body and the charging / discharging equipment, for example, by terminating the communication between the mobile body and the charging / discharging equipment that is currently communicating for charging and discharging purposes.

[0152] On the other hand, if the monitoring device 100 determines, for example, that the communication status between the mobile body and the charging / discharging equipment will not be changed (No in S30), then, for example, the communication status will not be changed, meaning that communication and charging / discharging between the mobile body and the charging / discharging equipment will continue, and the process of detecting an attack on at least one of them will continue to be executed.

[0153] (summary) The following describes examples of technologies that can be obtained from the disclosures in this specification, and explains the effects that can be obtained from these examples.

[0154] Technology 1 is a monitoring device 100, 101 comprising: an attack detection unit 110 that detects an attack on at least one of a mobile body that uses an electric motor 200 as a driving source for travel, and a charging / discharging facility that charges and discharges the mobile body while communicating with the mobile body; a response determination unit 120, 121 that determines whether or not to change the communication status between the mobile body and the charging / discharging facility based on the risk level of the detected attack determined based on the content of the detected attack; and a communication control unit 130 that changes the communication status between the mobile body and the charging / discharging facility if it is determined that the communication status between the mobile body and the charging / discharging facility should be changed.

[0155] With such monitoring devices 100 and 101, communication between the mobile device and the charging / discharging equipment can be continued or terminated depending on the risk level, that is, depending on the nature of the detected attack. Therefore, with such monitoring devices 100 and 101, charging and discharging of the mobile device can be continued or stopped depending on the nature of the detected attack. Therefore, with such monitoring devices 100 and 101, communication can be prevented from being unnecessarily terminated when an attack is detected, depending on the nature of the detected attack.

[0156] Technology 2 is a monitoring device 100, 101 as described in Technology 1, wherein the corresponding determination units 120, 121 identify the type of attack detected and determine the risk level of the detected attack based on the type of attack detected.

[0157] Examples of attack types include port scanning, sending malicious messages, and firmware tampering, as mentioned above. Some attack types are highly dangerous, while others are less dangerous. Therefore, monitoring devices 100 and 101 can control the communication state according to the danger level of the detected attack.

[0158] Technology 3 is a monitoring device 100, 101 according to Technology 1 or 2, in which the response determination units 120, 121 identify the victim who has been subjected to the detected attack and determine the risk level of the detected attack based on the victim.

[0159] Depending on the attacker, high-risk behavior may occur, but not always. Therefore, these monitoring devices 100 and 101 can control the communication state depending on whether or not high-risk behavior occurs.

[0160] Technology 4 is a monitoring device 100, 101 as described in Technology 3, in which the response determination units 120, 121 identify the attack source that carried out the detected attack and determine the risk level of the detected attack based on the victim and the attack source.

[0161] Such monitoring devices 100 and 101 allow for control of the communication state while also considering the source of the attack.

[0162] Technology 5 is a monitoring device 101 according to any one of Technologies 1 to 4, which includes a power level monitoring unit 150 that monitors the remaining power of the battery in the mobile device.

[0163] Depending on the remaining power, it may be better to continue charging and discharging, or it may be acceptable to stop charging and discharging immediately. Therefore, such a monitoring device 101 can further prevent unnecessary termination of communication.

[0164] Technology 6 is a monitoring device 101 described in Technology 5, in which the response determination unit 121 determines whether or not to change the communication status between the mobile device and the charging / discharging equipment based on the remaining power monitored by the remaining power monitoring unit 150 and the detected risk level of attack.

[0165] With such a monitoring device 101, the remaining power level is also taken into consideration, which further helps to prevent unnecessary termination of communications.

[0166] Technology 7 is a monitoring device 100, 101 according to any one of Technologies 1 to 6, wherein the attack detection unit 110 detects an attack on at least one of the devices based on attack information received from an external device regarding an attack on at least one of the devices.

[0167] The external device is, for example, a computer capable of communicating with a mobile object and detecting attacks.

[0168] Such monitoring devices 100 and 101 can detect attacks using information from external devices.

