A charging facility security control method and device based on a dynamic identity code and an electronic device

By employing a dual-channel mechanism and a dynamic identity code authentication method with multiple authentication steps, the problem of charging piles being unable to effectively defend against network attacks has been solved, achieving better security protection.

CN121418216BActive Publication Date: 2026-04-24NINGBO DIGITAL TWIN (EASTERN UNIV OF TECH) RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NINGBO DIGITAL TWIN (EASTERN UNIV OF TECH) RES INST
Filing Date
2025-12-30
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing security protection solutions for charging piles are unable to effectively prevent attacks, especially man-in-the-middle attacks, and are difficult to defend against cyberattacks while ensuring the normal operation of the charging piles.

Method used

A dual-channel mechanism is adopted, which uses a dedicated network to transmit dynamic identity codes for authentication, and combines historical identity codes and numbers for multi-factor authentication to ensure that control commands are executed only after successful authentication.

Benefits of technology

It effectively prevents attacks, enhances the security of charging piles, resists man-in-the-middle attacks, and ensures that the normal operation of charging facilities is not affected.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121418216B_ABST
    Figure CN121418216B_ABST
Patent Text Reader

Abstract

The embodiment of the specification discloses a charging facility security control method and device based on a dynamic identity code and electronic equipment. The method comprises the following steps: in response to the fact that a general network receives a control instruction sent by a server, sending an identity authentication request to the server based on a special network; obtaining identity information replied by the server based on the identity authentication request, determining a first number corresponding to the identity information, and querying a first historical identity code in a local first historical database according to a second number corresponding to the first number based on a preset rule; verifying the identity information based on the first historical identity code and a first dynamic identity code stored locally, and executing the control instruction after the identity information passes the verification. In the embodiment, the attack behavior can be effectively prevented in normal work, the man-in-the-middle attack can be more effectively resisted, and the safety protection effect of the charging pile is better.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments in this specification pertain to the field of charging facility safety authentication, and specifically relate to a charging facility safety control method, device, and electronic device based on dynamic identification codes. Background Technology

[0002] With the rapid popularization of new energy vehicles, the construction of charging piles has entered a period of rapid growth. Simultaneously, attacks targeting charging piles are also on the rise. Currently, most charging pile security protection solutions primarily address the detection of attacks targeting charging piles. They cannot effectively prevent ongoing attacks while ensuring the normal operation of the charging piles remains unaffected, and they are unable to defend against new types of network attacks targeting charging piles, such as "man-in-the-middle attacks," which are compliant with protocols and maintain normal network communication. In summary, existing charging pile security protection solutions offer limited protection and are insufficient to meet the security requirements of charging piles. Summary of the Invention

[0003] Embodiments of this disclosure provide a method, apparatus, and electronic device for safety control of charging facilities based on dynamic identification codes, which are intended to solve one or more of the above-mentioned problems and other potential problems.

[0004] According to a first aspect of this disclosure, a charging facility security control method based on a dynamic identity code is provided. The method includes: responding to a control command received from a server via a general network; sending an authentication request to the server via a dedicated network, wherein the general network is used to transmit regular data and the dedicated network is used to transmit a dynamic identity code, the dynamic identity code being updated based on random time; obtaining identity information replied by the server based on the authentication request; determining a first number corresponding to the identity information; calculating a second number corresponding to the first number based on a preset rule; querying a first historical identity code in a local first historical database based on the second number; the identity information being composed of a second dynamic identity code from the server, a second historical identity code randomly obtained from the second historical database, and a first number corresponding to the second historical identity code; and verifying the identity information based on the first historical identity code and the locally stored first dynamic identity code, so as to execute the control command after the identity information is verified.

[0005] According to a second aspect of this disclosure, a charging facility safety control device based on a dynamic identity code is provided. The device includes an instruction receiving module configured to receive a control instruction sent by a server via a general network, and send an authentication request to the server via a dedicated network. The general network is used to transmit regular data, and the dedicated network is used to transmit a dynamic identity code, which is updated based on random time. A number determination module is configured to obtain identity information replied by the server based on the authentication request, determine a first number corresponding to the identity information, calculate a second number corresponding to the first number based on a preset rule, and query a first historical identity code in a local first historical database based on the second number. The identity information is composed of a second dynamic identity code from the server, a second historical identity code randomly obtained from the second historical database, and a first number corresponding to the second historical identity code. An execution module is configured to verify the identity information based on the first historical identity code and the locally stored first dynamic identity code, and execute the control instruction after the identity information is verified.

