Authenticating wireless sensor nodes in network using physical phenomena
By modifying current or voltage in the wireless battery management system and comparing physical phenomena, the problem of whitelist dependence in the wireless battery management system is solved, safe authentication and stable communication of the wireless battery management system are realized, and the maintenance and management of the battery module is simplified.
Patent Information
- Application Number
- CN202510013067.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-01-17
- Filing Date
- 2025-01-06
- Publication Date
- 2025-07-18
AI Technical Summary
In the existing wireless battery management system, node authentication relies on whitelists, resulting in the inability to effectively monitor and control the battery module while complex wiring and weight increase, and is susceptible to changes in wireless communication channel bandwidth and interference.
By modifying the current or voltage of the battery pack, using the physical phenomenon comparison between trusted nodes and unauthenticated nodes, an authentication process without whitelisting is achieved, ensuring that nodes can accurately observe and report current or voltage changes.
It realizes security authentication in the wireless battery management system, prevents malicious node interference, simplifies the maintenance and management of battery modules, reduces system complexity and weight, and improves communication stability.
Smart Images

Figure CN120343546A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to authenticating wireless sensor nodes in a network using physical phenomena. Background Art
[0002] Modern vehicles can include multiple battery cells. Information associated with the cells, such as temperature, voltage, and other indicators of cell state and health, can be monitored for vehicle safety and to ensure proper operation. In a conventional wired battery management system, a rechargeable battery is managed through circuitry for safe and efficient operation of the battery. A wired communication interface can be used to connect a main microcontroller (main node or master node) to each battery module (auxiliary node), and each battery module is linked to the remaining battery modules in a daisy chain. Through the wired communication interface, without complex wiring, the main microcontroller cannot monitor and control all battery modules in parallel. This wiring makes repair or replacement of individual battery cells more difficult, and importantly, increases the overall system weight and volume.
[0003] A wireless connection between the battery module and the microcontroller makes management of the battery module more flexible and easier to repair. In a wireless battery management system (WBMS), the microcontroller monitors each battery module and communicates with the battery modules using a wireless communication interface. The main microcontroller controls all battery modules using a WBMS protocol. The wireless communication interface is subject to wireless communication channel bandwidth variations, interference, and / or other problems, which will impede proper monitoring and management in the WBMS. Summary of the Invention
[0004] The disclosed technology facilitates authentication of nodes in a wireless network without a whitelist, such as nodes in a battery management system (BMS). The technology includes modifying a physical phenomenon, such as voltage or current, and receiving a calculated value from an unauthenticated node to verify whether the unauthenticated node can observe the modified physical phenomenon, thereby demonstrating an association with the physical phenomenon.
[0005] In some instances, the BMS includes a battery pack and a first node, the battery pack including a plurality of battery cells. The first node is configured to: cause one or more battery cells of the battery pack to change current or voltage; receive a first value from a second node; compare the first value with a second value calculated based on the changed current or the changed voltage; and authenticate the second node as a member of the BMS based on comparing the first value with the second value.
[0006] In other instances, a method for authenticating a wireless node in a network by a first node in the network includes: changing a physical phenomenon in a pattern known to the first node; receiving a first value from a second node; comparing the first value with a second value calculated based on the known pattern; and authenticating the second node as a member of the network based on comparing the first value with the second value.
[0007] In other instances, a method for authenticating a second node in a wireless battery management system (WBMS) includes: sampling a current or voltage of a battery pack; calculating a first value based on the sampled current or the sampled voltage; sending the first value to a first node; and receiving an indication of authentication as a member of the WBMS in response to sending the first value to the first node. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 is a block diagram of a WBMS in accordance with various instances.
[0009] Figure 2A is a block diagram of a WBMS in accordance with various instances.
[0010] Figure 2B is a block diagram of a WBMS in accordance with various instances.
[0011] Figure 3 is a sequence diagram in accordance with various instances showing interactions between a trusted node and an unauthenticated node for authenticating the unauthenticated node in a BMS.
[0012] Figure 4 is a flowchart of a method for authenticating nodes of a BMS in accordance with various instances.
[0013] Figure 5 is a flowchart of a method for a node to be authenticated by a BMS in accordance with various instances. DETAILED DESCRIPTION
[0014] Some electronic devices operate using batteries. For example, electric vehicles include multiple battery cells that provide power to these vehicles. Because the battery cells in an electronic device can provide a large amount of power, and further because the power provided by the battery cells may be critical to the operation of the electronic device, the electronic device may include a system for managing the battery cells.
