Information processing method, information processing device, and program

The information processing method and device address vulnerabilities in charging/discharging systems by analyzing logs to identify and manage abnormalities, enhancing security and power management.

WO2025220470A1PCT designated stage Publication Date: 2025-10-23PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/012696
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-16
Filing Date
2025-03-28
Publication Date
2025-10-23

AI Technical Summary

Technical Problem

Existing systems for charging and discharging mobile objects like electric vehicles are vulnerable to cyberattacks, which can lead to unauthorized charge amounts and require effective identification and handling of abnormalities to ensure proper power management.

Method used

An information processing method and device that analyze charging/discharging information using logs from specified chargers, management servers, and station servers to identify and analyze abnormalities, including potential cyberattacks.

Benefits of technology

Facilitates easier identification and handling of abnormalities, ensuring accurate power management and security in charging/discharging systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025012696_23102025_PF_FP_ABST
    Figure JP2025012696_23102025_PF_FP_ABST
Patent Text Reader

Abstract

An information processing method according to one embodiment of the present disclosure includes: acquiring, from a prescribed charging / discharging device, charge / discharge information relating to charging / discharging between the prescribed charging / discharging device and a prescribed moving body (S10); determining whether there is an abnormality on the basis of the charge / discharge information (S20); and, when it is determined that there is an abnormality (Yes in S20), analyzing the abnormality on the basis of at least one of a plurality of first logs that are managed by a prescribed management server and include information relating to charging / discharging for the plurality of moving bodies including a prescribed moving body, and a plurality of second logs that are managed by a prescribed station server and include information relating to charging / discharging for the plurality of charging / discharging devices including the prescribed charging / discharging device (S30).
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, information processing device, and program

[0001] The present disclosure relates to an information processing method, an information processing device, and a program.

[0002] 2. Description of the Related Art Conventionally, there is a device that detects abnormalities based on vehicle logs (see, for example, Patent Document 1).

[0003] Patent Document 1 discloses an anomaly detection server that is a server for dealing with abnormal frames transmitted over an in-vehicle network. The anomaly detection server disclosed in Patent Document 1 acquires information about frames received over the in-vehicle networks of one or more vehicles including a single vehicle, and calculates the degree of anomaly of the frame received over the in-vehicle network of the single vehicle based on the acquired information about the multiple frames and information about frames received over the in-vehicle network of the single vehicle that was acquired after the acquisition of the information about the multiple frames.

[0004] International Publication No. 2017 / 104112

[0005] Conventionally, there are systems in which mobile objects such as electric vehicles are charged and discharged using chargers and dischargers. Even in such systems, there is a possibility that abnormalities may occur due to cyberattacks and the like. For example, if a cyberattack is carried out during charging from a charger and discharger to a mobile object, and the actual charge amount is tampered with to an unauthorized charge amount, the management company that manages the charger and discharger may charge the user of the mobile object an unauthorized charging fee. Therefore, even in such systems, it is necessary to identify the cause of the abnormality and deal with the abnormality. Thus, in order to enable appropriate power management from the perspective of, for example, smart grids and vehicle-to-grid (V2G), it is desirable to be able to identify the cause of the abnormality in a system in which a charger and discharger charge and a mobile object are charged and discharged.

[0006] The present disclosure provides an information processing method and the like that can make it easier to identify the cause of an abnormality.

[0007] An information processing method according to one aspect of the present disclosure acquires charging / discharging information regarding charging / discharging between a specified charger / discharger and a specified mobile body from the specified charger / discharger, determines whether or not an abnormality exists based on the charging / discharging information, and if it is determined that an abnormality exists, analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server, which contain information regarding charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server, which contain information regarding charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

[0008] An information processing device according to one aspect of the present disclosure includes an acquisition unit that acquires charging / discharging information regarding charging / discharging between a specified charger / discharger and a specified mobile body from the specified charger / discharger, a determination unit that determines whether or not an abnormality exists based on the charging / discharging information, and, if it is determined that an abnormality exists, an analysis unit that analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that contain information regarding charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that contain information regarding charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the information processing method described above.

[0010] According to the present disclosure, it is possible to provide an information processing method that makes it easier to identify the cause of an abnormality.

[0011] FIG. 1A is a block diagram showing the configuration of a charging / discharging system according to an embodiment. FIG. 1B is a block diagram showing a specific example of the configuration of a charging / discharging system according to an embodiment. FIG. 2 is a block diagram showing the configuration of a charger / discharger according to an embodiment. FIG. 3 is a block diagram showing the configuration of a station server according to an embodiment. FIG. 4 is a block diagram showing the configuration of a service server according to an embodiment. FIG. 5 is a block diagram showing the configuration of a transaction management server according to an embodiment. FIG. 6 is a block diagram showing the configuration of a vehicle management server according to an embodiment. FIG. 7 is a block diagram showing the configuration of a vehicle according to an embodiment. FIG. 8 is a block diagram showing the configuration of a power company server according to an embodiment. FIG. 9 is a diagram showing an abnormality detection rule according to an embodiment. FIG. 10 is a diagram showing communication information according to an embodiment. FIG. 11 is a diagram showing a charger / discharger log according to an embodiment. FIG. 12 is a diagram showing a station list according to an embodiment. FIG. 13 is a diagram showing an abnormality case according to an embodiment. FIG. 14 is a diagram showing monitoring information according to an embodiment. FIG. 15 is a diagram showing an abnormality response list according to an embodiment. FIG. 16A is a diagram showing an analysis rule list according to an embodiment. FIG. 16B is a diagram showing the analysis rule list according to an embodiment. FIG. 17 is a diagram showing a vehicle management server list according to an embodiment. FIG. 18 is a diagram showing a service server list according to an embodiment. FIG. 19 is a diagram showing vehicle basic information according to an embodiment. FIG. 20 is a diagram showing a vehicle state log according to an embodiment. FIG. 21 is a diagram showing a vehicle charge / discharge log according to an embodiment. FIG. 22 is a sequence diagram showing a first example of a processing procedure executed by a charge / discharge system according to an embodiment. FIG. 23 is a sequence diagram showing a second example of a processing procedure executed by a charge / discharge system according to an embodiment. FIG. 24 is a flowchart showing a processing procedure executed by a station server according to an embodiment. FIG. 25 is a flowchart showing a processing procedure executed by an abnormality detection rule update unit according to an embodiment. FIG. 26 is a flowchart showing a processing procedure executed by a log collection processing unit according to an embodiment. FIG. 27 is a flowchart showing a processing procedure executed by an abnormality detection unit according to an embodiment. FIG. 28 is a diagram showing an example of an abnormality alert according to an embodiment.Fig. 29 is a flowchart showing a processing procedure executed by a log analysis processing unit according to an embodiment. Fig. 30 is a diagram showing an example of an analysis result output by an analysis server according to an embodiment. Fig. 31 is a diagram showing an example of an analysis report output by a transaction management server according to an embodiment. Fig. 32 is a flowchart showing a processing procedure executed by an abnormality processing unit according to an embodiment. Fig. 33 is a flowchart showing a processing procedure executed by a transaction management server according to an embodiment. Fig. 34 is a flowchart showing a specific example of an analysis report creation process according to an embodiment. Fig. 35 is a flowchart showing an information processing method according to an embodiment.

[0012] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0013] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not recited in the independent claims of the present disclosure are described as optional components. Furthermore, the drawings are not necessarily strict illustrations. In the drawings, substantially identical components are denoted by the same reference numerals, and redundant descriptions may be omitted or simplified.

[0014] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.

[0015] Furthermore, in this specification, when a statement is made in contrast to, for example, "greater than a threshold value" or "less than a threshold value," it means that the distinction is made on the basis of the threshold value, and may mean "greater than the threshold value" or "less than the threshold value," respectively.

[0016] Furthermore, the numerical values ​​such as the threshold values ​​in the present embodiment are merely examples, and other numerical values ​​may be used.

[0017] (Embodiment) [Configuration] FIG. 1A is a block diagram showing the configuration of a charge / discharge system 10 according to an embodiment.

[0018] The charging / discharging system 10 is a system in which a vehicle 100 and a charger / discharger 600 charge and discharge the vehicle 100. For example, the charger / discharger 600 is placed in a station (charging / discharging station) where charging and discharging are performed. The charger / discharger 600 charges (supplies power to) the vehicle 100 and accepts discharge from the vehicle 100.

[0019] In this specification, at least one of the charger / discharger 600 charging the vehicle 100 and the charger / discharger 600 receiving discharge from the vehicle 100 is also referred to as charging / discharging.

[0020] The charging / discharging system 10 includes a vehicle 100 , a charger / discharger 600 , a vehicle management server 200 , a station server 500 , a transaction management server 300 , and a service server 400 .

[0021] Vehicle 100 is a vehicle that uses electricity, such as an electric vehicle (EV). Note that vehicle 100 may be any moving body that uses electricity, such as a motorcycle or a mobile robot. Vehicle 100 is an example of a moving body.

[0022] Charger / discharger 600 is an EV charger / discharger that charges vehicle 100 and accepts discharge from vehicle 100. Charger / discharger 600 supplies electric power from, for example, a system power supply 800 (see FIG. 3 ), which is an external commercial power supply owned by an electric power company or the like, to vehicle 100, and supplies electric power from vehicle 100 to system power supply 800. In this way, transactions such as selling or purchasing electric power are carried out between a user who owns vehicle 100 and a management company that manages charger / discharger 600.

[0023] The charger / discharger 600 has, for example, a function for charging and a function for discharging, but it is sufficient if it has either function, and it does not have to have a function for charging or a function for discharging.

[0024] The vehicle management server 200 is a computer for managing the vehicle 100. For example, the vehicle management server 200 receives information relating to charging and discharging with the charger / discharger 600 from the vehicle 100 (also referred to as charge / discharge information of the vehicle 100) and stores the received charge / discharge information as a log (also referred to as a vehicle log) including information relating to charging and discharging of the vehicle 100 (charge / discharge information). For example, the vehicle management server 200 also receives and stores information relating to the vehicle 100, such as the manufacturer of the vehicle 100 (also referred to as basic vehicle information), from the vehicle 100. For example, when charging and discharging between the vehicle 100 and the charger / discharger 600 is performed, the vehicle management server 200 stores charge / discharge information relating to the charging and discharging as a vehicle charge / discharge log. The vehicle management server 200 is an example of a management server. For example, the vehicle management server 200 periodically communicates with the vehicle 100 to receive information indicating the vehicle's running state and other conditions (also referred to as vehicle condition information) from the vehicle 100. The vehicle status information includes, for example, information indicating the status of the vehicle 100, such as whether the vehicle 100 is running or whether the vehicle 100 is being charged. The vehicle status information also includes, for example, information indicating the remaining charge of the battery provided in the vehicle 100. The vehicle management server 200 stores the vehicle status information received from the vehicle 100 as a vehicle status log.

[0025] The vehicle charge / discharge log and the vehicle state log are collectively referred to as a vehicle log. In other words, the vehicle log includes the vehicle charge / discharge log and the vehicle state log.

[0026] Furthermore, for example, the timing at which the vehicle management server 200 receives the vehicle state information from the vehicle 100 may be determined arbitrarily and is not particularly limited.

[0027] The station server 500 is a computer for managing a station where the charger / discharger 600 is installed. The station server 500 receives, for example, information relating to charging and discharging with the vehicle 100 from the charger / discharger 600 (also referred to as charge / discharge information of the charger / discharger 600), and stores the received charge / discharge information as a log (also referred to as a charger / discharger log) including information relating to the charging and discharging of the charger / discharger 600 (charge / discharge information). The station server 500 also stores, for example, information relating to the charger / discharger 600, such as the charging / discharging capacity of the charger / discharger 600 and the type of the charger / discharger 600 (also referred to as charger / discharger basic information).

[0028] The transaction management server 300 is a computer for managing transactions of charging and discharging between the vehicle 100 and the charger / discharger 600 between a user who owns the vehicle 100 and a management company that manages the charger / discharger 600 .

[0029] Service server 400 is a computer for providing services relating to charging and discharging between vehicle 100 and charger / discharger 600 .

[0030] Each computer of the vehicle management server 200, the station server 500, the transaction management server 300, and the service server 400 is realized, for example, by a communication interface, a non-volatile memory in which a program is stored, a volatile memory which is a temporary storage area for executing the program, an input / output port for transmitting and receiving signals, and a processor for executing the program. The communication interface may have, for example, an antenna and a wireless communication circuit for enabling wireless communication, or a connector to which a communication line is connected for wired communication. The communication standard used for communication may be determined arbitrarily and is not particularly limited.

[0031] 1B is a block diagram showing a specific example of the configuration of the charge / discharge system 10a according to the embodiment. The charge / discharge system 10a is a specific example of the configuration of the charge / discharge system 10, which is assumed to be used in practice.

[0032] The charging / discharging system 10a includes vehicles 100a to 100d, chargers / dischargers 600a to 600h, vehicle management servers 200a to 200b, station servers 500a to 500d, a transaction management server 300, service servers 400a to 400b, and electric power company servers 700a to 700c.

[0033] Each of the vehicles 100a to 100d is a specific example of the vehicle 100. Each of the charger / discharger 600a to 600h is a specific example of the charger / discharger 600. Each of the vehicle management servers 200a to 200b is a specific example of the vehicle management server 200. Each of the service servers 400a to 400b is a specific example of the service server 400.

[0034] In this example, vehicle management server 200a manages vehicles 100a and 100b, and vehicle management server 200b manages vehicles 100c and 100d. Also, in this example, station server 500a manages chargers / dischargers 600a-600b, station server 500b manages chargers / dischargers 600c-600d, station server 500c manages chargers / dischargers 600e-600f, and station server 500d manages chargers / dischargers 600g-600h. Specifically, chargers / dischargers 600a-600b are located in the same station, and station server 500a manages charge / discharge information and charger / discharger basic information for chargers / dischargers 600a-600b. Also, chargers / dischargers 600c-600d are located in the same station, and station server 500b manages charge / discharge information and charger / discharger basic information for chargers / dischargers 600c-600d. Furthermore, chargers / dischargers 600e-600f are located in the same station, and station server 500c manages charge / discharge information and charger / discharger basic information for chargers / dischargers 600e-600f. Chargers / dischargers 600g-600h are located in the same station, and station server 500d manages charge / discharge information and charger / discharger basic information for chargers / dischargers 600g-600h. For example, chargers / dischargers 600a-600b, chargers / dischargers 600c-600d, chargers / dischargers 600e-600f, and chargers / dischargers 600g-600h are located in different stations. In this example, service server 400a provides services to station servers 500a-500b and manages information for station servers 500a-500b and chargers / dischargers 600a-600d managed by station servers 500a-500b. Furthermore, service server 400b provides services to station servers 500c to 500d and manages information on station servers 500c to 500d and chargers / dischargers 600a to 600d managed by station servers 500c to 500d. Service server 400a and service server 400b are, for example, servers owned by different service provider companies and provide different services.

