Information processing device, information processing system, information processing method, and program

WO2026159968A1PCT designated stage Publication Date: 2026-07-30PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
Filing Date
2025-10-23
Publication Date
2026-07-30

Smart Images

  • Figure JP2025037312_30072026_PF_FP_ABST
    Figure JP2025037312_30072026_PF_FP_ABST
Patent Text Reader

Abstract

An information processing device according to the present disclosure comprises at least one processor. The at least one processor: manages a reservation for use of a charging spot relating to a mobile object configured to enable an onboard battery to be externally charged; acquires a notification about electric power status of a target electric power system from at least one of aggregator servers, each of which adjusts a supply-demand balance of electric power of the target electric power system supplying electric power to at least one charging spot among a plurality of charging spots; detects a cyberattack on the own device, on the basis of the notification about electric power status; determines, when the cyberattack on the own device is detected, an alert level according to the expansion status of the detected cyberattack; and generates and outputs display information for displaying an attack alert of the determined alert level.
Need to check novelty before this filing date? Find Prior Art

Description

Information Processing Apparatus, Information Processing System, Information Processing Method, and Program

[0001] The present disclosure relates to an information processing apparatus, an information processing system, an information processing method, and a program.

[0002] In recent years, with the spread of electric vehicles (EVs), the installation of EV charging spots that supply power to EVs using power from the power grid has been progressing.

[0003] For example, Patent Document 1 discloses a technology related to a charging reservation system that makes a charging reservation for an EV in response to an inquiry from a user terminal used by an EV user.

[0004] Japanese Unexamined Patent Application Publication No. 2021 - 174181

[0005] However, when a cyber - attack occurs against a charging reservation system such as a server or an EV that manages charging reservations, if the situation of the cyber - attack, such as its scale and damage, cannot be appropriately grasped, there is a risk that EV users will be unable to charge at charging spots.

[0006] The present disclosure has been made in view of the above, and one of its purposes is to easily grasp the situation of cyber - attacks against a charging reservation system.

[0007] The information processing apparatus according to the present disclosure includes at least one processor. The at least one processor manages a reservation for using a charging spot for a moving body configured to be externally charged to a mounted battery, obtains a notification of the power situation of a target power grid from at least one aggregator server that adjusts the power supply - demand balance of the power in the target power grid that supplies power to at least one of a plurality of charging spots, detects a cyber - attack against the self - device based on the notification of the power situation, and when a cyber - attack against the self - device is detected, determines an alert level according to the expansion situation of the detected cyber - attack, and generates and outputs display information for displaying an attack alert at the determined alert level.

[0008] Figure 1 is a diagram showing an example of the configuration of a charging reservation system according to the embodiment. Figure 2 is a diagram showing an example of the hardware configuration of an information processing device that realizes each device of the charging reservation system according to the embodiment. Figure 3 is a flowchart showing an example of the flow of information processing performed by the charging reservation server according to the embodiment. Figure 4 is a flowchart showing an example of the flow of information processing performed by the EV according to the embodiment. Figure 5 is a flowchart showing an example of the flow of server-side attack detection processing and GUI display processing performed by the charging reservation server according to the embodiment. Figure 6 is a flowchart showing an example of the flow of EV-side attack detection processing and GUI display processing performed by the EV according to the embodiment. Figure 7 is a diagram showing an example of screen display in the GUI display processing according to the embodiment. Figure 8 is a diagram showing an example of screen display in the GUI display processing according to the embodiment. Figure 9 is a diagram showing an example of screen display in the GUI display processing according to the embodiment. Figure 10 is a diagram showing an example of screen display in the GUI display processing according to the embodiment.

[0009] Hereinafter, embodiments of the information processing method, information processing apparatus, information processing system, program, and recording medium related to this disclosure will be described with reference to the drawings.

[0010] In this disclosure, components having the same or substantially the same function as those described above in previously shown drawings are denoted by the same reference numerals, and explanations may be omitted as appropriate. Furthermore, even when representing the same or substantially the same parts, the dimensions and proportions may be shown differently in different drawings. In addition, for example, from the viewpoint of ensuring the readability of the drawings, reference numerals may be assigned only to the main components in the explanation of each drawing, and reference numerals may not be assigned to components having the same or substantially the same function as those described above in previously shown drawings.

[0011] In addition, in the descriptions of this disclosure, components having the same or substantially the same function may be distinguished by adding alphanumeric characters and / or symbols to the end of the reference numeral. Alternatively, if multiple components having the same or substantially the same function are not to be distinguished, they may be described together by omitting the alphanumeric characters and / or symbols to the end of the reference numeral.

[0012] Figure 1 shows an example of the configuration of a charging reservation system 1 according to an embodiment. As shown in Figure 1, the charging reservation system 1 includes a power generation company server 2, an aggregator server 3, a charging service provider server 4, a plurality of EV spots 45, a charging reservation server 6, and an EV 7.

[0013] Here, the charging reservation system 1 according to this embodiment is an example of the information processing system of this disclosure. Note that the power generator server 2, aggregator server 3, charging service provider server 4, and the multiple EV spots 45 may be implemented as external components to the charging reservation system 1.

[0014] Furthermore, at least two of the power generation operator server 2, aggregator server 3, charging service provider server 4, and charging reservation server 6 may be integrated and implemented as a single device. In other words, the power generation operator server 2, aggregator server 3, charging service provider server 4, and charging reservation server 6 may each be operated by different operators, or some or all of them may be operated by the same operator.

[0015] Note that Figure 1 illustrates three EV spots 45a to 45c as examples of multiple EV spots 45, but is not limited to these. Also, Figure 1 illustrates one charging service provider server 4, but is not limited to this. The number of multiple EV spots 45 included in the charging reservation system 1 and the number of charging service provider servers 4 are arbitrary and can be changed as appropriate. Furthermore, multiple charging service provider servers 4 may be provided by two or more charging service providers.

