Continuous identity authentication method and device for electric vehicle and charging pile, electronic equipment and storage medium

By constructing the state space and dynamically adjusting the authentication strategy using the authentication decision model, the security risks of identity authentication of electric vehicles and charging piles in dynamically changing environments are solved, and continuous and reliable vehicle pile authentication is achieved, and data security is improved.

CN120372589APending Publication Date: 2025-07-25STATE GRID INFORMATION & TELECOMM GRP CO LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510270163.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing identity authentication methods for electric vehicles and charging piles cannot be flexibly adjusted under long-term conversations, and cannot cope with dynamic changes such as equipment loss and abnormal user behavior, which poses security risks such as unauthorized access and data leakage.

Method used

By obtaining device physical information, environmental information, reputation evaluation information, historical charging information and current abnormal state, constructing the state space, and using the authentication decision model to output the optimal authentication strategy, dynamically adjusting the authentication strategy, including identity authentication, device authentication and environmental authentication, etc., to ensure the rationality and efficiency of the authentication strategy.

Benefits of technology

It realizes continuous and reliable vehicle pile certification in dynamically changing charging scenarios, improves data security, and ensures high reliability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372589A_ABST
    Figure CN120372589A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a continuous identity authentication method and device for an electric vehicle and a charging pile, electronic equipment and a storage medium. The continuous identity authentication method comprises the steps that equipment physical information, environment information, reputation evaluation information, historical charging information, historical authentication information and a current abnormal state are acquired; constructing a state space based on the equipment physical information, the environment information, the reputation evaluation information, the historical charging information, the historical authentication information and the current abnormal state; inputting the state in the state space into a preset authentication decision model, and outputting an optimal authentication strategy by the authentication decision model; and when the authentication strategy is continuous authentication, the electric vehicle and the charging pile are authenticated based on the authentication mode set and the authentication evidence quantity in the authentication strategy. According to the invention, continuous and reliable vehicle pile authentication can be realized, and the data security of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of information security technology, and in particular, to a method, device, electronic device and storage medium for continuous identity authentication between an electric vehicle and a charging pile. Background Art

[0002] In the context of the vehicle-grid interaction ecosystem, with the rapid growth of the number of electric vehicles and the wide deployment of charging piles, the amount of interactive data between vehicles and piles is increasing continuously. The data generated during the charging process not only involves sensitive information such as vehicle and pile identities, but also is the basis for power dispatching, and a secure and effective data security mechanism needs to be established. The current vehicle-pile identity authentication method mainly conducts two-way identity authentication when an electric vehicle and a charging pile are initially connected. After the authentication is passed, a long-term session state is maintained, and repeated identity authentication is no longer performed. However, during the long charging process, abnormal situations such as equipment loss, network address change, abnormal user behavior, and abnormal vehicle charging may occur, and there are security risks such as unauthorized access and data leakage. Since the authentication strategy cannot be flexibly adjusted in a dynamically changing environment, it is difficult to ensure data security. Summary of the Invention

[0003] In view of this, the purpose of the embodiments of the present application is to propose a method, device, electronic device and storage medium for continuous identity authentication between an electric vehicle and a charging pile to solve the problem of vehicle-pile identity authentication.

[0004] Based on the above purpose, the embodiments of the present application provide a method for continuous identity authentication between an electric vehicle and a charging pile, including:

[0005] Obtain device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status;

[0006] Construct a state space based on the device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status;

[0007] Input the states in the state space into a preset authentication decision model, and the authentication decision model outputs the optimal authentication strategy;

[0008] When the authentication strategy is to continue authentication, authenticate the electric vehicle and the charging pile based on the set of authentication methods and the amount of authentication evidence in the authentication strategy.

[0009] Optionally, the authentication decision model selects the optimal authentication strategy based on the Q-value function, and the Q-value function includes an immediate reward, and the immediate reward includes an authentication success reward, an authentication efficiency reward, and a strategy rationality reward; wherein, the authentication efficiency reward is determined according to the number of authentication methods in the set of authentication methods and the amount of authentication evidence.

[0010] Optionally, the immediate reward is expressed as:

[0011] R t = R succss,t + R efficeecy,t + R strtategy,t (5)

[0012] R eficienecy,t = -α × amount of authentication evidence - β × number of authentication methods (6)

[0013] Wherein, R t is the immediate reward value at time t. When authentication is successful, the authentication success reward R succss,t is a positive reward value. When authentication fails, the authentication success reward is a negative reward value; when the authentication strategy is reasonable, the strategy rationality reward R strtategy,t is a positive reward value. When the authentication strategy is unreasonable, the strategy rationality reward is a non - positive reward value; R eficienecy,t is the authentication efficiency reward, and α and β are weight parameters for the amount of authentication evidence and the number of authentication methods respectively.

[0014] Optionally, the set of authentication methods includes identity authentication, and one or more of device authentication, environment authentication, and historical behavior authentication;

[0015] Authenticating the electric vehicle and the charging pile based on the set of authentication methods and the amount of authentication evidence in the authentication strategy includes:

[0016] For each authentication method in the set of authentication methods, allocate the amount of authentication evidence according to a preset allocation ratio;

[0017] Generate authentication evidence for each authentication method according to the amount of authentication evidence allocated to each authentication method;

[0018] Authenticate the electric vehicle and the charging pile according to each authentication method and the corresponding authentication evidence.