[0015] A battery management system (BMS) can manage the battery cells of an electronic device in various ways. For example, the BMS can monitor the health (e.g., voltage, current, temperature, pressure) of the battery cells in the electronic device. In addition, the BMS can control various battery cells to manage the amount of electrical power provided by the battery cells and where the power is directed within the electronic device. Generally, the BMS includes multiple components, such as multiple battery modules and a controller for managing the battery modules. Each battery module can in turn be coupled to multiple battery cells and includes a battery monitor for monitoring those battery cells. Thus, the battery cells coupled to the battery module provide power to the electronic device; the battery monitor in the battery module monitors the health and operation of the battery cells in the battery module; and the controller communicates with the battery monitor to ensure that the battery module and its cells operate correctly. The controller can also communicate with the battery monitor to control the operation of the battery cells in order to turn on, turn off, redirect, or otherwise balance the power provided by those battery cells.
[0016] The BMS can incorporate wireless technology. For example, the primary network node contains or is coupled to the controller, and the secondary network node contains the battery module that controls multiple battery cells. The primary network node and the secondary network node can communicate wirelessly with each other, for example, using radio frequency.
[0017] In some examples of the present disclosure, the BMS includes a trusted node that is configured to initiate a process of authenticating other nodes in the network. The authentication process is based on the ability of these other nodes, called unauthenticated nodes, to observe and report changes in physical phenomena. In the case of the BMS, this physical phenomenon is typically the current or voltage of the battery pack.
[0018] The trusted node can be configured to initiate the authentication process by causing one or more battery cells of the battery pack to change the current or voltage. This change follows a pattern known to the trusted node. The trusted node instructs the unauthenticated node that wishes to be authenticated to sample the current or voltage of the battery pack at a predetermined interval. The unauthenticated node observes the change pattern of the current or voltage and calculates a value (e.g., a voltage value) based on the observed pattern.
[0019] The unauthenticated node then sends this calculated value to the trusted node. The trusted node can be configured to independently calculate a value based on the known change pattern of the current or voltage. The trusted node can be configured to compare the value received from the unauthenticated node with the value it independently calculates. Based on the comparison, for example, if the two values match within a predetermined tolerance, the trusted node can authenticate the unauthenticated node as a member of the BMS.
[0020] These authentication techniques can be used to prevent malicious nodes within the network from interfering with the network. Malicious nodes can be external to the system (e.g., outside of a vehicle or machine) and thus cannot measure the requested system metrics. The trusted nodes can reject the authentication of malicious nodes that are unable to accurately measure the system metrics and upload the measured metrics to the trusted nodes. The authentication techniques described herein can be used with or without an authentication whitelist or other network security methods. Authentication without a whitelist is useful for cases where nodes are replaced with new nodes that are not listed on an existing whitelist.
[0021] Figure 1 、 2A and 2B describe examples of WBMSs in which these authentication techniques can be implemented for unauthenticated nodes. Specifically, Figure 1 is a perspective view of an example system 98, such as a motor vehicle, that includes a wireless battery management system (WBMS) 100. In some examples, system 98 can be any system that can include a WBMS to power one or more components of system 98. Although this system is described in the context of an automotive system and a battery management system, the techniques of the present disclosure can be implemented in other systems such as, for example, home automation, industrial automation, and wireless sensor networks. Such systems can include one or more central nodes and two or more secondary nodes, and can or cannot be used to monitor battery cells.
[0022] As shown, WBMS 100 includes a main network node 102, a battery controller 104, a plurality of secondary network nodes 106, and a plurality of battery cells 108. In one example, WBMS 100 can include a plurality of main network nodes. Although the present disclosure primarily describes communication techniques in the context of wireless systems, these techniques can also be applicable to wired systems (e.g., the connection between nodes 102 and 106 is wired). The WM and / or WD in the WBMS can be implemented as the CC2662 and / or BQ79616 made by Texas Instruments Incorporated of Dallas, Texas, USA. Additional example details of the CC2662 and BW79616 can be found in the data sheet titled “CC2662R-Q1 SimpleLinkTM Wireless BMS MCU” revised in July 2023 and available at https: / / www.ti.com / product / CC2662R-Q1 and the data sheet titled “BQ79616-Q1, BQ79614-Q1, BQ79612-Q1 Functional Safety Compliant Automotive 16S / 14S / 12S Battery Monitor, Balancer, and Integrated Hardware Protector” revised in September 2022 and available at https: / / www.ti.com / product / BQ79616-Q1, each of which is incorporated herein by reference in its entirety.
[0023] In one example, the master network node 102 is coupled to the battery controller 104 using a first wired connection 110. In one example, the first wired connection 110 between the master network node 102 and the battery controller 104 is a Universal Asynchronous Receiver / Transmitter (UART), Inter-Integrated Circuit (I2C), or the like. The slave network node 106 is wirelessly coupled to the master network node 102 and is coupled to the battery cell 108 using a second wired connection 112.
