Method, apparatus, battery management system and storage medium for managing encryption keys
By integrating update keys in the key switching application and performing validity verification, the flexibility and security issues of vehicle battery pack key updates are solved, and are suitable for situations where vehicles cannot connect to the Internet.
Patent Information
- Application Number
- CN202210044990.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-14
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-01-14
AI Technical Summary
The existing vehicle battery pack key update method has poor flexibility and security, and is restricted by the vehicle network environment and is prone to tampering.
Integrate the update key in the key switching application, transmit it through different transmission methods, and perform validity verification before application to ensure the security of the key switching application.
It realizes the flexibility and security of key updates, avoids security risks during transmission, and is suitable for situations where vehicles cannot be connected to the Internet.
Smart Images

Figure CN115834029B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of vehicle safety, and more particularly, to a method and apparatus for managing keys, a battery management system, and a storage medium. Background Art
[0002] During the usage cycle of a vehicle battery pack, the operating enterprise corresponding to the battery pack may change. Along with the change of the operating enterprise, the key inside the battery pack also needs to be updated.
[0003] The existing key update method is as follows: The vehicle controller connects to a remote vehicle management server, obtains an updated key from the vehicle management server, and then changes the key of the battery pack to the updated key to achieve key update. This key update method has poor flexibility and security. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to provide a method and apparatus for managing keys, a battery management system, and a storage medium, so as to improve the flexibility and security of key update.
[0005] In a first aspect, an embodiment of the present application provides a method for managing keys, including: obtaining a key switching application program; the key switching application program includes a first key; determining that the key switching application program is a valid key switching application program; and updating a second key of a battery pack to the first key through the key switching application program.
[0006] In the technical solution of the embodiment of the present application, the updated key (i.e., the first key) is integrated in the key switching application program, and the key of the battery pack is updated through the key switching application program. On the one hand, the key switching application program can be transmitted to the battery management system through different transmission methods. For example: online transmission or offline transmission, etc., without being restricted by the vehicle network environment, and the key can be updated when the vehicle is not connected to the network, improving the flexibility of key update. On the other hand, the updated key is integrated in the key switching application program. By verifying the validity of the key switching application program, when it is determined that the key switching application program is valid, it is applied, realizing the secure use of the key switching application program, without considering the security risks during the transmission process, and improving the security of key update.
[0007] In some embodiments, the key switching application further includes signature information, which includes a third key and the ciphertext corresponding to the key switching application. The encryption key corresponding to the ciphertext is the encryption key corresponding to the third key. Determining that the key switching application is a valid key switching application includes: determining whether the third key is the same as the second key; if the third key is the same as the second key, decrypting the ciphertext based on the third key to obtain a first hash value; performing a hash calculation on the key switching application to obtain a second hash value; determining whether the first hash value is the same as the second hash value; if the first hash value is the same as the second hash value, determining that the key switching application is a valid key switching application.
[0008] In the technical solution of the embodiments of the present application, the key switching application further includes signature information, which includes a third key and a ciphertext. By determining whether the third key is the same as the second key, it can be determined whether the identity of the provider of the key switching application is legal. When the identity is determined to be legal, the ciphertext is then decrypted to obtain a first hash value, and then the second hash value obtained by performing a hash calculation based on the key switching application is compared with the first hash value. If the two are the same, it means that the key switching application has not been tampered with, and the key switching application is a valid key switching application.
[0009] Through the above verification process, the security of the key switching application is effectively verified, ensuring the security of key update.
[0010] In some embodiments, the second key is stored in a one-time programmable memory.
[0011] In the technical solution of the embodiments of the present application, by storing the second key in a one-time programmable memory, since the content stored in the one-time programmable memory cannot be changed once written, the reliability of the second key can be ensured, and thus the validity of the key switching application can be verified reliably and accurately.
[0012] In some embodiments, the key switching application further includes: a key switching code; updating the second key of the battery pack to the first key through the key switching application includes: by running the key switching code, writing the first key into the one-time programmable memory and invalidating the second key.
