Networking method, system, medium, product and device of wireless battery management system
By using an initial key to verify signature data in WBMS, and performing two-way authentication between the master node and slave nodes, a network topology that does not require pre-storing the unique identifier of the slave node is realized. This solves the problems of long networking time and low efficiency in WBMS, and improves networking efficiency and security.
Patent Information
- Application Number
- CN202511183258.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2045-08-22
AI Technical Summary
Existing wireless battery management systems (WBMS) require pre-storing unique identifiers for slave nodes when networking, resulting in long networking times, low efficiency, and high costs.
The master and slave nodes pre-store initial keys, verify signature data through keys, and allow slave nodes to actively send unique identifiers to form a network, eliminating the step of pre-storing unique identifiers and ensuring data security through two-way verification.
It simplifies the networking process, improves networking efficiency and security, reduces production costs and time, and ensures the stability and reliability of data transmission.
Smart Images

Figure CN120730349B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of battery management technology, and in particular to a networking method, system, medium, product, and device for a wireless battery management system. Background Technology
[0002] WBMS (Wireless Battery Management System) is an intelligent system for battery management that uses wireless communication to perform functions such as online monitoring, charge / discharge control, and fault detection of batteries. Before using WBMS for wireless battery monitoring, the master and slave nodes in the WBMS need to be networked.
[0003] In related technologies, WBMS networking requires storing the unique identifiers of slave nodes in the master node in advance. This method results in a long networking time and low networking efficiency for WBMS. Summary of the Invention
[0004] This application provides a networking method, system, medium, product, and device for a wireless battery management system, which enables wireless battery management system networking without the need to pre-store the unique identifiers of slave nodes, thereby improving the networking efficiency of the wireless battery management system.
[0005] In a first aspect, embodiments of this application provide a networking method for a wireless battery management system. The wireless battery management system includes a master node and multiple slave nodes. Both the master node and the slave nodes store an initial key. The method includes: the master node signing a first networking request data based on its stored initial key, generating and sending first signature data to each of the multiple slave nodes; each slave node verifying the first signature data based on its stored initial key, and if the verification is successful, sending first response data to the master node, the first response data including a unique identifier for networking with the master node; and the master node responding to the first response data fed back by the slave nodes and networking with the slave node corresponding to the unique identifier.
[0006] In this embodiment, initial keys are pre-stored in both the master and slave nodes. The master and slave nodes use their own initial keys to verify the signature data to determine which slave nodes can participate in the network. After successful verification between the master and slave nodes using the initial keys, the slave node proactively sends its unique identifier to the master node, eliminating the need for the master node to pre-store the slave node's unique identifier. This simplifies the wireless battery management system's networking process and improves its networking efficiency.
[0007] In some embodiments, the first response data further includes second signature data; the networking method of the wireless battery management system further includes: each slave node signing the networking request response data based on its own stored initial key, generating and sending the second signature data to the master node; the master node responding to the first response data fed back by the slave node and networking with the slave node corresponding to the unique identifier includes: the master node verifying the second signature data based on its own stored initial key, and if the verification is successful, networking with the corresponding slave node according to the unique identifier.
[0008] During the networking process of master and slave nodes, bidirectional authentication between the master and slave nodes can ensure that the data has not been tampered with and that the signature data received by each node comes from a legitimate node, thereby enhancing the security of WBMS networking. At the same time, it can also reduce the problem of WBMS networking failure due to data tampering and / or illegitimate nodes, thus improving the networking efficiency of WBMS.
[0009] In some embodiments, the networking method of the wireless battery management system further includes: when the master node determines that it has completed networking with all slave nodes, disabling the networking access function of the master node to prevent unauthorized slave nodes from accessing the network and improve the networking security of WBMS.
[0010] In some embodiments, disabling the network access function of the master node includes: adjusting the working status flag of the master node to a target flag, wherein the target flag is used to instruct the master node to disable the network access function of the master node.
[0011] Controlling the activation and deactivation of the network access function of the master node based on its working status flags can improve the accuracy of network access function control.
[0012] In some embodiments, the networking method of the wireless battery management system further includes: the master node marking the initial key as invalid after determining that all slave nodes have completed networking, and generating and storing a first key, the first key being used for renetworking.
[0013] After the network is set up, the master node can re-establish the network by generating a first key, which can reduce the risk of unauthorized nodes using old keys to access the network and improve the security of the network.
[0014] In some embodiments, the master node determines that a network has been formed with all slave nodes, including: when the master node determines that the network formation end condition has been met, determining that all slave nodes have formed a network, wherein the network formation end condition includes the number of networked slave nodes reaching a preset number.
[0015] The number of slave nodes already in the network can be used to determine whether the network is finished. This allows the master node's network access function to be shut down in a timely manner after the network is completed. This not only reduces the risk of missing slave nodes and improves the rationality of WBMS network formation, but also prevents unauthorized nodes from participating in the network, thus enhancing the security of WBMS network formation.
[0016] In some embodiments, the wireless battery management system further includes a battery management unit, and the networking method of the wireless battery management system further includes: the master node sending a first key to the battery management unit; and the battery management unit storing the first key.
[0017] By sending the first key to the BMU for storage backup, the first key can be retrieved from the BMU when the master node fails and the first key is lost, thus enabling normal data transmission between the master and slave nodes and improving the stability and reliability of WBMS data transmission.
