Charging Facility Data Security Protection Method, System, Electronic Device and Storage Medium
By verifying the vehicle identity in the charging facility network and encrypting the charging parameters and billing parameters based on the vehicle information generation key, the problem of insufficient security of charging parameters and billing parameters in the prior art is solved, and efficient and reliable security protection of data is achieved.
Patent Information
- Application Number
- CN202510323301.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-03-19
AI Technical Summary
The existing charging facility network lacks an effective security protection mechanism when processing charging requests, which makes it difficult to guarantee the confidentiality, integrity and availability of charging parameters and billing parameters, and is prone to data leakage and tampering.
By verifying the vehicle identity when receiving the vehicle's charging request, obtaining charging parameters and billing parameters, and generating keys based on the vehicle information to encrypt the parameters, and finally adding a timing identifier during transmission to achieve layered encryption of data and differentiated security protection.
It improves the confidentiality of charging parameters and billing parameters, effectively prevents data leakage and tampering, and enhances the reliability and integrity of data transmission through the introduction of timing identification, thereby improving the data security protection level of charging stations.
Smart Images

Figure CN119854041B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and particularly to a method, system, electronic device and storage medium for data security protection of charging facilities. Background Art
[0002] With the rapid popularization of new energy vehicles, the construction scale of intelligent charging facilities is constantly expanding. Intelligent charging facilities not only need to complete the charging function, but also need to process a large amount of data interaction including charging control instructions, billing data, etc. The security of these data is directly related to the reliability of the charging process and the property safety of users.
[0003] Currently, when the existing charging facility network processes a vehicle charging request, it usually directly starts the charging process after a simple authentication of the vehicle. The processing of data such as charging parameters and billing parameters is relatively rough. In terms of data transmission, most use plaintext or simple encryption methods, lacking an effective security protection mechanism. Especially in the face of increasingly complex network attacks and security threats, it is impossible to guarantee the confidentiality, integrity and availability of charging parameters and billing parameters, and it is easy to cause problems such as data leakage and tampering, thus resulting in low data security protection for charging stations. Summary of the Invention
[0004] This application provides a method, system, electronic device and storage medium for data security protection of charging facilities, which can improve the confidentiality of charging parameters and billing parameters, reduce risks such as data leakage and tampering, and further enhance the data security of charging stations.
[0005] In the first aspect, this application provides a method for data security protection of charging facilities, and the method includes:
[0006] When receiving a charging request from a vehicle for a target charging pile in a charging station, verify the identity of the vehicle based on the charging request to obtain a verification result;
[0007] When the verification result is successful, obtain the charging parameters of the target charging pile control layer and the billing parameters of the service layer based on the charging request;
[0008] Generate a first key for the control layer and a second key for the service layer based on the vehicle information of the vehicle and the charging request;
[0009] Perform a first encryption process on the charging parameters based on the first key to obtain first encrypted data, and perform a second encryption process on the billing parameters based on the second key to obtain second encrypted data;
[0010] Add a time sequence identifier to the first encrypted data and the second encrypted data respectively, and then transmit them to the vehicle terminal of the vehicle.
[0011] By adopting the above technical solution, when receiving a charging request from a vehicle, the vehicle identity is first verified to ensure the legitimacy of the request source; after the verification passes, the charging parameters of the control layer and the charging fee parameters of the business layer are respectively obtained to achieve hierarchical management of data; meanwhile, based on the vehicle information and the charging request, keys for the control layer and the business layer are respectively generated, and these keys are used to encrypt the parameters of the corresponding layers to obtain encrypted data, thereby realizing differential security protection for data at different layers; finally, by adding a time sequence identifier to the encrypted data and then transmitting it, while ensuring the security of data transmission, the traceability of the data transmission process is also provided. This method of combining hierarchical encryption with time sequence transmission not only improves the confidentiality of the charging parameters and the charging fee parameters, effectively preventing data leakage and tampering, but also enhances the reliability and integrity of data transmission through the introduction of the time sequence identifier, thus comprehensively improving the data security protection level of the charging station.
[0012] In the second aspect of the present application, a charging facility data security protection system is provided, and the system includes:
[0013] An identity verification module, configured to, when receiving a charging request from a vehicle for a target charging pile in a charging station, verify the identity of the vehicle based on the charging request to obtain a verification result;
[0014] A data acquisition module, configured to, when the verification result is verification success, obtain the charging parameters of the control layer and the charging fee parameters of the business layer of the target charging pile based on the charging request;
[0015] A key generation module, configured to generate a first key for the control layer and a second key for the business layer based on the vehicle information of the vehicle and the charging request;
[0016] An encryption processing module, configured to perform first encryption processing on the charging parameters based on the first key to obtain first encrypted data, and perform second encryption processing on the charging fee parameters based on the second key to obtain second encrypted data;
[0017] A data transmission module, configured to add time sequence identifiers to the first encrypted data and the second encrypted data respectively and then transmit them to the vehicle terminal of the vehicle.
[0018] In the third aspect of the present application, a computer storage medium is provided. The computer storage medium stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the above method steps.
[0019] In the fourth aspect of the present application, an electronic device is provided, including: a processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the above method steps.
[0020] In summary, one or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages:
[0021] When the present application receives a charging request from a vehicle, it first verifies the vehicle identity to ensure the legitimacy of the request source. After successful verification, it separately obtains the charging parameters of the control layer and the billing parameters of the business layer to achieve hierarchical management of data. At the same time, based on the vehicle information and the charging request, keys for the control layer and the business layer are respectively generated, and these keys are used to encrypt the parameters of the corresponding levels to obtain encrypted data, thereby realizing differential security protection for data at different levels. Finally, by adding a timing identifier to the encrypted data before transmission, while ensuring the security of data transmission, it also provides the ability to trace the data transmission process. This method of combining hierarchical encryption with timing transmission not only improves the confidentiality of charging parameters and billing parameters, effectively preventing data leakage and tampering, but also enhances the reliability and integrity of data transmission through the introduction of timing identifiers, thus comprehensively improving the data security protection level of the charging station. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 is a schematic flowchart of a method for data security protection of a charging facility provided by an embodiment of the present application;
[0023] Figure 2 is a schematic block diagram of a data security protection system for a charging facility provided by an embodiment of the present application;
[0024] Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present application.
