System, method, device and equipment for safe communication between charging pile and BMS and storage medium
By establishing a two-way authentication, communication encryption, and three-level verification mechanism between the charging pile and the BMS, the problem of insufficient communication security in the charging control system is solved, identity mutual trust and secure information exchange are achieved, and the availability of the system is improved.
Patent Information
- Application Number
- CN202510815393.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2026-01-13
AI Technical Summary
In existing charging control systems, the communication security between charging piles and BMS is insufficient, with vulnerabilities in the key negotiation mechanism and risks of malicious firmware injection, and it fails to effectively defend against man-in-the-middle attacks and replay attacks.
The system employs a two-way authentication module, a communication encryption module, and a verification module. A two-way authentication protocol is constructed through a hardware security module. The transport layer security protocol is customized using open-source tools. A three-level verification mechanism and a containerized deployment redundancy backup scheme are designed to ensure mutual trust between the charging pile and the BMS and information security.
It effectively defends against man-in-the-middle attacks and replay attacks, ensures mutual trust and secure information exchange between charging piles and vehicle BMS, enables rapid hot-swapping processes, and improves system availability.
Smart Images

Figure CN121333618A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of electric vehicle charging control, in particular to a system, method, device and equipment for secure communication between a charging pile and a BMS (Battery Management System) and a storage medium. BACKGROUND
[0002] Most of the charging piles in the current charging control system use traditional RSA one-way authentication, and communicate and encrypt through obsolete protocols such as TLS1.1 to realize communication between the charging pile and the system.
[0003] The key negotiation mechanism in the above method has vulnerabilities, OTA upgrade without integrity verification leads to malicious firmware injection risk, and key processes are vulnerable to memory attacks.
[0004] Therefore, how to realize the process of secure communication between the charging pile and the BMS (Battery Management System) is a technical problem to be solved. SUMMARY
[0005] The purpose of the embodiments of the present application is to provide a method for secure communication between a charging pile and a BMS, which can realize the effect of the process of secure communication between the charging pile and the BMS through the technical solutions of the embodiments of the present application.
[0006] In a first aspect, the embodiments of the present application provide a system for secure communication between a charging pile and a BMS, comprising a two-way authentication module, a communication encryption module, a verification module and an optimization module; the two-way authentication module is configured to construct a two-way authentication protocol between the charging pile and the BMS based on a hardware security module, and authenticate the identity; the communication encryption module is configured to customize and integrate a transmission layer security protocol line through an open source tool, and encrypt the secure communication data; the verification module is configured to design a three-level verification mechanism, block the malicious firmware injection path, and verify the secure communication process; and the optimization module is configured to optimize the key processes by using a containerized deployment redundancy backup scheme.
[0007] In the above embodiments, the two-way authentication, communication encryption and three-level verification can effectively defend against man-in-the-middle attacks and replay attacks, ensure the identity trust and information security intercommunication between the charging pile and the vehicle BMS. Finally, through optimizing the key processes, the fast hot switching process can be realized, the system availability can be improved, and the secure communication between the charging pile and the BMS can be realized.
[0008] In some embodiments, the two-way authentication module is specifically configured to determine a unique authentication method for the charging pile and the BMS through the public key of the preset algorithm of the hardware module HSM; and authenticate the identity of the charging pile and the BMS through the two-factor authentication mechanism of the device identity and the dynamic key in the unique authentication method.
[0009] In the above embodiment, the two-factor authentication mechanism of the device identity and the dynamic key in the unique authentication method can effectively prevent man-in-the-middle attacks and replay attacks, and ensure the identity trust between the charging pile and the vehicle BMS.
[0010] In some embodiments, the communication encryption module is specifically configured to: tailor a standard transport layer security protocol and remove a compatibility module of a historical version through an open source tool, and customize and integrate a transport layer security protocol line; and encrypt secure communication data through the transport layer security protocol line, a pre-stored shared key and a session key.
[0011] In the above embodiment, the encryption of the secure communication data through the transport layer security protocol line, the pre-stored shared key and the session key can ensure the secure information intercommunication between the charging pile and the vehicle BMS.
