BMS upper computer system identity authentication method based on network security and BMS upper computer system

By using the elliptic curve algorithm to generate keys and introducing a revocation mechanism in the BMS host computer system, the anonymity and unlinkability problems are solved, the system security and the effectiveness of user identity authentication are enhanced, and user privacy and data security are protected.

CN120455136APending Publication Date: 2025-08-08HEFEI GUOXUAN HIGH TECH POWER ENERGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510773482.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing BMS host computer systems have threats in terms of data privacy and security, especially anonymity and unlinkability, and lack effective malicious user revocation mechanisms.

Method used

The elliptic curve algorithm is used to generate the master key and public key, verify the user's identity through the gateway and generate a password, establish a session key, and introduce a revocation mechanism to deal with malicious users, encrypt the user's identity with random numbers and authenticate through open channels.

Benefits of technology

It realizes anonymity and unlinkable message, enhances the security of the system, and effectively revokes malicious users, protects user privacy and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455136A_ABST
    Figure CN120455136A_ABST
Patent Text Reader

Abstract

The invention discloses a BMS upper computer system identity authentication method based on network security and a BMS upper computer system. The method comprises the following steps: generating a master key and a public key of the BMS upper computer system and a public key and a private key of a user based on an elliptic curve algorithm; a user registers by adopting a real identity, and a gateway verifies whether the identity of the user is valid based on a master key and a public key of a BMS upper computer system and generates a password for the user; when a user logs in, the gateway performs user identity authentication, and establishes a session key after successful authentication. According to the method, the random number is generated through the gateway to encrypt the real identity of the user, so that anonymity is realized; according to the scheme, the security requirements of anonymity, non-linkability, revocable and the like are met, and the method is safer and more suitable for the upper computer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security and privacy protection of a host computer, and in particular to a BMS host computer system identity authentication method based on network security and a BMS host computer system. Background Art

[0002] With the rapid development of internet technology, BMS (Battery Management System) computers, as a model for the application of next-generation technologies, play a crucial role in promoting intelligent energy management. During BMS operation, users can leverage a variety of information sensing methods to achieve real-time information exchange between battery packs and between battery packs and users. This feature has led to widespread application of BMS computers in a variety of fields, including green energy management, remote monitoring, intelligent traffic scheduling, smart home integration, and urban energy planning.

[0003] Regardless of their location, users can monitor the battery pack's operating status at any time through the BMS host computer, including key information such as power level, temperature, and health. They can also remotely control the battery pack, such as adjusting charging strategies and optimizing discharge patterns. This not only greatly improves the convenience of energy management, but also provides strong support for achieving efficient energy utilization and sustainable development.

[0004] However, with the increasing adoption of BMS host computers, data privacy and security issues are becoming increasingly prominent. Due to security vulnerabilities in the transmission channels within the IoT, unauthorized users could illegally access sensor data, posing a serious threat to system stability and user privacy. Consequently, a growing number of researchers are turning their attention to privacy protection technologies for BMS host computers, developing conditional user authentication schemes to ensure that only authorized users can access and operate the system, effectively safeguarding data privacy and security. These efforts not only provide a solid security foundation for the widespread adoption of BMS host computers but also inject new vitality into the intelligent development of energy management.

[0005] Patel et al. proposed an efficient, reliable, lightweight remote user authentication scheme using mutually authenticated key exchange for a user-gateway model. They formally analyzed the proposed scheme using Dolev-Yao channels and employed BAN logic to provide mutual authentication. However, we found that the scheme did not achieve anonymity and unlinkability. Summary of the Invention

[0006] The purpose of the present invention is to provide a BMS host computer system identity authentication method and a BMS host computer system based on network security, so as to protect the security and privacy of the BMS host computer in the Internet of Things system in a safer and more effective way.