[0018] In some embodiments, the networking method of the wireless battery management system further includes: the master node adds its own unique identifier and the unique identifier of the slave node to the slave node unique identifier list stored by the master node, so that in the next networking, the master node does not need to obtain the unique identifier of the slave node by sending signature data, but directly obtains the unique identifier of the slave node from the slave node unique identifier list, thereby improving the networking efficiency of WBMS.
[0019] In some embodiments, the wireless battery management system further includes a battery management unit, and the networking method of the wireless battery management system further includes: when it is determined that networking with all slave nodes is completed, sending a list of unique identifiers of slave nodes to the battery management unit; the battery management unit stores the list of unique identifiers of slave nodes to back up the unique identifiers of the master node itself and the unique identifiers of the slave nodes, so as to correct the unique identifier list of slave nodes locally on the master node after the master node malfunctions and its own unique identifier and / or the unique identifiers of the slave nodes are lost or illegally tampered with, thereby ensuring the security of the WBMS networking.
[0020] In some embodiments, the networking method of the wireless battery management system further includes: if the first slave node fails after networking, the master node signs the second networking request data based on the first key, generates and sends the third signature data to the second slave node; the second slave node stores the first key; the second slave node verifies the third signature data based on its stored first key, and if the verification is successful, sends the second response data to the master node, the second response data including a unique identifier for networking with the master node; the master node responds to the first response data fed back by the slave node and networks with the second slave node.
[0021] When a slave node fails, a new slave node is used to replace the failed node, and the new slave node is connected to the master node's network, thus ensuring normal network communication.
[0022] In some embodiments, the networking method of the wireless battery management system further includes: the master node removing the unique identifier of the first slave node from the unique identifier list of slave nodes, and adding the unique identifier of the second slave node to the unique identifier list of slave nodes, thereby obtaining an updated unique identifier list of slave nodes. This method not only reduces the memory occupied by the master node's security storage module by the faulty slave node, but also reduces the impact of the faulty slave node on the communication data between the master node and the slave node, laying the foundation for the accuracy of subsequent data analysis and / or data processing, thereby ensuring the precision of the control of the power-consuming device.
[0023] In some embodiments, the networking method of the wireless battery management system further includes: the master node sending the updated list of unique identifiers of slave nodes to the battery management unit; the battery management unit storing the updated list of unique identifiers of slave nodes to achieve storage backup of the updated list of unique identifiers of slave nodes.
[0024] In some embodiments, the networking method of the wireless battery management system further includes: the master node marking the first key as invalid, generating and storing the second key; the second key is used to re-network.
[0025] After replacing the faulty slave node, the key stored in the BMU is updated to achieve key storage backup, laying the foundation for the reliability of WBMS network communication.
[0026] Secondly, embodiments of this application also provide a wireless battery management system, which includes: a master node and a plurality of slave nodes, wherein the master node and slave nodes each store an initial key; the master node and slave nodes are used to execute the method described in the first aspect.
[0027] Thirdly, embodiments of this application provide a machine-readable storage medium storing program instructions, which, when executed by a processor, implement the method described in the first aspect.
[0028] Fourthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the method described in the first aspect.
[0029] Fifthly, embodiments of this application provide a battery device including a battery management system as described in the second aspect.
[0030] Sixthly, embodiments of this application provide an electrical device that includes a battery device as described in the fifth aspect.
[0031] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0032] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on the drawings without creative effort.
[0033] Figure 1 This is a schematic diagram of the structure of WBMS provided in the embodiments of this application;
[0034] Figure 2 One of the flowcharts illustrating the networking method of the wireless battery management system provided in this application embodiment;
[0035] Figure 3 A flowchart illustrating the networking process of master and slave nodes provided in this application embodiment;
[0036] Figure 4 A second schematic flowchart illustrating the networking method of the wireless battery management system provided in this application embodiment;
[0037] Figure 5 A flowchart illustrating the interaction between various units in a WBMS provided in this application embodiment;
[0038] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0039] The accompanying drawings are not drawn to scale. Detailed Implementation
[0040] The embodiments of this application will be described in further detail below with reference to the accompanying drawings and examples. The detailed description of the following embodiments and the accompanying drawings are used to illustrate the principles of this application by way of example, but should not be used to limit the scope of this application, that is, this application is not limited to the described embodiments.
[0041] In the description of this application, it should be noted that, unless otherwise stated, "a plurality of" means two or more; the terms "upper," "lower," "left," "right," "inner," and "outer," etc., indicating orientation or positional relationships, are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation on this application. Furthermore, the terms "first," "second," and "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. "Vertical" is not vertical in the strict sense, but within the allowable tolerance range. "Parallel" is not parallel in the strict sense, but within the allowable tolerance range.
[0042] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application can be combined with other embodiments.
[0043] Unless otherwise specified, all embodiments and optional embodiments of this application can be combined to form new technical solutions.
[0044] Unless otherwise specified, all technical features and optional technical features of this application may be combined to form new technical solutions.
[0045] Unless otherwise specified, all steps of this application may be performed sequentially or randomly, preferably sequentially. For example, the method includes steps (a) and (b), indicating that the method may include steps (a) and (b) performed sequentially, or it may include steps (b) and (a) performed sequentially. For example, the mention that the method may also include step (c) indicates that step (c) may be added to the method in any order; for example, the method may include steps (a), (b), and (c), or it may include steps (a), (c), and (b), or it may include steps (c), (a), and (b), etc.
