Information processing method, information processing device, and program
The information processing method and device provide user-centric control of electrical equipment by allowing users to set conditions and record decisions in a distributed ledger, addressing the lack of user-tailored control and transparency in existing technologies, enhancing trust and satisfaction.
Patent Information
- Application Number
- PCT/JP2025/024331
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-06
- Filing Date
- 2025-07-07
- Publication Date
- 2026-02-12
AI Technical Summary
Existing power control technologies, such as those described in Patent Documents 1 and 2, do not allow for control methods tailored to user needs, lack transparency in control rules, and are vulnerable to unauthorized intermediary control, especially in the context of evolving electricity markets and VPP systems.
An information processing method and device that allows users to determine control modes between an energy management system and themselves, with conditions set by the user, and records these decisions in a distributed ledger, using smart contracts to ensure transparency and prevent tampering.
Enables user-centric control of electrical equipment, enhances transparency, and prevents unauthorized control by recording control rules and decisions in a distributed ledger, thereby increasing user trust and satisfaction.
Smart Images

Figure JP2025024331_12022026_PF_FP_ABST
Abstract
Description
Information processing method, information processing device, and program
[0001] The present disclosure relates to an information processing method, an information processing device, and a program.
[0002] Various power control technologies have been known for achieving energy conservation, etc. For example, a technology is known in which an EMS (Energy Management System) installed in each facility monitors and controls devices such as solar power generation systems, storage batteries, fuel cells, and storage batteries such as electric vehicles (EVs), as well as home appliances. This allows the EMS to comprehensively manage the power usage status in each facility.
[0003] For example, Patent Literature 1 discloses a control device that controls power while ensuring user convenience even when a power reduction command is received. Also, for example, Patent Literature 2 discloses a control device that can arbitrarily control a home appliance device while ensuring that the home appliance device transitions to a predetermined state.
[0004] JP 2017-55482 A JP 2019-149922 A
[0005] However, the techniques of Patent Documents 1 and 2 do not allow control to be performed in accordance with the needs of the user.
[0006] Therefore, the present disclosure has been made in consideration of the above circumstances, and provides an information processing method, an information processing device, and a program that are capable of performing control according to the needs of the user.
[0007] An information processing method according to one aspect of the present disclosure is an information processing method for controlling electrical equipment installed in a facility, which obtains control decision information regarding the control of the electrical equipment, and determines, based on the control decision information and a predetermined first condition, whether the electrical equipment will be controlled in a first control mode in which an energy management system capable of controlling the electrical equipment controls the electrical equipment, or a second control mode in which a user of the facility controls the electrical equipment, and outputs information regarding the control of the electrical equipment according to the determination result.
[0008] An information processing device according to one aspect of the present disclosure is an information processing device that controls electrical equipment installed in a facility, and includes: an acquisition unit that acquires control decision information regarding the control of the electrical equipment; a determination unit that determines, based on the control decision information and a predetermined first condition, whether the electrical equipment should be controlled in a first control mode in which an energy management system capable of controlling the electrical equipment controls the electrical equipment, or a second control mode in which a user of the facility controls the electrical equipment; and an output unit that outputs information regarding the control of the electrical equipment according to the determination result.
[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described information processing method.
[0010] According to one aspect of the present disclosure, it is possible to realize an information processing method or the like that can perform control according to the needs of a user.
[0011] FIG. 1 is a diagram illustrating an example of the overall configuration of an information processing system according to an embodiment. FIG. 2 is a diagram illustrating an example of the overall configuration of a house according to an embodiment. FIG. 3 is a block diagram illustrating an example of the functional configuration of a controller shown in FIG. 2. FIG. 4 is a block diagram illustrating an example of the functional configuration of a ledger server according to an embodiment. FIG. 5 is an explanatory diagram illustrating the data structure of a blockchain according to an embodiment. FIG. 6 is a block diagram illustrating an example of the functional configuration of a detection server according to an embodiment. FIG. 7 is a block diagram illustrating an example of the functional configuration of a management server according to an embodiment. FIG. 8 is a sequence diagram illustrating the overall operation of an information processing system according to an embodiment. FIG. 9 is a sequence diagram illustrating the overall operation of the consent information registration process shown in FIG. 8. FIG. 10 is a sequence diagram illustrating the overall operation of the data acquisition process shown in FIG. 8. FIG. 11A is a first sequence diagram illustrating the overall operation of the control process shown in FIG. 8. FIG. 11B is a second sequence diagram illustrating the overall operation of the control process shown in FIG. 8. FIG. 12 is an explanatory diagram illustrating the data structure of transaction data. FIG. 13 is an explanatory diagram illustrating transaction data related to the execution of a smart contract. FIG. 14 is an explanatory diagram illustrating processing related to the execution of a smart contract.
[0012] (Background to the Invention of the Present Disclosure) Before describing the embodiments of the present disclosure, the background to the invention of the present disclosure will be described.
[0013] As described in the "Background Art" above, the technologies of Patent Documents 1 and 2 are unable to perform control tailored to user needs, etc. Furthermore, the technologies of Patent Documents 1 and 2 do not allow users to know the rules under which control was performed, and are unable to perform control tailored to the circumstances of the control request. Furthermore, in recent years, with the liberalization of the electricity market, a control method called VPP (Virtual Power Plant) has been proposed. In such VPP technology, a management system called an aggregator comprehensively controls various devices via an EMS installed in each facility. Following this trend, it is expected that in the future, various intermediaries and intermediary systems, including aggregators, will control various devices via EMS and the like. In this case, there is also the issue that control by unauthorized intermediaries and intermediary systems may occur.
[0014] Therefore, the inventors of the present application have conducted extensive research into information processing methods and the like that can perform control tailored to user needs, and furthermore, information processing methods and the like that can ensure transparency of device control rules for users by granting control rights to an EMS or a user when predetermined conditions are met, and can perform control tailored to the circumstances of a control request, and have devised the information processing methods and the like described below. This can increase users' trust, understanding, and satisfaction with the information processing system.
[0015] An information processing method according to a first aspect of the present disclosure is an information processing method for controlling electrical equipment installed in a facility, which obtains control judgment information regarding the control of the electrical equipment, and determines, based on the control judgment information and a predetermined first condition, whether the electrical equipment will be controlled in a first control mode in which an energy management system capable of controlling the electrical equipment controls the electrical equipment, or a second control mode in which a user of the facility controls the electrical equipment, and outputs information regarding the control of the electrical equipment according to the determination result.
[0016] This allows the user to determine the control of the electrical appliances, which makes it possible to perform control according to the user's needs, compared to when the control of the electrical appliances is determined solely by the energy management system. For example, this increases the user's freedom in controlling the electrical appliances.
[0017] Also, for example, the information processing method according to the second aspect may be the information processing method according to the first aspect, and in the first control mode, the energy management system may automatically control the electrical equipment based on a predetermined second condition.
[0018] This improves the transparency of the control details of the electrical device when the second condition is a condition set by the user.
[0019] Furthermore, for example, an information processing method according to a third aspect may be the information processing method according to the second aspect, in which the second condition includes a condition set in advance by the user.
[0020] This allows the electrical appliances to be controlled based on the conditions set in advance by the user, thereby improving the transparency of the control details of the electrical appliances.
[0021] Furthermore, for example, an information processing method according to a fourth aspect may be an information processing method according to any one of the first to third aspects, and may acquire transaction data including at least one of a determination result based on the first condition and a result of executing control of the electrical device, and record the acquired transaction data in a distributed ledger.
[0022] This allows at least one of the judgment results and the execution results to be recorded in the distributed ledger, thereby improving transparency regarding the control of electrical equipment.
[0023] Furthermore, for example, an information processing method according to a fifth aspect may be an information processing method according to any one of the first to fourth aspects, in which transaction data including consent information set by the user is acquired, and the acquired transaction data is recorded in a distributed ledger, and the consent information may include the first condition.
[0024] This ensures the transparency of control rules when the control rules for electrical devices are set based on consent information set by the user. Furthermore, since the consent information is recorded in a distributed ledger, it is possible to prevent tampering with the acquired consent information. This further ensures the transparency of the control rules.
[0025] Furthermore, for example, an information processing method according to a sixth aspect may be an information processing method according to any one of the first to fifth aspects, and may determine the control mode of the electrical device using a smart contract based on the control determination information and the first condition.
[0026] This makes the contents of the smart contract open, ensuring transparency regarding the determination of the control mode.
[0027] Also, for example, an information processing method according to a seventh aspect is an information processing method according to any one of the first to sixth aspects, and the control judgment information may include at least one of the degree of power shortage, the expiration date of the manufacturer's warranty for the electrical equipment, and fluctuations in the market price of power.
[0028] This makes it possible to perform control according to the needs of the user when the degree of power shortage, the expiration date of the manufacturer's warranty for the electrical equipment, and fluctuations in the market price of power reach predetermined situations.
[0029] Furthermore, for example, an information processing method according to an eighth aspect may be an information processing method according to any one of the first to seventh aspects, and the first condition may include a condition indicating that, when the control judgment information includes information regarding the degree of power shortage, the control mode is set to the second control mode when the degree of shortage is less than a predetermined degree, and the control mode is set to the first control mode when the degree of shortage is equal to or greater than the predetermined degree.
[0030] This makes it possible to perform control according to the user's needs when the degree of power shortage is less than a predetermined level.
[0031] Furthermore, for example, the information processing method according to the ninth aspect may be the information processing method according to the eighth aspect, wherein the facility is provided with a plurality of electrical devices, and in the first control mode, at least one of the following may be automatically executed: control to reduce power consumption of the plurality of electrical devices in order of power consumption, starting with the electrical device that consumes the most power; control to reduce power consumption of the plurality of electrical devices in order of power consumption, starting with the electrical device that is used least frequently; control to reduce power consumption of the plurality of electrical devices evenly; and control to consume more power when there is a power surplus.
[0032] As a result, when each control is set by consent information, it is possible to perform control according to the user's needs even in the first control mode.
[0033] Furthermore, for example, an information processing method according to a tenth aspect is an information processing method according to any one of the first to ninth aspects, and the first condition may include a condition indicating that, when the control judgment information includes information related to the expiration date of a manufacturer's warranty of the electrical equipment, the control mode is set to the first control mode when the remaining period until the expiration date of the manufacturer's warranty is less than a predetermined period, and the control mode is set to the second control mode when the remaining period is equal to or greater than the predetermined period.
