A BMS capability token-driven vehicle-pile safety fast charging interaction method

The vehicle-charging safe fast charging interaction method driven by BMS capability tokens solves the problem of trusted binding and smooth switching of the charging safety envelope allowed by BMS in vehicle-charging interaction in the existing technology. It realizes the trusted transmission and stable switching of battery safety boundary, improves charging safety and stability, and is applicable to the field of electric vehicle charging safety technology.

CN122293341APending Publication Date: 2026-06-26CHONGQING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHONGQING UNIV OF POSTS & TELECOMM
Filing Date
2026-04-10
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing vehicle-charging fast charging interaction solutions struggle to transform the permissible charging safety envelope determined by the BMS based on real-time battery status into verifiable, executable, and continuously updatable parameter constraints. This results in charging settings deviating from battery safety boundaries when the charging pile-side control logic is tampered with or negotiated parameters are illegally modified. Furthermore, the issues of smooth activation and stable switching between the old and new safety envelopes on the charging pile execution side remain unresolved.

Method used

The vehicle-charging safe fast charging interaction method driven by BMS capability tokens generates a session capability token through session initialization, binds the allowed charging safety envelope to the current session, uses digital signatures to ensure its trustworthiness, and achieves smooth activation and stable switching when the target safety envelope is updated. By encapsulating the transition safety envelope and duration through rolling capability tokens, a progressive activation mechanism is designed. Combined with multi-dimensional token verification and anomaly detection, a closed-loop safety control system is constructed for the entire process.

Benefits of technology

It achieves reliable transmission of battery safety boundaries from the vehicle to the charging station, avoiding the risk of charging exceeding limits due to control logic tampering and illegal parameter modification, ensuring charging stability and safety, being compatible with existing communication protocols, requiring no hardware modification, and supporting graded safety handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122293341A_ABST
    Figure CN122293341A_ABST
Patent Text Reader

Abstract

This invention provides a BMS capability token-driven vehicle-to-charging safe fast-charging interaction method, relating to the field of electric vehicle charging safety. The method includes: step S1, session initialization; step S2, initial parameter constraint benchmark generation; step S3, initial parameter constraint benchmark loading and constraint execution; step S4, rolling capability token generation and transition envelope construction; step S5, transition safety envelope loading and target safety envelope switching; and step S6, closed-loop verification and safety control based on the currently effective parameter constraint benchmark. This method enables the reliable loading, rolling update, progressive activation, and closed-loop verification of the BMS real-time safety boundary in the vehicle-to-charging session.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electric vehicle charging safety technology, specifically to a vehicle-charging safe fast charging interaction method driven by BMS capability tokens. Background Technology

[0002] In the process of DC fast charging of electric vehicles, session establishment, parameter negotiation, status reporting, and control execution are all indispensable. Due to the high charging power, frequent updates of control parameters, and the relatively open deployment environment of charging piles, there are risks such as message sniffing, replay attacks, man-in-the-middle attacks, fake pile access, and tampering with negotiated parameters during the vehicle-to-pile interaction process, which may lead to safety issues such as overcharging, overcurrent, and abnormal temperature rise.

[0003] Existing technologies often enhance the security of vehicle-charging pile interaction through communication link encryption, identity authentication, key negotiation, certificate management, or backend platform verification. However, these solutions primarily address communication confidentiality and the trustworthiness of both parties. Even when charging piles are compromised, control strategies are maliciously tampered with, session information is reused, or parameter negotiation results are illegally modified, issues can still arise where charging pile-side control parameters exceed the battery's real-time safety boundaries. Specifically, existing solutions lack a mechanism to reliably bind the permissible charging safety envelope calculated by the Battery Management System (BMS) based on real-time battery status to the current charging session and directly use it as the basis for charging pile-side parameter negotiation and control execution constraints. Furthermore, existing parameter update schemes often lack corresponding mechanisms for ensuring a smooth and stable transition between old and new safety envelopes on the charging pile execution side. When the target safety envelope is rapidly tightened or loosened, it can easily lead to sudden changes in setpoints, control oscillations, or boundary violations.

[0004] In summary, existing vehicle-to-charging (VTC) fast-charging interaction solutions primarily focus on communication link security, identity authentication, or backend verification. They struggle to transform the permissible charging safety envelope determined by the BMS based on real-time battery status into verifiable, executable, and continuously updatable parameter constraints within the current charging session. This leads to situations where, if the charging station control logic is tampered with, negotiated parameters are illegally modified, or session information is reused, the charging station setpoints and control execution results may still deviate from the battery's real-time safety boundaries. Furthermore, existing parameter-update-based control schemes often only focus on the transmission or replacement of the updated safety boundaries, failing to address the smooth implementation and stable switching of the old and new safety envelopes on the charging station execution side. When the updated target safety envelope rapidly tightens or loosens compared to the currently effective parameter constraint benchmark, issues such as sudden changes in setpoints, control oscillations, execution exceeding limits, or unstable target safety envelope switching may arise due to charging station control execution delays, limited parameter adjustment rates, communication jitter, or disturbances near the boundaries. Summary of the Invention

[0005] To address the problems existing in the prior art, the present invention aims to provide a vehicle-to-pile safe fast charging interaction method driven by BMS capability tokens. This method transforms the allowable charging safety envelope calculated by BMS based on real-time battery status into a verifiable, executable, and continuously updatable parameter constraint basis in the current charging session. At the same time, it achieves smooth activation, stable switching, and closed-loop backtesting of vehicle-to-pile safe fast charging interaction when the target safety envelope is updated.