[0046] WBMS (Wireless Battery Management System) enables online monitoring, charge / discharge control, and fault detection of batteries via wireless means, serving as a core system for ensuring the safe and efficient operation of battery packs. In the WBMS architecture, data acquisition devices on each battery cell are connected wirelessly. Therefore, a network of master and slave nodes is required to enable data communication between the master node and each slave node.
[0047] For example, Figure 1A schematic diagram of the WBMS structure is shown, as follows: Figure 1 As shown, the WBMS mainly includes a master node 10, multiple slave nodes 11, a BMU (Battery Management Unit), and a secure storage module (…). Figure 1 (Not shown in the diagram), where master node 10 and slave node 11 are wireless nodes. The following describes the above-mentioned components of WBMS.
[0048] For the master node 10, it can serve as the central control node of the entire wireless communication network, used to implement core functions such as initiating network setup, scheduling communication links between slave nodes, generating and updating system keys, and data interaction with the BMU. The master node 10 can integrate a high-performance processor and secure storage unit, possessing powerful computing and data encryption capabilities, and can effectively manage the access and communication of all slave nodes within the network.
[0049] For node 11, it is typically integrated into the CMC (Cell Monitoring Controller) in a modular form and deployed in a distributed manner. Figure 1 The battery pack 12 shown represents the various cell module areas. Typically, a battery pack deploys multiple Control Centers (CMCs), each monitoring one or more cell modules. Each CMC has multiple slave nodes deployed, such as... Figure 1 As shown, n (n is a positive integer) slave nodes are deployed in the battery pack 12. Each slave node can monitor data from one or more battery cell modules. Slave node 11 can collect key parameters such as voltage, temperature, and charging / discharging current of the corresponding battery cell in real time, and accurately transmit the collected data to master node 10 via wireless radio frequency technology. Each slave node has a built-in unique identifier and a low-power communication module to achieve stable data acquisition and transmission under low power consumption.
[0050] The Battery Management Unit (BMU) serves as the upper-level management core of the WBMS, receiving and storing critical data such as node lists and key information transmitted by the master node. It also comprehensively monitors and manages the overall state of the battery pack, including SOC (State of Charge) estimation, SOH (State of Health) assessment, fault diagnosis, and protection functions. It is a key unit for ensuring the safe and stable operation of the battery system. The BMU can be connected to the master node via wired or wireless connections. Furthermore, the BMU can interact with other components within the electrical device (e.g., a vehicle) or with systems outside the electrical device. For example, the BMU can obtain cell temperature and SOC data returned by each slave node from the master node and send this data to the vehicle's controller. The vehicle controller then uses the received data to determine the battery's operating status and control the vehicle's operation accordingly (e.g., acceleration, deceleration).
[0051] The secure storage module, deployed in the master node, slave nodes, and BMU of the WBMS, uses encrypted storage technology to store sensitive information such as the initial keys of the master and slave nodes, dynamically updated communication keys, and unique identifiers of the slave nodes. In addition, the secure storage module also possesses security features against physical tampering and unauthorized access, providing protection for system data security.
[0052] In the aforementioned WBMS, the security, stability, and production economy of the master and slave nodes are crucial. Traditional WBMS networking requires pre-storing unique identifiers of slave nodes in the master node. These unique identifiers can be any information that uniquely identifies a slave node, such as its serial number or MAC (Media Access Control) address. Because traditional WBMS networking requires pre-storing these identifiers in the master node, a dedicated step must be added during actual master node production to read and store each slave node's unique identifier in the master node. Pre-storing these identifiers is time-consuming, extending the production process, increasing labor and equipment costs, prolonging networking time, and reducing networking efficiency. Therefore, there is an urgent need for a WBMS networking implementation method that can improve network security, simplify the faulty node replacement process, reduce production steps, and lower costs.
[0053] In view of the problems existing in the related technologies, the embodiments of this application provide a networking method, system, medium, product and device for a wireless battery management system.
[0054] In this embodiment, both the master node and slave nodes pre-store initial keys. The master node generates signature data based on its stored initial key and sends the signature data to the slave node. The slave node then verifies the received signature data using its stored initial key. If the verification is successful, the slave node returns its unique identifier to the master node, allowing the master node to network with the slave node based on this unique identifier. Therefore, after the initial key verification is successful, the slave node returns its unique identifier to the master node. This eliminates the need for the master node to pre-store the unique identifiers of each slave node, simplifying the WBMS networking process and improving its networking efficiency.
[0055] The following describes the networking method of the wireless battery management system provided in the embodiments of this application. This networking method can be achieved by... Figure 1 The WBMS shown is the execution entity, such as Figure 1 As shown, the WBMS includes a master node and multiple slave nodes. Both the master node and the slave nodes store the initial key. Specifically, the secure storage modules of the master node and the slave nodes can store the corresponding initial key respectively.
[0056] The following describes the method provided in the embodiments of this application, taking the master node and slave node in WBMS as the execution subjects.
[0057] like Figure 2 As shown, the networking method of the wireless battery management system provided in this application embodiment includes the following steps S201 to S203:
[0058] In step S201, the master node signs the first network request data based on its own stored initial key, generates and sends the first signature data to each of the multiple slave nodes.
[0059] In step S201, the master node and slave node are nodes in the WBMS, specifically wireless nodes. That is, in this embodiment, the master node and slave node communicate wirelessly. Both the master node and slave node in the WBMS have their own corresponding initial keys, which can be used to verify whether the master and slave nodes can form a network.
