Behavior management method and system of battery management system, medium and equipment

By obtaining and analyzing system events in the battery management system, identifying user behaviors and matching security policies, the problem that existing systems cannot distinguish attacks and operation and maintenance behaviors is solved, and the security of the system is improved.

CN119995899APending Publication Date: 2025-05-13HANGZHOU BMSER TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510211854.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing battery management system cannot accurately distinguish between attack behavior and normal operation and maintenance behavior, resulting in serious threats to asset security.

Method used

By obtaining system events in the battery management system, reading the event stream and uploading the status information of the current state machine to the user behavior signature library, obtaining the user behavior recognition results. If the result is identified as a valid behavior, match the corresponding security policy and apply the security policy according to the enabled status to ensure the security of user behavior.

Benefits of technology

The behavior management of the battery management system is realized, accurately distinguishing attack behavior from normal operation and maintenance behavior, improving the security of the system, and preventing malicious attackers from implementing effective attacks after breaking through physical security restrictions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995899A_ABST
    Figure CN119995899A_ABST
Patent Text Reader

Abstract

The invention provides a behavior management method of a battery management system. The behavior management method comprises the following steps: acquiring a system event in the battery management system; reading an event stream of the system event, and uploading the event stream and the state information of the current state machine to a user behavior signature library to obtain a user behavior recognition result; and if the user behavior identification result is an effective behavior, matching a security policy of the user behavior corresponding to the system event, and applying the security policy according to an enabling state of the security policy so as to execute the user behavior when the security policy takes effect. The application can ensure that a malicious attacker cannot implement an effective attack behavior after breaking through physical security limitation. And if the user behavior is an effective behavior, the security during execution of the user behavior can be guaranteed by matching the security policy. The invention further provides a behavior management system of the battery management system, a computer readable storage medium and electronic equipment, which have the above beneficial effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of energy technology, and in particular to a behavior management method, system, medium and device for a battery management system. Background Art

[0002] The deployment environment of the BMS (Battery Management System) battery protection system is often complex. On the one hand, there are issues of personal safety of operation and maintenance personnel, and on the other hand, there are issues of asset safety such as lithium battery pack theft prevention. In addition, there are also issues of information security.

[0003] Currently, the main method of preventing theft is to lock the BMS. However, once the physical lock is broken, the assets will have serious security problems because the battery protection system cannot distinguish between malicious attackers and normal operation and maintenance personnel. On this basis, if malicious attackers directly attack through hardware ports such as network ports, serial ports, and CAN (Controller Area Network) ports, it will cause serious damage to the battery management system. Summary of the invention

[0004] The purpose of this application is to provide a behavior management method, system, computer-readable storage medium and electronic device for a battery management system, which can accurately distinguish between attack behaviors and normal operation and maintenance behaviors and improve the safety of the battery management system.

[0005] In order to solve the above technical problems, the present application provides a behavior management method of a battery management system, and the specific technical solution is as follows:

[0006] Get system events in the battery management system;

[0007] Read the event stream of the system event, upload the event stream and the state information of the current state machine to the user behavior signature library, and obtain the user behavior recognition result;

[0008] If the user behavior identification result is a valid behavior, the security policy corresponding to the system event is matched, and the security policy is applied according to the enabling state of the security policy, so as to execute the user behavior when the security policy takes effect.

[0009] Optionally, before reading the event stream of the system event and uploading the event stream and the state information of the current state machine to the user behavior signature library and obtaining the user behavior recognition result, the method further includes:

[0010] Use finite state machines or hierarchical state machines to define transition tables based on business scenario modeling;

[0011] The transfer table is searched according to the system event to obtain the state information of the current state machine.

[0012] Optionally, reading the event stream of the system event and uploading the event stream and state information of the current state machine to the user behavior signature library includes:

[0013] Capturing user operations as event streams of the system events; the user operations include at least one of user click operations, user slide operations, and sensor data; the event stream includes an event operation sequence and an operation interval;

[0014] The event stream and the state information of the current state machine are uploaded to the user behavior signature library as input data to be matched.

[0015] Optionally, if the user behavior recognition result is a valid behavior, it also includes:

[0016] The user behavior and the system event are written into a database as behavior association events; the database is used to record the association relationship between the user behavior and the system event.