[0013] In the technical solution of the embodiment of the present application, although the second key cannot be changed, it can be invalidated. Therefore, by using the key switching code, the original key is invalidated and a new key (i.e., the first key) is written to achieve effective key update.
[0014] In some embodiments, the key switching application further includes: a list of battery pack serial numbers that allow key change; the management method further includes: obtaining the battery pack serial number of the battery pack; determining whether the battery pack serial number belongs to the list of battery pack serial numbers that allow key change; correspondingly, updating the second key of the battery pack to the first key through the key switching application includes: if the battery pack serial number belongs to the list of battery pack serial numbers that allow key change, updating the second key of the battery pack to the first key through the key switching application.
[0015] In the technical solution of the embodiment of the present application, by means of the list of battery pack serial numbers that allow key change, the battery packs capable of key update can be limited. Furthermore, in application, for the battery packs with key change value, key update can be performed; while for the battery packs without key change value, key update can be not performed, improving the flexibility of key update.
[0016] In some embodiments, the battery pack serial number is stored in a one-time programmable memory.
[0017] In the technical solution of the embodiment of the present application, by storing the battery pack serial number in a one-time programmable memory, since the content stored in the one-time programmable memory cannot be changed once written, the battery pack serial number cannot be illegally tampered with. Therefore, the reliability of the battery pack serial number can be ensured, and thus an effective and accurate judgment on whether to update the key can be achieved.
[0018] In some embodiments, the battery pack corresponds to a first operation end and a second operation end, and the second operation end is another operation end that replaces the first operation end; the designer of the key switching application is the first operation end, the provider of the second key is the first operation end, and the provider of the first key is the second operation end.
[0019] In the technical solution of the embodiment of the present application, when another operation end needs to replace the original operation end, the key to be updated (i.e., the second key) in the battery pack is provided by the original operation end. Therefore, the original operation end designs a key switching application program and writes the update key (i.e., the first key) of the other operation end into the key switching application program, so that the key switching application program can realize the key update. In this application scenario, the other operation end and the original operation end can negotiate the key and can also negotiate some contents included in the key switching application program, improving the flexibility of key update.
[0020] In some embodiments, the obtaining of the key switching application program includes: obtaining the key switching application program uploaded by the second operation end.
[0021] In the technical solution of the embodiment of the present application, based on the above application scenario, after the first operation end designs the key switching application program, it can be provided to the second operation end, and then the second operation end directly uploads it to the battery management system. Therefore, this key update method is not restricted by the vehicle network environment and can update the key when the vehicle is not connected to the network, improving the flexibility of key update.
[0022] In a second aspect, an embodiment of the present application provides a key management device, including: each functional module for implementing the key update method described in the first aspect and any possible implementation manner of the first aspect.
[0023] In a third aspect, an embodiment of the present application provides a battery management system, including: a processor; and a memory communicatively connected to the processor; wherein, the memory stores instructions executable by the processor, and when the instructions are executed by the processor, the processor can execute the key management method described in the first aspect and any possible implementation manner of the first aspect.
[0024] In a fourth aspect, an embodiment of the present application provides a battery, including: the battery management system described in the third aspect.
[0025] In a fifth aspect, an embodiment of the present application provides an electrical device, including: the battery described in the fourth aspect.
[0026] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a computer, it executes the key management method described in the first aspect and any possible implementation manner of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the accompanying drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0028] Figure 1 Structural schematic diagram of the vehicle provided by the embodiment of the present application;
[0029] Figure 2 Flowchart of the key management method provided by the embodiment of the present application;
[0030] Figure 3 Schematic diagram of the signature process of the key switching application provided by the embodiment of the present application;
[0031] Figure 4 Schematic diagram of the verification process of the key switching application provided by the embodiment of the present application;
[0032] Figure 5 Structural schematic diagram of the key management device provided by the embodiment of the present application;
[0033] Figure 6 Structural schematic diagram of the battery management system provided by the embodiment of the present application.