[0060] In practical applications, chip manufacturers pre-embed initial keys into the secure storage modules of the master and slave nodes during the production process of the WBMS master and slave nodes. This initial key is unique and immutable, serving as the initial verification basis for the master and slave nodes to form a network.
[0061] In step S201, the first signature data may be data sent by the master node to detect probe signals from slave nodes, and the first network request may be specific data agreed upon between the master and slave nodes, including but not limited to the master node's identity identifier, timestamp, and other agreed information. For example, after the master and slave nodes power on, the master node automatically enters a low-power mode and broadcasts the first signature data at a preset scanning frequency to periodically scan for slave nodes capable of wireless communication with the master node. The preset scanning frequency can be a low frequency, for example, 1 scan / second, which can be determined by data such as the battery pack module's power consumption, the power consumption of the slave nodes and the CMC of the AFE (Analog Front End), and the network setup waiting time.
[0062] In step S202, each slave node verifies the first signature data based on its own stored initial key, and sends the first response data to the master node if the verification is successful.
[0063] In step S202, each slave node continuously monitors and receives the first signature data sent by the master node at a low frequency to achieve preliminary signal sensing between the master and slave nodes. The frequency at which the slave node monitors the first signature data can be the same as the master node's scanning frequency, or it can be a frequency within the same frequency band as the master node's scanning frequency. That is, in this embodiment, when the slave node's monitoring frequency and the master node's scanning frequency are within the same frequency band, the slave node can receive the probe signal containing the first signature data sent by the master node.
[0064] In some examples, during the chip manufacturing stage of master-slave nodes, chip manufacturers can embed the keys corresponding to symmetric or asymmetric algorithms into the secure storage modules of the master and slave nodes. After receiving the first signature data, the slave node verifies the first signature data using its own initial key. For example, it decrypts the first signature data using its own initial key to obtain specific data between the master node and the communicatively connected slave node. The slave node compares the decrypted specific data with its local specific data. If they match, the first signature data verification is successful, and the slave node sends the first response data to the master node; otherwise, the first signature data verification fails, and the slave node does not send the first response data to the master node.
[0065] It should be noted that in the above example, the first response data includes a unique identifier used for networking with the master node. The unique identifier of the slave node is embedded in its own storage module during chip manufacturing, requiring no additional reading during the manufacturing phase. In this embodiment, if the first signature data verification is successful, meaning the slave node is one that needs to network with the master node, the slave node will send its unique identifier back to the master node.
[0066] In step S203, the master node responds to the first response data fed back by the slave node and forms a network with the slave node corresponding to the unique identifier.
[0067] It should be noted that successful verification of the first signature data indicates that the connection between the master node and the slave node can be established. Since the slave node will send its unique identifier to the master node, there is no need to store the slave node's unique identifier in the master node in advance. This eliminates the step of writing the slave node's unique identifier into the master node in advance, simplifies the networking process of the wireless battery management system, and improves the networking efficiency of the wireless battery management system.
[0068] In step S203, after receiving the unique identifier of the slave node, the master node and the slave node can use existing networking methods to form a network. For example, the master node sends a networking signal to the slave node with the unique identifier, and the slave node with the unique identifier responds to the networking signal and establishes a communication connection with the master node, thereby forming the topology of the WBMS network, that is, realizing the networking of WBMS.
[0069] Based on the scheme defined in steps S201 to S203 above, it can be understood that in this embodiment, initial keys are pre-stored in both the master node and the slave node. The master node and the slave node use their own initial keys to verify the signature data to determine which slave node can participate in the network. After the initial key verification between the master and slave nodes is successful, the slave node actively sends its unique identifier to the master node, without the need for the master node to pre-store the slave node's unique identifier. This eliminates the step of pre-writing the slave node's unique identifier into the master node, simplifies the networking process of the wireless battery management system, and improves the networking efficiency of the wireless battery management system.
[0070] The specific implementation process of the method provided in the embodiments of this application is described below.
[0071] In some embodiments, the first response data further includes second signature data. That is, in this embodiment, each slave node also signs the network request response data based on its own stored initial key, generates and sends the second signature data to the master node. At this time, after the master node receives the second signature data, the master node can verify the second signature data based on its own stored initial key, and if the verification is successful, it can form a network with the corresponding slave node according to the unique identifier.
[0072] In one example, such as Figure 3 As shown, the networking process of master and slave nodes, i.e., step S203, may include the following steps S2031 to S2033:
[0073] Step S2031: The master node uses its own initial key to verify the second signature data and obtains the verification result. If the verification result indicates that the second signature data has been successfully verified, step S2032 is executed; otherwise, step S2033 is executed.
[0074] Step S2032: The master node determines that the slave node is a legitimate node and uses the unique identifier returned by the slave node to form a network;
[0075] In step S2033, the master node determines that the slave node is an illegal node and does not form a network with the slave node, thereby reducing the risk of network failure due to forming a network with an illegal node.
[0076] Through steps S2031 to S2033, bidirectional verification is performed between the master and slave nodes during the networking process, which can ensure that the data has not been tampered with and that the signature data received by each node comes from a legitimate node. This enhances the security of the WBMS network and reduces the problem of WBMS network failure due to data tampering and / or illegitimate nodes, thereby improving the networking efficiency of WBMS.
[0077] In some embodiments, when the master node determines that it has completed networking with all slave nodes, the networking access function of the master node is turned off.
