Method, system and device for establishing secure communication of wireless BMS (Battery Management System)
By verifying the access request of the host computer in the wireless BMS and generating random number seeds, ensuring the consistency between the first key and the second key, the problem of insufficient communication security and attack resistance of traditional wireless BMS is solved, and higher security and communication reliability are achieved.
Patent Information
- Application Number
- CN202510131855.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-05
- Publication Date
- 2025-05-30
AI Technical Summary
Traditional wireless BMS communications have security threats, such as data leakage, tampering and replay attacks, and the key generation algorithm has a high security risk when facing attacks such as brute force cracking and circular collisions.
By verifying the access request of the host computer in the wireless BMS, a random number seed is generated and shared with the host computer, a first key and a second key are generated based on the seed, and the consistency of the two is judged to determine the communication security.
Improve the security and attack resistance of wireless BMS communication, ensure the dynamicity and consistency of keys through multiple security mechanisms, and prevent illegal access and data tampering.
Smart Images

Figure CN120075796A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of wireless battery management, and particularly to a method, system and device for establishing secure communication of a wireless BMS. Background Art
[0002] With the rapid development of electric vehicles and energy storage systems, wireless BMS (Battery Management System) has gradually become the core technology of the new generation of battery management systems. The host computer can achieve battery management by wirelessly communicating with the wireless BMS and sending control instructions to the wireless BMS. However, traditional communication methods make data face security threats such as leakage, tampering and replay attacks. Therefore, when the host computer establishes wireless communication with the wireless BMS, key verification is required to prevent data from facing security threats such as leakage, tampering and replay attacks.
[0003] However, traditional key generation algorithms have certain limitations in the face of access request mechanisms and security key management, and fail to adjust corresponding strategies according to actual threats. Especially in the face of attack means such as brute force cracking and cyclic collision, it shows a relatively high security risk. Since the wireless BMS does not effectively limit the number and frequency of access requests, attackers can repeatedly send requests to continuously obtain the seed key, thereby greatly increasing the success rate of cracking the key. Once the key is successfully cracked, the attacker can access the wireless BMS, and then mount unauthenticated third-party software or malicious applications on the wireless BMS to tamper with the data of the wireless BMS, or even remotely attack the wireless BMS. This causes problems such as poor security and anti-attack ability of the wireless BMS communication.
[0004] Therefore, there is still an urgent need for a secure communication establishment method that can improve the security and anti-attack ability of wireless BMS communication. Summary of the Invention
[0005] The main object of the present invention is to propose a method, system and device for establishing secure communication of a wireless BMS, so as to solve the problem of poor security and anti-attack ability of the existing defective wireless BMS communication.
[0006] To achieve the above object, the present invention proposes a method for establishing secure communication of a wireless BMS, and the method for establishing secure communication of the wireless BMS includes:
[0007] Receiving an access request sent by a host computer, and determining whether the access request passes verification;
[0008] If the access request passes verification, generating a random number seed and sending the random number seed to the host computer;
[0009] Generate a first key according to the random number seed, and receive a second key generated by the host computer according to the random number seed;
[0010] Determining whether the first key is consistent with the second key;
[0011] If the first key is consistent with the second key, secure communication is established with the host computer.
[0012] In some embodiments, determining whether the access request is verified includes:
[0013] Determine, according to the access request, a current access number corresponding to the access request;
[0014] Compare the current access count with a preset maximum access count, wherein the preset maximum access count is greater than zero;
[0015] If the current access number is less than or equal to the preset maximum access number, determining that the access request passes the verification;
[0016] If the current access number is greater than the preset maximum access number, it is determined that the access request has not passed the verification.
[0017] In some embodiments, after determining whether the access request passes the verification, the method further includes:
[0018] If the access request fails the verification, the access request is rejected, an access failure instruction is generated, and the access failure instruction is sent to the host computer.
[0019] In some embodiments, after determining whether the access request passes the verification, the method further includes:
[0020] If the access request fails to pass the verification, the lock mode is activated, the access request is rejected, and the lock time is recorded;
[0021] Determine the locking duration according to the locking time, and judge whether the locking duration is greater than a preset duration;
[0022] If the locking time is longer than the preset time, the locking mode is released, the access request sent by the host computer is received, the current access times corresponding to the access request is set to zero, and a step of verifying whether the access request passes the verification is performed.