[0035] The power company servers 700a to 700c are servers owned by power companies. For example, the power company servers 700a, 700b, and 700c are servers owned by different power companies.

[0036] For example, when charging / discharging is performed between the charger / discharger 600a and the vehicle 100a, the charging / discharging information of the charger / discharger 600a is transmitted to the station server 500a. The station server 500a stores the received charging / discharging information as a charger / discharger log. The charger / discharger log is an example of a second log. In this case, the charging / discharging information of the vehicle 100 is transmitted to the vehicle management server 200a. The vehicle management server 200a stores the received charging / discharging information as a vehicle log (specifically, a vehicle charging / discharging log). The vehicle log is an example of a first log.

[0037] Next, the specific configurations of vehicles 100a-100d, chargers / dischargers 600a-600h, vehicle management servers 200a-200b, station servers 500a-500d, transaction management server 300, service servers 400a-400b, and power company servers 700a-700c will be described. Note that the specific configurations of vehicle 100a, charger / discharger 600a, vehicle management server 200a, station server 500a, transaction management server 300, service server 400a, and power company server 700a will be described below. Vehicles 100a to 100d have substantially the same configuration, chargers / dischargers 600a to 600h have substantially the same configuration, vehicle management servers 200a to 200b have substantially the same configuration, station servers 500a to 500d have substantially the same configuration, service servers 400a to 400b have substantially the same configuration, and power company servers 700a to 700c have substantially the same configuration. In the following example, as a specific example of charging / discharging between a vehicle and a charger / discharger, an example in which charging is performed between charger / discharger 600a and vehicle 100a will be described.

[0038] FIG. 2 is a block diagram showing the configuration of a charger / discharger 600a according to an embodiment.

[0039] The charger / discharger 600a is a device that charges and discharges a vehicle (vehicle 100a in this example). The charger / discharger 600a supplies power to the vehicle 100a from a power grid 800 owned by an electric power company or the like that uses an electric power company server 700a, or supplies power from the vehicle 100a to the power grid. The charger / discharger 600a includes a charge / discharge mechanism unit 601, a charge / discharge information acquisition unit 602, a charge / discharger control unit 604, and a communication unit 603.

[0040] The charge / discharge mechanism 601 is a mechanism for charging / discharging the vehicle 100a. The charge / discharge mechanism 601 is realized by, for example, a power line for supplying power from the system power supply 800 to the vehicle 100a.

[0041] The charge / discharge information acquisition unit 602 is a processing unit that acquires charge / discharge information of the charger / discharger 600a. For example, when power is supplied from the system power supply 800 or the like to the vehicle 100a, the charge / discharge information acquisition unit 602 acquires, as charge / discharge information, information indicating the amount of power actually supplied from a power meter (not shown) or the like. In addition, for example, the charge / discharge information acquisition unit 602 communicates with the vehicle 100a to acquire basic vehicle information of the vehicle 100a.

[0042] The charger / discharger control unit 604 is a processing unit that performs overall control of the charger / discharger 600a. For example, the charger / discharger control unit 604 controls communication with the station server 500a and determines the power supply conditions for the amount of power to be supplied to the vehicle 100a based on control information. The charge / discharge mechanism unit 601 is controlled by the charger / discharger control unit 604 so that power is supplied to the vehicle 100a under the determined power supply conditions, for example.

[0043] The communication unit 603 is a communication interface for communicating with the vehicle 100a and the station server 500a. The communication unit 603 transmits charge / discharge information to the station server 500a, for example.

[0044] FIG. 3 is a block diagram showing the configuration of the station server 500a according to the embodiment.

[0045] The station server 500a manages the chargers / dischargers 600a and 600b arranged in the stations managed by the station server 500a. The station server 500a includes a communication unit 501, a log collection processing unit 502, a charger / discharger log storage unit 503, a charger / discharger list storage unit 504, an abnormality detection unit 505, an abnormality detection rule update unit 506, an abnormality detection rule storage unit 507, a power monitoring unit 508, and a power control unit 509.

[0046] The communication unit 501 is a communication interface for communicating with the service server 400a and the chargers / dischargers 600a and 600b. The communication unit 501 receives charge / discharge information from the chargers / dischargers 600a and 600b, for example.

[0047] The log collection processing unit 502 is a processing unit that collects (acquires) the charge and discharge information of the chargers and dischargers 600a and 600b received via the communication unit 501 as a charger and discharger log. Specifically, the log collection processing unit 502 stores the charge and discharge information of the chargers and dischargers 600a and 600b as a charger and discharger log in the charger and discharger log storage unit 503. The log collection processing unit 502 is an example of an acquisition unit.

[0048] The charger / discharger log storage unit 503 is a storage device that stores the charger / discharger log collected by the log collection processing unit 502 .

[0049] The charger / discharger list storage unit 504 is a storage device that stores a charger / discharger list. The charger / discharger list is a list of information related to the chargers / dischargers 600a and 600b managed by the station server 500a. The charger / discharger list storage unit 504 stores the charger / discharger list, which includes information related to the chargers / dischargers 600a and 600b, such as the identifiers of the chargers / dischargers 600a and 600b, the types of the chargers / dischargers 600a and 600b, and the performance of the chargers / dischargers 600a and 600b, such as the maximum charge amounts of the chargers / dischargers 600a and 600b.

[0050] The abnormality detection unit 505 is a processing unit that detects an abnormality based on information transmitted from the charger / discharger 600a and the charger / discharger 600b. For example, the abnormality detection unit 505 determines whether or not an abnormality has occurred based on the charge / discharge information of the charger / discharger 600a. The abnormality detection unit 505 is an example of a determination unit.

[0051] For example, when determining whether or not an abnormality exists using the charge / discharge information of the charger / discharger 600a, the abnormality detection unit 505 determines whether or not an abnormality exists by performing a predetermined detection process from the start to the end of charging / discharging between the vehicle 100a and the charger / discharger 600a. In the present embodiment, the abnormality detection unit 505 performs abnormality detection (i.e., determines whether or not an abnormality exists) in accordance with the detection rule stored in the abnormality detection rule storage unit 507. For example, when determining whether or not an abnormality exists using the charge / discharge information of the charger / discharger 600a, the abnormality detection unit 505 determines whether or not an abnormality exists by performing abnormality detection using the abnormality detection rule for each piece of acquired charge / discharge information based on the charge / discharge information of the charger / discharger 600a that is sequentially acquired from the start to the end of charging / discharge between the vehicle 100a and the charger / discharger 600a. Furthermore, for example, the abnormality detection unit 505 monitors the charging and discharging performed by the charger / discharger 600a and the charger / discharger 600b by determining whether the timing, duration, amount of power, and the like of the charging and discharging performed by the charger / discharger 600a and the charger / discharger 600b are appropriate based on the charging and discharging information received from each of the charger / discharger 600a and the charger / discharger 600b. The abnormality detection unit 505 determines whether the timing, duration, amount of power, and the like of the charging and discharging performed by the charger / discharger 600a and the charger / discharger 600b are appropriate by determining whether they satisfy predetermined conditions indicated in the abnormality detection rule. The predetermined conditions may be determined arbitrarily in advance and are not particularly limited.

[0052] When the anomaly detection unit 505 detects an anomaly, that is, when it determines that an anomaly exists, it creates (generates) information indicating that an anomaly exists (also referred to as an anomaly alert). For example, in determining whether or not an anomaly exists in the charge / discharge information of the charger / discharger 600a, the anomaly detection unit 505 further determines the content of the anomaly and creates an anomaly alert including information indicating the content of the anomaly. For example, the anomaly detection unit 505 transmits the anomaly alert to the transaction management server 300 via the service server 400a. Furthermore, for example, when it determines that an anomaly exists, the anomaly detection unit 505 further determines the content of the anomaly. Specific examples of the anomaly determination process performed by the anomaly detection unit 505 will be described later.

[0053] Furthermore, for example, the abnormality detection unit 505 determines whether or not an abnormality exists based on the charge / discharge information acquired from the charger / discharger 600a and one or more other charge / discharge information related to charging / discharging between at least one of the multiple chargers / dischargers managed by the station server 500a, excluding the charger / discharger 600a, and the vehicle. The one or more other charge / discharge information is, for example, the charge / discharge information of the charger / discharger 600b. Furthermore, for example, if the charge / discharge information acquired from the charger / discharger 600a is related to charging / discharging between the vehicle 100a and the charger / discharger 600a, the at least one vehicle is the vehicle 100a, but the at least one vehicle may be a vehicle other than the vehicle 100a.

[0054] The abnormality detection rule update unit 506 is a processing unit that sets (e.g., optimizes) the threshold value of the detection rule depending on the type of vehicle 100a on which charging / discharging is performed, the type of station where the charger / discharger 600a on which charging / discharging is performed is located, and the type of charger / discharger 600a on which charging / discharging is performed.

[0055] The anomaly detection rule storage unit 507 is a storage device that stores anomaly detection rules.

[0056] The power monitoring unit 508 is a processing unit that monitors charging and discharging performed in the chargers / dischargers 600a and 600b. For example, the power monitoring unit 508 uses a sensor that detects the amount of power exchanged between the system power supply 800 and the chargers / dischargers 600a and 600b to acquire information such as the timing, duration, and amount of power charged and discharged between the system power supply 800 and the chargers / dischargers 600a and 600b. The information acquired in this manner (also referred to as monitoring information) is used, for example, to detect power theft. The monitoring information may be stored as charging and discharging information (charger / discharger log) of the chargers / dischargers 600a and 600b.

[0057] The power control unit 509 is a processing unit that controls the power for charging and discharging performed by the chargers and dischargers 600 a and 600 b. For example, the power control unit 509 supplies the power supplied from the system power supply 800 to a battery or the like used by the chargers and dischargers 600 a and 600 b for charging and discharging, thereby charging the battery or outputting the power of the battery to the system power supply.

[0058] FIG. 4 is a block diagram showing the configuration of the service server 400a according to the embodiment.

[0059] Service server 400a classifies a plurality of charger / discharger logs and performs an abnormality analysis in accordance with the analysis rule received from transaction management server 300. Specifically, service server 400a extracts one or more charger / discharger logs used in the analysis rule from the plurality of charger / discharger logs, and performs an abnormality analysis using the extracted one or more charger / discharger logs. Service server 400a includes a communication unit 401, a log collection processing unit 402, a log analysis processing unit 403, an abnormality processing unit 404, a charger / discharger log storage unit 405, a station list storage unit 406, and an abnormality case storage unit 407.

[0060] The communication unit 401 is a communication interface for communicating with the transaction management server 300 and the station servers 500a and 500b. The communication unit 401 receives, for example, charge / discharge information of the chargers / dischargers 600a, 600b, 600c, and 600d from the station servers 500a and 500b.

[0061] The log collection processing unit 402 is a processing unit that collects (acquires) the charge / discharge information received via the communication unit 401 as a charger / discharger log. The log collection processing unit 402 stores the acquired charger / discharger log in the charger / discharger log storage unit 405.

[0062] The log analysis processing unit 403 is a processing unit that analyzes the charger / discharger log in accordance with an instruction from the transaction management server 300. For example, when an abnormality is detected by the abnormality detection unit 505, an abnormality alert is sent to the transaction management server 300. The transaction management server 300 determines an analysis server that will perform the abnormality analysis. When the transaction management server 300 determines the service server 400a as the analysis server, the transaction management server 300 sends an instruction to perform the abnormality analysis (specifically, information indicating an analysis rule) from the transaction management server 300 to the service server 400a. When the service server 400a (specifically, the log analysis processing unit 403) receives the instruction, the service server 400a performs the abnormality analysis using multiple charger / discharger logs stored in the charger / discharger log storage unit 405, including the charger / discharger log of the charger / discharger 600a and the charger / discharger logs of chargers / dischargers other than the charger / discharger 600a (e.g., chargers 600b, 600c, and 600d). As a result, the log analysis processor 403 analyzes the abnormality. For example, the log analysis processor 403 transmits the analysis result (specifically, information indicating the analysis result) to the transaction management server 300.

[0063] As described above, in the charging / discharging system 10a, when the abnormality detection unit 505 detects an abnormality using the charge / discharge information of the charger / discharger 600a, at least one of the vehicle management server and the service server determined as the analysis server performs an abnormality analysis (specifically, identifies the cause of the abnormality). Specifically, in the charging / discharging system 10a, when the abnormality detection unit 505 determines that there is an abnormality in the charge / discharge information of the charger / discharger 600a, the abnormality is analyzed based on at least one of a plurality of vehicle logs of a plurality of vehicles including the vehicle 100a, which are managed by the vehicle management server 200a, and a plurality of charger / discharger logs of the vehicle 100a and a plurality of chargers / dischargers, including the charger / discharger 600a that has charged or discharged, which are managed by the station server 500a.

[0064] Furthermore, for example, in anomaly analysis, the log analysis processors 203 and 403 identify whether the anomaly has been caused by an attack (specifically, a cyber attack).

[0065] The abnormality processing unit 404 is a processing unit that handles the abnormality (also referred to as abnormality handling processing) based on the analysis report received from the transaction management server 300. For example, when the transaction management server 300 acquires an analysis result from the service server 400a, the transaction management server 300 transmits an analysis report to the service server 400a, including information indicating the cause of the abnormality and information indicating how to handle the abnormality, such as whether or not there is a possibility of a cyber-attack, based on the acquired analysis result. Based on the received analysis report, the abnormality processing unit 404 handles the abnormality, such as stopping the charging and discharging of the charger / discharger 600a. For example, the abnormality processing unit 404 stops the charging and discharging of the charger / discharger 600a by transmitting information indicating an instruction to stop the charging and discharging of the charger / discharger 600a to the station server 500a based on the received analysis report.