[0019] Optionally, the allocation ratio of the identity authentication is a preset ratio value; the allocation ratios of the device authentication, environment authentication, and historical behavior authentication are determined according to the credibility scores of the device physical information, environment information, reputation evaluation information, and historical charging information.

[0020] Optionally, constructing a state space based on the device physical information, environment information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal state includes:

[0021] For the device physical information, environment information, reputation evaluation information, and historical charging information, calculate the credibility score value corresponding to each information according to the information items included in each information and the corresponding weight values;

[0022] Based on the credible score values corresponding to the device physical information, environmental information, reputation evaluation information, and historical charging information respectively, each information item of the historical authentication information, and the current abnormal state, a state space is constructed.

[0023] Optionally, the device physical information includes a device unique identifier, firmware upgrade performance, data storage security performance, and communication security performance; the environmental information includes the vehicle-pile position range, network connection security performance, physical environment security performance, and power supply stability performance; the reputation evaluation information includes the historical evaluation information of the charging pile operator and the historical evaluation information of the charging pile operator for electric vehicles; the historical charging information includes the historical charging information of electric vehicles and the historical charging information of charging piles.

[0024] An embodiment of the present application further provides a continuous identity authentication device for an electric vehicle and a charging pile, including:

[0025] An acquisition module, configured to acquire device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and the current abnormal state;

[0026] A construction module, configured to construct a state space based on the device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and the current abnormal state;

[0027] A decision module, configured to input the states in the state space into a preset authentication decision model, and output an optimal authentication strategy by the authentication decision model;

[0028] An authentication module, configured to, when the authentication strategy is to continue authentication, authenticate the electric vehicle and the charging pile based on the set of authentication methods and the amount of authentication evidence in the authentication strategy.

[0029] Optionally, the authentication decision model selects an optimal authentication strategy based on a Q-value function, and the Q-value function includes an immediate reward, and the immediate reward includes an authentication success reward, an authentication efficiency reward, and a strategy rationality reward; wherein, the authentication efficiency reward is determined according to the number of authentication methods in the set of authentication methods and the amount of authentication evidence.

[0030] Optionally, the immediate reward is expressed as:

[0031] R t =R succss,t +R efficeecy,t +R strtategy,dt (5)

[0032] R eficienecy,t =-α×amount of authentication evidence - β×number of authentication methods (6)

[0033] Wherein, Rt is the immediate reward value at time t. When the authentication is successful, the authentication success reward is R succss,t is the positive reward value. When the authentication fails, the authentication success reward is the negative reward value; when the policy is reasonable, the policy rationality reward is R strtategy,t is the positive reward value. When the policy is unreasonable, the policy rationality reward is the non - positive reward value; R eficienecy,t is the authentication efficiency reward, and α and β are the weight parameters of the amount of authentication evidence and the number of authentication methods.

[0034] Optionally, the authentication method set includes identity authentication, and one or more of device authentication, environment authentication, and historical behavior authentication;

[0035] The authentication module is configured to, for each authentication method in the authentication method set, allocate the amount of authentication evidence according to a preset allocation ratio; generate authentication evidence for each authentication method according to the amount of authentication evidence allocated to each authentication method; and authenticate the electric vehicle and the charging pile according to each authentication method and the corresponding authentication evidence.

[0036] Optionally, the allocation ratio of the identity authentication is a preset ratio value; the allocation ratios of the device authentication, environment authentication, and historical behavior authentication are determined according to the credibility scores of the device physical information, environment information, reputation evaluation information, and historical charging information.

[0037] Optionally, the construction module is configured to, for the device physical information, environment information, reputation evaluation information, and historical charging information, calculate the credibility score values corresponding to each information according to the information items included in each information and the corresponding weight values; and construct a state space based on the credibility score values corresponding to the device physical information, environment information, reputation evaluation information, and historical charging information respectively, the information items of the historical authentication information, and the current abnormal state.

[0038] Optionally, the device physical information includes a device unique identifier, firmware upgrade performance, data storage security performance, and communication security performance; the environment information includes the vehicle - pile position range, network connection security performance, physical environment security performance, and power supply stability performance; the reputation evaluation information includes the historical evaluation information of the charging pile operator and the historical evaluation information of the charging pile operator for the electric vehicle; the historical charging information includes the historical charging information of the electric vehicle and the historical charging information of the charging pile.

[0039] The embodiment of the present application also provides a non - transitory computer - readable storage medium, and the non - transitory computer - readable storage medium stores computer instructions, and the computer instructions are used to make the computer execute the continuous identity authentication method for the electric vehicle and the charging pile.

[0040] An embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the continuous identity authentication method for an electric vehicle and a charging pile as described above is implemented.

[0041] As can be seen from the above, the continuous identity authentication method, device, electronic device, and storage medium for an electric vehicle and a charging pile provided by the embodiments of the present application obtain device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal states, construct a state space based on the device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal states, input the states in the state space into a preset authentication decision model, and the authentication decision model outputs an optimal authentication strategy. When the authentication strategy is to continue authentication, the electric vehicle and the charging pile are authenticated based on the authentication method set and the amount of authentication evidence in the authentication strategy. The present application can achieve continuous and reliable vehicle-pile authentication and improve the data security of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0043] Figure 1 It is a schematic flowchart of the method for the embodiment of the present application;

[0044] Figure 2 It is a schematic flowchart of the method for another embodiment of the present application;

[0045] Figure 3 It is a schematic flowchart of the decision-making process of the authentication decision model for the embodiment of the present application;

[0046] Figure 4 It is a block diagram of the device structure for the embodiment of the present application;

[0047] Figure 5 It is a block diagram of the electronic device structure for the embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] To make the objectives, technical solutions, and advantages of the present disclosure clearer and more understandable, the following further describes the present disclosure in detail with reference to specific embodiments and the accompanying drawings.