[0023] In some embodiments, after determining whether the access request passes the verification, the method further includes:
[0024] If the access request fails to pass the verification, the lock mode is activated, the access request is rejected, and the unlocking mode is entered;
[0025] Receiving an unlock request sent by the host computer, wherein the unlock request includes a request to release the lock mode and identity information of the host computer;
[0026] Verifying the identity information of the host computer;
[0027] If the identity information of the host computer passes the verification, the locking mode is released, the access request sent by the host computer is received, the current access times corresponding to the access request is set to zero, and the step of verifying whether the access request passes the verification is executed.
[0028] In some embodiments, generating a random number seed includes:
[0029] Generate a random number and obtain multiple factors, wherein the multiple factors include a timestamp and a unique identifier;
[0030] The random number seed is generated according to the random number and the multivariate factors.
[0031] In some embodiments, generating the first key according to the random number seed includes:
[0032] Dividing the random number seed to obtain multiple sub-seeds;
[0033] Perform encryption operations on the multiple sub-seeds respectively to obtain multiple sub-keys;
[0034] The first key is generated according to a plurality of the subkeys.
[0035] In some embodiments, after determining whether the first key is consistent with the second key, the method further includes:
[0036] If the first key is inconsistent with the second key, the secure communication with the host computer is refused.
[0037] The present invention also proposes a safety communication establishment system for a wireless BMS, the safety communication establishment system for the wireless BMS comprising a wireless BMS and a host computer; the safety communication establishment system for the wireless BMS can execute any of the safety communication establishment methods for the wireless BMS described above.
[0038] The present invention also proposes a device for establishing secure communication of a wireless BMS, comprising:
[0039] at least one processor; and,
[0040] a memory communicatively connected to the at least one processor; wherein,
[0041] The memory stores instructions to be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method for establishing secure communication of the wireless BMS described in any one of the above.
[0042] In the present invention, the wireless BMS first verifies the access request of the host computer. When the access request passes the verification, the wireless BMS generates a random number seed and sends the random number seed to the host computer. The wireless BMS generates a first key according to the random number seed, and the host computer generates a second key according to the random number seed, and then determines whether the first key is consistent with the second key. When they are consistent, the wireless BMS establishes secure communication with the host computer. Through multiple security mechanisms such as access verification, random number seed generation, and key judgment, the wireless BMS generates a new key when the access request passes the verification and uses the new key for secondary verification, thereby improving the security and anti-attack ability of the wireless BMS communication. Description of the Drawings
[0043] Figure 1 It is a schematic flowchart of the method for establishing secure communication of the wireless BMS in an embodiment of the present invention;
[0044] Figure 2 It is another schematic flowchart of the method for establishing secure communication of the wireless BMS in an embodiment of the present invention;
[0045] Figure 3 It is another schematic flowchart of the method for establishing secure communication of the wireless BMS in an embodiment of the present invention;
[0046] Figure 4 It is another schematic flowchart of the method for establishing secure communication of the wireless BMS in an embodiment of the present invention;
[0047] Figure 5 It is another schematic flowchart of the method for establishing secure communication of the wireless BMS in an embodiment of the present invention;
[0048] Figure 6 It is another schematic flowchart of the method for establishing secure communication of the wireless BMS in an embodiment of the present invention;
[0049] Figure 7 It is a schematic structural diagram of the system for establishing secure communication of the wireless BMS involved in the embodiment solution of the present invention;
[0050] Figure 8 It is a schematic structural diagram of the device for establishing secure communication of the wireless BMS involved in the embodiment solution of the present invention.
[0051] The realization, functional features and advantages of the object of the present invention will be further described in conjunction with the embodiments with reference to the drawings. Detailed implementation manners
[0052] Next, the solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.
[0053] It should be noted that all directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indications will also change accordingly.
[0054] It should also be noted that when an element is referred to as "fixed to" or "disposed on" another element, it can be directly on the other element or there may be an intermediate element at the same time. When an element is referred to as "connected" to another element, it can be directly connected to the other element or there may be an intermediate element at the same time.
