Phone

    00852-6915 1330

cyberattacks Related Articles

Stay Ahead with Expert Electronics Insights,
Industry Trends, and Innovative Tips

General electronic semiconductor

Electric Vehicle Vulnerabilities - Risks and Solutions

Overview: This article explores the potential risks associated with cyber attacks on electric vehicles and provides solutions for protecting both in-vehicle and external network vulnerabilities.One of the key technologies that has helped society achieve its high decarbonization and sustainable energy targets over the last decade has been electric vehicles (EVs).What are the elements that make electric vehicles susceptible to security breaches?Efforts are being made to standardize cyber-physical interfaces for both residential and commercial electric vehicles, as these vehicles are prone to vulnerabilities and have social costs.This article examines electric vehicle vulnerabilities resulting from:In-Vehicular VulnerabilitiesController Area Network BusController Area Network (CAN) is a peer-to-peer system that works on an isolated trust model. If an attacker gets into the CAN bus or even just one electronic control unit, they can completely control how the electric vehicle works because the CAN bus security architecture is not protected against malware being put into it.To pursue a desired harmful goal, an attacker with full control could alter, eavesdrop, reverse engineer, spoof, or replay the CAN communications.Every peer that is connected to the CAN bus, such as an electronic control unit or peripheral device, receives messages sent by these devices.Furthermore, in order to minimize memory costs and ensure a prompt transfer of the information, the CAN bus message is neither authenticated nor encrypted. This is critical for time-sensitive electronic control units like the brake control unit.Sending and receiving peer IDs are not included in a message that is sent over the CAN system. Instead, it is sent according to its arbitration ID, which indicates the priority of the message. Due to its low bandwidth, the CAN bus cannot support complex and computationally demanding encryption.On-Board Diagnostic PortFrom this angle, the attacker's main task is to damage the CAN bus. The (on-board diagnostic port) OBD2 port of the CAN bus has been the focus of extensive investigation and has been designated as a critical access point to the CAN bus due to its sizable infiltration surface made possible by both physical and remote vulnerabilities.Many times during an electric vehicle's lifetime, third parties like a mechanic during vehicle maintenance, a valet while parking, and a charging station helper can physically access the OBD2 port.Furthermore, smartphone applications such as the Open Vehicle Monitoring System (OVMS) that are connected to a cellular network or a wireless short-range network can compromise the OBD2 port. Thus, the apps enable remote monitoring and management of the electric vehicle's parts and functions.There have been reports of similar vulnerabilities in FlexRay, LIN, and MOST. If the LIN and MOST were broken into, they would not allow the key attacks listed above. This is because they are not as vulnerable as the CAN and FlexRay. This is so because the LIN is less exposed to external EV networks and the MOST network is limited to non-critical ECUs like the in-vehicular infotainment system.Tire Pressure Monitoring System Another in-vehicular attack vector is the Tire Pressure Monitoring System (TPMS). The technology is susceptible to hacks, which might compromise electric vehicle security and privacy. The tire pressure sensors transmit unencrypted signals; their identification is static 32-bit strings, and their messages lack authentication.Attackers can overhear, reverse engineer, and spoof communications with an electric vehicle within 40 meters because of these security weaknesses. False data injections into the electric vehicle in-vehicular infotainment system and remote tracking of the electric vehicle are the outcomes of the attack.External Network VulnerabilitiesPhysically Accessible PortsIn addition to the OBD2 connector, there are other physical interfaces that are connected and can be utilized to control the electronic control units and external cyber layer. It includes things like USB ports, SD card ports, CD/DVD drives, headphone connectors, touchscreens, and optical media readers.For the in-vehicular infotainment system's software updates, smartphone charging, media playback, and human interface, these ports are frequently physically accessed. When malicious devices are placed into these ports, an attacker can use them to introduce persistent malware into the in-vehicular infotainment system, start a denial-of-service attack, and even act as a side-channel