[0017] Optionally, the process of generating the user behavior recognition result includes:

[0018] In the user behavior signature library, a behavior rule discrimination table is called to detect whether the user operations included in the event flow are all legal operations;

[0019] If so, detecting whether there is a matching target user behavior between the operation interval or the operation sequence of the user operation;

[0020] If there is a matching target user behavior, confirm that the user behavior recognition result is a valid behavior;

[0021] If there is no matching target user behavior, the user behavior identification result is confirmed to be an invalid behavior.

[0022] Optionally, if the user behavior identification result is a valid behavior, matching the security policy of the system event corresponding to the user behavior, and executing the security policy according to the enabling state of the security policy includes:

[0023] If the user behavior identification result is a valid behavior, determine whether the valid behavior has a security risk;

[0024] If so, match the security policy including the security protection action or the security range threshold, and set the enable state of the security policy; and only when the enable state is valid, allow the user behavior to be executed.

[0025] Optionally, when matching the security policy of the user behavior corresponding to the system event, the following is further included:

[0026] The alarm operation included in the security policy is set, and the alarm operation is executed when the user operation is abnormal or exceeds the security range threshold.

[0027] The present application also provides a behavior management system for a battery management system, including:

[0028] An event acquisition module, used to acquire system events in the battery management system;

[0029] A user behavior identification module is used to read the event stream of the system event, upload the event stream and the state information of the current state machine to the user behavior signature library, and obtain the user behavior identification result;

[0030] The user behavior management module is used to match the security policy of the system event corresponding to the user behavior if the user behavior identification result is a valid behavior, and apply the security policy according to the enablement status of the security policy so as to execute the user behavior when the security policy takes effect.

[0031] The present application also provides a computer-readable storage medium having a computer program stored thereon, and the computer program implements the steps of the above-mentioned method when executed by a processor.

[0032] The present application also provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps of the above-mentioned method when calling the computer program in the memory.

[0033] The present application provides a behavior management method for a battery management system, comprising: obtaining a system event in a battery management system; reading an event stream of the system event, uploading the event stream and state information of a current state machine to a user behavior signature library, and obtaining a user behavior recognition result; if the user behavior recognition result is a valid behavior, matching a security policy of the user behavior corresponding to the system event, and applying the security policy according to an enabled state of the security policy, so as to execute the user behavior when the security policy takes effect.

[0034] When a system event in the battery management system is detected, this application reads the event stream and uploads it to the user behavior signature library in combination with the current state information, and identifies the user behavior in the user behavior signature library to determine whether the user behavior is valid. If the user behavior is invalid, the user behavior can be rejected, so that a malicious attacker cannot carry out effective attack behavior after breaking through the physical security restrictions. If the user behavior is valid, the security of the user behavior can be guaranteed by matching the security policy.

[0035] The present application also provides a behavior management system of a battery management system, a computer-readable storage medium, and an electronic device, which have the above-mentioned beneficial effects and are not described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0037] Figure 1 A flow chart of a behavior management method for a battery management system provided in an embodiment of the present application;

[0038] Figure 2 A schematic diagram of a behavior management process of a battery management system provided in an embodiment of the present application;

[0039] Figure 3 A flowchart of a user behavior identification process provided in an embodiment of the present application;

[0040] Figure 4 A schematic diagram of the structure of a behavior management system of a battery management system provided in an embodiment of the present application;

[0041] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0042] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0043] Please refer to Figure 1 , Figure 1 A flow chart of a behavior management method of a battery management system provided in an embodiment of the present application, the method comprising:

[0044] S101: Obtaining system events in the battery management system;

[0045] S102: reading the event stream of the system event, uploading the event stream and the state information of the current state machine to the user behavior signature library, and obtaining the user behavior recognition result;

[0046] S103: If the user behavior identification result is a valid behavior, match the security policy of the system event corresponding to the user behavior, and apply the security policy according to the enabling state of the security policy, so as to execute the user behavior when the security policy takes effect.

[0047] First, the system events in the battery management system are detected. The specific type and content of the system events are not limited here. Common system events include network port on / off, button pressing, touch screen clicking and input, etc.

[0048] From the perspective of event types, it can include battery status related events, communication related events, protection and alarm events, system operation and control events, system maintenance and diagnosis events, etc. For example, communication related events may include communication interruption, that is, communication interruption between BMS and external devices (such as vehicle control unit, energy storage system dispatching system, etc.). It can also include communication errors, that is, communication data errors or protocol mismatches. It should be noted that the system events described in this application are mainly aimed at system events that include user operations or system events that may be triggered by user operations, in order to manage user behaviors constituted by user operations.

