System for authenticating a user at a charging device and for reporting on its use

A secure, user-friendly charging system for electric vehicles uses public key cryptography and one-way authentication elements to manage charging processes offline, addressing the impracticality and cost of existing infrastructure-dependent solutions, ensuring reliable billing and data integrity.

DE202020006121U1Active Publication Date: 2025-07-10HEYCHARGE GMBH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE202020006121
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2020-10-30
Publication Date
2025-07-10
Estimated Expiration
2030-10-31

AI Technical Summary

Technical Problem

Existing charging systems for electric vehicles require costly and complex infrastructure-side Internet connections, such as 3/4/5G radio modules or DSL lines, for user authentication and billing, which are impractical in areas without mobile network coverage, and suffer from high operational costs and user-unfriendliness.

Method used

A secure authentication and reporting system that uses public key cryptography to enable user authentication and charging process management without infrastructure-side Internet connections, utilizing one-way authentication elements and encrypted charging reports, allowing operation in disconnected environments and reducing hardware and installation complexity.

Benefits of technology

Enables secure, user-friendly, and cost-effective charging operations in areas without mobile network coverage, eliminating the need for costly infrastructure connections and simplifying system setup, while ensuring reliable billing and data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Authentication and reporting system (10) for authenticating a user on a charging device (40) and for reporting on the use thereof, comprising: - at least one database unit comprising: - at least one cryptography module (22) designed to sign and / or encrypt authentication elements (28) and to decrypt load report elements (48), and - at least one transmitting and receiving module (26) designed to transmit encrypted authentication elements (28) and to receive encrypted loading report elements (48); - at least one charging device (40) comprising: - at least one wireless communication module (44), - at least one encryption and decryption unit (46), - at least one memory module (42), and - at least one control module, wherein the at least one charging device (40) is configured to decrypt the authentication elements (28), control a charging process of a connected rechargeable device, provide encrypted charging report elements (48), and store a timestamp parameter of a sent encrypted charging report element (48) or a group of sent encrypted charging report elements (48); and - at least one mobile device (30) designed to transmit the authentication elements (28) from the database unit (20) to the charging device (40) and the charging report elements (28) from the charging device (40) to the database unit (20).
Need to check novelty before this filing date? Find Prior Art

Description

The present invention relates to an authentication and reporting system for authenticating a user on a charging device and reporting the use thereof, and more particularly to a secure end-to-end authentication and reporting system between a database unit and a charging device. Further, the present invention relates to a method for authenticating a user at a charging device and reporting on the use thereof. Furthermore, the present invention relates to the use of an authentication and reporting system and a charging device.In practice, a charging device or device that charges electric vehicles and bills users for the consumed power requires communication between a central system (via which access is managed, bills are consolidated, and payments are made) and the individual charging points or devices.Generally, charging devices used by a particular group of users that pay for the charged stream use a real-time client-server architecture (requiring an IP connection) with a protocol called open charge point protocol (OCPP). Multiple manufacturers of charging devices support their own proprietary control protocols, sometimes in place of or otherwise in addition to OCPP. All of these solutions have in common that they require a central server, which notifies the charging device whether a particular user is allowed to charge (or, when the user starts the charging process via an application that communicates directly with the central server, the server simply notifies the charging device to start the charging process). This means that each installation using this system requires an infrastructure-side Internet connection - either one per charging device (in the case of an embedded 3G / 4G radio module in the charging device) or a connection shared by all charging devices (possible e.g. with a DSL line to the site (DSL= Digital subscriber line)).OCPP and similar proprietary protocols bypass the problem of user access in areas without mobile network coverage by extending the charging device with an RFID reader (RFID= Radio-frequency identification) and giving the user an RFID card. When an RFID card is presented, the charging device can query the OCPP server as to whether the card holder is allowed to start a charging session or a charging process.However, the widely used real-time communication systems that enable this (standards such as OCPP sent over IP networks using physical connections such as 3 / 4 / 5G radio, DSL, etc.) have several major drawbacks:Operating costs: 3 / 4 / 5G-SIMs cost at least several modifier / month, depending on how much data is used. A DSL line to an installation site may cost about 20 / month.Installation Cost / Effort: Multiple visits to a site may be required to determine the most suitable communication channel, to access and contact the installation technician, and to install supporting hardware such as routers and cabinets. Also, the configuration of chargers for connection to a central system using modern standards such as OCPP is complex and requires a skilled technician.User-friendliness: An inherent prerequisite of this architecture is that the user authenticates himself at the charging points with his mobile device or an RFID card. In a low-level garage, the user often has no cellular network coverage, so it is unable to use his mobile application to access his charger. Solutions such as RFID cards, while solving the network coverage problem, have poor consumer acceptance (a card to be cut out for loading is a malicious user