Method and battery management system for authenticating battery measurement data
The method uses one-way functions with time-changing key values to authenticate battery measurement data, safeguarding against manipulation and unauthorized changes, ensuring reliable and secure battery management.
Patent Information
- Application Number
- DE102013219100
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2013-09-24
- Publication Date
- 2025-09-25
- Estimated Expiration
- 2033-09-24
AI Technical Summary
Existing battery management systems lack effective methods to authenticate and protect measurement data from manipulation and unauthorized replacement, posing safety and reliability risks.
A method involving module control units generating unique, time-changing key values using one-way functions to create signatures for measurement data, which are validated by a central control unit, ensuring data integrity and detecting unauthorized changes.
Prevents data manipulation and unauthorized replacements, enhancing safety and reliability by quickly authenticating measurement data with minimal computational effort, while maintaining system integrity and enabling rapid detection of tampering attempts.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
State of the art
[0001] The invention relates to a method for authenticating measurement data of a battery comprising at least one battery module with an associated module control unit and a central control unit, wherein measurement data of battery units are recorded by the at least one module control unit.
[0002] Furthermore, a data structure with such measurement data, a computer program, and a battery management system are specified, which are particularly configured to carry out the method. Furthermore, a battery and a motor vehicle with such a battery are specified.
[0003] Electronic control units are increasingly being used in the automotive industry today. Examples include engine control units and control units for ABS or airbags. For electrically powered vehicles, a current research focus is the development of high-performance battery packs with associated battery management systems—i.e., control units equipped with software for monitoring battery functionality. Battery management systems ensure, among other things, the safe and reliable operation of the battery cells and battery packs used. They monitor and control currents, voltages, temperatures, insulation resistance, and other variables for individual cells and / or the entire battery pack. These variables can be used to implement management functions that increase the service life, reliability, and safety of the battery system.
[0004] From DE 10 2009 030 091 A1, a method for communication between a charging station and an electric vehicle is known, which includes an integrity and authenticity check, wherein data packets are sent that are signed by means of hash codes, in particular by means of one-way functions and device keys, so that it can be determined on the receiver side whether a change to the data packets must have taken place.
[0005] DE 10 2011 089 352 A1 discloses a battery management system in which configuration parameters are checked. These configuration parameters include both battery usage data and parameters determined by factory tests. A firmware checks that the values in the registers actually have values that result in checksums identical to factory-programmed error detection data, e.g., checksums or hash functions. If some of the configuration parameters are found to be incorrect, measures can be taken, such as blocking battery operation, storing a memory failure message, or resetting the system.
[0006] From DE 102 04 065 A1, a method and an arrangement for processing data collected by individually identified data acquisition instruments are known, as well as a corresponding computer program product and a corresponding computer-readable storage medium, which can be used in particular in facility and energy management.
[0007] From US 2012 / 0316813 A1, a control of a battery that drives a drive motor of a vehicle is known, which is carried out by determining status data that represent the operation and wear of the battery, authenticating the status data using an encryption method and transmitting the authenticated status data for display on an on-board computer of the vehicle. Disclosure of the invention
[0008] A method according to the invention for authenticating measurement data of a battery comprises the following steps: a) Collection of measurement data from battery units by a module control unit; b) Determination by the module control unit of at least one additional information carrier which is configured to authenticate the measurement data; c) transmitting the measurement data and the at least one additional information carrier from the module control unit to the central control unit; d) validation of the measurement data using at least one additional information carrier by the central control unit, whereby the additional information carrier is determined based on the measurement data and a key value defined by the module control unit based on a specific measured value.
[0009] Measurement data typically recorded and monitored by module control units includes, for example, temperature, insulation resistance, state of charge, delivered current, or supplied voltage. Measurement data can also include variables derived from these, such as temporally summed or integrated variables, multiplied by one another, or otherwise aggregated variables. Furthermore, the derived measurement data can include difference values between minimum and maximum states, for example, states of charge, relative battery performance, or the number of charge and discharge cycles. Battery management functions are implemented using such measurement data, such as determining the expected service life of the battery system or the state of health (SOH) of the battery.
