SoS (System of Systems) and method
The horizontal SoS facilitates information exchange and integrated service provision across multiple industrial domains by managing server devices, addressing the challenge of information exchange barriers and enhancing resilience and operational efficiency.
Patent Information
- Application Number
- JP2021034527
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-03-04
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2041-03-04
AI Technical Summary
Existing systems face challenges in smoothly exchanging information between multiple server devices belonging to different industrial fields, hindering the provision of high-quality services, particularly in the context of personal information use for public interest purposes.
A horizontal System of Systems (SoS) manages server devices across various industrial domains, enabling the transmission of personal information without prior consent, subject to terms of use determined by the SoS, facilitating information exchange and service integration.
Enables seamless information exchange and integrated service provision across diverse industrial domains, enhancing resilience and operational efficiency by optimizing and controlling geographically dispersed systems.
Smart Images

Figure 0007778485000001 
Figure 0007778485000002 
Figure 0007778485000003
Abstract
Description
[Technical Field]
[0001] FIELD OF THE INVENTION Embodiments of the present invention relate to an SoS and a method. [Background technology]
[0002] In recent years, technologies have been developed that analyze data collected in the real world (physical space) in cyberspace and utilize the results of that analysis in various industrial fields.
[0003] Furthermore, in such technology, it is considered that higher quality services can be provided by deploying at least one server device called a horizontal SoS (System of Systems) that oversees multiple systems (server devices) belonging to different industrial fields, and by comprehensively utilizing information generated based on data collected in the multiple systems.
[0004] However, as mentioned above, there are cases where information cannot be exchanged smoothly between multiple systems (server devices) belonging to various industrial fields, which may result in the inability to provide high-quality services. For example, even under the current Personal Information Protection Act, the use of personal information for public interest purposes is considered permissible in certain cases, but to date, such use has not been actively carried out, and the current situation is one in which the use of personal information to bring benefits to the entire nation, such as solving social issues, has not been sufficiently promoted. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Patent No. 6612450 Summary of the Invention [Problem to be solved by the invention]
[0006] Therefore, the problem to be solved by one embodiment of the present invention is to provide an SoS and method that enables smooth exchange of information between multiple server devices belonging to various industrial fields. [Means for solving the problem]
[0007] According to an embodiment, a method is provided that is executed by a horizontal SoS (System of Systems) that manages a first server device belonging to a first industrial domain and a second server device belonging to a second industrial domain different from the first industrial domain. The method includes: when the horizontal SoS confirms that a first condition is satisfied, the horizontal SoS determines a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; and when the first server device is determined as the first system and the second server device is determined as the second system, the horizontal SoS transmits information to the first server device and the second server device to permit transmission of first information from the first server device to the second server device. The first information includes personal information about natural persons collected by the first server device from one or more first edges. The transmission of the first information is permitted when a second condition is satisfied, even if the consent of the natural persons is not obtained. The horizontal SoS transmits information for specifying the terms of use of the first information to at least one of the first server device and the second server device, where the terms of use of the first information are determined by the horizontal SoS and may differ from the terms of use previously agreed upon by the natural person. [Brief explanation of the drawings]
[0008] [Figure 1] FIG. 1 is a diagram showing an example of a network configuration of an integrated system according to an embodiment. [Figure 2] FIG. 1 is a diagram showing an example of a horizontal SoS system configuration. [Figure 3] A diagram for explaining the relationship between the edge, CPS server, and Mizuchoku SoS. [Figure 4] FIG. 10 is a diagram for explaining an example of the operation of the integrated system. [Figure 5] FIG. 1 is a diagram showing an example of a system configuration for exchanging information. [Figure 6]10 is a flowchart showing an example of a processing procedure of the integrated system when an increased risk of a socially difficult situation is detected. [Figure 7] FIG. 10 is a diagram showing an example of a real-time hazard map. [Figure 8] A diagram for explaining a mobile phone management system connected to a resilience SoS. [Figure 9] 10 is a flowchart showing an example of a processing procedure of the integrated system when a flood actually occurs. [Figure 10] 10 is a flowchart showing an example of a processing procedure for information transmission permission processing. [Figure 11] 10 is a flowchart showing another example of the processing procedure of the information transmission permission process. [Figure 12] A diagram for specifically explaining the operation of the integrated system when personal information of users held by the mobile phone management system is used to provide resilience solutions. [Figure 13] FIG. 10 is a diagram for explaining a case where personal information of a user is transmitted to a medical system. [Figure 14] This diagram specifically explains the operation of the integrated system when personal information of users held by the mobility SoS is used to provide resilience solutions. [Figure 15] FIG. 10 is a diagram for explaining a case where image data is transmitted from a mobility SoS to a river, levee, and dam management CPS server. [Figure 16] FIG. 10 is a diagram for explaining a case where EV information is transmitted from a mobility SoS to a VPP power transmission and distribution CPS server. [Figure 17] A diagram to explain the overview of digital twins. [Figure 18] A diagram showing that the resilience SoS has storage, browsing, and automatic deletion functions. [Figure 19] FIG. 10 is a diagram showing an example of the data structure of basic information included in permission content information. [Figure 20] FIG. 10 is a diagram showing an example of the data structure of detailed information included in permission content information. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, embodiments will be described with reference to the drawings. 1 shows an example of a network configuration of an integrated system according to this embodiment. As shown in FIG. 1, the integrated system includes a plurality of edges (edge terminals) 11 and 12, and a plurality of server devices 21 and 22.
[0010] Each of the plurality of edges 11 and 12 is communicatively connected to a server device 21 or 22 corresponding to the edge 11 or 12. Each of the plurality of edges 11 or 12 is configured to collect data measured periodically by various sensors installed (mounted) on the edge 11 or 12, for example, and transmit the collected data to the server device 21 or 22 corresponding to the edge 11 or 12.
[0011] Each of the plurality of server devices 21 and 22 is configured to provide various services using data transmitted from the edges 11 and 12 corresponding to the server devices 21 and 22. Each of the plurality of server devices 21 and 22 is also configured to control the operation of the edges 11 and 12 so that desired data can be received from the edges 11 and 12 corresponding to the server devices 21 and 22.
[0012] In the example shown in FIG. 1, it is shown that each of the plurality of edges 11 corresponds to each of the plurality of server devices 21, and each of the plurality of edges 12 corresponds to each of the plurality of server devices 22.
[0013] Each of the multiple edges 11 and 12 is an electronic device incorporating a control unit that controls the operation of the edge in accordance with the content of communication with, for example, the multiple server devices 21 and 22. As each of the multiple edges 11 and 12, various electronic devices are envisioned, such as an electric vehicle (EV), a smartphone, a machine tool, a battery control unit, a control unit for a renewable energy power generation facility, an infrastructure monitoring device, etc. For the sake of convenience of explanation, FIG. 1 shows one edge for one server device, but it is common for many edges (i.e., a group of edges) to be connected to one server device.
[0014] Furthermore, each of the multiple server devices 21 and 22 in this embodiment is referred to as a CPS (Cyber Physical System) server. CPS refers to a mechanism for creating added value by collecting data in real space (physical) and analyzing the results using digital technology in cyberspace (i.e., information generated from the collected data) and feeding the results back to the real space. Note that the CPS server may have a function called a digital twin, which accumulates data received from an edge or the like corresponding to the CPS server and digitally reproduces the real space (i.e., cyberspace). In the following description, for convenience, server devices such as the multiple server devices 21 and 22 will be referred to as CPS servers.
[0015] Here, it is assumed that each of the multiple edges 11 and 12 can communicate directly with each of the multiple server devices 21 and 22, but each of the multiple edges 11 and 12 and each of the multiple server devices 21 and 22 may also be able to communicate via other devices.
[0016] In this embodiment, for example, it is assumed that the above-mentioned multiple CPS servers 21 and multiple CPS servers 22 belong to different industrial domains. In the example shown in Fig. 1, it is shown that the multiple CPS servers 21 belong to a first industrial domain, and the multiple CPS servers 22 belong to a second industrial domain.
[0017] In this embodiment, an "industrial domain" may refer to any domain that can be classified as a single industry. For example, medical care, education, industry, welfare, and legal affairs may each be considered an industrial domain. Furthermore, for example, connected industry's key domains, such as "smart life (healthcare through precision medicine, purchasing management using smart receipts, etc.)," "autonomous driving and mobility services (EV sharing, etc.)," "manufacturing and robotics (factory automation, smart manufacturing)," "bio / materials," and "plant and infrastructure safety," may each be considered an industrial domain. Furthermore, the above-mentioned "plant and infrastructure safety" may be divided into, for example, the energy sector and the infrastructure sector. In other words, the above-mentioned examples of industrial domains may be further subdivided into multiple industrial domains. Furthermore, some of the above-mentioned examples of industrial domains may be merged into a single industrial domain. Furthermore, the classification of each industrial domain is not limited to the above examples; industrial domains may have different definitions depending on the corporation, government, or public organization.
[0018] Specifically, for example, a first industry domain to which multiple CPS servers 21 belong may be "autonomous driving and mobility services," and a second industry domain to which multiple CPS servers 22 belong may be "plant and infrastructure security (energy sector)."
[0019] As described above, when the first industrial domain is "autonomous driving / mobility services," the multiple CPS servers 21 belonging to the first industrial domain are, for example, multiple CPS servers installed in each area where mobility services are provided. In this case, the multiple edges 11 corresponding to the multiple CPS servers 21 include EVs (electric vehicles), etc.
[0020] On the other hand, when the second industry domain is "plant and infrastructure security (energy field)," the multiple CPS servers 22 belonging to the second industry domain are, for example, a VPP (Virtual Power Plant) power generation CPS server installed for each power generation facility and a VPP power transmission and distribution CPS server installed for each area subject to power transmission and distribution. In this case, the multiple edges 12 corresponding to the multiple CPS servers 22 include control units of various power generation facilities and power meters installed in homes or buildings.
[0021] Here, the integrated system in this embodiment includes an SoS (System of Systems) that orchestrates a plurality of server devices that belong to each of the above-mentioned industrial domains.
[0022] In this embodiment, for example, each of the multiple CPS servers 21 connected to each of the multiple edges 11 is configured to be able to operate independently as a single system, and each of the multiple CPS servers 22 connected to each of the multiple edges 12 is configured to be able to operate independently as a single system, but the SoS provides functions (services) that cannot be realized by the single systems, for example, by controlling these geographically dispersed systems.
[0023] In this embodiment, "controlling multiple systems" includes one or more of the following concepts: executing a process to optimize the multiple systems as a whole, exchanging information between the multiple systems, or controlling each of the multiple systems. In other words, the process executed to control the multiple systems may be, for example, control for partial optimization in each system, from the perspective of optimizing the multiple systems as a whole controlled by the SoS. Furthermore, the process executed to control the multiple systems may be, for example, a process for realizing a function that is completely different from the function provided by each of the multiple systems being controlled.
[0024] The SoS in this embodiment is classified into a vertical SoS and a horizontal SoS depending on the number of industrial domains to which the multiple systems it manages belong.
[0025] A vertical SoS controls multiple CPS servers (systems) that belong to a single industrial domain. In the example shown in Fig. 1, a vertical SoS 31 controls multiple CPS servers 21 that belong to a first industrial domain, and a vertical SoS 32 controls multiple CPS servers 22 that belong to a second industrial domain. Although not shown in Fig. 1, the integrated system may further include a vertical SoS configured to control multiple vertical SoSs that belong to the same industrial domain, for example.
[0026] A horizontal SoS controls multiple CPS servers (systems) belonging to two or more different industrial domains. In this case, the horizontal SoS may be configured to directly control multiple CPS servers belonging to two or more industrial domains, or may be configured to control multiple vertical SoSs that control multiple CPS servers belonging to each of the two or more industrial domains. Furthermore, the horizontal SoS may be configured to indirectly control the CPS servers controlled by the vertical SoSs by controlling the vertical SoSs. In the example shown in FIG. 1, the integrated system includes a horizontal SoS 40 that controls a vertical SoS 31 that controls multiple CPS servers 21 belonging to a first industrial domain and a vertical SoS 32 that controls multiple CPS servers 22 belonging to a second industrial domain. Although not shown in FIG. 1, the integrated system may further include a horizontal SoS configured to control multiple horizontal SoSs.
[0027] In this embodiment, the multiple CPS servers 21, 22, vertical SoSs 31, 32 and horizontal SoS 40 are each realized by one or more server devices (computer resources), and may be realized, for example, by IaaS (Infrastructure as a Service), PaaS (Platform as a Service), etc.
[0028] Fig. 2 shows an example of the hardware configuration of the horizontal SoS 40 shown in Fig. 1. As shown in Fig. 2, the horizontal SoS 40 includes a CPU 40a, a nonvolatile memory 40b, a main memory 40c, and a communication device 40d. Note that Fig. 2 shows an example of a hardware structure included in a single computer, but the horizontal SoS 40 may be realized by multiple computers. The CPU 40a is a hardware processor that controls the operation of each component in the horizontal SoS 40. The CPU 40a may be a single processor or may be configured with multiple processors. The CPU 40a executes programs loaded from the nonvolatile memory 40b, which is a storage device, to the main memory 40c. These programs include an operating system (OS) and various application programs. The application programs executed by the CPU 40a in this manner include application programs for realizing various functions (and processes) provided by the horizontal SoS 40, which will be described below.
[0029] The nonvolatile memory 40b is a storage medium used as an auxiliary storage device. The main memory 40c is a storage medium used as a main storage device. Although only the nonvolatile memory 40b and the main memory 40c are shown in FIG. 2, the horizontal SoS 40 may include other storage devices, such as a hard disk drive (HDD) and a solid state drive (SSD).
[0030] The communication device 40d is a device configured to perform wired or wireless communication with an external device of the horizontal SoS 40 (for example, the vertical SoSs 31 and 32, etc.).
[0031] Although the system configuration of the horizontal SoS 40 has been described with reference to FIG. 2, the multiple CPS servers 21 and 22 and vertical SoSs 31 and 32 shown in FIG. 1 also have the same system configuration as the horizontal SoS 40.
[0032] Next, with reference to Fig. 3, an example of the relationship between the functions of the multiple edges 11 and 12, the multiple CPS servers 21 and 22, and the vertical SoSs 31 and 32 shown in Fig. 1 will be described. As shown in Fig. 1 above, the integrated system includes the multiple edges 11 and 12, the multiple CPS servers 21 and 22, and the multiple vertical SoSs 31 and 32, but for convenience, the relationship between one edge 11, one CPS server 21 corresponding to that edge 11, and the vertical SoS 31 that controls the multiple CPS servers 21 will be described here.
[0033] The edge 11 has a control function for controlling the operation of the edge 11 as a function based on the IoT (Internet of Things) perspective.
[0034] The control functions possessed by the edge 11 include a communication function for communicating with the CPS server 21, an analysis function for performing various analyses on the edge 11 side, a state change function for changing the state of the edge 11, a sensing function for measuring data using sensors installed on the edge 11, and an actuation function for operating the edge 11.
[0035] The CPS server 21 (platform) has a data function, an analysis function, and an operation function as functions based on the viewpoint of IoS (Internet of Service).
[0036] The data function of the CPS server 21 includes a master data function that stores master data related to the specifications, blueprints, maintenance history, etc. of the edge 11, and a data lake function that stores (accumulates) data received (collected) from the edge 11 via the IoT bus. Note that the data held by the CPS server 21 by the data function is data on an edge group including the edge 11 and data related to the edge group. In addition, the master data function may store data related to the usage environment of the edge 11 (or the edge group including the edge 11).
[0037] The analysis functions of the CPS server 21 include a statistical processing function that performs statistical processing to analyze data stored by the data function, a machine learning function that performs analysis using AI (Artificial Intelligence) generated by machine learning and deep learning, etc., and an optimization function that optimizes the operation of the system (edge 11 and CPS server 21).
[0038] The operation functions of the CPS server 21 include, for example, a monitoring and diagnostic function that monitors and diagnoses the operation of the edge 11, and a management function that manages the edge 11, and generate operation information for the edge 11 using data stored by the data function, data derived by the analysis function (i.e., analysis results obtained by analysis), or manually input data. The operation information includes, for example, information for operating the communication function, edge analysis function, state change function, sensing function, and actuation function included in the control function of the edge 11 described above, and is transmitted to the edge 11.
[0039] The functions of the edge 11 and the CPS server 21 described above enable the following operations to be realized. The edge 11 transmits data collected by the edge 11 to the CPS server 21 and receives operation information from the CPS server 21. The operation of the edge 11 is controlled based on the operation information received from the CPS server 21. In this case, the edge 11 transmits data collected by the edge 11 (i.e., measured by a sensor) to the CPS server 21 in accordance with a change in the state of the edge 11 based on the operation information, for example, and receives further operation information from the CPS server 21. By repeating this control loop (CPS loop) through the exchange of data and operation information, control of the edge(s) 11 is realized based on the data accumulated in the platform (data stored by the data function of the CPS server 21) and the analysis results of that data.
[0040] Although the CPS server 21 has been described here as having a data function, an analysis function, and an operation function, it is sufficient that the CPS server 21 has at least a data function. That is, the CPS server 21 may be configured to have only a data function, or may be configured to have only a data function and an analysis function, or may be configured to have only a data function and an operation function.
[0041] Vertical SoS 31 (Enterprise Services) comprises SoS functions provided by the SoS.