[0012] In some embodiments, the verification module is specifically configured to: construct a four-level start verification system and construct a three-level verification mechanism through vehicle wireless download technology; and block a malicious firmware injection path through the four-level start verification system and the three-level verification mechanism, and verify a secure communication process.
[0013] In the above embodiment, the three-level verification mechanism and the four-level start verification system can block the malicious firmware injection path and verify the secure communication process.
[0014] In some embodiments, the optimization module is specifically configured to: adopt a containerized deployment redundancy backup scheme to divide a secure world and a normal world; deploy a key management module and an authentication core algorithm module in the secure world; and optimize a key process through the key management module and the authentication core algorithm module.
[0015] In the above embodiment, the containerized deployment redundancy backup scheme is adopted to divide the secure world and the normal world, so that the key process can be optimized to realize a fast hot switching process.
[0016] In a second aspect, the embodiments of the present application provide a method for secure communication between a charging pile and a BMS, including: constructing a bidirectional authentication protocol between the charging pile and a battery management system (BMS); customizing and integrating a transport layer security protocol line through an open source tool; designing a three-level verification mechanism and a containerized deployment redundancy backup scheme; and authenticating, encrypting, verifying and optimizing a communication process between the charging pile and the BMS through the bidirectional authentication protocol, the integrated transport layer security protocol line, the three-level verification mechanism and the containerized deployment redundancy backup scheme.
[0017] In the above embodiments, the bidirectional authentication, communication encryption and three-level verification can effectively prevent man-in-the-middle attacks and replay attacks, ensure the identity trust and information security intercommunication of the charging pile and the vehicle BMS. Finally, through optimizing the key process, the fast hot switching process can be realized, the system availability is improved, and the safe communication between the charging pile and the BMS is realized In some embodiments, the communication process between the charging pile and the BMS is authenticated, encrypted, verified and optimized through a bidirectional authentication protocol, an integrated transport layer security protocol line, a three-level verification mechanism and a containerized deployment redundancy backup scheme, including: determining a unique authentication method for the charging pile and the BSM through the public key of the preset algorithm of the hardware module HSM; authenticating the identity of the charging pile and the BMS through the two-factor authentication mechanism of the device identity and the dynamic key in the unique authentication method; customizing the integrated transport layer security protocol line through the open source tool, tailoring the standard transport layer security protocol and removing the compatible module of the historical version; encrypting the secure communication data through the transport layer security protocol line, the pre-stored shared key and the session key; constructing a four-level start verification system and a three-level verification mechanism through the vehicle wireless download technology; blocking the malicious firmware injection path through the four-level start verification system and the three-level verification mechanism to verify the secure communication process; dividing the secure world and the ordinary world through the containerized deployment redundancy backup scheme; deploying the key management module and the authentication core algorithm module in the secure world; and optimizing the key process through the key management module and the authentication core algorithm module.
[0018] In a third aspect, the embodiments of the present application provide a device for safe communication between a charging pile and a BMS, including: A construction module is configured to construct a bidirectional authentication protocol between the charging pile and the battery management system (BMS). An integration module is configured to customize an integrated transport layer security protocol line through an open source tool. A design module is configured to design a three-level verification mechanism and a containerized deployment redundancy backup scheme. A communication module is configured to authenticate, encrypt, verify and optimize the communication process between the charging pile and the BMS through the bidirectional authentication protocol, the integrated transport layer security protocol line, the three-level verification mechanism and the containerized deployment redundancy backup scheme.
[0019] Optionally, the communication module is specifically configured to: Determine a unique authentication method for the charging pile and the BSM through the public key of the preset algorithm of the hardware module HSM. Authenticate the identity of the charging pile and the BMS through the two-factor authentication mechanism of the device identity and the dynamic key in the unique authentication method. Customize the integrated transport layer security protocol line through the open source tool, tailor the standard transport layer security protocol and remove the compatible module of the historical version. The secure communication data is encrypted through a transport layer security protocol line, a pre-stored shared key and a session key; A four-level start verification system is constructed, and a three-level verification mechanism is constructed through vehicle wireless download technology; The four-level start verification system and the three-level verification mechanism are used to block malicious firmware injection paths and verify the secure communication process; A redundancy backup scheme of containerization deployment is adopted to divide a secure world and a normal world; A key management module and an authentication core algorithm module are deployed in the secure world; The key management module and the authentication core algorithm module are used to optimize key processes.
