Control method, power system, and program

The control method uses group signatures to anonymize transaction data in decentralized electricity trading, preventing user identification and maintaining privacy by recording data in a distributed ledger.

JP7773515B2Active Publication Date: 2025-11-19PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023138058
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-01-29
Filing Date
2023-08-28
Publication Date
2025-11-19
Estimated Expiration
2038-10-10

AI Technical Summary

Technical Problem

Existing decentralized electricity trading systems using blockchain technology risk leaking private information about consumer availability by making transaction data public, which can infer whether a consumer is at home or not.

Method used

A control method that acquires and verifies transaction data from power facilities, using group signatures to ensure anonymity and record data in a distributed ledger, preventing identification of users even if transaction data is made public.

Benefits of technology

Prevents leakage of private information by ensuring that user identities cannot be inferred from transaction data, maintaining privacy in decentralized electricity trading.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007773515000001
    Figure 0007773515000001
  • Figure 0007773515000002
    Figure 0007773515000002
  • Figure 0007773515000003
    Figure 0007773515000003
Patent Text Reader

Abstract

To provide a control method and the like capable of suppressing leakage of privacy information.SOLUTION: A control method includes the steps of: receiving first transaction data including a first electronic signature from a home 100a used by a first user (S204); verifying the first electronic signature included in the received first transaction data (S205); verifying the validity of the received first transaction data (S206); executing a first consensus algorithm for the first transaction data when the verifications are successful (S209); and recording a block including the first transaction data in a distributed ledger when the validity of the first transaction data is verified according to the first consensus algorithm (S209). The first electronic signature is a group signature assigned to a group to which the first user belongs.SELECTED DRAWING: Figure 12
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a control method, a controller, and an electricity trading system, and in particular to an electricity trading system that trades electricity generated at homes and the like, as well as a control method, a controller, and a data structure in the electricity trading system. [Background technology]

[0002] In recent years, renewable energy sources such as solar power generation have become more widespread. With solar power generation, not only is the electricity generated at home used, but surplus electricity is also sold to power companies.

[0003] In the future, it is expected that electricity will be sold not only to power companies but also directly to local residents. However, direct buying and selling between consumers, i.e., private electricity trading, requires matching between consumers who sell electricity and consumers who buy it, and the exchange of electricity, so an intermediary such as a power company is needed.

[0004] In response to this, technology is being considered for building an autonomous decentralized system that utilizes blockchain technology for person-to-person electricity transactions in the electricity sector (for example, Non-Patent Document 1). According to the technology disclosed in Non-Patent Document 1, for example, if a consumer who owns a solar power generation system wants to sell excess electricity to other consumers, the value can be transferred using blockchain technology without going through an intermediary such as a power company. [Prior art documents] [Non-patent literature]

[0005] [Non-Patent Document 1] Mizuho Industry Research, How Will Digital Innovation Transform Business? - Exploring Issues and Strategies from Notable Initiatives, Electricity - Prospects for an Electricity Sharing Economy Utilizing Blockchain Technology, Vol. 57, No. 1, 2017 (URL: https: / / www.mizuhobank.co.jp / corporate / bizinfo / industry / sangyou / m1057.html) [Non-patent document 2] Mihir Bellare and two others, "Foundations of Group Signatures: Formal Definitions, Simplified Requirements, and a Construction Based on General Assumptions," [online], "Advances in Cryptology - EUROCRYPT 2003," [Retrieved January 11, 2018], Internet (URL: https: / / cseweb.ucsd.edu / ~mihir / papers / gs.pdf), Springer Berlin Heidelberg Summary of the Invention [Problem to be solved by the invention]

[0006] However, with the technology disclosed in Non-Patent Document 1, transaction data of consumers who sell electricity is made public, which raises the problem that whether a consumer is at home or not can be inferred from the time or amount of electricity that the consumer can supply. In other words, with the technology disclosed in Non-Patent Document 1, there is a possibility that private information may be leaked.

[0007] The present disclosure has been made in consideration of the above circumstances, Properly conduct private electricity transactions The object of the present invention is to provide a control method and the like that can achieve this. [Means for solving the problem]

[0008] In order to achieve the above object, the control method of the present disclosure acquires, from a first power facility, first transaction data including an amount of transmitted power transmitted from the first power facility to a second power facility, acquires, from the second power facility, second transaction data including an amount of received power received from the first power facility, verifies whether the amount of transmitted power or the amount of received power is consistent with an amount of traded power traded between the first power facility and the second power facility, and if the verification is successful, records the first transaction data or the second transaction data in a distributed ledger.

[0009] These comprehensive or specific aspects may be realized as a system, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or may be realized as any combination of a system, a method, an integrated circuit, a computer program, and a recording medium. [Effects of the Invention]

[0010] According to the control method and the like of the present disclosure, it is possible to suppress the leakage of private information. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a diagram illustrating an example of an overall configuration of an energy trading system according to an embodiment. [Figure 2] 1 is a diagram illustrating an example of the overall configuration of a house according to an embodiment. [Figure 3] FIG. 3 is a block diagram showing the functional configuration of a controller shown in FIG. 2. [Figure 4] FIG. 10 is a diagram illustrating an example of an input screen for inputting power sale request information according to the embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of an input screen for inputting power purchase request information according to the embodiment. [Figure 6] FIG. 2 is a block diagram showing a functional configuration of an authentication server according to an embodiment. [Figure 7A]FIG. 1 is an explanatory diagram showing the data structure of a blockchain. [Figure 7B] FIG. 2 is an explanatory diagram illustrating the data structure of transaction data. [Figure 8A] FIG. 4 is a diagram illustrating an example of a power selling list according to the embodiment. [Figure 8B] FIG. 4 is a diagram illustrating an example of a power purchase list according to the embodiment. [Figure 8C] FIG. 2 is a diagram illustrating an example of an energy trade list according to an embodiment. [Figure 9] FIG. 2 is a block diagram showing a functional configuration of a service server according to the embodiment. [Figure 10] FIG. 10 is a sequence diagram showing a service registration process between the service server, the home, and the authentication server according to the embodiment. [Figure 11] FIG. 2 is an overall sequence diagram of an energy transaction between a house and an authentication server according to an embodiment. [Figure 12] FIG. 10 is a sequence diagram of a power sale request process between a house and an authentication server according to an embodiment. [Figure 13] FIG. 10 is a sequence diagram of a power purchase request process between a home and an authentication server according to an embodiment. [Figure 14] FIG. 10 is a sequence diagram of an energy trading process between a house and an authentication server according to an embodiment. [Figure 15] FIG. 10 is a sequence diagram of an energy trading process between a house and an authentication server according to an embodiment. [Figure 16] FIG. 10 is a sequence diagram of an incentive payment process between a house and a service server according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] A control method according to one embodiment of the present disclosure includes: acquiring, from a first power facility, first transaction data including an amount of transmitted power transmitted from the first power facility to a second power facility; acquiring, from the second power facility, second transaction data including an amount of received power received from the first power facility; verifying whether the amount of transmitted power or the amount of received power is consistent with an amount of traded power traded between the first power facility and the second power facility; and, if the verification is successful, recording the first transaction data or the second transaction data in a distributed ledger.

[0013] Furthermore, a control method according to one embodiment of the present disclosure is an energy trading system including a first power facility, a second power facility, and a first server communicatively connected to the first power facility and the second power facility via a network, wherein the first server acquires, from the first power facility, first transaction data including an amount of transmitted energy that the first power facility transmitted to the second power facility, and acquires, from the second power facility, second transaction data including an amount of received energy that the second power facility received from the first power facility, verifies whether the amount of transmitted energy or the amount of received energy is consistent with an amount of traded energy traded between the first power facility and the second power facility, and if the verification is successful, records the first transaction data or the second transaction data in a distributed ledger.

[0014] A control method according to one aspect of the present disclosure is a program for causing a computer to execute the above control method.

[0015] A control method according to one aspect of the present disclosure is a control method executed by a first server of an energy trading system including a first power facility used by a first user, a second power facility used by a second user, and a plurality of servers communicatively connected to the first power facility and the second power facility via a network, the control method including the steps of receiving, from the first power facility via the network, first transaction data, the first transaction data including a first blockchain address that is an identifier identifying at least one of the first user and the first power facility, power sales amount information indicating the amount of power that the first power facility can sell, and a first electronic signature linked to the first user; the step of verifying a first electronic signature; the step of verifying the legitimacy of the received first transaction data; and, if the verification of the first electronic signature and the legitimacy of the first transaction data are successful, the step of executing a first consensus algorithm together with a plurality of second servers different from the first server among the plurality of servers to agree on the legitimacy of the first transaction data; and, if the legitimacy of the first transaction data is agreed upon by the first consensus algorithm, the step of recording a block including the first transaction data in a distributed ledger of the first server, wherein the first electronic signature is a first group signature assigned to a first group to which a plurality of users including the first user belong.

[0016] In this way, the signature included in the transaction data from the residence is used as a group signature.

[0017] As a result, even if the first transaction data of the blockchain indicating a request to sell electricity is made public, the home and the user of the home cannot be identified from the first transaction data, thereby preventing the leakage of private information.

[0018] The method may further include the steps of receiving second transaction data from the second power facility via the network, the second transaction data including a second blockchain address that is an identifier identifying at least one of the second user and the second power facility, power purchase amount information that indicates the amount of power that the second power facility is able to purchase, and a second electronic signature linked to the second user; verifying the second electronic signature included in the received second transaction data; verifying the legitimacy of the received second transaction data; and, if the verification of the second electronic signature and the verification of the legitimacy of the second transaction data are successful, executing a second consensus algorithm together with the plurality of second servers to reach an agreement on the legitimacy of the second transaction data; and, if the legitimacy of the second transaction data is agreed upon by the second consensus algorithm, recording a block including the second transaction data in the distributed ledger of the first server, wherein the second electronic signature may be a second group signature assigned to a second group to which a plurality of users including the second user belong.