[0025] Description of the reference numerals: 300, electronic device; 301, processor; 302, communication bus; 303, user interface; 304, network interface; 305, memory. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments.
[0027] In the description of the embodiments of the present application, words such as "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "for example" or "for instance" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of words such as "for example" or "for instance" is intended to present related concepts in a specific manner.
[0028] In the description of the embodiments of the present application, the term "a plurality of" means two or more. For example, a plurality of systems means two or more systems, and a plurality of screen terminals means two or more screen terminals. In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "include", "comprise", "have" and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0029] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments.
[0030] Please refer to Figure 1 , and a schematic flowchart of a method for protecting the data security of charging facilities is specifically proposed. This method can be implemented relying on a computer program, can be implemented relying on a single-chip microcomputer, or can run on a charging facility data security protection system. This computer program can be integrated in a computer device or can run as an independent tool application. Specifically, this method includes steps 10 to 50, and the above steps are as follows:
[0031] Step 10: When a charging request for a target charging pile in a charging station sent by a vehicle is received, verify the identity of the vehicle based on the charging request to obtain a verification result.
[0032] The target charging pile in the embodiments of the present application refers to a specific charging pile requested by the vehicle for charging. This charging pile has two functional levels, namely a control layer and a service layer. The control layer is used to manage the charging parameters during the charging process, and the service layer is used to manage the billing parameters during the charging process.
[0033] The charging request in the embodiments of the present application refers to a data request sent by the vehicle to the charging station. This request includes information such as a vehicle identification code, a charging port type, a charging mode, a target charging amount, and a user identifier, and is used to apply to the charging station to use a specific charging pile for charging.
[0034] Specifically, when the charging station receives a charging request sent by a vehicle through the on-vehicle terminal, it is necessary to first confirm the legitimacy of the requester to prevent illegal users from using the charging facilities or malicious attacks. When receiving a charging request for a target charging pile in the charging station from the vehicle, two key pieces of information, namely the vehicle identification code and the charging port type, are extracted from the charging request. Among them, the vehicle identification code is the unique identifier of each vehicle and is used to confirm the true identity of the vehicle; the charging port type contains the specification parameters of the vehicle charging interface and is used to determine whether the vehicle matches the target charging pile. After obtaining this information, first, the extracted vehicle identification code is compared and verified with the vehicle identity database pre-stored in the charging station system. The identities of all registered vehicles are stored in this database, and the first verification result can be obtained through query and comparison. At the same time, the charging port type in the charging request is also matched and verified with the charging port type supported by the target charging pile to ensure the physical compatibility of the charging equipment, and thus the second verification result is obtained. Only when both of these verifications pass will the system confirm that the current verification result is verified and allow subsequent charging operations.
[0035] Based on the above embodiments, as an alternative embodiment, the identity of the vehicle is verified based on the charging request to obtain a verification result. This step may further include the following steps:
[0036] Step 101: Obtain the vehicle identification code and the charging port type of the vehicle from the charging request.
[0037] Specifically, in order to accurately identify the identity of the vehicle requesting charging, it is first necessary to parse the data of the received charging request. The charging request is encapsulated in a preset data format, which contains multiple data fields. By reading the data header information of the charging request, the storage locations of the vehicle identification code field and the charging port type field are located, and thus these two key pieces of information are extracted. Specifically, the vehicle identification code is usually a 17-digit alphanumeric combination, such as "LVGDM4A58DN071249", and the charging port type may be standard types such as "GB / T", "CHAdeMO", or "CCS".
[0038] Step 102: Verify the vehicle identification code with the preset vehicle identity database to obtain the first verification result.
[0039] Specifically, after obtaining the vehicle identification number, access the preset vehicle identity database in the charging station system for verification. This database uses a key-value pair storage structure, where the vehicle identification number serves as the primary key, associated with information such as the vehicle's registration status and charging permissions. The verification process first performs a query operation in the database using the vehicle identification number. If a matching record is found, further check whether the vehicle's registration status is valid and the charging permissions are normal. For example, when the record corresponding to the vehicle identification number "LVGDM4A58DN071249" shows that the vehicle is in a normal registration status and has charging permissions, the system marks the first verification result as verified; otherwise, if no record is found, or the vehicle status is abnormal, or the permissions are restricted, the first verification result is marked as verification failed.
[0040] Step 103: Verify the charging port type and the charging port types supported by the target charging pile to obtain the second verification result.
[0041] Specifically, to ensure the physical compatibility of the charging equipment and charging safety, after completing the vehicle identity verification, it is also necessary to verify the matching of the charging interfaces. First, read the list of supported charging port types from the device configuration information of the target charging pile. This list contains all the charging standard types supported by the charging pile and their corresponding technical parameters, such as voltage level, maximum charging power, etc. Subsequently, compare the charging port type obtained from the charging request with this list. The verification process is carried out in a multi-dimensional matching manner, not only to confirm the consistency of the charging standard types, but also to verify whether the specific technical parameters meet the requirements. For example, when the charging port type of the vehicle is "GB / T", the system will first check whether the target charging pile supports the "GB / T" standard. If it does, further compare whether the voltage level is within the output range of the charging pile. Only when all technical parameters meet the requirements will the system mark the second verification result as verified; if any mismatched parameters are found, the second verification result is marked as verification failed.
[0042] Step 104: When both the first verification result and the second verification result are verified, determine that the verification result is verified.
[0043] Specifically, after obtaining the first verification result and the second verification result, the final verification confirmation will be executed. The system judges the status of the two verification results through a logical AND operation. Only when both the vehicle identity verification (the first verification result) and the charging port type verification (the second verification result) are in a passed state will the final verification result be determined as verified. This dual verification mechanism ensures that only legal vehicles with matching technical parameters can obtain charging authorization.
