Information processing method, information processing device, and information processing program
Patent Information
- Application Number
- PCT/JP2025/039050
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-21
- Filing Date
- 2025-11-07
- Publication Date
- 2026-08-27
Smart Images

Figure JP2025039050_27082026_PF_FP_ABST
Abstract
Description
Information Processing Method, Information Processing Apparatus, and Information Processing Program
[0008]
[0001] The present disclosure relates to an information processing method, an information processing apparatus, and an information processing program.
[0002] In power facilities such as power plants and electric vehicle charging stations, when a cyber attack occurs, for example, there is a risk of excessive load and damage, or irregularities. Therefore, as a countermeasure against cyber attacks targeting power facilities, an external security monitoring system may be introduced, and the monitoring and analysis of power facilities may be outsourced. The external security monitoring system will monitor and analyze the power facilities using the communication data logs related to the power facilities.
[0003] Japanese Patent No. 4767750
[0004] However, for example, communication data logs related to power facilities may contain a lot of private information, confidential information in competition, etc. Therefore, when outsourcing the monitoring and analysis of power facilities, it is necessary to provide log information in which private information and confidential information in competition included in the communication data logs are anonymized, and there is room for improvement.
[0005] One of the problems to be solved by the present disclosure is to appropriately handle abnormalities in power facilities even with anonymized log information.
[0006] The information processing method according to the present disclosure is an information processing method executed in an information processing apparatus that transmits log information indicating a log related to communication performed between a first power facility configured to be capable of performing at least one of power supply and power reception with a connected charge / discharge device and a second power facility that controls the first power facility, and includes performing anonymization control for anonymizing anonymized information including one or more pieces of private information or confidential information in the log information.
[0007] According to the present disclosure, it is possible to appropriately handle abnormalities in power facilities even with anonymized log information.
[0008] Figure 1 is a diagram showing an example of the configuration of a charging system according to the embodiment. Figure 2 is a block diagram showing an example of the functional configuration of a charging device according to the embodiment. Figure 3 is a schematic diagram for explaining the first log information according to the embodiment. Figure 4 is a block diagram showing an example of the functional configuration of a management device according to the embodiment. Figure 5 is a schematic diagram showing an example of the second log information according to the embodiment. Figure 6 is a schematic diagram showing an example of encrypted log information according to the embodiment. Figure 7 is a block diagram showing an example of the functional configuration of a charging station management server according to the embodiment. Figure 8 is a schematic diagram showing an example of key information according to the embodiment. Figure 9 is a block diagram showing an example of the functional configuration of a security monitoring server according to the embodiment. Figure 10 is a block diagram showing an example of the functional configuration of a first terminal according to the embodiment. Figure 11 is a schematic diagram showing an example of decrypted encrypted log information according to the embodiment. Figure 12 is a schematic diagram showing an example of decrypted encrypted log information according to the embodiment. Figure 13 is a sequence diagram showing an example of the processing flow executed by the charging system according to the embodiment. Figure 14 is a sequence diagram showing an example of the processing flow executed by the charging system according to the embodiment. Figure 15 is a schematic diagram showing an example of operation information according to the first modified example. Figure 16 is a schematic diagram showing an example of second log information according to the second modified example. Figure 17 is a block diagram showing an example of the functional configuration of an external server according to the second modified example. Figure 18 is a sequence diagram showing an example of the processing flow executed by the charging system according to the second modified example. Figure 19 is a schematic diagram showing an example of second log information according to the third modified example. Figure 20 is a block diagram showing an example of the functional configuration of an external server according to the third modified example. Figure 21 is a sequence diagram showing an example of the processing flow executed by the charging system according to the third modified example. Figure 22 is a sequence diagram showing an example of the processing flow executed by the charging system according to the fourth modified example. Figure 23 is a block diagram showing an example of the hardware configuration of a charging system according to the embodiment and modified examples.
[0009] Hereinafter, embodiments of the information processing method, information processing device (management device), and information processing program related to this disclosure will be described with reference to the drawings.
[0010] In this disclosure, components having the same or substantially the same function as those described above in previously shown drawings are denoted by the same reference numerals, and explanations may be omitted as appropriate. Furthermore, even when representing the same or substantially the same parts, the dimensions and proportions may be shown differently in different drawings. In addition, for example, from the viewpoint of ensuring the readability of the drawings, reference numerals may be assigned only to the main components in the explanation of each drawing, and reference numerals may not be assigned to components having the same or substantially the same function as those described above in previously shown drawings.
[0011] In addition, in the descriptions of this disclosure, components having the same or substantially the same function may be distinguished by adding alphanumeric characters to the end of the reference numeral. Alternatively, if multiple components having the same or substantially the same function are not to be distinguished, they may be described together by omitting the alphanumeric characters at the end of the reference numeral.
[0012] In this disclosure, we provide an example of a charging system that provides charging services and electricity sales services to mobile devices such as electric vehicles that are configured to be driven using power from an on-board battery, using power equipment installed at a charging station (power infrastructure).
[0013] Here, a charging service is a service that supplies power from a charging station to a mobile vehicle, such as by selling electricity to the user of the mobile vehicle, to charge the battery installed in the mobile vehicle. A power sales service is a service that discharges the battery installed in the mobile vehicle, such as by purchasing electricity from the user of the mobile vehicle, to charge the battery of the charging station using the power from the mobile vehicle, or to supply power from the mobile vehicle to the upstream power grid.
[0014] Here, "mobile device" refers to an example of a charge / discharge device equipped with a battery (storage battery) and configured to perform charging of the battery using power supplied from an external source, and discharging of the battery to receive power from an external source. Any battery can be used as the battery for this charge / discharge device, such as lithium-ion batteries, nickel-metal hydride batteries, or solid-state batteries. The "mobile device" may be any type of electric vehicle, including electric vehicles (EVs) driven by a motor, or hybrid vehicles driven by both an engine (internal combustion engine) and a motor.
[0015] Furthermore, the mobile vehicle may be, for example, a passenger car, truck, or motorcycle, but it may also be an electric bicycle, electric scooter, electric wheelchair, construction machinery, agricultural machinery, ship, train, airplane, etc. Also, the mobile vehicle is not limited to passenger vehicles; it may also be a cargo vehicle such as a baggage transport vehicle. In addition, the mobile vehicle may be configured to operate autonomously, or it may be configured to operate in response to direct or remote operation by a driver.
[0016] Furthermore, the technology disclosed herein is not limited to mobile devices such as electric vehicles, but can be applied to various power devices and power facilities whose power output or input is controlled by communication, such as energy storage devices, power generation devices, and charging devices for charging stations.
[0017] Figure 1 is a diagram showing an example of the configuration of a charging system 1 according to an embodiment. As shown in Figure 1, the charging system 1 includes an external server 2, a charging station 3, a charging station management server 6, and a security monitoring server 7. The external server 2 is, for example, a system that handles payments when using a power company or the charging device 31.
[0018] The charging station 3 is a facility (power infrastructure) for providing charging services or electricity sales services to visiting vehicles 4 (mobile entities). The charging station 3 includes a charging device 31, a BESS (battery energy storage system) 32, a power meter 33, a power generator 34, and a management device 35. The security monitoring server 7 includes a first terminal 8 and a second terminal 9.
[0019] As shown in Figure 1, the external server 2, the charging station management server 6, the security monitoring server 7, and the management device 35 are connected to each other via an external network N, which is, for example, a telecommunications line such as the Internet. The security monitoring server 7, the first terminal 8, and the second terminal 9 are also connected to each other via the external network N. The charging device 31 is connected to the upstream grid power 5 via a power transmission network such as power lines, enabling it to exchange power.
[0020] The charging device 31 is configured to operate in accordance with instructions (control messages) from the management device 35. The charging device 31 is configured to perform at least one of supplying and receiving power to and from the connected vehicle 4. The charging device 31 is an example of a first power facility.