[0016] Note that Figure 1 illustrates one aggregator server 3, but is not limited to this. The charging reservation system 1 may include multiple aggregator servers 3. Furthermore, the multiple aggregator servers 3 may be provided by two or more service providers.

[0017] Figure 1 illustrates one EV7, but it is not limited to this. The charging reservation system 1 may include multiple EV7s. Here, the EV7s included in the charging reservation system 1 are EV7s registered in the charging reservation system 1, or EV7s used by users registered in the charging reservation system 1. Note that registration in the charging reservation system 1 may also mean registration for a charging service that becomes available by making a reservation using the charging reservation system 1.

[0018] The aggregator server 3, the power generator server 2, the charging service provider server 4, and the charging reservation server 6 are each connected to each other via public telecommunications lines such as the Internet and / or dedicated telecommunications lines such as a LAN (Local Area Network). The charging service provider server 4 and each of the multiple EV spots 45 are each connected to each other via public telecommunications lines such as the Internet and / or dedicated telecommunications lines such as a LAN. The charging reservation server 6 and the EV 7 are each connected to each other via public telecommunications lines such as the Internet and / or dedicated telecommunications lines such as a LAN. This communication may be wired, wireless, or a combination of both. For example, the EV 7 may communicate with the charging reservation server 6 via a charging cable while electrically connected to one of the multiple EV spots 45 via the charging cable.

[0019] The power generation operator server 2 is, for example, a computer installed and operated by a power generation operator. The power generation operator server 2 is implemented by, for example, a server device, but it may also be implemented using various other computers such as personal computers (PCs), tablet PCs, and smartphones.

[0020] The power generation business operator may be a power company that generates electricity using various energy sources such as thermal and hydroelectric power, or it may be a business operator that generates electricity as a distributed energy source (DER) using natural energy such as solar and wind power. The electricity generated by this power generation business operator is supplied to the power grid to which the charging reservation system 1 is applied. The power generation business operator server 2 notifies the aggregator server 3 of information indicating the power status of the power grid, such as the power generation plan or the power generation amount forecast based on the plan (power status notification).

[0021] Aggregator server 3 is a computer installed and operated by, for example, a company that supplies electricity from power generators to the power grid. Aggregator server 3 is implemented by, for example, a server device, but may also be implemented using various other computers besides server devices, such as personal computers (PCs), tablet PCs, and smartphones.

[0022] As shown in Figure 1, the aggregator server 3 has the functions of a notification unit 31 and a storage unit 32.

[0023] The notification unit 31 performs various adjustments with the power supply side, such as power generators, and / or the power demand side, such as charging service providers and charging reservation service providers. Specifically, the notification unit 31 controls the balance between the amount of power supplied and demanded in the target power grid (supply-demand balance) based on information from the power generator server 2 regarding power generation plans and power generation forecasts (power status notifications), and / or notifications of information indicating demand status from the charging service provider server 4 and charging reservation server 6 (demand status notifications). As an example, the notification unit 31 predicts power status information and peak shift request necessity information based on the power generation plan from the power generator server 2 and the demand forecast from the charging service provider server 4 and charging reservation server 6. The notification unit 31 also manages said power status information and peak shift request necessity information.

[0024] Here, power status information refers to information regarding the power status in the power grid. This power status may be, for example, the value of power consumption as a percentage of the available power supply. Furthermore, the power status information may also be information on a predetermined unit of the power grid targeted by the aggregator server 3, such as a main transmission line unit or a branch line unit.

[0025] Furthermore, the peak shift request necessity information indicates whether a request for peak shifting of electricity usage is necessary. This peak shift may be a geographical peak shift, which is the distribution of electricity usage in predetermined units within the power grid; a temporal peak shift, which is the distribution of electricity usage over time; or a combination of both. For example, a request for geographical peak shifting may mean that it is necessary to request the use of an EV spot 45 connected to a predetermined unit of power grid that has surplus power supply capacity, instead of an EV spot 45 connected to a predetermined unit of power grid that has no surplus power supply capacity. For example, a request for temporal peak shifting may mean that, with respect to an EV spot 45 connected to a predetermined unit of power grid that has no surplus power supply capacity, it is necessary to request its use during times outside of the peak electricity usage period.

[0026] If a change in the supply-demand balance is expected, the notification unit 31 may send a notification to the power generation operator server 2 requesting a reduction or increase in power generation. If a change in the supply-demand balance is expected, the notification unit 31 may also send a notification (power status notification) to the charging service operator server 4 or the charging reservation server 6 requesting a reduction or increase in power consumption, or the supply of power through the sale of electricity.

[0027] Furthermore, the notification unit 31 may notify information indicating the power status of the power grid, not limited to power status notifications that request adjustments to power consumption or the sale of electricity.

[0028] Furthermore, reducing or promoting electricity consumption can be achieved, for example, by adjusting the number and operating hours of EV Spot 45, and the number and reservation times for charging and selling electricity from EV 7.

[0029] The memory unit 32 stores information on power status and information on whether or not a peak shift request is necessary.

[0030] The charging service provider server 4 is a computer installed and operated by a service provider that provides charging services to, for example, an EV 7 that visits an EV spot 45. The charging service provider server 4 is implemented by, for example, a server device, but may also be implemented using various other computers such as personal computers (PCs), tablet PCs, and smartphones.

[0031] As shown in Figure 1, the charging service provider server 4 functions as a charging service management unit 41.