[0044] Step 20: When the verification result is successful, obtain the charging parameters of the target charging pile control layer and the billing parameters of the business layer based on the charging request.
[0045] Specifically, to achieve a safe and controllable charging process and accurate cost calculation, after completing the identity verification, it is necessary to extract charging-related parameters from the charging request and perform hierarchical processing. First, parse the parameter information in the charging request, including control layer parameters such as the target charging amount, maximum charging current, and expected charging duration, as well as business layer parameters such as the billing method selected by the user and coupon information. For the control layer parameters, the system will match the target charging amount with the remaining battery capacity feedback by the battery management system to determine the actual executable charging current curve, and dynamically adjust the charging power according to the temperature change during the charging process to ensure charging efficiency and safety. For example, when the target charging amount is set to 40 kWh, the system will formulate a segmented charging strategy based on the current state of the battery and automatically reduce the charging power after the battery capacity reaches 80% to protect the battery life. For the business layer parameters, the system will calculate the estimated charging cost by combining the billing method selected by the user (such as peak-valley time-of-use billing, prepayment, post-payment, etc.) and the current applicable preferential policies, and update the billing data in real time during the charging process. For example, when the user selects peak-valley time-of-use billing and uses a full reduction coupon, the system will dynamically calculate the cost according to the electricity price and preferential rules at different times. This hierarchical parameter processing mechanism not only ensures the precise control of the charging process, but also provides a flexible billing scheme, and improves the charging efficiency and user experience through real-time adjustment of parameters.
[0046] Based on the above embodiments, as an optional embodiment, the step of obtaining the charging parameters of the target charging pile control layer and the billing parameters of the business layer based on the charging request may further include the following steps:
[0047] Step 201: Obtain the charging mode and the target charging amount from the charging request, and determine the charging index based on the historical charging information of the target charging pile.
[0048] Specifically, to achieve scientific and reasonable charging control, it is first necessary to obtain the basic parameters in the charging request and evaluate the performance status of the charging pile. By parsing the data structure of the charging request, the charging mode set by the user (such as fast charging mode, standard mode, or economy mode) and the target charging amount information are extracted. At the same time, access the historical database of the target charging pile to obtain the charging records in the recent period, including the number of charging times, the duration of each charging, the charging power fluctuation, and other information. Based on these historical data, a preset evaluation model is used to calculate the charging index, which reflects the current usage status and performance level of the charging pile. For example, when the historical data shows that the charging pile has completed 10 charges in the past 24 hours and the power fluctuation is within the normal range, the system will evaluate the charging index as excellent; conversely, if it is found that the charging power often fluctuates abnormally, the charging index will be correspondingly reduced. This performance evaluation mechanism based on historical data can timely detect potential problems of the charging equipment and provide important references for subsequent charging parameter configuration.
[0049] Step 202: Determine the charging parameters after the target charging pile charges according to the charging mode based on the charging index.
[0050] Specifically, to ensure the safety and efficiency of the charging process, it is necessary to intelligently adjust the charging parameters according to the charging index. The system first determines the reference charging parameters based on the charging mode, including charging voltage, charging current, power curve, etc., and then dynamically optimizes them in combination with the charging index. For example, when the charging index is in an excellent state, the charging current in the fast charging mode can reach the rated value of the device; while when the charging index is low, the system will correspondingly reduce the upper limit of the charging current and adjust the climbing rate of the power curve. Through this adaptive parameter adjustment mechanism, the performance of the charging equipment can be fully utilized, and the equipment can be effectively prevented from overloading, thus extending the service life of the equipment.
[0051] Step 203: Determine the charging duration to reach the target charging amount based on the charging mode, and calculate the billing parameters based on the charging duration and the unit price corresponding to the charging mode.
[0052] Specifically, to accurately calculate the charging cost, it is necessary to scientifically estimate the charging duration and determine the cost in combination with the billing strategy. The system first calculates the estimated charging duration through an algorithm model according to the power curve corresponding to the charging mode and the target charging amount. For example, in the fast charging mode, if the target charging amount is 40 degrees of electricity, the system will consider the power change during the charging process and estimate that it will take about 40 minutes of charging duration. Subsequently, in combination with the billing standards of different charging modes (such as 1.5 yuan / degree for the fast charging mode and 1.2 yuan / degree for the standard mode), the estimated charging cost and other service costs are calculated to form complete billing parameters. This intelligent billing method based on the charging mode not only ensures the rationality of billing but also improves the accuracy of cost calculation.
[0053] Step 204: Store the charging parameters into the control layer and store the charging fee parameters into the service layer.
[0054] Specifically, write charging parameters such as charging voltage and charging current into the parameter table of the control layer for subsequent charging process control; at the same time, save charging fee parameters such as charging fee and charging method into the database of the service layer for fee settlement and bill generation. This hierarchical storage mechanism not only improves the modularity of the system, but also facilitates the independent maintenance and upgrade of each functional module, enhancing the scalability and maintainability of the system.
[0055] Step 30: Generate a first key for the control layer and a second key for the service layer based on the vehicle information and charging request of the vehicle.
[0056] Specifically, to ensure the security of the charging process and the reliability of transactions, it is necessary to establish independent encryption mechanisms for the control layer and the service layer respectively. First, based on vehicle information (including vehicle identification number, charging port type, etc.) and information such as timestamp and request sequence number in the charging request, generate a key pair using a preset encryption algorithm. For the control layer, the system uses the vehicle identification number and charging parameters as seeds, and generates a first key through a secure hash algorithm such as SHA-256. This key is used to encrypt the control instructions during the charging process to ensure the security of instruction transmission. For example, when the vehicle identification number is "LVGDM4A58DN071249", the system will combine it with parameters such as charging voltage and current to generate a unique key for the control layer. For the service layer, the system generates a second key based on the sequence number of the charging request and charging fee parameters using an asymmetric encryption algorithm such as RSA to protect the security of transaction data. For example, the system combines the charging request sequence number with data such as charging standard and preferential information to generate a key for the service layer dedicated to this charging transaction. This double-layer encryption mechanism not only realizes the secure isolation of control instructions and transaction data, but also provides different levels of security protection through different encryption algorithms, effectively preventing data tampering and illegal access, and improving the security and reliability of the entire charging process.