[0042] The SoS function includes an SoS API service function and a control function, and controls multiple systems (multiple CPS servers 21) based on data stored in the CPS server 21 and analysis results of the data. The data stored in the CPS server 21 and analysis results of the data are collected via the SoS API. The SoS function can also transmit analysis results of the data stored in the CPS server 21 (information generated from the data) to other domains (for example, a horizontal SoS 40, a vertical SoS 32 belonging to an industrial domain different from the vertical SoS 31, or a CPS server 22).
[0043] In the integrated system, a server device other than the CPS server 21 or the vertical SoS 31 may have a service function used by the system management side (such as a system administrator) and a business management function for managing business.
[0044] Service functions include functions for implementing business operations and maintenance, as well as functions for man-machine interaction, such as an intelligent heuristic engine function, an interface function providing various interfaces such as an API (Application Programming Interface) and a UI (User Interface), and logic and workflow functions. These functions incorporate the Internet of People (IoP) perspective. For example, data stored in the CPS server 21 and the analysis results of that data are acquired via an API, and the acquired data and analysis results are then verified programmatically or by an administrator. This enables the status of the CPS loop to be inspected and changed based on the program's automatic judgment results and the administrator's knowledge. Furthermore, the administrator inspects and audits the status of the CPS loop based on his or her expert human knowledge (IoP) to detect AI errors (CPS loop abnormalities) caused by abnormalities or attacks. In other words, the administrator can visually confirm whether the system is operating properly. When an administrator detects (perceives) an abnormality in the CPS loop, the administrator may troubleshoot the CPS loop via the service function (or other function).
[0045] The business management function is a function for realizing specific business requirements within the entire system, and includes functions such as CRM (Customer Relationship Management), ERP (Enterprise Resources Planning), PLM (Product Lifecycle Management), EAM (Enterprise Asset Management), etc. The business management function is used to manage the business status based on the data accumulated in the CPS server 21, the analysis results of the data, the detection results (check results) by the administrator using the service functions, and the administrator's operations based on the detection results.
[0046] Here, the service function and business management function have been described as being possessed by a server device different from the CPS server 21 and the vertical SoS 31, but the service function and business management function may be possessed, for example, by the CPS server 21 or the vertical SoS 31. Also, the SoS function may be possessed by the horizontal SoS 40 instead of the vertical SoS 31.
[0047] Furthermore, at least one of the above-mentioned edge 11, CPS server 21, and vertical SoS 31 has a common service function. The common service function includes a security function, a logging function, and a billing function. The security function is a function that ensures the security of each of the edge 11, CPS server 21, and vertical SoS 31, and the security of communications between the edge 11, CPS server 21, and vertical SoS 31. The logging function is a function that records, as a log, the operation of each of the edge 11, CPS server 21, and vertical SoS 31, and the history of communications between the edge 11, CPS server 21, and vertical SoS 31. The billing function is a function for issuing invoices, processing payments, and checking itemized statements in accordance with the use of services provided by the vertical SoS 31 and CPS server 21.
[0048] The arrows shown in Fig. 3 represent communication or data transfer between the functions connected by the arrows. Also, in Fig. 3, the mark 21a attached to the operation function of the CPS server 21 and the mark 31a attached to the SoS function of the vertical SoS 31 indicate that an administrator can manually operate them. The same applies to the marks identical to the mark 31a attached to the service function and business management function shown in Fig. 3.
[0049] The functions of the edge 11, the CPS server 21, and the vertical SoS 31 described in FIG. 3 are merely examples, and may be changed as appropriate depending on the services provided in the integrated system.
[0050] In FIG. 3, the edge 11, the CPS server 21, and the vertical SoS 31 have been described, but the same applies to other edges, CPS servers, and vertical SoSs.
[0051] Next, an example of the operation of the integrated system in this embodiment will be described with reference to Fig. 4. In Fig. 4, it is assumed that the integrated system provides a resilience solution.
[0052] In this case, the integrated system is assumed to include a resilience SoS40 corresponding to the horizontal SoS40 shown in Figure 1, a first mobility SoS31A and a second mobility SoS31B corresponding to the vertical SoS31, and a VPP SoS32 corresponding to the vertical SoS32.
[0053] 4 assumes a case where two vertical SoSs (i.e., a first mobility SoS 31A and a second mobility SoS 31B) are provided as the vertical SoS 31 belonging to the first industry domain described above, and the first mobility SoS 31A is a vertical SoS that manages a plurality of CPS servers (hereinafter referred to as first mobility CPS servers) 21A that provide, for example, an "autonomous driving and mobility service" by company A. On the other hand, the second mobility SoS 31B is a vertical SoS that manages a plurality of CPS servers (hereinafter referred to as second mobility CPS servers) 21B that provide, for example, an "autonomous driving and mobility service" by company B.
[0054] The VPP SoS 32 is a vertical SoS that controls a plurality of CPS servers (hereinafter referred to as VPP CPS servers) 22A and 22B.
[0055] That is, the resilience SoS 40 shown in FIG. 4 is a horizontal SoS that controls the first mobility SoS 31A, the second mobility SoS 31B, and the VPP SoS 32 described above.
[0056] Here, the resilience SoS (horizontal SoS) 40 can also control systems other than the vertical SoS. For this reason, FIG. 4 illustrates an example in which the resilience SoS 40 controls an infrastructure management system 33 in addition to the first mobility SoS 31A, the second mobility SoS 31B, and the VPP SoS 32. The infrastructure management system 33 is realized by one or more server devices (computer resources thereof) and is configured to manage multiple CPS servers (hereinafter referred to as infrastructure CPS servers) 23A-23C that belong to an industrial domain (e.g., a third industrial domain) different from the first mobility SoS 31A, the second mobility SoS 31B, and the VPP SoS 32. The infrastructure management system 33 illustrated in FIG. 4 is not an SoS as described above, but rather a system that collects information from the multiple infrastructure CPS servers 23A-23C, visualizes the current status of various infrastructures managed by each of the multiple infrastructure CPS servers 23A-23C, and controls their operation and maintenance.
[0057] It is assumed that each of the multiple first mobility CPS servers 21A controlled by the first mobility SoS 31A is installed in a different region (area), for example, but they may be installed in the same region to distribute the processing load, or may be installed for each function realized by the first mobility SoS (multiple first mobility CPS servers 21A). Here, multiple first mobility CPS servers 21A (i.e., multiple CPS servers controlled by the first mobility SoS 31A) have been described, but the same applies to other multiple CPS servers controlled by the second mobility SoS 31B, VPP SoS 32, and infrastructure management system 33.
[0058] As described above, the integrated system shown in FIG. 4 provides resilience solutions. Resilience solutions refer to services that provide solutions to prevent socially difficult situations from occurring, minimize damage or adverse effects on society if they do occur, and facilitate post-event recovery. In this embodiment, "socially difficult situations" may be based on various types of weather (typhoons, tornadoes, gusts of wind, heavy rain, linear rain bands, lightning, hail, heavy snow, etc.), earthquakes, tsunamis, and other natural disasters. Furthermore, "socially difficult situations" may be based on accidents, terrorism, crime, infectious diseases, power shortages, water shortages, etc.
[0059] In this embodiment, the resilience SoS 40 controls the first mobility SoS 31A, the second mobility SoS 31B, the VPP SoS 32, and the infrastructure management system 33, which belong to three industrial domains (mobility, energy, and infrastructure), to perform control to enhance resilience against the above-mentioned socially difficult situations. Note that, although not shown in FIG. 4 , the resilience SoS 40 may be configured to control vertical SoSs and other systems in various industrial domains other than the above-mentioned three industrial domains, such as "smart life" and "manufacturing / robotics (factory automation, smart manufacturing)," to perform control to enhance the resilience of society as a whole.
[0060] As described above, in this embodiment, the integrated system (horizontal SoS40) is described as providing a resilience solution, but the application of the horizontal SoS40 can be anything that can create new social value by integrating vertical SoSs and other systems belonging to different industrial fields.
[0061] Also, although omitted in Figure 4, each of the multiple CPS servers 21A, 21B, 22A, 22B and 23A to 23C shown in Figure 4 is communicatively connected to an edge corresponding to the CPS server, such as the multiple edges 11 and 12 described in Figure 1.
[0062] In this embodiment, it is assumed that resilience solutions are provided in response to the occurrence of socially difficult situations. First, an example of normal operation of the above-mentioned first mobility SoS31A, second mobility SoS31B, VPP SoS32 and infrastructure management system 33 will be described.
[0063] First, the first mobility SoS 31A will be described. The first mobility SoS 31A manages multiple first mobility CPS servers 21A. The first mobility SoS 31A and the multiple first mobility CPS servers 21A provide services that provide means and routes for user mobility or services that assist in selecting the means and routes (hereinafter referred to as mobility services). Note that mobility services are services that move users from a starting point to a destination using at least one of different modes of transportation, such as walking, bicycle, car, train, bullet train, and airplane. Note that bicycles, which are one mode of transportation, may include, for example, shared electric bicycles. Furthermore, automobiles, which are one mode of transportation, may be privately or corporately owned automobiles or may be automobiles used for car sharing. Furthermore, various automobiles can be used, such as electric automobiles, hybrid automobiles, gasoline-powered automobiles, and hydrogen-powered automobiles.
[0064] To provide the mobility services described above, the first mobility SoS 31A and the first mobility CPS servers 21A may have functions such as selecting a route to avoid traffic congestion or automatically driving multiple vehicles (such as automobiles) in the same area at the same time to avoid traffic congestion (hereinafter referred to as a synchronized driving function). The synchronized driving function may prohibit vehicles from entering a school zone during school hours or drive vehicles to reduce noise pollution. Furthermore, the first mobility SoS 31A and the first mobility CPS servers 21A may have functions such as reducing environmental impact by prioritizing the selection of transportation modes with low environmental impact. The first mobility SoS 31A and the first mobility CPS servers 21A may also provide functions for implementing dynamic pricing based on supply and demand or dynamic pricing in response to environmental impacts and social impacts when providing the mobility services described above.
[0065] The following describes a case where the first mobility SoS 31A and multiple first mobility CPS servers 21A provide mobility services by controlling, for example, electric vehicles with autonomous driving functions that are shared by users. Note that the first mobility SoS 31A and multiple first mobility CPS servers 21A may also control means for other mobility.
[0066] Here, each of the multiple first mobility CPS servers 21A managed by the above-mentioned first mobility SoS31A is a CPS server that provides mobility services in, for example, different areas (hereinafter referred to as service provision areas), and it is assumed that a user uses mobility services in the service provision area of one of the multiple first mobility CPS servers 21A (hereinafter simply referred to as first mobility CPS server 21A).
[0067] In this case, for example, a smartphone used by a user functions as an edge corresponding to the first mobility CPS server 21A, and the first mobility CPS server 21A performs control to support the autonomous driving function of each electric vehicle based on data acquired by the smartphone. Specifically, the first mobility CPS server 21A receives a departure point, a desired departure time, and a destination point, a desired arrival time input by the user on the smartphone (edge), and transmits to the smartphone electric vehicles selectable by the user, (information about) the route the electric vehicle is scheduled to travel, the scheduled departure time, and the scheduled arrival time.
[0068] The edges corresponding to the first mobility CPS server 21A include the electric vehicles mentioned above, and the first mobility CPS server 21A holds the specifications of each electric vehicle as master data, and receives and analyzes data from each electric vehicle under its control regarding the surrounding conditions when the electric vehicle is running or stopped, and the operation and various controls of the electric vehicle. Based on the results of such analysis, the first mobility CPS server 21A performs control to assist the operation of the electric vehicle from the starting point to the destination.
[0069] The control for supporting the automatic driving function by the first mobility CPS server 21A may differ depending on the level (supportable range) of the automatic driving function installed in each electric vehicle.
[0070] Specifically, depending on the model of the electric vehicle, the control of autonomous driving may be completed only on the edge (i.e., the electric vehicle itself). In this case, the electric vehicle may receive information about the area surrounding the route that the electric vehicle is scheduled to travel immediately after its current location, and use this information to control the driving of the electric vehicle.
[0071] On the other hand, when autonomous driving control is realized through collaboration between the electric vehicle (edge) and the first mobility CPS server 21A, the electric vehicle can run, for example, on highways using only the autonomous driving function installed in the electric vehicle, and on urban roads using the autonomous driving function based on control by the first mobility CPS server 21A.
[0072] In addition, the electric vehicle may be controlled to drive taking into account traffic congestion forecasts around the route, information about residents or facilities, and the like.
[0073] The data regarding the situation around the electric vehicle may be acquired using a sensor (such as a LiDAR or millimeter wave radar) or a camera mounted on the electric vehicle, or may be acquired by a stationary surveillance camera or sensor, or may be acquired by other electric vehicles around the electric vehicle.
[0074] Here we have explained the case where a user uses a mobility service in the service area of one first mobility CPS server 21A, but the same applies to the case where a user uses a mobility service in the service area of another first mobility CPS server 21A, for example.
[0075] The first mobility SoS 31A, which controls the multiple first mobility CPS servers 21A operating as described above, receives information on accurate future travel schedules of electric vehicles (edges) under the control of the multiple first mobility CPS servers 21A, data on the conditions surrounding the electric vehicles, etc. As a result, the first mobility SoS 31A can provide each first mobility CPS server 21A with information on optimal transportation means and routes based on the travel schedules of a wider range and a larger number of electric vehicles than when each first mobility CPS server 21A operates independently. As a result, by controlling the first mobility SoS 31A and at least one of the multiple first mobility CPS servers 21A, it is possible to provide a synchronized driving function that prevents congestion by, for example, completely matching the travel speeds of all electric vehicles under the control of the first mobility CPS server 21A that exist within a specific area. Furthermore, in situations where pedestrian entry into a specific area can be controlled, automatic driving and synchronized driving of all-electric vehicles can be realized in an environment where traffic lights are eliminated by controlling the first mobility SoS31A and at least one of the multiple first mobility CPS servers 21A.
[0076] While the operation of the first mobility SoS 31A (and the multiple first mobility CPS servers 21A) has been described above, the same applies to the operation of the second mobility SoS 31B (and the multiple second mobility CPS servers 21B). In other words, the second mobility SoS 31B and the multiple second mobility CPS servers 21B operate to provide the same mobility services (mobility-related services) as the first mobility SoS 31A and the multiple first mobility CPS servers 21A. However, regarding the relationship between the first mobility SoS 31A and the second mobility SoS 31B, the company (corporation) that manages the first mobility SoS 31A and the multiple first mobility CPS servers 21A and the company (corporation) that manages the second mobility SoS 31B and the multiple second mobility CPS servers 21B are in a competitive relationship with each other, and it is assumed that at least a portion of their service areas overlap.
[0077] Next, we will explain the VPP SoS 32. As shown in Fig. 4, the VPP SoS 32 manages multiple VPP CPS servers 22A and 22B, and for example, the VPP CPS server 22A is a VPP power generation CPS server (hereinafter referred to as VPP power generation CPS server 22A), and the VPP CPS server 22B is a VPP power transmission and distribution CPS server (hereinafter referred to as VPP power transmission and distribution CPS server 22B).
[0078] The VPP power generation CPS server 22A is a CPS server for performing maintenance and management of power generation facilities such as wind power generation facilities and solar power generation facilities, and is installed for each power generation facility. Note that the VPP power generation CPS server 22A may be configured to collectively control renewable energy power generation devices and facilities in a specific area.
[0079] Here, the edge corresponding to the VPP power generation CPS server 22A includes a controller provided in various types of power generation facilities that use renewable energy, such as wind power generation facilities, solar power generation facilities, geothermal power generation facilities, and hydroelectric power generation facilities. In this case, the VPP power generation CPS server 22A acquires data on the operating status and power generation history of the various types of power generation facilities from the controller (edge) for operation and maintenance of the power generation facilities, and controls the power generation facilities based on the acquired data.
[0080] Here, we have described renewable energy-related wind power generation facilities, solar power generation facilities, geothermal power generation facilities, and hydroelectric power generation facilities as power generation facilities, but the VPP power generation CPS server 22A may also be configured to control, for example, thermal power generation facilities or nuclear power generation facilities.
[0081] The VPP power generation CPS server 22A may receive information regarding the balance of power supply and demand from the VPP power transmission and distribution CPS server 22B by transmitting the power generation amount and its predicted value of each power generation facility to the VPP power transmission and distribution CPS server 22B, and may control the power generation amount of each power generation facility based on the information from the VPP power transmission and distribution CPS server 22B. Note that the transmission of the power generation amount and its predicted value to the VPP power transmission and distribution CPS server 22B and the reception of the information regarding the balance of power supply and demand from the VPP power transmission and distribution CPS server 22B may be performed via the VPP SoS 32, or may be performed directly between the VPP power generation CPS server 22A and the VPP power transmission and distribution CPS server 22B.
[0082] The VPP power generation CPS server 22A may also control power electronics circuits to convert the power output (DC voltage and DC current) from renewable energy sources into AC current that matches the grid, and may also control the orientation of wind power generation equipment according to wind direction based on the surrounding environment (weather conditions, etc.) to maximize power generation. Furthermore, the VPP power generation CPS server 22A may control the orientation of solar power generation panels to promote efficient power generation. The VPP power generation CPS server 22A may also detect abnormalities in each power generation equipment and formulate plans for operation, shutdown, and maintenance of each power generation equipment.
[0083] The VPP power transmission and distribution CPS server 22B is a CPS server for providing power transmission and distribution services (services for transmitting and supplying power), and is assumed to be installed, for example, for each region that is the target of the power transmission and distribution. In this case, the areas where the VPP power transmission and distribution CPS servers 22B installed for each region provide services may partially overlap, and multiple VPP power transmission and distribution CPS servers for providing services by different companies (corporations) may exist in the same region.