experience) and increase the hardware cost of the load points (addition of an RFID reader).It is an object of the present invention to further develop a system and a method of the type mentioned at the beginning, in particular such that the authentication and the reporting are more user-friendly, reliable and secure even without mobile radio network coverage at the location of the charging device.This object with respect to the authentication and reporting system is achieved by the system according to claim 1. Advantageous embodiments of the present invention with respect to the system and method are described in the dependent claims 2 to 10 and also below.According to the present invention, there is provided an authentication and reporting system for authenticating a user at a charging device and reporting the use thereof. The authentication and reporting system comprises:at least one database unit comprising:at least one cryptography module, which is designed to sign authentication elements and / or encrypt them and decrypt charge report elements, andat least one transmitting and receiving module configured to transmit encrypted authentication elements and to receive encrypted charging report elements;at least one charging device comprising:at least one wireless communication module,at least one encryption and decryption unit,at least one memory module, andat least one control module,wherein the at least one charging device is configured to decrypt the authentication elements, control a charging process of a connected chargeable device, provide encrypted charging report elements and store a time stamp parameter of a transmitted encrypted charging report element or a group of transmitted encrypted charging report elements; andat least one mobile device configured to transmit the authentication elements from the database unit to the charging device and the charging report elements from the charging device to the database unit.The invention is based on the basic idea that the charging devices are enabled to authenticate authorized users and to send charging reports back to a central database unit or a backend server without an infrastructure-side Internet connection or mobile network connection. In other words, the system operates partially without any network connection, i.e., the system is also operable in a partially disconnected state due to the fact that encrypted authentication elements for enabling and unlocking the charging station can be sent to an authenticated user and encrypted charging reporting elements can be received to ensure a correct billing operation. The system can also be used in an environment without an Internet connection, such as e.g. in deep garages or in areas with a poor Internet or mobile radio connection. It is configured in such a way that it establishes an independent connection to the charging device and carries out the necessary data transfer for authentication and billing via this independent connection. As soon as the Internet connection is available again (e.g. via WiFi or via the mobile radio network), the mobile device of the system connects again to the server infrastructure of the overall system in order to complete the overall process, in particular the billing process. Furthermore, the asynchronous (non-real-time based) nature of the system allows the user's mobile device to activate the charging device using a one-way authentication element or token stored on the user's mobile device as long as a mobile network connection was available, even if the mobile device is outside cellular network coverage near the charging device, such as in a low-volume garage.Thus, this solution can be used with a mobile application installed on the user's mobile device regardless of whether there is cellular network coverage at the location where the charging device is installed. Accordingly, the system benefits from the fact that no WiFi and / or 3G / 4G / 5G radio hardware, no OCPP client, and no RFID card and reader are needed. In addition, the charging devices can be equipped with smaller processors, as no combination of TCP / IP network stack and OCPP client implementation is needed, which lowers the cost of the device.Furthermore, this solution operates without cost and installation complexity. Moreover, the complexity of the overall system layout is reduced. The need for an Internet connection on the infrastructure side of the charging device is no longer absolutely necessary, since the system also functions without a network connection.What distinguishes the system of the present invention as compared to the above described disadvantages of prior art systems is the manner in which public key cryptography is used to remotely provide and save access to a remote, unconnected resource and guarantee return of charge report data from that charging device or resource by limiting further access until secure charge reports are returned to the database unit.Among other things, the database unit or the backend server authenticates users, communicates with OCPP chargers, generates one-way authentication elements, processes charge report elements and can generate monthly bills and manage the bill of the provided payment types.Preferably, and in one possible embodiment, the database unit has a hierarchical structure with at least two levels, the upper level being based on a high-level real-time database platform such as Firebase (but could also be implemented on any other suitable platform) that handles all direct user communication, authentication methods, persistence or data storage and kernel application logic such as user management, charging determination, billing or billing, etc. The lower level may be based on an OCPP platform handling all communication with OCPP wall boxes, where the lower level forwards high level messages to / from the high level Firebase platform.Signing of the cryptography module is achieved, among other things, by encryption. Signing is done to the effect that the recipient of an element sent by the database unit can validate that the sender of the element had the private key corresponding to a locally stored copy of the sender's public key and that no data was changed during data transfer, the encryption preventing intermediate parties or entities from reading the transferred data.The transmitting and receiving module may be configured to establish a wireless and / or wired network connection for transmitting and receiving elements or messages. It is also conceivable that the transmitting and receiving module comprises a connector module, which enables the