EV Engineering News

SwRI finds cybersecurity risks in EV fast charging equipment

Engineers at Southwest Research Institute (SwRI) have identified cybersecurity vulnerabilities in DC fast charging EVSE.

In a laboratory, the SwRI team exploited vulnerabilities in the power line communication (PLC) layer that transmits smart-grid data between vehicles and charging equipment, gaining access to network keys and digital addresses on both the charger and the vehicle. The SwRI team developed an adversary-in-the-middle (AitM) device with specialized software and a modified combined charging system interface. The device let testers intercept traffic between EVs and electric vehicle supply equipment (EVSE) for data collection, analysis and attack. The team found unsecure key generation present on older chips when testing, which was confirmed through online research to be a known concern. 

SwRI has also developed a zero-trust architecture that can address interruptions in a vehicle’s functionality or performance. It connects several embedded systems using a single cybersecurity protocol.

“Through our penetration testing, we found that the PLC layer was poorly secured and lacked encryption between the vehicle and the chargers,” said Lead Project Engineer Katherine Kozan. 

Source: Southwest Research Institute

Comment
Create Account. Already Registered? Log In

Virtual Conference on EV Engineering: Free to Attend

Don't miss our next Virtual Conference on September 16-19, 2024. Register for the free webinar sessions below and reserve your spot to watch them live or on-demand.

LOAD MORE SESSIONS

EV Engineering Webinars & Whitepapers

EV Tech Explained