Power battery anti-tampering evaluation method and system based on multi-source heterogeneous cross-end verification

By using a cross-terminal verification method involving oracle charging nodes and blockchain smart contracts, the problem of inaccurate identification of power battery data tampering is solved, ensuring the authenticity and credibility of battery data, and making it suitable for the entire life cycle management and transactions of batteries.

CN122640194APending Publication Date: 2026-08-25CHINA AUTOMOTIVE ENG RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610784481.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-02
Publication Date
2026-08-25

AI Technical Summary

Technical Problem

Existing technologies cannot effectively identify data tampering in power batteries, especially data forgery by black market organizations that tamper with the underlying logic of the BMS system or intercept communication messages. This makes it impossible for blockchain-based evidence to verify the physical authenticity of the data, and static verification methods are prone to false alarms or missed alarms during battery aging.

Method used

By introducing oracle charging nodes as third-party observers and combining them with blockchain smart contracts for dual verification, macroscopic verification is based on the principle of energy conservation and microscopic verification is based on dynamic trajectory characteristics. Dynamic benchmark thresholds are generated to conduct cross-end verification and identify tampering behavior of battery health and capacity.

Benefits of technology

It accurately identifies battery data tampering, improves the accuracy and coverage of tamper identification, adapts to anti-tampering verification scenarios throughout the battery lifecycle, ensures the authenticity and credibility of data, and supports the reliability of battery lifecycle management and transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122640194A_ABST
    Figure CN122640194A_ABST
Patent Text Reader

Abstract

The application belongs to the field of batteries, and particularly relates to a power battery anti-tampering evaluation method and system based on multi-source heterogeneous cross-end verification, which comprises the following steps: S1: a prophet charging node collects charging characteristic data of a battery and uploads the charging characteristic data to a block chain; S2: apparent business state data of the battery is acquired and uploaded to the block chain; S3: an intelligent contract of the block chain calculates a real total capacity estimation value of the current battery, and performs a first-time tampering judgment according to a preset macroscopic verification rule; S4: the intelligent contract of the block chain generates a dynamic reference threshold value according to the apparent business state data of the battery, and performs a second-time tampering judgment according to the dynamic reference threshold value and a preset microscopic verification rule; and S5: a tampering report is generated according to the tampering judgment result, and multi-party joint disposal instructions are generated based on the tampering judgment result. The problem of inaccurate tampering identification is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of batteries, and in particular relates to a method and system for evaluating the anti-tampering of power batteries based on multi-source heterogeneous cross-end verification. Background Technology

[0002] With the large-scale development of the new energy vehicle industry, the full life cycle management, residual value assessment, and decommissioning utilization of power batteries have become core demands and pain points in the industry. As the core of power battery data acquisition and control, the authenticity and reliability of the data reported by the Battery Management System (BMS) are directly related to several key aspects such as vehicle safety assessment, used car transaction pricing, and insurance claim verification.

[0003] Currently, to address the issues of tamper-proof and reliable traceability of battery data, existing technologies generally employ a solution where apparent data such as voltage, current, and State of Health (SoH) collected and calculated by the Battery Management System (BMS) are directly uploaded to the blockchain for storage via an IoT module. This solution leverages the immutability and traceability of the blockchain to a certain extent ensure the integrity of the data after it is uploaded to the chain.

[0004] However, the above-mentioned pure data on-chain solution has the following problems in practical applications: 1) Existing technologies establish the trust anchor entirely within the vehicle's BMS. In practice, malicious organizations crack the underlying logic of the BMS system, such as by flashing firmware, tampering with Controller Area Network (CAN) bus messages, forcibly relaxing the physical upper and lower limits of battery charging and discharging voltage to release hidden capacity beyond the design safety range, or artificially modifying the cycle count and health value estimate. Since blockchain technology can only guarantee that data cannot be tampered with after it is uploaded to the chain, it cannot verify the physical authenticity of the data before it is uploaded to the chain. Existing technologies cannot effectively identify such tampering behaviors.

[0005] 2) In existing technologies, security verification often adopts a static lookup table comparison method based on the highest and lowest voltages. When black market organizations carry out bottom deep discharge tampering or conduct man-in-the-middle attacks by intercepting communication messages, the voltage value they report is still within the rated operating range, and the static threshold verification is completely ineffective.

[0006] 3) In addition, batteries have non-linear aging characteristics throughout their entire life cycle. Using a uniform static standard to measure batteries with different aging levels can easily lead to false alarms or missed alarms. It is difficult to identify cheating behavior by tampering parties who use software to conceal the internal resistance distortion of old batteries and forcibly inflate the health value valuation. Summary of the Invention

[0007] This invention provides a method and system for evaluating the anti-tampering of power batteries based on multi-source heterogeneous cross-end verification, which solves the problem of inaccurate tampering identification.

[0008] This invention provides a basic solution: a power battery anti-tampering evaluation method based on multi-source heterogeneous cross-end verification, comprising the following steps: S1: Oracle charging nodes collect battery charging characteristic data during vehicle charging and upload it to the blockchain; the charging characteristic data includes the total physically injected energy. Actual tail trajectory characteristics during the constant voltage charging phase Changes in state of charge read from the charging protocol ; S2: Obtain battery apparent business status data, generate business status evidence data and upload it to the blockchain; S3: Blockchain smart contracts inject total energy based on physics. Change in state of charge Calculate the current battery's true total capacity estimate. And based on the current vehicle's factory-approved maximum rated physical capacity of the battery. True total capacity estimate The first level of tampering detection is performed according to the preset macro-level verification rules; S4: The blockchain's smart contract generates a dynamic baseline threshold based on the battery's apparent business status data, and then uses this data along with actual tail trajectory characteristics. A second tampering determination is performed by combining a dynamic benchmark threshold with preset micro-verification rules; S5: Generate a tampering report based on the tampering determination result, and generate multi-party coordinated handling instructions based on the tampering determination result.

