Information processing method, information processing device, and program

The information processing method and device address cyberattack vulnerabilities in electric vehicle charging systems by analyzing multiple logs to identify and manage abnormalities, ensuring secure and efficient power transactions.

WO2025220469A1PCT designated stage Publication Date: 2025-10-23PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/012695
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-16
Filing Date
2025-03-28
Publication Date
2025-10-23

AI Technical Summary

Technical Problem

Existing systems for charging and discharging mobile objects like electric vehicles are vulnerable to cyberattacks, which can lead to unauthorized charge amounts and require effective identification and management of abnormalities to ensure proper power management.

Method used

An information processing method and device that analyze charging/discharging information using multiple logs from management servers and station servers to identify abnormalities, determine their causes, and implement countermeasures.

Benefits of technology

Facilitates easier identification of abnormality causes, enabling appropriate power management and reducing the risk of unauthorized charges through comprehensive analysis and response to cyber threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025012695_23102025_PF_FP_ABST
    Figure JP2025012695_23102025_PF_FP_ABST
Patent Text Reader

Abstract

An information processing method according to one aspect of the present disclosure involves acquiring charging / discharging information about charging / discharging between a prescribed charging / discharging apparatus and a prescribed mobile body from the prescribed mobile body (S10), using the charging / discharging information to determine whether there is an abnormality (S20), and when it has been determined that there is an abnormality (Yes at S20), analyzing the abnormality on the basis of at least one of a plurality of first logs that are managed by a prescribed management server and include information about charging / discharging for a plurality of mobile bodies that include the prescribed mobile body and a plurality of second logs that are managed by a prescribed station server and include information about charging / discharging for a plurality of charging / discharging apparatuses that include the prescribed charging / discharging apparatus (S30).
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, information processing device, and program

[0001] The present disclosure relates to an information processing method, an information processing device, and a program.

[0002] 2. Description of the Related Art Conventionally, there is a device that detects abnormalities based on vehicle logs (see, for example, Patent Document 1).

[0003] Patent Document 1 discloses an anomaly detection server that is a server for dealing with abnormal frames transmitted over an in-vehicle network. The anomaly detection server disclosed in Patent Document 1 acquires information about frames received over the in-vehicle networks of one or more vehicles including a single vehicle, and calculates the degree of anomaly of the frame received over the in-vehicle network of the single vehicle based on the acquired information about the multiple frames and information about frames received over the in-vehicle network of the single vehicle that was acquired after the acquisition of the information about the multiple frames.

[0004] International Publication No. 2017 / 104112

[0005] Conventionally, there are systems in which mobile objects such as electric vehicles are charged and discharged using chargers and dischargers. Even in such systems, there is a possibility that abnormalities may occur due to cyberattacks and the like. For example, if a cyberattack is carried out during charging from a charger and discharger to a mobile object, and the actual charge amount is tampered with to an unauthorized charge amount, the management company that manages the charger and discharger may charge the user of the mobile object an unauthorized charging fee. Therefore, even in such systems, it is necessary to identify the cause of the abnormality and deal with the abnormality. Thus, in order to enable appropriate power management from the perspective of, for example, smart grids and vehicle-to-grid (V2G), it is desirable to be able to identify the cause of the abnormality in a system in which a charger and discharger charge and a mobile object are charged and discharged.

[0006] The present disclosure provides an information processing method and the like that can make it easier to identify the cause of an abnormality.

[0007] An information processing method according to one aspect of the present disclosure acquires charging / discharging information regarding charging / discharging between a specified charger / discharger and a specified mobile body from the specified mobile body, determines whether or not an abnormality exists based on the charging / discharging information, and if it is determined that an abnormality exists, analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server, which contain information regarding charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server, which contain information regarding charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

[0008] An information processing device according to one aspect of the present disclosure includes an acquisition unit that acquires charging / discharging information regarding charging / discharging between a specified charger / discharger and a specified mobile body from the specified mobile body, a determination unit that determines whether or not an abnormality exists based on the charging / discharging information, and, if it is determined that an abnormality exists, an analysis unit that analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that contain information regarding charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that contain information regarding charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the information processing method described above.

[0010] According to the present disclosure, it is possible to provide an information processing method that makes it easier to identify the cause of an abnormality.

[0011] FIG. 1A is a block diagram showing the configuration of a charging / discharging system according to an embodiment. FIG. 1B is a block diagram showing a specific example of the configuration of a charging / discharging system according to an embodiment. FIG. 2 is a block diagram showing the configuration of a vehicle according to an embodiment. FIG. 3 is a block diagram showing the configuration of a vehicle management server according to an embodiment. FIG. 4 is a block diagram showing the configuration of a transaction management server according to an embodiment. FIG. 5 is a block diagram showing the configuration of a service server according to an embodiment. FIG. 6 is a block diagram showing the configuration of a station server according to an embodiment. FIG. 7 is a block diagram showing the configuration of a charger / discharger according to an embodiment. FIG. 8 is a block diagram showing the configuration of a power company server according to an embodiment. FIG. 9 is a diagram showing real-time anomaly detection rules according to an embodiment. FIG. 10 is a diagram showing termination anomaly detection rules according to an embodiment. FIG. 11 is a diagram showing communication information according to an embodiment. FIG. 12 is a diagram showing a vehicle log according to an embodiment. FIG. 13 is a diagram showing basic vehicle information according to an embodiment. FIG. 14 is a diagram showing an anomaly case according to an embodiment. FIG. 15 is a diagram showing an anomaly response list according to an embodiment. FIG. 16A is a diagram showing an analysis rule list according to an embodiment. FIG. 16B is a diagram showing an analysis rule list according to an embodiment. FIG. 17 is a diagram showing a vehicle management server list according to an embodiment. FIG. 18 is a diagram showing a service server list according to an embodiment. FIG. 19 is a diagram showing a station list according to an embodiment. FIG. 20 is a diagram showing a charger / discharger log according to an embodiment. FIG. 21 is a sequence diagram showing a first example of a processing procedure executed by a charging / discharging system according to an embodiment. FIG. 22 is a sequence diagram showing a second example of a processing procedure executed by a charging / discharging system according to an embodiment. FIG. 23 is a flowchart showing a processing procedure executed by a vehicle management server according to an embodiment. FIG. 24 is a flowchart showing a processing procedure executed by an abnormality detection rule setting unit according to an embodiment. FIG. 25 is a flowchart showing a processing procedure executed by a log collection processing unit according to an embodiment. FIG. 26 is a flowchart showing a processing procedure executed by an abnormality detection unit according to an embodiment. FIG. 27 is a diagram showing an example of an abnormality alert according to an embodiment.Fig. 28 is a flowchart showing the processing procedure executed by the log analysis processing unit according to the embodiment. Fig. 29 is a diagram showing an example of an analysis result output by the analysis server according to the embodiment. Fig. 30 is a diagram showing an example of an analysis report output by the transaction management server according to the embodiment. Fig. 31 is a flowchart showing the processing procedure executed by the abnormality processing unit according to the embodiment. Fig. 32 is a flowchart showing the processing procedure executed by the transaction management server according to the embodiment. Fig. 33 is a flowchart showing a specific example of analysis report creation processing according to the embodiment. Fig. 34 is a flowchart showing an information processing method according to the embodiment.

[0012] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0013] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not recited in the independent claims of the present disclosure are described as optional components. Furthermore, the drawings are not necessarily strict illustrations. In the drawings, substantially identical components are denoted by the same reference numerals, and redundant descriptions may be omitted or simplified.

[0014] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.

[0015] Furthermore, in this specification, when a statement is made in contrast to, for example, "greater than a threshold value" or "less than a threshold value," it means that the distinction is made on the basis of the threshold value, and may mean "greater than the threshold value" or "less than the threshold value," respectively.

[0016] Furthermore, the numerical values ​​such as the threshold values ​​in the present embodiment are merely examples, and other numerical values ​​may be used.

[0017] (Embodiment) [Configuration] FIG. 1A is a block diagram showing the configuration of a charge / discharge system 10 according to an embodiment.

[0018] The charging / discharging system 10 is a system in which a vehicle 100 and a charger / discharger 600 charge and discharge the vehicle 100. For example, the charger / discharger 600 is placed in a station (charging / discharging station) where charging and discharging are performed. The charger / discharger 600 charges (supplies power to) the vehicle 100 and accepts discharge from the vehicle 100.

[0019] In this specification, at least one of the charger / discharger 600 charging the vehicle 100 and the charger / discharger 600 receiving discharge from the vehicle 100 is also referred to as charging / discharging.

[0020] The charging / discharging system 10 includes a vehicle 100 , a charger / discharger 600 , a vehicle management server 200 , a station server 500 , a transaction management server 300 , and a service server 400 .

[0021] Vehicle 100 is a vehicle that uses electricity, such as an electric vehicle (EV). Note that vehicle 100 may be any moving body that uses electricity, such as a motorcycle or a mobile robot. Vehicle 100 is an example of a moving body.

[0022] Charger / discharger 600 is an EV charger / discharger that charges vehicle 100 and accepts discharge from vehicle 100. Charger / discharger 600 supplies electric power from an external commercial power source (not shown) owned by an electric power company or the like to vehicle 100, and supplies electric power from vehicle 100 to the external commercial power source. In this way, a transaction such as selling or purchasing of electric power is carried out between a user who owns vehicle 100 and a management company that manages charger / discharger 600.

[0023] The charger / discharger 600 has, for example, a function for charging and a function for discharging, but it is sufficient if it has either function, and it does not have to have a function for charging or a function for discharging.

[0024] The vehicle management server 200 is a computer for managing the vehicle 100. For example, the vehicle management server 200 receives information relating to charging and discharging with the charger / discharger 600 from the vehicle 100 (also referred to as charging and discharging information of the vehicle 100), and stores the received charging and discharging information as a log (also referred to as a vehicle log) including information relating to charging and discharging of the vehicle 100 (charging and discharging information). Furthermore, for example, the vehicle management server 200 receives and stores information relating to the vehicle 100, such as the manufacturer of the vehicle 100 (also referred to as basic vehicle information), from the vehicle 100. The vehicle management server 200 is an example of a management server.

[0025] The station server 500 is a computer for managing a station where the charger / discharger 600 is installed. The station server 500 receives, for example, information relating to charging and discharging with the vehicle 100 from the charger / discharger 600 (also referred to as charge / discharge information of the charger / discharger 600), and stores the received charge / discharge information as a log (also referred to as a charger / discharger log) including information relating to the charging and discharging of the charger / discharger 600 (charge / discharge information). The station server 500 also stores, for example, information relating to the charger / discharger 600, such as the charging / discharging capacity of the charger / discharger 600 and the type of the charger / discharger 600 (also referred to as charger / discharger basic information).

[0026] The transaction management server 300 is a computer for managing transactions of charging and discharging between the vehicle 100 and the charger / discharger 600 between a user who owns the vehicle 100 and a management company that manages the charger / discharger 600 .

[0027] Service server 400 is a computer for providing services relating to charging and discharging between vehicle 100 and charger / discharger 600 .

[0028] Each computer of vehicle management server 200, station server 500, transaction management server 300, and service server 400 is realized, for example, by a communication interface for communication, non-volatile memory storing programs, volatile memory serving as a temporary storage area for executing the programs, input / output ports for transmitting and receiving signals, and a processor for executing the programs. The communication interface may have, for example, an antenna and a wireless communication circuit for wireless communication, or a connector to which a communication line is connected for wired communication. The communication standard used for communication may be determined arbitrarily and is not particularly limited.

[0029] 1B is a block diagram showing a specific example of the configuration of the charge / discharge system 10a according to the embodiment. The charge / discharge system 10a is a specific example of the configuration of the charge / discharge system 10, which is assumed to be used in practice.

[0030] The charging / discharging system 10a includes vehicles 100a to 100d, chargers / dischargers 600a to 600h, vehicle management servers 200a to 200b, station servers 500a to 500d, a transaction management server 300, service servers 400a to 400b, and electric power company servers 700a to 700c.

[0031] Each of the vehicles 100a to 100d is a specific example of the vehicle 100. Each of the charger / discharger 600a to 600h is a specific example of the charger / discharger 600. Each of the vehicle management servers 200a to 200b is a specific example of the vehicle management server 200. Each of the service servers 400a to 400b is a specific example of the service server 400.

[0032] In this example, vehicle management server 200a manages vehicles 100a and 100b, and vehicle management server 200b manages vehicles 100c and 100d. Also, in this example, station server 500a manages chargers / dischargers 600a-600b, station server 500b manages chargers / dischargers 600c-600d, station server 500c manages chargers / dischargers 600e-600f, and station server 500d manages chargers / dischargers 600g-600h. Specifically, chargers / dischargers 600a-600b are located in the same station, and station server 500a manages charge / discharge information and charger / discharger basic information for chargers / dischargers 600a-600b. Also, chargers / dischargers 600c-600d are located in the same station, and station server 500b manages charge / discharge information and charger / discharger basic information for chargers / dischargers 600c-600d. Furthermore, charger / dischargers 600e to 600f are located in the same station, and station server 500c manages charge / discharge information and charger / discharger basic information for charger / dischargers 600e to 600f. Furthermore, charger / dischargers 600g to 600h are located in the same station, and station server 500d manages charge / discharge information and charger / discharger basic information for charger / dischargers 600g to 600h. For example, charger / dischargers 600a to 600b, charger / dischargers 600c to 600d, charger / dischargers 600e to 600f, and charger / dischargers 600g to 600h are located in different stations.