[0084] Here, the edges corresponding to the VPP power transmission and distribution CPS server 22B include, for example, watt-hour meters (or smart meters) installed at power consumption locations such as individual homes, apartment buildings, buildings, and commercial facilities. In this case, the VPP power transmission and distribution CPS server 22B receives the power generation amount and its predicted value of each power generation facility from the VPP power generation CPS server 22A, and receives the power usage amount and its predicted value at each power consumption location from the watt-hour meters. The VPP power transmission and distribution CPS server 22B also holds master data on the costs related to the transmission and distribution of power between each power generation facility and each power consumption location. The VPP power transmission and distribution CPS server 22B executes control of power transmission and distribution based on the power generation amount and its predicted value of each power generation facility, the power usage amount and its predicted value at each power consumption level, and the costs related to power transmission and distribution.
[0085] The VPP power transmission and distribution CPS server 22B also has functions related to the selling and purchasing of power based on power consumption values (for individual homes, apartment buildings, buildings, commercial facilities, etc.). Specifically, the VPP power transmission and distribution CPS server 22B may transmit the selling price, buying price, and predicted value of power at each date and time to each watt-hour meter (edge) for the purpose of selling or purchasing power, and may receive information on the amount of stored power (dischargeable amount) and current or future power purchase requests from the watt-hour meter. The VPP power transmission and distribution CPS server 22B may also store (i.e., store) power in a secondary battery (such as an SCiB (registered trademark) or LiB) when the total amount of power generated by each power generation facility received from the VPP power generation CPS server 22A is expected to be greater than the total amount of power used in each power consumption area. In this case, power may be converted to hydrogen or the like (power to gas: P2G) or carbon dioxide may be converted into fuel (power to chemical: P2C).
[0086] The VPP power transmission and distribution CPS server 22B may also have a demand response function. Demand response is defined as a change in power consumption patterns by consumers to curb power usage in response to electricity rate settings or incentive payments, for example, when market prices rise or grid reliability declines. When the total amount of power generated by each power generation facility received from the VPP power generation CPS server 22A is assumed to be smaller than the total amount of power used in each power consumption area, the VPP power transmission and distribution CPS server 22B may determine whether or not to transmit or distribute power from outside the power consumption area or whether or not to discharge stored power within or near the power consumption area. This allows power consumption to be reduced through demand response.
[0087] The VPP SoS 32 controls multiple VPP power generation CPS servers 22A and multiple VPP power transmission and distribution CPS servers 22B, and performs control to satisfy power demand using renewable energy. The VPP SoS 32 receives power generation history and power generation forecast values for each power generation facility from the multiple VPP power generation CPS servers 22A, and receives power consumption history and power consumption forecast values for each power consumption area from the multiple VPP power transmission and distribution CPS servers 22B. The amount of power generated by renewable energy fluctuates over time due to natural factors, and power consumption in each power consumption area also fluctuates over time depending on the trends of consumers. Taking these circumstances into consideration, in order to match the demand and supply at each time, the VPP SoS32 can perform control for efficient storage of electricity when there is a power surplus, efficient discharge of electricity when there is a power shortage, and the exchange of electricity between each power consumption area based on the power generation history and predicted power supply amount of each power generation facility, which covers a wider range than each VPP power generation CPS server 22A and each VPP transmission and distribution server 22B, and the consumption history and predicted power demand of each power consumption area.
[0088] Next, the infrastructure management system 33 will be described. The infrastructure management system 33 is a system for managing infrastructure provided by, for example, the national government and local public organizations, and in the example shown in Fig. 4, manages multiple infrastructure CPS servers 23A to 23C. Here, the infrastructure CPS server 23A is a bridge / road management CPS server (hereinafter referred to as bridge / road management CPS server 23A), the infrastructure CPS server 23B is a river / levee / dam management CPS server (hereinafter referred to as river / levee / dam management CPS server 23B), and the infrastructure CPS server 23C is a water supply / sewerage CPS server (hereinafter referred to as water supply / sewerage CPS server 23C). Each of the bridge / road management CPS server 23A, the river / levee / dam management CPS server 23B, and the water supply / sewerage CPS server 23C is installed for each management unit (i.e., region) such as a country, prefecture, or city / ward / town / village, and may be shared by multiple organizations.
[0089] The edge corresponding to the bridge / road management CPS server 23A includes, for example, sensors or monitoring units installed on bridges, roads, or cliffs or slopes adjacent to the roads. In this case, the bridge / road management CPS server 23A can analyze data collected by such sensors or monitoring units, such as displacement of the bridge and road positions and changes in internal pressure. Furthermore, if the edge corresponding to the bridge / road management CPS server 23A is a camera installed on various vehicles, including inspection vehicles, or a surveillance camera installed near the bridge or road, it can analyze data such as the usage status of the bridge or road and cracks and cracks on the surface of the bridge or road captured or measured by the camera. Based on these analysis results, the bridge / road management CPS server 23A sequentially estimates the condition of the bridge or road and generates information for operation and maintenance of the bridge, road, and its surrounding areas.
[0090] In addition, the bridge / road management CPS server 23A may identify the occurrence or risk of abnormalities (collapse, collapse, sinkhole, heavy rain, heavy snow, dense fog, etc.) in bridges, roads, and their surrounding areas, and may issue warnings by displaying the occurrence or risk of the abnormality on digital signs or by contacting various vehicles (edges), or may generate information for formulating construction or repair plans for bridges and roads.
[0091] The bridge / road management CPS server 23A can also be used as a database that collects data based on residents' opinions, in addition to the data collected from the above-mentioned edges. In this case, the bridge / road management CPS server 23A can store data on locations where there are many complaints about noise from vehicles traveling on the road, locations where there are many complaints about exhaust fumes, locations where there is a high risk of accidents (near miss reports from residents), school zones, etc., and use this data in combination with the data collected from the edges.
[0092] The edges corresponding to the river, levee, and dam management CPS server 23B include sensors (including rain gauges) or surveillance cameras installed in (or near) rivers, levees, and dams. In this case, the river, levee, and dam management CPS server 23B acquires data such as meteorological information (such as rainfall history measured by rain gauges), the history of water usage or release volume at the dam, changes in the dam's water level, and changes in water level at each location on the river, using such sensors or surveillance cameras. By analyzing the data acquired by the above-mentioned edges and future weather forecast information received from a weather information cloud service, the river, levee, and dam management CPS server 23B can transmit information for controlling the release volume of water stored in the dam to a gate (edge) installed at the dam.
[0093] In addition, the river / levee / dam management CPS server 23B may analyze data such as displacement of water level position and changes in internal pressure of structures (walls of levee or dam) collected by sensors or monitoring units (edges) installed on levees or dams, or data such as cracks and fissures on the surface of levees or dams photographed or measured by monitoring cameras (edges), to sequentially estimate the condition of levees or dams and generate information for operating and maintaining the levees or dams.
[0094] Furthermore, the river / levee / dam management CPS server 23B may analyze information on future weather forecasts and data such as the current water level of a dam and changes in water level at each position on the river to grasp the condition of the levee or dam and identify risks of collapse, overflow, etc. The river / levee / dam management CPS server 23B may generate information for formulating construction plans for reinforcing or expanding levee or dams that are at high risk of collapse, overflow, etc.
[0095] The edges corresponding to the water supply and sewerage CPS server 23C include sensors or monitoring units that acquire data on the usage status and usage history of various equipment (filters, pipes, valves, etc.) at the water purification plant and sewage treatment plant, or data on flow rates at each location, for the operation and maintenance of the water purification plant and sewage treatment plant (i.e., water supply and sewerage).The water supply and sewerage CPS server 23C controls the various equipment (edges) at the water purification plant and sewage treatment plant based on the data acquired by such sensors or monitoring units.
[0096] In addition, the water supply and sewerage CPS server 23C holds digital twin information of various facilities at, for example, water purification plants and sewage treatment plants, and may use this information to generate information for formulating maintenance, upkeep, new construction plans, etc. for various facilities at water purification plants and sewage treatment plants.
[0097] Furthermore, the water supply and sewerage CPS server 23C may perform dynamic pricing (dynamic price setting) of water charges and drainage charges according to the amount of drainage, based on the data acquired from the above-mentioned edges.
[0098] The infrastructure management system 33 acquires information from the bridge / road management CPS server 23A, river / levee / dam management CPS server 23B, and water / sewerage CPS server 23C, including the latest status of infrastructure such as bridges, roads, rivers, levee, dam, and water / sewerage systems, the status of operation and maintenance, the risk of abnormalities and anticipated damage for each type of infrastructure, and information necessary for developing plans for infrastructure maintenance. The infrastructure management system 33 lists and organizes the different needs for new construction, renewal, renovation, repair, and maintenance for different types of infrastructure, and generates information that serves as the basis for renovation, expansion, and renewal plans for the entire infrastructure in the relevant area. The information generated in this way is provided to the infrastructure management corporation, the national government, prefectures, cities, towns, and villages, etc.
[0099] Here, the infrastructure management system 33 has been described as managing the bridge / road management CPS server 23A, the river / levee / dam management CPS server 23B, and the water supply / sewerage CPS server 23C (i.e., managing bridges, roads, rivers, levee, dams, and water supply / sewerage), but the infrastructure managed by the infrastructure management system 33 may also include various facilities such as government offices and hospitals.
[0100] Incidentally, the above-mentioned second mobility SoS31B can optimize the entire mobility service provided by the second mobility SoS31B and the multiple second mobility CPS servers 21B and improve efficiency even if it only manages multiple second mobility CPS servers 21B, but it may also communicate with VPP SoS32 as shown in Figure 4.
[0101] When electric vehicles are controlled by the mobility service provided by the second mobility SoS 31B (and the multiple second mobility CPS servers 21B), the electric vehicles consume a large amount of power when charging. For example, if multiple electric vehicles are charging at the same time, the total amount of power consumed by charging the electric vehicles may exceed the total amount of power generated by each power generation facility (the total amount of power that can be provided by the VPP), creating a risk of a power outage or other malfunction. Furthermore, if power generation facilities are expanded to accommodate situations where multiple electric vehicles are charging at the same time, this will increase the environmental load.
[0102] For this reason, the second mobility SoS31B receives from the VPP SoS32 information on the history and predicted value of electricity prices in each region (power consumption area) during each time period, as well as information on the history and predicted value of the difference between the total maximum amount of electricity supply and the total amount of electricity consumed in each region during each time period. In other words, the second mobility SoS31B receives from the VPP SoS32 information on the amount of electricity available for charging electric vehicles in each region during each time period. Based on the information received from the VPP SoS32, the second mobility SoS31B formulates a plan for the time period, location, and amount of charging for each electric vehicle. Note that locations where each electric vehicle is charged include, for example, EV stands, homes, commercial facilities, and public facilities. This plan is formulated from the perspective of minimizing the risk of each electric vehicle running out of power (when the battery runs out and the electric vehicle becomes unable to move), minimizing the total electricity costs required to charge all electric vehicles, and cooperating with controls to avoid failures (power outages) at each power generation facility (for example, preventing the total power demand from exceeding the total available power supply in the relevant area). Note that cooperation with controls to avoid failures at each power generation facility can be achieved, for example, by shifting the charging times of each electric vehicle, or by shifting the charging times of electric vehicles from peak times of power usage at homes, commercial facilities, public facilities, business facilities, etc.
[0103] That is, according to a configuration in which communication is performed between the second mobility SoS31B and the VPP CPS32 (i.e., information is exchanged), the magnitude of the peak amount of electric power that must be supplied by each power generation facility (VPP) can be effectively reduced as the number of electric vehicles controlled by the second mobility SoS31B increases. Therefore, when the second mobility SoS31B and the VPP SoS32 cooperate with each other, it is possible to reduce the risk of failure in each power generation facility, and also to reduce the number of power generation facilities required, thereby reducing the environmental load.
[0104] In the example shown in Figure 4, the first mobility SoS31A does not communicate with the VPP SoS32, but in this case, the first mobility SoS31A formulates a plan regarding the time, location, and amount of charge for each electric vehicle to be charged, regardless of the state of the VPP, from two perspectives, for example, minimizing the risk of each electric vehicle running out of power and minimizing the total electricity cost required to charge all electric vehicles.
[0105] On the other hand, even if the first mobility SoS 31A only manages multiple first mobility CPS servers 21A, it is possible to optimize the entire mobility service provided by the first mobility SoS 31A and multiple first mobility CPS servers 21A and improve efficiency, but it may also communicate with an infrastructure management system 33 as shown in Figure 4.
[0106] The first mobility CPS server 21A, managed by the first mobility SoS 31A, receives data from sensors (such as LiDAR and millimeter-wave radar) and cameras installed in numerous electric vehicles under its control. This allows the server 21A to continuously collect up-to-date road perimeter information based on the driving behavior of numerous electric vehicles. The road perimeter information can be generated from data obtainable by sensors and cameras installed on the edge (such as electric vehicles). For example, the information can be used to detect dirt, damage, and aging deterioration of roads, signs, guardrails, electric lights, and convex mirrors, or to detect abnormalities in the orientation of signs, guardrails, electric lights, and convex mirrors. Furthermore, the road perimeter information can be based on sensing data regarding people, objects, stores, and other items present around the road at various times and locations, and can also include information indicating the current state of society. Furthermore, the first mobility CPS server 21A can collect driving logs for numerous electric vehicles (groups). By analyzing the driving logs of many electric vehicles using AI, etc., it is possible to identify (information about) locations where traffic jams are frequent, locations where acceleration and deceleration are frequent, locations where there is a high risk of accidents, locations where there is a high risk of running out of battery, and locations where there is a high risk of vehicles (autonomous vehicles and vehicles driven by people) driving in an illegal manner.
[0107] In this case, the first mobility SoS31A transmits the above-mentioned information about the road area and the driving logs of the numerous electric vehicles to the infrastructure management system 33. By analyzing this information and driving logs, the infrastructure management system 33 can generate information for formulating maintenance and repair plans for roads, signs, guardrails, electric lights, convex mirrors, etc. Furthermore, the infrastructure management system 33 may generate information for formulating more beneficial infrastructure maintenance, repair, and new construction plans based on the above-mentioned information indicating the current state of society.
[0108] That is, according to a configuration in which communication (i.e., information is exchanged) is performed between the first mobility SoS 31A and the infrastructure management system 33, as the number of electric vehicles controlled by the first mobility SoS 31A increases, it becomes possible to formulate and implement plans for infrastructure maintenance, renovation, and new construction that more accurately grasp the current state of society. Therefore, when the first mobility SoS 31A and the infrastructure management system 33 cooperate as described above, it is possible to improve the contribution of mobility to society as a whole and contribute to reducing the environmental load.
[0109] The resilience SoS 40 shown in Figure 4 controls the first mobility SoS 31A, the second mobility SoS 31B, the VPP SoS 32, and the infrastructure management system 33, and provides a resilience solution. The resilience SoS 40 provides information that contributes to measures against socially difficult situations to various systems (such as SoSs, CPS servers, and other systems operated by various corporations and organizations). The resilience SoS 40 can provide information for changing the control and processing in various systems and the exchange of information (or data) between the various systems from the perspective of resilience.
[0110] Furthermore, under normal circumstances, the resilience SoS 40 continuously executes processing to detect the occurrence of a socially difficult situation. For example, assuming that the socially difficult situation is a natural disaster, the resilience SoS 40 is communicatively connected to a cloud server (hereinafter referred to as a weather system) 50 that provides meteorological information (information about weather conditions) and information about earthquake and tsunami predictions. The resilience SoS 40 sequentially receives information provided by the weather system 50, predicts the occurrence of various natural disasters (weather disasters, earthquake and tsunami disasters, etc.), and detects an increase in the risk of the occurrence of the natural disaster or the occurrence of the natural disaster. Note that the weather system 50 in this embodiment may include, for example, multiple server devices (systems) operated by multiple companies (or corporations, etc.).
[0111] In this case, the resilience SoS40 may receive from the first mobility SoS31A and the second mobility SoS31B information on the surroundings of electric vehicles obtained based on data collected by the first mobility SoS31A, the multiple first mobility CPS servers 21A, the second mobility SoS31B, and the multiple second mobility CPS servers 21B, information on the occurrence of abnormal traffic congestion (such as an abnormal concentration of electric vehicles in a specific location), and information on abnormal trends of electric vehicles (such as an abnormal evacuation of electric vehicles from a specific location), and may predict the occurrence of natural disasters from the received information.
[0112] In addition, the resilience SoS40 may receive from the VPP SoS32 information indicating abnormal (e.g., large) amounts of electricity being used, obtained based on data collected by the VPP SoS32 and multiple VPP CPS servers (VPP power generation CPS server and VPP power transmission / distribution CPS server) 22A and 22B, information regarding the risk (or prediction) of demand exceeding supply, information regarding the risk (prediction) of power line breaks due to fallen trees, etc., and information regarding the risk (prediction) of underground power line breaks due to fault displacement, and may predict the occurrence of natural disasters from the received information.
[0113] Furthermore, the resilience SoS40 may receive information indicating that the infrastructure is in a dangerous state and information indicating that a failure has occurred in the infrastructure from the infrastructure management system 33, which is obtained based on various sensor data and surveillance camera image data collected by the infrastructure management system 33 and multiple infrastructure CPS servers (bridge / road management CPS server, river / levee / dam management CPS server, and water supply and sewerage CPS server) 23A to 23C, and may predict the occurrence of a natural disaster from the received information.