[0169] Technology 8 is a monitoring device 100, 101 described in any of Technologies 1 to 7, in which the corresponding determination units 120, 121 acquire risk level information indicating the risk level of an attack detected from an external device.

[0170] With such monitoring devices 100 and 101, the risk level of a detected attack can be determined using information from external devices.

[0171] Technology 9 is a monitoring device 100, 101 described in any of Technologies 1 to 8, in which the response determination units 120, 121 determine the risk level of a detected attack based on risk table information that shows the correspondence between the content of the attack and the risk level.

[0172] With such monitoring devices 100 and 101, the risk level of a detected attack can be easily determined using risk table information.

[0173] Technology 10 is a monitoring device 100, 101 described in any of Technologies 1 to 9, wherein the response determination unit 120, 121 outputs notification information indicating that communication between the mobile device and the charging / discharging equipment should be terminated if it determines to do so based on the detected risk level of the attack.

[0174] The notification information is transmitted, for example, to a terminal used by the user of the mobile device. With such monitoring devices 100, 101, the user of the mobile device can immediately understand that communication between the mobile device and the charging / discharging equipment has ended, that is, that charging and discharging has stopped.

[0175] Technology 11 is a monitoring method that detects an attack on at least one of a mobile body that uses an electric motor 200 as a driving source for propulsion, and a charging and discharging facility that charges and discharges the mobile body while communicating with the mobile body (S10), determines whether or not to change the communication status between the mobile body and the charging and discharging facility based on the risk level of the detected attack determined based on the content of the detected attack (S20), and if it is determined that the communication status between the mobile body and the charging and discharging facility should be changed (Yes in S30), changes the communication status between the mobile body and the charging and discharging facility (S40).

[0176] This monitoring method produces the same effect as the monitoring devices 100 and 101 of Technology 1.

[0177] Furthermore, this disclosure may be implemented as a program for a computer to execute the monitoring method described above, or as a computer-readable non-temporary recording medium for recording said program.

[0178] (Other embodiments) Although each embodiment has been described above, this disclosure is not limited to the embodiments described above.

[0179] For example, monitoring devices 100 and 101 may determine whether the charging / discharging station 30 is an infrastructure-independent charging / discharging station (i.e., not connected to a network), such as a household charging / discharging station. If the charging / discharging station 30 is infrastructure-independent, monitoring devices 100 and 101 may, regardless of whether an attack is detected, allow the vehicles 20 and 21 to be charged and discharged as if no attack were detected. On the other hand, if the charging / discharging station 30 is not infrastructure-independent, monitoring devices 100 and 101 may execute the flowchart shown in Figures 4, 7, or 11. Monitoring devices 100 and 101 may obtain information indicating whether the charging / discharging station 30 is infrastructure-independent from the charging / discharging station 30, a terminal used by a user, or an external communication device such as a server.

[0180] Furthermore, risk levels may be set using categories such as "high," "medium," or "low," or they may be set using numerical values ​​such as "1," "2," or "3."

[0181] Furthermore, for example, the monitoring devices 100 and 101 are attached to the mobile body, but only need to be able to communicate with the mobile body, and may be located outside the mobile body. The monitoring devices 100 and 101 may, for example, communicate with the mobile body (for example, the vehicle control unit 220 provided in the vehicles 20 and 21) to cause the vehicle control unit 220 to change the communication status between the mobile body and the charging / discharging equipment.

[0182] Furthermore, the mobile object is, for example, a vehicle, but it may be any mobile object such as an automobile, a motorcycle, or a mobile robot powered by a battery.

[0183] Furthermore, the charging and discharging equipment may have both the function of charging a mobile device and the function of receiving discharge from a mobile device, or it may have only one of these functions.

[0184] Furthermore, for example, in each of the above embodiments, a process executed by a specific processing unit may be executed by another processing unit. Also, the order of multiple processes may be changed, or multiple processes may be executed in parallel.

