Summary of the invention
The secure data switching method, safety information management center and the secure data switching system that the objective of the invention is to propose a kind of electric automobile and fill electrical changing station can and fill the assurance that data exchange process between the electrical changing station provides reliability to electric automobile.
For achieving the above object, the invention provides a kind of electric automobile and the secure data switching method of filling electrical changing station, comprising:
Electric automobile fills at needs and changes when service electricity, fills the electrical changing station that fills that changes the electricity service and sends self integrity information through digital signature to providing, and fill the request that electrical changing station obtains the other side's integrity information to described;
Describedly fill the integrity information that electrical changing station submits to described electric automobile to send to the safety information management center, and submit integrity information to described electric automobile through digital signature according to this request;
Described electric automobile is submitted the described integrity information that electrical changing station sends that fills to described safety information management center;
Described safety information management center authenticates described electric automobile and the integrity information that fills electrical changing station respectively according to the integrality tabulation of self storage, and the feedback authentication result;
When authentication result all met, described electric automobile and described filling between the electrical changing station connected, and carry out exchanges data, and the described electrical changing station that fills provides the electricity service of changing of filling for electric automobile.
Further, when the registration of the described electric automobile service of in intelligent grid, charging, described electric automobile calculates the integrity value of the core component correspondence of self, and reporting the log-on message and the integrity value of described electric automobile to described safety information management center, described safety information management center deposits the log-on message and the integrity value of described electric automobile in described integrality tabulation.
Further, register when disposing at the described electrical changing station that fills, described integrity value of filling the core component correspondence of electrical changing station calculating self, and reporting described log-on message and integrity value of filling electrical changing station to described safety information management center, described safety information management center deposits described log-on message and integrity value of filling electrical changing station in described integrality tabulation.
Further, described electric automobile also comprises the step of the integrity value of the core component correspondence that recomputates described electric automobile self submitting to before the integrity information of digital signature to the exchange power station.
Further, submitted to before the integrity information of digital signature to described electric automobile according to this request at the described electrical changing station that fills, comprise that also the described electrical changing station that fills reads self the integrity value of core component correspondence that recalculates when starting, perhaps recomputate the step of integrity value of the core component correspondence of self according to the request of described electric automobile.
Further, described electric automobile and described filling when carrying out exchanges data between the electrical changing station, adopt the session key of consulting to obtain to carry out the encryption of data.
Further, described session key adopts the mode of each session generation or the mode that generates according to predetermined period.
Further, described electric automobile fills at needs and changes when service electricity, submits to the operation through the integrity information of digital signature to be specially to the safety information management center:
Described electric automobile is in the time can't connecting network, by filling electrical changing station to the integrity information of safety information management center forwarding through digital signature;
Described electric automobile is when network-connectable, directly to the integrity information of safety information management center submission through digital signature.
Further, hash algorithm is adopted in the calculating of described integrity value.
For achieving the above object, the present invention also provides a kind of safety information management center, comprising:
Module is preserved in the integrality tabulation, is used for preserving electric automobile and the integrity information that fills electrical changing station by the integrality tabulation;
The integrated authentication module, the authentication request that is used to receive electric automobile He fills electrical changing station, and according to the tabulation of described integrality described electric automobile and the integrity information that fills electrical changing station are authenticated;
The authentication result feedback module is used for to described electric automobile and fills electrical changing station feedback authentication result.
Further, also comprise:
Device certificate promulgation module, be used at described electric automobile or fill electrical changing station when inserting intelligent grid first, whether correctly check described electric automobile or fill the facility information of electrical changing station, if check correct, then allow registration, and for described electric automobile or fill electrical changing station promulgation corresponding equipment certificate.
Further, also comprise:
Session certificate promulgation module is used for generating session certificate before each session or according to predetermined period, and for described electric automobile or fill electrical changing station and issue described session certificate.
For achieving the above object, the present invention also provides a kind of secure data switching system that comprises aforementioned safety information management center, also comprises:
Electric automobile, be used for filling and change when service electricity at needs, submit self integrity information to the described electrical changing station that fills through digital signature, and to the request that electrical changing station sends the integrity information that obtains the other side of filling of changing the electricity service of filling is provided, and the integrity information through digital signature that will exchange the power station transmission reports described safety information management center, and after described safety information management center is passed through described electric automobile and the integrity information authentication of filling electrical changing station, and described filling between the electrical changing station connects, carry out exchanges data, and accept to fill the electricity service of changing of filling that electrical changing station provides;
Fill electrical changing station, be used for submitting to the integrity information of described electric automobile transmission to described safety information management center, and the request of sending according to described electric automobile is submitted integrity information through digital signature to described electric automobile, after described safety information management center is passed through described electric automobile and the integrity information authentication of filling electrical changing station, and connect between the described electric automobile, carry out exchanges data, and change electric the service for electric automobile provides to fill.