[0006] The objective of this invention is achieved through the following technical solution:

[0007] A BMS capability token-driven vehicle-to-charging safe fast charging interaction method includes: Step S1, Session Initialization: The charging pile sends the charging pile identification information EVSE_ID and the session challenge value nonce_s to the vehicle. The vehicle BMS calculates the allowed charging safety envelope of the current session according to the current battery pack status parameters, associates the allowed charging safety envelope with the current vehicle-charging pile session binding information, and generates a session capability token through digital signature by the vehicle security module. Step S2: Initial parameter constraint benchmark generation: The charging pile verifies the validity of the session capability token and loads its corresponding allowed charging safety envelope as the current effective parameter constraint benchmark. Then, the upper limit of the target charging parameters is pruned according to the current effective parameter constraint benchmark. Step S3: Initial parameter constraint benchmark loading and execution constraints: During the charging execution phase, the vehicle generates an updated target safety envelope based on the real-time changes in the battery pack status. Based on the current effective parameter constraint benchmark, the target safety envelope, the tightening degree of the target safety envelope relative to the current effective parameter constraint benchmark, and the charging pile response capability parameters, the transition safety envelope and transition duration are determined. The target safety envelope, transition safety envelope, and transition duration are encapsulated in a rolling capability token, digitally signed, and sent to the charging pile. Step S4, Rolling Capability Token Generation and Transition Envelope Construction: The charging pile verifies the validity of the rolling capability token; then, the transition safety envelope is loaded as the current execution envelope, and the charging parameters are adjusted according to the preset parameter change rate limit during the transition duration (without directly replacing the current effective parameter constraint benchmark with the target safety envelope). Step S5, Transitional safety envelope loading and target safety envelope switching: When the parameters constrained by the transitional safety envelope in the actual charging voltage, actual charging current and / or actual charging power meet the target safety envelope entry conditions for N consecutive sampling periods, the charging pile will switch the target safety envelope to the currently effective parameter constraint benchmark. Step S6: Closed-loop verification and safety control based on the current effective parameter constraint benchmark: The vehicle-side performs consistency verification and dynamic over-limit verification on the charging parameters set on the charging pile side and the actual charging parameters based on the real-time updated current effective parameter constraint benchmark. Once a consistency abnormality, dynamic over-limit abnormality, abnormal token or transition abnormality is detected, the vehicle-side will jointly perform graded safety handling and generate a safety event record.

[0008] Based on further optimization of the above scheme, in step S1, the allowed charging safety envelope includes the maximum allowed charging voltage. V max Maximum allowable charging current I max Maximum allowable charging power P max and the maximum permissible rate of change of terminal voltage (dV / dt) max Maximum allowable rate of change of current (dI / dt) max Maximum permissible rate of temperature rise (dT / dt) max One or more of the maximum permissible state of charge range (SOC_range).

[0009] Based on further optimization of the above scheme, in step S1, the payload_s of the session capability token includes the identifier SID (used to identify the current vehicle-to-charging station session), the charging station identifier digest H (EVSE_ID), the session challenge value nonce_s (used to characterize the freshness of the current session and prevent the session capability token from being replayed), the session capability token expiration time ts_exp_s, and the allowed charging safety envelope parameter; and the vehicle-side security module digitally signs the payload_s to obtain the signature value Sig_s, and generates the session capability token Token_S based on the payload_s and Sig_s. ; The digital signature algorithm can be any of ECDSA, SM2, or EdDSA.

[0010] Based on the further optimization of the above scheme, step S2 specifically involves: the vehicle sending a session capability token Token_S to the charging pile; upon receiving Token_S, the charging pile obtains the public key information required for token verification based on a locally pre-configured public key, a certificate whitelist, or a background authentication service, and verifies the signature value Sig_s in Token_S; simultaneously, the charging pile also verifies the consistency between H(EVSE_ID) and the current charging pile identifier, and the consistency between nonce_s and the session challenge value sent by the charging pile during the current session initialization phase, ensuring that the time interval from the moment the session challenge value is sent to the moment the session capability token is received and verified does not exceed a preset freshness time window. Furthermore, the current time is earlier than the time when the session capability token expires (ts_exp_s); After the signature verification and validation are passed, the charging pile loads the corresponding allowed charging safety envelope of the session capability token as the current effective parameter constraint benchmark, and performs upper limit pruning on the target charging voltage, target charging current and target charging power respectively based on the current effective parameter constraint benchmark during parameter negotiation and control execution. If any verification fails during signature verification or validation, the charging station will refuse to use the session capability token and will execute at least one of the following tiered safety actions: refuse negotiation, limit output power, or suspend charging.

[0011] Based on further optimization of the above scheme, during the parameter negotiation process, the vehicle and the charging pile negotiate to obtain target charging parameters; the target charging parameters include one or more of the following: target charging voltage, target charging current, and target charging power.

[0012] Based on further optimization of the above scheme, in step S3, the tightening degree of the target safety envelope relative to the current effective parameter constraint benchmark is characterized by one or more of the following: maximum allowable charging voltage boundary difference, maximum allowable charging current boundary difference, maximum allowable charging power boundary difference, maximum allowable terminal voltage change rate boundary difference, and maximum allowable current change rate boundary difference. The charging pile response capability parameters include one or more of the following: upper limit of charging voltage adjustment rate, upper limit of charging current adjustment rate, upper limit of charging power adjustment rate, control execution delay, and sampling period; The lifecycle information of the rolling capability token is characterized by one or more of the remaining valid duration, the expiration time, and the reference valid window length. When constructing the transition safety envelope, the vehicle end coordinates the convergence speed of the transition boundary and the duration of the transition based on the tightening magnitude and the lifecycle information of the rolling capability token. The vehicle-side rolling capability token payload_r(k) includes the session identifier SID, charging pile identifier digest H(EVSE_ID), session challenge value nonce_s, rolling sequence number k, previous rolling capability token digest, rolling capability token expiration time ts_exp_r, rolling random number, target security envelope parameters, transition security envelope parameters, and transition duration. The vehicle-side security module digitally signs the payload_r(k) to obtain the signature value Sig_r(k), generating the session capability token Token_R(k). .

