Method for resetting a battery system with at least one battery
A method for resetting battery systems by decommissioning initial applications and deactivating security modules with crypto-authentication allows secure reprogramming, addressing the EU Battery Directive's requirements and enabling battery reuse.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- ROBERT BOSCH GMBH
- Filing Date
- 2024-11-27
- Publication Date
- 2026-05-28
AI Technical Summary
Existing battery systems face challenges in being reused for different applications due to stringent cybersecurity requirements that prevent deletion of original software and installation of new software, as mandated by the EU Battery Directive, necessitating a secure reset function.
A method involving decommissioning software that deletes initial applications, deactivates hardware security modules, and installs new software with a generic programming interface, using crypto-based authentication and vehicle manufacturer-specific signatures to enable secure reprogramming.
Enables the secure reset of battery systems to allow reuse for new applications by disabling security features and allowing third-party reprogramming, compliant with EU regulations and ensuring data deletion and security.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical field
[0001] The invention relates to a method for resetting a battery system comprising at least one battery and a hardware security module from a primary application to a secondary application. Furthermore, the invention relates to the use of the method for resetting a battery system from a primary application to a secondary application. State of the art
[0002] US 2020 / 0264864 A1 relates to an upgrade procedure for a vehicle-integrated device and the device itself. The procedure can be applied to a vehicle-based system, a vehicle-based control device, and one or more vehicle-based devices to be upgraded. The procedure includes, among other things, receiving a vehicle-based upgrade package via the vehicle-based control system, wherein the vehicle-based upgrade package comprises a number of upgrade documents, and each upgrade document is used to upgrade at least one vehicle-based device to be upgraded. The vehicle-based control device performs a security check on the multiple upgrade documents. The vehicle-based control device then sends a target upgrade document to a vehicle-based device to be upgraded.
[0003] CN 111385191 A refers to a vehicle-based connectivity portal, a vehicle upgrade system (OTA, Over the Air) and a vehicle upgrade procedure (OTA), furthermore a storage medium and a vehicle which is capable of performing a one-stop refresh by using the vehicle-based connectivity portal.
[0004] Automotive electronic control units (ECUs) must meet very high cybersecurity requirements today. Current specifications can be found, for example, in UNECE R155 and ISO 21434. Various software security features, as well as hardware components such as hardware security modules, are used for technical implementation. This also applies to battery control units and battery management systems.
[0005] The new battery regulation requires a reset function for the battery management system to allow batteries to be used in a different application after their initial use, thus enabling the multiple use of a single battery. This reuse requires deleting the original software and data of the battery management system and allowing any third party to program new software for the new application. This process is also known as "flashing."
[0006] The requirements of the EU Battery Directive regarding the reset function are ambitious due to the aforementioned security mechanisms in the battery packs. The hardware security module prevents the deletion of existing serial software as well as the "flashing" of new software by a third party, which might be necessary for a new application. State-of-the-art security mechanisms are used for this purpose. In particular, crypto-based authentication, which can be performed online or offline, is required before "flashing," as is crypto-based signature verification to validate the new software. To program new software in the field, a vehicle manufacturer-specific signature of the software and prior authentication are mandatory.
[0007] A solution must be found to bring secured batteries or battery packs, which are installed at the vehicle manufacturer or in the vehicle at the time of desired reuse, into a suitable state in order to meet the requirement of a reset function.
[0008] The following describes a procedure to achieve a reset function based on commonly used safety mechanisms present on the battery packs.
[0009] WO 2022 / 002167 A1 relates to a method and a device for replacing a vehicle battery and to a battery detection device. Disclosure of the invention
[0010] According to the invention, a method for resetting a battery system is proposed, comprising at least one battery and at least one hardware security module for a secondary application, with the following method steps: a) Creation of decommissioning software which deletes an initial application of the battery system, initiates a software diagnostic procedure and includes a generic programming interface which represents a software interface to upload the secondary application to the battery system, b) Creation of a series software or an update of a series software which latently contains the decommissioning software created according to procedure step a), which can be activated by means of an authenticable trigger. c) Installation of the standard software or an update of the standard software as part of a regular vehicle manufacturer's software update to the battery system and d) Activation of the battery system reset for secondary use by the vehicle manufacturer after authentication using a crypto-based key or a crypto-based procedure.
