Transaction verification method and device of charging pile, computer device and storage medium

By installing a dedicated security chip in the billing control terminal of the charging pile and using symmetric encryption algorithm and digital certificate authentication, the security protection problem of a multi-gun charging pile is solved, and higher security and integrity of charging transactions are achieved.

CN116331047BActive Publication Date: 2025-11-07BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310309021.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-27
Publication Date
2025-11-07
Estimated Expiration
2043-03-27

AI Technical Summary

Technical Problem

Existing billing control terminals lack sufficient security protection in multi-gun charging piles, making them vulnerable to cyberattacks and illegal operations, and failing to effectively guarantee the security and integrity of charging transactions.

Method used

A dedicated security chip is installed in the billing control terminal of the charging pile. Through symmetric encryption algorithm and digital certificate security authentication, the confidentiality and integrity of data are achieved, preventing the forgery of the billing control terminal identity and replay attacks, and supporting charging services with multiple guns on one pile.

Benefits of technology

This improves the security level of the charging control system, prevents the forgery of billing control terminal identities and illegal operations, and ensures the security and integrity of charging transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116331047B_ABST
    Figure CN116331047B_ABST
Patent Text Reader

Abstract

The application discloses a transaction verification method of a charging pile, which is applied to a billing control terminal of the charging pile and comprises the following steps: in the case that a charging card is read, determining a machine gun identifier of a target charging machine gun selected for providing electric energy and frozen resource data in the charging card, and acquiring a terminal identifier and a key index number from a security chip; in the case that the key index number can be supported by the charging card, receiving a pseudo-random number and a resource offline transaction serial number sent by the charging card; sending an initialization gray lock message authentication code calculation command to the security chip to obtain a sub-key corresponding to a consumption key; and sending a gray lock command to the charging card to instruct the charging card to perform transaction verification. Thus, the special security chip of the billing control terminal is used for safe data interaction, so that malicious damage of the charging control system caused by attack means such as forging of the identity of the billing control terminal and replay attack can be effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, and particularly relates to a transaction verification method and device of a charging pile, a computer device and a storage medium. BACKGROUND

[0002] An electric vehicle uses a power battery as a power source, has the advantages of small noise, no pollution and low loss, and is gradually becoming the mainstream of the automobile industry. A charging pile, as a main electric vehicle charging facility, is an important node linking electric vehicles, energy and data. In the existing electric vehicle charging pile technology implementation, the charging control technology of the charging pile is the key.

[0003] As an important part of the charging control technology of the charging pile, the billing control terminal is mainly responsible for reading a charging billing card, charging billing, communicating and interacting with the Internet of Vehicles through a network, and other functions. It is crucial to ensure the normal operation of the charging pile and to realize the remote communication between the Internet of Vehicles and the charging pile.

[0004] In the related art, the billing control terminal generally supports secure charging services in a one-pile-one-gun mode. However, with the gradual development and popularization of electric vehicles, one-pile-multiple-gun charging piles are gradually replacing one-pile-one-gun charging piles, and the security protection level of the billing control terminal needs to be improved. SUMMARY

[0005] The present application aims to at least solve one of the technical problems in the related art. To this end, the first object of the present application is to propose a transaction verification method of a charging pile, which can support the security protection of one-pile-multiple-gun charging services based on the security data interaction of the special security chip of the billing control terminal, and improve the protection level of the charging control system.

[0006] The second object of the present application is to propose a transaction verification device of a charging pile.

[0007] The third object of the present application is to propose a computer device.

[0008] The fourth object of the present application is to propose a computer-readable storage medium.

[0009] To achieve the above object, the first aspect of the present application provides a transaction verification method of a charging pile, applied to a billing control terminal of the charging pile; the charging pile has at least one charging gun; a terminal identifier, a consumption key and a key index number of the billing control terminal are stored in a security chip of the billing control terminal; the method comprises: in the case of reading a charging card, determining a gun identifier of a target charging gun selected to provide electric energy and frozen resource data in the charging card, and obtaining the terminal identifier and the key index number from the security chip; in the case that the key index number can be supported by the charging card, receiving a pseudo-random number and a resource offline transaction serial number sent by the charging card; sending an initialization gray lock message authentication code calculation command carrying the gun identifier to the security chip, to instruct the security chip to calculate the consumption key according to a terminal transaction serial number, the gun identifier, the pseudo-random number and the resource offline transaction serial number, to obtain a sub-key corresponding to the consumption key; calculating a transaction type identifier, transaction time data, the terminal identifier and the frozen resource data by using the sub-key, to obtain a first message authentication code; sending a gray lock command based on the first message authentication code, a terminal random number, the transaction time data and the terminal transaction serial number to the charging card, to instruct the charging card to perform transaction verification on the first message authentication code.

[0010] According to one embodiment of the present application, before receiving the pseudo-random number and the resource offline transaction serial number sent by the charging card in the case that the key index number can be supported by the charging card, the transaction verification method of the charging pile further comprises: sending a gray lock wallet initialization command based on the gun identifier, the frozen resource data, the terminal identifier and the key index number to the charging card, to instruct the charging card to verify the key index number, and if the verification is passed, sending the pseudo-random number and the resource offline transaction serial number to the billing control terminal.

[0011] According to one embodiment of the present application, the transaction verification method of the charging pile further comprises: in the case that the first message authentication code passes the transaction verification, receiving a second message authentication code sent by the charging card, to verify the legitimacy of the charging card.

[0012] According to one embodiment of the present application, the transaction verification method of the charging pile further comprises: in the case that the charging operation is completed, sending a gray lock verification code calculation instruction to the security chip based on the transaction type identifier, the charging card identifier, the resource offline transaction serial number and the resource transaction data, to instruct the security chip to calculate a gray lock verification code and a secure storage module check code using the sub-key; and sending the resource transaction data, the resource offline transaction serial number, the terminal identifier, the machine gun identifier, the terminal transaction serial number, the transaction time data, the gray lock verification code and the secure storage module check code to the charging card.

[0013] According to one embodiment of the present application, the security chip further stores a first random number; and the transaction verification method of the charging pile further comprises: sending handshake information to a security gateway based on the first random number, to instruct the security gateway to issue a second random number, link certificate data, initial signature data and an initial signature value; sending the handshake information, the second random number, the link certificate data, the initial signature data and the initial signature value to the security chip, to instruct the security chip to extract a signature verification public key from the link certificate data; verifying the initial signature data and the initial signature value using the signature verification public key; calculating a handshake digest value based on the handshake information, and calculating a handshake digest signature value of the handshake digest value using the signature verification public key; receiving the handshake digest value and the handshake digest signature value sent by the security chip; and sending a key agreement instruction to the security chip, to instruct the security chip to generate a pre-master key according to the first random number, the second random number and the client version number, and to derive a working key based on the pre-master key.

[0014] According to one embodiment of the present application, the transaction verification method of the charging pile further comprises: receiving client verification data sent by the security chip; wherein the client verification data is calculated based on the handshake digest value and a client label pre-stored in the security chip.

[0015] According to one embodiment of the present application, the transaction verification method of the charging pile further comprises: receiving pre-master key ciphertext sent by the security chip; wherein the pre-master key ciphertext is obtained by encrypting a pre-master key using a working key by the security chip; combining the client verification data, a client certificate and the pre-master key ciphertext to obtain client result data; and sending the client result data to the security gateway, to instruct the security gateway to verify the client result data.

[0016] According to an embodiment of the present application, the transaction verification method of the charging pile further comprises: receiving the service end verification data returned by the security gateway; wherein the service end verification data is used to instruct the security chip to verify the security gateway and establish a connection with the security gateway.

[0017] According to an embodiment of the present application, the transaction verification method of the charging pile further comprises: receiving the ciphertext of the application data and the verification code; decrypting the ciphertext of the application data by using the working key to obtain the plaintext of the application data; performing a corresponding application layer protocol processing operation according to the plaintext of the application data to obtain the execution result data of the application layer protocol processing operation; and sending the execution result data to the security chip to instruct the security chip to calculate the ciphertext and the verification code of the execution result data.

[0018] According to an embodiment of the present application, the transaction verification method of the charging pile further comprises: sending the chip information of the security chip to the Internet of Vehicles platform to instruct the Internet of Vehicles platform to generate authentication data based on the chip information; receiving the authentication data sent by the Internet of Vehicles platform; the authentication data is used to instruct the security chip to verify the authentication data and generate authentication verification information and an application session key; and sending the authentication verification information to the Internet of Vehicles platform to instruct the Internet of Vehicles platform to verify the authentication verification information.

[0019] According to an embodiment of the present application, the transaction verification method of the charging pile further comprises: sending the specified type data agreed in advance with the mobile client to the security chip to instruct the security chip to encrypt the specified type data; receiving the encrypted specified type data and displaying a graphical code generated based on the encrypted specified type data; and establishing a communication connection with the mobile client in the case that the mobile client scans the graphical code and decrypts the encrypted specified type data in the graphical code.

[0020] According to an embodiment of the present application, the transaction verification method of the charging pile further comprises: obtaining the controller information of the controller of the charging pile; the controller information comprises a controller serial number and a symmetric key version number; sending the first control random number generated by the security chip to the controller to instruct the security chip of the controller to calculate the authentication data of the first control random number and generate a second control random number; receiving the authentication data of the first control random number and the second control random number; sending a control instruction to the security chip to instruct the security chip to encrypt the control instruction by using the controller serial number, the authentication data of the first control random number and the second control random number; and sending the encrypted control instruction to the controller.

[0021] According to one embodiment of the present application, the transaction verification method of the charging pile further comprises: sending a meter reading instruction to the electric meter; the meter reading instruction carries the electric meter random number generated by the security chip, and the meter reading instruction is used to instruct the security chip of the electric meter to generate security reading data in a preset security mode based on the electric meter random number; the preset security mode comprises a plaintext mac mode, a ciphertext mode and a ciphertext mac mode; receiving the security reading data sent by the electric meter and verifying the security reading data.