[0006] According to a third aspect of this disclosure, an electronic device is provided, including one or more processors and a memory associated with the one or more processors, the memory being used to store program instructions that, when read and executed by the one or more processors, perform a method provided according to a first scheme.

[0007] According to a fourth aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the method provided according to the first aspect.

[0008] The solution provided in the embodiments of this specification can use a dual-channel dynamic identity code interaction mechanism. The dynamic identity code is authenticated by a dedicated network, and data interaction is only carried out on the general network after the authentication is successful. During identity authentication, the currently used dynamic identity code and the historical identity code randomly selected for this authentication are double-authenticated. This effectively prevents attack behavior during normal operation and more effectively resists man-in-the-middle attacks, resulting in better security protection for charging piles. Attached Figure Description

[0009] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:

[0010] Figure 1 A flowchart illustrating a charging facility security control method based on dynamic identification codes, according to some embodiments of this disclosure, is shown.

[0011] Figure 2 A schematic diagram of the structure of a charging facility safety control device based on a dynamic identification code, according to some embodiments of the present disclosure, is shown.

[0012] Figure 3 A schematic block diagram of an electronic device according to some embodiments of the present disclosure is shown. Detailed Implementation

[0013] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0014] The terms “comprising” and “having”, and any variations thereof, in this specification, claims, and the foregoing drawings are intended to cover a non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. Depending on the context, the word “if” as it applies herein may be interpreted as “when”, “in response to determination”, or “in response to detection”.

[0015] Figure 1 A flowchart illustrating a dynamic identification code-based security control method 100 for charging facilities, representing some embodiments of this disclosure, is shown. Method 100 can be executed by a charging facility, such as a charging pile, shared power bank, or electric bicycle. Figure 1 As shown, in method 100, step 102 may respond to the general network receiving a control command sent by the server and send an authentication request to the server based on the private network. The general network is used to transmit regular data, and the private network is used to transmit dynamic identity codes, which are updated based on random time.

[0016] In this embodiment, a dual-channel connection can be established between the charging facility and the server, meaning that two channels exist simultaneously: a general network and a dedicated network. The general network corresponds to the business data channel, used to transmit regular data (such as charging amount, amount, start / stop commands, etc.). This channel has poor security and will be defined as an "untrusted channel." The dedicated network corresponds to the security verification channel, used to transmit dynamic identity codes, verification requests for dynamic identity codes, update commands for dynamic identity codes, etc. This will be defined as a "trusted channel," which can be a channel connected by a physical cable, or a logical channel built using a VPN tunnel, a separate port, or a specific encryption protocol. The dedicated network will be specifically used to verify the reliability of the server sending the command through the dynamic identity code. After verification, the data will be transmitted normally through the general network. Since all normal data goes through the general network, it increases the difficulty of discovering the dynamic identity code in the smaller dedicated network. Furthermore, because the channels are separate, the dedicated network can use asymmetric encryption to transmit data, further increasing the difficulty of cracking the channel once it is discovered.

[0017] When a server wants to control a charging facility, the charging facility does not directly execute control commands. Instead, it uses the server's IP address or ID to determine the dedicated network connected to that server and sends an authentication request to the server via that dedicated network. This request informs the server that identity verification based on a dynamic identity code is required. The dynamic identity code is a code that updates randomly over a period of time (typically between 30-60 minutes to avoid excessively long intervals). Each update synchronizes the dynamic identity codes of both the server and the charging facility via the dedicated network, ensuring that their dynamic identity codes are consistent under normal circumstances.

[0018] In method 100, step 104 can obtain the identity information replied by the server based on the identity authentication request, determine the first number corresponding to the identity information, calculate the second number corresponding to the first number based on preset rules, and query the first historical identity code in the local first historical database according to the second number. The identity information is composed of the server's second dynamic identity code, the second historical identity code randomly obtained from the second historical database, and the first number corresponding to the second historical identity code.