[0024] In one example, the WBMS 100 provides radio frequency (RF) communication between the master network node 102 and the slave network node 106. In one example, the wireless RF communication uses the unlicensed 2.4 gigahertz (GHz) Industrial, Scientific, and Medical (ISM) band from 2.4 GHz to 2.483 GHz, which is compliant with the Bluetooth Special Interest Group (SIG). In an example, the WBMS 100 uses 2 megabits per second (Mbps) Low Energy Bluetooth (BLE) across the Physical Layer (PHY). The Open Systems Interconnection (OSI) model includes the PHY as the layer for transmitting raw bits over a physical medium. In this case, the PHY is free space, and the WBMS 100 uses it to communicate wirelessly between the master network node 102 and the slave network node 106. In one example, the transmit power of the WBMS 100 is less than or equal to 10 decibel-milliwatts (dBm).
[0025] In one example, the wireless RF communication between the master network node 102 and the slave network node 106 utilizes frequency hopping and time slot allocation to transmit and receive data across a superframe (SF). A superframe, also referred to as a superframe interval, is a time interval that contains the time and frequency allocations for data exchange between the master network node 102 and the slave network node 106, including the inter-frame spacing between these allocations. Frequency hopping involves transmitting an RF signal by rapidly changing the transmit frequency among many different frequencies that occupy the frequency band. In one example, the frequency hopping occurs based on a linear feedback shift register and a master identification (ID) of the master network node 102. The linear feedback shift register uses linear bit rotation to indicate the pattern of frequencies on which the master network node 102 and the slave network node 106 will communicate. Time slot allocation is a time slot assigned to one or more of the master network node 102 or the slave network node 106 for transmitting to one or more of the slave network nodes 106 or the master network node 102. The time slot allocation occurs in a half-duplex mode because both the master network node 102 and the slave network node 106 switch between the transmit mode and the receive mode according to the moments specified in the scan / pairing frames for exchanging data in the downlink (DL) / uplink (UL) duration.
[0026] In one example, the WBMS 100 uses Frequency Division Multiple Access (FDMA) and changes the frequency at which frames are transmitted between the primary network node 102 and the secondary network node 106 to increase robustness against interference. In one example, the WBMS 100 uses a frequency hopping table, a blacklist of frequencies, and configured channels to mitigate interference with other wireless networks. Frequency hopping occurs on a per-superframe (SF) basis, where during the SF, time slots are allocated for frame exchange. The blacklist suspends the use of frequency channels that may be vulnerable to interference. The configured channels can be used for scanning, pairing, and negotiating communications between the primary network node 102 and the secondary network node 106.
[0027] In one example, the wireless RF communication between the primary network node 102 and the secondary network node 106 uses 40 channels, where a subgroup of the 40 channels (e.g., channels 37, 38, and 39) are used for system configuration, and the remaining 37 channels are used to exchange data. In one example, a single channel can be used as the configured channel.
[0028] In one example, the WBMS 100 supports periodic and aperiodic data exchange from the secondary network node 106 to the primary network node 102 using wireless RF communication. The primary network node 102 and the secondary network node 106 use a common data format structure for periodic and aperiodic data exchange. Periodic data exchange occurs based on a repeating interval, while aperiodic data exchange does not occur based on a repeating interval. A data format is a description of the rules that the data that fills a file will follow. Generally, the more detailed the description of the data format, the easier it is to write verification rules on both the transmitting side and the receiving side of the WBMS 100.
[0029] In one example, the primary network node 102 scans the network to obtain a master ID and discovers the secondary network node 106. The primary network node 102 scans the network by transmitting management frames to coordinate media access, wake-up schedules, and clock synchronization within the secondary network node 106. The primary network node 102 also uses management frames to learn about the secondary network node 106 in the network. Initially, the primary network node 102 performs a passive scan to obtain (or check) the master ID values used by other nodes and / or devices. The primary network node 102 then selects a master ID different from the master ID used by other nodes and / or devices.
[0030] In one example, after the master network node 102 has selected a master ID, as long as there are secondary network nodes 106 that are not connected to the master network node 102, the master network node 102 transmits a scan request frame in each SF period. In one example, the master network node 102 is programmed with the total number of secondary network nodes 106 to be connected to the master network node 102. After all secondary network nodes 106 are connected and authenticated, the master network node 102 will no longer transmit scan requests. The scan request frame contains information about the structure of the SF and the frame formatting of the DL and UL time slots.
[0031] To scan for secondary network nodes 106, the master network node 102 enters a scan state. In this state, the master network node 102 transmits a scan request frame in each SF period. The secondary network node 106 replies to the master network node 102 with a scan response and waits for a pairing request frame from the master network node 102. After the secondary network node 106 receives the pairing request, the secondary network node 106 responds in the same SF in the frequency slot assigned by the master network node 102. In an example, this exchange occurs in a configured channel. No data exchange occurs in this state. Additional example details of establishing a communication channel can be found in U.S. patent application Ser. No. 17 / 233,106, titled “Wireless Protocol for Battery Management,” filed Apr. 16, 2021, and U.S. patent application Ser. No. 17 / 399,793, titled “WBMS Setup,” filed Aug. 11, 2021, each of which is incorporated herein by reference in its entirety.