[0011] The method proposed according to the invention is further characterized in that the deactivation software according to method step a) contains a hardware security module deactivation software which deactivates security features of the hardware security module and puts it into an idle mode as long as the secondary application is being installed on the battery system.
[0012] Furthermore, in the method proposed according to the invention, it is advantageously provided that the decommissioning software according to process step a) includes host decommissioning software, basic software for controlling hardware components and user software for performing calculations and diagnoses, which are suitable for deleting the first application of the battery system, including the generic interface, in order to install the second application on the battery system.
[0013] Advantageously, in the method proposed according to the invention, it is further provided that the authenticatable trigger activating the latent shutdown software is represented by a diagnostic command within the framework of a diagnostic service.
[0014] Furthermore, the method proposed according to the invention provides that, after activation of the decommissioning software, the installation of the service software onto the decommissioning software is initiated and controlled by means of a decommissioning software activator.
[0015] Furthermore, the method proposed according to the invention is characterized in that the series software created according to process step b) or the update of the series software, which latently contains the deactivation software, is transmitted to the vehicle manufacturer.
[0016] Furthermore, the method proposed according to the invention provides that the series software to be installed or the update of the series software to be installed, each of which latently contains the deactivation software, is signed by the vehicle manufacturer using a specific private key.
[0017] Furthermore, in the method proposed according to the invention, it is advantageously provided that the series software signed by the vehicle manufacturer or the update of the series software signed by the vehicle manufacturer, which latently contains the deactivation software, is installed on the battery system inside or outside the vehicle.
[0018] Furthermore, in the method proposed according to the invention, it is advantageously provided that the signed serial software or the signed update of the serial software, each latently containing the deactivation software, is checked against a certificate of the battery system to be reset.
[0019] Furthermore, the invention relates to the use of the method for resetting a battery system from a first application to a second application different from the first application. Advantages of the invention
[0020] The solution proposed according to the invention allows software applied to a battery system with at least one battery, including its security features, to be deleted, thus creating the possibility of installing battery system software for a new application, i.e., for a second application on the same battery system, as required by the EU Battery Regulation. The method proposed according to the invention specifically disables the security features of the battery systems that prevent both the deletion of the initial application and reprogramming, thereby making the battery system accessible for a new application, for example, one originating from a third party.
[0021] By fulfilling the reset function required by the EU Battery Regulation, it becomes possible to reuse a battery or battery system for a new application that may differ from the initial application. According to the method proposed in the invention, the initial application is erased, and a possibility is created to reprogram the battery system, in particular the battery management system, for a new application, namely a secondary application.
[0022] The latent reset functionality within the standard software, or its activation via a private key from the vehicle manufacturer, allows the battery to be reset without the battery manufacturer's intervention. Furthermore, it is advantageous to emphasize that this concept offers a secure way to comply with the EU Battery Directive and to reset batteries with a hardware safety module. This is ensured by the necessary authentication using a vehicle manufacturer's tool with appropriate crypto-based procedures.
[0023] This also allows compliance with various safety regulations. A further advantage is that existing tools and methods are used to perform the reset. The reset software is integrated into the battery system in the same way as a factory software update during initial use. This makes the reset process relatively simple, as the necessary tools, processes, and trained personnel are already available at the vehicle manufacturer.
[0024] Another advantage is that the remaining control unit, battery, or battery system is preserved with only a generic bootloader, free from manufacturer-specific limitations and with defined starting behavior. This allows for handover to independent third-party recyclers with minimal software documentation. Brief description of the drawings
[0025] Embodiments of the invention are explained in more detail with reference to the drawings and the following description.
[0026] They show: Fig. 1 a schematic representation of the method proposed according to the invention and Fig. 2 a block diagram to illustrate the steps to be taken during the method proposed according to the invention. Embodiments of the invention
[0027] In the following description of embodiments of the invention, identical or similar elements are designated by the same reference numerals, and repeated descriptions of these elements are omitted in individual cases. The figures represent the subject matter of the invention only schematically.
[0028] Fig. Figure 1 shows a schematic representation of the method proposed according to the invention.
[0029] According to the representation in Fig. 1 comprises a series software 10 or an update of a series software 10, comprising several parts. The series software 10 or an update of the series software 10 includes, in addition to a deactivation software 18, another deactivation software, namely a hardware security module deactivation software 24, and furthermore a host deactivation software 26. An activator 34 is provided within the deactivation software 18, since the deactivation software 18 is latently contained in the series software 10 or in an update of the series software 10.