[0010] The method can be applied particularly to lithium-ion batteries and nickel-metal hydride batteries. It is preferably applied to several, and in particular to all, modules of one or more batteries that are operated in essentially the same way.
[0011] Advantageous further developments and improvements of the method specified in the independent claim are possible by the measures listed in the dependent claims.
[0012] The key value defined by the module control unit is also referred to as a seed or seed key within the scope of the invention. The key value defined by the module control unit is determined based on the specific measured value of a variable, for example, the temperature, the state of charge, the output current, or the supplied voltage, or based on a derived or otherwise aggregated variable, which can be formed as previously described. The specific measured value used should remain secret to make it as difficult as possible for third parties to circumvent the encryption.
[0013] The determined measured value is preferably a measured value that belongs to the measured data that is or has been transmitted with the at least one additional information carrier or previously from the module control unit to the central control unit and validated by the central control unit. In particular, the determined measured value can belong to the most recently transmitted and validated measured data of the module control unit or to the currently transmitted and to be validated measured data of the module control unit.
[0014] The first key value defined by the module control unit is also referred to as the starting value. A specific measured value belonging to the currently transmitted and validated measurement data of the module control unit can serve as the starting value, for example, the first measured cell voltage.
[0015] Particularly preferably, the additional information carrier is determined using a one-way function f(x,y) from the key value defined by the module control unit and the measurement data. The one-way function f(x,y) → z is preferably defined with properties such that its function value z is easy to calculate, and inverting the function is very complex and practically impossible. Examples of such one-way functions can be found in cryptography, for example, hash functions, in particular SHA-1, SHA-2, or SHA-3, or as multiplication of prime numbers.
[0016] Hash functions are suitable for confirming the integrity of data. This means that it is practically impossible to generate measurement data with the same hash value as the given measurement data through intentional modification. Without knowledge of the calculation rules of the additional information carrier, a potential attacker cannot generate a plausible combination of measurement data and a matching signature and store it in the control unit.
[0017] The checksum can also be generated using a cyclic redundancy check (CRC). In the cyclic redundancy check (CRC), a bit sequence of the measured data is divided modulo 2 by a specified generator polynomial, the so-called CRC polynomial, leaving a remainder. This remainder is the CRC value, which is appended to the measured data.
[0018] For the one-way function f(x,y) → z, the value y is the key value defined by the module control unit. The value y ensures that the same one-way function produces different results in different control units. Each module control unit has its own key values and therefore uses a different one-way function from the others, even with the same measured data. The input value x is the measured data. The value x and the value y result in the key, i.e. the information that parameterizes the cryptographic algorithm. For example, all measured data can be linked to a single value using an XOR function, which is then used together with the value y to calculate the additional information carrier. The use of the module control unit-specific key makes it very difficult to draw conclusions about the calculation rule.
[0019] After being captured, the measurement data is provided, either individually or in a bundle, with an additional information carrier, which in this context can also be referred to as authentication information or a so-called signature. The signature, for example, a 32-bit value, is stored in a data structure together with the measurement data.
[0020] The key value defined by the module control unit is preferably changed randomly by the module control unit. A time point can be described as randomly calculated by the module control unit using true random numbers or pseudo-randomly, for example based on the evaluation of noise or using a random number generator. Pseudo-randomness can in particular also be designed such that a change occurs on average after a defined number of measurement cycles, for example after every hundredth, every thousandth, or every ten thousandth. Alternatively, the pseudo-randomness can be set up so that a change occurs on average after a specific period of time or after a specific usage time, for example once per day that the battery was used.
