Battery data management method, battery data management system, and program

The battery data management method employs a distributed ledger system to securely manage battery data for electric vehicles, preventing tampering and ensuring accurate evaluation of battery residual value, thus enhancing the reliability of battery replacement and reuse services.

JP7699550B2Active Publication Date: 2025-06-27PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021571220
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-01-17
Filing Date
2021-01-14
Publication Date
2025-06-27
Estimated Expiration
2041-01-14

AI Technical Summary

Technical Problem

The challenge is to manage battery data for electric vehicles in a way that prevents tampering, ensuring the integrity of the data for effective battery replacement and reuse services.

Method used

A battery data management method utilizing a distributed ledger system, where electric vehicles acquire sensor information, generate transaction data, and an authentication server records this data in a blockchain, ensuring data integrity and preventing tampering.

Benefits of technology

This approach allows for secure and tamper-proof management of battery data, enhancing the reliability of battery replacement and reuse services by ensuring accurate evaluation of battery residual value.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007699550000001
    Figure 0007699550000001
  • Figure 0007699550000002
    Figure 0007699550000002
  • Figure 0007699550000003
    Figure 0007699550000003
Patent Text Reader

Abstract

In this battery data management method for a battery data management system provided with a plurality of authentication servers, each having a distributed ledger, and an electric vehicle: the electric vehicle (10) acquires first sensor information relating to a battery (140) installed in the electric vehicle (10); the electric vehicle (10) generates first transaction data including an ID of the battery (140) and the first sensor information (S208); one authentication server from among the plurality of authentication servers acquires the first transaction data (S210); and the one authentication server records a block including the first transaction data in the distributed ledger.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a battery data management method, a battery data management system, and a program.

Background Art

[0002] In recent years, electric vehicles such as electric cars and electric motorcycles have begun to be used. And, for example, by adopting a replaceable battery as the power source of an electric vehicle, not only can the battery be charged, but also services such as replacing the battery installed at a charging station are considered. In this service, by charging a plurality of batteries simultaneously at a charging station, the charged batteries can be provided to users at any time. For this reason, a user can replace a battery with a low remaining battery level with another charged battery at a charging station. As a result, the user can continue driving the electric vehicle only by replacing the battery without considering the charging time of the battery, and an extension of the driving distance can be expected.

[0003] Also, in this service, by using a battery that is standardized among electric vehicle manufacturers, a scale merit is expected in which charging stations by multiple manufacturers are arranged everywhere.

[0004] On the other hand, it is also assumed that if an illegal battery is mixed in a service for replacing a battery, the electric vehicle may not operate properly, or in the worst case, a fire caused by the battery may occur. For example, Patent Document 1 discloses a method for detecting an illegal battery.

[0005] Also, even for a regular battery, the degree of deterioration varies depending on usage conditions and the like. Therefore, in order to provide a charged battery to the user at any time, it is necessary to evaluate the residual value of the battery. Even when using a regular battery in a battery replacement service, the distance that can be continuously traveled varies depending on the replaced battery. Therefore, depending on the degree of deterioration, it may be necessary to remove the battery from the charging station.

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] However, if the usage conditions of the battery are tampered with, the residual value of the battery cannot be correctly evaluated, and there is a problem that a service for replacing a battery with scale merit cannot be established.

[0008] The present disclosure has been made in view of the above circumstances, and an object thereof is to provide a battery data management method and the like that can manage the data of the battery mounted on an electric vehicle so as not to be tampered with.

Means for Solving the Problems

[0009] To achieve the above object, a battery data management method of the present disclosure is a battery data management method in a battery data management system including a plurality of authentication servers each having a distributed ledger and an electric vehicle, wherein the electric vehicle acquires first sensor information about a battery mounted on the electric vehicle, the electric vehicle generates first transaction data including the battery ID and the first sensor information, one of the plurality of authentication servers acquires the first transaction data, and the one authentication server records a block including the first transaction data in the distributed ledger.

[0010] Note that these general or specific aspects may be implemented in a system, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or may be implemented in any combination of a system, a method, an integrated circuit, a computer program, and a recording medium.

Effect of the Invention

[0011] According to the battery data management method and the like of the present disclosure, it is possible to manage the data of the battery mounted on the electric vehicle so as not to be tampered with.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

DETAILED DESCRIPTION OF THE INVENTION

[0013] A battery data management method according to an aspect of the present disclosure is a battery data management method in a battery data management system including a plurality of authentication servers each having a distributed ledger and an electric vehicle, wherein the electric vehicle acquires first sensor information about a battery mounted on the electric vehicle, the electric vehicle generates first transaction data including the ID of the battery and the first sensor information, one of the plurality of authentication servers acquires the first transaction data, and the one authentication server records a block including the first transaction data in the distributed ledger.

[0014] Thereby, the first sensor information, which is battery data, can be stored in the distributed ledger. Therefore, it is possible to manage the data of the battery mounted on the electric vehicle so as not to be tampered with.

[0015] Also, when acquiring the first sensor information, the electric vehicle may acquire driving data obtained when the electric vehicle is running and the first sensor information at the time of running, and when generating the first transaction data, the electric vehicle may generate first transaction data including the ID of the battery, the driving data, and the first sensor information at the time of running.

[0016] Also, the battery data management method may further perform first mutual authentication between the electric vehicle and the battery before acquiring the first sensor information about the battery, and when the first mutual authentication is successful, the electric vehicle may acquire the first sensor information about the battery.

[0017] Also, the first sensor information may include the voltage, current, temperature, impedance of the battery, and acceleration information of the electric vehicle on which the battery is mounted.

[0018] Further, the battery data management system further includes a charging station capable of charging the battery by being connected to the battery. The battery data management method further includes: the charging station obtaining second sensor information of the battery charged by being connected to the charging station; the charging station generating second transaction data including the ID of the battery and the second sensor information; the one authentication server obtaining the second transaction data; and the one authentication server recording a block including the second transaction data in the distributed ledger.

[0019] Further, the battery data management method further includes performing second mutual authentication between the charging station and the battery connected to the charging station for charging before obtaining the second sensor information of the battery, and if the second mutual authentication is successful, the charging station obtaining the second sensor information.

[0020] Further, the second sensor information may include the voltage, current, temperature, and impedance of the battery.

[0021] Further, the battery data management system further includes a battery evaluation server. The battery data management method further includes: the battery evaluation server obtaining transaction data related to the battery recorded in the distributed ledger; the battery evaluation server evaluating the battery from the obtained transaction data related to the battery; the battery evaluation server generating third transaction data including the evaluation result of the battery and the ID of the battery; the one authentication server obtaining the third transaction data; and the one authentication server recording a block including the third transaction data in the distributed ledger.

[0022] Further, the evaluation result of the battery may include an evaluation result regarding the state of the battery including the residual value of the battery.

[0023] Further, the evaluation result of the battery may include the presence or absence of reuse of the battery based on the state of the battery and the battery ID of the battery.

[0024] Moreover, a battery data management system according to an embodiment of the present disclosure is a battery data management system including a plurality of authentication servers each having a distributed ledger and an electric vehicle, wherein the electric vehicle includes a first communication unit that acquires first sensor information about a battery mounted on the electric vehicle, and a transaction data generation unit that generates first transaction data including the battery ID and the first sensor information, and one of the plurality of authentication servers includes a second communication unit that acquires the first transaction data, and a recording unit that records a block including the first transaction data in the distributed ledger.

[0025] Hereinafter, embodiments will be described with reference to the drawings. Note that each of the embodiments described below shows a preferred specific example of the present disclosure. That is, the numerical values, shapes, materials, components, arrangements and connection forms of the components, steps, order of steps, etc. shown in the following embodiments are merely examples and are not intended to limit the present disclosure. The present disclosure is specified based on the description of the claims. Therefore, among the components in the following embodiments, the components not described in the independent claims indicating the most general concept of the present disclosure are not necessarily required to achieve the problems of the present disclosure, but are described as components constituting a more preferable form.

[0026] (Embodiment) First, the system configuration of the present disclosure will be described.

[0027] [1. System Configuration] The battery data management of the present disclosure records battery data used to evaluate the residual value of a battery in a distributed ledger. Thereby, the battery data management system of the present disclosure can utilize blockchain technology to store the data at least to prevent forgery. Furthermore, by recording the data in a distributed ledger, the reliability of the data can be guaranteed. For this reason, individual batteries can be effectively utilized, such as using a battery with early deterioration for other uses than in an electric vehicle at an appropriate timing, and performing uses suitable for individual batteries.

[0028] Hereinafter, a battery data management system and the like in an embodiment will be described with reference to the drawings.

[0029] [1.1 Overall Configuration of Battery Data Management System 1] FIG. 1 is a diagram showing an example of the overall configuration of a battery data management system 1 according to the present embodiment. As shown in FIG. 1, the battery data management system 1 includes an electric vehicle 10, a charging station 20, authentication servers 30a, 30b, 30c, a battery manufacturer server 40, a battery reuse business operator server 50, and charging facilities 60. These are connected by a communication network 70 except for the charging facilities 60.

[0030] Each of the authentication servers 30a, 30b, 30c is connected to a storage device having a distributed ledger in which blockchain transaction data and blocks are electronically recorded. Note that the authentication servers 30a, 30b, 30c may be connected to the storage device via the communication network 70, or may be provided with the storage device inside. The authentication servers 30a, 30b, 30c may hereinafter sometimes be expressed as the authentication server 30.