[0009] The principles and advantages of this invention are as follows: 1. By introducing oracle charging nodes as independent third-party physical observers, the trust anchor is no longer limited to the vehicle-side battery management system (BMS). Even if the vehicle-side BMS code and CAN messages are completely cracked, the tampering party cannot tamper with the actual injected energy and charging trajectory characteristics measured by the charging pile's physical meter. This can effectively identify data fraud behaviors before being uploaded to the blockchain, such as BMS firmware flashing, CAN bus message interception and tampering, and man-in-the-middle attacks, thus making up for the shortcomings of blockchain in that it only stores evidence and cannot trace and verify the authenticity of the original physical data.

[0010] 2. Dual verification is implemented: macroscopic verification is based on the principle of energy conservation, while microscopic verification is based on the principle of dynamic trajectory. This allows for accurate identification of hidden capacity unlocking and health status fraud. Specifically, at the macroscopic level, the actual battery capacity is calculated by collecting real injected energy and changes in state of charge from third-party charging nodes. This is then compared with the vehicle's factory-rated physical capacity, accurately identifying deep tampering behaviors such as illegal unlocking of hidden battery capacity, excessive capacity expansion, and false capacity expansion by black market organizations. At the microscopic level, relying on the battery charging dynamics and combining the unique tail trajectory characteristics of the constant voltage charging stage, a refined verification is conducted. This overcomes the limitations of traditional single voltage threshold verification and can accurately identify fraud scenarios that traditional static verification cannot detect, such as concealed tampering, deep discharge tampering, and minor message fine-tuning cheating within the rated voltage operating range. This significantly improves the accuracy and coverage of tamper identification.

[0011] 3. Abandoning the traditional fixed static verification threshold, an adaptive dynamic benchmark threshold is adopted to complete micro-verification. Based on real-time battery apparent business status data, a verification benchmark threshold adapted to the current battery aging level and operating condition is dynamically generated through smart contracts, rather than using uniform and fixed standard parameters for verification. The verification standard can be adaptively adjusted according to the natural aging state of the battery, such as the number of battery cycles, capacity decay, and polarization impedance distortion. This effectively avoids the false alarms and false alarms caused by the differences in battery aging in traditional static verification methods. It can accurately identify sophisticated fraudulent behaviors such as deliberately concealing internal resistance distortion, forcibly inflating health valuations, and falsifying cycle counts in old batteries. It is suitable for anti-tampering verification scenarios at all stages of the battery's life cycle, and the verification accuracy and scenario adaptability are greatly improved.

[0012] 4. This invention integrates two heterogeneous data sources: charging data from oracle charging nodes and apparent business data from vehicle-side batteries. Through cross-terminal synchronous on-chain storage, and relying on the immutable and traceable characteristics of blockchain, it ensures that all original verification data, verification processes, and judgment results are fully traceable, verifiable, and documented. Simultaneously, it can automatically generate tampering assessment reports and multi-party collaborative handling instructions based on tampering judgment results, achieving full automation of the battery data collection, multi-source verification, tampering identification, risk assessment, and closed-loop handling process. This provides real, reliable, and accurate data support for core scenarios such as new energy vehicle residual value assessment, used car transaction pricing, insurance claim verification, vehicle safety supervision, and battery retirement utilization, demonstrating strong practicality and industry adaptability.

[0013] Preferably, in step S2, the strategy for uploading business status evidence data to the blockchain is as follows: 1) If the current vehicle's vehicle networking system or the car manufacturer's cloud platform is authorized, the business status data calculated by the battery management system will be automatically uploaded to the blockchain after being symmetrically encrypted and signed with a private key through the application programming interface of the vehicle networking system or the car manufacturer's cloud platform; 2) In scenarios where car manufacturers' data interfaces are not interconnected or transactions are conducted offline, business status data is extracted from the dashboard or application interface through decentralized applications or business terminals by manual input or optical character recognition, and then uploaded to the blockchain after being signed by the inputter's private key.

[0014] Beneficial effects: Strategy 1 relies on the vehicle-to-everything (V2X) API for automatic on-chain data upload, offering high efficiency and real-time performance; Strategy 2 uses decentralized applications or business terminals for on-chain data upload via manual input or OCR, suitable for scenarios where automakers' data is not interconnected or transactions are offline. Both strategies employ symmetric encryption and private key signing to ensure the confidentiality, integrity, and non-repudiation of data transmission and on-chain data upload.

[0015] Preferably, in step S3, the current estimated total capacity of the battery is... The calculation formula is as follows:

[0016] In the formula, Injecting total energy into physics, This is the change in state of charge. The energy conversion efficiency constant for battery charging. This is the factory rated voltage of the battery pack.

[0017] More preferably, in step S3, the macroscopic verification rule is: If the boundary violation formula is satisfied, then a macroscopic tampering behavior is determined to exist. The boundary violation formula is:

[0018] In the formula, This refers to the maximum rated physical capacity of the battery as currently specified by the manufacturer for the vehicle. This is the preset physical tolerance threshold; If the out-of-bounds formula is not satisfied, it is determined that there is no macroscopic tampering behavior.

[0019] Beneficial effects: By inversely estimating the true total battery capacity using the law of conservation of energy, the anchor of trust is shifted from the potentially tamperable vehicle-side BMS to the objective measurement data of the charging pile's physical meter. Any relaxation of voltage limits to release hidden capacity will cause the estimated capacity to deviate significantly from the rated capacity. At the same time, the out-of-bounds inequality introduces a physical tolerance threshold, comprehensively considering metering errors and SOC estimation drift, avoiding false alarms in normal scenarios while ensuring detection sensitivity. Furthermore, the judgment rules are only simple numerical comparisons, with low computational overhead, and are adapted for efficient on-chain execution of smart contracts.

[0020] In another preferred embodiment, the physical tolerance threshold is set based on the allowable error of the metering instrument of the oracle charging node and the reasonable drift error of the SOC estimation algorithm in the battery management system.

[0021] Beneficial effects: By comprehensively considering the allowable error of the measuring instrument and the drift error of SOC estimation, a physical tolerance threshold is set, achieving a balance between detection sensitivity and anti-interference capability. This threshold ensures that calculation fluctuations caused by factors such as measurement error, temperature influence, and normal battery aging under normal charging scenarios will not trigger out-of-bounds inequalities, thereby effectively avoiding false alarms.