[0020] In a fourth aspect, an electronic device is provided, including a processor and a memory, the memory storing computer readable instructions, when the computer readable instructions are executed by the processor, the steps in the method provided in the first aspect are executed.
[0021] In a fifth aspect, a readable storage medium is provided, and the readable storage medium stores a computer program, when the computer program is executed by a processor, the steps in the method provided in the first aspect are executed.
[0022] Other features and advantages of the present application will be described in the following description, and some will become apparent from the description, or will be understood through implementation of the embodiments of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as a limitation on the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0024] Figure 1 A schematic block diagram of a system for secure communication between a charging pile and a BMS provided by the embodiments of the present application; Figure 2 A flowchart of a method for secure communication between a charging pile and a BMS provided by the embodiments of the present application; Figure 3 A schematic block diagram of an apparatus for secure communication between a charging pile and a BMS provided by the embodiments of the present application; Figure 4 A structural schematic block diagram of an apparatus for secure communication between a charging pile and a BMS provided by the embodiments of the present application. DETAILED DESCRIPTION
[0025] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the present application.
[0026] It should be noted that: similar reference numbers and letters represent similar items in the following drawings, therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. Meanwhile, in the description of the present application, the terms "first", "second", etc. are only used for differentiation, and cannot be understood as indicating or implying relative importance.
[0027] First, some terms involved in the embodiments of the present application are explained, so as to facilitate understanding by those skilled in the art.
[0028] Yocto is an open source community. It helps developers create customized systems based on the Linux kernel by providing templates, tools and methods, supporting ARM, PPC, MIPS, x86 (32 & 64 bit) hardware architecture.
[0029] Transport Layer Security (TLS) is used to provide confidentiality, data integrity and authenticity between two communicating applications.
[0030] ARM TrustZone technology is a basic function of all Cortex-A class processors, which is introduced through ARM architecture security extension.
[0031] OTA vehicle refers to a vehicle with over-the-air (OTA) technology. OTA technology allows car manufacturers to remotely push software or system updates through wireless networks, similar to online upgrades of mobile phones or computers. This technology enables vehicles to automatically detect, download and install the latest software or system updates through networking without going to a 4S store, thereby optimizing the functionality, performance and safety of the vehicle The present application is applied to the scene of electric vehicle charging control, and the specific scene is that through two-way authentication, communication encryption and three-level verification, fast hot switching process can be realized through optimization of key processes, system availability is improved, and safe communication between charging piles and BMS is realized.
[0032] Most of the charging piles in the current charging control system use traditional RSA one-way authentication, and communicate and encrypt through obsolete protocols such as TLS1.1 to realize communication between the charging pile and the system. The key negotiation mechanism in the above method has vulnerabilities, malicious firmware injection risk caused by OTA upgrade without integrity verification, and key processes are vulnerable to memory attacks.
[0033] To this end, the application provides a system for secure communication between a charging pile and a BMS, which includes a two-way authentication module, a communication encryption module, a verification module, and an optimization module; the two-way authentication module is configured to construct a two-way authentication protocol between the charging pile and the battery management system (BMS) based on a hardware security module, and authenticate the identity; the communication encryption module is configured to encrypt secure communication data by customizing and integrating a transport layer security protocol line through an open source tool; the verification module is configured to design a three-level verification mechanism to block malicious firmware injection paths and verify the secure communication process; and the optimization module is configured to optimize key processes by using a containerized deployment redundancy backup scheme. Through two-way authentication, communication encryption, and three-level verification, man-in-the-middle attacks and replay attacks can be effectively prevented, and the identity of the charging pile and the BMS and the secure intercommunication of information can be ensured. Finally, through optimizing the key processes, a fast hot switching process can be realized, the system availability can be improved, and secure communication between the charging pile and the BMS can be realized.
[0034] In the embodiments of the application, the execution subject can be a charging pile and BMS secure communication device in the charging pile and BMS secure communication system. In actual applications, the charging pile and BMS secure communication device can be electronic devices such as terminal devices and servers, without limitation.