[0007] In order to achieve the above object, the technical solution adopted by the present invention is as follows:

[0008] In a first aspect, the present invention provides a BMS host computer system identity authentication method based on network security, wherein the BMS host computer system includes a gateway, a node, and a user, and the method includes:

[0009] Generate the master key and public key of the BMS host system, as well as the user's public key and private key based on the elliptic curve algorithm;

[0010] The user registers with their real identity, and the gateway verifies the validity of the user's identity based on the master key and public key of the BMS host system and generates a password for the user;

[0011] When a user logs in, the gateway performs user identity authentication and establishes a session key after successful authentication.

[0012] Preferably, the generation of the master key and public key of the BMS host system, as well as the public key and private key of the user based on the elliptic curve algorithm includes:

[0013] Gateway random selection and , and calculate and ,in and They are the master key and public key of the BMS host system, and The user's private key and public key respectively. is a set of integers, is a point on the elliptic curve;

[0014] The user's public key and private key are stored in the secret memory of the user's device; the public key of the BMS host system and the user's public key are made public.

[0015] Preferably, the user registers using a real identity, including:

[0016] User input and random integers , and randomly select a number , then calculate:

[0017] ,

[0018] ,

[0019] Then, through the secure channel, , }Sent to the gateway.

[0020] Preferably, the gateway verifies whether the user identity is valid based on the master key and public key of the BMS host computer system and generates a password for the user: including:

[0021] The gateway verifies that the user identity is valid and then calculates:

[0022] ,

[0023] Generate random numbers ,calculate:

[0024] ,

[0025] ,

[0026] ,

[0027] ,

[0028] in, Represents elliptic curve calculation;

[0029] Finally, the gateway generates the password , stored for each user and sent to the user;

[0030] The user will Deposit ,

[0031] .

[0032] Preferably, when the user logs in, the gateway performs user identity authentication, including:

[0033] The user sends a verification message to the gateway to verify whether it is legal. After verification, the gateway sends a verification message to the user to verify whether it is legal.

[0034] If the gateway and the user successfully authenticate each other, the public session key can be obtained.

[0035] Preferably, the user sends a verification message to the gateway to verify whether it is legal, including:

[0036] User input , password, and Insert the card reader, and the card reader calculates:

[0037] , ,

[0038] verify Is it equal to ;

[0039] Then, the gateway's key calculation center calculates:

[0040] ,

[0041] ,

[0042] ,

[0043] ,

[0044] ,

[0045] is a random number, Indicates the user login request time, which is sent to the gateway through an insecure channel. ;

[0046] Upon receiving user information After that, the gateway verifies whether , Indicates a timestamp;

[0047] If the inequality holds, calculate:

[0048] ,

[0049] ,

[0050] ,

[0051] ,

[0052] ,

[0053] and check Is it equal to To verify the authenticity of the user,

[0054] If so, the user is verified to be legitimate.

[0055] Preferably, after the verification is legal, the gateway sends a verification message to the user to verify whether it is legal, including:

[0056] After the gateway verifies that the user is legitimate, it randomly generates a and the current timestamp ;

[0057] calculate:

[0058] ,

[0059] ,

[0060] ,

[0061] The gateway sends the data to the user through the open channel. ;

[0062] After receiving the broadcast message, the user first passes the verification To check the freshness of the message;

[0063] If the inequality holds, calculate ,

[0064] as well as, ,

[0065] examine Is it true? If the equality is true, the user identity authentication is successful and the session key is successfully established.

[0066] Preferably, the method further comprises, after the communication between the two parties is completed, updating the key before the next communication,

[0067] The key update includes:

[0068] The user will Insert the card into the reader and enter your personal credentials including: and random numbers ;

[0069] Gateway's key calculation center calculates get ,

[0070] calculate , ,

[0071] examine Is it equal to ;

[0072] If equal, the gateway randomly generates a random number And calculate:

[0073] ,

[0074] ,

[0075] ,

[0076] ;

[0077] Then generate an updated password:

[0078] .