Based on technique scheme, the present invention verifies electric automobile by the authentication of appliance integrality information and fills the fail safe of the equipment state of electrical changing station, the normal electric automobile of Guarantee Status and fill between the electrical changing station and can carry out normal exchanges data, and fill and change the electricity operation, and then user and ISP's interests have been ensured.
Embodiment
Below by drawings and Examples, technical scheme of the present invention is described in further detail.
Distort the identification information or the destruction of electric automobile and fill electrical changing station in order to prevent malicious user, whether therefore need to adopt a kind of means can detect electric automobile is in normally with the state that fills electrical changing station, so that in time take the recording exceptional situation, sending reports to the police and do not provide fills treatment measures such as changing the electricity service.
The inventor notices at electric automobile and fills and generally included some core components in the electrical changing station, promptly relevant parts with computing, as the starting state information of device registration or chip address, embedded software on the version information of battery in the electric automobile, device coding, the battery status supervisory control system device bus etc. as core component, these core components can not change after dispatching from the factory substantially, only when being distorted or destroying, can cause the state information of core component to change by malicious user.For filling electrical changing station, the running status of embedded device, device numbering, starting state information, geography information etc. also all can be used as core component, these core components can not change after electrical changing station is disposed filling usually yet, only after being distorted or destroy, just can cause the state information of core component to change by malicious user.
And the core component that can not change under these normal conditions also can not change by Hash calculation acquisition integrity value, therefore can be used as the important evidence of judgment device state reliability.
As shown in Figure 1, be the schematic flow sheet of electric automobile of the present invention with an embodiment of the secure data switching method of filling electrical changing station.In the present embodiment, the secure data switching method comprises:
Step 101, electric automobile are filled when changing the electricity service at needs, fill the electrical changing station that fills that changes the electricity service and send self integrity information through digital signature to providing, and fill the request that electrical changing station obtains the other side's integrity information to described;
Step 102, describedly fill the integrity information that electrical changing station submits to described electric automobile to send to the safety information management center, and submit integrity information to described electric automobile through digital signature according to this request;
Step 103, described electric automobile are submitted the described integrity information that electrical changing station sends that fills to described safety information management center;
Step 104, described safety information management center authenticate described electric automobile and the integrity information that fills electrical changing station respectively according to the integrality tabulation of self storage, and the feedback authentication result;
Step 105, when authentication result all meets, described electric automobile and described filling between the electrical changing station connect, and carry out exchanges data, the described electrical changing station that fills provides the electricity service of changing of filling for electric automobile.
In the present embodiment, electric automobile and fill electrical changing station and all need verify integrity information at the safety information management center to method, apparatus, in other words, provide fill the electricity service of changing before, need guarantee that service equipment and attendee all determine to be in normal condition, do not distorted or destroyed, can be guaranteed that by these means fake equipment can't obtain unlawful interests, ensure to fill and change normally carrying out of electricity service.
In the step 103 in the present embodiment, electric automobile can by wireless or wired mode with fill electrical changing station and be connected so that send authentication request and exchanges data.Electric automobile can be connected with the safety information management center of network side by some wireless networks based on short-range wireless communication protocol (for example Zigbee, Bluetooth etc.).When electric automobile can connect network, then can directly submit to and fill the integrity information that electrical changing station sends through digital signature to the safety information management center, if and electric automobile does not have network communications capability or can't be connected with network at present, can also transmit this integrity information through digital signature to the safety information management center this moment by filling electrical changing station.
Electric automobile and fill electrical changing station when integrity information is submitted at the safety information management center to, also need integrity information is carried out digital signature, the safety information management center determines whether to be validated user by detecting this signing messages, and then whether the number of the account that can also check this user has enough expenses etc., can also this detection provide whether the equipment of service is legitimate device, avoid illegal or false charging station or charging pile to extract user's information and expense.The safety information management center can notify whether fill this electric automobile of electrical changing station be legal access user, can not confirm concrete user identity and fill electrical changing station, thereby the guarantee privacy of user, the current scope of activities of user is extrapolated in time and the position of avoiding the malice keeper to utilize the user to charge.
Need compare according to the integrality tabulation of self preserving when carrying out integrated authentication in the safety information management center, this integrality tabulation then is according to electric automobile and fills integrity value and the log-on message formation that electrical changing station reports.When electric automobile charges the registration of serving in intelligent grid, electric automobile calculates the integrity value of the core component correspondence of self, and reporting the log-on message and the integrity value of this electric automobile to the safety information management center, the safety information management center then deposits the log-on message and the integrity value of this electric automobile in the integrality tabulation.
