USENIX Security2019Top-tier venue
Losing the Car Keys: Wireless PHY-Layer Insecurity in EV Charging
Richard Baker, Ivan Martinovic
Abstract
Electric vehicles (EVs) are proliferating quickly, along with the charging infrastructure for them. A new generation of charger technologies is emerging, handling more sensitive data and undertaking more complex interactions, while using the charging cable as the communication channel. This channel is used not only for charging control, but will soon handle billing, vehicle-to-grid operation, internet access and provide a platform for third-party apps -all with a public interface to the world. We highlight the threat posed by wireless attacks on the physical-layer of the Combined Charging System (CCS), a major standard for EV charging that is deployed in many thousands of locations worldwide and used by seven of the ten largest auto manufacturers globally. We show that design choices in the use of power-line communication (PLC) make the system particularly prone to popular electromagnetic side-channel attacks. We implement the first wireless eavesdropping tool for PLC networks and use it to observe the ISO 15118 network implementation underlying CCS, in a measurement campaign of 54 real charging sessions, using modern electric vehicles and state-of-the-art CCS chargers. We find that the unintentional wireless channel is sufficient to recover messages in the vast majority of cases, with traffic intercepted from an adjacent parking bay showing 91.8% of messages validating their CRC32 checksum. By examining the recovered traffic, we further find a host of privacy and security issues in existing charging infrastructure including plaintext MAC-layer traffic recovery, widespread absence of TLS in public locations and leakage of private information, including long-term unique identifiers. Of particular concern, elements of the recovered data are being used to authorise billing in existing charging implementations. We discuss the implications of pervasive susceptibility to known electromagnetic eavesdropping techniques, extract lessons learnt for future development and propose specific improvements to mitigate the problems in existing chargers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b0e46466-5b40-4663-af3d-04e720602ab7Cited by top-tier papers6
- Demystifying the Security Implications in IoT Device Rental ServicesYi He, Yunchao Guan, Ruoyu Lun, Shangru Song et al.USENIX Security 2024 · 2 citations
- Drift with Devil: Security of Multi-Sensor Fusion based Localization in High-Level Autonomous Driving under GPS SpoofingJunjie Shen, Jun Yeon Won, Zeyuan Chen, Qi Alfred ChenUSENIX Security 2020
- Evading Voltage-Based Intrusion Detection on Automotive CANRohit Bhatia, Vireshwar Kumar, Khaled Serag, Z. Berkay Celik et al.NDSS 2021
- EdgeTDC: On the Security of Time Difference of Arrival Measurements in CAN Bus SystemsMarc Roeschlin, Giovanni Camurati, Pascal Brunner, Mridula Singh et al.NDSS 2023
- Current Affairs: A Security Measurement Study of CCS EV Charging DeploymentsMarcell Szakály, Sebastian Köhler, Ivan MartinovicUSENIX Security 2025
Builds on4
- Screaming Channels: When Electromagnetic Side Channels Meet Radio TransceiversGiovanni Camurati, Sebastian Poeplau, Marius Muench, Tom Hayes et al.CCS 2018 · 186 citations
- All Your GPS Are Belong To Us: Towards Stealthy Manipulation of Road Navigation SystemsKexiong Curtis Zeng, Shinan Liu, Yuanchao Shu, Dong Wang et al.USENIX Security 2018 · 174 citations
- Lock It and Still Lose It - on the (In)Security of Automotive Remote Keyless Entry SystemsFlavio D. Garcia, David F. Oswald, Timo Kasper, Pierre PavlidèsUSENIX Security 2016 · 151 citations
- One&Done: A Single-Decryption EM-Based Attack on OpenSSL's Constant-Time Blinded RSAMonjur Alam, Haider Adnan Khan, Moumita Dey, Nishith Sinha et al.USENIX Security 2018 · 62 citations
Related papers
- Brokenwire : Wireless Disruption of CCS Electric Vehicle ChargingSebastian Köhler, Richard Baker, Martin Strohmeier, Ivan MartinovicNDSS 2023
- ChargePrint: A Framework for Internet-Scale Discovery and Security Analysis of EV Charging Management SystemsTony Nasr, Sadegh Torabi, Elias Bou-Harb, Claude Fachkha et al.NDSS 2023
- Fast or Secure? Push the Limit of Privacy Leakage Threat via Charging Side-Channel AttacksJiaxin Jiang, Xutong Zhang, Jiahao Li, Leqi Zhao et al.WWW 2026
- Wireless Charging Power Side-Channel AttacksAlexander S. La Cour, Khurram K. Afridi, G. Edward SuhCCS 2021 · 40 citations
- OCPPuzz: Specification-Driven Fuzzing of Charging Station Management Systems with Large Language ModelJongchan Hong, Jaewon Kim, Sungjae HwangFSE 2026