[0055] In addition, the descriptions involving "first", "second", etc. in the present invention are only for descriptive purposes, and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions results in contradictions or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.
[0056] To achieve the above object, the present invention proposes a method for establishing secure communication of a wireless BMS. The method for establishing secure communication of a wireless BMS includes:
[0057] Step S110: Receive an access request sent by the host computer and determine whether the access request passes verification;
[0058] Step S120: If the access request passes verification, generate a random number seed and send the random number seed to the host computer;
[0059] Step S130: Generate a first key according to the random number seed and receive a second key generated by the host computer according to the random number seed;
[0060] Step S140: Determine whether the first key is the same as the second key;
[0061] Step S150: If the first key is the same as the second key, establish a secure communication with the host computer.
[0062] In this embodiment, with reference to Figure 1 and Figure 7 , the method for establishing secure communication of the wireless BMS is applied to the system for establishing secure communication of the wireless BMS; the system for establishing secure communication of the wireless BMS is used to establish secure communication with the host computer, thereby improving the security and anti-attack ability of the wireless BMS communication. The system for establishing secure communication of the wireless BMS includes a wireless BMS and a host computer. The wireless BMS can be used to manage the battery or manage the battery according to the information sent by the host computer; the host computer can be used to send information for managing the battery to the wireless BMS. For the wireless BMS to receive the information sent by the host computer, it needs to establish communication with the host computer first. In order to ensure the security and anti-attack ability of the wireless BMS communication, in this embodiment, the wireless BMS will establish secure communication with the host computer. The execution subject of the method steps in this embodiment is the wireless BMS.
[0063] It can be understood that the same key generation algorithm is stored in both the wireless BMS and the host computer. When the random number seeds are the same, it is ensured that the keys generated by the wireless BMS and the host computer are the same.
[0064] When the user wants to access the wireless BMS through the host computer, the user can send an access request to the wireless BMS through the host computer. At this time, the wireless BMS can receive the access request sent by the host computer. After receiving the access request, the wireless BMS will verify the access request to determine whether the access request passes the verification.
[0065] If the access request passes the verification, the wireless BMS will generate a random number seed. Among them, the wireless BMS can be configured with a hardware random number generator or installed with a software random number generation module. The wireless BMS can generate a random number through the random number generator or the random number generation module, and then the wireless BMS generates a random number seed according to the random number and in combination with multiple factors. Among them, the multiple factors can include information such as time and the current state of the wireless BMS, etc., so as to ensure the dynamicity and uniqueness of the random number seed. After generating the random number seed, the wireless BMS will save a copy and at the same time send the random number seed to the host computer.
[0066] After the wireless BMS sends the random number seed to the host computer, the wireless BMS will use the key generation algorithm to operate on the random number seed to obtain the first key. At the same time, after receiving the random number seed, the host computer will also use the key generation algorithm to operate on the random number seed to obtain the second key; after the host computer obtains the second key, it will send the second key to the wireless BMS. At this time, the wireless BMS can receive the second key generated by the host computer according to the random number seed.
[0067] After the wireless BMS obtains the first key and the second key, it can judge the first key and the second key to determine whether the first key is consistent with the second key. The wireless BMS will establish a secure communication with the host computer only when it is determined that the first key is consistent with the second key. At this time, the wireless BMS will accept the access of the host computer, and at the same time, the wireless BMS will monitor the access behavior of the host computer and record the access log of the host computer.
[0068] If the wireless BMS determines that the first key is not consistent with the second key, it can be indicated that the second key does not come from a legitimate host computer. Because the legitimate host computer is configured with the same key generation algorithm as the wireless BMS, the key generated by the synthesized host computer and the key generated by the wireless BMS should be consistent. Therefore, when the wireless BMS determines that the first key is not consistent with the second key, the second key may come from an illegal host computer; the illegal host computer intercepts the random number seed by illegal means and then obtains the second key according to its own algorithm. At this time, the second key is not consistent with the first key; at this time, the wireless BMS will not establish a secure communication with the host computer. Among them, the legitimate host computer refers to the host computer that stores the identity information in the wireless BMS; the illegal host computer refers to the host computer that does not store the identity information in the wireless BMS. Only the legitimate host computer is configured with the same key generation algorithm as the wireless BMS. Therefore, the illegal host computer intercepts the random number seed by illegal means and cannot obtain the second key that is consistent with the first key according to the random number seed. Thus, the security and anti-attack ability of the wireless BMS communication are improved.