[0033] In this example, service server 400a provides services to station servers 500a to 500b and manages information on station servers 500a to 500b and chargers / dischargers 600a to 600d managed by station servers 500a to 500b. Service server 400b provides services to station servers 500c to 500d and manages information on station servers 500c to 500d and chargers / dischargers 600a to 600d managed by station servers 500c to 500d. Service server 400a and service server 400b are owned by different service provider companies, for example, and provide different services.

[0034] The power company servers 700a to 700c are servers owned by power companies. For example, the power company servers 700a, 700b, and 700c are servers owned by different power companies.

[0035] For example, when charging / discharging is performed between the charger / discharger 600a and the vehicle 100a, the charging / discharging information of the charger / discharger 600a is transmitted to the station server 500a. The station server 500a stores the received charging / discharging information as a charger / discharger log. The charger / discharger log is an example of a second log. In this case, the charging / discharging information of the vehicle 100 is transmitted to the vehicle management server 200a. The vehicle management server 200a stores the received charging / discharging information as a vehicle log. The vehicle log is an example of a first log.

[0036] Next, the specific configurations of vehicles 100a-100d, chargers / dischargers 600a-600h, vehicle management servers 200a-200b, station servers 500a-500d, transaction management server 300, service servers 400a-400b, and power company servers 700a-700c will be described. Note that the specific configurations of vehicle 100a, charger / discharger 600a, vehicle management server 200a, station server 500a, transaction management server 300, service server 400a, and power company server 700a will be described below. Vehicles 100a to 100d have substantially the same configuration, chargers / dischargers 600a to 600h have substantially the same configuration, vehicle management servers 200a to 200b have substantially the same configuration, station servers 500a to 500d have substantially the same configuration, service servers 400a to 400b have substantially the same configuration, and power company servers 700a to 700c have substantially the same configuration. In the following example, as a specific example of charging / discharging between a vehicle and a charger / discharger, an example in which charging is performed between charger / discharger 600a and vehicle 100a will be described.

[0037] FIG. 2 is a block diagram showing the configuration of a vehicle 100a according to an embodiment.

[0038] The vehicle 100a controls charging and discharging and the vehicle itself, and transmits charging and discharging information and basic vehicle information to a vehicle management server 200a that manages the vehicle. The vehicle management server 200a that manages the vehicle may be determined arbitrarily in advance and is not particularly limited. The vehicle management server 200a that manages the vehicle may be stored in advance in a storage device (not shown) that the vehicle 100a is equipped with. The vehicle 100a includes a charging and discharging control unit 101, a charging and discharging information acquisition unit 102, a charging and discharging port unit 103, a vehicle control unit 104, and a communication unit 105.

[0039] The charge / discharge control unit 101 is a processing unit that controls charging and discharging between the vehicle 100a and the charger / discharger 600a. For example, in order to control charging and discharging of the vehicle 100a, the charge / discharge control unit 101 controls charging and discharging of a battery (not shown) provided in the vehicle 100a.

[0040] The charge / discharge information acquisition unit 102 is a processing unit that acquires charge / discharge information of the vehicle 100a. For example, when charging / discharging is performed between the vehicle 100a and the charger / discharger 600a, the charge / discharge information acquisition unit 102 acquires, as charge / discharge information, the amount of electric power actually charged / discharged.

[0041] The charge / discharge information may include an identifier indicating the charger / discharger 600a that charged / discharged the vehicle 100a, and location information indicating the location of the vehicle 100a when charging / discharging with the charger / discharger 600a was performed.

[0042] The charge / discharge port unit 103 is a port to which a power line or the like is connected in order to charge / discharge between the vehicle 100a and the charger / discharger 600a.

[0043] The vehicle control unit 104 is a processing unit that controls the running of the vehicle 100a.

[0044] The communication unit 105 is a communication interface for communication.

[0045] The vehicle 100a may include a storage device that stores basic vehicle information about the vehicle itself. The vehicle 100a may also include a measuring device such as a GPS (Global Positioning System) for identifying the location of the vehicle itself.

[0046] FIG. 3 is a block diagram showing the configuration of the vehicle management server 200a according to the embodiment.

[0047] The vehicle management server 200a manages the vehicles 100a and 100b by storing charge / discharge information and basic vehicle information of the vehicles 100a and 100b. In this example, the vehicle management server 200a performs abnormality detection (specifically, determines whether an abnormality exists) based on information such as charge / discharge information transmitted from the vehicles 100a and 100b. The vehicle management server 200a is an example of an information processing device. The vehicle management server 200a includes a communication unit 201, an abnormality detection unit 202, an abnormality detection rule setting unit 203, a log collection processing unit 204, a log analysis processing unit 205, an abnormality processing unit 206, a real-time abnormality detection rule storage unit 207, a termination abnormality detection rule storage unit 208, a vehicle log storage unit 209, a basic vehicle information storage unit 210, and an abnormality case storage unit 211.

[0048] The communication unit 201 is a communication interface for communication. For example, the communication unit 201 receives charge / discharge information from the vehicles 100a and 100b. Furthermore, for example, when an abnormality is detected, in other words, when it is determined that an abnormality exists, the communication unit 201 communicates with the transaction management server 300 to exchange information such as information for analyzing the detected abnormality (e.g., information for identifying the cause of the abnormality, such as a vehicle log) and the analysis result of the abnormality (specifically, the result of identifying the cause of the abnormality).

[0049] The abnormality detection unit 202 is a processing unit that performs abnormality detection based on information transmitted from the vehicles 100a and 100b. For example, the abnormality detection unit 202 determines whether or not an abnormality has occurred based on charge / discharge information of the vehicle 100a. The abnormality detection unit 202 is an example of a determination unit.

[0050] Specifically, when determining whether or not an abnormality exists using the charge / discharge information of the vehicle 100a, the abnormality detection unit 202 determines whether or not an abnormality exists by performing a first detection process from the start to the end of charging / discharging between the vehicle 100a and the charger / discharger 600a. Furthermore, after charging / discharging between the vehicle 100a and the charger / discharger 600a is completed, the abnormality detection unit 202 determines whether or not an abnormality exists by performing a second detection process different from the first detection process. In this embodiment, the abnormality detection unit 202 performs abnormality detection in accordance with the detection rules stored in the real-time abnormality detection rule storage unit 207 and the end-of-charge abnormality detection rule storage unit 208. For example, when determining whether or not an abnormality exists using the charge / discharge information of the vehicle 100a, the abnormality detection unit 202 determines whether or not an abnormality exists by performing abnormality detection using the real-time abnormality detection rule for each piece of acquired charge / discharge information based on the charge / discharge information of the vehicle 100a that is sequentially acquired from the start to the end of charging / discharge between the vehicle 100a and the charger / discharger 600a. Furthermore, the abnormality detection unit 202 determines whether or not an abnormality exists by performing an abnormality detection using an end-time abnormality detection rule that is different from the real-time abnormality detection rule, for example, based on a plurality of pieces of charge / discharge information about the vehicle 100a acquired from the start to the end of charging / discharging between the vehicle 100a and the charger / discharger 600a. The first detection process is, for example, an abnormality detection performed using the real-time abnormality detection rule. The second detection process is, for example, an abnormality detection performed using the end-time abnormality detection rule.

[0051] When the anomaly detection unit 202 detects an anomaly, that is, when it determines that an anomaly exists, it creates (generates) information indicating that an anomaly exists (also referred to as an anomaly alert). The anomaly detection unit 202, for example, transmits the anomaly alert to the transaction management server 300. Furthermore, when it determines that an anomaly exists, for example, the anomaly detection unit 202 further determines the nature of the anomaly. A specific example of the anomaly determination process performed by the anomaly detection unit 202 will be described later.

[0052] The abnormality detection rule setting unit 203 is a processing unit that sets (e.g., optimizes) the threshold value of the detection rule depending on the type of vehicle 100a on which charging / discharging is performed, the type of station where the charger / discharger 600a on which charging / discharging is performed is located, and the type of charger / discharger 600a on which charging / discharging is performed.

[0053] The log collection processing unit 204 is a processing unit that collects (acquires) information transmitted from the vehicles 100a and 100b as a log. For example, the log collection processing unit 204 acquires charge / discharge information related to charging / discharging between the charger / discharger 600a and the vehicle 100a from the vehicle 100a. The log collection processing unit 204 stores the acquired charge / discharge information as a log (vehicle log) of the vehicle 100a in the vehicle log storage unit 209. The log collection processing unit 204 is an example of an acquisition unit.

[0054] The charge / discharge information may include, for example, information indicating whether the vehicles 100a and 100b are being charged, or, if not being charged, information indicating the state of the vehicles 100a and 100b, such as whether the vehicles 100a and 100b are running. The charge / discharge information may also include location information indicating the locations of the vehicles 100a and 100b. The vehicle management server 200a may obtain this information by periodically communicating with the vehicles 100a and 100b, even if the vehicles 100a and 100b are not being charged.

[0055] The log analysis processing unit 205 is a processing unit that analyzes the vehicle log in accordance with instructions from the transaction management server 300. When the abnormality detection unit 202 detects an abnormality using the charge / discharge information of the vehicle 100a, that is, when it determines that an abnormality exists, an abnormality alert is sent from the vehicle management server 200a to the transaction management server 300. When the transaction management server 300 receives the abnormality alert, it determines (selects) a server (also referred to as an analysis server) that will identify the cause of the abnormality from among multiple servers, such as the vehicle management server 200a, station server 500a, and service server 400a, that are included in the charge / discharge system 10a. If the vehicle management server 200a is determined as the analysis server, the transaction management server 300 sends an instruction to the vehicle management server 200a to perform an abnormality analysis process (specifically, a process for identifying the cause of the abnormality, also referred to simply as an abnormality analysis). Upon receiving the instruction, the vehicle management server 200a (specifically, the log analysis processing unit 205) performs an abnormality analysis using multiple vehicle logs, including the vehicle log of the vehicle 100a and the vehicle log of a vehicle other than the vehicle 100a (e.g., the vehicle 100b) stored in the vehicle log storage unit 209. As a result, the log analysis processing unit 205 performs the abnormality analysis, i.e., identifies the cause of the abnormality. The log analysis processing unit 205 transmits information indicating the analysis result to, for example, the transaction management server 300.

[0056] The abnormality processing unit 206 is a processing unit that handles abnormalities (also referred to as abnormality handling processing) based on the analysis report received from the transaction management server 300. For example, when the transaction management server 300 acquires an analysis result from the vehicle management server 200a, the transaction management server 300 transmits an analysis report to the vehicle management server 200a based on the acquired analysis result, the analysis report including information indicating the cause of the abnormality and information indicating how to handle the abnormality, which is indicated by the presence or absence of aggression, which indicates whether or not there is a possibility of a cyber attack, etc. Based on the received analysis report, the abnormality processing unit 206 handles the abnormality, for example, by stopping charging and discharging of the vehicle 100a.

[0057] Furthermore, for example, when it is determined that an abnormality exists, the abnormality processing unit 206 executes a countermeasure for the abnormality when it is determined that an abnormality exists, based on abnormality case information indicating the cause of the abnormality that was previously identified. For example, when the abnormality case information includes information indicating the cause of the abnormality that was identified when the same abnormality content as the content of the abnormality that was determined to exist by the abnormality detection unit 202 was detected, the abnormality processing unit 206 executes the same countermeasure as the countermeasure for the abnormality included in the abnormality case information.

[0058] The real-time anomaly detection rule storage unit 207 is a storage device that stores real-time anomaly detection rules.

[0059] The termination abnormality detection rule storage unit 208 is a storage device that stores termination abnormality detection rules.

[0060] The vehicle log storage unit 209 is a storage device that stores charge / discharge information transmitted from the vehicles 100a and 100b as a vehicle log.

[0061] The vehicle basic information storage unit 210 is a storage device that stores basic vehicle information (vehicle basic information) such as the vehicle models of the vehicles 100a and 100b.

[0062] The anomaly case storage unit 211 is a storage device that stores anomaly cases (anomaly case information) that indicate the causes of anomalies previously detected by the anomaly detection unit 202. The anomaly cases include, for example, the causes of anomalies previously detected by the anomaly detection unit 202 and information that indicates the analysis results of the causes of the anomalies. The analysis results include, for example, information that indicates whether or not there is aggression. For example, the content of the response to the anomaly differs depending on whether or not there is aggression.

[0063] FIG. 4 is a block diagram showing the configuration of the transaction management server 300 according to the embodiment.

[0064] Based on the abnormality alert received from vehicle management server 200a or 200b, transaction management server 300 determines the analysis rule to be used for the abnormality analysis by selecting items (analysis items) necessary for the abnormality analysis, such as logs to be used for the analysis (vehicle log and charger / discharger log), and transmits the determined analysis rule (specifically, information indicating the analysis rule) to the analysis server that performs the abnormality analysis. Transaction management server 300 then requests the analysis server to perform the abnormality analysis. Transaction management server 300 includes a communication unit 301, an abnormality analysis control unit 302, an abnormality response list storage unit 303, an analysis rule list storage unit 304, a vehicle management server list storage unit 305, a station server identification unit 306, and a service server list storage unit 307.

[0065] The communication unit 301 is a communication interface for exchanging information such as information relating to abnormality analysis with the vehicle management servers 200a and 200b and the service servers 400a and 400b.

