Battery pack and firmware update method
The firmware update method for battery packs, involving encrypted data verification and authentication, addresses the vulnerability of BMS to malicious attacks, ensuring secure and stable battery operations.
Patent Information
- Application Number
- JP2025508494
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-08-24
- Filing Date
- 2023-08-28
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2043-08-28
AI Technical Summary
Existing battery management systems (BMS) are vulnerable to malicious attacks that can lead to abnormal operations, potentially causing serious accidents such as fires or explosions.
A method for updating firmware of a battery pack involves transmitting and decrypting encrypted battery data, comparing it with stored data, and only proceeding with the update if they match, ensuring the update is legitimate, and using a shared secret key to authenticate the server and update device.
Prevents unauthorized updates by malicious attackers, ensuring stable operation of the battery pack and preventing potential accidents.
Smart Images

Figure 0007810338000001 
Figure 0007810338000002 
Figure 0007810338000003
Abstract
Description
[Technical Field]
[0001] The present invention claims the benefit of priority based on Korean Patent Application No. 10-2022-0108710 filed on August 29, 2022 and Korean Patent Application No. 10-2023-0111386 filed on August 24, 2023, and all contents disclosed in the documents of said Korean patent applications are incorporated herein by reference.
[0002] The embodiments disclosed herein relate to a battery pack including a battery for storing power and a method for updating firmware thereof. [Background technology]
[0003] In recent years, research and development into secondary batteries has been actively conducted. Secondary batteries are batteries that can be charged and discharged, and include conventional Ni / Cd batteries, Ni / MH batteries, and more recent lithium-ion batteries. Lithium-ion batteries have the advantage of having a much higher energy density than conventional Ni / Cd batteries, Ni / MH batteries, etc. Furthermore, because lithium-ion batteries can be manufactured to be small and lightweight, they are used as power sources for mobile devices. In recent years, their range of use has expanded to include power sources for electric vehicles, and they are attracting attention as a next-generation energy storage medium.
[0004] Devices that use batteries as power sources can be equipped with a battery management system (BMS) that controls the operation of the battery along with the battery that stores the power. A BMS can be realized as a combination of software and hardware, and the hardware can be operated by software that drives and controls the hardware. In particular, since such software can directly control the operation of the BMS, if it is arbitrarily modified by a malicious attacker, there is a problem that abnormal operation of the BMS can lead to serious accidents such as fires or explosions. Summary of the Invention [Problem to be solved by the invention]
[0005] An object of the embodiments disclosed in this document is to provide a battery pack and a method for updating its firmware that can prevent malfunctions due to malicious attacks.
[0006] The technical problems of the embodiments disclosed in this document are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art from the following description. [Means for solving the problem]
[0007] A method for updating firmware of a battery pack according to one embodiment of the present invention may include the steps of transmitting battery data indicating a state of battery cells included in the battery pack to a server; receiving a request from the server to enter an update mode for updating the firmware; receiving encrypted battery data from the server, which is data obtained by encrypting the battery data; decrypting the encrypted battery data; comparing the decrypted battery data with battery data stored in the battery pack; and, if the decrypted battery data and the battery data stored in the battery pack match each other, updating the firmware stored in the battery pack using the firmware received from the server.
[0008] A method for updating firmware of a battery pack by a server according to one embodiment of the present invention may include the steps of receiving, from the battery pack, battery data indicating the status of battery cells included in the battery pack; if a firmware update of the battery pack is necessary, sending to the battery pack a request to enter an update mode for updating the firmware; encrypting the battery data and sending the encrypted battery data to the battery pack; and sending firmware corresponding to the battery pack to the battery pack to update the firmware stored in the battery pack.