[0019] As a result, even if the transaction data of the second blockchain indicating the power purchase request is made public, the home and the user of the home cannot be identified from the second transaction data, thereby preventing the leakage of private information.

[0020] Furthermore, the first transaction data may further include a first timestamp indicating a first date and time when the sold power can be sold, and the second transaction data may further include a second timestamp indicating a second date and time when the purchased power can be purchased, and the control method may further include the steps of: matching the power transaction by comparing the power sale amount information and the first timestamp with the power purchase amount information and the second timestamp, both of which are recorded in the distributed ledger; generating third transaction data, if the matching of the power transaction is established, including the first blockchain address, the second blockchain address, and the amount of power traded in the energy transaction; transferring the third transaction data to the plurality of second servers and executing a third consensus algorithm together with the plurality of second servers to reach an agreement on the legitimacy of the third transaction data; and, if the legitimacy of the third transaction data is agreed upon by the third consensus algorithm, recording a block including the third transaction data in the distributed ledger.

[0021] This means that even if the third transaction data on the blockchain showing the matching results of the electricity transaction is made public, the home that made the transaction and the user of the home cannot be identified from the third transaction data, thereby preventing the leakage of privacy information.

[0022] Furthermore, the control method further includes the steps of, when the energy trade is concluded, notifying the first power facility and the second power facility that the energy trade has been concluded, and receiving fourth transaction data from the first power facility via the network, the fourth transaction data including a fourth blockchain address that is an identifier for identifying at least one of the first user and the first power facility, power transmission information that indicates an amount of power transmitted from the first power facility to the second power facility, and the first electronic signature; verifying the first electronic signature included in the received fourth transaction data and verifying the legitimacy of the received fourth transaction data; and, when the verification of the first electronic signature and the verification of the legitimacy of the fourth transaction data are successful, executing a fourth consensus algorithm together with the plurality of second servers to agree on the legitimacy of the fourth transaction data; and If an agreement is reached, a step of recording a block including the fourth transaction data in the distributed ledger of the first server; a step of receiving fifth transaction data from the second power facility via the network, the fifth transaction data including a fifth blockchain address which is an identifier identifying at least one of the second user and the second power facility, power reception information indicating the amount of power received by the second power facility from the first power facility, and the second electronic signature; a step of verifying the second electronic signature included in the received fifth transaction data and verifying the legitimacy of the received fifth transaction data; if the verification of the second electronic signature and the verification of the legitimacy of the fifth transaction data are successful, a step of executing a fifth consensus algorithm together with the plurality of second servers to reach an agreement on the legitimacy of the fifth transaction data; and if the legitimacy of the fifth transaction data is agreed upon by the fifth consensus algorithm,and recording a block including the fifth transaction data in the distributed ledger of the first server.

[0023] This means that even if blockchain transaction data showing the results of electricity trading is made public, the home that conducted the transaction and the user of the home cannot be identified from the transaction data, thereby preventing the leakage of private information.

[0024] The energy trading system may further include a service server, and the control method may include a step in which the service server generates a group signature key assigned to a group to which the first user and the second user belong, and the key generating step may include a step of generating a private key for the group signature used to generate the first electronic signature and transmitting it to the first electric power facility, a step of generating a private key for the group signature used to generate the second electronic signature and transmitting it to the second electric power facility, and a step of distributing a public key that is a signature verification key for the group signature to the plurality of servers.

[0025] The energy trading system may further include a service server, and the control method may include a step in which the service server generates a group signature key assigned to a group to which the first user belongs, the step of generating the key including the steps of: generating a group signature key assigned to the first group to which a plurality of users including the first user belong; generating a private key for signing the group signature used to generate the first electronic signature and transmitting the private key to the first electric power facility; and distributing a public key, which is a signature verification key for the group signature assigned to the first group, to the plurality of servers.

[0026] The energy trading system may further include a service server, and the control method may include a step in which the service server generates a group signature key assigned to a group to which the second user belongs, the step of generating the key including the steps of: generating a group signature key assigned to the second group to which a plurality of users including the second user belong; generating a private key for signing the group signature used to generate the second electronic signature and transmitting the private key to the second electric power facility; and distributing a public key, which is a signature verification key for the group signature assigned to the second group, to the plurality of servers.

[0027] Furthermore, the method may further include the steps of the service server referencing the distributed ledger of the first server and obtaining transaction data, and the service server disclosing a group signature included in the obtained transaction data and identifying the user who made the group signature.

[0028] Furthermore, the method may further include a step in which the service server notifies the identified user that the incentive has been paid after the incentive has been paid to the identified user.

[0029] In addition, the second blockchain address may be generated each time by a controller of the second power equipment as an identifier that identifies at least one of the second user and the second power equipment.

[0030] In addition, the first blockchain address may be generated each time by a controller of the first power equipment as an identifier that identifies at least one of the first user and the first power equipment.

[0031] Furthermore, the step of executing the first consensus algorithm may include the steps of receiving first reports from each of the plurality of second servers indicating whether verification of the legitimacy of the first transaction data was successful or not, determining whether the number of the first reports exceeds a predetermined number, and determining, when the number of the first reports exceeds the predetermined number, that this is a case in which the first consensus algorithm has agreed on the legitimacy of the first transaction data.

[0032] Furthermore, the step of executing the second consensus algorithm may include a step of receiving second reports from each of the plurality of second servers indicating whether verification of the legitimacy of the second transaction data was successful or not, and a step of determining whether the number of the second reports exceeds a predetermined number, and a step of determining that, when the number of the second reports exceeds the predetermined number, the second consensus algorithm has agreed on the legitimacy of the second transaction data.

[0033] The first power facility and the second power facility may include at least one of a solar power generation system, a gas power generation system, and a wind power generation system.

[0034] Furthermore, a controller according to one aspect of the present disclosure is a controller that controls a first power facility in an energy trading system including a first power facility used by a first user, a second power facility used by a second user, and a plurality of servers with which the first power facility and the second power facility can communicate via a network, the controller including a processor and a memory storing a program that causes the processor to execute a predetermined process, the predetermined process including a step of determining whether or not an amount of surplus energy of the first power facility is equal to or greater than a predetermined value, and, if the amount of surplus energy is equal to or greater than the predetermined value, a step of generating a first block of data that is an identifier that identifies at least one of the first user and the first power facility. generating first transaction data including a blockchain address, power sales amount information indicating the amount of power sales that the first power facility can sell, and a first electronic signature linked to the first user; transmitting the first transaction data to a first server among the plurality of servers via the network; when the plurality of servers verify the legitimacy of the first transaction data and a block including the first transaction data is recorded in the distributed ledger of each of the plurality of servers, displaying on a display power sales registration information including the power sales amount information and indicating the first power facility's desire to sell power, wherein the first electronic signature is a group signature assigned to a group to which the first user belongs.

[0035] Furthermore, a control method of a controller according to one aspect of the present disclosure is a control method of a display that displays information on energy trading of a first power facility in an energy trading system including a first power facility used by a first user, a second power facility used by a second user, and a plurality of servers with which the first power facility and the second power facility can communicate via a network, and when the amount of surplus energy of the first power facility is equal to or greater than a predetermined value, displays first transaction data, the first transaction data including a first blockchain address that is an identifier identifying at least one of the first user and the first power facility, energy sales amount information indicating the amount of energy that the first power facility can sell, and a first electronic signature linked to the first user. During the period from when the transaction data is transmitted to a first server among the plurality of servers via the network until the legitimacy of the first transaction data is verified by the plurality of servers, the display displays electricity sales registration information including the electricity sales amount information and indicating the first power facility's desire to sell electricity; when the legitimacy of the first transaction data is verified by the plurality of servers, the display displays the electricity sales registration information; when the legitimacy of the first transaction data is not agreed upon by the plurality of servers, the display displays failure information indicating that agreement has not been reached; and the first electronic signature is a group signature assigned to a group to which the first user belongs.

[0036] Furthermore, a data structure according to one embodiment of the present disclosure is a data structure used for blocks recorded as a blockchain in an energy trading system comprising a first power facility used by a first user, a second power facility used by a second user, and a plurality of servers communicatively connected to the first power facility and the second power facility via a network, the data structure including a blockchain address, which is an identifier for identifying at least one of the first user and the first power facility, included in a block generated using the private key of the first user, power sales amount information indicating the amount of power that the first power facility can sell, and a first electronic signature, which is linked to the first user and is a group signature assigned to a group to which the first user belongs, and the power sales amount information is used for matching energy transactions by comparing it with power purchase amount information indicating the amount of power that the second power facility can purchase and a second timestamp indicating a second date and time when the purchased power can be purchased.

[0037] An energy trading system according to one aspect of the present disclosure is an energy trading system including a first power facility used by a first user, a second power facility used by a second user, and a plurality of servers communicatively connected to the first power facility and the second power facility via a network, wherein a first controller included in the first power facility generates first transaction data, the first transaction data including a first blockchain address which is an identifier identifying at least one of the first user and the first power facility, power selling amount information indicating an amount of power that the first power facility is able to sell, and a first electronic signature linked to the first user, and transmits the first transaction data to a first server among the plurality of servers via the network; and a second controller included in the second power facility generates second transaction data, the second transaction data including a second blockchain address which is an identifier identifying at least one of the second user and the second power facility, and power purchasing amount information indicating an amount of power that the second power facility is able to purchase. generating second transaction data including power quantity information, a second timestamp indicating a second date and time when the purchased power can be purchased, and a second electronic signature associated with the second user, and transmitting the second transaction data to a second server among the plurality of servers via the network, the first server verifying the first electronic signature included in the received first transaction data and verifying the legitimacy of the received first transaction data, and if the verification of the first electronic signature and the legitimacy of the first transaction data is successful, transferring the first transaction data to the plurality of servers excluding the first server, the second server verifying the second electronic signature included in the received second transaction data and verifying the legitimacy of the received second transaction data, and if the verification of the second electronic signature and the legitimacy of the second transaction data is successful, transferring the second transaction data to the plurality of servers excluding the second server, and the plurality of serversa first consensus algorithm is executed to reach an agreement on the validity of the first transaction data, and if the first consensus algorithm reaches an agreement on the validity of the first transaction data, a block including the first transaction data is recorded in a distributed ledger of each of the plurality of servers; a second consensus algorithm is executed to reach an agreement on the validity of the second transaction data, and if the second consensus algorithm reaches an agreement on the validity of the second transaction data, the second transaction data is recorded in the distributed ledger;

[0038] Hereinafter, embodiments will be described with reference to the drawings. Note that each of the embodiments described below represents a preferred specific example of the present disclosure. In other words, the numerical values, shapes, materials, components, component arrangements and connection forms, steps, and step orders shown in the following embodiments are merely examples and are not intended to limit the present disclosure. The present disclosure is defined based on the claims. Therefore, among the components in the following embodiments, components that are not recited in the independent claims that represent the superordinate concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components that constitute more preferred embodiments.