[0035] The charging pile and BMS secure communication system of the embodiments of the application will be described in detail below. Figure 1 The charging pile and BMS secure communication system of the embodiments of the application will be described in detail below.
[0036] Please refer to Figure 1 , Figure 1 A schematic block diagram of the charging pile and BMS secure communication system provided in the embodiments of the application is shown in FIG. 1. Figure 1 The charging pile and BMS secure communication system 100 includes: a two-way authentication module 110, a communication encryption module 120, a verification module 130, and an optimization module 140; the two-way authentication module 110 is configured to construct a two-way authentication protocol between the charging pile and the battery management system (BMS) based on a hardware security module, and authenticate the identity; the communication encryption module 120 is configured to encrypt secure communication data by customizing and integrating a transport layer security protocol line through an open source tool; the verification module 130 is configured to design a three-level verification mechanism to block malicious firmware injection paths and verify the secure communication process; and the optimization module 140 is configured to optimize key processes by using a containerized deployment redundancy backup scheme.
[0037] The security communication between the security module user charging pile and the battery management system BMS includes a security communication protocol and algorithm. The two-way authentication protocol includes a hardware security module (HSM)-based national secret SM2 two-way authentication protocol, which replaces the traditional RSA one-way authentication. The open source tool can be an embedded system information security protection of the Yocto open source project. The transmission layer security protocol line can be a standard TLS protocol stack. The redundancy backup scheme of containerization deployment can be set according to actual needs. The key processes include multiple processes encountered by each node during the charging process, such as charging start, starting power supply and closing power supply, etc.
[0038] In some embodiments of the present application, the two-way authentication module 110 is specifically configured to: determine a unique authentication method for the charging pile and the BSM through the public key of the preset algorithm of the hardware module HSM; and authenticate the identity of the charging pile and the BSM through a two-factor authentication mechanism of device identity and dynamic key in the unique authentication method.
[0039] In the above process, the two-factor authentication mechanism of device identity and dynamic key in the unique authentication method can effectively prevent man-in-the-middle attacks and replay attacks, and ensure mutual trust of the identity of the charging pile and the vehicle BMS.
[0040] The preset algorithm can be an SM2 national secret algorithm. The device identity includes the charging pile and the vehicle. For example, the Yocto system layer integrates the operator-level identification authentication capability, generates and stores the public and private key pair of the SM2 national secret algorithm through the HSM hardware module, and issues a unique digital certificate for the charging pile and the BMS device. In the authentication process, the device fingerprint (such as the MAC address hash value) and the dynamic session key are fused to form a two-factor authentication mechanism of "device identity + dynamic key". A hierarchical certificate architecture is adopted, and a three-level trust chain is composed of a root certificate (Root CA), a device manufacturer intermediate certificate (Sub-CA) and a device terminal certificate. The certificate chain is signed by a commercial cryptographic algorithm authenticated by a cryptographic authority, to ensure the authenticity of each certificate is verifiable.
[0041] In some embodiments of the present application, the communication encryption module 120 is specifically configured to: through the open source tool, tailor the standard transmission layer security protocol and remove the compatible module of the historical version, and customize and integrate the transmission layer security protocol line; and encrypt the secure communication data through the transmission layer security protocol line, the pre-stored shared key and the session key.
[0042] In the above process, the transmission layer security protocol line, the pre-stored shared key and the session key can encrypt the secure communication data to ensure the secure intercommunication of the charging pile and the vehicle BMS.
[0043] Among them, the customized integrated transport layer security protocol line includes the implementation of a forward secure key agreement mechanism by customizing the integrated TLS1.3 protocol stack in Yocto. For example, during the Yocto build process, the standard TLS protocol stack is trimmed, the necessary components of TLS1.3 are retained, and the historical version compatibility module is removed. By dividing the secure storage area through ARM TrustZone, the pre-shared key (PSK) and session key are stored separately to prevent memory leakage attacks. Forward secure key agreement: Based on the Elliptic Curve Diffie-Hellman (ECDH), a temporary key exchange is implemented to generate a unique encryption key for each session. Combined with the SM3 hash algorithm, the integrity of the key agreement process is verified to prevent man-in-the-middle tampering.