[0034] Icons: 1000 - vehicle; 200 - battery; 500 - key management device; 510 - acquisition module; 520 - processing module; 600 - battery management system; 610 - processor; 620 - memory. Detailed implementation manners
[0035] The following will describe the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings in the embodiments of the present application.
[0036] In the description of the embodiments of the present application, the term "and / or" is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
[0037] In the description of the embodiments of the present application, the term "plural" refers to two or more (including two). Similarly, "multiple groups" refers to two or more groups (including two groups), and "multiple pieces" refers to two or more pieces (including two pieces).
[0038] In the description of the embodiments of the present application, unless otherwise clearly defined and limited, technical terms such as "installation", "connection", "connection", "fixation" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or integrated; it can also be a mechanical connection or an electrical connection; it can be directly connected, or indirectly connected through an intermediate medium, and can be the communication inside two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to specific situations.
[0039] At present, from the perspective of the development of the market situation, the application of batteries is becoming more and more extensive. Batteries are not only used in energy storage power systems such as hydropower, thermal power, wind power, and solar power stations, but also widely used in electric vehicles such as electric bicycles, electric motorcycles, and electric vehicles, as well as in many fields such as military equipment and aerospace. With the continuous expansion of the application fields of power batteries, the market demand is also constantly increasing.
[0040] Currently, during the entire life cycle of a vehicle battery pack, the operating enterprises may change. For example, the original equipment manufacturer of the battery can be regarded as the primary operating enterprise of the battery pack. As the vehicle is used, the State Of Health (SOH) of the battery gradually decreases. Some battery packs with low remaining capacity can be reused by other operating enterprises, such as being used in energy storage. At this time, the operating enterprise of the battery will change, and the internal key of the battery pack also needs to be switched, that is, the internal key of the battery pack needs to be updated.
[0041] During the key update process, the original equipment manufacturer needs to ensure the security of its original key, and only the battery packs designated by the original equipment manufacturer can change the key.
[0042] The applicant's research found that in the existing key update method, since the vehicle controller needs to obtain the update key from the vehicle management server, and the vehicle controller and the vehicle management server communicate through Ethernet, it is required that the vehicle where the battery pack is located has the ability to connect to Ethernet. In fact, the vehicle may be unable to connect to the network due to reasons such as arrears or faults. That is, limited by the vehicle network environment, the existing keys cannot be updated flexibly.
[0043] Moreover, the transmission between the vehicle controller and the vehicle management server generally uses non-encrypted communication. For a third party, by adopting certain communication deception means, the key used for update can be replaced with other keys, resulting in the finally updated key not being the correct key, and the security is relatively low.
[0044] After careful consideration by the applicant, if the key for update is not used as the direct transmission object, the problem that the key is easily tampered with can be solved. Moreover, if the acquisition of the update key does not depend on the Ethernet communication between the vehicle controller and the vehicle management server, the problem that the key transmission relies on the vehicle network environment can be solved.
[0045] Based on this, the applicant has designed a technical solution to improve the flexibility and security of key update. This technical solution integrates the update key into the key switching application program, and realizes the update of the key of the battery pack through the key switching application program.
[0046] On the one hand, the key switching application program can be designed by the original equipment manufacturer. After being designed, it is transmitted to the battery management system through different transmission methods, and is no longer restricted by the vehicle network environment. The key can be updated when the vehicle is not connected to the network, improving the flexibility of key update.
[0047] On the other hand, the update key is integrated in the key switching application program. Before applying the key switching application program, its validity can be verified. When it is determined that the key switching application program is valid, it is applied to realize the safe use of the key switching application program. Equivalently, an insecure key switching application program will not be applied, so there is no need to consider the security risks during the transmission process, improving the security of key update.
[0048] Therefore, adopting the technical solution provided by the embodiment of the present application can improve the flexibility and security of key update.
[0049] The technical solution provided by the embodiment of the present application can be applied to the battery management system of the battery. The battery can be used in power-consuming devices such as vehicles, ships or aircraft, but is not limited thereto. In this way, it is beneficial to the security and flexibility of key update of the power-consuming device.