[0185] Furthermore, in each of the above embodiments, each component may be realized by executing a software program suitable for that component. Each component may also be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0186] Furthermore, each component may be implemented by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or they may be separate circuits. Also, each of these circuits may be a general-purpose circuit or a dedicated circuit.

[0187] Furthermore, the general or specific embodiments of this disclosure may be implemented in devices, systems, methods, integrated circuits, computer programs, or non-temporary recording media such as computer-readable CD-ROMs. Also, the general or specific embodiments of this disclosure may be implemented in any combination of devices, systems, methods, integrated circuits, computer programs, and recording media.

[0188] Furthermore, this disclosure also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art could conceive, or forms realized by arbitrarily combining the components and functions of each embodiment without departing from the spirit of this disclosure. [Industrial applicability]

[0189] This disclosure is useful for devices that perform processing in response to attacks on vehicles or charging / discharging equipment. [Explanation of symbols]

[0190] 10, 11 Charging and discharging systems Vehicles 20 and 21 30 charging / discharging stands 100, 101 Monitoring equipment 110 Attack Detection Unit 120, 121 Correspondence determination unit 130 Communication Control Unit 140 Risk Table Storage Unit 150 Power remaining monitoring unit 160 Compatible Table Storage Unit 200 Electric motor 210 battery 220 Vehicle Control Unit 230 Communications Department

Claims

1. An attack detection unit that detects an attack on at least one of a mobile body that uses an electric motor as a drive source, and a charging and discharging facility that charges and discharges the mobile body in conjunction with communication with the mobile body, A response determination unit determines whether or not to change the communication status between the mobile unit and the charging / discharging equipment based on the risk level of the detected attack, which is determined based on the content of the detected attack. The system includes a communication control unit that changes the communication status between the mobile unit and the charging / discharging equipment when it is determined that the communication status between the mobile unit and the charging / discharging equipment should be changed. Monitoring equipment.

2. The correspondence determination unit, Identify the type of attack detected, Based on the type of attack detected, the risk level of the detected attack is determined. The monitoring device according to claim 1.

3. The correspondence determination unit, Identify the victim who was subjected to the detected attack, Based on the aforementioned attacker, the risk level of the detected attack is determined. The monitoring device according to claim 1.

4. The correspondence determination unit, Identify the source of the attack that carried out the detected attack, Based on the aforementioned victim and the aforementioned source of attack, the risk level of the detected attack is determined. The monitoring device according to claim 3.

5. The mobile unit is equipped with a power level monitoring unit that monitors the remaining power of the battery it has. A monitoring device according to any one of claims 1 to 4.

6. The corresponding determination unit determines whether or not to change the communication status between the mobile unit and the charging / discharging equipment based on the remaining power monitored by the remaining power monitoring unit and the detected attack risk level. The monitoring device according to claim 5.

7. The attack detection unit detects an attack against at least one of the aforementioned based on attack information received from an external device relating to an attack against at least one of the aforementioned. A monitoring device according to any one of claims 1 to 4.

8. The corresponding determination unit acquires risk level information from an external device indicating the risk level of the detected attack. A monitoring device according to any one of claims 1 to 4.

9. The response determination unit determines the risk level of the detected attack based on risk table information that shows the correspondence between the content of the attack and the risk level. A monitoring device according to any one of claims 1 to 4.

10. If the corresponding determination unit determines, based on the detected attack risk level, that it should terminate communication between the mobile device and the charging / discharging equipment, it outputs notification information indicating that it will terminate communication between the mobile device and the charging / discharging equipment. A monitoring device according to any one of claims 1 to 4.

11. An attack is detected against at least one of the following: a mobile body that uses an electric motor as a drive source, and a charging and discharging facility that charges and discharges the mobile body while communicating with the mobile body. Based on the content of the detected attack, and the risk level of the detected attack, it is determined whether or not to change the communication status between the mobile device and the charging / discharging equipment. If it is determined that the communication status between the mobile body and the charging / discharging equipment should be changed, the communication status between the mobile body and the charging / discharging equipment should be changed. Monitoring method.