[0019] In this embodiment, the charging facility and the server are equipped with a first historical database and a second historical database, respectively, to store the old dynamic identity codes that are replaced after the dynamic identity codes are updated. That is, the old dynamic identity codes are stored as historical identity codes in the first / second historical databases, and each historical identity code is assigned a corresponding number. To further increase the difficulty of cracking, the same historical identity code may not have the same number in the two historical databases; instead, a mapping is performed based on a preset rule. As an example, for the same historical identity code C in the charging facility's historical database A and the server's historical database B, the preset rule could be set as A+3=B, meaning that the number of C in A plus three equals the number of C in B. If the maximum number is exceeded, the counting continues from the minimum number. The identity information sent by the server can be encoded using the latest updated dynamic identity code currently in use by the server (i.e., the second dynamic identity code), a second historical identity code randomly selected from the historical database, and the first number. By decoding the identity information, the charging facility can obtain a second dynamic identity code, a second historical identity code, and a first number. Then, it converts the first number according to the stored preset rules to obtain the second number, and retrieves the first historical identity code from the first historical database stored locally in the charging facility based on the second number.

[0020] In method 100, step 106 can verify the identity information based on the first historical identity code and the first dynamic identity code stored locally, so as to execute control instructions after the identity information is verified.

[0021] In this embodiment, the charging facility also locally stores the latest updated first dynamic identity code. By comparing the first dynamic identity code with the retrieved first historical identity code, the reliability of the identity information can be verified. If both match, the identity information is considered verified, and control commands will be executed. In this way, not only is a dedicated network used for dynamic identity code identification and authentication, but also historical identity codes and corresponding numbers are used for multi-factor authentication. Even if the dedicated network is discovered, it is difficult for hackers to determine the corresponding number of the historical identity code on the charging facility's local storage, ultimately leading to verification failure. This provides better security protection and control for the charging facility.

[0022] In one possible implementation, before sending an authentication request to the server via a dedicated network, the method further includes:

[0023] Place control commands into the execution queue and lock the hardware control interface;

[0024] After identity information is verified, control commands are executed, including:

[0025] After the identity information is verified, the hardware control interface is unlocked, and control commands are retrieved and executed from the queue to be executed.

[0026] In this embodiment, after receiving a control command, the charging facility does not immediately execute it. Instead, it temporarily stores the command in an execution queue and temporarily locks the hardware control interface. Only after successful identity verification will the charging facility unlock the hardware control interface and retrieve the control command from the execution queue for execution.

[0027] In one possible implementation, the method further includes:

[0028] In response to the failure to verify the identity information, the control command is removed from the queue to be executed, and the server that sent the control command is marked as abnormal.

[0029] In this embodiment, if the identity information fails verification (generally due to a mismatch in the identity code or the inability to parse the corresponding identity code, resulting in a verification timeout), the identity information is considered invalid. In this case, the control command in the execution queue can be deleted, and the server sending the control command can be marked as abnormal, with the corresponding attack log recorded. For servers marked as abnormal, attack decoys can be implemented; instead of immediately severing the connection with the server, a "masquerade mode" is entered to record the attacker's IP address, command characteristics, and attack frequency, without performing any actual action. In this way, any control command is first placed in the execution queue, and then the decision to extract it from the queue for execution is based on the identity information verification result, ensuring that even if the charging facility is attacked, the normal execution of normal commands will not be affected.

[0030] In one possible implementation, the method further includes:

[0031] If both the first dynamic identity code and the second dynamic identity code, as well as the first historical identity code and the second historical identity code, are matched, the identity information is marked as verified.

[0032] In this embodiment, the identity information will only be marked as verified if the first dynamic identity code and the second dynamic identity code match, and the first historical identity code obtained by querying the second number matches the second historical identity code obtained by parsing the identity information. Only then can the corresponding control command be considered a legitimate command.

[0033] In one possible implementation, the method further includes:

[0034] A first waiting time is randomly generated based on a timer. After the first waiting time, a third dynamic identity code is generated. Based on the first dynamic identity code and the third dynamic identity code, a first update information is generated and sent to the server through a dedicated network.

[0035] The system receives the first update confirmation instruction returned by the server from the dedicated network, stores the first dynamic identity code as a historical identity code in the first historical database, uses the third dynamic identity code as the new first dynamic identity code, and regenerates the first waiting time.

