EV Charging Authentication Using PKI and Lightweight CAN Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current EV charging systems lack secure and lightweight communication protocols for Plug and Charge scenarios, especially when using CAN cables, which have lower bandwidth than PLC cables, leading to insecure payment transactions and privacy concerns.
Innovation Solution
Implementing a system that uses complex Public Key Infrastructure (PKI) mechanisms for secure communication between EVs, CS, and CSMS, while employing lightweight authentication via CAN cables to facilitate secure Plug and Charge transactions, including the computation of lightweight credentials and the use of session identities for privacy preservation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex Public Key Infrastructure (PKI) mechanisms are used for secure communication, then security and authentication are improved, but communication overhead and processing complexity increase
Solution Approach 1:
The patent segments the authentication process into two distinct phases: (1) a setup phase using complex PKI mechanisms to establish long-term digital certificates and keys between the EV and CSMS, and (2) an operational phase using lightweight session tokens and pre-shared keys for actual charging transactions. This segmentation allows the heavy computational burden of PKI to be performed only once during setup, while subsequent communications use simplified authentication methods, thereby resolving the contradiction between security and communication overhead.
Solution Approach 2:
The patent implements preliminary action by pre-establishing security credentials and digital certificates between the EV and CSMS before the actual charging transaction occurs. The EV obtains a digital certificate from the CSMS in advance, and both parties pre-share cryptographic keys. When the charging session begins, these pre-established credentials are used to rapidly authenticate the EV without requiring real-time complex PKI operations, thus reducing communication overhead while maintaining high security standards.
2Productivity
If lightweight authentication is used for CAN cable communication, then bandwidth efficiency is improved, but security strength is reduced
Solution Approach 1:
The patent introduces an intermediary approach by using the CSMS as a trusted third party that mediates the security relationship between the EV and CS. The CSMS issues digital certificates to the EV and manages the distribution of cryptographic keys. This intermediary enables the EV-CS communication to use lightweight authentication methods (such as token-based authentication) while the CSMS provides the underlying security infrastructure, thus achieving both bandwidth efficiency and security strength simultaneously.
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting the authentication mechanism based on the communication medium. For PLC communications, full PKI validation is performed, while for CAN cable communications, the system transitions to using lightweight session tokens derived from pre-shared keys. This parameter change in authentication strength matches the bandwidth characteristics of each communication medium, optimizing both security and bandwidth efficiency for each specific channel.
3Reliability
If payment on the spot is required, then revenue collection is improved, but user convenience and charging speed are reduced
Solution Approach 1:
The patent implements self-service by enabling automatic authentication and billing through the Plug and Charge functionality. The EV automatically presents its digital certificate to the CS upon connection, the CS validates the certificate through secure communication with the EV, and the charging session is automatically authorized and billed without requiring the user to manually insert a payment card or interact with the charging interface. This self-service mechanism ensures reliable revenue collection through automated billing while maximizing user convenience by eliminating all manual payment steps.
Solution Approach 2:
The patent replaces the mechanical payment system (physical payment cards, cash handling, manual insertion into card readers) with an electronic cryptographic authentication system. The EV's digital certificate and cryptographic keys substitute for physical payment media, and the secure electronic communication protocol replaces the mechanical card-swiping or cash-handling processes. This substitution eliminates the need for users to carry payment cards or interact with physical payment terminals, thereby improving convenience while maintaining reliable revenue collection through automated electronic billing.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
This document describes a system and method for authenticating communication between a vehicle, a charging station and a charging station management server. In particular, the document describes of complex Public Key Infrastructure (PKI) mechanisms that are used to establish strong and secure communication mechanisms between the vehicle and the charging station management server and between the charging station and the charging station management server, while lightweight authentication is used for establishing communications between the vehicle and the charging station when a Controller Area Network (CAN) cable is used to transfer data between the vehicle and the charging station.