[0034] This makes it possible to perform control according to the needs of the user when the remaining time until the expiration of the manufacturer's warranty for the electrical equipment is equal to or longer than a predetermined period.
[0035] Also, for example, an information processing method according to an eleventh aspect may be the information processing method according to the tenth aspect, wherein in the first control mode, control is automatically executed to determine whether the electrical equipment will operate normally before the manufacturer's warranty period of the electrical equipment expires.
[0036] As a result, when the control to be executed is set by the consent information, it is possible to perform control according to the user's needs even in the first control mode.
[0037] Furthermore, for example, an information processing method according to a twelfth aspect is an information processing method according to any one of the first to eleventh aspects, and the first condition may include a condition indicating that, when the control determination information includes information regarding the market price of electricity, the control mode is set to the second control mode when the amount of change in the market price is less than a predetermined amount, and the control mode is set to the first control mode when the amount of change is equal to or greater than the predetermined amount.
[0038] This makes it possible to perform control according to the needs of users when the amount of change in the market price of electricity is less than a predetermined amount.
[0039] Also, for example, an information processing method according to a thirteenth aspect may be an information processing method according to the twelfth aspect, in which, in the first control mode, the electrical equipment is automatically controlled so that the electrical equipment consumes power during a time period when the market price is predicted to be relatively low.
[0040] As a result, when the control to be executed is set by the consent information, it is possible to perform control according to the user's needs even in the first control mode.
[0041] Furthermore, for example, the information processing method according to the fourteenth aspect may be the information processing method according to the thirteenth aspect, in which, if the electrical device is a storage battery and the time period when the market price is relatively low is predicted to be nighttime, the first control mode may control the storage battery to charge at nighttime.
[0042] As a result, when the control for receiving power from the charger is set by the consent information, it is possible to perform control according to the user's needs even when in the first control mode.
[0043] Also, for example, an information processing device according to a fifteenth aspect is an information processing device that controls electrical equipment installed in a facility, and includes an acquisition unit that acquires control decision information regarding the control of the electrical equipment, a determination unit that determines, based on the control decision information and a predetermined first condition, whether the electrical equipment should be controlled in a first control mode in which an energy management system capable of controlling the electrical equipment controls the electrical equipment, or a second control mode in which a user of the facility controls the electrical equipment, and an output unit that outputs information regarding the control of the electrical equipment according to the determination result.
[0044] This provides the same effect as the above-described information processing method.
[0045] Also, for example, a program according to a sixteenth aspect is a program for causing a computer to execute the information processing method according to any one of the first to fourteenth aspects.
[0046] This provides the same effect as the above-described information processing method.
[0047] These comprehensive or specific aspects may be realized as a system, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or may be realized as any combination of a system, a method, an integrated circuit, a computer program, and a recording medium.
[0048] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not described in independent claims are described as optional components.
[0049] Furthermore, each figure is a schematic diagram and is not necessarily an exact illustration. Therefore, for example, the scales of the figures do not necessarily match. Furthermore, in each figure, substantially the same components are given the same reference numerals, and redundant explanations are omitted or simplified.
[0050] Furthermore, in this specification, numerical values and numerical ranges are not expressions that express only the strict meaning, but are expressions that mean that they also include a substantially equivalent range, for example, a difference of about several percent (or about 10%).
[0051] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.
[0052] (Embodiment) Hereinafter, an information processing system according to the present embodiment will be described with reference to FIGS.
[0053] [1. Configuration of Information Processing System] First, the configuration of an information processing system according to this embodiment will be described with reference to Figures 1 to 7. Figure 1 is a diagram showing an example of the overall configuration of an information processing system 10 according to this embodiment. Note that Figure 1 shows an exemplary configuration of the information processing system 10, and the configuration of the information processing system 10 is not limited to that shown in Figure 1.
[0054] In the following, an example will be described in which the information processing system 10 of the present disclosure controls devices using blockchain technology, thereby enabling transparent device control, but the use of blockchain technology is not essential. In addition, the following will describe an energy trading system and the like in the embodiment with reference to the drawings.
[0055] As shown in FIG. 1 , the information processing system 10 includes, for example, houses 100a, 100b, and 100c, ledger servers 200a, 200b, and 200c, a detection server 300, and a management server 400. These are communicatively connected via a communication network 500. The houses 100a, 100b, and 100c and the detection server 300 are connected via the communication network 500 or a power network 600. In the example of FIG. 1 , the houses 100a, 100b, and 100c and the detection server 300 are connected via the power network 600. The power network 600 is an example of a power line. The power network 600 may be a dedicated line or a power network installed by a power company or the like.
[0056] Hereinafter, the ledger servers 200a, 200b, and 200c will be referred to as ledger servers 200a, etc. (ledger servers 200a to 200c) or as multiple ledger servers 200, and any one of the ledger servers 200a, 200b, and 200c will be referred to as ledger server 200. In addition, the houses 100a, 100b, and 100c will be referred to as houses 100a, etc., and the storage devices 201a, 201b, and 201c will be referred to as storage devices 201a, etc.
[0057] The ledger servers 200a, etc. are connected to the storage devices 201a, etc. The ledger servers 200a, etc. may be connected to the storage devices 201a, etc. via a communication network 500, or may include the storage devices 201a, etc. internally. The storage devices 201a, etc. have a distributed ledger in which transaction data and blocks of the blockchain are electronically recorded. At least one of the ledger servers 200a, 200b, and 200c is an example of an information processing device. The ledger servers 200a, 200b, and 200c form a ledger system (also referred to as a distributed ledger system). The ledger system manages a distributed ledger in which predetermined conditions (e.g., consent information, described below) for determining the control mode of an electrical device are recorded, for example.
[0058] 1 shows an example in which the information processing system 10 includes three homes and three ledger servers, but the number of homes and ledger servers is not limited to this. That is, the information processing system 10 may include one or more homes and one or more ledger servers. For example, the information processing system 10 may include four or more homes and four or more ledger servers, or one to two homes and one to two ledger servers.
[0059] [1-1. Configuration of the house 100a] The configuration of the house 100a will be described with reference to Fig. 2. Fig. 2 is a diagram showing an example of the overall configuration of the house 100a according to this embodiment. Note that the configurations of the houses 100b and 100c are similar to that of the house 100a, and therefore the following description will be given using the house 100a as an example.
[0060] 2, the home 100a includes a controller 101, a power meter 102, and electrical appliances 103a, 103b, and 103c, which are connected to each other via a power network 600 or a communication network 500. The power meter 102 is connected to the power network 600 outside the home 100a.
[0061] 2 shows an example in which the house 100a includes three electrical devices, but the number of electrical devices is not limited to this. That is, the house 100a may include one or more electrical devices. For example, the house 100a may include four or more electrical devices.
[0062] Here, the residence 100a etc. is an example of a building having power equipment used by a user, and is, for example, a house (residential facility) such as a residential home, but is not limited to this. The residence 100a etc. may also be a building (non-residential facility) such as a factory or office building. In other words, the form of the residence 100a etc. is not important as long as it is a building having power equipment used by a user.
[0063] <Controller 101> The controller 101 is, for example, a controller of an energy management system (EMS), and is an example of a controller that controls devices such as the electrical appliances 103a, 103b, and 103c. An example in which the controller 101 is a HEMS (Home Energy Management System) targeted at an ordinary home will be described, but the controller 101 may also be, for example, a BEMS (Building Energy Management System) targeted at an office building.
[0064] The controller 101 may also collect history information such as the operation history or manipulation history of the electrical appliances 103a, 103b, 103c, etc., or may collect measurement data obtained by measuring the appliances. Note that some of the functions of the controller 101 may be performed via an application on a smartphone or the like connected via the communication network 500. Hereinafter, the electrical appliances 103a, 103b, 103c will also be referred to as the electrical appliances 103a, etc.
[0065] Furthermore, the controller 101 may transmit collected data such as historical information and measurement data to the detection server 300 or the management server 400, or may transmit generated transaction data to the ledger server 200.
[0066] An example of the configuration of the controller 101 will now be described with reference to Fig. 3. Fig. 3 is a block diagram showing an example of the functional configuration of the controller 101 shown in Fig. 2.
[0067] The controller 101 includes a processor and a memory storing a program that causes the processor to execute a predetermined process. In other words, the controller 101 is realized by the processor executing the predetermined program using the memory. In this embodiment, the controller 101 includes an input unit 1011, a transaction data generation unit 1012, a control unit 1013, a recording unit 1014, and a communication unit 1015.
[0068] The input unit 1011 generates user consent information regarding data utilization. Here, the consent information is information indicating the content of the user's consent to the utilization of acquired or collected data, the control of the electrical appliances 103a, etc. using that data, and is generated based on the user's operation. The consent information may be generated, for example, by the user selecting or deselecting from a list of service providers to which data is provided or a data list provided by the input unit 1011. Furthermore, the consent information may be generated, for example, by the user selecting or deselecting from a list of control algorithms for the electrical appliances 103a, etc., a list of electrical appliances 103a, etc. that are permitted to be controlled, or a data list provided by the input unit 1011.
[0069] In this case, the consent information includes at least one of the service provider that can provide data to which the user has consented, the data or type of data that the user has consented to provide, the control algorithm that the user has consented to, and the type of electrical appliance 103a, etc. that the user has consented to being controlled. For example, the consent information includes at least one of the service provider that the user has consented to providing, the control algorithm, the type of electrical appliance 103a, etc. that the user has consented to being controlled, and the data or type of data. The consent information may further include information agreeing to providing the incentive or feedback when the incentive or feedback is equal to or greater than a certain level. The consent information may further include information (e.g., a threshold value) used for control mode determination. The information (e.g., a threshold value) used for control mode determination is an example of a first condition.
[0070] The input unit 1011 may also generate a smart contract based on the generated consent information. Here, the smart contract is an executable program that determines whether data can be provided or whether the electrical device 103a, etc. can be controlled. The consent information generated by the input unit 1011 may be included in this smart contract.
[0071] The input unit 1011 may be an application installed in the controller 101, in which case the installed application realizes the above-described functions of the input unit 1011. The input unit 1011 may also be an application installed in a smartphone or the like (not shown) connected via the communication network 500, in which case the installed application realizes the above-described functions of the input unit 1011.