[0039] (Embodiment) First, the system configuration of the present disclosure will be described.

[0040] [1. System Configuration] The energy trading system 10 of the present disclosure uses group signatures, which have the property that group members can sign anonymously as part of the group, to conduct energy trading using blockchain technology while protecting privacy information.

[0041] Here, we will explain group signatures. Using group signatures, members of a group can authenticate that they belong to the group. Furthermore, with group signatures, anyone can verify that the signature was generated by a legitimate group member. Note that while it is possible to verify that the signature was generated by a group member, it has the characteristic that it is not possible to identify the group member from the signature. However, if a problem occurs or if necessary, only the administrator who issued the group signature can identify the signer.

[0042] Hereinafter, an energy trading system and the like according to an embodiment will be described with reference to the drawings.

[0043] [1.1 Overall Configuration of Energy Trading System 10] FIG. 1 is a diagram showing an example of the overall configuration of an energy trading system 10 according to the present embodiment.

[0044] As shown in Fig. 1, the energy trading system 10 includes, for example, residences 100a, 100b, and 100c, authentication servers 200a, 200b, and 200c, and a service server 300. These are connected via a communication network 400. The residences 100a, 100b, and 100c are also connected via a power network 500. The power network 500 is a network that allows the residences to share power, and may be a dedicated line or may utilize a power network installed by a power company.

[0045] Furthermore, authentication servers 200a, 200b, and 200c are connected to storage devices 201a, 201b, and 201c. Authentication servers 200a, etc. may be connected to storage devices 201a, etc. via a communication network 400, or may include storage device 201a internally. Storage device 201a has a distributed ledger in which transaction data and blocks of the blockchain are electronically recorded.

[0046] 1 shows an example in which the energy trading system 10 includes three residences and three authentication servers, but the present invention is not limited to this. That is, the energy trading system 10 may include four or more residences and four or more authentication servers.

[0047] [1.2 Configuration of the house 100a] Since the houses 100b and 100c have the same configuration, the house 100a will be described below as an example.

[0048] FIG. 2 is a diagram showing an example of the overall configuration of a house 100a according to this embodiment.

[0049] 2, the home 100a includes a controller 101, a solar power generation unit 102, a storage battery 103, and a power meter 104. The controller 101, the solar power generation unit 102, the storage battery 103, and the power meter 104 are connected to a communication network 110. The solar power generation unit 102, the storage battery 103, and the power meter 104 are also connected to a power network 111, and the power meter 104 is connected to a power network 500 outside the home 100a.

[0050] Here, the residence 100a etc. is an example of a building having power equipment used by the first user or the second user, and is, for example, a house such as a residential building, but is not limited to this. The residence 100a etc. may also be a building such as a factory or office building. In other words, the residence 100a etc. can be of any type as long as it is a building having power equipment used by a user.

[0051] <Controller 101> The controller 101 is, for example, a controller of an energy management system, and is an example of a controller that controls the first power facility or the second power facility in the energy trading system 10.

[0052] In this embodiment, the controller 101 displays the power generation status of the solar power generation system 102, displays the power storage state of the storage battery 103, and inputs applications for selling or purchasing power. The controller 101 also controls the solar power generation system 102 and the storage battery 103, and transmits power to the power network 111 or the power network 500. The controller 101 also manages the amount of power transmitted to the power network 500, and notifies the authentication server 200a and the like. Details will be described later.

[0053] <Solar Power Generation 102> The solar power generation system 102 is an example of a solar power generation device included in the first power facility or the second power facility. The solar power generation system 102 is a device equipped with a power generation method that directly converts sunlight into electric power using a solar cell. The solar power generation system 102 stores the generated electric power in a storage battery 103 or transmits the generated electric power to the electric power network 500. The solar power generation system 102 transmits the generated electric power to the electric power network 500 via the electric power network 111, for example, in response to a power transmission instruction from the controller 101.

[0054] The solar power generation system 102 is not limited to a solar power generation system, but may be a gas power generation system, a wind power generation system, or the like.

[0055] <Storage Battery 103> The storage battery 103 stores the power generated by the solar power generation system 102. The storage battery 103 transmits the stored power to the power network 500, for example, in response to a power transmission instruction from the controller 101. The storage battery 103 may also store power received from the power network 500 in response to a power reception instruction from the controller 101. The storage battery 103 is not an essential component, and may not be provided in the house 100a.

[0056] <Power meter 104> The power meter 104 is included in the first power facility or the second power facility, and measures the amount of power transmitted to or received from the power network 500. When the solar power generation unit 102 or the storage battery 103 transmits power to the power network 500 in response to a power transmission instruction from the controller 101, the power meter 104 measures the time and amount of power transmitted and notifies the controller 101. In addition, in response to a power usage instruction from the controller 101, the power meter 104 measures the amount of power received from the power network 500 and used.

[0057] An example of the configuration of the controller 101 will be described below.

[0058] [1.3 Controller 101 Configuration] FIG. 3 is a block diagram showing the functional configuration of the controller 101 shown in FIG.

[0059] The controller 101 includes a processor and a memory that stores a program that causes the processor to execute a predetermined process. In other words, the controller 101 is realized by the processor executing the predetermined program using the memory. In this embodiment, the controller 101 includes an input unit 1011, a transaction data generation unit 1012, a signature generation unit 1013, a control unit 1014, a recording unit 1015, and a communication unit 1016. Each component will be described below.

[0060] <Input section 1011> Fig. 4 is a diagram showing an example of an input screen for inputting power sale request information according to the present embodiment. Fig. 5 is a diagram showing an example of an input screen for inputting power purchase request information according to the present embodiment.

[0061] The input unit 1011 accepts input of information for a user to apply for an energy trading service, and transmits the information to the service server 300 via the communication unit 1016. The input unit 1011 also creates an input screen for a user to input information for requesting to sell or purchase electricity.

[0062] When a user inputs power sale request information or power purchase request information on the created input screen, the input unit 1011 transmits the input power sale request information or power purchase request information to the transaction data generation unit 1012 and the signature generation unit 1013.

[0063] For example, as shown in Fig. 4, the date, the amount of electricity to be sold, and the unit price of the electricity to be sold are input by the user on the input screen 105a for inputting electricity sale request information. Note that in the example shown in Fig. 4, the amount of electricity to be sold is displayed in kWh, but this is not limitative. The amount of electricity to be sold may be specified by the amount of electricity stored after the electricity sale, or may be specified as a percentage of the amount of electricity stored. Furthermore, the unit price of the electricity to be sold does not necessarily have to be input by the user, but may also be determined in advance in the energy trading system 10. Note that the input unit 1011 may present the date, the amount of electricity to be sold, and the unit price of the electricity to be sold on the input screen 105a in a state where they have been provisionally input, and have the user input whether or not they agree, such as "yes" or "no."

[0064] Furthermore, as shown in Fig. 5, for example, the date, the amount of electricity to be sold, and the unit price of the electricity to be purchased are input by the user on input screen 105b for inputting electricity purchase request information. Note that in the example shown in Fig. 5, the amount of electricity to be purchased is displayed in kWh, but this is not limitative. The amount of electricity to be purchased may also be specified by the amount of electricity stored after the electricity purchase. The unit price of the electricity to be purchased does not necessarily have to be input by the user, but may also be determined in advance in energy trading system 10. Note that input unit 1011 may present the date, the amount of electricity to be purchased, and the unit price of the electricity to be purchased on input screen 105b in a provisionally input state, and have the user input "yes" or "no" to indicate whether or not they agree.

[0065] <Transaction Data Generation Unit 1012> The transaction data generation unit 1012 generates transaction data in the blockchain based on the power sale request information or the power sale request information received from the input unit 1011 and the signature information received from the signature generation unit 1013. The transaction data generation unit 1012 may determine whether the amount of surplus power of the solar power generation unit 102 is equal to or greater than a predetermined value, and generate transaction data if the amount is equal to or greater than the predetermined value. Here, the predetermined value is, for example, the amount of power to be sold included in the power sale request information received from the input unit 1011 as the amount of surplus power.

[0066] The transaction data generated by the transaction data generation unit 1012 is an example of the first transaction data and the second transaction data.

[0067] The first transaction data includes a first blockchain address, which is an identifier that identifies at least one of the first user and the first power facility, power sales amount information indicating the amount of power that the first power facility can sell, a first timestamp indicating a first date and time when the power can be sold, and a first electronic signature associated with the first user. Here, the first electronic signature is a first group signature assigned to a first group to which multiple users, including the first user, belong. Note that the first transaction data may not include the first timestamp.

[0068] The second transaction data includes a second blockchain address, which is an identifier identifying at least one of the second user and the second power facility; power purchase amount information indicating the amount of power that the second power facility can purchase; a second timestamp indicating a second date and time when the power can be purchased; and a second electronic signature associated with the second user. Here, the second electronic signature is a second group signature assigned to a second group to which multiple users including the second user belong. Note that the first user and the second user belong to the same group. The second transaction data may not include the second timestamp. The first blockchain address may be generated each time by a controller of the first power facility as an identifier identifying at least one of the first user and the first power facility. The second blockchain address may be generated each time by a controller of the second power facility as an identifier identifying at least one of the second user and the second power facility. In other words, the first blockchain address and the second blockchain address may be one-time addresses.