[0057] Based on the above embodiments, as another alternative embodiment, the step of generating a first key for the control layer and a second key for the service layer based on the vehicle information and charging request of the vehicle may further include the following steps:
[0058] Step 301: Extract the vehicle identification number from the vehicle information of the vehicle and obtain the timestamp of the charging request.
[0059] Specifically, to generate a unique and secure key, it is first necessary to obtain the vehicle's unique identifier and time information. By parsing the data structure of the vehicle information, locate and extract the 17-digit vehicle identification number, such as "LVGDM4A58DN071249". At the same time, read the timestamp information at the time of the request initiation from the data header of the charging request. This timestamp is in the Unix timestamp format, accurate to the millisecond level. This combination based on the vehicle's unique identifier and precise time provides a unique input source for subsequent key generation.
[0060] Step 302: Concatenate and operate on the vehicle identification number and the timestamp to obtain the first raw key, and perform a hash calculation on the first raw key to obtain the first key.
[0061] Specifically, to ensure the security of the control layer key, multiple processes need to be performed on the original information. First, concatenate the extracted vehicle identification number and the timestamp in a preset format to generate the first raw key. For example, concatenate "LVGDM4A58DN071249" and "1676438400000" to form the raw key string. Subsequently, use a secure hash algorithm such as SHA-256 to calculate this raw key, generating a hash value of a fixed length as the first key. This processing method based on the hash algorithm not only ensures the uniqueness of the key but also improves the security strength of the key.
[0062] Step 303: Extract the user identifier from the charging request and obtain the device serial number of the target charging pile.
[0063] Specifically, by parsing the user information field of the charging request, extract the user's unique identification code, which may be a mobile phone number or a membership number, etc. At the same time, obtain the unique device serial number from the device information of the target charging pile. This combination of dual identifications ensures the uniqueness and traceability of the business layer key.
[0064] Step 304: Perform an exclusive OR operation on the user identifier and the device serial number to obtain the second raw key, and perform asymmetric encryption on the second raw key to obtain the second key.
[0065] Specifically, to improve the security of the business layer key, a combination scheme of exclusive OR operation and asymmetric encryption is adopted. First, perform a bit-level exclusive OR operation on the user identifier and the device serial number to generate the second raw key. For example, perform an exclusive OR operation on the user identifier "13800138000" and the device serial number "CP20240215001". Subsequently, use an asymmetric encryption algorithm such as RSA to encrypt the second raw key to generate the final second key. This multi-level encryption processing ensures the security and immutability of business data.
[0066] Step 305: Store the first key and the second key into the key table of the control layer and the key table of the service layer respectively.
[0067] Specifically, in order to achieve effective management and use of keys, a hierarchical key storage mechanism needs to be established. The system writes the generated first key into the key table of the control layer for encrypting and verifying subsequent charging control instructions; at the same time, the second key is stored in the key table of the service layer for encrypting transaction data and security verification. This hierarchical storage method not only realizes the security isolation between the control layer and the service layer, but also facilitates key update and management, improving the security and maintainability of the system.
[0068] Step 40: Perform a first encryption process on the charging parameters based on the first key to obtain first encrypted data, and perform a second encryption process on the billing parameters based on the second key to obtain second encrypted data.
[0069] Specifically, in order to ensure the secure transmission of control instructions and transaction data during the charging process, the charging parameters and billing parameters need to be encrypted respectively. For the charging parameters of the control layer, first read the first key from the key table of the control layer, then serialize parameters such as charging voltage and charging current according to a preset data format to form a data packet to be encrypted. Subsequently, use a symmetric encryption algorithm such as AES-256, and use the first key as the encryption key to encrypt the data packet to generate first encrypted data. For example, when the charging parameters include information such as "voltage 220V, current 10A", the system will convert it into a binary data stream and then generate ciphertext through the symmetric encryption algorithm. For the billing parameters of the service layer, the system obtains the second key from the key table of the service layer, structurally encapsulates billing information such as charging rate and discount amount, and then uses an asymmetric encryption algorithm such as RSA to encrypt the data with the public key part of the second key to generate second encrypted data. For example, when the billing parameters include information such as "unit price 1.5 yuan / kWh, discount amount 10 yuan", the system will convert it into a standard format data structure and then generate ciphertext through the asymmetric encryption algorithm. This hierarchical encryption mechanism not only realizes the security isolation between control data and service data, but also provides different levels of security protection through different encryption algorithms, effectively preventing data from being stolen or tampered with during transmission, and improving the security and reliability of the entire charging process. At the same time, due to the use of efficient encryption algorithms, the time overhead of the encryption process is small and will not affect the normal operation of the charging service.
[0070] Based on the above embodiments, as another alternative embodiment, the step of performing a first encryption process on the charging parameters based on the first key to obtain first encrypted data, and performing a second encryption process on the billing parameters based on the second key to obtain second encrypted data may further include the following steps:
[0071] Step 401: Calculate the data entropy values of the charging parameters and the billing parameters.
[0072] Specifically, in order to evaluate the complexity of the data and select an appropriate encryption strategy, it is necessary to perform entropy analysis on the parameter data. The system first converts the charging parameters (such as charging voltage, current, etc.) and the billing parameters (such as rates, discounts, etc.) into binary sequences respectively, and then uses the information entropy calculation formula to analyze the data. For example, for the charging parameter "voltage 220V, current 10A", the system will count the probability distribution of different bit positions and calculate its information entropy value according to the Shannon entropy formula; the same method is also used to calculate the entropy value of the billing parameters. This evaluation method based on information entropy can accurately reflect the randomness and complexity of the data, providing a scientific basis for the subsequent selection of encryption strategies.