[0031] Note that FIG. 1 shows an example in which the battery data management system 1 includes three authentication servers 30, but it is not limited thereto. That is, the battery data management system 1 may include four or more authentication servers 30.

[0032] The following describes each component.

[0033] [1.2 Configuration of Electric Vehicle 10] FIG. 2 is a block diagram showing an example of the overall configuration of the electric vehicle 10 according to the present embodiment.

[0034] The electric vehicle 10 is, for example, an electric motorcycle or an electric vehicle, but is not limited thereto. As long as the electric vehicle 10 can generate power with the power of the battery 140 and accelerate the vehicle body, it may be a flying car, a flying motorcycle, an airplane, or a ship.

[0035] In the present embodiment, as shown in FIG. 2, the electric vehicle 10 includes a vehicle management unit 110, a battery connection unit 120, and a communication unit 130.

[0036] The vehicle management unit 110 is a processing unit that controls the operation of the electric vehicle 10. The specific configuration of the vehicle management unit 110 will be described later with reference to FIG. 3.

[0037] The battery connection unit 120 is used to connect to the battery 140. When the battery 140 is connected by mounting the battery 140 at a predetermined position of the electric vehicle 10, the battery connection unit 120 receives power supply from the battery 140. The power from the battery 140 is supplied to an actuator (for example, a motor) that generates the power of the electric vehicle 10, a control circuit that realizes the vehicle management unit 110, a communication interface that realizes the communication unit 130, and the like.

[0038] The communication unit 130 communicates with the authentication server 30 via the communication network 70. The communication unit 130 may be communicably connected not only to the authentication server 30 via the communication network 70, but also to other devices via the communication network 70. Further, the communication unit 130 may be directly communicably connected to other devices. The communication interface that realizes the communication unit 130 may be any communication interface that can communicate with the communication network 70. Note that the communication interface that realizes the communication unit 130 may be included in the control circuit that realizes the vehicle management unit 110.

[0039] [1.2.1 Vehicle Management Unit 110] Hereinafter, an example of the configuration of the vehicle management unit 110 will be described.

[0040] FIG. 3 is a block diagram showing an example of the configuration of the vehicle management unit 110 shown in FIG. 2.

[0041] The vehicle management unit 110 is a processing unit that controls the operation of the electric vehicle 10 as described above. The vehicle management unit 110 is realized by, for example, a control circuit including a processor and a memory. The vehicle management unit 110 includes, for example, as shown in FIG. 3, an authentication unit 1101, a control unit 1102, a charge management unit 1103, a transaction data generation unit 1104, and a recording unit 1105. Hereinafter, each component will be described.

[0042] <Authentication Unit 1101> The authentication unit 1101 authenticates the battery 140 connected to the battery connection unit 120. The authentication unit 1101 has a security chip that holds an encryption key or a certificate used for authentication. This security chip has tamper resistance in order to prevent forgery and leakage of the held encryption key or certificate. Note that the authentication unit 1101 may perform the authentication process of the battery 140 using, for example, TLS (Transport Layer Security), or may perform mutual authentication with the battery 140 using TLS.

[0043] Further, the authentication unit 1101 may not have a security chip that holds an encryption key or a certificate. When the authentication unit 1101 does not have a security chip, for example, the vehicle management unit 110 may have a security chip. Even in this case, the authentication unit 1101 holds an encrypted encryption key or certificate. Therefore, the authentication unit 1101 may decrypt the encrypted encryption key or certificate in the security chip of the vehicle management unit 110 and perform authentication using the decrypted encryption key or certificate.

[0044] The authentication unit 1101 authenticates the battery 140. As a result of the authentication, if the battery 140 connected to the battery connection unit 120 is unauthorized, the authentication unit 1101 outputs the ID of the unauthorized battery 140 (hereinafter also referred to as the battery ID) to the recording unit 1105. When the electric vehicle 10 is connected to the battery manufacturer server 40 via the communication network 70, the authentication unit 1101 may notify the battery manufacturer server 40 of the battery ID of the unauthorized battery 140 connected to the battery connection unit 120.

[0045] Note that the authentication unit 1101 may authenticate the user who operates the electric vehicle 10. In this case, the authentication unit 1101 may, for example, obtain user information from a user authentication server to authenticate the user, or may send the user information to the user authentication server for authentication.

[0046] <Control unit 1102> The control unit 1102 controls the operation of the electric vehicle 10. The control unit 1102 controls the operation of an actuator that generates power for the electric vehicle 10 according to an operation by the user of the electric vehicle 10. For example, the control unit 1102 controls operations related to the running of the electric vehicle 10 according to the user's operation. As described above, the control unit 1102 operates with power supplied from the battery 140 via the battery connection unit 120.

[0047] <Charge management unit 1103> The charging management unit 1103 controls the charging of the battery 140 connected to the battery connection unit 120. When the electric vehicle 10 is connected to a power source, the charging management unit 1103 charges the battery 140 connected to the battery connection unit 120 with the power from the power source. The power source may be, for example, a charging facility 60 or a household outlet.

[0048] <Transaction data generation unit 1104> The transaction data generation unit 1104 acquires sensor information of the battery 140 during charging or when the electric vehicle 10 is running.

[0049] In the present embodiment, the transaction data generation unit 1104 acquires sensor information (also referred to as first sensor information) of the battery 140 when the electric vehicle 10 is running. Here, the first sensor information includes the voltage, current, temperature, impedance of the battery 140 when the electric vehicle 10 is running, and acceleration information of the electric vehicle 10 on which the battery 140 is mounted. Note that the transaction data generation unit 1104 can acquire temperature, voltage, and current from the battery 140 when the electric vehicle 10 is running among the first sensor information, and acquire acceleration information from the control unit 1102 as the acceleration of the electric vehicle 10. This is because the acceleration information of the electric vehicle 10 is information about the physical impact applied to the battery 140. Note that the first sensor information may include the discharge amount during running. Also, the first sensor information includes at least one of the voltage, current, temperature, impedance during running, and acceleration information of the electric vehicle 10.

[0050] Further, for example, the transaction data generation unit 1104 acquires sensor information (also referred to as second sensor information) of the battery 140 during charging. Here, the second sensor information includes the voltage, current, temperature, and impedance of the battery 140 during charging. The second sensor information may further include the charge amount and the number of charging times. Note that the transaction data generation unit 1104 can acquire the second sensor information from the battery 140 during charging.

[0051] The transaction data generation unit 1104 generates transaction data in the blockchain.

[0052] In the present embodiment, the transaction data generation unit 1104 generates transaction data including the acquired sensor information, that is, the first sensor information or the second sensor information, and the battery ID of the battery 140. Here, when the transaction data generation unit 1104 includes the first sensor information in the generated transaction data, it may further include the ID of the electric vehicle 10 or the driving data of the electric vehicle 10. Also, when the transaction data generation unit 1104 includes the second sensor information in the generated transaction data, it may further include the ID of the charging station 20 or the ID of the charging facility 60 used for charging the battery 140.

[0053] The transaction data generation unit 1104 transmits the generated transaction data to the authentication server 30.

[0054] <Recording unit 1105> The recording unit 1105 may be a storage medium composed of a rewritable non-volatile memory such as a hard disk drive or a solid state drive, for example. The recording unit 1105 records the battery ID of the unauthorized battery 140. The recording unit 1105 manages the battery ID of the unauthorized battery 140 by storing the battery ID of the unauthorized battery 140 connected to the battery connection unit 120 each time the unauthorized battery 140 is connected to the battery connection unit 120.

[0055] Note that the recording unit 1105 may further manage the battery ID of the regular battery 140. That is, the recording unit 1105 may store the battery IDs of all the batteries 140 connected to the battery connection unit 120 regardless of whether they are unauthorized. In this case, each time a battery 140 is connected to the battery connection unit 120, the recording unit 1105 stores the battery ID of the battery 140 connected to the battery connection unit 120. Then, in order to distinguish between the battery ID of the unauthorized battery 140 and the battery ID of the regular battery 140, the recording unit 1105 may further store an identifier indicating whether it is unauthorized or regular. Thereby, the recording unit 1105 can record and manage the battery ID of the unauthorized battery 140 and the battery ID of the regular battery 140.

[0056] [1.2.2 Configuration of Battery 140] Next, an example of the configuration of the battery 140 will be described.

[0057] FIG. 4 is a block diagram showing an example of the configuration of the battery 140 according to the present embodiment.

[0058] The battery 140 includes, for example, as shown in FIG. 4, an authentication unit 1401, a measurement unit 1402, a control unit 1403, a recording unit 1404, and a communication unit 1405. Hereinafter, each component will be described.

[0059] <Authentication Unit 1401> The authentication unit 1401 authenticates the vehicle management unit 110 connected to supply the power stored in the battery 140 or the charging station 20 connected to charge the battery 140. The authentication unit 1401 has a security chip that holds an encryption key or a certificate used for authentication. This security chip has tamper resistance in order to prevent forgery and leakage of the held encryption key or certificate.