[0069] In this embodiment, the wireless BMS first verifies the access request of the host computer. When the access request passes the verification, the wireless BMS generates a random number seed and then sends the random number seed to the host computer; the wireless BMS generates the first key according to the random number seed, and the host computer generates the second key according to the random number seed, and then judges whether the first key is consistent with the second key; in the case of consistency, the wireless BMS establishes a secure communication with the host computer; through multiple security mechanisms of access verification, random number seed generation and key judgment, the wireless BMS generates a new key when the access request passes the verification and uses the new key for secondary verification, thereby improving the security and anti-attack ability of the wireless BMS communication.
[0070] In some embodiments, determining whether the access request passes verification as described above includes:
[0071] Step S160, determining the current access count corresponding to the access request according to the access request;
[0072] Step S161, comparing the current access count with a preset maximum access count, where the preset maximum access count is greater than zero;
[0073] Step S162, if the current access count is less than or equal to the preset maximum access count, determining that the access request passes verification;
[0074] Step S163, if the current access count is greater than the preset maximum access count, determining that the access request fails verification.
[0075] In this embodiment, referring to Figure 2 , when the wireless BMS executes step S110, it verifies the current access count. It can be understood that an illegal host computer, in order to crack the key generation algorithm, will send access requests multiple times and obtain random number seeds multiple times to increase the success rate of cracking the key generation algorithm. Through this embodiment, verifying the current access count can prevent the illegal host computer from obtaining random number seeds multiple times. By verifying the current access count, the number of times the host computer obtains random number seeds can be restricted.
[0076] The current access count corresponding to the access request can be determined according to the access request; among them, before the wireless BMS establishes a secure communication with the host computer and accepts the access of the host computer; each time the host computer sends an access request, the current access count corresponding to the access request will be incremented by one. Specifically, in this embodiment, the current access count corresponding to the access request initially sent by the host computer is the zeroth time. The wireless BMS can determine the current access count according to the number of received access requests.
[0077] The wireless BMS stores a preset maximum access count; among them, the preset maximum access count is greater than zero, and the preset maximum access count can be determined according to requirements. After the wireless BMS obtains the current access count, it will compare the current access count with the preset maximum access count to determine the size relationship between the current access count and the preset maximum access count.
[0078] If the current access count is less than or equal to the preset maximum access count, the wireless BMS will determine that the access request passes the verification, and at this time, the current access count corresponding to the access request is incremented by one (wherein, when the wireless BMS establishes secure communication with the host computer, the current access count corresponding to the access request is set to zero). If the current access count is greater than the preset maximum access count, the wireless BMS will determine that the access request fails the verification.
[0079] Because when the access request passes the verification, the host computer can obtain the random number seed; therefore, in this embodiment, the wireless BMS verifies the current access count. When the current access count is greater than the preset maximum access count, the access request cannot pass the verification, thereby restricting the number of times the host computer obtains the random number seed.
[0080] In some embodiments, after determining whether the access request passes the verification as described above, it further includes:
[0081] If the access request fails the verification, reject the access request, generate an access failure instruction, and send the access failure instruction to the host computer.
[0082] In this embodiment, after the wireless BMS executes step S110, if the access request fails the verification, it will reject the access of the host computer. If the wireless BMS determines that the access request fails the verification (the current access count is greater than the preset maximum access count), it will reject the access request, thereby rejecting the access of the host computer; at the same time, it will generate an access failure instruction and send the access failure instruction to the host computer; to inform the host computer that the access fails, thereby restricting the number of times the host computer obtains the random number seed.
[0083] When the host computer sends access requests continuously for multiple times and fails to establish secure communication with the wireless BMS successfully for multiple times; once the current access count corresponding to the access request is greater than the preset maximum access count, there is reason to suspect that the host computer is not a legitimate host computer; at this time, the wireless BMS will reject the access request (here, rejecting the access request can also be rejecting any information from this host computer), generate an access failure instruction, and send the access failure instruction to the host computer to inform the host computer that the access fails.