[0009] A battery pack according to one embodiment of the present invention includes at least one battery module and a pack BMS (battery management system) that controls the at least one battery module. The pack BMS may include a communication unit that transmits battery data indicating a state of a battery cell included in the at least one battery module to a server and receives from the server a request to enter an update mode for updating firmware and encrypted battery data, which is data obtained by encrypting the battery data. The battery pack may also include a controller that compares decrypted battery data generated by decrypting the encrypted battery data with battery data stored in the pack BMS, and updates the firmware stored in the pack BMS using the firmware received from the server if the decrypted battery data matches the battery data stored in the pack BMS. [Effects of the Invention]
[0010] According to an embodiment of the battery pack and the method for updating its firmware disclosed in this document, it is possible to prevent unauthorized updates by malicious attackers and ensure stable operation of the battery pack. In addition, this document can provide various other benefits that can be perceived directly or indirectly. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a block diagram illustrating a battery pack and a server according to one embodiment disclosed herein. [Figure 2] FIG. 2 is a block diagram showing the pack BMS shown in FIG. 1 in more detail. [Figure 3] 1 is a flowchart illustrating a procedure for updating a BMS image according to an embodiment of the present invention. [Figure 4] FIG. 4 is a diagram illustrating information used in the update procedure of the BMS image of FIG. 3. [Figure 5] 10 is a flowchart illustrating a procedure for updating a BMS image according to another embodiment of the present invention. [Figure 6] FIG. 6 is a diagram illustrating information used in the update procedure of the BMS image of FIG. 5. [Figure 7] FIG. 1 is a block diagram illustrating a hardware configuration of a computing system for performing an embodiment of a method for operating a battery management system disclosed herein. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, the embodiments disclosed herein will be described in detail with reference to exemplary drawings. When assigning reference numerals to components in each drawing, it should be noted that the same reference numerals are assigned to the same components when they appear in other drawings as much as possible. Furthermore, when describing the embodiments disclosed herein, if a detailed description of related known structures or functions is deemed to hinder understanding of the embodiments disclosed herein, such detailed description will be omitted.
[0013] In describing components of the embodiments disclosed herein, terms such as first, second, A, B, (a), (b), etc. may be used. Such terms are merely used to distinguish the component from other components and do not limit the nature, order, or sequence of the components. Furthermore, unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as commonly understood by a person of ordinary skill in the art to which the embodiments disclosed herein belong. Terms defined in commonly used dictionaries should be interpreted as having a meaning consistent with the context of the relevant art, and should not be interpreted in an idealized or overly formal sense unless expressly defined in this application.
[0014] Figure 1 is a block diagram illustrating a battery pack and a server according to one embodiment disclosed herein. Figure 2 is a block diagram illustrating the pack BMS shown in Figure 1 in more detail.
[0015] Referring to FIGS. 1 and 2, a battery system according to one embodiment disclosed herein may include a battery pack 100 and a server (cloud server) 400.
[0016] The battery pack 100 can be mounted on other devices (e.g., electric scooters, electric vehicles, etc.) and supply the power necessary to drive the devices. The battery pack 100 can include a pack BMS (battery management system) 200, a first battery module 310, a second battery module 320, a third battery module 330, and a fourth battery module 340. While FIG. 1 shows the battery pack 100 including four battery modules 310-340, this is merely an example, and any number of battery modules (e.g., two, ten, etc.) can be included in the battery pack 100 as needed.
[0017] The pack BMS 200 controls the overall operation of the battery pack 100 and can communicate with a server 400. As shown in FIG. 2 , the pack BMS 200 can include a controller 210, a communication unit 220, a main memory 230, a security memory 240, and an input / output terminal 250.
[0018] The controller 210 may control the overall operation of the pack BMS 200. According to one embodiment, the controller 210 may control the communication unit 220 and communicate with each of the first to fourth battery modules 310 to 340 and / or the server 400. According to one embodiment, the controller 210 may store data received from the outside and / or data processed or generated by the controller 210 in the main memory 230 and / or the security memory 240, or may read data stored in the main memory 230 and / or the security memory 240. The controller 210 may also be electrically connected to a specific device (e.g., the update device of FIG. 6) connected thereto via the input / output terminal 250, and may control the pack BMS 200 to perform an operation requested by the specific device.