[0013] Based on further optimization of the above scheme, in step S3, the charging pile performs upper limit pruning on the corresponding target charging parameters based on the current effective parameter constraint benchmark, so that the target charging parameters do not exceed the upper limit of the allowable charging safety envelope limit; Specifically, when the target charging voltage obtained through negotiation is U req At that time, set the charging voltage. U set = min(U req , V max ) When the target charging current obtained through negotiation is I req At that time, set the charging current. I set = min(I req , I max ) When the target charging power obtained through negotiation is P rep At that time, set the charging power P set ≤ P max .

[0014] Based on further optimization of the above scheme, in step S4, the validity of the rolling capability token includes two aspects: the legality judgment result and the validity measurement value. The validity determination result is used to determine whether the rolling capability token is allowed to participate in the update of the currently effective parameter constraint benchmark: ; In the formula: Indicates the signature verification result of the rolling capability token (1 if the verification is successful, 0 otherwise); This indicates whether the session identifier SID, charging pile identifier digest H(EVSE_ID), and session challenge value nonce_s in the rolling capability token are consistent with the current vehicle-charging pile session (1 if consistent, 0 otherwise). Indicates the current time t Whether it is earlier than the time when the rolling capability token expires (ts_exp_r) (1 if satisfied, 0 otherwise); Indicates whether the rolling sequence number satisfies the monotonically increasing constraint and the preset receiving sequence number range constraint (1 if satisfied, 0 otherwise); Indicates whether the consistency check of the preceding rolling capability token digest has passed (1 if it passes, 0 otherwise); This indicates whether the rolling random number passes the deduplication check (1 if there are no duplicates, 0 otherwise). Indicates the result of the validity determination of the rolling capability token (when When, it indicates that the scrolling capability token has passed the validity check; when When this occurs, it indicates that the rolling capability token is invalid, and the charging pile will not update the currently effective parameter constraint benchmark based on the rolling capability token. The validity metric is used to characterize the degree of trustworthiness of the rolling capability token at the current moment, and is used to collaboratively determine the transition security envelope, transition duration, and the criteria for formal handover of the target security envelope. ; In the formula: Indicates the preset reference valid window length; This represents the validity metric of the rolling capability token, and its value ranges from [0,1] (when the rolling capability token chain is complete and the remaining validity time is sufficient). Approaching 1; when the scrolling capability token is nearing expiration, Gradually decrease; when the legality check fails, (0).

[0015] Based on the further optimization of the above scheme, in step S5, the vehicle sends a rolling capability token Token_R(k) to the charging pile in a periodic manner, with an update interval of 1s to 15s. After receiving the rolling capability token Token_R(k), the charging pile verifies the signature and checks whether the session identifier SID is consistent with the current vehicle-charging pile session, whether the charging pile identifier digest H(EVSE_ID) is consistent with the current charging pile identifier, whether the session challenge value nonce_s is consistent with the current session, whether the rolling random number is associated with the current session and is not repeated, and whether the rolling sequence number k is relative to the previously verified rolling sequence number. k last It meets the monotonically increasing requirement and is within the preset receiving sequence number range. k last +1, k last Within +W] (W is a positive integer), whether the digest of the preceding scroll capability token is consistent with the digest of the most recently verified and effective scroll capability token of the current session, and whether the current time is earlier than the time when the scroll capability token expires (ts_exp_r); Once the rolling capability token Token_R(k) passes signature verification and validation, the charging pile generates a rolling capability token validity determination result Valid_r based on the signature verification result, session consistency verification result, rolling sequence number verification result, previous rolling capability token digest consistency verification result, rolling random number deduplication verification result, and token validity period verification result. Furthermore, assuming the validity determination is passed, a rolling capability token validity metric is generated based on the remaining valid duration between the current time and the expiration time of the rolling capability token. ; After successful verification, the charging pile will load the transition safety envelope as the current execution envelope (instead of directly replacing the current effective parameter constraint benchmark with the target safety envelope), and adjust the set charging voltage, set charging current, and / or set charging power according to the preset parameter change rate limit during the transition duration; simultaneously, the charging pile will adjust the set charging voltage, set charging current, and / or set charging power according to the rolling capability token validity metric. Adjust the transition execution strategy when When the value is large, a relatively fast transition convergence strategy is adopted; when... When the value is small, a relatively conservative transition convergence strategy is adopted, and the strength of the stability criterion required to formally switch to the target safe envelope is increased. When the parameters constrained by the transition safety envelope in the actual charging voltage, actual charging current and / or actual charging power meet the target safety envelope entry condition for N consecutive sampling periods, the target safety envelope is switched to the currently effective parameter constraint reference, and subsequent charging control is continued accordingly. When the rolling capability token Token_R(k) fails the signature verification or the aforementioned verification, or At that time, the charging pile will not update the currently effective parameter constraint benchmark based on the rolling capability token.

[0016] Based on further optimization of the above scheme, the target safety envelope entry conditions include: the actual charging voltage does not exceed the maximum allowable charging voltage defined by the target safety envelope, the actual charging current does not exceed the maximum allowable charging current defined by the target safety envelope, the actual charging power does not exceed the maximum allowable charging power defined by the target safety envelope, and the actual charging voltage change rate and / or the actual charging current change rate does not exceed the upper limit of the change rate defined by the target safety envelope.

[0017] Based on further optimization of the above scheme, in step S6, the charging parameters set on the pile side include setting the charging voltage, setting the charging current, and setting the charging power; the actual charging parameters include the actual charging voltage, actual charging current, and actual charging power.