[0060] Note that the authentication unit 1401 may perform authentication processing of the vehicle management unit 110 or the charging station 20 using, for example, TLS, or may perform mutual authentication with the vehicle management unit 110 or the charging station 20 using TLS.

[0061] In addition, the authentication unit 1401 may not have a security chip that holds an encryption key or a certificate. When the authentication unit 1401 does not have a security chip, for example, the battery 140 may have a security chip. Even in this case, the authentication unit 1401 holds an encrypted encryption key or certificate. Therefore, the authentication unit 1401 may decrypt the encrypted encryption key or certificate in the security chip of the battery 140 and perform authentication using the decrypted encryption key or certificate.

[0062] The authentication unit 1401 authenticates the electric vehicle 10 or the charging station 20 each time they are connected. As a result of the authentication, if the connected electric vehicle 10 is unauthorized or the connected charging station 20 is unauthorized, the authentication unit 1401 records the ID of the unauthorized electric vehicle 10 (hereinafter also referred to as the vehicle ID) or the ID of the unauthorized charging station 20 in the recording unit 1404.

[0063] <Measurement unit 1402> The measurement unit 1402 measures the number of times the battery 140 has been charged and the amount of charge. The measurement unit 1402 also measures the temperature, voltage, and current of the battery during charging. If the measurement unit 1402 has an acceleration sensor or the like, it may measure the acceleration of the battery 140.

[0064] The measurement unit 1402 may measure the temperature, voltage, and current of the battery at regular intervals. In addition, the measurement unit 1402 may measure each time it is connected to the electric vehicle 10 or the charging station 20.

[0065] <Control unit 1403> The control unit 1403 controls the charging and discharging of the battery 140.

[0066] <Recording unit 1404> The recording unit 1404 may be a storage medium composed of a rewritable non-volatile memory such as a hard disk drive or a solid state drive, for example. The recording unit 1404 records the measurement data measured by the measurement unit 1402. The recording unit 1404 may store the measurement data in association with the date and time when the measurement data was measured. The recording unit 1404 may have a security chip (memory) with tamper resistance so that the measured data cannot be falsified.

[0067] <Communication unit 1405> The communication unit 1405 is communicably connected to the electric vehicle 10 when the battery 140 is connected to the battery connection part 120 of the electric vehicle 10. Similarly, the communication unit 1405 is communicably connected to the charging station 20 when the battery 140 is connected to the charging station 20 for charging.

[0068] [1.3 Configuration of charging station 20] Next, an example of the configuration of the charging station 20 will be described.

[0069] The charging station 20 is a facility that can charge and hold one or more batteries 140 simultaneously. The charging station 20 has, for example, as shown in FIG. 1, one or more compartments capable of charging the battery 140 respectively. That is, each of the one or more compartments can charge the battery 140 when the battery 140 is stored and connected.

[0070] FIG. 5 is a block diagram showing an example of the configuration of the charging station 20 according to the present embodiment.

[0071] The charging station 20 includes, for example, as shown in FIG. 5, a user authentication unit 201, a battery authentication unit 202, a charging control unit 203, a transaction data generation unit 204, a recording unit 205, and a communication unit 206.

[0072] <User authentication unit 201> The user authentication unit 201 authenticates a user who uses the charging station 20.

[0073] For example, the user authentication unit 201 may perform password authentication using the user's ID and password by obtaining the user's ID and password from an input interface (not shown). In password authentication, the user authentication unit 201 can authenticate the user by comparing the pre-registered user ID and password with the user ID and password obtained from the input interface. The pre-registered user ID and password are an example of user information.

[0074] Also, for example, the user authentication unit 201 may authenticate the user using the membership card held by the user. In authentication using the membership card, the user authentication unit 201 can authenticate the user by comparing the pre-registered membership card information with the membership card information read by the input interface. The pre-registered membership card information is an example of user information.

[0075] Also, the user authentication unit 201 may perform biometric authentication on the user. In biometric authentication, for example, face authentication or iris authentication using an input interface such as a camera may be performed. In biometric authentication, the user authentication unit 201 can authenticate the user by comparing the pre-registered biometric information of the user with the biometric information of the user read by the input interface. The pre-registered biometric information of the user is an example of user information.

[0076] In addition to the above authentication methods, the user authentication unit 201 may use a conventional authentication method. The user authentication unit 201 may obtain the pre-registered user information used for user authentication from the authentication server 30. The user authentication unit 201 may send the user information obtained from the input interface at the time of authentication to the authentication server 30 and obtain the result of the authentication process performed by the authentication server 30.

[0077] <Battery authentication unit 202> The battery authentication unit 202 is stored in the charging station 20 and authenticates the battery 140 connected for charging. The battery authentication unit 202 has a security chip that holds an encryption key or a certificate used for authentication. This security chip has tamper resistance in order to prevent forgery or leakage of the held encryption key or certificate.

[0078] Note that the battery authentication unit 202 may perform the authentication process of the battery 140 connected for charging using, for example, TLS, or may perform mutual authentication with the battery 140 connected for charging using TLS.

[0079] Also, the battery authentication unit 202 may not have a security chip that holds an encryption key or a certificate. When the battery authentication unit 202 does not have a security chip, for example, the battery 140 may have a security chip. Even in this case, the battery authentication unit 202 holds an encrypted encryption key or certificate. Therefore, the battery authentication unit 202 may decrypt the encrypted encryption key or certificate in the security chip of the battery 140 and perform authentication using the decrypted encryption key or certificate.

[0080] Also, when the authentication of the battery 140 is successful and the charging is completed, the battery authentication unit 202 may notify the authentication server 30 of the number of charging times.

[0081] Note that when the connected battery 140 is illegal as a result of the authentication of the battery 140, the battery authentication unit 202 outputs the battery ID of the illegal battery 140 to the recording unit 205. When the charging station 20 is connected to the battery manufacturer server 40 via the communication network 70, the battery authentication unit 202 may notify the battery manufacturer server 40 of the battery ID of the connected illegal battery 140.

[0082] <Charging control unit 203> The charging control unit 203 is stored in the charging station 20 and controls the charging of the battery 140 connected for charging.

[0083] In addition, when the user authentication by the user authentication unit 201 fails and the authentication of the battery 140 by the battery authentication unit 202 fails, the charging control unit 203 does not charge the battery 140. That is, when the user is an unauthorized user or the battery 140 is an unauthorized battery 140, the charging of the battery 140 is prohibited, so the charging control unit 203 does not charge the battery 140.

[0084] <Transaction data generation unit 204> The transaction data generation unit 204 acquires the second sensor information of the battery 140 during charging. As described above, the second sensor information includes the voltage, current, temperature, and impedance of the battery 140 during charging. The second sensor information may further include the charge amount and the number of charging times.

[0085] The transaction data generation unit 204 generates transaction data in the blockchain. In the present embodiment, the transaction data generation unit 204 generates transaction data including the acquired second sensor information and the battery ID of the battery 140. Here, the transaction data generation unit 204 may further include the ID of the charging station 20 used for charging the battery 140 and the temperature of the charging station 20 during charging in the transaction data.

[0086] Also, the transaction data generation unit 204 transmits the generated transaction data to the authentication server 30.

[0087] <Recording unit 205> The recording unit 205 may be a storage medium composed of a rewritable non-volatile memory such as a hard disk drive or a solid state drive, for example. The recording unit 205 records the battery ID of the battery 140 connected to the charging station 20 for charging. The recording unit 205 may record data of the battery 140 such as the number of charging times of the battery 140 having the battery ID in association with the battery ID.

[0088] The recording unit 205 may record the battery IDs of all the batteries 140 connected for charging. In this case, the recording unit 205 may record the battery ID of the connected battery 140 each time the battery 140 is connected to the charging station 20. Note that the recording unit 205 may record the battery ID and the date and time when the battery 140 having the battery ID is connected to the charging station 20 in association with each other. Further, the recording unit 205 may further record an identifier indicating whether it is illegal or regular in order to distinguish the battery ID of the illegal battery 140 from the battery ID of the regular battery 140. Thereby, the recording unit 205 can manage the battery ID of the illegal battery 140 and the battery ID of the regular battery 140.

[0089] <Communication unit 206> The communication unit 206 is communicably connected to the battery 140 when the battery 140 is connected to the charging station 20 for charging. The communication unit 206 acquires the battery data of the battery 140, that is, the second sensor information and the battery ID, from the battery 140 connected to the charging station 20. Note that the communication unit 206 is an example of an acquisition unit.

[0090] [1.4 Configuration of Authentication Server 30] The authentication servers 30a, 30b, and 30c utilize blockchain technology to manage the data of the battery 140 mounted on the electric vehicle 10 so that it is not tampered with.

[0091] Since the authentication servers 30a, 30b, and 30c have the same configuration, the authentication server 30a will be described as an example below.

[0092] FIG. 6 is a block diagram showing an example of the configuration of the authentication server 30a according to the present embodiment. As shown in FIG. 6, the authentication server 30a includes a transaction data verification unit 301, a block generation unit 302, a synchronization unit 303, a recording unit 304, and a communication unit 305. The authentication server 30a can be realized by a processor executing a predetermined program using a memory. Each component will be described below.

[0093] <Transaction data verification unit 301> The transaction data verification unit 301 verifies the acquired transaction data. For example, when the authentication server 30a acquires transaction data from the electric vehicle 10 or the charging station 20, etc., the transaction data verification unit 301 verifies whether the address and signature attached to the transaction data are valid.