[0066] Furthermore, for example, when the anomaly detection unit 505 determines that there is an anomaly, the anomaly processing unit 404 executes a countermeasure for the anomaly when it is determined that there is an anomaly, based on anomaly case information indicating a cause of the anomaly that was previously identified. For example, when the anomaly case information includes information indicating a cause of the anomaly that was identified when the same anomaly content as that of the anomaly that was determined to exist by the anomaly detection unit 505 was detected, the anomaly processing unit 404 executes the same countermeasure as the countermeasure for the anomaly included in the anomaly case information.

[0067] The charger / discharger log storage unit 405 is a storage device that stores the charger / discharger log collected by the log collection processing unit 402 .

[0068] Station list storage unit 406 is a storage device that stores a station list. The station list is information that lists station servers and chargers / dischargers managed by the station servers. Station list storage unit 406 stores a station list that includes, for example, information about station servers 500a and 500b and information about chargers / dischargers 600a to 600d.

[0069] The anomaly case storage unit 407 is a storage device that stores anomaly cases (anomaly case information) that indicate the causes of anomalies previously detected by the anomaly detection unit 505. The anomaly cases include, for example, the causes of anomalies previously detected by the anomaly detection unit 505 and information indicating the results of analysis of the causes of the anomalies. The analysis results include, for example, information indicating the presence or absence of aggression. For example, the content of the response to the anomaly differs depending on the presence or absence of aggression.

[0070] The service server may also include an analysis target list creation unit. The analysis target list creation unit is a processing unit that creates the analysis target list. The analysis target list is information that lists charger / discharger logs of chargers / dischargers that have the same conditions (e.g., the same type) as the charger / discharger indicated by the charger / discharger log that is the target of abnormality analysis, extracted from the station list. The analysis target list creation unit creates the analysis target list based on the station list as necessary. The analysis target list creation unit transmits the created analysis target list to, for example, the transaction management server. The log analysis processing unit 403 may perform abnormality analysis using the charger / discharger logs of the chargers / dischargers included in the acquired analysis target list.

[0071] FIG. 5 is a block diagram showing the configuration of the transaction management server 300 according to the embodiment.

[0072] Based on the abnormality alert received from service server 400a or 400b (specifically, the abnormality alert received from station servers 500a-500d via service server 400a or 400b), transaction management server 300 determines an analysis rule to be used for the abnormality analysis by selecting items (analysis items) necessary for the abnormality analysis, such as logs to be used for the analysis (vehicle log and charger / discharger log), and transmits the determined analysis rule (specifically, information indicating the analysis rule) to an analysis server that performs the abnormality analysis. Transaction management server 300 then requests the analysis server to perform the abnormality analysis. Transaction management server 300 includes a communication unit 301, an abnormality analysis control unit 302, an abnormality response list storage unit 303, an analysis rule list storage unit 304, a vehicle management server list storage unit 305, and a service server list storage unit 306.

[0073] The communication unit 301 is a communication interface for exchanging information such as information relating to abnormality analysis with the vehicle management servers 200a and 200b and the service servers 400a and 400b.

[0074] The abnormality analysis control unit 302 is a processing unit that transmits a command (in this embodiment, information indicating an analysis rule) to the analysis server to perform an abnormality analysis based on an abnormality alert received from the service server 400a or 400b. The abnormality analysis control unit 302 also selects one or more analysis servers to perform the abnormality analysis from among the multiple servers included in the charging / discharging system 10a. For example, the abnormality analysis control unit 302 determines an analysis server to perform the abnormality analysis from among the multiple servers based on the predetermined log classification conditions determined by the abnormality detection unit 505. As a result, the charging / discharging system 10a performs the abnormality analysis using the determined analysis server. For example, the abnormality analysis control unit 302 selects one or more servers as analysis servers from among the vehicle management server and service server indicated by the abnormality alert.

[0075] The analysis server may be any server, and the number of servers selected as the analysis server may be one or more.

[0076] The specific process for determining the analysis server will be described later.

[0077] The abnormality response list storage unit 303 is a storage device that stores an abnormality response list. The abnormality response list is information that lists the type of abnormality alert (the name of the abnormality alert) and the analysis rule used to analyze the abnormality indicated by the abnormality alert, in association with each other.

[0078] The analysis rule list storage unit 304 is a storage device that stores an analysis rule list. The analysis rule list is information that lists the specific contents of each of a plurality of analysis rules. The analysis rules include, for example, information indicating the requirements for a server to be selected as an analysis server, the classification conditions for logs (vehicle logs and charger / discharger logs) used by the analysis server to analyze an abnormality, the contents of the logs to be checked, the abnormality determination criteria, and whether or not there is aggressiveness. The abnormality analysis control unit 302 determines an analysis rule to be used for abnormality analysis of the contents of the abnormality included in the abnormality alert, for example, based on the contents of the abnormality included in the received abnormality alert and the abnormality response list, and determines an analysis server that will execute the determined analysis rule based on the analysis rule list. Furthermore, the abnormality analysis control unit 302 determines an analysis rule to be used for abnormality analysis of the abnormality content included in the received abnormality alert, for example, based on the content of the abnormality included in the received abnormality alert and the abnormality response list, extracts the specific content of the determined analysis rule (for example, classification conditions for logs (vehicle logs and charger / discharger logs) used by the analysis server when analyzing abnormalities, log check contents, abnormality judgment criteria, and whether or not there is aggressiveness, etc.) from the analysis rule list, and transmits the extracted information to the analysis server as the analysis rule to be used for abnormality analysis. The analysis rule list is an example of information that includes specified log classification conditions.

[0079] The vehicle management server list storage unit 305 is a storage device that stores a vehicle management server list. The vehicle management server list is information that lists vehicle management servers that have a trust relationship. In this embodiment, the vehicle management server list stored in the vehicle management server list storage unit 305 includes, for example, information (e.g., identifiers) indicating the vehicle management servers 200a and 200b and information indicating the communication addresses of the vehicle management servers 200a and 200b. The transaction management server 300, for example, obtains the communication address of the vehicle management server 200a from the vehicle management server list storage unit 305 and communicates with the vehicle management server 200a.

[0080] The service server list storage unit 306 is a storage device that stores a service server list. The service server list is information that lists service servers that have a trust relationship. In this embodiment, the service server list includes information (e.g., identifiers) that indicate the service servers 400a and 400b, and information that indicates the communication addresses of each of the service servers 400a and 400b. The transaction management server 300, for example, obtains the communication address of the service server 400a from the service server list storage unit 306 and communicates with the service server 400a.

[0081] FIG. 6 is a block diagram showing the configuration of the vehicle management server 200a according to the embodiment.

[0082] The vehicle management server 200a manages the vehicles 100a and 100b by storing vehicle state information, charge / discharge information, and basic vehicle information of the vehicles 100a and 100b. The vehicle management server 200a includes a communication unit 201, a log collection processing unit 202, a log analysis processing unit 203, a vehicle type identification unit 204, a vehicle state log storage unit 205, a vehicle charge / discharge log storage unit 206, and a vehicle basic information storage unit 207.

[0083] The communication unit 201 is a communication interface for communicating with the vehicles 100a and 100b and the transaction management server 300. For example, the communication unit 201 receives charge / discharge information from the vehicles 100a and 100b. In addition, for example, the communication unit 201 communicates with the transaction management server 300 to exchange information such as information for analyzing an abnormality detected by the abnormality detection unit 505 (e.g., information for identifying the cause of the abnormality, such as a vehicle log) and the results of the abnormality analysis (specifically, the results of identifying the cause of the abnormality).

[0084] The log collection processing unit 202 is a processing unit that collects (acquires) information transmitted from the vehicles 100a and 100b as a log. For example, the log collection processing unit 202 acquires charge / discharge information related to charging / discharging between the charger / discharger 600a and the vehicle 100a from the vehicle 100a. The log collection processing unit 202 stores the acquired charge / discharge information as a log (vehicle charge / discharge log) of the vehicle 100a in the vehicle charge / discharge log storage unit 206.

[0085] Furthermore, for example, the log collection processing unit 202 receives vehicle status information indicating the status of the vehicles 100a and 100b from the vehicles 100a and 100b, such as information indicating whether the vehicles 100a and 100b are charging and information indicating whether the vehicles 100a and 100b are running, and stores the information as a vehicle status log in the vehicle status log storage unit 205. Note that the charge / discharge information and vehicle status information may also include location information indicating the locations of the vehicles 100a and 100b. The vehicle management server 200a, for example, periodically communicates with the vehicles 100a and 100b to obtain this information even when the vehicles 100a and 100b are not charging.

[0086] The log analysis processing unit 203 is a processing unit that analyzes the vehicle log in accordance with instructions from the transaction management server 300. When the abnormality detection unit 505 detects an abnormality using the charge / discharge information of the charger / discharger 600a, that is, when it determines that an abnormality exists, an abnormality alert is transmitted from the station server 500a to the transaction management server 300 via the service server 400a. Upon receiving the abnormality alert, the transaction management server 300 determines (selects) a server (also referred to as an analysis server) that will identify the cause of the abnormality from among multiple servers, such as the vehicle management server 200a, the station server 500a, and the service server 400a, that are included in the charge / discharge system 10a. If the vehicle management server 200a is determined as the analysis server, the transaction management server 300 transmits an instruction to the vehicle management server 200a to perform an abnormality analysis process (specifically, a process for identifying the cause of the abnormality, also referred to simply as an abnormality analysis). Upon receiving the instruction, the vehicle management server 200a (specifically, the log analysis processing unit 203) performs an abnormality analysis using multiple vehicle logs, including the vehicle log of the vehicle 100a and the vehicle log of another vehicle (e.g., the vehicle 100b) other than the vehicle 100a, stored in the vehicle state log storage unit 205 and the vehicle charge / discharge log storage unit 206. As a result, the log analysis processing unit 203 performs the abnormality analysis, i.e., identifies the cause of the abnormality. The log analysis processing unit 203 transmits information indicating the analysis result to, for example, the transaction management server 300.

[0087] As described above, for example, log analysis processing units 203 and 403 extract multiple logs from two or more vehicle logs stored in vehicle state log storage unit 205 or vehicle charge / discharge log storage unit 206, or from two or more charger / discharger logs stored in charger / discharger log storage unit 405, based on predetermined log classification conditions, and perform abnormality analysis based on the extracted multiple logs. Log analysis processing units 203 and 403 are each an example of an analyzer. The predetermined log classification conditions are, for example, information included in analysis rules described below.

[0088] Furthermore, for example, in anomaly analysis, the log analysis processors 203 and 403 identify whether the anomaly has been caused by an attack (specifically, a cyber attack).

[0089] The vehicle type identification unit 204 is a processing unit that identifies the vehicle types of the vehicles 100a and 100b. For example, the vehicle type identification unit 204 identifies the vehicle types of the vehicles 100a and 100b based on basic vehicle information received from the vehicles 100a and 100b.

[0090] The vehicle state log storage unit 205 is a storage device that stores vehicle state information transmitted from the vehicles 100a and 100b.

[0091] The vehicle charge / discharge log storage unit 206 is a storage device that stores charge / discharge information transmitted from the vehicles 100a, 100b, etc. as a vehicle charge / discharge log.

[0092] The vehicle basic information storage unit 207 is a storage device that stores basic vehicle information (vehicle basic information) such as the vehicle models of the vehicles 100a and 100b.

[0093] FIG. 7 is a block diagram showing the configuration of a vehicle 100a according to an embodiment.

[0094] The vehicle 100a controls charging and discharging and the vehicle itself, and transmits vehicle status information, charging and discharging information, and basic vehicle information to a vehicle management server 200a that manages the vehicle. The vehicle management server 200a that manages the vehicle may be determined arbitrarily in advance and is not particularly limited. The vehicle management server 200a that manages the vehicle may be stored in advance in a storage device (not shown) that the vehicle 100a is equipped with. The vehicle 100a includes a charging and discharging control unit 101, a charging and discharging information acquisition unit 102, a charging and discharging port unit 103, a vehicle control unit 104, a communication unit 105, and a vehicle status acquisition unit 106.

[0095] The charge / discharge control unit 101 is a processing unit that controls charging and discharging between the vehicle 100a and the charger / discharger 600a. For example, in order to control charging and discharging of the vehicle 100a, the charge / discharge control unit 101 controls charging and discharging of a battery (not shown) provided in the vehicle 100a.

[0096] The charge / discharge information acquisition unit 102 is a processing unit that acquires charge / discharge information of the vehicle 100a. For example, when charging / discharging is performed between the vehicle 100a and the charger / discharger 600a, the charge / discharge information acquisition unit 102 acquires, as charge / discharge information, the amount of electric power actually charged / discharged.

[0097] The charge / discharge information may include an identifier indicating the charger / discharger 600a that charged / discharged the vehicle 100a, and location information indicating the location of the vehicle 100a when charging / discharging with the charger / discharger 600a was performed.

[0098] The charge / discharge port unit 103 is a port to which a power line or the like is connected in order to charge / discharge between the vehicle 100a and the charger / discharger 600a.

[0099] The vehicle control unit 104 is a processing unit that controls the running of the vehicle 100a.

[0100] The communication unit 105 is a communication interface for communicating with the vehicle management server 200a.

[0101] Vehicle 100a may communicate with charger / discharger 600a via communication unit 105, or via a power line connected to charge / discharge port unit 103. Vehicle 100a may also include a storage device that stores basic vehicle information about the vehicle. Vehicle 100a may also include a measuring device such as a GPS (Global Positioning System) for identifying the location of the vehicle.

[0102] FIG. 8 is a block diagram showing the configuration of the electric power company server 700a according to the embodiment.

[0103] The electric power company server 700a is a server used by a company that owns the system power supply 800 that is the supply source of power supplied by the charger / discharger 600a, etc. The electric power company server 700a includes a communication unit 701 and a power management command unit 702.

[0104] The communication unit 701 is a communication interface for communicating with the station server 500a.

[0105] The power management command unit 702 is a processing unit that transmits control information indicating control details related to charging and discharging to the station server 500a via the communication unit 701. The station server 500a, for example, transfers the control information to the charger / discharger 600a, and the charger / discharger 600a charges and discharges the vehicle 100a based on the control information.