[0021] For example, the charging device 31 is configured to perform operations related to a charging service, which involves supplying power (selling electricity) to the connected vehicle 4 in response to a request from the user of the vehicle 4, and charging the battery installed in the vehicle 4. Also, for example, the charging device 31 is configured to perform operations related to a power sales service, which involves receiving power discharged from the battery installed in the connected vehicle 4 in response to a request from the management device 35 or the grid power 5, and discharging the battery installed in the vehicle 4.
[0022] The power sales service may be provided upon request from the user of vehicle 4. Furthermore, the charging device 31 capable of operating in normal mode and suppression mode, and the charging device 31 capable of operating in power sales mode, may each be configured as independent devices. The functional configuration of the charging device 31 will now be described.
[0023] Figure 2 is a block diagram showing an example of the functional configuration of a charging device 31 according to an embodiment. As shown in Figure 2, the charging device 31 includes a communication unit 311, a charging control unit 312, and a generation unit 313. However, the functions of the charging device 31 are not limited to these.
[0024] The communication unit 311 is a communication circuit that communicates with the outside of the charging device 31. The communication unit 311 can be a wired or wireless communication circuit as appropriate. For wireless communication, a communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.
[0025] The charging control unit 312 and the generation unit 313 are implemented by one or more processors. For example, each of the above units may be implemented by having a processor such as a CPU (Central Processing Unit) execute a program, i.e., by software. Each of the above units may also be implemented by a dedicated IC or other processor, i.e., by hardware. Each of the above units may also be implemented by using both software and hardware. When multiple processors are used, each processor may implement one of the above units, or two or more of the above units.
[0026] The charging control unit 312 controls the charging and discharging of the connected vehicle 4 in accordance with the control of the management device 35. The charging control unit 312 operates the charging device 31 in one of several charging control modes, which include at least a normal mode, a suppression mode, and a power sales mode. In this way, the charging control unit 312 realizes the charging and discharging functions of the charging device 31. As an example, the charging control unit 312 controls the charging control mode of the charging device 31 in accordance with instructions (control messages) from the charging control instruction unit 353 installed in the management device 35.
[0027] The charging control mode of the charging device 31 is information indicating the degree of tightness in electricity demand. This charging control mode of the charging device 31 includes at least a normal mode and a suppression mode in which the charging device 31 performs operations related to charging services. The charging control mode of the charging device 31 may further include a power selling mode in which the charging device 31 performs operations related to power selling services. Furthermore, the charging control mode of the charging device 31 may further include operating modes other than the normal mode, suppression mode and power selling mode in the charging device 31, for example, an inoperable mode in which the charging device 31 is not operating.
[0028] For example, the normal mode is an operating mode in which charging is performed without the constraint of a charging limit. Specifically, the normal mode is an operating mode in which power is supplied to vehicle 4 when there is no power supply restriction due to a power shortage, such as when power demand is not tight. Here, a power supply restriction due to a power shortage refers to setting upper limits (thresholds) on the amount of power supplied, the power supply speed, the number of power supply cycles, and the power supply frequency, or reducing the set upper limits.
[0029] For example, the suppression mode is an operating mode in which charging is performed with a constraint on the upper limit of the charge. Specifically, the suppression mode is an operating mode in which power is supplied to the vehicle 4 in a state that involves restrictions on power supply due to power shortages, for example, in response to requests from the management device 35 or the grid power 5, such as when power demand is tight.
[0030] For example, the power sales mode is an operating mode in which power is supplied from the vehicle 4 to the charging device 31. Specifically, the power sales mode is an operating mode in which, for example, when there is a shortage of electricity, the battery installed in the vehicle 4 connected to the charging device 31 is discharged in response to a request from the management device 35 or the grid power 5, and the power discharged from that battery is supplied.
[0031] The generation unit 313 generates first log information, which includes a log of communication data between the charging device 31 and the vehicle 4 connected to it, and a log of communication data between the charging device 31 and the management device 35 connected to it. The generation unit 313 transmits the generated first log information to the management device 35 within a predetermined time. The first log information will now be explained using Figure 3.
[0032] Figure 3 is a schematic diagram illustrating the first log information according to the embodiment. The first log information T1 is a table in which items such as "User ID," "Payment Information," "Vehicle ID," "Charging Device ID," "Charging Rate [%]," "Output [kWh]," and "Remaining Time [h]" are associated. However, the first log information T1 is not limited to this and may also include, for example, the timestamp when the log was generated and the time when the charging device 31 started / ended charging the vehicle 4.
[0033] The user ID is, for example, an identifier that identifies the user using the charging device 31. The payment information is, for example, information about the payment method used when using the charging device 31. The vehicle ID is, for example, an identifier that identifies the vehicle 4 connected to the charging device 31. The charging device ID is, for example, an identifier that identifies the charging device 31.
[0034] The charge rate [%] is, for example, the charge percentage of the battery installed in the vehicle 4 connected to the charging device 31. The output [kWh] is, for example, the value output by the charging device 31 to the battery of the vehicle 4. The remaining time [h] is, for example, the remaining time until the charging device 31 has finished charging the battery of the vehicle 4.
[0035] Returning to Figure 1, let's continue the explanation. BESS32 is a system equipped with a battery that stores power from the charging station 3 and power generated by the power generator 34. BESS32 is an example of the first power equipment. Any battery can be used as appropriate, such as lithium-ion batteries, nickel-metal hydride batteries, or all-solid-state batteries.
[0036] BESS32 transmits battery status information, including the remaining battery capacity (SOC: State Of Charge) and the battery degradation status (SOH: State Of Health), to the management device 35 at predetermined intervals, or when it receives a request to acquire battery status information from the charging station management server 6 or the management device 35.
[0037] The power meter 33 measures the amount of energy consumed by the charging system 1 and the charging device 31. Specifically, the power meter 33 measures the amount of energy supplied to the charging system 1 per unit time from the total power consumption per unit time consumed by the charging system 1. The power meter 33 also measures the total power consumption per unit time consumed by the charging device 31. Furthermore, the power meter 33 transmits the power measurement results to the management device 35 at predetermined intervals, or when it receives a power measurement result acquisition request information from the charging station management server 6 or the management device 35.
[0038] The power generation device 34 is a device that generates electricity and outputs the generated electricity to BESS 32. The power generation device 34 is, for example, a photovoltaics (PV) or an eco-friendly water heater. The power generation device 34 transmits power generation status information, including the amount of electricity generated, to the charging station management server 6 or management device 35 at predetermined intervals or when it receives a power generation status acquisition request information from the charging station management server 6 or management device 35.
[0039] The control device 35 manages the charging device 31, BESS 32, power meter 33, and power generator 34. The control device 35 also controls the charging device 31. The control device 35 is an example of a second power facility. For example, the control device 35 is configured to control both the power supply to the vehicle 4 by the charging device 31 and the discharge by the vehicle 4, i.e., the power reception from the vehicle 4.
[0040] Furthermore, the management device 35 transmits log information indicating a log of communication taking place between a first power facility, which is configured to perform at least one of supplying and receiving power to connected charging and discharging equipment, and a second power facility that controls the first power facility. The functional configuration of the management device 35 will now be explained using Figure 4.
[0041] Figure 4 is a block diagram showing an example of the functional configuration of the management device 35 according to the embodiment. As shown in Figure 3, the management device 35 includes a communication unit 351, a storage unit 352, a charge control instruction unit 353, a receiving unit 354, a first generation unit 355, and a second generation unit 356. However, the functions of the management device 35 are not limited to these.
[0042] The communication unit 351 is a communication circuit that communicates with the outside of the management device 35. The communication unit 351 can be a wired or wireless communication circuit as appropriate. For wireless communication, a communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.