[0019] Meanwhile, the controller 210 can process status data (e.g., voltage, current, resistance, temperature, etc. of the battery cells) received from each of the first to fourth battery modules 310-340 to generate processed status data (e.g., SOC (state of charge), SOH (state of health), etc.). Here, the received status data and / or processed status data can be stored in the main memory 230 as battery data for a corresponding battery module among the first to fourth battery modules 310-340 under the control of the controller 210. That is, the battery data may be information indicating the status of the corresponding battery module (or the corresponding battery cell).
[0020] Furthermore, the controller 210 may control the configuration included in the battery pack 100 based on the BMS image stored in the main memory 230. According to an embodiment, the BMS image may be firmware for driving the battery pack 100. As an example, the BMS image may have the form of binary data, although the scope of the present invention is not limited thereto.
[0021] Furthermore, the controller 210 can process requests received from the server 400, and for example, can decrypt encrypted battery data received from the server 400 and perform a verification operation on the server 400 using the decrypted battery data, a more detailed description of which will be given later with reference to FIGS. 3 and 4.
[0022] In addition, the controller 210 may analyze a clock signal received from a specific device (e.g., the update device of FIG. 6) connected via the input / output terminal 250 and perform a verification operation for the specific device, which will be described in more detail below with reference to FIGS. 5 and 6.
[0023] The communication unit 220 can establish a wired communication channel and / or a wireless communication channel between the pack BMS 200 and the server 400 and / or between the pack BMS 200 and at least one of the battery modules (310 to 340), and transmit and receive data with the server 400 and / or at least one of the battery modules (310 to 340) via the established communication channel. For example, the communication unit 220 can transmit and receive data with other devices based on at least one radio access technology (RAT).
[0024] The main memory 230 may store instructions required for the operation of the battery pack 100 and / or information related to the battery modules 310-340. According to one embodiment, the main memory 230 may store a BMS image. According to one embodiment, the main memory 230 may store battery data for each of the battery modules 310-340. Here, the main memory 230 may include an allocated area for storing battery data for each of the battery modules 310-340, and the main memory 230 may sequentially store battery data received and generated for the corresponding battery module in the allocated area. Furthermore, when battery data is received in excess of the storage capacity of the allocated area, the main memory 230 may delete the oldest battery data stored in the allocated area and store the currently received battery data. That is, the main memory 230 may store the latest battery data corresponding to the storage capacity of the allocated area.
[0025] The security memory 240 may store a secret key. Here, the secret key is an encryption / decryption key used for a verification operation on the server 400, and may be a symmetric key pre-shared between the server 400 and the battery pack 100. That is, the secret key stored in the security memory 240 and the secret key stored in the server 400 may be the same. According to an embodiment, the secret key pre-shared between the server 400 and the battery pack 100 may be updated at a predetermined interval (e.g., every day) or according to a predetermined condition (e.g., when the BMS image is updated).
[0026] In this disclosure, it is assumed that encryption and decryption of battery data is performed according to a symmetric key algorithm, but the scope of the present invention is not limited thereto, and according to other embodiments, encryption and decryption of battery data may be performed according to an asymmetric key algorithm.
[0027] Each of the main memory 230 and the security memory 240 can be implemented with non-volatile memory, volatile memory, or a combination thereof.
[0028] The input / output terminal 250 may be a terminal provided separately for electrical connection and / or communication with a specific device (e.g., the update device of FIG. 6). According to one embodiment, the input / output terminal 250 may be a JTAG (Joint Test Action Group) connector that supports a method of transmitting and receiving data in a serial communication method for digital input / output. The controller 210 may update the BMS image using data received via the input / output terminal 250. The procedure for updating the BMS image via the input / output terminal 250 will be described later with reference to FIGS.
[0029] 1, the first to fourth battery modules 310 to 340 may have the same or corresponding structures and operations. The following description will focus on the first battery module 310, but this description can also be applied to the second to fourth battery modules 320 to 340.
[0030] The first battery module 310 may include a first module BMS 315 that controls the overall operation of the first battery module 310. Although not shown in FIG. 1 , the first battery module 310 may include at least one battery cell that stores (charges) and releases (discharges) power. According to one embodiment, the first battery module 310 may include at least one sensor that can obtain information regarding the status of the at least one battery cell. For example, the at least one sensor may obtain information regarding the voltage, current, resistance, and / or temperature of the battery cell and transmit the information to the first module BMS 315.