[0021] The measurement data from the individual module control units and the additional information carriers configured to authenticate the measurement data are transmitted to the central control unit. The central control unit also knows all previously defined key values from the module control units. The central control unit validates the measurement data by comparing the transmitted additional information carriers with self-calculated additional information carriers, which are determined using the known key values and the measurement data.
[0022] Since each module control unit can change the key values, validation by the central control unit is preferably performed in two stages: in a first stage, validation is performed against a known key value. If validation fails in the first stage, validation is performed against a new key value in a second stage. Since the new key value is part of the transmitted and validated measurement data of the module control unit or is part of the currently transmitted and to be validated measurement data of the module control unit, the central control unit has immediate access to it.
[0023] According to a preferred embodiment, if the validation fails, the central control unit generates an error message and makes it available, for example, on the CAN bus. Alternatively or additionally, the central control unit can partially disable or reduce the battery, for example, by initiating a so-called limp-home.
[0024] According to a preferred embodiment, the method comprises the following further step: e) Storing the measurement data in a non-volatile memory of the central control unit.
[0025] Such non-volatile memory is, for example, a so-called EEPROM (electrically erasable programmable read-only memory), i.e. a non-volatile, electronic memory chip whose stored information can be electrically erased. The storage of measurement data in the non-volatile memory can include both verified measurement data and unsuccessfully verified data, whereby the former can be done in particular for the purpose of providing measurement data for battery management functions. Measurement data provided in this way can, for example, be used to determine the average or cumulative usage of the battery, for example in the context of damage cases to determine causes. Stored unsuccessfully verified data, on the other hand, can prove that an attack on the system has occurred.
[0026] Preferably, verification takes place after a defined number of measurement cycles, for example, after every measurement cycle, every tenth, every hundredth, every thousandth, or every ten thousandth. Alternatively, verification can take place after a specific period of time or after a specific usage period, for example, every day if the battery was used on that day.
[0027] Furthermore, a data structure is proposed containing measurement data from battery units and at least one additional information carrier configured to validate the measurement data. The data structure was created during the implementation of one of the described methods. The data structure is read, for example, by a computer device for maintenance and service purposes or for authentication of the measurement data.
[0028] Furthermore, a computer program is proposed, according to which one of the methods described herein is carried out when the computer program is executed on a programmable computer device. The computer program can be, for example, a module for implementing a device for providing measurement data for a battery management system and / or a module for implementing a battery management system of a vehicle. The computer program can be stored on a machine-readable storage medium, for example on a permanent or rewritable storage medium or in association with a computer device, for example on a portable memory such as a CD-ROM, DVD, USB stick, or memory card.Additionally or alternatively, the computer program may be made available for download on a computer device, such as a server or a cloud server, for example via a data network such as the Internet or a communications connection such as a telephone line or a wireless connection.
[0029] According to the invention, a battery management system (BMS) is also provided, comprising a unit for acquiring measurement data from battery units, a unit for determining an additional information carrier configured to authenticate the measurement data and determined based on the measurement data and a key value defined by the module control unit, units for transmitting the measurement data and the additional information carrier from a module control unit to a central control unit, and a unit for validating the measurement data based on the additional information carrier. The battery management system preferably has a non-volatile memory and a unit for storing the transmitted and validated measurement data in a non-volatile memory.
[0030] Furthermore, a battery, in particular a lithium-ion battery or a nickel-metal hydride battery, is provided, which comprises a battery management system and can be connected to a drive system of a motor vehicle, wherein the battery management system is designed as described above and / or is configured to carry out the method according to the invention.
[0031] In this description, the terms "battery" and "battery unit" are used to refer to accumulator and accumulator unit, respectively, in accordance with common usage. The battery preferably comprises one or more battery units, which may include a battery cell, a battery module, a module string, or a battery pack. The battery cells are preferably spatially grouped and interconnected by circuitry, for example, connected in series or parallel to form modules. Several modules can form so-called battery direct converters (BDCs), and several battery direct converters can form a battery direct inverter (BDI).