[0072] The transaction data generation unit 1012 generates transaction data in a blockchain based on the user's consent information regarding data utilization received from the input unit 1011. For example, the transaction data generation unit 1012 generates transaction data including a blockchain address held by the user, at least one of the following included in the consent information: a service provider that can provide data that the user has consented to providing; data or types of data that the user has consented to providing; a control algorithm that the user has consented to; and types of electrical devices 103a that the user has consented to allowing control of; and a signature. An example of the data structure of the transaction data will be described later with reference to FIG. 12 .
[0073] The transaction data generation unit 1012 may further assign an identifier to the transaction data when generating the transaction data. The transaction data generation unit 1012 may generate a signature using a signature generation key individual to the user.
[0074] Furthermore, the transaction data generation unit 1012 may generate transaction data including the smart contract generated by the input unit 1011. Furthermore, the transaction data generation unit 1012 may generate transaction data including the consent information and the smart contract generated by the input unit 1011.
[0075] Furthermore, the transaction data generation unit 1012 may generate, as transaction data, information indicating data such as history information or measurement data collected by the control unit 1013. In this case, the transaction data generation unit 1012 may generate transaction data including, for example, a blockchain address held by the user, information indicating data collected by the control unit 1013, and a signature. Here, the information indicating the data may be the data itself acquired by the control unit 1013, a hash value of the data, or a hash value of the data and attribute information of the data. The attribute information of the data may include, for example, the type of the electrical device 103a or the like that collected the data. The information indicating the data may also include data items indicating when, how, and for which items the data was measured or collected, as well as the operation history or operation date and time of the electrical device 103a or the like.
[0076] When the consent information is updated, the transaction data generation unit 1012 records the generated transaction data in the recording unit 1014. The transaction data generation unit 1012 transmits the generated transaction data to at least one of the ledger servers 200a, etc., or the management server 400 via the communication unit 1015.
[0077] Note that the controller 101 is not limited to having the transaction data generation unit 1012. For example, another device such as the management server 400 may have some or all of the functions of the transaction data generation unit 1012. For example, the management server 400 may have the functions of the transaction data generation unit 1012. Data may be transmitted to the management server 400, and the management server 400 may generate transaction data on behalf of the user. In this case, the management server 400 may manage a signature generation key individual to each user.
[0078] The control unit 1013 controls the electrical appliances 103a and the like. In the example shown in FIG. 3 , the control unit 1013 operates the electrical appliances 103a and the like and manages their operation history, status, and the like. The control unit 1013 may also display the operation status of the electrical appliances 103a and the like on a display unit. The display unit may be a display included in the controller 101 or a display of an information terminal such as a smartphone owned by the user. For example, if the electrical appliances 103a and the like are heat pump water heaters, the control unit 1013 may display the operation status, hot water storage status, and the like on the display unit. For example, if the electrical appliances 103a and the like are solar power generators, the control unit 1013 may display the power generation status, and the like on the display unit. For example, if the electrical appliances 103a and the like are storage batteries, the control unit 1013 may display the power storage status, charge / discharge status, and the like on the display unit. For example, if the electrical appliances 103a and the like are electric vehicles, the control unit 1013 may display the connection status, charge / discharge status, and the like on the display unit. In this way, the control unit 1013 may display on the display unit an operating status specific to the electrical device 103a, etc. Furthermore, for example, if the electrical device 103a, etc. is a body composition monitor, a blood pressure monitor, etc., the control unit 1013 may display vital data. Furthermore, for example, the control unit 1013 may collect history information such as the operation history and manipulation history of the electrical device 103a, etc. Furthermore, for example, the control unit 1013 may collect measurement data measured by the electrical device 103a, etc.
[0079] The recording unit 1014 records information such as transaction data generated by the transaction data generation unit 1012. The recording unit 1014 may also record information such as consent information and smart contracts generated by the input unit 1011. The recording unit 1014 may also record data such as history information and measurement data collected by the control unit 1013.
[0080] The communication unit 1015 communicates with the ledger server 200a, etc. and the management server 400 via the communication network 500. The communication unit 1015 also communicates with the detection server 300 via the communication network 500 or the power network 600. This communication may be performed using TLS (Transport Layer Security). In this case, an encryption key for TLS communication may be held in the communication unit 1015. The communication unit 1015 may be configured to include, for example, a communication circuit (or a communication module).
[0081] 2 again, the power meter 102 measures the amount of power transmitted to the power network 600 or the amount of power received from the power network 600. When the power meter 102 transmits power to the power network 600 in response to a power transmission instruction from the controller 101, the power meter 102 measures the time and amount of power transmitted and notifies the controller 101. In response to a power usage instruction from the controller 101, the power meter 102 measures the amount of power received from the power network 600 and used. The power meter 102 may be included in the controller 101.
[0082] <Electrical Device 103a> The electrical devices 103b and 103c have the same configuration as the electrical device 103a, and therefore the electrical device 103a will be described below as an example.
[0083] The electrical appliances 103a, 103b, and 103c are connected to the controller 101 via the power network 600 or the communication network 500 and utilize electricity. The electrical appliance 103a is an electrical appliance that uses power and may be, for example, but is not limited to, a household electrical appliance. The electrical appliance 103a may be, for example, a body composition monitor, a blood pressure monitor, a heat pump water heater, a solar power generation system, a storage battery, an electric vehicle, or the like.
[0084] 4 is a block diagram showing an example of the functional configuration of the ledger server 200a according to this embodiment. Since the ledger servers 200b and 200c have the same configuration as the ledger server 200a, the ledger server 200a will be used as an example for explanation.
[0085] 4, the ledger server 200a includes a transaction data verification unit 211, a block generation unit 212, a synchronization unit 213, a smart contract execution unit 214, a recording unit 215, and a communication unit 216. The ledger server 200a can be realized by a processor using a memory to execute a predetermined program. Each component will be described below.
[0086] <Transaction Data Verification Unit 211> The transaction data verification unit 211 verifies received transaction data. Specifically, when transaction data is received from a device such as the home 100a, the transaction data verification unit 211 verifies whether the format of the transaction data is correct and whether the signature is valid. For example, when verifying transaction data that includes consent information, the transaction data verification unit 211 verifies whether the address, consent information, and signature included in the transaction data are valid. Furthermore, for example, when verifying transaction data that includes information indicating data, the transaction data verification unit 211 verifies whether the address, information indicating the data, and signature included in the transaction data are valid.
[0087] In this way, the transaction data verification unit 211 verifies the transaction data by checking the validity of the received transaction data. Furthermore, if the transaction data verification unit 211 confirms the validity of the transaction data as a result of the verification (if the transaction data is valid), it records the transaction data in the recording unit 215. Here, if the transaction data verification unit 211 determines that the transaction data is valid, it notifies the synchronization unit 213 of the transaction data.
[0088] <Block Generation Unit 212> If the transaction data verification unit 211 successfully verifies the transaction data, the block generation unit 212 executes a consensus algorithm for the transaction data among multiple ledger servers 200. Here, the consensus algorithm may be a consensus algorithm called PBFT (Practical Byzantine Fault Tolerance) or another well-known consensus algorithm such as PoW (Proof of Work). Furthermore, if the validity of the transaction data is verified by the consensus algorithm, the block generation unit 212 records a block including the transaction data in the distributed ledger in the storage device 201a of the ledger server 200a.
[0089] As described above, in this embodiment, the block generation unit 212 executes a consensus algorithm among the ledger servers 200a, 200b, and 200c. That is, the block generation unit 212 first generates a blockchain block including one or more transaction data. Next, the block generation unit 212 executes the consensus algorithm. Then, if consensus is reached by executing the consensus algorithm, the block generation unit 212 records the generated block in the recording unit 215. The block generated by the block generation unit 212 is connected to the blockchain recorded in the recording unit 215 and recorded.
[0090] Here, the data structure of the blockchain and the data structure of transaction data will be described with reference to Fig. 5. Fig. 5 is an explanatory diagram showing the data structure of the blockchain according to this embodiment. Fig. 5 shows blocks B1, B2, and B3 included in the blockchain.
[0091] As shown in Figure 5, a blockchain is a chain of blocks, which are its units of record. Each block contains multiple transaction data and the hash value of the immediately preceding block. Specifically, block B2 contains the hash value of the previous block B1. A hash value calculated from the multiple transaction data contained in block B2 and the hash value of block B1 is included in block B3 as the hash value of block B2. In this way, by connecting blocks in a chain while including the contents of the previous block as a hash value, tampering with the connected transaction data is effectively prevented.
[0092] If past transaction data is changed (in other words, tampered with), the hash value of the block containing that transaction data will be different from the value before the change, and to make the tampered block appear correct, all blocks after that block in the distributed ledger stored on multiple servers would have to be recreated, which is extremely difficult in reality. This feature makes it virtually impossible to tamper with transaction data contained in a blockchain.
[0093] When a node stores transaction data in a blockchain, it generates a block containing the transaction data to be stored and attempts to reach a consensus on the generated block by executing processing based on a consensus algorithm with other nodes. The node then controls the storage of the block in the blockchain once consensus is reached. This allows multiple nodes operating in an autonomous, decentralized manner to add legitimate blocks to the blockchain.
[0094] <Synchronization Unit 213> Referring again to Figure 4, the synchronization unit 213 synchronizes blockchain blocks or transaction data between multiple ledger servers (such as ledger server 200a). The synchronization units 213 of multiple ledger servers 200 synchronize blockchain transaction data on a peer-to-peer basis. The synchronization unit 213 then records the synchronized blockchain transaction data in the recording unit 215. For example, when the transaction data verification unit 211 verifies the validity of the transaction data, the synchronization unit 213 transfers the verified transaction data to other ledger servers 200, such as ledger servers 200b and 200c. Furthermore, when the synchronization unit 213 receives verified transaction data from another ledger server 200, it records the received verified transaction data in the recording unit 215.
[0095] <Smart Contract Execution Unit 214> The smart contract execution unit 214 stores smart contracts recorded in the distributed ledger in the working memory. The smart contract execution unit 214 executes the smart contracts stored in the working memory. For example, when transaction data including a data acquisition request is recorded in the distributed ledger, i.e., when a block including the transaction data is generated and recorded in the distributed ledger, the smart contract execution unit 214 stores a smart contract generated based on the user's consent information in the working memory. By executing the smart contract stored in the working memory, the smart contract can determine whether or not to provide the data. Furthermore, the executed smart contract notifies the result of the determination on whether or not to provide the data and grants access rights to the blockchain address included in the transaction data including the data acquisition request. In this way, the smart contract execution unit 214 executes the smart contract in response to access from the management server 400, thereby managing the management server 400's access to the data it holds.