[0084] In some embodiments, after determining whether the access request passes the verification as described above, it further includes:
[0085] Step S170, if the access request fails the verification, start the locking mode, reject the access request, and record the locking time;
[0086] Step S171, determine the locking duration according to the locking time, and judge whether the locking duration is greater than the preset duration;
[0087] Step S172, if the locking time is longer than the preset time, the locking mode is released, an access request sent by the host computer is received, the current access times corresponding to the access request is set to zero, and a step of verifying whether the access request passes the verification is executed.
[0088] In this embodiment, refer to Figure 3 After the wireless BMS executes step S110, if the access request fails to pass the verification, it will take some time before receiving the access request again. In order to ensure the security of communication and anti-attack capability, the wireless BMS will refuse to receive the access request if it receives too many access requests within a certain period of time, and will receive it again after a period of time. If the wireless BMS determines that the access request fails to pass the verification (the current access count is greater than the preset maximum access count), it will start the lock mode, refuse to receive the access request, and record the lock time.
[0089] The wireless BMS stores a preset duration, which can be set according to actual usage requirements; at the same time, the preset duration can also be set in a gradient, and each time the wireless BMS starts the lock mode, the preset duration increases by a gradient. For example: when the wireless BMS starts the lock mode for the first time, the preset duration can be 10 seconds; when the wireless BMS starts the lock mode for the second time, the preset duration can be 20 seconds; when the wireless BMS starts the lock mode for the third time, the preset duration can be 30 seconds, and so on. Of course, the preset duration can also be the same, no matter how many times the wireless BMS starts the lock mode, the value of each preset duration is the same. The wireless BMS determines the lock duration based on the recorded lock time, and then compares the lock duration with the preset duration to determine whether the lock duration is greater than the preset duration.
[0090] If the wireless BMS determines that the lock duration is greater than the preset duration, it will release the lock mode, receive the access request sent by the host computer, set the current access count corresponding to the access request to zero, and execute the step of verifying whether the access request is verified. Since the wireless BMS sets the current access count corresponding to the access request to zero, the access request sent by the host computer this time is considered to be the first access request sent; therefore, when the wireless BMS executes the step of verifying whether the access request is verified, the access request will definitely be verified, that is, the wireless BMS will continue to execute step S120 and the steps below step S120.
[0091] If the lock duration is less than or equal to the preset duration, the wireless BMS will wait for the lock duration to be greater than the preset duration. If the wireless BMS determines that the lock duration is less than or equal to the preset duration, the wireless BMS will be in a waiting state, and after the lock duration is greater than the preset duration, the unlocking mode will be executed.
[0092] In some embodiments, after determining whether the access request passes the verification in the foregoing, the method further includes:
[0093] Step S180, if the access request fails to pass the verification, the lock mode is activated, the access request is rejected, and the unlocking mode is entered;
[0094] Step S181, receiving an unlock request sent by a host computer, wherein the unlock request includes a request to release the lock mode and identity information of the host computer;
[0095] Step S182, verifying the identity information of the host computer;
[0096] Step S183, if the identity information of the host computer passes the verification, the lock mode is released, the access request sent by the host computer is received, the current access times corresponding to the access request is set to zero, and the step of verifying whether the access request passes the verification is executed.
[0097] In this embodiment, refer to Figure 4 , after the wireless BMS executes step S110, if the access request fails to pass the verification, it is necessary to verify the identity of the host computer before receiving the access request. In order to ensure the security and anti-attack capability of the communication, the wireless BMS will refuse to receive the access request when the number of access requests received is too many, and will verify the identity information of the host computer, and then receive the access request after the verification is passed. Among them, the wireless BMS can store the identity information of the legitimate host computer. If the wireless BMS determines that the access request fails to pass the verification (the current number of accesses is greater than the preset maximum number of accesses), it will start the lock mode, refuse to receive the access request, and enter the unlocking mode. At this time, the wireless BMS only refuses to receive the access request, but can also receive other requests, for example: receiving an unlocking request sent by the host computer. Among them, the unlocking request includes a request to release the lock mode and the identity information of the host computer.
