Determination method, information processing device, program, and response method
The method ensures secure communication by determining the security status of communication partner devices, addressing the lack of verification in existing technologies and reducing security risks through legitimate and authorized interactions.
Patent Information
- Application Number
- PCT/JP2024/015085
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-16
- Publication Date
- 2025-10-23
AI Technical Summary
Existing technologies fail to verify whether appropriate security operations are being performed on communication partner devices, leading to potential security risks such as unauthorized control and compromised systems.
A determination method and response method that allow a first system to request and obtain the security status of a second system's device, making determinations based on security status information including history of anomalies, vulnerabilities, and monitoring, and ensuring legitimate and authorized communication.
Enables secure communication by verifying that appropriate security operations are performed on communication partner devices, reducing security risks and preventing unauthorized control.
Smart Images

Figure JP2024015085_23102025_PF_FP_ABST
Abstract
Description
Determination method, information processing device, program, and response method
[0001] The present disclosure relates to a determination method, an information processing device, a program, and a response method.
[0002] When communicating, it is necessary to authenticate the other party and perform secure communication. For example, Patent Literature 1 discloses a technology for authenticating the other party using a digital certificate. Also, for example, Non-Patent Literature 1 discloses a technology for determining access permission based on system context information in a zero trust architecture.
[0003] Japanese Patent Application Laid-Open No. 2020-031378
[0004] Scott Rose and three others, "Zero Trust Architecture," [online], August 2020, NIST Special Publication 800-207, [accessed April 1, 2024], Internet: <https: / / nvlpubs.nist.gov / nistpubs / SpecialPublications / NIST.SP.800-207.pdf>
[0005] However, the technology of Patent Document 1 only performs authentication using a digital certificate and does not verify whether appropriate security operations are being performed on the device of the other party of communication. The technology of Non-Patent Document 1 determines access permission based on system context information, but it may be difficult to collect context information for systems owned by different parties. Furthermore, the technology of Non-Patent Document 1 also does not verify whether appropriate security operations are being performed on the device of the other party of communication.
[0006] If the device with which you are communicating does not implement appropriate security operations, new security risks such as unauthorized control may arise, so it is desirable to communicate with devices that implement appropriate security operations.
[0007] Therefore, the present disclosure provides a determination method, an information processing device, a program, and a response method that can determine whether appropriate security operations are being performed in a communication partner device.
[0008] A determination method according to one aspect of the present disclosure is a determination method executed by an information processing device included in a first system, in which when a first device included in the first system communicates with a second device included in a second system different from the first system, a request to obtain the security status of the second device is output to the second system, the security status of the second device is obtained from the second system that obtained the acquisition request, and a determination regarding the communication is made based on the security status of the second device obtained from the second system.
[0009] An information processing device according to one aspect of the present disclosure is an information processing device included in a first system, and when a first device included in the first system communicates with a second device included in a second system different from the first system, the information processing device includes: an output unit that outputs a request to the second system to obtain the security status of the second device; an acquisition unit that acquires the security status of the second device from the second system that obtained the acquisition request; and a judgment unit that makes a judgment regarding the communication based on the security status of the second device obtained from the second system.
[0010] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described determination method.
[0011] A response method according to one aspect of the present disclosure is a response method executed by an information processing device included in a second system, which, when a first device included in a first system different from the second system communicates with a second device included in the second system, obtains a request to obtain the security status of the second device from the first device and outputs the security status of the second device to the first device.
[0012] An information processing device according to one aspect of the present disclosure is an information processing device included in a second system, and includes: an acquisition unit that acquires a request to acquire the security status of the second device from the first device when communication is performed between a first device included in a first system different from the second system and a second device included in the second system; and an output unit that outputs the security status of the second device to the first device.
[0013] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described response method.
[0014] According to one aspect of the present disclosure, it is possible to realize a determination method or the like that can determine whether appropriate security operations are being performed in a communication partner device.
[0015] FIG. 1 is a diagram illustrating an overall configuration of a security status linking system according to a first embodiment. FIG. 2 is a diagram illustrating a configuration of an in-vehicle network system according to the first embodiment. FIG. 3 is a block diagram illustrating a functional configuration of a central ECU according to the first embodiment. FIG. 4 is a diagram illustrating an example of a vehicle status according to the first embodiment. FIG. 5 is a diagram illustrating an example of vehicle configuration information according to the first embodiment. FIG. 6 is a block diagram illustrating a functional configuration of a battery management ECU according to the first embodiment. FIG. 7 is a diagram illustrating an example of version information according to the first embodiment. FIG. 8 is a block diagram illustrating a functional configuration of an EV management server according to the first embodiment. FIG. 9 is a diagram illustrating an example of a certification certificate held by a certification certificate holding unit according to the first embodiment. FIG. 10 is a diagram illustrating an example of vehicle information according to the first embodiment. FIG. 11 is a diagram illustrating a configuration of a charging station according to the first embodiment. FIG. 12 is a block diagram illustrating a functional configuration of a station management server according to the first embodiment. FIG. 13 is a diagram illustrating an example of a certification certificate held by the station management server according to the first embodiment. FIG. 14 is a diagram illustrating an example of a station status according to the first embodiment. FIG. 15 is a sequence diagram illustrating an operation of the security status linking system according to the first embodiment. FIG. 16 is a flowchart illustrating an operation of the station management server according to the first embodiment. FIG. 17 is a flowchart showing a first example of the detailed operation of step S32 shown in FIG. 16 . FIG. 18 is a flowchart showing a second example of the detailed operation of step S32 shown in FIG. 16 . FIG. 19 is a flowchart showing a detailed operation of step S34 shown in FIG. 16 . FIG. 20 is a flowchart showing an operation that is subsequently executed after the operation shown in FIG. 19 is completed. FIG. 21 is a flowchart showing an operation that is executed in a continuous monitoring mode according to the first embodiment. FIG. 22 is a sequence diagram showing an operation of a security status linking system according to a modification of the first embodiment. FIG. 23 is a flowchart showing a first example of the operation of a station management server according to a modification of the first embodiment. FIG. 24 is a flowchart showing a second example of the operation of a station management server according to the modification of the first embodiment. FIG. 25 is a block diagram showing a functional configuration of a charging device according to a second embodiment.Fig. 26 is a diagram showing an example of the security status of a charging device according to embodiment 2. Fig. 27 is a sequence diagram showing the operation of the security status linking system according to embodiment 2. Fig. 28 is a flowchart showing the operation of a charging device according to embodiment 2. Fig. 29 is a diagram showing an example of the display of a security status inquiry.
[0016] (Background to the Invention of the Present Disclosure) Before describing the embodiments of the present disclosure, the background to the invention of the present disclosure will be described.
[0017] The connection of different systems, such as between electric vehicles (EVs) and EV charging stations, can create new security risks. Examples of new security risks include the risk that a compromised EV could exploit vulnerabilities in an EV charging station, thereby affecting the power infrastructure, and the risk that a compromised EV charging station could improperly control an EV, thereby causing harm to users.
[0018] Furthermore, since security operations are performed by different organizations in different systems, it is difficult to grasp the reliability or security status of the system with which you are communicating. However, from the perspective of reducing security risks, it is desirable to communicate with systems that are performing appropriate security operations.
[0019] Patent Document 1 discloses that a communication partner is authenticated using an electronic certificate to enable secure communication, but does not disclose that the communication partner's device is verified to ensure that it has not been compromised or that appropriate security operations are being carried out.
[0020] Therefore, the inventors of the present application have conducted extensive research into a determination method that can determine whether appropriate security operations are being performed in a communication partner device, and have devised the determination method described below.
[0021] A determination method according to a first aspect of the present disclosure is a determination method executed by an information processing device included in a first system, in which when a first device included in the first system communicates with a second device included in a second system different from the first system, a request to obtain the security status of the second device is output to the second system, the security status of the second device is obtained from the second system that obtained the acquisition request, and a determination regarding the communication is made based on the security status of the second device obtained from the second system.
[0022] This allows the first device to obtain the security status of the second device belonging to a different system, and therefore makes it possible to determine from the security status of the second device whether appropriate security operations are being carried out in the second device (the device with which the first device is communicating).
[0023] A determination method according to a second aspect of the present disclosure may be a determination method according to the first aspect, in which the security state of the second device is determined based on at least one of information regarding a history of security abnormalities in the second device, information regarding vulnerabilities contained in software constituting the second device, and information regarding security monitoring of the second device.
[0024] This allows the first device to acquire the security status of the second device, which is determined based on at least one of information regarding the history of security anomalies in the second device, information regarding vulnerabilities contained in the software that constitutes the second device, and information regarding security monitoring of the second device. Such security status can be useful information for determining whether appropriate security operations are being performed in the second device.
[0025] A determination method according to a third aspect of the present disclosure is a determination method according to the first or second aspect, in which, when the first device receives a request from the second device to use a function possessed by the first device, the determination method may output the acquisition request to the second system.
[0026] This allows a decision to be made regarding communication with the second device when the security risk in the first device is higher, thereby effectively reducing the security risk in the first device.
[0027] A determination method according to a fourth aspect of the present disclosure is a determination method according to the third aspect, and may output to the second system at least one of information indicating the function requested by the second device from the first device, equipment information of the second device obtained from the second device, and information indicating the current location of the device itself.
[0028] This allows the second system to determine whether the first device is a legitimate device based on the information acquired from the first device, thereby preventing the second system from outputting the security status of the second device in response to an unauthorized acquisition request.
[0029] A determination method according to a fifth aspect of the present disclosure is a determination method according to any one of the first to fourth aspects, wherein the first system may manage the security status of only the first device out of the first device and the second device.
[0030] This makes it possible to use the security status of a second device that is not managed by the first system to determine whether appropriate security operations are being performed for the second device.