[0079] Preferably, the method further includes a revocation mechanism as follows:

[0080] The gateway creates and records a revocation list. When a malicious user appears, the gateway finds out the user's true identity and records it in the revocation list.

[0081] The gateway will no longer provide key generation services for users in the revocation list, making it impossible for them to establish session keys with the node, thus achieving the revocation of malicious users.

[0082] In a second aspect, the present invention provides a BMS host computer system, which uses the above-mentioned BMS host computer system identity authentication method based on network security to perform user identity authentication and establish a session key.

[0083] Compared with the prior art, the present invention has the following advantages:

[0084] (1) The present invention provides a BMS host computer system identity authentication method based on network security. The method generates a random number through the gateway to encrypt the user's real identity, solving the problems of anonymity and message unlinkability. The method of the present invention is more secure and more suitable for the host computer.

[0085] (2) The present invention also adds a revocation mechanism, which is more effective against malicious users. BRIEF DESCRIPTION OF THE DRAWINGS

[0086] Figure 1 The BMS host computer system architecture provided by the embodiment of the present invention;

[0087] Figure 2 A schematic diagram of the user registration process in the BMS host computer system identity authentication method based on network security provided by an embodiment of the present invention;

[0088] Figure 3 A schematic diagram of the identity authentication and session key establishment phases in the BMS host computer system identity authentication method based on network security provided by an embodiment of the present invention;

[0089] Figure 4 This is a schematic diagram of the password update phase process in the BMS host computer system identity authentication method based on network security provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0090] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments and the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.

[0091] It should also be noted that, in order to avoid obscuring the present invention due to unnecessary details, the accompanying drawings only show structures and / or processing steps closely related to the solutions according to the present invention, while other details that are not closely related to the present invention are omitted.

[0092] It should be emphasized that the term "include / comprises" when used herein refers to the existence of features, elements, steps or components, but does not exclude the existence or addition of one or more other features, elements, steps or components.

[0093] It should also be noted that, unless otherwise specified, the term "connection" herein may refer not only to a direct connection but also to an indirect connection involving an intermediate.

[0094] It should be emphasized here that the step marks mentioned below do not limit the order of the steps, but it should be understood that the steps can be executed in the order mentioned in the embodiment, or in a different order from the embodiment, or several steps can be executed simultaneously.

[0095] The embodiment of the present invention provides a BMS host computer system identity authentication method based on network security, which is applied to the BMS host computer system. The host computer system architecture is shown in FIG. Figure 1 , mainly includes three participants, namely: gateway (GW), node (SN), and user (US).

[0096] Gateway (GW): A universally trusted, authoritative entity within a secure environment. When a new user joins the host system, the gateway verifies the user's identity and then establishes session secrets between the user and the sensor so they can communicate securely. If the gateway detects a user maliciously attacking a device to steal information, it can revoke their identity.

[0097] Node (SN): A sensor is deployed in a specific area or open environment to monitor and collect battery cell voltage, current, and temperature data, which is then transmitted to a gateway via wireless channels. Due to the open nature of wireless channels, these channels are vulnerable to malicious attacks. Sensors have limited computing, storage, and power resources, so the computational and communication costs of sensors should be considered in the design of the solution.

[0098] User (US): After the user passes the authentication of the gateway, he can obtain the real-time data of the target sensor node and perform remote control.

[0099] Based on the above-mentioned host computer system, an embodiment of the present invention provides a BMS host computer system identity authentication method based on network security, including the following contents:

[0100] (1) The host computer system initialization phase includes public parameter generation and user registration.

[0101] (2) The authentication phase between the user and the gateway, including identity authentication and establishment of session keys.

[0102] (3) Password update and revocation phase, including authorized users can update passwords and the gateway can revoke malicious users.