[0114] Here, we assume the occurrence of a socially difficult situation such as a natural disaster, but the resilience SoS40 may also detect the occurrence of a socially difficult situation such as an accident, terrorism, or crime from data collected in the first mobility SoS31A, multiple first mobility CPS servers 21A, second mobility SoS31B, multiple second mobility CPS servers 21B, VPP SoS32, multiple VPP CPS servers 22A and 22B, infrastructure management system 33, and multiple infrastructure CPS servers 23A to 23C.
[0115] In this way, the resilience SoS 40 collects information not only from various SoSs (in the example shown in Figure 4, the first mobility SoS 31A, the second mobility SoS 31B, the VPP SoS 32, and the infrastructure management system 33) that communicate with each other via the SoS API, but also from other systems (including the media, the government and public agencies, local governments, etc.), and performs processing to detect the occurrence of socially difficult situations.
[0116] When the resilience SoS 40 detects an increased risk of a socially difficult situation occurring, the operation of the resilience SoS 40 is switched from the above-described normal control to high-risk control. Furthermore, when the resilience SoS 40 actually detects the occurrence of a socially difficult situation, the operation of the resilience SoS 40 is switched from high-risk control to control when a socially difficult situation occurs.
[0117] 4, the horizontal SoS 40 is a resilience SoS 40, and the resilience SoS 40 has been described as providing a resilience solution for socially difficult situations such as sudden or infrequent natural disasters. However, the resilience SoS 40 may be implemented in a manner that can execute processing for detecting the risk of a socially difficult situation occurring and the occurrence of the socially difficult situation during normal times. Furthermore, in the example shown in FIG. 4, the horizontal SoS 40 may be an SoS for a specific purpose or function other than resilience.
[0118] Here, in the above-mentioned Figure 4, it has been explained that information is exchanged by executing communication between the second mobility SoS31B and the VPP SoS32, and information is exchanged by executing communication between the first mobility SoS31A and the infrastructure management system 33. However, below, with reference to Figure 5, an example of a system configuration for the exchange of information performed in this embodiment will be explained.
[0119] The system configuration shown in Figure 5 shows a system 61 that provides information (hereinafter referred to as an information providing system) and a system 62 that receives the information (hereinafter referred to as an information receiving system). The information providing system 61 is assumed to be the first mobility SoS 31A and VPP SoS 32 shown in Figure 4, but the information providing system 61 may be an SoS (horizontal SoS or vertical SoS), a CPS server, an edge, or other system that constitutes an integrated system. Similarly, the information receiving system 62 is assumed to be the second mobility SoS 31B and infrastructure management system 33 shown in Figure 4, but the information receiving system 62 may be an SoS (horizontal SoS or vertical SoS), a CPS server, an edge, or other system that constitutes an integrated system.
[0120] 5 also shows an authentication server 63 and an intermediary server 64. As described above, information generated (created) via SoS, CPS servers, edges, etc. is valuable to its holders or sovereigns, such as countries (governments), local governments, companies (corporations), or individuals. For this reason, the authentication server 63 and the intermediary server 64 evaluate and authenticate the information providing system 61 and the information receiving system 62 (entities) from various perspectives before information is exchanged.
[0121] Specifically, the administrator or management organization (such as a national or local government or company) of the information providing system 61 and the information receiving system 62 obtains prior certification from the certification server 63 in order to participate in a mechanism (platform) for the exchange of information via the intermediary server 64. Requirements for obtaining certification may be any requirement that takes into consideration the sovereignty of information and confirms that appropriate and secure information exchange is possible. Examples of requirements for obtaining certification include, for example, that the administrator or management organization of the information providing system 61 (hereinafter simply referred to as the information providing side) can receive appropriate compensation from the administrator or management organization of the information receiving system 62 (hereinafter simply referred to as the information receiving side), that the information receiving side complies with the rules (purpose of use, form of use, etc.) established by the information providing side, that the security of the information receiving system 62 is guaranteed, and that the information providing system 61 and the information receiving system 62 handle information in accordance with the laws, regulations, ordinances, and cabinet orders of the country of origin, country of use, region of origin, and region of use of the information.
[0122] Furthermore, the usage patterns included in the rules established by the information provider include, for example, the manner in which information is processed, the scope of disclosure, whether it can be provided to a third party, etc. Furthermore, ensuring the security of the information receiving system 62 includes the information receiving system 62 having a sufficient configuration to prevent unintentional information leakage and unauthorized access to the information.
[0123] It is assumed that the administrators or management organizations (i.e., the information provider and information receiver) of each of the SoS, CPS server, edge, and other systems that make up the integrated system shown in Figure 4 meet the requirements for obtaining authentication described above and have obtained authentication from the authentication server 63.
[0124] Here, we have explained that the information provider and information recipient have obtained authentication from the authentication server 63, but the administrator or management organization (intermediary side) of the intermediary server 64 also obtains authentication from the authentication server 63.
[0125] That is, only entities that have been authenticated by the authentication server 63 can become either the information provider, information receiver, or intermediary.
[0126] In practice, the above-mentioned certification may be carried out after a person in charge at a certification authority audits each system itself and the organization that manages each system, and checks the track record, etc.
[0127] The intermediary server 64 has a function of mediating the exchange of information (i.e., information transactions) between information providers and information recipients who have obtained authentication from the authentication server 63. In this case, the intermediary server 64 registers supplementary information (hereinafter referred to as metadata) related to information (hereinafter referred to as provideable information) that is held by each of the management organizations and administrators of the SoS, CPS servers, edges, and other systems that have obtained authentication from the authentication server 63 and that can be provided to other management organizations or administrators. Note that the provideable information for which metadata is registered in the intermediary server 64 may be, for example, information that includes at least a portion of the data collected from the above-mentioned edges, and may also be information generated from the data (information obtained by processing the data), etc.
[0128] This metadata includes the content, type, quantity, quality, freshness, acquisition method, format, type, and guarantee of the available information, as well as conditions required by the information provider for providing the available information. The amount of available information included in the metadata refers to the capacity and size of the available information, but may also refer to, for example, the capacity and size per hour. The freshness of the available information included in the metadata indicates, for example, the time lag between the creation of the available information and its provision. The format of the available information included in the metadata includes, for example, the file format and extension, as well as whether it complies with specific standards, specifications, and rules. The type of available information included in the metadata indicates whether the available information is personal information, anonymously processed information (information in which the name of personal information has been anonymously processed), or pseudonymized information (information in which the name of personal information has been pseudonymized). The conditions included in the metadata include the consideration (amount) for providing the available information, rules established by the information provider (holder), and matters to be observed by the information provider and the information recipient. These conditions may be set by the owner of the available information, by an information provider commissioned by the owner, by a person who collects information other than the owner, or by a combination of one or more of these.
[0129] The intermediary server 64 has the function of presenting a list of the registered metadata as described above, and serves as an information trading market (marketplace).
[0130] Here, assume that the information receiving system 62 receives information from the information providing system 61. In this case, the information receiving system can access the intermediary server 64 and specify specific information that can be provided by the information providing system in the marketplace described above. Note that if the information providing system 61 is the VPP SoS 32 and the information receiving system 62 is the second mobility SoS 31B, the information receiving system 62 specifies information such as the amount of power available for charging electric vehicles in each region during each time period.
[0131] As a result, when an agreement is reached between the information providing system 61 (information providing side) and the information receiving system 62 (information receiving side) that information specified by the information receiving side will be provided from the information providing side to the information receiving side, the intermediary server 64 permits the information providing system 61 to transmit (provide) the information (hereinafter referred to as provided information) to the information receiving system 62. In this case, the intermediary server 64 transmits information (hereinafter referred to as permission information) to the information providing system 61 and the information receiving system 62 to permit the transmission of the provided information.
[0132] In this embodiment, the permission information is, for example, information for permitting transmission of specific provided information from a specific information provider to a specific information receiver, but may be any information that enables exchange of provided information between the information providing system 61 (information provider) and the information receiving system 62 (information receiver). Specifically, the permission information may be information indicating the range (use range) of provided information for which transmission is permitted, information indicating a period (use period) for which transmission or use of the provided information is permitted, or security information for securely transmitting the provided information. Note that the security information may be, for example, information specifying a communication method for ensuring security (public key cryptography, quantum cryptography communication, etc.), information using a security token, or security parameters (information specifying an encryption method and an encryption key), etc. The permission information sent to the information providing system 61 and the permission information sent to the information receiving system 62 may be of any type as long as it allows the transmission of specific provided information from the information providing system 61 to the information receiving system 62, and the same information may be sent to the information providing system 61 and the information receiving system 62, or different information may be sent to the information providing system 61 and the information receiving system 62.
[0133] The permission information described above is transmitted to the information providing system 61 and the information receiving system 62 after the intermediary server 64 confirms an agreement between the information providing side and the information receiving side to provide (transfer) information or the fulfillment of the conditions between the information providing side and the information receiving side for the provision of the information (or the intention to fulfill the conditions). Note that the intermediary server 64 may confirm the fulfillment of the conditions between the information providing side and the information receiving side or the intention to fulfill the conditions by confirming that the payment procedure for the consideration for the provision of the information has been completed or that there is an intention to make the payment (including an agreement to continuous payment of the consideration for the period during which the provided information can be used).
[0134] Furthermore, the intermediary server 64 may confirm the intention to use the provided information for a specific purpose, instead of or in addition to confirming payment of compensation for the provision of information. The specific purpose for using the provided information includes, for example, a purpose related to resilience response, a purpose of a high public nature such as providing information to the government or local public bodies for formulating infrastructure renovation plans, and a purpose from which the information provider can directly or indirectly benefit.
[0135] The intermediary server 64 may also be configured to confirm that the information provider is willing to fulfill its obligations under specific alternative conditions. Specifically, the willingness to fulfill its obligations under specific alternative conditions includes, for example, a willingness to fulfill obligations that will have a positive impact on the information provider's business, and a willingness to comply with the Sustainable Development Goals (SDGs) or specific guidelines that require a separate contract to be concluded for fulfilling obligations that differ from laws, etc. Furthermore, for example, if the information providing system 61 is a VPP SoS 32 and the information receiving system 62 is a second mobility SoS 31B, the intermediary server 64 may confirm that the information provider agrees to cooperate in reducing peak power consumption by staggering the charging of electric vehicles or in demand response.
[0136] It has been explained here that various matters, including the completion of the payment procedures for the consideration mentioned above, are confirmed in order to confirm whether the conditions between the information provider and the information recipient when providing information are met or whether the recipient intends to meet those conditions. However, matters other than those described here may be confirmed, or two or more of the matters described here may be confirmed in combination.
[0137] Here, when the information providing system 61 (e.g., VPP SoS 32) and the information receiving system 62 (e.g., second mobility SoS 31B) receive permission information from the intermediary server 64, P2P (direct) communication is established between the information providing system 61 and the information receiving system 62, and the information providing system 61 starts transmitting provided information to the information receiving system 62. The provided information transmitted from the information providing system 61 to the information receiving system 62 (e.g., information on the amount of power available for charging electric vehicles in each region during each time period) is updated successively, including, for example, past history and future predictions, and the information providing system 61 and the information receiving system 62 regularly and continuously perform direct communication within the range (range of use and period of use) permitted by the intermediary server 64.
[0138] For example, if the information providing system 61 is a VPP SoS32 and the information receiving system 62 is a second mobility SoS31B, the condition that the second mobility SoS31B must satisfy to receive information from the VPP SoS32 may be payment of a fee or handling of the information in accordance with the laws, regulations, ordinances, and cabinet orders of the country where the information is created, the country where the information is used, the region where the information is created, and the region where the information is used. Furthermore, the condition that the second mobility SoS31B must satisfy to receive information from the VPP SoS32 may be cooperation in reducing peak power consumption and distributing power consumption by controlling the time periods for charging electric vehicles based on information on the difference between the total amount of maximum power that can be supplied and the total amount of power consumed in each region during each time period.
[0139] Furthermore, the information providing system 61, the intermediary server 64, or another cloud server (not shown) may provide, together with the provided information, the format of the provided information to be transmitted from the information providing system 61 to the information receiving system 62 and information for interpreting the provided information. Even if the information providing system 61 and the information receiving system 62, or multiple information providing systems 61, share information based on different formats or different data definitions, the provided information can be appropriately used in the information receiving system 62 by converting and unifying the format using the information for interpreting the provided information. The format conversion and unification may be performed by at least one of the information providing system 61, the information receiving system 62, the intermediary server 64, or a cloud server providing a service related to the format conversion and unification. The information receiving system 62 may receive information related to the format conversion and unification from the intermediary server 64, etc.
[0140] Here, we have mainly explained the case where the information providing system 61 is a VPP SoS32 and the information receiving system 62 is a second mobility SoS31B, but the exchange of information between the information providing system 61 and the information receiving system 62 is a first mobility SoS31A and the infrastructure management system 33 can also be realized according to the scheme described in Figure 5.
[0141] In this case, the first mobility SoS 31A transmits provided information (for example, information about road areas and driving logs of a large number of electric vehicles) to the infrastructure management system 33, and the provided information is transmitted (provided) sequentially, for example, when an abnormality in the infrastructure is detected in at least one of the multiple infrastructure CPS servers 23A to 23C managed by the infrastructure management system 33. Furthermore, when the provided information from the first mobility SoS 31A is used for the purpose of maintaining and inspecting roads, signs, guardrails, electric lights, convex mirrors, etc., the provided information may be transmitted from the first mobility SoS 31A to the infrastructure management system 33 approximately once a day. Furthermore, when the provided information is used for future infrastructure planning (urban planning), etc., the information obtained up to that time may be transmitted collectively, for example, once every month, every three months, or every six months.
[0142] Note that the exchange of information between the resilience SoS 40, the first mobility SoS 31A, the second mobility SoS 31B, the VPP SoS 32, and the infrastructure management system 33 shown in Fig. 4 may also be realized using the scheme described in Fig. 5. The same applies to communication between each SoS and each CPS server, and communication between each CPS server and an edge.
[0143] Here, in Figure 4 above, for example, the operation of the integrated system under normal circumstances was explained, but if an increased risk of a socially difficult situation is detected, the operation of the integrated system (resilience SoS40) will be switched from normal control to high-risk control as described above.
[0144] Below, we will explain an example of the processing procedure of the integrated system when an increased risk of a socially difficult situation is detected, with reference to the flowchart in Figure 6. Note that the "socially difficult situation" in the following explanation is assumed to be concentrated heavy rain caused by a typhoon and the accompanying flooding, inland flooding, power outages, etc. (hereinafter simply referred to as flood damage).
[0145] First, the integrated system (resilience SoS40, first mobility SoS31A, multiple first mobility CPS servers 21A, second mobility SoS31B, multiple second mobility CPS servers 21B, VPP SoS32, multiple VPP CPS servers 22A and 22B, infrastructure management system 33, multiple infrastructure CPS servers 23A to 23C, and edges corresponding to each of the CPS servers) executes the processing shown in Figure 6 while repeating the operations described in Figure 4 above.
[0146] In this case, the resilience SoS 40 determines whether the risk of flooding is high or not based on continuous and periodic predictions of the risk of occurrence of the above-mentioned flooding (hereinafter simply referred to as flood risk) (step S1).
[0147] The flood risk prediction may be performed by the resilience SoS40 based on weather information provided by the weather system 50, for example, or may be performed by another system or server device (for example, the weather system 50). For example, when the flood risk prediction is performed in the weather system 50, the resilience SoS40 may receive the flood risk prediction results (or information for identifying an increase in flood risk, etc.) from the weather system 50.
[0148] If it is determined that the risk of flood damage is not high (NO in step S1), the process returns to step S1 and is repeated.
[0149] On the other hand, for example, assume that the weather system 50 predicts that a typhoon will hit a specific region in a few days, and information for identifying an increased risk of flood damage is received from the weather system 50. In this case, the resilience SoS 40 detects the increased risk of flood damage and determines that the risk of flood damage is high (YES in step S1).
[0150] If it is determined in step S1 that the risk of flooding is high, the following processing from step S2 onwards is executed, but the operations described above in Figure 4 are continued. This allows, for example, the prediction of the occurrence of socially difficult situations different from flooding and the understanding of risks other than flooding risks to be continued.
[0151] Next, the resilience SoS 40 predicts the details of the flood risk (step S2). In this case, the resilience SoS 40 predicts the likelihood of what types of risks occurring in each region based on meteorological information held by the weather system 50 (forecasts of future precipitation for each region, the path of typhoons, predicted locations of sudden heavy rain, etc.) and information about infrastructure held by the infrastructure management system 33 (water storage capacity of dams, drainage capacity of each drainage facility, etc.). As mentioned above, the (types of) flood risk include, for example, flood risk, inland flooding risk, and power outage risk.
[0152] Regarding flood risk, areas that are predicted to be inundated due to levee breaches and overflows are set as flood warning areas, for example, based on the results of periodic checks of levee facilities, for example, based on locations predicted to be prone to levee breaches (i.e., locations with a high risk of breaches) and locations on the levee that are close to the river water level and predicted to be prone to overflows when the river rises (i.e., locations with a high risk of overflows).In addition, areas surrounding flood warning areas may be set as flood caution areas.
[0153] Regarding the risk of inland flooding, for example, an area that is predicted to be flooded when the amount of rainfall exceeds the drainage capacity of drainage facilities (storm drains and pump facilities) and water cannot be discharged is set as an inland flood warning area. In addition, areas surrounding an inland flood warning area may be set as an inland flood caution area.
