Electric vehicle safety battery swapping method based on quantum key
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-15
- Publication Date
- 2026-08-11
AI Technical Summary
[0004]目前电车车企通常设置有自己的换电站,只服务于自家电车进行换电(后续称为“域内换电”),这导致换电站不具有通用性,无法服务于该换电站所属车企以外的电车,不利于电车的整体推广,使得很多电车出现“无站可换”、“无电可用”的尴尬情况
Smart Images

Figure CN122539955A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of vehicle networking technology, and in particular relates to a safe battery swapping method for electric vehicles based on quantum key distribution. Background Technology
[0002] With the accelerated advancement of vehicle electrification and connectivity, the development of electric vehicles (hereinafter referred to as "EVs") has entered a new stage of deep integration with "intelligent electric" technology. EVs belong to the category of clean energy vehicles driven by electricity. Compared with traditional fuel vehicles, they have higher energy efficiency, help reduce air pollution, and play a key role in building the future energy system. However, EVs currently face a major bottleneck: their battery range cannot meet the needs of vehicle use, which seriously affects the widespread adoption and popularization of EVs.
[0003] The emergence of battery swapping technology for electric vehicles offers a new solution to the range anxiety problem. This technology improves the reliability and practicality of electric vehicles by directly replacing battery modules at swapping stations. Furthermore, the separation of the vehicle and battery allows users to purchase vehicles without the battery, eliminating the risk of battery degradation and significantly lowering the barrier to entry for consumers, thus greatly stimulating consumption. In addition, the swapped-out batteries can be charged outside of peak grid usage times, reducing pressure on the power grid.
[0004] Currently, electric vehicle manufacturers typically set up their own battery swapping stations, which only serve their own electric vehicles (hereinafter referred to as "intra-regional battery swapping"). This results in the lack of universality of the battery swapping stations, which cannot serve electric vehicles from other manufacturers. This is not conducive to the overall promotion of electric vehicles and leads to the embarrassing situation of many electric vehicles having "no station to swap at" or "no electricity available".
[0005] Therefore, there is an urgent need for a battery swapping method that allows electric vehicles to safely swap batteries at battery swapping stations of different car manufacturers. Summary of the Invention
[0006] The purpose of this invention is to overcome the shortcomings of the prior art and provide a quantum key-based safe battery swapping method for electric vehicles, which enables electric vehicles from different car manufacturers to safely swap batteries at battery swapping stations.
[0007] To achieve the above objectives, the present invention adopts the following technical solution: A quantum key-based secure battery swapping method for electric vehicles includes the following: The electric vehicle travels to a battery swapping station. If the battery swapping station and the electric vehicle belong to the same manufacturer, the electric vehicle initiates intra-domain authentication with the station based on the same communication protocol. The station then completes the intra-domain authentication via the cloud. If the intra-domain authentication is successful, the electric vehicle obtains a first communication key generated by the station, and simultaneously unlocks its battery slot, allowing for battery swapping at the station. During the battery swapping process, the electric vehicle and the station conduct symmetric encrypted communication using the first communication key until the battery swapping session is completed. If the battery swapping station and the electric vehicle do not belong to the same manufacturer, the electric vehicle, upon receiving a verification message broadcast by the station containing its own communication protocol number, conducts cross-domain authentication with the station via the cloud. If the cross-domain authentication is successful, the electric vehicle obtains the station's communication protocol and a second communication key generated by the cloud, and simultaneously unlocks its battery slot, allowing for battery swapping at the station. During the battery swapping process, the electric vehicle and the station conduct symmetric encrypted communication using the station's communication protocol and the second communication key until the battery swapping session is completed.
[0008] Preferably, before the trolley travels to the battery swapping station, steps 01-04 are also included: Step 01: The car manufacturer's VE registers with the cloud-based QCSP; Step 02: The electric vehicle (EV) completes registration at the cloud-based QCSP. Step 03: The electric vehicle (EV) registers with its manufacturer's (VE) partner and completes the binding of the EV information with the manufacturer's information in the cloud-based QCSP through the manufacturer's VE. Step 04: After the battery swapping station SC registers directly with the vehicle manufacturer VE, it then registers indirectly with the cloud-based QCSP through the vehicle manufacturer VE.
[0009] Preferably, step 01 further includes the following sub-steps: Step 011: The car manufacturer VE randomly generates its own unique car manufacturer identification code ID. VE and the first random value R VE,1 Afterwards, the first registration application A1 is generated and uploaded to the cloud-based QCSP through offline secure channels: A1={SK VE ||O VE ||C VE ||PID VE};PID VE =R VE,1 ·ID VE ; Among them, SK VE This represents the car manufacturer's VE private key; C VE This indicates the communication protocol used by the car manufacturer's VE (Vehicle Equipment); O VEIndicates the communication protocol number used by the automaker's VE; PID VE The VE symbol represents the car manufacturer; || represents the connector. Step 012: After receiving the first registration application A1, the cloud-based QCSP will obtain the vehicle manufacturer's pseudonym PID. VE And generate a second random value R VE,2 The third random value R VE,3 Then, calculate the corresponding authorized value AN. VE The first feedback message BM1 is generated and transmitted to the vehicle manufacturer's VE through offline security channels, including AN. VE =R VE,2 ·R VE,3 ·PID VE ;BM1={AN VE ||PK QCSP};SK QCSP This represents the cloud-based QCSP public key; simultaneously, the cloud-based QCSP will store the PID. VE O VE C VE and SK VE The information is bound to the vehicle manufacturer's VE registration information and stored. At this time, the vehicle manufacturer's VE completes the registration at the cloud QCSP. Step 013, Automakers' VE Storage Comparison QCSP Cloud public key PK QCSP and authorized value AN VE ; Automaker VE private key SK VE and cloud-based QCSP public key SK QCSP All are quantum keys.
[0010] Preferably, step 02 also includes the following: After the electric vehicle (EV) is manufactured, a unique EV identification code ID is transferred through offline security channels. EV Uploaded to the cloud-based QCSP, the cloud-based QCSP will use the session key packet KP generated by the quantum random number generator. EV And a pair of public and private keys for the tram EV and SK EV The safety medium is filled into the electric vehicle (EV), and the EV completes registration at the cloud-based QCSP. Simultaneously, the cloud-based QCSP transfers the KP (Key Point). EV PK EV SK EV With ID EV The information is bound to the EV registration information and stored. At this point, the EV completes its registration at the QCSP in the cloud; Session Key Packet KP EV It contains k session keys, each with a uniquely bound key identifier.
[0011] Preferably, step 03 further includes the following sub-steps: Step 031: The electric vehicle (EV) sends the second registration application A2 to the automaker (VE) via offline security channels: A2={ID} EV ||PK EV}; Step 032: After receiving the second registration application A2, the vehicle manufacturer VE obtains the EV identification code ID. EV The vehicle profile information (RI) for the EV is then generated. EV The information is then stored and sent to the cloud-based QCSP via wireless communication as the first session information M1. Simultaneously, the vehicle manufacturer's VE generates a second feedback message BM2 and transmits it to the electric vehicle (EV) through offline secure channels. At this point, the EV completes its registration with its respective vehicle manufacturer's VE. RI EV ={ID EV ||α EV ||PID EV ||PK EV};α EV =H(PID EV ); PID EV =ID EV ·AN VE ; BM2={RI EV ||C VE ||O VE}; M1={PK QCSP (PID VE ||PK VE (RI EV ))}; PID EV The alpha symbol for electric vehicles (EVs); EV This represents the pseudonym hash value of the electric vehicle (EV); H(·) indicates that a hash calculation is performed; PK QCSP (·) indicates that asymmetric encryption is performed using the cloud-based QCSP public key; PK VE This indicates the use of the automaker's VE public key; PK VE (·) indicates the use of the automaker's VE public key PK. VE Perform asymmetric encryption; After receiving the second feedback message BM2, the electric vehicle (EV) stores the RI. EV C VE And O VE To its own safety medium; Step 033: After receiving the first session information M1, the cloud-based QCSP first uses its own private key SK. QCSPAfter performing asymmetric decryption, the car manufacturer's pseudonym is obtained. Then, based on the pseudonym, the corresponding car manufacturer's registration information is found. From the corresponding car manufacturer's registration information, the corresponding car manufacturer's private key is obtained. Finally, the corresponding car manufacturer's private key is used to asymmetricly decrypt the PK. VE (RI EV After that, the tram file information RI was obtained. EV Then, the corresponding EV registration information and EV file information (RI) will be entered. EV It is linked to the VE registration information of car manufacturers.
[0012] Preferably, step 04 further includes the following sub-steps: Step 041: After the battery swapping station (CS) is built, it randomly generates its own unique identification code (ID). CS After generating the third registration application A3, it is sent to the car manufacturer's VE through offline secure channels: A3={ID} CS ||PK CS}; where PK CS This represents the public key of the battery swapping station's CS (Content Controller). Step 042: After receiving the third-party registration application A3, the vehicle manufacturer VE obtains the battery swapping station identification code ID. CS And generate the swap station profile information RI for the swap station CS. CS After storage, the second session information M2 is sent to the cloud QCSP via wireless communication; simultaneously, the vehicle manufacturer's VE generates a third feedback message BM3 and transmits it to the battery swapping station's CS through offline security channels. At this point, the battery swapping station's CS completes direct registration with its respective vehicle manufacturer's VE. RI CS ={ID CS ||α CS ||PID CS ||PK CS};α CS =H(PID CS ); PID CS =ID CS ·AN VE ; BM3={α CS ||PID CS ||PK QCSP ||C VE ||O VE}; M2={PK QCSP (PID VE ||PK VE (RI CS ))}; PID CS The pseudonym for CS (Conversion Center) of a battery swapping station; α CS This represents the pseudonym hash value of the CS (Customer Service) of the battery swapping station; After receiving the third feedback message BM3, the CS of the battery swapping station stores α. CS PID CS PK QCSP C VE and O VE ; Step 043: After receiving the second session information M2, the cloud-based QCSP first uses its own private key SK. QCSP After performing asymmetric decryption, the car manufacturer's pseudonym is obtained. Then, based on the pseudonym, the corresponding car manufacturer's registration information is found. From the corresponding car manufacturer's registration information, the corresponding car manufacturer's private key is obtained. Finally, the corresponding car manufacturer's private key is used to asymmetricly decrypt the PK. VE (RI CS After that, the battery swapping station file information RI was obtained. CS Then, it is bound to the corresponding vehicle manufacturer's VE registration information. At this time, the battery swapping station CS completes the indirect registration at the cloud QCSP.
[0013] Preferably, intra-domain authentication further includes the following steps 11 to 15: Step 11: The trolley sends a first verification message containing the trolley session key identifier to the battery swapping station; Step 12: The battery swapping station authenticates the trolley based on the received first authentication message. If the authentication is successful, a second authentication message containing the battery swapping station information and the trolley session key identifier is generated and sent to the cloud. Step 13: The cloud performs comprehensive identity verification on the battery swapping station and the trolley through the second verification message. If the comprehensive identity verification is successful, the cloud generates a fourth feedback message and sends it to the corresponding battery swapping station. The fourth feedback message contains the trolley session key corresponding to the trolley session key identifier. Step 14: The battery swapping station authenticates the cloud based on the fourth feedback message. If the authentication is successful, the battery swapping station obtains the corresponding trolley session key from the fourth feedback message, generates a fifth feedback message containing the first communication key, and sends it to the corresponding trolley. Step 15: The trolley verifies the identity of the battery swapping station based on the fifth feedback message. If the identity verification is successful, it means that the intra-domain authentication is successful. The trolley then obtains the first communication key from the fifth feedback message. After successful authentication within the domain, the EV battery slot lock is opened, and the battery is replaced at the current battery swapping station CS. During the battery replacement process, the EV and the battery swapping station CS communicate via a symmetric encrypted connection using the first communication key until the battery swapping of the EV at the battery swapping station CS is completed.