[0043] The storage unit 352 is a storage medium or a storage device that stores a control program, parameters, in-process data, and data of processing results related to each process executed by the management device 35. The storage unit 352 is, for example, a semiconductor memory element such as a RAM (Random Access Memory), a flash memory, a hard disk, an optical disk, or the like. Note that the storage unit 352 may be a storage device provided outside the management device 35. Further, the storage unit 352 may be a storage medium that downloads and stores or temporarily stores a program and various kinds of information via a LAN (Local Area Network), the Internet, or the like.
[0044] The charge control instruction unit 353, the reception unit 354, the first generation unit 355, and the second generation unit 356 are realized by one or a plurality of processors. For example, each of the above units may be realized by causing a processor such as a CPU to execute a program, that is, by software. Each of the above units may be realized by a processor such as a dedicated IC, that is, by hardware. Each of the above units may be realized by using software and hardware in combination. When using a plurality of processors, each processor may realize one of the units or two or more of the units.
[0045] The charge control instruction unit 353 controls the operation of the charging device 31 by communication performed with the charging device 31. For example, the charge control instruction unit 353 transmits a control message (transmission / reception information) for controlling the operation of the charging device 31 by the communication unit 351. Further, for example, the charge control instruction unit 353 receives a message (transmission / reception information) from the charging device 31 by the communication unit 351.
[0046] As an example, the message transmitted to the charging device 31 includes a control message for controlling power supply to the connected vehicle 4. As an example, the message transmitted to the charging device 31 includes a control message for controlling discharge from the connected vehicle 4. As an example, the message received from the charging device 31 includes a message indicating that the transmitted control message has been received. As an example, the message received from the charging device 31 includes a message indicating the status of power supply or discharge, such as the amount of power supplied or discharged, start time, end time, duration, and remaining battery level.
[0047] As an example, the message received from the charging device 31 includes a message indicating the status of the charging device 31 during power supply or discharge, such as observed values of temperature, communication bandwidth, etc. Note that these messages (transmission / reception information) may include a message for instructing the charging control mode (operation mode) for the charging device 31, or a message for notifying the charging control mode being executed or executed by the charging device 31.
[0048] The receiving unit 354 receives the first log information T1. Specifically, the receiving unit 354 receives the first log information T1 transmitted by the charging device 31. The receiving unit 354 receives the key information transmitted by the charging station management server 6.
[0049] The first generation unit 355 generates second log information. Specifically, the first generation unit 355 generates second log information corresponding to the first log information T1 received by the receiving unit 354. The second log information is information obtained by anonymizing private information and competitively confidential information. Here, the second log information will be described using FIG. 5.
[0050] FIG. 5 is a schematic diagram showing an example of the second log information according to the embodiment. The second log information T2 is, for example, a table in which items including "DST IP", "SRC IP", "site name", "user ID", "payment information", "vehicle ID", "charging device ID", "charging rate [%]", "output [kwh]", "remaining time [h]", "command", and "result" are associated.
[0051] The DST IP is, for example, the destination IP address where the log was received. The SRC IP is, for example, the source IP address from which the log was sent. The site name is, for example, the name of charging station 3. The command is, for example, the content of the control that the management device 35 performed on the charging device 31. The result is, for example, the result of the control that the management device 35 performed on the charging device 31.
[0052] Area 21 contains items related to privacy information and competitive confidential information. Therefore, the first generation unit 355 masks the logs of "site name," "user ID," "payment information," and "vehicle ID" in area 21 shown in Figure 5 and generates concealed second log information T2. In other words, if the log information contains concealed information that includes one or more pieces of privacy information or confidential information, the first generation unit 355 performs concealment control to conceal the concealed information. The first generation unit 355 then stores the generated second log information T2 in the storage unit 352.
[0053] The information to be concealed is not limited to this. The second log information T2 is not limited to this and may include, for example, the timestamp when the log was generated or the time when the charging device 31 started / stopped charging the vehicle 4. The second generation unit 356, described later, may perform concealment control to conceal the concealed information if the log information contains one or more pieces of private information or confidential information.
[0054] The second generation unit 356 generates encrypted log information. Specifically, the second generation unit 356 generates encrypted log information based on the key information received by the receiving unit 354 and the second log information T2 generated by the first generation unit 355. The encrypted log information is an example of the third log information. Here, the encrypted log information will be explained using Figure 6.
[0055] Figure 6 is a schematic diagram showing an example of encrypted log information according to the embodiment. The encrypted log information T3 is a table in which items such as "DST IP", "SRC IP", "Site name", "User ID", "Charging device ID", "Charging rate [%]", "Output [kWh]", "Remaining time [h]", "Instruction", and "Result" are associated.
[0056] The second generation unit 356 uses, for example, the encryption key included in the key information transmitted by the charging station management server 6 to encrypt the "DST IP", "SRC IP", "Site Name", "User ID", and "Charging Device ID" in area 22 shown in Figure 6, and generates encrypted log information T3. Area 22 contains items related to privacy information and competitive confidential information. Therefore, the second generation unit 356 encrypts the log shown in area 22 using, for example, the key included in the key information transmitted by the charging station management server 6. Then, the second generation unit 356 transmits the encrypted log information T3 generated at a predetermined time to the security monitoring server 7. A detailed explanation of the key information will be given later.
[0057] The encrypted log information T3 has a setting for the type of information to be concealed, which indicates the type of information to be concealed, in response to a detection event, which is a security event detected based on the encrypted log information T3. In other words, the second generation unit 356 controls the setting of the type of information to be concealed, which indicates the type of information to be concealed, in response to a detection event, which is a security event detected based on the log information. Furthermore, regarding the control of the setting of the type of information to be concealed, the second generation unit 356 sets an encryption key to encrypt the confidential information and a decryption key corresponding to the encryption key, in response to the detection event.
[0058] For example, the encrypted log information T3 monitored by the first terminal 8 and the encrypted log information T3 monitored by the second terminal 9 have different settings for the type of information to be concealed. A detailed explanation of the encrypted log information T3 monitored by the first terminal 8 and the encrypted log information T3 monitored by the second terminal 9 will be given later.
[0059] The encrypted log information T3 is not limited to this and may include, for example, the timestamp when the log was generated and the time when the charging device 31 started / stopped charging the vehicle 4. The second generation unit 356 does not encrypt the timestamp when the log was generated and the time when the charging device 31 started / stopped charging the vehicle 4, as these are items necessary for security monitoring.
[0060] The control device 35 may be installed inside the charging station 3 together with the charging device 31, or it may be installed outside the charging station 3. Furthermore, the control device 35 may control the charging devices 31 of other charging stations 3. In this case, the other charging stations 3 do not need to be equipped with the control device 35.
[0061] Returning to Figure 1, let's continue the explanation. The charging station management server 6 manages the charging station 3. For example, the charging station management server 6 is used by the operators of the charging station 3. Now, let's explain the functional configuration of the charging station management server 6 in Figure 7.
[0062] Figure 7 is a block diagram showing an example of the functional configuration of the charging station management server 6 according to the embodiment. As shown in Figure 7, the charging station management server 6 has a communication unit 611, a storage unit 612, and a key generation unit 613. However, the functions of the charging station management server 6 are not limited to these.
[0063] The communication unit 611 is a communication circuit that communicates with the outside world of the charging station management server 6. The communication unit 611 can be a wired or wireless communication circuit as appropriate. For wireless communication, a communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.
[0064] The storage unit 612 is a storage medium or storage device that stores control programs and parameters, data during processing, and processing result data related to each process executed by the charging station management server 6. The storage unit 612 is, for example, a semiconductor memory element such as RAM or flash memory, a hard disk, or an optical disc. The storage unit 612 may also be a storage device provided outside the charging station management server 6. Furthermore, the storage unit 612 may be a storage medium that stores or temporarily stores programs and various information downloaded via a LAN or the Internet.