[0106] Each of the above processing units is realized by, for example, a processor such as a CPU (Central Processing Unit) and a memory that stores a control program executed by the processor. The above storage device is realized by, for example, a storage device such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive).

[0107] The memories provided in these processing units may be realized by a common memory for each device, or may be realized by one or more independent memories for each device. Also, the processors provided in these processing units may be realized by a common processor for each processing unit for each device, or may be realized by one or more independent processors for each processing unit.

[0108] The communication interface may be realized by, for example, an antenna and a wireless communication circuit for wireless communication, or by a connector to which a communication line is connected. For example, PLC (Power Line Communication) may be used for communication between the devices. Each device may include a circuit or other configuration for performing PLC as a communication interface.

[0109] [Specific Examples of Various Information] Next, specific examples of various information such as charge / discharge information, vehicle log, charger / discharger log, abnormality response list, and analysis rule list will be described.

[0110] 9 is a diagram showing an anomaly detection rule according to the embodiment. For example, the anomaly detection rule storage unit 507 stores the information shown in FIG.

[0111] The anomaly detection rule includes, for example, information indicating the rule name, information indicating the check content, and information indicating the check operation.

[0112] The information indicating the rule name is information indicating the name of each check content that is individually assigned to each check content.

[0113] The information indicating the check content is information indicating the content of the determination of the presence or absence of an abnormality executed by the abnormality detection unit 505 .

[0114] The information indicating the check operation is information indicating the content of the process to be executed when the abnormality detection unit 505 determines that an abnormality exists.

[0115] For example, in the "power theft detection check," the abnormality detection unit 505 detects an abnormality based on the results of charging and discharging by all chargers and dischargers arranged at the station. Specifically, in the "power theft detection check," the abnormality detection unit 505 determines whether or not there is a difference of 20 kW or more between the total amount of power (supplied power amount) supplied from the grid power supply 800 to all chargers and dischargers (e.g., chargers 600a and 600b) arranged at a predetermined station (e.g., a station where chargers and dischargers 600a and 600b are arranged) and the total amount of power (charged power amount) used to charge vehicles by all chargers and dischargers (e.g., chargers and dischargers 600a and 600b) arranged at the predetermined station. The "power theft detection check" is a specific example of a determination process executed to determine whether power theft has occurred. For example, when the abnormality detection unit 505 receives charge / discharge information from the charger / discharger 600a while charging is being performed between the vehicle 100a and the charger / discharger 600a, the abnormality detection unit 505 makes the above determination based on the received charge / discharge information, the charger / discharger log stored in the charger / discharger log storage unit 503, and the monitoring information acquired by the power monitoring unit 508. For example, the abnormality detection unit 505 determines that an abnormality has occurred (specifically, that power theft has occurred) when there is a difference between the total amount of supplied power and the total amount of charged power that is equal to or greater than a predetermined value, such as 20 kW. Here, when the abnormality detection unit 505 determines that an abnormality has occurred, the abnormality detection unit 505 creates an abnormality alert indicating power theft, for example, and transmits the created abnormality alert to the transaction management server 300 via the service server 400a.

[0116] Furthermore, in the "excess charging power check," for example, the abnormality detection unit 505 determines whether the charging power value in charging performed by the charger / discharger 600a is equal to or greater than a set maximum charging power. Here, if the abnormality detection unit 505 determines that the charging power value is equal to or greater than the set maximum charging power value, it determines that an abnormality has occurred, creates an abnormality alert indicating that the charging power is excessive, and forcibly terminates the charging session (specifically, charging between the vehicle 100a and the charger / discharger 600a) (i.e., stops charging and discharging).

[0117] The threshold values ​​such as the maximum charge power value, the minimum charge power value, and the minimum discharge power value are set by, for example, the anomaly detection rule update unit 506. Note that these threshold values ​​may be arbitrarily determined in advance.

[0118] The abnormality detection unit 505 determines whether or not an abnormality exists in the charging / discharging information received from the charger / discharger 600a when charging / discharging is being performed between the vehicle 100a and the charger / discharger 600a, for example, by using all the check contents included in the abnormality detection rules.

[0119] 10 is a diagram showing communication information according to an embodiment of the present invention, specifically, showing a specific example of information communicated between devices.

[0120] 10A shows information transmitted from vehicle 100a to charger / discharger 600a. The information includes, for example, an identifier (also referred to as a vehicle number) for vehicle 100a, information indicating current and voltage values ​​(respective command values) required when charging or discharging vehicle 100a, and information indicating the remaining power of the battery provided in vehicle 100a.

[0121] 10(b) shows information transmitted from the vehicle 100a to the vehicle management server 200a. Specifically, the information shown in FIG. 10(b) is charge / discharge information for the vehicle 100a. The charge / discharge information for the vehicle 100a includes, for example, information indicating the date and time when charging / discharging was performed, information indicating the vehicle number, location information indicating the location of the vehicle 100a, information transmitted from the vehicle 100a to the charger / discharger 600a, and information transmitted from the charger / discharger 600a to the vehicle 100a.

[0122] 10(c) shows information transmitted from the charger / discharger 600a to the vehicle 100a. The information includes, for example, an identifier (also referred to as a charger / discharger number) identifying the charger / discharger 600a and information indicating the current and voltage values ​​of the charge / discharge performed by the charger / discharger 600a when charging / discharging the vehicle 100a.

[0123] 10(d) shows information transmitted from charger / discharger 600a to station server 500a. Specifically, the information shown in FIG. 10(d) is charge / discharge information of charger / discharger 600a. The charge / discharge information of charger / discharger 600a includes, for example, information indicating the date and time when charge / discharge was performed, information indicating the charger / discharger number, information transmitted from charger / discharger 600a to vehicle 100a, and information indicating the remaining power of the battery provided in vehicle 100a.

[0124] 11 is a diagram showing a charger / discharger log according to an embodiment. In the charger / discharger log storage unit 405, for example, the information shown in FIG.

[0125] The charger / discharger log includes, for example, information indicating the charger / discharger number of charger / discharger 600a to 600d that performed charging / discharging, information indicating the station server numbers of station servers 500a and 500b that manage charger / discharger 600a to 600d, information indicating the date and time when the charging / discharging was performed, information indicating the charging / discharging power during the charging / discharging, information indicating the remaining power of the battery equipped in the vehicle where the charging / discharging was performed, information indicating the charging / discharging rate during the charging / discharging (the charging rate in the example shown in Figure 11), and information indicating whether the charging / discharging was performed normally.

[0126] The charger / discharger log storage unit 503 stores, as a charger / discharger log, information relating to the charger / discharger 600a, for example, from among the information included in the charger / discharger log shown in FIG.

[0127] 12 is a diagram showing a station list according to the embodiment. For example, the station list storage unit 406 stores the information shown in FIG.

[0128] The station list is information relating to the station servers 500a and 500b.

[0129] The station list includes, for example, identifiers (also referred to as station server numbers) indicating station servers 500a and 500b, location information indicating the locations of stations where chargers / dischargers 600a to 600d managed by station servers 500a and 500b are located, identifiers (also referred to as power company server numbers) indicating power company servers 700a and 700b used by power companies that exchange power with chargers / dischargers 600a to 600d managed by station servers 500a and 500b, charger / discharger numbers of chargers / dischargers 600a to 600d, information indicating the types of chargers / dischargers 600a to 600d, protocols used by chargers / dischargers 600a to 600d for charging and discharging, information indicating whether chargers / dischargers 600a to 600d are capable of discharging, information indicating the maximum charge amounts of chargers / dischargers 600a to 600d, and information indicating the maximum current amounts of chargers / dischargers 600a to 600d.

[0130] 12, the location information indicating the location of the station server 500a is indicated by a predetermined number corresponding to the location, such as "45A." The location indicated by the location information may be any predetermined number corresponding to the location, or may be GPS coordinates (values ​​indicating latitude and longitude), and may be determined arbitrarily.

[0131] 13 is a diagram showing abnormality cases according to an embodiment. The abnormality case storage unit 407 stores, for example, information indicating the abnormality cases shown in FIG. 13. Specifically, the abnormality case storage unit 407 stores received analysis reports, which will be described later, as abnormality cases.

[0132] The abnormality case includes, for example, information included in the abnormality alert and information indicating the results of the analysis performed in response to the abnormality alert. In the example shown in FIG. 13 , the abnormality case includes information indicating the abnormality alert created when the abnormality detection unit 505 determines that an abnormality exists ("abnormal alert number" in FIG. 13 ), information indicating the results of the abnormality analysis performed when the abnormality alert was created ("cause of abnormality" in FIG. 13 ), information indicating the date and time when the abnormality analysis was performed, information indicating the value determined to be abnormal by the abnormality analysis ("abnormal value" in FIG. 13 ), information indicating the charge / discharge threshold value used in the abnormality analysis ("appropriate value" in FIG. 13 ), and information regarding the vehicle and charger / discharger that performed the charge / discharge that resulted in the creation of the abnormality alert (e.g., the type of vehicle, location information, identifier of the charger / discharger, identifier of the station server managing the charger / discharger, and service server managing the station server). Note that the abnormality case may also include information indicating whether the abnormality may have been caused by a cyberattack or the like (i.e., information indicating the presence or absence of an attack).

[0133] Here, for example, even if the abnormality detection unit 505 determines that an abnormality exists, the content of the countermeasure executed by the abnormality processing unit 404 differs depending on whether or not aggression is present. For example, the abnormality processing unit 404 executes a first process when aggression is present, and executes a second process different from the first process when aggression is not present. For example, in the first process, an abnormality alert is generated and charging / discharging between the vehicle and the charger / discharger that performed the charging / discharging that resulted in the generation of the abnormality alert is stopped. On the other hand, in the second process, for example, an abnormality alert is generated but charging / discharging between the vehicle and the charger / discharger is not stopped.

[0134] 14 is a diagram illustrating monitoring information according to an embodiment. Specifically, FIG. 14 illustrates an example of information acquired by the power monitoring unit 508, for example, information stored in the charger / discharger log storage unit 503.

[0135] The monitoring information includes, for example, information indicating the amount of received power and information indicating the amount of supplied power.

[0136] The information indicating the amount of received power is information indicating the total amount of power supplied from system power supply 800 to charger / dischargers 600a and 600b. The amount of received power is calculated by a power meter (for example, a power system for monitoring the total amount) installed in the station where charger / dischargers 600a and 600b are located. The power meter is, for example, included in power monitoring unit 508 and monitors the amount of power supplied from power control unit 509.

[0137] The information indicating the amount of power supply is information indicating the total amount of power that chargers / dischargers 600a and 600b charge (in other words, output) to vehicles 100a and 100b, etc. For example, the amount of power supply is calculated from the charger / discharger logs of chargers / dischargers 600a and 600b.

[0138] The abnormality detection unit 505 determines that power theft has occurred if the difference between the amount of power received and the amount of power supplied is greater than a predetermined threshold. Note that each charger / discharger (e.g., charger / discharger 600a and 600b) monitors the amount of power charged and discharged by each charger / discharger itself, and the monitoring results are transmitted from each charger / discharger as charge / discharge information.

[0139] 15 is a diagram showing an abnormality response list according to an embodiment of the present invention, in which the information shown in FIG.

[0140] The anomaly response list is information indicating what kind of anomaly analysis will be performed for the generated anomaly alert.

[0141] The anomaly response list includes information indicating anomaly alert names and information indicating analysis rule names.

[0142] The information indicating the abnormality alert name is information indicating the name of the rule used to determine the presence or absence of an abnormality that led to the creation of the abnormality alert. In this example, the abnormality alert name indicates the content of the abnormality.

[0143] The information indicating the analysis rule name is information indicating the name of the analysis rule used in anomaly analysis. In this example, the analysis rule name corresponds to the cause of the anomaly. For example, when an analysis rule with a certain analysis rule name is used in anomaly analysis and the conditions indicated in the analysis rule are satisfied, the content indicated by the certain analysis rule name is identified as the cause of the anomaly.

[0144] The information indicating the anomaly alert name and the information indicating the analysis rule are linked and stored as an anomaly response list.

[0145] For example, if an anomaly alert with the name "power theft" is created, an anomaly analysis is performed according to the analysis rule for "power theft detection anomaly." If the result of the anomaly analysis satisfies the conditions specified in the analysis rule (specifically, the "anomaly determination criteria" shown in FIG. 16B), the cause of the anomaly is identified as "charging detection anomaly."

[0146] Furthermore, for example, when an abnormality alert with an abnormality alert name of "excess charging power" is created, an abnormality analysis is performed according to the analysis rule for "excess charging power abnormality." Here, if the result of the abnormality analysis satisfies the conditions indicated in the analysis rule (specifically, the "abnormality determination criteria" shown in FIG. 16B ), the cause of the abnormality is identified as "excess charging power abnormality."

[0147] 16A and 16B are diagrams showing an analysis rule list according to an embodiment of the present invention. The analysis rule list storage unit 304 stores, for example, the information shown in FIGS. 16A and 16B as an analysis rule list.

[0148] The analysis rule list is information indicating the specific contents of the analysis rules shown in FIG.

[0149] The analysis rule list includes information indicating the conditions (analysis server requirements) required of the analysis server that executes the analysis rules, information indicating the classification conditions for the logs (vehicle logs and / or charger / discharger logs) used in abnormality analysis, information indicating the check contents for abnormality analysis, and information indicating the abnormality determination criteria.

[0150] Note that, for example, an analysis server for an abnormality alert may be selected as the analysis server. For example, in FIGS. 16A and 16B, the analysis server requirements may be indicated as "vehicle management server for an abnormality alert." "Vehicle management server for an abnormality alert" indicates that the analysis server must be a server identified by an identifier, such as a vehicle management server number, included in the abnormality alert. For example, "service server for an abnormality alert" indicates that the service server identified by the service server number included in the abnormality alert is selected as the analysis server. Furthermore, for example, when the "analysis server requirement" is "service server," this indicates that either the service server 400a or the service server 400b included in the charging / discharging system 10a may be selected as the analysis server. For example, a server that can collect logs that satisfy the log classification conditions shown in FIG. 16A may be selected as the analysis server.