[0032] The charging service management unit 41 manages the charging service to the EV 7 by the EV spot 45. Here, the EV spot 45 is a power infrastructure that supplies power to the EV 7 using power from the power grid and receives power discharged from the EV 7, and is an example of a charging spot. The EV spot 45 is installed, for example, in a store parking lot or a service area on a highway. Specifically, the charging service management unit 41 manages the operating status of each of the multiple EV spots 45. This operating status may be information indicating whether each EV spot 45 is in operation. In addition, the charging service management unit 41 may manage information related to each EV spot 45 as part of the operating status, such as the ID of the EV spot 45, the amount of charge stored, the ID of the user who performed the charging / discharging, charging / discharging identification information, the amount of charge and time at the start / end of charging / discharging, charging efficiency, and the number of charge / discharge cycles.

[0033] The charging reservation server 6 is a computer installed and operated by a business operator that manages reservations and provides information for, for example, EV spots 45. The charging service provider server 4 is implemented by, for example, a server device, but may also be implemented using various other computers besides server devices, such as personal computers (PCs), tablet PCs, and smartphones.

[0034] As shown in Figure 1, the charging reservation server 6 has the functions of a reservation management unit 61, a storage unit 62, an attack detection unit 63, and an attack display unit 64.

[0035] The reservation management unit 61 manages EV spot information such as the reservation status, operating status, and environmental information of EV spots 45, based on information from the aggregator server 3 and the charging service provider server 4.

[0036] Here, the environmental information for EV Spot 45 may include information on weather and traffic, such as natural disasters, weather, and accidents in the location or region where each EV Spot 45 is installed. For example, weather information may include information such as temperature, presence or absence of rainfall, precipitation amount, wind speed, wind direction, total solar radiation, snowfall amount, road surface temperature, light intensity, visibility (fog), radiation dose, linear rainbands, and torrential downpours. For example, traffic information may not be limited to accidents, but may also include information on traffic volume and congestion.

[0037] This environmental information may be obtained from outside the charging reservation system 1, for example, via an internet or other telecommunication line, or it may be obtained by sensors mounted on or adjacent to the EV spot 45.

[0038] Furthermore, the reservation management unit 61 notifies EV7 of EV spot information and accepts reservations for charging and discharging using EV spot 45 in response to EV7's EV spot reservation requests. The reservation management unit 61 may also notify (request) EV7 to sell surplus electricity in response to a power supply request from aggregator server 3. In other words, the reservation management unit 61 manages reservations for the use of EV spot 45 for charging and discharging related to EV7. In addition to charging and discharging, or as an alternative, the reservation management unit 61 may also manage reservations for the use of EV spot 45 for updating the software of EV7's onboard computer.

[0039] The memory unit 62 stores reservation status information indicating the reservation status of EV spots 45, EV spot status information indicating the status of EV spots 45 such as operating status, and environmental information related to weather and traffic such as natural disasters, weather, and accidents. The memory unit 62 may also store information of users registered for the charging service, location information of EV spots 45, and map information such as road information.

[0040] The attack detection unit 63 detects cyberattacks against its own device (charging reservation server 6) based on whether or not it has received power status notifications from the aggregator server 3 and the consistency of the notification content. As an example, the attack detection unit 63 detects abnormalities in the aggregator server 3 that sends power status notifications to its own device. This abnormality detection includes, for example, spoofing detection, which detects communications that impersonate the legitimate aggregator server 3.

[0041] Furthermore, when the attack detection unit 63 detects a cyberattack against the charging reservation server 6, it determines the level of the attack alert according to the extent of the impact of the cyberattack, i.e., the degree of the cyberattack's expansion. For example, the attack detection unit 63 determines a higher alert level the more aggregator servers 3 that have detected anomalies (impersonation) are detected. For example, suppose that the correspondence between the number of aggregator servers 3 that have detected cyberattacks and the set alert level is predetermined, and information indicating this correspondence is stored in the storage unit 62. For example, the attack detection unit 63 determines the highest alert level when the number of aggregator servers 3 that have detected impersonation, or the proportion of aggregator servers 3 that have detected impersonation among those that send power status notifications to the device, exceeds a predetermined threshold stored in the storage unit 62. In other words, the more aggregator servers 3 that have detected impersonation are detected, the larger the scale of the cyberattack against the charging reservation server 6 is, and the more widespread the impact of the cyberattack on the charging reservation server 6 is considered to be.

[0042] Furthermore, the attack detection unit 63 notifies the attack display unit 64 and the relevant EV7s of the determined attack level (server attack information). These relevant EV7s may be, for example, all EV7s registered in the charging service of the charging reservation system 1, or all EV7s that are currently reserved.

[0043] The attack display unit 64 generates visualization information (display information) indicating the situation of a cyber attack on the charging reservation system 1 based on the server attack information from the attack detection unit 63 and / or the attack alert notification (EV attack information) from the EV 7, and outputs this information. The output of this display information is realized, for example, by screen display on a display implemented or connected to the charging reservation server 6, but may also be realized by transmission to an external information processing device.

[0044] The EV 7 may be various electric vehicles (EVs) such as, for example, a battery electric vehicle (BEV), a hybrid electric vehicle (HEV), or a plug-in hybrid electric vehicle (PHEV).

[0045] Note that the EV 7 may be various moving bodies configured to enable the reception (charging) of power from the outside (for example, the EV spot 45) to the mounted battery and / or the supply (discharge) of power from the battery to the outside (for example, the EV spot 45). This moving body may be a passenger car, a goods vehicle, a bus, a motorcycle, an electric kick scooter, an electric wheelchair, a construction machine, an agricultural machine, a ship, a railway vehicle, an airplane, etc. Further, the moving body may be configured to be capable of autonomous movement or may be configured to be movable in response to direct and / or remote operation by the user.

[0046] As shown in FIG. 1, the EV 7 has functions as a charging management unit 71, a storage unit 72, an attack detection unit 73, and an attack display unit 74.