[0031] A determination method according to a sixth aspect of the present disclosure is a determination method according to any one of the first to fifth aspects, wherein the first device is one of an electric vehicle and a charging / discharging device, and the second device is the other of the electric vehicle and the charging / discharging device.
[0032] This allows communication with the other of the electric vehicle and the charging / discharging device, where appropriate security operations are being carried out.
[0033] An information processing device according to a seventh aspect of the present disclosure is an information processing device included in a first system, and when a first device included in the first system communicates with a second device included in a second system different from the first system, the information processing device includes: an output unit that outputs a request to the second system to obtain the security status of the second device; an acquisition unit that acquires the security status of the second device from the second system that obtained the acquisition request; and a judgment unit that makes a judgment regarding the communication based on the security status of the second device obtained from the second system.
[0034] This provides the same effect as the above-mentioned determination method.
[0035] A program according to an eighth aspect of the present disclosure is a program for causing a computer to execute the determination method according to any one of the first to sixth aspects.
[0036] This provides the same effect as the above-mentioned determination method.
[0037] A response method according to a ninth aspect of the present disclosure is a response method executed by an information processing device included in a second system, and when a first device included in a first system different from the second system communicates with a second device included in the second system, the response method obtains a request to obtain the security status of the second device from the first device and outputs the security status of the second device to the first device.
[0038] This allows the first device to obtain the security status of the second device belonging to a different system from the second system, and therefore makes it possible to determine from the security status of the second device whether appropriate security operations are being carried out in the second device (the device with which the first device is communicating).
[0039] A response method according to a tenth aspect of the present disclosure may be a response method according to the ninth aspect, wherein the security state of the second device is determined based on at least one of information regarding a history of security anomalies in the second device, information regarding vulnerabilities contained in software constituting the second device, and information regarding security monitoring of the second device.
[0040] This allows the first device to acquire the security status of the second device, which is determined based on at least one of information regarding the history of security anomalies in the second device, information regarding vulnerabilities contained in the software that constitutes the second device, and information regarding security monitoring of the second device. Such security status can be useful information for the first device to determine whether appropriate security operations are being performed in the second device.
[0041] A response method according to an eleventh aspect of the present disclosure may be the response method according to the ninth or tenth aspect, which determines whether the acquired acquisition request is an acquisition request from the first device communicating with the second device, and if the acquired acquisition request is an acquisition request from the first device communicating with the second device, outputs the security status of the second device to the first device.
[0042] This allows the information processing device of the second system to output information on the security status of the second device to an appropriate device (first device).
[0043] A response method according to a twelfth aspect of the present disclosure is the response method according to the eleventh aspect, and may determine that the acquired acquisition request is an acquisition request from the first device communicating with the second device when the physical location of the first device and the physical location of the second device are within a predetermined range.
[0044] This makes it possible to prevent the security status information of the second device from being output to a device in an inappropriate physical location.
[0045] A response method according to a thirteenth aspect of the present disclosure is the response method according to the eleventh or twelfth aspect, and if the first device holds device information output by the second device, it may be determined that the acquired acquisition request is an acquisition request from the first device communicating with the second device.
[0046] This makes it possible to prevent the security status information of the second device from being output to a device that has inappropriate identification information for the second device.
[0047] A response method according to a fourteenth aspect of the present disclosure is a response method according to any of the eleventh to thirteenth aspects, and may determine that the acquired acquisition request is an acquisition request from the first device communicating with the second device if the security status of the first device satisfies a predetermined condition.
[0048] This makes it possible to prevent information on the security status of the second device from being output to a device whose security status does not satisfy a predetermined condition.
[0049] A response method according to a fifteenth aspect of the present disclosure is a response method according to any of the eleventh to fourteenth aspects, in which, when information indicating a function of the first device that the second device has requested the first device to use is obtained from the first device along with the acquisition request, a method for determining whether the obtained acquisition request is an acquisition request from the first device communicating with the second device may be changed depending on the type of the function.
[0050] This allows the second device to determine whether the acquisition request is from an appropriate device (first device) using an appropriate method according to the function requested by the second device, thereby improving the accuracy of the determination (i.e., security performance).
[0051] A response method according to a sixteenth aspect of the present disclosure is a response method according to the fifteenth aspect, and may further transition to a continuous monitoring mode in which, depending on the information indicating the function, it monitors whether any unauthorized control is being performed while the function is being used.
[0052] This makes it possible to monitor whether a security abnormality occurs due to unauthorized control or the like while the function is being used (for example, during smart charging).
[0053] A response method according to a seventeenth aspect of the present disclosure is a response method according to the fifteenth or sixteenth aspect, and may determine that a security anomaly has occurred when, in the continuous monitoring mode, at least one of the communication logs of the first device and the second device and the status of the functions of the first device and the second device is inconsistent.
[0054] This makes it possible to detect a security anomaly based on at least one of the communication log and the status of the function.
[0055] A response method according to an 18th aspect of the present disclosure is the response method according to the 17th aspect, wherein one of the first device and the second device is an electric vehicle, the other of the first device and the second device is a charging device, the function is related to vehicle charging, and when the power state is in a tight state, the response method may transition to the continuous monitoring mode.
[0056] This makes it possible to monitor whether unauthorized charging is occurring during charging.
[0057] An information processing device according to a 19th aspect of the present disclosure is an information processing device included in a second system, and includes: an acquisition unit that acquires a request to acquire the security status of the second device from the first device when communication is performed between a first device included in a first system different from the second system and a second device included in the second system; and an output unit that outputs the security status of the second device to the first device.
[0058] This provides the same effect as the above response method.
[0059] A program according to a twentieth aspect of the present disclosure is a program for causing a computer to execute the response method according to any one of the ninth to eighteenth aspects.
[0060] This provides the same effect as the above response method.
[0061] These general or specific aspects may be realized as a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or as any combination of the system, method, integrated circuit, computer program, or recording medium. The program may be pre-stored in the recording medium, or may be supplied to the recording medium via a wide area communication network including the Internet.
[0062] Hereinafter, embodiments and the like will be specifically described with reference to the drawings.
[0063] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not described in independent claims are described as optional components.
[0064] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.
[0065] Furthermore, in this specification, terms indicating relationships between elements, such as "same" and "match," as well as numerical values and numerical ranges, are not expressions that express only the strict meaning, but are expressions that also include a substantially equivalent range, for example, a difference of about several percent (or about 10%).
[0066] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.
[0067] First Embodiment A determination method and the like according to this embodiment will be described below with reference to FIGS.
[0068] [1-1. Configuration of security status linking system] First, the configuration of a security status linking system that executes a determination method will be described with reference to Figures 1 to 14. Figure 1 is a diagram showing the overall configuration of a security status linking system 1 according to this embodiment.
[0069] 1 , the security status linking system 1 includes an electric vehicle 10, an EV management server 20, a charging station 30 having one or more charging devices 601, and a station management server 40. A first system includes the electric vehicle 10 and the EV management server 20, and a second system includes the charging station 30 (e.g., the charging device 601) and the station management server 40.
[0070] The EV management server 20 is a server that manages the security status of the electric vehicle 10, but does not manage the security status of the charging device 601. In other words, the first system is a system that manages the security status of only the electric vehicle 10 out of the electric vehicle 10 and the charging device 601. The station management server 40 is a server that manages the security status of the charging device 601, but does not manage the security status of the electric vehicle 10. In other words, the second system is a system that manages the security status of only the charging device 601 out of the electric vehicle 10 and the charging device 601.
[0071] The security status linkage system 1 is a system that assists in communication with a device that is undergoing appropriate security operations when one of the devices belongs to a different system and is undergoing security operations by a different organization (for example, a server operated by an organization) communicates with another device.
[0072] The electric vehicle 10 is a vehicle (electrically driven vehicle) that runs using all or part of the electric energy stored in a battery 300 (see FIG. 2 ). The electric vehicle 10 is an electric vehicle (EV), but may also be, for example, a plug-in hybrid vehicle (PHEV, PHV) or a hybrid vehicle (HEV, HV). The electric vehicle 10 is communicably connected to each of the EV management server 20, the charging station 30 (or the charging device 601), and the station management server 40. The electric vehicle 10 is an example of a first device included in a first system.
[0073] FIG. 2 is a diagram showing the configuration of an in-vehicle network system according to this embodiment.
[0074] As shown in FIG. 2 , the electric vehicle 10 includes a central ECU (Electronic Control Unit) 100 , a battery management ECU 200 a , an ECU 200 b , a battery 300 , and a display 400 .
[0075] The central ECU 100 is an ECU that controls the entire vehicle by acting as the center of ECUs (e.g., battery management ECU 200a, ECU 200b), each of which realizes a vehicle function, and is a central ECU that integrates multiple ECUs. In this embodiment, the central ECU 100 has an interface for communication with a server outside the vehicle. In response to a request for function use from the charging device 601, the central ECU 100 makes an inquiry to the station management server 40 to determine whether to authorize the function use. The central ECU 100 is an example of an information processing device included in the first system.
[0076] The battery management ECU 200a and the ECU 200b are also called zone ECUs, and are connected to the central ECU 100 via an in-vehicle network.
[0077] 3 is a block diagram showing the functional configuration of the central ECU 100 according to this embodiment. The central ECU 100 includes, as its functional components, a server communication unit 101, a vehicle function access control unit 102, a user terminal communication unit 103, a vehicle network communication unit 104, a vehicle state storage unit 105, and a vehicle configuration information storage unit 106.
[0078] The server communication unit 101 is a communication interface for communicating with the station management server 40 (and the charging device 601) outside the vehicle.
[0079] The vehicle function access control unit 102 determines whether or not to permit access to a vehicle function, particularly when requested by an external system. The vehicle function access control unit 102 determines whether or not to permit access to a vehicle function from the charging device 601 based on the security status of the charging device 601 acquired via the server communication unit 101. The vehicle function access control unit 102 is an example of a determination unit.