[0078] In this embodiment of the application, when the master node determines that the network completion condition has been met, the master node determines that all slave nodes have completed the network formation.
[0079] In the above embodiments, the network termination condition includes the number of networked slave nodes reaching a preset number.
[0080] In one example, the master node pre-writes a preset number of nodes to be networked. The master node determines the number of slave nodes that have already responded with their first response data as the number of slave nodes that have been networked. If the number of networked slave nodes is the preset number, the master node confirms that the network has been completed with all slave nodes; if the number of networked slave nodes is less than the preset number, the master node continues scanning until the number of slave nodes that have responded with their first response data reaches the preset number.
[0081] If the number of scans by the master node exceeds a preset scan count threshold, and / or the scan duration exceeds a preset scan duration threshold, and the number of networked slave nodes is still less than a preset number, then the master node confirms that the slave node that has sent the first response data has completed network formation. If the number of networked slave nodes exceeds a preset number, the master node can consider the signal strength of the networked slave nodes, for example, sort them in descending order of signal strength, and select a preset number of slave nodes from the networked slave nodes to form a new network.
[0082] It should be noted that the number of networked slave nodes can be used to determine whether the network is finished. This allows the master node's network access function to be shut down in a timely manner after the network is completed. This not only reduces the risk of missing slave nodes and improves the rationality of WBMS network formation, but also prevents unauthorized nodes from participating in the network, thus enhancing the security of WBMS network formation.
[0083] In one embodiment, the network termination condition may further include that the master node does not receive first response data from other slave nodes within a preset time period after receiving first response data from a slave node. For example, assuming the master node is not faulty, if the master node does not receive first response data from other slave nodes for a long period of time, the master node can determine that it has received first response data from all slave nodes capable of forming a network, and at this time, the master node can disable the network access function.
[0084] It should be noted that determining whether all slave nodes have completed networking based on the first response data sent by other slave nodes within a preset time after receiving the first response data can improve the accuracy of the judgment on whether all slave nodes have completed networking. This allows the master node's networking access function to be shut down in a timely manner, which not only reduces the risk of missing slave nodes and improves the rationality of WBMS networking, but also prevents unauthorized nodes from participating in networking, thus improving the networking security of WBMS.
[0085] In another embodiment, the master node can also determine whether it has completed networking with all slave nodes based on the signal strength corresponding to the slave nodes.
[0086] In one example, the master node obtains the signal strength of each slave node that returns the first response data to the master node, and forms a network with all slave nodes whose signal strength is higher than the preset signal strength threshold. After completing the network formation, the master node disables the network access function.
[0087] Once all slave nodes have completed their network formation, the master node automatically triggers a network function lock-up mechanism, disabling its network access function. This not only prevents unauthorized attackers from creating fake slave nodes to access the network but also prevents unauthorized slave nodes from accessing the network and stealing data, thereby enhancing the network security of WBMS. The permission for slave nodes to network with the master node can be set by the chip manufacturer before the battery pack production is complete.
[0088] In some embodiments, the master node can disable or enable its network access function based on a working status flag. Specifically, the master node can adjust its working status flag to a target flag, which instructs the master node to disable its network access function. For example, if the target flag is 1, when the master node completes networking with all slave nodes, the master node adjusts its working status flag from 0 to 1. At this time, the master control unit in the master node disables its network access function. After the master node starts up or receives a network enable command, it adjusts its working status flag from 1 to 0 to enable its network access function.
[0089] It should be noted that controlling the activation and deactivation of the network access function of the master node based on the working status flag bit of the master node not only reduces hardware costs compared with the method of using hardware switch control, but also solves the problem of poor switch control accuracy caused by unstable signals in the circuit, thus improving the accuracy of network access function control.
[0090] In some embodiments, such as Figure 4 As shown, the networking method of the wireless battery management system further includes: step S204, whereby the master node marks the initial key as invalid after determining that all slave nodes have completed networking, and generates and stores the first key.
[0091] In the above embodiments, the first key is used for re-networking. In this embodiment, the first key is different from the initial key of the master node. The first key has higher security, that is, the security of the first key is greater than that of the initial key of the master node.
[0092] In one example, after the master node and all slave nodes have completed the network formation, the master node or BMU can use an existing key generation algorithm to generate a first key, mark the first key as invalid, and store the first key in the master node's secure storage module. The master node can use the first key to form a network with the slave nodes the next time the network is formed.
[0093] It is worth noting that the initial key is input into the master node by the chip manufacturer during the production process. Therefore, for the same batch of chips, the corresponding initial key may be the same, which poses a risk that unauthorized nodes may use the initial key to network with the master node, thus creating a security risk in the network. In this embodiment, after all slave nodes have completed networking, a new first key is generated. During the next networking attempt, the master node uses the first key to network with the slave nodes, thus preventing unauthorized nodes from using the initial key to network with the master node, thereby improving network security.
[0094] In some embodiments, such as Figure 1 As shown in the embodiments of this application, the Wireless Battery Management System (WBMS) also includes a Battery Management Unit (BMU). The master node and the BMU can be connected via a wired connection or a wireless connection. After generating the first key, the master node can also send the first key to the battery management unit so that the battery management unit stores the first key.
[0095] In this embodiment, the master node sends the newly generated first key to the BMU, which then stores the first key in its local secure storage module for backup. The BMU may also send the first key to other control units of the electrical device, such as the vehicle controller, so that the vehicle controller can use the first key to decrypt data transmitted between the master and slave nodes and use the decrypted data to control the electrical device.