[0066] The abnormality analysis control unit 302 is a processing unit that transmits a command (in this embodiment, information indicating an analysis rule) to the analysis server to perform an abnormality analysis based on an abnormality alert received from the vehicle management server 200a or 200b. The abnormality analysis control unit 302 also selects one or more analysis servers to perform the abnormality analysis from among the multiple servers included in the charging / discharging system 10a. For example, the abnormality analysis control unit 302 determines an analysis server to perform the abnormality analysis from among the multiple servers based on the content of the abnormality determined by the abnormality detection unit 202. As a result, the charging / discharging system 10a performs the abnormality analysis using the determined analysis server. For example, the abnormality analysis control unit 302 selects one or more servers as analysis servers from among the vehicle management server and service server indicated by the abnormality alert.

[0067] The analysis server may be any server, and the number of servers selected as the analysis server may be one or more.

[0068] The specific process for determining the analysis server will be described later.

[0069] The abnormality response list storage unit 303 is a storage device that stores an abnormality response list. The abnormality response list is information that lists the type of abnormality alert (the name of the abnormality alert) and the analysis rule used to analyze the abnormality indicated by the abnormality alert, in association with each other.

[0070] The analysis rule list storage unit 304 is a storage device that stores an analysis rule list. The analysis rule list is information that lists the specific contents of each of a plurality of analysis rules. The analysis rules include, for example, information indicating the requirements for a server to be selected as an analysis server, the classification conditions for logs (vehicle logs and charger / discharger logs) used by the analysis server to analyze an abnormality, the contents of the logs to be checked, the abnormality determination criteria, and whether or not there is aggressiveness. The abnormality analysis control unit 302 determines an analysis rule to be used for abnormality analysis of the contents of the abnormality included in the abnormality alert, for example, based on the contents of the abnormality included in the received abnormality alert and the abnormality response list, and determines an analysis server that will execute the determined analysis rule based on the analysis rule list. Furthermore, the abnormality analysis control unit 302 determines an analysis rule to be used for abnormality analysis of the abnormality content included in the abnormality alert, for example, based on the content of the abnormality included in the received abnormality alert and the abnormality response list, extracts the specific content of the determined analysis rule (for example, classification conditions for logs (vehicle logs and charger / discharger logs) used by the analysis server when analyzing abnormalities, log check content, abnormality determination criteria, and whether or not there is aggressiveness, etc.) from the analysis rule list, and sends the extracted information to the analysis server as the analysis rule to be used for abnormality analysis.

[0071] The vehicle management server list storage unit 305 is a storage device that stores a vehicle management server list. The vehicle management server list is information that lists vehicle management servers that have a trust relationship. In this embodiment, the vehicle management server list stored in the vehicle management server list storage unit 305 includes, for example, information (e.g., identifiers) indicating the vehicle management servers 200a and 200b and information indicating the communication addresses of the vehicle management servers 200a and 200b. The transaction management server 300, for example, obtains the communication address of the vehicle management server 200a from the vehicle management server list storage unit 305 and communicates with the vehicle management server 200a.

[0072] The station server identification unit 306 is a processing unit that identifies the station server that manages the charger / discharger that has performed charging / discharging with the vehicle. For example, the station server identification unit 306 transmits location information indicating the location of the vehicle 100a transmitted from the vehicle 100a to the service servers 400a-400b, and receives a reply from the service server that owns the station corresponding to the location information, thereby identifying the station server that manages the charger / discharger that has performed charging / discharging with the vehicle 100a. At this time, the station server identification unit 306 may also transmit a charger / discharger number indicating the charger / discharger that has performed charging / discharging with the vehicle 100a, along with the location information indicating the location of the vehicle 100a.

[0073] In this way, for example, the station server identification unit 306 identifies the station server that manages the charger / discharger that charged / discharged the vehicle from among multiple station servers based on location information indicating the vehicle's location contained in the charge / discharge information received from the vehicle.

[0074] The service server list storage unit 307 is a storage device that stores a service server list. The service server list is information that lists service servers that have a trust relationship. In this embodiment, the service server list includes information (e.g., identifiers) that indicates the service servers 400a and 400b, and information that indicates the communication addresses of each of the service servers 400a and 400b. The transaction management server 300, for example, obtains the communication address of the service server 400a from the service server list storage unit 307 and communicates with the service server 400a.

[0075] FIG. 5 is a block diagram showing the configuration of the service server 400a according to the embodiment.

[0076] Service server 400a classifies a plurality of charger / discharger logs and performs an abnormality analysis in accordance with the analysis rule received from transaction management server 300. Specifically, service server 400a extracts one or more charger / discharger logs used in the analysis rule from the plurality of charger / discharger logs, and performs an abnormality analysis using the extracted one or more charger / discharger logs. Service server 400a includes a communication unit 401, a log collection processing unit 402, a log analysis processing unit 403, an analysis target list creation unit 404, a charger / discharger log storage unit 405, and a station list storage unit 406.

[0077] The communication unit 401 is a communication interface for communicating with the transaction management server 300 and the station servers 500a and 500b. The communication unit 401 receives, for example, charge / discharge information of the chargers / dischargers 600a, 600b, 600c, and 600d from the station servers 500a and 500b.

[0078] The log collection processing unit 402 is a processing unit that collects (acquires) the charge / discharge information received via the communication unit 401 as a charger / discharger log. The log collection processing unit 402 stores the acquired charger / discharger log in the charger / discharger log storage unit 405.

[0079] The log analysis processing unit 403 is a processing unit that analyzes the charger / discharger log in accordance with an instruction from the transaction management server 300. For example, when an abnormality is detected by the abnormality detection unit 202, an abnormality alert is sent to the transaction management server 300. The transaction management server 300 determines an analysis server that will perform the abnormality analysis. When the transaction management server 300 determines the service server 400a as the analysis server, the transaction management server 300 sends an instruction to perform the abnormality analysis (specifically, information indicating an analysis rule) from the transaction management server 300 to the service server 400a. When the instruction is received, the service server 400a (specifically, the log analysis processing unit 403) performs the abnormality analysis using multiple charger / discharger logs stored in the charger / discharger log storage unit 405, including the charger / discharger log of the charger / discharger 600a and the charger / discharger logs of chargers / dischargers other than the charger / discharger 600a (e.g., chargers 600b, 600c, and 600d). As a result, the log analysis processor 403 analyzes the abnormality. For example, the log analysis processor 403 transmits the analysis result (specifically, information indicating the analysis result) to the transaction management server 300.

[0080] As described above, in the charging / discharging system 10a, when the abnormality detection unit 202 detects an abnormality using the charging / discharging information of the vehicle 100a, at least one of the vehicle management server and the service server determined as the analysis server identifies the cause of the abnormality. Specifically, in the charging / discharging system 10a, when the abnormality detection unit 202 determines that there is an abnormality in the charging / discharging information of the vehicle 100a, an analysis of the abnormality is performed based on at least one of a plurality of vehicle logs of a plurality of vehicles including the vehicle 100a, which are managed by the vehicle management server 200a, and a plurality of charger / discharger logs of a plurality of chargers / dischargers, including the vehicle 100a and the charger / discharger 600a that has charged / discharged, which are managed by the station server 500a.

[0081] Furthermore, for example, when determining whether or not there is an abnormality in the charge / discharge information of vehicle 100a, abnormality detection unit 202 further determines the content of the abnormality. Here, when identifying the cause of the abnormality, for example, log analysis processing units 205 and 403 extract multiple logs from two or more vehicle logs stored in vehicle log storage unit 209 or two or more charger / discharger logs stored in charger / discharger log storage unit 405 based on the content of the abnormality, and analyze the abnormality based on the extracted multiple logs. Log analysis processing units 205 and 403 are each an example of an analysis unit.

[0082] Furthermore, for example, when identifying the cause of an abnormality, the log analysis processors 205 and 403 identify whether the abnormality has been caused by an attack (specifically, a cyber attack).

[0083] The analysis target list creation unit 404 is a processing unit that creates an analysis target list. The analysis target list is information that lists charger / discharger logs of chargers / dischargers that have the same conditions (for example, the same type) as the charger / discharger indicated by the charger / discharger log that is the target of abnormality analysis, extracted from the station list. The analysis target list creation unit 404 creates the analysis target list based on the station list as necessary. The analysis target list creation unit 404 transmits the created analysis target list to, for example, the transaction management server 300. The log analysis processing unit 403 may perform abnormality analysis using the charger / discharger logs of the chargers / dischargers included in the acquired analysis target list.

[0084] The charger / discharger log storage unit 405 is a storage device that stores the charger / discharger log collected by the log collection processing unit 402 .

[0085] Station list storage unit 406 is a storage device that stores a station list. The station list is information that lists station servers and chargers / dischargers managed by the station servers. Station list storage unit 406 stores a station list that includes, for example, information about station servers 500a and 500b and information about chargers / dischargers 600a to 600d.

[0086] FIG. 6 is a block diagram showing the configuration of a station server 500a according to the embodiment.

[0087] The station server 500a manages the chargers / dischargers 600a and 600b arranged in the stations managed by the station server 500a. The station server 500a includes a communication unit 501, a log collection processing unit 502, a charger / discharger log storage unit 503, and a charger / discharger list storage unit 504.

[0088] The communication unit 501 is a communication interface for communicating with the service server 400a and the chargers / dischargers 600a and 600b. The communication unit 501 receives charge / discharge information from the chargers / dischargers 600a and 600b, for example.

[0089] The log collection processing unit 502 is a processing unit that collects (acquires) the charge and discharge information of the chargers and dischargers 600a and 600b received via the communication unit 501 as a charger and discharger log. Specifically, the log collection processing unit 502 stores the charge and discharge information of the chargers and dischargers 600a and 600b as a charger and discharger log in the charger and discharger log storage unit 503.

[0090] The charger / discharger log storage unit 503 is a storage device that stores the charger / discharger log collected by the log collection processing unit 502 .

[0091] The charger / discharger list storage unit 504 is a storage device that stores a charger / discharger list. The charger / discharger list is a list of information related to the chargers / dischargers 600a and 600b managed by the station server 500a. The charger / discharger list storage unit 504 stores the charger / discharger list, which includes information related to the chargers / dischargers 600a and 600b, such as the identifiers of the chargers / dischargers 600a and 600b, the types of the chargers / dischargers 600a and 600b, and the performance of the chargers / dischargers 600a and 600b, such as the maximum charge amounts of the chargers / dischargers 600a and 600b.

[0092] FIG. 7 is a block diagram showing the configuration of a charger / discharger 600a according to an embodiment.

[0093] The charger / discharger 600a is a device that charges and discharges a vehicle (vehicle 100a in this example). The charger / discharger 600a supplies power to the vehicle 100a from an external commercial power source owned by an electric power company that uses an electric power company server 700a, for example, or supplies power from the vehicle 100a to the external commercial power source. The charger / discharger 600a includes a charge / discharge mechanism unit 601, a charge / discharge information acquisition unit 602, a charge / discharger control unit 604, and a communication unit 603.

[0094] The charge / discharge mechanism 601 is a mechanism for charging / discharging the vehicle 100a. The charge / discharge mechanism 601 is realized by, for example, a power line for supplying power from an external commercial power source to the vehicle 100a.

[0095] The charge / discharge information acquisition unit 602 is a processing unit that acquires charge / discharge information of the charger / discharger 600a. For example, when power is supplied to the vehicle 100a from an external commercial power source, the charge / discharge information acquisition unit 602 acquires, as charge / discharge information, information indicating the amount of power actually supplied from a power meter (not shown). In addition, for example, the charge / discharge information acquisition unit 602 communicates with the vehicle 100a to acquire basic vehicle information of the vehicle 100a.

[0096] The charger / discharger control unit 604 is a processing unit that performs overall control of the charger / discharger 600a. For example, the charger / discharger control unit 604 controls communication with the station server 500a and determines the power supply conditions for the amount of power to be supplied to the vehicle 100a based on control information. The charge / discharge mechanism unit 601 is controlled by the charger / discharger control unit 604 so that power is supplied to the vehicle 100a under the determined power supply conditions, for example.

[0097] The communication unit 603 is a communication interface for communicating with the vehicle 100a and the station server 500a. The communication unit 603 transmits charge / discharge information to the station server 500a, for example.

[0098] FIG. 8 is a block diagram showing the configuration of the electric power company server 700a according to the embodiment.

[0099] The electric power company server 700a is a server used by a company that owns an external commercial power source that serves as the supply source of power supplied by the charger / discharger 600a, etc. The electric power company server 700a includes a communication unit 701 and a power management command unit 702.

[0100] The communication unit 701 is a communication interface for communicating with the station server 500a.

[0101] The power management command unit 702 is a processing unit that transmits control information indicating control details related to charging and discharging to the station server 500a via the communication unit 701. The station server 500a, for example, transfers the control information to the charger / discharger 600a, and the charger / discharger 600a charges and discharges the vehicle 100a based on the control information.

[0102] Each of the above processing units is realized by, for example, a processor such as a CPU (Central Processing Unit) and a memory that stores a control program executed by the processor. The above storage device is realized by, for example, a storage device such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive).

[0103] The memories provided in these processing units may be realized by a common memory for each device, or may be realized by one or more independent memories for each device. Also, the processors provided in these processing units may be realized by a common processor for each processing unit for each device, or may be realized by one or more independent processors for each processing unit.

[0104] The communication interface may be realized by, for example, an antenna and a wireless communication circuit for wireless communication, or by a connector to which a communication line is connected. For example, PLC (Power Line Communication) may be used for communication between the devices. Each device may include a circuit or other configuration for performing PLC as a communication interface.

[0105] [Specific Examples of Various Information] Next, specific examples of various information such as charge / discharge information, vehicle log, charger / discharger log, abnormality response list, and analysis rule list will be described.