[0032] Furthermore, a motor vehicle with such a battery is provided, wherein the battery is connected to a drive system of the motor vehicle. The method is preferably applied to electrically powered vehicles in which a plurality of battery cells are interconnected to provide the necessary drive voltage. Advantages of the invention
[0033] The method according to the invention can prevent the manipulation of measurement data and / or the unauthorized replacement of battery modules. Furthermore, the unauthorized use of battery packs outside of specifications can be detected by manipulating the measurement data. If measurement data does not contain the correct additional information carrier, this is an indication of manipulation of the measurement data or a defective memory.
[0034] Without precise knowledge of the calculation rule and the unique key value of the module control unit, a potential attacker cannot calculate a plausible signature. Reverse engineering of the signature calculation using a sufficient number of known measurement data-signature combinations is also made significantly more difficult by using the module control unit's individual key. In the unlikely event that an attacker has decrypted the secured usage information for one module, they can only falsify the usage information for that one module; all other modules remain protected. Another particularly advantageous feature is that the one-way functions can be implemented identically on all module control units, since the module control units uniquely change the one-way function for each module control unit.
[0035] Particularly advantageous for safety reasons and for handling warranty claims, the replacement of module control units is also detected. If an unauthorized replacement is detected, the battery management system can block the use of the entire battery pack or put it into emergency mode.
[0036] The central battery control unit and the local module control units can be configured as desired and react to the counterfeit, for example, by entering a note in the error log or blocking the battery. The control unit is also given the ability to detect memory defects and react accordingly, stopping the use of the defective memory cells.
[0037] Another particularly advantageous feature is that authentication can be performed very quickly and with minimal effort, since only a single signature is communicated and needs to be verified. The method is also characterized by minimal additional data volume, since a single signature can be assigned to multiple measured values. Furthermore, the battery management system's startup process, known as system boot, is not delayed, since the signatures can be compared during the cyclical measurement data communication. Short description of the drawings
[0038] Embodiments of the invention are illustrated in the drawings and explained in more detail in the following description.
[0039] They show: Fig. 1 a battery management system, Fig. 2 an example of a manipulation attempt in the communication between module control units and a central control unit, Fig. 3 an example of a system and method according to the invention and Fig. 4 an example of process steps according to the invention. Embodiments of the invention
[0040] The battery management system 1 in Fig. 1 comprises a central control unit 2, which can also be referred to as a BCU (Battery Control Unit), and a number of battery modules 4, each of which has its own module control units 6, also referred to as CMC (Cell Module Controller). Each battery module 4 is assigned battery units 8, typically comprising several battery cells, which are connected in series and sometimes also in parallel in order to achieve the required performance and energy data with the battery system. The individual battery cells are, for example, lithium-ion batteries with a voltage range of 2.8 to 4.2 volts. Communication between the central control unit 2 and the module control units 6 takes place via a communication channel 5, for example, via a CAN bus, and suitable interfaces 10, 12.
[0041] Fig. 2 shows a further schematic representation of the battery management system 1 from Fig. 1. The battery management system 1 comprises the central control unit 2 and the battery modules 4, each of which has module control units 6. Each battery module 4 is assigned battery units 8 with multiple battery cells. Communication between the central control unit 2 and the module control units 6 takes place via the communication channel 5, for example, via the CAN bus, and suitable interfaces 10, 12. Sensors 14 are connected to the communication channel 5 via additional interfaces 16. Fig. Figure 2 illustrates an attempt by an attacker 23 to manipulate the communication between the module control units 12 and the central control unit 2. The attacker 23 gains access to the communication channel 5 and falsifies transmission data. To do so, the attacker 23 interrupts the communication between the central control unit 2 and the module control units 6 and responds to service requests from the central control unit 2 with self-generated messages. These messages simulate valid communication with the module control units 6. The attacker 23 can, for example, falsify measured values to increase the battery's performance. In particular, the attacker 23 could indicate a higher battery charge level than it actually is. This allows the central control unit 2 to draw more energy from the battery and release more power to the vehicle.This can lead to damage and deep discharge of the battery and cause safety-critical conditions that cannot be detected by the central control unit 2 due to corrupted communication. This poses a significant safety risk, as the battery may be operated outside of its specifications, thus creating the possibility of battery damage.