[0031] The first module BMS 315 may generate status data including information obtained from at least one sensor and / or information generated by processing the obtained information. Such status data may be data regarding the status of the battery cells of the first battery module 310.
[0032] The first module BMS 315 can communicate with the pack BMS 200 to send and receive data. According to one embodiment, the first module BMS 315 can send status data of the first battery module 310 to the pack BMS 200, and can receive requests from the pack BMS 200 and perform operations according to the requests.
[0033] The server 400 may provide a service for managing at least one battery pack (e.g., 100). To this end, the server 400 may communicate with the battery pack 100 to transmit and receive data. As an example, the server 400 may be a cloud server, although the scope of the present invention is not limited thereto. According to an embodiment, the server 400 may store battery data received from the battery pack 100 and maintain or change control settings for the battery pack 100 based on the results of analyzing the stored battery data. Such changes in the control settings may be reflected in a BMS image for the battery pack 100. When a new BMS image is generated and stored, the server 400 may send a request to the battery pack 100 to enter an update mode for updating the BMS image. According to an embodiment, the BMS image may be updated based on various factors (e.g., a design error in the battery pack 100, a change in the battery operation policy, etc.) as well as the results of analyzing the battery data. The procedure for updating the BMS image via sending a request to enter the update mode will be described later with reference to FIGS.
[0034] Fig. 3 is a flowchart showing a procedure for updating a BMS image according to an embodiment of the present invention. Fig. 4 is a diagram showing information used in the procedure for updating the BMS image of Fig. 3.
[0035] 3 and 4, a BMS image (i.e., firmware) update procedure according to one embodiment of the present invention may be initiated and proceeded by a server 400.
[0036] The pack BMS 200 can receive status data from each of the battery modules 310-340 and generate battery data based on the status data. The pack BMS 200 can store the battery data in the main memory 230 and transmit it to the server 400 (S110). The server 400 can store the received battery data by matching it with identification information (e.g., an ID (identifier)) of the pack BMS 200. The battery data transmission and reception operations between the battery modules 310-340, the pack BMS 200, and the server 400 can be performed according to a predetermined algorithm (e.g., a fixed cycle or fixed conditions).
[0037] The server 120 can determine whether a new BMS image for the pack BMS 200 has been registered (ie, updated) (S120).
[0038] If a new BMS image for the pack BMS 200 has not been registered (No in S120), step S110 may be performed again. When a new BMS image for the pack BMS 200 is registered (Yes in S120), the server 400 checks the version information of the BMS image stored in the current pack BMS 200 (S130), compares the version information of the BMS image stored in the current battery pack 100 with the version information of the new BMS image, and determines whether the BMS image needs to be updated (S140). Here, the version information is information related to the version of the BMS image, and when the update of the BMS image for the pack BMS 200 is completed, the server 400 can match the version information of the BMS image with the identification information (e.g., ID) of the pack BMS 200 and store them.
[0039] If the version information of the BMS image stored in the pack BMS 200 and the version information of the new BMS image are identical to each other and there is no need to update the BMS image (No in S140), step S110 can be performed again.
[0040] If the version information of the BMS image stored in the pack BMS 200 differs from the version information of the new BMS image and an update of the BMS image is required (Yes in S140), the server 400 can send a request to the pack BMS 200 to enter update mode (S150). The request to enter update mode may be a message requesting the pack BMS 200 to update the BMS image after operation of the device in which the pack BMS 200 is mounted has ended (for example, after the start of an electric scooter has been turned off).
[0041] The pack BMS 200 that has received the request to enter the update mode can transmit a response to the request to enter the update mode to the server 400 .
[0042] The server 400 can extract battery data corresponding to the verification rule from the battery data corresponding to the pack BMS 200 stored in the server 400, and encrypt the extracted battery data using the private key (S160). Here, the verification rule may mean a rule that determines what to encrypt from the battery data sequentially received corresponding to the pack BMS 200 (i.e., a rule regarding which battery data to select and encrypt).