[0050] For the convenience of description, the following embodiments take the power-consuming device as a vehicle as an example for description.
[0051] Please refer to Figure 1 , which is a schematic structural diagram of the vehicle 1000 provided by the embodiment of the present application. The vehicle 1000 can be a fuel vehicle, a gas vehicle or a new energy vehicle. The new energy vehicle can be a pure electric vehicle, a hybrid vehicle or an extended-range vehicle, etc.
[0052] A battery 200 is arranged inside the vehicle 1000, and a battery management system 600 is arranged on the battery 200.
[0053] In some embodiments of the present application, the battery 200 can not only be used as the operating power source of the vehicle, but also be used as the driving power source of the vehicle, completely or partially replacing fuel or natural gas to provide driving power for the vehicle.
[0054] In the above vehicle 1000, the battery management system 600 is used to manage the battery pack key of the battery 200.
[0055] In some embodiments, the number of battery packs of the battery can be one or multiple, and multiple battery packs correspond to keys. When the operating enterprise changes, the keys of some battery packs may need to be updated, while the keys of some battery packs do not need to be updated.
[0056] The battery management system 600 can manage the keys of the battery packs based on the key switching application program. Therefore, the hardware operating environment of the technical solution provided in the embodiments of the present application is the battery management system 600.
[0057] In the application scenario of updating the keys of the battery packs, after determining that an enterprise change needs to be made, the primary operating enterprise and the secondary operating enterprise negotiate which battery packs need to be handed over, and then the primary operating enterprise sorts the battery pack sequences of these battery packs into a list.
[0058] Then, the secondary operating enterprise provides its own key (i.e., the update key) to the primary operating enterprise, and the primary operating enterprise designs a key switching application program based on the above list and the update key provided by the secondary operating enterprise.
[0059] After designing the key switching application program, the primary operating enterprise signs it to generate an encrypted key switching application program, and the encrypted key switching application program has signature information.
[0060] The primary operating enterprise or the secondary operating enterprise can download the encrypted key switching application program to the battery management system 600, and the battery management system 600 realizes the update of the key based on the encrypted key switching application program.
[0061] In the above application scenario, the primary operating enterprise can be the original equipment manufacturer, and the secondary operating enterprise can be an operating enterprise that cooperates with the original equipment manufacturer and is responsible for taking over the operation and management of the battery pack.
[0062] In some embodiments, after the secondary operating enterprise takes over the operation and management of the battery pack, if there is a subsequent change in the operating enterprise, at this time, the identity of the secondary operating enterprise can be equivalent to that of the primary operating enterprise, and the changed operating enterprise can be equivalent to the secondary operating enterprise.
[0063] That is, the above-mentioned primary operation enterprise and secondary operation enterprise should be understood in a broad sense. The primary operation enterprise can be understood as the operation enterprise before the change, and the secondary operation enterprise can be understood as the operation enterprise after the change. In different application scenarios, based on different operation change requirements, there can be multiple implementation methods for the primary operation enterprise and the secondary operation enterprise, which are not limited in the embodiments of this application.
[0064] Based on the above introduction of the inventive concept and application scenarios, next, please refer to Figure 2 , which is a flowchart of the key management method provided by the embodiments of this application. The management method includes:
[0065] Step 210: Obtain a key switching application. The key switching application includes a first key.
[0066] Step 220: Determine that the key switching application is a valid key switching application.
[0067] Step 230: Update the second key of the battery pack to the first key through the key switching application.
[0068] In step 210, the first key can be understood as the update key of the battery pack, that is, the key managed by the operation enterprise after the change.
[0069] In step 230, the second key can be understood as the original key of the battery pack, that is, the key managed by the operation enterprise before the change.
[0070] In some embodiments, if the asymmetric encryption method is adopted, then both the first key and the second key are public keys, that is, the battery pack holds the public key of the asymmetric encryption, while the operation enterprise has both the public key and the private key.
