Ev charger safety system and method thereof

By introducing safety devices for end-to-end encryption in the EV charging system, the issues of insecure and non-compliant data transmission are resolved, achieving secure data transmission and compliance protection, and enhancing the system's security and reliability.

CN122477620APending Publication Date: 2026-07-28XINANYUAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XINANYUAN TECHNOLOGY CO LTD
Filing Date
2024-10-23
Publication Date
2026-07-28

AI Technical Summary

Technical Problem

Existing EV charging systems suffer from insecure data transmission, vulnerability to man-in-the-middle attacks, insufficient authentication mechanisms, and difficulty in complying with regional data protection regulations, impacting user privacy and financial security. Furthermore, there is a lack of dedicated security solutions for the EV charging ecosystem.

Method used

Security devices, including a communication module, microprocessor, FPGA chip, and security element, are used for end-to-end encryption in the EV charging network. Two-factor authentication is achieved through certified security element and administrator authentication module to ensure the security and compliance of data during transmission.

Benefits of technology

It enables comprehensive encryption and decryption of data in the EV charging network, enhancing system security and compliance, protecting user privacy and financial security, and preventing unauthorized access and data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122477620A_ABST
    Figure CN122477620A_ABST
Patent Text Reader

Abstract

The present invention provides a security device suitable for an EV charging network having a plurality of EV chargers and an EV charging backend. The security device comprises a communication module having an interface for locally connecting to an EV charger or an EV charging backend to transmit data over a communication network, a microprocessor as a control unit of the security device and processing data flow, a FPGA chip for encrypting / decrypting data, and a secure element for processing key distribution required for the FPGA chip to encrypt / decrypt data. The security device is locally connected to an EV charger or an EV charging backend and, in operation, encrypts / decrypts data transmitted over a communication network such that the data is end-to-end encrypted by the security device throughout the EV charging network. The present invention also provides an EV charging network and corresponding methods.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to safety systems. More specifically, this invention relates to systems and methods for protecting data at electric vehicle (EV) charging stations. Background Technology

[0002] The expansion of electric vehicle (EV) charging infrastructure brings various challenges related to the safe and efficient management of charging operations. Traditional EV charging systems typically involve direct communication between charging stations and backend data centers to process transactions, manage user data, and update firmware. However, these systems suffer from numerous security vulnerabilities, including but not limited to insecure data transmission, vulnerability to man-in-the-middle attacks, and inadequate authentication mechanisms. These vulnerabilities not only compromise user privacy and financial security but also undermine the reliability and integrity of the EV charging infrastructure.

[0003] Furthermore, existing solutions typically employ standard encryption technologies without considering the unique needs and challenges of the EV charging ecosystem, such as the need for real-time data exchange, the management of large volumes of transaction data, and the necessity for interoperability across different manufacturers and service providers. In addition, the geographical diversity of charging stations further complicates matters regarding unified security measures and compliance with regional data protection regulations.

[0004] The limitations of existing systems highlight the need for a data transmission security solution specifically designed for the EV charging ecosystem. Such a system would need to comprehensively address the aforementioned vulnerabilities, ensuring robust encryption, secure authentication, and regulatory compliance, while facilitating efficient and reliable communication between EV charging stations and backend data centers.

[0005] As the adoption of electric vehicles continues to increase, the infrastructure supporting their operation, especially EV charging stations, is becoming increasingly critical. Along with this growth, the secure transmission of data (including payment information, user identification information, and charging status) is essential to ensuring user trust and preventing unauthorized access and potential data breaches. Summary of the Invention

[0006] In one aspect of the invention, a safety device is provided suitable for an EV charging network having multiple EV chargers and one EV charging backend. The safety device includes: a communication module having an interface for locally connecting as a gateway to an EV charger or EV charging backend to transmit data via the communication network; a microprocessor acting as a control unit of the safety device and processing the data stream; an FPGA chip for encrypting / decrypting the data; and a security element for handling key distribution processing required by the FPGA chip for encrypting / decrypting the data. The safety device is locally connected to the EV charger or EV charging backend and, in operation, encrypts / decrypts data transmitted via the communication network, such that the data is end-to-end encrypted by the safety device throughout the EV charging network.