[0080] The user terminal communication unit 103 is a communication interface for communicating with a user terminal (e.g., a smartphone). The user terminal communication unit 103 is used when predetermined information is displayed via an application rather than on an in-vehicle display (e.g., the display 400).
[0081] The vehicle network communication unit 104 is a communication interface for communicating with each component included in the vehicle network.
[0082] The vehicle state storage unit 105 is a storage device that stores the current vehicle state of the electric vehicle 10. The vehicle state is transmitted to the station management server 40 as necessary. The vehicle state storage unit 105 is realized by a semiconductor memory or the like.
[0083] 4 is a diagram showing an example of a vehicle state according to this embodiment. The vehicle state shown in FIG.
[0084] As shown in Fig. 4, the vehicle state includes the remaining battery charge, location information, and driving state. The remaining battery charge indicates the current remaining battery charge of the electric vehicle 10, the location information indicates the current location of the electric vehicle 10, and the driving state indicates the current driving state of the electric vehicle 10. In the example of Fig. 4, the driving state is charging, but it may also be, for example, driving, temporarily stopped, etc.
[0085] 3 , the vehicle configuration information storage unit 106 is a storage device that stores version information indicating the current version of the vehicle software installed in the electric vehicle 10. The version information is transmitted to the station management server 40 as needed. The vehicle configuration information storage unit 106 is realized by a semiconductor memory or the like.
[0086] 5 is a diagram showing an example of vehicle configuration information according to the present embodiment. The vehicle configuration information shown in FIG.
[0087] 5 , the vehicle configuration information is information that associates the identification information, version, and last update date of each ECU installed in the electric vehicle 10. The vehicle configuration information includes the software version of each of the multiple vehicles (including the electric vehicle 10) that are monitored by the EV management server 20.
[0088] The ECU version is updated according to the notification content, for example, when the ECU is updated or periodically, when each ECU notifies the current version and the last update date via the in-vehicle network.
[0089] Although FIG. 5 illustrates an example in which one version corresponds to each ECU, this is not limiting. For example, if one ECU is equipped with multiple applications, a software version may be managed for each application. Furthermore, the software version information notified from the ECU may be protected from tampering. For example, the software version information may be protected using a message authentication code based on the ECU's private key.
[0090] Referring back to FIG. 2, the battery management ECU 200a grasps the charging state of the battery 300 and notifies the charging device 601 of the state, thereby managing charging.
[0091] FIG. 6 is a block diagram showing the functional configuration of the battery management ECU 200a according to this embodiment.
[0092] As shown in FIG. 6, the battery management ECU 200a includes an application unit 201a, a communication unit 202a, and a version storage unit 203a.
[0093] The application unit 201a is a processing unit that executes different applications for each function of the ECU. In this embodiment, the application unit 201a performs functions such as obtaining and notifying the remaining battery charge, and managing charging. The battery management ECU 200a also has a function of controlling the charging mode, and can change the charging mode via an external system (for example, via the charging device 601). The application unit 201a may control such charging modes. The application unit 201a may also have functions such as a normal charging function, a smart charging control function, driving history information acquisition, billing information acquisition, and a commercial display request.
[0094] The communication unit 202a is a communication interface that enables the battery management ECU 200a to communicate with a vehicle network (e.g., other ECUs).
[0095] The version storage unit 203a is a storage device that stores the current software version of the device itself. In this embodiment, the version storage unit 203a stores the current software version of the battery management ECU 200a, which is the device itself. The version storage unit 203a is realized by a semiconductor memory or the like.
[0096] 7 is a diagram showing an example of version information according to the present embodiment. In FIG. 7, the identification information of the battery management ECU 200a is shown as "A."
[0097] 7, the version information stores, for example, that the current software version of the battery management ECU 200a is "3.0." Note that the number of versions is not limited to one. For example, if the battery management ECU 200a has multiple pieces of software, multiple software versions may be stored in the version storage unit 203a. For example, the version storage unit 203a may store versions of multiple applications, versions of libraries that constitute the software, and the like.
[0098] Each ECU is configured to store and be able to refer to its current software version.
[0099] 2, the ECU 200b is an ECU for realizing other functions of the electric vehicle 10. The functional configuration of the ECU 200b may be the same as the functional configuration of the battery management ECU 200a, and therefore a description thereof will be omitted. Note that the number of ECUs included in the electric vehicle 10 is not particularly limited.
[0100] The battery 300 stores electric energy as power for running the electric vehicle 10. The battery 300 has a charging interface and is charged by a charging device 601 at the charging station 30. The battery 300 may also be dischargeable via a charging / discharging device such as the charging station 30.
[0101] The display 400 is a user interface provided on the electric vehicle 10, and is realized by, for example, a display device provided in a navigation system. The display 400 displays, for example, information on charging the electric vehicle 10 using the charging device 601, information on the charging station 30, reservation information for the charging device 601, and the like.
[0102] 1 , the EV management server 20 is a server managed by, for example, a vehicle manufacturer, and manages the security status of each vehicle including the electric vehicle 10. The EV management server 20 is capable of communicating with each of the electric vehicle 10, the charging station 30 (or the charging device 601), and the station management server 40.
[0103] FIG. 8 is a block diagram showing the functional configuration of the EV management server 20 according to this embodiment.
[0104] As shown in FIG. 8, the EV management server 20 includes a communication unit 501 , a security status response unit 502 , a security monitoring unit 503 , an authorization certificate holding unit 504 , and a vehicle information holding unit 505 .
[0105] The communication unit 501 is a communication interface for the EV management server 20 to communicate with the electric vehicle 10, the station management server 40, and the like.
[0106] The security status response unit 502 executes a process of responding with the security status of one of the multiple vehicles being monitored (here, electric vehicle 10) in response to an inquiry about the security status of the vehicle from an external system (e.g., charging device 601, station management server 40, etc.) that communicates with the vehicle.
[0107] The security monitoring unit 503 determines the security status of a vehicle (here, the electric vehicle 10) that communicates with an external system based on the vehicle information (see FIG. 10 described later) stored in the vehicle information storage unit 505. The security monitoring unit 503 determines the security status of the vehicle based on whether the security patches for the software that configures the vehicle are up to date, whether there has been a history of security intrusions in the past, etc.
[0108] The certification certificate holding unit 504 is a storage device that holds a certificate indicating that the EV management server 20 is operating in a certified manner. The certification certificate holding unit 504 also holds a private key and a public key, allowing an external system to verify their legitimacy. In this way, the certification certificate holding unit 504 holds information that allows an external system to verify whether the EV management server 20 is operating in a certified manner. The certification certificate holding unit 504 is realized by a semiconductor memory or the like.
[0109] FIG. 9 is a diagram showing an example of a certification certificate held by the certification certificate holding unit 504 according to this embodiment.
[0110] As shown in FIG. 9, the certification certificate includes an EV management server certificate and a server private key.
[0111] The EV management server certificate is a certificate that certifies that certified security operations are being performed in the EV management server 20. The EV management server certificate is issued by, for example, a certification authority.
[0112] The server private key is used to sign data transmitted by the EV management server 20 .
[0113] The certification certificate also includes the public key of the EV management server 20, information about the certificate authority, and the like, and can prove that the EV management server 20 is a legitimate server that manages the electric vehicle 10.
[0114] 8 again, the vehicle information holding unit 505 is a storage device that holds vehicle information such as current location information, remaining battery charge, and security level for all managed vehicles. The vehicle information holding unit 505 is realized by a semiconductor memory or the like.
[0115] FIG. 10 is a diagram showing an example of vehicle information according to the present embodiment.
[0116] 10 , the vehicle information includes information about vehicles under the management of the EV management server 20. The vehicle information is information in which vehicle identification information (e.g., 10A) is associated with items and statuses. The items include "software version" indicating the current software version, "security intrusion history" indicating the history of security intrusions, "security monitoring" indicating whether a security monitoring service is being used, "security level" indicating the security level of the electric vehicle 10 determined by the security monitoring unit 503, "remaining battery power" indicating the remaining power of the battery 300, and "location information" indicating the current location of the electric vehicle 10 (electric vehicle 10A in FIG. 10 ).
[0117] The security monitoring service is, for example, a monitoring service using a Security Operations Center (SOC), a vulnerability management system, an anomaly detection system, etc. The security level may be two levels, "high" and "low," or may be three or more levels, such as "high," "medium," and "low," or may be indicated by a numerical value.
[0118] 1 , charging station 30 is a station for charging electric vehicle 10 and includes one or more charging devices 601. Note that charging station 30 may also include, for example, a charger that charges battery 300 and a charging / discharging device that functions as a discharger that outputs (discharges) the power stored in battery 300.
[0119] Fig. 11 is a diagram showing the configuration of charging station 30 according to this embodiment. For convenience, three charging devices 601 are shown as charging devices 601a to 601c in Fig. 11.
[0120] As shown in FIG. 11, the charging station 30 includes charging devices 601 a to 601 c and a station management unit 602 .
[0121] The station management unit 602 manages the usage status (output, usage time), future usage schedule, etc. of each of the charging devices 601a to 601c. The station management unit 602 also has a communication interface for communicating with the station management server 40, and may transmit the usage status, future usage schedule, etc. of each of the charging devices 601a to 601c to the station management server 40. The station management unit 602 may be realized by a local server.
[0122] 1 , the station management server 40 is a server managed by a charging service provider, a charging owner, or the like, and monitors the security status of the charging station 30 and issues control instructions. The station management server 40 is an example of an information processing device included in the second system. The station management server 40 is operated by an organization different from the EV management server 20 and is independent from the EV management server 20.
[0123] FIG. 12 is a block diagram showing the functional configuration of the station management server 40 according to this embodiment.
[0124] As shown in FIG. 12, the station management server 40 includes a communication unit 701 , a security status response unit 702 , a security monitoring unit 703 , an authorization certificate holding unit 704 , and a station status holding unit 705 .