[0022] Preferably, the battery apparent business status data includes claimed health. ; Step S4 includes: S4-1) The blockchain's smart contract determines the current data status on the consortium blockchain. If the data is complete, proceed to step S4-2; otherwise, proceed to step S4-3. S4-2) The blockchain's smart contract retrieves the current vehicle battery's factory-anchored electrochemical model and claims its health status. Substituting into the electrochemical model, the expected trajectory feature vector that should theoretically be exhibited under this health condition is calculated. ; Calculate the actual tail trajectory features With the expected trajectory feature vector Euclidean distance between The calculation formula is:

[0023] In the formula, This represents the actual tail trajectory characteristics. The feature vector of the expected trajectory; Euclidean distance With the first dynamic benchmark threshold Comparison, if Euclidean distance Greater than the first dynamic benchmark threshold If so, it is determined that there has been tampering. The first dynamic reference threshold Dynamically generated based on apparent business status data and electrochemical model confidence levels; S4-3) The blockchain's smart contract filters a preset number of real cycle count data of normal vehicles of the same type on the consortium blockchain, and calculates the population distribution mean vector, population distribution covariance matrix, and population distribution standard deviation of the filtered data. Calculate the actual rear trajectory characteristics of the current vehicle Mahalanobis distance from the population distribution mean vector The calculation formula is:

[0024] In the formula, This represents the actual tail trajectory characteristics. The vector of the population distribution mean. The population distribution covariance matrix; Mahalanobis distance Compared with the second dynamic benchmark threshold, if the Mahalanobis distance If the value exceeds the second dynamic benchmark threshold, it is determined that there has been tampering. The second dynamic benchmark threshold is the standard deviation of the three population distributions.

[0025] Beneficial Effects: The system automatically selects the verification mode based on the completeness of data on the consortium blockchain, demonstrating excellent scenario adaptability and seamless switching between the two modes. This ensures effective detection of tampering under any data conditions, significantly improving the solution's versatility and feasibility for industrial application. The use of dynamic benchmark thresholds instead of traditional static standards enables adaptive judgment rules. The dynamic thresholds are adjusted in real-time based on the confidence level of the electrochemical model or the standard deviation of the population distribution. Normal battery aging behavior always falls within the threshold range, preventing false alarms. Furthermore, the deviation between the expected and measured trajectories corresponding to false health status is effectively amplified by the dynamic thresholds, making tampering difficult to prevent.

[0026] More preferably, in step S4-2, the first dynamic reference threshold The generation strategy is as follows: Features of the actual tail trajectory The dimensions of features in the data are processed using dimensionless standardization. The first dynamic baseline threshold is determined based on statistical anomaly detection criteria. .

[0027] More preferably, in step S4-2, the first dynamic reference threshold The generation strategy is as follows: Oracle charging nodes calculate the characteristic temperature of the battery's true thermodynamic state based on battery temperature data. And a temperature compensation coefficient is introduced for correction; The smart contract generates the first dynamic baseline threshold according to the following formula. :

[0028] in, The standard operating condition reference tolerance threshold is based on... The principle is established. This is the characteristic temperature of the battery's true thermodynamic state. This is a correction factor.

[0029] Preferably, it further includes: The smart contract monitors the alarm behavior of each oracle charging node. When a single oracle charging node continuously issues tampering judgment alarms for more than a preset threshold number of different legitimate vehicles, the system reverses the judgment based on Byzantine fault tolerance logic to determine that the oracle node has suffered hardware failure or data corruption, and automatically strips the oracle node of its signature on-chain weight.

[0030] Beneficial Effects: By monitoring the alarm behavior of oracle nodes through smart contracts and implementing two-way checks and balances based on Byzantine fault-tolerant logic, when a single charging pile continuously issues tampering alarms to a large number of different legitimate vehicles, the system reversely determines that the node is faulty or contaminated, automatically stripping its signature weight on the chain, thus avoiding large-scale false alarms due to a single point of failure. This mechanism neither fully trusts the vehicle end nor blindly trusts the charging pile end, achieving a two-way trust verification closed loop between the vehicle and charging pile ends, significantly improving the system's robustness and fault tolerance, and ensuring the self-purification and trustworthy operation of the consortium blockchain ecosystem.

[0031] Another basic solution provided by this invention: a power battery anti-tampering evaluation system based on multi-source heterogeneous cross-end verification, comprising: Oracle charging nodes, deployed on charging equipment, are used to collect battery charging characteristic data during vehicle charging and upload it to the blockchain; the charging characteristic data includes the total physically injected energy. Actual tail trajectory characteristics during the constant voltage charging phase Changes in state of charge read from the charging protocol ; The vehicle-to-everything (V2X) status verification node is used to obtain battery apparent business status data, generate business status evidence data, and upload it to the blockchain. The blockchain smart contract layer, deployed on the consortium blockchain node, is used to receive and store charging feature data uploaded by the oracle charging node and business status evidence data uploaded by the vehicle network status verification node. Used to determine the total energy injected physically. Change in state of charge Calculate the current battery's true total capacity estimate. And based on the current vehicle's factory-approved maximum rated physical capacity of the battery. True total capacity estimate The first level of tampering detection is performed according to the preset macro-level verification rules; It is also used to generate dynamic benchmark thresholds based on battery apparent business status data, and based on battery apparent business status data and actual tail trajectory characteristics. A second tampering determination is performed by combining a dynamic benchmark threshold with preset micro-verification rules; It is also used to generate tampering reports based on the tampering determination results, and to generate multi-party joint handling instructions based on the tampering determination results. Attached Figure Description

[0032] Figure 1 This is a flowchart of the present invention; Figure 2 This is a system block diagram of the present invention; Figure 3 This is a diagram of the blockchain structure of the present invention. Detailed Implementation

[0033] The following detailed description illustrates the specific implementation method: The specific implementation process is as follows: (See details) Figures 1 to 3 A method for tamper-proof evaluation of power batteries based on multi-source heterogeneous cross-end verification includes the following steps: S1: Oracle charging nodes collect battery charging characteristic data during vehicle charging and upload it to the blockchain; the charging characteristic data includes the total physically injected energy. Actual tail trajectory characteristics during the constant voltage charging phase Changes in state of charge read from the charging protocol .