[0069] As such, in this embodiment, the transaction data generated by the transaction data generation unit 1012 includes the blockchain address of the user or controller, power sale request information or power purchase request information, and the group signature generated by the signature generation unit 1013.

[0070] The transaction data generation unit 1012 records the generated transaction data in the recording unit 1015. The transaction data generation unit 1012 also transmits the generated transaction data via the communication unit 1016 to at least one of the authentication servers 200a, etc.

[0071] Furthermore, when the transaction data generation unit 1012 receives a notification from the power meter 104 that power has been transmitted to the power network 500, the transaction data generation unit 1012 generates transaction data including the time and amount of power transmitted included in the notification, and records the transaction data in the recording unit 1015. The transaction data generation unit 1012 transmits the generated transaction data to at least one of the authentication servers 200a, etc. via the communication unit 1016. More specifically, the transaction data generated by the transaction data generation unit 1012 upon receiving a notification from the power meter 104 is an example of the fourth transaction data and the fifth transaction data.

[0072] The fourth transaction data includes a fourth blockchain address that is an identifier identifying at least one of the first user and the first power facility, power transmission information indicating the amount of power transmitted from the first power facility to the second power facility, and a first electronic signature. The fifth transaction data includes a fifth blockchain address that is an identifier identifying at least one of the second user and the second power facility, power reception information indicating the amount of power received from the first power facility by the second power facility, and a second electronic signature.

[0073] <Signature generation section 1013> The signature generation unit 1013 generates a signature for a group signature based on the power sale request information or the power sale request information received from the input unit 1011. The signature generation unit 1013 receives a signature generation key from the service server 300 in advance and stores it.

[0074] More specifically, the signature generation unit 1013 receives and stores a private key for signing the group signature, i.e., a signature generation key individual to the user, which is generated by the service server 300 in response to information for applying for the energy trading service transmitted in advance by the input unit 1011. The signature generation unit 1013 uses the stored signature generation key to generate a first electronic signature or a second electronic signature, which is a signature of the group signature, based on the power sale request information or the power purchase request information received from the input unit 1011.

[0075] Note that group signatures may be generated and used using the method described in Non-Patent Document 2. The group signature generated by signature generation unit 1013, i.e., the first electronic signature or the second electronic signature, is generated using a signature generation key individual to each user, i.e., the signature generation key of the first user or the signature generation key of the second user. From the first electronic signature or the second electronic signature generated by signature generation unit 1013, it is possible to determine that the first user or the second user is a member of the same group, but it is not possible to identify which user generated the first electronic signature or the second electronic signature. This is a characteristic of the group signature described above.

[0076] <Control unit 1014> When the control unit 1014 receives an energy trade completion notification indicating that an energy trade has been completed from the authentication server 200a or the like, the control unit 1014 transmits an instruction to the solar power generation unit 102 or the storage battery 103 based on the energy trade completion notification. For example, when performing control to transmit energy, the control unit 1014 transmits an energy transmission instruction to the solar power generation unit 102 and the storage battery 103 indicating that the energy generated by the solar power generation unit 102 or the energy stored in the storage battery 103 is to be transmitted to the energy network 500. Furthermore, when performing control to use energy, the control unit 1014 transmits an energy receiving instruction to the storage battery 103 indicating that the energy is to be used from the energy network 500 and stored in the storage battery 103.

[0077] The control unit 1014 may control a display built into or connected to the controller 101 to display the power sale request information or the power purchase request information transmitted to the authentication server 200a. Furthermore, when the multiple authentication servers agree on the legitimacy of the first transaction data and a block including the first transaction data is recorded in the distributed ledger of each of the multiple authentication servers, the control unit 1014 may cause the display to display power sale registration information including the power sale amount information and the first timestamp and indicating the first power facility's desire to sell power. Note that the control unit 1014 may also cause the display to display the power sale registration information until the multiple authentication servers agree on the legitimacy of the first transaction data.

[0078] On the other hand, for example, if multiple authentication servers fail to agree on the legitimacy of the first transaction, the control unit 1014 may cause failure information to be displayed on the display.

[0079] <Recording Unit 1015> The recording unit 1015 records the transaction data generated by the transaction data generation unit 1012. In this embodiment, the recording unit 1015 records the first transaction data or the second transaction data, or the fourth transaction data or the fifth transaction data generated by the transaction data generation unit 1012.

[0080] <Communications Department 1016> The communication unit 1016 communicates with the service server 300, the authentication server 200a, etc. via the communication network 400. This communication may be performed using TLS (Transport Layer Security). In this case, the communication unit 1016 may hold an encryption key for the TLS communication.

[0081] In this embodiment, the communication unit 1016 transmits the first transaction data or the second transaction data to a first server among the multiple authentication servers via the communication network 400. The communication unit 1016 also transmits the fourth transaction data or the fifth transaction data to the first authentication server, which is at least one server among the multiple authentication servers, via the communication network 400.

[0082] Next, the authentication server 200a and the like will be described.

[0083] 1.4 Configuration of the authentication server 200a 6 is a block diagram showing the functional configuration of authentication server 200a according to this embodiment. Since authentication servers 200b and 200c have the same configuration, authentication server 200a will be taken as an example for explanation.

[0084] As shown in Fig. 6, authentication server 200a includes signature verification unit 211, transaction data verification unit 212, block generation unit 213, synchronization unit 214, transaction generation unit 215, recording unit 216, and communication unit 217. Authentication server 200a can be realized by a processor executing a predetermined program using a memory. Each component will be described below.

[0085] <Signature Verification Unit 211> When the signature verification unit 211 receives first transaction data, it verifies the first electronic signature included in the received first transaction data. When the signature verification unit 211 receives second transaction data, it verifies the second electronic signature included in the received second transaction data. Similarly, when the signature verification unit 211 receives fourth transaction data, it verifies the first electronic signature included in the received fourth transaction data. When the signature verification unit 211 receives fifth transaction data, it verifies the second electronic signature included in the received fifth transaction data. Here, the signature verification unit 211 holds a public key that is a signature verification key for the group signature distributed by the service server 300. The signature verification unit 211 verifies the first electronic signature or the second electronic signature using the held public key.

[0086] In this way, the signature verification unit 211 verifies the first digital signature or the second digital signature, which is the group signature of the received transaction data. The signature verification unit 211 receives and stores the signature verification key for the group signature from the service server 300 in advance.

[0087] Furthermore, if the verification result shows that the group signature, that is, the first digital signature or the second digital signature, is correct, the signature verification unit 211 notifies the transaction data verification unit 212 to that effect.

[0088] In verifying the group signature, the signature verification key is common to all services. By using the signature verification key, the signature verification unit 211 can verify that the first digital signature was generated using a signature generation key registered in the service server 300, but cannot identify which signature generation key was used to generate the first digital signature. In other words, the authentication server 200a can identify which home the received transaction data belongs to by the blockchain address. However, since the authentication server 200a cannot identify the home from the blockchain address, it cannot identify which home generated the transaction data. This is a characteristic of the group signature described above.

[0089] <Transaction Data Verification Unit 212> When the transaction data verification unit 212 receives first transaction data, it verifies the legitimacy of the received first transaction data. When the transaction data verification unit 212 receives second transaction data, it verifies the legitimacy of the received second transaction data. Similarly, when the transaction data verification unit 212 receives fourth or fifth transaction data, it verifies the legitimacy of the received fourth or fifth transaction data.

[0090] In this way, the transaction data verification unit 212 verifies the legitimacy of transaction data received from the residence 100a, etc. More specifically, when the transaction data verification unit 212 receives transaction data from the residence 100a, etc., it verifies whether the blockchain address and the power sale request information, power purchase request information, or power information included in the transaction data are correct. If the transaction data verification unit 212 determines as a result of the verification that the transaction data is legitimate transaction data and receives a notification of the legitimacy of the signature from the signature verification unit 211, it records the transaction data in the recording unit 216.

[0091] Furthermore, to verify whether the power information is correct, the transaction data verification unit 212 refers to transaction data indicating the power trading results recorded in the recording unit 216, and verifies whether the power is being transmitted or used correctly. If the transaction data verification unit 212 confirms the validity of the transaction data as a result of the verification, it notifies the synchronization unit 214 of the transaction data.

[0092] <Block Generation Unit 213> If the verification of the first electronic signature and the validity of the first transaction data are successful, the block generation unit 213 executes a first consensus algorithm together with other authentication servers 200b, 200c, which are multiple second servers different from the first server, to reach an agreement on the validity of the first transaction data. Furthermore, if the verification of the second electronic signature and the validity of the second transaction data are successful, the block generation unit 213 executes a second consensus algorithm together with the other authentication servers 200b, 200c to reach an agreement on the validity of the second transaction data. Furthermore, if the verification of the first electronic signature and the validity of the fourth transaction data are successful, the block generation unit 213 may execute a fourth consensus algorithm together with the other authentication servers 200b, 200c to reach an agreement on the validity of the fourth transaction data. Furthermore, if the verification of the second digital signature and the verification of the legitimacy of the fifth transaction data are successful, the block generation unit 213 may execute a fifth consensus algorithm together with the other authentication servers 200b and 200c to reach an agreement on the legitimacy of the fifth transaction data. Furthermore, if third transaction data (described later) is transferred to the other authentication servers 200b and 200c, the block generation unit 213 may execute a third consensus algorithm together with the other authentication servers 200b and 200c to reach an agreement on the legitimacy of the third transaction data.

[0093] In this way, the block generation unit 213 executes a consensus algorithm among multiple authentication servers. The consensus algorithm may be a consensus algorithm called PBFT (Practical Byzantine Fault Tolerance), or any other known consensus algorithm. When PBFT is used, the block generation unit 213 first receives reports from each of the other authentication servers 200b, 200c indicating whether the verification of the validity of the transaction was successful, and determines whether the number of such reports exceeds a predetermined number. When the number of such reports exceeds the predetermined number, the block generation unit 213 determines that the validity of the transaction data has been agreed upon by the consensus algorithm.