[0022] To achieve the above-mentioned purpose, the second aspect of the present application provides a transaction verification device of a charging pile, which is applied to a billing control terminal of the charging pile; the charging pile has at least one charging gun; a terminal identifier, a consumption key and a key index number of the billing control terminal are stored in a security chip of the billing control terminal; the device comprises: a charging card reading module, which is used to read a charging card; a resource data determining module, which is used to determine a gun identifier of a target charging gun selected to provide electric energy and frozen resource data in the charging card when the charging card is read; an identifier and index number obtaining module, which is used to obtain the terminal identifier and the key index number from the security chip; a random number and serial number receiving module, which is used to receive a pseudo-random number and a resource offline transaction serial number sent by the charging card when the key index number can be supported by the charging card; an authentication code calculation command sending module, which is used to send an initialization gray lock message authentication code calculation command carrying the gun identifier to the security chip, so as to instruct the security chip to calculate the consumption key according to a terminal transaction serial number, the gun identifier, the pseudo-random number and the resource offline transaction serial number, and obtain a sub-key corresponding to the consumption key; the sub-key is used to calculate a transaction type identifier, transaction time data, the terminal identifier and the frozen resource data, and obtain a first message authentication code; a gray lock command sending module, which is used to send a gray lock command to the charging card based on the first message authentication code, a terminal random number, the transaction time data and the terminal transaction serial number, so as to instruct the charging card to perform transaction verification on the first message authentication code.

[0023] According to one embodiment of the present application, the transaction verification device of the charging pile further comprises: an initialization command sending module, which is used to send a gray lock wallet initialization command to the charging card based on the gun identifier, the frozen resource data, the terminal identifier and the key index number, so as to instruct the charging card to verify the key index number, and send a pseudo-random number and a resource offline transaction serial number to the billing control terminal if the verification is passed.

[0024] According to one embodiment of the present application, the transaction verification device of the charging pile further comprises: a verification code calculation instruction sending module, configured to send a gray lock verification code calculation instruction to the secure chip based on the transaction type identifier, the charging card identifier, the resource offline transaction serial number and the resource transaction data, to instruct the secure chip to calculate a gray lock verification code and a secure storage module check code using the sub-key; and a transaction data sending module, configured to send the resource transaction data, the resource offline transaction serial number, the terminal identifier, the machine gun identifier, the terminal transaction serial number, the transaction time data, the gray lock verification code and the secure storage module check code to the charging card.

[0025] To achieve the above object, the third aspect of the present application provides a computer device, comprising a memory and a processor, the memory stores a computer program, and the processor implements the steps of the method according to any one of the preceding embodiments when executing the computer program.

[0026] To achieve the above object, the fourth aspect of the present application provides a computer readable storage medium, which stores a computer program, and the computer program implements the steps of the method according to any one of the preceding embodiments when executed by a processor.

[0027] According to the embodiments of the present application, a special secure chip is installed in the charging pile billing control terminal, so that the billing control terminal can realize the confidentiality, integrity and security of the service data transmitted between the internal and external communication interaction objects of the charging pile based on the secure chip. This can prevent malicious damage to the charging control system caused by attack means such as fake billing control terminal identity and replay attack, and can support the security protection of one-pile multi-gun charging service, thereby effectively improving the security protection level of the charging control system.

[0028] Additional aspects and advantages of the present application will be made apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0029] Figure 1 A scene diagram for the charging pile transaction verification method according to one embodiment of the present application.

[0030] Figure 2a A flowchart of the charging pile transaction verification method according to one embodiment of the present application.

[0031] Figure 2b A flowchart of the charging pile transaction verification method according to one embodiment of the present application.

[0032] Figure 3a Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0033] Figure 3b Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0034] Figure 4 Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0035] Figure 5 Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0036] Figure 6 Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0037] Figure 7a Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0038] Figure 7b Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0039] Figure 8a Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0040] Figure 8b Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0041] Figure 8c Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0042] Figure 8d Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0043] Figure 9a Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0044] Figure 9b Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0045] Figure 9c Flowchart of a charging pile transaction verification method according to an embodiment of the present specification.

[0046] Figure 10a A flowchart of a transaction verification method of a charging pile according to an embodiment of the present specification.

[0047] Figure 10b A flowchart of a transaction verification method of a charging pile according to an embodiment of the present specification.

[0048] Figure 11a A flowchart of a transaction verification method of a charging pile according to an embodiment of the present specification.

[0049] Figure 11b A flowchart of a transaction verification method of a charging pile according to an embodiment of the present specification.

[0050] Figure 12a A structural block diagram of a transaction verification device of a charging pile according to an embodiment of the present specification.

[0051] Figure 12b A structural block diagram of a transaction verification device of a charging pile according to an embodiment of the present specification.

[0052] Figure 12c A structural block diagram of a transaction verification device of a charging pile according to an embodiment of the present specification.

[0053] Figure 13 A structural block diagram of a computer device according to an embodiment of the present specification. DETAILED DESCRIPTION

[0054] Embodiments of the present application are described in detail below with reference to examples thereof shown in the attached drawings, wherein the same or similar reference numerals denote the same or similar elements throughout. The embodiments described below by reference to the drawings are exemplary and are intended to explain the present application, and cannot be understood as limiting the present application.

[0055] An electric vehicle is a vehicle powered by a power battery. Compared with a conventional vehicle powered by energy such as oil, an electric vehicle has the advantages of low noise, no pollution, low loss, etc., and is gradually becoming the mainstream of the automobile industry.

[0056] In order to facilitate charging of electric vehicles, the state has invested a large amount of funds for the construction of charging stations for electric vehicles. As the main electric vehicle charging facility in a charging station, a charging pile is an important node linking electric vehicles, energy and data, and is an important part of the automobile Internet and the energy Internet. In the existing technical implementation of electric vehicle charging piles, the charging control technology of the charging pile is a key part.

[0057] The charging control technology of the charging pile is mainly realized through a charging pile control system. The charging pile control system includes a charging device controller and a billing control terminal. The billing control terminal, as an important device in the charging pile, is mainly responsible for reading a charging billing card, charging and collecting fees, communicating with a vehicle network, controlling a liquid crystal display of the charging pile, and other functions. It is crucial for ensuring the normal operation and accurate billing of the charging pile, and for realizing remote communication and remote control of the vehicle network to the charging pile.

[0058] In related technologies, in a first aspect, a billing control terminal is usually arranged for a one-pile-one-gun charging pile to support safe charging services in a one-pile-one-gun mode. However, with the gradual development and popularization of electric vehicles, the charging demand of electric vehicles is increasing, and the development of low-cost charging piles has become an inevitable trend for the development of electric vehicle charging stations. A one-pile-one-gun charging pile will gradually develop into a one-pile-multi-gun charging pile to meet the application scenario that multiple users can use one charging pile at the same time. In this case, the billing control terminal for a one-pile-one-gun charging pile cannot meet the safety protection technical requirements of a one-pile-multi-gun charging pile. In a second aspect, the billing control terminal of the charging pile usually communicates directly with a vehicle network platform through an Ethernet interface. The communication line between the billing control terminal and the vehicle network platform is vulnerable to network attack risks from public networks or private networks. Attackers can damage the integrity and correctness of the data transmitted between the billing control terminal and the vehicle network platform by maliciously copying or tampering with confidential information. In a third aspect, the billing control terminal of the charging pile usually sends control commands to the charging device controller of the charging pile through a CAN bus. Attackers can steal electricity and other illegal operations by impersonating the identity of a false billing control terminal and sending abnormal control instructions to the charging device controller as the billing control terminal. In a fourth aspect, the billing control terminal of the charging pile usually communicates directly with the charging pile application on the user's mobile phone through a Bluetooth interface. Since Bluetooth technology itself has certain security risks, communication through the Bluetooth interface is vulnerable to attacks from various Bluetooth hackers, which puts higher security protection requirements on the Bluetooth communication between the billing control terminal and the charging pile application on the user's mobile phone.

[0059] In order to improve the security protection level of the charging pile billing control terminal in all aspects, it is necessary to propose a charging pile transaction verification method which can support the security protection of the charging service of one pile and multiple guns. A special security chip is installed in the charging pile billing control terminal and the charging device controller. The special security chip of the billing control terminal can be used to store and manage the key and digital certificate of the billing control terminal, and to perform cryptographic operations. Based on the special security chip, the billing control terminal adopts symmetric encryption algorithm data encryption and message authentication mode with the security gateway, charging pile application, electric vehicle charging card and charging pile meter, and adopts digital certificate based security authentication mode between the billing control terminal and the vehicle networking platform, to realize the confidentiality, integrity and security of the business data transmitted between the billing control terminal of the charging pile and each communication object inside and outside the charging pile, to prevent malicious damage to the charging control system caused by fake billing control terminal identity, replay attack and other attack means, and to prevent electricity stealing and other illegal operations, so as to prevent charging control system accidents.

[0060] Figure 1 A charging pile transaction verification method applied to the scene provided in the present specification. Taking an electric vehicle charging pile containing an object-oriented protocol meter, a billing control terminal TCU, a charging device controller, an electric vehicle charging card reader and a Bluetooth interface as an example, wherein the object-oriented protocol meter is used as a power metering unit, and the charging device controller can control the working of the charging gun of the charging pile. Corresponding to the multiple charging guns of the charging pile, the object-oriented protocol meter and the charging device controller can have multiple ones. The billing control terminal TCU and the object-oriented protocol meter can communicate through the RS485 bus; the billing control terminal TCU and the charging device controller can communicate through the CAN bus; the billing control terminal TCU can include a Bluetooth interface, so that the billing control terminal TCU can communicate with the user's mobile phone app through the Bluetooth interface; the billing control terminal TCU and the electric vehicle charging card reader can communicate through the RS232 interface, so that the billing control terminal TCU can interact with the electric vehicle charging card. The billing control terminal TCU can communicate with multiple charging device controllers and send control commands to multiple charging device controllers to control multiple different charging guns on the same charging pile to work.

[0061] Further, the billing control terminal TCU is embedded with a security chip of the billing control terminal for data encryption and message security authentication when the billing control terminal transmits data with other communication objects; the charging device controller is embedded with a controller security chip for verifying the legitimacy of the billing control terminal to prevent illegal billing control terminals from stealing electricity and other operations by sending abnormal control instructions to the controller.