[0032] In one example, the transmission cycle or SF depends on the number of secondary network nodes 106 and / or battery cells 108 in the network. The master network node 102 determines the SF interval based on the number of secondary network nodes 106. Given the number of secondary network nodes 106, the master network node 102 estimates the number of DL time slots available to transmit packets to the secondary network nodes 106. Thus, the total number of time slots in the communication time interval is as follows:
[0033] Total_slots = nr_of_WD + nr_DL_slots,
[0034] where nr_of_WD is the number of secondary network devices and nr_DL_slots is the number of DL time slots available to the secondary network devices.
[0035] The WBMS 100 manages battery cells 108 using a primary network node 102, a battery controller 104, and a secondary network node 106. The primary network node 102 and the secondary network node 106 communicate with each other regarding the state of the battery cells 108. The primary network node 102 and the secondary network node 106 can communicate with each other using various protocol formats. For example, the primary network node 102 and the secondary network node 106 use a DL protocol format and a UL protocol format, where each of the DL protocol format and the UL protocol format includes a frame control field to convey battery management information. When a battery cell 108 notifies a condition to the secondary network node 106, the secondary network node 106 conveys that the condition exists to the primary network node 102. The primary network node 102 receives notification of the condition from the secondary network node 106 and alerts the battery controller 104 of the condition. The battery controller 104 determines the correct response to the condition and sends an instruction to the primary network node 102. The primary network node 102 transmits the instruction to the secondary network node 106. The secondary network node 106 receives an instruction to manage the battery cell 108 in response to the condition. The secondary network node 106 manages the battery cell 108 in response to the condition.
[0036] Although Figure 1 a single primary network node 102 and a single battery controller 104 are shown, other example network architectures with multiple master / primary nodes can be used to implement the techniques of the present disclosure. Additional example details of the network architecture for the WBMS can be found in co-pending U.S. patent application Ser. No. 17 / 823,138, filed Aug. 30, 2022, entitled “Multiple Master Nodes for Wireless Battery Management System Robustness” and U.S. patent application Ser. No. 18 / 345,636, filed Jun. 30, 2023, entitled “Hierarchical Wireless Battery Management System,” each of which is incorporated herein by reference in its entirety.
[0037] Figure 2AAn example WBMS200 is shown. WBMS200 is an example of the WBMS100 described above. As shown, WBMS200 includes a main network node 102, a battery controller 104, a memory 202, a processor 204, a first sub-network node 206, a first plurality of battery cells 208, a second sub-network node 210, and a second plurality of battery cells 212. Additional sub-network nodes 206, 210 may be included, but they are not explicitly shown. The main network node 102 includes the memory 202 and the processor 204, and the processor is configured to execute code 205 stored on the memory 202 to perform one or more of the actions attributed to the main network node 102 herein. In one example, a portion of the memory 202 may be non-transitory, and a portion of the memory 202 may be transitory. The sub-network nodes 206, 210 may also include a processor and a memory. For example, as shown, the sub-network node 206 includes a processor 262 that is coupled to a memory 264 storing code 265 that can be executed by the processor 262 to perform one or more of the actions attributed to the sub-network node 206 herein.
[0038] The main network node 102 is coupled to the battery controller 104 using a first wired connection 110 and is wirelessly coupled to each of the sub-network nodes 206, 210. The first sub-network node 206 is coupled to the first plurality of battery cells 208 using a third wired connection 214 and is wirelessly coupled to the main network node 102. The second sub-network node 210 is coupled to the second plurality of battery cells 212 using a fourth wired connection 216 and is wirelessly coupled to the main network node 102. Figure 2A There is no limit to the number of sub-network nodes in WBMS200; rather, the naming convention indicates that each of the sub-network nodes is coupled to a plurality of battery cells.
[0039] In one example, the main network node 102 is wirelessly coupled to at least eight sub-network nodes 206, 210. In one example, each of the sub-network nodes 206, 210 may be coupled to at least sixteen battery cells using a wired connection. In an example, WBMS200 includes one main network node. In other examples, WBMS200 includes multiple main network nodes.