[0094] Furthermore, when the validity of the transaction data is agreed upon by the consensus algorithm, the block generation unit 213 records a block including the transaction data in the distributed ledger of the storage device 201a of the authentication server 200a. Note that this consensus algorithm refers to the first to fifth consensus algorithms, and this transaction data refers to the first to fifth transaction data.

[0095] As described above, in this embodiment, the block generation unit 213 executes a consensus algorithm between the authentication servers 200a, 200b, and 200c. That is, the block generation unit 213 first generates a block of a blockchain including one or more transaction data. Next, the block generation unit 213 executes the consensus algorithm. Then, when consensus is reached by executing the consensus algorithm, the block generation unit 213 records the generated block in the recording unit 216. The block generated by the block generation unit 213 is connected to the blockchain recorded in the recording unit 216 and recorded.

[0096] Here, the data structure of the blockchain and the data structure of the transaction data will be described.

[0097] FIG. 7A is an explanatory diagram showing the data structure of a blockchain.

[0098] A blockchain is a chain of blocks, which are the units of record. Each block contains multiple transaction data and the hash value of the previous block. Specifically, block B2 contains the hash value of the previous block B1. A hash value calculated from the multiple transaction data contained in block B2 and the hash value of block B1 is included in block B3 as the hash value of block B2. In this way, by connecting blocks in a chain while including the contents of the previous block as a hash value, tampering with the connected transaction data is effectively prevented.

[0099] If past transaction data were to be changed, the hash value of the block would be different from before the change, and in order to make the altered block appear correct, all subsequent blocks would have to be recreated, which is a very difficult task in reality.

[0100] In this embodiment, each transaction data indicates first transaction data indicating a request to sell electricity, second transaction data indicating a request to buy electricity, and third transaction data indicating a matching result of electricity trading, which will be described later. Also, each transaction data indicates fourth transaction data indicating the result of electricity trading for selling electricity, and fifth transaction data indicating the result of electricity trading for buying electricity.

[0101] FIG. 7B is an explanatory diagram showing the data structure of the transaction data.

[0102] Transaction data D1 shown in Figure 7B is an example of the first to fifth transaction data. Transaction data D1 includes an address P1 indicating the holder, an address P2 indicating the recipient, and an electronic signature P3 generated by signing the hash values ​​of addresses P1 and P2 with the holder's signature key. When new transaction data is generated, address P1 is left blank.

[0103] <Synchronization unit 214> The synchronization unit 214 synchronizes the blocks of the blockchain or the transaction data among the multiple authentication servers (authentication servers 200a to 200c).

[0104] More specifically, when the transaction data verification unit 212 verifies the authenticity of the transaction data acquired from the house 100a, the synchronization unit 214 transfers a copy of the transaction data to the other authentication servers 200b and 200c. The multiple authentication servers synchronize the blockchain transaction data on a peer-to-peer basis. The synchronization unit 214 then records the synchronized blockchain transaction data in the recording unit 216.

[0105] For example, when the synchronization unit 214 receives first transaction data indicating a request to sell electricity or second transaction data indicating a request to buy electricity and verifies the legitimacy, it transfers the first or second transaction data to the other authentication servers 200b and 200c and records the verified transaction data in the recording unit 216. Furthermore, when the synchronization unit 214 receives transaction data from the other authentication servers 200b and 200c, it records the transaction data in the recording unit 216.

[0106] <Transaction Generation Unit 215> The transaction generation unit 215 matches the energy transaction by comparing the energy selling amount information and the first timestamp recorded in the distributed ledger of the storage device 201a with the energy purchasing amount information and the second timestamp. When the energy transaction is matched, the transaction generation unit 215 generates third transaction data including a first blockchain address indicating the energy seller and a second blockchain address indicating the energy buyer with whom the energy transaction is matched, and the amount of energy traded in the energy transaction. When the energy transaction is matched, the transaction generation unit 215 may notify the first power facility and the second power facility that the energy transaction has been completed.

[0107] In this embodiment, the transaction generation unit 215 performs matching of an electricity buying and selling transaction by comparing a power selling list consisting of a plurality of power selling requests recorded in the recording unit 216 with a power buying list consisting of power buying requests. When matching is established, the transaction generation unit 215 generates third transaction data indicating the matching result of the electricity transaction and records it in the recording unit 216.

[0108] FIG. 8A is a diagram showing an example of a power selling list according to the present embodiment. FIG. 8B is a diagram showing an example of a power purchasing list according to the present embodiment. As shown in FIG. 8A, the power selling list includes a blockchain address, a date on which power can be sold, the amount of power that can be sold on that date, the unit price of the power sale, and a group signature. As such, each row of the power selling list includes a first blockchain address, a first timestamp indicating a first date and time on which power can be sold, and a first electronic signature linked to a first user. Also, as shown in FIG. 8B, the power purchasing list includes a blockchain address, a date on which power can be purchased, the amount of power that can be purchased on that date, the unit price of the power purchase, and a group signature. As such, each row of the power purchasing list includes a second blockchain address, a second timestamp indicating a second date and time on which power can be purchased, and a second electronic signature linked to a second user.

[0109] The transaction generation unit 215 performs matching by referring to the available dates and amounts of electricity sold in the electricity selling list as shown in Fig. 8A and the dates and amounts of electricity purchased in the electricity purchasing list as shown in Fig. 8B. For example, Fig. 8A records that blockchain address "0x03547921" wishes to sell electricity in an amount of "20 kWh" at a unit price of "20 yen" from the date "13:00 on December 15, 2017." On the other hand, Fig. 8B records that blockchain address "0x04587463" wishes to purchase electricity in an amount of "10 kWh" at a unit price of "20 yen" from the date "13:30 on December 15, 2017." From this, the transaction generation unit 215 determines that an electricity transaction has been established from blockchain address "0x03547921" to blockchain address "0x04587463" on the date "13:30, December 15, 2017" for a transaction volume of "10 kWh" at a unit price of "20 yen." When an electricity transaction is established, the transaction generation unit 215 generates transaction data indicating the matching result of the electricity transaction, including the blockchain addresses of the electricity seller and the electricity buyer, the date, the transaction volume, and the unit price, and records this in the recording unit 216.

[0110] Fig. 8C is a diagram showing an example of an energy transaction list showing the matching results of an energy transaction performed by the transaction generation unit 215 according to this embodiment. The energy transaction list shown in Fig. 8C shows the energy seller address, which is the blockchain address of the energy seller, the energy buyer address, which is the blockchain address of the energy buyer, the date, the energy transaction volume, and the unit price. The energy transaction list also includes a signature of the authentication server 200a, but this is not shown here. As such, each line of the energy transaction list includes a first blockchain address indicating the energy seller and a second blockchain address indicating the energy buyer with whom matching for an energy transaction has been achieved, as well as the amount of energy traded in the energy transaction.

[0111] The transaction generation unit 215 generates transaction data indicating the matching result of the energy transaction, including the information shown in the row of the energy transaction list in Fig. 8C, and records the transaction data in the recording unit 216. After generating the transaction data indicating the matching result of the energy transaction, the transaction generation unit 215 notifies the residence 100a, etc., which are conducting the energy transaction, of the energy transaction result indicating the details of the energy transaction. Note that the transaction generation unit 215 may periodically broadcast the energy transaction result, or may notify each of the residences which are conducting the energy transaction if they can be identified by their blockchain addresses.

[0112] <Recording Unit 216> The recording unit 216 records the transaction data of the blockchain in blocks in the storage device 201a. The storage device 201a may be configured inside the recording unit 216, or may be configured outside the authentication server 200a as shown in FIG. 1. This transaction data is the above-mentioned first transaction data indicating a request to sell electricity, second transaction data indicating a request to buy electricity, and third transaction data indicating the matching result of the electricity transaction. Furthermore, this transaction data may be fourth transaction data indicating the result of the electricity transaction for selling electricity, and fifth transaction data indicating the result of the electricity transaction for buying electricity.

[0113] <Communications Department 217> The communication unit 217 communicates with two or more residences 100a, etc., other authentication servers 200b, 200c, and the service server 300. More specifically, the communication unit 217 is a communication interface that communicates with two or more residences 100a, etc., other authentication servers 200b, 200c, and the service server 300. Communication with the two or more residences 100a, etc. and the service server 300 may be performed using TLS. In this case, an encryption key for TLS communication may be held in the communication unit 217.

[0114] Next, the service server 300 will be described.

[0115] [1.5 Configuration of the service server 300] FIG. 9 is a block diagram showing the functional configuration of service server 300 according to this embodiment.

[0116] As shown in Fig. 9, service server 300 includes key management unit 311, signature disclosure unit 312, incentive management unit 313, recording unit 314, and communication unit 315. Service server 300 can be realized by a processor executing a predetermined program using a memory. Each component will be described below.

[0117] <Key management section 311> The key management unit 311 generates and manages a group signature key based on an application from a user, such as the residence 100a, who has registered for the service. For example, the key management unit 311 generates a group signature key assigned to a group to which a first user and a second user belong. In this embodiment, the key management unit 311 generates a group signature private key used to generate a first digital signature and transmits it to the first power equipment. The key management unit 311 also generates a group signature private key used to generate a second digital signature and transmits it to the second power equipment. The key management unit 311 also distributes a public key, which is a signature verification key for the group signature, to multiple authentication servers. The key management unit 311 also generates a group signature disclosure key and records it in the recording unit 314.

[0118] More specifically, the key management unit 311 generates a group signature key assigned to a first group to which multiple users including the first user belong, and generates a group signature key assigned to a second group to which multiple users including the second user belong.

[0119] The key management unit 311 also generates a private key for the group signature used to generate the first digital signature, transmits it to the first power equipment, and distributes the public key, which is the signature verification key for the group signature assigned to the first group, to multiple authentication servers. The key management unit 311 also generates a private key for the group signature used to generate the second digital signature, transmits it to the second power equipment, and distributes the public key, which is the signature verification key for the group signature assigned to the second group, to multiple authentication servers.