[0007] In one embodiment, the security element is certified according to Common Criteria (CC) or Federal Information Processing Standards (FIPS).

[0008] In another embodiment, the security device may further include an administrator authentication module for authenticating access to the security device. The administrator authentication module may be configured as a card and have its own security element embedded therein. Alternatively, the administrator authentication module may be integrated into the security device in the form of a biometric scanner / sensor. Furthermore, the administrator authentication module may be remotely deployed with the security device.

[0009] In another aspect of the invention, an EV charging network is also provided, comprising multiple EV chargers connected to an EV charging backend via a communication network, wherein the communication network can be a wired network or a wireless network. The EV charging network includes the aforementioned safety device, wherein the safety device is local and directly connected to the EV charger, such that data passes through the safety device before being transmitted to the communication network, and another safety device is directly connected before the EV charging backend.

[0010] In another aspect of the invention, a method for providing additional encryption / decryption to an EV charging network via a communication network is also provided. The method includes: adding a safety device to an EV charging network having an EV charger and an EV charging backend connected via the communication network; activating a safety element of the safety device; encrypting data from the EV charger via the safety device; transmitting the encrypted data to the EV charging backend via the communication network; and decrypting the encrypted data by the safety device for processing by the EV charging backend. The data transmitted via the communication network is end-to-end encrypted by the safety device.

[0011] In one embodiment, the end-to-end encryption is performed by the aforementioned security device. Attached Figure Description

[0012] The present invention will now be described with reference to the accompanying drawings and non-limiting embodiments, wherein: Figure 1 A block diagram of an EV charging system according to an embodiment of the present invention is shown; Figure 2 An EV charging network according to an alternative embodiment of the present invention is shown; Figure 3 The flow chart of an EV charging network according to an embodiment of the present invention is shown; Figure 4 An embodiment of the present invention is shown, having Figure 1 A schematic diagram of the EV charging network for the safety device shown; Figure 5 A block diagram of a safety device according to an alternative embodiment of the present invention is shown. Detailed Implementation

[0013] Consistent with the foregoing description of the invention, the following provides a description of several specific and alternative embodiments to illustrate the inventive features of the present invention. However, those skilled in the art will understand that the invention can be practiced without these specific details. To avoid obscuring the invention, certain details may not be repeated. For ease of reference, common reference numerals will always be used when referring to the same or similar common features in the various drawings.

[0014] Figure 1 A block diagram of a secure transmission system for an electric vehicle (EV) charging network 100 according to an embodiment of the present invention is shown. The EV charging network 100 includes a plurality of EV chargers 110 connected to an EV charging backend 120 via a communication network 150. Each EV charger is locally connected to a security device 182 for encrypting / decrypting data to be transmitted via the communication network 150. The communication network 150 may be a private data network dedicated to the EV charging network, or it may be a public data network or a cloud network. The EV charging network 100 also includes a central security device 184, which is locally connected directly to the EV charging backend 120 for decrypting data transmitted via the communication network 150.

[0015] Security device 182 and central security device 184 each include a certified security element adapted to encrypt / decrypt data transmitted through communication network 150. The certified security element should at least be certified according to the Common Criterion (CC) and / or the Federal Information Processing Standard (FIPS). Those skilled in the art will readily understand that CC and FIPS certifications are security standards used to evaluate the security features of devices or systems, including smart chips, also known as security elements. These certifications assess a range of security features, such as access control, authentication, secure boot, and key management, to ensure that the device or system is securely designed and implemented.

[0016] The communication network 150 can be any data communication network, wired and / or wireless, and includes a local area network (LAN) or a wide area network (WAN). In one embodiment, the communication network 150 can be a cloud network. In another embodiment, it can also be a mobile communication network.

[0017] In one embodiment, safety devices 182 and 184 are adapted to be plug-and-play devices. Safety devices 182 and 184 may employ connectors compatible with data communication network 150, such as Power over Ethernet (PoE), coaxial cable, RJ45, etc.

[0018] It should be noted that EV charging stations or EV charging towers and their components are well known in the art. These components are available as off-the-shelf products.