[0151] The analysis server extracts (classifies) stored logs (vehicle logs or charger / discharger logs) based on the log classification conditions, and performs an abnormality analysis on the extracted logs.

[0152] In the anomaly analysis, logs are judged (checked) based on the "check contents" shown in Fig. 16B, and it is determined whether the number of logs that satisfy the check contents meets the "anomaly judgment criteria." For example, in the anomaly analysis, if the "anomaly judgment criteria" are met, it is determined that the cause of the anomaly is the anomaly named in the "analysis rule name."

[0153] The analysis rule list may include information indicating whether or not there is aggression. The information indicating whether or not there is aggression is information indicating whether or not there is a possibility that the abnormality has been caused by an attack.

[0154] For example, when the analysis rule for "power theft detection anomaly" is executed, the vehicle management server indicated in the anomaly alert is selected as the analysis server. In this case, for example, the vehicle management server indicated in the anomaly alert extracts one or more vehicle logs (vehicle charge / discharge logs in the condition shown in FIG. 16A ) that satisfy the "log classification condition" from among the multiple vehicle logs stored. In this case, for example, the vehicle management server indicated in the anomaly alert determines whether the one or more extracted vehicle logs satisfy the condition "the charging power value that is the same as the abnormal value exceeds by 5 kW or more." If the vehicle management server indicated in the anomaly alert determines that this condition is satisfied, it determines that the cause of the anomaly is "power theft detection anomaly" and transmits the determination result to the transaction management server 300 as the analysis result.

[0155] In the anomaly analysis, only the normal logs may be used out of the "normal / abnormal" logs shown in FIG. 11 and FIG. 21 described later.

[0156] Furthermore, the presence or absence of aggressiveness corresponding to the analysis rule may be arbitrarily determined in advance.

[0157] For example, in the case of "power theft detection abnormality," when an abnormality is determined by the "power theft detection check," an abnormality analysis is performed based on the vehicle charge / discharge log stored in the vehicle management server that manages the charger / discharger and the vehicle that has been charged / discharged. This abnormality analysis assumes, for example, that the charger / discharger log has been tampered with.

[0158] In the "power theft detection anomaly," for example, when the "power theft detection check" determines that an anomaly exists, the analysis server analyzes whether all vehicles managed by the analysis server are being charged correctly using the vehicle charge / discharge logs. In this way, for example, when determining whether an anomaly exists, the anomaly detection unit 505 determines whether power theft has occurred in the charging / discharging between the charger / discharger 600a and the vehicle 100a. Furthermore, for example, when the anomaly detection unit 505 determines that power theft has occurred, the analysis server analyzes the anomaly based on multiple vehicle logs (specifically, multiple vehicle charge / discharge logs).

[0159] For example, in the case of an "excessive charging power anomaly," when an abnormality is determined by the "excessive charging power check," an anomaly analysis is performed based on the vehicle charge / discharge log stored in the vehicle management server that manages the charger / discharger and the vehicle that performed the charging / discharging. In this anomaly analysis, the analysis server checks whether the vehicle charge / discharge log contains an example of an abnormal termination when a high voltage (e.g., a voltage above a predetermined threshold) was applied during charging / discharging for a vehicle of the same model as the charger / discharger that output the charging / discharging information determined to have an abnormality and the vehicle that performed the charging / discharging. In other words, in the case of an "excessive charging power anomaly," it is checked whether an abnormality occurred during a similar charging operation when the charging power was high. For example, in an anomaly analysis using the analysis rules for an "excessive charging power anomaly," if charging continues (i.e., the charging session has not ended) despite an example of an abnormal termination under such conditions being found in the vehicle charge / discharge log, the cause of the anomaly is determined to be an "excessive charging power anomaly."

[0160] Furthermore, for example, in the case of an "excessive discharge power abnormality," when an abnormality is determined by the "excessive discharge power check," an abnormality analysis is performed based on the vehicle charge / discharge log stored in the vehicle management server that manages the charger / discharger and the vehicle that performed the charge / discharge. In this abnormality analysis, for example, the vehicle charge / discharge log of the vehicle that performed the charge / discharge is compared with other vehicle charge / discharge logs, and if the discharge amount is greater than or equal to a predetermined threshold, it is deemed to be an "excessive discharge power abnormality," and it is determined that there is some kind of abnormality in the vehicle that performed the charge / discharge.

[0161] Furthermore, for example, in the case of an "overcharged amount abnormality," when an abnormality is determined by the "charged amount check," an abnormality analysis is performed based on the vehicle status log stored in the vehicle management server that manages the charger / discharger and the vehicle that performed the charge / discharge. In this abnormality analysis, the analysis server checks whether power is being consumed correctly, for example, when the charge amount is high. Specifically, in the case of an "overcharged amount abnormality," an analysis is performed to determine whether the vehicle is correctly consuming the amount of power charged to the vehicle. In other words, this abnormality analysis determines whether power has suddenly decreased due to data tampering or the like. For example, in this abnormality analysis, if the charge amount is equal to or greater than a predetermined threshold, based on the vehicle status log of the vehicle that performed the charge / discharge, the cause of the abnormality is determined to be an "overcharged amount abnormality." In this way, for example, multiple vehicle logs include vehicle status information indicating the status of multiple vehicles. In this example, the vehicle status information is stored as a vehicle status log. In addition, for example, the analysis server analyzes the abnormality based on the vehicle status information (vehicle status log). Specifically, the analysis server extracts a vehicle log from a plurality of vehicle logs based on the vehicle state information, and performs an abnormality analysis based on the extracted vehicle log.

[0162] Furthermore, for example, in the case of an "excessive discharge amount abnormality," when an abnormality is determined by the "discharge amount check," an abnormality analysis is performed based on the charger / discharger log stored in the service server that manages the vehicle and the charger / discharger that performed the charge / discharge. In this abnormality analysis, the analysis server checks, for example, the total value of the discharge amount performed by the charger / discharger. For example, in this abnormality analysis, if the total value is greater than the total value of the charger / discharge amount performed in the past, the analysis server determines that the cause of the abnormality is an "excessive discharge amount abnormality." In this way, for example, in the case of an "excessive discharge amount abnormality," it is checked whether there have been any cases in which an abnormal amount of discharge has occurred at stations managed by the same electric power company.

[0163] If the abnormality analysis determines that there is some kind of abnormality, each charger / discharger stops the charging session (emergency stop) while charging the vehicle.

[0164] 17 is a diagram showing a vehicle management server list according to an embodiment of the present invention, the vehicle management server list storage unit 305 stores, for example, the information shown in FIG.

[0165] The vehicle management server list is information used by the transaction management server 300 to communicate with the vehicle management servers 200a and 200b.

[0166] The vehicle management server list includes, for example, identifiers of vehicle management servers 200a and 200b (also called vehicle management server numbers), communication addresses of vehicle management servers 200a and 200b, information indicating the business type of the company using vehicle management servers 200a and 200b, and information indicating the manufacturers of vehicles 100a to 100d managed by vehicle management servers 200a and 200b.

[0167] 17, for example, a vehicle management server 200b whose "business type" is "sharing" may manage vehicles from multiple manufacturers. Therefore, a vehicle management server 200b whose "business type" is "sharing" may be more likely to be able to analyze anomalies.

[0168] 18 is a diagram showing a service server list according to an embodiment of the present invention, in which the information shown in FIG.

[0169] The service server list is information used by the transaction management server 300 to communicate with the service servers 400a and 400b.

[0170] The service server list includes, for example, identifiers (also called service server numbers) indicating the service servers 400a and 400b, the communication addresses of the service servers 400a and 400b, the charge rates and discharge rates of the chargers / dischargers 600a to 600h managed by the station servers 500a to 500d managed by the service servers 400a and 400b, and information indicating the manufacturers of the chargers / dischargers 600a to 600h.

[0171] 19 is a diagram showing basic vehicle information according to an embodiment of the present invention. The basic vehicle information storage unit 207 stores, for example, the basic vehicle information shown in FIG.

[0172] The vehicle basic information shown in FIG. 19 is information acquired from the vehicles 100a and 100b, for example.

[0173] The vehicle basic information is information relating to the vehicles 100a and 100b. The vehicle basic information includes, for example, information indicating the vehicle number, information indicating the user name of the user who owns the vehicle 100a or 100b, information indicating the type (model) of the vehicle 100a or 100b, information indicating the version of software used by the vehicles 100a or 100b, and information indicating the fully charged capacity of the batteries provided in the vehicles 100a and 100b.

[0174] 20 is a diagram showing a vehicle state log according to the embodiment. The vehicle state log storage unit 205 stores, for example, the information shown in FIG.

[0175] The vehicle state log shown in FIG. 20 is, for example, information acquired as vehicle state information from the vehicles 100a and 100b.

[0176] The vehicle status log includes, for example, information indicating the vehicle number, information indicating the date and time when the vehicle status information was received (specifically, information indicating the date and time when vehicles 100a and 100b entered a state such as the vehicle state shown in Figure 20), information indicating the vehicle status, information indicating the positions of vehicles 100a and 100b, information indicating changes in the amount of power in the batteries equipped in vehicles 100a and 100b, and information indicating the remaining charge of the batteries equipped in vehicles 100a and 100b.

[0177] The basic vehicle information and vehicle state information may be acquired from the vehicles 100a and 100b at any time.

[0178] 21 is a diagram showing a vehicle charge / discharge log according to the embodiment. The vehicle charge / discharge log storage unit 206 stores, for example, the information shown in FIG.

[0179] The vehicle charge / discharge log includes, for example, charge / discharge information received from the vehicles 100a and 100b, information indicating the date and time when the charge / discharge information was received, information indicating the status of the vehicles 100a and 100b (for example, information indicating whether the vehicles 100a and 100b were being charged when the charge / discharge information was transmitted), information indicating the charger / discharger numbers of the chargers / dischargers that charged / discharged the vehicles 100a and 100b, information indicating the charge / discharge rates, information indicating the remaining capacity of the batteries provided in the vehicles 100a and 100b, and information indicating whether charging is being performed normally ("Normal / Abnormal" shown in FIG. 21). The "Normal / Abnormal" is, for example, information indicating whether the charging session (specifically, charging between the vehicle and the charger / discharger) is being performed normally. For example, if a power line used to charge the vehicle 100a and the charger / discharger 600a is unintentionally disconnected during charging between the vehicle 100a and the charger / discharger 600a, preventing proper charging (i.e., if charging / discharging ends abnormally), it is determined to be an abnormality. This determination may be made by the vehicle 100a and the charger / discharger 600a and included in the charge / discharge information of the vehicle 100a and the charger / discharger 600a, or may be made by the vehicle management server 200a and the station server 500a. For example, if the vehicle management server 200a and the station server 500a do not receive information from the vehicle 100a and the charger / discharger 600a indicating that the charging session has ended abnormally until charging is completed, the vehicle management server 200a and the station server 500a determine that the "normal / abnormal" status of the logs (vehicle log and charger / discharger log) corresponding to all charge / discharge information received during this charging is normal and link the information to the logs. For example, when the vehicle 100a and the charger / discharger 600a are charging, the "normal / abnormal" information (flag) may not be assigned.

[0180] The information indicating the charge / discharge rate may be transmitted from the vehicles 100a and 100b, or may be calculated based on the received charge / discharge information and past vehicle logs, etc. The station server number, the service server number, and the charge rate are received from the service server 400a via the transaction management server 300, for example, and are stored as a vehicle log in association with the charge / discharge information.

[0181] [Processing Procedure] Next, the processing procedure in the charging / discharging system 10a will be described. Note that in Figures 22 to 34, the processing of the vehicle 100a, the vehicle management server 200a, the transaction management server 300, the service server 400a, the station server 500a, and the charger / discharger 600a when charging of the vehicle 100a is performed between the vehicle 100a and the charger / discharger 600a will be described.

[0182] 22 is a sequence diagram illustrating a first example of a processing procedure executed by the charging / discharging system 10a according to the embodiment. Specifically, FIG. 22 illustrates a processing procedure executed by the charging / discharging system 10a when it is determined that no abnormality exists.

[0183] First, vehicle 100a transmits information indicating an instruction to start charging to charger / discharger 600a (S101).

[0184] Next, when charger / discharger 600a receives information indicating an instruction to start charging, charger / discharger 600a starts charging (power supply) to vehicle 100a (S102).

[0185] When charging is started, the vehicle 100a transmits charge / discharge information relating to charging to the vehicle management server 200a (S103).

[0186] The vehicle management server 200a collects and stores the received charge / discharge information as a vehicle log (specifically, a vehicle charge / discharge log) (S104).

[0187] When charging starts, the charger / discharger 600a transmits charge / discharge information relating to charging to the station server 500a (S105).

[0188] The station server 500a collects and stores the received charge / discharge information as a charger / discharger log, and transfers it to the service server 400a (S106).

[0189] The service server 400a collects and stores the received charge / discharge information as a charger / discharger log (S107).

[0190] Next, the station server 500a performs anomaly detection using the received charge / discharge information and the anomaly detection rule (S108). Specifically, the station server 500a determines whether or not an anomaly exists based on the received charge / discharge information. That is, the station server 500a performs anomaly detection to determine whether or not an anomaly exists in the received charge / discharge information.

[0191] If the station server 500a determines that there is no abnormality (S109), charging continues and steps S103 to S107 are repeated.

[0192] When the above process is repeatedly executed and a predetermined amount of power is charged, vehicle 100a transmits information indicating an instruction to end charging to charger / discharger 600a in order to end charging (S110).

[0193] When the charger / discharger 600a receives the information indicating the instruction to end charging, the charger / discharger 600a ends charging of the vehicle 100a (S111).

[0194] Furthermore, charger / discharger 600a transmits a completion report (completion report information) indicating that charging has been completed to station server 500a. Station server 500a transfers the received completion report to service server 400a.

[0195] When service server 400a receives the completion report, it calculates the fee for charging, for example, based on the charger / discharger log, and sends a fee report (fee report information) indicating the calculated fee to transaction management server 300. Transaction management server 300 forwards the received fee report to vehicle management server 200a. For example, vehicle management server 200a notifies the user of vehicle 100a of the fee, and the user pays the notified fee to the company that manages station server 500a.