[0014] Preferably, the electric vehicle (EV) and the battery swapping station (DS) belong to different automakers; the EV undergoes cross-domain certification at the battery swapping station (DS), including steps 11' to 14': Step 11': The DS of the battery swapping station generates a third verification message containing its own communication protocol number and pseudonym and broadcasts it. Step 12': The electric vehicle (EV) verifies the timeliness of the third verification message. If the verification is successful, the EV generates a fourth verification message containing the DS communication protocol number and DS pseudonym of the swapping station based on the third verification message and sends it to the cloud. Step 13': The cloud performs comprehensive identity verification on the DS of the battery swapping station and the EV through the fourth verification message. If the comprehensive identity verification is successful, the cloud generates a sixth feedback message and sends it to the EV. The sixth feedback message is the second communication key encrypted with the EV session key and the DS communication protocol of the battery swapping station. Step 14': The electric vehicle (EV) authenticates itself with the cloud based on the sixth feedback message. If the authentication is successful, it means that the cross-domain authentication is successful. The electric vehicle (EV) then obtains the second communication key and the communication protocol of the battery swapping station (DS) from the seventh feedback message. After successful cross-domain authentication, the EV battery slot lock is opened, and the battery is replaced at the current DS battery swapping station. During the battery replacement process, the EV and the DS battery swapping station communicate using the symmetric encryption protocol of the DS battery swapping station and a second communication key until the battery swapping of the EV at the DS battery swapping station is completed.
[0015] Preferably, step 11 further includes the following: After the electric vehicle (EV) arrives at the battery swapping station (CS), it receives the station's public key (PK) via broadcast. CS Afterwards, the electric vehicle (EV) generates the first verification message VM1 and sends it to the battery swapping station (CS). VM1={C1||S1||T1};C1=PK CS (G); G=(PID EV ||KS EV,1 ||KS EV,2 ||KS EV,3 S1=SK EV [C1]=SK EV ·C1; Where C1 represents the first ciphertext; S1 represents the first signature; T1 represents the first timestamp, which is the time when the first verification message VM1 was generated; G represents the trolley parameters; K EV,1 K EV,2 K EV,3 These represent the first session key, the second session key, and the third session key, respectively, which are obtained by the EV from its own key packet KP. EV Randomly obtained from; KS EV,1 KS EV,2 KS EV,3These represent the first key identifier, the second key identifier, and the third key identifier, respectively, and are associated with K. EV,1 K EV,2 K EV,3 One-to-one correspondence; ⊕ is the XOR symbol; PK CS (·) indicates the use of the battery swapping station's public key PK. CS Perform asymmetric encryption; SK EV [·] indicates the use of the EV private key SK EV Sign it; Step 12 also includes the following steps 121 to 122: Step 121: After receiving the first verification message VM1, the CS of the battery swapping station performs timeliness verification on the first timestamp in the first verification message VM1. If the timeliness verification is successful, the battery swapping station CS obtains the first signature S1 and the first ciphertext C1 from the first verification message VM1, and then uses the trolley public key PK received via broadcast. EV The first ciphertext C1 is used to verify the first signature S1; if the signature verification of the first signature S1 is successful, the identity verification of the electric vehicle VE by the battery swapping station CS is successful, and step 122 is executed. Step 122, the battery swapping station CS uses its own private key SK CS After asymmetric decryption of the first ciphertext C1, the trolley parameter G is obtained, and the second key identifier KS is obtained from the trolley parameter G. EV,2 Third key identifier KS EV,3 And the PID of the train EV Then, the battery swapping station CS generates a second verification message VM2 and sends it to the cloud QCSP: VM2={C2||S2||T2}; C2=PK QCSP (G||PID CS S2=SK CS [C2]; Where C2 represents the second ciphertext; S2 represents the second signature; SK CS [·] indicates the use of the battery swapping station's private key SK CS Perform the signing; T2 represents the second timestamp, which is the moment when the second verification message VM2 is generated; Step 13 also includes the following steps 131 to 132: Step 131: The cloud-based QCSP verifies the timeliness of the second timestamp in the second verification message VM2; If the timeliness verification is successful, the cloud-based QCSP will obtain the second ciphertext C2 and the second signature S2 from the second verification message VM2, and then use the cloud-based private key to perform a PK. QCSP After performing asymmetric decryption, the trolley parameter G and the alias PID of the battery swapping station are obtained. CSThen the cloud-based QCSP uses the alias PID of the battery swapping station. CS Retrieve the corresponding public key PK of the battery swapping station from its own stored battery swapping station profile information. CS Then, based on the second ciphertext C2, the second signature S2 is verified. If the signature verification of the second signature S2 is successful, the cloud QCSP obtains the corresponding vehicle file information based on the vehicle pseudonym in the vehicle parameter G. Then, in the vehicle registration information bound to the vehicle file information, the three corresponding vehicle session keys are obtained based on the session key identifier in the vehicle parameter G. At this time, the cloud QCSP successfully verifies the integrated identity of the battery swapping station CS and the vehicle EV, and then proceeds to step 132. Step 132: After generating the fourth feedback message BM4, the cloud-based QCSP sends it to the corresponding battery swapping station CS: BM4={C3||S3||T3}; C3=PK CS (K EV,1 ||K EV,2 ||K EV,3 S3 = SK QCSP [C3]; Where C3 represents the third ciphertext; S3 represents the third signature; SK QCSP [·] indicates the use of the cloud-based QCSP private key SK QCSP Perform the signature; T3 represents the third timestamp, which is the moment when the fourth feedback message BM4 is generated; Step 14 also includes the following sub-steps: Step 141: The CS of the battery swapping station verifies the timeliness of the third timestamp in the fourth feedback message BM4; If the timeliness verification is successful, the swapping station CS obtains the third signature S3 and the third ciphertext C3 from the fourth feedback message BM4, and then uses the cloud public key to perform a PK. QCSP The third ciphertext C3 is used to verify the signature of the third signature S3; if the signature verification of the third signature S3 is successful, the identity verification of the swap station CS to the cloud QCSP is successful, and step 142 is executed. Step 142, the battery swapping station CS uses its own private key SK CS After asymmetric decryption of the third ciphertext C3, three tram session keys are obtained. Then, the fifth feedback message BM5 is generated and sent to the corresponding tram EV. BM5={C4||S4||T4};C4=PK EV (MD3); S4=SK CS [C4];MD3=TX1⊕K EV,3 ;TX1=MD1⊕MD2;MD2=(PID EV ⊕KS EV,2 )·K EV,2 MD1=(PK) QCSP ⊕KEV,1 )·KS EV,1 ; Wherein, C4 represents the fourth ciphertext; S4 represents the fourth signature; T4 represents the fourth timestamp, which is the moment when the fifth feedback message BM5 is generated; MD1, MD2, and MD3 represent the first-level key ciphertext, the second-level key ciphertext, and the third-level key ciphertext, respectively; and TX1 represents the first communication key. Step 15 also includes the following sub-steps: Step 151: The electric vehicle (EV) verifies the timeliness of the fourth timestamp in the fifth feedback message BM5. If the timeliness verification is successful, the EV will obtain the fourth signature S4 and the fourth ciphertext C4 from the fifth feedback message BM5, and then use the public key of the battery swapping station to perform a PK. CS Verify the signature of the fourth signature S4 against the fourth ciphertext C4. If the signature verification of the fourth signature S4 is successful, proceed to step 152. Step 152, the electric vehicle (EV) uses its own private key SK EV After asymmetric decryption of the fourth ciphertext C4, a copy of the third-level key ciphertext MD3' is obtained; then the third session key K is used. EV,3 Calculate the first copy of the first communication key: TX1´=MD3´⊕K EV,3 ; Then, the EV uses its stored second session key identifier, first session key identifier, second session key, first session key, EV pseudonym, and cloud public key to calculate the second-level key ciphertext copy MD2´ and the first-level key ciphertext copy MD1´. Then, it calculates the first communication key second copy TX1´´=MD1⊕MD2´. If TX1´=TX1´´, the EV successfully authenticates with the CS of the battery swapping station, which means that the intra-domain authentication is successful. At this time, TX1=TX1´=TX1´´, and the EV obtains the first communication key TX1. If TX1´≠TX1´´, then the EV vehicle fails to authenticate with the CS of the battery swapping station, which means that the intra-domain authentication has failed.
[0016] Preferably, step 11' further includes the following: The battery swapping station DS generates a third verification message VM3 and broadcasts it: VM3={α DS ||C5||T5};C5=PK DS (O DE ||PID DS );α DS =H(PID DS ); Among them, the battery swapping station DS belongs to the car manufacturer DE; PID DS The pseudonym for DS, representing a battery swapping station; αDS T5 represents the pseudonym hash value of the swapping station DS; T5 represents the fifth timestamp, the time when the swapping station DS generates the third verification message VM3; C5 represents the fifth ciphertext; PK DS (·) indicates the use of the battery swapping station's public key PK. DS Perform asymmetric encryption; O DE This indicates the communication protocol number used by the vehicle manufacturer's DE (Digital Engine). Step 12' also includes the following sub-steps: The electric vehicle (EV) verifies the timeliness of the fifth timestamp in the third verification message VM3. If the verification is successful, the EV generates a fourth verification message VM4 and sends it to the cloud QCSP. VM4={C6||T6};S5=SK EV [C5];C6=PK QCSP (α DS |||C5||S5||PID EV ); Where S5 represents the fifth signature; T6 represents the sixth timestamp, which is the moment when the fourth verification message VM4 was generated; SK EV [·] indicates the use of the EV private key SK EV Sign the document; C6 represents the sixth ciphertext; Step 13' includes the following sub-steps: Step 131': The cloud-based QCSP performs a timeliness verification on the sixth timestamp in the fourth verification message VM4; If the timeliness verification is successful, the cloud-based QCSP will use the cloud-based private key to perform a key check. QCSP After performing asymmetric decryption on the sixth ciphertext C6, the trolley alias copy PID is obtained. EV ´、Swapping station pseudonym hash value copy α DS The fifth signature copy S5 and the fifth ciphertext copy C5; Then the cloud-based QCSP uses the PID of the train's katakana copy. EV Retrieve the corresponding tram public key (PK) from its own stored information. EV If cloud-based QCSP uses PK EV If the signature of the fifth ciphertext copy C5' and the fifth signature copy S5' is successfully authenticated, then S5' = S5 and C5' = C5 and PK... EV ´=PK EV ; Then the cloud-based QCSP copies α based on the alias hash value of the battery swapping station. DS Retrieve the corresponding battery swapping station private key (PK) from its own stored information. DS ´、Swapping station pseudonym PID DS ´´ and the communication protocol number O for the battery swapping station DEAfter that, use PK. DS After performing asymmetric decryption on the fifth ciphertext C5, the communication protocol number copy O is obtained. DE ´ and the alias copy of the PID of the battery swapping station DS If PID DS ´=PID DS ´´and O DE ´=O DE If the cloud-based QCSP successfully performs integrated identity verification between the battery swapping station's DS and the electric vehicle's EV, then the PID will be available. DS =PID DS ´=PID DS ´´and O DE =O DE ´=O DE ´´; Step 132', the cloud-based QCSP retrieves the communication protocol C of the battery swapping station's DS from its stored information. DE Simultaneously, three session keys are randomly selected from the session key packet of the electric vehicle (EV) stored within the device itself, and denoted as the fourth session key K. EV,4 Fifth session key K EV,5 Sixth Session Key K EV,6 The sixth feedback message, BM6, is then generated and sent to the electric vehicle (EV). BM6={C7||S6||T7};C7=PK EV (MD6||SC||KS EV,4 ||KS EV,5 ||KS EV,6 S6 = SK EV [C7];MD6=MD5⊕K EV,6 MD5=K EV,5 (PID EV ⊕MD4); MD4=K EV,4 (TX2⊕KS EV,4 ); SC=TX2(C DE ); Among them, KS EV,4 KS EV,5 KS EV,6 These represent the fourth key identifier, the fifth key identifier, and the sixth key identifier, respectively, and are associated with K. EV,4 K EV,5 K EV,6 One-to-one correspondence; C7 represents the seventh ciphertext; S6 represents the sixth signature; T7 represents the seventh timestamp, the time when the sixth feedback message BM6 was generated; MD4, MD5, and MD6 represent the fourth, fifth, and sixth level key ciphertexts respectively; TX2 represents the second communication key; ⊕ represents XOR; SC represents the communication protocol ciphertext; K EV,5(·) indicates the use of the fifth session key K EV,5 Perform symmetric encryption; K EV,4 (·) indicates the use of the fourth session key K EV,4 Perform symmetric encryption; Step 14' includes the following: Based on the seventh timestamp T7, the EV performs timeliness verification on the sixth feedback message BM6. If the verification is successful, the EV obtains the sixth signature copy S6´ and the seventh ciphertext copy C7´ from the sixth feedback message, and then uses its own public key to perform PK. EV The signature of the sixth signature copy S6' is verified based on the seventh ciphertext copy C7': if the signature verification of the sixth signature copy is successful, then S6' = S6 and C7' = C7. Then the electric vehicle (EV) uses its own private key to perform a PK. EV Asymmetric decryption of the seventh ciphertext copy C7' yields the sixth-level key ciphertext copy MD6' and the fourth to sixth key identifier copies KS. EV,4 ´~KS EV,6 First, a ciphertext copy of the communication protocol, SC; then, the EV retrieves the corresponding session key from its own session key packet based on the three key identifier copies, which are denoted as the fourth session key copy K. EV,4 Fifth Session Key Copy K EV,5 ´ and the sixth session key copy K EV,6 ´; Then the electric vehicle EV uses the sixth session key copy K EV,6 The fifth-level key ciphertext copy MD5 is obtained by XORing MD5 with the sixth-level key ciphertext copy MD6; then the fifth session key copy K is used. EV,5 After symmetrically decrypting the fifth-level key ciphertext copy MD5, an XOR operation is performed using its own trolley code to obtain the fourth-level key ciphertext copy MD4; then the fourth session key copy K is used... EV,4 After symmetrically decrypting the MD4 ciphertext copy of the fourth-level key, it is then compared with the fourth-level key identifier copy K. EV,4 After performing an XOR operation, the final second communication key TX2 is obtained; finally, the EV uses the second communication key TX2 to symmetrically decrypt the ciphertext copy SC' of the communication protocol to obtain the communication protocol C. DE At this point, cross-domain authentication is successful.
