The deployment of electric vehicle charging infrastructure is occurring at a rapid pace. Simultaneously, existing standards, such as ISO 15118, which defines critical charging communication, are being improved and further developed. In this paper, we conduct a measurement study of already deployed DC charging stations to analyze the current state of deployment for various protocols. We present the adoption of TLS, and various EV charging protocols with a direct security impact, as well as observations about the Signal Level Attenuation Characterization (SLAC) process, and encryption keys. Our results indicate that even recently installed charging stations (December 2023) do not adhere to the latest version of the standard, leaving them vulnerable to attacks. We found that 84% of the surveyed charging stations do not implement Transport Layer Security (TLS), and are thus unable to implement the latest versions of the ISO 15118 protocol, leaving them vulnerable to attacks already demonstrated years ago. Finally, we observe and document anomalous behavior and violations of the standard.
翻译:电动汽车充电基础设施正以极快的速度部署。与此同时,定义关键充电通信的现有标准(如ISO 15118)也在不断改进与完善。本文对已部署的直流充电站开展测量研究,分析各类协议的当前部署状况。我们揭示了TLS的应用情况、对安全性有直接影响的多种电动汽车充电协议,并观察了信号电平衰减特性(SLAC)过程及加密密钥。我们的研究结果表明,即便是近期(2023年12月)安装的充电站,也未遵循最新版本的标准,从而易受攻击。在所调查的充电站中,84%未实施传输层安全(TLS)协议,因此无法采用ISO 15118协议的最新版本,导致它们对多年前已公开的攻击方法缺乏防御能力。此外,我们还观测并记录了违反标准规范的异常行为。