[0043] According to one embodiment, the verification rule may be shared in advance between the pack BMS 200 and the server 400. For example, the verification rule may be to extract the last (or latest) transmitted / received battery data from the battery data corresponding to the pack BMS 200.
[0044] According to one embodiment, the verification rule may be shared via a response to a request to enter the update mode. That is, the response to the request to enter the update mode may include information about the verification rule. For example, the pack BMS 200 may include a randomly determined number (e.g., 60) from among a plurality of numbers (e.g., 1 to 100) as information about the verification rule in the response to the request to enter the update mode and transmit the response to the request to enter the update mode to the server 400. The server 400 may receive the response to the request to enter the update mode and extract and encrypt the 60th last transmitted / received battery data from among the battery data corresponding to the pack BMS 200 in accordance with the information about the verification rule. In this case, the pack BMS 200 may compare the decrypted battery data with the 60th last transmitted / received battery data from among the battery data already stored during a subsequent comparison operation.
[0045] According to another embodiment, the verification rule may be shared via a request to enter the update mode. That is, the request to enter the update mode may include information about the verification rule. For example, the server 400 may include a randomly determined number (e.g., 60) from among a plurality of numbers (e.g., 1 to 100) in the request to enter the update mode as information about the verification rule and transmit the request to the pack BMS 200. In addition, the server 400 may extract and encrypt the 60th last transmitted / received battery data from the battery data corresponding to the pack BMS 200 in accordance with the verification rule. The pack BMS 200 may receive the request to enter the update mode, extract the 60th last transmitted / received battery data from the already stored battery data in accordance with the information about the verification rule, and then compare the decrypted battery data with the 60th last transmitted / received battery data from the already stored battery data in a subsequent comparison operation.
[0046] According to another embodiment, the verification rule may be included in a private key shared in advance between the server 400 and the battery pack 100. That is, the private key may include information about the verification rule. The information about the verification rule may include time information and date information.
[0047] Here, the time information may include a time offset indicating the amount of time preceding the current time, and the data information may include a data identification item indicating specific data among the data included in the battery data (e.g., the voltage, current, resistance, temperature, SOC, SOH, etc. of the battery cell).
[0048] The server 400 can extract and encrypt data corresponding to a data identification item (e.g., one of the voltage, current, and temperature of the battery cell) from battery data corresponding to the pack BMS 200 that was transmitted or received at a time preceding the current time by a time offset, among battery data corresponding to the pack BMS 200, according to information on the verification rule included in the private key shared in advance. The pack BMS 200 can extract data corresponding to a data identification item (e.g., one of the voltage, current, and temperature of the battery cell) from battery data transmitted or received at a time preceding the current time by a time offset, among battery data already stored, according to information on the verification rule included in the private key shared in advance, and then, during a comparison operation, compare the decrypted battery data with the battery data extracted from the already stored battery data in accordance with the verification rule. Here, the battery data to be compared can correspond to a portion of the battery data.
[0049] The server 400 can extract battery data that meets the verification rule from the battery data corresponding to the pack BMS 200 stored in the server 400, and encrypt the extracted battery data using the private key (S160).
[0050] The server 400 can transmit the encrypted battery data to the pack BMS 200 (S170), and the pack BMS 200 can decrypt the encrypted battery data using a private key stored in the security memory 240 (S180). For example, the encryption / decryption method using the private key may be an AES (Advanced Encryption Standard) encryption algorithm, but the scope of the present invention is not limited to this.
[0051] The pack BMS 200 can compare the battery data received and decrypted from the server 400 with the battery data extracted from the main memory 230 in accordance with the verification rule to confirm whether they match (S190). For example, if the verification rule is to extract the last (or latest) transmitted / received battery data from the battery data corresponding to the pack BMS 200, the pack BMS 200 can extract the last transmitted battery data from the battery data stored in the main memory 230 and compare it with the battery data received and decrypted from the server 400.