[0098] In the unlocking mode, the wireless BMS will receive the unlocking request sent by the host computer. When the wireless BMS receives the unlocking request sent by the host computer, it will extract the identity information of the host computer from the unlocking request, and then verify the identity information of the host computer. Determine whether the identity information of the host computer is saved in the wireless BMS. If the identity information of the host computer is saved in the wireless BMS, it is determined that the identity information of the host computer has passed the verification. If the identity information of the host computer is not saved in the wireless BMS, it is determined that the identity information of the host computer has not passed the verification.
[0099] If the wireless BMS determines that the identity information of the host computer has been verified, it will release the lock mode, receive the access request sent by the host computer, set the current access count corresponding to the access request to zero, and execute the step of verifying whether the access request has been verified. Since the wireless BMS has set the current access count corresponding to the access request to zero, the access request sent by the host computer this time is considered to be the first access request sent; therefore, when the wireless BMS executes the step of verifying whether the access request has been verified, the access request will definitely be verified, that is, the wireless BMS will continue to execute step S120 and the steps below step S120.
[0100] If the identity information of the host computer fails to pass the verification, the access request sent by the host computer will be rejected. If the wireless BMS determines that the identity information of the host computer fails to pass the verification, the wireless BMS can determine that the host computer is an illegal host computer, and the wireless BMS will always refuse to receive access requests from the host computer, or the wireless BMS will always refuse to receive any information from the host computer.
[0101] In some embodiments, generating a random number seed in the foregoing includes:
[0102] Step S190, generating a random number and obtaining multiple factors, wherein the multiple factors include a timestamp and a unique identifier;
[0103] Step S191, generating a random number seed according to a random number and multiple factors.
[0104] In this embodiment, refer to Figure 5 When the wireless BMS executes step S120, it generates a random number seed based on the random number and multiple factors. The wireless BMS can be configured with a hardware random number generator, or a software random number generation module can be installed. The wireless BMS can generate random numbers through a random number generator or a random number generation module. The wireless BMS will also obtain multiple factors, where the multiple factors include timestamps and unique identifiers, etc. In this embodiment, the multiple factors are explained as timestamps and unique identifiers. The wireless BMS can obtain the current timestamp and its own unique identifier; then generate a random number seed based on the random number and multiple factors. Among them, the timestamp can ensure the dynamic nature of the random number seed, and the unique identifier can ensure the uniqueness of the random number seed.
[0105] In a preferred embodiment, a random number seed is generated based on a random number and multiple factors, including:
[0106]
[0107] Among them, Seed is the random number seed, GetRanDom is the random number generation function, H PUFis the unique identifier, H Time is the timestamp, is the exclusive OR (XOR) operator.
[0108] In some embodiments, generating the first key according to the random number seed as described above includes:
[0109] Step S200, dividing the random number seed to obtain multiple sub-seeds;
[0110] Step S201, performing encryption operations on the multiple sub-seeds respectively to obtain multiple sub-keys;
[0111] Step S202, generating the first key according to the multiple sub-keys.
[0112] In this embodiment, referring to Figure 6 , when the wireless BMS executes step S130, it divides the random number seed, then performs encryption operations, and then generates the first key. Among them, the generation method of the second key is the same as that of the first key. The key generation algorithm configured in the wireless BMS is also configured in the host computer. The wireless BMS first divides the random number seed to obtain multiple sub-seeds; then performs an encryption operation on each sub-seed to obtain multiple sub-keys; finally, combines the multiple sub-keys to obtain the first key.
[0113] In a preferred embodiment, dividing the random number seed to obtain multiple sub-seeds includes:
[0114] Seed = (Seed 1 , Seed 2 , Seed 3 ,..., Seed n )
[0115] where Seed is the random number seed, and Seed 1 to Seed n are multiple sub-seeds, 1 to n are the number of sub-seeds, and n is greater than 1 and is an integer.
[0116] In a preferred embodiment, performing encryption operations on the multiple sub-seeds respectively to obtain multiple sub-keys includes:
[0117] K i = ECC_256(Seed i )
[0118] where K i is the sub-key corresponding to any one of the sub-seeds from 1 to n (K i can be K 1 , K 2 , K 3 ,..., Kn any one of), Seed i is any one of the sub - seeds from 1 to n, and ECC_256 is an encryption algorithm (elliptic curve encryption algorithm based on 256 - bit).