[0019] For the avoidance of doubt, the term "secure element" in this specification refers to a secure module designed to provide secure storage and processing of sensitive data, such as encryption keys, certificates, and passwords. A secure element is a microchip embedded in a device, designed to provide a secure execution environment for sensitive operations such as authentication, encryption, and decryption, and is typically used in applications requiring a high level of security, such as mobile payments, digital identity, and secure communications. Furthermore, it provides a range of security features, such as secure boot, hardware-based encryption, and secure storage of encryption keys. These features help protect the secure element from physical and logical attacks, such as side-channel attacks, brute-force attacks, and tampering. Secure elements are typically certified by independent organizations, such as Common Guidelines (CC) or Federal Information Processing Standards (FIPS), to ensure they meet specific security requirements. These certifications assure users and customers that the secure element has undergone rigorous testing and evaluation to ensure it achieves a high level of security.

[0020] The security element is a hardware-based solution for protecting data at the transmission layer. This solution is a plug-and-play system that can be customized and upgraded to meet the owner's requirements and can be manufactured and configured independently without affecting the EV charger, thus allowing for complete owner control. The owner can remotely and securely manage the entire EV charger system and its security. End-to-end encryption of data transmitted over the network is provided using independent encryption and decryption devices. Furthermore, this external device with the security element can be added to existing EV chargers. These additions protect data transmission on the EV charging network, even relative to the EV charging system manufacturer.

[0021] Figure 2 A secure transmission system for an EV charging network 200 according to an alternative embodiment of the present invention is illustrated. Similarly, the EV charging network 200 includes a plurality of EV chargers 210 connected to an EV charging backend 220 via a communication network 250. Each EV charger is connected to a security device 282 for encrypting / decrypting data to be transmitted via the communication network 250. The EV charging network 200 also includes a central security device 284 directly connected to the EV charging backend 220 for decrypting data received from the communication network 250.

[0022] Security devices 282 and 284 each include a security element located therein for encrypting / decrypting data transmitted to security devices 282 and 284. The EV charging network 200 also includes an administrator authentication module 292. The administrator authentication module 292 is adapted and personalized for a user carrying the administrator authentication module 292. In one embodiment, the administrator authentication module 292 carries a user's biometrics and / or password for authentication. This authentication is required to operate and manage security devices 282 and 284. This enables two-factor authentication (2FA) to activate and operate security devices 282 and 284, thereby providing additional security for the EV charging network 200. Therefore, authentication via the administrator authentication module 292 is required to access upstream and downstream security elements. In a preferred embodiment, the administrator authentication module 292 also includes a security element that works in conjunction with security devices 282 and 284. Security devices 282 and 284 may also include a reader that performs verification and authentication of the administrator authentication module 292 during operation. The reader may be equipped with a wired or wireless device for reading the administrator authentication module 292. In one embodiment, the administrator authentication module may be in the form of a card for storing administrator user authentication details. In another embodiment, the administrator authentication module may be integrated into security devices 282, 284 in the form of a biometric scanner / sensor, thereby allowing authorized personnel to access security elements in security devices 282, 284 for maintenance using their registered biometric information.

[0023] When security devices 282 and 284 are equipped with readers, they can be activated upon first use via administrator authentication module 292, and any subsequent maintenance should require access to these devices via administrator authentication module 292. Therefore, in the absence of administrator authentication module 292, unauthorized personnel will not be able to access security devices 282 and 284 due to the highly secure security elements embedded within it. Even with administrator authentication module 292, authentication factors such as passwords and biometric identification are required to verify the identity of the person holding the module.

[0024] The administrator authentication module 292 may be a handheld device with a secure element. In another embodiment, the administrator authentication module 292 may be in the form of a smart chip / card, or in the form of a token with a secure element that is easy to carry. In one embodiment, the security devices 282, 284 may also include a biometric reader and / or a keypad.

[0025] The authentication process involves the use of biometric authentication, such as fingerprint or facial recognition, combined with encrypted credentials to provide multiple layers of security, thereby ensuring that only authorized personnel can access security devices 282 and 284.