[0030] According to the solution proposed by the invention, the serial software 10 serves to reset at least one battery 14 of a battery system 12 or the battery system 12 itself. This means that the battery system 12 can be reset from an original initial application to a further, namely a secondary application 38, by means of the serial software 10 or an update of the serial software 10, so that a reset function in accordance with the EU Battery Regulation can be implemented. By fulfilling the reset function requirement of the EU Battery Regulation, it becomes possible to configure the battery system 12 for a new application. For this purpose, it is necessary to delete the software provided for the original initial application in the battery system 12 and to create a means of reprogramming the battery system 12 for the secondary application 38.
[0031] The deactivation software 18, which is latently contained in the standard software 10 or an update of the standard software 10, deletes the content of the entire current software for the original initial application on the battery system 12, as well as all data, in particular sensitive and / or protected data of a vehicle manufacturer 30 and / or an end user. Furthermore, the deactivation software 18, which is latently embedded in the standard software 10 or an update of the standard software 10, enables a third party to install its own software, i.e., the secondary application 38, on the battery system 12 and thereby overwrite the previously activated deactivation software 18, which is required for the reset process.
[0032] This is achieved by first installing the new series software 10, or an update of the series software 10, onto the battery system 12, for example, via a regular software update from the vehicle manufacturer 30. This software latently contains the deactivation software 18 and is otherwise identical to the current series software. The functionality of the deactivation software 18 is thus part of the series software 10 or an update of the series software 10 and is present on the battery system 12 after installation, but is not active. Activation can be performed by an authenticated trigger, such as an activator 34, which activates the reset functionality as part of a diagnostic command from a diagnostic service when resetting the battery system 12 is desired.
[0033] The series software 10 or an update of the series software 10 including the latent decommissioning software 18 present therein may include a generic programming interface 20 (bootloader) that acts as a software interface 22 for the third party that wishes to install the secondary application 38 on the battery system 12 to be reset.
[0034] For the sake of completeness, it should be mentioned that each of the reset battery systems 12 includes at least one battery 14 and a hardware security module 16. This module implements security mechanisms. To bypass the hardware security module 16, whose security mechanisms cannot be deactivated, the standard software 10, or an update to the standard software 10, includes the hardware security module disabling software 24. This software disables the security features of the hardware security module 16 by means of a software update to the hardware security module 16 and then puts it into an idle loop.This engages the hardware security module 16 with a software update relating to the hardware security module deactivation software 24 (confirmed?), such that the hardware security module 16 allows the third party to install the secondary application 38 and the access protection is lifted, as long as the third party installs the secondary application 38 on the battery system 12 or its battery management system or a suitable control system.
[0035] Furthermore, the series software 10, or the update to the series software 10, includes a component referred to as host deactivation software 26. The host software typically contains basic software as well as other application software and additional software components. These are overwritten by the host deactivation software 26, which provides the generic programming interface 20 (bootloader) and deletes all other files on the host. The purpose of the host deactivation software 26, as part of the deactivation software 18, is to delete all software components of the battery system 12 relating to its initial application and to provide the generic programming interface 20 in the form of the bootloader in order to enable the reprogramming of the secondary application 38 by the third party.
[0036] Following the solution proposed according to the invention, the new series software 10 or the update of the series software 10 is installed on series battery systems 12, which are protected by authentication and, for example, a crypto-based signature check. The decommissioning software 18 is delivered as part of a software package of the series software 10, as shown in Fig. 1 indicated. Authentication is required at vehicle manufacturer 30, as is a signature by vehicle manufacturer 30 with a vehicle manufacturer key 32, which is also in Fig. As indicated in point 1. To install the standard software version 10 or to update the standard software version 10, the regular customer update or a regular customer update routine is used, which fulfills the security features, i.e., takes authentication or signature verification into account.
[0037] The authenticated activation of the deactivation software 18, which is embedded in the standard software 10 or the update of the standard software 10, occurs as soon as the battery system 12 is to be reset. Within the standard software 10, the latent deactivation software 18 must be activated. However, this may only be carried out by an authenticated party. For example, authentication can be performed using crypto-based authentication with a corresponding key 36. This activation can be implemented, for example, as part of a diagnostic service, as described in Fig. 2 (see reference 56) will be indicated.