[0018] The following are the technical effects of the present invention: This invention overcomes the limitations of existing solutions that only focus on communication layer security. It encapsulates the allowable charging safety envelope determined by the BMS based on real-time battery status into a cryptographically verifiable capability token uniquely bound to the current session. Once verified, this token directly serves as a mandatory constraint benchmark for pile-side parameter negotiation and control execution, achieving end-to-end trusted transmission of battery safety boundaries from the vehicle to the charging pile. This fundamentally solves the risk of charging exceeding limits caused by tampering with the charging pile's control logic and unauthorized parameter modification. Simultaneously, this invention encapsulates the target safety envelope, transition safety envelope, and transition duration through a rolling capability token, designing a gradual activation mechanism of "first transition execution, continuous stability determination, then formal switching." This avoids control abrupt changes, parameter oscillations, and execution out-of-bounds issues caused by directly replacing the activation benchmark, significantly improving charging stability during dynamic updates of the safety envelope. Furthermore, the transition safety envelope of this invention is not a fixed preset boundary but an executable boundary jointly determined by the current activation benchmark, target safety envelope, tightening range, charging pile response capability, and token validity. This allows for precise matching with charging pile hardware characteristics, control latency, and sampling period, achieving an adaptive and smooth transition for safety boundary updates.

[0019] This invention constructs a full-process closed-loop security control mechanism consisting of "boundary generation - trusted transmission - progressive execution - stable switching - closed-loop verification - anomaly handling". It constrains both the pile-side set value and the vehicle-side measured electrical parameters with the current effective parameter constraint benchmark. Combined with multi-dimensional token verification and anomaly detection, it effectively prevents various security threats such as parameter tampering, replay attacks, reverse tokens, and cross-session reuse.

[0020] This invention is compatible with existing vehicle-charging fast charging communication protocols, requires no large-scale modification to the hardware architecture, can be quickly implemented through software upgrades, and supports tiered safety handling strategies, balancing charging safety and charging efficiency, thus possessing strong engineering practicality and promotional value. Attached Figure Description

[0021] Figure 1 This is a schematic diagram of the vehicle-charging station safe fast charging interactive system in an embodiment of the present invention.

[0022] Figure 2 This is a schematic diagram of the vehicle-charging station safe fast charging interaction method in an embodiment of the present invention. Detailed Implementation

[0023] The technical solutions in the embodiments of the present invention will be clearly and completely described below. In the following description, specific details such as specific system structures and technologies are presented for illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present invention.

[0024] Example 1: A BMS capability token-driven vehicle-to-charging safe fast-charging interaction method employs a vehicle-to-charging safe fast-charging interaction system including both vehicle and charging pile ends. The vehicle end includes a Battery Management System (BMS), a vehicle controller, a vehicle safety module, and a vehicle-side communication unit. The charging pile end includes a parameter negotiation module, a charging control module, a capability token verification module, and a charging pile communication unit. The vehicle safety module uses a Hardware Security Module (HSM), a Trusted Execution Environment (TEE), or a security chip to store signature keys and perform digital signature operations. The specific method includes: Step S1, Session Initialization: The charging pile sends the charging pile identification information EVSE_ID and the session challenge value nonce_s to the vehicle. The vehicle BMS calculates the allowed charging safety envelope of the current session according to the current battery pack status parameters, associates the allowed charging safety envelope with the current vehicle-charging pile session binding information, and generates a session capability token through digital signature by the vehicle security module. The current battery pack status parameters include one or more of the following: individual cell voltage, total battery pack voltage, charging current, battery temperature, state of charge (SOC), state of health (SOH), insulation status, and historical rate of change.

[0025] The permissible charging safety envelope includes the maximum permissible charging voltage. V max Maximum allowable charging current I max Maximum allowable charging power P max and the maximum permissible rate of change of terminal voltage (dV / dt) max Maximum allowable rate of change of current (dI / dt) max Maximum permissible rate of temperature rise (dT / dt) max One or more of the following: maximum permissible state of charge range (SOC_range); Maximum allowable charging current I max : ; In the formula: This indicates the upper limit of the allowable charging current determined by the state of charge (SOC). This indicates the upper limit of the allowable charging current, determined by the battery temperature T. This indicates the upper limit of the allowable charging current determined by the battery's state of health (SOH). This represents the upper limit of the allowable charging current determined by the insulation state parameter Rins; the BMS takes the minimum value among the corresponding upper limits of the allowable charging current of the above constraints as the maximum allowable charging current for the current session. I max ; The payload_s of the session capability token includes the identifier SID (to identify the current vehicle-to-charging station session), the charging station identifier digest H (EVSE_ID), the session challenge value nonce_s (to characterize the freshness of the current session and prevent the session capability token from being replayed), the session capability token expiration time ts_exp_s, and the allowed charging safety envelope parameters; the vehicle-side security module digitally signs the payload_s to obtain the signature value Sig_s, and generates the session capability token Token_S based on the payload_s and Sig_s. ; The digital signature algorithm can be any of ECDSA, SM2, or EdDSA.

[0026] Step S2, Initial Parameter Constraint Baseline Generation: The charging pile verifies the validity of the session capability token and loads its corresponding allowed charging safety envelope as the currently effective parameter constraint baseline. Then, the upper limit of the target charging parameters is pruned based on the currently effective parameter constraint baseline; specifically: The vehicle sends a session capability token (Token_S) to the charging station. Upon receiving Token_S, the charging station obtains the public key information required for token verification based on its local pre-configured public key, certificate whitelist, or backend authentication service, and verifies the signature value Sig_s in Token_S. Simultaneously, the charging station also verifies the consistency between H(EVSE_ID) and the current charging station identifier, and the consistency between nonce_s and the session challenge value sent by the charging station during the current session initialization phase. Furthermore, the time interval from the moment the session challenge value is sent to the moment the session capability token is received and verified does not exceed a preset freshness time window. Furthermore, the current time is earlier than the time when the session capability token expires (ts_exp_s); After the signature verification and validation are passed, the charging pile loads the corresponding allowed charging safety envelope of the session capability token as the current effective parameter constraint benchmark, and performs upper limit pruning on the target charging voltage, target charging current and target charging power respectively based on the current effective parameter constraint benchmark during parameter negotiation and control execution; during parameter negotiation, the vehicle and the charging pile negotiate to obtain the target charging parameters; the target charging parameters include one or more of the target charging voltage, target charging current and target charging power.