[0119] In a preferred embodiment, generating a first key according to a plurality of sub - keys includes:
[0120] K complete = K 1 + K 2 + K 3 +...+ K n
[0121] wherein, K complete is the first key, and K 1 to K n are a plurality of sub - keys.
[0122] In some embodiments, after determining whether the first key and the second key are consistent as described above, it further includes:
[0123] If the first key and the second key are inconsistent, reject establishing a secure communication with the host computer.
[0124] In this embodiment, after the wireless BMS executes step S140, if the first key and the second key are inconsistent, the wireless BMS will reject establishing a secure communication with the host computer. If the wireless BMS determines that the first key and the second key are inconsistent, it can be indicated that the second key does not come from a legitimate host computer. Because a legitimate host computer is configured with the same key generation algorithm as the wireless BMS, the key generated by the synthesized host computer and the key generated by the wireless BMS should be consistent. Therefore, when the wireless BMS determines that the first key and the second key are inconsistent, the second key may come from an illegal host computer; the illegal host computer intercepts the random number seed by illegal means and then obtains the second key according to its own algorithm, and at this time the second key is inconsistent with the first key; at this time, the wireless BMS will not establish a secure communication with the host computer. Thus, the security and anti - attack ability of the wireless BMS communication are improved.
[0125] The present invention first verifies the access request from the host computer through the wireless BMS. When the access request passes the verification, the wireless BMS generates a random number seed and sends the random number seed to the host computer. The wireless BMS generates a first key based on the random number seed, and the host computer generates a second key based on the random number seed, and then determines whether the first key is the same as the second key. When they are the same, the wireless BMS establishes a secure communication with the host computer. Through multiple security mechanisms such as access verification, random number seed generation, and key judgment, the wireless BMS generates a new key when the access request passes the verification and uses the new key for secondary verification, thereby improving the security and anti-attack ability of the wireless BMS communication.
[0126] The present invention also proposes a secure communication establishment system for a wireless BMS. The secure communication establishment system for the wireless BMS includes a wireless BMS and a host computer. The secure communication establishment system for the wireless BMS can execute the secure communication establishment method for the wireless BMS described in any one of the above.
[0127] In this embodiment, referring to Figure 7 , the secure communication establishment system for the wireless BMS is used to establish secure communication with the host computer, thereby improving the security and anti-attack ability of the wireless BMS communication. The secure communication establishment system for the wireless BMS includes a wireless BMS and a host computer. The wireless BMS can be used to manage the battery or manage the battery according to the information sent by the host computer; the host computer can be used to send information for managing the battery to the wireless BMS.
[0128] The present invention also proposes a secure communication establishment device for a wireless BMS. Referring to Figure 8 , Figure 8 is a schematic structural diagram of the secure communication establishment device for the wireless BMS in the hardware operating environment involved in the embodiment solution of the present invention.
[0129] The secure communication establishment device for the wireless BMS in the embodiment of the present invention can be a processor capable of running the secure communication establishment method for the wireless BMS; there is at least one processor. As Figure 8As shown in the figure, the security communication establishment device of the wireless BMS may include: a processor 1001 (such as a CPU), a network interface 1004, a user interface 1003, a memory 1005, and a communication bus 1002. Among them, the communication bus 1002 is used to implement the connection and communication between these components. The user interface 1003 may include a display screen (Display) and an input unit, such as a keyboard (Keyboard). Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory or a stable memory (non-volatile memory), such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0130] Those skilled in the art can understand that Figure 8 the structure of the security communication establishment device of the wireless BMS shown in the figure does not constitute a limitation on the security communication establishment device of the wireless BMS, and may include more or fewer components than those shown, or combine certain components, or have different component arrangements.
[0131] As Figure 8 shown, the memory 1005, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a computer program.
[0132] In Figure 8 the security communication establishment device of the wireless BMS shown in the figure, the network interface 1004 is mainly used to connect to the background server and perform data communication with the background server; the user interface 1003 is mainly used to connect to the client (user side) and perform data communication with the client; and the processor 1001 may be used to call the computer program stored in the memory 1005, and when the computer program is called and executed by the processor 1001, the steps of the above-mentioned security communication establishment method of the wireless BMS are implemented.
