EV Charging Cross-Certification for Multi-Root CA Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electric vehicle charging systems face challenges in managing trust relationships between different vehicle-to-grid (V2G) root certificate authorities, leading to difficulties in authenticating users and securing the charging infrastructure, which can be exploited by unauthorized groups for malicious purposes.
Innovation Solution
A cross certification method is introduced, allowing electric vehicles (EVs) and charge point operators (CPOs) to establish trust relationships by verifying certificate chains using cross certificates issued by a second V2G root CA, ensuring secure power transfer and flexible trust management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single V2G root CA is used for certificate verification, then the trust relationship management is simple, but the charging infrastructure cannot support multiple operators and the system lacks flexibility
Solution Approach 1:
The patent introduces a cross-certificate as an intermediary element that bridges trust between different V2G root CAs. The cross-certificate acts as a mediator that allows an EV trusting a second V2G root CA to verify certificates issued by a first V2G root CA, enabling multi-operator support while maintaining simple trust management for each individual EV
Solution Approach 2:
The patent segments the trust verification process into two distinct parts: the EV's native trust anchor (second V2G root CA) and the cross-certificate that bridges to the operator's certificate authority (first V2G root CA). This segmentation allows the system to maintain simple individual trust relationships while supporting complex multi-operator environments
2Adaptability or versatility
If cross-certification is implemented to support multiple V2G root CAs, then the system flexibility and multi-operator support are improved, but the certificate chain verification process becomes more complex
Solution Approach 1:
The cross-certificate is pre-configured in the EV's trust store alongside the EV's native root CA certificates. This preliminary setup eliminates the need for complex runtime decisions about which CA to trust, as the EV automatically has the cross-certificate available to verify certificates from multiple operators without increasing verification complexity
3Reliability
If traditional certificate verification is used without cross-certification, then the verification process is simple, but unauthorized entities can exploit security vulnerabilities in the charging infrastructure
Solution Approach 1:
The cross-certificate serves as a trusted intermediary that enables secure verification across different operator domains. It acts as a bridge that maintains security by ensuring that EVs can verify the authenticity of charging infrastructure certificates from multiple operators without compromising the trust model or increasing management complexity
Data Source
Figure 1~2
Figure 3
Figure 4A~5
AI summary
A cross-certificate method is performed by an electric vehicle (EV) for being supplied with power from electric vehicle supply equipment (EVSE) associated with a charging point operator (CPO) having established a trust relationship with a first vehicle to grid (V2G) root certificate authority (rootCA) and a second V2G root certificate authority. The cross-certificate method may include steps of: requesting charging from the electric vehicle supply equipment; receiving, from the electric vehicle supply equipment, a certificate chain held by the electric vehicle supply equipment; and verifying whether or not a last certificate of the certificate chain has been signed by the second V2G root certificate authority, wherein the last certificate of the certificate chain can be a cross-certificate issued by the second V2G root certificate authority.