[0154] Regarding the risk of power outages, for example, based on the location where power lines are predicted to be cut by fallen trees (i.e., the location where the risk of power line breakage is high), the area where a power outage is predicted to occur when the power line is cut is set as the power outage warning area. In addition, the area surrounding the power outage warning area may be set as the power outage caution area.
[0155] The resilience SoS40 creates a hazard map (hereinafter referred to as a real-time hazard map) as a result of the prediction in step S2. The infrastructure management system 33 holds, for example, a hazard map for each region, and the resilience SoS40 creates a real-time hazard map (information) based on the hazard map by reflecting the prediction results for each type of risk described above. Furthermore, basic information for creating the real-time hazard map (map information including the locations of homes, commercial facilities, infrastructure, etc., and information on the height of each piece of land) can be obtained from the hazard map held by the infrastructure management system 33 described above, but may also be obtained from a source other than the infrastructure management system 33.
[0156] FIG. 7 shows an example of the real-time hazard map. In the example shown in FIG. 7, a slide bar is provided at the bottom of the real-time hazard map. That is, the real-time hazard map is created so that, by operating the slide bar, information on current and future flood risk can be provided for each time period, such as now, 1 hour, 2 hours, 3 hours, half a day later, 1 day later, 2 days later, 3 days later, and several days later, based on the current time. Note that the real-time hazard map in this embodiment may be created to provide information on past flood risk in addition to information on current and future flood risk.
[0157] Next, the resilience SoS 40 provides (transmits) the flood risk (flood risk, inland flooding risk, and power outage risk) prediction content obtained in step S2 to the first mobility SoS 31A, second mobility SoS 31B, VPP SoS 32, and infrastructure management system 33 managed by the resilience SoS 40 (step S3). The prediction content provided in step S3 may be the real-time hazard map itself, or may be partial information extracted from the real-time hazard map. In other words, the prediction content provided in step S3 may differ depending on the recipient. The flood risk prediction content may also be provided to systems other than the first mobility SoS 31A, second mobility SoS 31B, VPP SoS 32, and infrastructure management system 33.
[0158] When the process of step S3 is executed, the resilience SoS40 collects information according to the flood risk predicted in step S2 (step S4). In this case, the resilience SoS40 collects information on people, vehicles, facilities, electricity, etc. present in the flood warning area (flood warning area), inland water flooding warning area (inland water flooding warning area), and power outage warning area (power outage warning area).
[0159] Here, the resilience SoS 40 is assumed to be communicably connected to a system 70 that manages mobile phones (hereinafter referred to as a mobile phone management system) as shown in Fig. 8. The mobile phones managed by the mobile phone management system 70 are assumed to be, for example, smartphones with a GPS (Global Positioning System) function, but the mobile phones may also be conceptually understood to include mobile terminals such as tablet computers with a GPS function.
[0160] The mobile phone management system 70 in this embodiment may include multiple server devices (systems) operated by multiple companies (or corporations, etc.) Note that Fig. 8 is the same as Fig. 4 except for the addition of the mobile phone management system 70, and therefore a detailed description thereof will be omitted here.
[0161] The above-mentioned person information is collected, for example, from the mobile phone management system 70 based on location information from mobile phones or smartphones. The collected person information makes it possible to identify the number of people present in each of the alert areas and caution areas set for the above-mentioned flood risk. The person information collected from the mobile phone management system 70 also includes demographic information (attribute information) such as age and gender.
[0162] In this case, the risk of power outage can be calculated (predicted) based on the estimated power restoration period based on the number of people in the power outage warning area and the power outage warning area, and the amount of power required by each person in the power outage warning area and the power outage warning area. Note that the amount of power required by each person is assumed to be stored in advance in the VPP SoS 32 or the VPP CPS servers 22A and 22B, etc.
[0163] Furthermore, flood risk and inland flooding risk can be calculated (predicted) by taking into account, for example, the number of people present in a flood warning area, flood warning area, inland flooding warning area, and inland flooding warning area, and the likelihood of evacuation in the event of an emergency based on the demographic information of each person present in the flood warning area, flood warning area, inland flooding warning area, and inland flooding warning area. Note that the demographic information in this case may also include information on the need for assistance (such as whether or not a person requires nursing care or has a disability).
[0164] It should be noted that the information about people collected from the mobile phone management system 70 here does not need to be information that can identify individuals (i.e., personal information), but rather information that includes each person's location and demographic information (anonymously processed information or pseudonymized information, etc.).
[0165] Vehicle information is collected from the first mobility SoS31A and the second mobility SoS31B based on the location information of electric vehicles (and other vehicles). In this case, vehicles present in each alert area, each caution area, and their surrounding areas can be used as a means of evacuation and transportation, and the number of people that can be accommodated (the number of people who can be evacuated using vehicles) for each area (region) is identified (predicted). In addition, the vehicle information may include image data captured by cameras mounted on vehicles present in each alert area, each caution area, and their surrounding areas. Note that mobility means such as electric vehicles controlled by the first mobility SoS31A and the second mobility SoS31B are assumed to be usable as a means of transportation in the same way as in normal times until actual damage occurs (flooding occurs) or until such damage is imminent.
[0166] Facility information is collected from the infrastructure management system 33 based on the location information of each facility (government offices, hospitals, etc.). Based on the facility information collected in this way, it is possible to calculate (predict) flood risk in consideration of the fact that normal operation at each facility will be impossible in the event of a flood (flood, inland water inundation, or power outage) or that some functions will have to be reduced due to dependence on emergency power equipment. The facility information may include, for example, image data captured by a surveillance camera installed within the facility.
[0167] Power information is collected from the VPP SoS32 based on the location information of various power generation facilities and the areas subject to power transmission and distribution. This information includes, for example, the status of power generation facilities within each alert and warning area, the status of power transmission and distribution, the status of power storage, and forecasts of supply and demand in the event of a power outage. This power information can be used to calculate (predict) flood risk by considering the difference between the amount of power generated by power generation facilities installed within each alert and warning area under normal circumstances and the amount of power generated during a flood. The power generation facilities that will be unavailable during a flood or inland flooding can be determined based on the installation location and height of the facilities and their associated equipment. The power generation facilities that will be unavailable during a power outage can be determined based on whether they are facilities that cannot operate without grid power, or whether they have a black start function that allows them to operate even during a power outage (when there is no power supply to the grid).
[0168] The resilience SoS40 calculates (predicts) flood risk, including risk of inland flooding and risk of power outages, for all alert and caution areas based on the four perspectives of people, vehicles, facilities, and electricity, for each region (for example, an area divided into a mesh of 100m intervals or an area based on units such as cities, wards, towns, and villages). Note that various methods can be applied to calculate flood risk (flood risk, risk of inland flooding, and risk of power outages), and AI (deep learning, machine learning, etc.) may be used, for example. The resilience SoS40 may collect information other than those mentioned above and may consider (calculate) risks other than those mentioned above.
[0169] After the processing of step S4 is executed as described above, the process returns to step S2 and is repeated. In this case, through the exchange of various information described above with the first mobility SoS 31A, the second mobility SoS 31B, the VPP SoS 32, the infrastructure management system 33, the meteorological system 50, and the mobile phone management system 70, the resilience SoS 40 can sequentially predict flood risks (flood risk, inland flooding risk, and power outage risk) for each region, from detecting an increase in flood risk due to a direct hit of a typhoon to eliminating the flood risk due to a significant shift in the typhoon's path or the typhoon passing by, and provide real-time hazard maps to relevant organizations, etc. Providing such real-time hazard maps is useful for encouraging voluntary early evacuation and advance precautions.
[0170] As described above, when an increased flood risk is detected, the resilience SoS 40 must sequentially update the real-time hazard map created based on information regarding all alert and caution areas. The resilience SoS 40 operates to collect various information even under normal circumstances. However, when an increased flood risk is detected, the resilience SoS 40 operates to continuously and periodically receive a large amount of information at a higher frequency than under normal circumstances. In other words, when an increased flood risk (risk of a socially difficult situation) is detected in the integrated system of this embodiment, information exchange between the horizontal SoS, the vertical SoS, and other systems becomes more intensive. Meanwhile, communication between the resilience SoS 40 and the first mobility SoS 31A, the second mobility SoS 31B, the VPP SoS 32, the infrastructure management system 33, etc. under normal circumstances may be less frequent than when an increased flood risk is detected.
[0171] The manner in which information is exchanged between the resilience SoS 40 and each of the first mobility SoS 31A, second mobility SoS 31B, VPP SoS 32, infrastructure management system 33, weather system 50, and mobile phone management system 70 is determined in advance based on the predictions of various natural disasters and the risk levels of those natural disasters. In other words, when the integrated system is configured as shown in FIG. 8, for example, the weather system 50 can receive (information for identifying) an increased risk of various natural disasters, and real-time human information, which is basic information for predicting (calculating) the risk in the event of a natural disaster, from the mobile phone management system 70. The preparatory procedures (including contracts, etc.) for enabling the weather system 50 to receive information for identifying the increased risk of various natural disasters from the mobile phone management system 70 are assumed to have been completed in advance according to the scheme described above in FIG. 5. The weather system 50 and the mobile phone management system 70, like the resilience SoS 40, are systems (i.e., systems that constitute the integrated system) that have been authenticated by the authentication server 63 shown in FIG. 5.
[0172] 6, steps S2 to S4 are repeatedly executed to collect a large amount of information about each area (alert area and caution area), and the accuracy of information about various risks and information about expected damage (for example, real-time hazard maps) can be improved based on the collected large amount of information. Note that such a large amount of collected information corresponds to information that can be used to construct a digital twin, for example.
[0173] Although not shown in Fig. 6, when the accuracy of the information on the risk and the information on the expected damage described above reaches a certain level, the resilience SoS40 may execute a process (control) for disaster mitigation. Note that whether the accuracy is at a certain level or above can be determined based on, for example, the number of times the processes of steps S2 to S4 shown in Fig. 6 are executed, but it may also be determined from other perspectives.
[0174] In this case, the resilience SoS 40 can prepare for securing power in the event of a flood by, for example, charging all electric vehicles via the first mobility SoS 31A and the second mobility SoS 31B, and can guarantee (improve) the possibility of evacuation by gathering electric vehicles in advance near each alert area and each caution area for evacuation in the event of an emergency. However, if a flood risk of a certain level or higher is confirmed, all vehicles, including electric vehicles, may be evacuated outside each area (alert area and caution area).
[0175] The resilience SoS 40 also suppresses power consumption by raising electricity rates via the VPP SoS 32, and promotes the accumulation of power (i.e., charging stationary storage batteries installed in individual homes, apartment complexes, commercial facilities, and public facilities, converting stored power to hydrogen via P2C at hydrogen stations, etc.) in conjunction with the suppression of power consumption. This allows for preparations to ensure power supply in the event of a natural disaster, so that stored power can be discharged even in the event of a power outage. Power storage may be performed according to the characteristics of each area (alert area and caution area). In this case, for areas with a high risk of flooding, for example, power may be stored in high-ground facilities (such as stationary storage batteries) or the charging of electric vehicles may be prioritized. Furthermore, for areas (regions) that would be isolated in the event of a power outage, power storage may be prioritized in facilities that can provide power to the area.
[0176] Furthermore, the resilience SoS 40 can reduce the risk of flooding in each area (alert area and caution area) in advance by reducing the amount of water stored in the dam (i.e., opening the dam) via the infrastructure management system 33 (river / levee / dam management CPS server 23B), for example. Furthermore, processing may be performed to maximize the drainage capacity of wastewater treatment facilities in each area (alert area and caution area).
[0177] Here, the processing for disaster mitigation has been described as being performed by the resilience SoS40, but as described above, each of the first mobility SoS31A, the second mobility SoS31B, the VPP SoS32 and the infrastructure management system 33 may perform processing (control) for disaster mitigation based on the real-time hazard map provided sequentially by the resilience SoS40.
[0178] Furthermore, although the description herein has been given assuming that disaster mitigation processing is executed when the accuracy of information on risk and information on expected damage, etc., reaches a certain level, executing the above-mentioned disaster mitigation processing imposes a heavy burden on society even when the probability of a natural disaster (e.g., flood) occurring is low. For this reason, disaster mitigation processing may be executed when it is determined that a flood risk is imminent based on meteorological information, etc., provided by the weather system 50 (i.e., there is an extremely high probability, for example, that a typhoon will hit directly in the next few days). However, since it is preferable to complete disaster mitigation processing before a natural disaster actually occurs, the processing is executed in consideration of the time allowance between the detection of an increased risk of flooding due to a direct typhoon hit and the actual typhoon hitting.
[0179] Figure 6 explains the operation of the integrated system when an increase in flood risk (risk of occurrence of a socially difficult situation) is detected, but if the occurrence of such flood is actually detected, the operation of the integrated system described above will switch to control when such flood occurs.
[0180] An example of the processing procedure of the integrated system when a flood actually occurs will be described below with reference to the flowchart in Figure 9. Note that the above-mentioned normal operation and the operation (processing) when an increase in the risk of flooding is detected are assumed to be performed continuously, separate from the processing shown in Figure 9.
[0181] First, the resilience SoS 40 determines whether a flood (natural disaster) has actually occurred (step S11). As described above, if the flood includes flooding, inundation by inland water, and power outage, in step S11, it is determined that a flood has occurred if at least one of flooding, inundation by inland water, and power outage has occurred.
[0182] In addition, whether or not a flood has actually occurred can be determined from the information provided by the above-mentioned weather system 50, as well as data on the damage situation regarding the occurrence of floods collected by, for example, the national government, local governments, police, fire departments, and news organizations.
[0183] If it is determined that no flood damage has occurred (NO in step S11), the process returns to step S11 and is repeated.
[0184] On the other hand, if it is determined that a flood has occurred (YES in step S11), the resilience SoS40 identifies the area where the flood (damage caused by the flood) occurred (hereinafter referred to as the flood-occurred area) and the area surrounding the flood-occurred area (hereinafter referred to as the flood-surrounding area) (step S12).
[0185] In step S12, the flood-prone area is identified by receiving information from the national government, local governments, police, fire departments, and news organizations, etc., to identify the area where flooding (flooding, inland flooding, and power outages) has occurred.
[0186] The flood-prone area may be identified based on, for example, image data captured by a camera mounted on an electric vehicle and received via the first mobility SoS 31A and the second mobility SoS 31B, and image data captured by a surveillance camera installed in various public facilities and received via the infrastructure management system 33. The flood-prone area includes an area where flooding has occurred (hereinafter referred to as a flood-prone area), an area where inland flooding has occurred (hereinafter referred to as an inland flooding area), and an area where a power outage has occurred (hereinafter referred to as a power outage area).
[0187] In addition, if it is determined that a flood has occurred as described above (i.e., if the occurrence of a flood is detected), the above-mentioned disaster mitigation processing may be executed for the flood surrounding area identified in step S12.
[0188] Below, the resilience SoS40 collects information regarding the flood-prone area and surrounding areas identified in step S12 described above, but when a flood occurs, it is preferable to obtain more information than during normal times or when an increased risk of flooding is detected.
[0189] Here, when a flood occurs, identifying the above-mentioned flood-prone area and people in the surrounding area with water can be useful information for rescuing the user.
[0190] In this case, because the mobile phone management system 70 holds personal information (personal information related to natural persons) of users who own mobile phones managed by the mobile phone management system 70, it is conceivable that the resilience SoS 40 could use, for example, personal information of users who are in the flood-prone area and the surrounding area from the mobile phone management system 70 in providing resilience solutions. However, even if advance procedures have been taken to enable the reception of personal information such as location information and demographic information (anonymously processed information or pseudonymized information) from the mobile phone management system 70 in accordance with the scheme described in Figure 5 above, the resilience SoS 40 would not be able to use the personal information described above.
[0191] For this reason, as described above, it is preferable to carry out advance procedures in accordance with the scheme described in Figure 5 in order to use personal information held by the mobile phone management system 70 to provide resilience solutions in the event of a flood, for example.
[0192] However, while the law requires prior consent from users (those who have authority over the personal information) when providing personal information to third parties, it is difficult to obtain prior consent from all users who may reside within the flood-prone and flood-prone areas mentioned above. Furthermore, the scope of the exceptions in the Personal Information Protection Act that exempt third parties from requiring consent for use is unclear. In such cases, it is conceivable to obtain consent from users residing within the flood-prone and flood-prone areas before using their personal information in the Resilience SoS40. However, obtaining consent from each user is not practical in the face of socially challenging situations such as floods. On the other hand, using the personal information of users for whom prior consent has been obtained but not the personal information of users for whom prior consent has not been obtained (i.e., not including it in information on people needing rescue or damage information, etc.) would be considered unethical.
[0193] Here we have explained the personal information of users held by the mobile phone management system 70, but from the perspective of providing high-quality resilience solutions in the event of a socially difficult situation such as a flood, it is preferable for information to be exchanged flexibly between the SoS, CPS server, edge, and other systems that make up the integrated system.
[0194] Therefore, in this embodiment, when a socially difficult situation such as a flood occurs, the resilience SoS40 executes a process (hereinafter referred to as information transmission permission process) for permitting specific information (provided information) used for a specific purpose to be transmitted (provided) from a specific information providing system to a specific information receiving system (step S13) in accordance with the scheme described in Fig. 5. Details of the information transmission permission process will be described later.
[0195] When the process of step S13 is executed, the resilience SoS40 collects various information regarding the flood-prone area and the flood-prone area identified in step S12, including the specific provision information permitted for transmission in step S13 (step S14). The information collected in step S14 is used to provide resilience solutions.