[0040] The WBMS 200 manages the first plurality of battery cells 208 and the second plurality of battery cells 212 using the main network node 102, the battery controller 104, the memory 202, the processor 204, the first network node 206, and the second network node 210. Instructions in the memory 202 cause the processor 204 to direct the main network node 102 to communicate wirelessly with the first network node 206 and the second network node 210 regarding the status of the first plurality of battery cells 208 and the second plurality of battery cells 212. The main network node 102 and the secondary network nodes 206, 210 communicate using various protocol formats. For example, the main network node 102 and the secondary network nodes 206, 210 use the DL protocol format and the UL protocol format, where each of the DL protocol format and the UL protocol format includes a frame control field to convey battery management information. When the first plurality of battery cells 208 notify a condition to the first network node 206, the first network node 206 conveys to the main network node 102 that the condition exists. The main network node 102 receives notification of the condition from the first network node 206 and alerts the battery controller 104 of the condition. The battery controller 104 determines the correct response to the condition and sends an instruction to the main network node 102. The main network node 102 transmits the instruction to the first network node 206. The first network node 206 receives the instruction to manage the first plurality of battery cells 208 in response to the condition of the first plurality of battery cells 208. The first network node 206 manages the first plurality of battery cells 208 in response to the condition. When a condition exists in the second plurality of battery cells 212, a similar process can be applied to the second network node 210. Figure 2B An example WBMS 250 is shown. The WBMS 250 is an example of the WBMS 100 described above. As shown, the WBMS 250 includes a first network node 206, the first plurality of battery cells 208, a plurality of main network nodes 252, a memory 254, a processor 256, a first wired connection 258, and a plurality of battery controllers 260. The plurality of main network nodes 252 includes a memory 254 and a processor 256. In one example, a portion of the memory 254 may be non - transitory and a portion of the memory 254 may be transitory. In an example, the memory 254 includes executable code 255 that, when executed by the processor 256, causes the processor 256 to perform the actions attributed to the main network node 252 herein.
[0041] The plurality of main network nodes 252 are coupled to the plurality of battery controllers 260 using the first wired connection 258 and are wirelessly coupled to the secondary network node 206. The first network node 206 is coupled to the first plurality of battery cells 208 using a wired connection 214 and is wirelessly coupled to the plurality of main network nodes 252. As Figure 2AAs shown, the first network node 206 may include a processor and a memory (e.g., processor 262 and memory 264). Figure 2B There is no limit to the number of secondary network nodes in the WBMS 250. In one example, each of the plurality of primary network nodes 252 is wirelessly coupled to at least eight secondary network nodes. In one example, the first network node 206 may be coupled to at least sixteen battery cells using a fourth wired connection 216.
[0042] The WBMS 250 manages the first plurality of battery cells 208 using the plurality of primary network nodes 252, the plurality of battery controllers 260, the memory 254, the processor 256, and the first network node 206. Instructions in the memory 254 cause the processor 256 to direct the plurality of primary network nodes 252 to communicate wirelessly with the first network node 206 regarding the status of the first plurality of battery cells 208. The plurality of primary network nodes 252 and the first network node 206 communicate using various protocol formats. For example, the plurality of primary network nodes 252 and the first network node 206 use a DL protocol format and a UL protocol format, where each of the DL protocol format and the UL protocol format includes a frame control field to convey battery management information. When the first plurality of battery cells 208 notify the first network node 206 of a condition, the first network node 206 communicates to the plurality of primary network nodes 252 that the condition exists. The plurality of primary network nodes 252 receive notification of the condition from the first network node 206 and alert the plurality of battery controllers 260 of the condition. The plurality of battery controllers 260 determine the correct response to the condition and send instructions to the plurality of primary network nodes 252. The plurality of primary network nodes 252 transmit the instructions to the first network node 206. The first network node 206 receives instructions to manage the first plurality of battery cells 208 in response to the condition of the first plurality of battery cells 208. The first network node 206 manages the first plurality of battery cells 208 in response to the condition.
[0043] In one example, a first network node 206 communicates with a first primary network node among the plurality of primary network nodes 252 based on instructions from a master controller (not shown). The first network node 206 may transition the communication from the first primary network node to a second primary network node among the plurality of primary network nodes 252. The first primary network node and the second primary network node communicate with each other to coordinate transferring the active connection of the first network node 206 from the first primary network node to the second primary network node. In one example, the first primary network node communicates with the first network node 206, and the second primary network node monitors the status of the first primary network node. The status may indicate whether the first primary network node has power and is operating within normal operating conditions. The first primary network node provides a clock signal to the second primary network node to synchronize the communication. The first primary network node and the second primary network node select different frequencies to communicate with the first network node 206. Selecting different frequencies allows the plurality of primary network nodes 252 to minimize interference when communicating with the first network node 206. For example, if the first primary network node loses power, or if the status of the first primary network node deviates from normal operating conditions, the second primary network node may connect to the first network node 206 to supplement the communication until the first primary network node can operate normally again.