[0044] In some embodiments of the present application, the verification module 130 is specifically used to build a four-level startup verification system and a three-level verification mechanism through vehicle wireless download technology: block the malicious firmware injection path through the four-level startup verification system and the three-level verification mechanism, and verify the secure communication process.
[0045] In the above process, the three-level verification mechanism and the four-level startup verification system can block the malicious firmware injection path and verify the secure communication process.
[0046] Among them, the four-level startup verification system includes a four-level startup verification system of BL0→BL1→BL2→OS, specifically: BL0 (ROM code) verifies the digital signature of BL1, BL1 verifies the hash value of BL2, BL2 verifies the certificate chain of the kernel and the driver module, and the OS layer implements runtime memory write protection. The three-level verification mechanism can be: digital signature verification: use a device-specific private key to sign the firmware package. Hash tree verification: build a Merkle tree to verify the integrity of the firmware fragments. Sandbox verification: simulate running new firmware in a TEE environment, and activate after detecting abnormal behavior.
[0047] Optionally, blocking the malicious firmware injection path through the four-level startup verification system and the three-level verification mechanism to verify the secure communication process includes: combining the design of the secure boot chain (Secure Boot Chain) to implement the three-level verification mechanism (digital signature verification, hash tree verification, and runtime memory protection) during the OTA upgrade process, and block the malicious firmware injection path. On the hardware-level secure execution environment, rely on the ARM TrustZone technology to create a trusted execution environment (TEE), isolate the running of the charging control core algorithm, key management, and other modules to prevent memory tampering and side channel attacks. On the dynamic behavior monitoring system, deploy an anomaly detection module based on a machine learning model to analyze CAN bus communication characteristics, charging power fluctuation patterns, and other parameters to implement a microsecond-level response intrusion blocking mechanism.
[0048] In some embodiments of the present application, the optimization module 140 is specifically configured to: divide the secure world and the normal world by using the containerized deployment redundancy backup scheme; deploy the key management module and the authentication core algorithm module in the secure world; and optimize the key process through the key management module and the authentication core algorithm module.
[0049] In the above process, the present application can optimize the key process to realize the fast hot switching process by dividing the secure world and the normal world through the containerized deployment redundancy backup scheme.
[0050] The secure world and the normal world are two hardware isolation domains divided by the ARM TrustZone technology, the secure world is used to run security-sensitive modules, and the normal world is used to run non-security-sensitive regular processes. The key management module and the authentication core algorithm module are components deployed in the secure world. For example, by using the containerized deployment redundancy backup scheme, the lightweight characteristics of the Yocto system (memory occupation <128 MB) are maintained, and the fast hot switching of the key process is realized, and the system availability is improved.
[0051] For example, by using the TrustZone technology of the ARM Cortex-A series processor, the secure world (Secure World) and the normal world (Normal World) are divided. The key management, authentication core algorithm and other modules are deployed in the secure world, and are physically isolated from the charging control logic. The password operation acceleration optimization is realized through the special password engine of the HSM module, including: the SM2 signature speed is improved to 2000 times / sec, the SM4 encryption and decryption throughput is up to 5Gbps, and the random number generator (TRNG) resistant to side channel attacks. This implementation scheme combines the password technology and trusted computing in depth, which not only meets the national secret compliance requirements, but also meets the real-time requirements (authentication delay <50ms, encryption packet processing delay <5μs) of the vehicle-mounted communication scene.
[0052] In the above Figure 1In the process, the application provides a system for secure communication between charging piles and BMS, including a two-way authentication module 110, a communication encryption module 120, a verification module 130, and an optimization module 140; the two-way authentication module 110 is used to construct a two-way authentication protocol between the charging pile and the battery management system (BMS) based on the hardware security module, and to authenticate the identity; the communication encryption module 120 is used to encrypt secure communication data by customizing and integrating a transmission layer security protocol line through an open source tool; the verification module 130 is used to design a three-level verification mechanism to block malicious firmware injection paths and verify the secure communication process; and the optimization module 140 is used to optimize key processes by using a containerized deployment redundancy backup scheme. Through two-way authentication, communication encryption, and three-level verification, man-in-the-middle attacks and replay attacks can be effectively prevented, and the identity trust and information security interworking of the charging pile and the vehicle BMS can be ensured. Finally, through the optimization of key processes, a fast hot switching process can be realized, the system availability can be improved, and secure communication between the charging pile and the BMS can be realized.