access point to interfere with the operation of other electronic control units.An electric vehicle may come into contact with such a malicious device at several stages of its maintenance and supply chain.Internet Service PortalsThe in-vehicular infotainment system has wireless interfaces (like Bluetooth) for interacting with cellphones in addition to USB connections. Despite being short-range, this pairing is susceptible to cyberattacks.This flaw gives an attacker the ability to infect the in-vehicular infotainment system with malware, prevent its service from working, and take control of smartphones and in-vehicular infotainment data.Malicious smartphone apps that are mirrored in the in-vehicular infotainment dashboard also present data integrity risks to the in-vehicular infotainment system and side-channel threats to the CAN bus.When electric vehicle drivers use different third-party smartphone applications for electric vehicle charging station locating and remote electric vehicle monitoring and control, these vulnerabilities probably present security problems. Moreover, third-party programs that have been installed on the in-vehicular infotainment system may be dangerous or vulnerable to attack.Electric Vehicle Charging StationAn electric vehicle typically connects to an electric vehicle charging station using a CAN bus or the Power Line Communication's wired communication layer. This communication protocol, ISO 15118, is susceptible to cyberattacks.ISO 15118 governs the connection between an electric vehicle and an electric vehicle charging station but does not include any security measures like message certification or end-to-end encryption. It could allow a remote attacker to intercept, alter, and fake the electric vehicle charging message.Radio StationsRemote cyberattacks like spoofing and jamming can affect GPS signals, allowing attackers to supply erroneous geographical information and potentially disable the navigation system in electric vehicles.Long travel distances cause the GPS signals to be relatively faint; as a result, the GPS receiver prefers the attacker-generated stronger signals. Similarly, signals sent to an electric vehicle radio by FM radio stations are susceptible to malware injection and remote spoofing attacks.Road-Side Infrastructure and VehiclesIntelligent and autonomous transportation advancements necessitate the wireless communication of vehicles. The vehicles and roadside units (RSUs) in this futuristic communication architecture, known as the vehicular ad-hoc network (VANET), are connected through LANs or cellular networks.For improved safety, comfort, and efficiency when driving and routing, vehicles communicate with roadside units and other vehicles regarding information on road conditions, traffic, accidents, and vehicle position and speed. Nevertheless, these interfaces make the vehicles' data integrity and privacy more vulnerable to attacks from other networks and devices.By imitating the presence of several virtual vehicles in the network, an attacker may, for instance, conduct a Sybil-type attack on VANET. These fake vehicles have the ability to disrupt the network or propagate false information to roadside units and other linked cars.Original Equipment Manufacturers/VendorsThe original equipment manufacturer and outside suppliers must access electronic control units to provide security patches and software updates. Traditionally, the OBD2 and USB connections have been used to connect actual dongles and USB flash drives for this purpose.These conventional techniques are therefore susceptible to supply chain and maintenance intrusions. Currently, in order to get around the obstacles and expenses related to physical delivery, OEMs and third-party providers are moving to wireless updates.Updates are provided as code or data pictures together with metadata that includes authentication information. As a result, man-in-the-middle cyberattacks, in which an attacker can remotely spy, reject, and modify the update, are possible with wireless software upgrades. An illustration of the multi-level, cyber-physical nexus of electric vehicles, electric vehicle charging stations, and the power grid is shown in Fig. 1.Fig. 1 A schematic diagram of the multi-level, cyber-physical nexus of EVs, EVCSs, and the power grid Source: IEEE AccessSummarizing the Key PointsThe article discusses vulnerabilities in the Controller Area Network bus, Tire Pressure Monitoring System, and other physically accessible ports.ReferenceAcharya, Samrat, Yury Dvorkin, Hrvoje Pandzic, and Ramesh Karri. “Cybersecurity of Smart Electric Vehicle Charging: A Power Grid Perspective.” IEEE Access 8 (2020): 214434–53. https://doi.org/10.1109/access.2020.3041074.
Rakesh Kumar, Ph.D. On 2023-11-29   95
Robots