[0120] In other words, the key management unit 311 transmits the generated signature generation key for the group signature to the user of the subscribed residence 100a, etc. The key management unit 311 also transmits the generated signature verification key for the group signature to the authentication server 200a, etc. The key management unit 311 records the generated signature disclosure key in the recording unit 314.

[0121] <Signature Disclosure Unit 312> The signature disclosing unit 312 references the distributed ledger of one authentication server and acquires the transaction data. The signature disclosing unit 312 discloses the group signature included in the acquired transaction data and identifies the user who issued the group signature.

[0122] In this embodiment, signature disclosing unit 312 sends a request to authentication server 200a or the like to refer to transaction data indicating the results of the energy trading of the energy sale, and receives the contents of the distributed ledger, such as a block containing the transaction data. Signature disclosing unit 312 discloses the group signature included in the received transaction data and identifies the user who sold the energy. This is a process that is possible only in service server 300 due to the characteristics of the group signature described above. Then, signature disclosing unit 312 notifies the incentive management unit of user information indicating the identified user.

[0123] <Incentive Management Department 313> After paying the incentive to the identified user, the incentive management unit 313 notifies the user that the incentive has been paid.

[0124] In this embodiment, upon receiving user information from signature disclosure unit 312, incentive management unit 313 notifies the identified user of an incentive. The incentive may be paid by transferring cash, by paying energy trading points, or by using virtual currency that utilizes blockchain technology. The incentive may also be paid as a discount on other energy transactions or product purchases. Note that when the incentive is paid in virtual currency, incentive management unit 313 may make the payment without disclosing user information from signature disclosure unit 312, i.e., without disclosing the group signature.

[0125] <Recording Unit 314> The recording unit 314 records the signature generation key, signature verification key, and signature disclosure key of the group key generated by the key management unit 311.

[0126] <Communications Department 315> The communication unit 315 communicates with two or more residences 100a, etc. and the authentication servers 200a, 200b, and 200c. More specifically, the communication unit 315 is a communication interface that communicates with two or more residences 100a, etc. and the authentication servers 200a, 200b, and 200c. Communication between the two or more residences 100a, etc. and the authentication servers 200a, 200b, and 200c may be performed using TLS. In this case, an encryption key for TLS communication may be held in the communication unit 315.

[0127] [1.6 Registration process between service server and home] Next, a description will be given of the service registration process between the service server 300, the residence 100a, etc., and the authentication server 200a, etc. Here, as an example, a case will be described in which a user of each residence applies for a service to the service server 300 using the controller 101 in the residence 100a, etc.

[0128] FIG. 10 is a sequence diagram showing the service registration process between the service server 300, the house 100a or the like, and the authentication server 200a or the like according to this embodiment.

[0129] First, in step S101, the user of residence 100a transmits application information, which is information for applying for the energy trading service, to service server 300. Similarly, in step S102, the user of residence 100b transmits application information to service server 300. Furthermore, in step S103, the user of residence 100c transmits application information to service server 300. In this way, the users of each residence apply for the service by transmitting application information for the service from their respective homes to service server 300.

[0130] Next, in step S104, upon receiving the application information from each residence, service server 300 generates a group signature key based on the application information. Specifically, service server 300 generates a user-specific signature generation key, which is a private key for signing the group signature, for each residence based on the application information, and transmits the key to each residence. Service server 300 also generates a signature disclosure key based on the application information and retains it. Service server 300 also generates a public key, which is a signature verification key for the group signature, based on the application information, and transmits the signature verification key to authentication server 200a, etc.

[0131] Next, in step S105, the user of residence 100a receives and registers a user-specific signature generation key from service server 300. Similarly, in step S106, the user of residence 100b receives and registers a user-specific signature generation key from service server 300. Also, in step S107, the user of residence 100c receives and registers a user-specific signature generation key from service server 300. In this way, each residence receives and registers a private key for signing a group signature from service server 300.

[0132] Next, in step S108, authentication server 200a or the like receives the public key, which is the signature verification key for the group signature, from service server 300 and registers it.

[0133] [1.7 Overall sequence of electricity trading between a home and an authentication server] Next, a sequence of an energy transaction between the home 100a, etc. and the authentication server 200a, etc. will be described. Fig. 11 is an overall sequence diagram of an energy transaction between the home 100a, etc. and the authentication server 200a, etc. according to this embodiment. Each process will be described later.

[0134] First, in step S200, a power sale request process is performed between, for example, the house 100a and the authentication servers 200a, 200b, and 200c.

[0135] Next, in step S300, a power purchase request process is performed between, for example, the house 100c and the authentication servers 200a, 200b, and 200c.

[0136] Next, in step S400, when matching for an energy transaction is established in one of the authentication servers 200a, 200b, and 200c, an energy transaction process is carried out based on the established energy transaction.

[0137] Either the power sale request process in step S200 or the power purchase request process in step S300 may be executed first, and they are executed irregularly. The power trading process in step S400 may be executed every time the power sale request process in step S200 or the power purchase request process in step S300 is executed, or may be executed periodically.

[0138] [1.7.1 Power sales request processing between the home and the authentication server] Next, the power sale request process between the house 100a, etc. and the authentication server 200a, etc. will be described. Fig. 12 is a sequence diagram of the power sale request process between the house 100a, etc. and the authentication server 200a, etc. according to this embodiment. In Fig. 12, the house 100a will be described as selling power as an example, but this is not limiting. The same power sale request process sequence will also be used for other houses, such as the house 100b.

[0139] First, in step S201, the controller 101 or the user of the residence 100a inputs information requesting the sale of electricity if they wish to sell electricity. For example, the request to sell electricity is made when the user of the residence 100a is out and there are no plans to use electricity at the residence 100a. Also, for example, the request to sell electricity is made when the electricity generated by the solar power generation system 102 at the residence 100a becomes surplus or when it is expected that the electricity generated by the solar power generation system 102 will become surplus.

[0140] Next, in step S203, the controller 101 of the house 100a generates transaction data indicating a power sale request (hereinafter referred to as first transaction data) based on the input power sale request information. As described above, the first transaction data includes a blockchain address, a date, an amount of power sold, a unit price, and a group signature.

[0141] Next, in step S204, the controller 101 of the house 100a transmits the generated first transaction data to the authentication server 200a. Note that in the example shown in Fig. 12, the controller 101 of the house 100a transmits the generated first transaction data to the authentication server 200a, but it may also transmit it to other authentication servers 200b, 200c. The same applies when transmitting the data to other authentication servers 200b, 200c.

[0142] Next, in step S205, the authentication server 200a verifies the group signature of the first transaction data received from the residence 100a.

[0143] In step S205, if the group signature of the first transaction data is successfully verified (Y in S205), the authentication server 200a verifies the authenticity of the first transaction data received from the residence 100a (S206).

[0144] If the authenticity of the first transaction data is verified successfully in step S206 (Y in S206), the first transaction data is transferred to the other authentication servers 200b and 200c (S208). The other authentication servers 200b and 200c also verify the received first transaction data in the same manner.

[0145] In step S205, if the group signature of the first transaction data is not successfully verified (N in S205), the authentication server 200a sends a notification to that effect to the residence 100a (S207) and ends the process. Similarly, in step S206, if the authenticity of the first transaction data is not successfully verified (N in S206), the authentication server 200a sends a notification to that effect to the residence 100a (S207) and ends the process. Steps S205 and S206 do not have to be performed in the order shown in FIG. 12, and may be performed in the reverse order.

[0146] Next, in step S209, authentication server 200a, authentication server 200b, and authentication server 200c execute a consensus algorithm. When authentication server 200a, authentication server 200b, and authentication server 200c verify that the first transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block including the first transaction data. Then, authentication servers 200a, 200b, and 200c record the block including the first transaction data in the distributed ledger of storage devices 201a, 201b, and 201c.

[0147] [1.7.2 Power purchase request processing between the home and the authentication server] Next, the power purchase request process between the house 100a, etc. and the authentication server 200a, etc. will be described. Fig. 13 is a sequence diagram of the power purchase request process between the house 100a, etc. and the authentication server 200a, etc. according to this embodiment. In Fig. 13, the house 100c will be described as selling power as an example, but this is not limiting. The same power purchase request process sequence will also be used for other houses such as the house 100b.

[0148] First, in step S301, the controller 101 or the user of the residence 100c inputs information on a request to purchase electricity if the residence 100c desires to purchase electricity. For example, the electricity purchase request is made when the amount of electricity stored in the storage battery 103 is low and a large amount of electricity is expected to be used. Also, for example, the residence 100c may make a request to purchase electricity if it is cheaper to purchase surplus electricity from another residence 100a or the like than to purchase electricity from a power company.

[0149] Next, in step S303, the controller 101 of the house 100c generates transaction data indicating the power purchase request (hereinafter referred to as second transaction data) based on the input power purchase request information. As described above, the second transaction data includes a blockchain address, a date, an amount of power purchased, a unit price, and a group signature.

[0150] Next, in step S304, the controller 101 of the house 100c transmits the generated second transaction data to the authentication server 200c. Note that in the example shown in Fig. 13, the controller 101 of the house 100c transmits the generated second transaction data to the authentication server 200c, but it may also transmit it to another authentication server 200a, 200b. The same applies when transmitting it to another authentication server 200a, 200b.

[0151] Next, in step S305, the authentication server 200c verifies the group signature of the second transaction data received from the residence 100c.

[0152] In step S305, if the group signature of the second transaction data is successfully verified (Y in S305), the authentication server 200c verifies the authenticity of the second transaction data received from the residence 100c (S306).

[0153] If the verification of the authenticity of the second transaction data is successful in step S306 (Y in S306), the second transaction data is transferred to the other authentication servers 200a and 200b (S308). The other authentication servers 200a and 200b also verify the received second transaction data in the same manner.

