论文标题
电动汽车充电协议的安全性
Security of EV-Charging Protocols
论文作者
论文摘要
电动汽车充电领域涉及参与者,设备,网络和协议的复杂组合。这些协议正在开发,而没有明确关注安全性。在本文中,我们概述了荷兰使用的主要角色和协议。我们描述了一个明确的攻击者模型和安全要求,表明鉴于这许多协议有安全问题,并提供了有关如何解决这些问题的建议。最重要的结论是需要端到端的安全性,以便在静止状态下数据和长期真实性。此外,我们强调需要改善EV驱动器的身份验证,例如通过使用银行卡。对于通信链接,我们建议强制使用TLS,TLS选项和配置的标准化以及使用TLS客户端证书改进身份验证。
The field of electric vehicle charging involves a complex combination of actors, devices, networks, and protocols. These protocols are being developed without a clear focus on security. In this paper, we give an overview of the main roles and protocols in use in the Netherlands. We describe a clear attacker model and security requirements, show that in light of this many of the protocols have security issues, and provide suggestions on how to address these issues. The most important conclusion is the need for end-to-end security for data in transit and long-term authenticity for data at rest. In addition, we highlight the need for improved authentication of the EV driver, e.g. by using banking cards. For the communication links we advise mandatory use of TLS, standardization of TLS options and configurations, and improved authentication using TLS client certificates.