[0034] Among them, the total energy injected physically The collection strategy is as follows: the oracle charging node directly extracts the accumulated charging field generated by the underlying physical metering meter of the charger from the data packets of the charging interaction protocol (such as GB / T 27930 and mapping standards); Alternatively, the voltage actually output by the oracle charging node to the charging pile. and current The result is obtained by integration, and the formula is as follows:

[0035] In the formula, This is the actual output voltage of the charging station. This represents the actual output current of the charging pile. The charging time begins. This is the end time of charging. This is a fixed physical transmission efficiency constant for charging pile cables.

[0036] Actual tail trajectory characteristics during constant voltage (CV) charging phase The acquisition strategy is as follows: at the end of the charging process, after the battery reaches its maximum limiting voltage, it enters a constant voltage decay stage. The oracle charging node records the current decay timing at this time and extracts the actual physical feature vector as the actual tail trajectory feature. The formula is:

[0037] In the formula, The actual time constant for which the current decays exponentially; This represents the total duration of the constant pressure phase. This represents the slope of the maximum current decay.

[0038] Change in state of charge The acquisition strategy is as follows: the oracle charging node extracts the initial SOC and the end SOC sent by the battery management system (BMS) during the charging start-stop phase through the standard charging protocol (such as the message in GB / T 27930), and calculates the difference.

[0039] The oracle charging node collects charging characteristic data, such as... , , In addition to other message data required by GB / T 27930, the extracted charging feature data is combined to calculate a hash digest (such as using the SHA-256 algorithm) using the built-in security encryption module (such as an HSM or TEE computing environment). The hash digest is then digitally signed using the private key of the identity registered in the consortium blockchain network. The signed data is accompanied by the current timestamp, encapsulated into a physical on-chain transaction with a standard structure, and broadcast to the consortium blockchain network.

[0040] In this embodiment, we take an example of a used car dealer who takes an old electric vehicle that has been cycled 1,500 times and has only 75% health left. He modifies the BMS chip and the underlying code to relax the voltage limit for charging and discharging in order to "squeeze" out more apparent driving range. At the same time, he tampers with the health display to 98% in an attempt to sell it at a high price.

[0041] Potential buyers or third-party testing agencies connect the vehicle to a standard charging pile deployed by a charging network operator node (such as a large public charging station) that supports consortium blockchain interaction. The oracle charging node records the time and slope of the actual current output from the physical meter in real time through the underlying gateway. After charging is complete, the node extracts the actual charging characteristic data, generates a hash certificate using its dedicated oracle private key, and broadcasts it to the blockchain. In this embodiment, the extracted charging characteristic data includes the total physically injected energy. Actual tail trajectory characteristics during constant voltage charging phase for 55kWh for, =0.5A / min, the change in state of charge read and calculated in the charging protocol. The percentage is 80%, and the characteristic temperature of the battery cell is 25℃.

[0042] S2: Obtain battery apparent business status data, generate business status evidence data and upload it to the blockchain; At the end of the same charging cycle or during asset appraisal (such as used car transactions or extended warranty claims), obtain the battery apparent business data claimed by the current vehicle. The battery apparent business data includes the claimed health status. Cumulative number of loops The current vehicle's factory-approved maximum rated physical capacity of the battery. Rated voltage Parameters such as these.

[0043] To adapt to different levels of openness in vehicle-to-everything (V2X) connectivity and actual transaction scenarios, different methods are used to upload business status evidence data to the blockchain according to different scenarios. In step S2, the strategy for uploading business status evidence data to the blockchain is as follows: 1) If the current vehicle's vehicle networking system T-BOX or the vehicle manufacturer's cloud platform is authorized, the business status data calculated by the battery management system will be automatically uploaded to the blockchain after being symmetrically encrypted and signed with a private key through the application programming interface of the vehicle networking system or the vehicle manufacturer's cloud platform. 2) In scenarios where car manufacturers' data interfaces are not interconnected or transactions are conducted offline, vehicle owners or third-party appraisers can extract business status data from the dashboard or application interface through decentralized applications or business terminals by manual input or optical character recognition (e.g., taking photos of the dashboard / official vehicle control APP interface through the terminal and then automatically extracting the data using OCR). The data is then uploaded to the blockchain after being signed by the inputter's private key.

[0044] Preferably, in order to ensure that the battery apparent business status is shared among multiple parties (competing car manufacturers, used car dealers, and insurance companies) in the consortium blockchain without leaking the car manufacturer's core business secrets, and to ensure the non-repudiation of the data source, the generation of business status evidence data and its uploading to the blockchain rely on the consortium blockchain's built-in layered public key infrastructure (PKI) and cryptographic encryption algorithms. Specifically, during system initialization, the industry regulatory department node in the system architecture acts as the Root Certificate Authority (Root CA) to issue sub-certificates to each automaker node. When a vehicle leaves the factory, the automaker generates and issues a unique vehicle identity private key for the vehicle's T-BOX security chip (TEE / HSM) based on an asymmetric encryption algorithm (such as the national cryptographic SM2 or ECDSA algorithm), and simultaneously binds its corresponding public key to the vehicle's VIN code and registers it in the consortium blockchain identity ledger. Compliant third-party evaluation terminals are also issued corresponding business private keys by authorized institutions. When the vehicle-to-everything (V2X) system T-BOX or evaluation terminal extracts the above-mentioned apparent business status, in order to prevent the core attenuation data from being intercepted and tampered with during public network transmission and on-chain process, the corresponding acquisition terminal executes digital envelope encapsulation logic locally. First, a random key is generated using a symmetric encryption algorithm (such as the national cryptographic SM4 or AES-256 algorithm) to encrypt the plaintext of the business, including the health status SoH, and generate ciphertext of the business status to protect the privacy of car manufacturers. Subsequently, a unique data digest is calculated from the ciphertext using a hash algorithm (such as the Chinese national cryptographic algorithm SM3 or SHA-256), and the digest is digitally signed using the aforementioned secure identity private key. Finally, the encrypted business status, digital signature, and symmetric key encrypted with the smart contract's public key are packaged together into a standard blockchain transaction payload and broadcast to the consortium blockchain network. After receiving the broadcast transaction, the consensus nodes in the consortium blockchain network (such as oracle charging nodes) first retrieve the corresponding vehicle or terminal public key through the public identity ledger and decrypt and verify the attached digital signature. If the verification is successful, it proves from a cryptographic mathematical perspective that the claimed health data was sent by the T-BOX of the corresponding specific vehicle or a legitimate decentralized application (DApp) and has not been tampered with in the transmission link, thus achieving data integrity and absolute non-repudiation of responsibility. After the verification is successful, the encrypted transaction containing the subjective claim data will be packaged into the latest block by the consensus node and permanently fixed in the distributed ledger through a Merkle Tree structure, waiting for the subsequent tamper-proof smart contract to be triggered, and then cross-verified with the physical data of the oracle for micro-dynamics.