[0017] The beneficial effects of this invention are as follows: (1) The safe battery swapping method of the present invention enables electric vehicles to swap batteries at different vehicle manufacturers’ battery swapping stations, and the absolute safety of the battery swapping process is also guaranteed.
[0018] (2) The registration process of this invention not only takes into account the construction time of the cloud, car manufacturers, electric vehicles and battery swapping stations in actual applications, but also ensures that the registered electric vehicles, car manufacturers and battery swapping stations will not be registered repeatedly; and only the registration of electric vehicles, car manufacturers and battery swapping stations with legal identities can be successful. Furthermore, the process of binding the electric vehicle with the information of its car manufacturer in the cloud is completed by the interaction between the car manufacturer and the cloud when the electric vehicle registers with its car manufacturer; and the electric vehicle does not need to go to the battery swapping station of its car manufacturer to register during the registration stage, which also takes into account the actual application (electric vehicles are constantly being manufactured and battery swapping stations of car manufacturers are constantly being built, so it is obviously impractical to ask every electric vehicle to go to the battery swapping station of its car manufacturer to register); and greatly saves the time spent in the registration stage after the electric vehicle is manufactured. The entire registration process of this invention takes into account the inconvenience of moving battery swapping stations and their need for rapid deployment. It only requires the battery swapping station to complete registration with its respective vehicle manufacturer. Subsequent processes, such as uploading the registration information to the cloud and binding the registration information between the battery swapping station and its manufacturer, are handled by the vehicle manufacturer. In other words, the entire registration process of this invention is highly efficient and secure, facilitating the rapid deployment of electric vehicles and battery swapping stations.
[0019] (3) The secure battery swapping method of the present invention, whether it is intra-domain authentication or extra-domain authentication, is controlled by the cloud. Only the battery swapping station and the electric vehicle with legitimate identity can be successfully authenticated, which ensures the safety of the electric vehicle and the battery swapping station with legitimate identity during the battery swapping process: the electric vehicle with legitimate identity can only have its battery swapped at the battery swapping station with legitimate identity; the battery swapping station with legitimate identity cannot swap the battery of the electric vehicle with abnormal identity (the communication protocols used are different): ① Once the electric vehicle arrives at a battery swapping station, it knows whether the station belongs to the same vehicle manufacturer as the vehicle. The swapping station, however, is unaware of whether the electric vehicle belongs to the same manufacturer. Therefore, in this invention, both intra-domain and inter-domain authentication are initiated by the electric vehicle. If the swapping station and the electric vehicle belong to the same manufacturer, they use the same communication protocol. Therefore, the electric vehicle does not need to verify the communication protocol information during intra-domain authentication, as the entire intra-domain authentication process is based on the same communication protocol. Otherwise, the electric vehicle and the swapping station would be unable to complete the intra-domain authentication. After successful intra-domain authentication, the electric vehicle and the corresponding swapping station will communicate using the first communication key during the battery swapping process.
[0020] ② External authentication is performed by the battery swapping station broadcasting its third verification message, which includes the communication protocol number and pseudonym, to the trolley. This is unrelated to whether the trolley and the battery swapping station use the same communication protocol. Subsequent external authentication also occurs between the trolley and the cloud, still unrelated to whether the trolley and the battery swapping station use the same communication protocol. Only after the cloud successfully authenticates both the battery swapping station and the trolley will it send the corresponding trolley a second communication key encrypted with the trolley's session key and the battery swapping station's DS communication protocol, i.e., the sixth feedback message. The corresponding trolley is only considered to have successfully authenticated with the cloud based on the sixth feedback message. Only then can the trolley obtain the battery swapping station's communication protocol and second communication key, and only then can the trolley conduct symmetric encrypted dialogue with the corresponding battery swapping station during the battery replacement process based on this communication protocol and the second communication key.
[0021] ③ Even if the third-party intercepts the third-party verification message broadcast by the battery swapping station, it will not matter, as it only contains the communication protocol number and the alias of the battery swapping station, and will not have any adverse effect on the authentication between the trolley and the battery swapping station; if the third party intercepts and modifies the third-party verification message and resends it to the trolley, it will cause subsequent external authentication to fail, making it impossible for the third party to carry out malicious operations on the trolley and the battery swapping station.
[0022] (4) In the safe battery swapping method of the present invention, as long as the authentication is successful, the electric vehicle will use the same communication protocol as the battery swapping station to conduct the dialogue during the battery swapping process. The electric vehicle can only know whether the battery swapping station belongs to its own car company, and the battery swapping station can only know whether the current electric vehicle belongs to its own car company. Furthermore, the communication during the subsequent battery replacement process can only use the communication key obtained after successful authentication in this round. That is, the communication key is time-sensitive. This not only further improves the communication security between the electric vehicle and the battery swapping station during the battery swapping process, but also hides the car company information to which the electric vehicle and the battery swapping station belong, thus avoiding the leakage of some market share information related to different car companies (such as user transaction information and core corporate data).
[0023] (5) In the secure battery swapping method of the present invention, whether it is intra-domain authentication or inter-domain authentication, the final checkpoint for successful authentication is encrypted using a nested encryption method with randomly selected session keys from the session key packet. If any session key is incorrect, the trolley will fail to authenticate. This also means that if a message is intercepted and tampered with by a third party during the authentication process, or if a replay attack is launched, or if a third party obtains partial knowledge of the currently used session key, authentication will fail, thus ensuring the absolute security of the authentication process of the present invention. Attached Figure Description
[0024] Figure 1 This is a flowchart of a quantum key-based safe battery swapping method for electric vehicles according to the present invention. Detailed Implementation
[0025] To make the technical solution of the present invention clearer and more explicit, the present invention will be clearly and completely described below with reference to the accompanying drawings. Solutions derived by those skilled in the art through equivalent substitution and conventional reasoning of the technical features of the present invention without creative effort all fall within the protection scope of the present invention.
[0026] like Figure 1 The diagram shown is a flowchart of a quantum key-based secure battery swapping method for electric vehicles in this embodiment, including the following: When an electric vehicle travels to a battery swapping station, if the current battery swapping station and the electric vehicle belong to the same vehicle manufacturer, intra-domain authentication is performed; otherwise, cross-domain authentication is performed. After successful intra-domain or cross-domain authentication, the electric vehicle's battery slot lock is opened, and the battery is swapped.
[0027] Before the trolley travels to the battery swapping station, step 0 is also included: Step 0: The electric vehicle, the battery swapping station, and the car manufacturer complete the registration in the cloud, and the electric vehicle and the battery swapping station also complete the registration with their respective car manufacturers.
[0028] Step 0 also includes the following: Step 01: The car manufacturer's VE registers with the cloud-based QCSP; Step 02: The electric vehicle (EV) completes registration at the cloud-based QCSP. Step 03: The electric vehicle (EV) registers with its manufacturer's (VE) partner and completes the binding of the EV information with the manufacturer's information in the cloud-based QCSP through the manufacturer's VE. Step 04: After the battery swapping station SC registers directly with the vehicle manufacturer VE, it then registers indirectly with the cloud-based QCSP through the vehicle manufacturer VE.
[0029] The full English name for VE stands for Electric Vehicle; the full English name for QCSP stands for Quantum Cloud Service Provider; and the full English name for VE stands for Vehicle Enterprise. The characters SC and DS for battery swapping stations are simply used to indicate different battery swapping stations.
[0030] Step 01 includes the following sub-steps: Step 011: The car manufacturer VE randomly generates its own unique car manufacturer identification code ID within the range [1, n-1]. VE and the first random value R VE,1 Afterwards, the first registration application A1 is generated and uploaded to the cloud-based QCSP through offline secure channels: A1={SK VE ||O VE ||CVE ||PID VE};PID VE =R VE,1 ·ID VE ; Among them, SK VE This represents the car manufacturer's VE private key; C VE This indicates the communication protocol used by the car manufacturer's VE (Vehicle Equipment); O VE Indicates the communication protocol number used by the automaker's VE; PID VE The VE symbol represents the car manufacturer; || represents the connector.
[0031] Step 012: After receiving the first registration application A1, the cloud-based QCSP will obtain the vehicle manufacturer's pseudonym PID. VE If the current car manufacturer's pseudonym PID VE If the PID already exists in the vehicle manufacturer's registration information, the cloud-based QCSP will send a duplicate registration message to the vehicle manufacturer's VE; if the PID does not exist in the vehicle manufacturer's registration information... VE Then, the cloud-based QCSP generates a second random value R within the range [1, n-1]. VE,2 The third random value R VE,3 Then, calculate the corresponding authorized value AN. VE The first feedback message BM1 is generated and transmitted to the vehicle manufacturer's VE through offline security channels, including AN. VE =R VE,2 ·R VE,3 ·PID VE ;BM1={AN VE ||PK QCSP};SK QCSP This represents the cloud-based QCSP public key; simultaneously, the cloud-based QCSP will store the PID. VE O VE C VE and SK VE The information is bound to the vehicle manufacturer's VE registration information and stored. At this point, the vehicle manufacturer's VE completes the registration at the cloud QCSP.
