Battery data chain for multi-stage hybrid encryption of data battery

By integrating SM4 hardware encryption chip, transmission layer SM2 key negotiation and cloud SM3 hash verification in the battery management system, a multi-level hybrid encryption system is built, which solves the problems of complex key management and the risk of quantum attacks in battery data transmission, and achieves efficient and secure battery data transmission.

CN120301650APending Publication Date: 2025-07-11GUANGDONG HAOYIDIAN TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510464304.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

There are problems such as complex key management, risk of quantum attacks and insufficient end-to-end protection caused by a single encryption algorithm in the existing battery data transmission, especially in the cross-platform exchange scenario of battery health data, which cannot meet the national security compliance requirements and excessive hardware resource consumption.

Method used

The multi-level hybrid encryption scheme of data batteries is adopted, including integrating SM4 hardware encryption chips in the battery management system to encrypt the original data in real time; dynamic negotiation of session keys through the SM2 algorithm to establish a secure channel for the transmission layer; the cloud uses the SM3 algorithm to generate hash values to verify data integrity, and build a three-level combined encryption technology system for SM2/SM4/SM3.

Benefits of technology

It has achieved 40% improvement in lightweight national security compliance, anti-quantum attacks, and end-to-end encryption efficiency, and supports cross-vendor battery data security exchange to ensure the integrity and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301650A_ABST
    Figure CN120301650A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of battery data transmission encryption, and provides a data battery multi-stage hybrid encrypted battery data link, which comprises a battery management system, a transmission layer security channel and a cloud data processing layer, according to the battery management system, an SM4 hardware encryption chip is integrated at a battery BMS end, and original data such as voltage / temperature and the like are encrypted in real time; the transport layer secure channel dynamically negotiates a session key through an SM2 algorithm, and establishes a secure channel to transmit a ciphertext data packet; the cloud data processing layer generates a hash value for the received data by using SM3, and verifies the data integrity; preferably, the battery management system comprises a data acquisition module, an SM4 hardware encryption chip and an encrypted data packet packaging module. According to the invention, through the SM2 / SM4 / SM3 three-level combination encryption technology, light-weight national-security compliance is realized on the hardware layer, an anti-quantum attack channel is constructed on the transmission layer, the data is ensured to be complete and credible on the cloud layer, and a full-stack security protection system covering'end-management-cloud 'is formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of battery data transmission encryption, and specifically to a battery data chain with multi-level hybrid encryption for data batteries. Background Art

[0002] Battery data transmission usually involves transmitting information related to battery performance through various technologies and protocols, such as the voltage, temperature, remaining power, charging status, cycle count, etc. of the battery. Such data transmission is crucial for the battery management system (BMS), especially in electric vehicles (EVs) and mobile devices.

[0003] Battery data transmission encryption is an important technology to ensure that battery data is not accessed or tampered with by unauthorized third parties during the transmission process. Encryption technology can protect sensitive data in the battery management system (BMS), such as information about the battery's voltage, temperature, remaining power, etc., prevent data leakage or malicious modification, and thus ensure the security of the system.

[0004] Existing battery data transmissions mostly use a single encryption algorithm (such as AES or RSA). Due to the three major defects of algorithm isolation (single-layer encryption), standard fragmentation (non-national cryptographic system), and energy efficiency imbalance (high-energy-consuming encryption), there are problems such as complex key management, quantum attack risks, and insufficient end-to-end protection, making it difficult to meet the security requirements of the battery data chain in the Internet of Things environment. Especially in the scenario of cross-platform exchange of battery health data, traditional encryption methods cannot meet the requirements of national cryptographic compliance and consume too much hardware resources. Summary of the Invention

[0005] The purpose of the present invention is to provide a battery data chain with multi-level hybrid encryption for data batteries to solve the problems in the prior art that most battery data transmissions use a single encryption algorithm, resulting in complex key management, quantum attack risks, and insufficient end-to-end protection.