[0049] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of this application should have the ordinary meanings understood by those of ordinary skill in the art to which this disclosure belongs. The "first", "second" and similar terms used in the embodiments of this application do not denote any order, quantity or importance, but are only used to distinguish different components. Words such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. Words such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Upper", "lower", "left", "right", etc. are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0050] As described in the background art section, in the charging scenario of an electric vehicle and a charging pile, after they successfully connect for the first time through identity authentication, a long-term session connection will be maintained. When situations such as device loss, abnormal user charging behavior, or abnormal vehicle charging occur, the system will not trigger re-authentication due to the abnormality, resulting in potential data security risks; this identity authentication method cannot adapt to dynamic charging scenarios, will not flexibly adjust the identity authentication strategy according to the actual state of the system, and it is difficult to ensure data security.

[0051] In view of this, the embodiments of this application provide a method for continuous identity authentication between an electric vehicle and a charging pile. During the charging process, the optimal identity authentication strategy can be determined according to the actual state of the system, ensuring high reliability of authentication during the vehicle-pile interaction process, and improving data security by dynamically adjusting the authentication strategy.

[0052] Hereinafter, the technical solution of this application will be further described in detail through specific embodiments.

[0053] As Figure 1 shown, the embodiments of this application provide a method for continuous identity authentication between an electric vehicle and a charging pile, including:

[0054] S101: Obtain device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status;

[0055] In this embodiment, after the initial connection between the electric vehicle and the charging pile, during the charging process, various information of the vehicle and the charging pile, the abnormal status of the system, and the recorded historical authentication information are obtained in real time. The current overall state of the system is determined by combining the various information, and a suitable authentication decision is determined based on the current overall state.

[0056] In some embodiments, the device physical information covers the basic attributes and technical characteristics of vehicles and charging pile devices, reflecting the hardware and communication security. The device physical information includes the device unique identifier, firmware upgrade performance, data storage security performance, communication security performance, etc.; among them, the device unique identifier is used to verify the identity legality of vehicles and charging piles, the communication security performance records whether it supports encryption transmission protocols (e.g., SSL, TLS), the firmware upgrade performance records whether it supports online upgrade to repair vulnerabilities, and the data storage security performance records whether the stored sensitive information is encrypted and protected.

[0057] The environmental information covers factors such as the locations of vehicles and charging piles, network stability and security, reflecting the reliability and security of the communication network. The environmental information includes the vehicle-pile location range, network connection security performance, physical environment security performance, power supply stability performance, etc.; among them, the vehicle-pile location range includes whether the location between the vehicle and the charging pile is within the normal range, the network connection security performance includes whether the networks where the vehicle and the charging pile are located are encrypted and whether there are public network risks, the physical environment security performance includes whether the charging pile is located in a legally recorded charging place, and the power supply stability performance includes whether the current area can provide stable power supply.

[0058] The credit evaluation information includes the historical evaluation information of electric vehicle users on charging pile operators and the historical evaluation information of charging pile operators on electric vehicle users; the historical evaluation information of electric vehicle users on charging pile operators includes the service scores of users on charging pile operators, the historical scores of the current charging pile, etc.

[0059] The historical charging information includes the historical charging information of electric vehicles and the historical charging information of charging piles. Among them, the historical charging information of electric vehicles includes the time period of each charge (e.g., 7 am, 10 pm), the geographical location of charging (e.g., residential community, company parking lot, highway service area), the amount of electricity charged each time (in kWh), the number of charging times within a certain period (e.g., charging once a day, charging five times a week, etc.), charging preferences (selected charging pile type, charging function, location habit, etc.), the duration of each charge, the charging time distribution within a certain period (e.g., weekdays or weekends, day or night), etc. The historical charging information of charging piles includes the total number of uses or cumulative operation duration of the charging pile, historical abnormal events (e.g., charging interruption, communication anomaly), whether regular maintenance or emergency repair is completed as planned, the ratio of the number of faults occurring within a certain period to the total number of uses, etc.

[0060] The historical authentication information is used to record the authentication-related results in the historical authentication process. The historical authentication information includes the authentication result of whether the last authentication was successful, the number of authentication evidences provided in each authentication, the accuracy rate of answering reserved questions during the authentication process, etc.

[0061] The current abnormal state is used to record whether there is an abnormality during the interaction between the charging vehicle and the charging pile, and if there is an abnormality, the severity of the abnormality.

[0062] S102: Construct a state space based on device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and the current abnormal state;

[0063] In this embodiment, after obtaining various pieces of information, a state space is constructed based on the various pieces of information, so that the authentication decision model determines an authentication strategy that conforms to the overall current system state based on the states in the state space.

[0064] In some ways, the method of constructing the state space includes:

[0065] For device physical information, environmental information, reputation evaluation information, and historical charging information, according to the information items included in each piece of information and the corresponding weight values, calculate the credible score values corresponding to each piece of information;

[0066] Based on the credible score values respectively corresponding to the device physical information, environmental information, reputation evaluation information, and historical charging information, each information item of the historical authentication information, and the current abnormal state, a state space is formed.