[0045] The consortium blockchain network includes a block header, which records the hash value of the previous block to ensure the immutability of the chain, and contains the timestamp of the current block generation, the consensus node signature, and a Merkle root generated by calculating upwards from the hash values ​​of the aforementioned "physical on-chain transactions" and "business declaration transactions".

[0046] The consortium blockchain network also includes blocks that store the complete cross-end verified transaction ciphertext, which is signed and verified.

[0047] In this embodiment, the "Current Health Status 98%" displayed on the vehicle's central control screen or app, along with nameplate parameters such as rated capacity and rated voltage, are photographed or manually entered. This data is then uploaded to the consortium blockchain as the subjectively claimed business status encrypted text. Specifically, in this embodiment, the battery apparent business status data includes... =98%, cumulative number of cycles =1500, the factory rated capacity of the battery. =137.5Ah, rated voltage =400V.

[0048] S3: The blockchain's smart contract injects total energy based on the physical energy contained in the latest block's block body. Change in state of charge Calculate the current battery's true total capacity estimate. And based on the current vehicle's factory-approved maximum rated physical capacity of the battery. True total capacity estimate The first level of tampering detection is performed according to the preset macro-level verification rules; In step S3, the current estimated total capacity of the battery is... The calculation formula is as follows:

[0049] In the formula, Injecting total energy into physics, This is the change in state of charge. The energy conversion efficiency constant for battery charging. This refers to the factory rated voltage of the battery pack. By extracting the total physical injection energy from the block body of the latest block. Change in state of charge Reverse calculation of the current battery's true total capacity estimate This technology can obtain a true quantitative indicator of battery capacity based on objective physical data independently measured by charging piles, thereby shifting the trust anchor from the vehicle-side BMS, which is easily hijacked by software, to an external physical verification mechanism based on the law of conservation of energy. This mechanism ensures that even if the underlying logic of the vehicle-side BMS is cracked, CAN messages are tampered with, or the claimed SOC value is maliciously forged, the tampering party cannot simultaneously tamper with the actual injected energy measured by the charging pile's physical meters. Any abnormal behavior deviating from the law of conservation of energy will be exposed at the macro level, effectively identifying violations such as hidden capacity unlocking and deep discharge tampering. This solves the underlying trust vulnerability problem of existing technologies, which can only guarantee the immutability of data after it is uploaded to the blockchain but cannot verify the true physical attributes of data "before being uploaded to the blockchain."

[0050] In step S3, the macroscopic verification rule is as follows: If the boundary violation formula is satisfied, then a macroscopic (first-level) tampering behavior is determined to exist. The boundary violation formula is:

[0051] In the formula, This refers to the maximum rated physical capacity of the battery as currently specified by the manufacturer for the vehicle (stored in the genesis block or entered by the user). This is the preset physical tolerance threshold; If the out-of-bounds formula is not satisfied, it is determined that there is no macroscopic (first level) tampering behavior.

[0052] Macro-level tampering: This refers to the act of determining, based on macro-level verification rules, whether an unauthorized party has illegally modified the underlying voltage control logic of the battery management system (BMS) (such as relaxing the charging cut-off voltage or lowering the discharging cut-off voltage) to forcibly unlock hidden capacity that exceeds the factory-designed safety range, resulting in the battery's actual storable energy being significantly higher than its rated physical capacity.

[0053] The physical tolerance threshold is set based on the allowable error (1%~2%) of the metering instruments at the oracle charging node and the reasonable drift error of the SOC estimation algorithm in the battery management system. In this embodiment, the physical tolerance threshold is... The preferred setting range is 3% to 8%.

[0054] If the out-of-bounds formula holds true, it means that the absolute physical energy injected into the battery by the current oracle charging node (charging pile), after deducting reasonable losses and errors, is still significantly greater than the maximum energy that the BMS should consume for the SOC progress span. The smart contract immediately determines that the underlying BMS voltage control logic of the battery has been maliciously tampered with (for example, the maximum charging cutoff voltage of the cell has been illegally relaxed), resulting in the unlocking of the hidden capacity and a very high risk of thermal runaway. Subsequently, the system directly triggers the high-risk blocking mechanism.

[0055] Based on the current vehicle's factory-approved maximum rated physical capacity and physical tolerance threshold, an out-of-bounds inequality is constructed. The maximum rated physical capacity approved by the vehicle at the factory is used as the judgment benchmark. This parameter is stored in the genesis block or filled in by the user and has uniqueness and immutability. The out-of-bounds inequality uses the ratio of the calculated capacity to the rated capacity as the judgment basis, rather than relying on the specific capacity value, so that the judgment rule has consistency and portability between different vehicle models and batteries of different capacities.

[0056] Preferably, the physical tolerance threshold The settings take into account both metering instrument errors and SOC estimation drift, ensuring that reasonable fluctuations under normal charging scenarios will not trigger misjudgments, while retaining the ability to sensitively identify real tampering behavior.

[0057] In this embodiment, the change in state of charge is based on the data read from the charging protocol. and physical injection total energy The value is 55 kWh, which was first obtained through macroscopic verification. Smart contracts are combined with preset physical tolerance thresholds. Calculate the legal capacity limit as follows: Therefore, the estimated value The voltage level is far above the legal limit. The first level of tampering determination results in the conclusion that the underlying physical voltage boundary of the battery has been breached, indicating illegal unlocking of the hidden capacity and posing a serious risk of thermal runaway.

[0058] S4: The blockchain's smart contract generates a dynamic baseline threshold based on the battery's apparent business status data, and then uses this data along with actual tail trajectory characteristics. A second tampering determination is performed by combining the dynamic benchmark threshold with preset micro-verification rules.