transmitting and receiving module to establish a wireless and / or wired network connection. The connector can either be integrated into the transmitting and receiving module or connected thereto by a permanent or temporary wireless and / or wired connection.The system according to the present invention is operable with OCPP-capable charging devices and / or a charging device as described further below. In particular, the system is (also) capable of replacing or displacing OCPP (or equivalent charger protocols associated therewith).For establishing a mobile network connection between the mobile device and the database unit, 3G / 4G / 5G or WiFi wireless network connections or the like may be used.The authentication element or token is, in effect, a one-way "coupon" generated by the database unit for a particular combination of user and charging device to which the user is granted access. Each authentication element can be used by a specific user for a charging process at the provided charging device.The charging report element is generated by the charging device for transmission back to the database unit upon termination of the charging process and contains all information which is required to take into account the charging process carried out to the user, including, among other things, the amount of energy consumed, the length of the charging process, a charging device identification parameter, the real (clock) time at which the charging process was started / stopped, a user identification parameter assigned to the charging process and a sequence parameter of the authentication element used for triggering the charging process.The charging device may be a charging point, a charging socket or other device that can be connected to a rechargeable device and charges it with a resource such as power.The mobile device may be a smartphone, a laptop, a tablet, or the like. The term mobile device applies to any mobile element, i.e. also to a vehicle such as an electric car.The encryption and decryption unit may be a single unit that provides both encryption and decryption, or the unit may comprise an encryption module and a decryption module.A rechargeable device can be connected to the charging device by making a physical plug connection by means of a charging cable. However, other connections are also conceivable, such as magnetic field-induced, wireless charging.The communication between database unit, mobile device with (mobile) application and charging device can be carried out asynchronously and opportunistically in the background. Possibly, the only exception to the adjusted background communication is communication associated with a user-initiated operation using the application running on the mobile device, such as starting a charging operation, which occurs in foreground and synchronously. In effect, this means that all data, i.e. in particular charging report elements, stored on the charging device, which is bound to the database unit, are opportunistically sent to a mobile device when a user comes within range of the charging device. Likewise, all data from a charging device, which are buffer-stored on a mobile device bound to the database unit, are sent to this database unit as soon as a usable mobile network connection (and thus the database unit) becomes available. Moreover, data, i.e. in particular authentication elements on the database unit, that are waiting for a mobile device are sent whenever possible, since they are likely to be needed on the mobile device in a situation where no mobile network connection to the database unit is available.In another possible embodiment, the authentication elements are one-way elements, which can each be used for a charging process.The one-way authentication elements or tokens may be associated with a particular user and / or a particular charging device.According to a core aspect of the present invention, after a first one-way authentication element has been provided to a user, a second or further one-way authentication element is provided only in exchange with a charging report element or a bundle of charging report elements relating to the preceding authentication element or elements.In another possible embodiment, an authentication element comprises:a charging device identification parameter,a sequence parameter,a user identification parameter; anda confirmation time stamp of a load report element.The system may provide one or more authentication elements at system startup. The exact number is a system parameter that determines the overall risk in the case of a malicious user. Typical numbers would be 1, 2 or 3, but also any other number.The authentication element is assigned to a specific charging device by the charging device identification parameter. Likewise, the user identification parameter assigns the authentication element to a specific user, so that, for example, when using the authentication element to initiate a charging process, the user becomes the recipient of the bill.The sequence parameter is checked by the charging device as part of the validation of the authentication element in order to ensure that a new, subsequent authentication element is used for the charging process. For this purpose, it is checked whether the value of the sequence parameter is greater than the value of the last sequence parameter stored in the charging device. The value of the sequence parameters can thus simply be an integer.Authentication elements used with one or more charging devices may be generated.As soon as the loading device registers the confirmation time stamp when validating the authentication element, it discards all previously opened load report elements from the storage module, since the time stamp serves as a confirmation that the previously opened load report elements were securely sent to the database unit for billing.In another possible embodiment, the authentication element additionally comprises configuration data of an associated charging device.Configuration data may be any values that must be set by the charging device with respect to the connected rechargeable device of the user before the charging process begins.In a further possible embodiment, the at least one mobile device synchronizes with the database unit whenever mobile radio network coverage is available.In order to ensure that the user always has a valid authentication element on the mobile device, with which he can optionally carry out a charging process on the charging device, on whose installation side there may be no mobile radio network connection, the mobile device regularly