[0026] It is well known that secure components certified by CC and / or FIPS possess a high level of security. One reason is that these secure components are designed for specific functions, possess isolation mechanisms, and have a limited number of associated commands, meaning a very small attack surface. Strict control and regulation mechanisms ensure that only authorized users can access the secure device and perform necessary operations. Furthermore, the limited number of available commands makes it more difficult for attackers to exploit vulnerabilities in the secure component, as there are fewer exploitable avenues. This limited functionality makes the secure component highly secure and provides robust protection against a wide range of threats. Overall, secure components certified by CC or FIPS are an essential component of modern security architectures and provide a critical layer of protection for sensitive data and applications.

[0027] In another embodiment, security device 282 can only be accessed via remote authentication through security device 284, which is typically managed by a central office.

[0028] Figure 3 A processing flow of an EV charging network according to an embodiment of the present invention is illustrated. The flow includes: adding a safety device to the EV charging network in step 302; activating the safety element of the safety device in step 304; encrypting data from the EV chargers via the safety device in step 306; transmitting the encrypted data to the EV charging backend via a communication network in step 308; and decrypting the encrypted data by the safety device in step 312 for processing by the EV charging backend. It should be noted that the communication via the communication network is bidirectional. All EV chargers can obtain information from the EV charging backend, and vice versa.

[0029] In step 302, security devices are added to each EV charger and backend of the EV charging network. Each security device includes a security element for at least protecting encryption keys. Each security device can be manufactured as an external or additional device to the EV charging network. In step 304, each security element should be activated by an authorized administrator upon first use. The authorized administrator is typically an authorized person from the operator or owner of the EV charging network. Only those security elements that have been activated can be used to encrypt / decrypt data.

[0030] In step 306, all data transmitted via the EV charging network is encrypted using an encryption key by the security element of the security device. In step 308, the encrypted data is transmitted to the EV charging backend via the communication network. It should be noted and understood that when encrypted data is transmitted over a communication network that may include external networks such as the Internet, the encrypted data can only be decrypted by the key of the intended recipient. In this case, the encrypted data can only be decrypted by the security device connected to the backend (i.e., the intended recipient). In step 312, when the security device receives encrypted data from the corresponding EV charger to which the security device is connected, it decrypts the encrypted data and then feeds the decrypted data to the EV charging backend for further processing and storage.

[0031] Figure 4 An embodiment of the present invention is shown having Figure 1 A schematic diagram of the EV charging network 100 with the safety devices shown is presented. As shown, safety devices 182 and 184 include a communication module 402, a microprocessor 404, and a safety element 406. Safety device 182 is located at each EV charger on the upstream side, and safety device 184 is located on the downstream side, such that data from the upstream side is encrypted before traversing the network and decrypted by the downstream safety device. Communication module 402 provides a communication port for interfacing the EV chargers and EV charging back-ends with the communication network 150. Data is processed by microprocessor 404 as it passes through the safety devices to encrypt / decrypt the data using a key held by safety element 406. Specifically, data 410 from EV charger 110 is encrypted by safety device 182. The encrypted data 420 is then transmitted through network 150 to charging back-end 120. Without safety device 184, the encrypted data 420 would be meaningless to EV charging back-end 120. Therefore, safety device 184 is connected to charging back-end 120 to decrypt the encrypted data 420. Then, the decrypted data 430 can be processed and stored on the EV charging backend 120.

[0032] In one embodiment, data processing is performed by microprocessor 404 in conjunction with security element 406 to encrypt / decrypt data, thereby enhancing security.

[0033] This invention provides an additional, self-managed, hardware-based peer-to-peer encryption to protect data on a network at the transport layer.

[0034] In another embodiment, the communication module may include a wireless communication device, such as an antenna, a GSM module, a WiFi module, or a Bluetooth module.

[0035] Figure 5A block diagram of a security device 500 according to an alternative embodiment of the present invention is shown. The security device 500 includes a microprocessor 502, an FPGA chip 504, a security element 506, an Ethernet transceiver 508, and an RJ45 socket 509.