[0196] 23 is a sequence diagram illustrating a second example of the processing procedure executed by the charging / discharging system 10a according to the embodiment. Specifically, FIG. 23 illustrates the processing procedure executed by the charging / discharging system 10a when it is determined that an abnormality has occurred.

[0197] If it is determined in the process of step S109 shown in FIG. 22 that there is no abnormality, for example, the processes of steps S101 to S108 shown in FIG. 22 are repeatedly executed.

[0198] Here, for example, it is assumed that information indicating an instruction to charge more than 70 kW in total is transmitted from vehicle 100a to charger / discharger 600a (S201). In other words, it is assumed that some abnormal request is transmitted from vehicle 100a to charger / discharger 600a.

[0199] In this case as well, the vehicle 100a transmits the charge / discharge information to the vehicle management server 200a (S202), and the vehicle management server 200a collects and stores the received charge / discharge information as a vehicle charge / discharge log (S203).

[0200] The charger / discharger 600a transmits the charge / discharge information to the station server 500a (S204), and the station server 500a collects and stores the received charge / discharge information as a charger / discharger log and transfers it to the service server 400a (S205). The service server 400a collects and stores the received charge / discharge information as a charger / discharger log (S206).

[0201] Furthermore, the station server 500a performs abnormality detection based on the received charge / discharge information (S207).

[0202] Now, let us assume that the station server 500a determines that an abnormality has occurred (S208). In this case, the station server 500a transmits an abnormality alert to the service server 400a (S209). Furthermore, when the service server 400a receives the abnormality alert, it transmits an analysis request (analysis request information) to the transaction management server 300 to request an analysis of the abnormality (S210). The information transmitted as the analysis request is, for example, the abnormality alert. For example, when the station server 500a determines that an abnormality has occurred, it transmits an abnormality alert indicating the details of the abnormality to the transaction management server 300 via the service server 400a.

[0203] The content of the abnormality may be determined arbitrarily in advance and is not particularly limited. Examples of the content of the abnormality include an abnormality in which the difference between the amount of power supplied to a plurality of chargers / dischargers arranged in the station where the charger / discharger 600a is arranged and the amount of power charged by the plurality of chargers / dischargers is equal to or greater than a predetermined power value (first power value), an abnormality in which the charging power is greater than a predetermined charging power value (second power value) (excessive charging power), an abnormality in which the charging power is less than a predetermined charging power value (third power value) (insufficient charging power), an abnormality in which the discharging power is greater than a predetermined discharging power value (excessive discharging power), an abnormality in which the charging amount is greater than a predetermined power value (excessive charging amount), or an abnormality in which the discharging amount is greater than a predetermined power value (excessive discharging amount).

[0204] When the transaction management server 300 receives an analysis request, specifically an abnormality alert, it determines the information necessary for abnormality analysis (S211). Specifically, the transaction management server 300 determines the analysis rules to be used for abnormality analysis based on the abnormality alert. The transaction management server 300 also determines the analysis server based on the abnormality alert.

[0205] The transaction management server 300 transmits information requesting an abnormality analysis to the selected analysis server (S212). In this example, the vehicle management server 200a is selected as the analysis server. In this case, the transaction management server 300 transmits information requesting an abnormality analysis to the vehicle management server 200a. The information requesting an abnormality analysis includes, for example, information indicating the analysis rule.

[0206] When the vehicle management server 200a receives information requesting an abnormality analysis, it performs an abnormality analysis, for example, using the analysis rules and vehicle log included in the information, and transmits the analysis results to the transaction management server 300 (S213).

[0207] As a result, in this example, the vehicle management server 200a identifies the cause of the abnormality. The identified cause of the abnormality may be determined in advance and is not particularly limited. Examples of the cause of the abnormality include a power theft detection abnormality, which indicates the possibility of power theft; an excessive charging power abnormality, which indicates an abnormality where the charging power value is too high; an excessive discharging power abnormality, which indicates an abnormality where the discharging power value is too high; an excessive charging amount abnormality, which indicates an abnormality where too much power has been charged to the vehicle 100a; and an excessive discharging amount abnormality, which indicates an abnormality where too much power has been discharged from the vehicle 100a. Identifying the cause of the abnormality may mean, for example, performing an abnormality analysis according to the content of the abnormality and identifying the cause of the abnormality according to the content. However, it may also mean determining whether the determination result of the abnormality detection unit 505, which determined that there is an abnormality, is correct. In other words, the content of the abnormality determined by the abnormality detection unit 505 and the cause of the abnormality indicated by the analysis result by the analysis server may be the same or different.

[0208] The transaction management server 300 generates an analysis report (analysis report information) based on the analysis results received from the vehicle management server 200a (S214). The transaction management server 300 generates an analysis report that includes, for example, information contained in the abnormality alert and the analysis results.

[0209] The transaction management server 300 transmits the created analysis report to, for example, the analysis server and the server that sent the analysis request (S215). In this example, the transaction management server 300 transmits the analysis report to the vehicle management server 200a and the service server 400a.

[0210] The service server 400a stores the received analysis report as an abnormality case (abnormality case information), and takes measures to deal with the abnormality that is determined to exist based on information indicating the presence or absence of aggression included in the analysis report (S216). In this example, the service server 400a transmits an instruction to the charger / discharger 600a to deal with the abnormality (specifically, information indicating an instruction to stop charging) to the station server 500a. When the station server 500a receives the information indicating the instruction to stop charging, it transmits the information indicating the instruction to stop charging to the charger / discharger 600a.

[0211] When the charger / discharger 600a receives the information indicating an instruction to stop charging, the charger / discharger 600a stops charging the vehicle 100a (S217).

[0212] As a result, if it is determined that there is an abnormality, for example, the cause of the abnormality (for example, the aggressiveness of the abnormality) is analyzed, and based on the analysis results, measures such as emergency stopping of charging are taken.

[0213] The service server 400a may transfer the received analysis report to the station server 500a. The station server 500a may take measures based on the received analysis report, such as urgently stopping charging of the charger / discharger 600a.

[0214] FIG. 24 is a flowchart showing a processing procedure executed by the station server 500a according to the embodiment.

[0215] First, the station server 500a receives charge / discharge information from the charger / discharger 600a (S301).

[0216] Next, the station server 500a determines whether the charge / discharge information of the charger / discharger 600a received in step S301 is the first charge / discharge information it has received (S302). For example, the station server 500a determines whether the received charge / discharge information is the first charge / discharge information when charging / discharging between the vehicle 100a and the charger / discharger 600a is started, based on the charger / discharger log stored in the charger / discharger log storage unit 503.

[0217] When the station server 500a determines that the charge / discharge information is the first one it has received (Yes in S302), it performs an anomaly detection rule update process (S303). Specifically, the station server 500a updates the anomaly detection rule.

[0218] If the answer is No in step S302 or after step S303, the station server 500a performs a log collection process (S304). Specifically, the station server 500a stores the received charge / discharge information as a charger / discharger log.

[0219] Next, the station server 500a performs an abnormality detection process (S305). Specifically, the station server 500a determines whether or not an abnormality has occurred by using the received charge / discharge information and the abnormality detection rule. For example, if the station server 500a determines that an abnormality has occurred in step S305, the station server 500a creates an abnormality alert and transmits the created abnormality alert to the service server 400a.

[0220] Next, the station server 500a receives an instruction to deal with the abnormality (S306).

[0221] Next, the station server 500a takes action against the abnormality based on the instruction to deal with the abnormality received in step S306 (S307). For example, the station server 500a stores the analysis report as an abnormality case, or based on the instruction to deal with the abnormality, transmits an instruction to the charger / discharger 600a to stop charging, thereby stopping charging / discharging.

[0222] If the station server 500a does not receive an instruction to deal with the abnormality in step S306, the station server 500a may end the process without executing step S307.

[0223] 25 is a flowchart illustrating a processing procedure executed by the anomaly detection rule update unit 506 according to the embodiment. Specifically, FIG. 25 illustrates details of the processing in step S303.

[0224] First, the abnormality detection rule update unit 506 acquires one or more charger / discharger logs of chargers / dischargers other than the charger / discharger 600a, which are stored in the charger / discharger log storage unit 503 (S401). The abnormality detection rule update unit 506 performs the processes of steps S402 to S407 using, for example, the acquired one or more charger / discharger logs, the charger / discharger basic information, and the vehicle basic information.

[0225] The station server 500a may acquire the basic vehicle information of the vehicle 100a by transmitting the basic vehicle information from the vehicle 100a to the charger / discharger 600a when the vehicle 100a and the charger / discharger 600a charge or discharge the vehicle 100a, and the charger / discharger 600a including the basic vehicle information in the charge or discharge information and transmitting the information to the station server 500a. Also, for example, the station server 500a may acquire the basic vehicle information of the vehicle 100a from the vehicle management server 200a via the service server 400a and the transaction management server 300.

[0226] For example, when the station server 500a receives charging / discharging information regarding charging / discharging between the vehicle 100a and the charger / discharger 600a for the first time, the station server 500a may transmit the identifier of the charger / discharger 600a and the location information of the station where the charger / discharger 600a is located to the transaction management server 300 via the service server 400a. The station location information may be included in a station list or may be stored in advance in the station server 500a. For example, the station server 500a transmits the identifier of the charger / discharger 600a to the service server 400a, and the service server 400a transmits the identifier of the charger / discharger 600a and the location information of the station to the transaction management server 300. For example, upon receiving the identifier of the charger / discharger 600a and the location information of the station, the transaction management server 300 transmits this information to all vehicle management servers (in this embodiment, vehicle management servers 200a and 200b). If the vehicle management server stores a vehicle charge / discharge log including the received identifier of the charger / discharger 600a and location information of the vehicle 100a that indicates the same location as the station location information, the vehicle management server transmits basic vehicle information of the vehicle 100a to the transaction management server 300. For example, the transaction management server 300 transfers the received basic vehicle information of the vehicle 100a to the service server 400a, and the service server 400a transfers the received basic vehicle information including information such as the model of the vehicle 100a to the station server 500a. In this way, the station server 500a and the service server 400a can obtain information about the vehicle 100a even if the charger / discharger 600a does not receive the vehicle number of the vehicle 100a, for example. For example, when the service server 400a functions as an analysis server, it extracts a charger / discharger log related to the vehicle 100a using the information about the vehicle 100a obtained in this manner. Therefore, for example, when extracting multiple charger / discharger logs, the log analysis processing unit 403 can extract multiple charger / discharger logs based on the identifier of the charger / discharger 600a and the location information of the station where the charger / discharger 600a is located.

[0227] Similarly, the vehicle management server 200a can also obtain information about the charger / discharger 600a based on the identifier of the charger / discharger 600a included in the charge / discharge information for the vehicle 100a and the location information for the vehicle 100a. For example, when the transaction management server 300 receives location information for the vehicle 100a from the vehicle management server 200a, it transmits the location information for the vehicle 100a to all service servers (in this embodiment, the service servers 400a and 400b). If a station managed by the service server 400a or 400b is located at the location indicated by the location information, the service server 400a or 400b transmits information about the station server managing the corresponding station to the transaction management server 300. Specifically, the service server extracts information about the station server managing the charger / discharger located at the location indicated by the location information and information about the charger / discharger managed by the station server from the station list and transmits the extracted information to the transaction management server 300. The transaction management server 300 forwards the received information to the vehicle management server 200a. As a result, the vehicle management server 200a can acquire information about the vehicle 100a using the location information of the vehicle 100a and the identifiers of the charger / discharger 600a that charged / discharged the vehicle 100a. Therefore, for example, when extracting multiple vehicle logs, the log analysis processing unit 203 can extract multiple vehicle logs based on the identifier of the charger / discharger 600a and the location information of the vehicle 100a.

[0228] The anomaly detection rule update unit 506 determines whether the number of charger / discharger logs in which charging / discharging was performed using a combination of a vehicle of the same type (model) as the vehicle 100a and a charger / discharger of the same type (model) as the charger / discharger 600a is equal to or greater than a predetermined number (S402). Note that the predetermined number may be set arbitrarily and is not particularly limited. The predetermined number is, for example, 10.

[0229] If the answer is Yes in step S402, that is, if it is determined in step S402 that the number is equal to or greater than a predetermined number, the abnormality detection rule update unit 506 extracts, from the one or more acquired charger / discharger logs, charge / discharge logs in which charging / discharging was performed using a combination of a vehicle of the same type as the vehicle 100a and a charger / discharger of the same type as the charger / discharger 600a (S403).

[0230] If the answer is No in step S402, that is, if it is determined in step S402 that the number is less than the predetermined number, the abnormality detection rule update unit 506 extracts, from the one or more acquired charger / discharger logs, charge / discharge logs in which charging / discharging was performed by a charger / discharger of the same type as the charger / discharger 600a (S404).

[0231] After step S403 or step S404, the anomaly detection rule update unit 506 sets the most frequent value indicated by the charger / discharger log extracted in step S403 or step S404 as each threshold value of the anomaly detection rule (S405). Specifically, the anomaly detection rule update unit 506 updates the set maximum charge power value and maximum discharge power value in the anomaly detection rule.

[0232] The abnormality detection rule update unit 506 calculates the charging rate, for example, by calculating ((remaining battery capacity of vehicle 100a indicated by the charging / discharging information received in step S301) / (full charge capacity of vehicle 100a indicated by the vehicle basic information)) × 100. For example, if the calculated charging rate is less than a predetermined value, the abnormality detection rule update unit 506 updates the most frequent value in the charger / discharger log for which the charging rate is less than the predetermined value to the maximum charging power. On the other hand, for example, if the calculated charging rate is equal to or greater than the predetermined value, the abnormality detection rule update unit 506 updates the most frequent value in the charger / discharger log for which the charging rate is equal to or greater than the predetermined value to the maximum charging power.

[0233] The predetermined value may be set arbitrarily and is not particularly limited, and is, for example, 80%.

[0234] 26 is a flowchart showing the processing procedure executed by the log collection processor 502 according to the embodiment. Specifically, FIG. 26 shows details of the processing in step S304.

[0235] First, the log collection processing unit 502 determines whether the charge / discharge information received in step S301 is the first charge / discharge information when charging / discharging between the vehicle 100a and the charger / discharger 600a is started (S501).

