Search NASA⌕ Search

Engineering topics

Carroll, Thomas E.

Publications and source records attributed to Carroll, Thomas E..

The Design and Evaluation of Zero Trust Architecture for Electric Vehicle Charging Infrastructure: EVs @ Scale Series on EV Charging Station Cybersecurity

Implementing a zero trust architecture can significantly bolster the security of electric vehicle (EV) charging infrastructure. EV charging infrastructure includes numerous networked interfaces, each of which can present potential vulnerabilities. When these vulnerabilities are exploited, they can compromise the entire system, leading to severe operational and security risks. Zero trust is a security model that operates on the principle of "never trust, always verify," which helps manage the attack surface and limit the scope of any potential compromises. Fundamentally, this model ensures that no entity, whether inside or outside the network, is trusted by default. The design principles of zero trust include continuous verification, strict deny-by-default access controls, and micro-segmentation. Continuous verification ensures that every request is thoroughly checked, regardless of its origin. Strict access controls enforce the principle of least privilege, allowing users and devices only the minimum necessary access to perform their functions. Micro-segmentation involves dividing the network into smaller, isolated segments to prevent lateral movement in case of a breach. In the context of EV charging infrastructure, zero trust can be implemented through various strategies. For example, multi-factor authentication (MFA) can be required for engineers to access the management interfaces and control systems of charging stations. Real-time monitoring and analysis of network traffic can help detect and respond to anomalies. Systems that do not need to communicate with each other can be micro-segmented to enhance security. All communications should adhere to predefined policies to be permitted. Additionally, encrypting communications can protect sensitive information exchanged between chargers and management systems. This paper presents a zero trust architecture specifically designed for EV charging infrastructure. Implementing zero trust not only mitigates risks but also builds a resilient infrastructure capable of withstanding and quickly recovering from cyber threats. The architecture addresses six defined security objectives. A comprehensive test plan is developed to assess the architecture against these objectives, and the results of the evaluation are reported. This approach is essential for maintaining the reliability and integrity of EV charging services in an increasingly interconnected and vulnerable digital landscape. This is the first in a planned series of papers exploring the implementation of zero trust in EV charging infrastructure. Each paper will delve into different aspects and applications of zero trust, highlighting how various work processes and requirements can lead to distinct architectural designs. These architectures will be tailored to address specific security challenges and operational needs within the EV charging ecosystem, ensuring a robust and adaptable security framework.

33 ADVANCED PROPULSION SYSTEMS↗

Slide Decks for EV@S Stakeholder Meeting at INL September 2024

These slides were used at the Electric Vehicles at Scale National Lab Consortium, Stakeholder Meeting hosted at INL in September 2024. The slides are now requested to be made available publicly for reference. All slides review projects that are already in the public domain and their information is intended for public release. They are not from sensitive topics or areas with any restrictions. A few projects are overviewed in detail and some slides were just an aid to the breakout sessions that were conducted with stakeholders and lab staff.

25 ENERGY STORAGE↗

Exploring the Adoption Challenges of Post-Quantum Cryptography in EV Charging Infrastructure

The rapid evolution of electric vehicle (EV) technology and the corresponding growth of the Electric Vehicle Charging Infrastructure (EVCI) brings to light significant cybersecurity concerns, notably in the context of emerging post-quantum computing capabilities. This report, prepared by Pacific Northwest National Laboratory (PNNL) under the U.S. Department of Energy contract, delves into the challenges associated with integrating Post-Quantum Cryptography (PQC) into EVCI to safeguard against potential quantum computing threats. Post-quantum computers will eventually be able to invalidate technologies secured through public key cryptography. As part of this effort, the primary gaps and challenges in the EVCI were investigated with a focus on comparing traditional algorithms against PQC algorithms. One of the notable findings was that the P-521 algorithm was frequently surpassed in performance by PQC algorithms. This document provides a thorough examination of the hurdles the industry can expect when transitioning to PQC within the EVCI, such as interoperability concerns, the computational and memory demands of PQC algorithms, and the organizational readiness for such a transition. It emphasizes the necessity of a forward-thinking approach to cybersecurity, advocating for early and strategic engagement among EVCI stakeholders to ensure a seamless and cost-effective migration to quantum-resistant cryptographic standards. Through this report, the authors aim to catalyze awareness and action among policymakers, industry leaders, and cybersecurity professionals towards fortifying the EVCI against emerging quantum threats, thereby securing the infrastructure essential for the future of electric mobility.