[0065] The key generation unit 613 is implemented by one or more processors. For example, each of the above parts may be implemented by having a processor such as a CPU execute a program, i.e., by software. Each of the above parts may be implemented by a dedicated IC or other processor, i.e., by hardware. Each of the above parts may be implemented by using both software and hardware. When multiple processors are used, each processor may implement one of the parts, or two or more of the parts.
[0066] The key generation unit 613 generates key information including a key for the management device 35 to generate encrypted log information T3. Specifically, in response to a detection event, the key generation unit 613 generates an encryption key to encrypt the confidential information of the encrypted log information T3 and a decryption key corresponding to the encryption key, and generates key information including a key for the management device 35 to generate encrypted log information T3. Here, the key information will be explained using Figure 4.
[0067] Figure 8 is a schematic diagram showing an example of key information according to the embodiment. Key information T4 is a table in which items including "first key", "second key", "second key password", and "encryption area time zone" are associated.
[0068] The first key is, for example, a key used only by the analyst using the first terminal 8. The second key is, for example, a key used only by the analyst using the second terminal 9. The first and second keys are keys for decrypting the encrypted log information T3 generated by the management device 35. The password for the second key is the password for decrypting the second key. The encrypted area time zone is, for example, the time zone during which the first key, the second key, and the password for the second key are available.
[0069] For example, the key generation unit 613 generates a first key, a second key, and a password for the second key using a known method, and generates key information T4 including the generated first key, the second key, the password for the second key, and the encryption area time zone. The key generation unit 613 then transmits the generated key information T4 to the security monitoring server 7. The key generation unit 613 also generates an encryption key for encrypting confidential information corresponding to the first key and the second key, and generates key information T4 including the generated encryption key, the first key, the second key, the password for the second key, and the encryption area time zone. The key generation unit 613 then transmits the generated key information T4 to the management device 35.
[0070] Returning to Figure 1, the explanation continues. The security monitoring server 7 monitors the bidirectional communication between the charging device 31 and the management device 35. The security monitoring server 7 also detects security events indicating abnormalities or the risk of cyberattacks based on the control messages sent and received in this communication. Now, the functional configuration of the security monitoring server 7 will be explained using Figure 9.
[0071] Figure 9 is a block diagram showing an example of the functional configuration of a security monitoring server 7 according to an embodiment. As shown in Figure 9, the security monitoring server 7 includes a communication unit 711, a storage unit 712, a receiving unit 713, and an anomaly detection unit 714. However, the functions of the security monitoring server 7 are not limited to these.
[0072] The communication unit 711 is a communication circuit that communicates with the outside world of the security monitoring server 7. The communication unit 711 can be a wired or wireless communication circuit as appropriate. For wireless communication, a communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.
[0073] The storage unit 712 is a storage medium or storage device that stores control programs and parameters, data during processing, and processing result data related to each process executed by the security monitoring server 7. The storage unit 712 is, for example, a semiconductor memory element such as RAM or flash memory, a hard disk, or an optical disc. The storage unit 712 may also be a storage device located outside the security monitoring server 7. Furthermore, the storage unit 712 may be a storage medium that stores or temporarily stores programs and various types of information downloaded via a LAN or the Internet.
[0074] The receiving unit 713 receives key information T4. Specifically, the receiving unit 713 receives key information T4 transmitted by the charging station management server 6. The receiving unit 713 then stores the received encrypted log information T3 in the storage unit 712.
[0075] Furthermore, the receiving unit 713 receives encrypted log information T3. Specifically, the receiving unit 713 receives encrypted log information T3 transmitted by the management device 35. The receiving unit 713 then stores the received encrypted log information T3 in the storage unit 712.
[0076] The anomaly detection unit 714 performs anomaly detection regarding charging or discharging at the charging station 3 based on encrypted log information T3. For example, if the analysis results analyzed by the first terminal 8 or the second terminal 9 are not normal (abnormal), the anomaly detection unit 714 detects it as a security event. When the anomaly detection unit 714 detects a security event, it outputs detection information indicating the detection result to the storage unit 712 or an external source. As an example, the anomaly detection unit 714 transmits the detection information to the charging station management server 6 or the management device 35.
[0077] Returning to Figure 1, let's continue the explanation. The first terminal 8 and the second terminal 9 are information processing devices used by analysts who perform analysis of encrypted log information T3. The first terminal 8 and the second terminal 9 are configured to perform anomaly detection processing and analysis processing for anomaly detection according to the embodiment. For example, the first terminal 8 is a terminal that performs anomaly detection processing. The second terminal 9 is a terminal that performs analysis processing for anomaly detection. For example, the first terminal 8 receives anomaly detection processing from the security monitoring server 7. The second terminal 9 also receives analysis processing for anomaly detection from the first terminal 8.
[0078] Figure 10 is a block diagram showing an example of the functional configuration of the first terminal 8 according to the embodiment. As shown in Figure 9, the first terminal 8 has a communication unit 811, a storage unit 812, a display unit 813, an acquisition unit 814, a decoding unit 815, and an analysis unit 816. However, the functions of the first terminal 8 are not limited to these. Furthermore, since the functional configuration of the second terminal 9 is the same as that of the first terminal 8, the differences between the functions of the first terminal 8 and the functions of the second terminal 9 will be explained separately.
[0079] The communication unit 811 is a communication circuit that communicates with the security monitoring server 7. The communication unit 811 can be a wired or wireless communication circuit as appropriate. For wireless communication, a communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.
[0080] The storage unit 812 is a storage medium or storage device that stores control programs and parameters, data during processing, and processing result data related to each process executed on the first terminal 8. The storage unit 812 is, for example, a semiconductor memory element such as RAM or flash memory, a hard disk, or an optical disc. The storage unit 812 may also be a storage device provided outside the first terminal 8. Furthermore, the storage unit 812 may be a storage medium that stores or temporarily stores programs and various types of information downloaded via a LAN or the Internet.
[0081] The display unit 813 is a display that shows various types of information. Suitable display devices for this unit include liquid crystal displays (LCDs), organic EL (Electroluminescence) displays, and projectors.
[0082] The acquisition unit 814 of the first terminal 8 acquires various types of information. Specifically, the acquisition unit 814 of the first terminal 8 acquires key information T4 from the security monitoring server 7. The acquisition unit 814 of the first terminal 8 also acquires encrypted log information T3 from the security monitoring server 7. The acquisition unit 814 of the first terminal 8 stores the acquired key information T4 and encrypted log information T3 in the storage unit 812 of the first terminal 8.
[0083] The decryption unit 815 of the first terminal 8 decrypts the encrypted log information T3. Specifically, the decryption unit 815 of the first terminal 8 uses the key information T4 acquired by the acquisition unit 814 of the first terminal 8 to decrypt the encrypted log information T3. Here, the encrypted log information decrypted by the decryption unit 815 of the first terminal 8 will be explained with reference to Figure 11.
[0084] Figure 11 is a schematic diagram showing an example of decrypted encrypted log information according to the embodiment. The decrypted encrypted log information T5 shown in Figure 11 is log information decrypted by an analyst using the first terminal 8 with the first key. Area 23 is an item that remains confidential even after decryption. Specifically, the types of information to be kept confidential in area 23 are DST IP (destination IP address), SRC IP (receiving IP address), destination site information (site), and user ID using the first power equipment.
[0085] The decryption unit 815 of the first terminal 8 decrypts the encrypted log information T3 using the first key, which is included in the key information T4 acquired by the acquisition unit 814 and is associated with the time period to be decrypted. Comparing area 23 with area 22 shown in Figure 6, the item to be decrypted by the first key is the "charging device ID".
[0086] For example, an analyst using the first terminal 8 performs anomaly detection processing while checking the "charging device ID," "charging rate [%]," "output [kWh]," "remaining time [h]," "command," and "result" contained in the decrypted encrypted log information T5 output to the display unit 813.