[0049] Before executing step S102, it is necessary to deploy the state machine in the battery management system. In a feasible implementation, a finite state machine or a hierarchical state machine can be used to define a transfer table based on business scenario modeling, so that the transfer table can be searched according to the system event to obtain the state information of the current state machine. By defining a state transition table, the state changes of the system triggered by different events can be clearly described, thereby achieving accurate management and control of the system state. First, all possible states and events of the system need to be clarified. Taking the battery management system as an example, the following states and events can be defined:

[0050] Initial state: The default state when the system starts.

[0051] Normal Operation: The system operates normally.

[0052] Overvoltage Protection: The state entered after an overvoltage event is detected.

[0053] Undervoltage Protection: The state entered after an undervoltage event is detected.

[0054] Overcurrent Protection: The state entered after an overcurrent event is detected.

[0055] Overtemperature Protection: The state entered after an overtemperature event is detected.

[0056] Fault state: The state entered after other serious faults are detected.

[0057] Maintenance status: The status when maintenance is required.

[0058] The transition table is a two-dimensional table used to describe the rules for the battery management system to transition from one state to another when triggered by different events.

[0059] If the battery management system is complex, a hierarchical state machine (HSM) can be used to further simplify state management. HSM reduces the number of states and the complexity of the transfer logic by layering the states and allowing state inheritance and nesting. For example, a protection state (such as overvoltage, undervoltage, overcurrent, and overtemperature) can be defined as a parent state, and each specific protection state can be defined as a child state.

[0060] After that, the event stream of the system event is read. The user operation can be captured as the event stream of the system event. The user operation includes at least one of a user click operation, a user slide operation and sensor data, and the event stream includes an event operation sequence and an operation interval. Thus, the event stream and the state information of the current state machine are uploaded to the user behavior signature library as input data to be matched.

[0061] In the user behavior signature library, the matching process can be as follows:

[0062] Step 1: In the user behavior signature library, the behavior rule discrimination table is called to detect whether the user operations contained in the event flow are all legal operations; if so, proceed to step 2;

[0063] The second step is to detect whether there is a matching target user behavior in the operation interval or operation sequence of the user operation; if there is a matching target user behavior, confirm that the user behavior identification result is a valid behavior; if there is no matching target user behavior, confirm that the user behavior identification result is an invalid behavior.

[0064] If there are illegal operations performed by the user, an alarm system can be responded to, indicating that a malicious attacker may break through the physical limitations and perform illegal operations on the battery management system that are not recorded in the user behavior signature library.

[0065] In addition, in a feasible implementation, if the user behavior recognition result is a valid behavior, the user behavior and the system event can be written into the database as a behavior association event. The database is used to record the association between user behavior and system events. By recording the association between user behavior and system events, the user behavior can be quickly matched in the subsequent behavior management process, and the system event can be matched with the corresponding user behavior that has occurred, or the triggered user behavior can be sorted by frequency, so as to give priority to matching the user behavior with a higher triggering frequency, thereby improving the matching efficiency of the user behavior signature library for user behavior.

[0066] In addition, due to the high risk in the actual application scenarios of battery management systems, most of them rely on high-voltage isolation circuits and on-site practical training. However, if the training is insufficient or the operation and maintenance personnel are not familiar with it, improper operation or high-risk operations may occur, which may pose a high safety hazard. Therefore, in this embodiment, if the user behavior recognition result is a valid behavior, it can be determined whether the valid behavior poses a safety risk. If there is a safety risk, a security policy containing a safety protection action or a safety range threshold can be matched, and the enable state of the security policy can be set; and user behavior is allowed to execute only when the enable state is valid.

[0067] At the same time, when matching the security policy, you can also set the alarm operation included in the security policy, and execute the alarm operation when the user operation is abnormal or exceeds the security range threshold.

[0068] In order to ensure the security of user behavior, that is, the personal safety of operation and maintenance personnel, security protection actions or security range thresholds can be set through security policies, so that when user behavior is effective, the security risks of user behavior can be managed and controlled, including but not limited to the use of prompts or alarms. For example, when there is a high risk of user behavior, corresponding behavior prompts or alarms can be generated, thereby improving the safety of user behavior.