[0094] If the transaction data verification unit 301 confirms the validity of the transaction data as a result of the verification, it records the transaction data in the recording unit 304. Here, when the transaction data verification unit 301 confirms the validity of the transaction data, it notifies the synchronization unit 303 to that effect.

[0095] <Block generation unit 302> When the verification of the transaction data by the transaction data verification unit 301 is successful, the block generation unit 302 executes a consensus algorithm for the transaction data among the authentication servers 30. Here, as the consensus algorithm, a consensus algorithm called PBFT (Practical Byzantine Fault Tolerance) may be used, or other known consensus algorithms such as PoW (Proof of Work) may be used.

[0096] In this embodiment, the block generation unit 302 executes a consensus algorithm between the authentication server 30b and the authentication server 30c. That is, the block generation unit 302 first generates a block of the blockchain including one or more pieces of transaction data. Next, the block generation unit 302 executes a consensus algorithm. Then, when consensus is reached by executing the consensus algorithm, the block generation unit 302 records the generated block in the recording unit 304. The block generated by the block generation unit 302 is connected to and recorded in the blockchain by the recording unit 304.

[0097] Here, the data structure of the blockchain will be described.

[0098] FIG. 7 is an explanatory diagram showing the data structure of the blockchain.

[0099] The blockchain is a chain of blocks that are connected in a chain (linked) form as its recording unit. Each block has a plurality of pieces of transaction data and the hash value of the previous block. Specifically, the block B2 contains the hash value of the previous block B1. Then, the hash value calculated from the plurality of pieces of transaction data included in the block B2 and the hash value of the block B1 is included in the block B3 as the hash value of the block B2. In this way, by connecting the blocks in a chain while including the content of the previous block as a hash value, it is possible to effectively prevent the alteration of the connected transaction data.

[0100] If the past transaction data is changed, the hash value of the block will become a different value from before the change. In order to make the altered block appear to be correct, all the subsequent blocks must be recreated, and this operation is very difficult in reality.

[0101] <Synchronization unit 303> In the synchronization unit 303 of the plurality of authentication servers 30, peer-to-peer synchronization of blockchain transaction data is performed. Then, the synchronization unit 303 records the synchronized blockchain transaction data in the recording unit 304. For example, when the validity of the transaction data is verified in the transaction data verification unit 301, the synchronization unit 303 transfers the verified transaction data to the authentication servers 30b and 30c, which are other authentication servers 30. Also, when the synchronization unit 303 receives verified transaction data from another authentication server 30, it records the received verified transaction data in the recording unit 304.

[0102] <recording unit 304> The recording unit 304 may be, for example, a rewritable non-volatile memory such as a hard disk drive or a solid state drive. The recording unit 304 includes the transaction data in a block and records it in the distributed ledger of the authentication server 30a. The distributed ledger may be configured inside the recording unit 304 or inside an external storage device of the authentication server 30a.

[0103] Note that the transaction data includes transaction data acquired from the electric vehicle 10 or the charging station 20, etc.

[0104] In the present embodiment, when the validity of the transaction data received from the electric vehicle 10 or the charging station 20, etc. is confirmed, the recording unit 304 records the block including the transaction data in the distributed ledger of the authentication server 30a. Also, when the validity of the transaction data received from the battery manufacturer server 40 or the battery reuse business operator server 50 is confirmed, the recording unit 304 also records the block including the transaction data in the distributed ledger of the authentication server 30a.

[0105] Note that the blockchain blocks recorded in the distributed ledger may be disclosed to the battery manufacturer server 40 or the battery reuse business operator server 50.

[0106] <Communication unit 305> The communication unit 305 communicates with the electric vehicle 10, the charging station 20, the battery manufacturer server 40, and the battery reuse business operator server 50. The communication unit 305 also communicates with another authentication server 30. These communications may be performed by TLS. In this case, the encryption key for TLS communication may be held by the communication unit 305.

[0107] [1.5 Configuration of the battery manufacturer server 40] The battery manufacturer server 40 is an example of a battery evaluation server managed by a service provider. The service provider of the battery manufacturer server 40 is a manufacturer that manufactures the battery 140. The battery manufacturer server 40 acquires battery data from the distributed ledger of the authentication server 30 and provides a service that utilizes the acquired battery data.

[0108] Hereinafter, an example of the configuration of the battery manufacturer server 40 will be described.

[0109] FIG. 8 is a block diagram showing an example of the configuration of the battery manufacturer server 40 according to the present embodiment.

[0110] As shown in FIG. 8, the battery manufacturer server 40 includes a battery management unit 401, a battery evaluation unit 402, a transaction data generation unit 403, a recording unit 404, and a communication unit 405. The battery manufacturer server 40 can be realized by a processor executing a predetermined program using a memory. Hereinafter, each component will be described.

[0111] <Battery management unit 401> The battery management unit 401 manages the battery 140 used in the electric vehicle 10. For example, the battery management unit 401 manages the battery ID of the battery 140, or manages the residual value of the battery 140 evaluated by the battery evaluation unit 402 based on the battery data recorded in the distributed ledger of the authentication server 30. Also, for example, the battery management unit 401 manages the battery ID of the manufactured and shipped battery 140.

[0112] In addition, when the battery management unit 401 detects an illegal battery 140, it may perform management to invalidate the battery ID. For example, when the battery management unit 401 detects a plurality of the same battery IDs for the battery 140 connected to the charging station 20 acquired by the communication unit 405, for example, it can detect the battery ID of the battery 140 as an illegal battery ID. In this case, the battery management unit 401 stores the detected illegal battery ID in the recording unit 404 as an illegal battery ID. In this way, the battery management unit 401 can perform management to invalidate the battery ID of the illegal battery.

[0113] <Battery evaluation unit 402> The battery evaluation unit 402 evaluates the state of the battery 140 based on the battery data. The battery evaluation unit 402 acquires the transaction data regarding the shipped battery 140 from the distributed ledger of the authentication server 30, and uses the battery data included in the acquired transaction data to evaluate, for example, the residual value of the battery 140.

[0114] Here, the battery data includes data such as sensor information of the battery 140, such as first sensor information and second sensor information, battery ID, and the situation during battery use such as driving data of the electric vehicle 10. Further, the residual value of the battery 140 may be an estimated value of the state of the battery, such as SOC (State Of Charge) or SOH (State Of Health). SOH is an index indicating the degree of deterioration, that is, the residual value of the battery, and can be calculated, for example, by (remaining capacity (Ah) at the time of deterioration / initial full charge capacity (Ah)) × 100. SOC is an index indicating the state of charge, that is, the remaining amount of the battery, and can be calculated, for example, by (remaining capacity (Ah) / full charge capacity (Ah)) × 100.

[0115] Note that the evaluation of the state of the battery 140 may be not limited to the residual value, but also the driving distance of the electric vehicle 10 in which the battery 140 is mounted. Further, the evaluation of the state of these batteries 140 may be automatically performed using AI or the like.

[0116] <Transaction data generation unit 403> The transaction data generation unit 403 generates transaction data in the blockchain.

[0117] In the present embodiment, the transaction data generation unit 403 acquires, for example, the evaluation result of the state of the battery 140 by the battery evaluation unit 402, such as the residual value. The transaction data generation unit 403 generates transaction data including the acquired evaluation result and the battery ID of the battery 140. The transaction data generation unit 403 transmits the generated transaction data to the authentication server 30.

[0118] Note that the transaction data generation unit 403 may further generate transaction data including the ID of the battery manufacturer that evaluated the battery 140.

[0119] <Recording unit 404> The recording unit 404 may be a storage medium composed of a rewritable non-volatile memory such as a hard disk drive or a solid state drive. The recording unit 404 records the battery ID managed by the battery management unit 401. The recording unit 404 may record, for example, the evaluation result of the state of the battery 140 by the battery evaluation unit 402 such as the residual value. Further, the recording unit 404 records the transaction data generated by the transaction data generation unit 403.

[0120] <Communication unit 405> The communication unit 405 communicates with the electric vehicle 10, the charging station 20, and the battery reuse business operator server 50. Further, the communication unit 405 communicates with the authentication server 30. These communications may be performed by TLS. In this case, the encryption key for TLS communication may be held by the communication unit 405.

[0121] [1.6 Configuration of the battery reuse business operator server 50] The battery reuse business operator server 50 is an example of a battery evaluation server managed by a service provider. The service provider of the battery reuse business operator server 50 is a provider that provides a service for reusing the battery 140. The battery reuse business operator server 50 acquires battery data from the distributed ledger of the authentication server 30 and uses the acquired battery data to provide a service for reusing, for example, the battery 140.

[0122] Hereinafter, an example of the configuration of the battery reuse business operator server 50 will be described.

[0123] FIG. 9 is a block diagram showing an example of the configuration of the battery reuse business operator server 50 according to the present embodiment.

[0124] As shown in FIG. 9, the battery reuse business operator server 50 includes a battery evaluation unit 501, a battery reuse management unit 502, a transaction data generation unit 503, a recording unit 504, and a communication unit 505. The battery reuse business operator server 50 can be realized by a processor executing a predetermined program using a memory. Hereinafter, each component will be described.