[0087] Returning to Figure 10, the explanation continues. The analysis unit 816 of the first terminal 8 performs anomaly detection regarding charging or discharging at the charging station 3 based on the decrypted encrypted log information T5. Specifically, the analysis unit 816 of the first terminal 8 performs anomaly detection regarding charging or discharging at the charging station 3 based on the encrypted log information T5 decrypted by the decryption unit 815 of the first terminal 8.
[0088] Here, anomaly detection refers to a detection event where, for example, the output [kWh] item of the decrypted encrypted log information T5 shows an abnormal value. Here, an abnormal value means that the power output to the connected vehicle 4 is higher than normal (for example, 500 for the output [kWh] of the encrypted log information T5 in Figure 11). In other words, a detection event occurs when the output value output by the first power equipment exceeds a predetermined threshold. However, the content of anomaly detection is not limited to this.
[0089] Furthermore, if the analysis unit 816 of the first terminal 8 detects an anomaly from the decrypted encrypted log information T5, it transmits key information T4 obtained from the security monitoring server 7 to the second terminal 9 in order to identify the cause and scope of the anomaly and to determine and implement countermeasures to address the anomaly detection. The analyst using the second terminal 9 then performs an analysis of the anomaly detection from the first terminal 8. The details of the processing performed by the second terminal 9 will be explained below.
[0090] The acquisition unit 814 of the second terminal 9 acquires various types of information. Specifically, the acquisition unit 814 of the second terminal 9 acquires key information T4 from the first terminal 8. The acquisition unit 814 of the second terminal 9 acquires encrypted log information T3 from the security monitoring server 7. The acquisition unit 814 of the second terminal 9 stores the acquired encrypted log information T3 and key information T4 in the storage unit 812 of the second terminal 9.
[0091] The decryption unit 815 of the second terminal 9 decrypts the encrypted log information T3. Specifically, the decryption unit 815 of the second terminal 9 decrypts the encrypted log information T3 using the key information T4 acquired by the acquisition unit 814 of the second terminal 9. For example, if the detection event exceeds a predetermined threshold value output by the first power equipment, the decryption unit 815 of the second terminal 9 decrypts the encrypted log information T3 using the decryption key corresponding to the encryption key. The encrypted log information decrypted by the decryption unit 815 of the second terminal 9 will now be explained using Figure 12.
[0092] Figure 12 is a schematic diagram showing an example of decrypted encrypted log information according to the embodiment. The decrypted encrypted log information T6 shown in Figure 12 is log information decrypted by an analyst using the second key on the second terminal 9. Area 24 is an item that remains confidential even after decryption.
[0093] The decryption unit 815 of the second terminal 9 decrypts the second key using the password for the second key, which is associated with the time period to be decrypted and is included in the key information T4 acquired by the acquisition unit 814. Then, the decryption unit 815 of the second terminal 9 decrypts the encrypted log information T3 using the second key. Comparing area 24 with area 22 shown in Figure 6, the items decrypted by the second key are "User ID" and "Charging device ID".
[0094] For example, an analyst using the second terminal 9 performs an analysis of the anomaly detection while checking the "User ID," "Charging Device ID," "Charging Rate [%]," "Output [kWh]," "Remaining Time [h]," "Command," and "Result" contained in the decrypted encrypted log information T6 output to the display unit 813.
[0095] The analysis unit 816 of the second terminal 9 performs an analysis to respond to anomaly detection regarding charging or discharging at the charging station 3, based on the decrypted encrypted log information T6. Specifically, the analysis unit 816 of the second terminal 9 performs an analysis to respond to anomaly detection regarding charging or discharging at the charging station 3, based on the encrypted log information T6 decrypted by the decryption unit 815 of the second terminal 9. Then, the analysis unit 816 of the second terminal 9 performs an analysis to respond to anomaly detection and implements countermeasures to respond to said anomaly detection.
[0096] Here, the analysis corresponding to anomaly detection is, for example, the process of adding the user ID associated with an abnormal value of the output [kWh] to a blacklist. As a result, for example, when the analysis unit 816 of the second terminal 9 adds the user ID to the blacklist, authentication with the charging device 31 becomes impossible thereafter, and the charging device 31 cannot be used.
[0097] The content of the analysis is not limited to this. For example, the analysis unit 816 of the second terminal 9 sends an instruction to the security monitoring server 7 to stop the charging process for the user ID corresponding to the anomaly detection. The security monitoring server 7 sends an instruction to the management device 35 to stop the charging process, and the management device 35 may perform control to stop the charging process for the corresponding charging device ID.
[0098] Figure 13 is a sequence diagram showing an example of the processing flow executed by the charging system 1 according to the embodiment. The sequence diagram shown in Figure 13 explains the processing content up to the point when the security monitoring server 7 receives encrypted log information T3.
[0099] In step S131, the generation unit 313 of the charging device 31 generates first log information T1, which includes a log of communication data with the vehicle 4 connected to the charging device 31 and a log of communication data with the management device 35 connected to the charging device 31, and transmits the generated first log information T1 to the management device 35 within a predetermined time. In step S132, the receiving unit 354 of the management device 35 receives the first log information T1 transmitted by the charging device 31. In step S133, the key generation unit 613 of the charging station management server 6 generates key information T4, which includes a key for the management device 35 to generate encrypted log information T3.
[0100] In step S134, the key generation unit 613 of the charging station management server 6 transmits the generated key information T4 to the security monitoring server 7. In step S135, the receiving unit 713 of the security monitoring server 7 receives the key information T4 transmitted by the charging station management server 6. In step S136, the key generation unit 613 of the charging station management server 6 transmits the generated key information T4 to the management device 35. In step S137, the receiving unit 354 of the management device 35 receives the key information T4 transmitted by the charging station management server 6.
[0101] In step S138, the first generation unit 355 of the management device 35 generates second log information T2 corresponding to the first log information T1 received by the receiving unit 354. In step S139, the second generation unit 356 of the management device 35 generates encrypted log information T3 based on the key information T4 received by the receiving unit 354 and the second log information T2 generated by the first generation unit 355.
[0102] In step S140, the second generation unit 356 of the management device 35 transmits the encrypted log information T3 generated in a predetermined time to the security monitoring server 7. In step S141, the receiving unit 713 of the security monitoring server 7 receives the encrypted log information T3 transmitted by the management device 35.
[0103] Figure 14 is a sequence diagram showing an example of the processing flow executed by the charging system 1 according to this embodiment. The sequence diagram shown in Figure 14 explains the content of the processing up to the point when the second terminal 9 implements countermeasures in response to an anomaly detection.
[0104] In step S151, the acquisition unit 814 of the first terminal 8 acquires key information T4 from the security monitoring server 7. In step S152, the acquisition unit 814 of the first terminal 8 acquires encrypted log information T3 from the security monitoring server 7. In step S153, the decryption unit 815 of the first terminal 8 decrypts the encrypted log information T3 using the key information T4 acquired by the acquisition unit 814 of the first terminal 8.
[0105] In step S154, the analysis unit 816 of the first terminal 8 performs an anomaly detection regarding charging or discharging at the charging station 3 based on the encrypted log information T5 decrypted by the decryption unit 815 of the first terminal 8. In step S155, if the analysis unit 816 of the first terminal 8 detects an anomaly from the decrypted encrypted log information T5, it transmits the key information T4 obtained from the security monitoring server 7 to the second terminal 9. In step S156, the acquisition unit 814 of the second terminal 9 acquires the key information T4 from the first terminal 8.
[0106] In step S157, the acquisition unit 814 of the second terminal 9 acquires encrypted log information T3 from the security monitoring server 7. In step S158, the decryption unit 815 of the second terminal 9 decrypts the encrypted log information T3 using the key information T4 acquired by the acquisition unit 814 of the second terminal 9. In step S159, the analysis unit 816 of the second terminal 9 performs an analysis to respond to an anomaly detection regarding charging or discharging at the charging station 3, based on the encrypted log information T6 decrypted by the decryption unit 815 of the second terminal 9. In step S160, the analysis unit 816 of the second terminal 9 performs an analysis to respond to an anomaly detection and implements countermeasures to respond to the anomaly detection.