[0059] The battery apparent business status data includes claimed health. ; Step S4 includes: S4-1) The blockchain's smart contract determines the current data status on the consortium blockchain. If the data is complete, proceed to step S4-2; otherwise, proceed to step S4-3. S4-2) The blockchain's smart contract retrieves the current vehicle battery's factory-anchored electrochemical model and claims its health status. Substituting into the electrochemical model, the expected trajectory feature vector that should theoretically be exhibited under this health condition is calculated. ; Calculate the actual tail trajectory features With the expected trajectory feature vector Euclidean distance between The calculation formula is:

[0060] In the formula, This represents the actual tail trajectory characteristics. The feature vector of the expected trajectory; Euclidean distance With the first dynamic benchmark threshold Comparison, if Euclidean distance Greater than the first dynamic benchmark threshold If the actual physical polarization impedance measured by the charging pile is significantly different from the false health status declared or altered by humans, the smart contract will immediately determine that the apparent statement is falsified and that there is tampering. The first dynamic reference threshold Dynamically generated based on apparent business status data and electrochemical model confidence levels; In step S4-2, the first dynamic benchmark threshold The generation strategy is as follows: Features of the actual tail trajectory Features of each dimension ( The dimensions of features in the data are standardized and dimensionless. The first dynamic baseline threshold is determined based on statistical anomaly detection criteria. In this embodiment, the first dynamic benchmark threshold Preferably, it deviates from the expected normal distribution. The corresponding dimensionless distance threshold.

[0061] In other embodiments, in step S4-2, the first dynamic reference threshold The generation strategy is as follows: The charging characteristic data also includes battery temperature data; Oracle charging nodes calculate the characteristic temperature of the battery's true thermodynamic state based on battery temperature data. And a temperature compensation coefficient is introduced for correction; The smart contract generates the first dynamic baseline threshold according to the following formula. :

[0062] in, The standard operating condition reference tolerance threshold is based on... The principle is established. This is the characteristic temperature of the battery's true thermodynamic state. This is the corrected temperature coefficient.

[0063] S4-3) The blockchain's smart contract filters a preset number of real cycle count data of normal vehicles of the same type on the consortium blockchain, and calculates the population distribution mean vector, population distribution covariance matrix, and population distribution standard deviation of the filtered data. Calculate the actual rear trajectory characteristics of the current vehicle Mahalanobis distance from the population distribution mean vector The calculation formula is:

[0064] In the formula, This represents the actual tail trajectory characteristics. The vector of the population distribution mean. The population distribution covariance matrix; Mahalanobis distance Compared with the second dynamic benchmark threshold, if the Mahalanobis distance If the value exceeds the second dynamic benchmark threshold, it is determined that there has been tampering. The second dynamic benchmark threshold is the standard deviation of three population distributions, i.e., if the Mahalanobis distance... If the deviation from the normal distribution of the same type of group exceeds 3 standard deviations, it indicates that the electrochemical behavior of the vehicle exhibits abnormalities due to non-natural aging, and it is determined that there is concealed tampering or excessive abuse.

[0065] In this embodiment, the smart contract retrieves the "98% health expected decay model" of the car model pre-shared by the car manufacturer's nodes, or the model obtained through federated computation and the law of large numbers on the consortium blockchain, and compares it with the "measured long-tail decay trajectory" on the oracle node's blockchain. After using probe temperature to rule out the increased polarization impedance caused by the low temperature environment, the contract finds that the Euclidean distance between the two is seriously beyond the dynamic threshold, and determines that the health data is maliciously tampered with.

[0066] In this embodiment, the data is complete, and micro-verification is performed using step S4-2. The smart contract will then verify any false claims of health. Substituting the theoretical degradation model (electrochemical model) of the car manufacturer, the expected degradation trajectory under this health level is calculated. It should be: , , =2A / min. The contract introduces a temperature coefficient for battery temperature calculation. =1.0, combined with the baseline tolerance =3, thus obtaining the dynamic threshold. =3. The contract will measure the characteristics of the long, actual tail trajectory. With the expected trajectory feature vector Perform Euclidean distance calculations to obtain spatial distance. =8.5. After eliminating the influence of temperature, the conclusion is: the distance to 8.5 is much greater than the dynamic threshold. 3.0. The polarization impedance change is significantly higher than the level that should be expected for a 98% health rating. Therefore, the second tampering determination is that the apparent 98% health rating is a maliciously tampered and false data.

[0067] In other embodiments, where the data is incomplete, micro-verification is performed using step S4-3. The contract uses the "98% health" to be falsified as a search condition. It automatically searches and filters a preset number (e.g., N=500 vehicles) of similar reference vehicles with an apparent health of around 98% and a cycle count of 1500 times in the global historical ledger of the consortium blockchain. The contract then extracts the recent CV actual tail trajectory features of these 500 vehicles, endorsed by the oracle. Calculate the population distribution mean vector and covariance matrix of these 500 vehicles. Then calculate the population distribution mean vector of this "98% healthy group" at the current suitable temperature. The population distribution covariance matrix is This matrix reflects the variance and covariance of the peer group across three dimensions: time constant, constant pressure duration, and decay slope. The smart contract obtains the feature vector of the vehicle's actual rear trajectory. The Mahalanobis distance was calculated. =8.6. According to the system settings, the second dynamic benchmark threshold is the standard deviation of the three group distributions of 3.0. The Mahalanobis distance (8.6) of the current vehicle far exceeds the dynamic statistical threshold. The second tampering judgment in this embodiment is: the measured long-tail trickle decay trajectory of the target vehicle deviates significantly from the physical normal distribution characteristics of the other 500 vehicles in the network that are also labeled as "98% health". This vehicle has engaged in covert tampering or excessive abuse, and the apparent 98% health is a false data maliciously tampered with.

[0068] S5: Generate a tampering report based on the tampering determination results of the first and second tampering determinations, and generate multi-party joint handling instructions based on the tampering determination results.

