OCPP in the spotlight: threats and countermeasures for electric vehicle charging infrastructures 4.0

TitleOCPP in the spotlight: threats and countermeasures for electric vehicle charging infrastructures 4.0
Publication TypeJournal Article
Year of PublicationIn Press
AuthorsC. Alcaraz, J. Cumplido, and A. Triviño
JournalInternational Journal of Information Security
PublisherSpringer
Place PublishedSpringer Verlag
ISSN Number1615-5262
Abstract

Undoubtedly, Industry 4.0 in the energy sector improves the conditions for automation, generation and distribution of energy, increasing the rate of electric vehicle manufacturing in recent years. As a result, more grid-connected charging infrastructures are being installed, whose charging stations (CSs) can follow standardized architectures, such as the one proposed by the open charge point protocol (OCPP). The most recent version of this protocol is v.2.0.1, which includes new security measures at device and communication level to cover those security issues identified in previous versions. Therefore, this paper analyzes OCPP-v2.0.1 to determine whether the new functions may still be susceptible to specific cyber and physical threats, and especially when CSs may be connected to microgrids. To formalize the study, we first adapted the well-known threat analysis methodology, STRIDE, to identify and classify threats in terms of control and energy, and subsequently we combine it with DREAD for risk assessment. The analyses indicate that, although OCPP-v2.0.1 has evolved, potential security risks still remain, requiring greater protection in the future.

URLhttps://link.springer.com/article/10.1007/s10207-023-00698-8
DOI10.1007/s10207-023-00698-8
Citation KeyAlcaraz2023b