[0047] As an example, the functions of EV7 may be realized by an in-vehicle computer such as a DCU (Domain Control Unit) like an ECU (Electronic Control Unit) provided inside or a CDC (Cockpit Domain Controller) integrating a plurality of ECUs, or an OBU (On Board Unit). This in-vehicle computer may be an externally attached computer installed near the dashboard of EV7. Also, the in-vehicle computer may be realized by cooperation or integration with various infotainment systems such as an in-vehicle car navigation device. It may be configured integrally. Further, the in-vehicle computer of EV7 may transmit and receive information to and from other computers installed in EV7 via an in-vehicle network including a CAN (Controller Area Network) in EV7 (a mobile body), Ethernet (registered trademark), USB (Universal Serial Bus (registered trademark)), etc., or may communicate with an information processing device outside EV7 via a network such as the Internet.

[0048] As an example, some or all of the functions of EV7 may be realized by a terminal owned or carried by an owner, a driver, a passenger, etc. This terminal may be various computers such as a personal computer (PC), a tablet PC, a smartphone, a smartwatch, etc.

[0049] The charge management unit 71 manages the charge and discharge of EV7 based on the input result by the user and the EV spot information from the charge reservation server 6. For example, the charge management unit 71 receives the EV spot information and the notice of power selling request from the charge reservation server 6. For example, the charge management unit 71 accepts a user operation and obtains an operation result (for example, an input result) by the user. For example, the charge management unit 71 transmits an EV spot reservation request for requesting a reservation of charge and discharge at the EV spot 45 to the charge reservation server 6 based on the input result by the user, the remaining battery level, the driving plan, the EV spot information from the charge reservation server 6, the power selling request, etc.

[0050] The storage unit 72 stores reservation information indicating the reservation status of the vehicle's EV spot 45, as well as EV spot information from the charging reservation server 6. The storage unit 72 may also store information of users registered for the charging service, location information of the EV spot 45, and map information such as road information.

[0051] The attack detection unit 73 detects cyberattacks against the EV7 (the device itself) based on whether or not it has received notifications of EV spot information and power sales requests from the charging reservation server 6, the consistency of the notification content, and the version information and behavior of application software installed on the vehicle's onboard computer. For example, the attack detection unit 73 performs impersonation detection to detect communications that impersonate the legitimate charging reservation server 6. For example, the attack detection unit 73 detects security risks such as malware that has infiltrated the vehicle's onboard computer.

[0052] Furthermore, if the attack detection unit 73 detects a cyberattack against the EV7, it determines the level of the attack alert according to the extent of the attack's spread. This extent of the attack's spread includes the severity of the cyberattack. For example, the attack detection unit 73 determines the alert level of the detected cyberattack based on information indicating the correspondence between the type of cyberattack and the alert level, which is pre-configured and stored in the memory unit 72, etc., and the type of cyberattack detected. Here, the type of cyberattack may be a type of security risk such as malware intrusion or detection of an application program that is not the latest version, or it may be the location of detection, or a combination of these. For example, the attack detection unit 73 determines a higher alert level if the detection location affects charging / discharging or driving. For example, the attack detection unit 73 determines a higher alert level the more detection locations there are. Here, cyberattacks that affect charging / discharging or driving, or cyberattacks with many detection locations, are examples of cyberattacks that are expanding their impact.

[0053] Furthermore, the attack detection unit 73 notifies the attack display unit 74 and the charging reservation server 6 of the determined attack level (EV attack information).

[0054] The attack display unit 74 generates visualization information (display information) indicating the status of the cyberattack against the charging reservation system 1 based on EV attack information from the attack detection unit 73 and / or attack alert notifications (server attack information) from the charging reservation server 6, and outputs this information. This output of display information is realized, for example, by displaying it on a screen on a display implemented in or connected to the in-vehicle computer of the EV 7, but it may also be realized by transmitting it to an external information processing device.

[0055] Furthermore, the attack indicator unit 74 may provide guidance to EV7, which has a reservation for an EV spot 45 in the power system of aggregator server 3 where a cyberattack (e.g., impersonation) has been detected, by guiding EV7 to at least one EV spot 45 in the power system of aggregator server 3 where no cyberattack has been detected. For example, the guidance may recommend the use of at least one safe EV spot 45 in another power system. For example, the guidance may suggest the reservation of any of the at least one safe EV spot 45. For example, the guidance may transfer the reservation to any of the at least one safe EV spot 45. For example, the guidance may provide directions to any of the at least one safe EV spot 45. The display information for the guidance may be generated in the attack indicator unit 74 of EV7, or it may be generated in the charging reservation server 6 and transmitted to EV7.

[0056] Figure 2 shows an example of the hardware configuration of an information processing device 8 that implements each device of the charging reservation system 1 according to the embodiment. Note that one device of the charging reservation system 1 may be implemented by one information processing device 8, or by the cooperation of two or more information processing devices 8. Similarly, two or more devices of the charging reservation system 1 may be integrated and implemented by a single information processing device 8.

[0057] As shown in Figure 2, the information processing device 8 includes a processor 81, a main memory 82, an auxiliary storage device 83, and an I / F (interface) 84. The processor 81, main memory 82, auxiliary storage device 83, and I / F 84 are interconnected by a bus or the like, resulting in a hardware configuration that utilizes a typical computer. Note that each component of the information processing device 8 may be realized by a combination of two or more components. Similarly, two or more components of the information processing device 8 may be integrated and realized by a single component.

[0058] The processor 81 is, for example, at least one CPU (Central Processing Unit). The processor 81 comprehensively controls the operation of the information processing device 8 and realizes each of the functions of the information processing device 8 by, for example, loading a program stored in the auxiliary storage device 83 into the main memory device 82 and executing it.