[0069] The multi-party coordinated response instructions include: Asset Status Update: The report is recorded as an internal transaction triggered by the smart contract itself, directly modifying the world state of the vehicle's digital asset certificate (dNFT) in the consortium blockchain ledger and forcibly downgrading its residual value rating; the result of this status change will be permanently sealed in the next generated block along with a hash operation, and will simultaneously trigger the release instruction of the associated insurance node. Financial risk control: Send a waiver instruction to the insurance company node that underwrites the vehicle through the cross-chain oracle charging node or internal API to automatically terminate the fire and spontaneous combustion insurance or extended warranty service for the battery. Safety Interruption: Broadcast the vehicle's safety risks to the regulatory platform and charging network, limit the maximum permissible charging current of the vehicle during subsequent charging, and prevent thermal runaway accidents; Staking and Forfeiture: The business staking deposit that was pre-locked when the violating node joined the consortium blockchain will be automatically frozen or forfeited and transferred to the consortium risk compensation pool. At the same time, the node's reputation score will be significantly reduced in the global ledger, and its digital identity certificate (DID) will be added to the anti-fraud blacklist shared by regulatory authorities, car manufacturers, and insurance companies. If the number of times the same node triggers the red line reaches the threshold, the smart contract will permanently revoke its business private key signing permission and expel it from the consortium network, achieving a decentralized and strict industry ban.

[0070] In this embodiment, the tampering determination result is: the apparent health rate of 98% is false data maliciously tampered with, posing a risk of thermal runaway. The generated multi-party linkage disposal instruction is as follows: the valuation of the vehicle's digital asset certificate (dNFT) is cleared to zero, and a red anti-counterfeiting warning label of "bottom boundary breach" is added. The transaction is terminated immediately after the buyer scans the code; the insurance node is synchronized to automatically cut off the vehicle's eligibility for battery extended warranty claims and spontaneous combustion insurance, enabling the car company to prove its legal exemption from liability; the business deposit that the counterfeit used car dealer pledged in advance on the consortium blockchain is confiscated.

[0071] Step S5 also includes a positive incentive step: the smart contract automatically triggers reward settlement logic for oracle charging nodes that successfully provide objective physical benchmark data and compliant nodes that have consistently performed well and whose submitted data remains consistent with physical verification results. Alliance reputation tokens are then issued to these nodes, which are used to offset service fees or increase the node's weight or revenue sharing ratio in the consensus process. In this embodiment, reputation token rewards are issued to the charging network operator nodes (oracles) that successfully provide objective physical verification quantification data, forming a positive autonomous closed loop.

[0072] It also includes: smart contract monitoring of the alarm behavior of each oracle charging node. When a single oracle charging node continuously issues tampering judgment alarms for more than a preset threshold number of different legitimate vehicles, it reverses the judgment based on Byzantine fault tolerance logic to determine that the oracle node has suffered hardware failure or data corruption, and automatically strips the oracle node of its signature on-chain weight.

[0073] It also includes a power battery anti-tampering evaluation system based on multi-source heterogeneous cross-end verification, used to implement the above method, including: Oracle charging nodes, deployed on charging equipment, are used to collect battery charging characteristic data during vehicle charging and upload it to the blockchain; the charging characteristic data includes the total physically injected energy. Actual tail trajectory characteristics during the constant voltage charging phase Changes in state of charge read from the charging protocol ; The vehicle-to-everything (V2X) status verification node is used to obtain battery apparent business status data, generate business status evidence data, and upload it to the blockchain. The blockchain smart contract layer, deployed on the consortium blockchain node, is used to receive and store charging feature data uploaded by the oracle charging node and business status evidence data uploaded by the vehicle network status verification node. Used to determine the total energy injected physically. Change in state of charge Calculate the current battery's true total capacity estimate. And based on the current vehicle's factory-approved maximum rated physical capacity of the battery. True total capacity estimate The first level of tampering detection is performed according to the preset macro-level verification rules; It is also used to generate dynamic benchmark thresholds based on battery apparent business status data, and based on battery apparent business status data and actual tail trajectory characteristics. A second layer of tampering detection is performed by combining dynamic benchmark thresholds with preset micro-verification rules; It is also used to generate a tampering report based on the tampering determination results of the first and second tampering determinations, and to generate multi-party joint handling instructions based on the tampering determination results.

[0074] The above are merely embodiments of the present invention. Commonly known structures and characteristics are not described in detail here. Those skilled in the art are aware of all common technical knowledge in the field prior to the application date or priority date, are aware of all existing technologies in that field, and have the ability to apply conventional experimental methods prior to that date. Those skilled in the art can, under the guidance of this application, improve and implement this solution in combination with their own capabilities. Some typical known structures or methods should not be obstacles for those skilled in the art to implement this application. It should be noted that those skilled in the art can make several modifications and improvements without departing from the structure of the present invention. These should also be considered within the scope of protection of the present invention, and will not affect the effectiveness of the implementation of the present invention or the practicality of the patent. The scope of protection claimed in this application should be determined by the content of its claims, and the specific embodiments described in the specification can be used to interpret the content of the claims.

Claims

1. A method for evaluating the tamper-proof properties of power batteries based on multi-source heterogeneous cross-end verification, characterized in that, Includes the following steps: S1: Oracle charging nodes collect battery charging characteristic data during vehicle charging and upload it to the blockchain; the charging characteristic data includes the total physically injected energy. Actual tail trajectory characteristics during the constant voltage charging phase Changes in state of charge read from the charging protocol ; S2: Obtain battery apparent business status data, generate business status evidence data and upload it to the blockchain; S3: Blockchain smart contracts inject total energy based on physics. Change in state of charge Calculate the current battery's true total capacity estimate. And based on the current vehicle's factory-approved maximum rated physical capacity of the battery. True total capacity estimate The first level of tampering detection is performed according to the preset macro-level verification rules; S4: The blockchain's smart contract generates a dynamic baseline threshold based on the battery's apparent business status data, and then uses this data along with actual tail trajectory characteristics. A second tampering determination is performed by combining a dynamic benchmark threshold with preset micro-verification rules; S5: Generate a tampering report based on the tampering determination result, and generate multi-party coordinated handling instructions based on the tampering determination result.