[0236] If the answer to step S501 is Yes, that is, if the log collection processing unit 502 determines in step S501 that the charge / discharge information is the first, it transmits to the transaction management server 300 the vehicle management server number indicating the vehicle management server 200a that manages the vehicle 100a and information for requesting basic vehicle information of the vehicle 100a (S502). For example, as described above, the station server 500a transmits the identifier of the charger / discharger 600a and the location information of the station where the charger / discharger 600a is located to the transaction management server 300 via the service server 400a. For example, upon receiving the identifier of the charger / discharger 600a and the location information of the station, the transaction management server 300 transmits this information to all vehicle management servers. If the vehicle management server stores a vehicle charge / discharge log including the received identifier of the charger / discharger 600a and location information of the vehicle 100a that indicates the same location as the station location information, it transmits the basic vehicle information of the vehicle 100a and its own vehicle management server number to the transaction management server 300. For example, the transaction management server 300 transfers the received information to the service server 400a, and the service server 400a transfers the received information to the station server 500a, which then acquires information indicating the vehicle model of the vehicle 100a and an identifier (vehicle management server number) indicating the vehicle management server 200a that manages the vehicle 100a.

[0237] If the answer is No in step S501, that is, if it is determined in step S501 that the charge / discharge information is not the first one, or after step S502, the log collection processing unit 502 associates the received charge / discharge information with the received vehicle management server number and the vehicle model of the vehicle 100a and stores the associated information as a charge / discharger log in the charge / discharger log storage unit 503 (S503). Note that if the answer is No in step S501, that is, if the charge / discharge information is received for the second or subsequent time, the already received information indicating the vehicle management server number and the vehicle model is received in the first process of receiving the information indicating the vehicle management server number and the vehicle model, and therefore the already received information indicating the vehicle management server number and the vehicle model is associated with the charge / discharge information and stores the associated information as a charge / discharger log in the charge / discharger log storage unit 503.

[0238] As a result, station server 500a receives and stores information that is not included in the charge / discharge information received from charger / discharger 600a from vehicle management server 200a via service server 400a and transaction management server 300.

[0239] 27 is a flowchart illustrating a processing procedure executed by the abnormality detection unit 505 according to the embodiment. Specifically, FIG. 27 illustrates details of the processing of step S305.

[0240] First, the abnormality detection unit 505 detects an abnormality using the charge / discharge information and the abnormality detection rule (S601).

[0241] The abnormality detection unit 505 determines whether or not an abnormality has occurred as a result of the abnormality detection performed in step S601 (S602).

[0242] If the abnormality detection unit 505 determines that there is no abnormality (No in step S602), the process ends.

[0243] On the other hand, if the anomaly detection unit 505 determines that an anomaly has occurred (Yes in step S602), it creates an anomaly alert indicating the details of the detected anomaly (S603).

[0244] Next, the anomaly detection unit 505 determines whether an anomaly case indicating an analysis result of an anomaly similar to the detected anomaly is stored in the anomaly case storage unit 407 (S604). For example, the anomaly detection unit 505 may transmit the details of the detected anomaly to the service server 400a, causing the service server 400a to determine whether an anomaly case indicating an analysis result of an anomaly similar to the detected anomaly is stored in the anomaly case storage unit 407, and by receiving the determination result, determines whether an anomaly case indicating an analysis result of an anomaly similar to the detected anomaly is stored in the anomaly case storage unit 407. The service server 400a may store an anomaly response list to determine the cause of an anomaly that may be the same as the detected anomaly. Furthermore, the anomaly case may include information indicating the details of the anomaly.

[0245] If the anomaly detection unit 505 determines that there is no anomaly case stored in the anomaly case storage unit 407 that indicates an analysis result of an anomaly similar to the detected anomaly (No in step S604), it sends the created anomaly alert to the transaction management server 300 via the service server 400a (S605) and terminates processing.

[0246] On the other hand, if the anomaly detection unit 505 determines that an anomaly case indicating an analysis result of an anomaly similar to the detected anomaly is stored in the anomaly case storage unit 407 (Yes in step S604), the anomaly detection unit 505 takes action against the anomaly indicated by the anomaly case based on the anomaly case corresponding to the similar anomaly (S606), and terminates the processing. For example, if the anomaly detection unit 505 determines Yes in step S604, the anomaly detection unit 505 receives information indicating a response to the anomaly indicated by the anomaly case from the service server 400a, and takes action against the anomaly based on the received information. If the anomaly case indicates aggression, the anomaly is addressed by causing the charger / discharger 600a to stop charging / discharging with the vehicle 100a, as shown in step S703 described below. On the other hand, for example, if the anomaly case indicates no aggression, the anomaly detection unit 505 terminates the processing without taking action against the anomaly, for example.

[0247] When the station server 500a executes step S606, the station server 500a may end the process without transmitting the abnormality alert to the service server 400a. When the station server 500a executes step S606, the station server 500a may transmit the abnormality alert to the service server 400a and execute the processes from step S306 onwards.

[0248] FIG. 28 is a diagram illustrating an example of an abnormality alert according to the embodiment.

[0249] The abnormality alert includes, for example, information indicating the abnormality alert number of the abnormality alert, information indicating the content of the abnormality, information indicating the date and time when the abnormality was detected, information indicating the value determined to be abnormal (the ``abnormal value'' shown in Figure 28), information indicating the threshold value used to detect the abnormality (the ``appropriate value'' shown in Figure 28), information indicating the vehicle model of vehicle 100a, the charger / discharger number of charger / discharger 600a, the station server number indicating station server 500a, the service server number indicating service server 400a, and location information indicating the location of vehicle 100a.

[0250] Fig. 29 is a flowchart showing a processing procedure executed by log analysis processing unit 203 according to the embodiment. Specifically, Fig. 29 shows details of the processing executed by the analysis server. For example, when service server 400a is selected as the analysis server, log analysis processing unit 403 also performs the processing shown in Fig. 29. In this case, the vehicle log described in Fig. 29 becomes the charger / discharger log.

[0251] First, the log analysis processing unit 203 receives the analysis rule from the transaction management server 300 (S701).

[0252] Next, the log analysis processing unit 203 searches for a vehicle log that satisfies the log classification conditions from among one or more vehicle logs stored in the vehicle state log memory unit 205 or the vehicle charge / discharge log memory unit 206, based on the log classification conditions included in the analysis rules (S702).

[0253] The log analysis processing unit 203 determines whether or not a log (in this example, a vehicle log) that satisfies the log classification condition is found as a result of the search in step S702 (S703).

[0254] If the log analysis processing unit 203 determines that there is a vehicle log that satisfies the log classification conditions (Yes in step S703), it counts the number of vehicle logs that satisfy the check conditions included in the analysis rule among the one or more vehicle logs that satisfy the log classification conditions (S704).

[0255] The log analysis processing unit 203 determines whether the number of vehicle logs that satisfy the check conditions as a result of the counting in step S704 satisfies the abnormality determination criterion included in the analysis rule (S705).

[0256] If the log analysis processing unit 203 determines that the abnormality determination criteria are met (Yes in step S705), it determines that an abnormality has occurred (S706). Furthermore, the log analysis processing unit 203 identifies the cause of the abnormality as the received analysis rule, that is, the cause of the abnormality corresponding to the analysis rule used for the abnormality analysis (in this example, the analysis rule name).

[0257] If it is determined that the abnormality determination criteria are not met (No in step S705), the log analysis processing unit 203 determines that there is no abnormality (S707). That is, in this case, even if the abnormality detection unit 505 determines that there is an abnormality, the log analysis processing unit 203 determines that there is no abnormality as a result of the abnormality analysis.

[0258] Furthermore, if the answer to step S703 is No, that is, if it is determined that there are no vehicle logs that satisfy the log classification conditions, in other words, if there are no vehicle logs that can be used for abnormality analysis, the log analysis processing unit 203 determines that analysis is not possible (S708).

[0259] After step S706, S707, or S708, the log analysis processor 203 transmits the determination result (analysis result) in step S706, S707, or S708 to the transaction management server 300 (S709).

[0260] 30 is a diagram showing an example of an analysis result output by an analysis server according to an embodiment. The example shown in FIG. 30 shows the analysis result sent from the vehicle management server 200a to the transaction management server 300 when the analysis server is the vehicle management server 200a.

[0261] The analysis results include, for example, information indicating the abnormality alert number, information indicating the cause of the abnormality, information indicating the judgment result in step S706, S707, or S708, information indicating the analysis server number (information such as an identifier indicating the analysis server that performed the abnormality analysis) (i.e., an identifier indicating the device itself), and information indicating whether or not there is aggressiveness.

[0262] For example, if the service server 400a is selected as the analysis server, the service server 400a also transmits the analysis results shown in Fig. 30 to the transaction management server 300. In this case, for example, the analysis server number shown in Fig. 30 becomes 400a.

[0263] 31 is a diagram showing an example of an analysis report output by the transaction management server 300 according to an embodiment. For example, when the transaction management server 300 receives an analysis result from the analysis server, the transaction management server 300 creates the analysis report shown in FIG. 31 and transmits the created analysis report to the server that sent the abnormality alert (in this example, the service server 400a) and the analysis server (in this example, the vehicle management server 200).

[0264] The analysis report includes, for example, information included in the received analysis result and information included in the received abnormality alert. In the example shown in FIG. 31 , the analysis report includes information indicating an abnormality alert number, information indicating the cause of the abnormality, information indicating the determination result in step S706, S707, or S708, information indicating the presence or absence of aggression, information indicating the date and time when the abnormality was detected, information indicating the value determined to be abnormal (the “abnormal value” shown in FIG. 31 ), information indicating the threshold value used to detect the abnormality (the “appropriate value” shown in FIG. 31 ), information indicating the vehicle model of vehicle 100a, the charger / discharger number of charger / discharger 600a, the station server number indicating station server 500a, the service server number indicating service server 400a, and location information indicating the location of vehicle 100a. Note that the analysis report may also include information indicating an analysis server number.

[0265] 32 is a flowchart showing the processing procedure executed by the abnormality processing unit 404 according to the embodiment. Specifically, FIG. 32 shows details of the processing executed by the service server 400a when the service server 400a receives an analysis report.

[0266] First, the abnormality processing unit 404 receives an analysis report from the transaction management server 300 (S801).

[0267] Next, the anomaly processing unit 404 determines whether or not there is an attack, that is, whether or not there is a possibility that the anomaly detected by the anomaly detection unit 505 is caused by an attack, based on the received analysis report (S802).

[0268] If the abnormality processing unit 404 determines that there is aggression (Yes in step S802), it transmits an instruction to the station server 500a to cause the charger / discharger 600a to stop charging / discharging, that is, an instruction to deal with the abnormality (S803).

[0269] On the other hand, if it is determined that there is no aggression (No in step S802), the abnormality processing unit 404 does not transmit an instruction to stop charging / discharging to the charger / discharger 600a.

[0270] Furthermore, for example, the abnormality processing unit 404 stores the received analysis report as an abnormality case in the abnormality case storage unit 407 .

[0271] If there is no aggression, the abnormality processing unit 404 may notify the station server 500a only that an abnormality has occurred without stopping the charging / discharging. Also, the abnormality processing unit 404 may send an analysis report to the station server 500a.

[0272] FIG. 33 is a flowchart showing the processing procedure executed by the transaction management server 300 according to the embodiment.

[0273] When the transaction management server 300 receives an abnormality alert from the service server 400a (S901), it executes the processes from step S902 onwards.

[0274] The transaction management server 300 creates an analysis rule to be used for anomaly analysis based on the received anomaly alert, anomaly response list, and analysis rule list (S902). Specifically, the transaction management server 300 creates an analysis rule to be used for anomaly analysis by selecting one or more analysis rules from the multiple analysis rules included in the analysis rule list based on the received anomaly alert, anomaly response list, and analysis rule list.

[0275] Next, the transaction management server 300 performs an analysis report creation process (S903). Specifically, the transaction management server 300 determines an analysis server, receives analysis results from the determined analysis server, and creates an analysis report based on the received analysis results.

[0276] Next, the transaction management server 300 sends the created analysis report to the vehicle management server indicated by the vehicle management server number included in the abnormality alert (in this example, vehicle management server 200a) and to the service server indicated by the service server number included in the abnormality alert (in this example, service server 400a) (S904).

[0277] The transaction management server 300 communicates with each server based on, for example, a vehicle management server list and a service server list.

[0278] If necessary, transaction management server 300 may request service server 400a to provide a list of chargers / dischargers of the same model as charger / discharger 600a. In this case, for example, service server 400a may create a list by listing chargers / dischargers of the same model as charger / discharger 600a based on the charger / discharger number, and transmit the created list to transaction management server 300.

[0279] 34 is a flowchart showing a specific example of the analysis report creation process according to the embodiment. Specifically, FIG. 34 shows details of the process executed in step S903.

[0280] First, the transaction management server 300 determines an analysis server based on the abnormality alert, the abnormality response list, and the analysis rule list (S1001).

[0281] Next, the transaction management server 300 transmits the analysis rule created in step S902 to the determined analysis server (S1002).

[0282] Next, the transaction management server 300 receives the analysis results from the analysis server (S1003).

[0283] Next, the transaction management server 300 creates an analysis report based on the received analysis results (S1004).

[0284] By performing the above process, when an abnormality is detected in the station server 500a, the abnormality is analyzed in more detail and the cause of the abnormality is identified.

[0285] The analysis server may be selected arbitrarily. For example, the transaction management server 300 may preferentially select a server that has not been requested to perform analysis as the analysis server. Furthermore, for example, the transaction management server 300 may select a server indicated by the vehicle management server number, service server number, and station server number included in the abnormality alert as the analysis server.

[0286] In addition, the vehicle management server 200a, the vehicle management server 200b, and the transaction management server 300 may be realized by a single server.

[0287] Furthermore, the service servers 400a and 400b and the station servers 500a, 500b, 500c and 500d may be integrated into a single server.

[0288] Furthermore, the service servers 400a and 400b, the station servers 500a, 500b, 500c and 500d, and the transaction management server 300 may be integrated into a single server.

[0289] Furthermore, vehicle management servers 200a and 200b, transaction management server 300, service servers 400a and 400b, and station servers 500a, 500b, 500c, and 500d may be collectively implemented as a single server.

[0290] In this way, the components of the devices included in the charging / discharging system 10a may be realized in any combination.