[0032] Step 013, Automakers' VE Storage Comparison QCSP Cloud public key PK QCSP and authorized value AN VE .
[0033] Automaker VE private key SK VE and cloud-based QCSP public key SK QCSP All of these are quantum keys generated by a quantum random number generator.
[0034] It should be noted that the time when car manufacturers complete the registration in the cloud is the earliest, and only then will car manufacturers start producing electric vehicles and building corresponding battery swapping stations.
[0035] Step 02 also includes the following: After an electric vehicle (EV) is manufactured, its unique vehicle identification number (ID) is transferred through offline security channels. EV Uploaded to the cloud-based QCSP, the cloud-based QCSP will receive the tram identification code ID. EV The current trolley identification code is compared with the trolley identification code in all trolley registration information in the cloud QCSP. EV If the EV ID already exists in the EV registration information, the cloud-based QCSP will send a duplicate registration message to the EV; if the EV ID does not exist in the EV registration information... EV Then the cloud-based QCSP will use the session key packet KP generated by the quantum random number generator. EV And a pair of public and private keys for the tram EV and SK EV The safety medium is filled into the electric vehicle (EV), and the EV completes registration at the cloud-based QCSP. Simultaneously, the cloud-based QCSP transfers the KP (Key Point). EV PK EV SK EV With ID EV The information is bound to the EV registration information and stored. At this point, the EV completes its registration at the QCSP in the cloud. Session key packet KP EV It contains k session keys, each with a uniquely bound key identifier.
[0036] The registration information for trams may also include information such as the registration date.
[0037] In this embodiment, the safety medium of the tram is a quantum security chip.
[0038] Step 03 also includes the following sub-steps: Step 031: The electric vehicle (EV) sends the second registration application A2 to the automaker (VE) via offline security channels: A2={ID} EV ||PK EV}
[0039] Step 032: After receiving the second registration application A2, the vehicle manufacturer VE obtains the EV identification code ID. EV If the current tram identification code ID EV If the EV ID already exists in the vehicle registration information, the vehicle manufacturer (VE) sends a duplicate registration message to the EV; if the current EV ID does not exist in the vehicle registration information... EV Then the automaker VE generates the electric vehicle profile information RI for that electric vehicle EV. EVThe information is then stored and sent to the cloud-based QCSP via wireless communication as the first session information M1. Simultaneously, the vehicle manufacturer's VE generates a second feedback message BM2 and transmits it to the electric vehicle (EV) through offline secure channels. At this point, the EV completes its registration with its respective vehicle manufacturer's VE. RI EV ={ID EV ||α EV ||PID EV ||PK EV};α EV =H(PID EV ); PID EV =ID EV ·AN VE ; BM2={RI EV ||C VE ||O VE}; M1={PK QCSP (PID VE ||PK VE (RI EV ))}; PID EV The alpha symbol for electric vehicles (EVs); EV This represents the pseudonym hash value of the electric vehicle (EV); H(·) indicates that a hash calculation is performed; PK QCSP (·) indicates that asymmetric encryption is performed using the cloud-based QCSP public key; PK VE This indicates the use of the automaker's VE public key; PK VE (·) indicates the use of the automaker's VE public key PK. VE Perform asymmetric encryption.
[0040] After receiving the second feedback message BM2, the electric vehicle (EV) stores the RI. EV C VE And O VE To its own safety medium.
[0041] In the subsequent use of electric vehicles (EVs), the communication protocol and communication protocol number used by the EV itself will be the same as the communication protocol and communication protocol number of the vehicle manufacturer to which it belongs.
[0042] Step 033: After receiving the first session information M1, the cloud-based QCSP first uses its own private key SK. QCSP After performing asymmetric decryption, the car manufacturer's pseudonym is obtained. Then, based on the pseudonym, the corresponding car manufacturer's registration information is found. From the corresponding car manufacturer's registration information, the corresponding car manufacturer's private key is obtained. Finally, the corresponding car manufacturer's private key is used to asymmetricly decrypt the PK. VE (RI EV After that, the tram file information RI was obtained. EVThen, the corresponding EV registration information and EV file information (RI) will be entered. EV It is linked to the VE registration information of car manufacturers.
[0043] Step 04 also includes the following: Step 041: After the battery swapping station CS is built, it randomly generates its own unique identification code ID in the range [1, n-1]. CS After generating the third registration application A3, it is sent to the car manufacturer's VE through offline secure channels: A3={ID} CS ||PK CS}; where PK CS This represents the public key of the battery swapping station's CS (Content Controller). Step 042: After receiving the third-party registration application A3, the vehicle manufacturer VE obtains the battery swapping station identification code ID. CS If the current battery swapping station identification code ID CS If the current battery swapping station ID already exists in the station's records, the vehicle manufacturer's VE (Vehicle Equipment) sends a duplicate registration message to the station's CS (Customer Service); if the current battery swapping station ID does not exist in the station's records... CS Then the vehicle manufacturer's VE generates the battery swapping station profile information RI for the CS of that battery swapping station. CS The information is then stored and sent to the cloud-based QCSP via wireless communication as the second session information M2. Simultaneously, the vehicle manufacturer's VE generates a third feedback message BM3 and transmits it to the battery swapping station's CS via offline secure channels. At this point, the battery swapping station's CS completes direct registration with its respective vehicle manufacturer's VE. RI CS ={ID CS ||α CS ||PID CS ||PK CS};α CS =H(PID CS ); PID CS =ID CS ·AN VE ; BM3={α CS ||PID CS ||PK QCSP ||C VE ||O VE}; M2={PK QCSP (PID VE ||PK VE (RI CS ))}; PID CS The pseudonym for CS (Conversion Center) of a battery swapping station; α CS This represents the pseudonym hash value of the CS (Customer Service) of the battery swapping station.
[0044] After receiving the third feedback message BM3, the CS of the battery swapping station stores α. CS PID CS PK QCSP C VE and O VE In the subsequent operation, the communication protocol and communication protocol number used by the battery swapping station CS itself are the same as the communication protocol and communication protocol number of the vehicle manufacturer to which it belongs.
[0045] Step 043: After receiving the second session information M2, the cloud-based QCSP first uses its own private key SK. QCSP After performing asymmetric decryption, the car manufacturer's pseudonym is obtained. Then, based on the pseudonym, the corresponding car manufacturer's registration information is found. From the corresponding car manufacturer's registration information, the corresponding car manufacturer's private key is obtained. Finally, the corresponding car manufacturer's private key is used to asymmetricly decrypt the PK. VE (RI CS After that, the battery swapping station file information RI was obtained. CS Then, it is bound to the corresponding vehicle manufacturer's VE registration information. At this time, the battery swapping station CS completes the indirect registration at the cloud QCSP.
[0046] In this embodiment, all random values and identification codes can be generated first using a quantum random number generator, and then filtered within a set range [1, n-1]. n represents the order of the generator P point on the elliptic curve in the elliptic cryptography algorithm. n is a large prime number, and the generator P point can be randomly obtained by technicians; that is, the generator P point is a known quantity. The cloud-based QCSP, electric vehicle EV, and battery swapping station VE all generate their own private keys within the range [1, n-1]. Then, based on the known generator P point on the elliptic cryptography algorithm, they obtain the public key corresponding to the private key. Specifically, if the private key is k, the corresponding public key is a point Q on the elliptic curve, satisfying Q = k·P.
[0047] Each cloud-based QCSP, electric vehicle (EV), and battery swapping station (VE) stores at least one pair of public and private keys; and the public and private keys of the cloud-based QCSP, electric vehicle (EV), and battery swapping station (VE) are all generated based on the same elliptic curve and generator point P.
[0048] The registration process, from steps 01 to 04, not only takes into account the construction time of the cloud, car manufacturers, EVs, and battery swapping stations in actual applications, but also ensures that registered EVs, car manufacturers, and battery swapping stations are not registered repeatedly; and only EVs, car manufacturers, and battery swapping stations with legitimate identities can successfully register. Furthermore, the process of binding an EV with its car manufacturer information in the cloud is completed through interaction between the car manufacturer and the cloud when the EV registers with its car manufacturer; and EVs do not need to go to their car manufacturer's battery swapping station to register during the registration phase, which also takes into account practical applications (EVs are constantly being manufactured, and battery swapping stations of car manufacturers are constantly being built, so it is obviously impractical to require every EV to go to its car manufacturer's battery swapping station to register); this significantly saves time spent on the registration phase after the EVs are manufactured. The entire registration process of this invention takes into account the inconvenience of moving battery swapping stations and their need for rapid deployment. It only requires the battery swapping station to complete registration with its respective vehicle manufacturer. Subsequent processes, such as uploading the registration information to the cloud and binding the registration information between the battery swapping station and its manufacturer, are handled by the vehicle manufacturer. In other words, the entire registration process of this invention is highly efficient and secure, facilitating the rapid deployment of electric vehicles and battery swapping stations.
[0049] Intra-domain authentication also includes the following steps 11 to 15: Step 11: The trolley sends a first verification message containing the trolley session key identifier to the battery swapping station.
[0050] Step 12: The battery swapping station authenticates the trolley based on the received first authentication message. If the authentication is successful, a second authentication message containing the battery swapping station information and the trolley session key identifier is generated and sent to the cloud.
[0051] Step 13: The cloud performs comprehensive identity verification on the battery swapping station and the trolley through the second verification message. If the comprehensive identity verification is successful, the cloud generates a fourth feedback message and sends it to the corresponding battery swapping station. The fourth feedback message contains the trolley session key corresponding to the trolley session key identifier.
[0052] Step 14: The battery swapping station authenticates the cloud based on the fourth feedback message. If the authentication is successful, the battery swapping station obtains the corresponding trolley session key from the fourth feedback message, generates a fifth feedback message containing the first communication key, and sends it to the corresponding trolley.
[0053] Step 15: The trolley verifies the identity of the battery swapping station based on the fifth feedback message. If the identity verification is successful, it means that the intra-domain authentication is successful. The trolley then obtains the first communication key from the fifth feedback message.
[0054] After successful authentication within the domain, the EV battery slot lock is opened, and the battery is replaced at the current battery swapping station CS. During the battery replacement process, the EV and the battery swapping station CS communicate via a symmetric encrypted connection using the first communication key until the battery swapping of the EV at the battery swapping station CS is completed.
[0055] If the electric vehicle (EV) arrives at the battery swapping station (CS) again, after a new round of successful domain authentication, the EV and the CS will conduct a symmetric encrypted conversation using a new first communication key.
[0056] Step 11 also includes the following: After the electric vehicle (EV) arrives at the battery swapping station (CS), it receives the station's public key (PK) via broadcast. CS Afterwards, the electric vehicle (EV) generates the first verification message VM1 and sends it to the battery swapping station (CS). VM1={C1||S1||T1};C1=PK CS (G); G=(PID EV ||KS EV,1 ||KS EV,2 ||KS EV,3 S1=SK EV [C1]=SK EV ·C1; Where C1 represents the first ciphertext; S1 represents the first signature; T1 represents the first timestamp, which is the time when the first verification message VM1 was generated; G represents the trolley parameters; K EV,1 K EV,2 K EV,3 These represent the first session key, the second session key, and the third session key, respectively, which are obtained by the EV from its own session key packet KP. EV Randomly obtained from; KS EV,1 KS EV,2 KS EV,3 These represent the first key identifier, the second key identifier, and the third key identifier, respectively, and are associated with K. EV,1 K EV,2 K EV,3 One-to-one correspondence; ⊕ is the XOR symbol; PK CS (·) indicates the use of the battery swapping station's public key PK. CS Perform asymmetric encryption; SK EV [·] indicates the use of the EV private key SK EV Sign it.