synchronizes with the database unit if there is an adequate mobile radio network connection.It can be provided that the synchronization takes place at regular time intervals when the mobile network connection is sufficient, or at least once, so that the next valid authentication element is transmitted to the mobile device.In a further possible embodiment, the charging device is previously paired with the database unit or combined to form a pair."Pre-paired" means that during the manufacturing process of charging devices, on the one hand, the public key is extracted (or otherwise recorded) from each charging device manufactured and stored or recorded in a database unit according to the present invention. On the other hand, the public key of the database unit is loaded beforehand into the memory module of the respective charging devices, in particular into the nonvolatile region of the memory module.Furthermore, the pairing performed in advance can consist in storing an association between a specific charging device manufactured and a specific user in the database unit before the respective charging device is delivered to the user. This results in a loader already configured to operate from start to end once powered on, thus requiring no trained technician to set up and configure the product. In other words, the charging device provided is a plug-and-play device that only needs to be connected to the power, since there is nothing to configure specifics, such as communication settings or channels, and the encryption keys necessary to establish an end-to-end connection with the charging device have already been extracted at the time of manufacture, thereby avoiding the need for the exchange of keys during an on-site setup process.In yet another embodiment, the cryptography module of the database unit and the encryption and decryption module use public key cryptography.Both the charging device and the database unit are equipped with a public key cryptography module, wherein symmetrical encryption keys are preferably used.In a further possible embodiment, the mobile device comprises an application configured to cooperate with the database unit and the charging device.Different applications are provided, each intended for a different user group:In the case of users of a rechargeable device, such as drivers of an electric vehicle, the mobile application may include:starting a charging process, wherein it is necessary to distinguish whether the charging device has a network connection or not. If the charger is connected to a network, e.g. to the Internet via a 3G / 4G / 5G wireless connection or a LAN connection, the charging process is enabled directly from the database unit via this connection. In the event of insufficient network coverage, a valid authentication element is sent to the charging device to start the charging process. However, it is self-evident that the authentication element can also be used in the case of an existing network connection, that is to say can be used for starting the charging process by transmission. Accordingly, initiation of the load operation by the database entity at an existing network connection is optional (e.g., a one-way element may be available on the mobile device with or without a network connection, and it may be used whether or not there is any type of Internet connection);terminating the charging process, wherein the same conditions apply as for the beginning of the charging process;inputting / updating payment types;looking at the charging process history together with the calculations; andmonitoring the charging process.In the case of the OwnerVerwalter, the application, which may be a mobile or a web application, may comprise:configuring newly installed charging devices;loading new users;removing existing users;adding / removing permissions to use certain charging devices;monitoring the use of property charging devices; anddefining prices (if applicable) for the use of the property's charging devices.Furthermore, a back office administrator application can be provided, which comprises:onboarding, processing and / or maintenance of property and charging devices on the part of this property;loading property administrators for a particular property; andproviding customer service such as billing or handling exceptions in billing.According to a further possible embodiment, the application is further configured to start and stop the charging process, monitor the charging process and display charging report items.It is further possible that the mobile device and / or the application are not trusted."Untrusted" means that the mobile device, and in particular the application running on the mobile device, is considered to be insecure. Accordingly, it cannot be guaranteed that the application is not invoked, abused or re-made by malicious parties.However, by using encrypted authentication elements as well as encrypted charging reporting elements, it is impossible to bypass the end-to-end guarantees provided by the system according to the present invention, even if one has unrestricted access to examine, modify, or enter into the mobile device and / or the mobile application.The object of the present invention can be further achieved by a method for authenticating a user at a charging device and reporting on the use thereof, comprising the steps of:generating at least one first encrypted authentication element in a database unit;transmitting the first encrypted authentication element to a charging device via a first mobile device;decrypting the first encrypted authentication element in the charging device;validating the decrypted authentication element to trigger a first load;generating a first encrypted charging report element in the charging device after the end of the first charging process;storing the first encrypted charging report element in a memory module of the charging device;transmitting the first encrypted charging report item to the database unit via the first mobile device or another mobile device; andproviding a second encrypted authentication element after processing the first encrypted charging report element.The method is designed in particular to operate the system described above. It therefore has the same advantages as the system described above.Generally, since the user and its mobile device are considered to be untrusted, data cannot be assured to be returned for completed loads. A malicious user could modify (or manipulate) the application by deleting it between loads and re-installing it) to prevent load report elements from being returned to the