[论文解读] Brokenwire : Wireless Disruption of CCS Electric Vehicle Charging
Brokenwire 提出了一种新颖的无线拒绝服务攻击,通过在未屏蔽的电力线通信(PLC)链路上引入电磁干扰,破坏联合充电系统(CCS)电动汽车充电。该攻击可使用市售无线电设备在长达47米外执行,无需用户交互且技术门槛极低,通过中断控制信号导致充电会话中止。
We present a novel attack against the Combined Charging System, one of the most widely used DC rapid charging technologies for electric vehicles (EVs). Our attack, Brokenwire, interrupts necessary control communication between the vehicle and charger, causing charging sessions to abort. The attack requires only temporary physical proximity and can be conducted wirelessly from a distance, allowing individual vehicles or entire fleets to be disrupted stealthily and simultaneously. In addition, it can be mounted with off-the-shelf radio hardware and minimal technical knowledge. By exploiting CSMA/CA behavior, only a very weak signal needs to be induced into the victim to disrupt communication - exceeding the effectiveness of broadband noise jamming by three orders of magnitude. The exploited behavior is a required part of the HomePlug Green PHY, DIN 70121 & ISO 15118 standards and all known implementations exhibit it. We first study the attack in a controlled testbed and then demonstrate it against eight vehicles and 20 chargers in real deployments. We find the attack to be successful in the real world, at ranges up to 47 m, for a power budget of less than 1 W. We further show that the attack can work between the floors of a building (e.g., multi-story parking), through perimeter fences, and from `drive-by' attacks. We present a heuristic model to estimate the number of vehicles that can be attacked simultaneously for a given output power. Brokenwire has immediate implications for a substantial proportion of the around 12 million battery EVs on the roads worldwide - and profound effects on the new wave of electrification for vehicle fleets, both for private enterprise and crucial public services, as well as electric buses, trucks and small ships. As such, we conducted a disclosure to the industry and discussed a range of mitigation techniques that could be deployed to limit the impact.
研究动机与目标
- 识别并利用联合充电系统(CCS)中的关键漏洞,实现对电动汽车充电会话的远程无线干扰。
- 评估电磁干扰(IEMI)对未屏蔽充电电缆中CCS电力线通信(PLC)的实际可行性与现实影响。
- 证明该攻击可使用低成本市售无线电设备和极少技术知识实施,从而对车队或单个车辆造成大规模干扰。
- 评估该漏洞在多种现实部署环境中的影响,包括公共充电站、多层建筑以及物理障碍物之后的情况。
- 提出并评估缓解策略,特别是基于软件的重新认证和“即插即充”机制,以降低攻击影响。
提出的方法
- 在测试平台环境中开展受控实验,分析CCS PLC在有意电磁干扰下的行为。
- 部署自制的低功耗无线电发射器,在CCS系统中使用的HomePlug Green PHY PLC频段发射定向电磁噪声。
- 在18个充电站和7辆电动汽车上开展真实环境实地测试,涵盖公共充电站和多层停车结构。
- 测量通信中断的有效范围达47米,并评估信号在墙体、围栏及楼层之间的传播情况。
- 开发启发式模型,基于发射功率和天线增益估算可同时干扰的车辆数量。
- 评估缓解策略,包括通过近距离引导(Proximity Pilot)和“即插即充”实现的自动重新认证,以减轻单次攻击的影响。
实验结果
研究问题
- RQ1是否可以不依赖物理接触,仅通过电磁干扰破坏电动汽车充电系统中的CCS电力线通信(PLC)?
- RQ2使用市售硬件实现无线远程干扰CCS充电会话的有效范围和功率预算是多少?
- RQ3该攻击在真实环境中的表现如何,包括穿墙、跨楼层以及在多车充电站中的表现?
- RQ4现有CCS实现中,通信恢复后自动恢复失败的程度有多大?
- RQ5哪些基于软件的缓解策略可有效降低此类攻击的影响,且无需硬件改动?
主要发现
- Brokenwire攻击在使用低于1瓦发射功率的情况下,成功在长达47米的距离内中断CCS充电会话。
- 该攻击在穿墙、穿越围栏以及多层停车结构中跨楼层均有效,证明了其在真实环境中的可行性。
- 在真实部署中测试的所有车辆和充电设备在通信中断时均中止了充电会话,且无自动重连机制。
- 该攻击可使用市售无线电设备和极少技术知识实施,显著降低了攻击者的进入门槛。
- 开发了启发式模型,可基于发射功率和天线增益估算可同时干扰的车辆数量。
- 基于软件的缓解策略,如通过近距离引导(Proximity Pilot)和“即插即充”实现的自动重新认证,被证明可显著降低单次攻击的影响。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。