News: 1648639910

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Electric Vehicle DC charging tripped by a wireless hack

(2022/03/30)


Researchers from the University of Oxford [1]published details of a vulnerability in the Combined Charging System that has the potential to abort charging.

The Combined Charging System (CCS) is one of the plethora of standards in the EV charging world, and allows DC fast charging.

Different plug types are used for the US and EU regions (dubbed Combo 1 and 2 respectively) but both use the same underlying technology. As well as taking in all that lovely charge, the EV and the Electric Vehicle Supply Equipment (EVSE) swap messages concerning how charged things are, the maximum possible current and so on. The link used for the communication is provided by the HomePlug Green PHY (HPGP) power-line communication (PLC) technology.

[2]

The researchers created a lab testbed that consisted of the same HPGP modems used in most EVs and charging stations at the victim end, and a software defined radio replete with a 1W RF amplifier on an antenna the team made themselves (with which to carry out the attack).

[3]

[4]

They also took the kit out into the real world and tried it in test sites on seven vehicles from different manufacturers and 18 DC high-power chargers.

[5]Alibaba smart electric vehicles now in mass production

[6]Fitbit recalls Ionic smartwatch for burning fat – literally

[7]Crack team of boffins hash out how e-scooters should sound – but they need your help*

[8]Could BYOB (Bring Your Own Battery) offer a solution for charging electric vehicles? Microlino seems to think so

The results make for grim reading. The off-the-shelf gear managed to abort the charging process from up to 10 meters away from the target with a power budget of 10mW. The closer one got, the less power was needed to cause a 100 percent packet loss. When outside the lab, the team stuck to a maximum output power of 1W to avoid breaking any national transmission regulations.

Before EV vehicle owners panic about their beloved trundle-wagons being targeted in this way, the attack only interrupts the charging (a victim would need to simply disconnect and reconnect their vehicle.) Researchers found no evidence of any long-term damage caused by the attack. They also reckoned that home AC chargers (which use a different communication standard) were also unlikely to be affected, although cautioned that things could change as home chargers received ISO 15118 support.

However, an unexpectedly uncharged battery could be more than an inconvenience for some users (such as the emergency services) and the wireless nature of the attack makes it stealthier than simply hitting the off button or snipping a cable.

[9]

The research is a reminder of the ever-widening attack surface afforded by smart vehicles, not just through the onboard chippery, but also via the connection used to charge the growing fleet of EVs in the world. The team has made a preprint of its paper available [10]here [PDF], with parts redacted for the sake of responsible disclosure. ®

Get our [11]Tech Resources



[1] https://www.brokenwire.fail/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YkR@sTrdV19fL2ZJ0m9uXQAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkR@sTrdV19fL2ZJ0m9uXQAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YkR@sTrdV19fL2ZJ0m9uXQAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/03/07/alibaba_smart_electric_vehicles/

[6] https://www.theregister.com/2022/03/02/fitbit_smartwatch_recall/

[7] https://www.theregister.com/2022/01/28/escooter_sound/

[8] https://www.theregister.com/2022/01/14/microlino/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkR@sTrdV19fL2ZJ0m9uXQAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://arxiv.org/pdf/2202.02104.pdf

[11] https://whitepapers.theregister.com/



Cancelling Charging

Red Ted

My experience is that you don't need to hack anything to make a charge abort early, as charging points seem to do it all by themselves!

The likes of Zap-Map are full of review comments about charging stopping early.

Security is for the weak!

ThatOne

Yet another case of cheap & cheerful implementation...

I'm no RF engineer, but I'm sure there must be ways to shield the cable in a way that war-driving kids can't wreak havoc, and that a nearby lightning strike doesn't trigger the car's self-destruction procedure (I'm sure there is one somewhere in there).

Re: Security is for the weak!

Yet Another Anonymous coward

I think the issue is that that data link is a low voltage AC on top of the DC power cable. Either the original connector standard didn't include data and this was a bodge or they were trying to save on pins/use standard industrial cable.

It's difficult to RF shield the thick DC power cable while keeping it flexible, and would mean you would need special expensive cable.

Re: Security is for the weak!

ThatOne

Point taken, but I'm pretty sure those are not cheap throwaway cables, so why can't they afford to add a coax for the data transmission? Just because the added cost of a couple cents per cable?

Obviously it's even cheaper to say "we take the security of our customers very seriously (now get out of my hair)" when something happens...

Re: Security is for the weak!

Doctor Syntax

it's even cheaper to say "we take the security of our customers very seriously (now get out of my hair)"

Are you sure? Those mouthpieces must cost money. Ten a penny? Fair enough.

Re: Security is for the weak!