[0073] Step 402: When the data entropy value is greater than the preset threshold, segment the first key and the second key to obtain multiple sub-keys.
[0074] Specifically, in order to improve the encryption strength, a segmented encryption strategy needs to be adopted when the data complexity is high. The system sets a preset threshold (such as 4.5 bits / byte), and when the calculated entropy value exceeds this threshold, the key segmentation mechanism is activated. For the first key, the system divides it into multiple sub-key segments according to the preset segmentation length (such as 32 bytes); for the second key, modular decomposition is performed according to the structural characteristics of the RSA key. For example, the 256-bit first key is evenly divided into 8 32-bit sub-keys, and each sub-key is responsible for encrypting a specific range of data. This segmentation processing mechanism not only improves the utilization efficiency of the key, but also increases the complexity of the encryption process.
[0075] Step 403: Construct an encryption chain based on each sub-key, and determine different encryption algorithms in the encryption chain according to the size of the data entropy value.
[0076] Specifically, in order to achieve multi-level security protection, a flexible encryption algorithm chain needs to be constructed. The system first forms the segmented sub-keys into an encryption chain according to the preset order, and then assigns different strength encryption algorithms to each encryption link according to the size of the data entropy value. For example, when the entropy value of a certain segment of data is high, the AES-256 algorithm with greater computational intensity is used; when the entropy value is at a medium level, the lightweight ChaCha20 algorithm is selected; when the entropy value is low, the simple XOR encryption algorithm is used. This dynamic algorithm selection mechanism based on entropy value not only ensures the encryption strength, but also optimizes the usage efficiency of computing resources.
[0077] Step 404: Encrypt the charging parameters and the billing parameters based on the corresponding encryption algorithms to obtain the first encrypted data and the second encrypted data.
[0078] Specifically, to complete the security encryption of data, it is necessary to perform encryption operations in the order of the constructed encryption chain. The system first divides the charging parameters into multiple data blocks according to the data structure, and then encrypts them sequentially using the corresponding algorithms and sub-keys in the encryption chain. The output of each encryption link is used as the input of the next link, and finally the first encrypted data is generated. The same process is also applied to the encryption of billing parameters, and the second encrypted data is finally generated through multiple rounds of encryption conversion. For example, for the charging voltage data, it is first encrypted using the first sub-key and the AES-256 algorithm, and then the ciphertext is continuously encrypted using the second sub-key and the ChaCha20 algorithm, and so on until the entire encryption process is completed. This chain encryption mechanism not only provides multi-layer security protection, but also achieves a balance between security and efficiency through the reasonable combination of algorithms, effectively ensuring the security of the data transmission process.
[0079] Step 50: Add timing identifiers to the first encrypted data and the second encrypted data respectively and then transmit them to the vehicle terminal of the vehicle.
[0080] Specifically, to ensure the orderly transmission and timely verification of encrypted data, it is necessary to perform timing marking and standardized transmission on the encrypted data. The system first generates a timestamp accurate to the millisecond level and adds it to the data headers of the first encrypted data and the second encrypted data. For example, if the current timestamp is "1676438400000", the system combines it with the first encrypted data to form a complete data packet, including the data packet header (timestamp), data payload (encrypted charging parameters), and checksum; the same processing method is also applied to the second encrypted data to form a complete data packet containing billing parameters. Subsequently, the system transmits these two data packets with timing identifiers to the vehicle terminal through a preset secure communication channel (such as a TLS encrypted channel) respectively. After receiving the data packets, the vehicle terminal first verifies the validity of the timing identifier to ensure the timeliness of the data. For example, a 5-second time window is set. If the time difference between the reception time and the time of the timing identifier exceeds the window threshold, the data is determined to be expired and a retransmission is requested. For the data packets that pass the verification, the vehicle terminal stores them in the control buffer and the service buffer respectively for subsequent charging control and fee calculation. This transmission mechanism based on timing identifiers not only ensures the orderliness and real-time nature of the data, but also improves the efficiency of data processing through partitioned storage, providing a reliable guarantee for the smooth progress of the charging process. At the same time, the complete data packet format and strict timeliness verification mechanism also effectively prevent replay attacks and data tampering, enhancing the security of the entire charging system.
[0081] Based on the above embodiments, as another alternative embodiment, the step of adding timing identifiers to the first encrypted data and the second encrypted data respectively and then transmitting them to the vehicle terminal of the vehicle may further include the following steps:
[0082] Step 501: Generate incremental time sequence numbers based on the first encrypted data and the second encrypted data respectively, and combine each time sequence number with the charging session identifier to generate a time sequence identifier.
[0083] Specifically, set independent sequence number counters for the first encrypted data and the second encrypted data respectively, and incrementally generate time sequence numbers starting from 1. For example, for the control instruction of the first encrypted data, generate a sequence number in the form of "SEQ_001"; for the billing information of the second encrypted data, generate a sequence number in the form of "SEQ_002". At the same time, the system generates a unique session identifier when the charging session is established, such as "SESSION_20240215_001". Subsequently, combine the time sequence number and the session identifier in a preset format to generate a complete time sequence identifier, such as "SESSION_20240215_001_SEQ_001". This combined time sequence identifier mechanism not only ensures the uniqueness and traceability of data packets, but also provides a reliable basis for the breakpoint resumption of data transmission.
[0084] Step 502: Encapsulate the corresponding time sequence identifiers into the data headers of the first encrypted data and the second encrypted data respectively, and transmit the encapsulated data packets to the vehicle terminal of the vehicle in a hierarchical manner according to the preset transmission priority, where the transmission priority of the first encrypted data is higher than that of the second encrypted data.