Securing the Future of Electric Vehicles - Addressing Cybersecurity Threats

Overview: This article discusses cybersecurity's importance for electric vehicles and their charging infrastructure, highlighting vulnerabilities and protective measures against cyberattacks.   Electric vehicles (EVs) have developed into one of the key technologies to help society meet challenging clean energy and decarbonization goals over the past ten years. The electric vehicle market has expanded by 60% annually on average. In the near future, this growth is anticipated to continue with even higher adoption rates. Electric Vehicle Advantages Many nations have implemented policies to promote the use of clean-fuel vehicles. The main obstacle to the adoption of electric vehicles is frequently identified as range anxiety. Recent advancements in battery and charging technology are reducing this range anxiety. For instance, the 100 kWh battery in the Tesla Model S is enough for a trip of up to 402 miles.    Similarly, electric vehicle charging stations and the infrastructure that supports them have grown significantly in size and number. At the end of the year, there were 7.3 million electric vehicle charging stations implemented worldwide, an increase of 60% from the previous year. Additionally, the electric vehicle charging stations now have a higher charging capacity and can provide faster charging services. These electric vehicle charging stations with a rated charging power of up to 350 kW have been recently developed. An electric vehicle can be charged using these chargers in under 15 minutes.   Smart electric vehicle charging features like remote control through smartphone apps are not only making electric vehicle charging faster but also more approachable and, therefore, more available to broader customer audiences.   Cyberattacks in Electric Vehicles Although significant and well-publicized cyberattacks have not yet targeted smart electric vehicle charging stations, threats and reasonable ways of attack have been reported. According to Kaspersky Lab, ChargePoint Home's smartphone electric vehicle charging app has security flaws. Through the charging device's WiFi connection, this flaw would allow a remote attacker to break into the charger and interfere with electric vehicle charging.    Cyberattacks might also target electric vehicle charging station web applications, such as those from Circontrol, an electric vehicle charging station vendor with over 80,000 electric vehicle charging stations in 60 nations. This flaw would make use of the poor login information for electric vehicle charging. These well-known vulnerabilities highlight the cyber risks associated with electric vehicles and electric vehicle charging stations. Protective Measures Against these Cyberattacks Because of these attacks and the social costs they produce, efforts are being made to standardize cyber-physical interfaces for both residential and commercial electric vehicle charging.    Electric vehicles and electric vehicle charging stations are vulnerable to attacks that could harm equipment due to non-standard cyber-physical interfaces. For a number of electric vehicle charging architectures, the European Network on Cybersecurity suggested security standards. These standards provide security for both electric vehicle charging stations and their possessions. It also secures communications between charging station operators and power grid operators.    The standard specifies access control, future security compatibility of charging stations, monitoring and controlling system security, and message encryption for secure communication. Additionally, due to flaws in these interfaces, it is possible to weaponize electric vehicles and use them to launch extensive demand-side cyberattacks against the power grid.    Demand-side cyberattacks on electricity grids involve manipulating appliances like electric vehicles, distributed energy resources, and heating, ventilation, and air conditioning (HVAC) loads. These appliances are internet-connected and have high power. Although such attacks on power grids have not occurred in the past, there is growing awareness among electric vehicle owners that they could be carried out using vulnerabilities that already exist. Power grid operators won't be able to handle them.  