[0096] By sending the first key to the BMU for storage backup, the first key can be retrieved from the BMU when the master node fails and the first key is lost, thus enabling normal data transmission between the master and slave nodes and improving the stability and reliability of WBMS data transmission.
[0097] In some embodiments, the master node may also add its own unique identifier and the unique identifier of the slave node to the slave node unique identifier list stored by the master node.
[0098] In this embodiment of the application, the master node's secure storage module stores a list of unique identifiers for slave nodes, which are used to identify the unique identifiers of slave nodes that can form a network with the master node.
[0099] For example, after receiving the first response data sent by the slave node, the master node obtains the unique identifier of the slave node from the first response data and stores the unique identifier of the slave node in the master node's slave node unique identifier list. Thus, in the next network formation, the master node does not need to obtain the unique identifier of the slave node by sending signature data, but directly obtains the unique identifier of the slave node from the slave node unique identifier list, thereby improving the networking efficiency of WBMS.
[0100] In some embodiments, if the master node determines that a network has been formed with all slave nodes, it may also send a list of unique identifiers of the slave nodes to the battery management unit so that the battery management unit stores the list of unique identifiers of the slave nodes.
[0101] In one example, after the master node and all slave nodes have completed the network formation, the master node can send the list of unique identifiers of the slave nodes to the BMU for backup. This way, if the master node encounters an anomaly that causes the loss or illegal alteration of its own unique identifier and / or the unique identifiers of the slave nodes, the master node can obtain the list of unique identifiers of the slave nodes from the BMU to correct the unique identifier list of the slave nodes on the master node's local network, thus ensuring the security of the WBMS network.
[0102] In another example, the master node can also send the unique identifier of the slave node to the BMU for storage backup after obtaining the unique identifier of the slave node. This method can achieve real-time storage backup of the unique identifier of the slave node. Compared with the method of transmitting a list of unique identifiers of slave nodes, it can also reduce the communication bandwidth between the master node and the BMU and improve the data transmission rate.
[0103] In some embodiments, if the first slave node fails after the network is formed, the master node may also sign the second network request data based on the first key, generate and send the third signature data to the second slave node; the second slave node verifies the third signature data based on the first key it stores, and sends the second response data to the master node if the verification is successful; then, the master node responds to the first response data fed back by the slave node and forms a network with the second slave node.
[0104] In the above embodiments, the second slave node is a node that replaces the first slave node. The second slave node stores the first key, and the key stored in the second slave node can be stored in the secure storage module of the first key by the administrator of the electrical device.
[0105] In the above embodiment, the second response data includes a unique identifier used for networking with the master node. The second slave node uses the first key as the initial key to perform signature verification with the master node, thereby realizing networking between the master node and the second slave node. This process is similar to the networking process between the master node and the slave node described above, except that the initial key used is different.
[0106] In one example, when the electrical device is operating normally, the master node can receive data from other slave nodes, but cannot receive data from the first slave node, or the data sent by the first slave node is abnormal (e.g., the value exceeds the normal range). This indicates that the first slave node has failed. In this case, the administrator of the electrical device can replace the slave node. Specifically, the processor of the electrical device can connect to the WBMS, acquire the communication data between the master and slave nodes, and analyze the acquired data. Based on the analysis results, the faulty first slave node can be identified, and its unique identifier can be used to determine its location within the battery pack. The administrator can then replace the first slave node with a working second slave node based on its location and write the first key to the second slave node. After the replacement operation is completed, the second slave node needs to be connected to the WBMS network coverage area, i.e., a network is formed between the master node and the second slave node.
[0107] After the second slave node powers on, the master node enters a low-frequency scanning state, signs the second network request data based on the second key, generates third signature data, and sends the third signature data to the second slave node. The second slave node uses the locally stored second key to verify the third signature data. If the verification is successful, the second slave node sends its unique identifier to the master node, which then stores the second slave node's unique identifier in its slave node unique identifier list, thus establishing the network between the master node and the second slave node.
[0108] When a slave node fails, a new slave node is used to replace the failed node, and the new slave node is connected to the master node's network, thus ensuring normal network communication.
[0109] In some embodiments, the master node may also remove the unique identifier of the first slave node from the unique identifier list and add the unique identifier of the second slave node to the unique identifier list, resulting in an updated unique identifier list. This method not only reduces the memory occupied by the master node's security storage module by the failed slave node, but also reduces the impact of the failed slave node on the communication data between the master and slave nodes, laying the foundation for the accuracy of subsequent data analysis and / or data processing, thereby ensuring the precision of electrical device control.
[0110] In some embodiments, the master node may also send the updated list of slave node unique identifiers to the battery management unit, so that the battery management unit stores the updated list of slave node unique identifiers to achieve storage backup of the updated list of slave node unique identifiers.
[0111] In some embodiments, the master node may also mark the first key as invalid and generate and store a second key; the second key is used to reconfigure the network.
[0112] After replacing the failed slave node, the master node also updates its key, replacing the original first key with the second key, which will be used for subsequent re-networking between the master node and all slave nodes. Then, the master node encrypts and transmits the updated list of unique slave node identifiers and the newly generated updated key (i.e., the second key) to the BMU. Upon receiving this, the BMU updates the unique identifiers and keys of the slave nodes in its local secure storage module and deletes the unique identifier of the failed slave node (i.e., the first slave node).