[0052] If the battery data received and decrypted from the server 400 is different from the battery data extracted from the main memory 230 according to the verification rule (No in S190), step S110 can be performed again.
[0053] If the battery data received and decrypted from the server 400 and the battery data extracted from the main memory 230 according to the verification rules are identical to each other (No in S190), the subsequent BMS image update operation can be performed.
[0054] This is to prevent a malicious attacker from hacking the communication line between the pack BMS 200 and the server 400 to imitate the server 400, causing the pack BMS 200 to be updated to an incorrect BMS image, which could result in a serious accident such as a fire or explosion. In the present disclosure, the pack BMS 200 verifies in advance whether the server 400 has a valid private key, valid verification rules, and valid battery data, and only performs the BMS image update operation by the verified server 400, thereby preventing the BMS image update operation due to hacking via the communication line between the pack BMS 200 and the server 400.
[0055] After step S190, the pack BMS 200 can determine whether the start-up of the device in which the battery pack 100 is installed has been turned off based on a signal received from the device (S200).
[0056] The pack BMS 200 may wait until a signal indicating that the starter has been turned off is received (No in S200), and if a signal indicating that the starter has been turned off is received (Yes in S200), the pack BMS 200 may enter update mode (S210) and update the BMS image (S220). According to one embodiment, the pack BMS 200 may receive a new BMS image for the pack BMS 200 from the server 400, and may update the BMS image by replacing the BMS image already stored in the main memory 230 with the new BMS image and storing it.
[0057] The BMS images may include BMS images stored in the pack BMS 200 (ie, pack BMS images) and / or BMS images stored in each of the module BMSs 315-345 (ie, module BMS images).
[0058] If the new BMS image contains only the pack BMS image (ie, if no module BMS update is required, No in S230), the BMS image update procedure can be terminated.
[0059] If the new BMS image includes a module BMS image (i.e., if a module BMS needs to be updated, Yes in S230), the pack BMS 200 can transmit the module BMS image to the module BMS and control the module BMS to update the module BMS image (S240).
[0060] As shown in FIG. 4, the pack BMS 200 and the server 400 may store private keys, battery data, and verification rules that are shared and stored at different times and through different paths, and only when the server 400 has all of the private keys, battery data, and verification rules stored in the pack BMS 200 can the server 400 be verified as a legitimate server 400 by the pack BMS 200, and the BMS image of the server 400 can be updated to the pack BMS 200.
[0061] Fig. 5 is a flowchart showing a procedure for updating a BMS image according to another embodiment of the present invention. Fig. 6 is a diagram showing information used in the procedure for updating a BMS image in Fig. 5.
[0062] 5 and 6, a BMS image (i.e., firmware) update procedure according to another embodiment of the present invention can be initiated and performed by an update device 500. The update device 500 can update the BMS image for the pack BMS 200.
[0063] As described in FIG. 2, the pack BMS 200 may include an input / output terminal 250 for electrical connection and / or communication with the update device 500. According to one embodiment, the input / output terminal 250 may be attached inside the battery pack 100 without being exposed to the outside, and after the battery pack 100 is disassembled, the input / output terminal 250 may be exposed to the outside (S310).
[0064] 6, the input / output terminal 250 exposed to the outside and the update device 500 may be connected via a cable 510 (S320). Here, the cable 510 may be a flat cable, but the scope of the present invention is not limited thereto.
[0065] The update device 500 can generate a clock signal based on a pre-stored clock pattern and transmit the clock signal to the pack BMS 200 via the cable 510 (S330). Here, the clock pattern is a pattern that determines the waveform of the clock signal, and may be a pattern determined by varying the amplitude, period, frequency, duty cycle, or a combination thereof of the clock signal. For example, if the input / output terminal 250 is a JTAG connector, the clock signal can be received via a clock pin of the JTAG connector.
[0066] The pack BMS 200 can analyze the clock signal received via the cable 510 and extract the clock pattern of the received clock signal. According to one embodiment, the pack BMS 200 can detect the amplitude, period, frequency, duty cycle, or a combination thereof of the received clock signal and determine the clock pattern of the received clock signal based on the detected results. To this end, the pack BMS 200 can further include a timer, a voltage meter, an analog-to-digital converter, etc.