[0125] The communication unit 701 is a communication interface for the station management server 40 to communicate with the station management unit 602, the EV management server 20, and the like.
[0126] The security status response unit 702 executes a process of responding with the security status of the charging device 601 in response to an inquiry about the security status of the charging device 601 from an external system (for example, the electric vehicle 10) that communicates with the charging device 601.
[0127] The security monitoring unit 703 determines the security status of the charging device 601 that communicates with an external system based on the station status (see FIG. 14 described later) stored in the station status storage unit 705. The security monitoring unit 703 determines the security status of the charging device 601 based on the security status, schedule, power tightness rate, etc. of the charging station 30 (charging station 30A in FIG. 14).
[0128] The certification certificate holding unit 704 is a storage device that holds a certificate indicating that the station management server 40 is operating in a certified manner. The certification certificate holding unit 704 also holds a private key and a public key, allowing an external system to verify their legitimacy. In this way, the certification certificate holding unit 704 holds information that allows an external system to verify whether or not the station management server 40 is operating in a certified manner. The certification certificate holding unit 704 is realized by a semiconductor memory or the like.
[0129] FIG. 13 is a diagram showing an example of an accreditation certificate held by the station management server 40 according to this embodiment.
[0130] As shown in FIG. 13, the authentication certificate includes a charging station management server certificate and a server private key.
[0131] The charging station management server certificate is a certificate that certifies that authorized operation is being performed in the station management server 40. The charging station management server certificate is issued by, for example, a certification authority.
[0132] The server private key is used to sign data that the station management server 40 transmits.
[0133] The certification certificate also includes the public key of the station management server 40, information about the certification authority, etc., and can prove that the station management server 40 is a legitimate server that manages the charging station 30 (e.g., the charging device 601).
[0134] The station status storage unit 705 stores, as station status, the security status, usage status schedule, and the like of each managed charging station 30. The station status storage unit 705 also stores the status of power supply from the power company. The station status storage unit 705 is realized by a semiconductor memory or the like.
[0135] 14 is a diagram showing an example of a station state according to this embodiment. The station state shown in FIG.
[0136] As shown in FIG. 14 , the station status includes information about the charging station 30 under the management of the station management server 40. The station status is information that associates information identifying the charging station (e.g., 30A), items, and content. The items include a "location" indicating the location of the charging station 30A, an "access destination" indicating the access destination of the charging station 30A, a "power utilization rate" indicating the power utilization rate of the charging station 30A, a "security status" indicating the security status of the charging station 30A, a "schedule" indicating the utilization status (or reservation information) of each charging device 601a to 601c included in the charging station 30A, and a "power constraint rate" indicating the current power constraint rate. The security status includes information indicating the presence or absence of a security anomaly and information indicating the presence or absence of software vulnerabilities. The presence or absence of software vulnerabilities can be identified based on the software version. The security status may be maintained for each charging device 601a to 601c. The station status may also include an updated list of the current software versions for each charging device 601a to 601c.
[0137] [1-2. Operation of the Security Status Linking System] Next, the operation of the security status linking system 1 configured as described above will be described with reference to Figs. 15 to 21. Fig. 15 is a sequence diagram showing the operation (determination method, response method) of the security status linking system 1 according to this embodiment. Fig. 15 shows the sequence up to the start of control of the charge mode for charging the electric vehicle 10. The operation of the electric vehicle 10 shown in Fig. 15 is an example of a determination method executed by an information processing device included in the first system, and the operation of the station management server 40 is an example of a response method executed by an information processing device included in the second system.
[0138] 15 , first, the electric vehicle 10 is connected to the charging device 601 (S11). When the electric vehicle 10 is connected to the charging device 601, communication between the electric vehicle 10 and the charging device 601 begins. Note that the connection between the electric vehicle 10 and the charging device 601 may be performed automatically or manually.
[0139] Next, the charging device 601 outputs a function request to the electric vehicle 10, for example, a request for access to a charge mode control function that controls charging (or charging / discharging) of the electric vehicle 10 for efficient power management (S12). The function request is a request to use a function of the electric vehicle 10 (for example, the central ECU 100 or a zone ECU), and in this case may be a request to access a smart charging function of the electric vehicle 10.
[0140] Next, because the electric vehicle 10 wants only external systems with guaranteed security to access the smart charging function, it inquires of the charging device 601 about the current security status of the charging device 601 (or the charging station 30) (S13). The server communication unit 101 of the electric vehicle 10 transmits the security status inquiry to the charging device 601, and the communication unit of the charging device 601 receives the inquiry.
[0141] Next, when the charging device 601 receives the security status inquiry from the electric vehicle 10, it transmits information about the station management server 40 that manages the security status of the charging device 601 (for example, access destination information for the station management server 40) as a response to the electric vehicle 10 (S14). The server communication unit 101 of the electric vehicle 10 receives the information about the station management server 40.
[0142] Next, the electric vehicle 10 inquires of the station management server 40 about the security status of the communication destination charging device 601 (for example, the charging device 601 connected via the charging interface of the battery 300) based on the access destination information acquired from the charging device 601 (S15). In response to a function request from the charging device 601 (or the charging station 30), the electric vehicle 10 inquires of the station management server 40 about the current security status of the charging device 601 that output the function request, in order to allow use of the function only for charging devices 601 that satisfy a predetermined security level. The inquiry about the current security status of the charging device 601 is an example of a request to acquire the security status of the charging device 601.
[0143] In this way, when an electric vehicle 10 belonging to a different system communicates with a charging device 601, the electric vehicle 10 (e.g., the central ECU 100) outputs a request to obtain the security status of the charging device 601 to the second system (here, the station management server 40).
[0144] The inquiry about the security status may be sent by the server communication unit 101. The server communication unit 101 is an example of an output unit.
[0145] The inquiry about the security status of the charging device 601 from the electric vehicle 10 may be acquired via the communication unit 701. The communication unit 701 is an example of an acquisition unit.
[0146] Next, the station management server 40 verifies the inquiry from the electric vehicle 10 and transmits the security status of the charging device 601 as a response to the electric vehicle 10 (S16). The security status of the charging device 601 can also be considered as information for proving to the first system, which is a different system, that the security of the charging device 601 is being appropriately operated. In step S16, the electric vehicle 10 obtains the security status of the charging device 601 from the station management server 40 that accepted the inquiry in step S15.
[0147] The security status of the charging device 601 may be transmitted to the electric vehicle 10 via the communication unit 701. The communication unit 701 is an example of an output unit.
[0148] The security status of charging device 601 may be acquired via server communication unit 101. Server communication unit 101 is an example of an acquisition unit.
[0149] Next, the electric vehicle 10 verifies the legitimacy of the charging device 601 based on the security status of the charging device 601, and if the security status is appropriate, permits the charging device 601 to access the smart charging function (function access) and outputs authorization to the charging device 601 (S17). The vehicle function access control unit 102 of the electric vehicle 10 determines whether to permit access to the smart charging function based on the security status of the charging device 601 acquired from the station management server 40. The legitimacy of the charging device 601 may be determined based on whether the charging device 601 has an appropriate security status. The appropriate security status may be stored in advance in the electric vehicle 10.
[0150] Determining whether to allow or deny access to the smart charging function is an example of making a determination regarding communication. Note that the determination regarding communication may be, for example, whether to allow or deny communication with the charging device 601 (or to continue communication).
[0151] Next, when the charging device 601 receives from the electric vehicle 10 that access has been permitted, it starts charging control (S18).
[0152] In this way, in the security status linkage system 1, when the security status of the charging device 601 (or charging station 30) is appropriate (for example, a security status corresponding to the smart charging function), that is, when appropriate security operations are being carried out for the charging device 601, access to the smart charging function by the charging device 601 is permitted, and access to the smart charging function is executed.
[0153] Next, the operation of each component of the security status linking system 1 will be described.
[0154] 16 is a flowchart showing the operation (response method) of the station management server 40 according to this embodiment.
[0155] 16 , when the communication unit 701 receives an inquiry from the electric vehicle 10 about the security status of the charging device 601 with which the electric vehicle 10 is communicating (S31), the security status response unit 702 verifies the validity of the inquiry content (S32). In other words, the security status response unit 702 determines whether the electric vehicle 10 that made the inquiry is a legitimate electric vehicle. Note that the processing of step S32 is not essential.
[0156] Next, security status response unit 702 determines whether the security status response is NG or not based on the verification result of step S32 (S33). If the security status response is OK (No in S33), that is, if security status response unit 702 determines that the security status is to be responded, security monitoring unit 703 determines the security status of charging device 601 (S34).
[0157] Next, the communication unit 701 transmits the security status of the charging device 601 as a response to the electric vehicle 10 (S35).
[0158] Next, the security status response unit 702 determines whether continuous monitoring of the electric vehicle 10 is necessary based on the security status of the charging device 601 and the function requested by the charging device 601 (S36). Continuous monitoring means monitoring the status (security abnormality) of the electric vehicle 10 while charging (e.g., while charging with access to the smart charging function permitted). The security status response unit 702, for example, calculates a risk value for using the function based on the security status of the charging device 601 and the function requested by the charging device 601, and determines whether continuous monitoring is necessary based on the calculated risk value. For example, the security status response unit 702 may determine that continuous monitoring is necessary if the risk value is equal to or greater than a predetermined value, and may determine that continuous monitoring is not necessary if the risk value is less than the predetermined value.
[0159] Next, if the security status response unit 702 determines that continuous monitoring of the electric vehicle 10 is necessary (Yes in S36), it transitions to a continuous monitoring mode in which continuous monitoring is performed (S37), and if it determines that continuous monitoring of the electric vehicle 10 is not necessary (No in S36), it terminates the processing.