[0062] In the present scenario example, the electric vehicle charging pile and the Internet of Vehicles platform can communicate based on the MQTT (Message Queuing Telemetry Transport) protocol. Specifically, the billing control terminal of the electric vehicle charging pile can transmit data to the security gateway of the Internet of Vehicles platform based on the MQTT protocol to access the Internet of Vehicles platform, so that the billing control terminal can perform identity authentication and uplink and downlink data transmission with the Internet of Vehicles platform.

[0063] The present specification embodiment provides a transaction verification method of a charging pile, applied to a billing control terminal of the charging pile; the charging pile has at least one charging gun; the terminal identifier, the consumption key, and the key index number of the billing control terminal are stored in the security chip of the billing control terminal. Referring to Figure 2a As shown, the transaction verification method of the charging pile can include the following steps.

[0064] S110, in the case of reading the charging card, determining the gun identifier of the target charging gun selected to provide electric energy and the frozen resource data in the charging card, and obtaining the terminal identifier and the key index number from the security chip.

[0065] The terminal identifier includes the number of the billing control terminal and the serial number of the security chip of the billing control terminal. The consumption key is the root key of the key for the gray lock consumption transaction of the current charging process, and the key index number is the key index number of the consumption key. The gun identifier is the corresponding number of the charging gun of the charging pile. Illustratively, the charging pile has 8 charging guns, and the corresponding gun identifiers are No. 1, No. 2, No. 3, …, and No. 8. The frozen resource data is the data such as the estimated deduction amount determined by the billing control terminal for the current charging card.

[0066] Specifically, when a user needs to use the charging pile to charge an electric vehicle, the user uses the charging card to perform a one-time card swipe at the corresponding position of the charging pile, and selects the charging gun to be used as the target charging gun to provide electric energy. After the user selects the target charging gun, the billing control terminal can determine the gun identifier corresponding to the target charging gun. The billing control terminal reads the card information in the charging card, the electricity purchase wallet information, etc. to determine the amount of money to be deducted from the electricity purchase wallet of the charging card for the current charging transaction, etc. as the frozen resource data in the charging card.

[0067] The billing control terminal sends an instruction to the security chip to obtain the terminal identifier and the key index number, to obtain the corresponding terminal identifier and key index number for subsequent gray lock processing of the electricity purchase wallet in the charging card. Illustratively, the key index number is obtained by the billing control terminal sending an ADF (Application Dedicated File) selection instruction to the security chip.

[0068] In some embodiments, the charging control terminal is a charging control unit (TCU) in a charging control system of the charging pile. The security chip (Embedded Secure Access Module, ESAM) is an embedded security control module using domestic cryptographic algorithms (SM1, SM2, SM3, SM4) for storing and managing keys and performing cryptographic operations, etc. The charging card is a smart card with a security module. The consumption key is a symmetric key previously negotiated by the charging card and the charging control terminal, and is stored in the security module of the charging card and the security chip of the charging control terminal, respectively.

[0069] S120, in the case that the key index number can be supported by the charging card, receiving the pseudo-random number and the resource offline transaction serial number sent by the charging card.

[0070] The resource offline transaction serial number is a wallet offline transaction serial number in the charging card.

[0071] Specifically, the charging control terminal sends the key index number obtained from the security chip to the charging card, and the charging card checks whether the received key index number is supported by the charging card. In the case that the charging card checks that the key index number can be supported by the charging card, the charging card generates a pseudo-random number and sends the pseudo-random number and other data such as the resource offline transaction serial number of the charging card to the charging control terminal.

[0072] S130, sending an initialization gray lock message authentication code calculation command carrying the machine gun identifier to the security chip, to instruct the security chip to calculate the consumption key according to the terminal transaction serial number, the machine gun identifier, the pseudo-random number, and the resource offline transaction serial number, to obtain a sub-key corresponding to the consumption key; and calculating the transaction type identifier, the transaction time data, the terminal identifier, and the frozen resource data by using the sub-key, to obtain a first message authentication code.

[0073] The terminal transaction serial number is stored in the security chip of the charging control terminal, and is updated correspondingly each time a transaction occurs on the charging pile. The sub-key is a group of sub-keys generated based on the consumption key, and is used for the gray lock consumption transaction between the charging card and the charging control terminal during the charging process. The transaction time data includes the transaction date, the transaction time, etc.

[0074] The frozen resource data is the actual frozen amount. The actual frozen amount is determined according to the balance of the electricity purchase wallet in the charging card and the expected deduction amount. When the balance of the electricity purchase wallet is greater than or equal to the expected deduction amount, the actual frozen amount is the expected deduction amount; and when the balance of the electricity purchase wallet is less than the expected deduction amount, the actual frozen amount is the balance of the electricity purchase wallet.

[0075] The pseudo-random number generated by the charging card is variable, that is, the pseudo-random number is different in each complete charging transaction process, and the sub-key generated thereby is also different, which can prevent the key in the charging transaction process from being stolen and the like, thereby improving the security protection level of data interaction between the charging control terminal and the charging card.

[0076] In S140, a gray lock command is sent to the charging card based on the first message authentication code, the terminal random number, the transaction time data and the terminal transaction serial number, to instruct the charging card to perform transaction verification on the first message authentication code.

[0077] The terminal random number is a random number generated by the security chip of the charging control terminal for the charging process.

[0078] Specifically, after the security chip calculates the first message authentication code, the first message authentication code, the terminal random number and the terminal transaction serial number are returned to the charging control terminal. The charging control terminal organizes the first message authentication code, the terminal random number, the transaction time data and the terminal transaction serial number into a gray lock command and sends it to the charging card. After receiving the gray lock command, the charging card verifies the first message authentication code using the sub-key.

[0079] It should be noted that the generation process of the sub-key used for verifying the first message authentication code in the above embodiment is the same as the generation process of the sub-key corresponding to the consumption key in step S130, which is calculated by the charging card using the terminal transaction serial number, the gun identifier, the pseudo-random number and the resource offline transaction serial number.

[0080] In the above embodiment, the embedded security chip of the charging control terminal is set, so that the charging control terminal can realize charging transaction between the charging control terminal and the electric vehicle charging card through the gray lock mechanism. In the charging transaction process, the charging card selects the charging gun number to be bound, so as to realize the security protection of one pile and multiple guns of charging business, and at most can support the security protection of one pile and eight guns of charging business. Therefore, the general protection principle of the new version of the charging facility standardization design scheme prepared by the State Grid Electric Vehicle Company can be followed, and the security protection level of the charging control system is improved.

[0081] In some embodiments, in the case that the key index number can be supported by the charging card, before receiving the pseudo-random number and the resource offline transaction serial number sent by the charging card, the transaction verification method of the charging pile can further include: sending a gray lock wallet initialization command to the charging card based on the gun identifier, the frozen resource data, the terminal identifier and the key index number, to instruct the charging card to verify the key index number, and if the verification is passed, the pseudo-random number and the resource offline transaction serial number are sent to the charging control terminal.

[0082] Specifically, the charging control terminal organizes the machine gun identification of the target charging gun, the frozen resource data, the terminal identification, the key index number, etc. into a gray lock wallet initialization command, and sends it to the charging card. After the charging card receives the gray lock wallet initialization command, it checks whether the key index number contained in the command is supported by the charging card. After the charging card checks that the key index number can be supported by the charging card, a pseudo-random number is generated, and then the charging card sends its resource offline transaction serial number and the pseudo-random number to the charging control terminal.

[0083] In some embodiments, the transaction verification method of the charging pile can further include: in the case that the first message authentication code passes the transaction verification, receiving a second message authentication code sent by the charging card to verify the legitimacy of the charging card.

[0084] Specifically, after the charging card verifies that the first message authentication code passes, the charging card applies a gray lock to the electricity purchase wallet in the charging card, and generates a second message authentication code and sends it to the charging control terminal. The security chip of the charging control terminal verifies the second message authentication code to check the legitimacy of the charging card. After the security chip verifies that the second message authentication code passes, the electric vehicle corresponding to the charging card can start using electricity. In some embodiments, the second message authentication code is a MAC verification code.

[0085] Exemplarily, Figure 2b The interaction flow between the charging control terminal and the security chip of the charging control terminal and the charging card is shown in the schematic diagram. Referring to Figure 2b As shown, the charging control terminal TCU sends a read terminal identification instruction to the security chip of the charging control terminal TCU according to the determined machine gun identification. The security chip receives the instruction and returns the terminal identification to the charging control terminal, and the charging control terminal obtains and saves the terminal identification. The charging control terminal sends an ADF (Application Dedicated File) selection instruction to the security chip, and the security chip receives the instruction and returns the key index number of the consumption key to the charging control terminal, and the charging control terminal obtains and saves the key index number.

[0086] The charging control terminal sends a read electricity purchase wallet information instruction to the charging card, and the charging card receives the instruction and returns the charging card valid date, electric vehicle information and disposable amount in the electricity purchase wallet to the charging control terminal. The charging control terminal obtains these data, determines the amount to be deducted for the current charging, etc. as the frozen resource data in the charging card.

[0087] The charging control terminal organizes the terminal identification, key index number, machine gun identification, and expected deduction amount into a gray lock wallet initialization command, and sends it to the charging card. After the charging card receives the gray lock wallet initialization command, it checks whether the key index number contained in the command is supported by the charging card. After the charging card checks that the key index number can be supported by the charging card, it generates a pseudo-random number ICC, and the charging card sends the balance of the electricity purchase wallet in the charging card, the offline transaction serial number of the wallet, the overdraft limit, the key version number, the security algorithm identification, the pseudo-random number ICC, and the actual frozen amount to the charging control terminal. The charging control terminal receives and saves the resource offline transaction serial number, the transaction date, the transaction time, the key version number, the security algorithm identification, the pseudo-random number ICC, and the actual frozen amount. In some embodiments, the security algorithm is a signature algorithm, a signature verification algorithm, an encryption and decryption algorithm, and the like.

[0088] The charging control terminal sends an initialization gray lock message authentication code calculation command containing the machine gun identification to the security chip of the charging control terminal. After the security chip of the charging control terminal receives the command, it calculates the consumption key using the terminal transaction serial number, the machine gun identification, the pseudo-random number ICC, and the resource offline transaction serial number to generate a sub-key corresponding to the consumption key. The security chip of the charging control terminal calculates the transaction type identification, the terminal identification, the transaction date, the transaction time, and the actual frozen amount using the sub-key to obtain a first message authentication code. In some embodiments, the first message authentication code is a MAC verification code.