[0042] Fig. 3 shows a battery management system 1 according to the invention, which carries out the method according to the invention. The battery management system 1 comprises a central control unit 2 and several module control units 6. The module control units 6 are coupled to sensors 14, which acquire measurement data, such as temperatures, state of charge, current, or voltage, and provide it to the module control units 6 via their interfaces 16 in a step S2. The module control units 6 each comprise a unit 20 for acquiring the measurement data, which receives the measurement data from the sensors 14. In each module control unit 6, the unit 20 for acquiring the measurement data is coupled to a unit 24 for determining an additional information carrier, which is configured to authenticate the measurement data.The unit 24 for determining the additional information carrier receives the measurement data from the unit 20 for acquiring the measurement data and determines a key value from a non-volatile memory 22 or based on the measurement data. Based on these input parameters, the unit 24 calculates the signature using the one-way function and provides it to a communication unit 26 in a step S3. In a further step S4, the communication unit 26 transmits the measurement data and the additional information carrier to the central control unit 2.
[0043] The central control unit 2 comprises a communication unit 32 for receiving the measurement data and the additional information carrier from the module control units 6. The communication unit 32 for receiving the measurement data and the additional information carrier provides the received measurement data and the additional information carrier to a unit 30 for validating the measurement data using the additional information carrier. The unit 30 for validating the measurement data comprises a unit 34 for determining the key value. The key value can be determined from a non-volatile memory 36 of the central control unit 2 in which it is stored. If the measurement data cannot be verified using the key value stored in the non-volatile memory 36 or during system startup, the unit 34 determines the key value based on a specific measured value.The unit 30 for validating the measurement data also includes a unit 38 for calculating a signature based on the measurement data and the key value and a unit 40 for comparing the transmitted signature with the calculated signature.
[0044] In a further step S6, the information is further processed. If the measurement data has been authenticated by the measurement data validation unit 30, it is further processed, for example, stored or provided to a communication bus. If the signatures do not match, the following scenarios may occur: a) The module control unit 6 was replaced; b) a non-volatile memory of the module control unit or the central control unit is defective; c) errors in data transmission and / or d) Measurement data have been falsified.
[0045] The central control unit 2 preferably then performs further tests to narrow down the source of the error, for example to determine whether the error is attributable to an individual module control unit 6 or whether every module control unit 6 is affected. In the latter case, a fault in the communication channel is to be assumed. In the case of errors that indicate corrupted measurement data, the central control unit 2 will block operation of the battery pack, since not all module control units 6 are in their original state. It can be provided that the central control unit 2 permits restricted operation of the battery pack, for example to keep the vehicle drivable enough to be taken to a workshop for inspection, which is also referred to as a so-called limp home.
[0046] Fig.4 shows further steps of the method according to the invention at four different times t1, t2, t3, t4. At a first time t1, in a step S8, the module control unit 6 determines a first key value 44 from a specific measured value from a set of first measured data 46, for example from a raw value of a first determined cell voltage. In a step S7, the measured data 46 are signed with the key value 44. The signature is present as an additional information carrier 48 together with the measured data 46 in a common data structure 50. In step S4, the module control unit 6 transmits the measured data 46 and the additional information carrier 48 to the central control unit 2. The central control unit 2 determines the key value 44 from the measured data 46 and authenticates the measured data 46 as valid. The central control unit 2 stores the key value 44, preferably in encrypted form, in a non-volatile memory in a step S9.