[0053] The following will be described in detail Figure 2 The method for secure communication between charging piles and BMSs of the embodiments of the application will be described in detail.
[0054] Please refer to Figure 2 , Figure 2 A flowchart of the method for secure communication between charging piles and BMSs provided by the embodiments of the application is shown in Figure 2 The method for secure communication between charging piles and BMSs includes the following steps: Step 210: Constructing a two-way authentication protocol between the charging pile and the battery management system (BMS).
[0055] Step 220: Customizing and integrating a transmission layer security protocol line through an open source tool.
[0056] Step 230: Designing a three-level verification mechanism and a containerized deployment redundancy backup scheme.
[0057] Step 240: Authenticating, encrypting, verifying, and optimizing the communication process between the charging pile and the BMS through the two-way authentication protocol, the integrated transmission layer security protocol line, the three-level verification mechanism, and the containerized deployment redundancy backup scheme.
[0058] Specifically, the communication process between the charging pile and the BMS is authenticated, encrypted, verified, and optimized through a two-way authentication protocol, an integrated transport layer security protocol line, a three-level verification mechanism, and a containerized deployment redundancy backup scheme. This includes: determining a unique authentication method for the charging pile and BSM using the public key of the preset algorithm in the hardware module HSM; authenticating the identity of the charging pile and BMS through a two-factor authentication mechanism using device identity and dynamic keys in the unique authentication method; customizing and integrating the transport layer security protocol line by using open-source tools, trimming the standard transport layer security protocol and removing compatible modules from previous versions; encrypting secure communication data using the transport layer security protocol line, pre-stored shared keys, and session keys; constructing a four-level boot verification system and a three-level verification mechanism using vehicle wireless download technology; blocking malicious firmware injection paths and verifying the secure communication process through the four-level boot verification system and the three-level verification mechanism; adopting a containerized deployment redundancy backup scheme to separate the secure world and the normal world; deploying the key management module and the authentication core algorithm module in the secure world; and optimizing key processes through the key management module and the authentication core algorithm module.
[0059] also, Figure 2 The specific methods and steps shown can be found in [reference]. Figure 1 The method shown will not be elaborated further here.
[0060] The previous text passed Figures 1-2 The system and method for secure communication between charging piles and BMS are described below. Figures 3-4 A device describing secure communication between a charging station and a BMS.
[0061] Please refer to Figure 3 This is a schematic block diagram of a device 300 for secure communication between a charging pile and a BMS provided in an embodiment of this application. The device 300 can be a module, program segment, or code on an electronic device. This device 300 is related to the above... Figure 1 The method implementation corresponds to this and can be executed. Figure 1 The various steps involved in the method embodiments and the specific functions of the device 300 can be found in the following description. To avoid repetition, detailed descriptions are appropriately omitted here.
[0062] Optionally, the device 300 includes: Module 310 is used to build a two-way authentication protocol between the charging pile and the battery management system (BMS). Integration module 320 is used to customize and integrate transport layer security protocol lines using open source tools; Design module 330 is used to design a three-level verification mechanism and a redundant backup scheme for containerized deployment; The communication module 340 is used to authenticate, encrypt, verify, and optimize the communication process between the charging pile and the BMS through a two-way authentication protocol, an integrated transport layer security protocol line, a three-level verification mechanism, and a containerized deployment redundancy backup scheme.
[0063] Optionally, the communication module is specifically used for: A unique authentication method is determined for the charging pile and BMS using the public key of the preset algorithm in the hardware module HSM. The identity of the charging pile and BMS is authenticated through a two-factor authentication mechanism using device identity and dynamic keys within the unique authentication method. Open-source tools are used to trim the standard transport layer security protocol and remove compatible modules from previous versions, while a customized transport layer security protocol line is integrated. Secure communication data is encrypted using the transport layer security protocol line, pre-stored shared keys, and session keys. A four-level boot verification system is constructed, along with a three-level verification mechanism built using vehicle wireless download technology. The four-level boot verification system and the three-level verification mechanism block malicious firmware injection paths and verify the secure communication process. A containerized deployment redundancy backup scheme is adopted, separating the secure world from the normal world. The key management module and the core authentication algorithm module are deployed in the secure world. Key processes are optimized through the key management module and the core authentication algorithm module.