[0059] For example, the processor 81 of the power generation operator server 2 may implement the functions of the power generation operator server 2. For example, the processor 81 of the aggregator server 3 may implement the functions of the aggregator server 3, including the notification unit 31 and storage unit 32 illustrated in Figure 1. For example, the processor 81 of the charging service provider server 4 may implement the functions of the charging service provider server 4, including the charging service management unit 41 illustrated in Figure 1. For example, the processor 81 of the charging reservation server 6 may implement the functions of the charging reservation server 6, including the reservation management unit 61, storage unit 62, attack detection unit 63, and attack display unit 64 illustrated in Figure 1. For example, the processor 81 of the EV 7 may implement the functions of the EV 7, including the charging management unit 71, storage unit 72, attack detection unit 73, and attack display unit 74 illustrated in Figure 1.

[0060] In the example shown in Figure 1, only the functions necessary for explaining the main parts of this embodiment are illustrated, but the functions of each device in the charging reservation system 1 are not limited to these. Furthermore, some or all of the functions of each device in the charging reservation system 1 may be implemented by dedicated hardware circuits.

[0061] Furthermore, in each device of the charging reservation system 1, two or more functions may be integrated and implemented as a single function. Similarly, in each device of the charging reservation system 1, one function may be divided and implemented as two or more functions. Furthermore, in the charging reservation system 1, the functions of two or more devices may be integrated and implemented as at least one function of any of the devices. Similarly, in the charging reservation system 1, the functions of one device may be divided and implemented as two or more functions of two or more devices.

[0062] Here, the processor 81 according to the embodiment is an example of at least one processor in the information processing device 8. Instead of the CPU, or in addition to the CPU, at least one other processor may be used as the at least one processor. As the other processor, various processors such as a CPU, GPU (Graphics Processing Unit), DSP (Digital Signal Processor), or dedicated arithmetic circuits implemented with ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array) can be used as appropriate.

[0063] The main memory 82 is, for example, RAM (Random Access Memory). The main memory 82 temporarily stores data necessary for various processes performed by the processor 81. Here, the main memory 82 in this embodiment is an example of the internal memory in the information processing device 8, and is an example of at least one memory.

[0064] The auxiliary storage device 83 is, for example, a ROM (Read Only Memory). The auxiliary storage device 83 stores programs and parameters that realize various processes by the processor 81. Here, the auxiliary storage device 83 according to this embodiment is an example of the internal memory in the information processing device 8, and is an example of at least one memory. In addition to or instead of ROM, various storage media and storage devices such as HDDs (Hard Disk Drives), SSDs (Solid State Drives), and Flash memory can be used as the auxiliary storage device 83 as appropriate.

[0065] For example, the main memory 82 and auxiliary storage 83 of the aggregator server 3 may implement a storage unit 32. For example, the main memory 82 and auxiliary storage 83 of the charging reservation server 6 may implement a storage unit 62. For example, the main memory 82 and auxiliary storage 83 of the EV 7 may implement a storage unit 72.

[0066] I / F84 is an interface to the user and / or external devices. For example, I / F84 may be an output interface for connecting or implementing an output device that outputs audio, images, or video. Suitable output devices include various displays such as liquid crystal displays (LCDs), organic EL (Electroluminescence) displays, head-up displays (HUDs), and projectors, as well as speakers. I / F84 may also be an input interface for connecting or implementing an input device that acquires audio, images, video, or user input. Suitable input devices include keyboards, mice, touch panels, and microphones. Furthermore, I / F84 may be a communication interface for connecting or implementing a communication device that communicates with external devices. Suitable communication devices include wired or wireless communication circuits. For wireless communication, communication circuits compatible with various standards such as 3G, 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.

[0067] For example, the I / F 84 of the power generation operator server 2 may implement a communication interface for communicating with the aggregator server 3. For example, the I / F 84 of the aggregator server 3 may implement a communication interface (notification unit 31) for communicating with the power generation operator server 2, the charging service operator server 4, and the charging reservation server 6, respectively. For example, the I / F 84 of the charging service operator server 4 may implement a communication interface (charging service management unit 41) for communicating with the aggregator server 3 and each of the multiple EV spots 45. For example, the I / F 84 of the charging reservation server 6 may implement a communication interface (reservation management unit 61) for communicating with the aggregator server 3 and each of the EV 7. For example, the I / F 84 of the charging reservation server 6 may implement an output interface (attack display unit 64) for displaying information on the screen. For example, the I / F 84 of the EV 7 may implement a communication interface (charging management unit 71) for communicating with the charging reservation server 6. For example, the I / F 84 of EV7 may implement an output interface (attack display unit 74) that displays information on the screen based on the displayed information. For example, the I / F 84 of EV7 may implement an input interface that acquires user operations such as the occupants of EV7, or a connection interface that connects terminals such as smartphones and smartwatches that acquire user operations via wired and / or wireless connections.

[0068] The operation example of the charging reservation system 1 according to the embodiment will be described below with reference to the drawings. Note that the process described below is just one example, and it is possible to change the order of processing, delete some processes, or add other processes.

[0069] Figure 3 is a flowchart showing an example of the information processing flow performed by the charging reservation server 6 according to the embodiment.

[0070] The charging reservation server 6 receives a power status notification from the aggregator server 3 (S101).

[0071] If no attack alert notification is received from EV7 (S102: No), the charging reservation server 6 executes the server-side attack detection process (S103). The flow of the server-side attack detection process will be described later (see Figure 5).

[0072] If no attack is detected on the charging reservation server 6 (S104: No), the charging reservation server 6 collects EV spot information (S105).

[0073] If the charging reservation server 6 receives an attack alert notification from EV7 (S102: Yes), it executes a server-side GUI display process to display the attack alert related to EV7 (S106).

[0074] Furthermore, if an attack on the charging reservation server 6 is detected (S104: Yes), the charging reservation server 6 executes a server-side GUI display process that displays an attack alert related to the charging reservation server 6 (S106).