[0096] Furthermore, for example, when transaction data including a data acquisition request is recorded in the distributed ledger, i.e., when a block including the transaction data is generated and recorded in the distributed ledger, the smart contract execution unit 214 stores in the working memory a smart contract generated based on the user's consent information. By executing the smart contract stored in the working memory, the smart contract execution unit 214 can also send a control request for the electrical appliance 103a, etc. to the house 100a, etc., and allow the user to decide whether or not to execute the control. Furthermore, the executed smart contract notifies the user of the results of the control request for the electrical appliance 103a, etc., the results of executing the control, etc., and grants access rights to the blockchain address included in the transaction data including the data acquisition request (e.g., a control data acquisition request).
[0097] Furthermore, for example, when transaction data including information regarding an incentive payment or feedback provision is recorded in the distributed ledger, the smart contract execution unit 214 stores in the working memory a smart contract generated based on the incentive payment or feedback provision. The smart contract execution unit 214 can execute the smart contract stored in the working memory to cause the executed smart contract to pay an incentive or provide feedback. The incentive payment or feedback provision may be a notification that the incentive payment or feedback provision has been made, or may be the incentive payment or feedback provision to the user.
[0098] <Recording Unit 215> The recording unit 215 includes transaction data in a block and records it in the distributed ledger of the ledger server 200a. The distributed ledger may be configured inside the recording unit 215 or inside an external storage device of the ledger server 200a. The transaction data includes transaction data received from the house 100a, etc.
[0099] In this embodiment, when the recording unit 215 confirms the authenticity of transaction data received from the device of the present disclosure, it records a block including the transaction data in the distributed ledger of the ledger server 200a. Note that the blockchain block recorded in the distributed ledger may be made public to the detection server 300, the management server 400, the house 100a, etc.
[0100] <Communication Unit 216> The communication unit 216 communicates with the house 100a etc., the ledger servers 200b and 200c, the detection server 300, and the management server 400. More specifically, the communication unit 216 is a communication interface that communicates with the house 100a etc., the ledger servers 200b and 200c, the detection server 300, and the management server 400. This communication may be performed using TLS. In this case, the encryption key for TLS communication may be stored in the communication unit 216.
[0101] 1-3. Configuration of Detection Server 300 FIG. 6 is a block diagram showing an example of the functional configuration of the detection server 300 according to this embodiment.
[0102] 6 , the detection server 300 includes a data management unit 311, a detection unit 312, a transaction data generation unit 313, a recording unit 314, and a communication unit 315. The detection server 300 can be realized by a processor using a memory to execute a predetermined program. Each component will be described below.
[0103] <Data management unit 311> The data management unit 311 manages data including information that serves as a basis for determining whether to control the devices. The data management unit 311 acquires data including information that serves as a basis for determining whether to control the devices from an external server (not shown) such as the house 100a. The data management unit 311 records the data including information that serves as a basis for determining whether to control the devices in the recording unit 314. The data management unit 311 transmits attribute information of the acquired data to the transaction data generation unit 313. Note that the attribute information of the data may include the sensor that collected the data, the type of device, the destination site, or the data item.
[0104] Furthermore, the data management unit 311 transmits data when it receives a data provision request from the management server 400. While the data provision request is described as being received from the management server 400, this is not limited thereto. The data management unit 311 may automatically (e.g., periodically) transmit collected data to the management server 400. Note that, in the case of user data acquired from the house 100a, etc., the user data may be provided based on consent information recorded in a distributed ledger such as the ledger server 200a. For example, assume that a smart contract generated based on consent information is executed in the ledger server 200a, etc., and the detection server 300 receives a notification from the ledger server 200a, etc. indicating that data provision is possible. In this case, the data management unit 311 provides the user's data when it receives a data provision request from the management server 400. Note that, the data management unit 311 may also receive, from the management server 400, a blockchain address corresponding to the data to be provided, along with the data provision request.
[0105] The data management unit 311 may also acquire, for example, information on the amount of power generated, information on local power usage, information on power outages, weather information, etc. from an external server (not shown) and manage this data. The data management unit 311 then transmits the information on the data acquired by the detection server 300 from the external server to the transaction data generation unit 313.
[0106] <Detection Unit 312> The detection unit 312 detects whether data including information used to determine whether or not a device should be controlled, acquired from the home 100a, the management server 400, an external server (not shown), or the like, satisfies conditions that may require device control. For example, the detection unit 312 detects whether the power pressure level is high based on the power pressure level acquired from the external server (not shown). In this case, the power pressure level may be acquired directly from the external server (not shown) or calculated from the amount of power generated and consumed in the home 100a. The power pressure level is an example of the degree of power pressure. The power pressure level may be indicated numerically or in multiple columns, such as "high," "medium," and "low." Furthermore, the detection unit 312 may detect, for example, that the warranty period for a device used by a user is approaching, based on information from the management server 400.
[0107] Here, the ledger server 200 makes the final decision on whether to control the device, and as a preliminary step, the detection unit 312 may collect data including information that can be used for the decision, and perform primary screening. The detection unit 312 records data including the detected content in the recording unit 314.
[0108] <Transaction Data Generation Unit 313> When the detection server 300 does not receive transaction data including information indicating the data from the house 100a, etc., but receives data attribute information from the data management unit 311 or the detection unit 312, the transaction data generation unit 313 generates transaction data including the data attribute information. The transaction data generation unit 313 records the generated transaction data in the recording unit 314. In addition, the transaction data generation unit 313 transmits the generated transaction data to the ledger server 200 via the communication unit 315.
[0109] <Recording unit 314> When data is acquired from a device disclosed herein, such as the house 100a, the recording unit 314 records the acquired data. The recording unit 314 also records the detection result of whether the data acquired by the detection server 300 satisfies a certain condition. When the transaction data generation unit 313 generates transaction data, the recording unit 314 records the transaction data.
[0110] <Communication Unit 315> The communication unit 315 communicates with the house 100a etc. via the communication network 500 or the power network 600, and communicates with the ledger server 200 and the management server 400 via the communication network 500. This communication may be performed using TLS. In this case, the encryption key for TLS communication may be held in the communication unit 315.
[0111] In this way, the detection server 300 detects whether data acquired from the house 100a, etc. is fraudulent data and records the data. Note that, in this embodiment, the detection server 300, the ledger server 200, and the management server 400 are described as independent servers, but this is not limited to this. All or part of the functions of the detection server 300 may be included in the ledger server 200 or the management server 400. In this case, the functions of the detection server 300 may be distributed between the ledger server 200 and the management server 400, or may be centralized in either the ledger server 200 or the management server 400.
[0112] 7 is a block diagram showing an example of the functional configuration of the management server 400 according to the present embodiment. The management server 400 is a server managed by a service provider to provide services, and is, for example, a server of a manufacturer or aggregator that manages HEMS.
[0113] 7, the management server 400 includes a data management unit 411, a user management unit 412, a transaction data generation unit 413, a recording unit 414, and a communication unit 415. In the management server 400, a processor can execute a predetermined program using memory. Each component will be described below.
[0114] <Data management unit 411> The data management unit 411 manages data including user information managed by the user management unit 412, and provides services by utilizing this data. For example, the data management unit 411 manages data acquired from the house 100a, etc., and utilizes this data to efficiently control devices, provide new device control methods, and demonstrate their effectiveness.
[0115] The data management unit 411 periodically acquires data from the controller 101 connected to the house 100a, etc., using user information managed by the user management unit 412. The data may be acquired periodically at a set time, or data acquisition request information indicating a request for data acquisition may be generated and the data may be acquired in response to that request. For example, when requested by the ledger server 200a, etc., the data management unit 411 may acquire data by transmitting the data acquisition request information to the house 100a, etc. The data management unit 411 manages the data acquisition request information and the data acquired thereby.
[0116] The data management unit 411 may also receive a request to control an appliance from the ledger server 200a, etc. When the data management unit 411 receives a request to control an appliance from the ledger server 200a, etc., the data management unit 411 transmits the request to control the appliance to the controller 101 of the house 100a, etc. via the communication network 500. The data management unit 411 may also manage data including the control algorithm of the appliance at that time, information on the request to control the appliance, etc.
[0117] <User Management Unit 412> The user management unit 412 acquires information on users who are to receive services from the house 100a and the like, and manages the acquired user information.
[0118] <Transaction Data Generation Unit 413> The transaction data generation unit 413 generates transaction data including data acquisition request information generated by the data management unit 411, information acquired from the house 100a, etc. The transaction data generation unit 413 generates transaction data including information related to data including the data acquisition request generated by the data management unit 411, the acquired data, a device control request, and a device control algorithm. The transaction data generation unit 413 may also generate transaction data including a smart contract generated by the data management unit 411.
[0119] <Recording Unit 414> The recording unit 414 records user information or service information required for providing a service. The recording unit 414 also records the transaction data generated by the transaction data generating unit 413.
[0120] <Communication Unit 415> The communication unit 415 communicates with the ledger server 200, the detection server 300, the house 100a, etc. via the communication network 500. This communication may be performed using TLS. In this case, the encryption key for TLS communication may be stored in the communication unit 415.
[0121] As a result, it is possible to realize an information processing system 10 that ensures transparency of device control rules (predetermined rules) for users and controls devices that use power in accordance with the status of a control request and the needs of the user, thereby increasing the user's trust, understanding, and satisfaction with the information processing system 10.
[0122] [2. Operation of Information Processing System] Next, the operation of the information processing system 10 configured as described above will be described with reference to FIGS. 8 to 11B. FIG. 8 is a sequence diagram showing the overall operation (information processing method) of the information processing system 10 according to this embodiment. FIG. 8 is a diagram showing the overall sequence of the information processing system 10. Note that, hereinafter, for convenience, a house will be referred to as house 100. House 100 refers to any one of houses 100a to 100c. Furthermore, the information processing method described below is a control method for controlling electrical appliances 103a and the like provided in house 100a.
[0123] As shown in FIG. 8, first, in step S100, consent information registration processing is performed between the house 100, the management server 400, the ledger server 200a, and the like.
[0124] Next, in step S200, data acquisition processing is performed between the house 100, the management server 400, the ledger server 200a, and the like.
[0125] Next, in step S300, control processing is performed among the house 100, the detection server 300, the management server 400, and the ledger servers 200a to 200c.
[0126] The control process of step S300 can be executed after the user's consent information is registered in the consent information registration process of step S100.