[0067] Specifically, for device physical information, environmental information, reputation evaluation information, and historical charging information, the method of calculating the credible score value is:

[0068]

[0069] where, V i is the i-th piece of information, that is, one of the device physical information, environmental information, reputation evaluation information, and historical charging information, x j is the j-th information item of the i-th piece of information. For example, the device unique identifier item in the device physical information, w j is the weight value of the j-th information item, and n is the number of information items.

[0070] After calculating the credible score values of each piece of information according to formula (1), a multi-dimensional score vector S K =(V1, V2, V3, V4) is formed by the credible score values of each piece of information, and the range of the credible score values of each piece of information is 0 - 100.

[0071] Construct a historical authentication vector H=(h1, h2, h3,..., h p ) according to each information item of the historical authentication information, where, h pis the p-th information item of the historical authentication information, where p is the number of information items of the historical authentication information. After each authentication, the historical authentication information needs to be updated according to the authentication result of this authentication, that is, the historical authentication information of the (t - 1)-th round is updated according to the authentication result of the t-th round, expressed as:

[0072] H t = update(H t-1 , authentication result) (2)

[0073] The current abnormal state includes the absence of abnormality or the severity of the abnormality, expressed as:

[0074]

[0075] Among them, a minor abnormality is, for example, an occasional communication timeout, a moderate abnormality is, for example, a certain number of communication timeouts, and a severe abnormality is, for example, multiple verification failures or the device being unable to communicate.

[0076] The state space S = [S K , H, E] is composed of the multi-dimensional scoring vector, historical authentication vector, and vector form of the current abnormal state corresponding to the device physical information, environmental information, reputation evaluation information, and historical charging information.

[0077] S103: Input the state in the state space into a preset authentication decision model, and the authentication decision model outputs the optimal authentication strategy;

[0078] In this embodiment, the authentication decision model selects the optimal authentication strategy based on the Q-value function. The Q-value function includes an immediate reward, and the immediate reward includes an authentication success reward, an authentication efficiency reward, and a strategy rationality reward; among them, the authentication efficiency reward is determined according to the number of authentication methods in the authentication method set and the amount of authentication evidence.

[0079] Specifically, as Figure 2 , 3 shown, the Q-value function Q(S, A) is used to evaluate the value of different actions according to the current state S, and select the action that can maximize the long-term benefit in the current state, expressed as:

[0080]

[0081] Among them, R t is the immediate reward obtained at time t, reflecting the direct benefit of the current state and action combination; γ max A′ Q(S′, A′) is the future benefit, indicating the maximum cumulative reward that may be obtained in the future after the model executes the current action A and causes the state to transfer to the next S′. A′ is all possible actions in the next state S′, and γ is the discount factor, used to weigh the influence of the immediate reward and the future benefit, 0 ≤ γ ≤ 1.

[0082] In some ways, the immediate reward provides direct positive or negative feedback for the current action, helping the model judge the effect of the decision-making, and can provide basic data for optimizing the authentication decision model to ensure that the model can adjust the decision-making direction in a timely manner. The immediate reward is expressed as:

[0083] R t = R succss,t + R efficeecy,t + R strtategy,t (5)

[0084] Among them, when the authentication is successful, the authentication success reward R succss,t is a positive reward value. When the authentication fails, the authentication success reward is a negative reward value; when the authentication strategy is reasonable, the strategy rationality reward R strtategy,t is a positive reward value. When the authentication strategy is unreasonable, the strategy rationality reward is a non-positive reward value; R eficienecy,t is the authentication efficiency reward, which is set according to the resource consumption to improve the authentication efficiency and can be expressed as:

[0085] R eficienecy,t = -α × the amount of authentication evidence - β × the number of authentication methods (6)

[0086] Among them, α and β are the weight parameters of the amount of authentication evidence and the number of authentication methods.

[0087] The authentication success reward R succss,t can be expressed as:

[0088]

[0089] Among them, λ is the reward intensity for successful or failed authentication.

[0090] The strategy rationality reward R strtategy,t can be expressed as:

[0091]

[0092] Among them, θ is the reward value for reasonable authentication strategy. If the authentication strategy is unreasonable, no reward will be given. According to the application scenario and actual requirements, corresponding strategy rationality rules can be set. For example, during the continuous charging process of an electric vehicle and a charging pile, when the credible score values of device physical information, environmental information, credit evaluation information, and / or historical charging information are relatively low, the amount of authentication evidence in the authentication strategy should be larger, that is, a larger number of authentication evidences need to be supplemented. When the credible score values of each piece of information are relatively high, the amount of authentication evidence in the authentication strategy can be smaller, that is, a smaller number of authentication evidences can be supplemented.

[0093] In some embodiments, the authentication decision-making model is iteratively updated through a reinforcement learning algorithm. The update process includes: in the current state S, the model selects an action A according to the policy network and executes it. After executing the action A, the system transfers to the next state S′, and at the same time, the immediate reward R is calculated. t ; Update the Q-value function according to the next state S′ and future rewards:

[0094]

[0095] where α is the learning rate, which is used to control the update pace.

[0096] Through multiple rounds of iterative updates, the Q-value function gradually approaches the optimal value, and the long-term rewards corresponding to each action are obtained. After the model evaluates the actions through the Q-value function, it adopts a greedy strategy to select the optimal action in the current state, which is expressed as:

[0097]

[0098] According to formula (10), select the action A with the largest Q-value in the current state as the optimal authentication policy in the current state.