[0196] After the process of step S14 is executed, the process returns to step S12 and is repeated. In this case, the processes of steps S12 to S14 are repeatedly executed until, for example, the flood damage and the damage related to the flood damage (i.e., the socially difficult situation) are resolved.
[0197] Next, an example of the processing procedure of the information transmission permission processing will be described with reference to the flowchart of FIG.
[0198] In the information transmission permission process, the resilience SoS 40 operates as the intermediary server described above. In this case, the resilience SoS 40 confirms that a specific information providing system and a specific information receiving system have been authenticated by the authentication server (step S21).
[0199] Next, the resilience SoS40 sets the usage conditions for the specific provided information according to the purpose and mode of use of the specific provided information (step S22). The usage conditions set in step S22 include the range within which the specific provided information can be used (usage range) and the period during which the provided information is transmitted from the information providing system to the information receiving system (usage period).
[0200] The use conditions set in step S22 may be different from the conditions registered (set) by the information providing system (information providing side) or the authority of the specific provided information described in FIG. 5 above. In this embodiment, the authority of the specific provided information is, for example, a person who has the right to make the final decision regarding the use of the specific provided information. If the specific provided information is personal information, the individual (natural person) is the authority of the specific provided information. On the other hand, if the specific provided information is information of a corporation, the corporation is the authority of the specific provided information. If the specific provided information is information of a government or local public body, the government or local public body is the authority of the specific provided information. Furthermore, the conditions registered (set) by the authority may include the use conditions previously agreed upon by the authority (e.g., a natural person). Note that the information provider and the authority may be different, for example, in cases where the information provider (system administrator or management organization) is simply the entity that collects the information.
[0201] When the processing of step S22 is executed, the resilience SoS40 assumes that the specific information provider and the specific information recipient have agreed to the terms of use set in step S22 (i.e., that the terms of use between the information provider and the information recipient for providing the specific information have been confirmed to be met) (step S23).
[0202] When the process of step S23 is executed, the resilience SoS 40 generates permission information for permitting the transmission of the specific provided information and transmits the permission information to the specific information providing system and the specific information receiving system. The permission information generated in the resilience SoS 40 includes the use conditions, etc., set in step S22. In other words, the permission information includes information for specifying the use conditions of the specific provided information. The permission information is transmitted to the specific information providing system and the specific information receiving system, but the information for specifying the use conditions of the specific provided information may be transmitted to at least one of the specific information providing system and the specific information receiving system.
[0203] As described above, the specific information providing system that receives the permission information transmitted from the resilience SoS 40 transmits the specific provided information to the information receiving system in accordance with the permission information. Meanwhile, the specific information receiving system that receives the permission information transmitted from the resilience SoS 40 receives the specific provided information transmitted from the specific information providing system. The specific provided information received by the specific information receiving system in this manner is used in accordance with the usage conditions (i.e., information for specifying the usage conditions) and the like included in the permission information transmitted from the resilience SoS 40.
[0204] Here, in the above-described FIG. 10, the resilience SoS 40 is described as operating as the intermediary server, but the intermediary server may be other than the resilience SoS 40 (that is, there may be an intermediary server other than the resilience SoS 40).
[0205] An example of the procedure for information transmission permission processing in the case where there is an intermediary server other than the resilience SoS 40 will be described below with reference to the flowchart of FIG.
[0206] In this case, the resilience SoS40 sets the use conditions of the specific provided information according to the purpose and mode of use of the specific provided information (step S31). The use conditions set in step S31 are the same as the use conditions set in step S22 shown in FIG.
[0207] Next, the resilience SoS40 assumes that the specific information provider and the specific information recipient have agreed to the terms of use set in step S31 (i.e., that the terms of use between the information provider and the information recipient for providing the specific information have been confirmed to be met) (step S32).
[0208] When the process of step S32 is executed, the resilience SoS40 transmits information (hereinafter referred to as instruction information) to the intermediary server instructing the intermediary server to permit transmission of the specific provided information (step S33). Note that the instruction information transmitted in step S33 includes an instruction to overwrite the use conditions set in step S31 as the use conditions of the specific provided information, an instruction that the specific information provider and the specific information recipient have agreed to the use conditions, and the like.
[0209] The intermediary server that receives the instruction information transmitted from the resilience SoS 40 as described above executes the same processing as that shown in FIG. 10 in accordance with the instruction from the resilience SoS 40 contained in the instruction information.
[0210] According to the information transmission permission process described above, while following the scheme described in Figure 5 (i.e., the same procedure as a normal marketplace), time-consuming procedures such as payment of fees can be skipped and the resilience SoS40 can permit (or instruct permission for) the transmission of specific provided information from a specific information providing system to a specific information receiving system.
[0211] In this embodiment, the resilience SoS 40 determines the exchange of specific provided information (provided information used for a specific purpose) between a specific information providing system and a specific information receiving system. However, the specific provided information, specific information providing system, and specific information receiving system (combination) may be predetermined in association with, for example, a type of socially difficult situation (e.g., flooding), or may be dynamically determined by analyzing information indicating the status of the flood-prone area and surrounding areas using AI or the like. The specific provided information, specific information providing system, and specific information receiving system may also be determined in consideration of the specifications of the system including the SoS, CPS server, and edge, whether or not authentication has been performed by an authentication server, legal compliance status, security level, information currently held, and information that can be obtained in the future. It is assumed that the resilience SoS 40 has previously acquired the information necessary to determine the specific provided information, specific information providing system, and specific information receiving system.
[0212] Furthermore, since this embodiment is configured to exceptionally allow the exchange of specific provided information in response to the occurrence of a socially difficult situation, the provided information, the information providing system, and the information receiving system are determined so that the scope of use of the provided information and the scope of disclosure of the provided information are kept to the minimum necessary.
[0213] The above-described information transmission permission process (determination of specific provided information, specific information providing system, and specific information receiving system) may be executed at the initiative of the resilience SoS 40. Specifically, the resilience SoS 40 can execute the information transmission permission process (determine to transmit specific provided information from a specific information providing system to a specific information receiving system) without receiving a request from the specific information receiving system for permission to transmit the specific provided information. The resilience SoS 40 can also execute the information transmission permission process without receiving a request from either the information providing system or the information receiving system for permission to transmit the provided information. The information transmission permission process may be executed in accordance with a request (demand) from the SoS, CPS server, edge, and other systems constituting the integrated system.
[0214] Furthermore, the determination of the specific information to be provided, the specific information providing system, and the specific information receiving system (i.e., the determination of whether to transmit the specific information to be provided from the specific information providing system to the specific information receiving system) may be made when the resilience SoS 40 confirms that a predetermined condition is met. Examples of the satisfaction of the predetermined condition include the occurrence of a flood or the expansion or contraction of the flood-affected area. Furthermore, the satisfaction of the predetermined condition may include, for example, an instruction that the occurrence of a flood has been confirmed or an instruction that specific information needs to be shared (i.e., manual input of specific information).
[0215] A specific example of the operation of the integrated system when a flood actually occurs will be described below. First, with reference to Fig. 12, a case will be described in which personal information of users held by the mobile phone management system 70 is used to provide resilience solutions.
[0216] The resilience SoS40 transmits information to identify the above-mentioned flood-prone areas (flood-prone areas, inland flooding areas, and power outage areas) and flood-surrounding areas to the mobile phone management system 70, and receives personal information of users who own mobile phones located within the flood-prone areas and flood-surrounding areas from the mobile phone management system 70.
[0217] In this case, it is assumed that the execution of the above-mentioned information transmission permission process allows the mobile phone management system 70 to transmit the user's personal information to the resilience SoS 40. Note that the specific provided information (provided information used for a specific purpose) in the information transmission permission process in this case is the user's personal information used to identify people in need of rescue in a flood and to understand the damage situation according to the flood. Furthermore, the specific information providing system and the specific information receiving system in the information transmission permission process are the mobile phone management system 70 and the resilience SoS 40, respectively.
[0218] As described above, the user's personal information received from the mobile phone management system 70 includes, for example, the user's name, age, sex, address, email address, mobile phone number, location information of the mobile phone, the time the location information was acquired, and at least some of the user's activity level, estimated health level, estimated evacuation situation, etc. based on changes in the location information over time.
[0219] Although the location information included in the user's personal information is assumed to be obtained by, for example, a GPS function (or a gyro sensor, etc.), the location information may also be information indicating a location estimated from the location of a base station with which the mobile phone communicates and connects. In other words, the location information may be information that indicates the location of the mobile phone with a certain degree of accuracy.
[0220] Furthermore, for example, in areas experiencing power outages, it is expected that a mobile phone will lose contact due to a disruption of communication between the mobile phone and a base station. Similarly, in flood-prone areas and areas subject to inland flooding, a mobile phone may lose contact due to a failure or malfunction of a base station, or due to being submerged in water. In such cases, personal information including location information indicating the location of the mobile phone immediately before it lost contact may be received from the mobile phone management system 70.
[0221] The resilience SoS 40 can use the personal information of users who own mobile phones located in the flood-affected area and surrounding areas, received (collected) from the mobile phone management system 70 as described above, to provide resilience solutions. In this case, the resilience SoS 40 transmits rescue needer information indicating people in need of rescue and damage information indicating the damage situation in response to the occurrence of flooding to, for example, a server device (hereinafter referred to as a firefighting system) 80 installed in a facility to which emergency teams and firefighters belong. In this case, an information transmission permission process is executed in which the specific provided information is the user's personal information, the specific information providing system is the resilience SoS 40, and the specific information receiving system is the firefighting system 80. It is assumed that the firefighting system 80 has been authenticated by the authentication server described above.
[0222] Here, the firefighting system 80 is assumed to be composed of a plurality of server devices, each installed in a different region. In this case, the destination of the user's personal information is assumed to be limited to the server device that has jurisdiction over the flood-affected area and the surrounding area. Furthermore, instead of transmitting all of the user's personal information, for example, only a portion of the information required for emergency response and firefighting may be transmitted.
[0223] In addition, although the information transmission permission process has been described here as being executed with the specific provided information being the user's personal information, the specific information providing system being the resilience SoS 40, and the specific information receiving system being the firefighting system 80, if it is assumed that the user's personal information will be transmitted (transferred) from the resilience SoS 40 to the firefighting system 80, permission information for permitting the transfer of the personal information to the firefighting system 80 may be transmitted to the resilience SoS 40 in the information transmission permission process with the specific provided information being the user's personal information, the specific information providing system being the mobile phone management system 70, and the specific information receiving system being the resilience SoS 40. In this case, the conditions for use of the personal information included in the permission information transmitted to the resilience SoS 40 may include, for example, information that can identify one or more other server devices (here, the firefighting system 80) to which the personal information (at least a portion of it) can be transferred.
[0224] In addition, considering that areas surrounding flood damage are less urgent than areas where flood damage occurs, for users who own mobile phones located within such areas surrounding flood damage, anonymous or pseudonymized information in which the names have been processed may be sent to the fire system 80 as information on future rescue recipients (future damage prediction information) rather than personal information including names, etc.
[0225] The personal information of users who own mobile phones located in the flood-prone area and surrounding areas described above is used as information on people needing rescue, and may therefore be transmitted to a server device (hereinafter referred to as a medical system) 90 installed in a medical institution such as a hospital, as shown in FIG. 13. In this case, an information transmission permission process is executed in which the specific information to be provided is the user's personal information, the specific information providing system is the resilience SoS 40, and the specific information receiving system is the medical system 90. Note that the medical system 90 is assumed to have been authenticated by the authentication server described above.
[0226] If the medical system 90 is configured with multiple server devices, each installed in a different region, the destination of the user's personal information is limited to the server device that has jurisdiction over the flood-affected area and surrounding areas. Instead of transmitting all of the user's personal information, only a portion of the information necessary for the user's treatment may be transmitted.
[0227] Next, with reference to FIG. 14, a case will be described in which personal information of a user held by the first mobility SoS 31A and the second mobility SoS 31B is used to provide a resilience solution.
[0228] The first mobility SoS 31A and the second mobility SoS 31B provide mobility services as described above, and are assumed to hold personal information of users who receive the mobility services. The personal information of users held by the first mobility SoS 31A and the second mobility SoS 31B is assumed to include, for example, the user's name, age, gender, address, email address, mobile phone number, etc.
[0229] In this case, the resilience SoS40 transmits information for identifying the flood-prone area and the flood-surrounding area to the first mobility SoS31A and the second mobility SoS31B, and receives information (hereinafter referred to as EV information) about mobility (e.g., electric vehicles) present within the flood-prone area and the flood-surrounding area from the first mobility SoS31A and the second mobility SoS31B.
[0230] The EV information received from the first mobility SoS 31A and the second mobility SoS 31B includes personal information of users receiving the above-mentioned mobility services (i.e., users currently using the electric vehicles). The transmission of the users' personal information from the first mobility SoS 31A and the second mobility SoS 31B to the resilience SoS 40 is permitted by the execution of the above-mentioned information transmission permission process. The specific provided information (information used for a specific purpose) in this information transmission permission process is the users' personal information used to understand the latest status of people in need of rescue in a flood disaster. Note that the specific provided information is not the personal information of all users currently using electric vehicles, but is limited to the personal information of users currently using electric vehicles whose current location is within a flood-prone area or a flood-surrounding area (particularly, an area surrounding a flood-prone area or an inland flooding-prone area) or whose destination is within a flood-prone area or a flood-surrounding area. Furthermore, the specific information providing systems in the information transmission permission process are the first mobility SoS 31A and the second mobility SoS 31B, and the specific information receiving system is the resilience SoS 40.
[0231] As described above, the EV information is explained as including personal information of the user who is using the electric vehicle, but the EV information further includes the starting point, destination value, current location information, and the driving range and status of the electric vehicle based on the remaining battery power, etc. The status included in the EV information may include, for example, whether or not the service is being provided (the user is using the vehicle), and if the user is using the vehicle, may be information indicating the situation of the user (i.e., the user's status).
[0232] The resilience SoS 40 can use the EV information received (collected) from the first mobility SoS 31A and the second mobility SoS 31B to provide a resilience solution. An example of a resilience solution using the EV information will be described below.
[0233] First, if the current location of the electric vehicle in use is within a flood-prone area (particularly, a flood or inland flooding area) or a surrounding area of the flood-prone area (particularly, an area surrounding the flood or inland flooding area), and the destination is outside the flood-prone area or the surrounding area, the resilience SoS 40 can infer that the user of the electric vehicle is evacuating. Such a user is set as a person in need of rescue, and the user's status can be updated during evacuation.
[0234] Furthermore, if the current location of an electric vehicle in use is outside the flood-prone area and the surrounding area, and the destination of the electric vehicle is within the flood-prone area and the surrounding area, the resilience SoS 40 (or the first mobility SoS 31A and the second mobility SoS 31B, etc.) will prompt the user to change the destination, except in special circumstances such as when the user is a rescue team. In this case, control may be executed to forcibly change the destination of the electric vehicle.
[0235] Furthermore, if the current location and destination of an electric vehicle in use are both within a flood-prone area or surrounding area, the resilience SoS40 (or the first mobility SoS31A and second mobility SoS31B) may prompt the driver to change the destination based on predictions of future changes in flood risk, etc.
[0236] Here, the resilience SoS 40 can receive (collect) information about electric vehicles (EV information) that are currently in use and whose current location and destination are both outside the flood-prone area and surrounding areas from the first mobility SoS 31A and the second mobility SoS 31B. This EV information does not need to include personal information about the user. Such electric vehicles whose current location and destination are both outside the flood-prone area and surrounding areas can be used as mobility for rescue, relief, and evacuation in the flood-prone area. Therefore, the resilience SoS 40 (or the first mobility SoS 31A and the second mobility SoS 31B) may secure and operate the electric vehicle whose current location and destination are both outside the flood-prone area and surrounding areas as mobility for rescue, relief, and evacuation in the flood-prone area as soon as the electric vehicle whose current location and destination are both outside the flood-prone area and surrounding areas is no longer in use. In this case, the destination of the electric vehicle that has been discontinued may be automatically set to a location near the flood-prone area and surrounding areas.
[0237] It should be noted that the resilience solution using the resilience SoS 40 (or the first mobility SoS 31A and the second mobility SoS 31B) described above is an example, and the resilience SoS 40 may be configured to perform other operations (controls).
[0238] Furthermore, the resilience SoS 40 may transmit personal information of a user whose electric vehicle is currently in use within the flood-prone area or surrounding area and whose destination is outside the flood-prone area or surrounding area as rescue recipient information to the firefighting system 80. In this case, an information transmission permission process is executed in which the specific information to be provided is the user's personal information, the specific information providing system is the resilience SoS 40, and the specific information receiving system is the firefighting system 80.
[0239] The first mobility SoS 31A and the second mobility SoS 31B each control a plurality of mobility CPS servers 21A and 21B and a large number of mobilities (electric vehicles, etc.). Therefore, when a large number of electric vehicles passing through different routes according to the travel requests of each user capture images of the surroundings of the electric vehicles using cameras (image capture devices) mounted on the electric vehicles, the captured image data is useful information for understanding the damage situation in the event of a flood.