[0107] As described above, the information processing method performed by the management device 35 of this embodiment is an information processing method performed in an information processing device that transmits log information indicating a log of communication taking place between a first power facility configured to perform at least one of supplying and receiving power with connected charging and discharging equipment, and a second power facility that controls the first power facility. Furthermore, the information processing method of this embodiment includes performing concealment control to conceal confidential information if the log information includes one or more pieces of private information or confidential information.
[0108] Furthermore, the concealment control performed by the management device 35 of this embodiment includes controlling the setting of the type of information to be concealed, which indicates the type of information to be concealed, in response to a detection event, which is a security event detected based on log information. Furthermore, the concealment control performed by the management device 35 of this embodiment includes setting an encryption key to encrypt the confidential information and setting a decryption key corresponding to the encryption key, in response to a detection event.
[0109] For example, the management device 35 generates log information in which privacy information and competitive confidential information are concealed in the log information that the charging device 31 sends to the management device 35. The management device 35 then sends the concealed log information it has generated to the security monitoring server 7. Furthermore, the first terminal 8 and the second terminal 9 can monitor and analyze the power equipment because the concealed log information sent by the security monitoring server 7 is log information that can detect abnormalities in the charging station 3. As a result, the security monitoring server 7 can appropriately deal with abnormalities in the power equipment even with concealed log information.
[0110] The following describes other embodiments of the charging system 1 according to this disclosure with reference to the drawings. In the following descriptions of each embodiment, the differences will be mainly explained, and any content that overlaps with the above description will be omitted as appropriate.
[0111] (First modified example) For example, the management device 35 may transmit operational information regarding the operation of the charging station 3 to the charging station management server 6.
[0112] Figure 15 is a schematic diagram showing an example of operational information related to the first modified example. Operational information T7 is a table in which items including "DST IP", "SRC IP", "Site", "Communication Category", "Category", and "Detailed Content" are associated.
[0113] The communication category is, for example, information indicating the content of communication between devices managed by the management device 35. The category is, for example, information corresponding to the content of the communication category. The detailed content is information corresponding to the content of the category.
[0114] Areas 25 and 26 in the detailed contents of Operation Information T7 include items related to privacy information and competitive confidential information. In other words, the type of information to be anonymized in Areas 25 and 26 is operational information related to the operation of the second power facility.
[0115] For example, the first generation unit 355 masks the contents of area 25, which includes the "power consumption" consumed by the charging station 3, the "connected vehicle ID" connected to the charging device 31, and the "user ID" corresponding to the vehicle ID, as well as the contents of area 26, which includes the "suppression information" that the grid power 5 is suppressing and the "incentive information" indicating the usage fee when the user ID uses the charging device 31, and generates concealed operational information T7. The first generation unit 355 then transmits the generated operational information T7 to the charging station management server 6.
[0116] (Second Modification) In the second modification, a configuration is described in which the security monitoring server 7 monitors bidirectional communication between BESS 32 and the management device 35.
[0117] Figure 16 is a schematic diagram showing an example of the second log information relating to the second modification. The second log information T8 is a table in which items including, for example, "DST IP", "SRC IP", "Battery ID", "Site", "Communication Category", "Category", and "Detailed Content" are associated. The Battery ID is, for example, an identifier that identifies the battery owned by BESS32.
[0118] For example, the first generation unit 355 generates second log information T8 based on the battery status information transmitted by BESS 32. Area 27 in the detailed contents of the second log information T8 contains information that allows for the understanding of the operating status of BESS 32 and includes items related to competitive confidential information. Therefore, the first generation unit 355 masks the contents of area 27, such as the SOH value and SOC value of BESS 32, and generates an anonymized second log information T8. The first generation unit 355 then transmits the generated second log information T8 to the security monitoring server 7.
[0119] For example, the security monitoring server 7 monitors the BESS 32 based on its lifespan information, including its lifespan, transmitted by the charging station management server 6. When the lifespan of the BESS 32 is exceeded, the failure rate increases. If a faulty BESS 32 is used at the charging station 3, it may lead to a decrease in the operating rate of the charging station 3, for example. Therefore, the security monitoring server 7 needs to monitor the BESS 32.
[0120] Figure 17 is a block diagram showing an example of the functional configuration of the external server 2 according to the second modified example. As shown in Figure 17, the external server 2 has a communication unit 211, a storage unit 212, an acquisition unit 213, a specification unit 214, and a notification unit 215. However, the functions of the external server 2 are not limited to these.
[0121] The communication unit 211 is a communication circuit that communicates with the outside world of the external server 2. The communication unit 211 can be a wired or wireless communication circuit as appropriate. For wireless communication, a communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.
[0122] The storage unit 212 is a storage medium or storage device that stores control programs and parameters, data during processing, and processing result data related to each process executed on the external server 2. The storage unit 212 is, for example, a semiconductor memory element such as RAM or flash memory, a hard disk, or an optical disc. The storage unit 212 may also be a storage device located outside the external server 2. Furthermore, the storage unit 212 may be a storage medium that stores or temporarily stores programs and various types of information downloaded via a LAN or the Internet.
[0123] The storage unit 212 stores durability information, including the durability period of BESS 32. The durability information includes, for example, an identifier "battery ID" that identifies the battery in BESS 32, the "durability period" of the battery, and the "date and time of use" when the battery was first put into use. However, the durability information is not limited to this.
[0124] The acquisition unit 213, the identification unit 214, and the notification unit 215 are implemented by one or more processors. For example, each of the above units may be implemented by having a processor such as a CPU execute a program, i.e., by software. Each of the above units may be implemented by a dedicated IC or other processor, i.e., by hardware. Each of the above units may be implemented by using both software and hardware. When multiple processors are used, each processor may implement one of the above units, or two or more of the above units.
[0125] The acquisition unit 213 acquires the durability period information stored in the storage unit 212.
[0126] The identification unit 214 identifies the target equipment based on the durability period information. Specifically, the identification unit 214 determines, based on the durability period information acquired by the acquisition unit 213, whether the usage date and time included in the durability period information has elapsed for a predetermined period and has not exceeded the durability period, and identifies the target equipment.
[0127] The notification unit 215 generates target device information indicating the target device that has exceeded its service life, as identified by the identification unit 214, and transmits it to the charging station management server 6.
[0128] The key generation unit 613 of the charging station management server 6 generates a log information modification instruction based on the target device information transmitted by the external server 2 and transmits it to the management device 35. Here, the log information modification instruction modifies the mask content of the second log information generated by the management device 35. For example, the log information modification instruction for the second log information T8 shown in Figure 16 is an instruction to generate second log information that does not mask area 27.
[0129] The first generation unit 355 of the management device 35 generates second log information based on the battery status information transmitted by BESS 32 and the log information change instruction transmitted by the charging station management server 6, and transmits it to the security monitoring server 7. In other words, the first generation unit 355 of the management device 35 changes the setting of the type of information to be concealed when the lifespan of the first power equipment is exceeded.
[0130] Then, the receiving unit 713 of the security monitoring server 7 receives the second log information transmitted by the management device 35. This allows the security monitoring server 7 to check the concealed SOC value and SOH value, and to detect equipment failures early based on the SOC value and SOH value.
[0131] Figure 18 is a sequence diagram showing an example of the processing flow performed by the charging system 1 according to the second modified example.
[0132] In step S181, the acquisition unit 213 of the external server 2 acquires the durability period information stored in the storage unit 212. In step S182, the identification unit 214 of the external server 2 determines, based on the durability period information acquired by the acquisition unit 213, whether the usage date and time included in the durability period information has elapsed for a predetermined period and has not exceeded the durability period, and identifies the target equipment. In step S183, the notification unit 215 generates target equipment information indicating the target equipment that has exceeded its durability period, as identified by the identification unit 214, and transmits it to the charging station management server 6.