[0099] In some embodiments, the optimal action output by the authentication decision-making model, that is, the optimal authentication policy, includes whether to continue authentication A conimine , the set of authentication methods A mothod and the amount of authentication evidence A num . When the authentication policy includes continuing authentication, the set of authentication methods, and the amount of authentication evidence, it means that in the current state of the system, it is necessary to authenticate the identities of the vehicle and the charging pile, and the authentication should be carried out according to the authentication methods and the amount of authentication evidence in the set of authentication methods; when the authentication policy only includes not needing to continue authentication (or passing the authentication), it means that in the current state of the system, it is not necessary to authenticate the identities of the vehicle and the charging pile, and this round of continuous authentication process can be ended, which is expressed as:

[0100]

[0101] In some ways, the set of authentication methods includes identity authentication, and one or more of device authentication, environment authentication, and historical behavior authentication. The set can be represented as A metotod∈{Identity authentication, device authentication, environment authentication, historical behavior authentication}. Among them, identity authentication is used to verify the identity of the vehicle charging pile, and identity verification is required for each verification; device authentication is used to authenticate the hardware performance and communication security of the vehicle charging pile. When the trust score of the device physical information is relatively low, device authentication is required; environment authentication is used to verify the safety of the operating environment of the vehicle charging pile. When the trust score of the environment information is relatively low, environment authentication is required; historical behavior authentication is used to verify the reliability of the vehicle and the charging pile through the historical evaluation and charging behavior records of the vehicle charging pile. When the trust score of the reputation evaluation information or historical charging information is relatively low, historical behavior authentication is required. It can be seen that the authentication decision model is based on the overall state of the current system, and preferentially verifies the necessary and relatively high-risk information to ensure system security.

[0102] In some ways, the amount of authentication evidence is used to control the complexity of identity authentication, denoted as A num ∈{1, 2, …, N max}, N max is the upper limit of the amount of authentication evidence, which can be dynamically adjusted according to the current state to ensure that the authentication intensity matches the risk level of the current system state.

[0103] S104: When the authentication policy is to continue authentication, authenticate the electric vehicle and the charging pile based on the set of authentication methods and the amount of authentication evidence.

[0104] In this embodiment, when the authentication decision model determines that continued authentication is required in combination with the overall state of the system, it is necessary to authenticate the vehicle charging pile according to the authentication methods and the amount of authentication evidence in the authentication policy. The method includes:

[0105] For each authentication method in the set of authentication methods, allocate the amount of authentication evidence according to a preset allocation ratio;

[0106] Generate the authentication evidence for each authentication method according to the allocated amount of authentication evidence for each authentication method;

[0107] Authenticate the electric vehicle and the charging pile according to each authentication method and the corresponding authentication evidence.

[0108] In this embodiment, the set of authentication methods includes identity authentication and one or several of device authentication, environment authentication, and historical behavior authentication. That is, as long as authentication is required, identity authentication is required to confirm the identity of the vehicle charging pile main body, and on this basis, other authentication methods are selected for authentication. For each authentication method in the set, allocate the amount of authentication evidence according to a certain allocation ratio, so as to generate the authentication evidence for the corresponding authentication method according to the allocated amount of authentication evidence, and authenticate the vehicle and the charging pile according to the authentication method and the corresponding authentication evidence.

[0109] In some embodiments, the allocation ratio of identity authentication is a preset ratio value; the allocation ratios of device authentication, environment authentication, and historical behavior authentication are determined according to the trust scores of device physical information, environment information, reputation evaluation information, or historical charging information. Or rather, the amount of authentication evidence for identity authentication is allocated according to a fixed allocation ratio, and the amount of authentication evidence for other authentication methods is allocated according to the trust score values of various information.

[0110] Among them, for the identity authentication method, according to the fixed allocation ratio W identity The allocated amount of authentication evidence is expressed as:

[0111] Q identity = [W identity ·A num (12)

[0112] The allocation ratio W identity has a value range of (0, 1), and the specific value can be set according to the specific application scenario and actual requirements. V thres

[0113] For the allocation ratios of device authentication, environment authentication, and historical behavior authentication, they are determined according to the trust score values of device physical information, environment information, reputation evaluation information, and historical charging information. The calculation method is:

[0114]

[0115] Among them, W i ′ is the initial allocation ratio of the authentication evidence amount for the i-th authentication method, V max is the maximum value in the trust score values, ∈ is a preset minimum weight value used to ensure that the denominator and numerator are always non-zero, V thresh is a preset threshold, V i is the trust score of the i-th item of information corresponding to the i-th authentication method, N is the number of authentication methods. For the historical behavior authentication method, V i is the trust score of the reputation evaluation information V 信誉 and the trust score of the historical charging information V 历史充电 The weighted sum is expressed as:

[0116] V i = W 信誉 ·V 信誉 + W 历史充电 ·V 历史充电 (14)

[0117] Among them, W 信誉 、W 历史充电 are respectively the weights of the trust score of the reputation evaluation information and the trust score of the historical charging information, W 信誉 + W历史充电 = 1.

[0118] Normalize the initial allocation ratio to within the remaining allocation ratio, expressed as:

[0119] W i = W i ′·(1 - W idcntity + ∈) (15) Obtain the authentication evidence quantity for the i-th authentication method as:

[0120] Q i = W i ·A num (16)

[0121] In some embodiments, according to the authentication evidence quantities allocated to each authentication method, generate the authentication evidence for each authentication method, including:

[0122] According to the authentication evidence quantity in the authentication policy, correct the authentication evidence quantities allocated to each authentication method;

[0123] Generate the corresponding authentication evidence according to the corrected authentication evidence quantities of each authentication method.