[0089] The security chip returns the first message authentication code, the terminal random number TRAN, and the terminal transaction serial number to the charging control terminal. The charging control terminal organizes the first message authentication code, the terminal random number TRAN, the transaction date, the transaction time, and the terminal transaction serial number into a gray lock command, and sends it to the charging card. After the charging card receives the gray lock command, it verifies the first message authentication code using the sub-key. After the charging card verifies that the first message authentication code is passed, it increments the internal transaction detail offline transaction serial number by 1, and performs gray lock processing on the electricity purchase wallet application in the charging card.

[0090] The charging card generates a second message authentication code and sends it to the charging control terminal. The charging control terminal sends a second message authentication code verification instruction to the security chip of the charging control terminal based on the second message authentication code. The security chip receives the instruction, verifies the second message authentication code, and returns the verification result to the charging control terminal. After the security chip verifies that the second message authentication code is passed, the electric vehicle corresponding to the charging card can start using electricity.

[0091] In some embodiments, the charging card generates a gray lock verification code GTAC when generating the second message authentication code. If the gray lock release command cannot be successfully executed at the moment due to abnormal interruption during the charging process, the gray lock verification code GTAC can be included in the terminal abnormal transaction data by the billing control terminal, so as to be uploaded to the host for gray lock verification subsequently.

[0092] In some embodiments, the charging pile transaction verification method can further include the following steps. Figure 3a

[0093] S210, in the case of ending the charging operation, based on the transaction type identifier, the charging card identifier, the resource offline transaction serial number and the resource transaction data, a gray lock verification code calculation instruction is sent to the security chip to instruct the security chip to calculate the gray lock verification code and the security storage module verification code using the sub-key.

[0094] The charging card identifier is the wallet application serial number in the charging card. The resource transaction data is the transaction amount and other data actually generated during the charging process. The security storage module is the security storage module in the billing control terminal.

[0095] Specifically, in the case of ending the charging of the electric vehicle, the billing control terminal sends a gray lock verification code calculation instruction to the security chip of the billing control terminal based on the transaction type identifier, the wallet application serial number in the charging card, the wallet offline transaction serial number and the transaction amount and other data. The security chip receives the gray lock verification code calculation instruction, calculates the gray lock verification code based on the transaction amount and other data using the sub-key corresponding to the consumption key, and calculates the security storage module verification code based on the transaction type identifier, the charging card identifier, the resource offline transaction serial number, the resource transaction data and the gray lock verification code using the gray lock sub-key. The security chip returns the calculated gray lock verification code and the security storage module verification code to the billing control terminal.

[0096] S220, the resource transaction data, the resource offline transaction serial number, the terminal identifier, the machine gun identifier, the terminal transaction serial number, the transaction time data, the gray lock verification code and the security storage module verification code are sent to the charging card.

[0097] Specifically, in the case of ending the charging of the electric vehicle, the user needs to perform secondary card swiping. After the billing control terminal receives the gray lock verification code and the security storage module verification code returned by the security chip, the billing control terminal sends a gray lock release instruction to the charging card based on the resource transaction data, the resource offline transaction serial number, the terminal identifier, the machine gun identifier, the terminal transaction serial number, the transaction time data, the gray lock verification code and the security storage module verification code.

[0098] ​Furthermore, after receiving the gray lock unlocking command, the charging card verifies the correctness of the gray lock verification code. Once the verification code is correct, the charging card executes the corresponding gray lock unlocking command, completing the unlocking and payment deduction operations.

[0099] For example, refer to Figure 3b As shown, when electric vehicle charging is complete, the billing control terminal (TCU) sends a gray lock verification code calculation instruction to the security chip based on data such as the transaction type identifier, the application serial number of the electricity purchase wallet in the charging card, the offline transaction serial number of the wallet, and the transaction amount. Upon receiving the gray lock verification code calculation instruction, the security chip uses the subkey corresponding to the consumption key to calculate the gray lock verification code GMAC against the transaction amount and other data. It then uses the gray lock subkey to calculate the secure storage module verification code SAMTAC against the transaction type identifier, the application serial number of the electricity purchase wallet in the charging card, the offline transaction serial number of the wallet, the transaction amount, the gray lock verification code GMAC, and the terminal transaction serial number plus 1. The security chip returns the gray lock verification code GMAC and the secure storage module verification code SAMTAC to the billing control terminal.

[0100] The billing control terminal sends a gray lock unlocking command to the charging card based on data such as transaction amount, wallet offline transaction sequence number, terminal identifier, machine gun identifier, terminal transaction sequence number, transaction date, transaction time, gray lock verification code (GMAC), and secure storage module verification code (SAMTAC). Upon receiving the gray lock unlocking command, the charging card checks if its physical card number matches the original card number of the gray-locked charging card. If they match, the charging card verifies the correctness of the gray lock verification code (GMAC). If the gray lock verification code (GMAC) is correct, the charging card executes the gray lock unlocking command, completing the unlocking and deduction operations, and returns the transaction verification code (TAC) to the billing control terminal. The billing control terminal receives the transaction verification code (TAC) and sends a command to the charging card to clear the transaction verification code pending read flag (TACUF). The charging card receives this command and clears the transaction verification code pending read flag (TACUF), indicating that the complete charging transaction process is finished.

[0101] In some implementations, the security chip also stores a first random number. (See reference...) Figure 4 As shown, the transaction verification method for charging piles may also include the following steps.

[0102] S310. Send handshake information to the security gateway based on the first random number to instruct the security gateway to send the second random number, link certificate data, initial signature data, and initial signature value.

[0103] The first random number is generated by the security chip. The security gateway is the security gateway of the vehicle networking platform.

[0104] Specifically, the charging control terminal takes a first random number from an embedded security chip of the charging control terminal, and then organizes handshake information data containing the first random number to send to a security gateway of the Internet of Vehicles platform. After receiving the handshake information data, the security gateway issues a second random number, link certificate data, initial signature data and initial signature value of the security gateway to the charging control terminal.

[0105] S320, sending the handshake information, the second random number, the link certificate data, the initial signature data and the initial signature value to the security chip to instruct the security chip to extract a signature verification public key from the link certificate data; verifying the initial signature data and the initial signature value by using the signature verification public key; calculating a handshake digest value based on the handshake information, and calculating a handshake digest signature value of the handshake digest value by using the signature verification public key.

[0106] Specifically, the charging control terminal receives the second random number, the link certificate data, the initial signature data and the initial signature value issued by the security gateway, and sends these data to the security chip of the charging control terminal. The security chip verifies the legality of the link certificate data according to the link certificate rule, and extracts the corresponding signature verification public key from the verified link certificate data, and then verifies the initial signature data and the initial signature value by using the signature verification public key. The charging control terminal sends the same handshake information data to the security chip, and the security chip calculates the corresponding handshake digest value of the handshake information data and sends it to the charging control terminal. The security chip also signs the handshake digest value by using the signature verification key to obtain a handshake digest signature value of the handshake digest value, and sends the handshake digest signature value to the charging control terminal.

[0107] It should be noted that the link certificate data may contain data of multiple certificates, such as signature verification certificate data, encryption and decryption certificate data, etc. The security chip may extract multiple public keys corresponding to the multiple certificates from the verified link certificate data, and the signature verification public key is the public key used for signature verification among the multiple public keys.

[0108] S330, receiving the handshake digest value and the handshake digest signature value sent by the security chip.

[0109] S340, sending a key negotiation instruction to the security chip to instruct the security chip to generate a pre-master key according to the first random number, the second random number and the client version number, and to derive a working key based on the pre-master key.

[0110] Specifically, the charging control terminal sends a charging control terminal version number to the secure chip and sends a key agreement instruction to the secure chip. The secure chip executes the key agreement instruction according to the first random number, the second random number and the charging control terminal version number to generate a pre-master key. The secure chip also simultaneously derives a plurality of working keys from the pre-master key, and the working keys correspond to working scenarios. The working keys are stored in the secure chip and used for subsequent security calculation when the charging control terminal and the secure gateway perform data transmission, so as to protect the security of the data.

[0111] Different working keys are applied to different scenarios, such as encryption and decryption scenarios, signature and verification scenarios, and the like, of data transmission between the charging control terminal and the secure gateway. The working keys corresponding to different application scenarios include encryption and decryption keys, signature and verification keys, and the like.

[0112] In some embodiments, the transaction verification method of the charging pile can further include: receiving client verification data sent by the secure chip. The client verification data is calculated according to a handshake digest value and a client label pre-stored in the secure chip.

[0113] The client is the charging control terminal.

[0114] Specifically, the secure chip of the charging control terminal performs security calculation on the handshake digest value according to the stored client label to obtain client verification data for key agreement confirmation, and sends the verification data to the charging control terminal. In some embodiments, the client label is a "client finished" label.

[0115] In the handshake process of the two communication parties, the two communication parties usually agree on corresponding labels in advance for security calculation in the handshake process of the two communication parties. The two communication parties include a client and a server, and the client corresponds to a stored client label and the server corresponds to a stored server label.

[0116] In some embodiments, referring to FIG. 1, the transaction verification method of the charging pile can further include the following steps. Figure 5

[0117] S410, receiving a pre-master key ciphertext sent by the secure chip. The pre-master key ciphertext is obtained by encrypting the pre-master key using the working key by the secure chip.

[0118] ​Specifically, after the security chip generates the pre-master key and derives a plurality of working keys based on the pre-master key, the security chip encrypts the pre-master key using the derived working keys to obtain pre-master key ciphertext, and sends the pre-master key ciphertext to the charging control terminal. The pre-master key ciphertext is used for subsequent sending to the security gateway, so that the security gateway can decrypt the pre-master key and further derive a plurality of working keys based on the pre-master key. It should be noted that the plurality of working keys derived by the security gateway based on the pre-master key correspond to and are the same as the plurality of working keys stored in the security chip, and are used for symmetrically encrypting data transmitted between the charging control terminal and the security gateway.

[0119] S420, combining the client verification data, the client certificate, and the pre-master key ciphertext to obtain client result data.