[0057] Step 12 also includes the following steps 121 to 122: Step 121: After receiving the first verification message VM1, the CS of the battery swapping station first verifies the timeliness of the first timestamp in the first verification message VM1 based on the time when the first verification message VM1 was received. If the timeliness verification is successful, the battery swapping station CS obtains the first signature S1 and the first ciphertext C1 from the first verification message VM1, and then uses the trolley public key PK received via broadcast. EV The first verification message VM1 is signed and verified to confirm its authenticity and integrity: if S1·P=C1·PK exists... EV If the signature verification of the first verification message VM1 is successful, the identity verification of the electric vehicle VE by the battery swapping station CS is successful, and step 122 is executed. If the battery swapping station CS fails to verify the timeliness or signature of the first verification message VM1, it will discard the current first verification message VM1.
[0058] It should be noted here that: Based on the public and private key pair obtained from the elliptic cryptography algorithm, and knowing the generator point P, the first signature S1 obtained by signing the first ciphertext C1 with the private key is given by the following equation: S1·P = C1·public key. This is well known to those skilled in the art and will not be elaborated upon here.
[0059] Step 122, the battery swapping station CS uses its own private key SK CS After asymmetric decryption of the first ciphertext C1, the trolley parameter G is obtained, and the second key identifier KS is obtained from the trolley parameter G. EV,2 Third key identifier KS EV,3 And the PID of the train EV Then, the battery swapping station CS generates a second verification message VM2 and sends it to the cloud QCSP. VM2={C2||S2||T2};C2=PK QCSP (G||PID CS S2=SK CS [C2]; Where C2 represents the second ciphertext; S2 represents the second signature; SK CS [·] indicates the use of the battery swapping station's private key SK CS Perform the signature; T2 represents the second timestamp, which is the moment when the second verification message VM2 is generated.
[0060] Step 13 also includes steps 131 to 132: Step 131: The cloud-based QCSP performs timeliness verification on the second timestamp in the second verification message VM2 based on the time when the second verification message VM2 is received. If the timeliness verification is successful, the cloud-based QCSP will obtain the second ciphertext C2 from the second verification message VM2, and then use the cloud-based private key to perform a PK. QCSP After performing asymmetric decryption, the trolley parameter G and the alias PID of the battery swapping station are obtained. CS Then the cloud-based QCSP uses the alias PID of the battery swapping station. CS Retrieve the corresponding public key PK of the battery swapping station from its own stored battery swapping station profile information. CS Then, the signature of the second verification message VM2 is verified to confirm its authenticity and integrity. If S²·P = C²·PK exists CS If the signature verification of the second verification message VM2 is successful, the cloud QCSP obtains the corresponding vehicle file information based on the vehicle pseudonym in the vehicle parameter G; then, in the vehicle registration information bound to the vehicle file information, it obtains the three corresponding vehicle session keys based on the session key identifier in the vehicle parameter G. At this time, the cloud QCSP successfully performs integrated identity verification of the battery swapping station CS and the vehicle EV, and executes step 132. If the cloud-based QCSP fails to verify the signature of the second verification message VM2, or if the vehicle pseudonym in the vehicle parameter G is not present in the vehicle file information of the cloud-based QCSP, or if not all of the session key identifiers in the vehicle parameter G are present in the corresponding bound vehicle registration information, it is recorded that the cloud-based QCSP has failed to perform integrated authentication of the battery swapping station CS and the vehicle EV, and the current second verification message VM2 is discarded.
[0061] Step 132: After generating the fourth feedback message BM4, the cloud-based QCSP sends it to the corresponding battery swapping station CS: BM4={C3||S3||T3}; C3=PK CS (K EV,1 ||K EV,2 ||K EV,3 S3 = SK QCSP [C3]; Where C3 represents the third ciphertext; S3 represents the third signature; SK QCSP [·] indicates the use of the cloud-based QCSP private key SK QCSP Perform the signature; T3 represents the third timestamp, which is the moment when the fourth feedback message BM4 is generated.
[0062] Step 14 also includes the following: Step 141: The CS of the battery swapping station verifies the timeliness of the third timestamp in the fourth feedback message BM4 based on the time when it receives the fourth feedback message BM4. If the timeliness verification is successful, the swapping station CS obtains the third signature S3 and the third ciphertext C3 from the fourth feedback message BM4, and then uses the cloud public key to perform a PK. QCSPThe signature of the fourth feedback message BM4 is verified to confirm its authenticity and integrity: if S3·P=C3·PK exists... QCSP If the signature verification of the fourth feedback message BM4 is successful, the identity verification of the swap station CS to the cloud QCSP is successful, and step 142 is executed. If the CS of the battery swapping station fails to verify the timeliness or signature of the fourth feedback message BM4, it will discard the current fourth feedback message BM4.
[0063] Step 142, the battery swapping station CS uses its own private key SK CS After asymmetric decryption of the third ciphertext C3, three tram session keys are obtained. Then, the fifth feedback message BM5 is generated and sent to the corresponding tram EV. BM5={C4||S4||T4};C4=PK EV (MD3); S4=SK CS [C4];MD3=TX1⊕K EV,3 ;TX1=MD1⊕MD2;MD2=(PID EV ⊕KS EV,2 )·K EV,2 MD1=(PK) QCSP ⊕K EV,1 )·KS EV,1 ; Wherein, C4 represents the fourth ciphertext; S4 represents the fourth signature; T4 represents the fourth timestamp, which is the time when the fifth feedback message BM5 is generated; MD1, MD2, and MD3 represent the first-level key ciphertext, the second-level key ciphertext, and the third-level key ciphertext, respectively; and TX1 represents the first communication key.
[0064] Step 15 also includes the following: Step 151: The electric vehicle EV verifies the timeliness of the fourth timestamp in the fifth feedback message BM5 based on the time when it receives the fifth feedback message BM5. If the timeliness verification is successful, the EV will obtain the fourth signature S4 and the fourth ciphertext C4 from the fifth feedback message BM5, and then use the public key of the battery swapping station to perform a PK. CS The signature of the fifth feedback message BM5 is verified to confirm its authenticity and integrity: if S4·P=C4·PK exists... CS If the signature verification of the fifth feedback message BM5 is successful, then proceed to step 152. If the EV fails to verify the timeliness or signature of the fifth feedback message BM5, the current fifth feedback message BM5 is discarded.
[0065] Step 152, the electric vehicle (EV) uses its own private key SK EVAfter asymmetric decryption of the fourth ciphertext C4, a copy of the third-level key ciphertext MD3' is obtained; then the third session key K is used. EV,3 Calculate the first copy of the first communication key: TX1´=MD3´⊕K EV,3 ; Then, the EV uses its stored second session key identifier, first session key identifier, second session key, first session key, EV pseudonym, and cloud public key to calculate the second-level key ciphertext copy MD2´ and the first-level key ciphertext copy MD1´. Then, it calculates the first communication key second copy TX1´´=MD1⊕MD2´. If TX1´=TX1´´, the EV successfully authenticates with the CS of the battery swapping station, which means that the intra-domain authentication is successful. At this time, TX1=TX1´=TX1´´, and the EV obtains the first communication key TX1. If TX1´≠TX1´´, then the EV vehicle fails to authenticate with the CS of the battery swapping station, which means that the intra-domain authentication has failed.
[0066] Electric vehicles (EVs) and battery swapping stations (DS) belong to different automakers; when EVs come to the battery swapping station (DS) for cross-domain certification, the process includes the following steps 11' to 15': Step 11': The DS of the battery swapping station generates a third verification message containing its own communication protocol number and pseudonym and broadcasts it. Step 12': The electric vehicle (EV) verifies the timeliness of the third verification message. If the verification is successful, the EV generates a fourth verification message containing the DS communication protocol number and DS pseudonym of the swapping station based on the third verification message and sends it to the cloud. Step 13': The cloud performs comprehensive identity verification on the DS of the battery swapping station and the EV through the fourth verification message. If the comprehensive identity verification is successful, the cloud generates a sixth feedback message and sends it to the EV. The sixth feedback message is the second communication key encrypted with the EV session key and the DS communication protocol of the battery swapping station. Step 14': The EV performs identity verification on the cloud based on the sixth feedback message. If the identity verification is successful, it means that the cross-domain authentication is successful. Then the EV obtains the second communication key and the communication protocol of the DS of the battery swapping station from the seventh feedback message.
[0067] After successful cross-domain authentication, the EV battery slot lock is opened, and the battery is replaced at the current DS battery swapping station. During the battery replacement process, the EV and the DS battery swapping station communicate using the symmetric encryption protocol of the DS battery swapping station and a second communication key until the battery swapping of the EV at the DS battery swapping station is completed.
[0068] If the electric vehicle (EV) arrives at the DS battery swapping station again, after a new round of successful cross-domain authentication, the EV will regain access to the DS communication protocol and use a new second communication key for symmetric encrypted communication.
[0069] Step 11' also includes the following: The battery swapping station DS generates a third verification message VM3 and broadcasts it: VM3={α DS ||C5||T5};C5=PK DS (O DE ||PID DS );α DS =H(PID DS ); Among them, the battery swapping station DS belongs to the car manufacturer DE; PID DS The pseudonym for DS, representing a battery swapping station; α DS T5 represents the pseudonym hash value of the swapping station DS; T5 represents the fifth timestamp, the time when the swapping station DS generates the third verification message VM3; C5 represents the fifth ciphertext; PK DS (·) indicates the use of the battery swapping station's public key PK. DS Perform asymmetric encryption; O DE This indicates the communication protocol number used by the vehicle manufacturer's DE (Digital Engine).
[0070] Step 12' also includes the following sub-steps: The electric vehicle (EV) verifies the timeliness of the fifth timestamp in the third verification message VM3. If the verification is successful, the EV generates a fourth verification message VM4 and sends it to the cloud QCSP. VM4={C6||T6};S5=SK EV [C5];C6=PK QCSP (α DS |||C5||S5||PID EV ); Where S5 represents the fifth signature; T6 represents the sixth timestamp, which is the moment when the fourth verification message VM4 was generated; SK EV [·] indicates the use of the EV private key SK EV Sign the document; C6 represents the sixth ciphertext.
[0071] If the electric vehicle (EV) fails to verify the timeliness of the fifth timestamp in the third verification message VM3, the EV will discard the current third verification message VM3.
[0072] Step 13' includes the following sub-steps: Step 131': The cloud-based QCSP verifies the timeliness of the sixth timestamp in the fourth verification message VM4 based on the time when the fourth verification message VM4 is received. If the timeliness verification is successful, the cloud-based QCSP will use the cloud-based private key to perform a key check. QCSP After performing asymmetric decryption on the sixth ciphertext C6, the trolley alias copy PID is obtained. EV ´、Swapping station pseudonym hash value copy α DS The fifth signature copy S5 and the fifth ciphertext copy C5; Then the cloud-based QCSP uses the PID of the train's katakana copy. EV Retrieve the corresponding tram public key (PK) from its own stored information. EV If S5'·P = C5'·PK exists... EV If ´, then the fifth signature copy is successfully verified. At this point, S5´=S5 and C5´=C5 and PK EV ´=PK EV The successful verification of the fifth signature copy indicates that the integrity of the fifth ciphertext copy has been successfully verified.
[0073] The successful verification of the integrity of the fifth ciphertext copy indicates that the fifth ciphertext copy was not tampered with during transmission, but it does not mean that the identity of the sender of the current fourth verification message is correct.