[0085] Specifically, add the generated time sequence identifier to the data packet header of the corresponding encrypted data to form a standard data transmission format. In the data packet header, in addition to the time sequence identifier, it also contains information such as data type markers and data lengths. Subsequently, the system sets the transmission priority according to the importance of the data, sets the first encrypted data related to charging control to the highest priority (such as Priority-1), and sets the second encrypted data related to billing to the secondary priority (such as Priority-2). During the actual transmission process, the system preferentially processes and sends data packets at the Priority-1 level to ensure the timely delivery of charging control instructions; after the control data transmission is completed, then transmit the billing data packets at the Priority-2 level. This hierarchical transmission mechanism effectively guarantees the real-time control requirements of the charging process and also takes into account the reliable transmission of service data.
[0086] Step 503: Monitor the data reception status of the vehicle terminal. When a data transmission interruption is detected, determine the interruption position based on the time sequence identifier, and retransmit the data starting from the interruption position until the vehicle terminal returns a reception confirmation message.
[0087] Specifically, the system monitors the communication status with the vehicle terminal in real time through heartbeat packets. When it detects that the heartbeat packets time out three times in a row or receives an abnormal response from the terminal, it determines that the transmission is interrupted. At this time, the system accurately locates the position of the transmission interruption based on the timing identifier of the last successfully received data packet. For example, if the timing identifier of the last successfully received data packet is "SESSION_20240215_001_SEQ_010", the system will start retransmitting data from sequence number 11. During the retransmission process, the system still follows the priority transmission strategy, giving priority to retransmitting the first encrypted data. After the vehicle terminal returns an acknowledgment message (such as an ACK packet), it then continues to retransmit the second encrypted data. This breakpoint resumption mechanism based on the timing identifier not only improves the reliability of data transmission but also, by accurately locating the interruption position, avoids unnecessary data retransmissions and improves the transmission efficiency. At the same time, the strict acknowledgment mechanism also ensures the integrity and accuracy of data transmission.
[0088] Based on the above embodiments, as another alternative embodiment, a method for data security protection of charging facilities may further include the following process:
[0089] Specifically, to promptly detect potential security threats, the system needs to monitor the data decryption process in real time. The system sets up a decryption failure counter to record the number of consecutive decryption failures. When the number of failures reaches a preset value (such as 3 times), it activates the security warning mechanism. The system calculates the current communication delay by measuring the round-trip time from the packet being sent to the acknowledgment being received. For example, the normal delay range is within 50 ms. When it detects abnormal decryption, the system generates a first-level security warning data packet containing information such as the number of decryption failures, communication delay, and timestamp. This timely anomaly monitoring mechanism provides warning support for system security protection.
[0090] When it detects that the communication delay exceeds the preset security threshold (such as 200 ms) and at the same time there is an abnormal decryption request (such as using an invalid key or an illegally formatted decryption instruction), the system determines that there is a major security hazard in the current charging process. At this time, the system immediately switches the target charging pile to the restricted charging mode, limits the charging power to no more than 30% of the rated power, and sets a maximum charging duration limit. At the same time, the system generates a second-level security warning, recording the characteristic information of the abnormal decryption request, delay data, and the charging status after the switch. This hierarchical response mechanism not only ensures system security but also avoids a complete interruption of the charging service.
[0091] In addition, to accurately evaluate the security threat level, the system needs to establish a comprehensive risk assessment mechanism. First, the system sets weight coefficients for different types of warning information. For example, the weight of the first-level warning is 0.3, and the weight of the second-level warning is 0.5. At the same time, a credibility score is given to the vehicle identity verification result, including factors such as the verification passing rate and historical charging records, with a weight of 0.2. Based on these factors, the system uses a weighted calculation method to generate a security risk score from 0 to 100. For example, when there are multiple first-level warnings, at least one second-level warning, and abnormal vehicle identity verification, the system may generate a high-risk score above 85 points.
[0092] When the security risk score exceeds a preset emergency threshold (such as 90 points), the system immediately triggers the highest-level security warning. First, the system cuts off all data communication links with the suspicious vehicle terminal through the communication management module and stops data exchange. Subsequently, the system integrates all relevant abnormal information, including warning records, risk score change trends, and abnormal behavior characteristics (such as the time distribution and feature patterns of illegal decryption attempts), to generate a security incident report in a standard format. The system uploads this report to the charging station management system in real time through a secure channel for subsequent security analysis and handling. This multi-level security protection mechanism can not only effectively prevent potential security threats but also provide an important basis for optimizing security policies through detailed event records and analysis.
[0093] Please refer to Figure 2 , which is a schematic diagram of the modules of a charging facility data security protection system provided by an embodiment of the present application. Among them, the system includes:
[0094] An identity verification module, configured to verify the identity of a vehicle based on a charging request when receiving a charging request from the vehicle for a target charging pile in a charging station, and obtain a verification result;
[0095] A data acquisition module, configured to obtain the charging parameters of the control layer and the billing parameters of the service layer of the target charging pile based on the charging request when the verification result is successful verification;
[0096] A key generation module, configured to generate a first key for the control layer and a second key for the service layer based on the vehicle information of the vehicle and the charging request;
[0097] An encryption processing module, configured to perform first encryption processing on the charging parameters based on the first key to obtain first encrypted data, and perform second encryption processing on the billing parameters based on the second key to obtain second encrypted data;
[0098] A data transmission module, configured to add time sequence identifiers to the first encrypted data and the second encrypted data respectively and then transmit them to the vehicle terminal of the vehicle.
[0099] Optionally, the authentication module is further configured to obtain the vehicle identification number and the charging port type of the vehicle from the charging request;
[0100] Verify the vehicle identification number against a preset vehicle identity database to obtain a first verification result;
[0101] Verify the charging port type against the charging port types supported by the target charging pile to obtain a second verification result;
[0102] When both the first verification result and the second verification result are verified to pass, determine that the verification result is verified to pass.