[0038] To enable a third party to install or update the series software 10 after a reset, the deactivation software 18 must include a generic programming interface 20 in the form of a bootloader. This interface enables the software interface 22 for programming the secondary application 38 onto the battery system 12, the battery management system, or the control unit. Simultaneously, the security features provided by the hardware security module 16, such as authentication, signature verification, and protection of the installation areas, must be deactivated so that the third party can actually install its secondary application 38 onto the battery system 12 via the generic programming interface 20.
[0039] The hardware security module deactivation software 24 and the host deactivation software 26 constitute the aforementioned deactivation software 18, which is latently embedded in the serial software 10 or the update of the serial software 10. The deactivation software 18 is activated by an authenticated activator 34. To qualify for the activation of the activator 34, a key could be used, for example, a crypto-based deactivation key 36, as described in Fig. 1 indicated. To initialize and control the installation steps for installing the series software 10 or updating the series software 10 after activating the deactivation software 18, the activator 34 is required.
[0040] Since the reset function, in the form of the deactivation software 18, is a latent part of the series software 10, it is installed on the battery system 12 together with, for example, the next series software release. If the battery system 12 is to be reset, the deactivation software 18 can be activated after authentication, for example using the crypto-based key 36, as part of a diagnostic service (see item 56 in Fig. 2).
[0041] After activation, the Hardware Security Module (HSM) Deactivation Software 24 is overwritten by the activator 34 to perform the installation of the Deactivation Software 18. First, the Hardware Security Module Deactivation Software 24 is installed, followed by the Host Deactivation Software 26. In addition to overwriting the memory areas with the new program code, the process also ensures that memory areas containing sensitive data are deleted. Finally, a deactivation marker is set in the software to indicate that the battery system 12 has been reset.
[0042] To install the series software 10 or to update the series software 10 to the battery system 12, the existing update customer routine of the vehicle manufacturer 30 is used, which is also used for regular software updates in the field.
[0043] The vehicle manufacturer signs the software 10 with its vehicle manufacturer key 32, also known as the private key. Crypto-based methods, which vary depending on the vehicle manufacturer 30, can be used for this purpose. To install the standard software 10 or an update to the standard software 10, which latently contains the deactivation software 18, the battery system 12 is connected to an installation tool provided by the vehicle manufacturer 30. This installation can be performed with the battery system 12 installed in the vehicle or removed from it.
[0044] To initiate reprogramming, a vehicle manufacturer-specific authentication process is first required. Both online and offline solutions can be used. After successful authentication, the installation process is started, and a manufacturer-required signature of the deactivation software 18 is verified against a certificate located on the battery system 12. If this verification is successful, the new standard software 10 or the update to the standard software 10 can be installed.As soon as the battery system 12 is to be reset for the secondary application 38, the vehicle manufacturer 30, after authentication, for example using the crypto-based deactivation key 36, activates the reset process and the deactivation software 18, along with its components described above, is installed on the battery system 12 or its battery management system or on a control unit. After successful installation of the deactivation software 18, all data of the primary application of the battery system is deleted, the security features are deactivated, and the third party can install its software required for the secondary application 38 on the battery system 12 or its battery management system via the generic interface 20 (bootloader), so that the battery system 12 can be considered reset.
[0045] According to the representation Fig.As can be seen from section 2, the decommissioning software 18 is first generated as part of a creation step 40. This includes, as mentioned above, the host decommissioning software 26 and the hardware security module decommissioning software 24.
[0046] The deactivation software 18 is then integrated into the series software 10 or the update of the series software 10 according to an integration step 42. Subsequently, the series software 10 or an update of the series software 10, which latently contains the deactivation software 18, is formatted 44 into a suitable format, which is then implemented as part of a regular update routine of the vehicle manufacturer 30.
[0047] The aforementioned series software 10, or the update to series software 10, is transmitted to the vehicle manufacturer 30 as part of a transfer step 46, during which a signature 48 is applied. The signature 48 of the series software 10, or the update to series software 10, which latently contains the deactivation software 18 with its components, is applied by a vehicle manufacturer-specific key 32.
[0048] Subsequently, step 50 involves the installation of the manufacturer-signed series software 10 or its update, which latently contains the deactivation software 18, using an installation tool. The battery system 12 can be located inside or outside the vehicle during this process.
