PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 6, 20260 citations

Physical-Layer Exploits on EV Chargers: Authentication and Systemic Protocol Weaknesses

View Full Paper
HSHetian ShiSSShangru SongYHYi He

Key Points

  • Examine security risks in electric vehicle charging protocols and their authentication mechanisms.
  • Investigated charging protocols including SAE J1772, CCS, IEC 61851, GB/T 20234, and NACS.
  • Demonstrated attack feasibility using PORTulator, a proof-of-concept attack hardware.
  • Evaluated vulnerabilities on real-world chargers with multiple charging standards.
  • Identified that chargers are prone to denial-of-service attacks through signal spoofing.
  • Highlighted risks of extortion and targeted sabotage due to weak authentication.
  • Proposed countermeasures involving enhanced authentication circuits and dynamic PWM signals.

Abstract

The proliferation of electric vehicles in recent years has significantly expanded the charging infrastructure while introducing new security risks to both vehicles and chargers. In this paper, we investigate the security of major charging protocols, including SAE J1772, CCS, IEC 61851, GB/T 20234, and NACS, and uncover new physical signal spoofing attacks in their authentication mechanisms. By inserting a compact malicious device into the charger connector, attackers can inject fraudulent signals to disrupt the charging process, resulting in denial-of-service, vehicle-induced charger lockout, and damage to the chargers or the vehicle’s charge management system. To demonstrate the feasibility of our attacks, we propose PORTulator, a proof-of-concept (PoC) attack hardware, including a charger gun plugin device for injecting physical signals and a wireless controller for remote manipulation. By evaluating PORTulator on multiple real-world chargers, we identify 7 charging standards used by 20 charger piles that are vulnerable to our attacks. These attack primitives are not merely protocol flaws, but practical cyber-physical threats that can be leveraged for service disruption, extortion, and targeted sabotage in public or fleet-dependent charging environments. The root cause is that chargers use simple physical signals for authentication and control, making them easily spoofed by attackers. To address this issue, we propose enhancing authentication circuits by integrating non-resistive memory components and utilizing dynamic high-frequency Pulse Width Modulation (PWM) signals to counter such physical signal spoofing attacks.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Shi et al. (2026) studied this question.

synapsesocial.com/papers/69fa8ef304f884e66b5316cfhttps://doi.org/10.1051/sands/2026012/pdf
Ask AI
Helpful
Bookmark
Share
View Full Paper