The Southwest Research Institute (SwRI) team has uncovered security weaknesses in electric vehicle (EV) systems that utilize direct current fast-charging technology. This high-voltage setup depends on power line communication (PLC) to exchange data between EVs and charging stations. During their research, SwRI engineers discovered that vulnerabilities in the PLC layer allowed them to access sensitive network keys and digital addresses associated with both the charging units and the vehicles.
Katherine Kozan, the lead engineer for SwRI’s high-reliability systems department, noted, “Our penetration testing revealed that the PLC layer was inadequately secured, lacking essential encryption for communication between vehicles and chargers.” The team observed that older chips featured unsecured key generation, a known issue corroborated by their online research.
This study is part of SwRI’s broader initiative to enhance automotive cybersecurity across embedded systems and smart-grid infrastructure. It builds on their 2020 project, where they demonstrated vulnerabilities in a J1772 charger by disrupting its operation with a lab-created spoofing device.
In their latest work, SwRI examined vehicle-to-grid (V2G) technologies following ISO 15118 standards for communication between EVs and electric vehicle supply equipment (EVSE). “As the grid accommodates more electric vehicles, safeguarding our critical infrastructure against cyber threats and ensuring secure payment systems for EV charging are crucial,” explained Vic Murray, assistant director of SwRI’s high-reliability systems department. “Our findings indicate significant areas for improvement.”
The team developed an adversary-in-the-middle (AitM) device, incorporating custom software and a modified charging system interface. This device enabled them to intercept and analyze data traffic between EVs and EVSEs, identifying network membership keys and monitoring network activity. “Introducing encryption to protect network membership keys is a crucial step toward securing the V2G charging process,” remarked FJ Olugbodi, an engineer on the project. “Without secure access keys, attackers could easily retrieve and reprogram nonvolatile memory regions on PLC-enabled devices, potentially leading to harmful firmware corruption.”
SwRI acknowledged that implementing encryption in embedded vehicle systems presents challenges, such as potential safety risks from authentication or decryption failures, which might affect vehicle performance or functionality. To address these issues, SwRI is developing a zero-trust architecture that integrates multiple embedded systems through a unified cybersecurity protocol. Future research will test zero-trust solutions for PLC and other network layers to strengthen EV cybersecurity.