[0160] Furthermore, if the security status response is NG (Yes in S33), the security status response unit 702 rejects the security status response (S38) because the electric vehicle 10 that made the inquiry may be an unauthorized vehicle.
[0161] Steps S32 and S34 will now be described with further reference to FIGS. 17 to 19. FIGS. 17 and 18 are flowcharts showing examples of detailed operations (response methods) of step S32 shown in FIG. 16. FIG. 17 illustrates an operation in which a response to a security status request is permitted when a vehicle (here, the electric vehicle 10) that has made a security status inquiry is physically close to the charging device 601 that is the communication partner. FIG. 18 illustrates an operation in which a response to a security status request is permitted when the electric vehicle 10 has received a token (e.g., a one-time token) in advance from the charging device 601 and the token held by the electric vehicle 10 is a token issued by the charging device 601 that is the communication partner. The token is an example of device information that the charging device 601 transmits to the electric vehicle 10. Note that the device information is not limited to a token and may be, for example, the ID (identification information) of the charging device 601.
[0162] 17 , the security status response unit 702 acquires the current location of the vehicle (electric vehicle 10) that has made the inquiry (S32a). For example, the security status response unit 702 may acquire the current location from the electric vehicle 10. Note that the security status response unit 702 may acquire the ID (identification information) of the electric vehicle 10 instead of or in addition to the current location.
[0163] Next, the security status response unit 702 determines whether the vehicle that made the inquiry is geographically close to the charging device 601 for which the security status was requested (S32b). In this case, the station management server 40 stores the location information of each charging device 601.
[0164] Next, if the security status response unit 702 determines that the vehicle that made the inquiry is geographically close to the charging device 601 for which the security status was requested (Yes in S32b), it determines that the security status response to the vehicle that made the inquiry is OK, i.e., a response will be made (S32c); if it determines that the vehicle that made the inquiry is geographically far from the charging device 601 for which the security status was requested (No in S32b), it determines that the security status response to the vehicle that made the inquiry is NG, i.e., no response will be made (S32d).
[0165] In this way, if the physical location of the electric vehicle 10 and the physical location of the charging device 601 are within a specified range, the security status response unit 702 may determine that the acquired acquisition request is an acquisition request from the electric vehicle 10 communicating with the charging device 601, and may determine to transmit the security status of the charging device 601 to the electric vehicle 10.
[0166] As shown in FIG. 18, the security status response unit 702 also receives the token issued by the communication partner charging device 601 from the inquiry source vehicle (electric vehicle 10) (S32e).
[0167] Next, the security status response unit 702 determines (S32f) whether the token received in step S32e is a token issued by the target charging device 601. The security status response unit 702 may make the determination in step S32f by verifying the issuer or legitimacy of the token received in step S32e.
[0168] For example, when requesting the charge mode control function, the charging device 601 may generate a token (e.g., a one-time token) and transmit the generated token to the electric vehicle 10 at the same time as the request. Any known technique may be used to generate the one-time token. For example, each charging device 601 may have a private key, and each charging device 601 may be able to generate a one-time token. Furthermore, the one-time token may be used only once, or may have an expiration date.
[0169] Next, if the security status response unit 702 determines that the token received in step S32e is a token issued by the target charging device 601 (Yes in S32f), it determines that the security status response to the inquiring vehicle is OK, i.e., a response will be made (S32g); if it determines that the token received in step S32e is not a token issued by the target charging device 601 (No in S32f), it determines that the security status response to the inquiring vehicle is NG, i.e., no response will be made (S32h).
[0170] In this way, if the electric vehicle 10 holds the device information output (e.g., issued) by the charging device 601, the security status response unit 702 may determine that the acquired acquisition request is an acquisition request from the electric vehicle 10 communicating with the charging device 601, and may determine to transmit the security status of the charging device 601 to the electric vehicle 10.
[0171] Fig. 19 is a flowchart showing the detailed operation (response method) of step S34 shown in Fig. 16. Note that Fig. 19 also shows the detailed operation (S35a and S35b) of step S35.
[0172] 19 , the security monitoring unit 703 determines whether or not the function requested by the charging device 601 (for example, the charge mode control function shown in FIG. 15 ) is a function that can be used by the charging device 601 (S34a). The security monitoring unit 703 acquires the function requested by the charging device 601 from the electric vehicle 10, and if the list of available functions for each charging device 601 stored in the station management server 40 states that the function acquired from the electric vehicle 10 is available to the charging device 601, the security monitoring unit 703 determines that the function is available to the charging device 601. If the list does not state that the function acquired from the electric vehicle 10 is available to the charging device 601, the security monitoring unit 703 determines that the function is unavailable to the charging device 601.
[0173] For example, the station management server 40 may store a list in advance of the door locking / unlocking function as a function that the charging device 601 cannot use, and the smart charging function as a function that the charging device 601 cannot use.
[0174] Note that the security monitoring unit 703 may determine No in step S34a when access to vehicle functions in the charging device 601 is temporarily disabled. This applies to cases such as when the firmware of the charging device 601 has a vulnerability and the use of advanced functions is temporarily prohibited.
[0175] Next, if the security monitoring unit 703 determines that the function requested by the charging device 601 is a function that the charging device 601 can use (Yes in S34a), it determines whether or not a security level request has been made by the electric vehicle 10 (S34b). The security level may be determined by the electric vehicle 10, for example, according to the function for which the electric vehicle 10 has received an access request from the charging device 601. For example, the electric vehicle 10 may store in advance a table that associates the function for which an access request has been made with the requested security level, and the requested security level may be determined based on the table. Furthermore, if a security level is available, the server communication unit 101 of the electric vehicle 10 may transmit the requested security level together with an inquiry about the security status to the station management server 40 in step S15.
[0176] Next, when the security monitoring unit 703 determines that a security level request has been made by the electric vehicle 10 (Yes in S34b), it determines whether the security status of the charging device 601 satisfies the security level requested by the vehicle (S34c). The security monitoring unit 703 determines the security level of the charging device 601 based on the security intrusion history of the charging device 601 (or the charging station 30 in which the charging device 601 is installed), whether security monitoring has been performed, the software version (whether or not there are known vulnerabilities), and the like, and determines whether the security level is higher than the security level requested by the electric vehicle 10. The security level may be a numerical value or may be a tiered level such as "high," "medium," or "low." The determination of whether the security level is satisfied may be, for example, a determination of whether the security levels match.
[0177] The security breach history of the charging device 601 (or the charging station 30 in which the charging device 601 is installed), whether security monitoring is performed, software version, etc. are stored in advance in the station management server 40 .
[0178] Next, if the security monitoring unit 703 determines that the security status of the charging device 601 meets the security level required by the vehicle (Yes in S34c), the communication unit 701 transmits a response indicating that the security status is OK to the electric vehicle 10 (S35a).
[0179] Furthermore, if the security monitoring unit 703 determines that there is no request for a security level from the electric vehicle 10 (No in S34b), it executes processing to change the verification level of the security status in accordance with the function requested by the charging device 601. If the result in step S34b is No, the security monitoring unit 703 determines whether or not the charging device 601 has any vulnerabilities (S34e). The security monitoring unit 703 determines whether or not the charging device 601 has any vulnerabilities based on, for example, the software version of the charging device 601.
[0180] Next, if the security monitoring unit 703 determines that the charging device 601 does not have a vulnerability (Yes in S34e), it further determines whether the function requested by the charging device 601 is related to vehicle control (S34f). The security monitoring unit 703 may make the determination in step S34f based on the function requested by the charging device 601 acquired from the electric vehicle 10 and a list of whether the function is related to vehicle control. For example, the station management server 40 may previously store a list of functions that are not related to vehicle control, such as functions that acquire billing information as vehicle information and functions that can be used remotely, and functions that are related to vehicle control, such as functions that acquire location information of the electric vehicle 10 as vehicle information, display commercial information, and route search.
[0181] Next, if the security monitoring unit 703 determines that the function requested by the charging device 601 is related to vehicle control (Yes in S34f), it further determines whether there has been a security abnormality in the charging device 601 recently, based on the history of security abnormalities in the charging device 601 (S34g).
[0182] Next, if the security monitoring unit 703 determines that there is no security abnormality in the charging device 601 most recently (Yes in S34g), and if it determines that the function requested by the charging device 601 is not related to vehicle control (No in S34f), it proceeds to step S35a.
[0183] In addition, if the security monitoring unit 703 determines that the function requested by the charging device 601 is not a function that the charging device 601 can use (No in S34a), if it determines that the security status of the charging device 601 does not meet the security level required by the vehicle (No in S34c), if it determines that the charging device 601 has a vulnerability (No in S34e), or if it determines that the charging device 601 has recently had a security abnormality (No in S34g), it proceeds to step S35b.
[0184] Next, the communication unit 701 transmits a response indicating that the security status is OK to the electric vehicle 10 in step S35a, and transmits a response indicating that the security status is NG to the electric vehicle 10 in step S35b.
[0185] In this way, the response content (security status) to the inquiry may be determined based on the security level required of the charging device 601 that uses the function, as determined by the electric vehicle 10, and the security level of the charging device 601.
[0186] Furthermore, the security status may also be determined using the presence or absence of security monitoring for charging device 601. The security status of charging device 601 is determined based on at least one of, for example, information on the history of security abnormalities in charging device 601, information on vulnerabilities included in software that constitutes charging device 601, and information on security monitoring for charging device 601.
[0187] Furthermore, after the operation shown in Fig. 19 is completed, the operation shown in Fig. 20 may be executed. Fig. 20 is a flowchart showing the operation (response method) that is executed subsequently after the operation shown in Fig. 19 is completed. Fig. 20 shows the operation of transitioning to a continuous monitoring mode to continuously check for security abnormalities for use of high-risk functions such as vehicle control and charging control during power shortages, even if the security status of charging device 601 is OK.
[0188] As shown in FIG. 20, the security monitoring unit 703 determines whether or not the charging device 601 has responded that the security status is OK (S61).