[0133] In step S184, the key generation unit 613 of the charging station management server 6 generates a log information change instruction based on the target device information transmitted by the external server 2 and transmits it to the management device 35. In step S185, the first generation unit 355 of the management device 35 generates second log information based on the battery status information transmitted by BESS 32 and the log information change instruction transmitted by the charging station management server 6.
[0134] In step S186, the first generation unit 355 of the management device 35 transmits the generated second log information to the security monitoring server 7. In step S187, the receiving unit 713 of the security monitoring server 7 receives the second log information transmitted by the management device 35.
[0135] As explained above, the information processing method performed by the management device 35 of the second modified example changes the setting of the type of data to be concealed when the lifespan of the first power equipment is exceeded. This allows the security monitoring server 7 to check the concealed SOC values and SOH values, and to detect equipment failures early from the SOC values and SOH values.
[0136] (Third Modification) In the third modification, a configuration is described in which the security monitoring server 7 monitors bidirectional communication between the power meter 33 and the management device 35.
[0137] Figure 19 is a schematic diagram showing an example of the second log information related to the third modified example. The second log information T9 is a table in which items such as "DST IP", "SRC IP", "Power Meter ID", "Site", "Communication Category", "Category", and "Detailed Content" are associated. The Power Meter ID is, for example, an identifier that identifies the power meter 33.
[0138] For example, the first generation unit 355 generates second log information based on the power output transmitted by the power meter 33. Area 28 in the detailed contents of the second log information T9 contains information that allows for the determination of the power consumption of the charging station 3 and includes items related to competitive confidential information. Therefore, the first generation unit 355 masks the contents of area 28 related to the power consumption of the charging station 3 and generates anonymized second log information T9. The first generation unit 355 then transmits the generated second log information T9 to the security monitoring server 7.
[0139] For example, the security monitoring server 7 monitors the power meter 33 based on demand reduction instructions sent by the charging station management server 6. Here, demand reduction refers to the operation of supplying power to the vehicle 4 when the grid power 5 is congested and power supply is restricted due to the power shortage. For example, when the grid power 5 is congested, an increase in power consumption by the charging station 3 due to an external cyberattack may increase the possibility of a blackout. Therefore, the security monitoring server 7 needs to monitor the power meter 33.
[0140] Figure 20 is a block diagram showing an example of the functional configuration of the external server 2 according to the third modified example. As shown in Figure 20, the external server 2 has a communication unit 211, a storage unit 212, an acquisition unit 213, a specification unit 214, and a notification unit 215, as well as a detection unit 216.
[0141] The detection unit 216 is implemented by one or more processors. For example, each of the above parts may be implemented by having a processor such as a CPU execute a program, i.e., by software. Each of the above parts may be implemented by a dedicated IC or other processor, i.e., by hardware. Each of the above parts may be implemented by using both software and hardware. When multiple processors are used, each processor may implement one of the parts, or two or more of the parts.
[0142] The storage unit 212 stores power information indicating the power status of the grid power 5. The power information includes, for example, the available power value of the grid power 5 and the power demand value of the grid power 5. However, the power information is not limited to this.
[0143] The acquisition unit 213 acquires power information stored in the storage unit 212.
[0144] The detection unit 216 detects a critical situation based on power information. Specifically, the detection unit 216, based on the power information acquired by the acquisition unit 213, determines whether the difference between the power value of the power demand of the grid power 5 included in the power information and the power value of the grid power 5 that can be supplied is greater than or equal to a predetermined threshold, and detects a critical situation. Here, the predetermined threshold is the value at which the grid power 5 is in a critical state.
[0145] The notification unit 215 generates a demand suppression instruction corresponding to the critical situation detected by the detection unit 216 and transmits it to the charging station management server 6.
[0146] The key generation unit 613 of the charging station management server 6 generates a log information modification instruction based on the demand suppression instruction transmitted by the external server 2 and transmits it to the management device 35. Here, the log information modification instruction modifies the mask content of the second log information generated by the management device 35. For example, the log information modification instruction for the second log information T9 shown in Figure 19 is an instruction to generate second log information that does not mask area 28.
[0147] The first generation unit 355 of the management device 35 generates second log information based on the power results transmitted by the power meter 33 and the log information change instruction transmitted by the charging station management server 6, and transmits it to the security monitoring server 7. In other words, the first generation unit 355 of the management device 35 changes the setting of the type of information to be concealed when the grid power 5 is in a critical state.
[0148] Then, the receiving unit 713 of the security monitoring server 7 receives the second log information transmitted by the management device 35. This allows the security monitoring server 7 to check the power consumption value of the concealed charging station 3 and detect whether the power consumption has been increased illegally.
[0149] Figure 21 is a sequence diagram showing an example of the processing flow performed by the charging system 1 according to the third modified example. Steps S186 and S187 shown in Figure 21 are the same processes as steps S186 and S187 shown in Figure 20, so their explanation is omitted.
[0150] In step S211, the acquisition unit 213 of the external server 2 acquires power information stored in the storage unit 212. In step S212, the detection unit 216 of the external server 2 determines, based on the power information acquired by the acquisition unit 213, whether the difference between the power value of the power demand of the grid power 5 included in the power information and the power value that the grid power 5 can supply is greater than or equal to a predetermined threshold, and detects a critical condition. In step S213, the notification unit 215 of the external server 2 generates a demand suppression instruction corresponding to the critical condition detected by the detection unit 216 and transmits it to the charging station management server 6.
[0151] In step S214, the key generation unit 613 of the charging station management server 6 generates a log information change instruction based on the demand suppression instruction transmitted by the external server 2 and transmits it to the management device 35. In step S215, the first generation unit 355 of the management device 35 generates second log information based on the power result transmitted by the power meter 33 and the log information change instruction transmitted by the charging station management server 6.
[0152] As explained above, the information processing method performed by the management device 35 of the third modified example changes the setting of the type of data to be concealed when the grid power 5 is in a strained state. This allows the security monitoring server 7 to check the power consumption value of the concealed charging station 3 and detect whether the power consumption has been increased illegally.
[0153] (Fourth Modification) For example, when the security monitoring server 7 issues a warning indicating the detection of an anomaly at the charging station 3, the management device 35 may generate unencrypted log information in which the information to be encrypted is not encrypted. This is because, when a warning is issued for the charging station 3, the security monitoring server 7 needs more detailed information about the second log information in order to identify the cause and prevent further damage. For example, the security monitoring server 7 checks whether an unauthorized user is operating the charging station 3 and implements countermeasures.
[0154] Figure 22 is a sequence diagram showing an example of the processing flow performed by the charging system 1 according to the fourth modified example. Steps S186 and S187 shown in Figure 22 are the same processes as steps S186 and S187 shown in Figure 20, so their explanation is omitted.
[0155] In step S221, the anomaly detection unit 714 of the security monitoring server 7 transmits warning information to the charging station management server 6 indicating that an anomaly has been detected in the charging station 3.
[0156] In step S222, the key generation unit 613 of the charging station management server 6 generates a log information modification instruction based on the warning information transmitted by the security monitoring server 7. This log information modification instruction generates unencrypted log information that is not encrypted, for the encrypted log information generated by the management device 35. For example, in the encrypted log information T3 shown in Figure 6, the log information modification instruction is an instruction not to encrypt area 22. The key generation unit 613 of the charging station management server 6 then transmits the generated log information modification instruction to the management device 35.