[0075] Furthermore, if an attack alert notification from EV7 has been received at least once (S102: Yes), or if an attack on the charging reservation server 6 has been detected (S104: Yes), the charging reservation server 6 will execute the server-side GUI display process related to alert level 0 (zero) (S106). On the other hand, if the process in S105 is performed without receiving an attack alert notification from EV7 or detecting an attack on the charging reservation server 6, the server-side GUI display process (S106) will not be executed. The flow of the server-side GUI display process will be described later (see Figure 5).

[0076] The charging reservation server 6 sends the EV spot information collected in the process of S105, or the attack alert notification for the server attack detected in the process of S103, to the EV 7 (S107).

[0077] If the attack alert is not at "level 0 (zero)" (S108: No), the flow in Figure 3 waits if the alert level of the attack alert has not changed (S109: No), and returns to processing S102 if it has changed (S109: Yes). On the other hand, if the attack alert is at "level 0 (zero)" (S108: Yes), the flow in Figure 3 ends.

[0078] Figure 4 is a flowchart showing an example of the information processing flow performed by EV7 according to this embodiment.

[0079] If EV7 has not received an attack alert notification from the charging reservation server 6 (S201: No), EV7 executes the attack detection process on the EV side (S202). The flow of the attack detection process will be described later (see Figure 6).

[0080] If no attack on EV7 is detected (S203: No), EV7 collects EV spot information from the charging reservation server 6 (S204).

[0081] If EV7 receives an attack alert notification from the charging reservation server 6 (S201: Yes), EV7 executes a GUI display process on the EV side that displays the attack alert related to the charging reservation server 6 (S205).

[0082] Furthermore, if an attack on EV7 is detected (S203: Yes), EV7 executes a GUI display process on the EV side that shows an attack alert related to EV7 (S205).

[0083] Furthermore, if an attack alert notification has been received from the charging reservation server 6 at least once (S201: Yes), or if an attack on EV7 has been detected (S203: Yes), EV7 will execute the GUI display process on the EV side related to alert level 0 (zero) (S205). On the other hand, if the process in S204 is performed without receiving an attack alert notification from the charging reservation server 6 or detecting an attack on EV7, the GUI display process on the EV side (S205) will not be executed. The flow of the GUI display process on the EV side will be described later (see Figure 6).

[0084] EV7 sends the EV spot information collected in the processing of S204, or the attack alert notification for the EV attack detected in the processing of S202, to the charging reservation server 6 (S206).

[0085] If the attack alert is not at "level 0 (zero)" (S207: No), the flow in Figure 4 waits if the alert level of the attack alert has not changed (S208: No), and returns to processing S201 if it has changed (S208: Yes). On the other hand, if the attack alert is at "level 0 (zero)" (S207: Yes), the flow in Figure 4 ends.

[0086] Figure 5 is a flowchart showing an example of the flow of server-side attack detection processing and GUI display processing performed by the charging reservation server 6 according to the embodiment.

[0087] In the server-side attack detection process, the charging reservation server 6 performs a detailed attack analysis (S301).

[0088] If the server-side attack detection process does not confirm that a cyberattack has occurred against the charging reservation server 6, that is, if no cyberattack is detected (S302: No), the process shown in Figure 5 ends. After that, the charging reservation server 6 proceeds to the process shown in S104 of Figure 3.

[0089] If the server-side attack detection process confirms that a cyberattack has occurred on the charging reservation server 6 (S302: Yes), and the impact analysis is underway (S303: Yes), the charging reservation server 6 displays a "Level 1" attack alert in the server-side GUI display process (see Figure 8) and notifies EV7 (S304). Subsequently, the process shown in Figure 5 returns to the process in S303.

[0090] If impact analysis is not underway (S303: No), and the impact is expanding (S305: Yes), the charging reservation server 6 displays a "Level 2" attack alert in the server-side GUI display process (see Figure 9) and notifies EV7 (S306). Subsequently, the flow shown in Figure 5 returns to the process in S303.

[0091] If the impact is not expanding (S305: No) and countermeasures are being taken (S307: Yes), the charging reservation server 6 will wait until the countermeasures are completed.

[0092] If countermeasures are not being taken (S307: No), and countermeasures have not been taken (S308: No), the flow in Figure 5 returns to the process in S303. On the other hand, if countermeasures have been taken (S308: Yes), the charging reservation server 6 displays a "Level 0" attack alert in the server-side GUI display process (see Figure 7) and notifies EV7 (S309). After that, the flow in Figure 5 ends.

[0093] Figure 6 is a flowchart showing an example of the flow of attack detection processing and GUI display processing on the EV side executed by EV7 according to the embodiment.

[0094] In the attack detection process on the EV side, EV7 performs a detailed attack analysis (S401).

[0095] If the EV's attack detection process does not confirm that a cyberattack has occurred on EV7, that is, if no cyberattack is detected (S402: No), the process shown in Figure 6 ends. After that, EV7 proceeds to the process shown in S203 of Figure 4.

[0096] If the EV's attack detection process confirms that a cyberattack has occurred on EV7 (S402: Yes), and the impact analysis is underway (S403: Yes), EV7 notifies the charging reservation server 6 of a "Level 1" attack alert (S404). Subsequently, if the vehicle's charge level is sufficient (S405: Yes), EV7 displays a "Level 0" attack alert in the EV's GUI display process (see Figure 7) and notifies the charging reservation server 6 (S406). On the other hand, if the vehicle's charge level is insufficient (S405: No), EV7 displays a "Level 1" attack alert in the EV's GUI display process (see Figure 8) and notifies the charging reservation server 6 (S407). After processing S406 or S407, the flow in Figure 6 returns to processing S403.