[0125] <Battery evaluation unit 501> The battery evaluation unit 501 evaluates the battery 140. In the present embodiment, the battery evaluation unit 501 acquires, as battery data, the evaluation result of the state of the battery 140 by the battery manufacturer server 40 from the distributed ledger of the authentication server 30, and evaluates the reuse method of the battery 140 from the acquired evaluation result. Examples of the evaluation of the reuse method include that a plurality of cells configured inside the battery 140 are reusable, a part of the plurality of cells is deteriorated and only some cells are reusable, the cells cannot be used but only the materials constituting the cells are reusable, and the like. Also, examples of the evaluation of the reuse method may include that it cannot be used for large or medium-sized electric vehicles 10 that require high output, but it can be reused for electric vehicles with low output such as motorized bicycles or for battery applications for houses.

[0126] Note that the battery evaluation unit 501 is not limited to acquiring the evaluation result of the state of the battery 140 such as the residual value from the distributed ledger of the authentication server 30, and may also evaluate the state of the battery 140 by itself. That is, the battery evaluation unit 501 acquires the transaction data related to the battery 140 from the distributed ledger of the authentication server 30, and uses the battery data included in the acquired transaction data to evaluate, for example, the residual value of the battery 140.

[0127] <Battery reuse management unit 502> Based on the evaluation result of the battery 140 performed by the battery evaluation unit 501, the battery reuse management unit 502 determines whether to reuse the battery 140. When the battery reuse management unit 502 determines to reuse the battery 140, it determines the reuse method of the battery 140 based on the reuse method evaluated by the battery evaluation unit 501. For example, the battery reuse management unit 502 determines the reuse method of the battery 140, such as directly reusing the cells that make up the battery 140, or disassembling the battery 140 to extract only the materials for reuse.

[0128] The battery reuse management unit 502 records the judgment result for the battery 140 and the battery ID or cell ID in the recording unit 504 to manage the reuse method of the battery 140.

[0129] <Transaction data generation unit 503> The transaction data generation unit 503 generates transaction data in the blockchain.

[0130] In this embodiment, the transaction data generation unit 503 obtains the judgment result for the battery 140 performed by the battery reuse management unit 502. Based on the obtained judgment result, the transaction data generation unit 503 generates transaction data. For example, when it is shown in the obtained judgment result that the cells of the battery 140 are to be reused, the transaction data generation unit 503 may generate transaction data including the ID of the battery to be reused and the IDs of each cell.

[0131] The transaction data generation unit 503 sends the generated transaction data to the authentication server 30.

[0132] Note that the transaction data generation unit 503 may further generate transaction data including the ID of the battery reuse operator who evaluated the battery 140. Further, the transaction data generation unit 503 may further generate transaction data including at least one of the evaluation result of the battery evaluation unit 501, the reuse method, the sensor information of the battery ID used by the battery evaluation unit 501 for evaluation, and the like.

[0133] <Recording unit 504> The recording unit 504 may be a storage medium composed of a rewritable non-volatile memory such as a hard disk drive or a solid state drive, for example. The recording unit 504 records the battery ID of the battery 140 determined to be reused and / or the ID of the cell. Further, the recording unit 504 may record the residual value of the battery 140 used to determine whether to reuse the battery 140.

[0134] Further, the recording unit 504 records the transaction data generated by the transaction data generation unit 503.

[0135] <Communication unit 505> The communication unit 505 communicates with the electric vehicle 10, the charging station 20, and the battery manufacturer server 40. Further, the communication unit 405 communicates with the authentication server 30. These communications may be performed by TLS. In this case, the encryption key for TLS communication may be held by the communication unit 505.

[0136] [1.7 Configuration of Charging Facility 60] The charging facility 60 charges the battery 140 removed from the electric vehicle 10 or charges the battery 140 mounted on the electric vehicle 10 via the charging equipment attached to the electric vehicle 10. In this case, the battery 140 may record the number of charging times and the charging amount, the information of the charging facility 60 that charged the battery 140, etc. in the recording unit 1105 of the vehicle management unit 110 as battery data.

[0137] Here, the information of the charging facility 60 may include the location where the charging facility 60 is installed, the charging time taken for charging the battery 140, the date and time when the charging was performed, information indicating whether the charging of the battery 140 is rapid charging or slow charging, and the like. When the electric vehicle 10 or the battery 140 can acquire position information indicating its own position such as GPS information, the battery 140 may store the position information of the electric vehicle 10 or the battery 140 at the time of charging as information of the charging facility 60.

[0138] In addition, when the charging facility 60 determines that abnormal charging has been performed on the battery 140, the charging facility 60 may stop charging the battery 140. The abnormal charging may be, for example, charging at a voltage higher than a predetermined voltage, charging at a current higher than a predetermined current, or charging at a temperature lower than a predetermined temperature (ambient temperature).

[0139] [1.8 Processing during Charging] Subsequently, the authentication process between the battery 140 and the charging station 20 and the processing during charging among the battery 140, the charging station 20, and the authentication servers 30a to 30c will be described.

[0140] FIG. 10 is a sequence diagram showing the authentication process between the battery 140 and the charging station 20 according to the present embodiment and the processing during charging between the charging station 20 and the authentication servers 30a to 30c.

[0141] First, the charging station 20 authenticates the user who has come to replace the battery 140 (S101). When the charging station 20 determines that the user is a legitimate user, the charging station 20 unlocks the door of the charging space on which the battery 140 that has already been charged at the charging station 20 is placed, and permits the door to be opened. As a result, the user can replace the battery 140 placed in the charging space with the door unlocked and the battery 140 that has already been charged with the battery 140 used in the electric vehicle 10.

[0142] Next, when the user stores the battery 140 that was being used in the electric vehicle 10 at the charging station 20, the charging station 20 and the battery 140 perform mutual authentication processing between the newly placed battery 140 and the charging station 20 in the charging space (S102).

[0143] Next, the battery 140 determines whether the authentication with the charging station 20 was successful (S103). In step S103, if the authentication between the battery 140 and the charging station 20 fails (N in S103), the ID of the charging station 20 is recorded (S104), and the process ends without charging.

[0144] On the other hand, the charging station 20 determines whether the authentication with the battery 140 was successful (S105). In step S105, if the authentication between the charging station 20 and the battery 140 fails (N in S105), the battery ID of the battery 140 is recorded (S106), and the charging of the battery 140 ends without charging.

[0145] In steps S103 and S105, if the authentication between the battery 140 and the charging station 20 is successful (Y in S103 and Y in S105), a charging process for charging the battery 140 is performed.

[0146] Next, the battery 140 acquires (S108) and records the second sensor information from the charging station 20. The second sensor information includes the amount of charge charged at the charging station 20, the temperature, current, voltage, and impedance during charging, and may further include the number of charging times.

[0147] Next, the charging station 20 acquires (S109) and records the second sensor information from the battery 140. This second sensor information also includes the amount of charge charged at the charging station 20, the temperature, current, voltage, and impedance during charging, and may further include the number of charging times.

[0148] Next, the charging station 20 generates transaction data (hereinafter referred to as second transaction data) including the second sensor information acquired in step S109 and the battery ID of the battery 140 (S110). Note that the second transaction data may include the ID of the charging station 20 in addition to the second sensor information and the battery ID as described above.

[0149] Next, the charging station 20 transmits the second transaction data generated in step S110 to the authentication server 30a (S111). In the example shown in FIG. 10, the charging station 20 transmits the generated second transaction data to the authentication server 30a, but it may also be transmitted to the authentication server 30b or the authentication server 30c. The same applies when it is transmitted to the authentication server 30b or the authentication server 30c.

[0150] Next, when the authentication server 30a acquires the second transaction data from the charging station 20 (S112), it verifies the acquired second transaction data (S113).

[0151] In step S113, if the verification of the second transaction data fails (N in S113), the authentication server 30a transmits a notification to that effect to the charging station 20 (S114).

[0152] On the other hand, in step S113, if the verification of the second transaction data is successful (Y in S113), the authentication server 30a transfers the second transaction data to the other authentication servers 30 (authentication servers 30b, 30c) (S115). Note that the other authentication servers 30 also verify the transferred second transaction data.

[0153] Next, the authentication servers 30a, 30b, and 30c execute a consensus algorithm (S116). When the authentication servers 30a, 30b, and 30c verify that the second transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block containing the second transaction data. Then, the authentication servers 30a, 30b, and 30c record the block containing the second transaction data in the distributed ledger.

[0154] In this way, the second sensor information and battery ID of the charged battery 140 are irreversibly recorded as battery data in the distributed ledger. Note that in order for the second sensor information and battery ID of the charged battery 140 to be recorded in the distributed ledger, the charging process is essential, but the authentication process shown in steps S101 to S106 is not essential.

[0155] [1.9 Authentication Process of Battery 140 and Electric Vehicle 10 and Running Process] Subsequently, the authentication process of the battery 140 and the electric vehicle 10 and the running process among the battery 140, the electric vehicle 10, and the authentication servers 30a to 30c will be described.

[0156] FIG. 11 is a sequence diagram showing the authentication process of the battery 140 and the electric vehicle 10 according to the present embodiment and the running process between the electric vehicle 10 and the authentication servers 30a to 30c.