[0006] To achieve the above purpose, the present invention provides the following technical solution: A battery data chain with multi-level hybrid encryption for data batteries, including a battery management system, a transport layer security channel, and a cloud data processing layer;

[0007] The battery management system integrates an SM4 hardware encryption chip at the battery BMS end to encrypt raw data such as voltage / temperature in real time;

[0008] The transport layer security channel dynamically negotiates a session key through the SM2 algorithm and establishes a secure channel to transmit ciphertext data packets;

[0009] The cloud data processing layer uses SM3 to generate a hash value for the received data to verify data integrity.

[0010] Preferably, the battery management system includes a data acquisition module, an SM4 hardware encryption chip, and an encrypted data packet encapsulation module.

[0011] Preferably, the data acquisition module is built-in with voltage, temperature, and internal resistance sensors; the SM4 hardware encryption chip is used for real-time encryption in the SM4-CTR mode and timestamp generation; the encrypted data packet encapsulation module includes a packet header, a data body, and a tail.

[0012] Preferably, the field composition of the packet header includes a battery ID, a cycle count, and a timestamp; the field composition of the data body includes the SM4-CTR encrypted ciphertext; the field composition of the tail includes an SM3 hash check code.

[0013] Preferably, the transport layer security channel includes an SM2 key negotiation engine and an SM4 session encryption channel.

[0014] Preferably, the SM2 key negotiation engine dynamically generates an SM2 temporary key pair and completes key negotiation through a three-way handshake protocol; the SM4 session encryption channel includes a key validity period and a replay attack prevention design.

[0015] Preferably, the cloud data processing layer includes a data reception and decryption module, an SM3 hash chain verification module, and a data storage and analysis platform.

[0016] Preferably, the data reception and decryption module includes SM4-CTR mode decryption and out-of-order tolerance; the SM3 hash chain verification module calculates the hash value packet by packet and marks abnormal breakpoints; the data storage and analysis platform includes a battery health status assessment and a cross-platform data exchange interface.

[0017] The present invention has at least the following beneficial effects:

[0018] A battery data chain with multi-level hybrid encryption for data batteries provided by the present invention adopts the Internet of Things technology + domestic cryptographic technology + encrypted communication transmission technology + cloud trusted data technology. Through the SM2 / SM4 / SM3 three-level combined encryption technology, lightweight national cryptography compliance is achieved at the hardware layer, a quantum-resistant attack channel is built at the transport layer, and data integrity and trustworthiness are ensured at the cloud layer, forming a full-stack security protection system covering "end-pipe-cloud". BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 It is the overall system architecture diagram of the present invention;

[0020] Figure 2 It is the schematic diagram of the SM2 key negotiation process of the present invention;

[0021] Figure 3 It is the schematic diagram of the encrypted data packet structure of the present invention. Detailed Implementation Manner

[0022] The technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0023] Embodiment 1

[0024] As Figure 1 shown, this embodiment provides a battery data chain for multi-level hybrid encryption of data batteries, including a battery management system, a transport layer security channel, and a cloud data processing layer;

[0025] The battery management system integrates an SM4 hardware encryption chip at the battery BMS end to encrypt raw data such as voltage / temperature in real time;

[0026] The transport layer security channel dynamically negotiates a session key through the SM2 algorithm and establishes a secure channel to transmit ciphertext data packets;

[0027] The cloud data processing layer uses SM3 to generate a hash value for the received data to verify the data integrity.

[0028] A three-layer national cryptographic algorithm fusion system is constructed through the battery management system, the transport layer security channel, and the cloud data processing layer.

[0029] The battery management system includes a data acquisition module, an SM4 hardware encryption chip, and an encrypted data packet encapsulation module; the data acquisition module is built-in with voltage, temperature, and internal resistance sensors; the SM4 hardware encryption chip is used for real-time encryption in the SM4-CTR mode and timestamp generation; the encrypted data packet encapsulation module includes a packet header, a data body, and a tail.

[0030] As Figure 3 shown, the field composition of the packet header includes the battery ID, the number of cycles, and the timestamp; the field composition of the data body includes the SM4-CTR encrypted ciphertext; the field composition of the tail includes the SM3 hash check code.