[0103] Optionally, the data acquisition module is further configured to obtain the charging mode and the target charging amount from the charging request, and determine a charging index based on the historical charging information of the target charging pile;
[0104] Determine the charging parameters after the target charging pile charges according to the charging mode based on the charging index;
[0105] Determine the charging duration to reach the target charging amount based on the charging mode, and calculate the charging fee parameters based on the charging duration and the unit price corresponding to the charging mode;
[0106] Store the charging parameters into the control layer, and store the charging fee parameters into the service layer.
[0107] Optionally, the key generation module is further configured to extract the vehicle identification number from the vehicle information of the vehicle, and obtain the time stamp of the charging request;
[0108] Perform a splicing operation on the vehicle identification number and the time stamp to obtain a first original key, and perform a hash calculation on the first original key to obtain a first key;
[0109] Extract the user identification from the charging request, and obtain the device serial number of the target charging pile;
[0110] Perform an exclusive OR operation on the user identification and the device serial number to obtain a second original key, and perform an asymmetric encryption on the second original key to obtain a second key;
[0111] Store the first key and the second key into the key table of the control layer and the key table of the service layer respectively.
[0112] Optionally, the encryption processing module is further configured to calculate the data entropy values of the charging parameters and the charging fee parameters;
[0113] When the data entropy value is greater than a preset threshold, perform a segmentation process on the first key and the second key to obtain multiple sub-keys;
[0114] Construct an encryption chain based on each sub-key, and determine different encryption algorithms in the encryption chain according to the magnitude of the data entropy value;
[0115] Encrypt the charging parameters and billing parameters based on the corresponding encryption algorithm to obtain the first encrypted data and the second encrypted data.
[0116] Optionally, the data transmission module is further configured to generate incremental time sequence numbers based on the first encrypted data and the second encrypted data respectively, and combine each time sequence number with the charging session identifier to generate a time sequence identifier;
[0117] Encapsulate the corresponding time sequence identifiers into the data headers of the first encrypted data and the second encrypted data respectively, and transmit the encapsulated data packets to the vehicle terminal of the vehicle according to a preset transmission priority level, where the transmission priority of the first encrypted data is higher than that of the second encrypted data;
[0118] Monitor the data reception status of the vehicle terminal. When a data transmission interruption is detected, determine the interruption position based on the time sequence identifier, and retransmit the data starting from the interruption position until the vehicle terminal returns a reception confirmation message.
[0119] Optionally, the data transmission module is further configured to monitor the decryption process of the first encrypted data and the second encrypted data in real time. When the decryption fails a preset number of times, calculate the current communication delay and generate a first-level security warning;
[0120] When the communication delay exceeds the preset security threshold and an abnormal decryption request is detected, switch the target charging pile to the restricted charging mode and generate a second-level security warning;
[0121] Based on the first-level security warning and the second-level security warning, combined with the vehicle's identity verification result, construct a security risk score;
[0122] When the security risk score reaches the emergency threshold, trigger a third-level security warning, cut off the data communication link with the vehicle terminal, and report the corresponding warning information, security risk score, and abnormal behavior characteristics to the charging station management system.
[0123] It should be noted that when the system provided in the above embodiments realizes its functions, only the above-mentioned division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the system and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be repeated here.
[0124] The embodiments of the present application also provide a computer storage medium, which can store multiple instructions. The instructions are suitable for being loaded and executed by a processor to perform a data security protection method for a charging facility in the above embodiments. The specific execution process can refer to the specific description in the above embodiments and will not be elaborated here.
[0125] Please refer to Figure 3 The present application also discloses an electronic device. Figure 3 FIG. is a schematic structural diagram of an electronic device disclosed in the embodiments of the present application. The electronic device 300 may include: at least one processor 301, at least one network interface 304, a user interface 303, a memory 305, and at least one communication bus 302.
[0126] Among them, the communication bus 302 is used to realize the connection and communication between these components.
[0127] Among them, the user interface 303 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 303 may further include a standard wired interface and a wireless interface.
[0128] Among them, the network interface 304 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).
[0129] Among them, the processor 301 may include one or more processing cores. The processor 301 connects various parts within the entire server through various interfaces and lines. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 305, and by calling the data stored in the memory 305, it performs various functions of the server and processes data. Optionally, the processor 301 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 301 may integrate one or several combinations of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, and application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communication. It can be understood that the above modem may not be integrated into the processor 301 and may be implemented separately by a single chip.
[0130] Among them, the memory 305 may include a Random Access Memory (RAM), or may also include a Read-Only Memory. Optionally, the memory 305 includes a non-transitory computer-readable storage medium. The memory 305 can be used to store instructions, programs, codes, code sets, or instruction sets. The memory 305 may include a program storage area and a data storage area. Among them, the program storage area can store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area can store the data involved in the above-mentioned method embodiments. Optionally, the memory 305 may also be at least one storage device located far from the aforementioned processor 301. Refer to Figure 3 , in the memory 305 as a computer storage medium, it may include an operating system, a network communication module, a user interface module, and an application program for a charging facility data security protection method.
[0131] In Figure 3 In the electronic device 300 shown, the user interface 303 is mainly used to provide an input interface for the user to obtain the data input by the user; while the processor 301 can be used to call the application program for a charging facility data security protection method stored in the memory 305. When executed by one or more processors 301, the electronic device 300 is caused to execute the method of one or more of the above embodiments. It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0132] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0133] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some service interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.
[0134] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0135] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0136] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to enable a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present application. And the aforementioned memory includes: various media such as USB flash drives, mobile hard disks, magnetic disks or optical discs that can store program codes.
[0137] The above are only exemplary embodiments of the present disclosure and cannot be used to limit the scope of the present disclosure. That is, any equivalent changes and modifications made according to the teachings of the present disclosure still fall within the scope covered by the present disclosure. Those skilled in the art will easily think of other implementation schemes of the present disclosure after considering the specification and the practice of the present disclosure.
[0138] The present application aims to cover any variations, uses or adaptive changes of the present disclosure. These variations, uses or adaptive changes follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not recorded in the present disclosure. The specification and the embodiments are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.