[0291] The station server 500 may also include a log analysis processing unit that executes anomaly analysis.

[0292] Furthermore, the vehicle management server 200 may perform an abnormality analysis using the charger / discharger log. In this case, for example, the vehicle management server 200 may receive the charger / discharger log by communicating with the service server 400 or the station server 500.

[0293] Furthermore, the service server 400 may perform an abnormality analysis using the vehicle log. In this case, for example, the service server 400 may receive the vehicle log by communicating with the vehicle management server 200.

[0294] [Representative Example] Figure 35 is a flowchart showing an information processing method according to an embodiment. For example, an information processing device includes a processor and a memory, and the processor uses the memory to perform the following processing. The information processing device is, for example, one of the vehicle management servers 200, 200a, and 200b.

[0295] First, the information processing device acquires charge / discharge information relating to charging / discharging between a predetermined charger / discharger and a predetermined mobile object from the predetermined charger / discharger (S10). The predetermined charger / discharger is, for example, one of charger / dischargers 600, 600a to 600h. The predetermined mobile object is, for example, one of vehicles 100, 100a to 100d. The charge / discharge information of the charger / discharger is, for example, the information shown in (d) of FIG.

[0296] Next, the information processing device determines whether or not there is an abnormality based on the acquired charge / discharge information (S20). The information processing device determines, for example, whether or not the information included in the charge / discharge information indicates an abnormal value. Information such as a threshold value for determining an abnormal value is stored in advance, for example, in a memory provided in the information processing device.

[0297] Next, if the information processing device determines that there is an abnormality in step S20 (Yes in S20), it analyzes the abnormality based on at least one of a plurality of first logs managed by a predetermined management server, which contain information regarding the charging and discharging of a plurality of mobile bodies including a predetermined mobile body, and a plurality of second logs managed by a predetermined station server, which contain information regarding the charging and discharging of a plurality of chargers including a predetermined charger and discharger (S30).

[0298] The plurality of first logs are, for example, logs including charge / discharge information of a plurality of mobile objects. The plurality of second logs are, for example, logs including charge / discharge information of a plurality of chargers / dischargers. The charge / discharge information of the mobile objects is, for example, the information shown in (b) of FIG. 10 .

[0299] The information processing device notifies the user of the cause of the identified abnormality, for example. For example, the information processing device displays, on a display or other display device, the charge / discharge information determined to have an abnormality, information indicating the mobile body that output the charge / discharge information, and information indicating the cause of the abnormality. Furthermore, for example, if the information processing device determines that there is no abnormality in step S20 (No in S20), it ends the processing and performs the processing again from step S10.

[0300] [Effects, etc.] Hereinafter, examples of techniques that can be obtained from the disclosure of this specification will be given, and effects, etc. that can be obtained from the exemplified techniques will be described.

[0301] Technique 1 is an information processing method that acquires charging / discharging information relating to charging / discharging between a specified charger / discharger and a specified mobile body from the specified charger / discharger (S10), determines whether or not there is an abnormality based on the charging / discharging information (S20), and if it is determined that there is an abnormality (Yes in S20), analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that contain information relating to charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that contain information relating to charging / discharging of a plurality of chargers including the specified charger / discharger (S30).

[0302] According to this, when some abnormality is detected in the charging / discharging between a mobile object and a charger / discharger, the cause of the detected abnormality can be analyzed and identified using multiple logs that are charging / discharging information for at least one of multiple mobile objects and multiple chargers / dischargers. This makes it possible to identify the cause of an abnormality that cannot be determined solely from the charging / discharging information for the charger / discharger in which the abnormality is detected. Therefore, the information processing method according to Technology 1 makes it easier to identify the cause of the abnormality.

[0303] Technique 2 is the information processing method according to Technique 1, in which the determination of whether or not an abnormality exists is based on charge / discharge information acquired from a predetermined charger / discharger and one or more other charge / discharge information related to charging / discharging between at least one of a plurality of chargers / dischargers other than the predetermined charger / discharger and a mobile object. For example, if the charge / discharge information of the predetermined charger / discharger is charge / discharge information of charger / discharger 600a, the one or more other charge / discharge information is charge / discharge information of charger / discharger 600b. Furthermore, for example, if the charge / discharge information acquired from the predetermined charger / discharger is charge / discharge information related to charging / discharging between vehicle 100a and charger / discharger 600a, at least one of the mobile objects is vehicle 100a, but may also be a vehicle other than vehicle 100a.

[0304] This allows a determination as to whether or not an abnormality has occurred to be made using a plurality of pieces of charge / discharge information, thereby enabling a determination as to whether or not an abnormality has occurred to be made with high accuracy.

[0305] Technique 3 is the information processing method described in Technique 1 or 2, further extracting multiple logs from at least one of the multiple first logs and the multiple second logs based on predetermined log classification conditions, and analyzing the abnormality based on the extracted multiple logs.

[0306] The predetermined log classification condition is, for example, the information shown in Fig. 16A. The log classification condition is, for example, stored in advance in the information processing device.

[0307] The information required for anomaly analysis varies depending on the nature of the anomaly. Therefore, logs required for anomaly analysis (specifically, for identifying the cause of the anomaly) are selected based on predetermined log classification conditions. This reduces the amount of processing required to identify the cause of the anomaly.

[0308] Technique 4 is an information processing method according to Technique 3, further comprising determining an analysis server from among a plurality of servers to analyze the abnormality based on predetermined log classification conditions, and using the determined analysis server to analyze the abnormality.

[0309] Depending on the content of the abnormality, for example, it may be better to perform the abnormality analysis using the log of the charger / discharger, or it may be better to perform the abnormality analysis using the log of the mobile object. Furthermore, even if the abnormality analysis is performed by a server that acquires both the log of the charger / discharger and the log of the mobile object, if the abnormality analysis processing is concentrated on one server, it may take a long time to complete the abnormality analysis. Therefore, by identifying the cause of the abnormality using one of multiple servers that can perform abnormality analysis based on the content of the abnormality, it is possible to prevent the abnormality analysis processing from being concentrated on one server.

[0310] The analysis server may be a management server, a station server, or a server other than the management server and the station server.

[0311] Technique 5 is an information processing method according to Technique 3 or 4, in which the plurality of second logs include an identifier indicating a specified charger / discharger, and the plurality of logs are extracted based on the identifier and location information of the station where the specified charger / discharger is located.

[0312] This allows a mobile object that has been charged or discharged with a charger or discharger to be identified without the charger or discharger acquiring an identifier of the mobile object, etc. Therefore, it is possible to extract a log related to the mobile object while suppressing the problem of important information of the mobile object being leaked in communication between the mobile object and the charger or discharger.

[0313] Technique 6 is an information processing method according to any one of techniques 1 to 5, in which the determination of whether or not there is an abnormality is made by determining whether or not electricity theft has occurred in charging and discharging between a specified charger / discharger and a specified mobile body, and if it is determined that electricity theft has occurred, analyzing the abnormality based on a plurality of first logs.

[0314] When power theft occurs, it is believed that an abnormal process has been performed in the mobile object. Therefore, when it is determined that power theft has occurred, the abnormality can be analyzed based on the plurality of first logs, and the abnormality can be analyzed using the log of the mobile object where the abnormal process is believed to have been performed. This makes it easier to identify the cause of the abnormality.

[0315] Technique 7 is an information processing method according to any one of techniques 1 to 6, in which the multiple first logs include status information indicating the status of multiple moving bodies, and in analyzing the abnormality, the abnormality is analyzed based on the status information.

[0316] The status information is, for example, information indicating whether the mobile object is being charged or is traveling (the above-mentioned vehicle status information).

[0317] For example, the management server receives from the mobile object not only charge / discharge information during charging but also information indicating the remaining battery charge of the vehicle while traveling, and stores the information as a first log. For example, if an abnormality occurs in charging between the mobile object and the charger / discharger, in which more power than expected is charged to the mobile object, an abnormal change may also be observed in the first log, which indicates information indicating the remaining battery charge while the mobile object is traveling. Therefore, in analyzing the abnormality, for example, multiple logs may be extracted based on the status information, and the extracted logs may be used to analyze the abnormality, making it easier to identify the cause of such an abnormality.

[0318] Technology 8 is an information processing device that includes an acquisition unit that acquires charge / discharge information regarding charging / discharging between a specified charger / discharger and a specified mobile body from the specified charger / discharger, a determination unit that determines whether or not an abnormality exists based on the charge / discharge information, and an analysis unit that, if it determines that an abnormality exists, analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that include information regarding charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that include information regarding charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

[0319] The acquisition unit is, for example, log collection processing unit 502. The determination unit is, for example, an abnormality detection unit 505. The analysis unit is, for example, at least one of log analysis processing units 403 and 203. The information processing device is realized by, for example, a device or system including some or all of the components of station servers 500, 500a to 500d, service servers 400, 400a to 400b, and vehicle management servers 200, 200a to 200b.

[0320] This provides the same effects as the information processing method according to Technique 1.

[0321] The analysis unit may be realized by a processing unit provided in any of the following servers: a processing unit provided in a station server (e.g., station servers 500, 500a to 500d), a processing unit provided in a service server (e.g., service servers 400, 400a to 400b), a processing unit provided in the transaction management server 300, or a processing unit provided in a vehicle management server (e.g., vehicle management servers 200, 200a to 200b). The information processing device may be realized by a single computer or may be realized as a system by multiple computers. For example, the multiple computers provided in the system are connected to each other so that they can communicate with each other, and perform the above processing by exchanging information with each other.

[0322] The ninth aspect of the present invention is a program for causing a computer to execute the information processing method according to any one of the first to seventh aspects.

[0323] This provides the same effect as the information processing method described in any one of Techniques 1 to 7.

[0324] (Other Embodiments) Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments.

[0325] In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. In addition, the order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.

[0326] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0327] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.

[0328] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a system, a method, an integrated circuit, a computer program, and a recording medium.

[0329] In addition, this disclosure also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art would conceive, or forms realized by arbitrarily combining the components and functions of each embodiment within the scope that does not deviate from the intent of this disclosure.

[0330] The present disclosure is useful for a device that analyzes abnormalities relating to charging and discharging between a charger and a vehicle.

[0331] 10, 10a Charging / discharging system 100, 100a to 100d Vehicle 101 Charging / discharging control unit 102, 602 Charging / discharging information acquisition unit 103 Charging / discharging port unit 104 Vehicle control unit 105, 201, 301, 401, 501, 603, 701 Communication unit 106 Vehicle state acquisition unit 200, 200a to 200b Vehicle management server 202, 402, 502 Log collection processing unit 203, 403 Log analysis processing unit 204 Vehicle type identification unit 205 Vehicle state log storage unit 206 Vehicle charging / discharging log storage unit 207 Vehicle basic information storage unit 300 Transaction management server 302 Abnormality analysis control unit 303 Abnormality response list storage unit 304 Analysis rule list storage unit 305 Vehicle management server list storage unit 306 Service server list storage unit 400, 400a to 400b Service server 404 Abnormality processing unit 405, 503 Charger / discharger log storage unit 406 Station list storage unit 407 Abnormality case storage unit 500, 500a to 500d Station server 504 Charger / discharger list storage unit 505 Abnormality detection unit 506 Abnormality detection rule update unit 507 Abnormality detection rule storage unit 508 Power monitoring unit 509 Power control unit 600, 600a to 600h Charger / discharger 601 Charging / discharging mechanism unit 604 Charger / discharger control unit 700a to 700c Power company server 702 Power management command unit 800 System power supply

Claims

1. An information processing method comprising: acquiring charging / discharging information relating to charging / discharging between a specified charger / discharger and a specified mobile body from the specified charger / discharger; determining whether or not an abnormality exists based on the charging / discharging information; and, if it is determined that an abnormality exists, analyzing the abnormality based on at least one of a plurality of first logs managed by a specified management server, which contain information relating to charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server, which contain information relating to charging / discharging of a plurality of chargers including the specified charger / discharger.

2. The information processing method according to claim 1, wherein the determination of whether or not an abnormality exists is made based on the charge / discharge information acquired from the specified charger / discharger and one or more other charge / discharge information relating to charging / discharging between at least one of the plurality of chargers / dischargers other than the specified charger / discharger and a mobile body.

3. The information processing method according to claim 1, further comprising: extracting a plurality of logs from at least one of the plurality of first logs and the plurality of second logs based on predetermined log classification conditions; and analyzing the abnormality based on the extracted plurality of logs.

4. The information processing method according to claim 3, further comprising: determining an analysis server from among a plurality of servers to analyze the abnormality based on the predetermined log classification conditions; and analyzing the abnormality using the determined analysis server.

5. The information processing method according to claim 3, wherein each of the plurality of second logs includes an identifier indicating the specified charger / discharger, and the plurality of logs are extracted based on the identifier and location information of the station where the specified charger / discharger is located.

6. The information processing method according to claim 1, wherein the determination of whether or not an abnormality exists includes determining whether or not electricity theft has occurred in charging / discharging between the specified charger / discharger and the specified mobile body, and if it is determined that electricity theft has occurred, analyzing the abnormality based on the plurality of first logs.

7. The information processing method according to claim 1, wherein the plurality of first logs each include status information indicating the status of the plurality of moving bodies, and the analysis of the abnormality is performed based on the status information.

8. An information processing device comprising: an acquisition unit that acquires charge / discharge information relating to charging / discharging between a specified charger / discharger and a specified mobile body from the specified charger / discharger; a determination unit that determines whether or not an abnormality exists based on the charge / discharge information; and an analysis unit that, if it is determined that an abnormality exists, analyzes the abnormality based on at least one of a plurality of first logs managed by a specified management server that contain information relating to charging / discharging of a plurality of mobile bodies including the specified mobile body, and a plurality of second logs managed by a specified station server that contain information relating to charging / discharging of a plurality of chargers / dischargers including the specified charger / discharger.

9. A program for causing a computer to execute the information processing method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Vehicle power supply system anomaly detection method and device, terminal equipment and storage medium

    CN116620030A

  • Battery abnormality diagnostic device and abnormality diagnostic method

    JP2016217900A

  • Embroidery data creation device, embroidery device, liquid discharge device, and embroidery data creation method

    JP2024004343A

  • KR20200098101A