Battery Control Unit Security Key Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing battery control units, such as BMS, BMU, and CSC, can be reused with replacement battery cells, posing risks of malfunctions, including fires and harmful substance release, as they are not designed to prevent reuse after their initial OEM introduction.

Innovation Solution

A control unit for a battery system that includes a power input, a control module, and a startup module with a non-volatile memory element storing a security key, which is validated to enable operation voltage supply to the control module only once, preventing subsequent startups and reuse by irreversibly erasing the security key upon initial activation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If control units are designed to be reusable with replacement battery cells, then cost reduction and resource efficiency are improved, but safety risks and malfunction potential increase

Engineering Contradiction:
Improvecost reductionVSAvoidsafety
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies preliminary action by erasing the security key from the non-volatile memory element during the initial startup phase, before the control unit is fully activated and before any potential reuse scenario could occur. This preemptive measure ensures that once the control unit has been used with a battery cell, it cannot be reused with replacement cells, thereby eliminating safety risks while allowing the control unit hardware to potentially be reused.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the state of the security key parameter in the non-volatile memory element from present to erased. This parameter change occurs automatically during the startup sequence and transforms the control unit from a reusable state to a non-reusable state, thereby ensuring safety without requiring complex additional hardware or manual intervention.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If control units prevent reuse through security key erasure, then safety and reliability are improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
ImprovesafetyVSAvoidcontrol unit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the non-volatile memory element serve multiple functions: it stores the security key for authentication purposes during normal operation, and it also serves as the mechanism for preventing reuse through key erasure. This multi-functionality avoids the need for separate reuse-prevention hardware, thereby minimizing the increase in device complexity while achieving the safety goal.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The control unit performs the security key erasure operation automatically during its own startup sequence without requiring external intervention or additional complex control systems. The startup module itself carries out the erasure function, making the system self-service and avoiding the need for separate reuse-prevention mechanisms that would increase device complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If security key validation is implemented for single activation, then unauthorized reuse is prevented, but startup process complexity and activation time increase

Engineering Contradiction:
Improveunauthorized reuse preventionVSAvoidstartup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security key validation and erasure operations are performed during the initial startup phase before the control unit is fully activated. By completing these security operations preliminarily during the mandatory startup sequence, the patent ensures that unauthorized reuse is prevented without requiring additional time checks during normal operation, as the prevention mechanism is already in place after the first startup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges the security key validation process with the existing startup sequence of the control unit. Instead of adding a separate validation step that would increase activation time, the security operations are integrated into the mandatory startup phase that already occurs before normal operation begins, thereby preventing unauthorized reuse without significant time penalty.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3331120B1Control unit for a battery system
Publication Date: 2018.10.17 SAMSUNG SDI CO LTD
  • EP3331120B1 patent drawingFigure 1~2
  • EP3331120B1 patent drawingFigure 3~4

AI summary

The present invention relates to a control unit (10) for a battery system (100), comprising a power input for an operation voltage of the control unit (10) that is provided by at least one battery cell (80); a control module (13) configured for performing at least control function with respect to the at least one battery cell (80); and a startup module (12) connected between the power input (11) and the control module (13). The startup module (12) comprises at least one non-volatile memory element (14) that is storing a security key, a verification circuit (15) that is configured for validating the security key and an activation circuit (16) that is configured for interconnecting the operation voltage to the control module (13) in response to the validation of the security key. According to the present invention the non-volatile memory element (14) is configured for irreversibly erasing the security key in response to an activation signal. The present invention further relates to a battery system (100) comprising a control unit (10) according to the invention and to a method for a startup of such a control unit (10).