database entity, thus completing billing. The method according to the present invention is therefore based on the idea that only one-way authentication elements are provided as counter power for completed charging report elements. Therefore, the maximum grip per user and charging device is limited by the maximum allowed charging process volume multiplied by the number of allowed outstanding authentication elements (typically one or two). In this way, the further use of the service is impaired by a user until he (or possibly another user of the system) provides the use information for the previous charging process.The individual steps can be divided into the following two groups:secure authentication taking place offline:The database unit generates a one-way authentication element which can be exchanged in each case for a single charging process with a fixed (maximum) length and volume with the provided charging device for which it was generated. The database unit generates a certain number (typically 1 or 2) of these authentication elements for each combination of authorised user and charging device, and the mobile application running on the user's mobile device synchronizes all available authentication elements for the logged-on user whenever it has mobile network coverage. This ensures that fully authorized users have one-way authentication elements for the charging device(s), for the use of which they are authorized, even if they do not have access to the mobile radio network at the location of the charging devices.An authentication element is generated by creating a clear text (insecure) authentication element that includes a user identification parameter, a loader identification parameter, some loader configuration data, a sequence number, and a load report acknowledgement time stamp. This authentication element is then signed (this allows the recipient to verify that the sender had the private key corresponding to the sender's locally stored copy of the public key and that no data has been changed) and encrypted (preventing intermediary parties from reading the data).When the authentication element is presented to the designated charging device, the charging device decrypts the data, checks the signature and easily the sequence number with a local table of users and sequence numbers stored last. If the signature is validated and the sequence number is greater than the last stored sequence number, the load is started (and the stored sequence number for this user is updated to the submitted sequence number).secure billing taking place offline:At the end of a charging process (regardless of whether it was explicitly ended by a user using the mobile application, or implicitly on account of a decoupled rechargeable device or the charging process parameters such as e.g. the maximum time or the maximum volume being exceeded), the charging device prepares a secure, signed charging report element and generates it, which contains all the data which are required for the user to charge. The charging device sends a packet of all unacknowledged charging reporting items to each available system user whose mobile device connects to the charging device for any purpose (end of charging, begin a new charging, etc.). The loader maintains a confirmation time stamp that allows it to discard (and no longer attempt to return) stored load report items already received from the database unit. In other words, to ensure the integrity of the load report items, a load report item is generated and sent to the database unit via the mobile device, the database unit decrypts the load report item and stores the item. After the item has been recorded, the database unit generates an acknowledgement message and / or a time stamp for the charging device to have successfully processed the charging report item. Only after receiving this confirmation is the charging device allowed to discard all stored charging report elements. Any mobile device having access to this charging device will access this message and once it is in the vicinity of the charging device, the mobile device will forward the acknowledgement message to the charging device. The charging device receives the acknowledgement from the database unit, discards the stored charging report items, and generates another message that the acknowledgement was successful. This message serves to notify the database entity and the mobile devices to stop sending the acknowledgement messages (from the previous step) to the charging device because the acknowledgement has already been processed. Additionally or alternatively, if the loader receives the next one-way authentication element with an acknowledgement time stamp, all pending load report elements may be discarded prior to the acknowledgement time stamp.In order to prevent the authentication element from being manipulated by a third party, at least one of the steps of decrypting and validating the transmitted authentication element in the charging device is absolutely necessary.In a further possible embodiment of the method, validating the decrypted authentication element comprises checking whether a sequence parameter of the decrypted authentication element is higher than a sequence parameter last stored in the memory module of the charging device.Additionally or alternatively, the validation of the decrypted authentication element comprises checking whether a charging device identification parameter of the decrypted authentication element matches a charging device identification parameter stored in the memory module of the charging device.This ensures a further security check prior to the release of the charging process, in order to avoid unauthorized access and in order to prevent the user from accidentally connecting his rechargeable device to the wrong charging device.In another possible embodiment, decoding uses a common password derived from an elliptical curve Diffie-Hellman (ECDH) public private key pair. In other words, the decoding uses a common password, which derives from the public ECDH key of the database unit and the private ECDH key of the charging device, which can be stored on a cryptochip, i.e. is not accessible to a mobile application. Furthermore, the shared password can also be stored in a cryptochip hardware slot, which is also used for decrypting elements received from the database unit.The object of the present invention can be further achieved by a charging device comprising:at least one wireless communication module configured to transmit charging reporting elements and receive authentication elements;at