[0097] If impact analysis is not underway (S403: No), and the impact is expanding (S408: Yes), EV7 displays a "Level 2" attack alert in the EV-side GUI display process (see Figure 10) and notifies the charging reservation server 6 (S409). At this time, EV7 cuts off the communication network with the outside world, including the charging reservation server 6, in order to suppress further expansion of the impact. After that, the flow in Figure 6 returns to the process in S403.

[0098] If the impact is not expanding (S408: No) and countermeasures are being taken (S410: Yes), EV7 will wait until the countermeasures are completed.

[0099] If countermeasures are not being taken (S410: No), and countermeasures have not been taken (S411: No), the flow in Figure 6 returns to the process in S403. On the other hand, if countermeasures have been taken (S411: Yes), EV7 displays a "Level 0" attack alert in the GUI display process on the EV side (see Figure 7) and notifies the charging reservation server 6 (S412). After that, the flow in Figure 6 ends.

[0100] Figures 7 to 10 show an example of screen display in the GUI display processing according to the embodiment.

[0101] Figure 7 illustrates the screen display on the charging reservation server 6 and EV 7 in the case of alert level 0 (zero). As shown in Figure 7, the display of the "Level 0" attack alert includes a notification that reads "Alert Lv0 (Recovered)" and a notification that reads "Guided to the originally reserved charging spot." This allows the user to easily understand that the cyberattack on the charging reservation system 1 has been recovered and that the reserved EV spot 45 is available.

[0102] Figure 8 illustrates the screen display on the charging reservation server 6 and EV7 in the case of alert level 1. As shown in Figure 8, the display of a "Level 1" attack alert includes a notification that reads "Alert Lv1 (Under Analysis)" and a notification that reads "Guided to the nearest charging spot." This allows the user to easily understand that a cyberattack on the charging reservation system 1 is under analysis and that another safe EV spot 45 is available instead of the reserved EV spot 45.

[0103] Figure 9 illustrates the screen display on the charging reservation server 6 in the case of alert level 2. As shown in Figure 9, the display on the charging reservation server 6 for a "level 2" attack alert includes a notification that reads "Alert Lv2 (Attack Expansion)" and a notification that reads "Service Suspended". This allows the user to easily understand that the cyberattack on the charging reservation system 1 is expanding and that all EV spots 45, including the reserved EV spot 45, are unavailable.

[0104] Figure 10 illustrates the screen display in EV7 in the case of alert level 2. As shown in Figure 10, the display in EV7 for a "level 2" attack alert includes a notification that reads "Alert Lv2 (Attack Expansion)", a notification that reads "Service Suspended", and a notification that reads "Network Blocked". This allows the user to easily understand that the cyberattack on the charging reservation system 1 is expanding, all EV spots 45, including the reserved EV spot 45, are unavailable, and the communication network of EV7 is blocked.

[0105] As described above, the charging reservation system 1 according to this embodiment notifies the user of an attack alert with an alert level corresponding to the extent of the cyberattack's impact when a cyberattack occurs against the charging reservation system 1. With this configuration, the user can easily understand the status of the cyberattack against the charging reservation system 1.

[0106] In this disclosure, "is A" means at least one of "is A" or "is not A". In other words, in each of the embodiments described above, the determination of "is A" may be achieved by determining that "is A", by determining that "is not A", or by determining both of these.

[0107] The programs executed by each device of the charging reservation system 1 of this disclosure may be provided as files in an installable or executable format, recorded on a computer-readable recording medium (Computer Program Product) such as a CD-ROM, floppy disk, CD-R, or DVD.

[0108] Furthermore, the programs executed by each device of the charging reservation system 1 of this disclosure may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network. Alternatively, the programs executed by each device of the charging reservation system 1 of this disclosure may be provided or distributed via a network such as the Internet.

[0109] Furthermore, the program executed by each device of the charging reservation system 1 of this disclosure may be pre-installed and provided in ROM or the like.

[0110] According to at least one embodiment described above, the status of cyberattacks on the charging reservation system 1 can be easily grasped. Furthermore, the possibility that EV users will be unable to charge at EV spots 45 when a cyberattack occurs can be reduced.

[0111] While several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be carried out in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims and their equivalents.