[0103] In the embodiment of the present invention, during the public parameter generation phase, the system is initialized by generating parameters through the gateway. The specific steps are as follows:

[0104] 11) The gateway randomly selects a prime number , and a definition over a finite field Elliptic curve on , and the elliptic curve is a set of equations satisfying All points plus a point O at infinity, where All in finite fields Evaluate above.

[0105] 12) Gateway random selection and , and calculate and ,in and They are the system's master key and public key, and The user's private key and public key respectively. is a set of integers, The system in this embodiment refers to the BMS host computer system.

[0106] 13) The user's public key ( ) and the user's private key ( ) is stored in the secret memory of the user's device; the system's public key ( ) and the user's public key ( ) for public disclosure.

[0107] like Figure 2 As shown, in the embodiment of the present invention, the specific implementation process of user registration includes:

[0108] 21) User Input and random integers , and randomly select a number , then calculate:

[0109] ,

[0110] ,

[0111] Then, through the secure channel, , }Sent to the gateway.

[0112] 22) The gateway verifies that the user identity is valid and then calculates:

[0113] ,

[0114] Generate random numbers ,calculate:

[0115] ,

[0116] ,

[0117] ,

[0118] ,

[0119] in, Represents elliptic curve calculation;

[0120] Finally, the gateway generates , stored for each user and sent to the user.

[0121] 23) The user will Deposit ,

[0122] .

[0123] like Figure 3 As shown, in this embodiment of the present invention, the specific steps of the identity authentication and session key establishment phase are as follows:

[0124] 31) User Input , password, and Insert the card reader, and the card reader calculates:

[0125] , ,

[0126] The card reader then verifies Is it equal to ;

[0127] Then, the SCR (the gateway's key calculation center) calculates:

[0128] ,

[0129] ,

[0130] ,

[0131] ,

[0132] ,

[0133] is a random number, Indicates the user login request time, which is sent to the gateway through an insecure channel. .

[0134] 32) After receiving the user's information After that, the gateway first passes the authentication to check the freshness of the login request, Indicates a timestamp;

[0135] If the above conditions are met, the gateway calculates:

[0136] ,

[0137] ,

[0138] ,

[0139] ,

[0140] ,

[0141] and check Is it equal to To verify the authenticity of the user,

[0142] If true, the gateway will randomly generate a random number and the current timestamp ;

[0143] The gateway also calculates:

[0144] ,

[0145] ,

[0146] ,

[0147] The gateway sends the data to the user through the open channel. .

[0148] 33) After receiving the broadcast message, the user first passes the verification to check the freshness of the message.

[0149] If the inequality holds, the user computes the key: To verify the session key and gateway.

[0150] Then the user calculates and check If the equality holds, the session key is successfully established.

[0151] like Figure 4 As shown, in this embodiment of the present invention, the session key is successfully established and communication is established. After the communication between the two parties ends, the key is updated before the next communication. The specific steps of the password update phase are as follows:

[0152] 41) The user first Insert the card reader and enter personal credentials such as , All are random numbers;

[0153] 42) SCR calculation get ,

[0154] calculate , ,

[0155] examine Is it equal to To verify the authenticity of the user;

[0156] If true, the gateway will randomly generate a And calculate:

[0157] ,

[0158] ,

[0159] ,

[0160] ;

[0161] Then SCR generates an updated password:

[0162] .

[0163] In the embodiment of the present invention, the revocation phase includes:

[0164] The gateway creates and records a revocation list. When a malicious user appears, the gateway finds out the user's true identity and records it in the revocation list.

[0165] The gateway will no longer provide key generation services for users in the revocation list, making it impossible for them to establish session keys with the node, thus achieving the revocation of malicious users.

[0166] Based on the above inventive concept, the present invention further provides a BMS host computer system, which uses the BMS host computer system identity authentication method based on network security of the above embodiment to perform user identity authentication and establish a session key.