Submitted to before the integrity information of digital signature to the safety information management center when electric automobile at every turn, need recomputate the integrity value of the core component correspondence of electric automobile self, so that determine whether the state information of current electric automobile is normal.
In like manner, filling electrical changing station registers in intelligent grid when disposing, also need to calculate the integrity value of the core component correspondence of filling electrical changing station self, and reporting this log-on message that fills electrical changing station and integrity value to the safety information management center, log-on message and integrity value that electrical changing station then will be filled in the safety information management center deposit the integrality tabulation in.
Submitted to before the integrity information of digital signature to the safety information management center according to this request when filling electrical changing station, can read self the integrity value of core component correspondence that recalculates when self starts, this integrity value is stored in the safety chip that fills electrical changing station.Also can all calculate the integrity value of the core component correspondence of filling electrical changing station self again, thereby obtain more reliable state information according to the request of each electric automobile.
Suppose that charging pile in the sub-district is by stealing, this moment, the malice user need install new software module or hardware usually on charging pile, or in charging pile the new application program of remote download, and this mode all can be destroyed the system mode of charging device, for example add hardware, then equipment can scan new hardware, can use even this hardware meets design specification, but have influence on final integrity value when also calculating because of integrality.In like manner, the inner hypothesis of electric automobile is illegally distorted, and then can have influence on final integrity value equally when integrality is calculated.
The safety information management center is when authenticating integrity information, the comparison of the integrity value of preserving and the integrity value of submission by self, whether unusually, just can in time find electric automobile or fill the state of electrical changing station, if it is unusual, then can take some treatment measures, for example refusal provides the service of discharging and recharging, sends information warning, recording exceptional situation etc. in daily record, the treatment measures that can take are not limited to several example given here, can also adopt the combination of these treatment measures or other treatment measures.
Except needs are checked electric automobile and the state information of filling electrical changing station, can also check that this can be finished the inspection of legitimacy by the safety information management center at the signature of checking electric automobile and filling the integrity information that electrical changing station reports to the user's of electric automobile legitimacy and described legitimacy of filling electrical changing station.
Pass through after integrated authentication and the validity checking electric automobile and filled electrical changing station when carrying out exchanges data, then can utilize the session key of consulting to obtain to carry out the encryption of session data.This encrypts employed session key through the key signature at third party authentication center or safety information management center, therefore provide service one side also can't directly obtain user's identity information, thereby the privacy of having guaranteed the user is not invaded.
Electric automobile or filled electrical changing station equipment before dispatching from the factory, all can issue the corresponding equipment certificate, this device certificate is by the signature authentication of device fabrication manufacturer, when inserting intelligent grid for the first time, need register the device certificate of self, because this device certificate has had the signature of production firm, therefore intelligent grid can differentiate that this new access device is that the production firm that meets relevant regulations produces, also can compare during information of same such as equipment lot number with the information of typing in early stage, after the confirmation, allow registration.Device certificate can be stored in the persistent storage of equipment usually.
Device certificate can be used for each request that inserts, but consider that device certificate will follow the equipment whole life, often participate in the signature verification computing, can increase the risk that is cracked, therefore can consider to produce session certificate, reduce the risk that device certificate cracks at exchanges data.The process of this session certificate promulgation is as follows:
It is right that at first equipment produces key, and send the signature of public keys and part identity information process device certificate to third party authentication center or safety information management center; Third party authentication center or safety information management center check according to signing messages whether signing messages submitted to by satisfactory equipment; If satisfactory equipment submission, then third party authentication center or safety information management center will send to session certificate of this equipment, comprise subscriber identity information and public key information in this certificate, also have the signing messages of authentication center simultaneously.Session key can adopt the mode of each session generation or the mode that generates according to predetermined period.
As shown in Figure 2, transmit schematic diagram for electric automobile of the present invention and the information of another embodiment of the secure data switching method of filling electrical changing station.Mode with similar signaling diagram has provided electric automobile, has filled the information exchanging process between electrical changing station and the safety information management center in the present embodiment, specifically comprises:
Step 201, electric automobile need fill when changing the electricity service, calculate the integrity value of the core component correspondence of self;
Step 202, electric automobile are submitted integrity value through digital signature by short-distance radio network (for example Zigbee network) to filling electrical changing station;
Step 203, fill the legitimacy that electrical changing station is submitted this integrity value to safety information management center checking electric automobile;
Step 204, electric automobile are also to the request that electrical changing station sends the checking integrity information of filling of changing the electricity service of filling is provided;
Step 205, fill electrical changing station and read self the integrity value of core component correspondence that recalculates when starting, perhaps recomputate the integrity value of the core component correspondence of self according to this request;
Step 206, fill electrical changing station and submit integrity value to through digital signature to electric automobile;
Step 207, the direct access network of electric automobile, just can directly submit this integrity information to administrative center, if there is not network insertion, then need data to be verified be submitted to the safety information management center through filling electrical changing station according to the interaction schemes of IEEE9798-3 agreement regulation.