[0069] In order to ensure the effectiveness of the security policy, an enabling state is further added to the security policy to ensure that user behavior can be applied to the battery management system only when the security policy is in effect.

[0070] In other words, when the present application detects user behavior, it first determines whether the user behavior is a valid behavior through the user behavior signature library. If the recognition result is a valid behavior, it is further determined whether the behavior poses a safety risk. For example, the current battery status (such as voltage, current, temperature, etc.) and the preset safety threshold can be combined to assess whether there is a safety risk. Safety risk assessment includes but is not limited to potential dangers such as overvoltage, undervoltage, overcurrent, and overtemperature. If the assessment results show that there is a safety risk, the battery management system will match a safety policy that includes a safety protection action or a safety range threshold. For example, when an overvoltage risk is detected, the matching safety policy may include cutting off the charging circuit, sounding an alarm, and so on.

[0071] Before executing a user action, the battery management system checks the enablement status of the corresponding security policy. The user action is allowed only when the enablement status is valid. If the enablement status is valid, the battery management system will execute the user action and continuously monitor the battery status to ensure safety. If a new security risk is detected during the execution process, the battery management system will immediately trigger the corresponding protection action.

[0072] An exemplary user behavior operation process may be as follows:

[0073] The first step is that the user requests a charging operation.

[0074] The second step is that BMS recognizes the behavior as a valid behavior.

[0075] Step 3: BMS evaluates that the current battery voltage is close to the maximum charging voltage and there is a risk of overvoltage.

[0076] Step 4: Match the safety strategy: cut off the charging circuit before the voltage reaches the threshold.

[0077] Step 5: Set the security policy enable status to valid.

[0078] Step 6. After checking that the enable status is valid, start the charging operation.

[0079] Step 7. During the charging process, monitor the battery status in real time to ensure safety.

[0080] Another exemplary safety strategy can be: after the BAU (Battery Array Unit) of the energy storage system confirms that the user behavior is the user behavior of the operation and maintenance personnel, it will perform insulation detection and voltage detection. When the insulation resistance value is in the first range, the BAU controls the energy storage cabinet to shut down part of the voltage output, reduce the voltage and insulation, and shut down the energy storage cabinet output when the detected insulation resistance value is lower than the second range to protect personal safety. The safety setting value of the insulation detection here is lower than the setting value when no one enters, that is, two sets of safety range values.

[0081] When a system event in the battery management system is detected, the embodiment of the present application reads the event stream and uploads it to the user behavior signature library in combination with the current state information, and identifies the user behavior in the user behavior signature library to determine whether the user behavior is valid. If the user behavior is invalid, the user behavior can be rejected, so that the malicious attacker cannot implement effective attack behavior after breaking through the physical security restrictions. If the user behavior is valid, the security of the user behavior during execution can be guaranteed by matching the security policy.

[0082] See also Figure 2 , Figure 2A schematic diagram of a behavior management process of a battery management system provided in an embodiment of the present application, Figure 2 The following modules are used to perform behavior management: event detection module, user behavior identification module, security policy management module, log recording module, alarm module, security protection module, audit and labeling module to achieve behavior management of the battery management system. Figure 2 The modular design enables the battery management system to be flexibly adjusted according to different application scenarios and requirements. It also makes it easier to upgrade and expand the behavior management of the battery management system. The following is a description of each module:

[0083] Event detection module: responsible for detecting various events of the system, including network port connection and disconnection, button pressing and releasing, touch screen click and input, etc., and sending these detected events to the user behavior recognition module.

[0084] User behavior identification module: obtains the event stream from the event detection module, establishes and maintains a state machine inside the module, sends the current state and events to the user behavior signature library, obtains the user's behavior results, and if the identified user operation is a valid behavior, sends the behavior to the security policy management module.

[0085] Security policy management module: matches the corresponding policy according to the input user behavior, and decides whether to execute the policy according to the policy's enablement status. The policy behaviors include: writing logs, issuing alarms, executing protection actions, etc.

[0086] Logging module: writes user behavior and related system events into the database.

[0087] Alarm module: calls specific alarm functions (such as sirens, sending short messages (Short Message Service, SMS), calling security numbers, etc.).

[0088] Safety protection module: If the user's behavior may involve personal safety, take safety protection actions (such as shutting down, spraying, etc.).