Smart Grids Cybersecurity A cyber-physical overview of the smart electric power grid is shown in Fig. 1. Resources that are IoT-enabled are still being used in all four power sectors, including generation, transmission, distribution, and customer service. However, by utilizing IoT-enabled devices, it also introduces new cyber threats to the power grid. An overview of these threats as they relate to smart grid cybersecurity can be found below. Fig. 1: A cyber-physical overview of the smart electric power grid Source: IEEE Access Stride Threat Model The STRIDE threat model, originally created by Microsoft to assess software threats, can be used to categorize cyberattacks. It is a categorical risk assessment model for spoofing, tampering, repudiation, integrity, denial-of-service (DoS), and elevation of privilege threats to a given cyber-physical system. Smart Grid Threats SCADA Threats SCADA is a centralized monitoring and control system that is frequently used in real-world power grids. It has four main parts: a central master terminal unit, a human-machine interface (HMI), field units like power line communications (PLC), remote terminal units (RTU), and communication channels. Despite having industry-standard defenses, the SCADA network is still susceptible to insider attacks.   SCADA Field Unit Threats Intelligent electronic devices (IEDs), PLCs, RTUs, and phasor measurement units (PMUs) are examples of SCADA field units. Relays, sensors, and breakers are examples of microprocessor-based IEDs. IEDs are monitored by RTUs, which send measurements to PLCs, SCADAs, or both. PLCs and SCADAs, in turn, use RTUs to communicate control signals to IEDs. This control capability of PLCs enables some control actions to be performed decentralized without involving SCADA.   The field units communicate with one another by using protocols. Additionally, these protocols are open to online threats. The system can become unstable if erroneous data is introduced into it.   Advanced Metering Infrastructure (AMI) Threats To allow interaction between the utility, consumers, and distributed energy resources (DERs), power grids are increasingly deploying AMI, such as smart meters. Residential consumers or prosumers may have IoT-enabled devices like smartphones linked to the exact same network as their smart meter, while commercial DER operators plan to protect their smart meter-connected network with a VPN. Smart meters and their communication channels are vulnerable to all types of cyberattacks because of this attack surface.   Demand Response Threats Demand response resources make use of AMIs and Smart meters, making them equally susceptible to threats. The data input and output of these devices can be manipulated causing problems to the grid operators.   Threats from Devices With IoT Intruders can get into high-wattage devices and appliances with IoT interfaces by taking advantage of weak passwords on local networks and the fact that they can connect to remote devices like smartphones and smart TVs, which are vulnerable to supply chain threats.    Electric Vehicle Charging Threats Cyberattacks on charging electric vehicles and the power grid pose greater social and economic risks. The charging methods can be wired charging or wireless charging, but the risks possessed are the same.   Summarizing the Key Points Cybersecurity is crucial for the growing electric vehicle industry and its charging infrastructure to prevent potential cyberattacks.Standardizing cyber-physical interfaces and implementing security measures are essential to protect electric vehicles and charging stations.Vulnerabilities in electric vehicle charging systems can be exploited, posing risks to equipment and potentially impacting power grids.The European Network on Cybersecurity has suggested security standards to safeguard communication between charging station operators and power grid operators.The rapid growth of electric vehicles and charging infrastructure necessitates a proactive approach to address cybersecurity challenges and ensure a secure and sustainable future. References [1] Acharya Samrat, Yury Dvorkin, Hrvoje Pandzic, and Ramesh Karri. “Cybersecurity of Smart Electric Vehicle Charging: A Power Grid Perspective.” IEEE Access 8 (2020): 214434–53. https://doi.org/10.1109/access.2020.3041074.
Rakesh Kumar, Ph.D. On 2023-06-20   158

Kynix

Kynix was founded in 2008, specializing in the electronic components distribution business. We adhere to honesty and ethics as our business philosophy and have gradually established an excellent reputation and credibility in our international business. With the accurate quotation, excellent credit, reasonable price, reliable quality, fast delivery, and authentic service, we have won the praise of the majority of customers.

Follow us

Join our mailing list!

Be the first to know about new products, special offers, and more.

Kynix

  • How to purchase

  • Order
  • Search & Inquiry
  • Shipping & Tracking
  • Payment Methods
  • Contact Us

  • Tel: 00852-6915 1330
  • Email: info@kynix.com
  • Follow Us

authentication

Kynix

© 2008-2026 kynix.com all rights reserve.