least one memory module configured to store a sequence parameter of received authentication elements;at least one control module configured to control a charging process of a rechargeable device connected to the charging device; andat least one encryption and decryption unit configured to decrypt encrypted authentication elements and to encrypt charging report elements.Possibly, the charging device may further comprise a pre-programmed public-private key pair or a self-generated public-private key pair.In a further possible embodiment of the charging device, the wireless communication module uses Bluetooth Low Energy.In order for a connection to a mobile device to be established, the charging device must be equipped with a wireless communication channel. Bluetooth Low Energy (BLE) is preferably used, since it is widely available in each smartphone and can be implemented easily and cost-effectively in a charging device. However, it should be understood that the wireless communication channel is not limited to BLE. Other wireless communication channels may also be provided, such as near field communication (NFC), ultra wide band (UWB), or the like.The invention further relates to a use of an authentication and reporting system as defined above.Further advantages and embodiments of the present invention will be described below in conjunction with the attached drawings. Here, the terms "left", "right", "bottom" and "top" refer to the drawings in an orientation of the drawings that enables the reference numerals to be read normally. The drawings are not necessarily to scale. Rather, the drawings are, where appropriate for explanation purposes, embodied in schematic and / or slightly distorted form. The features of the invention disclosed in the description, in the drawings and in the claims can be essential individually or in any combination for each continuation of the invention. The scope of the invention is not limited to the exact form or details of the preferred embodiments shown and described below, or to an article that would be limited in comparison to the article of the claims. For the sake of simplicity, the same or similar parts or parts having the same or similar functions are denoted below by the same reference numerals.In the drawings, there are shown: FIG. 1 shows an embodiment of the authentication and reporting system according to the invention in conjunction with an embodiment of the method according to the invention; FIG. 2 illustrates an embodiment of the method performed with the system shown in FIG. 1 ; and FIG. 3 illustrates an embodiment of the authentication element used in the system shown in FIG. 1.Figure 1 shows an embodiment of the authentication and reporting system according to the present invention in connection with an embodiment of the method according to the present invention.The system 10 comprises a database unit 20.In the embodiment, database unit 20 in turn includes cryptography module 22, memory module 24, and wireless transceiver module 26.The system 10 further includes a mobile device 30.In the embodiment, mobile device 30 includes a mobile application 32.The system 10 further includes a charging device 40.In the embodiment, the charging device 40 includes a connector 41, a wireless communication module 44, a storage module 42, an encryption and decryption unit 46, and a control module (not shown).The connector 41 is connected to a rechargeable device (not shown), preferably via a wireless data or network connection.Between the database unit 20 and the mobile device 30 there is at least temporarily a network connection 27, preferably wireless, which is established in a known manner. In this embodiment, the database unit 20 and the mobile device 30 are connected to a common network which is used for establishing a data connection, in particular the Internet and / or a mobile network connection. In various embodiments, wireless and wired connections may be provided, with wireless connections being preferred. An authentication element 28 generated and encrypted in the database unit 20 is sent to the mobile device 30 via the network connection.A wireless connection 34, for example via BLE, is established at least temporarily between the mobile device 30 and the charging device 40 in order to transmit or transmit the authentication element 28 from the mobile device 30 to the charging device 40.Furthermore, the wireless connection between the charging device 40 and the mobile device 30 is used to transmit a charging report element 48 which is further transmitted from the mobile device 30 to the database unit 20 via a mobile network connection.Referring to FIG. 2, an embodiment of how to perform the method is described. This is based on the aforementioned embodiment of the system, which is in turn specified in more detail in the following explanations.In the embodiment, a single charging operation of a user's chargeable device is described. However, it is pointed out at the same time to what extent the method also comprises further steps or intermediate steps if a plurality of users wish to charge their respective rechargeable devices with the system according to the present invention.In a step S 1, an authentication element 28 is generated in the database unit 20 upon request from a user. However, it is also conceivable for the database unit 20 already to have stored a corresponding authentication element in the memory module 24, which authentication element has been stored, for example, during the registration of the user.As shown in FIG. 3, an authentication element 28, which is preferably configured as a data structure, may include a user identification parameter 50, a loader identification parameter 52, a sequence number 56, and a load report confirmation time stamp 58. Furthermore, the authentication element 28 can comprise some configuration data 54.Referring again to FIG. 2, in a step S 2, the authentication element 28 is then signed in the cryptography module 22 of the database unit 20, which enables the recipient, i.e. the charging device 40, to validate that the sender, i.e. the database unit 20, had the private key corresponding to the locally stored copy of the public key of the sender and that no data have been changed. Additionally, the authentication element 28 is encrypted in the cryptography module 22, preventing intermediary parties from reading the data or content of the authentication element 28. Both safety measures can also be considered as independent method steps.In a subsequent step S 3, the signed and encrypted authentication element 28 is initially