[0127] [2-1. Consent Information Registration Process] Next, the consent information registration process between the house 100, the management server 400, and the ledger server 200a, etc. will be described with reference to Fig. 9. Fig. 9 is a sequence diagram showing the overall operation (information processing method) of the consent information registration process shown in Fig. 8. Specifically, Fig. 9 is a sequence diagram showing the consent information registration process between the house 100, the management server 400, and the ledger server 200a, etc. according to this embodiment.
[0128] First, the home 100 generates consent information based on a user operation (S101). That is, the consent information includes information set by the user of the home 100. The consent information may be different for each home 100.
[0129] Here, the consent information may be generated by a user's input to an information terminal such as a smartphone. In this case, the consent information may be transmitted to management server 400 from the information terminal rather than from home 100. Alternatively, an application may be installed in home 100 (devices provided in home 100) as input unit 1011, and the application may generate the consent information based on a user's operation. In this case, the user can cause home 100 (devices provided in home 100) to generate consent information simply by instructing the input unit 1011 to select or deselect from the list of service providers to which data is provided, the list of control algorithms, the list of electrical devices 103a etc. that are permitted to be controlled, and the list of data.
[0130] The control algorithm referred to here includes, for example, an algorithm for performing at least one of the following when power is tight: controlling power consumption in order of increasing power consumption, controlling power consumption in order of decreasing power consumption of devices using less power, controlling power consumption in order of decreasing power consumption of devices using less power, and controlling power consumption in order of decreasing power consumption of devices using less power. For example, if an air conditioner is removed from the list of electrical devices 103a, etc., that are permitted to be controlled, and a control algorithm for uniform control is selected, even when power becomes tight, the air conditioner will not be controlled, and power consumption will be uniformly reduced starting from the electrical devices 103a, etc., that are permitted to be controlled other than the air conditioner. The control algorithm may also include an algorithm for controlling power consumption when power is tight, i.e., when there is a power surplus.
[0131] Although examples of control algorithms for automatically controlling the electrical appliances 103a, etc. have been described above, a control algorithm may also be included in which the user has the final decision-making power over whether to control the electrical appliances 103a, etc. For example, when power is somewhat tight, a notification may be sent to the house 100, and upon receiving the notification, the user may input a decision on whether to accept the instructed control. In this case, control of the electrical appliances 103a, etc. is executed only if the user gives permission. In other words, the entity having the final decision-making power (control power) over whether to control the electrical appliances 103a, etc. may be dynamically switched depending on the level of power tightness. For example, when the level of power tightness is moderate, the control power is given to the user, and when the level of power tightness is severe, the control power is not given to the user but is given to an energy management system (EMS). A medium level of power shortage is, for example, an example of the level of shortage being less than a predetermined level, and a high level of power shortage is, for example, an example of the level of shortage being equal to or greater than a predetermined level.
[0132] The control right means the right (decision-making right) to decide whether or not to control the electric appliances 103 a etc., when power is tight, etc. For example, the controller 101 etc. stores a management table that manages whether the control entity of the electric appliances 103 a etc. is the energy management system or the user, and when the control right is switched from the energy management system to the user, for example, the control entity of the electric appliances 103 a etc. in the management table is updated from the energy management system to the user. The condition for determining whether the energy management system or the user has the control right is an example of a first condition.
[0133] Furthermore, for example, in the case of a control algorithm that leaves the final decision-making power to the user, the incentives and feedback may be changed depending on the control algorithm, such as by reducing the incentives from the service provider.
[0134] In addition to when power is tight, a control algorithm may also be used when the manufacturer's warranty is about to expire. For example, such a control algorithm may include an algorithm for controlling and operating the electrical appliances 103 a, etc., when the manufacturer's warranty is about to expire, to determine whether the electrical appliances 103 a, etc. will operate normally before the manufacturer's warranty expires. The control algorithm may also include an algorithm for determining whether the electrical appliances 103 a, etc. will operate normally before a period when the frequency of use of the electrical appliances 103 a, etc. increases. For example, a control algorithm may also be used when summer is approaching. The control algorithm may include an algorithm for controlling and operating the electrical appliances 103 a, etc., when summer is approaching and no one is in the house 100, to determine whether the electrical appliances 103 a, etc. will operate normally by operating the air conditioner under predetermined conditions (e.g., at 18 degrees for 30 minutes).
[0135] Also, a control algorithm may be considered that performs control to reduce the overall price of electricity in conjunction with the market price of electricity presented in advance or in real time, a predicted market price, etc. Such a control algorithm may include, for example, an algorithm for controlling the charging of EV vehicles at night when the market price of electricity is predicted to be low at night.
[0136] The first condition may be, for example, a threshold value of the degree of power shortage in the case of power shortage, a remaining warranty period in the case of the manufacturer's warranty period, or a threshold value of the amount of change in market price in the case of the market price. Furthermore, such a first condition is included in the consent information.
[0137] When generating consent information for the home 100, the user may generate the consent information after having the user determine whether there is a lot of feedback from the service provider. For example, the user may determine the data provider and control algorithm to select based on feedback such as incentives, such as the provision of virtual currency or coupons or discounts from the service provider, if the user agrees to control using a certain control algorithm, information on the extent to which the user's consent will contribute to alleviating the power shortage, and information such as the number of people who have agreed to data utilization. Furthermore, the user may determine the data provider and control algorithm to select based on feedback provided to the user, such as the amount of virtual currency or coupon or discount to be provided if the user provides data to the service provider and agrees to control using a certain control algorithm. The feedback content may be made public by the service provider or may be recorded in the blockchain of the ledger server 200.
[0138] Next, the house 100 transmits the consent information generated in step S101 to the management server 400 (S102). For example, the communication unit 1015 transmits the consent information to the management server 400 via the communication network 500. The consent information may be transmitted from the controller 101 of the house 100 or from a terminal of the user of the house 100 (for example, a smartphone).
[0139] Next, the management server 400 acquires the consent information transmitted in step S102 (S103).
[0140] Next, the management server 400 generates a smart contract based on the consent information acquired in step S103 (S104). The smart contract here is an executable program that determines whether data can be provided and which control algorithm can control the device. This smart contract may include the consent information generated in step S101. Furthermore, this smart contract may include an executable program that determines whether to provide data or whether to execute a control algorithm when the feedback is above a certain level.
[0141] Next, the management server 400 generates transaction data (hereinafter also referred to as first transaction data) including the generated consent information and smart contract (S105).
[0142] 9, the home 100 transmits the consent information generated in step S101 to the management server 400. However, instead of transmitting the consent information, the home 100 may generate a smart contract and generate transaction data including the smart contract. That is, steps S104 and S105 may be executed by the home 100. When the home 100 generates transaction data including the smart contract, the transaction data may be transmitted directly to the ledger server 200.
[0143] Next, the management server 400 transmits the first transaction data generated in step S105 to the ledger server 200a (S106). Note that in the example shown in Fig. 9, the management server 400 transmits the generated first transaction data to the ledger server 200a, but even if the management server 400 transmits the generated first transaction data to the ledger server 200b or 200c, the subsequent processing is similarly executed in the ledger server.
[0144] Next, when the ledger server 200a acquires the first transaction data from the management server 400 (S107), it verifies the acquired first transaction data (S108).
[0145] Next, if the verification of the first transaction data is not successful (N in S108), the ledger server 200a sends a notification to that effect to the management server 400 (S109). Note that in the example shown in Fig. 9, the notification is sent to the management server 400, but the notification may also be sent to the house 100. Furthermore, when the house 100 sends the first transaction data, the ledger server 200a may send a notification to that effect only to the house 100.
[0146] On the other hand, if the ledger server 200a has successfully verified the first transaction data (Y in S108), it transfers the first transaction data to the other ledger servers 200 (ledger servers 200b and 200c) (S110). The other ledger servers 200 also verify the transferred first transaction data.
[0147] Next, the ledger servers 200a, 200b, and 200c execute a consensus algorithm (S111). When the ledger servers 200a, 200b, and 200c verify that the first transaction data is legitimate (i.e., validity), they each generate a block containing the first transaction data. Then, the ledger servers 200a, 200b, and 200c record the block containing the first transaction data in the distributed ledger.
[0148] In this way, the consent information entered by the house 100 and the smart contract based on it are recorded in the distributed ledger. The smart contract becomes executable once it is recorded in the distributed ledger. For example, once the smart contract is recorded in the distributed ledger, it is stored in the working memory of the ledger server 200a, etc., and becomes executable.
[0149] Next, the smart contract execution unit 214 runs the smart contract (S112). That is, the smart contract execution unit 214 starts executing the smart contract generated based on the consent information. The smart contract operates in accordance with rules (predetermined rules) based on the consent information. The rules include rules on how to control the electrical appliances 103a, etc. (control mode and control content of the electrical appliances 103a, etc.) depending on the degree of power shortage, the expiration date of the manufacturer's warranty of the electrical appliances 103a, etc. Note that the smart contract generated may differ for each house 100.
[0150] [2-2. Data Acquisition Process] Next, the data acquisition process between the house 100, the management server 400, and the ledger server 200a, etc. will be described with reference to FIG. 10. FIG. 10 is a sequence diagram showing the overall operation (information processing method) of the data acquisition process shown in FIG. 8. Specifically, FIG. 10 is a sequence diagram showing the data acquisition process between the house 100, the management server 400, and the ledger server 200a, etc. according to this embodiment. The example shown in FIG. 10 describes a case where the house 100 provides data requested by the management server 400 and registers the data in the ledger server 200. Furthermore, the operation shown in FIG. 10 is performed, for example, during execution of a smart contract by the smart contract execution unit 214.
[0151] 10 , first, when the management server 400 determines what data of the house 100 it wants to acquire, it determines a request to acquire the data (S201). For example, the management server 400 determines to acquire data. For example, when power is somewhat tight, it may determine to acquire data indicating the operating status of the electrical appliances 103a, etc., and determine a request to acquire the data. Note that the processing of the house 100 is executed by, for example, the controller 101.
[0152] Next, the management server 400 requests the house 100 to provide data (S202).
[0153] Next, the controller 101 of the house 100 receives a request for data provision from the management server 400 (S203).
[0154] Next, the controller 101 of the house 100 determines whether or not the data requested by the management server 400 can be provided, that is, whether or not the data provision is permitted (S204). If the controller 101 of the house 100 determines that the data cannot be provided (N in S204), it transmits a notification to that effect to the management server 400 (S205). Note that, in the example shown in Fig. 10, the determination of whether or not the data can be provided is made by the house 100, but the determination of whether or not the data can be provided may also be made within the management server 400 depending on the consent information input by the house 100.