[0047] The measurement data 46 of a second measurement are also signed with the first key value 44 by the module control unit 6 at a second time t2 in step S7. The measurement data 46 are transmitted to the central control unit 2 in step S4 and authenticated as valid by the central control unit 2 based on the stored key value 44.
[0048] At a third time t3, the module control unit automatically changes the key value 44 for the third measurement to a new key value 44. This change is not actively communicated to the central control unit 2. The central control unit 2 attempts to authenticate the measurement data 46 with the stored key value 44, but this attempt fails.
[0049] At a fourth time t4, the central control unit 2 switches from a first validation stage to a second validation stage and determines the new key value 44 from the measurement data 46 and authenticates the measurement data 46 as valid based on the new key value 44. The new key value 44 is then stored in step S9.
[0050] If an attacker replicates the communication between control units 2, 6 but fails to calculate the correct key values 44, the central control unit 2 cannot perform a valid authentication of the measurement data 46. In the example shown, if the data is forged, the second authentication will also fail. This is a clear sign of forged measurement data. The seemingly random and externally undetectable change in the key values 44 makes reverse engineering of the signature function significantly more difficult.
[0051] The invention is not limited to the embodiments described here and the aspects highlighted therein. Rather, numerous modifications are possible within the scope of the claims, which are within the scope of one skilled in the art.
Claims
[1] Method for authenticating measurement data (46) of a battery comprising at least one battery module (4) with an associated module control unit (6) and a central control unit (2), comprising the following steps: a) detecting (S2) measurement data (46) from battery units (8) by the module control unit (6); b) determining (S3) at least one additional information carrier (48) which is configured to authenticate the measurement data (46) by the module control unit (6); c) transmitting (S4) the measurement data (46) and the additional information carrier (48) from the module control unit (6) to the central control unit (2); d) validating (S6) the measurement data (46) on the basis of the additional information carrier by the central control unit (2), wherein the additional information carrier (48) is determined on the basis of the measurement data (46) and a key value (44) defined by the module control unit (6), wherein the key value (44) defined by the module control unit (6) is determined on the basis of a specific measurement value. [2] Method according to claim 1, characterized by that the key value (44) defined by the module control unit (6) is changed randomly in time by the module control unit (6). [3] Method according to one of the preceding claims, characterized by that the validation (S6) by the central control unit (2) is carried out in two stages, wherein in a first stage a validation is carried out against a known key value (44) and if the validation in the first stage fails, in a second stage a validation is carried out against a new key value (44). [4] Method according to claim 3, characterized by that if the validation fails in the second stage, the central control unit (2) partially or completely blocks the battery and / or generates an error message. [5] Battery management system (1) of a battery, which comprises at least one battery module (4) with an associated module control unit (6) and a central control unit (2), with a unit (20) for recording measurement data (46) from battery units (8); a unit (24) for determining an additional information carrier (48) which is configured to authenticate the measurement data (46) and which is determined on the basis of the measurement data (46) and a key value (44) defined by the module control unit (6), wherein the key value (44) defined by the module control unit (6) is determined on the basis of a specific measurement value; Units (26, 32) for transmitting the measurement data (46) and the additional information carrier (48) from the module control unit (6) to the central control unit (2); and a unit (30) for validating the measurement data (46) using the additional information carrier (48).
Citation Information
Patent Citations
Method for providing communication between charging station and electric vehicle i.e. car, involves generating signature of data packet by private measuring key, and transmitting data packet and signature to electric vehicle
DE102009030091A1
Battery management system and associated method for determining the state of charge of a battery, battery with battery management system and motor vehicle with battery management system
DE102011079292A1
Checking configuration parameters
DE102011089352A1
Processing of meter data especially relating to utility consumption, involves transmitting meter readings over a public network such as Internet, telephone, GSM or the power network together with an identifying security hash code
DE10204065A1
Method and device for providing reliable information about the lifetime of a battery
US20120316813A1