[0120] The client certificate is a certificate of the security chip of the charging control terminal, and the public key of the security chip can be obtained from the certificate.

[0121] S430, sending the client result data to the security gateway to instruct the security gateway to verify the client result data.

[0122] Specifically, the charging control terminal organizes the client verification data, the handshake digest signature value, the client certificate, and the pre-master key ciphertext into the client result data, and sends the client result data to the security gateway. The security gateway receives the client result data and verifies the client verification data in the client result data.

[0123] In some embodiments, the transaction verification method of the charging pile can further include: receiving server verification data returned by the security gateway. The server verification data is used to instruct the security chip to verify the security gateway and establish a connection with the security gateway.

[0124] It should be noted that in the above embodiments, the charging control terminal corresponds to the client in the communication party, the security gateway corresponds to the server in the communication party, and the security gateway stores the server label. In some embodiments, the server label is "server finished".

[0125] Specifically, the security gateway receives the client result data and verifies the client authentication data in the client result data. After the client authentication data is verified, the security gateway performs security calculation according to the server label to obtain the server authentication data, and returns the server authentication data to the billing control terminal. The billing control terminal receives the server authentication data returned by the security gateway. The billing control terminal sends the server authentication data to the security chip, and the security chip executes the key agreement confirmation instruction to verify the correctness of the received server authentication data. If the server authentication data passes the verification, it indicates that the two-way authentication and key agreement between the billing control terminal and the security gateway are successful, and the security chip enables the working key for data transmission with the security gateway. Further, the security gateway derives the same working key according to the pre-master key. At this point, the billing control terminal and the security gateway successfully establish a secure data communication connection.

[0126] Exemplarily, the billing control terminal and the security gateway perform link layer secure data interaction through SSL VPN (Secure Sockets Layer; Virtual Private Network) to ensure the security of the communication link between the billing control terminal and the security gateway. The secure data interaction between the billing control terminal and the security gateway includes two parts of interaction for establishing a secure communication connection and interaction based on data protection. Referring to Figure 6 As shown, the interaction between the billing control terminal and the security gateway for establishing a connection can include the following processes:

[0127] The billing control terminal TCU sends a random number acquisition instruction to the security chip of the billing control terminal TCU, and the security chip takes the first random number R1 and returns it to the billing control terminal TCU. The billing control terminal organizes handshake information data containing the first random number R1 and sends it to the security gateway of the Internet of Vehicles platform. After the security gateway receives the handshake information data, it sends the second random number R2, the link certificate data CertData, the initial signature data Data0 of the security gateway and the initial signature value Sign0 to the billing control terminal.

[0128] The charging control terminal receives the second random number R2, the link certificate data CertData, the initial signature data Data0 and the initial signature value Sign0 sent by the security gateway, the security chip of the charging control terminal verifies the legitimacy of the link certificate data CertData according to the link certificate rule, and takes out the public key from the verified link certificate data CertData, and then verifies the initial signature value Sign0 using the signature verification public key. The charging control terminal sends the same handshake information data to the security chip, the security chip calculates the handshake digest value of the handshake information data and sends it to the charging control terminal. The security chip calculates the handshake digest signature value of the handshake digest value using the signature verification secret key and sends it to the charging control terminal.

[0129] The charging control terminal sends the charging control terminal version number to the security chip, and the security chip executes the key agreement instruction according to the first random number R1, the second random number R2 and the charging control terminal version number to generate a pre-master key, and derives a plurality of working keys from the pre-master key as a root key and saves them. The security chip encrypts the pre-master key using the derived working key to obtain the pre-master key ciphertext, and sends the pre-master key ciphertext to the charging control terminal.

[0130] The security chip performs a secure calculation on the handshake digest value according to the stored client label “client finished” to obtain client verification data for key agreement confirmation, and sends the verification data to the charging control terminal.

[0131] The charging control terminal organizes the client verification data, the handshake digest signature value, the TCU certificate and the pre-master key ciphertext into result data, and sends the result data to the security gateway. The security gateway receives the result data and verifies the client verification data in the result data. In the case where the verification of the client verification data is passed, the security gateway derives the same working key from the pre-master key, and performs a secure calculation according to the server label “server finished” to obtain server verification data, and returns the server verification data to the charging control terminal. The charging control terminal receives the server verification data returned by the security gateway. The charging control terminal sends the server verification data to the security chip, and the security chip executes the key agreement confirmation instruction to verify the correctness of the server verification data. If the verification result is correct, the security chip enables the working key. At this point, the charging control terminal and the security gateway successfully establish a data communication connection.

[0132] In some embodiments, referring to Figure 7a As shown in the figure, the transaction verification method of the charging pile can further include the following steps.

[0133] S510, receive the ciphertext of the application data and the verification code.

[0134] The application data is application layer protocol processing data issued by the security gateway. For example, the application data includes data read, setting, operation and the like issued by the security gateway to the charging control terminal.

[0135] Specifically, the data communication connection is established between the charging control terminal and the security gateway through the foregoing method. The security gateway encrypts the application data using the working key derived in the foregoing key negotiation process to obtain the ciphertext of the application data, and calculates the verification code of the application data using the working key to obtain the verification code of the application data. The security gateway sends the obtained ciphertext of the application data and the verification code to the charging control terminal. In some embodiments, the verification code is a MAC verification code.

[0136] S520, decrypting the ciphertext of the application data using the working key to obtain the plaintext of the application data.

[0137] Specifically, after receiving the ciphertext of the application data and the verification code, the charging control terminal causes the security chip to first verify the verification code, and in the case of passing the verification, causes the security chip to decrypt the ciphertext of the application data to obtain the plaintext of the application data. The charging control terminal executes corresponding application layer protocol processing according to the plaintext of the application data, including data read, setting, operation and the like.

[0138] Further, before sending the link decryption calculation instruction to the security chip, the charging control terminal also sends a link verification code verification instruction to the security chip, causing the security chip to verify the correctness of the verification code of the application data, and after the verification result is correct, sending the link decryption calculation instruction to the security chip.

[0139] S530, executing corresponding application layer protocol processing operation according to the plaintext of the application data to obtain the execution result data of the application layer protocol processing operation.

[0140] S540, sending the execution result data to the security chip to instruct the security chip to calculate the ciphertext and the verification code of the execution result data.

[0141] Specifically, after executing corresponding application layer protocol processing operation according to the plaintext of the application data, the charging control terminal generates corresponding execution result data of the executed application layer protocol processing. The charging control terminal sends the execution result data to the security chip and instructs the security chip to calculate the ciphertext and the verification code of the result data based on the result data, so as to verify the correctness of the result data by the security gateway. After the verification is correct, the communication interaction between the charging control terminal and the security gateway can be realized based on data protection.

[0142] For example, referring to Figure 7bAs shown, the data protection-based interaction process between the charging control terminal and the security gateway includes the following steps.

[0143] The security gateway calculates the verification code MAC1 and the cipher text Endata1 using the working key, and sends the MAC1 and the Endata1 to the charging control terminal TCU in a message.

[0144] After receiving the verification code MAC1 and the cipher text Endata1, the charging control terminal sends a link MAC verification instruction to the security chip based on the verification code MAC1 and the cipher text Endata1. The security chip receives the instruction and verifies the correctness of the verification code MAC1. The charging control terminal sends a link decryption calculation instruction to the security chip, and the security chip decrypts the cipher text Endata1 to obtain the plaintext of the application data Data1.

[0145] The security chip returns the plaintext of the application data Data1 to the charging control terminal, and the charging control terminal performs corresponding application layer protocol processing (reading, setting, operation, etc.) operations according to the application data Data1.

[0146] The charging control terminal sends the result data Data2 of the application layer protocol processing to the security chip, and the security chip calculates the verification value MAC2 and the cipher value Endata2 based on the result data Data2 to protect the result data, and sends them to the charging control terminal. The charging control terminal combines the verification value MAC2 and the cipher value Endata2, and sends them to the security gateway. The security gateway receives and verifies the correctness of the result data Data2. After the result data Data2 is verified, the charging control terminal and the security gateway can realize data protection-based communication interaction.

[0147] In some embodiments, referring to Figure 8a As shown, the transaction verification method of the charging pile can further include the following steps.

[0148] S610, send the chip information of the security chip to the Internet of Vehicles platform to instruct the Internet of Vehicles platform to generate authentication data based on the chip information.

[0149] The Internet of Vehicles platform includes the security gateway corresponding to any of the preceding embodiments. The authentication data is used for identity authentication between the charging control terminal and the Internet of Vehicles platform.

[0150] Specifically, the charging control terminal sends a chip information acquisition instruction to the security chip, and the security chip returns the corresponding chip information to the charging control terminal. The charging control terminal sends the chip information to the Internet of Vehicles platform, and the Internet of Vehicles platform generates corresponding authentication data based on the chip information of the security chip.

[0151] Exemplarily, the vehicle networking platform generates a counter and a random number according to the chip information of the security chip, and then encrypts the counter and the random number to obtain ciphertext of the counter and the random number. The vehicle networking platform signs the ciphertext, and combines the ciphertext and the signature of the ciphertext to obtain the authentication data.

[0152] In some embodiments, the chip information includes chip manufacturer, chip version number, chip serial number and the like.

[0153] S620, receiving the authentication data sent by the vehicle networking platform. The authentication data is used to instruct the security chip to verify the authentication data and generate authentication verification information and an application session key.

[0154] The application session key is used for encryption and decryption of data transmission between the charging control terminal and the vehicle networking platform.

[0155] Specifically, the vehicle networking platform issues the authentication data to the charging control terminal. After receiving the authentication data, the charging control terminal sends an instruction to the security chip, so that the security chip first verifies the authentication data and returns the authentication verification information to the charging control terminal according to the verification result. Secondly, in the case that the authentication data passes the verification, the security chip internally generates a corresponding application session key.

[0156] In some embodiments, the validity time of the application session key is set in advance, so that the application session key is valid within one session time. When the use time of the application session key reaches the pre-set validity time, the application session key is invalid. If the charging control terminal and the vehicle networking platform need to continue to communicate, the above-mentioned application session key negotiation process needs to be re-performed, and a new application session key needs to be generated before the communication can be performed again, so as to ensure the randomness and temporality of the session key and improve the security of data interaction.