[0189] Next, when it is determined that the security status is OK (Yes in S61), the security monitoring unit 703 determines whether the function requested by the charging device 601 is related to vehicle control (S62). The process of step S62 is the same as step S34f shown in FIG. 19 .
[0190] Next, if the security monitoring unit 703 determines that the function requested by the charging device 601 is not related to vehicle control (No in S62), it determines whether the function requested by the charging device 601 is related to charging control (S63). If the function requested by the charging device 601 is a function for controlling a charging mode (for example, a smart charging function), the security monitoring unit 703 determines that the function is related to charging control.
[0191] Next, if the security monitoring unit 703 determines that the function requested by the charging device 601 is related to charging control (Yes in S63), it further determines whether the current power tightness rate is equal to or greater than a threshold (S64). The security monitoring unit 703 makes the determination in step S64 based on, for example, whether the power tightness rate of the station state shown in Fig. 14 is equal to or greater than a threshold. Note that the power tightness rate may be a value published by a power company or a public institution.
[0192] Next, if the security monitoring unit 703 determines that the function requested by the charging device 601 is related to vehicle control (Yes in S62) or that the power pressure rate is equal to or greater than a threshold (Yes in S64), the security monitoring unit 703 transitions to a continuous monitoring mode (S65). This allows the security monitoring unit 703 to additionally monitor the electric vehicle 10 and the charging device 601 when the function is related to vehicle control (i.e., when the security risk is higher) even if the security status of the charging device 601 is OK. For example, the security monitoring unit 703 can monitor whether unauthorized charging is occurring during charging, i.e., whether unauthorized control is occurring while the function is being used. An example of a security risk here is the risk of excessive charging (unauthorized charging) occurring when power is tight at the charging station 30, resulting in a blackout or other problem. The threshold is acquired in advance and stored in the station management server 40.
[0193] In addition, if the security monitoring unit 703 determines that the security status has responded as NG (No in S61), if it determines that the function requested by the charging device 601 is not related to charging control (No in S63), or if it determines that the power shortage rate is less than the threshold value (No in S64), it terminates processing without transitioning to continuous monitoring mode.
[0194] In this way, the security monitoring unit 703 determines whether to transition to a continuous monitoring mode in which it monitors whether any unauthorized control is being performed while the function is being used, depending on the information indicating the function requested by the charging device 601.
[0195] The process executed in the continuous monitoring mode will now be described with reference to Fig. 21. Fig. 21 is a flowchart showing the operation (response method) executed in the continuous monitoring mode according to this embodiment.
[0196] 21 , the security monitoring unit 703 acquires a communication log with the charging device 601 from the electric vehicle 10 via the communication unit 701 (S71). In this way, in the continuous monitoring mode, a communication log with the charging device 601, which is the communication partner, is acquired from the electric vehicle 10, which is another system. Furthermore, the security monitoring unit 703 may acquire information related to the control status from the electric vehicle 10 instead of or in addition to the communication log. The information related to the control status is information indicating the status of the electric vehicle 10 related to the function requested by the charging device 601, and in this embodiment, includes information related to the charge status, such as the charge amount.
[0197] Next, the security monitoring unit 703 acquires a communication log with the electric vehicle 10 from the charging device 601 (S72). In this way, in the continuous monitoring mode, a communication log with the electric vehicle 10 is also acquired from the charging device 601.
[0198] Next, the security monitoring unit 703 determines whether or not there is a mismatch in the communication logs between the electric vehicle 10 and the charging device 601 (S73). The security monitoring unit 703 may determine whether or not there is any unauthorized control or unauthorized communication, for example, based on whether or not the communication log of the electric vehicle 10 matches the communication log of the charging device 601. For example, if the charge amount acquired from the electric vehicle 10 does not match the charge amount (supply amount) acquired from the charging device 601, the security monitoring unit 703 determines that there is a mismatch.
[0199] Next, if the security monitoring unit 703 determines that the communication logs between the electric vehicle 10 and the charging device 601 are inconsistent (Yes in S73), for example, if there is an inconsistency between the communication log notified from the electric vehicle 10 and the communication log notified from the charging device 601, the security monitoring unit 703 detects a security abnormality (S74). The security abnormality here is, for example, a security abnormality in the electric vehicle 10. If a security abnormality is detected, the security monitoring unit 703 may, for example, notify the electric vehicle 10 via the communication unit 701 to disable the use of functions.
[0200] Furthermore, if the security monitoring unit 703 determines that the communication logs between the electric vehicle 10 and the charging device 601 are consistent (No in S73), it ends the process without detecting a security abnormality.
[0201] (Variation of First Embodiment) A security status linking system according to this variation will be described below with reference to FIGS. 22 to 24. The following description will focus on differences from the first embodiment, and descriptions of content that is the same as or similar to that of the first embodiment will be omitted or simplified. The security status linking system according to this variation differs from the security status linking system 1 according to the first embodiment mainly in that the charging device 601 transmits information related to the station management server 40 when requesting access to the charge mode control function, and that the EV management server 20 responds with the security status of the electric vehicle 10 to the station management server 40. The security status linking system according to this variation may have the same configuration as the security status linking system 1 according to the first embodiment, and will be described below using the reference numerals of the security status linking system 1.
[0202] 22 is a sequence diagram showing the operation of the security status linking system 1 according to this modification. In FIG. 22, the sequence up to the start of control of the charging mode for charging the electric vehicle 10 is shown.
[0203] 22 , when the electric vehicle 10 is connected and communication is initiated, the charging device 601 requests access to the charge mode control function (S12a). In this modification, the charging device 601 transmits, to the electric vehicle 10, the request for access to the charge mode control function, as well as information about the station management server 40 that manages the charging device 601. The information about the station management server 40 includes access destination information (e.g., address) of the station management server 40.
[0204] Next, the electric vehicle 10 inquires of the station management server 40 about the security status of the communication destination charging device 601 (e.g., the charging device 601 connected via the charging interface of the battery 300) based on the access destination information acquired from the charging device 601 along with the request for access to the charging mode control function (S15).
[0205] Next, when the station management server 40 receives the security status inquiry from the electric vehicle 10 via the communication unit 701, it inquires of the EV management server 20 about the security status of the electric vehicle 10 to determine whether or not to respond to the request from the electric vehicle 10 (S19). The communication unit 701 of the station management server 40 transmits a request to acquire the security status of the electric vehicle 10 to the EV management server 20.
[0206] Next, when the EV management server 20 receives an inquiry about the security status of the electric vehicle 10 from the station management server 40, the EV management server 20 transmits the security status of the electric vehicle 10 as a response to the station management server 40 (S20). The acquisition of the inquiry and the transmission of the security status are performed by the communication unit 501.
[0207] Next, the station management server 40 acquires the security status of the electric vehicle 10 from the EV management server 20, and if the security status satisfies a predetermined condition, transmits the security status of the charging device 601 as a response to the electric vehicle 10 (S16). The acquisition of the security status of the electric vehicle 10 and the transmission of the security status of the charging device 601 are performed by the communication unit 701.
[0208] The operation of the station management server 40 will now be described with reference to Figs. 23 and 24. Fig. 23 is a flowchart showing a first example of the operation (response method) of the station management server 40 according to this modified example. Fig. 23 shows the operation of determining whether or not to respond to the vehicle (electric vehicle 10) that has made the inquiry about the security status of the charging device 601, depending on the security status of the vehicle. Fig. 23 also shows the operation that is executed after the station management server 40 receives an inquiry about the security status from the electric vehicle 10.
[0209] 23, the security status response unit 702 inquires of the EV management server 20 about the security status of the electric vehicle 10 via the communication unit 701 (S41). Step S41 corresponds to step S19 shown in FIG.
[0210] Next, when the security status response unit 702 acquires the security status of the electric vehicle 10 from the EV management server 20 via the communication unit 701, it determines whether the acquired security status of the electric vehicle 10 is OK (S42). The security status response unit 702 may make the determination in step S42 based on whether information indicating the security status is OK has been acquired from the EV management server 20, or may acquire vehicle information (see FIG. 12 ) from the EV management server 20, determine the security level of the electric vehicle 10 based on the acquired vehicle information, and make the determination in step S42 based on the determined security level and a threshold value, etc. The threshold value may be determined, for example, depending on the function requested by the charging device 601.
[0211] Next, if the security status response unit 702 determines that the security status of the electric vehicle 10 is OK (Yes in S42), it determines that the response regarding the security status of the charging device 601 is OK, that is, it will respond (S43), and if it determines that the security status of the electric vehicle 10 is NG (No in S42), it determines that the response regarding the security status is NG, that is, it will not respond (S44). If the response regarding the security status is OK, step S16 shown in FIG. 22 is executed.
[0212] In this way, if the security status of the electric vehicle 10 satisfies specified conditions, the security status response unit 702 may determine that the acquired acquisition request is an acquisition request from the electric vehicle 10 communicating with the charging device 601, and may determine to transmit the security status of the charging device 601 to the electric vehicle 10.
[0213] 24 is a flowchart showing a second example of the operation (response method) of the station management server 40 according to this modification. The operation of Fig. 24 shows how the method of checking the security status of the electric vehicle 10 is changed depending on the function requested by the charging device 601.
[0214] 24 , the security status response unit 702 acquires the type of vehicle function requested by the charging device 601 (S51). The security status response unit 702 may acquire the type of vehicle function requested by the electric vehicle 10, for example.
[0215] Next, the security status response unit 702 determines whether the function (vehicle function) requested by the charging device 601 is valid only when the charging device 601 and the electric vehicle 10 are in close proximity (S52). The security status response unit 702 may make the determination in step S52 based on a list of functions that are valid only when the charging device 601 and the electric vehicle 10 are in close proximity. Examples of functions that are valid only when the charging device 601 and the electric vehicle 10 are in close proximity include charging control and discharging control. This list is stored in advance in the station management server 40.