[0124] In this embodiment, after determining the authentication evidence quantities of various authentication methods, it is necessary to correct the allocated authentication evidence quantities. The specific method is to calculate the sum of the allocated authentication evidence quantities and judge whether it is consistent with the authentication evidence quantity in the authentication policy. If it exceeds the authentication evidence quantity in the authentication policy, reduce the authentication evidence quantity corresponding to the information with a high trust score until the sum of the authentication evidence quantities is consistent with the quantity. If it does not reach the authentication evidence quantity in the authentication policy, increase the authentication evidence quantity corresponding to the information with a low trust score until it is consistent with the quantity.

[0125] After correcting the authentication evidence quantities allocated to each authentication method, generate the corresponding authentication evidence according to the corrected authentication evidence quantities of each authentication method. Among them, the authentication evidence corresponding to the identity authentication method includes dynamic passwords, biometric verification information (fingerprint, face recognition, etc.), reserved question verification, etc.; the authentication evidence corresponding to the device authentication method includes unique identifier verification, device model verification, device brand verification, etc., and the authentication evidence corresponding to the environment authentication method includes geographical location verification (e.g., verifying the charging pile number), network environment verification (e.g., whether it is a public network), etc., and the authentication evidence corresponding to the historical behavior authentication method includes historical authentication time, historical charging location verification, historical charging frequency verification, historical usage anomaly verification, etc.

[0126] In some embodiments, if the authentication policy determined by the authentication decision model is continuous authentication, after the system authenticates the vehicle charger according to the authentication method and corresponding authentication evidence, a corresponding authentication result is generated, and the authentication result generated in this round is fed back to the model as the basis for the model to make the next round of authentication decisions.

[0127] In some embodiments, if the authentication policy is continuous authentication and the system fails to verify the vehicle charger, the system will re-obtain the latest information and use the authentication decision model to make an authentication policy decision based on the latest information until the authentication is successful or other termination conditions for authentication are met.

[0128] In some embodiments, when an electric vehicle makes an initial connection to a charging pile, digital signature-based identity verification is performed using various unique identity identifiers. The specific process is as follows:

[0129] The vehicle uses its private key K car_priv to perform a hash operation on the vehicle identification number to generate a hash value H car , and uses the private key to generate a digital signature S for the hash value car , expressed as:

[0130] H car = Hash(VIN) (17)

[0131] S car = Sign(H car ,K car_priv )(18)

[0132] The vehicle sends the hash value H of the vehicle identification number car and the digital signature S car to the charging pile together. After receiving the hash value H of the vehicle car and the signature S car , the charging pile uses the public key K of the vehicle car_pub to verify the signature, expressed as:

[0133] Verify(H car ,S car ,K car_pub )(19)

[0134] If the verification is successful, the charging pile can confirm that the vehicle identification code indeed comes from a legitimate vehicle. The charging pile uses its private key K chargrer_priv to perform a hash operation on its device ID (or the unique identifier of the charging pile) to generate a hash value H charger , and then uses the private key K charger_priv to generate a digital signature S for this hash value charger , expressed as:

[0135] H charger= Hash(ID charger ) (20)

[0136] S charger = Sign(H charger , K charger_priv ) (21)

[0137] The charging pile sends the hash value H of the device ID chrargr and the digital signature S charger to the vehicle together. After the vehicle receives the hash value H charger of the charging pile and the signature S charger , it uses the public key K charger_pub of the charging pile to verify the signature, which is expressed as:

[0138] Verify(H charger , S chargrer , K charger_pub )(22)

[0139] If the verification is successful, the vehicle can confirm the identity of the charging pile. After that, during the charging process between the vehicle and the charging pile, the current state of the system is continuously detected according to the method of this application, and the optimal authentication strategy suitable for the current state is determined by using the authentication decision model. By dynamically selecting appropriate authentication methods and the amount of authentication evidence, the authentication strength matching the current state is determined. The system authenticates the vehicle and the charging pile according to the optimal authentication strategy, which can achieve continuous and reliable vehicle-charging pile authentication and improve the data security of the system. The authentication decision model continuously evaluates and adjusts the authentication strategy according to the current state, which can realize the continuous optimization of the authentication strategy and ensure the security and efficiency of the authentication process.

[0140] It should be noted that the method of the embodiment of this application can be executed by a single device, such as a computer or a server, etc. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In this case of a distributed scenario, one of these multiple devices can only execute one or more steps of the method of the embodiment of this application, and these multiple devices will interact with each other to complete the described method.

[0141] It should be noted that the specific embodiments of this specification have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be executed in a different order from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0142] Such as Figure 4As shown in the figure, an embodiment of the present application provides a continuous identity authentication device for an electric vehicle and a charging pile, including:

[0143] An acquisition module, configured to acquire device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status;

[0144] A construction module, configured to construct a state space based on the device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status;

[0145] A decision-making module, configured to input the states in the state space into a preset authentication decision-making model, and output an optimal authentication strategy by the authentication decision-making model;

[0146] An authentication module, configured to authenticate the electric vehicle and the charging pile based on the authentication method set and the amount of authentication evidence when the authentication strategy is to continue authentication.