[0155] Furthermore, when the controller 101 of the house 100 determines that it is possible to provide the data requested by the management server 400 (Y in S204), it transmits the requested data to the management server 400, i.e., provides the data to the management server 400 (S206). Note that in the example shown in FIG. 10 , the management server 400 transmits the data provision request directly to the house 100, but instead, the management server 400 may generate transaction data including a data acquisition request, transmit it to the ledger server 200, and request the house 100 to acquire the data via the smart contract generated in step S104. At that time, the data of the house 100 may be provided to the ledger server 200.
[0156] Next, when the management server 400 acquires the requested data from the house 100 (S207), it generates transaction data (hereinafter also referred to as second transaction data) from the acquired data, including the contents of the acquired data (S208).
[0157] Next, the management server 400 transmits the second transaction data generated in step S208 to the ledger server 200c (S209). Note that in the example shown in Fig. 10, the management server 400 transmits the generated second transaction data to the ledger server 200c, but it may also transmit it to the ledger servers 200a and 200b. Even if the data is transmitted to the ledger servers 200a and 200b, the subsequent processing is similarly executed in the ledger servers.
[0158] Next, when the ledger server 200c acquires the second transaction data from the management server 400 (S210), it verifies the acquired second transaction data (S211). In step S211, the ledger server 200c determines whether the verification of the second transaction data is successful.
[0159] If the verification of the second transaction data is not successful (N in S211), the ledger server 200c sends a notification to that effect to the management server 400 (S212).
[0160] On the other hand, if the ledger server 200c has successfully verified the second transaction data (Y in S211), it transfers the second transaction data to the other ledger servers 200 (ledger servers 200a and 200b) (S213). The other ledger servers 200 also verify the transferred second transaction data.
[0161] Next, the ledger servers 200a, 200b, and 200c execute a consensus algorithm (S214). When the ledger servers 200a, 200b, and 200c verify that the second transaction data is legitimate (i.e., validity), they each generate a block containing the second transaction data. Then, the ledger servers 200a, 200b, and 200c record the block containing the second transaction data in the distributed ledger.
[0162] As a result, the first transaction data and the second transaction data are centrally managed in the distributed ledger.
[0163] 11A and 11B , the control process between the house 100, the detection server 300, the management server 400, and the ledger server 200a, etc., will be described. FIGS. 11A and 11B are sequence diagrams showing the overall operation (information processing method) of the control process shown in FIG. 8 . Specifically, FIGS. 11A and 11B are sequence diagrams showing the control process between the house 100, the detection server 300, the management server 400, and the ledger server 200a, etc. In the example shown in FIGS. 11A and 11B , a smart contract running on the ledger server 200, etc., determines whether or not device control is necessary based on control determination information acquired by the detection server 300, and requests the house 100 to control the device via the management server 400. The control determination information includes information regarding the control of the electrical appliances 103a, etc.
[0164] As shown in FIG. 11A , first, the detection server 300 acquires control determination information necessary to determine whether to control the devices (S301). Here, the detection server 300 may acquire the necessary information from the house 100, the management server 400, or the like, or from an external server (not shown). The control determination information includes, for example, at least one of the following: the degree of power shortage calculated from the amount of power generated and the amount of power consumed, provided by the power company; the usage status of the electrical appliances 103a and the like in the house 100, provided based on the consent information; the remaining manufacturer's warranty period for the electrical appliances 103a and the like; fluctuations in the market price of electricity; weather; and season. For example, the control determination information may include at least one of the degree of power shortage, the remaining manufacturer's warranty period for the electrical appliances 103a and the like, and fluctuations in the market price of electricity. The detection server 300 acquires this various information via the communication network 500 or the power network 600.
[0165] Next, the detection server 300 transmits the control determination information acquired in step S301 to the management server 400 (S302).
[0166] Next, the management server 400 acquires the control determination information transmitted from the detection server 300 in step S302 (S303).
[0167] Next, the management server 400 generates transaction data (hereinafter also referred to as third transaction data) including the control decision information acquired in step S303 (S304).
[0168] Next, the management server 400 transmits the third transaction data generated in step S304 to the ledger server 200c (S305). Note that in the example shown in Fig. 11A, the management server 400 transmits the generated third transaction data to the ledger server 200c, but it may also transmit it to the ledger servers 200a and 200b. Even if the data is transmitted to the ledger servers 200a and 200b, the subsequent processing is similarly executed in the ledger servers.
[0169] Next, when the ledger server 200c acquires the third transaction data from the management server 400 (S306), it verifies the acquired third transaction data (S307). In step S307, the ledger server 200c determines whether the verification of the third transaction data was successful. Acquiring the third transaction data is an example of acquiring control determination information. In step S306, for example, a communication unit of the ledger server 200c acquires the third transaction data. The communication unit functions as an acquisition unit.
[0170] If the verification of the third transaction data is not successful (N in S307), the ledger server 200c sends a notification to that effect to the management server 400 (S308).
[0171] On the other hand, if the ledger server 200c has successfully verified the third transaction data (Y in S307), it transfers the third transaction data to the other ledger servers 200 (ledger servers 200a and 200b) (S309). The other ledger servers 200 also verify the transferred third transaction data.
[0172] Next, the ledger servers 200a, 200b, and 200c execute a consensus algorithm (S310). When the ledger servers 200a, 200b, and 200c verify that the third transaction data is valid (i.e., legitimacy), they each generate a block containing the third transaction data. Then, the ledger servers 200a, 200b, and 200c record the block containing the third transaction data in the distributed ledger. In this way, the third transaction data containing the control decision information sent by the management server 400 is recorded in the distributed ledger.
[0173] Next, the ledger server 200a, the ledger server 200b, and the ledger server 200c execute a smart contract related to the control of the devices recorded in the distributed ledger (S311). The smart contract here is generated based on the consent information, and by being recorded in the distributed ledger, it is stored in the working memory and executable. In this embodiment, the smart contract related to the control of the devices may control the electrical devices 103a, etc. of the house 100. The execution of the smart contract may determine, for example, whether the electrical devices 103a, etc. should be controlled in a first control mode or a second control mode described below. In this case, the consent information includes a first condition (i.e., a threshold value for determining whether the control should be in the first control mode or the second control mode). Step S311 is executed by a smart contract execution unit provided in each of the ledger servers 200a, 200b, and 200c. The smart contract execution unit functions as a determination unit.
[0174] Then, for example, if the smart contract of the ledger server 200c determines that control is necessary, it sends a control request notification to the management server 400 (S312). The control request notification is an example of information regarding control of the electrical device 103a, etc., in accordance with the determination result. Step S312 is executed via a communication unit of the ledger server 200c. The communication unit functions as an output unit.
[0175] Next, when the management server 400 receives the control request notification sent in step S312 (S313), it sends a request to control the equipment to the home determined to require or be capable of control (home 100 in the example shown in Figure 11A) (S314).
[0176] Next, the controller 101 of the house 100 acquires the control request sent from the management server 400 in step S314 (S315).
[0177] Next, the controller 101 of the house 100 determines whether or not it is possible to control the device requested by the management server 400, that is, whether or not it is permitted to control the device (S316). The controller 101, for example, compares the stored consent information with the acquired control request, and determines that control of the device is permitted if the consent information indicates that the contents of the control request are permitted, and determines that control of the device is not permitted if the consent information does not indicate that the contents of the control request are permitted, or if the consent information indicates that the contents of the control request are prohibited. If the controller 101 of the house 100 determines that it is not possible to control the device requested by the management server 400 (N in S316), it sends a notification to that effect to the management server 400 (S317).
[0178] On the other hand, if the controller 101 of the home 100 determines that it is possible to control the appliances requested by the management server 400 (Y in S316), it executes (executes control of) the requested control of the electrical appliances 103 a, etc. in the home 100 (S318). Here, the controller 101 grants control authority to the energy management system of the home 100 or the user, depending on the content determined by the management server 400 based on the consent information. When the control authority is granted to the energy management system (i.e., when operating in the first control mode), control of the electrical appliances 103 a, etc. is executed in accordance with rules predetermined based on the consent information, etc. In other words, in the first control mode, the energy management system automatically controls the electrical appliances 103 a, etc. based on predetermined rules.
[0179] Furthermore, when the user is given control rights (i.e., when operating in the second control mode), a control request is made to the user in accordance with predetermined rules based on consent information, etc. When a control request is made, the user selects whether or not to control the device. The selection may be made via the controller 101 or by directly operating the device. The predetermined rules here are an example of predetermined second conditions, and include conditions (e.g., part of the consent information) previously set by the user of the home 100.
[0180] For example, the first condition may include a condition indicating that, when the control determination information includes information regarding the degree of power pressure, the control mode is set to the second control mode when the degree of power pressure is less than a predetermined level, and that the control mode is set to the first control mode when the degree of power pressure is equal to or greater than the predetermined level. In this case, for example, in the first control mode, at least one of the following is automatically executed by the energy management system: control to reduce power consumption of the multiple electrical appliances 103a, etc., starting with the most power-consuming electrical appliance; control to reduce power consumption of the multiple electrical appliances 103a, etc., starting with the least frequently used electrical appliance; control to evenly reduce power consumption of the multiple electrical appliances 103a, etc.; and control to consume more power when there is a power surplus. In this case, for example, in the second control mode, a notification is presented to the user to determine whether to execute at least one of the control operations, and if the user gives permission, the control of the electrical appliances 103a, etc. is executed with the control content permitted.
[0181] Furthermore, for example, the first condition may include a condition indicating that, when the control determination information includes information regarding the expiration date of a manufacturer's warranty of the electrical appliance 103a, etc., the control mode should be set to the first control mode when the remaining time until the manufacturer's warranty expiration is less than a predetermined period, and the control mode should be set to the second control mode when the remaining time is equal to or greater than the predetermined period. In this case, for example, in the first control mode, control to determine whether the electrical appliance 103a, etc. will operate normally before the expiration of the manufacturer's warranty of the electrical appliance 103a, etc. (e.g., forced operation of the electrical appliance 103a, etc.) is automatically executed by control of the energy management system. In this case, for example, in the second control mode, a notification is presented to the user to allow the user to determine whether to execute an operation to determine whether the electrical appliance 103a, etc. will operate normally, and if the user permits the control, control of the electrical appliance 103a, etc. is executed with the permitted control content.