transmitted to the mobile device 30 of the user, on which a mobile application 32 for operating the charging process is preferably operatively installed as soon as a sufficiently good mobile network connection, preferably a wireless network connection 27, is established between the database unit 20 and the mobile device 30. This allows the user to obtain a valid authentication element 28 to start the charging process at a particular charging device 40, and can go to the particular charging device 40, which in the case of a low-level garage is usually installed at a location where no direct network connection can be established between the database unit 20 and the mobile device 30. Therefore, a wireless connection 34, preferably a wireless BLE connection, is established between the mobile device 30 and the charging device 40, and the authentication element 28 is transmitted to the charging device 40 via this wireless connection 34.In a step S 4, the received authentication element 28 is first decrypted by the encryption and decryption unit 46 of the charging device 40. Furthermore, the decrypted authentication element 28 is validated in the encryption and decryption unit 46 by checking whether the charging device identification parameter 50 contained in the authentication element 28 corresponds to the charging device 40 to which the authentication element 28 has been transmitted and to which the chargeable device of the user is connected or is to be connected. In addition, the validation checks whether the sequence parameter 56 likewise contained in the authentication element 28 is greater than or higher than the sequence parameter stored in the memory module 42 of the charging device 40. This ensures, inter alia, that the authentication element 28 of the last charging process is not used again for starting the charging process, but that a subsequent authentication element 28 has been generated by the database unit 20.If the authentication element 28 has successfully passed through the checks in step S 4, the charging process can be started in step S 5. This process may begin, for example, as soon as the user connects his rechargeable device to the charging device 40. In the case of an electric vehicle, this would mean that the user inserts the charging cable into the charging device 40. However, it is also possible for the charging process to be started via the mobile application 32 on the mobile device 30 by user input. The charging process ends when, for example, the user initiates the termination of the charging process by input into the mobile application 32 or disconnects the connection between the rechargeable device and the charging device 40, or when the maximum charging time or the maximum charging volume is reached.After the charging process has ended, in a step S 6, a charging report element 48 is generated in the charging device 40, which contains all the required data in order to take into account the charging process for the user.In a following step S 7, the load report element 48 is then encrypted in the encryption and decryption unit 46, so that this element 48 is also protected against manipulations or the like during transmission to the database unit 20.In a step S 8, the encrypted charge report element 48 is transmitted to the mobile device 30 via the wireless connection 34. Preferably, not only the last charge report element 48, but all reports stored in the storage module of the charging device 40 and not yet transmitted, are transmitted to the mobile device 30. It is not important that the charging reporting element 48 is sent exactly to the mobile device 30 that sent the corresponding authentication element 28 to the charging device 40 in order to trigger the charging process. Rather, the charging report element 48 or the report bundle is sent to the mobile device 30, which then establishes a wireless connection 34 to the charging device 40 after the charging process has been completed or ended. The terminal then sends the charging report element 48 or the report bundle via the wireless network connection 27 to the database unit 20 as soon as this connection 27 is established, i.e. as soon as sufficient mobile radio network coverage is present.In a step S 9, the encrypted load report element 48 received from the database unit 20 or the bundle of encrypted reports is then decrypted in the cryptography module 22 of the database unit 20.Finally, in a step S 10, which can also be divided into two separate substeps, the decrypted charging report element 48 or the bundle of reports is processed, so that, on the one hand, the bill(s) can / can be issued to the user / s and, on the other hand, the next authentication element(s) 28 can / can be generated for one or more further charging processes. Moreover, after the charging report element 48 has been acquired or stored, the database unit 20 generates an acknowledgment message and / or a time stamp for the charging device 40 that it has successfully processed the charging report element 48. Only after receiving this confirmation message and / or the time stamp is the charging device 40 allowed to discard all charging report elements 48 stored in the storage module 42. Each mobile device 30 having access to this charging device 40 accesses this message, and once it is in proximity to the charging device 40, the mobile device will transmit the acknowledgement message to the charging device. The charging device 40 thus receives the confirmation from the database unit 20, discards the stored charging report element(s) 48(s) and generates a further message that the confirmation was successful. This message serves to inform the database unit 20 and the mobile device(s) 30 that they are to stop sending the confirmation messages to the charging device 40, since the confirmation has already been processed.Moreover, the present invention comprises the following aspects: 1. method for authenticating a user at a charging device (40) and reporting on the use thereof, comprising the following steps:generating at least one first encrypted authentication element (28) in a database unit (20);transmitting the first encrypted authentication element (28) to a charging device (40) via a first mobile device (30);decrypting the first encrypted authentication element (28) in the charging device (40);validating the decrypted authentication element (28) to trigger a first load;generating a first encrypted charging report element (48) in the charging device (40) after the end of the first charging process;storing the first encrypted charging report element (48) in a memory module (44) of the charging device (40);transmitting the first encrypted charging report element (48) to the database unit (20) via the first mobile device (30) or another mobile device; andproviding a second encrypted authentication element after processing the first encrypted charging report element (48).2. The method for authenticating a user at a charging device and reporting on the use thereof according to Aspect 1, wherein validating the decrypted authentication element (28) comprises verifying whether a sequence parameter (56) of the decrypted authentication element (28) is higher than the last sequence parameter stored in the storage module (44) of the charging device (40). 