[0106] 9 is a diagram showing real-time anomaly detection rules according to an embodiment of the present invention. For example, the real-time anomaly detection rule storage unit 207 stores the information shown in FIG.

[0107] The real-time anomaly detection rule includes, for example, information indicating the rule name, information indicating the check content, and information indicating the operation at the time of the check.

[0108] The information indicating the rule name is information indicating the content of each check.

[0109] The information indicating the check content is information indicating the content of the determination of the presence or absence of an abnormality executed by the abnormality detection unit 202 .

[0110] The information indicating the check operation is information indicating the content of the process to be executed when the abnormality detection unit 202 determines that an abnormality exists.

[0111] For example, in the "excess charging power check," the abnormality detection unit 202 determines whether the charging power value in charging the vehicle 100a is equal to or greater than a set maximum charging power value. If the abnormality detection unit 202 determines that the charging power value is equal to or greater than the set maximum charging power value, it determines that an abnormality has occurred, generates an abnormality alert indicating that the charging power is excessive, and forcibly terminates the charging session (specifically, charging between the vehicle 100a and the charger / discharger 600a) (i.e., stops charging and discharging).

[0112] The threshold values ​​such as the maximum charge power value, the minimum charge power value, and the minimum discharge power value are set by, for example, the abnormality detection rule setting unit 203. Note that these threshold values ​​may be arbitrarily determined in advance.

[0113] For example, the abnormality detection unit 202 determines whether or not there is an abnormality in the charging / discharging information from the vehicle 100a received in real time when charging / discharging is being performed between the vehicle 100a and the charger / discharger 600a, using all the check contents included in the real-time abnormality detection rules.

[0114] 10 is a diagram showing the termination abnormality detection rule according to the embodiment. For example, the termination abnormality detection rule storage unit 208 stores the information shown in FIG.

[0115] The termination anomaly detection rule includes, for example, information indicating the rule name, information indicating the check content, and information indicating the check operation. The meaning of each piece of information is the same as that of the real-time anomaly detection rule: the rule name information is information indicating each check content, the check content information is information indicating the content of the determination of the presence or absence of an anomaly executed by the anomaly detection unit 202, and the check operation information is information indicating the content of the process executed when the anomaly detection unit 202 determines that an anomaly exists.

[0116] For example, in the "charge amount check," the abnormality detection unit 202 determines whether the average charging speed for the entire charging performed on the vehicle 100a is equal to or less than a set threshold. If the abnormality detection unit 202 determines that the average charging speed is less than the maximum charging power, it determines that an abnormality exists and generates an abnormality alert indicating an abnormality in the charged amount. The average charging speed, for example, the average charging time, is calculated by (the charging amount (kWh) indicated in the vehicle log) / (the charging time (h) indicated in the vehicle log).

[0117] In addition, for example, in the "reason for termination check," the abnormality detection unit 202 determines whether charging was terminated without normal charging due to, for example, the power line used by the charger / discharger 600a to charge the vehicle 100a being cut off.

[0118] Furthermore, for example, the threshold values ​​used in the "charge amount check" are set by the anomaly detection rule setting unit 203. Note that these threshold values ​​may be arbitrarily determined in advance.

[0119] The abnormality detection unit 202 determines whether or not an abnormality exists, for example, based on the charging / discharging information of the vehicle 100a received from the start to the end of charging / discharging between the vehicle 100a and the charger / discharger 600a, using all the check contents included in the termination abnormality detection rule.

[0120] 11 is a diagram showing communication information according to an embodiment of the present invention, specifically, showing a specific example of information communicated between devices.

[0121] 11A shows information transmitted from vehicle 100a to charger / discharger 600a. The information includes, for example, an identifier (also referred to as a vehicle number) for vehicle 100a, information indicating current and voltage values ​​(respective command values) required when charging or discharging vehicle 100a, and information indicating the remaining power of the battery provided in vehicle 100a.

[0122] 11(b) shows information transmitted from the vehicle 100a to the vehicle management server 200a. Specifically, the information shown in FIG. 11(b) is charge / discharge information for the vehicle 100a. The charge / discharge information for the vehicle 100a includes, for example, information indicating the date and time when charging / discharging was performed, information indicating the vehicle number, location information indicating the location of the vehicle 100a, information transmitted from the vehicle 100a to the charger / discharger 600a, and information transmitted from the charger / discharger 600a to the vehicle 100a.

[0123] 11(c) shows information transmitted from the charger / discharger 600a to the vehicle 100a. The information includes, for example, an identifier (also referred to as a charger / discharger number) identifying the charger / discharger 600a and information indicating the current and voltage values ​​of the charge / discharge performed by the charger / discharger 600a when charging / discharging the vehicle 100a.

[0124] 11(d) shows information transmitted from the charger / discharger 600a to the station server 500a. Specifically, the information shown in FIG. 11(d) is charge / discharge information of the charger / discharger 600a. The charge / discharge information of the charger / discharger 600a includes, for example, information indicating the date and time when charging / discharging was performed, information indicating the charger / discharger number, information transmitted from the charger / discharger 600a to the vehicle 100a, and information indicating the remaining power of the battery provided in the vehicle 100a.

[0125] 12 is a diagram showing a vehicle log according to the embodiment. The vehicle log storage unit 209 stores, for example, the information shown in FIG.

[0126] The vehicle log includes, for example, charge / discharge information received from the vehicles 100a and 100b, information indicating the date and time when the charge / discharge information was received, information indicating whether the vehicles 100a and 100b were charging when they transmitted the charge / discharge information, information indicating the charge / discharge rate, an identifier (also referred to as a station server number) indicating a station server that manages the vehicles 100a and 100b and the charger / discharger that charged / discharged the vehicles, an identifier (also referred to as a service server number) indicating a service server that manages the station server, information indicating a charge rate (a charge per unit time for charging), and information indicating whether charging is being performed normally ("Normal / Abnormal" shown in FIG. 12 ). The "Normal / Abnormal" is, for example, information indicating whether a charging session (specifically, charging between the vehicle 100a and the charger / discharger 600a) is being performed normally. For example, if a power line for charging between the vehicle 100a and the charger / discharger 600a is unintentionally disconnected during charging between the vehicle 100a and the charger / discharger 600a, preventing proper charging, it is determined that an abnormality has occurred. This determination may be made by the vehicle 100a and the charger / discharger 600a and included in the charge / discharge information of the vehicle 100a and the charger / discharger 600a, or may be made by the vehicle management server 200a and the station server 500a. For example, if the vehicle management server 200a and the station server 500a do not receive information from the vehicle 100a and the charger / discharger 600a indicating that the charging session has ended abnormally until charging is completed, the vehicle management server 200a and the station server 500a determine that the "normal / abnormal" status of all logs (vehicle log and charger / discharger log) corresponding to the charge / discharge information received during this charging is normal and associates the information with the log.

[0127] The information indicating the charge / discharge rate may be transmitted from the vehicles 100a and 100b, or may be calculated based on the received charge / discharge information and past vehicle logs, etc. The station server number, the service server number, and the charge rate are received from the service server 400a via the transaction management server 300, for example, and are stored as a vehicle log in association with the charge / discharge information.

[0128] 13 is a diagram showing basic vehicle information according to an embodiment of the present invention. The basic vehicle information storage unit 210 stores, for example, the basic vehicle information shown in FIG.

[0129] The vehicle basic information shown in FIG. 13 is information acquired from the vehicles 100a and 100b, for example.

[0130] The vehicle basic information is information relating to the vehicles 100a and 100b. The vehicle basic information includes, for example, information indicating the vehicle number, information indicating the user name of the user who owns the vehicle 100a or 100b, information indicating the type (model) of the vehicle 100a or 100b, information indicating the version of software used by the vehicles 100a or 100b, and information indicating the fully charged capacity of the batteries provided in the vehicles 100a and 100b.

[0131] The vehicle basic information may be acquired from the vehicles 100a and 100b at any time.

[0132] 14 is a diagram showing abnormality cases according to an embodiment. The abnormality case storage unit 211 stores, for example, information indicating the abnormality cases shown in FIG. 14. Specifically, the abnormality case storage unit 211 stores received analysis reports, which will be described later, as abnormality cases.

[0133] The abnormality case includes, for example, information included in the abnormality alert and information indicating the results of the analysis performed in response to the abnormality alert. In the example shown in FIG. 14 , the abnormality case includes information indicating the abnormality alert created when the abnormality detection unit 202 determines that there is an abnormality ("abnormal alert number" in FIG. 14 ), information indicating the results of the abnormality analysis performed when the abnormality alert was created ("cause of abnormality" in FIG. 14 ), information indicating the analysis server that performed the abnormality analysis ("analysis server number" in FIG. 14 ), information indicating the date and time when the abnormality analysis was performed, information indicating the value determined to be abnormal by the abnormality analysis ("abnormal value" in FIG. 14 ), information indicating the charge / discharge threshold value used in the abnormality analysis ("appropriate value" in FIG. 14 ), information about the vehicle and charger / discharger that performed the charge / discharge that resulted in the creation of the abnormality alert (for example, the type of vehicle, location information, an identifier of the charger / discharger, an identifier of the station server that manages the charger / discharger, and a service server that manages the station server), and information indicating whether the abnormality may have been caused by a cyber attack or the like ("aggression" in FIG. 14 ).

[0134] Here, for example, even if the abnormality detection unit 202 determines that an abnormality exists, the content of the countermeasure executed by the abnormality processing unit 206 differs depending on whether or not aggression is present. For example, the abnormality processing unit 206 executes a first process when aggression is present, and executes a second process different from the first process when aggression is not present. For example, in the first process, an abnormality alert is generated and charging / discharging between the vehicle and the charger / discharger that performed the charging / discharging that resulted in the generation of the abnormality alert is stopped. On the other hand, for example, in the second process, an abnormality alert is generated but charging / discharging between the vehicle and the charger / discharger is not stopped.

[0135] 15 is a diagram showing an abnormality response list according to an embodiment of the present invention, in which the information shown in FIG.

[0136] The anomaly response list is information indicating what kind of anomaly analysis will be performed for the generated anomaly alert.

[0137] The anomaly response list includes information indicating an anomaly alert name, information indicating an analysis rule name, and information indicating an integration rule for analysis results.

[0138] The information indicating the abnormality alert name is information indicating the name of the rule used to determine the presence or absence of an abnormality that led to the creation of the abnormality alert. In this example, the abnormality alert name indicates the content of the abnormality.

[0139] The information indicating the analysis rule name is information indicating the name of the analysis rule used in anomaly analysis. In this example, the analysis rule name corresponds to the cause of the anomaly. For example, when an analysis rule with a certain analysis rule name is used in anomaly analysis and the conditions indicated in the analysis rule are satisfied, the content indicated by the certain analysis rule name is identified as the cause of the anomaly.

[0140] The information indicating the integration rule of the analysis results is information for ultimately determining (specifying) the cause of the abnormality based on one or more analysis results.

[0141] Information indicating the anomaly alert name, information indicating the analysis rule, and information indicating the integration rule for the analysis results are linked together and stored as an anomaly response list.

[0142] For example, when an abnormality alert with the name "Charging Power Excess Abnormality" is created, the abnormality is analyzed according to the analysis rule for "Charging Abnormality (Excess)." If the result of the abnormality analysis satisfies the conditions specified in the analysis rule (specifically, the "Abnormality Judgment Criteria" shown in FIG. 16B), the cause of the abnormality is identified as "Charging Abnormality (Excess)."

[0143] For example, if an abnormality alert with the name "charging power shortage abnormality" is created, the abnormality is analyzed according to the analysis rules for "power shortage abnormality," "station abnormality (power drop)," and "model combination abnormality." For example, if the conditions specified in two or more of the analysis rules for "power shortage abnormality," "station abnormality (power drop)," and "model combination abnormality" are satisfied, one of them is determined as the cause of the abnormality according to the integrated analysis rule. For example, in the example shown in FIG. 15 , if the conditions specified in the analysis rules for "power shortage abnormality," "station abnormality (power drop)," and "model combination abnormality" are all satisfied, the cause of the abnormality is ultimately determined to be "power shortage abnormality."

[0144] In this way, multiple analysis rules may be selected and used for anomaly analysis. Also, for example, if multiple analysis rules are used for anomaly analysis and multiple causes of anomalies are identified, the final cause of the anomaly is determined according to the "analysis result integration rule."

[0145] 16A and 16B are diagrams showing an analysis rule list according to an embodiment of the present invention. The analysis rule list storage unit 304 stores, for example, the information shown in FIGS. 16A and 16B as an analysis rule list.

[0146] The analysis rule list is information indicating the specific contents of the analysis rules shown in FIG.

[0147] The analysis rule list includes information indicating the conditions (analysis server requirements) required of the analysis server that executes the analysis rules, information indicating the classification conditions for logs (vehicle logs and / or charger / discharger logs) used in abnormality analysis, information indicating the check contents for abnormality analysis, information indicating the abnormality determination criteria, and information indicating whether or not there is aggressiveness.

[0148] 16A and 16B, the term "abnormal alert service server" in the analysis server requirements indicates that the analysis server must be a server identified by an identifier, such as a vehicle management server number, included in the abnormal alert. For example, "abnormal alert service server" indicates that the service server identified by the service server number included in the abnormal alert is selected as the analysis server. Furthermore, for example, when the "analysis server requirement" is "service server," this indicates that either the service server 400a or the service server 400b included in the charging / discharging system 10a may be selected as the analysis server. For example, a server that can collect logs that satisfy the log classification conditions shown in FIG. 16A may be selected as the analysis server.