[0027] If any verification fails during signature verification or validation, the charging station will refuse to use the session capability token and will execute at least one of the following tiered safety actions: refuse negotiation, limit output power, or suspend charging.

[0028] Step S3, Initial parameter constraint benchmark loading and execution constraint: During the charging execution phase, the vehicle generates an updated target safety envelope based on the real-time changes in the battery pack status. The tightening degree of the target safety envelope relative to the current effective parameter constraint benchmark is characterized by one or more of the following: maximum allowable charging voltage boundary difference, maximum allowable charging current boundary difference, maximum allowable charging power boundary difference, maximum allowable terminal voltage change rate boundary difference, and maximum allowable current change rate boundary difference. Based on the current effective parameter constraint benchmark, the target safety envelope, the tightening degree of the target safety envelope relative to the current effective parameter constraint benchmark, and the charging pile response capability parameters, the transition safety envelope and transition duration are determined. The charging pile response capability parameters include one or more of the following: upper limit of charging voltage adjustment rate, upper limit of charging current adjustment rate, upper limit of charging power adjustment rate, control execution delay, and sampling period. The target safety envelope, transition safety envelope, and transition duration are encapsulated in a rolling capability token, which is then digitally signed and sent to the charging pile. The lifecycle information of the rolling capability token is characterized by one or more of the remaining valid duration, the expiration time, and the reference valid window length. When constructing the transition safety envelope, the vehicle-side coordinates the convergence speed of the transition boundary and the transition duration based on the tightening amplitude and the lifecycle information of the rolling capability token. The vehicle-side rolling capability token payload_r(k) includes the session identifier SID, charging pile identifier digest H(EVSE_ID), session challenge value nonce_s, rolling sequence number k, previous rolling capability token digest, rolling capability token expiration time ts_exp_r, rolling random number, target security envelope parameters, transition security envelope parameters, and transition duration. The vehicle-side security module digitally signs the payload_r(k) to obtain the signature value Sig_r(k), generating the session capability token Token_R(k). .

[0029] The charging pile prunes the upper limit of the corresponding target charging parameters based on the current effective parameter constraint benchmark, so that the target charging parameters do not exceed the upper limit of the allowable charging safety envelope; Specifically, when the target charging voltage obtained through negotiation is U req At that time, set the charging voltage. U set = min(U req , V max ) When the target charging current obtained through negotiation is I req At that time, set the charging current. Iset = min(I req , I max ) When the target charging power obtained through negotiation is P rep At that time, set the charging power P set ≤ P max .

[0030] Step S4, Rolling Capability Token Generation and Transition Envelope Construction: The charging pile verifies the validity of the rolling capability token; the validity of the rolling capability token includes two aspects: the legality judgment result and the validity measurement value. The validity determination result is used to determine whether the rolling capability token is allowed to participate in the update of the currently effective parameter constraint benchmark: ; In the formula: Indicates the signature verification result of the rolling capability token (1 if the verification is successful, 0 otherwise); This indicates whether the session identifier SID, charging pile identifier digest H(EVSE_ID), and session challenge value nonce_s in the rolling capability token are consistent with the current vehicle-charging pile session (1 if consistent, 0 otherwise). Indicates the current time t Whether it is earlier than the time when the rolling capability token expires (ts_exp_r) (1 if satisfied, 0 otherwise); Indicates whether the rolling sequence number satisfies the monotonically increasing constraint and the preset receiving sequence number range constraint (1 if satisfied, 0 otherwise); Indicates whether the consistency check of the preceding rolling capability token digest has passed (1 if it passes, 0 otherwise); This indicates whether the rolling random number passes the deduplication check (1 if there are no duplicates, 0 otherwise). Indicates the result of the validity determination of the rolling capability token (when When, it indicates that the scrolling capability token has passed the validity check; when When this occurs, it indicates that the rolling capability token is invalid, and the charging pile will not update the currently effective parameter constraint benchmark based on the rolling capability token. The validity metric is used to characterize the degree of trustworthiness of the rolling capability token at the current moment, and is used to collaboratively determine the transition security envelope, transition duration, and the criteria for formal handover of the target security envelope. ; In the formula: Indicates the preset reference valid window length; This represents the validity metric of the rolling capability token, and its value ranges from [0,1] (when the rolling capability token chain is complete and the remaining validity time is sufficient). Approaching 1; when the scrolling capability token is nearing expiration, Gradually decrease; when the legality check fails, (0).

[0031] Then, the transition safety envelope is loaded as the current execution envelope, and the charging parameters are adjusted according to the preset parameter change rate limit during the transition duration (without directly replacing the current effective parameter constraint benchmark with the target safety envelope).