[0044] Figure 3 is a sequence diagram showing the process of authenticating nodes in an authentication WBMS, such as WBMS100, WBMS200, or WBMS250. This process involves a series of steps initiated by a trusted node, such as trusted node 352, and involves interactions with unauthenticated nodes, such as unauthenticated node 356, that wish to be authenticated. In various examples, the trusted node 352 is the master node of the WMBS or a node verified by the master node of the WBMS. For a star topology, the trusted node 352 can be the master node or a secondary node. For a mesh topology, the trusted node 352 can be one or more of the peer nodes. With respect to WBMS100 ( Figure 1 ), the trusted node 352 can be implemented in various system components, such as but not limited to one or more of the primary network node 102, the secondary network node 106, and the battery controller 104. If the master node and the trusted node 352 are different nodes, the trusted node 352 can start the process by forming a network with the master node. After this network formation, the master node can communicate with the trusted node 352 and instruct the trusted node 352 to charge or discharge one or more battery cells.
[0045] The unauthenticated node 356 is a node unknown to the trusted node 352 or a node not authenticated by the trusted node 352. In these examples, there may not be a whitelist of nodes. Figure 3The techniques shown do not require an explicit whitelist for uncertified nodes 356 to be members of the same battery pack (cluster), but some embodiments of the techniques of the present disclosure may still use an explicit whitelist. Such techniques can be used to initially provision a battery pack and at other times during the operation of the battery pack. Additionally, nodes can be authenticated during maintenance or repair of the battery pack, such as during replacement of individual battery cells. Relative to the WBMS 100 ( Figure 1 ), the uncertified node 356 can be one of the sub-network nodes 106.
[0046] Authentication is done on a per-node basis. Figure 3 The techniques shown authenticate a single uncertified node 356. Figure 3 The techniques shown begin with a trusted node 352 sending a scan request 302 on a predetermined configuration channel. Wireless devices that wish to join the cluster listen for the scan request 302 on one or more of the configuration channels. For example, member or non-member wireless devices of the uncertified node 356 that receive the scan request send a scan response 304 via a scan response frame to be authenticated by the trusted node 352.
[0047] After issuing the scan request, the trusted node 352 is configured to immediately receive scan responses from other nodes in the network that wish to be authenticated. In this context, the uncertified node 356 sends the scan response of the scan response 304 to the trusted node 352. The scan response 304 serves as an indication that the uncertified node 356 wishes to be authenticated and join the network.
[0048] The uncertified node 356 synchronizes with the trusted node 352 after the scan response 304. After the scan response 304, the uncertified node 356 receives a sampling instruction 306 from the trusted node 352 to monitor a physical phenomenon. For example, the uncertified node 356 can receive a sampling instruction 306 from the trusted node 352 to sample current / voltage between two given timestamps at a given sampling frequency. In response, the uncertified node 356 sends an acknowledgment 308 to the trusted node 352.
[0049] The trusted node 352 then modifies or manipulates the physical metric, such as charging and discharging the battery pack in a pattern known only to the trusted node 352, such as a random pattern known only to the master node and / or the trusted node 352 (modifying metric 310). In other instances, the pattern can be predefined or dynamically generated based on various factors, such as the state of the battery cells, network conditions, or other operating parameters of the WBMS. The unauthenticated node 356 measures the metric (measuring metric 312), for example, by sampling the current / voltage between two given timestamps at a given sampling frequency. The two timestamps can be after the trusted node 352 modifies the metric in step 310, such that the unauthenticated node 356 measures the modified metric rather than the unmodified metric.
[0050] After the period between the two timestamps, the unauthenticated node 356 receives a request 314 from the trusted node 352 to report a value based on the observed physical parameters. In response, the unauthenticated node 356 sends / uploads a value 316 calculated based on the physical parameters observed during a predetermined interval to the trusted node 352. In some instances, the unauthenticated node 356 can send the calculated value 316 to the trusted node 352 without receiving the request 314. The calculation can involve various mathematical or statistical operations, such as averaging, integration, or hashing, and can also take into account the timestamps at which the current or voltage was sampled.
[0051] The calculated value can involve encryption or other proprietary calculations that are unique to the WBMS and the authorized components for the WBMS. In this way, the disclosed techniques allow the battery pack manufacturer to control the installation and repair of the battery cells within the battery pack. For example, the techniques can be used to prevent the installation of unauthorized aftermarket battery cells, prevent the switching of OEM battery cells between vehicles, and / or prevent unauthorized individuals from repairing or replacing the battery cells. For example, the encryption or other proprietary calculations can be specific to each battery pack and / or vehicle. In some instances, the authentication techniques disclosed herein may require the battery cells to be configured with encryption or other proprietary calculations for the battery pack and / or vehicle. In other instances, more general encryption or other proprietary calculations can be used such that battery cells approved by the OEM are suitable for installation without a configuration specific to the vehicle or battery pack.