[0071] In the technical solution of the embodiments of this application, the update key (i.e., the first key) is integrated in the key switching application, and the key update of the battery pack is realized through the key switching application. On the one hand, the key switching application can be transmitted to the battery management system through different transmission methods, such as online transmission or offline transmission, without being restricted by the vehicle network environment, and the key can be updated when the vehicle is not connected to the network, improving the flexibility of key update. On the other hand, the update key is integrated in the key switching application. By verifying the validity of the key switching application, when it is determined that the key switching application is valid, it is applied to realize the safe use of the key switching application, without considering the security risks during the transmission process, and improving the security of key update.
[0072] In some embodiments, the key switching application further includes signature information, which includes a third key and an encrypted ciphertext corresponding to the key switching application, and the encryption key corresponding to the encrypted ciphertext is the encryption key corresponding to the third key. Step 220 includes: determining whether the third key is the same as the second key; if the third key is the same as the second key, decrypting the encrypted ciphertext based on the third key to obtain a first hash value; performing a hash calculation on the key switching application to obtain a second hash value; determining whether the first hash value is the same as the second hash value; if the first hash value is the same as the second hash value, determining that the key switching application is a valid key switching application.
[0073] In this embodiment, an asymmetric encryption method is adopted. The third key can be understood as the public key of the primary operating enterprise, and the encryption key corresponding to the third key can be understood as the private key of the primary operating enterprise.
[0074] Based on this, the process of the primary operating enterprise signing the key switching application can be as Figure 3 shown. In Figure 3 , the primary operating enterprise first performs a hash calculation on the key switching application to obtain a hash calculation value. Then, the private key is used to encrypt the hash calculation value to generate an encrypted ciphertext. Finally, based on the encrypted ciphertext and the third key (i.e., the Figure 3 public key), signature information is generated. Finally, the signature information and the key switching application are integrated into a key switching application including the signature information.
[0075] Then, for the battery management system, after obtaining the key switching application including the signature information, the validity of the key switching application can be verified based on the signature information.
[0076] In the technical solution of the embodiment of the present application, the key switching application further includes signature information, which includes a third key and an encrypted ciphertext. By determining whether the third key is the same as the second key, the identity of the provider of the key switching application can be determined whether it is legal. In the case of legal identity, the encrypted ciphertext is further decrypted to obtain a first hash value, and then the second hash value obtained by performing a hash calculation based on the key switching application is compared with the first hash value. If the two are the same, it indicates that the key switching application has not been tampered with, and the key switching application is a valid key switching application.
[0077] Through the above verification process, the effective verification of the security of the key switching application is realized, and the security of key update is ensured.
[0078] In some embodiments, the second key is stored in a one-time programmable memory.
[0079] It can be understood that by storing the second key in the one-time programmable memory, since the content stored in the one-time programmable memory cannot be changed once written, the second key has reliability, thereby ensuring reliable and accurate verification of the effectiveness of the key switching application.
[0080] Combined with the introduction of the signature process of the above-mentioned primary operating enterprise, please refer to Figure 4 , which is a schematic diagram of the battery management system verifying the key switching application.
[0081] In this verification process, first, it is judged whether the public key stored in the one-time programmable memory (i.e., the second public key) is consistent with the public key in the signature information (i.e., the third public key). If the two are consistent, it means that the public key in the signature information is correct. If the two are inconsistent, it means that the public key in the signature information is incorrect.
[0082] If the public key in the signature information is incorrect, it is directly determined that the key switching application is not a valid key switching application.
[0083] If the public key in the signature information is correct, the encrypted ciphertext can be decrypted using the public key to obtain the decrypted hash value (i.e., the first hash value). Also, a hash calculation is performed on the key switching application to obtain the calculated hash value (i.e., the second hash value). Then, the decrypted hash value and the calculated hash value are compared. If the two are consistent, it means that the key switching application has not been tampered with and is a valid key switching application. If the two are inconsistent, it means that the key switching application may have been tampered with and is not a valid key switching application.
[0084] If the key switching application is not a valid key switching application, the key switching application will not be applied, that is, the key will not be updated.