[0064] Please refer to Figure 4 This is a schematic block diagram of a device for secure communication between a charging pile and a BMS, provided in an embodiment of this application. The device may include a memory 410 and a processor 420. Optionally, the device may further include a communication interface 430 and a communication bus 440. This device is similar to the one described above. Figure 1 The method implementation corresponds to this and can be executed. Figure 1 The specific functions of the device involved in the method embodiments can be found in the following description.
[0065] Specifically, memory 410 is used to store computer-readable instructions.
[0066] Processor 420 is used to process readable instructions stored in memory and is capable of executing... Figure 1 Each step in the method.
[0067] The communication interface 430 is used for signaling or data communication with other node devices. For example, it is used for communication with a server or terminal, or for communication with other device nodes, but the embodiments of this application are not limited thereto.
[0068] Communication bus 440 is used to enable direct communication between the above components.
[0069] The communication interface 430 of the device in the embodiments of the present application is configured to communicate signaling or data with other node devices. The memory 410 can be a high-speed RAM memory or a non-volatile memory such as at least one disk memory. The memory 410 can alternatively be at least one storage device located remotely from the aforementioned processor. The memory 410 stores computer-readable instructions which, when executed by the processor 420, cause the electronic device to perform the method processes described above Figure 1 The processor 420 can be used in the device 300 and configured to perform the functions in the embodiments of the present application. By way of example, the processor 420 described above can be a general-purpose processor, a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component, and the embodiments of the present application are not limited thereto.
[0070] The embodiments of the present application further provide a readable storage medium. When the computer program is executed by the processor, the method processes performed by the electronic device in the method embodiments described above are performed. Figure 1 The embodiments of the present application further provide a readable storage medium. When the computer program is executed by the processor, the method processes performed by the electronic device in the method embodiments described above are performed.
[0071] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the device described above can refer to the corresponding processes in the foregoing methods, and will not be described in detail herein.
[0072] In summary, the embodiments of the present application provide a system, method, device, apparatus and storage medium for secure communication between a charging pile and a BMS. The system includes a two-way authentication module, a communication encryption module, a verification module and an optimization module. The two-way authentication module is configured to construct a two-way authentication protocol between the charging pile and the BMS based on a hardware security module, and authenticate the identity. The communication encryption module is configured to encrypt secure communication data by customizing and integrating a Transport Layer Security protocol line through an open source tool. The verification module is configured to design a three-level verification mechanism to block malicious firmware injection paths and verify the secure communication process. The optimization module is configured to optimize key processes using a containerized deployment redundancy backup scheme. The system can achieve the effect of secure communication between the charging pile and the BMS.
[0073] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can also be implemented by other means. The apparatus embodiments described above are only illustrative, for example, the flowcharts and block diagrams in the drawings show the possible implementation architecture, function and operation of the apparatus, method and computer program product according to the embodiments of the present application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment or a part of code, which contains one or more executable instructions for implementing the specified logic function. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur in different order from that shown in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and sometimes they can be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0074] In addition, the functional modules in the various embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0075] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.
[0076] The above merely provides an example of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, and thus, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.
[0077] The above merely provides an example of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, and thus, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.
[0078] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one from another entity or action without necessarily requiring or implying any actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus. An element proceeded by "comprises... a" does not, without more constraints, exclude the existence of additional identical elements in the process, method, article, or apparatus that comprises the element.
Claims
1. A system for secure communication between a charging pile and a BMS, characterized in that, include: Two-way authentication module, communication encryption module, verification module, and optimization module; The two-way authentication module is used to build a two-way authentication protocol between the charging pile and the battery management system (BMS) based on the hardware security module to authenticate the identity. The communication encryption module is used to encrypt secure communication data by customizing and integrating a transport layer security protocol line using open-source tools. The verification module is used to design a three-level verification mechanism to block malicious firmware injection paths and verify the secure communication process. The optimization module is used to optimize critical processes using a containerized deployment redundancy backup scheme.