[0074] Then the cloud-based QCSP copies α based on the alias hash value of the battery swapping station. DS Retrieve the corresponding battery swapping station private key (PK) from its own stored information. DS ´、Swapping station pseudonym PID DS ´´ and the communication protocol number O for the battery swapping station DE After that, use PK. DS After performing asymmetric decryption on the fifth ciphertext C5, the communication protocol number copy O is obtained. DE ´ and the alias copy of the PID of the battery swapping station DS If PID DS ´=PID DS ´´and O DE ´=O DE If the cloud-based QCSP successfully performs integrated identity verification between the battery swapping station's DS and the electric vehicle's EV, then the PID will be available. DS =PID DS ´=PID DS ´´and O DE =O DE ´=O DE ´´.
[0075] Step 132', the cloud-based QCSP retrieves the communication protocol C of the battery swapping station's DS from its stored information. DE Simultaneously, three session keys are randomly selected from the session key packet of the electric vehicle (EV) stored within the device itself, and denoted as the fourth session key K. EV,4Fifth session key K EV,5 Sixth Session Key K EV,6 The sixth feedback message, BM6, is then generated and sent to the electric vehicle (EV). BM6={C7||S6||T7};C7=PK EV (MD6||SC||KS EV,4 ||KS EV,5 ||KS EV,6 S6 = SK EV [C7];MD6=MD5⊕K EV,6 MD5=K EV,5 (PID EV ⊕MD4); MD4=K EV,4 (TX2⊕KS EV,4 ); SC=TX2(C DE ); Among them, KS EV,4 KS EV,5 KS EV,6 These represent the fourth key identifier, the fifth key identifier, and the sixth key identifier, respectively, and are associated with K. EV,4 K EV,5 K EV,6 One-to-one correspondence; C7 represents the seventh ciphertext; S6 represents the sixth signature; T7 represents the seventh timestamp, the time when the sixth feedback message BM6 was generated; MD4, MD5, and MD6 represent the fourth, fifth, and sixth level key ciphertexts respectively; TX2 represents the second communication key; ⊕ represents XOR; SC represents the communication protocol ciphertext; K EV,5 (·) indicates the use of the fifth session key K EV,5 Perform symmetric encryption; K EV,4 (·) indicates the use of the fourth session key K EV,4 Perform symmetric encryption; SK EV [·] indicates the use of the EV private key SK EV Sign it; If the cloud-based QCSP fails to verify the timeliness of the fourth verification message VM4, or fails to verify the fifth signature copy, or if the PID... DS ´≠PID DS ´´, or O DE ´≠O DE If this happens, the cloud-based QCSP will discard the current fourth verification message VM4 and stop executing step 132.
[0076] Step 14' includes the following: Based on the seventh timestamp T7, the EV performs timeliness verification on the sixth feedback message BM6. If the verification is successful, the EV obtains the sixth signature copy S6´ and the seventh ciphertext copy C7´ from the sixth feedback message, and then uses its own public key to perform PK. EV Verify the sixth signature copy S6': If S6'·P = C7'·PK, then... EV If S6' = S6 and C7' = C7, then the verification of the sixth signature copy is successful. At this time, S6' = S6 and C7' = C7. The successful verification of the sixth signature copy indicates that the integrity verification of the seventh ciphertext copy is successful. Similarly, the successful verification of the integrity of the seventh ciphertext copy indicates that the seventh ciphertext copy has not been tampered with during transmission. However, this does not mean that the identity of the sender of the current sixth feedback message is correct. Therefore, we still need to verify the information obtained after decrypting the seventh ciphertext copy C7'. This is also a necessary step to obtain the second communication key so that the electric vehicle EV and the battery swapping station DS can successfully perform battery swapping and communication.
[0077] Then the electric vehicle (EV) uses its own private key to perform a PK. EV Asymmetric decryption of the seventh ciphertext copy C7' yields the sixth-level key ciphertext copy MD6' and the fourth to sixth key identifier copies KS. EV,4 ´~KS EV,6 First, a ciphertext copy of the communication protocol, SC; then, the EV retrieves the corresponding session key from its own session key packet based on the three key identifier copies, which are denoted as the fourth session key copy K. EV,4 Fifth Session Key Copy K EV,5 ´ and the sixth session key copy K EV,6 ´.
[0078] It should be noted that there is a very small probability that even if the fourth to sixth key identifiers are tampered with, the corresponding identifiers may still exist in the EV's session key packet. This means that three session keys can still be found in the session key packet, but these three session keys can no longer successfully decrypt the subsequent second communication key. Therefore, the key identifiers decrypted from the seventh ciphertext copy C7' are denoted as the corresponding key identifier copies.
[0079] Then the electric vehicle EV uses the sixth session key copy K EV,6 The fifth-level key ciphertext copy MD5 is obtained by XORing MD5 with the sixth-level key ciphertext copy MD6; then the fifth session key copy K is used. EV,5 After symmetrically decrypting the fifth-level key ciphertext copy MD5, an XOR operation is performed using its own trolley code to obtain the fourth-level key ciphertext copy MD4; then the fourth session key copy K is used... EV,4After symmetrically decrypting the MD4 ciphertext copy of the fourth-level key, it is then compared with the fourth-level key identifier copy K. EV,4 After performing an XOR operation, the final second communication key TX2 is obtained. Finally, the second communication key TX2 is used to symmetrically decrypt the ciphertext copy SC' of the communication protocol to obtain the communication protocol C. DE At this point, the EV authenticates its identity with the cloud-based QCSP, meaning the cross-domain authentication is successful.
[0080] It should be noted that if all three session keys are different from the session keys issued by the cloud QCSP, or if the ciphertext copy SC´ of the communication protocol or the ciphertext copy MD6´ of the sixth-level key has been tampered with, then the EV will ultimately be unable to decrypt the plaintext of the second communication key and the communication protocol (which will all be unusable gibberish). Even if it decrypts the seemingly usable plaintext, subsequent battery swapping and communication between the EV and the DS will fail because the communication protocol is not the actual communication protocol of the corresponding DS battery swapping station.
[0081] If the EV fails to verify the timeliness of the sixth feedback message, or if there are no copies of the fourth to sixth key identifiers in its own session key package, or if the verification of the sixth signature copy fails, or if garbled characters are decrypted, the EV will discard the current sixth feedback message BM6 and stop performing subsequent decryption operations.
[0082] In this invention, once an electric vehicle arrives at a battery swapping station, it knows whether the station belongs to the same vehicle manufacturer as the vehicle. The swapping station, however, is unaware of whether the electric vehicle belongs to the same manufacturer. Therefore, in this invention, both intra-domain and inter-domain authentication are initiated by the electric vehicle. If the swapping station and the electric vehicle belong to the same manufacturer, they use the same communication protocol. Thus, the electric vehicle does not need to verify the communication protocol information during intra-domain authentication, as the entire intra-domain authentication process is based on the same communication protocol; otherwise, the electric vehicle and the swapping station would be unable to complete the intra-domain authentication. After successful intra-domain authentication, the electric vehicle and the corresponding swapping station will communicate using the first communication key during the battery swapping process.
[0083] External authentication is performed by the battery swapping station broadcasting a third verification message containing its communication protocol number and pseudonym to the trolley. This is independent of whether the trolley and the battery swapping station use the same communication protocol. Subsequent external authentication also occurs between the trolley and the cloud, again independent of whether the trolley and the battery swapping station use the same communication protocol. Only after the cloud successfully authenticates both the battery swapping station and the trolley will it send the corresponding trolley a second communication key encrypted with the trolley's session key and the battery swapping station's DS communication protocol, i.e., the sixth feedback message. The corresponding trolley is only considered to have successfully authenticated with the cloud based on the sixth feedback message. Only then can the trolley obtain the battery swapping station's communication protocol and second communication key, enabling it to conduct symmetric encrypted communication with the corresponding battery swapping station during battery replacement based on this communication protocol and the second communication key.
[0084] Even if the third-party interception of the third-party verification message broadcast by the battery swapping station is not a problem, it will not affect the authentication between the trolley and the battery swapping station, as it only contains the communication protocol number and the alias of the battery swapping station. However, if the third party intercepts and modifies the third-party verification message and resends it to the trolley, it will cause subsequent external authentication to fail, preventing the third party from maliciously operating on the trolley and the battery swapping station.
[0085] As the above analysis shows, both intra-domain and extra-domain authentication are controlled by the cloud. Only battery swapping stations and electric vehicles with legitimate identities (registered through steps 01 to 04) can be successfully authenticated, ensuring the safety of legitimate electric vehicles and battery swapping stations during the battery swapping process: legitimate electric vehicles can only have their batteries swapped at legitimate battery swapping stations; legitimate battery swapping stations cannot swap batteries for electric vehicles with abnormal identities (because they use different communication protocols).
[0086] Once authentication is successful, the electric vehicle will use the same communication protocol as the battery swapping station it arrives at for communication during the battery swapping process. The electric vehicle can only know whether the battery swapping station belongs to its own car manufacturer, and the battery swapping station can only know whether the current electric vehicle belongs to its own car manufacturer. Furthermore, subsequent communication during the battery replacement process can only use the communication key obtained after successful authentication in this round. That is, the communication key is time-limited. This not only further enhances the communication security between the electric vehicle and the battery swapping station during the battery swapping process, but also hides the car manufacturer information of the electric vehicle and the battery swapping station, avoiding the leakage of market share information of different car manufacturers (such as user transaction information and core corporate data).
[0087] Whether it's intra-domain or inter-domain authentication, the final step for successful authentication involves nested encryption of randomly selected session keys from the session key packet. If any session key is incorrect, the authentication process will fail. This also means that if a message is intercepted and tampered with by a third party during the authentication process, or if a replay attack is launched, or if a third party obtains partial knowledge of the currently used session key, authentication will fail, thus ensuring absolute security in the authentication process of this invention.
[0088] The safe battery swapping method of the present invention enables electric vehicles to swap batteries at different vehicle manufacturers' battery swapping stations, and the absolute safety of the battery swapping process is also guaranteed.
[0089] The technologies, shapes, and structures not described in detail in this invention are all known technologies.
[0090] It should also be noted that the above are merely preferred embodiments of the present invention and are not intended to limit the invention. The components or steps in the embodiments of the present invention can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions of the present invention and should all fall within the protection scope of the present invention.
Claims
1. A quantum key-based method for secure battery swapping in electric vehicles, characterized in that, Includes the following: The electric vehicle travels to the battery swapping station. If the current battery swapping station and the electric vehicle belong to the same vehicle manufacturer, the electric vehicle initiates intra-domain authentication with the current battery swapping station based on the same communication protocol. The current battery swapping station completes intra-domain authentication of the electric vehicle with the help of the cloud. If the authentication within the domain is successful, the trolley obtains the first communication key generated by the current battery swapping station, and at the same time, the trolley's battery card slot lock is opened, and the battery is swapped at the current battery swapping station. During the battery swapping process, the trolley and the current battery swapping station conduct symmetric encrypted communication through the first communication key until the battery swapping of the trolley at the current battery swapping station is completed. If the current battery swapping station and the electric vehicle do not belong to the same vehicle manufacturer, the electric vehicle, after receiving a verification message broadcast by the battery swapping station containing its own communication protocol number, will use the cloud to perform cross-domain authentication with the current battery swapping station. If the cross-domain authentication is successful, the electric vehicle will obtain the communication protocol of the current battery swapping station and the second communication key generated by the cloud. At the same time, the electric vehicle's battery card slot lock will be opened, and the battery will be replaced at the current battery swapping station. During the battery replacement process, the electric vehicle and the battery swapping station will conduct symmetric encrypted communication based on the current battery swapping station's communication protocol and through the second communication key until the current battery swapping of the electric vehicle at the battery swapping station is completed.