3.The method for authenticating a user at a charging device and reporting on the use thereof according to Aspect 1 or 2, wherein validating the decrypted authentication element (28) comprises checking whether a charging device identification parameter (50) of the decrypted authentication element (28) matches a charging device identification parameter (50) stored in the storage module (44) of the charging device (40). 4. a method of authenticating a user at a charging device (40) and reporting the use thereof according to any of aspects 1 to 3, wherein decrypting uses a common password derived from an elliptical curve Diffie-Hellman public private key pair.Reference Number:10 System 20 database unit 22 cryptography module 24 storage module 26 wireless transmission and reception module 27 wireless network connection 28 authentication element 30 mobile device 32 mobile application 34 wireless connection 40 charging device 41 connector 42 storage module 44 wireless communication module 46 encryption and decryption unit 48 charging report element 50 charging device identification parameter 52 user identification parameter 54 configuration data 56 sequence parameters 58 confirmation time stamps of a charging report element S 1 requesting and generating an authentication element at a database unit S 2 encrypting the authentication element in the database unit S 3 wirelessly transmitting the authentication element to the charging device by means of a mobile device S 4 decrypting and validating the authentication element in the charging device S 5 beginning and ending a charging process S 6 generating a charging process S 6 Charging report element S 7 encrypting the charging report element S 8 wirelessly transmitting the authentication element to the database unit by means of the mobile device S 9, decrypting the charging report element S 10 billing and generating a subsequent authentication element

Claims

Authentication and reporting system (10) for authenticating a user at a charging device (40) and reporting on the use thereof, comprising: - at least one database unit comprising: - at least one cryptography module (22) configured to sign and / or encrypt authentication elements (28) and decrypt charging reporting elements (48), and - at least one transmission and reception module (26) configured to transmit encrypted authentication elements (28) and to receive encrypted charging reporting elements (48); at least one charging device (40), comprising: at least one wireless communication module (44), at least one encryption and decryption unit (46), at least one storage module (42), and at least one control module, wherein the at least one charging device (40) is configured to decrypt the authentication elements (28), to control a charging process of a connected chargeable device, to provide encrypted charging report elements (48) and to store a time stamp parameter of a transmitted encrypted charging report element (48) or a group of transmitted encrypted charging report elements (48); and at least one mobile device (30) configured to transmit the authentication elements (28) from the database unit (20) to the charging device (40) and the charging report elements (28) from the charging device (40) to the database unit (20).The authentication and reporting system (10) of claim 1, wherein the authentication elements (28) are one-way elements each usable for a charging operation.Authentication and reporting system (10) according to claim 1 or 2, wherein an authentication element (28) comprises - a loader identification parameter (50), - a user identification parameter (52), - a sequence parameter (56), and - a charging report element (58) confirmation time stamp.The authentication and reporting system (10) of claim 3, wherein the authentication element (28) further includes configuration data (54) of an associated charging device (40).The authentication and reporting system (10) of any preceding claim, wherein the at least one mobile device (30) synchronizes with the database entity (20) whenever cellular network coverage is available.The authentication and reporting system (10) of any preceding claim, wherein the charging device (40) is pre-paired with the database unit (20).Authentication and reporting system (10) according to any of the preceding claims, wherein the cryptography module (22) of the database unit (20) and the encryption and decryption unit (46) use public key cryptography.The authentication and reporting system (10) of any preceding claim, wherein the mobile device (30) comprises an application (32) configured to cooperate with the database entity (20) and the charging device (40).The authentication and reporting system (10) of claim 8, wherein the application (32) is further configured to begin and end the charging operation, monitor the charging operation, and display the charging reporting element (48).The authentication and reporting system (10) of claim 9, wherein the mobile device (30) and / or the application (32) are untrusted.Charging device (40) comprising: - at least one wireless communication module (44) configured to transmit charging reporting elements (48) and receive authentication elements (28); - at least one storage module (42) configured to store a sequence parameter of received authentication elements (28); - at least one control module configured to control a charging process of a chargeable device connected to the charging device (40); and - at least one encryption and decryption unit (46) configured to decrypt encrypted authentication elements (28) and encrypt charging reporting elements (48).The charging device (40) of claim 11, wherein the charging device (40) further comprises a preprogrammed public-private key pair or a self-generated public-private key pair.The charging device (40) of claim 11 or 12, wherein the wireless communication module (44) uses Bluetooth Low Energy.