[0049] This is followed by a vehicle manufacturer-specific authentication 52, which can be performed online, offline, or using crypto-based methods. A signature check 54 of the series software 10 or the update of the series software 10, which includes the deactivation software 18 with its components hardware security module deactivation software 24 and host deactivation software 26, is performed as part of a verification of a certificate affixed to the battery system 12 to be reset.
[0050] The deactivation software 18 is initiated as soon as the battery system 12 is to be reset, which is carried out as part of a diagnostic service. Here, activation or programming of the deactivation software 18 is initiated after successful authentication, for example using the previously mentioned crypto-based deactivation key 36.
[0051] Following the activation of the deactivation software 18 after its successful authentication in the preceding step 58, the reset operation 60 takes place after the deactivation software 18 has been completely installed. This means that the data of the original initial application on the battery system 12 is now deleted, the hardware security module 16 is temporarily put into an idle state, and a generic programming interface 20 (bootloader) is available for the third party to install the secondary application 38.
[0052] Finally, the second application 38 is uploaded by the third party to the battery system 12 or the battery management system of the battery system 12 or to a control unit via the generic programming interface 20.
[0053] The invention is not limited to the embodiments described here and the aspects highlighted therein. Rather, within the scope specified by the claims, a multitude of modifications are possible that fall within the bounds of what is considered skilled in the art. QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] US 2020 / 0264864 A1
[0002] CN 111385191 A
[0003] WO 2022 / 002167 A1
[0009]
Claims
[1] Method for resetting a battery system (12) comprising at least one battery (14) and at least one hardware security module (16) for a secondary application (38) comprising the following method steps: e) Creation of decommissioning software (18) which deletes an initial application of the battery system (12), initiates a software diagnostic procedure and includes a generic programming interface (20) which represents a software interface (22) for installing the secondary application (38) on the battery system (12), f) Creation of a series software (10) or an update of a series software (10) which latently contains the decommissioning software (18) created according to procedure step a) which can be activated by means of an authenticatable activator (34). g) Installation of the standard software (10) or an update of the standard software (10) as part of a regular vehicle manufacturer's software update to the battery system (12) and h) Activation of the battery system reset (12) for secondary use (38) by the vehicle manufacturer (30) after authentication using a crypto-based key (36) or a crypto-based procedure. [2] Method according to claim 1, characterized by , that the deactivation software (18) according to procedure step a) contains a hardware security module deactivation software (24) which deactivates security features of the hardware security module (16) and puts it into an idle mode while the secondary application (38) is being installed on the battery system (12). [3] Method according to claims 1 and 2, characterized by, that the decommissioning software (18) according to procedure step a) includes host decommissioning software (26), basic software for controlling hardware components, application software for performing calculations, diagnostics, and is suitable for deleting the first application of the battery system (12), and includes the generic interface (20) for installing the second application (38) on the battery system (12). [4] Method according to claims 1 to 3, characterized by , that the authenticatable activator (34) activating the latent shutdown software (18) is represented by a diagnostic command as part of a diagnostic service. [5] Method according to claims 1 to 4, characterized by , that after activation of the decommissioning software (18) the installation of the serial software (10) onto the decommissioning software (18) is initiated and controlled by means of a decommissioning software activator (34). [6] Method according to claims 1 to 5, characterized by , that the series software (10) created according to procedure step b), which latently contains the deactivation software (18), is transmitted to the vehicle manufacturer (30). [7] Method according to claims 1 to 6, characterized by , that the series software (10) to be installed or the update of the series software (10), each containing a deactivation software (18), is signed at the vehicle manufacturer (30) by means of a specific key (32). [8] Method according to claims 1 to 7, characterized by , that the manufacturer-signed series software (10) or the update of the series software (10) latently containing the deactivation software (18) is installed on the battery system (12) inside or outside the vehicle. [9] Method according to claim 8, characterized by, that the signed serial software (10) or the signed update of the serial software (10), each latently containing the deactivation software (18), are checked against a certificate of the battery system (12) to be reset. [10] Use of the method according to any one of claims 1 to 9, for resetting a battery system (12) with a first application to a second application (38) different from the first application.
Citation Information
Patent Citations
Vehicle-mounted internet gateway, vehicle OTA upgrading system and method and computer storage medium
CN111385191A
Vehicle-mounted device upgrade method and related device
US20200264864A1
Method and apparatus for assisting in replacement of automobile battery, and battery detection device
WO2022002167A1
Battery management software reset
EP4485240A1
Interface for a hardware security module
US20210224377A1