Power jacking your station: In-depth security analysis of electric vehicle charging station management systems

被引:26
|
作者
Nasr, Tony [1 ]
Torabi, Sadegh [1 ]
Bou-Harb, Elias [2 ]
Fachkha, Claude [3 ]
Assi, Chadi [1 ]
机构
[1] Concordia Inst Informat Syst Engn, Cyber Secur Res Ctr, Montreal, PQ, Canada
[2] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX USA
[3] Univ Dubai, Coll Engn & Informat Technol, Dubai, U Arab Emirates
基金
美国国家科学基金会; 加拿大自然科学与工程研究理事会;
关键词
Electric Vehicle (EV); EV Charging Station Management; System; Security analysis; Zero-day vulnerabilities;
D O I
10.1016/j.cose.2021.102511
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The demand for Electric Vehicles (EVs) has been exponentially increasing, and to achieve sustainable growth, the industry dictated rapid development of the supporting infrastructure. This requires building a reliable EV charging ecosystem that serves customer demands while ensuring the security of the Internet-enabled systems and the connected critical infrastructure against possible cyber attacks. To this end, we devise a system lookup and collection approach to obtain a representative sample of widely deployed EV Charging Station Management Systems (EVCSMS). Furthermore, we leverage reverse engineering and penetration testing techniques to perform a first-of-a-kind comprehensive security and vulnerability analysis of the identified EVCSMS and their software/firmware implementations. Indeed, our systematic analysis unveils an array of vulnerabilities, which demonstrate the insecurity of the EVCSMS against remote cyber attacks. Considering the feasibility of such attacks, we discuss attack implications against the EV charging stations (EVCS) and their users. More importantly, we simulate the impact of practical cyber attack scenarios against the power grid, which result in possible service disruption and failure in the grid. Finally, while we recommend mitigation measures, our discoveries raise concerns about the lack of adequate security considerations in the design of the deployed EVCS, which will motivate vendors to take immediate action to patch their developed systems. Indeed, our communication with the concerned parties resulted in positive responses from some vendors such as Schneider Electric, who acknowledged our findings by reserving 12 CVEs, respectively. (c) 2021 Elsevier Ltd. All rights reserved.
引用
收藏
页数:22
相关论文
共 50 条
  • [1] An in-depth analysis of electric vehicle charging station infrastructure, policy implications, and future trends
    Mastoi, Muhammad Shahid
    Zhuang, Shenxian
    Munir, Hafiz Mudassir
    Haris, Malik
    Hassan, Mannan
    Usman, Muhammad
    Bukhari, Syed Sabir Hussain
    Ro, Jong-Suk
    [J]. ENERGY REPORTS, 2022, 8 : 11504 - 11529
  • [2] Analysis on Storage Power of Electric Vehicle Charging Station
    Wang Zhenpo
    Liu Peng
    [J]. 2010 ASIA-PACIFIC POWER AND ENERGY ENGINEERING CONFERENCE (APPEEC), 2010,
  • [3] An Electric Vehicle Charging Station: Monitoring and Analysis of Power Quality
    Pinto, R. J. C.
    Pombo, J.
    Calado, M. R. A.
    Mariano, S. J. P. S.
    [J]. PROCEEDINGS 2015 9TH INTERNATIONAL CONFERENCE ON CAMPATIBILITY AND POWER ELECTRONICS (CPE), 2015, : 37 - 42
  • [4] Dynamic management of electric vehicle charging station
    Pandey, Vartika
    Prakash, Prem
    [J]. 2020 3RD INTERNATIONAL CONFERENCE ON ENERGY, POWER AND ENVIRONMENT: TOWARDS CLEAN ENERGY TECHNOLOGIES (ICEPE 2020), 2021,
  • [5] Electric Vehicle Charging Station Security Enhancement Measures
    Saadat, Shahriar
    Maingot, Samantha
    Bahizad, Sahba
    [J]. 2020 5TH IEEE WORKSHOP ON THE ELECTRONIC GRID (EGRID), 2020,
  • [6] Impact analysis of electric vehicle charging station integration with distributed generators on power systems
    Aggarwal, Surbhi
    Singh, Amit Kumar
    [J]. INTERNATIONAL JOURNAL OF CIRCUIT THEORY AND APPLICATIONS, 2021, 49 (06) : 1811 - 1827
  • [7] Electric Vehicle Charging Station: Cyber Security Challenges and Perspective
    Pourmirza, Zoya
    Walker, Sara
    [J]. 2021 THE 9TH IEEE INTERNATIONAL CONFERENCE ON SMART ENERGY GRID ENGINEERING (SEGE 2021), 2021, : 111 - 116
  • [8] Power Flow Management in Multi-Source Electric Vehicle Charging Station
    Erick, Arwa O.
    Folly, Komla A.
    [J]. IFAC PAPERSONLINE, 2020, 53 (02): : 12590 - 12595
  • [9] Energy Management Strategy for Electric Vehicle Charging Station as Flexible Power Reserve
    Husnain, Ali
    Bamigbade, Abdullahi
    AlBeshr, Hamad
    Ghaoud, Tareg
    [J]. IECON 2021 - 47TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, 2021,
  • [10] Dynamic energy management of an electric vehicle charging station using photovoltaic power
    Kouka, Karima
    Masmoudi, Abdelkarim
    Abdelkafi, Achraf
    Krichen, Lotfi
    [J]. SUSTAINABLE ENERGY GRIDS & NETWORKS, 2020, 24