[0147] In some embodiments, the authentication decision-making model selects the optimal authentication strategy based on the Q-value function, and the Q-value function includes an immediate reward, and the immediate reward includes an authentication success reward, an authentication efficiency reward, and a strategy rationality reward; wherein, the authentication efficiency reward is determined according to the number of authentication methods in the authentication method set and the amount of authentication evidence.

[0148] In some embodiments, the immediate reward is expressed as:

[0149] R t =R succss,t +R efficeecy,t +R strtategy,t (5)

[0150] R eficienecy,t =-α×amount of authentication evidence - β×number of authentication methods (6)

[0151] Wherein, R t is the immediate reward value at time t. When the authentication is successful, the authentication success reward R succss,t is a positive reward value. When the authentication fails, the authentication success reward is a negative reward value; when the strategy is reasonable, the strategy rationality reward R strtategy,t is a positive reward value. When the strategy is unreasonable, the strategy rationality reward is a non-positive reward value; R eficienecy,t is the authentication efficiency reward, and α and β are weight parameters of the amount of authentication evidence and the number of authentication methods.

[0152] In some embodiments, the authentication method set includes identity authentication, and one or more of device authentication, environmental authentication, and historical behavior authentication;

[0153] An authentication module, which is configured to allocate authentication evidence amounts for each authentication method in the set of authentication methods according to a preset allocation ratio; generate authentication evidence for each authentication method according to the allocated authentication evidence amounts of each authentication method; and authenticate the electric vehicle and the charging pile according to each authentication method and the corresponding authentication evidence.

[0154] In some embodiments, the allocation ratio of identity authentication is a preset ratio value; the allocation ratios of device authentication, environment authentication, and historical behavior authentication are determined according to the trust scores of device physical information, environment information, reputation evaluation information, and historical charging information.

[0155] In some embodiments, a construction module is configured to calculate the trust score values corresponding to each information according to the information items included in each information and the corresponding weight values for device physical information, environment information, reputation evaluation information, and historical charging information; and construct a state space based on the trust score values respectively corresponding to the device physical information, environment information, reputation evaluation information, and historical charging information, each information item of the historical authentication information, and the current abnormal state.

[0156] In some embodiments, the device physical information includes a device unique identifier, firmware upgrade performance, data storage security performance, and communication security performance; the environment information includes the vehicle-pile position range, network connection security performance, physical environment security performance, and power supply stability performance; the reputation evaluation information includes the historical evaluation information of the charging pile operator and the historical evaluation information of the charging pile operator for the electric vehicle; and the historical charging information includes the historical charging information of the electric vehicle and the historical charging information of the charging pile.

[0157] For the convenience of description, the above device is described by dividing it into various modules according to functions. Of course, when implementing the embodiments of the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0158] The device in the above embodiments is used to implement the corresponding method in the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated herein.

[0159] Figure 5 FIG. shows a more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.

[0160] The processor 1010 can be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an Application Specific Integrated Circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.

[0161] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1020 and called and executed by the processor 1010.

[0162] The input / output interface 1030 is used to connect to the input / output module to achieve information input and output. The input / output module can be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device can include a display, a speaker, a vibrator, an indicator light, etc.

[0163] The communication interface 1040 is used to connect to a communication module (not shown in the figure) to achieve communication interaction between this device and other devices. Among them, the communication module can achieve communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.).

[0164] The bus 1050 includes a path for transmitting information between various components of the device (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).

[0165] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, this device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solutions of the embodiments of this specification, and does not necessarily include all the components shown in the figure.

[0166] The electronic device in the above embodiments is used to implement the corresponding method in the foregoing embodiments and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.

[0167] The computer-readable medium of this embodiment includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transitory medium that can be used to store information accessible by a computing device.

[0168] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples; within the context of the present disclosure, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of brevity.

[0169] In addition, for simplicity of explanation and discussion, and so as not to make the embodiments of the present application difficult to understand, known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that details regarding the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application will be implemented (i.e., these details should be entirely within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present disclosure, it will be apparent to those skilled in the art that the embodiments of the present application can be implemented without these specific details or with variations of these specific details. Accordingly, these descriptions should be considered illustrative rather than restrictive.

[0170] Although the present disclosure has been described in connection with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.

[0171] Embodiments of the present application are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the embodiments of the present application shall be included within the scope of protection of the present disclosure.

Claims

1. Method for continuous identity authentication of electric vehicle and charging pile, characterized in that, Including: Obtain device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status; Construct a state space based on the device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status; Input the states in the state space into a preset authentication decision model, and output the optimal authentication strategy by the authentication decision model; When the authentication strategy is to continue authentication, authenticate the electric vehicle and the charging pile based on the authentication method set and the amount of authentication evidence in the authentication strategy.

2. The method according to claim 1, wherein The authentication decision model selects the optimal authentication strategy based on the Q-value function, and the Q-value function includes an immediate reward, and the immediate reward includes an authentication success reward, an authentication efficiency reward, and a strategy rationality reward; wherein, the authentication efficiency reward is determined according to the number of authentication methods in the authentication method set and the amount of authentication evidence.

3. The method according to claim 2, wherein The immediate reward is expressed as: R t = R succss,t + R efficeecy,t + R strtategy,t (5) R eficienecy,t = -α × Quantity of authentication evidence - β × Quantity of authentication methods (6) Among them, R t is the immediate reward value at time t. When the authentication is successful, the authentication success reward R succss,t is a positive reward value. When the authentication fails, the authentication success reward is a negative reward value; when the authentication strategy is reasonable, the strategy rationality reward R strtategy,t is a positive reward value. When the authentication strategy is unreasonable, the strategy rationality reward is a non-positive reward value; R eficienecy,t is the authentication efficiency reward, and α and β are the weight parameters of the amount of authentication evidence and the number of authentication methods.