[0149] The analysis server extracts (classifies) stored logs (vehicle logs or charger / discharger logs) based on the log classification conditions, and performs an abnormality analysis on the extracted logs.

[0150] In the anomaly analysis, logs are judged (checked) based on the "check contents" shown in Fig. 16B, and it is determined whether the number of logs that satisfy the check contents meets the "anomaly judgment criteria." For example, in the anomaly analysis, if the "anomaly judgment criteria" are met, it is determined that the cause of the anomaly is the anomaly named in the "analysis rule name."

[0151] Furthermore, "presence or absence of aggression" indicates whether or not the abnormality is aggressive. In other words, "presence or absence of aggression" indicates whether or not the abnormality is likely to have been caused by an attack.

[0152] For example, when the analysis rule for "station abnormality (power drop)" is executed, the service server indicated in the abnormality alert is selected as the analysis server. In this case, for example, the service server indicated in the abnormality alert extracts one or more charger / discharger logs that satisfy the "log classification condition" from among the multiple charger / discharger logs stored therein. In this case, for example, the service server indicated in the abnormality alert determines whether all of the one or more extracted charger / discharger logs satisfy the condition "charging power amount is 30 kW or less." If the service server indicated in the abnormality alert determines that all of the one or more extracted charger / discharger logs satisfy the condition "charging power amount is 30 kW or less," it determines that the cause of the abnormality is "station abnormality (power drop)" and that aggression is present, and transmits the determination result to the transaction management server 300 as the analysis result.

[0153] In the abnormality analysis, only the normal logs may be used from among the "normal / abnormal" logs shown in FIG.

[0154] Furthermore, the presence or absence of aggressiveness corresponding to the analysis rule may be arbitrarily determined in advance.

[0155] For example, "model combination abnormality" is an abnormality that occurs when a vehicle and a charger / discharger are poorly matched. This abnormality is not an aggressive abnormality because it is a problem of compatibility between the vehicle and the charger / discharger, and is therefore set in the analysis rule list as being non-aggressive.

[0156] Furthermore, for example, a power shortage anomaly is an anomaly that occurs when power drops due to a power system shortage. Since this anomaly is caused by a power shortage and is not an anomaly that is offensive to the vehicle, it is set in the analysis rule list as being non-aggressive.

[0157] Furthermore, for example, a station abnormality (power drop) is an abnormality of power drop occurring only in the station where the charger / discharger where charging / discharging was performed is located. Therefore, this abnormality may be an attack on the station, and is set in the analysis rule list as having an attack potential.

[0158] Furthermore, for example, a charging abnormality (excessive) is an abnormality in a single charger / discharger, and therefore may be an attack, and is therefore set in the analysis rule list as having an attack potential.

[0159] Furthermore, for example, a charging time abnormality is an abnormality in which the charging time is longer than the normally expected charging time. This abnormality may result in an increased charge for the charging time, and is set in the analysis rule list as being aggressive, for example.

[0160] Furthermore, for example, a communication jamming anomaly is an anomaly that occurs when charging / discharging is terminated due to a communication error. For example, in the analysis rule for this anomaly, if two or more charger / discharger logs that indicate that the same charger / discharger is charging / discharging at the same time are included among multiple charger / discharger logs, this anomaly is deemed to be an anomaly. Because this anomaly occurs when an attack is made on a charger / discharger that uses a PLC, for example, this anomaly is set in the analysis rule list as being of an attack nature.

[0161] 17 is a diagram showing a vehicle management server list according to an embodiment of the present invention, the vehicle management server list storage unit 305 stores, for example, the information shown in FIG.

[0162] The vehicle management server list is information used by the transaction management server 300 to communicate with the vehicle management servers 200a and 200b.

[0163] The vehicle management server list includes, for example, identifiers of vehicle management servers 200a and 200b (also called vehicle management server numbers), communication addresses of vehicle management servers 200a and 200b, information indicating the business type of the company using vehicle management servers 200a and 200b, and information indicating the manufacturers of vehicles 100a to 100d managed by vehicle management servers 200a and 200b.

[0164] 17, for example, a vehicle management server 200b whose "business type" is "sharing" may manage vehicles from multiple manufacturers. Therefore, the vehicle management server 200b whose "business type" is "sharing" is likely to be able to analyze anomalies.

[0165] 18 is a diagram showing a service server list according to the embodiment. The service server list storage unit 307 stores, for example, the information shown in FIG.

[0166] The service server list is information used by the transaction management server 300 to communicate with the service servers 400a and 400b.

[0167] The service server list includes, for example, identifiers (also called service server numbers) indicating the service servers 400a and 400b, the communication addresses of the service servers 400a and 400b, the charge rates and discharge rates of the chargers / dischargers 600a to 600h managed by the station servers 500a to 500d managed by the service servers 400a and 400b, and information indicating the manufacturers of the chargers / dischargers 600a to 600h.

[0168] 19 is a diagram showing a station list according to the embodiment. For example, the station list storage unit 406 stores the information shown in FIG.

[0169] The station list is information relating to the station servers 500a and 500b.

[0170] The station list includes, for example, identifiers (also referred to as station server numbers) indicating station servers 500a and 500b, identifiers (also referred to as power company server numbers) indicating power company servers 700a and 700b used by power companies that exchange power with chargers / dischargers 600a to 600d managed by station servers 500a and 500b, charger / discharger numbers of chargers / dischargers 600a to 600d, information indicating the types of chargers / dischargers 600a to 600d, protocols used by chargers / dischargers 600a to 600d for charging and discharging, information indicating whether chargers / dischargers 600a to 600d are capable of discharging, information indicating the maximum charge amounts of chargers / dischargers 600a to 600d, information indicating the maximum current amounts of chargers / dischargers 600a to 600d, and location information indicating the locations of station servers 500a and 500b.

[0171] The charger / discharger list storage unit 504 stores, for example, information relating to the device itself (specifically, information about the station server 500a) from among the information shown in FIG.

[0172] 19, the location information indicating the location of the station server 500a is indicated by a predetermined number corresponding to the location, such as "45A." The location indicated by the location information may be any predetermined number corresponding to the location, or may be GPS coordinates (values ​​indicating latitude and longitude), and may be determined arbitrarily.

[0173] 20 is a diagram showing a charger / discharger log according to an embodiment. In charger / discharger log storage unit 405, for example, information shown in FIG. 20 is stored as a charger / discharger log.

[0174] The charger / discharger log includes, for example, information indicating the charger / discharger number of charger / discharger 600a to 600d that performed charging / discharging, information indicating the station server numbers of station servers 500a and 500b that manage charger / discharger 600a to 600d, information indicating the date and time when the charging / discharging was performed, information indicating the charging / discharging rate during the charging / discharging, information indicating the remaining power level of the battery equipped in the vehicle where the charging / discharging was performed, information indicating the charging / discharging rate during the charging / discharging (the charging rate in the example shown in Figure 20), and information indicating whether the charging / discharging was performed normally.

[0175] [Processing Procedure] Next, the processing procedure in the charging / discharging system 10a will be described. Note that in Figures 21 to 33, the processing of the vehicle 100a, the vehicle management server 200a, the transaction management server 300, the service server 400a, the station server 500a, and the charger / discharger 600a when charging of the vehicle 100a is performed between the vehicle 100a and the charger / discharger 600a will be described.

[0176] 21 is a sequence diagram illustrating a first example of a processing procedure executed by the charging / discharging system 10a according to the embodiment. Specifically, FIG. 21 illustrates a processing procedure executed by the charging / discharging system 10a when it is determined that no abnormality exists.

[0177] First, vehicle 100a transmits information indicating an instruction to start charging to charger / discharger 600a (S101).

[0178] Next, when charger / discharger 600a receives information indicating an instruction to start charging, charger / discharger 600a starts charging (power supply) to vehicle 100a (S102).

[0179] When charging is started, the vehicle 100a transmits charge / discharge information relating to charging to the vehicle management server 200a (S103).

[0180] The vehicle management server 200a collects and stores the received charge / discharge information as a vehicle log (S104).

[0181] When charging starts, the charger / discharger 600a transmits charge / discharge information relating to charging to the station server 500a (S105).

[0182] The vehicle management server 200a collects and stores the received charge / discharge information as a charger / discharger log, and transfers it to the service server 400a (S106).

[0183] The service server 400a collects and stores the received charge / discharge information as a charger / discharger log (S107).

[0184] Furthermore, when the vehicle management server 200a receives, for example, charge / discharge information relating to charging / discharging between the vehicle 100a and the charger / discharger 600a for the first time, it transmits to the transaction management server 300 the station server number indicating the station server 500a that manages the charger / discharger 600a, the service server number indicating the service server 400a that manages the station server 500a, and information for requesting the charge / discharge rate (charge rate or discharge rate) for charging / discharging between the vehicle 100a and the charger / discharger 600a (S108). The transaction management server 300 transfers the information to the service server 400a. The information is, for example, location information indicating the location of the vehicle 100a.

[0185] When the transaction management server 300 receives the information, it transmits to the transaction management server 300 the station server number indicating the station server 500a that manages the charger / discharger 600a, the service server number indicating the service server 400a that manages the station server 500a, and the charge / discharge rate for charging / discharging between the vehicle 100a and the charger / discharger 600a (S109). Upon receiving this information, the transaction management server 300 transfers this information to the vehicle management server 200a.

[0186] When the vehicle management server 200a receives this information, it associates it with the charge / discharge information received in S104 and stores this information and the charge / discharge information as a vehicle log (S110).

[0187] Through the processing of steps S108 to S110, the transaction management server 300 (specifically, the station server identification unit 306) and the vehicle management server 200a identify the station server 500a that manages the charger / discharger 600a that has performed charging / discharging with the vehicle 100a. At this time, the transaction management server 300 and the vehicle management server 200a may also transmit the charger / discharger number that indicates the charger / discharger 600a that has performed charging / discharging with the vehicle 100a, along with the location information that indicates the location of the vehicle 100a.

[0188] The information requesting the charging rate and the like includes, for example, the location information of vehicle 100a, which is included in the charge / discharge information of vehicle 100a. For example, when transaction management server 300 receives the location information of vehicle 100a, it transmits the location information of vehicle 100a to all service servers (in this embodiment, service servers 400a and 400b). If the location information indicates that a station managed by the service server 400a or 400b is located at the position indicated by the location information, the service server 400a or 400b transmits information about the station server managing the corresponding station to transaction management server 300 in step S109. Specifically, the service server extracts information about the station server managing the charger / discharger located at the position indicated by the location information and information about the charger / discharger managed by the station server from the station list and transmits the extracted information to transaction management server 300. Transaction management server 300 forwards the received information to vehicle management server 200a. As a result, in step S110, the vehicle management server 200a uses the location information of the vehicle 100a and the identifiers of the vehicle 100a and the charger / discharger 600a that charged / discharged to acquire and store the station server number indicating the station server 500a, the service server number indicating the service server 400a, and information indicating the charge / discharge rate. In this way, for example, the vehicle management server 200a identifies the station server 500a from the multiple station servers 500a to 500d based on the location information of the vehicle 100a included in the charge / discharge information of the vehicle 100a, and acquires the station server number indicating the station server 500a, the service server number indicating the service server 400a, and information indicating the charge / discharge rate.

[0189] Next, the vehicle management server 200a performs anomaly detection (real-time anomaly detection) using the received charge / discharge information and the real-time anomaly detection rule (S111). Specifically, the vehicle management server 200a determines whether or not an anomaly exists based on the received charge / discharge information. That is, the vehicle management server 200a performs anomaly detection to determine whether or not an anomaly exists in the received charge / discharge information.

[0190] If the vehicle management server 200a determines that there is no abnormality (S112), charging continues, and steps S103 to S107 and step S111 are repeated. Steps S108 and S109 do not need to be performed when receiving charge / discharge information for the second or subsequent time. In this case, for example, in step S110, the station server number, service server number, and charge / discharge rate that have already been received are linked to the charge / discharge information received for the second or subsequent time.

[0191] When the above process is repeatedly executed and a predetermined amount of power is charged, vehicle 100a transmits information indicating an instruction to end charging to charger / discharger 600a in order to end charging (S113).

[0192] When charger / discharger 600a receives the information indicating the instruction to end charging, charger / discharger 600a ends charging of vehicle 100a (S114).

[0193] Furthermore, the charger / discharger 600a transmits a completion report (completion report information) indicating that charging has been completed to the station server 500a (S115). The station server 500a transfers the received completion report to the service server 400a.

[0194] When the service server 400a receives the completion report, it calculates the charge for charging based on, for example, the charger / discharger log, and transmits a charge report (charge report information) indicating the calculated charge to the transaction management server 300 (S116). The transaction management server 300 transfers the received charge report to the vehicle management server 200a.

[0195] When the vehicle management server 200a receives the fee report, it performs abnormality detection (end-time abnormality detection) using the received charge / discharge information and the end-time abnormality detection rule (S117). Specifically, the vehicle management server 200a re-determines whether or not there is an abnormality based on the multiple charge / discharge information received from the start to the end of charging.

[0196] If the vehicle management server 200a determines that there is no abnormality (S118), the process for charging the vehicle 100a and the charger / discharger 600a ends. For example, the vehicle management server 200a notifies the user of the vehicle 100a of the fee, and the user pays the notified fee to the company that manages the station server 500a.