2. The method for secure battery swapping of electric vehicles based on quantum key distribution according to claim 1, characterized in that, Before the trolley travels to the battery swapping station, steps 01 through 04 are also included: Step 01: The car manufacturer's VE registers with the cloud-based QCSP; Step 02: The electric vehicle (EV) completes registration at the cloud-based QCSP. Step 03: The electric vehicle (EV) registers with its manufacturer's (VE) partner and completes the binding of the EV information with the manufacturer's information in the cloud-based QCSP through the manufacturer's VE. Step 04: After the battery swapping station SC registers directly with the vehicle manufacturer VE, it then registers indirectly with the cloud-based QCSP through the vehicle manufacturer VE.
3. The method for secure battery swapping of electric vehicles based on quantum key distribution according to claim 2, characterized in that, Step 01 also includes the following sub-steps: Step 011: The vehicle manufacturer (VE) generates its own unique vehicle manufacturer identification code (ID). VE and the first random value R VE,1 Afterwards, the first registration application A1 is generated and uploaded to the cloud-based QCSP through offline secure channels: A1={SK VE ||O VE ||C VE ||PID VE };PID VE =R VE,1 ·ID VE ; Among them, SK VE This represents the car manufacturer's VE private key; C VE This indicates the communication protocol used by the car manufacturer's VE (Vehicle Equipment); O VE Indicates the communication protocol number used by the automaker's VE; PID VE The VE symbol represents the car manufacturer; || represents the connector. Step 012: After receiving the first registration application A1, the cloud-based QCSP will obtain the vehicle manufacturer's pseudonym PID. VE And generate a second random value R VE,2 The third random value R VE,3 Then, calculate the corresponding authorized value AN. VE The first feedback message BM1 is generated and transmitted to the vehicle manufacturer's VE through offline security channels, including AN. VE =R VE,2 ·R VE,3 ·PID VE ;BM1={AN VE ||PK QCSP };SK QCSP This represents the cloud-based QCSP public key; simultaneously, the cloud-based QCSP will store the PID. VE O VE C VE and SK VE The information is bound to the vehicle manufacturer's VE registration information and stored. At this time, the vehicle manufacturer's VE completes the registration at the cloud QCSP. Step 013, Automakers' VE Storage Comparison QCSP Cloud public key PK QCSP and authorized value AN VE ; Automaker VE private key SK VE and cloud-based QCSP public key SK QCSP All are quantum keys.
4. The method for secure battery swapping of electric vehicles based on quantum key distribution according to claim 3, characterized in that, Step 02 also includes the following: After the electric vehicle (EV) is manufactured, a unique EV identification code ID is transferred through offline security channels. EV Uploaded to the cloud-based QCSP, the cloud-based QCSP will use the session key packet KP generated by the quantum random number generator. EV And a pair of public and private keys for the tram EV and SK EV The safety medium is filled into the electric vehicle (EV), and the EV completes registration at the cloud-based QCSP. Simultaneously, the cloud-based QCSP transfers the KP (Key Point). EV PK EV SK EV With ID EV The information is bound to the electric vehicle (EV) registration information and stored. At this time, the electric vehicle (EV) completes its registration at the cloud-based QCSP. Session key packet KP EV It contains k session keys, each with a uniquely bound key identifier.
5. A quantum key-based secure battery swapping method for electric vehicles according to claim 4, characterized in that, Step 03 also includes the following sub-steps: Step 031: The electric vehicle (EV) sends the second registration application A2 to the automaker (VE) via offline security channels: A2={ID} EV ||PK EV }; Step 032: After receiving the second registration application A2, the vehicle manufacturer VE obtains the EV identification code ID. EV The vehicle profile information (RI) for the EV is then generated. EV The information is then stored and sent to the cloud-based QCSP via wireless communication as the first session information M1. Simultaneously, the vehicle manufacturer's VE generates a second feedback message BM2 and transmits it to the electric vehicle (EV) through offline secure channels. At this point, the EV completes its registration with its respective vehicle manufacturer's VE. RI EV ={ID EV ||α EV ||PID EV ||PK EV };α EV =H(PID EV );PID EV =ID EV ·AN VE ; BM2={RI EV ||C VE ||O VE };M1={PK QCSP (PID VE ||PK VE (RI EV ))}; PID EV The alpha symbol for electric vehicles (EVs); EV This represents the pseudonym hash value of the electric vehicle (EV); H(·) indicates that a hash calculation is performed; PK QCSP (·) indicates that asymmetric encryption is performed using the cloud-based QCSP public key; PK VE This indicates the use of the automaker's VE public key; PK VE (·) indicates the use of the automaker's VE public key PK. VE Perform asymmetric encryption; After receiving the second feedback message BM2, the electric vehicle (EV) stores the RI. EV C VE And O VE To its own safety medium; Step 033: After receiving the first session information M1, the cloud-based QCSP first uses its own private key SK. QCSP After performing asymmetric decryption, the car manufacturer's pseudonym is obtained. Then, based on the pseudonym, the corresponding car manufacturer's registration information is found. From the corresponding car manufacturer's registration information, the corresponding car manufacturer's private key is obtained. Finally, the corresponding car manufacturer's private key is used to asymmetricly decrypt the PK. VE (RI EV After that, the tram file information RI was obtained. EV Then, the corresponding EV registration information and EV file information (RI) will be entered. EV It is linked to the VE registration information of car manufacturers.
6. A quantum key-based secure battery swapping method for electric vehicles according to claim 5, characterized in that, Step 04 also includes the following sub-steps: Step 041: After the battery swapping station (CS) is built, it randomly generates its own unique identification code (ID). CS After generating the third registration application A3, it is sent to the car manufacturer's VE through offline secure channels: A3={ID} CS ||PK CS }; where PK CS This represents the public key of the battery swapping station's CS (Content Controller). Step 042: After receiving the third-party registration application A3, the vehicle manufacturer VE obtains the battery swapping station identification code ID. CS And generate the swap station profile information RI for the swap station CS. CS After storage, the second session information M2 is sent to the cloud QCSP via wireless communication; simultaneously, the vehicle manufacturer's VE generates a third feedback message BM3 and transmits it to the battery swapping station's CS through offline security channels. At this point, the battery swapping station's CS completes direct registration with its respective vehicle manufacturer's VE. RI CS ={ID CS ||α CS ||PID CS ||PK CS };α CS =H(PID CS );PID CS =ID CS ·AN VE ; BM3={a CS ||PID CS ||PK QCSP ||C VE ||O VE }; M2={PK QCSP (PID VE ||PK VE (RI CS ))}; PID CS The pseudonym for CS (Conversion Center) of a battery swapping station; α CS This represents the pseudonym hash value of the CS (Customer Service) of the battery swapping station; After receiving the third feedback message BM3, the CS of the battery swapping station stores α. CS PID CS PK QCSP C VE and O VE ; Step 043: After receiving the second session information M2, the cloud-based QCSP first uses its own private key SK. QCSP After performing asymmetric decryption, the car manufacturer's pseudonym is obtained. Then, based on the pseudonym, the corresponding car manufacturer's registration information is found. From the corresponding car manufacturer's registration information, the corresponding car manufacturer's private key is obtained. Finally, the corresponding car manufacturer's private key is used to asymmetricly decrypt the PK. VE (RI CS After that, the battery swapping station file information RI was obtained. CS Then, it is bound to the corresponding vehicle manufacturer's VE registration information. At this time, the battery swapping station CS completes the indirect registration at the cloud QCSP.
7. A quantum key-based secure battery swapping method for electric vehicles according to claim 5, characterized in that, Intra-domain authentication also includes the following steps 11 to 15: Step 11: The trolley sends a first verification message containing the trolley session key identifier to the battery swapping station; Step 12: The battery swapping station authenticates the trolley based on the received first authentication message. If the authentication is successful, a second authentication message containing the battery swapping station information and the trolley session key identifier is generated and sent to the cloud. Step 13: The cloud performs comprehensive identity verification on the battery swapping station and the trolley through the second verification message. If the comprehensive identity verification is successful, the cloud generates a fourth feedback message and sends it to the corresponding battery swapping station. The fourth feedback message contains the trolley session key corresponding to the trolley session key identifier. Step 14: The battery swapping station authenticates the cloud based on the fourth feedback message. If the authentication is successful, the battery swapping station obtains the corresponding trolley session key from the fourth feedback message, generates a fifth feedback message containing the first communication key, and sends it to the corresponding trolley. Step 15: The trolley verifies the identity of the battery swapping station based on the fifth feedback message. If the identity verification is successful, it means that the intra-domain authentication is successful. The trolley then obtains the first communication key from the fifth feedback message. After successful authentication within the domain, the EV battery slot lock is opened, and the battery is replaced at the current battery swapping station CS. During the battery replacement process, the EV and the battery swapping station CS communicate via a symmetric encrypted connection using the first communication key until the battery swapping of the EV at the battery swapping station CS is completed.
8. A quantum key-based secure battery swapping method for electric vehicles according to claim 5, characterized in that, Electric vehicles (EVs) and battery swapping stations (DS) belong to different automakers; EVs undergo cross-domain certification at battery swapping stations (DS), including steps 11' to 14': Step 11': The DS of the battery swapping station generates a third verification message containing its own communication protocol number and pseudonym and broadcasts it. Step 12': The electric vehicle (EV) verifies the timeliness of the third verification message. If the verification is successful, the EV generates a fourth verification message containing the DS communication protocol number and DS pseudonym of the swapping station based on the third verification message and sends it to the cloud. Step 13': The cloud performs comprehensive identity verification on the DS of the battery swapping station and the EV through the fourth verification message. If the comprehensive identity verification is successful, the cloud generates a sixth feedback message and sends it to the EV. The sixth feedback message is the second communication key encrypted with the EV session key and the DS communication protocol of the battery swapping station. Step 14': The electric vehicle (EV) authenticates itself with the cloud based on the sixth feedback message. If the authentication is successful, it means that the cross-domain authentication is successful. The electric vehicle (EV) then obtains the second communication key and the communication protocol of the battery swapping station (DS) from the seventh feedback message. After successful cross-domain authentication, the EV battery slot lock is opened, and the battery is replaced at the current DS battery swapping station. During the battery replacement process, the EV and the DS battery swapping station communicate using the symmetric encryption protocol of the DS battery swapping station and a second communication key until the battery swapping of the EV at the DS battery swapping station is completed.