[0157] S630, sending the authentication verification information to the vehicle networking platform to instruct the vehicle networking platform to verify the authentication verification information.

[0158] Specifically, the charging control terminal sends the authentication verification information to the vehicle networking platform, and the vehicle networking platform receives and verifies the authentication verification information. On the premise that the verification information passes the verification, the charging control terminal and the vehicle networking platform complete the identity authentication process, and the charging control terminal and the vehicle networking platform can start the session.

[0159] Exemplarily, the interaction process of the charging control terminal and the vehicle networking platform includes identity authentication interaction and uplink and downlink data transmission interaction. Referring to Figure 8b As shown in the figure, the identity authentication interaction of the charging control terminal and the vehicle networking platform can include the following processes:

[0160] The charging control terminal TCU sends a chip information acquisition instruction to the secure chip, the secure chip receives the instruction, and returns the chip information of the secure chip to the charging control terminal TCU. The charging control terminal sends the chip information to the vehicle networking platform. The vehicle networking platform receives the chip information, and generates a counter ASCTR and a random number R1 according to the chip information iov , and then encrypts the counter ASCTR and the random number R1 iov to obtain ciphertext M1. The vehicle networking platform continues to sign the ciphertext M1 to obtain a signature S1, and then combines the ciphertext M1 and the signature S1 to obtain authentication data, and distributes the authentication data to the charging control terminal. After receiving the authentication data, the charging control terminal sends an asymmetric key negotiation instruction for the vehicle networking platform to the secure chip. The secure chip receives the asymmetric key negotiation instruction, first verifies the authentication data, and generates authentication verification information and returns it to the charging control terminal. Secondly, in the case that the authentication data passes the verification, the secure chip internally generates an application session key. The charging control terminal receives the authentication verification information and sends it to the vehicle networking platform, and the vehicle networking platform receives the authentication verification information and verifies the authentication verification information. After the authentication verification information passes the verification, the identity authentication process between the charging control terminal and the vehicle networking platform ends, and a one-time session between the vehicle networking platform and the charging control terminal begins.

[0161] The uplink and downlink data transmission between the charging control terminal and the vehicle networking platform needs to be performed after the identity authentication of the charging control terminal and the vehicle networking platform. The downlink data of the vehicle networking platform to the charging control terminal includes reset, parameter setting, control and other operation instructions. As shown in Figure 8c , the downlink data transmission interaction between the vehicle networking platform and the charging control terminal can include the following process: the vehicle networking platform performs symmetric encryption protection calculation on the downlink data, and then organizes to obtain downlink task data. Based on the downlink task data, the vehicle networking platform sends a downlink data packet to the charging control terminal TCU. The charging control terminal TCU receives the downlink data packet and sends it to the secure chip. The secure chip receives the downlink data packet and uses the currently valid application session key to decrypt and verify the downlink data. After the verification passes, the secure chip returns the decrypted downlink data to the charging control terminal TCU, and the charging control terminal TCU executes the corresponding operation instruction according to the downlink data.

[0162] The uplink data of the charging control terminal to the vehicle networking platform includes reporting, data returning, etc. As shown in Figure 8dAs shown, the uplink data transmission interaction between the charging control terminal and the vehicle networking platform can include the following processes: the charging control terminal TCU organizes the uplink data to obtain uplink task data, and sends the uplink task data to the security chip. The security chip receives the uplink task data, and uses the currently valid application session key to protect the uplink task data and returns it to the charging control terminal TCU after calculation. The charging control terminal TCU sends the uplink data packet to the vehicle networking platform based on the uplink task data and the encrypted uplink task data. After the vehicle networking platform receives the uplink data packet, the uplink data is decrypted and verified.

[0163] In the above embodiment, the identity authentication between the charging control terminal and the vehicle networking platform adopts a secure authentication method based on digital certificates, and the transmission of uplink and downlink data adopts a symmetric encryption method, thereby ensuring the integrity and reliability of data transmission.

[0164] In some embodiments, with reference to Figure 9a As shown, the transaction verification method of the charging pile can further include the following steps.

[0165] S710, sending the specified type data agreed in advance with the mobile client to the security chip to instruct the security chip to encrypt the specified type data.

[0166] The specified type data is data with a certain trusted range agreed in advance by the charging control terminal and the specified application program of the mobile client. In some embodiments, the specified type data is A-class confidential data.

[0167] S720, receiving the encrypted specified type data, and displaying a graphical code generated based on the encrypted specified type data.

[0168] Specifically, the charging control terminal receives the data obtained by the security chip after encrypting the specified type data, generates a corresponding graphical code, and displays the graphical code through the display screen of the charging pile. In some embodiments, the graphical code is a two-dimensional code.

[0169] S730, in the case of decrypting the encrypted specified type data in the graphical code through the scanning operation of the mobile client, establishing a communication connection with the mobile client.

[0170] Specifically, the specified application program of the mobile client is used to scan the graphical code, and the application program decrypts the encrypted specified type data in the graphical code. If the decryption result is within the trusted range, the charging control terminal establishes a communication connection with the mobile client. In some embodiments, the charging control terminal has a Bluetooth interface, so that the charging control terminal can establish a Bluetooth communication connection with the mobile client through the Bluetooth interface.

[0171] Exemplarily, the charging control terminal is connected with the mobile client through a Bluetooth interface, and further, the charging control terminal is connected with an application APP of the mobile client through the Bluetooth interface. Referring to Figure 9b As shown, the process of establishing connection between the charging control terminal and the mobile client can include: the charging control terminal TCU sends an instruction of encrypting A-class confidential data to the security chip, the security chip encrypts the A-class confidential data, and returns the encrypted A-class confidential data to the charging control terminal. The charging control terminal receives the encrypted data returned by the security chip, generates a corresponding two-dimensional code, and displays the two-dimensional code through the display screen of the charging pile. After the application APP of the mobile client scans and reads the two-dimensional code, the encrypted A-class confidential data is obtained, and the encrypted A-class confidential data is decrypted and verified. If the decryption result is within the trusted range, the verification is passed, and the application APP of the mobile client is connected with the charging control terminal through Bluetooth.

[0172] Further, after the charging control terminal is successfully connected with the mobile client, the session key negotiation is firstly performed. After the session key negotiation is successfully performed, the service data transmitted between the charging control terminal and the mobile client is encrypted and protected by the session key.

[0173] Exemplarily, referring to Figure 9c As shown, the session key negotiation process between the charging control terminal and the mobile client can include: the application APP of the mobile client uses the key in the corresponding SDK certificate to sign the version number, the security algorithm, the random number R1 app generated by the application APP, and the SDK certificate to obtain a signature value Sign1, and then the application APP sends a session key negotiation instruction to the charging control terminal TCU based on the version number, the security algorithm, the random number R1 app generated by the application APP, the SDK certificate, and the signature value Sign1. The charging control terminal receives the session key negotiation instruction, and sends an asymmetric key negotiation initialization instruction for the application APP of the mobile client to the security chip based on the above data. The security chip judges the validity of the SDK certificate, and after judging that the SDK certificate is valid, the SDK certificate is parsed to obtain the SDK public key. The security chip uses the SDK public key to verify the signature value Sign1, and after the verification is successful, the security chip generates random numbers R2 ESAM and R3 ESAM . The security chip uses the SDK public key to encrypt the random number R1 app + R2 ESAM + R3 ESAMEncryption is performed to obtain ciphertext Endata. Then, the version number, ciphertext Endata, and the application signature certificate of the charging control terminal (TCU) are signed using the key from the TCU's application signature certificate to obtain the signature value Sign2. Simultaneously, the security chip also uses a key algorithm to process the random number R1. app +R2 ESAM The system performs calculations to derive the session key `ks`, which is then stored in the security chip. The security chip sends the version number, encrypted `Endata`, the application signature certificate of the billing control terminal, and the signature value `Sign2` to the billing control terminal. The billing control terminal then sends this data along with the data to the mobile client's application (`APP`). The mobile client's application performs session key negotiation based on the received data and returns the session key negotiation result to the billing control terminal. The session key negotiation result contains the version number and the encrypted session key negotiation data. After receiving the session key negotiation result, the billing control terminal sends an asymmetric key negotiation confirmation command to the security chip for the mobile client's application (`APP`). The security chip uses the derived session key `ks` to decrypt the encrypted session key negotiation data and calculates the random number `R3`. ESAM A comparison is performed to verify its legitimacy. Using random number R3... ESAM After successful verification, the session key negotiation was completed. Subsequently, the mobile client application (APP) and the billing control terminal use the session key (ks) to encrypt and protect the data to be transmitted.

[0174] In some embodiments, the security chip uses a domestically developed cryptographic algorithm to process the random number R1. app +R2 ESAM Calculations are performed to derive the session key ks. For example, the security chip uses the domestically developed cryptographic algorithm SM3 to calculate the random number R1. app +R2 ESAM A hash calculation is performed to derive a 32-byte session key ks, which is stored in the secure chip. The first 16 bytes of the session key ks serve as the Initialization Vector (IV), and the last 16 bytes serve as the key.

[0175] In the above implementation, the billing control terminal uses a security chip to encrypt a specified type of data and generate a QR code. The mobile client scans this QR code through an application to establish a Bluetooth communication connection with the billing control terminal, enabling communication between the mobile client and the billing control terminal via Bluetooth. After establishing the communication connection, the mobile client and the billing control terminal negotiate a session key to generate a session key with a certain validity period. This session key is used to encrypt and decrypt the service data to be transmitted. Because the session key is random and diverse, it helps to improve the security of data interaction between the mobile client and the billing control terminal.

[0176] In some embodiments, referring to Figure 10a As shown, the transaction verification method of the charging pile can further include the following steps.

[0177] S810, obtaining controller information of a controller of the charging pile. The controller information includes a controller serial number and a symmetric key version number.

[0178] S820, sending a first control random number generated by a secure chip to the controller, to instruct the secure chip of the controller to calculate authentication data of the first control random number and generate a second control random number.

[0179] S830, receiving the authentication data of the first control random number and the second control random number.