[0197] 22 is a sequence diagram illustrating a second example of the processing procedure executed by the charging / discharging system 10a according to the embodiment. Specifically, FIG. 22 illustrates the processing procedure executed by the charging / discharging system 10a when it is determined that an abnormality exists.

[0198] 21, if it is determined that no abnormality is present (S112), the processes of steps S101 to S112 are repeatedly executed. As described above, steps S108 and S109 do not need to be executed when receiving the charge / discharge information for the second time or later.

[0199] Here, for example, it is assumed that the charging power of the charger / discharger 600a has dropped from a predetermined charging power (S201), that is, some kind of abnormality has occurred and the charging power of the charger / discharger 600a has dropped.

[0200] In this case as well, the vehicle 100a transmits the charge / discharge information to the vehicle management server 200a (S202), and the vehicle management server 200a collects and stores the received charge / discharge information as a vehicle log (S203).

[0201] The charger / discharger 600a transmits the charge / discharge information to the station server 500a (S204), and the vehicle management server 200a collects and stores the received charge / discharge information as a charger / discharger log and transfers it to the service server 400a (S205). The service server 400a collects and stores the received charge / discharge information as a charger / discharger log (S206).

[0202] Furthermore, the vehicle management server 200a performs real-time abnormality detection based on the received charge / discharge information (S207).

[0203] Here, it is assumed that the vehicle management server 200a determines that an abnormality has occurred (S208). In this case, the vehicle management server 200a sends an analysis request (analysis request information) to the transaction management server 300 to request an analysis of the abnormality (S209). The information sent as the analysis request is, for example, an abnormality alert. For example, when the vehicle management server 200a determines that an abnormality has occurred, it sends an abnormality alert indicating the details of the abnormality to the transaction management server 300.

[0204] The content of the abnormality may be determined arbitrarily in advance and is not particularly limited. Examples of the abnormality include an abnormality where charging power is greater than a predetermined charging power value (first power value) (excessive charging power abnormality), an abnormality where charging power is less than a predetermined charging power value (second power value) (insufficient charging power abnormality), an abnormality where discharging power is greater than a predetermined discharging power value (excessive discharging power abnormality), an abnormality where charging speed is less than a predetermined average charging speed (abnormal billing amount), or an abnormality where charging or discharging has abnormally ended (abnormal end).

[0205] When the transaction management server 300 receives an analysis request, specifically an abnormality alert, it determines the information necessary for abnormality analysis (S210). Specifically, the transaction management server 300 determines the analysis rules to be used for abnormality analysis based on the abnormality alert. The transaction management server 300 also determines the analysis server based on the abnormality alert.

[0206] The transaction management server 300 transmits information requesting an abnormality analysis to the determined analysis server (S211). In this example, it is assumed that the vehicle management server 200a and the service server 400a are determined as the analysis servers. In this case, the transaction management server 300 transmits information requesting an abnormality analysis to the vehicle management server 200a and the service server 400a. The information requesting an abnormality analysis includes, for example, information indicating the analysis rule.

[0207] When the vehicle management server 200a receives information requesting an abnormality analysis, it performs an abnormality analysis, for example, using the analysis rules and vehicle log included in the information, and transmits the analysis results to the transaction management server 300 (S212).

[0208] Similarly, when the service server 400a receives information requesting an abnormality analysis, it performs an abnormality analysis using, for example, the analysis rules and charger / discharger log included in the information, and transmits the analysis results to the transaction management server 300 (S213).

[0209] As a result, in this example, the vehicle management server 200a and the service server 400a identify the cause of the abnormality. The identified cause of the abnormality may be determined in advance and is not particularly limited. Examples of the cause of the abnormality include a power shortage abnormality (a power shortage abnormality) due to a power shortage from an external commercial power source, an abnormality in which charging is not performed properly due to some kind of malfunction at the station (a station abnormality), or an abnormality in which charging is not performed properly due to an incompatible model or other combination between the vehicle 100a and the charger / discharger 600a (a combination abnormality). Identifying the cause of the abnormality may mean, for example, performing an abnormality analysis based on the content of the abnormality and identifying the cause of the abnormality according to the content. However, it may also mean determining whether the determination result of the abnormality detection unit 202 that a malfunction has occurred is correct. In other words, the content of the abnormality determined by the abnormality detection unit 202 and the cause of the abnormality indicated by the analysis result by the analysis server may be the same or different.

[0210] The transaction management server 300 creates an analysis report (analysis report information) based on the analysis results received from the vehicle management server 200a and the service server 400a (S214). For example, if the analysis results identify multiple causes of the abnormality, the transaction management server 300 determines the cause of the abnormality by selecting one of the multiple causes using the analysis result integration rule shown in Figure 15. The transaction management server 300 creates an analysis report that includes information contained in the abnormality alert, information indicating the determined cause of the abnormality, and information indicating whether or not there is aggression.

[0211] The transaction management server 300 transmits the created analysis report to, for example, the analysis server and the server that sent the analysis request (S215). In this example, the transaction management server 300 transmits the analysis report to the vehicle management server 200a and the service server 400a.

[0212] The vehicle management server 200a stores the received analysis report as an abnormality case (abnormality case information), and takes action to address the abnormality that is determined to exist based on the information indicating the presence or absence of aggression contained in the analysis report (S216). In this example, the vehicle management server 200a transmits information to the vehicle 100a indicating an instruction to stop charging the vehicle 100a.

[0213] When receiving the information indicating the instruction to stop charging, vehicle 100a transmits the information indicating the instruction to stop charging to charger / discharger 600a (S217).

[0214] When the charger / discharger 600a receives the information indicating an instruction to stop charging, the charger / discharger 600a stops charging the vehicle 100a (S218).

[0215] As a result, if it is determined that there is an abnormality, for example, the cause of the abnormality (for example, the aggressiveness of the abnormality) is analyzed, and based on the analysis results, measures such as emergency stopping of charging are taken.

[0216] FIG. 23 is a flowchart showing a processing procedure executed by the vehicle management server 200a according to the embodiment.

[0217] First, the vehicle management server 200a receives charge / discharge information from the vehicle 100a (S301).

[0218] Next, the vehicle management server 200a determines whether the charge / discharge information of the vehicle 100a received in step S301 is the first charge / discharge information received (S302). For example, the vehicle management server 200a determines whether the received charge / discharge information is the first charge / discharge information when charging / discharging between the vehicle 100a and the charger / discharger 600a is started, based on the vehicle log stored in the vehicle log storage unit 209.

[0219] If the vehicle management server 200a determines that the charge / discharge information is the first one it has received (Yes in S302), it performs an abnormality detection rule update process (S303). Specifically, the vehicle management server 200a updates the real-time abnormality detection rule and the termination abnormality detection rule.

[0220] If the answer to step S302 is No, or after step S303, the vehicle management server 200a performs a log collection process (S304). Specifically, the vehicle management server 200a stores the received charge / discharge information as a vehicle log.

[0221] Next, the vehicle management server 200a performs an abnormality detection process (S305). Specifically, the vehicle management server 200a determines whether or not an abnormality has occurred by using the received charge / discharge information and the real-time abnormality detection rule or the termination abnormality detection rule.

[0222] Next, the vehicle management server 200a determines whether or not an abnormality alert has been sent to the transaction management server 300 (S306). Specifically, the vehicle management server 200a determines whether or not an abnormality alert has been created and sent to the transaction management server 300 after determining that an abnormality has occurred in step S305.

[0223] If the vehicle management server 200a determines that an abnormality alert has not been sent (No in S306), the process ends.

[0224] On the other hand, if the vehicle management server 200a determines that an abnormality alert has been sent (Yes in S306), it determines whether or not a request for abnormality analysis has been received from the transaction management server 300 (S307). Specifically, it determines whether or not the transaction management server 300 has selected the vehicle management server 200a as an analysis server and received information requesting abnormality analysis.

[0225] When the vehicle management server 200a determines that it has received a request for an abnormality analysis from the transaction management server 300 (Yes in S307), it performs an abnormality analysis process (S308). Specifically, the vehicle management server 200a performs an abnormality analysis (specifically, identifies the cause of the abnormality) using the analysis rule and vehicle log received together with the request for abnormality analysis. The vehicle management server 200a transmits to the transaction management server 300 an analysis result indicating the cause of the abnormality identified in the abnormality analysis process.

[0226] Next, the vehicle management server 200a receives the analysis report (S309).

[0227] Next, the vehicle management server 200a performs an abnormality handling process based on the analysis report received in step S309 (S310). Specifically, the vehicle management server 200a stores the analysis report as an abnormality case and sends an instruction to the vehicle 100a to stop charging.

[0228] 24 is a flowchart illustrating a processing procedure executed by the anomaly detection rule setting unit 203 according to the embodiment. Specifically, FIG. 24 illustrates details of the processing in step S303.

[0229] First, the abnormality detection rule setting unit 203 acquires one or more vehicle logs of vehicles other than the vehicle 100a stored in the vehicle log storage unit 209 (S401). The abnormality detection rule setting unit 203 performs the processes of steps S402 to S407 using, for example, the acquired one or more vehicle logs and the vehicle basic information.

[0230] The abnormality detection rule setting unit 203 determines whether the number of vehicle logs among the one or more acquired vehicle logs, which are for vehicle models identical to the vehicle 100a and for which charging / discharging was performed by chargers located in the same station as the charger / discharger 600a that charged the vehicle 100a, is equal to or greater than a predetermined number (S402). The chargers located in the same station as the charger / discharger 600a that charged the vehicle 100a are chargers managed by the station server 500a that manages the charger / discharger 600a. In this example, the chargers located in the same station as the charger / discharger 600a that charged the vehicle 100a are the chargers 600a and 600b. The predetermined number may be set arbitrarily and is not particularly limited. For example, the predetermined number is 10.

[0231] If the answer is Yes in step S402, that is, if it is determined in step S402 that the number is greater than or equal to a predetermined number, the abnormality detection rule setting unit 203 extracts from the one or more acquired vehicle logs those vehicle logs in which charging and discharging were performed by a charger / discharger of the same model as the vehicle 100a and located at the same station as the charger / discharger 600a that charged the vehicle 100a (S403).

[0232] If the answer is No in step S402, that is, if it is determined in step S402 that the number is less than the predetermined number, the anomaly detection rule setting unit 203 determines whether the number of vehicle logs in which charging and discharging were performed by a charger / discharger located in the same station as the charger / discharger 600a that charged the vehicle 100a is equal to or greater than a predetermined number (S405). Note that the predetermined number may be determined arbitrarily and is not particularly limited. For example, the predetermined number is 10. Furthermore, the predetermined number described in step S402 and the predetermined number described in step S405 may be the same number or different numbers.

[0233] If the answer is Yes in step S405, that is, if it is determined in step S405 that the number is greater than or equal to a predetermined number, the abnormality detection rule setting unit 203 extracts, from the one or more acquired vehicle logs, vehicle logs in which charging / discharging was performed by a charger / discharger located in the same station as the charger / discharger 600a that charged the vehicle 100a (S406).

[0234] If the answer is No in step S405, that is, if the abnormality detection rule setting unit 203 determines that the number is less than the predetermined number in step S405, it extracts vehicle logs of the same model as vehicle 100a from the one or more acquired vehicle logs (S407).

[0235] After step S403, step S406, or step S407, the anomaly detection rule setting unit 203 sets the most frequent value indicated by the vehicle log extracted in step S403, step S406, or step S407 as each threshold value of the anomaly detection rule (S408). Specifically, the anomaly detection rule setting unit 203 updates the set maximum charge power value, set minimum charge power value, and set maximum discharge power value in the real-time anomaly detection rule, and the set threshold values ​​in the termination anomaly detection rule.

[0236] The abnormality detection rule setting unit 203 calculates the charging rate, for example, by calculating ((remaining battery capacity indicated by the charge / discharge information received in step S301) / (full charge capacity indicated by the vehicle basic information)) × 100. For example, if the calculated charging rate is less than a predetermined value, the abnormality detection rule setting unit 203 updates the most frequent values ​​of the vehicle logs whose charging rates are less than the predetermined value to the maximum charging power, minimum charging power, and average charging speed (set thresholds). On the other hand, for example, if the calculated charging rate is equal to or greater than a predetermined value, the abnormality detection rule setting unit 203 updates the most frequent values ​​of the vehicle logs whose charging rates are equal to or greater than the predetermined value to the maximum charging power, minimum charging power, and average charging speed (set thresholds).

[0237] The predetermined value may be set arbitrarily and is not particularly limited, and is, for example, 80%.

[0238] 25 is a flowchart showing the processing procedure executed by the log collection processor 204 according to the embodiment. Specifically, FIG. 25 shows details of the processing of step S304.

[0239] First, the log collection processing unit 204 determines whether the charge / discharge information received in step S301 is the first charge / discharge information when charging / discharging between the vehicle 100a and the charger / discharger 600a is started (S501).

[0240] If the answer to step S501 is Yes, that is, if the log collection processing unit 204 determines in step S501 that the charge / discharge information is the first, it transmits to the transaction management server 300 the station server number indicating the station server 500a that manages the charge / discharger 600a, the service server number indicating the service server 400a that manages the station server 500a, and information for requesting the charge / discharge rate for charging / discharging between the vehicle 100a and the charge / discharger 600a (S502). The transaction management server 300 transfers the received information to the service server 400a. For example, the transaction management server 300 receives the station server number, service server number, and charge / discharge rate from the service server 400a and transfers them to the vehicle management server 200a. As a result, the log collection processing unit 204 receives the station server number, service server number, and charge / discharge rate.