[0157] First, the user mounts the battery 140 on the electric vehicle 10 (S201). Then, the battery 140 and the electric vehicle 10 detect that the battery 140 is mounted on the battery connection portion 120 of the electric vehicle 10. Note that the battery 140 may detect that it is connected to the battery connection portion 120 of the electric vehicle 10 by detecting that it has supplied power to the electric vehicle 10. Similarly, the electric vehicle 10 may detect that it is connected to the battery connection portion 120 of the electric vehicle 10 by detecting that power has been supplied from the battery 140.

[0158] Next, the battery 140 and the electric vehicle 10 perform mutual authentication (S202).

[0159] Next, the battery 140 determines whether the authentication with the electric vehicle 10 has been successful (S203). In step S203, if the authentication between the battery 140 and the electric vehicle 10 fails (N in S203), the battery 140 determines that the electric vehicle 10 is an unauthorized electric vehicle, records the vehicle ID of the electric vehicle 10 (S204), and ends without permitting discharge to the electric vehicle 10 side.

[0160] On the other hand, the electric vehicle 10 determines whether the authentication with the battery 140 has been successful (S205). In step S205, if the authentication between the electric vehicle 10 and the battery 140 fails (N in S205), the electric vehicle 10 determines that the battery 140 is an unauthorized battery, records the battery ID of the battery 140 (S206), and ends the process without permitting the start of the electric vehicle 10.

[0161] In step S203, if the authentication between the battery 140 and the electric vehicle 10 is successful (Y in S203), the battery 140 permits discharge to the electric vehicle 10 side. Similarly, in step S205, if the authentication between the battery 140 and the electric vehicle 10 is successful (Y in S205), the electric vehicle 10 permits starting of the electric vehicle 10. Thereafter, when the electric vehicle 10 is running, the battery 140 and the electric vehicle 10 acquire first sensor information about the battery 140 during running (S207). Here, the first sensor information includes, but is not limited to, the discharge amount, voltage, current, temperature, etc. during running. The first sensor information may include the impedance of the battery 140 during running, or may include the acceleration information of the electric vehicle 10.

[0162] Next, the electric vehicle 10 generates transaction data (hereinafter referred to as first transaction data) including the first sensor information acquired in step S207 and the battery ID of the battery 140 (S208). Note that the first transaction data may include, in addition to the first sensor information and the battery ID as described above, the vehicle ID of the electric vehicle 10 and the driving data of the electric vehicle 10.

[0163] Next, the electric vehicle 10 transmits the first transaction data generated in step S208 to the authentication server 30a (S209). Note that in the example shown in FIG. 11, the electric vehicle 10 transmits the generated first transaction data to the authentication server 30a, but it may also be transmitted to the authentication server 30b or the authentication server 30c. The same applies when it is transmitted to the authentication server 30b or the authentication server 30c.

[0164] Next, when the authentication server 30a acquires the first transaction data from the electric vehicle 10 (S210), it verifies the acquired first transaction data (S211).

[0165] In step S211, if the verification of the first transaction data fails (N in S211), the authentication server 30a transmits a notification to that effect to the electric vehicle 10 (S212).

[0166] On the other hand, in step S211, if the verification of the first transaction data is successful (Y in S211), the authentication server 30a transfers the first transaction data to the other authentication servers 30 (authentication servers 30b, 30c) (S213). Note that the other authentication servers 30 also verify the transferred first transaction data.

[0167] Next, the authentication server 30a, the authentication server 30b, and the authentication server 30c execute a consensus algorithm (S214). When the authentication server 30a, the authentication server 30b, and the authentication server 30c verify that the first transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block including the first transaction data. Then, the authentication servers 30a, 30b, and 30c record the block including the first transaction data in the distributed ledger.

[0168] In this way, the first sensor information and the battery ID regarding the battery 140 during running are irreversibly recorded in the distributed ledger as battery data.

[0169] Note that in order for the first sensor information regarding the battery 140 during running to be recorded in the distributed ledger, the running process is essential, but the authentication process shown in steps S201 to S206 is not essential.

[0170] Also, the processes of steps S207 and S208 may be repeated periodically or aperiodically. Furthermore, the process of step S207 may be repeated periodically or aperiodically, but the process of S208 may be performed even once. In this case, the electric vehicle 10 may send the first sensor information during running acquired from the start to the end of the electric vehicle 10 equipped with the battery 140 to the authentication server 30 included in one piece of first transaction data. In this way, the first sensor information regarding the battery 140 during running may include a plurality of discharge amounts, voltages, currents, temperatures, etc. acquired during the running period of the electric vehicle 10, or may mean a plurality of pieces of first sensor information acquired during the period when the electric vehicle 10 is running.

[0171] Also, although the mutual authentication process in step S202 has been described for the case where it is performed when the battery 140 is mounted on the electric vehicle 10, it is not limited to this. It may be performed when the electric vehicle 10 is started.

[0172] [1.10 Battery Evaluation Time Processing] Next, the battery evaluation time processing between the battery manufacturer server 40 and the authentication servers 30a to 30c will be described.

[0173] FIG. 12 is a sequence diagram of the battery evaluation time processing between the battery manufacturer server 40 and the authentication servers 30a to 30c according to the present embodiment.

[0174] First, the battery manufacturer server 40 acquires battery data for the target battery 140 from the distributed ledger of the authentication server 30a (S301). Specifically, first, the battery manufacturer server 40 generates a request for acquiring battery data for the target battery 140 to the authentication server 30a. The battery data here includes, for example, sensor information of the battery 140 such as first sensor information and second sensor information, and a battery ID, but may further include a charge amount, a number of charge times, and the like. In the acquisition request, the battery ID of the target battery 140 may be specified, or transaction data including the battery data of the target battery 140 may be specified. In the acquisition request, all data for the target battery 140 recorded in the distributed ledger of the authentication server 30a may be specified. Then, the battery manufacturer server 40 transmits the generated acquisition request to the authentication server 30a, thereby acquiring battery data for the target battery 140 from the distributed ledger of the authentication server 30a. In the example shown in FIG. 12, the battery manufacturer server 40 acquires battery data for the target battery 140 from the authentication server 30a, but may also acquire it from the authentication server 30b or the authentication server 30c. The same applies when acquired from the authentication server 30b or the authentication server 30c. Also, the battery manufacturer server 40 may generate transaction data indicating that it has acquired battery data for the target battery 140 from the distributed ledger of the authentication server 30a and record it in the distributed ledgers of the authentication servers 30a to 30c.

[0175] Next, the battery manufacturer server 40 performs battery evaluation processing on the battery based on the battery data acquired from the authentication server 30a (S302), and obtains an evaluation of the battery 140. In the present embodiment, the battery manufacturer server 40 performs battery evaluation processing for evaluating the state of the battery 140, such as the residual value of the battery 140, using the battery data, thereby obtaining a battery evaluation of the battery 140. Since the details have been described above, the description thereof is omitted.

[0176] Next, the battery manufacturer server 40 generates transaction data (hereinafter referred to as third transaction data) including the battery evaluation of the battery 140 obtained in step S302 and the battery ID of the battery 140 (S303).

[0177] Next, the battery manufacturer server 40 transmits the third transaction data generated in step S303 to the authentication server 30a (S304). In the example shown in FIG. 12, the battery manufacturer server 40 transmits the generated third transaction data to the authentication server 30a, but it may also be transmitted to the authentication server 30b or the authentication server 30c. The same applies when it is transmitted to the authentication server 30b or the authentication server 30c.

[0178] Next, when the authentication server 30a acquires the third transaction data from the battery manufacturer server 40 (S305), it verifies the acquired third transaction data (S306).

[0179] In step S306, if the verification of the third transaction data fails (N in S306), the authentication server 30a transmits a notification to that effect to the battery manufacturer server 40 (S307).

[0180] On the other hand, in step S306, when the verification of the third transaction data is successful (Y in S306), the authentication server 30a transfers the third transaction data to other authentication servers 30 (authentication servers 30b and 30c) (S308). Note that the other authentication servers 30 also verify the transferred third transaction data.

[0181] Next, the authentication servers 30a, 30b, and 30c execute a consensus algorithm (S309). When the authentication servers 30a, 30b, and 30c verify that the third transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block including the third transaction data. Then, the authentication servers 30a, 30b, and 30c record the block including the third transaction data in the distributed ledger.

[0182] In this way, the evaluation result of the battery 140 by the battery manufacturer server 40 is irreversibly recorded in the distributed ledger as the battery data of the battery 140.

[0183] [1.11 Battery reuse processing] Subsequently, the battery reuse processing between the battery reuse business operator server 50 and the authentication servers 30a to 30c will be described.

[0184] FIG. 13 is a sequence diagram of the battery reuse processing between the battery reuse business operator server 50 and the authentication servers 30a to 30c according to the present embodiment.