[0240] For this reason, the resilience SoS40 may transmit information for identifying the flood-prone area and the surrounding area to the first mobility SoS31A and the second mobility SoS31B, and may receive image data captured by electric vehicles located in the flood-prone area and the surrounding area from the first mobility SoS31A and the second mobility SoS31B. In this case, the resilience SoS40 may transmit the image data (still images or videos) received from the first mobility SoS31A and the second mobility SoS31B, or damage information indicating the latest damage situation based on the image data, to, for example, the infrastructure management system 33 and the fire protection system 80, or may provide it to a national or local government. Note that the image data received from the first mobility SoS31A and the second mobility SoS31B may be accompanied by information such as the time and location at which the image data was captured. Furthermore, the image data received from the first mobility SoS31A and the second mobility SoS31B may be range images or range videos obtained using, for example, LiDAR or millimeter-wave radar.
[0241] Here, the amount of information and data volume of image data received from a large number of electric vehicles becomes enormous, and there is a concern that this will further worsen the communication environment, which is expected to be constrained during floods (disasters). For this reason, it is preferable to reduce the number of communications during floods, for example.
[0242] In this case, when the resilience SoS40 determines the specific provided information, the specific information providing system, and the specific information receiving system in the information transmission permission process described above (i.e., generates permission information or instruction information), the resilience SoS40 may not receive the provided information to be exchanged. In other words, it is preferable that the resilience SoS40 receives information necessary for the resilience SoS40 to understand the current flood risk and damage situation (for example, to create a digital twin related to the damage situation), but other information may be exchanged directly between the SoS, CPS server, edge, and other systems that make up the integrated system without going through the resilience SoS40. Note that whether or not to include the resilience SoS40 in the information exchange path may be individually and specifically selected based on the provided information (contents) to be exchanged, etc.
[0243] Specifically, for example, when the above-mentioned information transmission permission process is executed with a specific information providing system being a mobile phone management system 70 and a specific information receiving system being a fire protection system 80, it is possible to transmit the user's personal information directly from the mobile phone management system 70 to the fire protection system 80.
[0244] Here, for example, one of the multiple infrastructure CPS servers managed by the infrastructure management system 33 is a river, levee, and dam management CPS server 23B. As shown in Figure 15, consider a case where image data captured by a camera mounted on an electric vehicle located (or traveling in the surrounding area) in the vicinity of a location where a levee managed (maintained) by the river, levee, and dam management CPS server 23B is located within a flood-prone area and surrounding area is transmitted from the first mobility SoS31A and the second mobility SoS31B to the river, levee, and dam management CPS server 23B.
[0245] In this case, if the prior procedures for exchanging image data between the first mobility SoS31A and the second mobility SoS31B and the river, levee and dam management CPS server 23B are not carried out, the river, levee and dam management CPS server 23B will not be able to receive the image data from the first mobility SoS31A and the second mobility SoS31B, even though the image data is useful information for understanding the damage status of the levee and carrying out maintenance.
[0246] In this case, the resilience SoS40 can provide specific information (information used for a specific purpose) as image data around the levee in the flood-prone area and surrounding areas, which is used to check the latest status of the levee (damage status, etc.), and by executing an information transmission permission process with the first mobility SoS31A and second mobility SoS31B as the specific information providing system and the river, levee, and dam management CPS server 23B as the specific information receiving system, it can enable (permit) the exchange of image data between the first mobility SoS31A and second mobility SoS31B and the river, levee, and dam management CPS server 23B.
[0247] Although the river, levee and dam management CPS server 23B is installed, for example, in each region, the destination of image data from the first mobility SoS31A and the second mobility SoS31B is limited to the river, levee and dam management CPS server 23B that manages levees within flood-prone areas and flood-surrounding areas.
[0248] Here, it is assumed that the first mobility SoS 31A and the second mobility SoS 31B manage image data captured by a large number of electric vehicles controlled by multiple mobility CPS servers 21A and 21B, respectively, for each predetermined area (region). In this case, the first mobility SoS 31A and the second mobility SoS 31B can transmit (provide) image data selected from all managed image data (i.e., redundant image data) based on criteria such as high pixel count, good image content, and the most recent image capture time (i.e., image data that has undergone redundancy elimination processing) to the river, levee, and dam management CPS server 23B. The river, levee, and dam management CPS server 23B can receive the image data transmitted from the first mobility SoS 31A and the second mobility SoS 31B and perform control such as levee maintenance based on the image data.
[0249] The image data may be transmitted directly from one of the plurality of mobility CPS servers 21A and 21B, for example, a mobility CPS server that controls electric vehicles located in the flood-prone area and surrounding areas, to the river, levee, and dam management CPS server 23B. In this case, an information transmission permission process may be executed in which the specific information to be provided (information used for a specific purpose) is image data of the area around the levee in the flood-prone area and surrounding areas that is used to check the latest status of the levee (damage status, etc.), the specific information providing system is the mobility CPS servers 21A and 21B, and the specific information receiving system is the river, levee, and dam management CPS server 23B.
[0250] In this configuration in which image data is transmitted directly from the mobility CPS servers 21A and 21B to the river, levee, and dam management CPS server 23B, image data that has not yet undergone redundancy elimination processing by the first mobility SoS 31A and the second mobility SoS 31B is received by the river, levee, and dam management CPS server 23B, and therefore processing equivalent to the processing for eliminating redundancy must be performed on the river, levee, and dam management CPS server 23B side. However, in this case, there is no need to transmit image data from the mobility CPS servers 21A and 21B to the first mobility SoS 31A and the second mobility SoS 31B, and therefore communication costs can be reduced.
[0251] Also, as shown in Figure 16, consider a case where information about electric vehicles (EV information) located in a power outage area (limited area) and the surrounding area of the power outage area is transmitted from the first mobility SoS31A and the second mobility SoS31B to the VPP power transmission and distribution CPS server 22B.
[0252] In this case, if the prior procedures for exchanging EV information between the first mobility SoS31A and the second mobility SoS31B and the VPP transmission and distribution CPS server 22B are not carried out, the VPP transmission and distribution CPS server 22B will not be able to receive the EV information from the first mobility SoS31A and the second mobility SoS31B, even though the EV information is useful information for utilizing the electricity stored in the batteries of electric vehicles.
[0253] In this case, the resilience SoS40 can enable (permit) the exchange of EV information between the first mobility SoS31A and the second mobility SoS31B and the VPP transmission and distribution CPS server 22B by executing an information transmission permission process in which specific provided information (information used for a specific purpose) is information on electric vehicles (EV information) located in the power outage area and surrounding areas used to resolve the power outage state, and the specific information providing system is the first mobility SoS31A and the second mobility SoS31B, and the specific information receiving system is the VPP transmission and distribution CPS server 22B.
[0254] Note that the VPP power transmission and distribution CPS server 22B is installed, for example, in each region, but the destination of EV information from the first mobility SoS31A and the second mobility SoS31B is limited to the VPP power transmission and distribution CPS server 22B (i.e., the VPP specific region power transmission and distribution server) whose power transmission and distribution area is the area where the power outage occurred (i.e., which transmits and distributes power to the area where the power outage occurred).
[0255] According to such a configuration in which EV information is transmitted from the first mobility SoS31A and the second mobility SoS31B to the VPP power transmission and distribution CPS server 22B, for example, electric vehicles with large remaining battery power can be gathered in the area where the power outage has occurred, and the power stored in the storage batteries installed in the electric vehicles can be simultaneously discharged under the control of the VPP power transmission and distribution CPS server 22B, thereby temporarily resolving the power outage in the area where the power outage has occurred.
[0256] Here, we have explained the case where the first mobility SoS31A and the second mobility SoS31B (multiple mobility CPS servers 21A and 21B) control an electric vehicle as mobility, but if, for example, an electric ship or drone is controlled as mobility, it is also possible to use the electricity stored in the storage battery installed on the electric ship or drone.
[0257] Although detailed explanation will be omitted, the meteorological system 50, the mobile phone management system 70, the firefighting system 80, and the medical system 90 described in this embodiment may be integrated by the resilience SoS 40.
[0258] As described above, in this embodiment, when the resilience SoS (horizontal SoS) 40 confirms that the objective condition is satisfied, the resilience SoS 40 determines, for example, whether to transmit first information including at least a portion of data collected by a first server device belonging to a first industrial domain from one or more first edges from the first server device to a second server device belonging to a second industrial domain, or whether to transmit second information including at least a portion of data collected by the second server device from one or more second edges from the second server device to the first server device (i.e., a combination of specific provided information, a specific information providing system, and a specific information receiving system). When the resilience SoS 40 determines that the first information is to be transmitted from the first server device to the second server device, the resilience SoS 40 transmits information to the first server device and the second server device to permit the transmission of the first information from the first server device to the second server device. On the other hand, if the resilience SoS40 decides to send the second information from the second server device to the first server device, the resilience SoS40 sends information to the first server device and the second server device to allow the second information to be sent from the second server device to the first server device.
[0259] In this embodiment, such a configuration allows smooth exchange of information between a plurality of server devices belonging to different industrial fields.
[0260] Specifically, the resilience SoS 40 has a function of permitting the transmission (exchange) of the provided information (provided information used for a specific purpose) according to a combination of the specific information providing system and the specific information receiving system. This allows the resilience SoS 40, which is a horizontal SoS that manages multiple industrial domains, to collect useful information from vertical SoSs, such as the first mobility SoS 31A, the second mobility SoS 31B, and the VPP SoS 32, that manage each of the industrial domains, and other systems, such as the infrastructure management system 33. Therefore, the resilience SoS 40 can promote the exchange of information necessary for resilience solutions across multiple industrial domains while maintaining an overall overview. When information is collected from multiple industrial domains (vertical SoSs, CPS servers, edge systems, and other systems) as described in this embodiment, it is possible to use the collected information to build a digital twin that recreates the real-world (real space) situation of each industrial domain (e.g., mobility, energy, and infrastructure) in cyberspace (virtual space), as shown in FIG. 17 . Furthermore, if the processing of steps S12 to S14 shown in Figure 9 above is repeated, the accuracy (level of detail) of this digital twin can be improved, and it is believed that high-quality resilience solutions can be provided using this digital twin.
[0261] Note that the resilience SoS40 has the function of an intermediary server in the scheme (information exchange scheme) described in Figure 5, but in general, the intermediary server confirms that the conditions for providing information set by the information provider are met, and then transmits permission information to the information providing system and the information receiving system to permit the provision (transmission) of information.
[0262] However, when a socially difficult situation such as a flood (disaster) occurs, confirming the fulfillment of conditions for information provision, which is equivalent to a consensus (such as a contract) between the information provider and the information recipient, goes against the demand for a rapid response. Furthermore, it is not realistic to achieve a consensus in advance for all combinations of corporations, systems, and servers that may exchange information in the event of a flood. Furthermore, simply achieving a consensus in advance may not be enough to respond to cases where unexpected information provision is required. For this reason, when a predetermined condition such as a flood occurs, the resilience SoS 40 according to this embodiment considers that the conditions for information provision set by the information provider have been met and permits the transmission of that information.
[0263] The above-mentioned first server device includes a first CPS server (e.g., first mobility CPS server 21A and second mobility CPS server 21B, etc.) and a first vertical SoS (e.g., first mobility SoS 31A and second mobility SoS 31B, etc.) that controls the first CPS server, and the above-mentioned second server device includes a second CPS server (e.g., VPP power generation CPS server 22A and VPP power transmission and distribution CPS server 22B, etc.) and a second vertical SoS (e.g., VPP SoS 32, etc.) that controls the second CPS server, and the resilience SoS 40 is configured to control the first and second vertical SoS. That is, the above-mentioned first information may be transmitted from the first vertical SoS to the second vertical SoS, or from the first vertical SoS to the second CPS server, or from the first CPS server to the second vertical SoS, or from the first CPS server to the second CPS server. Furthermore, the above-mentioned second information may be transmitted from the second vertical SoS to the first vertical SoS, or from the second vertical SoS to the first CPS server, or from the second CPS server to the first vertical SoS, or from the second CPS server to the first CPS server.
[0264] Furthermore, when the resilience SoS 40 determines that the first information is to be transmitted from the first server device to the second server device as described above, the resilience SoS 40 transmits permission information for specifying the conditions of use of the first information to at least one of the first server device and the second server device. The conditions of use of the first information are determined by the resilience SoS 40 and may be different from the conditions of use set by the administrator of the first server device (i.e., the information provider) or the authority of the first information (e.g., a user, etc.). On the other hand, when the resilience SoS 40 determines that the second information is to be transmitted from the second server device to the first server device, the resilience SoS 40 transmits permission information for specifying the conditions of use of the second information to at least one of the first server device and the second server device. The conditions of use of the second information are determined by the resilience SoS 40 and may be different from the conditions of use set by the administrator of the second server device or the authority of the second information. More specifically, if the above-mentioned first information or second information includes a user's personal information (personal information relating to a natural person), the terms of use of the first information or second information are determined by the resilience SoS40 and may differ from the terms of use previously agreed to by the user (natural person).
[0265] In this embodiment, with this configuration, even if the resilience SoS (horizontal SoS) 40 allows the transmission of information, the limited information is used only in a specific, limited information receiving system under limited conditions, thereby preventing the information from being used for fraudulent purposes, etc.
[0266] The use conditions included in the permission information transmitted from the resilience SoS 40 to the first and second server devices include, for example, the range or period of use of the information, but the permission information need only be information for permitting the transmission (transmission) of information. Specifically, the permission information may be information that allows the conditions regarding the transmission and reception of information to be deemed satisfied, or may be information necessary for the transmission and reception of information, or may further include the type, quantity, quality, freshness, acquisition method, format, type, etc. of the provided information to be transmitted and received. Furthermore, the use conditions included in the permission information may include, for example, information that allows the second server device to identify one or more other servers to which the second server device can transfer part of the provided information.
[0267] In addition, if the permission information sent from the resilience SoS40 to the first and second server devices does not include a usage period, the resilience SoS40 may send information to the information providing system and the information receiving system to stop the exchange of information (i.e., the transmission of information from the information providing system to the information receiving system) or the use of information (i.e., the use of information already received in the information receiving system) when it is determined that the flood and the damage related to the flood (i.e., the socially difficult situation) have subsided, or may send information to the intermediary server instructing the exchange or use of the information to be stopped.
[0268] Furthermore, when the resilience SoS 40 generates the permission information, at least a portion of the information used to generate the permission information may be received from another system or may be manually input. Note that at least a portion of the information used to generate the permission information may include, for example, specific provided information (specific purpose), information on a specific information providing system, and information on a specific information receiving system. Furthermore, at least a portion of the information used to generate the permission information may include, for example, information on whether to generate permission information.
[0269] Here, the case where the resilience SoS (horizontal SoS) 40 operates as an intermediary server has been described, but a configuration in which an intermediary server separate from the resilience SoS 40 is installed is also possible. Specifically, when it is determined that the first information is to be transmitted from the first server device to the second server device, the resilience SoS 40 may transmit instruction information to the intermediary server (third server device) to instruct the intermediary server to permit transmission of the first information from the first server device to the second server device. On the other hand, when it is determined that the second information is to be transmitted from the second server device to the first server device, the resilience SoS 40 may transmit instruction information to the intermediary server to instruct the intermediary server to permit transmission of the second information from the second server device to the first server device.
[0270] In this case, the intermediary server receives instruction information (request) from the resilience SoS40, assumes that the conditions regarding information provision set by the information provider have been met, and sends permission information to the information providing system and the information receiving system to allow the exchange (transmission) of the information.
[0271] Here, for convenience, the first and second server devices have been described as being a vertical SoS and a CPS server, but the first and second server devices may be at least one of the horizontal SoS, vertical SoS, CPS server, edge, and other systems that make up the integrated system described above. Also, in this embodiment, the horizontal SoS has been mainly described as controlling the vertical SoS, but the integrated system may be configured without a vertical SoS, and the horizontal SoS may be configured to control at least a plurality of CPS servers.
[0272] Furthermore, in this embodiment, the horizontal SoS (resilience SoS40) is described as executing the information transmission permission process (i.e., when certain conditions are confirmed to be met, the information providing system decides to transmit the provided information to the information receiving system), but the function for executing the information transmission permission process (i.e., the function related to permission to transmit information) may be realized, for example, on the vertical SoS side. Also, in this embodiment, the horizontal SoS is described as controlling a first server device belonging to a first industrial area and a second server device belonging to a second industrial area different from the first industrial area, but the first industrial area and the second industrial area may be different or the same.
[0273] As described above, this embodiment includes a configuration that exceptionally permits the exchange of specific provided information in response to the occurrence of a socially difficult situation, and therefore it is preferable that the permission to exchange the specific provided information is transparent.
[0274] For this reason, the resilience SoS 40 further has a storage function, a viewing function, and an automatic deletion function shown in FIG.
[0275] The storage function is a function for storing information (hereinafter referred to as permission content information) indicating that the exchange of specific provided information (i.e., specific information provided from a specific information providing system to a specific information receiving system for a specific purpose) is permitted when the permission information or instruction information described above is generated in the resilience SoS 40. Note that the resilience SoS 40 is equipped with a storage device (server) that stores information collected in the integrated system and information generated by the resilience SoS 40 according to each situation, for example, during normal times, when an increase in flood risk is detected, and when a flood occurs, and the above-mentioned permission content information is also stored in the storage device.
[0276] The permission information stored by the storage function will be described below: The permission information includes basic information and detailed information regarding the permission to exchange the specific provided information described above.
[0277] Fig. 19 shows an example of the data structure of basic information included in the permission content information. As shown in Fig. 19, the basic information includes type, information providing system, information receiving system, permission date and time, event, purpose, and deletion status.
[0278] The type indicates the type of specific provided information that is permitted to be exchanged, such as personal information, anonymously processed information, and pseudonymized information.