[0157] In step S223, in step S215, the second generation unit 356 of the management device 35 generates unencrypted log information based on the log information change instruction transmitted by the charging station management server 6 and the second log information T2 generated by the first generation unit 355. In other words, if the first power equipment is in a warning state, the second generation unit 356 of the management device 35 changes the setting of the type of data to be concealed. In step S224, the second generation unit 356 of the management device 35 transmits the generated unencrypted log information to the security monitoring server 7. In step S225, the receiving unit 713 of the security monitoring server 7 receives the unencrypted log information transmitted by the management device 35.
[0158] As explained above, the information processing method performed by the management device 35 of the fourth modified example changes the setting of the type of data to be concealed when the first power equipment is in a warning state. This allows the security monitoring server 7 to check the log information that has not been encrypted and to take immediate action to recover from the warning information.
[0159] Next, an example of the hardware configuration of the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generator 34, and management device 35 in the above embodiment and modified examples will be described.
[0160] (Hardware Configuration) Figure 23 is a block diagram showing an example of the hardware configuration of the charging system 1 according to the embodiment and modified examples.
[0161] In the above embodiment and its modified form, the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generator 34, and management device 35 are interconnected via a bus 18, with a CPU 10, ROM (Read Only Memory) 12, RAM 14, and I / F unit 16, etc., and have a hardware configuration using a normal computer.
[0162] The CPU 10 is a computing device that controls the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generation device 34, and management device 35 of the above embodiment and modified versions. The ROM 12 stores programs and the like that realize information processing by the CPU 10. The RAM 14 stores data necessary for various processes by the CPU 10. The I / F unit 16 is an interface connected to the storage unit, input unit, display unit, sensor, and communication unit, etc., for sending and receiving data.
[0163] In the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generator 34, and management device 35 of the above embodiment and its modifications, the CPU 10 reads a program from ROM 12 onto RAM 14 and executes it, thereby realizing each of the above-mentioned functional units on the computer.
[0164] Furthermore, the programs for executing the above-mentioned processes performed by the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generator 34, and management device 35 in the above-described embodiment and modified version may be stored in an HDD (hard disk drive). Alternatively, the programs for executing the above-mentioned processes performed by the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generator 34, and management device 35 in the above-described embodiment and modified version may be pre-installed and provided in ROM 12.
[0165] Furthermore, the programs for executing the above-described processes performed by the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generator 34, and management device 35 of the above-described embodiment and modified version may be stored in an installable or executable file format on a computer-readable storage medium such as a CD-ROM, CD-R, memory card, DVD (Digital Versatile Disk), or flexible disk (FD), and provided as a computer program product.
[0166] Furthermore, the program for executing the above-mentioned information processing performed by the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generation device 34, and management device 35 of the above-described embodiment and modified example may be stored on a computer connected to a network such as the Internet and provided by allowing download via the network. Alternatively, the program for executing the above-mentioned information processing performed by the external server 2, charging station management server 6, security monitoring server 7, first terminal 8, second terminal 9, charging device 31, BESS 32, power meter 33, power generation device 34, and management device 35 of the above-described embodiment and modified example may be provided or distributed via a network such as the Internet.
[0167] According to at least one embodiment described above, even with concealed log information, abnormalities in power equipment can be dealt with appropriately.
[0168] Although embodiments have been described above, these embodiments are presented as examples only and are not intended to limit the scope of the invention. This novel embodiment can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. This embodiment and its variations are included in the scope and spirit of the invention, as well as in the claims of the invention and its equivalents.
[0169] (Note) The various aspects of this disclosure are described below as a summary in the notes. (1) An information processing method performed in an information processing device that transmits log information indicating a log relating to communication between a first power facility configured to be able to supply and receive power to at least one of connected charging and discharging equipment and a second power facility that controls the first power facility, wherein if the log information includes confidential information including one or more pieces of privacy information or confidential information, the information processing method includes performing anonymization control to conceal the confidential information. (2) The information processing method according to (1) above, wherein performing the anonymization control includes controlling the setting of anonymization target type indicating the type of confidential information to be concealed in response to a detection event which is a security event detected based on the log information. (3) The information processing method according to (2) above, wherein controlling the setting of anonymization target type includes setting an encryption key to encrypt the confidential information and setting a decryption key corresponding to the encryption key in response to the detection event. (4) The information processing method according to (3) above, wherein controlling the setting of the type of information to be concealed includes setting a decryption key corresponding to the encryption key when the detection event exceeds a predetermined threshold value output by the first power equipment. (5) The information processing method according to (4) above, wherein the type of information to be concealed includes the IP address of the destination, the IP address of the recipient, the site information of the destination, and the user ID of the first power equipment. (6) The information processing method according to (3) above, wherein the type of information to be concealed includes operational information relating to the operation of the second power equipment. (7) The information processing method according to (2) above, wherein controlling the setting of the type of information to be concealed includes changing the setting of the type of information to be concealed when at least one of the following conditions is met: the lifespan of the first power equipment has been exceeded, the grid power is in a state of shortage, or the first power equipment is in a warning state.(8) An information processing device that transmits log information indicating a log of communication taking place between a first power facility configured to be able to supply power and receive power to a connected charging and discharging device and a second power facility that controls the first power facility, the information processing device comprising at least one processor configured to perform concealment control to conceal the concealed information if the log information includes one or more pieces of private information or confidential information. (9) An information processing program that causes a computer that implements an information processing device that transmits log information indicating a log of communication taking place between a first power facility configured to be able to supply power and receive power to a connected charging and discharging device and a second power facility that controls the first power facility, to perform concealment control to conceal the concealed information if the log information includes one or more pieces of private information or confidential information.
[0170] 1 Charging system 2 External server 3 Charging station 4 Vehicle 5 Grid power 6 Charging station management server 7 Security monitoring server 8 First terminal 9 Second terminal 31 Charging device 32 BESS 34 Power generation device 35 Management device 351 Communication unit 352 Storage unit 353 Charging control instruction unit 354 Receiving unit 355 First generation unit 356 Second generation unit
Claims
1. An information processing method performed in an information processing device that transmits log information indicating a log relating to communication between a first power facility configured to perform at least one of supplying and receiving power with connected charging and discharging equipment, and a second power facility that controls the first power facility, the method comprising: if the log information includes confidential information containing one or more pieces of private information or confidential information, performing anonymization control to conceal the confidential information.
2. The information processing method according to claim 1, wherein the concealment control includes controlling the setting of the type of concealment target, which indicates the type of information to be concealed, in response to a detection event, which is a security event detected based on the log information.
3. The information processing method according to claim 2, wherein controlling the setting of the type of information to be concealed includes setting an encryption key for encrypting the concealed information and setting a decryption key corresponding to the encryption key in response to the detection event.
4. The information processing method according to claim 3, wherein controlling the setting of the type of data to be concealed includes setting a decryption key corresponding to the encryption key if the detection event exceeds a predetermined threshold value output by the first power equipment.
5. The information processing method according to claim 4, wherein the type of information to be anonymized includes the IP address of the destination, the IP address of the recipient, the site information of the destination, and the user ID of the first power equipment.
6. The information processing method according to claim 3, wherein the type of information to be anonymized includes operational information relating to the operation of the second power equipment.
7. The information processing method according to claim 2, wherein the setting of the type of information to be concealed is changed when at least one of the following conditions is met: the lifespan of the first power equipment has been exceeded, the grid power is in a state of shortage, or the first power equipment is in a warning state.
8. An information processing device that transmits log information indicating a log relating to communication between a first power facility configured to perform at least one of supplying and receiving power to a connected charging and discharging device, and a second power facility that controls the first power facility, the information processing device comprising at least one processor configured to perform concealment control to conceal the concealed information if the log information includes one or more pieces of private information or confidential information.
9. An information processing program for a computer that implements an information processing device that transmits log information indicating a log of communication taking place between a first power facility configured to perform at least one of supplying and receiving power with connected charging and discharging equipment, and a second power facility that controls the first power facility, and for causing the computer to perform concealment control to conceal the concealed information if the log information includes one or more pieces of private information or confidential information.