4. The method according to claim 1, characterized in that, The authentication method set includes identity authentication, and one or more of device authentication, environmental authentication, and historical behavior authentication; Authenticating the electric vehicle and the charging pile based on the authentication method set and the amount of authentication evidence in the authentication strategy includes: For each authentication method in the authentication method set, allocate the amount of authentication evidence according to a preset allocation ratio; Generate authentication evidence for each authentication method according to the amount of authentication evidence allocated to each authentication method; Authenticate the electric vehicle and the charging pile according to each authentication method and the corresponding authentication evidence.

5. The method according to claim 4, characterized in that, The allocation ratio of the identity authentication is a preset ratio value; the allocation ratios of the device authentication, environmental authentication, and historical behavior authentication are determined according to the credibility scores of the device physical information, environmental information, reputation evaluation information, and historical charging information.

6. The method according to claim 1, wherein Constructing a state space based on the device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status includes: For the device physical information, environmental information, reputation evaluation information, and historical charging information, calculate the credibility score values corresponding to each information according to the information items included in each information and the corresponding weight values; Construct a state space based on the credibility score values corresponding to the device physical information, environmental information, reputation evaluation information, and historical charging information respectively, the information items of the historical authentication information, and the current abnormal status.

7. The method according to any one of claims 1-6, characterized in that, The device physical information includes a device unique identifier, firmware upgrade performance, data storage security performance, and communication security performance; the environmental information includes the vehicle-pile position range, network connection security performance, physical environment security performance, and power supply stability performance; the reputation evaluation information includes the historical evaluation information of the charging pile operator and the historical evaluation information of the charging pile operator for the electric vehicle; the historical charging information includes the historical charging information of the electric vehicle and the historical charging information of the charging pile.

8. Electric vehicle and charging pile continuous identity authentication device, characterized in that, Including: An acquisition module for acquiring device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal status; A construction module, configured to construct a state space based on the device physical information, environmental information, reputation evaluation information, historical charging information, historical authentication information, and current abnormal state; A decision-making module, configured to input the states in the state space into a preset authentication decision-making model, and output an optimal authentication strategy by the authentication decision-making model; An authentication module, configured to authenticate the electric vehicle and the charging pile based on the set of authentication methods and the amount of authentication evidence in the authentication strategy when the authentication strategy is to continue authentication.

9. The device according to claim 8, characterized in that, The authentication decision-making model selects an optimal authentication strategy based on a Q-value function, and the Q-value function includes an immediate reward, and the immediate reward includes an authentication success reward, an authentication efficiency reward, and a strategy rationality reward; wherein, the authentication efficiency reward is determined according to the number of authentication methods in the set of authentication methods and the amount of authentication evidence.

10. The device according to claim 9, characterized in that, The immediate reward is expressed as: R t = R succss,t + R efficeecy,t + R strtategy,t (5) R eficienecy,t = -α × amount of authentication evidence - β × number of authentication methods (6) Among them, R t is the instant reward value at time t. When the authentication is successful, the authentication success reward R succss,t is a positive reward value. When the authentication fails, the authentication success reward is a negative reward value; when the strategy is reasonable, the strategy rationality reward R strtategy,t is a positive reward value. When the strategy is unreasonable, the strategy rationality reward is a non-positive reward value; R eficienecy,t is the authentication efficiency reward, and α and β are the weight parameters of the amount of authentication evidence and the number of authentication methods.

11. The device according to claim 8, characterized in that, The set of authentication methods includes identity authentication, and one or more of device authentication, environmental authentication, and historical behavior authentication; The authentication module is configured to, for each authentication method in the set of authentication methods, allocate the amount of authentication evidence according to a preset allocation ratio; generate authentication evidence for each authentication method according to the amount of authentication evidence allocated to each authentication method; and authenticate the electric vehicle and the charging pile according to each authentication method and the corresponding authentication evidence.

12. The device according to claim 11, characterized in that The allocation ratio of the identity authentication is a preset ratio value; the allocation ratios of the device authentication, environmental authentication, and historical behavior authentication are determined according to the credibility scores of the device physical information, environmental information, reputation evaluation information, and historical charging information.

13. The device according to claim 8, wherein The construction module is configured to, for the device physical information, environmental information, reputation evaluation information, and historical charging information, calculate the credibility score values corresponding to the information according to the information items included in each information and the corresponding weight values; and construct a state space based on the credibility score values respectively corresponding to the device physical information, environmental information, reputation evaluation information, and historical charging information, the information items of the historical authentication information, and the current abnormal state.

14. The device according to any one of claims 8-13, characterized in that, The device physical information includes a device unique identifier, firmware upgrade performance, data storage security performance, and communication security performance; the environmental information includes the vehicle-pile position range, network connection security performance, physical environment security performance, and power supply stability performance; the reputation evaluation information includes the historical evaluation information of the charging pile operator and the historical evaluation information of the charging pile operator for the electric vehicle; the historical charging information includes the historical charging information of the electric vehicle and the historical charging information of the charging pile.

15. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause the computer to execute the method according to any one of claims 1 to 7.

16. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 7.