[0067] The pack BMS 200 can compare a clock pattern previously shared and stored with the clock pattern of the received clock signal to determine whether they match (S340). Here, "match" may refer not only to a perfect physical match, but also to a similarity within a certain range, taking into account the influence of other noise (e.g., noise depending on the state of the cable 510).
[0068] If the pre-stored clock pattern and the clock pattern of the received clock signal do not match (No in S340), the BMS image update procedure may be terminated.
[0069] If the pre-stored clock pattern matches the clock pattern of the received clock signal (Yes in S340), the pack BMS 200 can enter a system management mode (S350). Here, the system management mode can refer to a mode in which operations such as updating the BMS image and verifying whether commands required for the operation of the battery pack 100 are normal (e.g., debugging) can be performed.
[0070] The pack BMS 200 enters the system management mode and can perform the update operation and debugging of the BMS image according to the control of the update device 500 (S360). The update operation of the BMS image is substantially the same as the update operation of the BMS image for the pack BMS 200 and the module BMSs 315 to 345 described in FIG. 3, so a duplicated description will be omitted.
[0071] According to the present disclosure, it is possible to prevent a malicious attacker from hacking the input / output terminal 250 of the pack BMS 200 to imitate the update device 500, causing the pack BMS 200 to be updated to an incorrect BMS image, which could result in serious accidents such as fires or explosions. The pack BMS 200 verifies in advance whether the update device 500 is a legitimate one that can generate and transmit a clock signal according to a legitimate clock pattern, and only performs the update operation of the BMS image using the verified update device 500, thereby preventing the update operation of the BMS image due to hacking via the input / output terminal 250 of the pack BMS 200.
[0072] As shown in FIG. 6, the pack BMS 200 and the update device 500 can each store a clock pattern that is shared and stored in advance, and only when the update device 500 generates and transmits a clock signal based on the same clock pattern as the clock pattern stored in the pack BMS 200, it can be verified as a legitimate update device 500 by the pack BMS 200, and the BMS image of the update device 500 can be updated to the pack BMS 200.
[0073] FIG. 7 is a block diagram illustrating a hardware configuration of a computing system for performing an operation method of a battery management system according to an embodiment disclosed herein.
[0074] Referring to FIG. 7, a computing system 1000 according to one embodiment disclosed herein may include an MCU 1010, a memory 1020, an input / output I / F 1030, and a communication I / F 1040.
[0075] According to one embodiment, the computing system 1000 may be a system for performing the operations of the above-described pack BMS 200, module BMSs 315 to 345, or server 400 (hereinafter referred to as the "apparatus").
[0076] The MCU 1010 may be a processor that executes various programs stored in the memory 1020 . For example, the MCU 1010 may be a processor that processes various data and / or signals required for the pack BMS 200 to manage and control the battery pack 100.
[0077] The memory 1020 can store various programs and / or data required to manage and control the device. A plurality of memories 1020 may be provided as needed.
[0078] The memory 1020 may be a volatile memory or a non-volatile memory. The volatile memory 1020 may be a RAM, a DRAM, an SRAM, etc. The non-volatile memory 1020 may be a ROM, a PROM, an EAROM, an EPROM, an EEPROM, a flash memory, etc. The examples of the memory 1020 listed above are merely illustrative and are not limiting.
[0079] The input / output I / F 1030 can provide an interface that connects input devices (not shown) such as a keyboard, mouse, or touch panel, and output devices such as a display (not shown), to the MCU 1010, enabling data to be sent and received.
[0080] The communication I / F 1040 is configured to be able to send and receive various data to and from external components such as a server, and may be any of various devices capable of supporting wired or wireless communication.
[0081] In this way, the computer program of one embodiment disclosed in this document may be recorded in memory 1020 and implemented as a module that performs each of the operations described above in Figures 1 to 6 by being executed and processed by MCU 1010.