[0089] Audit and labeling module: The audit administrator determines the recognition accuracy of user behavior, labels the user behavior, and inputs the qualified user behavior and its labeling data into the behavior signature database to improve the subsequent recognition accuracy of user behavior.

[0090] Figure 3 This is a flowchart of a user behavior identification process provided in an embodiment of the present application, which can define multiple user behaviors. Taking "reset password user behavior identification" as an example, the identification process is as follows:

[0091] The user quickly plugs and unplugs the network port multiple times (for example, 10 times);

[0092] The software program monitors the user's plug-in and unplug events. When the interval and number of plug-in and unplug operations reach the threshold, the factory reset operation is performed. Judgment conditions: the number of plug-in and unplug operations of the network port and the time interval between two plug-ins. For example: if it is required to plug and unplug 10 times continuously and the time interval between two consecutive plug-ins does not exceed 1 second, if the number of plug-ins is greater than or equal to 10 times, the factory reset operation can be performed.

[0093] It can be seen that user behaviors and corresponding execution programs can be customized in advance by those skilled in the art.

[0094] The behavior management system of the battery management system provided in the embodiment of the present application is introduced below. The behavior management system of the battery management system described below and the behavior management method of the battery management system described above can be referenced to each other.

[0095] See also Figure 4 , Figure 4 This is a schematic diagram of the structure of a behavior management system of a battery management system provided in an embodiment of the present application. The present application also provides a behavior management system of a battery management system, including:

[0096] An event acquisition module, used to acquire system events in the battery management system;

[0097] A user behavior identification module is used to read the event stream of the system event, upload the event stream and the state information of the current state machine to the user behavior signature library, and obtain the user behavior identification result;

[0098] The user behavior management module is used to match the security policy of the system event corresponding to the user behavior if the user behavior identification result is a valid behavior, and apply the security policy according to the enablement status of the security policy so as to execute the user behavior when the security policy takes effect.

[0099] Based on the above embodiments, as a preferred embodiment, it also includes:

[0100] The state machine deployment module is used to define a transfer table according to business scenario modeling using a finite state machine or a hierarchical state machine; search the transfer table according to the system event to obtain state information of the current state machine.

[0101] Based on the above embodiment, as a preferred embodiment, the user behavior identification module includes:

[0102] An event capture unit, used to capture user operations as an event stream of the system events; the user operations include at least one of user click operations, user slide operations and sensor data; the event stream includes an event operation sequence and an operation interval;

[0103] The data uploading unit is used to upload the event stream and the state information of the current state machine as input data to be matched to the user behavior signature library.

[0104] Based on the above embodiments, as a preferred embodiment, it also includes:

[0105] The recording module is used to write the user behavior and the system event into a database as a behavior-related event if the user behavior recognition result is a valid behavior; the database is used to record the association relationship between the user behavior and the system event.

[0106] Based on the above embodiment, as a preferred embodiment, the user behavior signature library includes:

[0107] The user behavior matching module is used to perform the following steps:

[0108] In the user behavior signature library, a behavior rule discrimination table is called to detect whether the user operations included in the event flow are all legal operations;

[0109] If so, detecting whether there is a matching target user behavior between the operation interval or the operation sequence of the user operation;

[0110] If there is a matching target user behavior, confirm that the user behavior recognition result is a valid behavior;

[0111] If there is no matching target user behavior, the user behavior identification result is confirmed to be an invalid behavior.

[0112] Based on the above embodiment, as a preferred embodiment, the user behavior management module includes:

[0113] The policy matching module is used to determine whether the valid behavior poses a security risk if the user behavior identification result is a valid behavior; if so, match the security policy containing the security protection action or the security range threshold, and set the enable state of the security policy; and only allow the user behavior to be executed when the enable state is valid.

[0114] Based on the above embodiment, as a preferred embodiment, the strategy matching module further includes:

[0115] The alarm unit is used to set the alarm operation included in the security policy and execute the alarm operation when the user operation is abnormal or exceeds the safety range threshold.

[0116] The present application also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed, the steps provided in the above embodiment can be implemented. The storage medium may include: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.

[0117] The present application also provides an electronic device, see Figure 5 , a structural diagram of an electronic device provided in an embodiment of the present application, such as Figure 5 As shown, a processor 1410 and a memory 1420 may be included.