[0085] The above-mentioned implementation manner corresponds to the implementation manner of asymmetric encryption. If symmetric encryption is used, the corresponding verification method of symmetric encryption can be referred to to implement the verification of the key switching application.
[0086] It can be understood that if the second key is stored in the one-time programmable memory, it cannot be directly modified during the update. However, it can be invalidated and a new key can be written to achieve key update.
[0087] As an optional implementation manner, the key switching application further includes: a key switching code. Step 230 includes: by running the key switching code, writing the first key into the one-time programmable memory and invalidating the second key.
[0088] In this embodiment, the primary operating enterprise first designs a key switching code, the function of which is to invalidate the original key and write a new key. Therefore, after the key switching code is run, the first key is written into the one-time programmable memory, and the second key is invalidated.
[0089] In some embodiments, the number of keys that can be written into the one-time programmable memory may be limited. In this case, the number of times of change of the operating enterprise corresponding to the battery pack is limited, that is, the key cannot be updated infinitely.
[0090] In the technical solution of the embodiment of the present application, although the second key cannot be changed, it can be invalidated. Therefore, by using the key switching code, the original key is invalidated and a new key (i.e., the first key) is written to achieve effective update of the key.
[0091] As mentioned in the introduction of the foregoing application scenario, the primary operating enterprise and the secondary operating enterprise can also negotiate which battery packs need to be handed over. Therefore, as an alternative embodiment, the key switching application further includes: a list of battery pack serial numbers allowed to change keys. The management method further includes: obtaining the battery pack serial number of the battery pack; determining whether the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys. Correspondingly, step 230 includes: if the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys, updating the second key of the battery pack to the first key through the key switching application.
[0092] In this embodiment, the list of battery pack serial numbers allowed to change keys includes multiple battery pack serial numbers, and these multiple battery pack serial numbers are the serial numbers of the battery packs that the primary operating enterprise and the secondary operating enterprise have negotiated to hand over.
[0093] After the battery management system obtains the battery pack serial number of the battery pack, it matches the battery pack serial number with each battery pack serial number in the list of battery pack serial numbers allowed to change keys. If the same battery pack serial number as the obtained battery pack serial number is found in each battery pack serial number, it is determined that the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys; otherwise, it is determined that the battery pack serial number does not belong to the list of battery pack serial numbers allowed to change keys.
[0094] Furthermore, if the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys, step 230 is executed; otherwise, step 230 is not executed, that is, the key is not updated.
[0095] In the technical solution of the embodiment of the present application, by allowing the list of battery pack serial numbers whose keys can be changed, the battery packs capable of key update can be limited. Furthermore, during application, for the battery packs with the value of key change, key update can be performed; while for the battery packs without the value of key change, key update can be not performed, thus improving the flexibility of key update.
[0096] In some embodiments, the battery pack serial number is stored in a one-time programmable memory.
[0097] It can be understood that the one-time programmable memory here and the one-time programmable memory storing the second key mentioned above can be the same memory, that is, both the battery pack serial number and the second key are stored in the one-time programmable memory.
[0098] In the technical solution of the embodiment of the present application, by storing the battery pack serial number in a one-time programmable memory, since the content stored in the one-time programmable memory cannot be changed once written, the battery pack serial number cannot be illegally tampered with, ensuring the reliability of the battery pack serial number, and further realizing an effective and accurate judgment on whether to update the key.
[0099] Combined with the introduction of the foregoing embodiments, as an optional implementation manner, the battery pack corresponds to a first operation end and a second operation end, and the second operation end is another operation end that replaces the first operation end; the designer of the key switching application is the first operation end, the provider of the second key is the first operation end, and the provider of the first key is the second operation end.
[0100] Among them, the first operation end can be understood as the aforementioned primary operation enterprise, and the second operation end can be understood as the aforementioned secondary operation enterprise.
[0101] Then, the designer of the key switching application is the first operation end, and the provider of the second key is the first operation end, that is, the second operation end provides the updated key, and then the first operation end designs the key switching application according to the updated key and its own key.