[0052] The trusted node 352 receives the calculated value 316 from the unauthenticated node 356 and independently calculates a value based on a pattern. The trusted node 352 then compares the value received from the unauthenticated node 356 with the value it independently calculated. This comparison can involve determining whether the two values match within a predetermined tolerance. If the value received from the unauthenticated node 356 matches the independently calculated value within the predetermined tolerance, the trusted node 352 authenticates the unauthenticated node 356 as a member of the WBMS, denoted as authentication 318. This authentication process ensures that the authenticated node is physically connected to the battery pack.
[0053] In some cases, if the value received from the unauthenticated node 356 does not match the independently calculated value within the predetermined tolerance, the trusted node 352 may optionally reject the unauthenticated node 356. This ensures that nodes that are not able to accurately observe and report changes in the current or voltage of the battery pack, such as nodes that are not physically connected to the battery pack, are not authenticated, thereby maintaining the integrity and security of the WBMS.
[0054] By way of example only, the trusted node 352 may cause one or more battery cells to be discharged before the unauthenticated node 356 measures the battery voltage. The trusted node 352 then calculates the expected decrease in the battery voltage after discharging the one or more battery cells. The trusted node 352 may compare the expected decrease in voltage with the value received from the unauthenticated node 356 and, based on this comparison, determine whether to authenticate or reject the unauthenticated node 356. In this example, if the unauthenticated node 356 reports a value indicating an increase in the battery voltage, rather than the expected decrease in the battery voltage, the trusted node 352 may reject the unauthenticated node 356 from joining the WBMS.
[0055] The techniques described in the context of the trusted node 352 and the unauthenticated node 356 Figure 3 In some instances, a master node in the network may perform some or all of the functionality attributed to Figure 3 the trusted node 352 therein. The master node may provide a timestamp to the trusted node 352 for the sampling instruction 306. As another example, the master node may compare the measured metrics received from the unauthenticated node 356 with expected values.
[0056] Figure 4 is a flowchart of a method for authenticating nodes of a WBMS according to various examples, the WBMS being, for example, any one of WBMS100, WBMS200, WBMS250, or other WBMSs. For clarity, the techniques described Figure 3 are described Figure 4 in relation to
[0057] First, the trusted node 352 issues a scan request 302 on a predetermined channel (step 402). The trusted node 352 receives a scan response 304 from an unauthenticated node 356 that wishes to be authenticated (step 404). The trusted node 352 may receive additional scan responses from other nodes that wish to be authenticated.
[0058] After the scan response 304, the trusted node 352 sends a sampling instruction 306 to sample current / voltage at a given sampling frequency over a predetermined interval, e.g., between two given timestamps (step 406). In response, the trusted node 352 receives an acknowledgement 308 from the unauthenticated node 356.
[0059] The trusted node 352 then modifies a physical metric in a pattern known only to the trusted node 352, e.g., by charging and / or discharging a battery pack, the pattern being, e.g., a random pattern (step 408). After the modification of the physical metric, the trusted node 352 receives from the unauthenticated node 356 the value of the physical metric corresponding to the predetermined interval (step 410). The trusted node 352 may send a message to the unauthenticated node 356 requesting that the unauthenticated node 356 send the value to the trusted node 352.
[0060] The trusted node 352 independently calculates a value based on the physical metric corresponding to the predetermined interval, and compares its calculated value with the value of the physical metric from the unauthenticated node 356 corresponding to the predetermined interval (step 412). The value may be calculated based on a known pattern or another property of the physical metric during the predetermined interval.
[0061] Based on comparing the first value with the second value, if the value received from the unauthenticated node 356 indicates that the unauthenticated node 356 measured the physical metric during the predetermined interval, the trusted node 352 authenticates the unauthenticated node 356 as a member of the network (step 414). If the first value does not match the second value within a predetermined tolerance, the trusted node 352 optionally rejects the unauthenticated node 356.
[0062] Figure 5 is a flowchart of a method of a node to be authenticated by a WBMS according to various examples, the WBMS being, e.g., any one of WBMS100, WBMS200, WBMS250, or other WBMS. For clarity, with respect to a Figure 3 description Figure 5 of the technology.
[0063] First, the unauthenticated node 356 receives a wireless scan request 302 from the trusted node 352 on a predetermined channel (step 502). The unauthenticated node 356 sends a wireless scan response 304 to the trusted node 352 (step 504). After the scan response 304, the unauthenticated node 356 receives a sampling instruction 306 from the trusted node 352 to sample the current / voltage between two given timestamps at a given sampling frequency. In response, the unauthenticated node 356 sends an acknowledgement 308 to the trusted node 352. The unauthenticated node 356 measures a metric by sampling the current / voltage between two given timestamps at a given sampling frequency, and observes the mode (step 506).