[0182] Furthermore, for example, the first condition may include a condition indicating that, when the control determination information includes information regarding the market price of electricity, the control mode should be set to the second control mode when a change in the market price is less than a predetermined amount, and that the control mode should be set to the first control mode when the change is equal to or greater than the predetermined amount. In this case, for example, in the first control mode, the energy management system automatically controls the electrical appliances 103 a, etc. so that the electrical appliances 103 a, etc. consume power during a time period predicted to be relatively low. If the electrical appliances 103 a, etc. are storage batteries (or electric vehicles) and the time period predicted to be relatively low in the market price is nighttime, the energy management system controls the storage batteries (or electric vehicles) to charge at night.
[0183] In this case, for example, in the second control mode, a notification is presented to the user to prompt the user to determine whether or not to operate the electrical appliance 103 a, etc. (to consume power) during a time period predicted to be relatively low in market prices, and if the user gives permission, the electrical appliance 103 a, etc. is controlled according to the permitted control content. If the electrical appliance 103 a, etc. is a storage battery (or an electric vehicle) and the time period predicted to be relatively low in market prices is nighttime, the notification includes a notification to prompt the user to determine whether or not to control the storage battery (or electric vehicle) to charge during nighttime.
[0184] In step S311, the smart contract of the ledger server 200c may determine whether to control the electrical appliances 103a, etc. in a first control mode in which the energy management system installed in the house 100 controls the electrical appliances 103a, etc., or in a second control mode in which the user of the house 100 controls the electrical appliances 103a, etc., based on the control determination information and a predetermined rule. The smart contract of the ledger server 200c may determine whether to set the control mode of the electrical appliances 103a, etc. to the first control mode or the second control mode, based on, for example, the control determination information and the first condition.
[0185] In this way, when the smart contract is executed and it is determined that the electric appliances 103 a, etc. need to be controlled, the energy management system controls the electric appliances 103 a, etc. so that they are not uniformly controlled. For example, if the urgency is low, the second control mode is selected, and if the urgency is high, the first control mode is selected. Low urgency may mean, for example, that the degree of urgency is less than a predetermined threshold, and high urgency may mean, for example, that the degree of urgency is equal to or greater than a predetermined threshold.
[0186] Note that, in the example shown in FIG. 11A , the control request notification obtained by executing the smart contract is transmitted to the house 100 via the management server 400, but this is not limited thereto. For example, the ledger server 200 may transmit the control request notification directly to the house 100 without via the management server 400. Furthermore, for example, the ledger server 200 may transmit the control request notification directly to an information terminal such as a smartphone owned by the user without via the management server 400. In this case, permission to execute control in step S316 may be determined based on whether a user operation permitting control execution on the information terminal has been acquired. Furthermore, control execution may be remotely executed by, for example, the management server 400. In this case, permission to execute control in step S316 may be determined based on whether information indicating permission to execute control has been acquired from the management server 400.
[0187] Here, for example, management server 400 acquires the execution result of control of electrical appliance 103a, etc. For example, when management server 400 acquires a notification from controller 101 in step S317 indicating that it has been determined that device control is not possible, management server 400 acquires an execution result indicating that control is not possible. Furthermore, for example, when management server 400 does not acquire the notification of step S317 within a predetermined time after sending the control request in step S314, management server 400 determines that control of electrical appliance 103a, etc. has been executed, thereby acquiring an execution result indicating that control has been executed.
[0188] As shown in FIG. 11B, next, upon acquiring the execution results, the management server 400 generates transaction data (hereinafter also referred to as fourth transaction data) including the acquired execution results (S319).
[0189] Next, the management server 400 transmits the fourth transaction data generated in step S319 to the ledger server 200c (S320). Note that in the example shown in Fig. 11B, the management server 400 transmits the generated fourth transaction data to the ledger server 200c, but it may also transmit it to the ledger servers 200a and 200b. Even if the data is transmitted to the ledger servers 200a and 200b, the subsequent processing is similarly executed in the ledger servers.
[0190] Next, when the ledger server 200c acquires the fourth transaction data from the management server 400 (S321), the ledger server 200c verifies the acquired fourth transaction data (S322). In step S322, the ledger server 200c determines whether the verification of the fourth transaction data is successful.
[0191] If the verification of the fourth transaction data is not successful (N in S322), the ledger server 200c sends a notification to that effect to the management server 400 (S323).
[0192] On the other hand, if the ledger server 200c has successfully verified the fourth transaction data (Y in S322), it transfers the fourth transaction data to other ledger servers 200 (here, ledger servers 200a and 200b) (S324). The other ledger servers 200 also verify the transferred fourth transaction data.
[0193] 11B, the ledger servers 200a, 200b, and 200c then execute a consensus algorithm. After verifying that the fourth transaction data is legitimate (i.e., validity), the ledger servers 200a, 200b, and 200c each generate a block containing the fourth transaction data. The ledger servers 200a, 200b, and 200c then record the block containing the fourth transaction data in the distributed ledger.
[0194] In this way, the ledger server 200a etc. may record the execution results of the control of the electric devices 103a etc. in the distributed ledger. This allows the history of who (subject) performed what control (control content of the electric devices 103a etc.) and what the execution results were at that time to be recorded while preventing tampering. This improves the transparency of the control history of the electric devices 103a etc.
[0195] [3. Description of the Distributed Ledger System] The ledger system described above will be described with reference to FIGS. 12 to 14.
[0196] A distributed ledger system is a system that stores and maintains information using P2P (peer-to-peer) network technology connected to multiple nodes. A node is an information processing device that performs predetermined processing by using a processor (e.g., a CPU) to execute a program using memory.
[0197] In a distributed ledger system, multiple nodes autonomously hold copies of information and keep them synchronized. This allows the system to properly store information while substantially preventing tampering, without using a privileged node (e.g., a centralized server or a server in a client-server model).
[0198] Furthermore, a device attempting to access the distributed ledger only needs to access one of the multiple nodes included in the distributed ledger system; in other words, there is no need to access a small number of devices, such as a centralized server. This avoids the concentration of communication or processing load on the centralized server, which can occur in a centralized system. This has the advantage that nodes do not require particularly high specifications for their resources (CPU, memory, etc.), and that communication lines connecting the nodes do not require particularly large communication capacities. This allows the distributed ledger system to be configured using general (or general-purpose) nodes or communication lines, which can contribute to reducing the required computer or communication resources and the costs required for nodes and communication lines.
[0199] Furthermore, a distributed ledger system can store information with high fault tolerance and can also access information with high fault tolerance. Generally, the multiple nodes included in a distributed ledger system are physically or network-distributedly located. If all of the multiple nodes included in a distributed ledger system stop, the distributed ledger system will stop. However, since it is rare for all of the multiple nodes that are physically or network-distributedly located to stop, the distributed ledger system rarely stops. This can be said to be an advantage over a centralized system, where if a centralized server stops, information cannot be stored or accessed.
[0200] FIG. 12 is an explanatory diagram showing the data structure of the transaction data.
[0201] 12 includes a transaction body BP1 and a digital signature BP2 (also simply referred to as a signature). The transaction body BP1 is the data body included in the transaction data. The digital signature BP2 is generated by encrypting the hash value of the transaction body BP1 with the signature key (in other words, the private key) of the creator of the transaction data.
[0202] A node that receives transaction data can verify that the transaction body BP1 is legitimate (in other words, that it has not been tampered with) using the digital signature BP2 included in the transaction data. This makes it virtually impossible to tamper with the data included in the transaction body BP1. Furthermore, by storing successfully verified transaction data in the blockchain, the legitimacy of the transaction data stored in the blockchain can be maintained.
[0203] As described above, transaction data included in the blockchain is stored in a chain using the hash value of the transaction data and the hash value of the block. This allows the transaction data included in the blockchain to be stored and maintained substantially without being tampered with. This is an advantage over a database or a distributed database that simply stores a collection of data.
[0204] 13 and 14 are explanatory diagrams showing transaction data related to the execution of a smart contract, and processing related to the execution of a smart contract, respectively.
[0205] A series of processes related to the execution of a smart contract using a distributed ledger will be described with reference to Figures 13 and 14.
[0206] In step SB1, the node stores transaction data B11, including contract code B12 that describes the processing of the smart contract, in the distributed ledger B10. For example, the node acquires transaction data B11 by receiving the transaction data B11 from an information processing device via communication or by the node itself generating the transaction data B11, and stores the acquired transaction data B11 in the distributed ledger B10. Step SB1 is performed before executing the smart contract.
[0207] In step SB2, the node stores transaction data B15, including instructions B16 for executing the smart contract, in the distributed ledger B10. For example, the node receives transaction data B15 from an information processing device via communication and stores the received transaction data B15 in the distributed ledger B10.
[0208] In step SB3, in response to the transaction data B15 including the instruction B16 being stored in the distributed ledger B10 in step SB2, the node reads the contract code B12 from the distributed ledger B10 and executes processing based on the contract code B12. The results of the processing may be included in the transaction data and stored in the distributed ledger B10.
[0209] Through the above series of processes, when the distributed ledger system receives transaction data B15 including instructions B16 for executing a smart contract, it automatically (i.e., without manual intervention) executes the processing in accordance with the instructions B16, enabling highly efficient (i.e., high speed or short processing time). Achieving highly efficient processing has the effect of reducing power consumption. Furthermore, since no manual intervention is required, it is possible to prevent human tampering with information, fraud, or human error. Furthermore, since the results of the processing thus executed are stored in the blockchain, it is virtually impossible to tamper with the results of the processing.
[0210] (Other Embodiments) While the information processing method according to one or more aspects has been described above based on the embodiments, the present disclosure is not limited to these embodiments. As long as it does not deviate from the spirit of the present disclosure, various modifications conceivable by a person skilled in the art to the present embodiments and embodiments constructed by combining components of different embodiments may also be included in the present disclosure.
[0211] (1) In the above embodiment, a blockchain is used, but it is not necessary to use a blockchain. Furthermore, instead of a blockchain, a distributed ledger technology such as a hash graph may be used.
[0212] (2) In the above embodiment, the detection server 300 and the management server 400 are described as separate devices, but this is not limited to this. The detection server 300 and the management server 400 may be the same device. Furthermore, the ledger server 200 and the management server 400 may be the same device.