[0279] The information providing system refers to the system that provided the specific provided information that is permitted to be exchanged (i.e., the providing system). The information receiving system refers to the system that received the specific provided information that is permitted to be exchanged (i.e., the receiving system).
[0280] The permission date and time indicates the date and time when permission information or instruction information for permitting the exchange (transmission) of specific provided information was generated. The permission date and time may be the date and time when the permission information was transmitted from the resilience SoS 40 or the intermediary server to the information providing system and the information receiving system, or the date and time when the instruction information was transmitted from the resilience SoS 40 to the intermediary server.
[0281] The event indicates the background occurrence (i.e., the type of socially difficult situation) for which the resilience SoS40 allows the exchange of specific provided information, such as a flood.
[0282] The purpose indicates the purpose for which specific provided information is permitted to be sent from the information providing system to the information receiving system (i.e., the reason for providing the information). Note that the purpose may include, for example, identifying people in need of rescue in a flood disaster, understanding the damage situation, or resolving a power outage. Note that this purpose corresponds to the conditions for use, such as the scope of use of the specific provided information.
[0283] The deletion status indicates whether or not specific provided information transmitted (provided) from an information providing system to an information receiving system has been deleted in the information receiving system.
[0284] As described above, Figure 19 shows the permission content information (basic information included therein) stored by the memory function when permission information for permitting the transmission of a user's personal information from the mobile phone management system 70 to the resilience SoS40 or instruction information for instructing permission for such transmission is generated, and the permission content information is stored in the memory device each time permission information or instruction information is generated.
[0285] Furthermore, for example, as described above, in cases where the range in which specific provided information is exchanged between the information providing system or the information receiving system is limited (restricted) according to the flood-prone area, flood-surrounding area (region), etc., it is preferable that the permission content information be stored in a manner that clearly indicates that the information providing system or the information receiving system is limited. Furthermore, the basic information included in the permission content information may include various information based on various information stored in the storage device, and may further include, for example, (information about) the period of use of the specific provided information.
[0286] FIG. 20 shows an example of the data structure of detailed information included in permission content information. The detailed information is information indicating details of specific provided information that was actually exchanged. The example shown in FIG. 20 shows that provided information including name, age, sex, address, email address, mobile phone number, mobile phone location information, and the time the location information was acquired was transmitted from the information providing system (mobile phone management system 70) shown in FIG. 19 to the information receiving system (resilience SoS 40). Note that depending on the type of provided information, such as personal information, anonymously processed information, and pseudonymized information, some or all of the detailed information may be in a format that has been subjected to various data processing, such as anonymization or pseudonymization.
[0287] The viewing function is a function that presents the permission content information (basic information and detailed information) stored by the storage function in response to an external request (i.e., enables the permission-related information to be viewed from the outside). Note that, when the exchange of personal information of a user held by the mobile phone management system 70 is permitted as specific provided information, the viewing function can be used by the user (the user himself / herself), for example.
[0288] In this case, for example, a user accesses a website related to resilience solutions using a smartphone or the like and enters the ID and password assigned to the user. When the resilience SoS40 (its viewing function) determines that the personal information of the user identified by the entered ID, password, etc. (viewing request) is being transmitted (provided) as specific provided information from the information providing system to the information receiving system, it generates viewing screen information for displaying permission information (basic information and detailed information) indicating that the exchange of the user's personal information has been permitted, and sends the viewing screen information to the user's smartphone. On the smartphone side, a viewing screen including the permission information is displayed based on the viewing screen information, allowing the user to view (confirm) the permission information.
[0289] Whether or not the personal information of a user who has entered an ID and password has been transmitted (provided) from the information providing system to the information receiving system as specific provided information can be determined, for example, by comparing the name or mobile phone number of the user identified by the ID and password with the name or mobile phone number of the detailed information included in the permission content information. Alternatively, without comparing with the information included in the permission content information, it may be determined whether or not the personal information of the user has been transmitted (provided) from the information providing system to the information receiving system as specific provided information by linking it with the user's ID registered in the information providing system, for example.
[0290] In addition, as described above, when specific provided information is exchanged without going through the resilience SoS40, the information providing system or the information receiving system included in the permitted content information (basic information) may be inquired as to whether the user who accessed the website related to resilience solutions (the user who entered the ID and password) is a user who is allowed to view the permitted content information.
[0291] As described above, in this embodiment, the specific provided information that is permitted to be exchanged by the resilience SoS40 may include personal information, etc., for which prior consent has not been obtained for provision to a third party. However, the viewing function makes it possible to check the circumstances under which specific information, including personal information, has been provided to a third party (information provider, information recipient, content, timing, etc.).
[0292] It is preferable that the information providing system and the information receiving system displayed on the viewing screen be displayed so that it is possible to understand that specific information has been exchanged within a limited scope. For example, by displaying the event and the purpose of the information on the viewing screen, it becomes possible to understand that information has been exchanged within a limited scope, such as responding to the occurrence of a socially difficult situation, such as a water disaster (for example, a flood).
[0293] Here we have explained the case where a user who is authorized to exchange personal information uses the viewing function, but the viewing function can also be used by the information provider (i.e., the administrator or management organization of the information provider system).
[0294] The automatic deletion function is a function for controlling the automatic deletion of specific information transmitted from an information providing system to an information receiving system in the information receiving system.
[0295] In this case, after the resilience SoS 40 determines that the specific provided information should be transmitted from the information providing system to the information receiving system, the resilience SoS 40 determines whether the intended use of the specific provided information has been achieved. For example, if the socially difficult situation is a flood, the intended use of the specific provided information can be determined based on the damage situation related to the flood based on meteorological information and other information. Furthermore, the intended use of the specific provided information may be determined based on set usage conditions, such as whether the usage period included in the permission information or instruction information has elapsed.
[0296] When the resilience SoS 40 determines that the purpose of use of the specific provided information has been achieved, it transmits information (hereinafter referred to as an erasure request) to the information receiving system requesting the deletion of the specific provided information, and confirms whether the specific provided information has been deleted by receiving a response to the erasure request (e.g., a response indicating whether the provided information has been deleted) from the information receiving system. Note that the erasure request may include, for example, information that enables the information receiving system to identify a deadline for deleting the specific provided information. In this case, for example, the information receiving system can delete the specific provided information when the deadline for deleting the specific provided information has arrived, and transmit a response (response to the erasure request) to the resilience SoS 40 indicating that the provided information has been deleted.
[0297] When it is confirmed that the specific provided information has been deleted, the deletion status of the basic information included in the permission information is updated. This deletion status is displayed as permission information on the viewing screen, so that the user can understand that, for example, their personal information has been used only within the limited scope of responding to the socially difficult situation and has been appropriately deleted in the information receiving system.
[0298] As described above, the resilience SoS40 has memory, viewing, and automatic deletion functions, so that it can disclose that the specific information provided that the resilience SoS40 has authorized to be exchanged is only used in emergencies such as when a socially difficult situation arises, thereby providing a sense of security to users who have received personal information, etc. without their prior consent.
[0299] Although the present embodiment has been described primarily assuming the provision of resilience solutions for socially difficult situations such as floods, the resilience SoS 40 may also provide resilience solutions to prepare for social problems such as food waste, poverty alleviation, traffic accidents, and greenhouse gas emissions (decarbonization). However, unlike floods, such issues as food waste, poverty alleviation, traffic accidents, and greenhouse gas emissions (decarbonization) can occur with high frequency even under normal circumstances. Therefore, it is preferable that the resilience SoS 40 (horizontal SoS) be configured to constantly maintain close communication with various vertical SoSs, CPS servers, edges, and systems, and to perform orchestration to optimize the entire integrated system.
[0300] Furthermore, the application or use of the horizontal SoS according to this embodiment is not limited to resilience, and the horizontal SoS may be used for linking vertical SoS or CPS servers between different industrial domains.
[0301] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, as well as within the scope of the invention described in the claims and their equivalents. [Explanation of symbols]
[0302] 11, 12...Edge, 21, 21A, 21B, 22, 22A, 22B, 23A to 23C...CPS server (server device), 31, 31A, 31B, 32...Vertical SoS (server device), 33...Infrastructure management system, 40...Horizontal SoS (server device), 40a...CPU, 40b...Non-volatile memory, 40c...Main memory, 40d...Communication device, 50...Weather system, 61...Information providing system, 62...Information receiving system, 63...Authentication server, 64...Intermediary server, 70...Mobile phone management system, 80...Fire fighting system, 90...Medical system.
Claims
1. A method executed by a horizontal SoS (System of Systems) that manages a first server device belonging to a first industry domain and a second server device belonging to a second industry domain different from the first industry domain, the method comprising: When the horizontal SoS confirms that a first condition is satisfied, the horizontal SoS determines a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; When the first server device is determined as the first system and the second server device is determined as the second system, the horizontal SoS transmits, to the first server device and the second server device, information for permitting transmission of first information from the first server device to the second server device. Equipped with the first information includes personal information about natural persons collected by the first server device from one or more first edges; The transmission of the first information is permitted even without the consent of the natural person if a second condition is met; the horizontal SoS transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The terms of use of the first information are determined by the horizontal SoS and may differ from the terms of use previously agreed upon by the natural person. method.
2. A method executed by a horizontal SoS (System of Systems) that manages a first server device belonging to a first industry domain and a second server device belonging to a second industry domain different from the first industry domain, the method comprising: When the horizontal SoS confirms that a first condition is satisfied, the horizontal SoS determines a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; When the first server device is determined as the first system and the second server device is determined as the second system, the horizontal SoS transmits, to the first server device and the second server device, information for permitting transmission of first information from the first server device to the second server device. Equipped with the first information includes at least a portion of data collected by the first server device from one or more first edges; the horizontal SoS transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The use conditions of the first information are determined by the horizontal SoS and may be different from the use conditions set by the administrator of the first server device or the sovereign of the first information. method.
3. the first server device is a first vertical SoS that controls first CPS servers belonging to the first industrial domain; The horizontal SoS governs at least the first vertical SoS. The method according to claim 1 or claim 2.
4. the first server device is a first CPS server managed by a first vertical SoS belonging to the first industry domain, The horizontal SoS controls at least the first CPS server by controlling the first vertical SoS. The method according to claim 1 or claim 2.
5. the first information includes personal information relating to a natural person; The terms of use of the first information may be different from the terms of use previously agreed upon by the natural person. The method of claim 2.
6. 3. The method according to claim 1, wherein the conditions for use of the first information include information that enables the second server device to identify one or more other servers to which the second server device can transfer at least a portion of the first information.
7. the horizontal SoS transmits information to the second server device requesting deletion of the first information; The information for requesting the deletion of the first information includes information by which the second server device can identify a deadline for deleting the first information.
7. The method according to any one of claims 1 to 6.
8. 8. The method of claim 1, wherein the horizontal SoS determines the first system and the second system when it confirms satisfaction of the first condition without receiving a request for permission to transmit information from either the first server device or the second server device.
9. 8. A method according to any one of claims 1 to 7, wherein the horizontal SoS determines the first server device as the first system and determines the second server device as the second system when it confirms satisfaction of the first condition without receiving a request from the second server device to send the first information from the first server device to the second server device.
10. The method according to claim 1 , wherein the horizontal SoS presents first permission information indicating that transmission of the first information is permitted in response to an external request.
11. A method executed by a horizontal SoS (System of Systems) that controls a first server device belonging to a first industrial domain and a second server device belonging to a second industrial domain different from the first industrial domain, and is capable of communicating with a third server device that permits data transmission between at least the first server device and the second server device, the method comprising: When the horizontal SoS confirms that a first condition is satisfied, the horizontal SoS determines a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; When the first server device is determined as the first system and the second server device is determined as the second system, the horizontal SoS transmits to the third server device information for instructing the third server device to permit transmission of first information from the first server device to the second server device. Equipped with the first information includes personal information about natural persons collected by the first server device from one or more first edges; The transmission of the first information is permitted even without the consent of the natural person if a second condition is met, the horizontal SoS transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The terms of use of the first information are determined by the horizontal SoS and may differ from the terms of use previously agreed upon by the natural person. method.
12. A method executed by a horizontal SoS (System of Systems) that controls a first server device belonging to a first industrial domain and a second server device belonging to a second industrial domain different from the first industrial domain, and is capable of communicating with a third server device that permits data transmission between at least the first server device and the second server device, the method comprising: When the horizontal SoS confirms that a first condition is satisfied, the horizontal SoS determines a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; When the first server device is determined as the first system and the second server device is determined as the second system, the horizontal SoS transmits to the third server device information for instructing the third server device to permit transmission of first information from the first server device to the second server device. Equipped with the first information includes at least a portion of data collected by the first server device from one or more first edges; the horizontal SoS transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The use conditions of the first information are determined by the horizontal SoS and may be different from the use conditions set by the administrator of the first server device or the sovereign of the first information. method.
13. the first server device is a first vertical SoS that controls first CPS servers belonging to the first industrial domain; The horizontal SoS governs at least the first vertical SoS.
13. The method according to claim 11 or claim 12.
14. the first server device is a first CPS server managed by a first vertical SoS belonging to the first industry domain, The horizontal SoS controls at least the first CPS server by controlling the first vertical SoS.
13. The method according to claim 11 or claim 12.
15. the first information includes personal information relating to a natural person; The terms of use of the first information may be different from the terms of use previously agreed upon by the natural person.
13. The method of claim 12.
16. 13. The method according to claim 11, wherein the conditions for use of the first information include information that enables the second server device to identify one or more other servers to which the second server device can transfer at least a portion of the first information.
17. the horizontal SoS transmits information to the second server device requesting deletion of the first information; The information for requesting the deletion of the first information includes information by which the second server device can identify a deadline for deleting the first information.
17. The method of any one of claims 11 to 16.
18. 18. The method of claim 11, wherein the horizontal SoS determines the first system and the second system when it confirms satisfaction of the first condition without receiving a request for permission to transmit information from either the first server device or the second server device.
19. 18. A method according to any one of claims 11 to 17, wherein the horizontal SoS determines the first server device as the first system and determines the second server device as the second system when it confirms satisfaction of the first condition without receiving a request from the second server device to send the first information from the first server device to the second server device.
20. 20. The method according to claim 11, wherein the horizontal SoS presents first permission information indicating that transmission of the first information is permitted in response to an external request.
21. In a SoS (System of Systems) that controls a first server device belonging to a first industry domain and a second server device belonging to a second industry domain, a processing means for determining, when a first condition is confirmed to be satisfied, a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; a transmitting means for transmitting, when the first server device is determined as the first system and the second server device is determined as the second system, information for permitting transmission of first information from the first server device to the second server device to the first server device and the second server device; Equipped with the first information includes personal information about natural persons collected by the first server device from one or more first edges; The transmission of the first information is permitted even without the consent of the natural person if a second condition is met; the transmitting means transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The terms of use of the first information are determined by the SoS and may differ from the terms of use previously agreed upon by the natural person. SoS.
22. In a SoS (System of Systems) that controls a first server device belonging to a first industry domain and a second server device belonging to a second industry domain, a processing means for determining, when a first condition is confirmed to be satisfied, a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; a transmitting means for transmitting, when the first server device is determined as the first system and the second server device is determined as the second system, information for permitting transmission of first information from the first server device to the second server device to the first server device and the second server device; Equipped with the first information includes at least a portion of data collected by the first server device from one or more first edges; the transmitting means transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The use conditions of the first information are determined by the SoS and may be different from the use conditions set by the administrator of the first server device or the sovereign of the first information. SoS.
23. In a SoS (System of Systems) that controls a first server device belonging to a first industrial domain and a second server device belonging to a second industrial domain and is capable of communicating with a third server device that permits data transmission between at least the first server device and the second server device, a processing means for determining, when a first condition is confirmed to be satisfied, a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; a transmitting means for transmitting, when the first server device is determined as the first system and the second server device is determined as the second system, information to the third server device for instructing the third server device to permit transmission of first information from the first server device to the second server device; Equipped with the first information includes personal information about natural persons collected by the first server device from one or more first edges; The transmission of the first information is permitted even without the consent of the natural person if a second condition is met; the transmitting means transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The terms of use of the first information are determined by the SoS and may differ from the terms of use previously agreed upon by the natural person. SoS.
24. In a SoS (System of Systems) that controls a first server device belonging to a first industrial domain and a second server device belonging to a second industrial domain and is capable of communicating with a third server device that permits data transmission between at least the first server device and the second server device, a processing means for determining, when a first condition is confirmed to be satisfied, a first system that will be an information provider and a second system that will be an information receiver from among a plurality of server devices including at least the first server device and the second server device; a transmitting means for transmitting, when the first server device is determined as the first system and the second server device is determined as the second system, information to the third server device for instructing the third server device to permit transmission of first information from the first server device to the second server device; Equipped with the first information includes at least a portion of data collected by the first server device from one or more first edges; the transmitting means transmits information for defining a use condition of the first information to at least one of the first server device and the second server device; The use conditions of the first information are determined by the SoS and may be different from the use conditions set by the administrator of the first server device or the sovereign of the first information. SoS.
Citation Information
Patent Citations
Topology model of intelligent assembly workshop of distributed information physical system
CN109150678A
Information mediating system and information mediating method to be used in the system
JP2003044708A
Selection device, selection method, and selection program
JP2019046193A
Data processing flow management system and method
JP6612450B2
IoT COMMUNICATION UTILIZING SECURE ASYNCHRONOUS P2P COMMUNICATION AND DATA EXCHANGE
US20160337127A1