[0032] Step S5, Transitional safety envelope loading and target safety envelope switching: When the parameters constrained by the transitional safety envelope in the actual charging voltage, actual charging current and / or actual charging power meet the target safety envelope entry conditions for N consecutive sampling periods, the charging pile will switch the target safety envelope to the currently effective parameter constraint benchmark; specifically: the vehicle sends a rolling capability token Token_R(k) to the charging pile in a periodic manner, with an update interval of 1s to 15s; After receiving the rolling capability token Token_R(k), the charging pile verifies the signature and checks whether the session identifier SID is consistent with the current vehicle-charging pile session, whether the charging pile identifier digest H(EVSE_ID) is consistent with the current charging pile identifier, whether the session challenge value nonce_s is consistent with the current session, whether the rolling random number is associated with the current session and is not repeated, and whether the rolling sequence number k is relative to the previously verified rolling sequence number. k last It meets the monotonically increasing requirement and is within the preset receiving sequence number range. k last +1, k last Within +W] (W is a positive integer), whether the digest of the preceding scroll capability token is consistent with the digest of the most recently verified and effective scroll capability token of the current session, and whether the current time is earlier than the time when the scroll capability token expires (ts_exp_r); Once the rolling capability token Token_R(k) passes signature verification and validation, the charging pile generates a rolling capability token validity determination result Valid_r based on the signature verification result, session consistency verification result, rolling sequence number verification result, previous rolling capability token digest consistency verification result, rolling random number deduplication verification result, and token validity period verification result. Furthermore, assuming the validity determination is passed, a rolling capability token validity metric is generated based on the remaining valid duration between the current time and the expiration time of the rolling capability token. ; After successful verification, the charging pile will load the transition safety envelope as the current execution envelope (instead of directly replacing the current effective parameter constraint benchmark with the target safety envelope), and adjust the set charging voltage, set charging current, and / or set charging power according to the preset parameter change rate limit during the transition duration; simultaneously, the charging pile will adjust the set charging voltage, set charging current, and / or set charging power according to the rolling capability token validity metric. Adjust the transition execution strategy when When the value is large, a relatively fast transition convergence strategy is adopted; when... When the value is small, a relatively conservative transition convergence strategy is adopted, and the strength of the stability criterion required to formally switch to the target safe envelope is increased. When the parameters constrained by the transition safety envelope in the actual charging voltage, actual charging current and / or actual charging power meet the target safety envelope entry condition for N consecutive sampling periods, the target safety envelope is switched to the currently effective parameter constraint reference, and subsequent charging control is continued accordingly. When the rolling capability token Token_R(k) fails the signature verification or the aforementioned verification, or At that time, the charging pile will not update the currently effective parameter constraint benchmark based on the rolling capability token.

[0033] The entry conditions for the target safety envelope include: the actual charging voltage does not exceed the maximum permissible charging voltage defined by the target safety envelope; the actual charging current does not exceed the maximum permissible charging current defined by the target safety envelope; the actual charging power does not exceed the maximum permissible charging power defined by the target safety envelope; and the rate of change of the actual charging voltage and / or the rate of change of the actual charging current does not exceed the upper limit of the rate of change defined by the target safety envelope. Preferably, the entry conditions need to be met for N consecutive sampling periods to curb misjudgment switching caused by measurement noise, control execution delay, or short-term disturbances near the boundary, and to avoid premature switching when the actual charging parameters only momentarily enter the target safety envelope. The value of N consecutive sampling periods can be set according to the sampling period, control execution delay, and system disturbance level. If the value of N is too small, the probability of mis-switching may increase; if the value of N is too large, it will increase the time for formal switching to the target safety envelope.

[0034] If duplicate serial numbers, reverse serial numbers, rolling serial numbers exceeding the preset receiving serial number range, duplicate rolling random numbers, inconsistent digests of preceding rolling capability tokens, or cross-session reuse occur, the corresponding rolling capability token will be identified as an abnormal token. The charging pile will then perform tiered safety actions and generate a safety event record. If the actual charging parameters fail to enter the target safety envelope when the transition duration expires, or if the actual charging parameters exceed the transition safety envelope corresponding to the current execution state, it will be identified as a transition anomaly. The charging pile will then perform tiered safety actions and generate a safety event record. Abnormal token detection mainly occurs during the rolling capability token verification process on the charging pile side. The vehicle-side closed-loop backtesting focuses on consistency anomalies, dynamic limit exceeding anomalies, and transition anomalies.

[0035] The current effective parameter constraint benchmark is determined by the charging-allowed security envelope corresponding to the session capability token during the session initialization phase, by the transitional security envelope currently in the execution state during the rolling update phase, and by the target security envelope that has been switched and taken effect after the target security envelope entry conditions are met and the switch is completed. This forms a closed-loop control mechanism of boundary generation, boundary update, boundary progressive take-off and execution verification.

[0036] The current execution envelope refers to the transition safety envelope that the charging pile loads after the rolling capability token verification and validation are passed, and is used to constrain changes in the set charging parameters during the transition duration.

[0037] Step S6: Closed-loop verification and safety control based on the current effective parameter constraint benchmark: The vehicle-side performs consistency verification and dynamic over-limit verification on the charging parameters set on the pile side and the actual charging parameters based on the real-time updated current effective parameter constraint benchmark. The charging parameters set on the pile side include the set charging voltage, set charging current and set charging power; the actual charging parameters include the actual charging voltage, actual charging current and actual charging power; once a consistency anomaly, dynamic over-limit anomaly, anomaly token or transition anomaly is detected, the vehicle-side will jointly perform graded safety handling and generate a safety event record.

[0038] Specifically, the vehicle-side performs consistency checks and dynamic limit checks on the set charging voltage, set charging current, set charging power, and actual charging voltage, actual charging current, and actual charging power based on the currently effective parameter constraint benchmark. The currently effective parameter constraint benchmark is determined by the allowed charging security envelope corresponding to the currently effective session capability token Token_S, the transitional security envelope currently in execution, or the target security envelope that has been switched to take effect.

[0039] If the actual charging parameters fail to enter the target safety envelope by the end of the transition duration, or if the actual charging parameters exceed the transition safety envelope corresponding to the current execution state, it is considered a transition anomaly. If the set charging parameters exceed the upper limit of the current effective parameter constraint benchmark, or if the deviation between the actual charging parameters and the set charging parameters exceeds a preset threshold, it is considered a consistency anomaly. If the actual charging voltage change rate exceeds (dV / dt), it is considered a transition anomaly. max Or, the actual rate of change of charging current exceeds (dI / dt). max When this occurs, it is determined to be a dynamic over-limit anomaly.

[0040] The consistency check should at least include: comparing the set charging voltage with the maximum allowable charging voltage V. max The set charging current is compared with the maximum allowable charging current I. max The set charging power will be compared with the maximum allowable charging power P. max The actual charging voltage, actual charging current, or actual charging power collected are compared with the corresponding set charging parameters.