2. The system according to claim 1, characterized in that, The two-way authentication module is specifically used for: A unique authentication method is determined for the charging pile and the BSM using the public key of the preset algorithm of the hardware module HSM. The identities of the charging pile and the BMS are authenticated through a two-factor authentication mechanism using the device identity and dynamic key in the unique authentication method.
3. The system according to claim 1 or 2, characterized in that, The communication encryption module is specifically used for: Using the aforementioned open-source tools, standard transport layer security protocols are trimmed and compatibility modules from previous versions are removed, and custom integration of transport layer security protocol lines is achieved. The secure communication data is encrypted using the transport layer security protocol line, a pre-stored shared key, and a session key.
4. The system according to claim 1 or 2, characterized in that, The verification module is specifically used for; Construct a four-level startup verification system and build the three-level verification mechanism using vehicle wireless download technology: The four-level startup verification system and the three-level verification mechanism are used to block malicious firmware injection paths and verify the secure communication process.
5. The system according to claim 1 or 2, characterized in that, The optimization module is specifically used for: A redundant backup solution using containerized deployment is adopted to separate the secure world from the normal world; Deploy the key management module and the core authentication algorithm module in this secure world; The key process is optimized through the key management module and the authentication core algorithm module.
6. A method for secure communication between a charging pile and a BMS, characterized in that, include: Establish a two-way authentication protocol between charging piles and battery management systems (BMS); Customize and integrate transport layer security protocol lines using open-source tools; Design a three-level verification mechanism and a redundant backup scheme for containerized deployment; The communication process between the charging pile and the BMS is authenticated, encrypted, verified, and optimized through the two-way authentication protocol, the integrated transport layer security protocol line, the three-level verification mechanism, and the containerized deployment redundancy backup scheme.
7. The method according to claim 6, characterized in that, The process of authenticating, encrypting, verifying, and optimizing the communication process between the charging pile and the BMS through the two-way authentication protocol, the integrated transport layer security protocol line, the three-level verification mechanism, and the containerized deployment redundancy backup scheme includes: A unique authentication method is determined for the charging pile and the BSM using the public key of the preset algorithm of the hardware module HSM. The identities of the charging pile and the BMS are authenticated through a two-factor authentication mechanism using the device identity and dynamic key in the unique authentication method. Using the aforementioned open-source tools, standard transport layer security protocols are trimmed and compatibility modules from previous versions are removed, and custom integration of transport layer security protocol lines is achieved. The secure communication data is encrypted using the transport layer security protocol line, a pre-stored shared key, and a session key; Construct a four-level startup verification system and build the three-level verification mechanism using vehicle wireless download technology: The four-level boot verification system and the three-level verification mechanism are used to block malicious firmware injection paths and verify the secure communication process. A redundant backup solution using containerized deployment is adopted to separate the secure world from the normal world; Deploy the key management module and the core authentication algorithm module in this secure world; The key process is optimized through the key management module and the authentication core algorithm module.
8. A device for secure communication between a charging pile and a BMS, characterized in that, include: The building module is used to build a two-way authentication protocol between the charging pile and the battery management system (BMS). Integration modules are used to customize and integrate transport layer security protocol lines using open-source tools; The design module is used to design a three-level verification mechanism and a redundant backup scheme for containerized deployment; The communication module is used to authenticate, encrypt, verify, and optimize the communication process between the charging pile and the BMS through the two-way authentication protocol, the integrated transport layer security protocol line, the three-level verification mechanism, and the containerized deployment redundancy backup scheme.
9. An electronic device, characterized in that, include: A memory and a processor, the memory storing computer-readable instructions that, when executed by the processor, perform the steps of the method as described in any one of claims 6-7.
10. A computer-readable storage medium, characterized in that, include: A computer program that, when run on a computer, causes the computer to perform the method as described in any one of claims 6-7.
Citation Information
Cited By
Universal battery BMU bidirectional authentication method with dynamic protection and full-scene adaptation
CN121530775A
A universal battery BMU two-way authentication method with dynamic protection and full-scenario adaptability
CN121530775B