[0185] First, the battery reuse operator server 50 acquires battery data for the target battery 140 from the distributed ledger of the authentication server 30a (S401). Specifically, first, the battery reuse operator server 50 generates a request to acquire battery data for the target battery 140 to the authentication server 30a. The battery data here includes evaluation information about the battery 140, sensor information of the battery 140 such as first sensor information and second sensor information including the charge amount, and the battery ID. Also, in the acquisition request, the battery ID of the target battery 140 may be specified, or transaction data including the battery data of the target battery 140 may be specified. Further, in the acquisition request, all data about the target battery 140 recorded in the distributed ledger of the authentication server 30a may be specified. Then, the battery reuse operator server 50 transmits the generated acquisition request to the authentication server 30a, thereby acquiring battery data for the target battery 140 from the distributed ledger of the authentication server 30a. Note that in the example shown in FIG. 13, the battery reuse operator server 50 acquires battery data for the target battery 140 from the authentication server 30a, but it may also be acquired from the authentication server 30b or the authentication server 30c. The same applies when acquired from the authentication server 30b or the authentication server 30c. Also, the battery reuse operator server 50 may generate transaction data indicating that it has acquired battery data for the target battery 140 from the distributed ledger of the authentication server 30a and record it in the distributed ledgers of the authentication servers 30a to 30c.

[0186] Next, the battery reuse operator server 50 performs battery evaluation processing on the battery based on the battery data acquired from the authentication server 30a (S402), and obtains a battery evaluation of the battery 140. In the present embodiment, the battery reuse operator server 50 performs an evaluation process of evaluating whether the battery 140 should be reused and the reuse method in the case where it should be reused, using the battery data, thereby obtaining a battery evaluation of the battery 140. Details have been described above, so the description is omitted. Note that the evaluation of whether to reuse includes an evaluation of whether there is a battery 140 to be reused.

[0187] Next, the battery reuse operator server 50 determines whether the battery 140 should be reused based on the battery evaluation of the battery 140 obtained in step S402 (S403).

[0188] In step S403, if it is determined that the battery 140 should not be reused (N in S403), the process ends.

[0189] On the other hand, in step S403, if it is determined that the battery 140 should be reused (Y in S403), the battery reuse operator server 50 generates third transaction data including the battery evaluation of the battery 140 obtained in step S402 (S404). Note that this battery evaluation may include that the battery 140 should be reused, the reuse method, the battery ID of the battery 140, the ID of the cell, etc., or may include only the battery ID of the battery 140 to be reused and the ID of the cell.

[0190] Next, the battery reuse business operator server 50 transmits the third transaction data generated in step S404 to the authentication server 30a (S405). In the example shown in FIG. 13, the battery reuse business operator server 50 transmits the generated third transaction data to the authentication server 30a, but it may also be transmitted to the authentication server 30b or the authentication server 30c. The same applies when transmitted to the authentication server 30b or the authentication server 30c.

[0191] Next, when the authentication server 30a acquires the third transaction data from the battery reuse business operator server 50 (S406), it verifies the acquired third transaction data (S407).

[0192] In step S407, if the verification of the third transaction data fails (N in S407), the authentication server 30a transmits a notification to that effect to the battery reuse business operator server 50 (S408).

[0193] On the other hand, in step S407, if the verification of the third transaction data is successful (Y in S407), the authentication server 30a transfers the third transaction data to the other authentication servers 30 (authentication servers 30b, 30c) (S409). Note that the other authentication servers 30 also verify the transferred third transaction data.

[0194] Next, the authentication server 30a, the authentication server 30b, and the authentication server 30c execute a consensus algorithm (S410). When the authentication server 30a, the authentication server 30b, and the authentication server 30c verify that the third transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block containing the third transaction data. Then, the authentication servers 30a, 30b, and 30c record the block containing the third transaction data in the distributed ledger.

[0195] In this way, the evaluation result of the battery 140 by the battery reuse business operator server 50 is irreversibly recorded in the distributed ledger as the battery data of the battery 140.

[0196] [1.12 Effects of the Embodiment, etc.] As described above, according to the battery data management method and the like according to the present embodiment, by recording battery data from the regular battery 140, the electric vehicle 10, or the charging station 20 in the distributed ledger via the authentication server 30, it is possible to prevent falsification of the battery data. That is, according to the battery data management method and the like according to the present embodiment, by utilizing blockchain technology, it is possible to manage the battery data mounted on the electric vehicle 10 so as not to be falsified.

[0197] Furthermore, by recording the battery data in the distributed ledger, the reliability of the data is guaranteed. As a result, service providers such as battery manufacturers or reuse operators can use the battery data with confidence, and thus can provide services such as battery evaluation of, for example, the battery state, residual value, and reuse method.

[0198] Also, by recording battery evaluation as battery data in the distributed ledger from the server used by service providers such as battery manufacturers or reuse operators, it is possible to prevent falsification of the battery evaluation. As a result, battery data can be safely shared among enterprises that want to utilize the battery data via the authentication server 30. As a result, not only can battery data be used for the used evaluation of the electric vehicle 10, but also battery data can be used when the battery 140 is reused. In addition, by using battery data including battery evaluation, it is possible to effectively utilize each battery 140, such as using a battery 140 with early deterioration for other uses than being used in the electric vehicle 10 at an appropriate timing.

[0199] In addition, according to the present embodiment, by performing mutual authentication between the battery and the charging station or between the battery and the electric vehicle, unauthorized batteries can be excluded.

[0200] [2. Other Modification Examples] Although the present disclosure has been described based on the above-described embodiments, it goes without saying that the present disclosure is not limited to the above-described embodiments. The following cases are also included in the present disclosure.

[0201] (1) In the above-described embodiment, for example, as described in step S107 of FIG. 10, the charging of the battery 140 has been described as being performed by the charging station 20, but it is not limited thereto. The charging facility 60 may charge the battery 140. Hereinafter, the case where the battery 140 is charged by connecting the electric vehicle 10 to the charging facility 60 will be described with reference to FIG. 14.

[0202] FIG. 14 is a sequence diagram showing the authentication process between the battery 140 and the electric vehicle 10 according to the modification example and the charging process between the electric vehicle 10 and the authentication servers 30a to 30c.

[0203] First, the user connects the electric vehicle 10 to the charging facility 60 (S501). Then, the electric vehicle 10 detects that it (the electric vehicle 10) has been connected to the charging facility 60.

[0204] Next, the battery 140 and the electric vehicle 10 perform mutual authentication (S502).

[0205] Next, the battery 140 determines whether the authentication with the electric vehicle 10 has been successful (S503). In step S503, if the authentication between the battery 140 and the electric vehicle 10 is not successful (N in S503), the battery 140 determines that the electric vehicle 10 is an unauthorized electric vehicle, records the vehicle ID of the electric vehicle 10 (S504), and ends without being charged.

[0206] Note that the subsequent processing, i.e., the processing from step S505 to step S516, is the same as the processing from step S105 to step S116 in FIG. 10, so the description thereof is omitted.

[0207] As a result, the second sensor information of the battery 140 charged by the charging facility 60 is irreversibly recorded in the distributed ledger, so the battery data including the second sensor is guaranteed. Therefore, the battery data including the second sensor can be used with confidence.

[0208] (2) In the above embodiment, the authentication server 30, the battery manufacturer server 40, and the battery reuse business server 50 are described as separate servers, but this is not limiting. The battery manufacturer server 40 and / or the battery reuse business server 50 may have the functions of the authentication server 30.

[0209] (3) In the above embodiment, the battery ID, the ID of the charging station 20, and the vehicle ID are used, but this is not limiting. As the battery ID, the ID of the charging station 20, and the vehicle ID, the ID described in the certificate of the encryption key may be used.

[0210] (4) In the above embodiment, for example, as shown in FIGS. 11 and 14, the electric vehicle 10 transmits transaction data to the authentication server 30, but this is not limiting. When the electric vehicle 10 is not connected to the communication network 70, the generated transaction data may be recorded in the battery 140 mounted on the electric vehicle 10. In this case, when the battery 140 is charged at the charging station 20, the recorded transaction data may be transmitted to the authentication server 30 via the charging station 20. Thereby, the first sensor information and / or the battery data including the second sensor when the electric vehicle 10 is not connected to the communication network 70 can also be irreversibly recorded in the distributed ledger.

[0211] (5) In the above-described embodiment, for example, as shown in FIGS. 10, 11, and 14, the electric vehicle 10 or the charging station 20 generates transaction data, but it is not limited thereto. When the battery 140 has a transaction data generation unit, the battery 140 may generate transaction data including the first sensor information and / or the second sensor, and transmit it to the authentication server 30 via the electric vehicle 10 or the charging station 20.

[0212] (6) Each device in the above-described embodiment is specifically a computer system composed of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, and the like. A computer program is recorded in the RAM or the hard disk unit. When the microprocessor operates according to the computer program, each device achieves its function. Here, the computer program is composed of a combination of a plurality of instruction codes indicating instructions to the computer in order to achieve a predetermined function.

[0213] (7) Each device in the above-described embodiment may be configured such that some or all of the constituent components are composed of one system LSI (Large Scale Integration). The system LSI is a super multi-functional LSI manufactured by integrating a plurality of components on one chip, and specifically, is a computer system including a microprocessor, ROM, RAM, and the like. A computer program is recorded in the RAM. When the microprocessor operates according to the computer program, the system LSI achieves its function.

[0214] Also, each part of the constituent components constituting each of the above devices may be individually formed into one chip, or may be formed into one chip so as to include some or all of them.