[0113] After replacing the faulty slave node, the key stored in the BMU is updated to achieve key storage backup, laying the foundation for the reliability of WBMS network communication.
[0114] In one embodiment, Figure 5 This illustrates the interaction flow between various units in a WBMS. The following uses... Figure 5 The interactive diagram shown is used to further illustrate the solution provided in the embodiments of this application.
[0115] It should be noted that, in this embodiment, the master and slave nodes in the WBMS can be wireless communication chips with low power consumption characteristics. The unique identifier of the slave node (e.g., MAC address) is embedded in the secure storage module inside the slave node during chip manufacturing, eliminating the need for manual reading of the record during the manufacturing process.
[0116] like Figure 5 As shown, the interaction process includes the following steps S501 to S512:
[0117] Step S501: Power on and start the master node.
[0118] Step S502: Power on and start the node.
[0119] In step S503, the master node uses the initial key to sign specific data (e.g., identity identifier, timestamp, or other agreed information) to generate the first signature data.
[0120] It should be noted that during the master-slave node production phase, chip manufacturers can either use a symmetric algorithm to implant the same initial key K0 into the secure storage modules of both the master and slave nodes, or they can choose an asymmetric algorithm to implant different keys into the secure storage modules of both nodes. The following example uses the same initial key K0.
[0121] In step S504, the master node sends out a probe signal in a low-frequency (e.g., 1 time / second) scanning manner, the probe signal including the first signature data.
[0122] Step S505: The slave node receives the probe signal and uses its own initial key K0 to verify the first signature data to ensure that the data has not been tampered with and that the signature does indeed come from the legitimate master node.
[0123] Step S506: The slave node returns first response data to the master node, which includes second signature data and the unique identifier of the slave node.
[0124] Step S507: The master node verifies the second signature data in the first response data.
[0125] In step S508, after the second signature data is verified, the master node stores its own unique identifier and the unique identifier of the slave node in the slave node unique identifier list. The connection between the master node and the slave node is established, and new session keys or other communication parameters can be negotiated further.
[0126] Step S509: After the network is completed, the master node disables the network access function.
[0127] In step S510, the master node generates a new key, namely the first key K1.
[0128] In step S511, the master node sends the first key K1 and the list of unique identifiers of the slave nodes to the battery management unit (BMU).
[0129] In step S512, the BMU stores the first key K1 and a list of unique identifiers for slave nodes.
[0130] When a slave node fails, after replacing it with a new slave node, the new slave node performs a power-on scan. The master node sends a request containing verification information including the first key K1. The new slave node, after authorization and successful matching of the first key K1, automatically sends its own unique identifier to the master node. The master node deletes the faulty slave node's unique identifier from its local slave node unique identifier list and adds the new slave node's unique identifier. Simultaneously, it generates a new key, the second key K2, and transmits the updated slave node unique identifier list and the second key K2 to the BMU. The BMU updates the slave node unique identifier list and stores the second key K2, completing the replacement of the faulty slave node.
[0131] This concludes the introduction of the methods provided in the embodiments of this application.
[0132] This application aims to address the problems of low security, difficulty in replacing faulty nodes, and high costs and cumbersome processes caused by the need to additionally read the unique identifier of slave nodes in the existing WBMS system networking process. It provides a safe, reliable, easy-to-replace faulty nodes WBMS system networking implementation method that can reduce production steps and lower costs.
[0133] In the solution provided in this application embodiment, the chip manufacturer pre-implants initial keys into the master and slave nodes in the WBMS to ensure the security of the initial network verification. After network formation, the network function is locked and a new key is generated, effectively preventing unauthorized node intrusion and improving system security. Simultaneously, by automatically transmitting the slave node's unique identifier and writing it into the master node's slave node unique identifier list after successful key matching between the slave and master nodes, the extra step of specifically reading and recording the slave node's unique identifier during production is eliminated, reducing production processes and labor / equipment costs, and improving production efficiency. During faulty node replacement, matching verification is performed using the new key, and the master node's slave node unique identifier list is automatically updated, ensuring the security of the replacement process and the reliability and continuity of subsequent system communication. This method is simple to operate, highly secure, and cost-effective, greatly improving the stability, practicality, and economy of the WBMS system.
[0134] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. They are devices corresponding to the detection method of the above-mentioned battery cell baking equipment. All implementation methods in the above-mentioned method embodiments are applicable to the embodiments of this device. For details on its specific functions and the technical effects it brings, please refer to the method embodiment section. It will not be repeated here.
[0135] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0136] This application also provides a battery device, which includes a battery management system.
[0137] This application also provides an electrical device, which includes the battery device described above. This electrical device can be, but is not limited to, a vehicle, such as a new energy vehicle.
[0138] Reference Figure 6 The electronic device 6000 may include a processor 6001 and a memory 6002 storing programs or instructions. When the processor 6001 executes the program, it implements the steps in any of the above method embodiments.
[0139] For example, the program can be divided into one or more modules / units, one or more of which are stored in memory 6002 and executed by processor 6001 to complete this application. One or more modules / units can be a series of program instruction segments capable of performing a specific function, which describe the program's execution process in the device.
[0140] Specifically, the processor 6001 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0141] Memory 6002 may include mass storage for data or instructions. For example, and not limitingly, memory 6002 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 6002 may include removable or non-removable (or fixed) media. Where appropriate, memory 6002 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 6002 is non-volatile solid-state memory.
[0142] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this disclosure.