[0241] If the answer is No in step S501, that is, if it is determined in step S501 that the charge / discharge information is not the first one, or after step S502, the log collection processing unit 204 associates the received charge / discharge information with the received station server number, service server number, and information indicating the charge / discharge rate, and stores the associated information as a vehicle log in the vehicle log storage unit 209 (S503). Note that if the answer is No in step S501, that is, if the charge / discharge information is received for the second or subsequent time, the station server number, service server number, and charge / discharge rate have been received in the first process of receiving charge / discharge information, and therefore the already received station server number, service server number, and information indicating the charge / discharge rate are associated with the charge / discharge information and stored as a vehicle log in the vehicle log storage unit 209.

[0242] As a result, the vehicle management server 200a receives and stores information that is not included in the charge / discharge information received from the vehicle 100a via the transaction management server 300.

[0243] 26 is a flowchart illustrating a processing procedure executed by the abnormality detection unit 202 according to the embodiment. Specifically, FIG. 26 illustrates details of the processing of step S305.

[0244] First, the abnormality detection unit 202 determines whether the vehicle state indicated in the charge / discharge information is charging (S601). The vehicle state indicates the state of the vehicle, such as charging, stopped, or running.

[0245] When the abnormality detection unit 202 determines that the vehicle state indicated in the charge / discharge information is charging (Yes in step S601), the abnormality detection unit 202 detects an abnormality using the real-time abnormality detection rule (S602).

[0246] On the other hand, when the abnormality detection unit 202 determines that the vehicle state indicated in the charge / discharge information is not charging (No in step S601), the abnormality detection unit 202 detects an abnormality using the termination abnormality detection rule (S603). For example, when the vehicle state included in the received charge / discharge information is other than "charging," for example, when the vehicle state included in the most recently received charge / discharge information is "charging," the abnormality detection unit 202 determines that charging of the vehicle 100a has ended, and detects an abnormality using the termination abnormality detection rule.

[0247] As a result of detecting an abnormality in step S602 or step S603, the abnormality detection unit 202 determines whether or not an abnormality exists (S604).

[0248] If the abnormality detection unit 202 determines that no abnormality exists (No in step S604), the process ends.

[0249] On the other hand, if the anomaly detection unit 202 determines that an anomaly has occurred (Yes in step S604), the anomaly detection unit 202 creates an anomaly alert indicating the details of the detected anomaly (S605).

[0250] Next, the anomaly detection unit 202 determines whether an anomaly case indicating an analysis result of an anomaly similar to the detected anomaly is stored in the anomaly case storage unit 211 (S606). For example, the anomaly detection unit 202 determines a possible cause of the anomaly based on the content of the detected anomaly, and determines whether there is an anomaly case with the same cause as the determined anomaly cause. The vehicle management server 200 may store an anomaly response list to determine the cause of an anomaly that may be the same as the detected anomaly. Furthermore, the anomaly case may include information indicating the content of the anomaly.

[0251] If the anomaly detection unit 202 determines that there is no anomaly case stored in the anomaly case storage unit 211 that indicates an analysis result of an anomaly similar to the detected anomaly (No in step S606), it sends the created anomaly alert to the transaction management server 300 (S607) and terminates processing.

[0252] On the other hand, if the anomaly detection unit 202 determines that an anomaly case indicating an analysis result of an anomaly similar to the detected anomaly is stored in the anomaly case storage unit 211 (Yes in step S606), it executes a countermeasure against the anomaly indicated by the anomaly case based on the anomaly case corresponding to the similar anomaly (S608), and terminates the processing. For example, if the anomaly case indicates aggression, the anomaly countermeasure processing is executed by executing step S803, which will be described later. On the other hand, if the anomaly case indicates a lack of aggression, the anomaly countermeasure processing is executed by executing step S804, which will be described later.

[0253] In this case, the vehicle management server 200a may terminate the process without performing step S307 and subsequent steps. Alternatively, the vehicle management server 200a may send an abnormality alert to the transaction management server 300 and perform step S307 and subsequent steps. In this case, the vehicle management server 200a may not execute step S310 after executing step S309. In step S310, the vehicle management server 200a determines, based on the analysis report, whether the abnormality handling process to be executed in step S310 is the same as the abnormality handling process executed in step S608. If they are the same, the process may terminate as is, or if they are not the same, the vehicle management server 200a may execute abnormality handling process based on the analysis report.

[0254] FIG. 27 is a diagram illustrating an example of an abnormality alert according to the embodiment.

[0255] The abnormality alert includes, for example, information indicating the abnormality alert number of the abnormality alert, information indicating the content of the abnormality, information indicating the date and time when the abnormality was detected, information indicating the value determined to be abnormal (the ``abnormal value'' shown in Figure 27), information indicating the threshold value used to detect the abnormality (the ``appropriate value'' shown in Figure 27), information indicating the vehicle model of vehicle 100a, the charger / discharger number of charger / discharger 600a, the station server number indicating station server 500a, the service server number indicating service server 400a, and location information indicating the location of vehicle 100a.

[0256] 28 is a flowchart illustrating a processing procedure executed by the log analysis processor 205 according to the embodiment. Specifically, FIG. 28 illustrates details of the processing in step S308.

[0257] 28 is a flowchart of the abnormality analysis process executed by the analysis server. For example, when service server 400a is selected as the analysis server, log analysis processing unit 403 also performs the process shown in FIG. 28. In this case, the vehicle log described in FIG. 28 becomes the charger / discharger log.

[0258] First, the log analysis processing unit 205 receives the analysis rule from the transaction management server 300 (S701).

[0259] Next, the log analysis processing unit 205 searches for a vehicle log that satisfies the log classification condition from among one or more vehicle logs stored in the vehicle log storage unit 209, based on the log classification condition included in the analysis rule (S702).

[0260] The log analysis processing unit 205 determines whether or not there is a vehicle log that satisfies the log classification condition as a result of the search in step S702 (S703).

[0261] If the log analysis processing unit 205 determines that there is a vehicle log that satisfies the log classification conditions (Yes in step S703), it counts the number of vehicle logs that satisfy the check conditions included in the analysis rule among the one or more vehicle logs that satisfy the log classification conditions (S704).

[0262] The log analysis processing unit 205 determines whether the number of vehicle logs that satisfy the check conditions as a result of the counting in step S704 satisfies the abnormality determination criterion included in the analysis rule (S705).

[0263] If the log analysis processor 205 determines that the abnormality determination criteria are met (Yes in step S705), it determines that an abnormality has occurred (S706). The log analysis processor 205 also identifies the cause of the abnormality as the received analysis rule, i.e., the cause of the abnormality corresponding to the analysis rule used for the abnormality analysis (in this example, the analysis rule name).

[0264] If it is determined that the abnormality determination criteria are not met (No in step S705), the log analysis processing unit 205 determines that there is no abnormality (S707). That is, in this case, even if the abnormality detection unit 202 determines that there is an abnormality, the log analysis processing unit 205 determines that there is no abnormality as a result of the abnormality analysis.

[0265] Furthermore, if the answer to step S703 is No, that is, if it is determined that there are no vehicle logs that satisfy the log classification conditions, in other words, if there are no vehicle logs that can be used for abnormality analysis, the log analysis processing unit 205 determines that analysis is not possible (S708).

[0266] After step S706, S707, or S708, the log analysis processor 205 transmits the determination result (analysis result) in step S706, S707, or S708 to the transaction management server 300 (S709).

[0267] 29 is a diagram showing an example of an analysis result output by an analysis server according to an embodiment. The example shown in FIG. 29 shows the analysis result sent from the vehicle management server 200a to the transaction management server 300 when the analysis server is the vehicle management server 200a.

[0268] The analysis results include, for example, information indicating the abnormality alert number, information indicating the cause of the abnormality, information indicating the judgment result in step S706, S707, or S708, information indicating the analysis server number (i.e., an identifier indicating the device itself), and information indicating whether or not there is aggressiveness.

[0269] For example, if the service server 400a is selected as the analysis server, the service server 400a also transmits the analysis results shown in Figure 29 to the transaction management server 300. In this case, for example, the analysis server number shown in Figure 29 becomes 400a.

[0270] 30 is a diagram showing an example of an analysis report output by the transaction management server 300 according to the embodiment. The transaction management server 300 transmits the analysis report shown in FIG. 30 to the server that sent the abnormality alert and the analysis server (in this example, the vehicle management server 200 and the service server 400a).

[0271] 30 , the analysis report includes, for example, information included in the received analysis result and information included in the received abnormality alert. In the example shown in FIG. 30 , the analysis report includes information indicating an abnormality alert number, information indicating a cause of the abnormality, information indicating a determination result in step S706, S707, or S708, information indicating an analysis server number, information indicating the presence or absence of aggression, information indicating the date and time when the abnormality was detected, information indicating a value determined to be abnormal (the “abnormal value” shown in FIG. 30 ), information indicating a threshold value used for detecting the abnormality (the “appropriate value” shown in FIG. 30 ), information indicating the vehicle model of vehicle 100a, the charger / discharger number of charger / discharger 600a, the station server number indicating station server 500a, the service server number indicating service server 400a, and location information indicating the location of vehicle 100a.

[0272] 31 is a flowchart showing the processing procedure executed by the abnormality processing unit 206 according to the embodiment. Specifically, FIG. 31 shows a specific example of the processing executed in step S310.

[0273] First, the abnormality processing unit 206 receives an analysis report from the transaction management server 300 (S801).

[0274] Next, the anomaly processing unit 206 determines whether or not there is an attack, that is, whether or not there is a possibility that the anomaly detected by the anomaly detection unit 202 is caused by an attack, based on the received analysis report (S802).

[0275] If the abnormality processing unit 206 determines that there is aggression (Yes in step S802), it notifies (sends) an abnormality alert to the vehicle 100a and sends an instruction to the vehicle 100a to stop charging and discharging (S803).

[0276] On the other hand, if the abnormality processing unit 206 determines that there is no aggression (No in step S802), it notifies (transmits) an abnormality alert to the vehicle 100a (S804). In this case, the abnormality processing unit 206 does not transmit an instruction to stop charging / discharging to the vehicle 100a.

[0277] After step S803 or S804, the abnormality processing unit 206 stores the received analysis report as an abnormality case in the abnormality case storage unit 211 (S805).

[0278] In this way, the abnormality processing unit 206 stops charging / discharging the vehicle 100a if there is aggressiveness, and notifies the vehicle 100a that there is an abnormality without stopping charging / discharging if there is no aggressiveness.

[0279] FIG. 32 is a flowchart showing the processing procedure executed by the transaction management server 300 according to the embodiment.

[0280] When the transaction management server 300 receives an abnormality alert from the vehicle management server 200a (S901), it executes the processes from step S902 onwards.

[0281] The transaction management server 300 creates an analysis rule to be used for anomaly analysis based on the received anomaly alert, anomaly response list, and analysis rule list (S902). Specifically, the transaction management server 300 creates an analysis rule to be used for anomaly analysis by selecting one or more analysis rules from the multiple analysis rules included in the analysis rule list based on the received anomaly alert, anomaly response list, and analysis rule list.

[0282] Next, the transaction management server 300 determines whether the charger / discharger list is required for an abnormality analysis (S903). The transaction management server 300 determines whether it is necessary to analyze the charger / discharger log to identify the cause of the abnormality, for example, based on the content of the abnormality indicated in the received abnormality alert.

[0283] When the transaction management server 300 determines that a charger / discharger list is necessary (Yes in step S903), it transmits information requesting a charger / discharger list including the charger / discharger log to be analyzed to the service server 400a (S904). The information includes, for example, information indicating the charger / discharger 600a included in the abnormality alert (charger / discharger number). Based on the charger / discharger number included in the information, the service server 400a creates a charger / discharger list that lists chargers / dischargers of the same type as the charger / discharger 600a, for example, and transmits the created charger / discharger list to the transaction management server 300. As a result, the transaction management server 300 receives the charger / discharger list.

[0284] If the transaction management server 300 determines that the charger / discharger list is not required (No in step S903), or after step S904, the transaction management server 300 performs an analysis report creation process (S905). Specifically, the transaction management server 300 determines an analysis server, receives analysis results from the determined analysis server, and creates an analysis report based on the received analysis results.

[0285] Next, the transaction management server 300 sends the created analysis report to the vehicle management server indicated by the vehicle management server number included in the abnormality alert (in this example, vehicle management server 200a) and to the service server indicated by the service server number included in the abnormality alert (in this example, service server 400a) (S906).

[0286] The transaction management server 300 communicates with each server based on, for example, a vehicle management server list and a service server list.

[0287] 33 is a flowchart showing a specific example of the analysis report creation process according to the embodiment. Specifically, FIG. 33 shows details of the process executed in step S905.

[0288] First, the transaction management server 300 determines an analysis server based on the abnormality alert, the abnormality response list, and the analysis rule list (S1001).

[0289] Next, the transaction management server 300 transmits the analysis rule created in step S902 to the determined analysis server (S1002).

[0290] Next, the transaction management server 300 receives the analysis results from the analysis server (S1003).

[0291] Next, the transaction management server 300 creates an analysis report based on the received analysis results (S1004).

[0292] By performing the above process, when an abnormality is detected in the vehicle management server 200a, the abnormality is analyzed in more detail and the cause of the abnormality is identified.

[0293] The analysis server may be selected arbitrarily. For example, the transaction management server 300 may preferentially select a server that has not been requested to perform analysis as the analysis server. Furthermore, for example, the transaction management server 300 may select a server indicated by the vehicle management server number, service server number, and station server number included in the abnormality alert as the analysis server.