[0036] In this embodiment, the timer within the charging facility can randomly generate a first waiting period. After the first waiting period, the dynamic identity code update process will be triggered. Specifically, the charging facility first generates a new dynamic identity code, namely the third dynamic identity code, and generates first update information by encoding the first and third dynamic identity codes. Then, the first update information is sent to the server via a dedicated network. After receiving the first update information, the server decodes it and verifies whether the old dynamic identity code (i.e., the first dynamic identity code) is consistent with the second dynamic identity code currently stored locally. If they are inconsistent, the update will be rejected, a replay attack may be suspected, and communication will be locked. If they are consistent, the dynamic identity code used by the server will be updated according to the new dynamic identity code (i.e., the third dynamic identity code), and a first update confirmation instruction will be returned. After receiving the first update confirmation instruction and verifying that the hash is correct, the charging facility considers the update valid, officially activates the third dynamic identity code, stores the old first dynamic identity code as a historical identity code in the first historical database, and regenerates a new first waiting period to wait for the next update.

[0037] In other possible implementations, the conditions for triggering dynamic identity code updates may also include event-triggered methods, such as when the cumulative number of communications reaches a threshold, or when network fluctuations are detected and reconnection is initiated, which will force an update.

[0038] In one possible implementation, the method further includes:

[0039] In response to the second update confirmation command sent by the server from the private network, the second update confirmation command is parsed to obtain the second dynamic identity code and the fourth dynamic identity code. The fourth dynamic identity code is a new dynamic identity code generated by the server after a randomly generated second waiting period.

[0040] In response to the matching of the first dynamic identity code and the second dynamic identity code, the first dynamic identity code is stored as a historical identity code in the first historical database, the fourth dynamic identity code is used as the new first dynamic identity code, and a second update confirmation instruction is returned to the server through a dedicated network.

[0041] In this embodiment, similarly, in addition to the charging facility, the server also initiates an update of the dynamic identity code based on a randomly generated second waiting time. The first and second waiting times can be generated independently. According to the second update confirmation instruction, the charging facility parses the second and fourth dynamic identity codes using pre-set decoding rules. If the second dynamic identity code matches the locally stored first dynamic identity code, the fourth dynamic identity code (i.e., the new dynamic identity code generated by the server) is stored as the new first dynamic identity code, and the old dynamic identity code is stored as a historical identity code in the first historical database. Simultaneously, the charging facility returns a second update confirmation instruction to the server to inform it that the new dynamic identity code is officially activated.

[0042] Furthermore, if the server and the charging facility initiate update requests almost simultaneously (e.g., the time interval between updates is less than 1 minute), the new dynamic identity code generated by one party can be determined based on a preset priority (e.g., the server has a higher priority than the charging facility), and the other party will abandon the update request and respond to the other party.

[0043] In one possible implementation, the method further includes:

[0044] Determining the connection status of a private network based on heartbeat packet detection;

[0045] In response to a connection status indicating an interruption, the execution of instructions of the preset type is prohibited.

[0046] In this embodiment, the connection status of the dedicated network can be continuously monitored based on the heartbeat packet detection method. If the dedicated network is found to be interrupted, even if the general network is normal, a "soft circuit breaker" signal will be sent to the main control program immediately to forcibly prohibit the execution of all instructions involving preset types (such as funds and security), and only the status reporting function will be retained until the dedicated network is restored.

[0047] Figure 2 This document illustrates a schematic diagram of a charging facility safety control device 200 based on a dynamic identification code, representing some embodiments of this disclosure. The various embodiments in this specification are described in a progressive manner; similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on its differences from other embodiments. In particular, the device embodiments are largely similar to the method embodiments, and therefore the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments. Figure 2As shown, the device 200 includes an instruction receiving module 201, configured to receive a control instruction sent by a server via a general network, and send an authentication request to the server via a dedicated network. The general network is used to transmit regular data, and the dedicated network is used to transmit a dynamic identity code, which is updated based on random time. A number determination module 202 is configured to obtain the identity information replied by the server based on the authentication request, determine the first number corresponding to the identity information, calculate the second number corresponding to the first number based on a preset rule, and then query the first historical identity code in the local first historical database based on the second number. The identity information is composed of the server's second dynamic identity code, the second historical identity code randomly obtained from the second historical database, and the first number corresponding to the second historical identity code. An execution module 203 is configured to verify the identity information based on the first historical identity code and the locally stored first dynamic identity code, and execute the control instruction after the identity information is verified.