[0167] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A BMS host computer system identity authentication method based on network security, wherein the BMS host computer system includes a gateway, a node, and a user, characterized in that: The method comprises: Generate the master key and public key of the BMS host system, as well as the user's public key and private key based on the elliptic curve algorithm; The user registers with their real identity, and the gateway verifies the validity of the user's identity based on the master key and public key of the BMS host system and generates a password for the user; When a user logs in, the gateway performs user identity authentication and establishes a session key after successful authentication.

2. A BMS host computer system identity authentication method based on network security according to claim 1, characterized in that: The elliptic curve algorithm is used to generate the master key and public key of the BMS host system, as well as the public key and private key of the user, including: Gateway random selection and , and calculate and ,in and They are the master key and public key of the BMS host system, and The user's private key and public key respectively. is a set of integers, is a point on the elliptic curve; The user's public key and private key are stored in the secret memory of the user's device; the public key of the BMS host system and the user's public key are made public.

3. A BMS host computer system identity authentication method based on network security according to claim 2, characterized in that: The user registers with a real identity, including: User input and random integers , and randomly select a number , then calculate: , , Then, through the secure channel, , }Sent to the gateway.

4. A BMS host computer system identity authentication method based on network security according to claim 3, characterized in that: The gateway verifies the user's identity based on the master key and public key of the BMS host system and generates a password for the user, including: The gateway verifies that the user identity is valid and then calculates: , Generate random numbers ,calculate: , , , , in, Represents elliptic curve calculation; Finally, the gateway generates the password , stored for each user and sent to the user; The user will Deposit , 。 5. A BMS host computer system identity authentication method based on network security according to claim 4, characterized in that: When the user logs in, the gateway performs user identity authentication, including: The user sends a verification message to the gateway to verify whether it is legal. After verification, the gateway sends a verification message to the user to verify whether it is legal. If the gateway and the user successfully authenticate each other, the public session key can be obtained.

6. A BMS host computer system identity authentication method based on network security according to claim 5, characterized in that: The user sends a verification message to the gateway to verify whether it is legal, including: User input , password, and Insert the card reader, and the card reader calculates: , , verify Is it equal to ; Then, the gateway's key calculation center calculates: , , , , , is a random number, Indicates the user login request time, which is sent to the gateway through an insecure channel. ; Upon receiving user information After that, the gateway verifies whether , Indicates a timestamp; If the inequality holds, calculate: , , , , , and check Is it equal to To verify the authenticity of the user, If so, the user is verified to be legitimate.

7. A BMS host computer system identity authentication method based on network security according to claim 6, characterized in that: After the verification is legal, the gateway sends a verification message to the user to verify whether it is legal, including: After the gateway verifies that the user is legitimate, it randomly generates a and the current timestamp ; calculate: , , , The gateway sends the data to the user through the open channel. ; After receiving the broadcast message, the user first passes the verification To check the freshness of the message; If the inequality holds, calculate , as well as, , examine Is it true? If the equality is true, the user identity authentication is successful and the session key is successfully established.

8. A BMS host computer system identity authentication method based on network security according to claim 7, characterized in that: The method further includes, after the communication between the two parties is completed, updating the key before the next communication, The key update includes: The user will Insert the card into the reader and enter your personal credentials including: and random numbers ; Gateway's key calculation center calculates get , calculate , , examine Is it equal to ; If equal, the gateway randomly generates a random number And calculate: , , , ; Then generate an updated password: 。 9. A BMS host computer system identity authentication method based on network security according to claim 7, characterized in that: The method also includes a revocation mechanism as follows: The gateway creates and records a revocation list. When a malicious user appears, the gateway finds out the user's true identity and records it in the revocation list. The gateway will no longer provide key generation services for users in the revocation list, making it impossible for them to establish session keys with the node, thus achieving the revocation of malicious users.

10. A BMS host computer system, characterized in that: The BMS host computer system identity authentication method based on network security as described in any one of claims 1 to 9 is used to perform user identity authentication and establish a session key.