Peter2

To be honest, if I was trying to irritate EV drivers then i'd be inclined to just cut the cable with a pair of bolt cutters; something which may become quite popular if EV drivers have cables running across footpaths like tripwires as some people have suggested might happen.

Re: Security is for the weak!

ThatOne

> cut the cable with a pair of bolt cutters

That carries most likely the penalty of death by electrocution!...

Re: Security is for the weak!

Phil O'Sophical

At 600V and 10-40A there will be lots of pretty sparks too.

mark l 2

Without having ever charged an EV i don't know, can you not simply unplug the power cable mid charge to stop it charging up or is it locked into place until the charge is completed?

As if you can simply pull it out mid charging, i suspect there are way more people going to do if they wanted to cause inconvenience to the owner of an unattended EVs on charging than rig up a modem, software and antenna to do wireless hack to interrupt the charging process.

Anonymous Coward

no you need to stop the charge before you can pull the charger plug out. Be a bit dangerous if you could just yank the cable out mid charge, there are a lot of amps flying around!!!!

Yet Another Anonymous coward

At least with the standard here in the former colonies, the car locks the connector for home level 1/2 chargers but you can unplug the biggest fast chargers.

Whether this was a safety feature to unplug a smoking car or so parking lot owners can tow somebody overstaying, or just an oversight on the plug design

PS there are a couple of sense pins so it can kill the current quickly when you disconnect

NerryTutkins

The cables lock in place when the charging starts. On my car (VW ID4) you need to click the keyfob to unlock the car to release it, even if the car is unlocked already.

Similar happens at the other end if you are using a cable to connect to a lower output public charger, such as those outside supermarkets.

Typically you don't need to stay with the car while charging, you have an app on your phone so you can see the status. Therefore you want to make sure that someone else cannot stop your charging by unplugging you, or steal your cable.

Doctor Syntax

As TFA points out, this is stealthier. Read that as "less liable to retribution by the vehicle owner".

Yes another possibility...

hoola

Given the every increasing amount of technical gizmos that are incorporated within a vehicle now something like this is no surprise. What is interesting is that it is affected by such a low power.

Keyless entry is bad enough but all the Apps connecting things to phones for unlocking, remote start and so baffle me.

Keyless can be a convenience but just zapping a button on the keyfob is just has easy. As far as connectivity to a phone, I just fail to see the advantage. It is simply something that can be done and in this age, if something does not have an App, it appears to be considered "Old".

I suppose if you lose your car your could "remote wipe" it or maybe if self-driving is ever mad to work, press a button on your phone and the car comes to your location.

Now the only time I have experience of losing a car is when my wife took the kids swimming and parked in an empty carpark. When they returned the carpark was now quite full and they had not the foggiest idea which row the car was in. Panic phone call to me as if I could somehow locate the car from 10 miles away. All I could confirm was that it wasn't on the driveway, and yes she had taken the blue one......

Re: Yes another possibility...

Anonymous Coward

the tesla app is really pretty good, can't speak or any other cars. You can do stuff like turn the aircon or heaters on before you get back to the car. And our favorite beep the horn just as our daughter is right near the car, gets her every time!

Re: Yes another possibility...

Phil O'Sophical

If the car park was empty when she arrived, wouldn't the car most logically be parked in a row near the swimming pool entrance?

Re: Yes another possibility...

ThatOne

> press a button on your phone and the car comes to your location

And then somebody discovers that actually that feature is protected by pinky-swear-level security, and chop shops start hiring additional staff...

Let me get this straight...

Roger Greenwood

They used an unshielded cable to transmit RF between devices (which must therefore be broadcasting crap all over the place) and didn't protect the same devices from any outside interference?. Presumably this is down to cost and a co-ax along with the welding cables was too much?

It's a wonder these chargers are able to work alongside each other at all...

Re: Let me get this straight...

Yet Another Anonymous coward

It's not RF (well not deliberately) - RF would work! Doing bluetooth or zigbee or similar to a charger 1m away with all the authentication and error correction and channel management built into the radio protocol would be good.

Instead the electrical engineers started with power and voltage specs, and connectors that were different for all the makers, and nobody thought about data - why does a power plug need data ?

The home standards came up with a simple bodge with an extra 1Khz low voltage signal on top of the charge and it just detects, connected, can take more current, I'm full.

The commercial ones somebody realised that they might want to charge money as well as batteries. They invented a big fancy standard, which was in xml (because it was a big fancy standard) but everybody already had the expensive wires and connectors in place. So they bodged a low voltage modem signal on top of the DC. It at least has some data verification, which is why this attack works, if you add enough noise to scramble the data it shuts off rather than self destructs.

I wonder if there's anything GOOD on tonight?