[0154] If the verification of the group signature of the second transaction data is not successful in step S305 (N in S305), the authentication server 200c sends a notification to that effect to the residence 100c (S307) and ends the process. Similarly, if the verification of the legitimacy of the second transaction data is not successful in step S306 (N in S306), the authentication server 200c sends a notification to that effect to the residence 100c (S307) and ends the process. Steps S305 and S306 do not have to be performed in the order shown in FIG. 13, and may be performed in the reverse order.

[0155] Next, in step S309, authentication server 200a, authentication server 200b, and authentication server 200c execute a consensus algorithm. When authentication server 200a, authentication server 200b, and authentication server 200c verify that the second transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block including the second transaction data. Then, authentication servers 200a, 200b, and 200c record the block including the second transaction data in the distributed ledger of storage devices 201a, 201b, and 201c.

[0156] [1.7.3 Power trading process between the home and the authentication server] Next, the energy trading process between the house 100a, etc. and the authentication server 200a, etc. will be described. Figures 14 and 15 are sequence diagrams of the energy trading process between the house 100a, etc. and the authentication server 200a, etc. according to this embodiment. In Figure 14, as an example, the authentication server 200a performs matching of the energy trading, etc., but this is not limited to this. Other authentication servers 200b, 200c may also perform this, and the same energy trading process sequence will be followed.

[0157] First, in step S401, the authentication server 200a compares the power selling list with the power buying list. The authentication server 200a may compare the power selling list with the power buying list, that is, may perform matching periodically, or may perform matching each time an event of a power selling request or a power buying request occurs.

[0158] Next, in step S402, the authentication server 200a compares the power selling list with the power buying list to determine whether a match for the power transaction is established. More specifically, the authentication server 200a checks whether the date, amount of power, and unit price of the supplier of the blockchain address who wishes to sell power and the consumer of the blockchain address who wishes to buy power are within their respective allowable ranges. Note that, in step S402, if the authentication server 200a determines that a match for the power transaction is not established (N in S402), the authentication server 200a returns to step S401 and performs matching again.

[0159] On the other hand, in step S402, if the authentication server 200a determines that matching for the electricity trade is established (Y in S402), it generates transaction data (hereinafter referred to as third transaction data) indicating the matching result for the electricity trade (S403).

[0160] Next, in step S404, the authentication server 200a transfers the generated third transaction data to the other authentication servers 200b and 200c.

[0161] Next, in step S405, authentication server 200a, authentication server 200b, and authentication server 200c execute a consensus algorithm. When authentication server 200a, authentication server 200b, and authentication server 200c verify that the third transaction data is legitimate transaction data (i.e., legitimacy), they each generate a block including the third transaction data. Then, authentication servers 200a, 200b, and 200c record the block including the third transaction data in the distributed ledger of storage devices 201a, 201b, and 201c.

[0162] Next, in step S406, the authentication server 200a notifies the homes 100a, etc. participating in the service of the energy trading result indicating the details of the energy trading. As a notification method, the authentication server 200a may broadcast the energy trading result to the homes 100a, etc. participating in the service every time a matching for an energy trading is established, or may periodically notify each home 100a, etc. of the energy trading result.

[0163] Next, in step S407, the home 100a receives the results of the electricity trade and checks whether matching for the electricity trade has been established.

[0164] Next, in step S408, the home 100a transmits power to the power network 500 based on the result of the power trade.

[0165] On the other hand, in step S409, the home 100c receives the results of the electricity trade and checks whether matching for the electricity trade has been established.

[0166] Next, in step S410, the home 100c uses power from the power network 500 based on the result of the power trade.

[0167] Next, as shown in FIG. 15, in step S411, after transmitting the power to the power network 500, the house 100a generates transaction data (hereinafter referred to as fourth transaction data) indicating the power trading result of the power sale, including information on the power transmission.

[0168] Next, in step S412, the residence 100a transmits the generated fourth transaction data to the authentication server 200a. As described above, the fourth transaction data also includes a group signature, i.e., a first digital signature, generated using a signature generation key managed by the user of the residence 100a.

[0169] Next, in step S413, the authentication server 200a verifies the received fourth transaction data. More specifically, the authentication server 200a verifies the group signature of the fourth transaction data and the legitimacy of the fourth transaction data. The authentication server 200a also verifies whether the fourth transaction data is consistent with the energy trading result included in the third transaction data.

[0170] In step S413, if the verification of the fourth transaction data is not successful (N in S413), the authentication server 200a sends an error notification to the house 100a indicating that the verification of the fourth transaction data was not successful (S414), and terminates the processing.

[0171] On the other hand, if the authentication server 200a successfully verifies the fourth transaction data in step S413 (Y in S413), it transfers the fourth transaction data to the other authentication servers 200b and 200c (S415).The other authentication servers 200b and 200c also similarly verify the received fourth transaction data.

[0172] Furthermore, in step S416, after using the power from the power network 500, the home 100c generates transaction data (hereinafter referred to as fifth transaction data) indicating the result of the power purchase transaction, including information on the power usage.

[0173] Next, in step S417, the home 100c transmits the generated fifth transaction data to the authentication server 200c. As described above, the fifth transaction data also includes a group signature, i.e., a second digital signature, generated using a signature generation key managed by the user of the home 100c.

[0174] Next, in step S418, the authentication server 200c verifies the received fifth transaction data. More specifically, the authentication server 200c verifies the group signature of the fifth transaction data and the legitimacy of the fifth transaction data. The authentication server 200c also verifies whether the fifth transaction data is consistent with the energy trading result included in the third transaction data.

[0175] In step S418, if the verification of the fifth transaction data is not successful (N in S418), the authentication server 200c sends an error notification to the house 100c indicating that the verification of the fifth transaction data was not successful (S419), and terminates the processing.

[0176] On the other hand, if the authentication server 200c successfully verifies the fifth transaction data in step S418 (Y in S418), it transfers the fifth transaction data to the other authentication servers 200a and 200b (S420). The other authentication servers 200a and 200b also similarly verify the received fifth transaction data.

[0177] Next, in step S421, authentication server 200a, authentication server 200b, and authentication server 200c execute a consensus algorithm. If authentication server 200a, authentication server 200b, and authentication server 200c verify that the received fourth transaction data is legitimate (i.e., validity), they each generate a block containing the fourth transaction data. Then, authentication server 200a, 200b, and 200c record the block containing the fourth transaction data in the distributed ledgers of storage devices 201a, 201b, and 201c. Similarly, authentication server 200a, authentication server 200b, and authentication server 200c verify that the received fifth transaction data is legitimate (i.e., validity), they each generate a block containing the fifth transaction data. Then, authentication server 200a, 200b, and 200c record the block containing the fifth transaction data in the distributed ledgers of storage devices 201a, 201b, and 201c. The block containing the fourth transaction data and the block containing the fifth transaction data may be connected to a blockchain different from the blocks containing the first to third transaction data and recorded in a distributed ledger.

[0178] [1.8 Incentive payment processing between the home and the service server] Next, the sequence of incentive payment between the house 100a etc. and the service server 300 will be described.

[0179] Fig. 16 is a sequence diagram of the incentive payment process between the house 100a etc. and the service server 300 according to this embodiment. In Fig. 16, an example is explained in which an incentive is paid to the house 100a, but this is not limiting and the same applies to other houses such as the house 100b.

[0180] First, in step S501, the service server 300 generates a request to reference the distributed ledger, i.e., a request to reference the fourth transaction data indicating the results of the electricity transaction for selling electricity to be recorded in the distributed ledger. The service server 300 may generate the reference request periodically, or may generate the reference request after receiving a notification from the authentication server 200a or the like that an electricity transaction has occurred.

[0181] Next, in step S502, the service server 300 transmits the generated reference request to the authentication server 200a. In the example shown in Fig. 16, the service server 300 transmits the reference request to the authentication server 200a, but this is not limiting. The service server 300 may also transmit the reference request to another authentication server such as 200b. The same applies when the reference request is transmitted to another authentication server 200b, 200c.

[0182] Next, in step S503, the authentication server 200a transmits a block including the fourth transaction data. Note that the authentication server 200a may transmit the entire contents of the distributed ledger including the fourth transaction data, or, if the contents have been transmitted previously, may transmit only the difference from the previous transmission.

[0183] Next, in step S504, service server 300 reveals the group signature included in the fourth transaction data and identifies the user of home 100a, who is the user of the home that sold the electricity.

[0184] Next, in step S505, the service server 300 pays an incentive to the identified user.

[0185] Next, in step S506, the service server 300 pays the incentive to the identified user and then transmits a notification that the incentive has been paid. Note that the service server 300 may also transmit a notification that the incentive has been paid to the home 100a of the identified user.

[0186] [1.9 Effects, etc.] As described above, according to the energy trading system 10 etc. of the embodiment, the signature included in the transaction data from a residence is a group signature. As a result, even if the power sale request list and the power purchase request list are made public, the homes included in the power sale request list and the power purchase request list cannot be identified from the published blockchain transaction data, thereby protecting the privacy of the residential users. In this way, the energy trading system 10 etc. of the embodiment can prevent the leakage of privacy information.

[0187] Furthermore, according to the energy trading system 10 etc. according to the embodiment, only the service server can disclose the group signature, so that it is also possible to pay an incentive to a house that has conducted an energy trade or to a user thereof.

[0188] Furthermore, according to the energy trading system 10 etc. relating to the embodiments, even if a fraudulent user obtains the contents of the publicly disclosed blockchain distributed ledger and publishes a list of consumers who are buying electricity, even though the fraudulent user does not need electricity, the consumers who are buying electricity cannot be identified. Therefore, more electricity than necessary will not be sent to consumers who are buying electricity, causing instability in the electricity system. In other words, according to the energy trading system 10 etc. relating to the embodiments, even if the contents of the distributed ledger that records blockchain transaction data are leaked from the authentication server, it is possible to continue energy trading safely while protecting the privacy of users.

[0189] Furthermore, according to the energy trading system 10 etc. according to the embodiment, energy trading is performed using blockchain, so that tampering with the energy trading can be prevented, and incentives can be paid correctly.