[0215] Also, here, it is assumed to be a system LSI, but depending on the degree of integration, it may also be referred to as an IC, LSI, super LSI, or ultra LSI. Further, the method of integrating circuits is not limited to LSI, and it may be realized by a dedicated circuit or a general-purpose processor. After manufacturing the LSI, an FPGA (Field Programmable Gate Array) that can be programmed, or a reconfigurable processor that can reconfigure the connections and settings of circuit cells inside the LSI may be used.

[0216] Furthermore, if a technology for integrating circuits that replaces LSI appears due to the progress of semiconductor technology or another derived technology, naturally, the integration of functional blocks may be performed using that technology. The application of biotechnology, etc. is a possible example.

[0217] (8) Some or all of the components constituting each of the above devices may be configured from an IC card or a single module that can be detached from each device. The IC card or the module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or the module may include the above-mentioned super multifunctional LSI. By operating according to a computer program, the microprocessor enables the IC card or the module to achieve its function. This IC card or this module may have tamper resistance.

[0218] (9) The present disclosure may be the method shown above. It may also be a computer program that realizes these methods by a computer, or a digital signal composed of the computer program.

[0219] Further, the present disclosure may be recorded on a computer-readable recording medium, such as a flexible disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray (registered trademark) Disc), semiconductor memory, etc., for the computer program or the digital signal. Further, it may be the digital signal recorded on these recording media.

[0220] Further, the present disclosure may transmit the computer program or the digital signal via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, etc.

[0221] Further, the present disclosure may be a computer system including a microprocessor and a memory, where the memory stores the computer program, and the microprocessor operates according to the computer program.

[0222] Further, it may be implemented by another independent computer system by recording and transferring the program or the digital signal to the recording medium, or by transferring the program or the digital signal via the network or the like.

[0223] (10) It may be possible to combine the above embodiments and the above modifications respectively.

Industrial Applicability

[0224] The present disclosure can be used for a battery data management method, a battery data management system, and a program that can safely manage battery data by utilizing blockchain technology.

Explanation of Signs

[0225] 1 Battery data management system 10 Electric vehicle 20 Charging station 30a, 30b, 30c Authentication Servers 40 Battery Manufacturer Server 50 Battery Reuse Business Operator Server 60 Charging Equipment 70 Communication Network 110 Vehicle Management Department 120 Battery Connection Section 130, 206, 305, 405, 505, 1405 Communication Sections 140 Battery 201 User Authentication Section 202 Battery Authentication Section 203 Charging Control Section 204, 403, 503, 1104 Transaction Data Generation Sections 205, 304, 404, 504, 1105, 1404 Recording Sections 301 Transaction Data Verification Section 302 Block Generation Section 303 Synchronization Section 401 Battery Management Section 402, 501 Battery Evaluation Sections 502 Battery Reuse Management Section 1101, 1401 Authentication Sections 1102, 1403 Control Sections 1103 Charging Management Section 1402 Measurement Section

Claims

1. A battery data management method in a battery data management system comprising a plurality of authentication servers each having a decentralized ledger, an electric vehicle, and a charging station connectable to a battery removably attached to the electric vehicle to charge the battery, comprising: the electric vehicle determines whether the battery attached to the electric vehicle is an unauthorized battery by authenticating the battery; (i) When it is determined in the electric vehicle that the battery is a legitimate battery, the electric vehicle acquires first sensor information about the battery; the electric vehicle generates first transaction data including the ID of the battery and the first sensor information; one of the plurality of authentication servers acquires the first transaction data; the one authentication server records a block including the first transaction data in the decentralized ledger; (ii) When it is determined in the electric vehicle that the battery is an unauthorized battery, the electric vehicle records the ID of the unauthorized battery in a storage medium provided in the electric vehicle; does not permit the electric vehicle to start; the charging station determines whether the battery connected to the charging station is an unauthorized battery by authenticating the battery; (i) When it is determined in the charging station that the battery is a legitimate battery, the charging station acquires second sensor information about the battery charged by being connected to the charging station; the charging station generates second transaction data including the ID of the battery and the second sensor information; the one authentication server acquires the second transaction data; the one authentication server records a block including the second transaction data in the decentralized ledger; (ii) When it is determined in the charging station that the battery is an unauthorized battery, the charging station records the ID of the unauthorized battery in a storage medium provided in the charging station; does not charge the battery Battery data management method.

2. Furthermore, the electric vehicle notifies the ID of the unauthorized battery The battery data management method according to claim 1.

3. When acquiring the first sensor information, The electric vehicle acquires driving data obtained during driving of the electric vehicle and the first sensor information during the driving, when generating the first transaction data, the electric vehicle generates first transaction data including the ID of the battery, the driving data, and the first sensor information during the driving, The battery data management method according to claim 1.

4. The battery data management method further includes: before acquiring the first sensor information about the battery, performing first mutual authentication between the electric vehicle and the battery, when the first mutual authentication is successful, the electric vehicle acquires the first sensor information about the battery, The battery data management method according to any one of claims 1 to 3.

5. The first sensor information includes the voltage, current, temperature, impedance of the battery, and acceleration information of the electric vehicle on which the battery is mounted, The battery data management method according to any one of claims 1 to 4.

6. The battery data management method further includes: before acquiring the second sensor information of the battery, performing second mutual authentication between the charging station and the battery connected to the charging station for charging, when the second mutual authentication is successful, the charging station acquires the second sensor information, The battery data management method according to any one of claims 1 to 5.

7. The second sensor information includes the voltage, current, temperature, and impedance of the battery, The battery data management method according to any one of claims 1 to 6.

8. The battery data management system further includes a battery evaluation server, The battery data management method further includes: the battery evaluation server acquires transaction data related to the battery recorded in the distributed ledger, the battery evaluation server evaluates the battery from the acquired transaction data related to the battery, the battery evaluation server generates third transaction data including the evaluation result of the battery and the ID of the battery, the one authentication server acquires the third transaction data, the one authentication server records a block including the third transaction data in the distributed ledger, The battery data management method according to any one of claims 1 to 7.

9. The evaluation result of the battery includes the evaluation result of the state of the battery including the residual value of the battery. The battery data management method according to claim 8.

10. The evaluation result of the battery includes the availability of reuse of the battery based on the state of the battery and the battery ID of the battery. The battery data management method according to claim 8.

11. A program for causing a computer to execute a battery data management method in a battery data management system including a plurality of authentication servers each having a distributed ledger, an electric vehicle, and a charging station that can charge the battery by being connected to the battery detachably attached to the electric vehicle, The electric vehicle determines whether the battery mounted on the electric vehicle is an unauthorized battery by authenticating the battery. (i) When it is determined that the battery is a legitimate battery, The electric vehicle acquires first sensor information about the battery. The electric vehicle generates first transaction data including the ID of the battery and the first sensor information. One of the plurality of authentication servers acquires the first transaction data. The one authentication server records a block including the first transaction data in the distributed ledger. (ii) When it is determined that the battery is an unauthorized battery, The electric vehicle records the ID of the unauthorized battery in a storage medium provided in the electric vehicle. The electric vehicle is not permitted to start. The charging station determines whether the battery connected to the charging station is an unauthorized battery by authenticating the battery. (i) When it is determined at the charging station that the battery is a legitimate battery, The charging station acquires second sensor information of the battery charged by being connected to the charging station. The charging station generates second transaction data including the ID of the battery and the second sensor information. The one authentication server acquires the second transaction data. The one authentication server records a block including the second transaction data in the distributed ledger. (ii)When it is determined at the charging station that the battery is an unauthorized battery, the charging station records the ID of the unauthorized battery in a storage medium provided in the charging station, and causes a computer not to charge the battery. A program to be executed by a computer.

12. A battery data management system including a plurality of authentication servers each having a distributed ledger, an electric vehicle, and a charging station connectable to a battery detachably attached to the electric vehicle to charge the battery, wherein the electric vehicle has an authentication unit that determines whether the battery mounted on the electric vehicle is an unauthorized battery by authenticating the battery; a first communication unit that acquires first sensor information about the battery mounted on the electric vehicle when it is determined that the battery is a legitimate battery; a transaction data generation unit that generates first transaction data including the ID of the battery and the first sensor information; a vehicle recording unit that records the ID of the unauthorized battery when it is determined that the battery is an unauthorized battery; and a vehicle management unit that does not permit the electric vehicle to start when it is determined that the battery is an unauthorized battery. The charging station determines whether the battery connected to the charging station is an unauthorized battery by authenticating the battery, and (i) when it is determined at the charging station that the battery is a legitimate battery, acquires second sensor information of the battery charged by being connected to the charging station, generates second transaction data including the ID of the battery and the second sensor information, and (ii) when it is determined at the charging station that the battery is an unauthorized battery, the charging station records the ID of the unauthorized battery in a storage medium provided in the charging station, does not charge the battery, One of the plurality of authentication servers has a second communication unit that acquires the first transaction data and the second transaction data, and a recording unit that records a block including the first transaction data and a block including the second transaction data in the distributed ledger. A battery data management system.

Citation Information

Patent Citations

  • Battery authentication system of vehicle

    JP2012222945A

  • Battery replacement system for electric vehicle and program

    JP2015015827A

  • Power supply controller

    JP2016116310A

  • Management system, vehicle, and information processing method

    JP2019029988A

  • Control method, server, on-vehicle device and program

    JP2019192630A