[0112] (Note) The above description of embodiments discloses the following technologies: (1) An information processing device comprising at least one processor, wherein the at least one processor manages reservations for use of charging spots relating to a mobile device configured to allow external charging of its mounted battery, obtains notifications of the power status of a target power system from at least one aggregator server which adjusts the power supply and demand balance of a target power system that supplies power to at least one of a plurality of charging spots, detects a cyberattack against itself based on the notification of the power status, determines an alert level according to the extent of the detected cyberattack if a cyberattack against itself is detected, and generates and outputs display information for displaying an attack alert of the determined alert level. (2) The information processing device according to (1) above, wherein the at least one processor detects an anomaly in the at least one aggregator server that transmits the notification of the power status to itself as a cyberattack against itself, and determines a higher alert level for the attack alert the greater the number of aggregator servers in which an anomaly is detected. (3) The information processing device according to (1) or (2) above, wherein at least one processor generates and outputs display information to guide the aggregator server from which an abnormality has been detected to at least one charging spot that receives power from a power grid that is subject to supply and demand balance adjustment by other aggregator servers. (4) The information processing device according to any one of (1) to (3) above, wherein at least one processor notifies the target mobile object of the attack alert. (5) The information processing device according to any one of (1) to (4) above, wherein at least one processor, when it receives an attack alert from the mobile object regarding a cyberattack against the mobile object, generates and outputs display information to display the received attack alert.(6) An information processing system comprising at least one mobile body and an information processing device described in any one of (1) to (5) above, wherein the mobile body comprises at least one processor, and at least one processor of the mobile body detects a cyberattack against the mobile body, determines an alert level according to the extent of the detected cyberattack when a cyberattack against the mobile body is detected, and generates and outputs display information for displaying an attack alert of the determined alert level. (7) The information processing system described in (6) above, wherein at least one processor of the mobile body notifies the information processing device of the attack alert of a cyberattack against the mobile body. (8) The information processing system described in (6) or (7) above, wherein when at least one processor receives an attack alert from the information processing device regarding a cyberattack against the information processing device, it generates and outputs display information for displaying the received attack alert. (9) An information processing method performed by at least one processor in an information processing device comprising at least one processor, the method comprising: managing reservations for use of charging spots for a mobile device configured to allow external charging of its mounted battery; obtaining notifications of the power status of a target power system from at least one aggregator server which adjusts the power supply and demand balance of a target power system that supplies power to at least one of a plurality of charging spots; detecting a cyberattack against the device based on the notifications of the power status; determining an alert level according to the extent of the detected cyberattack if a cyberattack against the device is detected; and generating and outputting display information for displaying an attack alert of the determined alert level. (10) The information processing method according to (9) above, wherein an anomaly in at least one aggregator server that transmits notifications of the power status to the device is detected as a cyberattack against the device, and determining a higher alert level for the attack alert the more aggregator servers are found to be anomaly.(11) The information processing method according to (9) or (10) above, which generates and outputs display information to guide the aggregator server in which an abnormality has been detected to at least one charging spot that receives power from a power grid that is subject to supply and demand balance adjustment by other aggregator servers. (12) The information processing method according to any one of (9) to (11) above, which notifies the target mobile body of the attack alert. (13) The information processing method according to any one of (9) to (12) above, which, when an attack alert regarding a cyberattack against the mobile body is received from the mobile body, generates and outputs display information to display the received attack alert. (14) A program to cause a computer to perform the following actions: manage reservations for use of charging spots for a mobile device configured to allow external charging of its onboard battery; obtain notifications of the power status of a target power system from at least one aggregator server which adjusts the power supply and demand balance of a target power system that supplies power to at least one of multiple charging spots; detect cyberattacks against the device based on the notifications of the power status; if a cyberattack against the device is detected, determine an alert level according to the extent of the detected cyberattack; and generate and output display information for displaying an attack alert of the determined alert level. (15) A program to cause a computer to perform the information processing method described in any one of the above items (9) to (13).

[0113] 1 Charging reservation system 2 Power generation company server 3 Aggregator server 31 Notification unit 32 Storage unit 4 Charging service provider server 41 Charging service management unit 45, 45a, 45b, 45c EV spot 6 Charging reservation server 61 Reservation management unit 62 Storage unit 63 Attack detection unit 64 Attack display unit 7 EV 71 Charging management unit 72 Storage unit 73 Attack detection unit 74 Attack display unit 8 Information processing device 81 Processor 82 Main memory 83 Auxiliary memory 84 I / F

Claims

1. An information processing device comprising at least one processor, the at least one processor managing reservations for use of charging spots for a mobile device configured to allow external charging of its onboard battery, obtaining notifications of the power status of a target power system from at least one aggregator server which adjusts the power supply and demand balance of a target power system that supplies power to at least one of a plurality of charging spots, detecting a cyberattack against the device based on the notification of the power status, determining an alert level according to the extent of the detected cyberattack if a cyberattack against the device is detected, and generating and outputting display information for displaying an attack alert of the determined alert level.

2. The information processing apparatus according to claim 1, wherein the at least one processor detects an anomaly in the at least one aggregator server that transmits the power status notification to the device as a cyberattack against the device, and determines that the alert level of the attack alert is higher the more aggregator servers in which anomalies are detected.

3. The information processing apparatus according to claim 1, wherein the at least one processor generates and outputs display information for guiding users to at least one charging spot that receives power from a power grid targeted for supply and demand balance adjustment by other aggregator servers of the aggregator server where an abnormality has been detected.

4. The information processing apparatus according to claim 1, wherein at least one processor notifies the target mobile object of the attack alert.

5. The information processing apparatus according to claim 1, wherein the at least one processor, when it receives an attack alert from the mobile body regarding a cyberattack against the mobile body, generates and outputs display information for displaying the received attack alert.

6. An information processing system comprising at least one mobile body and an information processing device according to any one of claims 1 to 5, wherein the mobile body comprises at least one processor, the at least one processor of the mobile body detects a cyberattack against the mobile body, determines an alert level according to the extent of the detected cyberattack when a cyberattack against the mobile body is detected, and generates and outputs display information for displaying an attack alert of the determined alert level.

7. The information processing system according to claim 6, wherein at least one processor of the mobile body notifies the information processing device of the attack alert for a cyberattack against the mobile body.

8. The information processing system according to claim 6, wherein the at least one processor, upon receiving an attack alert from the information processing device regarding a cyberattack on the information processing device, generates and outputs display information for displaying the received attack alert.

9. An information processing method performed by at least one processor in an information processing device comprising at least one processor, the method comprising: managing reservations for use of charging spots for a mobile device configured to allow external charging of its mounted battery; obtaining notifications of the power status of a target power system from at least one aggregator server that adjusts the power supply and demand balance of a target power system that supplies power to at least one of a plurality of charging spots; detecting a cyberattack against the device based on the notification of the power status; determining an alert level according to the extent of the detected cyberattack if a cyberattack against the device is detected; and generating and outputting display information for displaying an attack alert of the determined alert level.

10. A program to cause a computer to perform the following actions: manage reservations for use of charging spots for a mobile device configured to allow external charging of its onboard battery; obtain notifications of the power status of a target power system from at least one aggregator server that adjusts the power supply and demand balance of the target power system that supplies power to at least one of multiple charging spots; detect cyberattacks against the device based on the notifications of the power status; if a cyberattack against the device is detected, determine an alert level according to the extent of the detected cyberattack; and generate and output display information for displaying an attack alert of the determined alert level.