[0031] The transport layer security channel includes an SM2 key negotiation engine and an SM4 session encryption channel; the SM2 key negotiation engine dynamically generates an SM2 temporary key pair and completes the key negotiation through a three-way handshake protocol; the SM4 session encryption channel includes a key validity period and a replay attack prevention design.

[0032] The cloud data processing layer includes a data reception and decryption module, an SM3 hash chain verification module, and a data storage and analysis platform; the data reception and decryption module includes SM4-CTR mode decryption and out-of-order tolerance; the SM3 hash chain verification module calculates the hash value for each packet and marks abnormal breakpoints; the data storage and analysis platform includes battery health status assessment and cross-platform data exchange interfaces.

[0033] The technical combination of this embodiment achieves a breakthrough through a three-layer fusion encryption architecture:

[0034] 1) Hardware (terminal encryption)

[0035] Technical type: Embedded SM4 hardware encryption chip (ASIC design);

[0036] Implementation steps:

[0037] Integrate an SM4 dedicated circuit at the BMS data acquisition end;

[0038] Real-time encrypt the original data such as voltage / temperature / internal resistance (encryption granularity ≤ 10ms);

[0039] Generate encrypted data packets with timestamps;

[0040] 2) Transmission (channel protection)

[0041] Technical type: Lightweight SM2 key negotiation protocol;

[0042] Implementation steps:

[0043] The initiating end generates an SM2 temporary key pair (dynamic seed based on the battery cycle count);

[0044] Complete the key negotiation through a three-way handshake protocol, as Figure 2 shown;

[0045] Establish an SM4 session key encrypted transmission channel (key validity period ≤ 24h);

[0046] 3) Cloud (data trustworthiness)

[0047] Technical type: SM3 hash chain verification;

[0048] Implementation steps:

[0049] The cloud receiving end calculates the SM3 hash value of the data packets in order;

[0050] Construct a hash chain and compare it with the original fingerprint (the tolerance mechanism allows ±3 packet out-of-order);

[0051] Trigger the abnormal data traceability mechanism (automatically mark the hash breakpoint).

[0052] The technical solution of this embodiment adopts:

[0053] Dynamic key update mechanism: Trigger key rotation according to the battery charge and discharge cycle (update every 50 cycles);

[0054] Lightweight protocol design: Compress the data packet header to 128 bits to adapt to narrowband Internet of Things transmission.

[0055] In this embodiment:

[0056] ①. Hardware encryption module at the BMS side:

[0057] SM4 ASIC chip: Integrated on the BMS main control board, supporting real-time encryption at the 10ms level, with power consumption < 5mW.

[0058] Physical binding design: Bind the impedance characteristics of the encryption chip and the BMS PCB board to prevent chip disassembly attacks.

[0059] ②. Dynamic key negotiation at the transport layer:

[0060] SM2 lightweight protocol: Optimize the elliptic curve parameters (use the SM2 standard curve sm2p256v1), with the single handshake time < 50ms.

[0061] Key update trigger condition: When the battery cycle count increases by 50 times or the time reaches 24 hours (whichever comes first).

[0062] ③. Cloud hash chain verification:

[0063] Disordered tolerance mechanism: Allow a maximum order deviation of 3 packets for data packets, and reconstruct the hash chain through the sliding window algorithm.

[0064] Abnormal traceability interface: Automatically generate a data integrity report and mark the position of the first data packet with a hash mismatch.

[0065] Comparative example 1

[0066] This comparative example provides a battery data chain with multi-level hybrid encryption for data batteries. Similar to Example 1, the difference is that SM9 is used instead of SM2 for key negotiation (PKG infrastructure needs to be added).

[0067] Comparative example 2

[0068] This comparative example provides a battery data chain with multi-level hybrid encryption for data batteries. Similar to Example 1, the difference is that the national cryptography SSL protocol is adopted to replace the custom transport layer (sacrificing some low-power characteristics).