[0133] Based on the computer program proposed in the foregoing embodiments, the present invention also proposes a storage medium that stores a computer program, and when the computer program is executed by a controller, the security communication establishment method recorded in the foregoing embodiments is implemented.
[0134] The present invention also proposes a storage medium that stores a computer program, and when the computer program is executed by a processor, the steps of the security communication establishment method of the wireless BMS according to any one of the above technical solutions are implemented.
[0135] The above are only some or preferred embodiments of the present invention. Neither the text nor the drawings can limit the scope of protection of the present invention. Any equivalent structural transformation made using the content of the specification and drawings of the present invention under the overall concept of the present invention, or any direct / indirect application in other related technical fields, is included in the scope of protection of the present invention.
Claims
1. A method for establishing secure communication of a wireless BMS, characterized in that: The method for establishing secure communication of the wireless BMS includes: Receive an access request sent by the host computer, and determine whether the access request is verified; If the access request passes the verification, a random number seed is generated and sent to the host computer; Generate a first key according to the random number seed, and receive a second key generated by the host computer according to the random number seed; Determining whether the first key is consistent with the second key; If the first key is consistent with the second key, secure communication is established with the host computer.
2. The method for establishing safe communication of a wireless BMS according to claim 1, characterized in that: The determining whether the access request passes the verification includes: Determine, according to the access request, a current access number corresponding to the access request; Compare the current access count with a preset maximum access count, wherein the preset maximum access count is greater than zero; If the current access number is less than or equal to the preset maximum access number, determining that the access request passes the verification; If the current access number is greater than the preset maximum access number, it is determined that the access request has not passed the verification.
3. The method for establishing safe communication of a wireless BMS according to claim 2, characterized in that: After determining whether the access request passes the verification, the method further includes: If the access request fails the verification, the access request is rejected, an access failure instruction is generated, and the access failure instruction is sent to the host computer.
4. The method for establishing secure communication of a wireless BMS according to claim 2, characterized in that: After determining whether the access request passes the verification, the method further includes: If the access request fails to pass the verification, the lock mode is activated to refuse to receive the access request and record the lock time; Determine the locking duration according to the locking time, and judge whether the locking duration is greater than a preset duration; If the locking time is longer than the preset time, the locking mode is released, the access request sent by the host computer is received, the current access times corresponding to the access request is set to zero, and a step of verifying whether the access request passes the verification is performed.
5. The method for establishing safe communication of a wireless BMS according to claim 2, characterized in that: After determining whether the access request passes the verification, the method further includes: If the access request fails to pass the verification, the lock mode is activated, the access request is rejected, and the unlocking mode is entered; Receiving an unlock request sent by the host computer, wherein the unlock request includes a request to release the lock mode and identity information of the host computer; Verifying the identity information of the host computer; If the identity information of the host computer passes the verification, the locking mode is released, the access request sent by the host computer is received, the current access times corresponding to the access request is set to zero, and the step of verifying whether the access request passes the verification is executed.
6. The method for establishing secure communication of a wireless BMS according to claim 1, characterized in that: The generating of random number seeds comprises: Generate a random number and obtain multiple factors, wherein the multiple factors include a timestamp and a unique identifier; The random number seed is generated according to the random number and the multivariate factors.
7. The method for establishing secure communication of a wireless BMS according to claim 1, characterized in that: The generating a first key according to the random number seed comprises: Dividing the random number seed to obtain multiple sub-seeds; Perform encryption operations on the multiple sub-seeds respectively to obtain multiple sub-keys; The first key is generated according to a plurality of the subkeys.
8. The method for establishing secure communication of a wireless BMS according to claim 1, characterized in that: After determining whether the first key is consistent with the second key, the method further includes: If the first key is inconsistent with the second key, the secure communication with the host computer is refused.
9. A wireless BMS secure communication establishment system, characterized in that: The safety communication establishment system of the wireless BMS includes a wireless BMS and a host computer; the safety communication establishment system of the wireless BMS can execute the safety communication establishment method of the wireless BMS according to any one of claims 1 to 8.
10. A device for establishing secure communication of a wireless BMS, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for establishing secure communication of the wireless BMS according to any one of claims 1 to 8.
Citation Information
Cited By
Secure communication establishment method, system and apparatus for wireless bms
WO2026166167A1