UK Government Funded Home EV Chargepoints Must Be “Smart” By July 2019

The UK Government announced earlier today that:

All government funded home chargepoints for electric vehicles must use innovative ‘smart’ technology from July 2019, the government announced today, fulfilling the commitment in the Road to Zero Strategy published earlier this year.

This means chargepoints must be able to be remotely accessed, and capable of receiving, interpreting and reacting to a signal. Smart charging can also reduce high peaks of electricity demands, minimising the cost of electric vehicles to the electricity system – and keeping costs down for consumers by encouraging off-peak charging.

Alongside this the government has also announced that they have maintained grants to install chargepoints at home and in the workplace at their current level of up to £500, making charging easier for consumers and ensuring that plug-in hybrids and battery electric vehicles can be used to their full potential.

Any “domestic” electric vehicle charging station manufacturers who feel they may be unable to meet the UK Government deadline using their in house resources may wish to contact the team here at V2G EVSE to obtain more information about our UK Department for Transport funded “smart” international standards compliant EVSE controller, particularly if vehicle-to-grid functionality is also of potential interest.

A picture is said to be worth a thousand words, so here’s what our proof of concept smart controller looks like:

Vulnerabilities in Connected EV Chargers Could Damage Home Networks?

Yesterday cybersecurity company Kaspersky Lab published a press release which claims that:

Kaspersky Lab experts have discovered that electric vehicle chargers supplied by a major vendor carry vulnerabilities that can be exploited by cyber-attackers, and the consequences of a successful attack could include damage to the home electricity network. While modern electric vehicles are tested constantly for vulnerabilities, this research reveals that some of their essential accessories, such as battery chargers, may remain at risk.

For more information on the electric vehicle charger vulnerabilities discovered by Kaspersky Lab, read the full report on Securelist.com.

The “major vendor” referred to is not identified in the press release, but the full report on Securelist reveals that ChargePoint, Inc. is the company in question.

Kaspersky continue:

The researchers found a way to initiate commands on the charger, to either stop the charging processor or set it to the maximum current possible. While the first option would only prevent a person from using the car, the second one could potentially cause the wires to overheat on a device that is not protected by a trip fuse. If compromised, the connected charger could therefore cause a power overload that would take down the network to which it was connected. This could result in significant financial impact and, in the worst-case scenario, damage to other devices connected to the network.

To change the amount of electricity being consumed, all that an attacker would need to do is obtain access to the Wi-Fi network that the charger is connected to. Since the devices are designed for home users, security for the wireless network is likely to be limited. This means that attackers could easily gain access, for example, by bruteforcing all possible password options – a common method of attack. According to Kaspersky Lab statistics, 94 percent of attacks on IoT in 2018 came from Telnet and SSH password bruteforcing. Once inside the wireless network, the intruders can easily find the charger’s IP address, which, in turn, will allow them to exploit any vulnerabilities and disrupt operations.

All the vulnerabilities discovered by Kaspersky Lab researchers were reported to the vendor and have now been patched.

The final paragraph is a relief, but here are Kaspersky Lab’s suggestions for avoiding similar problems in the future:

To protect your smart devices, including electric vehicle accessories:

  1. Regularly update all your smart devices to the latest software versions. Updates may contain patches for critical vulnerabilities, which, if left unpatched, could give cybercriminals access to your home and private life.
  2. Do not use the default password for Wi-Fi routers and other devices. Immediately after install, change it to a strong password, and do not use the same password for several devices.
  3. It is recommended to isolate the smart home network from the network used by your or your family’s personal devices for basic internet searching. This is to ensure that if a device is compromised with malware, your smart home system will not be affected.