Claims
1. A charging facility data security protection method, characterized in that: Methods include: When receiving a charging request from a vehicle to a target charging pile in a charging station, verifying the identity of the vehicle based on the charging request and obtaining a verification result; When the verification result is successful, the charging parameters of the target charging pile control layer and the billing parameters of the business layer are obtained based on the charging request; Generate a first key of the control layer and a second key of the business layer based on vehicle information and a charging request of the vehicle; Calculate the data entropy value of charging parameters and billing parameters; When the data entropy value is greater than a preset threshold, the first key and the second key are processed in segments to obtain multiple subkeys; Construct an encryption chain based on each subkey, and determine different encryption algorithms in the encryption chain according to the size of the data entropy value; The charging parameters and the billing parameters are encrypted using the corresponding encryption algorithm and subkey in the encryption chain, and the output of each encryption link is used as the input of the next link to obtain the first encrypted data and the second encrypted data; The first encrypted data and the second encrypted data are respectively added with timing identifiers and then transmitted to a vehicle terminal of the vehicle.
2. The charging facility data security protection method according to claim 1, characterized in that: The identity of the vehicle is verified based on the charging request, and a verification result is obtained, including: Get the vehicle identification number and charging port type of the vehicle from the charging request; Verifying the vehicle identification code with a preset vehicle identity database to obtain a first verification result; Verify the charging port type and the charging port type supported by the target charging pile to obtain a second verification result; When both the first verification result and the second verification result are verified to be passed, the verification result is determined to be verified to be passed.
3. The charging facility data security protection method according to claim 1, characterized in that: Based on the charging request, the charging parameters of the target charging pile control layer and the billing parameters of the business layer are obtained, including: Obtaining a charging mode and a target charging amount from a charging request, and determining a charging index based on historical charging information of a target charging pile; Determine charging parameters of the target charging pile after charging according to the charging mode based on the charging index; Determine the charging time required to reach the target charging amount based on the charging mode, and calculate the charging parameters based on the charging time and the unit price corresponding to the charging mode; The charging parameters are stored in the control layer, and the billing parameters are stored in the business layer.
4. The charging facility data security protection method according to claim 1, characterized in that: Generate a first key of the control layer and a second key of the business layer based on vehicle information and a charging request of the vehicle, including: Extract the vehicle identification code from the vehicle's vehicle information and obtain the timestamp of the charging request; The vehicle identification code and the timestamp are concatenated to obtain a first original key, and the first original key is hashed to obtain a first key; Extract the user ID from the charging request and obtain the device serial number of the target charging pile; Performing an XOR operation on the user identification and the device serial number to obtain a second original key, and asymmetrically encrypting the second original key to obtain a second key; The first key and the second key are stored in the key table of the control layer and the key table of the business layer respectively.
5. The charging facility data security protection method according to claim 1, characterized in that: The method of adding a timing mark to the first encrypted data and the second encrypted data respectively and transmitting the data to a vehicle terminal of the vehicle comprises: Generate an incremental timing sequence number based on the first encrypted data and the second encrypted data, respectively, and combine each timing sequence number with the charging session identifier to generate a timing identifier; Encapsulating the corresponding timing identifiers into the data headers of the first encrypted data and the second encrypted data, respectively, and transmitting the encapsulated data packets to the vehicle terminal of the vehicle in a hierarchical manner according to a preset transmission priority, wherein the transmission priority of the first encrypted data is higher than that of the second encrypted data; Monitor the data reception status of the vehicle terminal. When a data transmission interruption is detected, determine the interruption position based on the timing identifier, and retransmit the data from the interruption position until the vehicle terminal returns a reception confirmation message.
6. The charging facility data security protection method according to claim 1, characterized in that: The method further comprises: Monitor the decryption process of the first encrypted data and the second encrypted data in real time, and when a preset number of decryption failures occur, calculate the current communication delay and generate a first-level security warning; When the communication delay exceeds the preset safety threshold and an abnormal decryption request is detected, the target charging pile is switched to the restricted charging mode and a second-level safety warning is generated; Based on the first-level security warning and the second-level security warning, combined with the vehicle's identity verification results, a security risk score is constructed; When the safety risk score reaches the emergency threshold, the third-level safety warning is triggered, the data communication link with the vehicle terminal is cut off, and the corresponding warning information, safety risk score and abnormal behavior characteristics are reported to the charging station management system.
7. A charging facility data security protection system, characterized in that: The system includes: An identity verification module is used to verify the identity of the vehicle based on the charging request when receiving a charging request from the vehicle to the target charging pile in the charging station, and obtain a verification result; A data acquisition module, used to acquire charging parameters of the target charging pile control layer and billing parameters of the business layer based on the charging request when the verification result is successful; A key generation module, used to generate a first key of a control layer and a second key of a business layer based on vehicle information and a charging request of the vehicle; An encryption processing module is used to calculate the data entropy value of the charging parameters and the billing parameters; when the data entropy value is greater than a preset threshold, the first key and the second key are segmented to obtain multiple subkeys; an encryption chain is constructed based on each subkey, and different encryption algorithms are determined in the encryption chain according to the size of the data entropy value; the charging parameters and the billing parameters are encrypted using the corresponding encryption algorithm and subkey in the encryption chain, and the output of each encryption link is used as the input of the next link to obtain the first encrypted data and the second encrypted data; The data transmission module is used to add timing marks to the first encrypted data and the second encrypted data respectively and then transmit them to the vehicle terminal of the vehicle.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the method according to any one of claims 1 to 6.
9. An electronic device, characterized in that: It includes a processor, a memory, a user interface and a network interface, the memory is used to store instructions, the user interface and the network interface are used to communicate with other devices, and the processor is used to execute the instructions stored in the memory so that the electronic device executes the method as claimed in any one of claims 1-6.
Citation Information
Patent Citations
New energy automobile charging data interaction method and charging pile operation management system
CN119142189A