[0048] In one possible implementation, the instruction receiving module 201 is further configured to place control instructions into an execution queue and lock the hardware control interface; the execution module 203 is further configured to unlock the hardware control interface and retrieve and execute control instructions from the execution queue after the identity information is verified.

[0049] In one possible implementation, the execution module 203 is further configured to delete the control command from the queue to be executed and mark the server that sent the control command as abnormal in response to the failure of identity verification.

[0050] In one possible implementation, the execution module 203 is further configured to mark the identity information as verified in response to a match between the first dynamic identity code and the second dynamic identity code, as well as between the first historical identity code and the second historical identity code.

[0051] In one possible implementation, the device further includes a dynamic code update module, configured to randomly generate a first waiting period based on a timer, generate a third dynamic identity code after the first waiting period, generate first update information based on the first dynamic identity code and the third dynamic identity code, and send the first update information to the server via a dedicated network; receive a first update confirmation instruction returned by the server from the dedicated network, store the first dynamic identity code as a historical identity code in a first historical database, use the third dynamic identity code as a new first dynamic identity code, and regenerate the first waiting period.

[0052] In one possible implementation, in response to a second update confirmation instruction sent by the server from a dedicated network, the second update confirmation instruction is parsed to obtain a second dynamic identity code and a fourth dynamic identity code, wherein the fourth dynamic identity code is a new dynamic identity code generated by the server after a randomly generated second waiting period; in response to a match between the first dynamic identity code and the second dynamic identity code, the first dynamic identity code is stored as a historical identity code in a first historical database, the fourth dynamic identity code is used as a new first dynamic identity code, and the second update confirmation instruction is returned to the server through the dedicated network.

[0053] In one possible implementation, the device further includes a status detection module configured to determine the connection status of the private network based on heartbeat packet detection; and to prohibit the execution of preset type of instructions in response to a connection status characterized as an interruption.

[0054] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this specification is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., Digital Versatile Discs (DVDs)), or semiconductor media (e.g., Solid State Disks (SSDs)).

[0055] Figure 3 A block diagram of an electronic device 300 that can implement various embodiments of the present disclosure is shown. For example... Figure 3As shown, the electronic device 300 includes a processor 310, a disk drive 320, an input / output interface 330, a network interface 340, and a memory 350. The processor 310, disk drive 320, input / output interface 330, network interface 340, and memory 350 can communicate with each other via a communication bus 360.

[0056] The processor 310 can be implemented using a general-purpose CPU, microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits to execute relevant programs and implement the technical solution provided in this application.

[0057] The memory 350 can be implemented in the form of ROM (Read Only Memory), RAM (Read Access Memory), static memory, dynamic storage devices, etc. The memory 350 can store the operating system 351 used to control the operation of the electronic device 300, and the basic input / output system (BIOS) 352 used to control the low-level operations of the electronic device 300. Additionally, it can store a web browser 353, data storage management 354, etc. In summary, when the technical solution provided in this application is implemented through software or firmware, the relevant program code is stored in the memory 350 and is called and executed by the processor 310.

[0058] The input / output interface 330 is used to connect input / output modules to realize information input and output. Input / output modules can be configured as components within the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Input devices may include keyboards, mice, touchscreens, microphones, various sensors, etc., while output devices may include displays, speakers, vibrators, indicator lights, etc.

[0059] Network interface 340 is used to connect a communication module (not shown in the figure) to enable communication and interaction between the device and other devices. The communication module can communicate via wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0060] Bus 360 includes a pathway for transmitting information between various components of the device, such as processor 310, disk drive 320, input / output interface 330, network interface 340, and memory 350.

[0061] It should be noted that although the above-described device only shows the processor 310, disk drive 320, input / output interface 330, network interface 340, memory 350, bus 360, etc., in specific implementations, the device may also include other components necessary for normal operation. Furthermore, those skilled in the art will understand that the above-described device may only include the components necessary for implementing the method of this application, and does not necessarily include all the components shown in the figures.

[0062] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0063] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing. Furthermore, although operations are depicted in a specific order, this should be understood as requiring that such operations be performed in the specific order shown or in sequential order, or requiring that all illustrated operations be performed to achieve the desired result. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single implementation. Conversely, various features described in the context of a single implementation may also be implemented individually or in any suitable sub-combination in multiple implementations.