[0216] Next, if the security status response unit 702 determines that the function requested by the charging device 601 is valid only when the charging device 601 and the electric vehicle 10 are in close proximity (Yes in S52), it determines to confirm the physical positions of the charging device 601 and the electric vehicle 10 (S53). In this case, the security status response unit 702 executes an operation equivalent to the operation shown in FIG.
[0217] In this way, when the function requested by the charging device 601 is a function that can be used when the charging device 601 and the electric vehicle 10 are physically connected, such as for charging control, the physical positions of the electric vehicle 10 and the charging device 601 are confirmed.
[0218] Furthermore, if the security status response unit 702 determines that the function requested by the charging device 601 is not valid only when the charging device 601 and the electric vehicle 10 are in close proximity (No in S52), it further determines whether the function requested by the charging device 601 is related to the control of the electric vehicle 10 (S54). In this case, the security status response unit 702 executes an operation corresponding to step S62 shown in FIG.
[0219] Next, if the security status response unit 702 determines that the function requested by the charging device 601 is related to the control of the electric vehicle 10 (Yes in S54), it determines to check the security status of the electric vehicle 10 (S55). In this case, the security status response unit 702 executes an operation corresponding to the operation shown in FIG.
[0220] Furthermore, if the security status response unit 702 determines that the function requested by the charging device 601 is not related to the control of the electric vehicle 10 (No in S54), it determines to check the token (an example of device information) issued by the charging device 601 (S56). In this case, the security status response unit 702 executes an operation corresponding to the operation shown in FIG.
[0221] In this way, the verification contents (S53, S55, S56) are varied depending on whether the function requested by the charging device 601 is a function that can be used remotely, acquisition of vehicle information (e.g., acquisition of billing information, acquisition of vehicle position information (or driving history information)), or control of a vehicle function (display of commercial information, route search, etc.). Furthermore, whether to respond to the inquiry may be determined based on the function requested by the charging device 601 (e.g., smart charging control function, acquisition of driving history information, acquisition of billing information, commercial display request, etc.). For example, when the security status response unit 702 acquires, from the electric vehicle 10, information indicating the function of the electric vehicle 10 that the charging device 601 has requested to be used by the electric vehicle 10 (e.g., the type of vehicle function), together with the acquisition information, the security status response unit 702 may change the method of determining whether the acquired acquisition request is an acquisition request from the electric vehicle 10 that communicates with the charging device 601, depending on the type of function.
[0222] (Embodiment 2) A security status linking system according to this embodiment will be described below with reference to Figures 25 to 28. Note that the following description will focus on differences from embodiment 1, and descriptions of content that is the same as or similar to embodiment 1 will be omitted or simplified. The security status linking system according to this embodiment differs from the security status linking system 1 according to embodiment 1 mainly in that the charging station 30 has the functions of the security status response unit 702 and the like described in embodiment 1 and the like. An example in which the charging device has the functions of the security status response unit 702 and the like will be described below, but the charging station 30 may also have these functions.
[0223] [2-1. Configuration of security status linking system] First, the configuration of a security status linking system that executes the determination method will be described with reference to Fig. 25 and Fig. 26. Fig. 25 is a block diagram showing the functional configuration of a charging device 801 according to this embodiment.
[0224] As shown in FIG. 25, the security status linking system includes a charging device 801 instead of the charging device 601 according to the first embodiment.
[0225] The charging device 801 is configured to be able to respond to an inquiry about the security status of the charging device 801 from a vehicle. The charging device 801 includes a vehicle communication unit 811, a station management communication unit 812, a security status response unit 813, and a security status storage unit 814.
[0226] The vehicle communication unit 811 is a communication interface that enables the charging device 801 to communicate with the electric vehicle 10 .
[0227] The station management communication unit 812 is a communication interface for the charging device 801 to communicate with the station management unit 602 .
[0228] The security status response unit 813 has the same function as the security status response unit 702 shown in embodiment 1, and performs processing to respond with the security status of the charging device 801 in response to an inquiry about the security status of the charging device 801 from an external system (e.g., electric vehicle 10) that communicates with the charging device 801.
[0229] The security status holding unit 814 is a storage device that holds the security status of the charging device 801. The security status holding unit 814 is realized by, for example, a semiconductor memory.
[0230] 26 is a diagram showing an example of the security status of charging device 801 according to this embodiment. The security status shown in FIG.
[0231] 26, the security status is information in which items are associated with values. The items include a "security abnormality history" indicating the history of security abnormalities, a "firmware version" indicating the version of the firmware, a "security monitoring" indicating whether security monitoring is performed, a "security verification date" indicating the date on which station management server 40 verified the security of charging device 801, an "expiration date" indicating the expiration date of the security status, a "management server signature" indicating the signature of station management server 40, and a "management server certificate" indicating a certificate issued by station management server 40.
[0232] The security status is issued by the station management server 40 and is signed so that the charging device 801 cannot tamper with it.
[0233] By storing such a security status in the charging device 801, the electric vehicle 10 or the EV management server 20 can verify the validity of the charging station management server certificate.
[0234] In this embodiment, the charging device 801 may respond to the electric vehicle 10 via the vehicle communication unit 811 with the security status of the charging device 801, and have the electric vehicle 10 (or the EV management server 20) determine whether the use of the function requested by the charging device 801 is OK / NG.
[0235] [2-2. Operation of the Security Status Linking System] Next, the operation of the security status linking system configured as described above will be described with reference to Fig. 27 and Fig. 28. Fig. 27 is a sequence diagram showing the operation (determination method, response method) of the security status linking system according to this embodiment. Fig. 27 shows the sequence up to the start of control of the charge mode for charging the electric vehicle 10.
[0236] 27 , when the electric vehicle 10 receives a request for access to the charge mode control function from the charging device 801, it inquires about the security status of the charging device 801 from the charging device 801 (S13b). The communication unit of the electric vehicle 10 transmits the inquiry about the security status of the charging device 801 to the charging device 801, and the vehicle communication unit 811 receives the inquiry about the security status of the charging device 801 from the electric vehicle 10.
[0237] Next, the security status response unit 813 of the charging device 801 verifies the response of the security status of the charging device 801 (S81), and the vehicle communication unit 811 transmits the security status of the charging device 801 as a response to the electric vehicle 10 (S82).
[0238] In this manner, in this embodiment, the security status response is made without going through station management server 40. Because the processing for responding to the security status is completed locally (in charging station 30), the number of inquiries (e.g., communication volume) made to station management server 40 can be reduced.
[0239] Here, the operation of charging device 801 will be described with reference to Fig. 28. Fig. 28 is a flowchart showing the operation (response method) of charging device 801 according to this embodiment. The processing of steps S91 to S94 shown in Fig. 28 corresponds to the processing of step S81 shown in Fig. 27.
[0240] As shown in FIG. 28, the vehicle communication unit 811 receives an inquiry about the security status of the charging device 801 from the electric vehicle 10 (S91).
[0241] Next, the security status response unit 813 determines whether the security status request is from the electric vehicle 10 that has requested function use (S92). The processing of step S92 corresponds to the processing of step S32 shown in Fig. 16. The security status response unit 813 makes the determination of step S92 using, for example, at least one of the physical positions of the charging device 801 and the electric vehicle 10, the security status of the electric vehicle 10, and facility information output by the charging device 801 (for example, a token, an ID, etc.).
[0242] Next, if the security status response unit 813 determines that the security status request is from the electric vehicle 10 that has requested function use (Yes in S92), it further determines whether the expiration date of its own security status is valid (S93). The security status response unit 813 may make the determination in step S93 based on the security verification date, expiration date, and the current date shown in FIG.
[0243] Next, if security status response unit 813 determines that the expiration date of its own security status is not valid (No in S93), it requests station management server 40 to update the security status (S94). The communication unit of charging device 801 transmits a request to update the security status of charging device 801 to station management server 40. As a result, the security status of charging device 801 is updated.
[0244] Next, if the security status response unit 813 determines that the expiration date of its own security status is valid (Yes in S93), and if the processing of step S94 is executed, the vehicle communication unit 811 transmits the security status of the charging device 801 as a response to the electric vehicle 10 (S82).
[0245] Furthermore, if the security status response unit 813 determines that the security status request is not from the electric vehicle 10 that requested the use of the function (No in S92), it determines that the security status request may be from an unauthorized vehicle and therefore determines to reject the security status response (S95).
[0246] This allows the charging device 801 to respond only to inquiries about the security status from the electric vehicle 10 that has requested the use of its own function.
[0247] (Display Example) Next, a display example of the contents of a security status inquiry from the electric vehicle 10 will be described with reference to Fig. 29. Fig. 29 is a diagram showing a display example of the contents of a security status inquiry. Fig. 29 shows a display example of the contents of a security status inquiry for the charging devices 601a to 601c according to the first embodiment, but the contents of a security status inquiry for the charging device 801 according to the second embodiment are displayed in a similar manner.
[0248] 29, the displayed information corresponds to "time" indicating the time when the security status inquiry was received, "vehicle" indicating which vehicle the security status inquiry came from, "function" indicating the function that the charging device requested of the vehicle that received the inquiry, "charging device" indicating which charging device the security status inquiry was for, and "result" indicating the determination result of whether to respond to the security status. The result also includes the reason if the security status response was rejected (e.g., "The vehicle is not close to the charging device").
[0249] 29 is displayed to the administrator who manages the charging device or the administrator who manages the electric vehicle 10, allowing the administrator to understand the situation regarding the inquiry about the security status. In addition, the information shown in FIG. 29 may be stored as a log.
[0250] (Other Embodiments) As above, the determination method etc. according to one or more aspects have been described based on the embodiments etc., but the present disclosure is not limited to these embodiments etc. As long as it does not deviate from the spirit of the present disclosure, various modifications that a person skilled in the art can conceive of to the present embodiment and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.