[0069] The comparison between the technical solution provided in Embodiment 1 of the present invention and the prior art is shown in the following table:

[0070] Comparison Dimension Traditional Solution (RSA + AES) This Invention (SM2 / SM4 / SM3) Compliance Only meets the requirements of Equal Protection 2.0 Complies with the requirements of GB / T 39786-2021 Level 3 Quantum-Resistant Attack RSA-2048 can be cracked by a quantum computer within 8 hours SM2 requires 10^28 quantum gate operations to be cracked End-to-End Delay 230 - 350 ms ≤150 ms Hardware Resource Occupancy Requires an additional HSM module (cost + $5 / device) Integrated SM4 ASIC (cost + $0.8 / device) Cross-Platform Compatibility Relies on third-party CA institution certificates National Cryptography Standard Interface (GM / T 0015-2012)

[0071] The present invention adopts Internet of Things technology + domestic cryptography technology + encrypted communication transmission technology + cloud trusted data technology. Through the three-level combined encryption technology of SM2 / SM4 / SM3, it realizes lightweight national cryptography compliance at the hardware layer, constructs a quantum-resistant attack channel at the transmission layer, and ensures the integrity and credibility of data at the cloud layer, forming a full-stack security protection system covering "end-pipe-cloud".

[0072] The technical solution provided by the present invention has the following advantages: the end-to-end encryption efficiency is increased by 40% (compared with the traditional RSA solution); the ability to resist quantum computing attacks meets the requirements of GB / T 39786-2021 Level 3; it supports cross-vendor battery data security exchange (compatible with the national cryptography standard interface).

[0073] The foregoing has shown and described the basic principles, main features and advantages of the present invention. For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and without departing from the spirit or basic features of the present invention, the present invention can be implemented in other specific forms. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be embraced by the present invention.

[0074] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A battery data chain with multi-level hybrid encryption for data batteries, characterized in that, It includes a battery management system, a transport layer security channel, and a cloud data processing layer; The battery management system integrates an SM4 hardware encryption chip at the battery BMS side to encrypt raw data such as voltage / temperature in real time; The transport layer security channel dynamically negotiates a session key through the SM2 algorithm and establishes a secure channel to transmit ciphertext data packets; The cloud data processing layer uses SM3 to generate a hash value for the received data to verify data integrity.

2. The battery data chain with multi-level hybrid encryption for a data battery according to claim 1, characterized in that: The battery management system includes a data acquisition module, an SM4 hardware encryption chip, and an encrypted data packet encapsulation module.

3. A battery data chain for multi-level hybrid encryption of data batteries according to claim 2, characterized in that: The data acquisition module is built-in with voltage, temperature, and internal resistance sensors; the SM4 hardware encryption chip is used for real-time encryption in the SM4-CTR mode and timestamp generation; the encrypted data packet encapsulation module includes a packet header, a data body, and a tail.

4. A battery data chain for multi - level hybrid encryption of data batteries according to claim 3, characterized in that: The field composition of the packet header includes a battery ID, the number of cycles, and a timestamp; The field composition of the data body includes the SM4-CTR encrypted ciphertext; the field composition of the tail includes an SM3 hash check code.

5. A battery data chain for multi-level hybrid encryption of a data battery according to claim 1, characterized in that: The transport layer security channel includes an SM2 key negotiation engine and an SM4 session encryption channel.

6. A battery data chain with multi - level hybrid encryption for data batteries according to claim 5, characterized in that: The SM2 key negotiation engine dynamically generates an SM2 temporary key pair and completes key negotiation through a three-way handshake protocol; the SM4 session encryption channel includes a key validity period and a replay attack prevention design.

7. A battery data chain for multi - level hybrid encryption of data batteries according to claim 1, characterized in that: The cloud data processing layer includes a data reception and decryption module, an SM3 hash chain verification module, and a data storage and analysis platform.

8. A battery data chain with multi - level hybrid encryption for data batteries according to claim 7, characterized in that: The data reception and decryption module includes SM4-CTR mode decryption and out-of-order tolerance; the SM3 hash chain verification module calculates the hash value packet by packet and marks abnormal break points; the data storage and analysis platform includes battery health status assessment and cross-platform data exchange interfaces.

Citation Information

Cited By

  • Encryption protection method and device of energy storage system and energy storage system

    CN121051810A

  • Encryption protection methods, devices, and energy storage systems for energy storage systems

    CN121051810B