2. The power battery anti-tampering evaluation method based on multi-source heterogeneous cross-end verification according to claim 1, characterized in that: In step S2, the strategy for uploading business status evidence data to the blockchain is as follows: 1) If the current vehicle's vehicle networking system or the car manufacturer's cloud platform is authorized, the business status data calculated by the battery management system will be automatically uploaded to the blockchain after being symmetrically encrypted and signed with a private key through the application programming interface of the vehicle networking system or the car manufacturer's cloud platform; 2) In scenarios where car manufacturers' data interfaces are not interconnected or transactions are conducted offline, business status data is extracted from the dashboard or application interface through decentralized applications or business terminals by manual input or optical character recognition, and then uploaded to the blockchain after being signed by the inputter's private key.

3. The power battery anti-tampering evaluation method based on multi-source heterogeneous cross-end verification according to claim 1, characterized in that: In step S3, the current estimated total capacity of the battery is... The calculation formula is as follows: In the formula, Injecting total energy into physics, This is the change in state of charge. The energy conversion efficiency constant for battery charging. This is the factory rated voltage of the battery pack.

4. The power battery anti-tampering evaluation method based on multi-source heterogeneous cross-end verification according to claim 3, characterized in that: In step S3, the macroscopic verification rule is as follows: If the boundary violation formula is satisfied, then a macroscopic tampering behavior is determined to exist. The boundary violation formula is: In the formula, This refers to the maximum rated physical capacity of the battery as currently specified by the manufacturer for the vehicle. This is the preset physical tolerance threshold; If the out-of-bounds formula is not satisfied, then there is no macroscopic tampering behavior.

5. The power battery anti-tampering evaluation method based on multi-source heterogeneous cross-end verification according to claim 4, characterized in that: The physical tolerance threshold is set based on the allowable error of the metering instruments of the oracle charging node and the reasonable drift error of the SOC estimation algorithm in the battery management system.

6. The method for evaluating the anti-tampering properties of power batteries based on multi-source heterogeneous cross-end verification according to claim 1, characterized in that: The battery apparent business status data includes claimed health. ; Step S4 includes: S4-1) The blockchain's smart contract determines the current data status on the consortium blockchain. If the data is complete, proceed to step S4-2; otherwise, proceed to step S4-3. S4-2) The blockchain's smart contract retrieves the current vehicle battery's factory-anchored electrochemical model and claims its health status. Substituting into the electrochemical model, the expected trajectory feature vector that should theoretically be exhibited under this health condition is calculated. ; Calculate the actual tail trajectory features With the expected trajectory feature vector Euclidean distance between The calculation formula is: In the formula, This represents the actual tail trajectory characteristics. The feature vector of the expected trajectory; Euclidean distance With the first dynamic reference threshold Comparison, if Euclidean distance Greater than the first dynamic benchmark threshold If so, it is determined that there has been tampering. The first dynamic reference threshold Dynamically generated based on apparent business status data and electrochemical model confidence levels; S4-3) The blockchain's smart contract filters a preset number of real cycle count data of normal vehicles of the same type on the consortium blockchain, and calculates the population distribution mean vector, population distribution covariance matrix, and population distribution standard deviation of the filtered data. Calculate the actual rear trajectory characteristics of the current vehicle Mahalanobis distance from the population distribution mean vector The calculation formula is: In the formula, This represents the actual tail trajectory characteristics. The vector of the population distribution mean. The population distribution covariance matrix; Mahalanobis distance Compared with the second dynamic benchmark threshold, if the Mahalanobis distance If the value exceeds the second dynamic benchmark threshold, it is determined that there has been tampering. The second dynamic benchmark threshold is the standard deviation of the three population distributions.

7. The method for tamper-proof evaluation of power batteries based on multi-source heterogeneous cross-end verification according to claim 6, characterized in that: In step S4-2, the first dynamic benchmark threshold The generation strategy is as follows: Features of the actual tail trajectory The dimensions of features in the data are processed using dimensionless standardization. The first dynamic baseline threshold is determined based on statistical anomaly detection criteria. .

8. The power battery anti-tampering evaluation method based on multi-source heterogeneous cross-end verification according to claim 6, characterized in that: In step S4-2, the first dynamic benchmark threshold The generation strategy is as follows: Oracle charging nodes calculate the characteristic temperature of the battery's true thermodynamic state based on battery temperature data. And a temperature compensation coefficient is introduced for correction; The smart contract generates the first dynamic baseline threshold according to the following formula. : in, The standard operating condition reference tolerance threshold is based on... The principle is established. This is the characteristic temperature of the battery's true thermodynamic state. This is a correction factor.

9. The power battery anti-tampering evaluation method based on multi-source heterogeneous cross-end verification according to claim 1, characterized in that: Also includes: The smart contract monitors the alarm behavior of each oracle charging node. When a single oracle charging node continuously issues tampering judgment alarms for more than a preset threshold number of different legitimate vehicles, the system reverses the judgment based on Byzantine fault tolerance logic to determine that the oracle node has suffered hardware failure or data corruption, and automatically strips the oracle node of its signature on-chain weight.

10. A power battery anti-tampering evaluation system based on multi-source heterogeneous cross-end verification, characterized in that, include: Oracle charging nodes, deployed on charging equipment, are used to collect battery charging characteristic data during vehicle charging and upload it to the blockchain; the charging characteristic data includes the total physically injected energy. Actual tail trajectory characteristics during the constant voltage charging phase Changes in state of charge read from the charging protocol ; The vehicle-to-everything (V2X) status verification node is used to obtain battery apparent business status data, generate business status evidence data, and upload it to the blockchain. The blockchain smart contract layer, deployed on the consortium blockchain node, is used to receive and store charging feature data uploaded by the oracle charging node and business status evidence data uploaded by the vehicle network status verification node. Used to determine the total energy injected physically. Change in state of charge Calculate the current battery's true total capacity estimate. And based on the current vehicle's factory-approved maximum rated physical capacity of the battery. True total capacity estimate The first level of tampering detection is performed according to the preset macro-level verification rules; It is also used to generate dynamic benchmark thresholds based on battery apparent business status data, and based on battery apparent business status data and actual tail trajectory characteristics. A second tampering determination is performed by combining a dynamic benchmark threshold with preset micro-verification rules; It is also used to generate tampering reports based on the tampering determination results, and to generate multi-party joint handling instructions based on the tampering determination results.