[0041] Once a consistency anomaly, dynamic over-limit anomaly, abnormal token, or transition anomaly is detected, the vehicle and / or charging pile will perform corresponding graded safety actions and generate a safety event record; the graded safety actions include at least one of reducing output power, limiting output current, suspending charging, and disconnecting the charging connection.

[0042] In some implementations, the vehicle obtains the set charging voltage, set charging current, and / or set charging power through vehicle-to-pile control feedback messages, status messages, or control setting values ​​transmitted back from the pile side. After synchronizing the set charging parameters with the actual charging parameters according to a unified sampling period or timestamp, consistency verification and dynamic limit over-limit verification are performed.

[0043] The closed-loop backtesting performed on the vehicle is not based on a fixed threshold, but on the current effective parameter constraint benchmark to dynamically verify the consistency between the charging parameters set on the charging pile side and the actual charging parameters. In this way, the boundary update results at different stages can be tracked and backtested.

[0044] Example 2: As another preferred embodiment of the technical solution of the present invention, based on the above embodiment 1, in order to further illustrate the role of the rolling capability token verification mechanism in abnormal token scenarios, under the condition of keeping the current vehicle-charging session unchanged, the following abnormal rolling capability tokens are constructed respectively: duplicate serial number rolling capability token, reverse rolling capability token, abnormal token with inconsistent digest of previous rolling capability token, repeated rolling random number token, and cross-session reuse token.

[0045] After receiving the aforementioned abnormal rolling capability token, the charging pile verifies the signature and session binding information, rolling sequence number, previous rolling capability token digest, rolling random number, and validity period. If any verification fails, the charging pile does not update the current effective parameter constraint benchmark based on the corresponding abnormal rolling capability token, and executes the corresponding hierarchical safety actions and safety event records.

[0046] Therefore, the present invention can not only achieve trusted updates and smooth switching of the target security envelope, but also curb the impact of duplicate tokens, reversed tokens, abnormal tokens and cross-session reuse on the security of the current charging session.

Claims

1. A BMS capability token-driven vehicle-charging safe fast charging interaction method, characterized in that: include: Step S1, Session Initialization: The charging pile sends the charging pile identification information EVSE_ID and the session challenge value nonce_s to the vehicle. The vehicle-side BMS calculates the allowed charging safety envelope of the current session based on the current battery pack status parameters, associates the allowed charging safety envelope with the current vehicle-charging station session binding information, and generates a session capability token through digital signature by the vehicle-side security module. Step S2: Initial parameter constraint benchmark generation: The charging pile verifies the validity of the session capability token and loads its corresponding allowed charging safety envelope as the current effective parameter constraint benchmark. Then, the upper limit of the target charging parameters is pruned according to the current effective parameter constraint benchmark. Step S3: Initial parameter constraint benchmark loading and execution constraints: During the charging execution phase, the vehicle generates an updated target safety envelope based on the real-time changes in the battery pack status. Based on the current effective parameter constraint benchmark, the target safety envelope, the tightening degree of the target safety envelope relative to the current effective parameter constraint benchmark, and the charging pile response capability parameters, the transition safety envelope and transition duration are determined. The target safety envelope, transition safety envelope, and transition duration are encapsulated in a rolling capability token, digitally signed, and sent to the charging pile. Step S4, Rolling Capability Token Generation and Transition Envelope Construction: The charging pile verifies the validity of the rolling capability token; then, the transition safety envelope is loaded as the current execution envelope, and the charging parameters are adjusted according to the preset parameter change rate limit during the transition duration (without directly replacing the current effective parameter constraint benchmark with the target safety envelope). Step S5, Transitional safety envelope loading and target safety envelope switching: When the parameters constrained by the transitional safety envelope in the actual charging voltage, actual charging current and / or actual charging power meet the target safety envelope entry conditions for N consecutive sampling periods, the charging pile will switch the target safety envelope to the currently effective parameter constraint benchmark. Step S6: Closed-loop verification and safety control based on the current effective parameter constraint benchmark: The vehicle-side performs consistency verification and dynamic over-limit verification on the charging parameters set on the charging pile side and the actual charging parameters based on the real-time updated current effective parameter constraint benchmark. Once a consistency abnormality, dynamic over-limit abnormality, abnormal token or transition abnormality is detected, the vehicle-side will jointly perform graded safety handling and generate a safety event record.

2. The BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 1, characterized in that: In step S1, the allowed charging safety envelope includes the maximum allowed charging voltage. V max Maximum allowable charging current I max Maximum allowable charging power P max and the maximum permissible rate of change of terminal voltage (dV / dt) max Maximum allowable rate of change of current (dI / dt) max Maximum permissible rate of temperature rise (dT / dt) max One or more of the maximum permissible state of charge range (SOC_range).

3. A BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 1 or 2, characterized in that: In step S1, the payload_s of the session capability token includes the identifier SID, the charging pile identifier digest H (EVSE_ID), the session challenge value nonce_s, the session capability token expiration time ts_exp_s, and the allowed charging safety envelope parameters; and the vehicle-side security module digitally signs the payload_s to obtain the signature value Sig_s, and generates the session capability token Token_S based on the payload_s and Sig_s. 。 4. A BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 2 or 3, characterized in that: Step S2 specifically involves: the vehicle sending a session capability token Token_S to the charging pile; upon receiving Token_S, the charging pile obtains the public key information required for token verification based on a locally pre-configured public key, a certificate whitelist, or a background authentication service, and verifies the signature value Sig_s in Token_S; simultaneously, the charging pile also verifies the consistency between H(EVSE_ID) and the current charging pile identifier, and the consistency between nonce_s and the session challenge value sent by the charging pile during the current session initialization phase, ensuring that the time interval from the moment the session challenge value is sent to the moment the session capability token is received and verified does not exceed a preset freshness time window. Furthermore, the current time is earlier than the time when the session capability token expires (ts_exp_s); After the signature verification and validation are passed, the charging pile loads the corresponding allowed charging safety envelope of the session capability token as the current effective parameter constraint benchmark, and performs upper limit pruning on the target charging voltage, target charging current and target charging power respectively based on the current effective parameter constraint benchmark during parameter negotiation and control execution. If any verification fails during signature verification or validation, the charging station will refuse to use the session capability token and will execute at least one of the following tiered safety actions: refuse negotiation, limit output power, or suspend charging.