[0082] The above description is merely an illustrative example of the technical ideas disclosed in this document, and various modifications and variations are possible within the scope of those skilled in the art to which the embodiments disclosed in this document pertain without departing from the essential characteristics of the embodiments disclosed in this document.
[0083] Therefore, the embodiments disclosed in this document are intended to illustrate, not limit, the technical ideas disclosed in this document, and such embodiments do not limit the scope of the technical ideas disclosed in this document. The scope of protection of the technical ideas disclosed in this document should be interpreted according to the claims below, and all technical ideas within the scope equivalent thereto should be interpreted as being included in the scope of rights of this document.
Claims
1. A method for updating firmware of a battery pack, comprising: transmitting battery data indicating the status of the battery cells included in the battery pack to a server; receiving a request to enter an update mode for updating firmware from the server; receiving encrypted battery data from the server, the encrypted battery data being data obtained by encrypting the battery data; decrypting the encrypted battery data; comparing the decrypted battery data with battery data stored in the battery pack; updating the firmware stored in the battery pack with the firmware received from the server if the decrypted battery data and the battery data stored in the battery pack match each other; Including how to update firmware.
2. the battery data is encrypted using a private key stored in the server; The firmware update method according to claim 1 , wherein the encrypted battery data is decrypted using a private key stored in the battery pack.
3. The firmware update method according to claim 1 , wherein the battery data is the latest battery data last transmitted by the battery pack.
4. The firmware update method according to claim 1 , further comprising the step of transmitting a response to the request to enter the update mode to the server after the step of receiving the request to enter the update mode.
5. The firmware update method according to claim 4 , wherein the response to the request to enter the update mode includes information about a verification rule that determines what is to be encrypted.
6. 6. The firmware update method according to claim 5, wherein in the comparing step, the decrypted battery data and the battery data stored in the battery pack are each battery data determined in accordance with the verification rule.
7. 2. The firmware update method according to claim 1, wherein the step of updating the firmware stored in the battery pack is performed after the device in which the battery pack is mounted is turned off.
8. A method for updating firmware of a battery pack by a server, comprising: receiving battery data from the battery pack indicating the status of battery cells included in the battery pack; If the firmware of the battery pack needs to be updated, sending a request to the battery pack to enter an update mode for updating the firmware; encrypting the battery data and transmitting the encrypted battery data to the battery pack; transmitting firmware corresponding to the battery pack to the battery pack so as to update the firmware stored in the battery pack; Including how to update firmware.
9. The firmware update method according to claim 8 , wherein the battery data is the latest battery data last received by the server.
10. The firmware update method according to claim 8 , further comprising the step of receiving a response to the request to enter the update mode from the battery pack after the step of transmitting the request to enter the update mode.
11. The firmware update method according to claim 10 , wherein the response to the request to enter the update mode includes information about a verification rule that determines what is to be encrypted.
12. The firmware update method according to claim 11 , wherein the encrypted battery data is battery data determined in accordance with the verification rule.
13. at least one battery module; a pack BMS that controls the at least one battery module; Including, The pack BMS includes: a communication unit that transmits battery data indicating a state of a battery cell included in the at least one battery module to a server and receives, from the server, a request to enter an update mode for firmware update and encrypted battery data that is data obtained by encrypting the battery data; a controller that compares decrypted battery data generated by decrypting the encrypted battery data with battery data stored in the pack BMS, and updates firmware stored in the pack BMS using firmware received from the server if the decrypted battery data matches the battery data stored in the pack BMS; Including the battery pack.
14. the battery data is encrypted using a private key stored in the server; The battery pack according to claim 13 , wherein the encrypted battery data is decrypted using a private key stored in a security memory of the pack BMS.
15. The battery pack according to claim 13 , wherein the battery data is the latest battery data last transmitted by the communication unit.
Citation Information
Patent Citations
Energy storage end software upgrading method and system
CN114661316A
Battery power source
JP2001275270A
Charger and battery pack
JP2006197699A
Battery control circuit, battery pack, and update system of program for battery control
JP2009240055A
Program rewriting system and program rewriting method
JP2013050862A