[0118] Among them, the processor 1410 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 1410 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 1410 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 1410 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 1410 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0119] The memory 1420 may include one or more computer-readable storage media, which may be non-transitory. The memory 1420 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 1420 is at least used to store the following computer program 1421, wherein, after the computer program is loaded and executed by the processor 1410, it can implement the relevant steps in the method performed by the electronic device side disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory 1420 may also include an operating system 1422 and data 1423, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 1422 may include Windows, Linux, Android, etc.

[0120] In some embodiments, the electronic device may further include a display screen 1430 , an input / output interface 1440 , a communication interface 1450 , a sensor 1460 , a power source 1470 , and a communication bus 1480 .

[0121] certainly, Figure 5 The structure of the electronic device shown does not constitute a limitation on the electronic device in the embodiments of the present application. In actual applications, the electronic device may include Figure 5 More or fewer components than shown, or combinations of certain components.

[0122] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other. For the system provided in the embodiment, since it corresponds to the method provided in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description.

[0123] Specific examples are used herein to illustrate the principles and implementation methods of the present application, and the description of the above embodiments is only used to help understand the method and core ideas of the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the present application.

[0124] It should also be noted that, in this specification, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.

Claims

1. A behavior management method for a battery management system, characterized in that: include: Get system events in the battery management system; Read the event stream of the system event, upload the event stream and the state information of the current state machine to the user behavior signature library, and obtain the user behavior recognition result; If the user behavior identification result is a valid behavior, the security policy corresponding to the system event is matched, and the security policy is applied according to the enabling state of the security policy, so as to execute the user behavior when the security policy takes effect.

2. The behavior management method of a battery management system according to claim 1, characterized in that: Reading the event stream of the system event, uploading the event stream and the state information of the current state machine to the user behavior signature library, and obtaining the user behavior recognition result, further comprising: Use finite state machines or hierarchical state machines to define transition tables based on business scenario modeling; The transfer table is searched according to the system event to obtain the state information of the current state machine.

3. The behavior management method of the battery management system according to claim 2, characterized in that: Reading the event stream of the system event and uploading the event stream and the state information of the current state machine to the user behavior signature library includes: Capturing user operations as event streams of the system events; the user operations include at least one of user click operations, user slide operations, and sensor data; the event stream includes an event operation sequence and an operation interval; The event stream and the state information of the current state machine are uploaded to the user behavior signature library as input data to be matched.

4. The behavior management method of a battery management system according to claim 1, characterized in that: If the user behavior identification result is a valid behavior, it also includes: The user behavior and the system event are written into a database as behavior association events; the database is used to record the association relationship between the user behavior and the system event.

5. The behavior management method of a battery management system according to claim 1, characterized in that: The process of generating user behavior recognition results includes: In the user behavior signature library, a behavior rule discrimination table is called to detect whether the user operations included in the event flow are all legal operations; If so, detecting whether there is a matching target user behavior between the operation interval or the operation sequence of the user operation; If there is a matching target user behavior, confirm that the user behavior recognition result is a valid behavior; If there is no matching target user behavior, the user behavior identification result is confirmed to be an invalid behavior.

6. The behavior management method of a battery management system according to claim 1, characterized in that: If the user behavior identification result is a valid behavior, matching the security policy of the system event corresponding to the user behavior, and executing the security policy according to the enabling state of the security policy includes: If the user behavior identification result is a valid behavior, determine whether the valid behavior has a security risk; If so, match the security policy including the security protection action or the security range threshold, and set the enable state of the security policy; and only when the enable state is valid, allow the user behavior to be executed.

7. The behavior management method of a battery management system according to claim 6, characterized in that: When matching the security policy of the user behavior corresponding to the system event, it also includes: The alarm operation included in the security policy is set, and the alarm operation is executed when the user operation is abnormal or exceeds the security range threshold.

8. A behavior management system for a battery management system, characterized in that: include: An event acquisition module, used to acquire system events in the battery management system; A user behavior identification module is used to read the event stream of the system event, upload the event stream and the state information of the current state machine to the user behavior signature library, and obtain the user behavior identification result; The user behavior management module is used to match the security policy of the system event corresponding to the user behavior if the user behavior identification result is a valid behavior, and apply the security policy according to the enablement status of the security policy so as to execute the user behavior when the security policy takes effect.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. An electronic device, characterized in that: The method comprises a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the method according to any one of claims 1 to 7 are implemented.