[0213] (3) Some or all of the processes executed in the distributed ledger system in the above embodiments may be executed by another information processing device, such as the management server 400. For example, the management server 400 may execute at least one of acquiring control determination information (e.g., S303), determining the control mode, and outputting information related to the control of the electrical devices 103a, etc. (e.g., S314). Determining the control mode may be executed based on, for example, consent information and the control determination information. In this case, the management server 400 is an example of an information processing device.
[0214] (4) In the above embodiment, two control modes, the first control mode and the second control mode, are illustrated. However, the number of control modes is not limited to two and may be three or more. For example, if the degree of power pressure is divided into three levels, namely, "high," "medium," and "low," a different control mode may be determined for each level. For example, the third control mode may be a control mode in which the electrical appliances 103a, etc. are controlled with control content intermediate between the control content determined by the energy management system and the control content determined by the user, or may be a control mode in which the electrical appliances 103a, etc. are controlled with other control content.
[0215] (5) In the above embodiment, an example was described in which both the judgment result based on the first condition and the execution result of control of electrical equipment 103a, etc. were recorded in the distributed ledger, but it is sufficient if at least one of the judgment result and the execution result is recorded in the distributed ledger.
[0216] (6) Each device in the above embodiments is specifically a computer system comprising a microprocessor, ROM (Read Only Memory), RAM (Random Access Memory), a hard disk unit, a display unit, a keyboard, a mouse, etc. A computer program is recorded in the RAM or hard disk unit. Each device achieves its function when the microprocessor operates in accordance with the computer program. Here, a computer program is composed of a combination of multiple instruction codes that indicate instructions to a computer to achieve a predetermined function.
[0217] (7) In each of the above embodiments, some or all of the constituent elements may be configured from a single LSI (Large Scale Integration). A system LSI is an ultra-multifunctional LSI manufactured by integrating multiple components on a single chip, and specifically, is a computer system configured to include a microprocessor, ROM, RAM, etc. A computer program is stored in the RAM. The system LSI achieves its functions when the microprocessor operates in accordance with the computer program.
[0218] Furthermore, each of the components constituting each of the above-described devices may be individually integrated into a single chip, or some or all of them may be integrated into a single chip.
[0219] Although the term "system LSI" is used here, it may also be called an IC, LSI, super LSI, or ultra LSI depending on the level of integration. Furthermore, the method of integration is not limited to LSI, and may be realized using a dedicated circuit or a general-purpose processor. It is also possible to use a field programmable gate array (FPGA), which can be programmed after LSI manufacturing, or a reconfigurable processor, which allows the connections and settings of circuit cells within the LSI to be reconfigured.
[0220] Furthermore, if an integrated circuit technology that can replace LSI emerges due to advances in semiconductor technology or other derivative technologies, it is natural that such technology may be used to integrate functional blocks. The application of biotechnology, etc. is also a possibility.
[0221] (8) Some or all of the components constituting each of the above devices may be configured as an IC card or a standalone module that can be attached to each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-mentioned ultra-multifunctional LSI. The IC card or module achieves its functions when the microprocessor operates according to a computer program. This IC card or module may be tamper-resistant.
[0222] (9) The present disclosure may be embodied as the methods described above. Furthermore, the present disclosure may be embodied as a computer program that implements these methods on a computer, or as a digital signal comprising the computer program. For example, one aspect of the present disclosure may be a computer program that causes a computer to execute each of the characteristic steps included in the information processing methods shown in any of Figures 8 to 11B.
[0223] The present disclosure may also be a computer program or a digital signal recorded on a computer-readable recording medium, such as a flexible disk, a hard disk, a CD-ROM, an MO, a DVD, a DVD-ROM, a DVD-RAM, a BD (Blu-ray (registered trademark) Disc), a semiconductor memory, etc. Alternatively, the present disclosure may be a digital signal recorded on such a recording medium.
[0224] The present disclosure may also be applied to transmitting a computer program or digital signal via a telecommunications line, a wireless or wired communication line, a network such as the Internet, data broadcasting, or the like.
[0225] The present disclosure may also be a computer system having a microprocessor and a memory, the memory storing the computer program, and the microprocessor operating in accordance with the computer program.
[0226] Furthermore, the program or digital signal may be recorded on a recording medium and transferred, or the program or digital signal may be transferred via a network or the like, so that the program or digital signal can be implemented by another independent computer system.
[0227] (10) In the above embodiments, each component may be configured with dedicated hardware, or may be realized by executing a software program suitable for each component. Each component may be realized by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0228] (11) The order in which each step in the flowchart is executed is merely an example for specifically explaining the present disclosure, and an order other than the above may be used. Also, some of the steps may be executed simultaneously (in parallel) with other steps, or some of the steps may not be executed.
[0229] (12) The division of functional blocks in the block diagram is an example, and multiple functional blocks may be realized as a single functional block, one functional block may be divided into multiple blocks, or some functions may be moved to another functional block. Furthermore, the functions of multiple functional blocks having similar functions may be processed in parallel or time-shared by a single piece of hardware or software.
[0230] (13) Furthermore, each of the ledger server and management server according to the above embodiments may be realized as a single device or may be realized by multiple devices. When at least one of the ledger server and management server is realized by multiple devices, the components of the at least one device may be distributed in any manner among the multiple devices. When at least one of the devices is realized by multiple devices, the communication method between the multiple devices is not particularly limited and may be wireless communication or wired communication. Furthermore, wireless communication and wired communication may be combined between the devices.
[0231] (14) The above-described embodiments and modifications may be combined with each other.
[0232] (15) One aspect of the present disclosure can be utilized in an information processing device, an information processing method, and a program for a device that ensures transparency, for example, by automatically controlling appliances in a home under certain conditions using a smart contract generated based on user consent information.
[0233] The present disclosure is useful for an information processing device or the like that controls electrical equipment in a facility such as a home.
[0234] 10 Information processing system 100, 100a, 100b, 100c House 101 Controller 102 Power meter 103a, 103b, 103c Electrical equipment 200, 200a, 200b, 200c Ledger server 201a, 201b, 201c Storage device 211 Transaction data verification unit 212 Block generation unit 213 Synchronization unit 214 Smart contract execution unit 215, 314, 414, 1014 Recording unit 216, 315, 415, 1015 Communication unit 300 Detection server 311, 411 Data management unit 312 Detection unit 313, 413, 1012 Transaction data generation unit 400 Management server 412 User management unit 500 Communication network 600 Power network 1011 Input unit 1013 Control unit
Claims
1. An information processing method for controlling electrical equipment installed in a facility, comprising: acquiring control decision information regarding the control of the electrical equipment; determining, based on the control decision information and a predetermined first condition, whether the electrical equipment will be controlled in a first control mode in which an energy management system capable of controlling the electrical equipment controls the electrical equipment, or a second control mode in which a user of the facility controls the electrical equipment; and outputting information regarding the control of the electrical equipment according to the decision result.
2. The information processing method according to claim 1, wherein in the first control mode, the energy management system automatically controls the electrical equipment based on a predetermined second condition.
3. The information processing method according to claim 2, wherein the second condition includes a condition set in advance by the user.
4. An information processing method according to any one of claims 1 to 3, comprising acquiring transaction data including at least one of a judgment result based on the first condition and a result of executing control of the electrical device, and recording the acquired transaction data in a distributed ledger.
5. An information processing method according to any one of claims 1 to 3, comprising: acquiring transaction data including consent information set by the user; recording the acquired transaction data in a distributed ledger; and the consent information including the first condition.
6. An information processing method according to any one of claims 1 to 3, wherein the control mode of the electrical device is determined using a smart contract based on the control determination information and the first condition.
7. An information processing method according to any one of claims 1 to 3, wherein the control decision information includes at least one of the degree of power shortage, the expiration date of the manufacturer's warranty for the electrical equipment, and fluctuations in the market price of power.
8. An information processing method according to any one of claims 1 to 3, wherein the first condition includes a condition indicating that, when the control judgment information includes information regarding the degree of power shortage, the control mode is set to the second control mode when the degree of shortage is less than a predetermined degree, and the control mode is set to the first control mode when the degree of shortage is equal to or greater than the predetermined degree.
9. The information processing method according to claim 8, wherein the facility is provided with a plurality of the electrical devices, and in the first control mode, at least one of the following is automatically executed: control to reduce power consumption of the plurality of electrical devices in descending order of power consumption, control to reduce power consumption of the plurality of electrical devices in descending order of power consumption, control to reduce power consumption of the plurality of electrical devices in descending order of power use, control to reduce power consumption of the plurality of electrical devices evenly, and control to consume more power when there is a power surplus.
10. An information processing method according to any one of claims 1 to 3, wherein the first condition includes a condition indicating that, when the control judgment information includes information relating to the expiration date of the manufacturer's warranty of the electrical equipment, the control mode is set to the first control mode when the remaining period until the expiration date of the manufacturer's warranty is less than a predetermined period, and the control mode is set to the second control mode when the remaining period is equal to or greater than the predetermined period.
11. The information processing method according to claim 10, wherein in the first control mode, control is automatically executed to determine whether the electrical device will operate normally before the expiration of the manufacturer's warranty period for the electrical device.
12. An information processing method according to any one of claims 1 to 3, wherein the first condition includes a condition indicating that, when the control decision information includes information regarding the market price of electricity, the control mode is set to the second control mode when the amount of change in the market price is less than a predetermined amount, and the control mode is set to the first control mode when the amount of change is equal to or greater than the predetermined amount.
13. The information processing method according to claim 12, wherein in the first control mode, the electrical appliance is automatically controlled so that the electrical appliance consumes power during a time period when the market price is predicted to be relatively low.
14. The information processing method according to claim 13, wherein, when the electrical device is a storage battery and the time period during which the market price is relatively low is predicted to be nighttime, the first control mode controls the storage battery to charge at nighttime.
15. An information processing device that controls electrical equipment installed in a facility, comprising: an acquisition unit that acquires control decision information regarding the control of the electrical equipment; a determination unit that determines, based on the control decision information and a predetermined first condition, whether the electrical equipment should be controlled in a first control mode in which an energy management system capable of controlling the electrical equipment controls the electrical equipment, or a second control mode in which a user of the facility controls the electrical equipment; and an output unit that outputs information regarding the control of the electrical equipment according to the determination result.
16. A program for causing a computer to execute the information processing method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Electric power demand adjustment system and electric power demand adjustment device
JP2013090389A
Power management device, power management system, power management method, and program
JP2021197788A
Power control device, power control method, and power control program
WO2016084391A1
Data management method, data management system, and program
WO2020122039A1