[0143] The processor 6001 implements any of the methods described in the above embodiments by reading and executing programs or instructions stored in the memory 6002.
[0144] In one example, the electronic device may also include a communication interface 6003 and a bus 6004. The processor 6001, memory 6002, and communication interface 6003 are connected via the bus 6004 and communicate with each other.
[0145] The communication interface 6003 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0146] Bus 6004 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 6004 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.
[0147] Furthermore, in conjunction with the methods in the above embodiments, this application embodiment can provide a machine-readable storage medium for implementation. This machine-readable storage medium stores a program or instructions; when executed by a processor, the program or instructions implement any of the methods in the above embodiments. This machine-readable storage medium can be read by a machine such as a computer.
[0148] This application provides a computer program product stored in a machine-readable storage medium. The program product is executed by at least one processor to implement the various processes of the above method embodiments and achieve the same technical effects. To avoid repetition, it will not be described again here.
[0149] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0150] The functional modules shown in the above-described block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer grids such as the Internet, intranets, etc.
[0151] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0152] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by a computer program or instructions. These programs or instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0153] Although this application has been described with reference to preferred embodiments, various modifications can be made thereto and components can be replaced with equivalents without departing from the scope of this application. In particular, the technical features mentioned in the various embodiments can be combined in any manner, provided there is no structural conflict. This application is not limited to the specific embodiments disclosed herein, but includes all technical solutions falling within the scope of the claims.
Claims
1. A networking method for a wireless battery management system, characterized in that, The wireless battery management system includes a master node and multiple slave nodes. Both the master node and the slave nodes store an initial key. The method includes: The master node signs the first network request data based on the initial key stored in itself, generates and sends the first signature data to each of the plurality of slave nodes; Each slave node verifies the first signature data based on its own stored initial key, and if the verification is successful, sends first response data to the master node, the first response data including a unique identifier for networking with the master node; The master node responds to the first response data fed back by the slave node and forms a network with the slave node corresponding to the unique identifier; The first response data further includes second signature data; the method further includes: each slave node signing the network request response data based on its own stored initial key, generating and sending the second signature data to the master node; the master node responding to the first response data fed back by the slave node and forming a network with the slave node corresponding to the unique identifier includes: the master node verifying the second signature data based on its own stored initial key, and if the verification is successful, forming a network with the corresponding slave node according to the unique identifier.
2. The method according to claim 1, characterized in that, The method further includes: when the master node determines that it has completed networking with all slave nodes, disabling the networking access function of the master node.
3. The method according to claim 2, characterized in that, The method of disabling the network access function of the master node includes: The working status flag of the master node is adjusted to the target flag, which is used to instruct the master node to disable the network access function of the master node.
4. The method according to claim 1, characterized in that, The method further includes: when the master node determines that all slave nodes have completed networking, marking the initial key as invalid, and generating and storing a first key, which is used for renetworking.
5. The method according to claim 4, characterized in that, The master node determines and completes the network formation with all slave nodes, including: If the master node determines that the network termination condition has been met, then all slave nodes have completed the network formation. The network termination condition includes the number of slave nodes that have been networked reaching a preset number.
6. The method according to claim 4, characterized in that, The wireless battery management system further includes a battery management unit, and the method further includes: The master node sends the first key to the battery management unit; The battery management unit stores the first key.
7. The method according to any one of claims 1-6, characterized in that, The method further includes: the master node adding its own unique identifier and the unique identifier of the slave node to the slave node unique identifier list stored by the master node.
8. The method according to claim 7, characterized in that, The wireless battery management system further includes a battery management unit, and the method further includes: Once it is confirmed that networking has been completed with all slave nodes, the list of unique identifiers of the slave nodes is sent to the battery management unit; The battery management unit stores a list of unique identifiers for the slave nodes.
9. The method according to claim 5, characterized in that, The method further includes: If the first slave node fails after the network is formed, the master node signs the second network request data based on the first key, generates and sends third signature data to the second slave node; the second slave node stores the first key. The second slave node verifies the third signature data based on the first key stored in itself, and if the verification is successful, sends second response data to the master node. The second response data includes a unique identifier for networking with the master node. The master node responds to the first response data fed back by the slave node and forms a network with the second slave node.
10. The method according to claim 9, characterized in that, The method further includes: the master node removing the unique identifier of the first slave node from the list of unique identifiers of slave nodes, and adding the unique identifier of the second slave node to the list of unique identifiers of slave nodes, to obtain an updated list of unique identifiers of slave nodes.
11. The method according to claim 10, characterized in that, The method further includes: the master node sending the updated list of unique identifiers for slave nodes to the battery management unit; and the battery management unit storing the updated list of unique identifiers for slave nodes.
12. The method according to claim 9, characterized in that, The method further includes: the master node marking the first key as invalid, generating and storing a second key; the second key is used to reconfigure the network.
13. A wireless battery management system, characterized in that, include: The system includes a master node and multiple slave nodes, each of which stores an initial key. The master node and the slave node are used to perform the method according to any one of claims 1-12.
14. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores a program or instructions that, when executed by a processor, implement the method as described in any one of claims 1-12.
15. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-12.
16. A battery device, characterized in that, Including the battery management system as described in claim 13.
17. An electrical device, characterized in that, Includes the battery device as described in claim 16.
Citation Information
Patent Citations
Key refresh using session counting for wireless management of modular subsystems
CN115314892A
Equipment trusted connection method and device based on OpenHarmony system, equipment and storage medium
CN119906998A