[0064] Next, the unauthenticated node 356 calculates a value based on the sampled current or the sampled voltage (step 508). The unauthenticated node 356 sends the calculated value to the trusted node 352 (step 510).
[0065] In response to sending the calculated value to the trusted node 352, the unauthenticated node 356 is authenticated as a member of the WBMS (step 512).
[0066] The term "coupled" is used in this specification. The term can encompass a connection, communication, or signal path that achieves a functional relationship consistent with the description. For example, if device A generates a signal for controlling device B to perform an action, then: in a first instance, device A is coupled to device B; or in a second instance, device A is coupled to device B through an intermediate component C, provided that the intermediate component C does not substantially change the functional relationship between device A and device B, such that device B is controlled by device A via the control signal generated by device A.
[0067] A device "configured to" perform a task or function can be configured (e.g., programmed and / or hardwired) by a manufacturer to perform the function, and / or can be configured (or reconfigured) by a user after manufacture to perform the function and / or other additional or alternative functions. The configuration can be by programming of the device's firmware and / or software, by the construction and / or layout of the device's hardware components and interconnections, or a combination thereof.
[0068] Unless otherwise stated, "about", "approximately", or "substantially" in front of a value means + / - 10% of the stated value. Modifications can be made in the described examples, and other examples are within the scope of the claims.
Claims
1. A battery management system (BMS) comprising: A battery pack including a plurality of battery cells; And A first node configured to: Cause one or more battery cells of the battery pack to change current or voltage; Receive a first value from a second node; Compare the first value with a second value calculated based on the changed current or the changed voltage; And Authenticate the second node as a member of the BMS based on comparing the first value with the second value.
2. The BMS according to claim 1, wherein the first node is further configured to optionally reject the second node based on comparing the first value with the second value.
3. The BMS according to claim 1, wherein the first node is further configured to: Initiate a scanning process by wirelessly sending a scan request on a predetermined channel; Receive a scan response from the second node that desires to be authenticated; and Instruct the second node to sample the current or the voltage of the battery pack at a predetermined interval.
4. The BMS according to claim 3, wherein instructing the second node to sample the current or the voltage at the predetermined interval includes instructing the second node to sample a physical phenomenon at a given sampling frequency at a predetermined timestamp.
5. The BMS according to claim 1, wherein causing the one or more battery cells of the battery pack to change the current or the voltage includes causing the one or more battery cells of the battery pack to change the current or the voltage in a pattern known to the first node.
6. The BMS according to claim 1, wherein authenticating the second node as a member of the BMS based on comparing the first value with the second value includes determining whether the first value matches the second value within a predetermined tolerance.
7. The BMS according to claim 1, wherein the first node is a trusted node and the second node is an unauthenticated node.
8. The BMS according to claim 1, wherein the second node is a master node or a slave node in a star topology network.
9. The BMS according to claim 1, wherein the second node is one or more peer nodes in a mesh topology network.
10. The BMS according to claim 1, wherein the pattern of changing the current or the voltage is random.
11. The BMS according to claim 1, wherein the second node is authenticated without an explicit whitelist.
12. The BMS according to claim 1, wherein the second node is authenticated on a per-node basis.
13. A method for authenticating a wireless node in a network by a first node in the network, the method comprising: Changing a physical phenomenon in a pattern known to the first node; Receiving a first value from a second node; Comparing the first value with a second value calculated based on the known pattern; And Authenticating the second node as a member of the network based on comparing the first value with the second value.
14. The method according to claim 13, further comprising rejecting the second node if the first value does not match the second value within a predetermined tolerance.
15. The method according to claim 13, further comprising: issuing a scan request on a predetermined channel by the first node on the network; receiving a scan response from the second node desiring to be authenticated; and instructing the second node to sample the physical phenomenon at a predetermined interval.
16. The method according to claim 13, wherein the physical phenomenon is the current or voltage of a battery pack.
17. The method according to claim 13, wherein the first value is calculated based on the pattern.
18. A method for authenticating a second node in a wireless battery management system (WBMS), the method comprising: sampling the current or voltage of a battery pack; calculating a first value based on the sampled current or the sampled voltage; sending the first value to a first node; and receiving an indication of authentication as a member of the WBMS in response to sending the first value to the first node.
19. The method according to claim 18, further comprising: receiving a wireless scan request from the first node of the WBMS on a predetermined channel; and sending a wireless scan response to the first node.
20. The method according to claim 19, wherein the sampled current or the sampled voltage is a random pattern.
Citation Information
Patent Citations
Wireless battery management system setup
US12047778B2
Wireless protocol for battery management
US20220332213A1
Multiple primary nodes for wireless battery management system robustness
US20240069110A1
Hierarchical wireless battery management system
US20250008491A1
Cited By
Wireless battery management reverse wake up
US12738548B2
Wireless battery management reverse wake up
US20250070280A1