[0190] [2. Other variations] Although the present disclosure has been described based on the above-described embodiments, it goes without saying that the present disclosure is not limited to the above-described embodiments. The following cases are also included in the present disclosure.

[0191] (1) In the above embodiment, the authentication server 200a etc. and the service server 300 are described as separate devices, but the authentication server 200a etc. and the service server 300 may be the same device.

[0192] (2) In the above embodiment, when the authentication server 200a or the like fails to verify the transaction data, the authentication server 200a or the like notifies the residence 100a or the like, but the service server 300 may also be notified.

[0193] (3) In the above embodiment, the service server 300 sends a notification that the incentive has been paid after the incentive has been paid, but it may also generate transaction data after the incentive has been paid and record it in the authentication server. This transaction data may include the blockchain address to which the incentive has been paid, information indicating the content of the incentive, and the signature of the service server.

[0194] (4) If the authentication server 200a or the like matches a request to sell electricity with a request to buy electricity but the electricity transaction is not concluded, the request to sell electricity and / or the request to buy electricity may be made again. This makes it possible to reset the time and the electricity unit price for the request to sell electricity and the request to buy electricity, and to re-determine whether the electricity transaction can be concluded.

[0195] (5) When electricity is purchased in response to a power purchase request, the purchasing user may pay the electricity trading service company directly, or may pay with points or virtual currency earned from previous electricity sales.

[0196] (6) In the above embodiment, the service server 300 pays the incentive after the energy trading process, but the incentive may be paid to the user of the home that sold the energy after the payment process from the user of the home that purchased the energy. Also, the user of the home that purchased the energy may pay the incentive directly to the blockchain address of the user of the home that sold the energy.

[0197] (7) In the above embodiment, the authentication server 200a or the like determines whether an energy transaction can be concluded, but this is not limited to this. A program for determining whether an energy transaction can be concluded may be implemented in advance in the authentication server 200a using a smart contract function of a blockchain, so that the determination of whether an energy transaction can be concluded may be made automatically.

[0198] (8) In the above embodiment, the user inputs the unit prices for selling and purchasing electricity, but this is not limited to this. The service server 300 may set the unit prices for selling and purchasing electricity and allow the user to select whether or not to accept the price. In addition, the unit prices for selling and purchasing electricity may change depending on the time of day.

[0199] (9) In the above embodiment, the authentication server 200a, etc., matches energy transactions using time and unit price, but this is not limited to this. The authentication server 200a, etc. may make a determination based on the ease of transmitting energy in the energy network 500. For example, when a home selling energy passes through the energy network 500 to a home buying energy, energy transactions may be performed starting with the closest home. The authentication server 200a, etc. may also prioritize matching with homes that experience less energy loss in transmission through the energy network. This can reduce energy loss across the energy trading service as a whole.

[0200] (10) A home that sells electricity may issue a token for the right to use electricity, and a user of a home that buys electricity may purchase the token. This allows direct energy trading between users.

[0201] (11) In the above embodiment, the user requests the power sale process, but this is not limited to this. The controller 101 may automatically request the power sale when the power generated by the solar power generation system 102 exceeds the power storage capacity of the storage battery 103 or a set threshold. The threshold may be set by the user, may be set in advance, or may be set to the maximum amount of power used in the past by the house 100a, etc. This reduces the user's effort in the power sale process.

[0202] (12) In the above embodiment, transaction data is generated when the house 100a transmits power. However, transaction data may also be generated when the house uses power generated by the solar power generation system 102. This makes it possible to manage the power generated by the solar power generation system 102. Furthermore, when the power generated by the solar power generation system 102 is used, incentive points may be issued by the service server 300.

[0203] (13) The present disclosure also includes a data structure used for blocks recorded as a blockchain in the energy trading system 10 of the above-described embodiment. More specifically, the data structure of the present disclosure includes a blockchain address included in a block generated using a user's private key, power sales amount information indicating the amount of power that the first power facility can sell, a timestamp indicating the date and time when the power can be sold, and a group signature linked to the user and assigned to a group to which the user belongs. The power sales amount information and the timestamp included in the data structure of the present disclosure are used for matching energy transactions by comparing them with power purchase amount information indicating the amount of power that the second power facility can purchase and the timestamp indicating the date and time when the power can be purchased.

[0204] (14) Each device in the above embodiments is specifically a computer system comprising a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or hard disk unit. Each device achieves its function by the microprocessor operating in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate commands to a computer to achieve a predetermined function.

[0205] (15) In each of the above embodiments, some or all of the constituent elements may be configured from a single system LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is recorded in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.

[0206] Furthermore, each of the components constituting each of the above devices may be individually integrated into a single chip, or some or all of them may be integrated into a single chip.

[0207] Although we refer to it as a system LSI here, it may also be called an IC, LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the method of integration is not limited to LSI, but may be realized using dedicated circuits or general-purpose processors. It is also possible to use FPGAs (Field Programmable Gate Arrays), which can be programmed after LSI manufacturing, or reconfigurable processors, which allow the connections and settings of circuit cells within LSI to be reconfigured.

[0208] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that such technology may be used to integrate functional blocks. The application of biotechnology, etc. is also a possibility.

[0209] (16) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates according to a computer program. The IC card or module may be tamper-resistant.

[0210] (17) The present disclosure may be embodied as the methods described above, a computer program for implementing these methods on a computer, or a digital signal comprising the computer program.

[0211] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.

[0212] Furthermore, the present disclosure may involve transmitting the computer program or the digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.

[0213] The present disclosure may also be a computer system having a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.

[0214] The program or the digital signal may also be implemented by another independent computer system by recording it on the recording medium and transferring it, or by transferring it via the network or the like.

[0215] (18) The above-described embodiments and modifications may be combined with each other. [Industrial Applicability]

[0216] The present disclosure enables power trading to be carried out while protecting privacy in an energy trading system by transmitting transaction data of power information including a group signature from a residence and managing the data in an authentication server. [Explanation of symbols]

[0217] 100a, 100b, 100c Housing 101 Controller 102 Solar power generation 103 Storage battery 104 Power Meter 110 Communication Network 111 Power Network 1011 Input section 1012 Transaction Data Generation Unit 1013 Signature generation section 1014 control section 1015 Recording section 1016 Communications Department 200a, 200b, 200c authentication servers 211 Signature Verification Unit 212 Transaction Data Verification Unit 213 Block Generation Unit 214 Synchronization Unit 215 Transaction Generation Unit 216 Recording Department 217 Communications Department 300 Service Server 311 Key Management Department 312 Signature Disclosure Section 313 Incentive Management Department 314 Recording Department 315 Communications Department 400 Communication Network 500 Power Network

Claims

1. A control method executed by a server, comprising: acquiring, from a first power facility, first transaction data including an amount of transmitted power transmitted from the first power facility to a second power facility; acquiring second transaction data from the second power facility, the second transaction data including an amount of power received by the second power facility from the first power facility; verifying whether the amount of transmitted power or the amount of received power is consistent with the amount of power traded between the first power facility and the second power facility; If the verification is successful, recording the first transaction data or the second transaction data in a distributed ledger; Control method.

2. the first power facility is used by a first user; the first transaction data further includes a first group signature assigned to a first group to which a plurality of users including the first user belong; The verifying step further includes verifying the first group signature. The control method according to claim 1 .

3. the second power facility is used by a second user; the second transaction data further includes a second group signature assigned to a second group to which a plurality of users including the second user belong; The verifying step further includes verifying the second group signature. The control method according to claim 1 .

4. acquire a power sale request including an amount of power that the first power facility can sell and a power purchase request including an amount of power that the second power facility can purchase; When a match between the power selling request and the power purchasing request is established, a match including the amount of power to be traded is established. transmitting the result of the checking to the first power facility; The first power facility transmits power equivalent to the traded power amount to the second power facility. The control method according to any one of claims 1 to 3.

5. If a match between the request to sell electricity and the request to buy electricity is established, third transaction data including the amount of electricity traded is generated; recording the third transaction data in the distributed ledger; In the verification, it is verified whether the amount of transmitted power or the amount of received power is consistent with the amount of traded power recorded in the distributed ledger. The control method according to claim 4.

6. Matching the electricity sales request and the electricity purchase request using a smart contract function of the distributed ledger; The control method according to claim 4.

7. transmitting the first transaction data or the second transaction data to one or more servers that hold the distributed ledger; Executing a consensus algorithm with the one or more servers to generate a block including the first transaction data or the second transaction data; The first transaction data or the second transaction data is recorded in the distributed ledger by recording the block in the distributed ledger. The control method according to any one of claims 1 to 6.

8. If the verification is unsuccessful, the first transaction data or the second transaction data is not recorded in the distributed ledger. The control method according to claim 1 .

9. the first transaction data includes a first electronic signature associated with a first user who uses the first power facility; Verifying whether the first digital signature is correct; the second transaction data includes a second electronic signature associated with a second user who uses the second power facility; Verifying whether the second digital signature is correct; If verification of whether the amount of transmitted power or the amount of received power is consistent with the amount of power traded between the first power facility and the second power facility and verification of whether the first electronic signature or the second electronic signature is correct are successful, recording the first transaction data or the second transaction data in a distributed ledger. The control method according to claim 1 .

10. a first power facility; a second power facility; An energy trading system comprising: a first server communicatively connected to the first electric power facility and the second electric power facility via a network; The first server acquiring, from a first power facility, first transaction data including an amount of transmitted power transmitted from the first power facility to a second power facility; acquiring second transaction data from the second power facility, the second transaction data including an amount of power received by the second power facility from the first power facility; The amount of transmitted power or the amount of received power is determined based on the amount of power transmitted from the first power facility and the amount of power received from the second power facility. Verify whether there is any inconsistency with the amount of electricity traded in the market. If the verification is successful, recording the first transaction data or the second transaction data in a distributed ledger; Power system.

11. A program for causing a computer to execute the control method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Electric power interchange system

    JP2011101534A

  • Autonomous peer-to-peer energy networks operating on a blockchain

    US20180130130A1

  • Supply system and method for operating a supply system

    WO2017032541A1