[0180] S840, sending a control instruction to the secure chip, to instruct the secure chip to encrypt the control instruction using the controller serial number, the authentication data of the first control random number, and the second control random number.

[0181] S850, sending the encrypted control instruction to the controller.

[0182] The controller is a charging device controller of the charging pile, configured to receive a control instruction sent by a billing control terminal. The controller serial number and the symmetric key version number are stored in an embedded secure chip of the controller.

[0183] In some cases, in order to ensure that the billing control terminal sending the control instruction to the controller is a legitimate billing control terminal, it is necessary to verify the received control instruction at the controller end. Therefore, a secure chip is embedded in the controller, which is used to store the key of the controller and perform secure calculation, etc., to prevent illegal billing control terminals from sending abnormal control instructions to the controller and stealing electricity, etc.

[0184] For example, the billing control terminal sends the control instruction to the controller directly through the CAN bus. Referring to Figure 10b As shown, the interaction between the billing control terminal and the controller can include the following processes:

[0185] The billing control terminal TCU sends an instruction to obtain controller information to the controller of the charging pile, and the controller receives the instruction and sends it to the secure chip of the controller. The secure chip of the controller returns controller information data including the controller serial number and the symmetric key version number to the controller, and the controller receives the controller information data and performs data combination and sends it to the billing control terminal. The billing control terminal receives the controller information data.

[0186] The billing control terminal sends a random number obtaining command to the secure chip embedded in the billing control terminal. The secure chip of the billing control terminal returns a random number R1 TCUThe charging control terminal sends the control instruction to the controller. The controller receives the control instruction and sends it to the controller security chip. The controller security chip authenticates the control instruction and sends the authentication result to the controller. The controller receives the authentication result and sends it to the charging control terminal. TCU The charging control terminal sends the control instruction to the controller. The controller receives the control instruction and sends it to the controller security chip. The controller security chip authenticates the control instruction and sends the authentication result to the controller. The controller receives the authentication result and sends it to the charging control terminal. TCU The charging control terminal sends the control instruction to the controller. The controller receives the control instruction and sends it to the controller security chip. The controller security chip authenticates the control instruction and sends the authentication result to the controller. The controller receives the authentication result and sends it to the charging control terminal. con The charging control terminal sends the control instruction to the controller. The controller receives the control instruction and sends it to the controller security chip. The controller security chip authenticates the control instruction and sends the authentication result to the controller. The controller receives the authentication result and sends it to the charging control terminal. TCU The charging control terminal sends the control instruction to the controller. The controller receives the control instruction and sends it to the controller security chip. The controller security chip authenticates the control instruction and sends the authentication result to the controller. The controller receives the authentication result and sends it to the charging control terminal. con The charging control terminal sends the control instruction to the controller. The controller receives the control instruction and sends it to the controller security chip. The controller security chip authenticates the control instruction and sends the authentication result to the controller. The controller receives the authentication result and sends it to the charging control terminal.

[0187] The control instruction can be a control frame MAC calculation instruction. The charging control terminal sends the control frame MAC calculation instruction to the security chip of the charging control terminal. The security chip of the charging control terminal encrypts the control instruction using the controller serial number, the random number R2 con and the authentication data of the random number R1 TCU , and sends it to the charging control terminal. The charging control terminal sends the encrypted control instruction to the controller. The controller receives the encrypted control instruction and sends it to the controller security chip. The controller security chip verifies the control instruction. After the control instruction is verified, the controller performs the relevant control operation and sends the operation result to the charging control terminal.

[0188] In the above embodiment, the controller security chip is embedded in the controller. After the controller receives the control instruction sent by the charging control terminal, the controller security chip first authenticates the control instruction. The control instruction that passes the authentication can be executed by the controller. All security operations are implemented based on the security chip to prevent illegal charging control terminals from sending abnormal control instructions to the controller, which can meet the security protection requirements of the control instruction of the charging control terminal.

[0189] In some embodiments, as shown in Figure 11a , the transaction verification method of the charging pile can further include the following steps.

[0190] S910, send a meter reading instruction to the electric meter.

[0191] The meter reading instruction carries an electric meter random number generated by a security chip. The meter reading instruction is used to instruct the security chip of the electric meter to generate security reading data in a preset security mode based on the electric meter random number. The preset security mode includes a plaintext mac mode, a ciphertext mode and a ciphertext mac mode.

[0192] S920, receive the security reading data sent by the electric meter and verify the security reading data.

[0193] For example, as shown in Figure 11bAs shown, the process of the billing control terminal reading the electricity meter may include: the billing control terminal TCU sending a command to the security chip of the billing control terminal TCU to obtain a random number, and the security chip of the billing control terminal generating the random number R1. EM The result is returned to the billing control terminal. The billing control terminal uses the random number R1 as a reference. EM Send a meter reading command to the electricity meter. The electricity meter will then generate a random number R1. EM The data to be read is sent to the meter's security chip. The security chip calculates secure reading data according to three security modes and returns it to the meter: plaintext MAC mode, encrypted mode, and encrypted MAC mode. The meter combines the reading data corresponding to the three security modes and sends it to the billing control terminal. The billing control terminal receives the data sent by the meter and sends it to its own security chip. The security chip verifies the received data according to the format of the data and according to the three security modes: plaintext + MAC mode, encrypted mode, and encrypted + MAC mode.

[0194] This specification provides a transaction verification device for a charging pile, applied to the charging pile's billing control terminal; the charging pile has at least one charging gun; the security chip of the billing control terminal stores the terminal identifier, consumption key, and key index number of the billing control terminal. (Reference) Figure 12a As shown, the transaction verification device 1000 of the charging pile may include: a charging card reading module 1010, a resource data determination module 1020, an identification and index number acquisition module 1030, a random number and sequence number receiving module 1040, an authentication code calculation command sending module 1050, and a gray lock command sending module 1060.

[0195] The charging card reading module 1010 is used to read charging cards.

[0196] The resource data determination module 1020 is used to determine the machine gun identifier of the target charging machine gun selected to provide power and the frozen resource data in the charging card when the charging card is read.

[0197] The identifier and index number acquisition module 1030 is used to acquire the terminal identifier and key index number from the security chip.

[0198] The random number and sequence number receiving module 1040 is used to receive pseudo-random numbers and resource offline transaction sequence numbers sent by the charging card, provided that the key index number can be supported by the charging card.

[0199] The authentication code calculation command sending module 1050 is used to send an initialization gray lock message authentication code calculation command carrying a machine gun identifier to the security chip, so as to instruct the security chip to calculate the consumption key based on the terminal transaction sequence number, machine gun identifier, pseudo-random number, and resource offline transaction sequence number to obtain the subkey corresponding to the consumption key; and to use the subkey to calculate the transaction type identifier, transaction time data, terminal identifier, and frozen resource data to obtain the first message authentication code.

[0200] The gray lock command sending module 1060 is used to send a gray lock command to the charging card based on the first message authentication code, the terminal random number, the transaction time data, and the terminal transaction sequence number, so as to instruct the charging card to perform transaction verification on the first message authentication code.

[0201] In some implementations, reference Figure 12b As shown, the transaction verification device 1000 of the charging pile may further include: an initialization command sending module 1070.

[0202] The initialization command sending module 1070 is used to send a gray lock wallet initialization command to the charging card based on the machine gun identifier, frozen resource data, terminal identifier, and key index number, so as to instruct the charging card to verify the key index number. If the verification is successful, a pseudo-random number and resource offline transaction sequence number are sent to the billing control terminal.

[0203] In some implementations, reference Figure 12c As shown, the transaction verification device 1000 of the charging pile may further include: a verification code calculation instruction sending module 1080 and a transaction data sending module 1090.

[0204] The verification code calculation instruction sending module 1080 is used to send a gray lock verification code calculation instruction to the security chip based on the transaction type identifier, charging card identifier, resource offline transaction sequence number and resource transaction data when the charging operation is completed, so as to instruct the security chip to calculate the gray lock verification code and the security storage module verification code using the subkey.

[0205] The transaction data sending module 1090 is used to send resource transaction data, resource offline transaction sequence number, terminal identifier, machine gun identifier, terminal transaction sequence number, transaction time data, gray lock verification code, and secure storage module verification code to the charging card.

[0206] Specific limitations regarding the transaction verification device for charging piles can be found in the limitations of the transaction verification method for charging piles mentioned above, and will not be repeated here. Each module in the aforementioned device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device in hardware form, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0207] The embodiments of the present specification also provide a computer device, as shown in the reference Figure 13 The computer device 1100 includes a memory 1110, a processor 1120, and a computer program 1130 stored in the memory 1110 and capable of running on the processor 1120, and the processor 1120 implements the charging pile transaction verification method of any one of the preceding embodiments when executing the computer program 1130.

[0208] The embodiments of the present specification also provide a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the charging pile transaction verification method of any one of the preceding embodiments.

[0209] It should be noted that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a list of executable instructions for implementing logic functions, which can be embodied in any computer readable medium for use by or in connection with an instruction execution system, apparatus or device, such as a computer-based system, a system including a processor or other system that can fetch the instructions from the instruction execution system, apparatus or device and execute the instructions, or in conjunction with these instruction execution systems, apparatus or devices. For the purposes of this specification, a "computer readable medium" can be any device that can contain, store, communicate, propagate or transport a program for use by or in connection with an instruction execution system, apparatus or device, or in conjunction with these instruction execution systems, apparatus or devices. More specific examples (non-exhaustive list) of computer readable medium include the following: electrical connections having one or more wires (electronic devices), portable computer diskette (magnetic devices), random access memory (RAM), read only memory (ROM), erasable programmable read only memory (EPROM or flash memory), fiber optic devices, and portable compact disk read only memory (CD ROM). In addition, the computer readable medium can even be paper or other suitable medium on which the program can be printed, as the program can be electronically obtained, for example, by optical scanning of the paper or other medium, followed by electronic conversion, interpretation or processing, if necessary, in other suitable ways, and then stored in a computer memory.

[0210] It should be understood that portions of the present application can be realized with a hardware, software, firmware or a combination thereof. In the above-described embodiments, a plurality of steps or methods can be realized with software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if realized with hardware, and as in another embodiment, it can be realized with any one or a combination of the following technologies known in the art: discrete logic circuit having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.