[0036] The microprocessor 502 acts as a control unit, managing data flow, high-level tasks, and handling the communication protocol of the Ethernet transceiver 508. It hands over data to the FPGA chip 504 to perform computationally intensive encryption or decryption tasks. The FPGA chip 504 works in conjunction with a secure element 506 that handles key distribution processing to ensure that the encryption key is unique and secure. The secure element 506 generates or stores the encryption key during operation, making it difficult for unauthorized parties to access it. After the FPGA chip 504, assisted by the secure element 506, completes the encryption or decryption, the microprocessor 502 performs additional tasks, such as attaching metadata, error checking, or routing the encrypted data to its destination. The microprocessor can also dynamically reconfigure the FPGA as needed to switch between different algorithms and manage other security measures.

[0037] Those skilled in the art will readily understand that the microprocessor 502 or the server / computer could be compromised by hackers or compromised due to internal leaks. Therefore, data input / output via RJ45 socket 509 and Ethernet transceiver 508 is subsequently encrypted / decrypted in hardware by the FPGA chip 504. During encryption / decryption, the FPGA chip 504 obtains the key from the secure element 506, which performs key distribution processing. Therefore, without the key, any hacker or intruder who obtains the data cannot understand it.

[0038] When the safety device 500 is added to the upstream (i.e., EV charger) and downstream (i.e. EV charging backend) of the EV charging network, data transmitted through the communication network can be encrypted / decrypted by the safety device 500.

[0039] In an alternative embodiment, the secure element (SE) collaborates with a field-programmable gate array (FPGA) chip to automatically verify the digital signature of all received data packets, including ICMP echo requests commonly referred to as "ping" packets. If the digital signature of an incoming data packet does not match the cryptographic calculations performed internally by the SE, the packet is considered invalid. Therefore, the SE discards the packet without issuing any response, effectively preventing the device from responding to unauthorized ping requests and making its IP address invisible to potential attackers.

[0040] It should be understood that the present invention is not limited to the specific embodiments described herein. The use of the security element and communication module is broadly applicable to various technologies beyond the disclosed examples. Any system or apparatus requiring secure data transmission between upstream and downstream components can benefit from the integration of such a security element. For example, the present invention can also be applied to CCTV networks, power metering networks, and Internet of Things (IoT) networks to utilize the inventive concept to protect the integrity of data networks and ensure that transmitted information is protected from unauthorized access or interception, without departing from the scope of the present invention.

Claims

1. A safety device suitable for an EV charging network having multiple EV chargers and an EV charging backend, the safety device comprising: A communication module having an interface for locally connecting as a gateway to the EV charger or the EV charging backend to transmit data via a communication network; The microprocessor acts as the control unit of the security device and processes the data stream; An FPGA chip configured to encrypt / decrypt the data; A security element that handles the key distribution processing required by the FPGA chip to encrypt / decrypt data; The safety device is locally connected to the EV charger or the EV charging backend, and encrypts / decrypts data transmitted through the communication network during operation, so that the data is end-to-end encrypted by the safety device throughout the EV charging network.

2. The safety device according to claim 1, wherein, The security element is certified according to Common Criteria (CC) or Federal Information Processing Standards (FIPS).

3. The safety device according to claim 1, wherein, The security device also includes an administrator authentication module for authenticating access to the security device.

4. The safety device according to claim 3, wherein, The administrator authentication module is in card form and contains its own security element.

5. The safety device according to claim 3, wherein, The administrator authentication module is integrated into the security device in the form of a biometric scanner / sensor.

6. The safety device according to claim 3, wherein, The administrator authentication module and the security device are deployed remotely.

7. An EV charging network having multiple EV chargers connected to an EV charging backend via a communication network, wherein, The communication network can be a wired network or a wireless network, and the EV charging network includes: The safety device according to any one of claims 1 to 6, The safety device is local and directly connected to the EV charger, such that data passes through the safety device before being transmitted to the communication network, and another safety device is directly connected before the EV charger back end.

8. A method for providing additional encryption / decryption to an EV charging network via a communication network, the method comprising: Add a safety device to an EV charging network, which has EV chargers and EV charging back-ends connected via a communication network; Activate the safety element of the safety device; The security device encrypts the data from the EV charger; Encrypted data is transmitted to the EV charging backend via the communication network; as well as The security device decrypts the encrypted data for processing by the EV charging backend. The data transmitted through the communication network is encrypted end-to-end by the security device.

9. The method according to claim 8, wherein, The end-to-end encryption is performed by the security device according to any one of claims 1 to 6.