5. The BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 4, characterized in that: In step S3, the tightening extent of the target safety envelope relative to the current effective parameter constraint benchmark is characterized by one or more of the following: maximum allowable charging voltage boundary difference, maximum allowable charging current boundary difference, maximum allowable charging power boundary difference, maximum allowable terminal voltage change rate boundary difference, and maximum allowable current change rate boundary difference. The charging pile response capability parameters include one or more of the following: upper limit of charging voltage adjustment rate, upper limit of charging current adjustment rate, upper limit of charging power adjustment rate, control execution delay, and sampling period; The lifecycle information of the rolling capability token is characterized by one or more of the remaining valid duration, the expiration time, and the reference valid window length. When constructing the transition safety envelope, the vehicle end coordinates the convergence speed of the transition boundary and the duration of the transition based on the tightening magnitude and the lifecycle information of the rolling capability token. The rolling capability token payload_r(k) constructed on the vehicle side includes the session identifier SID, the charging pile identifier digest H(EVSE_ID), the session challenge value nonce_s, the rolling sequence number k, the digest of the preceding rolling capability token, the rolling capability token expiration time ts_exp_r, the rolling random number, the target safety envelope parameter, the transition safety envelope parameter, and the transition duration. The vehicle-side security module then digitally signs the payload_r(k) to obtain the signature value Sig_r(k), and generates a session capability token Token_R(k). 。 6. The BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 5, characterized in that: In step S4, the validity of the rolling capability token includes two aspects: the legality determination result and the validity measurement value. The validity determination result is used to determine whether the rolling capability token is allowed to participate in the update of the currently effective parameter constraint benchmark: ; In the formula: This indicates the signature verification result of the rolling capability token; This indicates whether the session identifier SID, charging pile identifier digest H(EVSE_ID), and session challenge value nonce_s in the rolling capability token are consistent with the current vehicle-charging pile session; Indicates the current time t Whether it is earlier than the time when the rolling capability token expires (ts_exp_r); This indicates whether the rolling sequence number satisfies the constraints of monotonically increasing and preset receiving sequence number range; Indicates whether the consistency check of the preceding rolling capability token digest has passed; Indicates whether the rolling random number passes the deduplication check; This indicates the result of the validity determination of the rolling capability token; The validity metric is used to characterize the degree of trustworthiness of the rolling capability token at the current moment, and is used to collaboratively determine the transition security envelope, transition duration, and the criteria for formal handover of the target security envelope. ; In the formula: Indicates the preset reference valid window length; This represents the validity metric for the rolling capability token, and its value ranges from [0,1].

7. The BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 6, characterized in that: In step S5, the vehicle sends a rolling capability token Token_R(k) to the charging pile in a periodic manner, with an update interval of 1s to 15s. After receiving the rolling capability token Token_R(k), the charging pile verifies the signature and checks whether the session identifier SID is consistent with the current vehicle-charging pile session, whether the charging pile identifier digest H(EVSE_ID) is consistent with the current charging pile identifier, whether the session challenge value nonce_s is consistent with the current session, whether the rolling random number is associated with the current session and is not repeated, and whether the rolling sequence number k is relative to the previously verified rolling sequence number. k last It meets the monotonically increasing requirement and is within the preset receiving sequence number range. k last +1, k last Within +W], whether the digest of the preceding scroll capability token is consistent with the digest of the most recently verified and effective scroll capability token in the current session, and whether the current time is earlier than the time when the scroll capability token expires (ts_exp_r); Once the rolling capability token Token_R(k) passes the signature verification and validation, the charging pile generates the rolling capability token legality determination result Valid_r based on the signature verification result, session consistency verification result, rolling sequence number verification result, previous rolling capability token digest consistency verification result, rolling random number deduplication verification result, and token validity period verification result. Provided that the validity is verified, a validity metric for the rolling capability token is generated based on the remaining valid duration between the current time and the expiration time of the rolling capability token. ; After successful verification, the charging station will load the transition safety envelope as the current execution envelope, and adjust the set charging voltage, set charging current, and / or set charging power according to the preset parameter change rate limit during the transition duration; simultaneously, the charging station will adjust the rolling capability token validity metric. Adjust the transition execution strategy when When the value is large, a relatively fast transition convergence strategy is adopted; when... When the value is small, a relatively conservative transition convergence strategy is adopted, and the strength of the stability criterion required to formally switch to the target safe envelope is increased. When the parameters constrained by the transition safety envelope in the actual charging voltage, actual charging current and / or actual charging power meet the target safety envelope entry condition for N consecutive sampling periods, the target safety envelope is switched to the currently effective parameter constraint reference, and subsequent charging control is continued accordingly. When the rolling capability token Token_R(k) fails the signature verification or the aforementioned verification, or At that time, the charging pile will not update the currently effective parameter constraint benchmark based on the rolling capability token.

8. The BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 7, characterized in that: The conditions for entering the target safety envelope include: the actual charging voltage does not exceed the maximum allowable charging voltage defined by the target safety envelope, the actual charging current does not exceed the maximum allowable charging current defined by the target safety envelope, the actual charging power does not exceed the maximum allowable charging power defined by the target safety envelope, and the actual charging voltage change rate and / or the actual charging current change rate does not exceed the upper limit of the change rate defined by the target safety envelope.

9. A BMS capability token-driven vehicle-charging safe fast charging interaction method according to claim 8, characterized in that: In step S6, setting the charging parameters on the pile side includes setting the charging voltage, setting the charging current, and setting the charging power; the actual charging parameters include the actual charging voltage, actual charging current, and actual charging power.