[0064] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A safety control method for charging facilities based on dynamic identification codes, characterized in that, The method includes: In response to receiving a control command from the server via a general network, an authentication request is sent to the server via a dedicated network. The general network is used to transmit regular data, and the dedicated network is used to transmit a dynamic identity code, which is updated based on random time. The system obtains the identity information replied by the server based on the identity authentication request, determines the first number corresponding to the identity information, calculates the second number corresponding to the first number based on a preset rule, and then queries the first historical identity code in the local first historical database according to the second number. The identity information is composed of the server's second dynamic identity code, the second historical identity code randomly obtained from the second historical database, and the first number corresponding to the second historical identity code. The identity information is verified based on the first historical identity code and the first dynamic identity code stored locally, so as to execute the control command after the identity information is verified.

2. The charging facility safety control method based on dynamic identity code according to claim 1, characterized in that, Before sending the authentication request to the server via the dedicated network, the process also includes: Place the control commands into the execution queue and lock the hardware control interface; The step of executing the control command after the identity information is verified includes: After the identity information is verified, the hardware control interface is unlocked, and the control command is retrieved and executed from the queue to be executed.

3. The charging facility safety control method based on dynamic identity code according to claim 2, characterized in that, The method further includes: In response to the identity information failing verification, the control command is deleted from the pending execution queue, and the server that sent the control command is marked as abnormal.

4. The charging facility safety control method based on dynamic identity code according to claim 1, characterized in that, The method further includes: In response to a match between the first dynamic identity code and the second dynamic identity code, as well as between the first historical identity code and the second historical identity code, the identity information is marked as verified.

5. The charging facility safety control method based on dynamic identity code according to claim 1, characterized in that, The method further includes: A first waiting time is randomly generated based on a timer. After the first waiting time, a third dynamic identity code is generated, and a first update information is generated based on the first dynamic identity code and the third dynamic identity code. The first update information is then sent to the server via a dedicated network. The system receives a first update confirmation instruction returned by the server from the dedicated network, stores the first dynamic identity code as a historical identity code in the first historical database, uses the third dynamic identity code as the new first dynamic identity code, and regenerates the first waiting time.

6. The charging facility safety control method based on dynamic identity code according to claim 1, characterized in that, The method further includes: In response to the second update information sent by the server from the private network, the second update information is parsed to obtain the second dynamic identity code and the fourth dynamic identity code, wherein the fourth dynamic identity code is a new dynamic identity code generated by the server after a randomly generated second waiting period; In response to the matching of the first dynamic identity code and the second dynamic identity code, the first dynamic identity code is stored as a historical identity code in the first historical database, the fourth dynamic identity code is used as the new first dynamic identity code, and a second update confirmation instruction is returned to the server through a dedicated network.

7. The charging facility safety control method based on dynamic identity code according to claim 1, characterized in that, The method further includes: Determining the connection status of a private network based on heartbeat packet detection; In response to the connection state being characterized as interrupted, the execution of a preset type of instruction is prohibited.

8. A safety control device for charging facilities based on dynamic identification codes, characterized in that, The device includes: The instruction receiving module is configured to respond to a control instruction sent by the server via a general network, and send an authentication request to the server via a dedicated network. The general network is used to transmit regular data, and the dedicated network is used to transmit a dynamic identity code, which is updated based on random time. The number determination module is configured to obtain the identity information replied by the server based on the identity authentication request, determine the first number corresponding to the identity information, calculate the second number corresponding to the first number based on preset rules, and then query the first historical identity code in the local first historical database according to the second number. The identity information is composed of the server's second dynamic identity code, the second historical identity code randomly obtained from the second historical database, and the first number corresponding to the second historical identity code. The execution module is configured to verify the identity information based on the first historical identity code and the first dynamic identity code stored locally, so as to execute the control command after the identity information is verified.

9. An electronic device, characterized in that, include: One or more processors, and A memory associated with the one or more processors, the memory being used to store program instructions that, when read and executed by the one or more processors, perform the steps of the charging facility security control method based on a dynamic identification code as described in any one of claims 1-7.

10. A computer program product, characterized in that, The method includes a computer program that, when executed by a processor, implements a charging facility security control method based on a dynamic identification code according to any one of claims 1-7.

Citation Information

Patent Citations

  • Short message verification method, device and system

    CN116471028A

  • User identity certificate processing method and device, identity authentication device and server

    CN120263438A