[0211] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Also, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0212] In addition, the terms "first", "second", "third", etc. are used only for the purpose of description and should not be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, for example, two, three, etc., unless otherwise explicitly specified and limited.

[0213] In the present application, unless otherwise explicitly specified and limited, the terms "mounting", "connection", "connecting", "fixing" and the like should be understood in a broad sense, for example, can be fixed connection, can also be detachable connection, or integral; can be mechanical connection, can also be electrical connection; can be directly connected, can also be indirectly connected through an intermediate medium, can be the internal communication of two elements or the interaction relationship between two elements, unless otherwise explicitly limited. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0214] Although the embodiments of the present application have been shown and described above, it should be understood that the above-described embodiments are exemplary and should not be construed as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above-described embodiments within the scope of the present application.

Claims

1. A transaction verification method of a charging pile, characterized in that, A charging control terminal applied to the charging pile; the charging pile has at least one charging gun; The security chip of the charging control terminal stores the terminal identification, the consumption key and the key index number of the charging control terminal; the method comprises: In the case of reading the charging card, the gun identification of the target charging gun selected to provide electric energy and the frozen resource data in the charging card are determined, and the terminal identification and the key index number are obtained from the security chip; wherein, if the balance of the electricity purchase wallet in the charging card is greater than or equal to the expected deduction amount, the expected deduction amount is determined as the frozen resource data; if the balance of the electricity purchase wallet is less than the expected deduction amount, the balance of the electricity purchase wallet is determined as the frozen resource data; the expected deduction amount is determined by the charging control terminal; In the case that the key index number can be supported by the charging card, the pseudo-random number and the resource offline transaction serial number sent by the charging card are received; An initialization gray lock message authentication code calculation command carrying the gun identification is sent to the security chip, so as to instruct the security chip to calculate the consumption key according to the terminal transaction serial number, the gun identification, the pseudo-random number and the resource offline transaction serial number, and obtain the sub-key corresponding to the consumption key; the transaction type identification, the transaction time data, the terminal identification and the frozen resource data are calculated by using the sub-key, and the first message authentication code is obtained; Based on the first message authentication code, the terminal random number, the transaction time data and the terminal transaction serial number, a gray lock command is sent to the charging card, so as to instruct the charging card to perform transaction verification on the first message authentication code, and in the case that the first message authentication code passes the transaction verification, a second message authentication code sent by the charging card is received, so as to verify the legitimacy of the charging card.

2. The method of claim 1, wherein, Before receiving the pseudo-random number and the resource offline transaction serial number sent by the charging card in the case that the key index number can be supported by the charging card, the method further comprises: Based on the gun identification, the frozen resource data, the terminal identification and the key index number, a gray lock wallet initialization command is sent to the charging card, so as to instruct the charging card to verify the key index number, and if the verification is passed, the pseudo-random number and the resource offline transaction serial number are sent to the charging control terminal.

3. The method of claim 1, wherein, The method further comprises: In the case that the charging operation is completed, based on the transaction type identification, the charging card identification, the resource offline transaction serial number and the resource transaction data, a gray lock verification code calculation instruction is sent to the security chip, so as to instruct the security chip to calculate the gray lock verification code and the security storage module verification code by using the sub-key; The resource transaction data, the resource offline transaction serial number, the terminal identification, the gun identification, the terminal transaction serial number, the transaction time data, the gray lock verification code and the security storage module verification code are sent to the charging card.

4. The method of claim 1, wherein, The first random number is also stored in the security chip; the method further comprises: sending handshake information to the security gateway based on the first random number, to instruct the security gateway to issue a second random number, link certificate data, initial signature data, and an initial signature value; sending the handshake information, the second random number, the link certificate data, the initial signature data, and the initial signature value to the security chip, to instruct the security chip to extract a signature verification public key from the link certificate data, use the signature verification public key to verify the initial signature data and the initial signature value, and calculate a handshake digest value based on the handshake information and a handshake digest signature value of the handshake digest value calculated using the signature verification public key; receiving the handshake digest value and the handshake digest signature value sent by the security chip; sending a key negotiation instruction to the security chip, to instruct the security chip to generate a pre-master key based on the first random number, the second random number, and a client version number, and derive a working key based on the pre-master key.

5. The method of claim 4, wherein, The method further comprises: receiving client verification data sent by the security chip, wherein the client verification data is calculated based on a client label pre-stored in the security chip and the handshake digest value.

6. The method of claim 5, wherein, The method further comprises: receiving pre-master key ciphertext sent by the security chip, wherein the pre-master key ciphertext is obtained by encrypting the pre-master key using the working key by the security chip; combining the client verification data, a client certificate, and the pre-master key ciphertext to obtain client result data; sending the client result data to the security gateway, to instruct the security gateway to verify the client result data.

7. The method of claim 6, wherein, The method further comprises: receiving server verification data returned by the security gateway, wherein the server verification data is used to instruct the security chip to verify the security gateway and establish a connection with the security gateway.

8. The method of claim 4, wherein, The method further comprises: receiving ciphertext of application data and a verification code; decrypting the ciphertext of the application data using the working key to obtain plaintext of the application data; performing a corresponding application layer protocol processing operation based on the plaintext of the application data to obtain execution result data of the application layer protocol processing operation; sending the execution result data to the security chip, to instruct the security chip to calculate ciphertext of the execution result data and a verification code.

9. The method of claim 4, wherein, The method further comprises: sending chip information of the security chip to a vehicle Internet of Things platform, to instruct the vehicle Internet of Things platform to generate authentication data based on the chip information; receiving the authentication data sent by the vehicle Internet of Things platform, wherein the authentication data is used to instruct the security chip to verify the authentication data and generate authentication verification information and an application session key; sending the authentication verification information to the vehicle Internet of Things platform, to instruct the vehicle Internet of Things platform to verify the authentication verification information.

10. The method of claim 1, wherein, The method further comprises: sending designated type data pre-agreed with a mobile client to the security chip, to instruct the security chip to encrypt the designated type data; Receiving encrypted specified type data, and displaying a graphical code generated based on the encrypted specified type data; In the case that the mobile client decrypts the encrypted specified type data in the graphical code in a scanning operation of the graphical code, a communication connection with the mobile client is established.

11. The method of claim 1, wherein, The method further comprises: Obtaining controller information of a controller of the charging pile; the controller information comprises a controller serial number and a symmetric key version number; Sending a first control random number generated by the security chip to the controller, so as to instruct the security chip of the controller to calculate authentication data of the first control random number and generate a second control random number; Receiving the authentication data of the first control random number and the second control random number; Sending a control instruction to the security chip, so as to instruct the security chip to encrypt the control instruction using the controller serial number, the authentication data of the first control random number, and the second control random number; Sending the encrypted control instruction to the controller.

12. The method of claim 1, wherein, The method further comprises: Sending a meter reading instruction to a meter; the meter reading instruction carries a meter random number generated by the security chip, and the meter reading instruction is used to instruct the security chip of the meter to generate security reading data in a preset security mode based on the meter random number; the preset security mode comprises a plaintext mac mode, a ciphertext mode, and a ciphertext mac mode; Receiving the security reading data sent by the meter and verifying the security reading data.

13. A transaction verification apparatus of a charging pile, characterized in that, A charging control terminal applied to the charging pile; the charging pile has at least one charging gun; a security chip of the charging control terminal stores a terminal identifier, a consumption key, and a key index number of the charging control terminal; the device comprises: A charging card reading module for reading a charging card; A resource data determination module for determining a gun identifier of a target charging gun selected to provide electric energy and frozen resource data in the charging card in the case that the charging card is read; wherein, if a balance of a power purchase wallet in the charging card is greater than or equal to a predicted deduction amount, the predicted deduction amount is determined as the frozen resource data; if the balance of the power purchase wallet is less than the predicted deduction amount, the balance of the power purchase wallet is determined as the frozen resource data; the predicted deduction amount is determined by the charging control terminal; An identifier and index number acquisition module for acquiring the terminal identifier and the key index number from the security chip; A random number and serial number receiving module for receiving a pseudo random number and a resource offline transaction serial number sent by the charging card in the case that the key index number can be supported by the charging card; The authentication code calculation command sending module is configured to send an initialization grey lock message authentication code calculation command carrying the machine gun identifier to the secure chip, to instruct the secure chip to calculate the consumption key according to a terminal transaction serial number, the machine gun identifier, the pseudo-random number, and the resource offline transaction serial number, to obtain a sub-key corresponding to the consumption key; and to calculate a transaction type identifier, transaction time data, the terminal identifier, and the frozen resource data by using the sub-key, to obtain a first message authentication code; The grey lock command sending module is configured to send a grey lock command to the charging card based on the first message authentication code, a terminal random number, the transaction time data, and the terminal transaction serial number, to instruct the charging card to perform transaction verification on the first message authentication code, and to receive a second message authentication code sent by the charging card in a case where the first message authentication code passes the transaction verification, to verify the legitimacy of the charging card.

14. The apparatus of claim 13, wherein, The device further comprises: The initialization command sending module is configured to send a grey lock wallet initialization command to the charging card based on the machine gun identifier, the frozen resource data, the terminal identifier, and the key index number, to instruct the charging card to verify the key index number, and to send a pseudo-random number and a resource offline transaction serial number to the charging control terminal if the verification is passed.

15. The apparatus of claim 13, wherein, The device further comprises: The verification code calculation instruction sending module is configured to send a grey lock verification code calculation instruction to the secure chip based on the transaction type identifier, a charging card identifier, the resource offline transaction serial number, and resource transaction data in a case where a charging operation is completed, to instruct the secure chip to calculate a grey lock verification code and a secure storage module verification code by using the sub-key. The transaction data sending module is configured to send the resource transaction data, the resource offline transaction serial number, the terminal identifier, the machine gun identifier, the terminal transaction serial number, the transaction time data, the grey lock verification code, and the secure storage module verification code to the charging card. 16.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-15. The processor executes the computer program to implement the steps of the method in any one of claims 1 to 12.

17. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1 to 12.

Citation Information

Patent Citations

  • System and methods for secure firmware validation

    US20160306977A1

  • Transaction Method, Payment Device, Check Device, and Server

    US20190362334A1