[0102] In the technical solution of the embodiment of the present application, when another operation end needs to replace the original operation end, the key to be updated (i.e., the second key) in the battery pack is provided by the original operation end. Therefore, the original operation end designs the key switching application and writes the updated key (i.e., the first key) of the other operation end into the key switching application, so that the key switching application can realize key update. In this application scenario, the other operation end and the original operation end can negotiate on the key and can also negotiate on some contents included in the key switching application, improving the flexibility of key update.
[0103] Based on the above implementations, for the battery management system, when obtaining the password switching application, multiple implementations can be adopted, some of which may depend on the vehicle network environment, and some of which may not depend on the vehicle network environment.
[0104] As an optional implementation, step 210 includes: obtaining a key switching application uploaded by the second operator.
[0105] In this implementation, after the first operator designs the key switching application, the key switching application can be sent to the second operator via online or offline transmission, and then the second operator transmits the key switching application to the battery management system via online or offline transmission.
[0106] The online transmission method may include but is not limited to: email transmission, Bluetooth transmission or other feasible transmission methods.
[0107] Offline transmission methods, for example: store the key switching application in a USB flash drive, then insert the USB flash drive into the vehicle controller, and upload the key switching application to the battery management system. Another example: connect two transmission devices with a data cable, and then transmit the key switching application between the two transmission devices. The two transmission devices here can be: the first operating terminal and the second operating terminal; or, the second operating terminal and the battery management system.
[0108] In the embodiment of the present application, the hardware forms of the first operating end and the second operating end may be electronic devices such as computers and mobile phones.
[0109] Compared with the prior art, the technical solution provided by the embodiment of the present application has the following advantages: easy implementation, not limited by the vehicle network environment, and the battery pack key can be updated when the vehicle cannot be connected to the Internet. The implementation cost is low, no support from the vehicle management background is required, and no diagnostic equipment that can be connected to the Internet is required. The information security risk is low, and only the validity of the key switching application needs to be verified, and there is no need to consider the security of the transmission process.
[0110] Based on the same invention concept, please refer to Figure 5 In the embodiment of the present application, a key management device 500 is also provided. It should be understood that the key management device 500 can execute the key management method of the above embodiments. Accordingly, the parts not described in detail in the following embodiments can refer to the above embodiments.
[0111] The key management device 500 includes at least one software function module that can be stored in a memory in the form of software or firmware or fixed in the operating system of the key management device 500. Specifically:
[0112] The key management device 500 includes: an acquisition module 510 and a processing module 520.
[0113] The acquisition module 510 is configured to acquire a key switching application; the key switching application includes a first key. The processing module 520 is configured to: determine that the key switching application is a valid key switching application; update a second key of the battery pack to the first key through the key switching application.
[0114] In an embodiment of the present application, the processing module 520 is specifically configured to: determine whether the third key is the same as the second key; if the third key is the same as the second key, decrypt the encrypted ciphertext based on the third key to obtain a first hash value; perform a hash calculation on the key switching application to obtain a second hash value; determine whether the first hash value is the same as the second hash value; if the first hash value is the same as the second hash value, determine that the key switching application is a valid key switching application.
[0115] In an embodiment of the present application, the processing module 520 is specifically configured to: write the first key into the one-time programmable memory by running the key switching code, and invalidate the second key.
[0116] In an embodiment of the present application, the acquisition module 510 is further configured to: acquire the battery pack serial number of the battery pack; the processing module 520 is further configured to: determine whether the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys; and is specifically configured to: if the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys, update the second key of the battery pack to the first key through the key switching application.
[0117] In an embodiment of the present application, the acquisition module 510 is specifically configured to: acquire the key switching application uploaded by the second operation end.
[0118] It should be understood that, for the sake of brevity of description, some content described in the method embodiments will not be repeated in this embodiment.
[0119] Please refer to Figure 6 , an embodiment of the present application further provides a battery management system 600, including: a processor 610; and, a memory 620 communicatively connected to the processor 610. The memory 620 stores instructions executable by the processor 610, and when the instructions are executed by the processor 610, the processor 610 can execute one or more programs stored in the memory 620 to implement the key management method in the above embodiment.