9. A quantum key-based secure battery swapping method for electric vehicles according to claim 7, characterized in that: Step 11 also includes the following: After the electric vehicle (EV) arrives at the battery swapping station (CS), it receives the station's public key (PK) via broadcast. CS Afterwards, the electric vehicle (EV) generates the first verification message VM1 and sends it to the battery swapping station (CS). VM1={C1||S1||T1};C1=PK CS (G); G=(PID EV ||KS EV,1 ||KS EV,2 ||KS EV,3 );S1=SK EV [C1]=SK EV ·C1; Where C1 represents the first ciphertext; S1 represents the first signature; T1 represents the first timestamp, which is the time when the first verification message VM1 was generated; G represents the trolley parameters; K EV,1 K EV,2 K EV,3 These represent the first session key, the second session key, and the third session key, respectively, which are obtained by the EV from its own key packet KP. EV Randomly obtained from; KS EV,1 KS EV,2 KS EV,3 These represent the first key identifier, the second key identifier, and the third key identifier, respectively, and are associated with K. EV,1 K EV,2 K EV,3 One-to-one correspondence; ⊕ is the XOR symbol; PK CS (·) indicates the use of the battery swapping station's public key PK. CS Perform asymmetric encryption; SK EV [·] indicates the use of the EV private key SK EV Sign it; Step 12 also includes the following steps 121 to 122: Step 121: After receiving the first verification message VM1, the CS of the battery swapping station performs timeliness verification on the first timestamp in the first verification message VM1. If the timeliness verification is successful, the battery swapping station CS obtains the first signature S1 and the first ciphertext C1 from the first verification message VM1, and then uses the trolley public key PK received via broadcast. EV The first ciphertext C1 is used to verify the first signature S1; if the signature verification of the first signature S1 is successful, the identity verification of the electric vehicle VE by the battery swapping station CS is successful, and step 122 is executed. Step 122, the battery swapping station CS uses its own private key SK CS After asymmetric decryption of the first ciphertext C1, the trolley parameter G is obtained, and the second key identifier KS is obtained from the trolley parameter G. EV,2 Third key identifier KS EV,3 And the PID of the train EV Then, the battery swapping station CS generates a second verification message VM2 and sends it to the cloud QCSP: VM2={C2||S2||T2}; C2=PK QCSP (G||PID CS S2=SK CS [C2]; Where C2 represents the second ciphertext; S2 represents the second signature; SK CS [·] indicates the use of the battery swapping station's private key SK CS Perform the signing; T2 represents the second timestamp, which is the moment when the second verification message VM2 is generated; Step 13 also includes the following steps 131 to 132: Step 131: The cloud-based QCSP verifies the timeliness of the second timestamp in the second verification message VM2; If the timeliness verification is successful, the cloud-based QCSP will obtain the second ciphertext C2 and the second signature S2 from the second verification message VM2, and then use the cloud-based private key to perform a PK. QCSP After performing asymmetric decryption, the trolley parameter G and the alias PID of the battery swapping station are obtained. CS Then the cloud-based QCSP uses the alias PID of the battery swapping station. CS Retrieve the corresponding public key PK of the battery swapping station from its own stored battery swapping station profile information. CS Then, based on the second ciphertext C2, the second signature S2 is verified. If the signature verification of the second signature S2 is successful, the cloud QCSP obtains the corresponding vehicle file information based on the vehicle pseudonym in the vehicle parameter G. Then, in the vehicle registration information bound to the vehicle file information, the three corresponding vehicle session keys are obtained based on the session key identifier in the vehicle parameter G. At this time, the cloud QCSP successfully verifies the integrated identity of the battery swapping station CS and the vehicle EV, and then proceeds to step 132. Step 132: After generating the fourth feedback message BM4, the cloud-based QCSP sends it to the corresponding battery swapping station CS: BM4={C3||S3||T3}; C3=PK CS (K EV,1 ||K EV,2 ||K EV,3 S3 = SK QCSP [C3]; Where C3 represents the third ciphertext; S3 represents the third signature; SK QCSP [·] indicates the use of the cloud-based QCSP private key SK QCSP Perform the signature; T3 represents the third timestamp, which is the moment when the fourth feedback message BM4 is generated; Step 14 also includes the following sub-steps: Step 141: The CS of the battery swapping station verifies the timeliness of the third timestamp in the fourth feedback message BM4; If the timeliness verification is successful, the swapping station CS obtains the third signature S3 and the third ciphertext C3 from the fourth feedback message BM4, and then uses the cloud public key to perform a PK. QCSP The third ciphertext C3 is used to verify the signature of the third signature S3; if the signature verification of the third signature S3 is successful, the identity verification of the swap station CS to the cloud QCSP is successful, and step 142 is executed. Step 142, the battery swapping station CS uses its own private key SK CS After asymmetric decryption of the third ciphertext C3, three tram session keys are obtained. Then, the fifth feedback message BM5 is generated and sent to the corresponding tram EV. BM5={C4||S4||T4};C4=PK EV (MD3);S4=SK CS [C4];MD3=TX1⊕K EV,3 ;TX1=MD1⊕MD2;MD2=(PID EV ⊕KS EV,2 )·K EV,2 ;MD1=(PK QCSP ⊕K EV,1 )·KS EV,1 ; Wherein, C4 represents the fourth ciphertext; S4 represents the fourth signature; T4 represents the fourth timestamp, which is the moment when the fifth feedback message BM5 is generated; MD1, MD2, and MD3 represent the first-level key ciphertext, the second-level key ciphertext, and the third-level key ciphertext, respectively; and TX1 represents the first communication key. Step 15 also includes the following sub-steps: Step 151: The electric vehicle (EV) verifies the timeliness of the fourth timestamp in the fifth feedback message BM5. If the timeliness verification is successful, the EV will obtain the fourth signature S4 and the fourth ciphertext C4 from the fifth feedback message BM5, and then use the public key of the battery swapping station to perform a PK. CS Verify the signature of the fourth signature S4 against the fourth ciphertext C4. If the signature verification of the fourth signature S4 is successful, proceed to step 152. Step 152, the electric vehicle (EV) uses its own private key SK EV After asymmetric decryption of the fourth ciphertext C4, a copy of the third-level key ciphertext MD3' is obtained; then the third session key K is used. EV,3 Calculate the first copy of the first communication key: TX1´=MD3´⊕K EV,3 ; Then, the EV uses its stored second session key identifier, first session key identifier, second session key, first session key, EV pseudonym, and cloud public key to calculate the second-level key ciphertext copy MD2´ and the first-level key ciphertext copy MD1´. Then, it calculates the first communication key second copy TX1´´=MD1⊕MD2´. If TX1´=TX1´´, the EV successfully authenticates with the CS of the battery swapping station, which means that the intra-domain authentication is successful. At this time, TX1=TX1´=TX1´´, and the EV obtains the first communication key TX1. If TX1´≠TX1´´, then the EV vehicle fails to authenticate with the CS of the battery swapping station, which means that the intra-domain authentication has failed.
10. A quantum key-based secure battery swapping method for electric vehicles according to claim 8, characterized in that: Step 11' also includes the following: The battery swapping station DS generates a third verification message VM3 and broadcasts it: VM3={a DS ||C5||T5};C5=PK DS (The DE ||PID DS );a DS =H(PID DS ); Among them, the battery swapping station DS belongs to the car manufacturer DE; PID DS The pseudonym for DS, representing a battery swapping station; α DS T5 represents the pseudonym hash value of the swapping station DS; T5 represents the fifth timestamp, the time when the swapping station DS generates the third verification message VM3; C5 represents the fifth ciphertext; PK DS (·) indicates the use of the battery swapping station's public key PK. DS Perform asymmetric encryption; O DE This indicates the communication protocol number used by the vehicle manufacturer's DE (Digital Engine). Step 12' also includes the following sub-steps: The electric vehicle (EV) verifies the timeliness of the fifth timestamp in the third verification message VM3. If the verification is successful, the EV generates a fourth verification message VM4 and sends it to the cloud QCSP. VM4={C6||T6};S5=SK EV [C5];C6=PK QCSP (α DS |||C5||S5||PID EV ); Where S5 represents the fifth signature; T6 represents the sixth timestamp, which is the moment when the fourth verification message VM4 was generated; SK EV [·] indicates the use of the EV private key SK EV Sign the document; C6 represents the sixth ciphertext; Step 13' includes the following sub-steps: Step 131': The cloud-based QCSP performs a timeliness verification on the sixth timestamp in the fourth verification message VM4; If the timeliness verification is successful, the cloud-based QCSP will use the cloud-based private key to perform a key check. QCSP After performing asymmetric decryption on the sixth ciphertext C6, the trolley alias copy PID is obtained. EV ´、Swapping station pseudonym hash value copy α DS The fifth signature copy S5 and the fifth ciphertext copy C5; Then the cloud-based QCSP uses the PID of the train's katakana copy. EV Retrieve the corresponding tram public key (PK) from its own stored information. EV If cloud-based QCSP uses PK EV If the signature of the fifth ciphertext copy C5' and the fifth signature copy S5' is successfully authenticated, then S5' = S5 and C5' = C5 and PK... EV ´=PK EV ; Then the cloud-based QCSP copies α based on the alias hash value of the battery swapping station. DS Retrieve the corresponding battery swapping station private key (PK) from its own stored information. DS ´、Swapping station pseudonym PID DS ´´ and the communication protocol number O for the battery swapping station DE After that, use PK. DS After performing asymmetric decryption on the fifth ciphertext C5, the communication protocol number copy O is obtained. DE ´ and the alias copy of the PID of the battery swapping station DS If PID DS ´=PID DS ´´and O DE ´=O DE If the cloud-based QCSP successfully performs integrated identity verification between the battery swapping station's DS and the electric vehicle's EV, then the PID will be available. DS =PID DS ´=PID DS ´´and O DE =O DE ´=O DE ´´; Step 132', the cloud-based QCSP retrieves the communication protocol C of the battery swapping station's DS from its stored information. DE Simultaneously, three session keys are randomly selected from the session key packet of the electric vehicle (EV) stored within the device itself, and denoted as the fourth session key K. EV,4 Fifth session key K EV,5 Sixth Session Key K EV,6 The sixth feedback message, BM6, is then generated and sent to the electric vehicle (EV). BM6={C7||S6||T7};C7=PK EV (MD6||SC||KS EV,4 ||KS EV,5 ||KS EV,6 );S6=SK EV [C7];MD6=MD5⊕K EV,6 ;MD5=K EV,5 (PID EV ⊕MD4);MD4=K EV,4 (TX2⊕KS EV,4 );SC=TX2(C DE ); Among them, KS EV,4 KS EV,5 KS EV,6 These represent the fourth key identifier, the fifth key identifier, and the sixth key identifier, respectively, and are associated with K. EV,4 K EV,5 K EV,6 One-to-one correspondence; C7 represents the seventh ciphertext; S6 represents the sixth signature; T7 represents the seventh timestamp, the time when the sixth feedback message BM6 was generated; MD4, MD5, and MD6 represent the fourth, fifth, and sixth level key ciphertexts respectively; TX2 represents the second communication key; ⊕ represents XOR; SC represents the communication protocol ciphertext; K EV,5 (·) indicates the use of the fifth session key K EV,5 Perform symmetric encryption; K EV,4 (·) indicates the use of the fourth session key K EV,4 Perform symmetric encryption; Step 14' includes the following: Based on the seventh timestamp T7, the EV performs timeliness verification on the sixth feedback message BM6. If the verification is successful, the EV obtains the sixth signature copy S6´ and the seventh ciphertext copy C7´ from the sixth feedback message, and then uses its own public key to perform PK. EV The signature of the sixth signature copy S6' is verified based on the seventh ciphertext copy C7': if the signature verification of the sixth signature copy is successful, then S6' = S6 and C7' = C7. Then the electric vehicle (EV) uses its own private key to perform a PK. EV Asymmetric decryption of the seventh ciphertext copy C7' yields the sixth-level key ciphertext copy MD6' and the fourth to sixth key identifier copies KS. EV,4 ´~KS EV,6 First, a ciphertext copy of the communication protocol, SC; then, the EV retrieves the corresponding session key from its own session key packet based on the three key identifier copies, which are denoted as the fourth session key copy K. EV,4 Fifth Session Key Copy K EV,5 ´ and the sixth session key copy K EV,6 ´; Then the electric vehicle EV uses the sixth session key copy K EV,6 The fifth-level key ciphertext copy MD5 is obtained by XORing MD5 with the sixth-level key ciphertext copy MD6; then the fifth session key copy K is used. EV,5 After symmetrically decrypting the fifth-level key ciphertext copy MD5, an XOR operation is performed using its own trolley code to obtain the fourth-level key ciphertext copy MD4; then the fourth session key copy K is used... EV,4 After symmetrically decrypting the MD4 ciphertext copy of the fourth-level key, it is then compared with the fourth-level key identifier copy K. EV,4 After performing an XOR operation, the final second communication key TX2 is obtained; finally, the EV uses the second communication key TX2 to symmetrically decrypt the ciphertext copy SC' of the communication protocol to obtain the communication protocol C. DE At this point, cross-domain authentication is successful.