Step 208, safety information management center authenticate described electric automobile and the integrity information that fills electrical changing station respectively according to the integrality tabulation of self storage;
Mind-set electric automobile feedback authentication result in step 209, the safety information management;
Mind-set is filled electrical changing station feedback authentication result in step 210, the safety information management;
Step 211, when authentication result all meets, electric automobile and described filling between the electrical changing station connect, and carry out exchanges data, the described electrical changing station that fills provides the electricity service of changing of filling for electric automobile.
In the example of above-mentioned information exchange, show the information transfering relation between each equipment in the secure data exchange process, but the not strict sequential relationship that is defined between above-mentioned each step does not for example have strict time order and function relation between step 207 and the step 208.
One of ordinary skill in the art will appreciate that: all or part of step that realizes said method embodiment can be finished by the relevant hardware of program command, aforesaid program can be stored in the computer read/write memory medium, this program is carried out the step that comprises said method embodiment when carrying out; And aforesaid storage medium comprises: various media that can be program code stored such as ROM, RAM, magnetic disc or CD.
As shown in Figure 3, be the structural representation of the embodiment at safety information management of the present invention center.In the present embodiment; the safety information management center is as electric automobile and fill the certifying key equipment that electrical changing station carries out the secure data exchange; can reduce malicious user as far as possible and distort or destroy electric automobile and fill the risk that electrical changing station brings, protection electric automobile user and the rights and interests of serving the supplier.Safety information management center in the present embodiment specifically comprises: module 11, integrated authentication module 12 and authentication result feedback module 13 are preserved in the integrality tabulation.Wherein, the module 11 responsible integrity informations of tabulating and preserving electric automobile and fill electrical changing station by integrality are preserved in the integrality tabulation.Integrated authentication module 12 is responsible for receiving electric automobile and the authentication request of filling electrical changing station, and according to described integrality tabulation described electric automobile and the integrity information that fills electrical changing station is authenticated.Authentication result feedback module 13 is responsible for to described electric automobile and is filled electrical changing station feedback authentication result.
In the embodiment at another safety information management center, also can comprise device certificate promulgation module, this module can or be filled electrical changing station when inserting intelligent grid first at described electric automobile, whether correctly check described electric automobile or fill the facility information of electrical changing station, if check correct, then allow registration, and for described electric automobile or fill electrical changing station promulgation corresponding equipment certificate.This device certificate will play a role as the proof of identification of this equipment.
Further, the safety information management center can also comprise session certificate promulgation module, and this module is responsible for generating session certificate before each session or according to predetermined period, and for described electric automobile or fill electrical changing station and issue described session certificate.Session certificate then can provide electric automobile and fill and session data is encrypted between changing a little, thereby guarantees the safety of data exchange process.
Based on the embodiment at aforesaid several safety information managements center, as shown in Figure 4, be the structural representation of an embodiment of secure data switching system of the present invention.In this secure data switching system, except comprising safety information management center 1, also comprise electric automobile 2 and fill electrical changing station 3.Wherein electric automobile 2 is responsible for filling at needs and is changed when service electricity, submit self integrity information to the described electrical changing station that fills through digital signature, and to the request that electrical changing station sends the integrity information that obtains the other side of filling of changing the electricity service of filling is provided, and the integrity information through digital signature that will exchange the power station transmission reports described safety information management center, and after described safety information management center is passed through described electric automobile and the integrity information authentication of filling electrical changing station, and described filling between the electrical changing station connects, carry out exchanges data, and accept to fill the electricity service of changing of filling that electrical changing station provides.
Fill electrical changing station 3 and be responsible for submitting to the integrity information of described electric automobile transmission to described safety information management center, and the request of sending according to described electric automobile is submitted integrity information through digital signature to described electric automobile, after described safety information management center is passed through described electric automobile and the integrity information authentication of filling electrical changing station, and connect between the described electric automobile, carry out exchanges data, and change electric the service for electric automobile provides to fill.
Should be noted that at last: above embodiment is only in order to illustrate that technical scheme of the present invention is not intended to limit; Although with reference to preferred embodiment the present invention is had been described in detail, those of ordinary skill in the field are to be understood that: still can make amendment or the part technical characterictic is equal to replacement the specific embodiment of the present invention; And not breaking away from the spirit of technical solution of the present invention, it all should be encompassed in the middle of the technical scheme scope that the present invention asks for protection.