[0294] In addition, the vehicle management server 200a, the vehicle management server 200b, and the transaction management server 300 may be realized by a single server.

[0295] Furthermore, the service servers 400a and 400b and the station servers 500a, 500b, 500c and 500d may be integrated into a single server.

[0296] Furthermore, the service servers 400a and 400b, the station servers 500a, 500b, 500c and 500d, and the transaction management server 300 may be integrated into a single server.

[0297] Furthermore, vehicle management servers 200a and 200b, transaction management server 300, service servers 400a and 400b, and station servers 500a, 500b, 500c, and 500d may be collectively implemented as a single server.

[0298] In this way, the components of the devices included in the charging / discharging system 10a may be realized in any combination.

[0299] The station server 500 may also include a log analysis processing unit that executes anomaly analysis.

[0300] Furthermore, the vehicle management server 200 may perform an abnormality analysis using the charger / discharger log. In this case, for example, the vehicle management server 200 may receive the charger / discharger log by communicating with the service server 400 or the station server 500.

[0301] Furthermore, the service server 400 may perform an abnormality analysis using the vehicle log. In this case, for example, the service server 400 may receive the vehicle log by communicating with the vehicle management server 200.

[0302] [Representative Example] Figure 34 is a flowchart showing an information processing method according to an embodiment. For example, an information processing device includes a processor and a memory, and the processor uses the memory to perform the following processing. The information processing device is, for example, one of the vehicle management servers 200, 200a, and 200b.

[0303] First, the information processing device acquires charge / discharge information relating to charging / discharging between a predetermined charger / discharger and a predetermined mobile object from the predetermined mobile object (S10). The charger / discharger is, for example, one of charger / dischargers 600, 600a to 600h. The mobile object is, for example, one of vehicles 100, 100a to 100d. The charge / discharge information of the mobile object is, for example, the information shown in FIG. 11(b).

[0304] Next, the information processing device determines whether or not there is an abnormality based on the acquired charge / discharge information (S20). The information processing device determines, for example, whether or not the information included in the charge / discharge information indicates an abnormal value. Information such as a threshold value for determining an abnormal value is stored in advance, for example, in a memory provided in the information processing device.

[0305] Next, if the information processing device determines that there is an abnormality in step S20 (Yes in S20), it analyzes the abnormality based on at least one of a plurality of first logs managed by a predetermined management server, which contain information regarding the charging and discharging of a plurality of mobile bodies including a predetermined mobile body, and a plurality of second logs managed by a predetermined station server, which contain information regarding the charging and discharging of a plurality of chargers including a predetermined charger and discharger (S30).

[0306] The plurality of first logs are, for example, logs including charge / discharge information of a plurality of mobile objects. The plurality of second logs are, for example, logs including charge / discharge information of a plurality of chargers / dischargers. The charge / discharge information of the chargers / dischargers is, for example, the information shown in (d) of FIG. 11 .

[0307] The information processing device notifies the user of the cause of the identified abnormality, for example. For example, the information processing device displays, on a display or other display device, the charge / discharge information determined to have an abnormality, information indicating the mobile body that output the charge / discharge information, and information indicating the cause of the abnormality. Furthermore, for example, if the information processing device determines that there is no abnormality in step S20 (No in S20), it ends the processing and performs the processing again from step S10.

[0308] [Effects, etc.] Hereinafter, examples of techniques that can be obtained from the disclosure of this specification will be given, and effects, etc. that can be obtained from the exemplified techniques will be described.

[0309] Technique 1 is an information processing method that acquires charging / discharging information relating to charging / discharging between a specified charger / discharger and a specified mobile body from the specified mobile body (S10), determines whether or not there is an abnormality based on the charging / discharging information (S20), and if it is determined that there is an abnormality (Yes in S20), analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that contain information relating to charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that contain information relating to charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger (S30).

[0310] According to this, when some abnormality is detected in charging / discharging between a mobile object and a charger / discharger, the cause of the detected abnormality can be analyzed and identified using multiple logs that are charging / discharging information for at least one of multiple mobile objects and multiple chargers / dischargers. This makes it possible to identify the cause of an abnormality that cannot be determined solely from the charging / discharging information of the mobile object in which the abnormality is detected. Therefore, the information processing method according to Technology 1 makes it easier to identify the cause of the abnormality.

[0311] Technique 2 is an information processing method described in Technique 1, in which the determination of whether or not there is an abnormality further determines the content of the abnormality, and the analysis of the abnormality involves extracting multiple logs from at least one of the multiple first logs and the multiple second logs based on the content of the abnormality, and analyzing the abnormality based on the extracted multiple logs.

[0312] The information required for anomaly analysis varies depending on the nature of the anomaly. Therefore, logs required for anomaly analysis (specifically, for identifying the cause of the anomaly) are selected based on the nature of the anomaly. This reduces the amount of processing required to identify the cause of the anomaly.

[0313] Technology 3 is an information processing method according to Technology 1 or 2, in which the charge / discharge information includes location information indicating the location of a specified mobile object when charging / discharging with a specified charger / discharger is performed, and the information processing method further identifies a specified station server from among multiple station servers based on the location information.

[0314] According to this, it is possible to identify the station server that manages the charger / discharger that has performed charging / discharging with the mobile object, based on the information obtained from the mobile object.

[0315] Technique 4 is an information processing method according to Technique 2, further comprising determining an analysis server from among a plurality of servers to analyze the anomaly based on the content of the anomaly, and using the determined analysis server to analyze the anomaly.

[0316] Depending on the content of the abnormality, for example, it may be better to perform the abnormality analysis using the log of the charger / discharger, or it may be better to perform the abnormality analysis using the log of the mobile object. Furthermore, even if the abnormality analysis is performed by a server that acquires both the log of the charger / discharger and the log of the mobile object, if the abnormality analysis processing is concentrated on one server, it may take a long time to complete the abnormality analysis. Therefore, by identifying the cause of the abnormality using one of multiple servers that can perform abnormality analysis based on the content of the abnormality, it is possible to prevent the abnormality analysis processing from being concentrated on one server.

[0317] The analysis server may be a management server, a station server, or a server other than the management server and the station server.

[0318] Technique 5 is an information processing method according to any one of techniques 1 to 4, in which a first detection process is performed from the start of charging / discharging between a specified mobile body and a specified charger / discharger until the end of charging / discharging to determine whether or not there is an abnormality, and after charging / discharging between the specified mobile body and the specified charger / discharger is ended, a second detection process different from the first detection process is performed to determine whether or not there is an abnormality.

[0319] The first detection process is, for example, an anomaly detection process performed using a real-time anomaly detection rule, and the second detection process is, for example, an anomaly detection process performed using a termination anomaly detection rule.

[0320] If charging or discharging is in progress, the amount of power used for charging or discharging is important. On the other hand, if charging or discharging is completed, the amount of money involved in charging or discharging and whether the charging or discharging process was completed properly are important. In this way, the type of abnormality that needs to be determined differs between during charging or discharging and after the charging or discharging process is completed. Therefore, whether or not an abnormality exists is determined using, for example, information that is at least partially different among the multiple pieces of information included in the charging or discharging information during charging or discharging and after the charging or discharging process is completed. This allows abnormalities that need to be detected to be properly detected.

[0321] Technique 6 is an information processing method according to any one of techniques 1 to 5, in which, when it is determined that an abnormality exists, measures are taken to deal with the abnormality when it is determined that an abnormality exists, based on abnormality case information indicating the analysis results of past abnormalities.

[0322] This allows for quick action to be taken when it is determined that an abnormality has occurred, without the need for abnormality analysis.

[0323] Technique 7 is the information processing method according to any one of techniques 1 to 6, in which the anomaly analysis identifies whether the anomaly has been caused by an attack.

[0324] The attack here refers to, for example, a cyber attack on a mobile object or a charger / discharger. For example, if a cyber attack is carried out on charging a mobile object from a charger / discharger, and the actual charge amount is tampered with to an unauthorized charge amount, the management company that manages the charger / discharger may charge the user of the mobile object an unauthorized charging fee. Therefore, in analyzing the abnormality, it is determined whether the abnormality is caused by an attack. This makes it possible to find and deal with fraudulent processing, such as fraudulent charging fee billing.

[0325] Technology 8 is an information processing device that includes an acquisition unit that acquires charge / discharge information regarding charging / discharging between a specified charger / discharger and a specified mobile body from the specified mobile body, a determination unit that determines whether or not an abnormality exists based on the charge / discharge information, and an analysis unit that, if it determines that an abnormality exists, analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that include information regarding charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that include information regarding charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

[0326] The acquisition unit is, for example, the log collection processing unit 204. The determination unit is, for example, the abnormality detection unit 202. The analysis unit is, for example, the log analysis processing unit 205. The information processing device is, for example, one of the vehicle management servers 200, 200a to 200b.

[0327] This provides the same effects as the information processing method according to Technique 1.

[0328] The analysis unit may be realized by a processing unit provided in a station server (e.g., station servers 500, 500a to 500b), or by a processing unit provided in a server other than the management server and station server, such as service server 400 or transaction management server 300. In other words, the information processing device may be realized by a single computer or by multiple computers.

[0329] The ninth aspect of the present invention is a program for causing a computer to execute the information processing method according to any one of the first to seventh aspects.

[0330] This provides the same effect as the information processing method described in any one of Techniques 1 to 7.

[0331] (Other Embodiments) Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments.

[0332] In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. Also, the order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.

[0333] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0334] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.

[0335] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a system, a method, an integrated circuit, a computer program, and a recording medium.

[0336] In addition, this disclosure also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of each embodiment within the scope of this disclosure.

[0337] The present disclosure is useful for a device that analyzes abnormalities relating to charging and discharging between a charger and a vehicle.

[0338] 10, 10a Charging / discharging system 100, 100a to 100d Vehicle 101 Charging / discharging control unit 102, 602 Charging / discharging information acquisition unit 103 Charging / discharging port unit 104 Vehicle control unit 105, 201, 301, 401, 501, 603, 701 Communication unit 200, 200a to 200b Vehicle management server 202 Abnormality detection unit 203 Abnormality detection rule setting unit 204, 402, 502 Log collection processing unit 205, 403 Log analysis processing unit 206 Abnormality processing unit 207 Real-time abnormality detection rule storage unit 208 End-of-life abnormality detection rule storage unit 209 Vehicle log storage unit 210 Vehicle basic information storage unit 211 Abnormality case storage unit 300 Transaction management server 302 Abnormality analysis control unit 303 Abnormality response list storage unit 304 Analysis rule list storage unit 305 Vehicle management server list storage unit 306 Station server identification unit 307 Service server list storage unit 400, 400a to 400b Service server 404 Analysis target list creation unit 405, 503 Charger / discharger log storage unit 406 Station list storage unit 500, 500a to 500d Station server 504 Charger / discharger list storage unit 600, 600a to 600h Charger / discharger 601 Charging / discharging mechanism unit 604 Charger / discharger control unit 700a to 700c Power company server 702 Power management command unit

Claims

1. An information processing method comprising: acquiring charging / discharging information relating to charging / discharging between a specified charger / discharger and a specified mobile body from the specified mobile body; determining whether or not an abnormality exists based on the charging / discharging information; and, if it is determined that an abnormality exists, analyzing the abnormality based on at least one of a plurality of first logs managed by a specified management server, which contain information relating to charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server, which contain information relating to charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

2. The information processing method according to claim 1, wherein the determination of whether or not an abnormality exists further includes determining the content of the abnormality; and the analysis of the abnormality includes extracting multiple logs from at least one of the multiple first logs and the multiple second logs based on the content of the abnormality; and analyzing the abnormality based on the extracted multiple logs.

3. The information processing method according to claim 1, wherein the charging / discharging information includes location information indicating the location of the specified mobile object when charging / discharging with the specified charger / discharger is performed, and the information processing method further identifies the specified station server from among multiple station servers based on the location information.

4. The information processing method according to claim 2, further comprising: determining an analysis server from among a plurality of servers to analyze the abnormality based on the content of the abnormality; and analyzing the abnormality using the determined analysis server.

5. The information processing method of claim 1, wherein the determination of whether or not there is an abnormality is made by performing a first detection process from the start of charging / discharging between the specified mobile body and the specified charger / discharger until it is completed, and after charging / discharging between the specified mobile body and the specified charger / discharger is completed, the determination of whether or not there is an abnormality is made by a second detection process different from the first detection process.

6. The information processing method according to claim 1, wherein, when it is determined that the abnormality exists, measures are taken to deal with the abnormality when it is determined that the abnormality exists, based on abnormality case information indicating the analysis results of past abnormalities.

7. The information processing method according to claim 1, wherein the analysis of the anomaly includes determining whether the anomaly has been caused by an attack.

8. An information processing device comprising: an acquisition unit that acquires charge / discharge information regarding charging / discharging between a specified charger / discharger and a specified mobile body from the specified mobile body; a determination unit that determines whether or not an abnormality exists based on the charge / discharge information; and an analysis unit that, if it is determined that an abnormality exists, analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that contain information regarding charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that contain information regarding charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

9. A program for causing a computer to execute the information processing method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Vehicle power supply system anomaly detection method and device, terminal equipment and storage medium

    CN116620030A

  • Battery abnormality diagnostic device and abnormality diagnostic method

    JP2016217900A

  • Embroidery data creation device, embroidery device, liquid discharge device, and embroidery data creation method

    JP2024004343A

  • KR20200098101A