[0251] For example, some or all of the functions of electric vehicle 10 in the above-described embodiments may be provided by EV management server 20. In other words, some or all of the operations performed by electric vehicle 10 may be performed by EV management server 20. For example, an inquiry about the security status of charging devices 601, 801 (such as charging device 601) may be sent from EV management server 20. Furthermore, some or all of the functions of EV management server 20 in the above-described embodiments may be provided by electric vehicle 10. In other words, some or all of the operations performed by EV management server 20 may be performed by electric vehicle 10.
[0252] Furthermore, some or all of the functions of the charging device 601, etc. in the above-described embodiments and the like may be executed by the station management server 40 or the station management unit 602. In other words, some or all of the operations executed by the charging device 601, etc. may be executed by the station management server 40 or the station management unit 602. Furthermore, some or all of the functions of the station management server 40 in the above-described embodiments and the like may be possessed by the charging device 601, etc. or the station management unit 602. In other words, some or all of the operations executed by the station management server 40 may be executed by the charging device 601, etc. or the station management unit 602.
[0253] Furthermore, in the above embodiments, an example has been described in which an inquiry about the security status is made after a request for access to the charge mode control function has been made, but this is not limited to this. For example, an inquiry about the security status may be made at the time when the electric vehicle 10 and the charging device 601, etc., start communication, for example, before a request for access to the charge mode control function is made, or when a request for access to the charge mode control function is not made.
[0254] Furthermore, in the above-described embodiment and the like, an example has been described in which an inquiry about the security status of the charging device 601, etc. is made when the charging device 601, etc. charges the electric vehicle 10, but the present invention is not limited to this, and for example, when the charging device 601, etc. charges the electric vehicle 10, an inquiry about the security status of the electric vehicle 10 may be made from the charging device 601, etc. In this way, a device requesting access to a function may make an inquiry about the security status of a device having the function.
[0255] Furthermore, in the above-described embodiments, the electric vehicle 10 is exemplified as the first device, and the charging device 601 or the like is exemplified as the second device, but the first device and the second device are not limited to this, and may be any other devices as long as they belong to different systems (security operations are performed by different organizations) and are capable of communicating. For example, each of the first device and the second device may be an electric vehicle such as an electric vehicle, or the first device may be the charging device 601 or the like, and the second device may be the electric vehicle 10. Furthermore, at least one of the first device and the second device may be a home appliance or the like.
[0256] Furthermore, in the above-described embodiment and the like, examples have been described in which the electric vehicle 10 and the charging device 601, etc. communicate directly, but this is not limiting, and communication may occur via another device. For example, communication between the electric vehicle 10 and the charging device 601, etc. may occur via at least one of the EV management server 20 and the station management server 40. Note that, for example, the charging device 601, etc., acquiring information from the electric vehicle 10 is an expression that includes both the charging device 601, etc. acquiring information directly from the electric vehicle 10, and the charging device 601, etc. acquiring information output by the electric vehicle 10 via another device.
[0257] In the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0258] The order in which the steps in the flowchart are executed is merely an example for specifically explaining the present disclosure, and other orders may be used. Some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.
[0259] The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block.Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or in time-sharing by a single piece of hardware or software.
[0260] Furthermore, the information processing device according to the above-described embodiments may be realized as a single device or may be realized by multiple devices. When the information processing device is realized by multiple devices, the components of the information processing device may be distributed among the multiple devices in any manner. When the information processing device is realized by multiple devices, the communication method between the multiple devices is not particularly limited, and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.
[0261] Furthermore, each component described in the above embodiments may be implemented as software or, typically, as an LSI, which is an integrated circuit. These components may be individually integrated into a single chip, or some or all of them may be integrated into a single chip. Here, the term "LSI" is used, but depending on the level of integration, it may also be referred to as an IC, system LSI, super LSI, or ultra LSI. Furthermore, the integrated circuit implementation method is not limited to LSI, and may be implemented using a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. After LSI fabrication, a field programmable gate array (FPGA) that can be programmed or a reconfigurable processor that can reconfigure the connections or settings of circuit cells within the LSI may also be used. Furthermore, if an integrated circuit technology that replaces LSI emerges due to advances in semiconductor technology or a derivative technology, that technology may naturally be used to integrate the components.
[0262] A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple processing units on a single chip. Specifically, it is a computer system that includes a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), etc. Computer programs are stored in the ROM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.
[0263] Furthermore, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the determination method or response method shown in any of Figures 15 to 24, 27, and 28.
[0264] Furthermore, for example, the program may be a program to be executed by a computer. Another aspect of the present disclosure may be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium and distributed or circulated. For example, the distributed program may be installed in a device having another processor, and the program may be executed by the processor, thereby causing the device to perform each of the above processes.
[0265] The present disclosure is useful for devices that monitor communications between different systems.
[0266] 1 Security status linking system 10, 10A Electric vehicle (first device) 20 EV management server 30, 30A Charging station 40 Station management server (information processing device) 100 Central ECU (information processing device) 101 Server communication unit (output unit, acquisition unit) 102 Vehicle function access control unit (determination unit) 103 User terminal communication unit 104 Vehicle network communication unit 105 Vehicle status storage unit 106 Vehicle configuration information storage unit 200a Battery management ECU 200b ECU 201a Application unit 202a, 501 Communication unit 203a Version storage unit 300 Battery 400 Display 502, 702, 813 Security status response unit 503, 703 Security monitoring unit 504, 704 Certification certificate storage unit 505 Vehicle information storage unit 601, 601a, 601b, 601c, 801 Charging device (second device) 602 Station management unit 701 Communication unit (output unit, acquisition unit) 705 Station status holding unit 811 Vehicle communication unit 812 Station management communication unit 814 Security status holding unit
Claims
1. A judgment method executed by an information processing device included in a first system, wherein, when a first device included in the first system communicates with a second device included in a second system different from the first system, a request to obtain the security status of the second device is output to the second system, the security status of the second device is obtained from the second system that obtained the acquisition request, and a judgment regarding the communication is made based on the security status of the second device obtained from the second system.
2. The method of claim 1, wherein the security status of the second device is determined based on at least one of information regarding the history of security anomalies in the second device, information regarding vulnerabilities contained in the software that constitutes the second device, and information regarding security monitoring of the second device.
3. The determination method according to claim 1 or 2, wherein when the first device receives a request from the second device to use a function possessed by the first device, the acquisition request is output to the second system.
4. The determination method described in claim 3, wherein at least one of information indicating the function requested by the second device from the first device, equipment information of the second device obtained from the second device, and information indicating the current location of the device itself is output to the second system.
5. The determination method according to claim 1 or 2, wherein the first system manages the security status of only the first device out of the first device and the second device.
6. The determination method according to claim 1 or 2, wherein the first device is one of an electric vehicle and a charging / discharging device, and the second device is the other of the electric vehicle and the charging / discharging device.
7. An information processing device included in a first system, comprising: an output unit that, when a first device included in the first system communicates with a second device included in a second system different from the first system, outputs a request to the second system to obtain the security status of the second device; an acquisition unit that obtains the security status of the second device from the second system that obtained the acquisition request; and a judgment unit that makes a judgment regarding the communication based on the security status of the second device obtained from the second system.
8. A program for causing a computer to execute the determination method according to claim 1 or 2.
9. A response method executed by an information processing device included in a second system, the response method comprising, when a first device included in a first system different from the second system communicates with a second device included in the second system, receiving a request to obtain the security status of the second device from the first device, and outputting the security status of the second device to the first device.
10. The response method described in claim 9, wherein the security status of the second device is determined based on at least one of information regarding the history of security anomalies in the second device, information regarding vulnerabilities contained in the software that constitutes the second device, and information regarding security monitoring of the second device.
11. A response method as described in claim 9 or 10, which determines whether the acquired acquisition request is an acquisition request from the first device communicating with the second device, and if the acquired acquisition request is an acquisition request from the first device communicating with the second device, outputs the security status of the second device to the first device.
12. The response method according to claim 11, wherein if the physical location of the first device and the physical location of the second device are within a predetermined range, it is determined that the acquired acquisition request is an acquisition request from the first device communicating with the second device.
13. The response method according to claim 11, wherein if the first device holds the device information output by the second device, it is determined that the acquired acquisition request is an acquisition request from the first device communicating with the second device.
14. The response method according to claim 11, wherein if the security status of the first device satisfies a predetermined condition, it is determined that the acquired acquisition request is an acquisition request from the first device communicating with the second device.
15. A response method as described in claim 11, in which, when information indicating a function of the first device that the second device has requested the first device to use is obtained from the first device together with the acquisition request, a method for determining whether the obtained acquisition request is an acquisition request from the first device communicating with the second device is changed depending on the type of the function.
16. The response method according to claim 15, further comprising switching to a continuous monitoring mode in which it is monitored to see if any unauthorized control is being performed while the function is being used, in accordance with the information indicating the function.
17. The response method according to claim 16, wherein in the continuous monitoring mode, if there is a discrepancy between at least one of the communication logs of the first device and the second device and the status of the functions of the first device and the second device, a security anomaly is determined to have occurred.
18. The response method according to claim 16, wherein one of the first device and the second device is an electric vehicle, the other of the first device and the second device is a charging device, and the function is related to vehicle charging and the power condition is in a tight state, the response method transitions to the continuous monitoring mode.
19. An information processing device included in a second system, comprising: an acquisition unit that acquires a request to acquire the security status of a second device from a first device included in a first system different from the second system when the first device communicates with a second device included in the second system; and an output unit that outputs the security status of the second device to the first device.
20. A program for causing a computer to execute the response method according to claim 9 or 10.
Citation Information
Patent Citations
Scan processing device, scan processing method, computer program, and scan processing system
JP2019207593A
Vehicle diagnosis system
WO2023170995A1