[0120] In some embodiments, the component used to implement the communication connection between the processor 610 and the memory 620 is a communication bus.
[0121] It can be understood that Figure 6 The structure shown is only schematic, and the battery management system 600 may also include more or fewer components than those shown Figure 6 in the figure, or have a different configuration from that Figure 6 shown.
[0122] In the embodiments of the present application, a computer-readable storage medium is also provided, such as a floppy disk, an optical disc, a hard disk, a flash memory, a USB flash drive, an SD (Secure Digital Memory Card) card, an MMC (Multimedia Card) card, etc. One or more programs for implementing the above steps are stored in the computer-readable storage medium. These one or more programs can be executed by one or more processors to implement the key management method in the above embodiments, which will not be elaborated here.
[0123] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some communication interfaces. The indirect couplings or communication connections of the devices or units can be electrical, mechanical or other forms.
[0124] In addition, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0125] Furthermore, in each embodiment of the present application, the various functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.
[0126] In this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0127] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A method for managing a secret key, characterized in that, Including: Obtain a key switching application; the key switching application includes a first key; Determine that the key switching application is a valid key switching application; Update the second key of the battery pack to the first key through the key switching application; The key switching application further includes signature information, which includes a third key and an encrypted ciphertext corresponding to the key switching application, and the encryption key corresponding to the encrypted ciphertext is the encryption key corresponding to the third key; The determining that the key switching application is a valid key switching application includes: Determine whether the third key and the second key are consistent; If the third key and the second key are consistent, decrypt the encrypted ciphertext based on the third key to obtain a first hash value; Perform a hash calculation on the key switching application to obtain a second hash value; Determine whether the first hash value and the second hash value are consistent; If the first hash value and the second hash value are consistent, determine that the key switching application is a valid key switching application.
2. The management method according to claim 1, wherein The second key is stored in a one-time programmable memory.
3. The management method according to claim 2, wherein The key switching application further includes: a key switching code; the updating the second key of the battery pack to the first key through the key switching application includes: By running the key switching code, write the first key into the one-time programmable memory and invalidate the second key.
4. The management method according to claim 1, wherein The key switching application further includes: a list of battery pack serial numbers allowed to change keys; the management method further includes: Obtain the battery pack serial number of the battery pack; Determine whether the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys; Correspondingly, the updating the second key of the battery pack to the first key through the key switching application includes: If the battery pack serial number belongs to the list of battery pack serial numbers allowed to change keys, update the second key of the battery pack to the first key through the key switching application.
5. The management method according to claim 4, characterized in that The battery pack serial number is stored in a one-time programmable memory.
6. The management method according to claim 1, characterized in that, The battery pack corresponds to a first operation end and a second operation end, and the second operation end is another operation end replacing the first operation end; the design party of the key switching application is the first operation end, the provider of the second key is the first operation end, and the provider of the first key is the second operation end.
7. The management method according to claim 6, characterized in that, The obtaining the key switching application includes: Obtain the key switching application uploaded by the second operation end.
8. A key management device implemented by using the method according to any one of claims 1 to 7, characterized in that, Including: An obtaining module, configured to obtain a key switching application; the key switching application includes a first key; A processing module, configured to: determine that the key switching application is a valid key switching application; update the second key of the battery pack to the first key through the key switching application.
9. A battery management system, characterized in that, Including: A processor; And a memory communicatively connected to the processor; Wherein, the memory stores instructions executable by the processor, and when the instructions are executed by the processor, the processor is enabled to execute the method for managing the key according to any one of claims 1 to 7.
10. A battery, characterized in that, Comprising the battery management system according to claim 9.
11. An electrical device, characterized in that, Comprising the battery according to claim 10.
12. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is run by a computer, it executes the method for managing the key according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method and apparatus for verifying battery authenticity
CN105793815A
Secret key updating method, gateway, control device, electronic equipment and medium
CN113259933A