33 ADVANCED PROPULSION SYSTEMS↗

2024 Electric Vehicles at Scale Semiannual Stakeholder Meeting

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Lab Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. This network will be critical to support tens of millions of light-, medium-, and heavy-duty EVs on American roads by 2030. The EVs@Scale Lab Consortium brings together national laboratories and key stakeholders to conduct infrastructure research and development (R&D) that advances innovations in, and sets unified standards for, high-power and wireless charging. The effort will also develop technologies to integrate vehicle charging with the power grid, and develop cybersecurity measures to protect drivers, vehicles, equipment, and the grid. The first hybrid EVs@Scale Lab Consortium Semiannual Stakeholder Meeting was held at ANL on September 27-28, 2023, to identify research, development, and deployment needs to accelerate technology development for electric vehicles at scale and explore opportunities for collaboration across government, academia, and industry.

advanced charging and grid interface technologies↗

Motivation and Design of the OCPP Security Service

Pacific Northwest National Laboratory is conducting in-depth research aimed at exploring how zero trust security principles can be effectively applied to electric vehicle charging infrastructure. This investigation seeks to enhance the resilience and reliability of these systems against cyber threats, ensuring secure and uninterrupted access to charging services for electric vehicle users and electric supply. Zero trust is a security concept centered on the belief that system operators should not automatically trust users or systems based on their location, whether inside or outside the organization, but instead must verify everything trying to connect to their systems before granting access. A key aspect of the project is to demonstrate and validate zero trust approaches targeted to electric vehicle (EV) charging infrastructure. It has been observed that both open-source and commercial solutions often overlook the specific protocols employed in managing EV charging stations and proceeded with a general, protocol-agnostic approach. While these strategies effectively block non-authorized routes to the charging infrastructure, they do not tackle the situations where attackers may exploit legitimate access channels, such as the inattentive operator model posited by the Idaho National Laboratory. To address this gap, this paper proposes and discusses a new security service targeted to the Open Charge Point Protocol (OCPP), which is the de facto protocol for the management of charging stations and serves a critical role in the broader adoption of electric vehicles. The design and architecture of the proposed OCPP security service are discussed in detail, outlining how it aims to safeguard charging station management system (CSMS) functions. The service is particularly important in scenarios where the charging station operator (CSO), responsible for the maintenance and operation of charging stations, and the charging network provider (CNP), which manages the charging network's accessibility and billing, are separate entities. This distinction is crucial because CSOs and CNPs often have different priorities, objectives, and operational responsibilities, which may not always align perfectly. For instance, a CSO might prioritize uptime and customer satisfaction, while a CNP might focus on maximizing revenue and network utilization. Such misalignment can create security vulnerabilities, as each entity might implement different policies and standards, potentially leaving gaps in the overall security posture.

33 ADVANCED PROPULSION SYSTEMS↗

EVs@Scale Lab Consortium Semi-Annual Stakeholder Meeting

The U.S. Department of Energy (DOE) Electric Vehicles at Scale Lab Consortium (EVs@Scale Lab Consortium) is accelerating research to support the establishment of a secure and scalable national network of charging infrastructure. This network will be critical to support tens of millions of light-, medium-, and heavy-duty EVs on American roads by 2030. The EVs@Scale Lab Consortium brings together national laboratories and key stakeholders to conduct infrastructure research and development (R&D) that advances innovations in, and sets unified standards for, high-power and wireless charging. The effort will also develop technologies to integrate vehicle charging with the power grid, and develop cybersecurity measures to protect drivers, vehicles, equipment, and the grid. The first hybrid EVs@Scale Lab Consortium Semiannual Stakeholder Meeting was held at ANL on September 27-28, 2023, to identify research, development, and deployment needs to accelerate technology development for electric vehicles at scale and explore opportunities for collaboration across government, academia, and industry.

advanced charging and grid interface technologies↗

Computing system operational methods and apparatus

Computing system operational methods and apparatus are described. According to one aspect, a computing system operational method includes accessing user information regarding a user logging onto a computing device of the computing system, processing the user information to determine if the user information is authentic, as a result of the processing determining that the user information is authentic, first enabling the computing device to execute an application segment, and as a result of the processing determining that the user information is authentic, second enabling the application segment to communicate data externally of the computing device via one of a plurality of network segments of the computing system.

Edgar, Thomas W.↗

Improving Resiliency for Electric Vehicle Charging

Electric vehicles are seeing growing adoption. However, challenges with range anxiety persists. While charging infrastructure is anticipated to expand, EV charger systems have not been as robust to challenges. This paper discusses potential outage conditions associated with EV charging and presents new technology in development to improve EV charging resilience.

Electric vehicle charging, electric vehicle chargi↗

Inventory of Public Key Cryptography in US Electric Vehicle Charging

Electric vehicles (EVs) and charging infrastructure are networked systems, which employ high-level communications in support of charging and grid service decisions. Public key cryptography (PKC) underlies much of the security and privacy protections of the information exchange. We are entering a new epoch where quantum computing threats must be seriously considered. A sufficiently large quantum computer, so named Cryptographically Relevant Quantum Computer (QRQC), will be able to perform the mathematical operations to efficiently attack the underpinnings of traditional PKC, thus jeopardizing the digital foundations for trust, communications security, and data security. Estimates suggest a QRQC can break public key encryption and digital signatures in the manner of tens to hundreds of hours, compared to traditional computing that would demand more than 10 18 years in a brute force-style attack. A consensus belief of quantum theorists, quantum experimenters, and cryptographers suggest that the quantum threat will be likely realized in the next twenty years. To address the threat, post-quantum cryptography, which is cryptosystems that are designed to be secure against both traditional and quantum computing threats, must be adopted. Migration from traditional PKC to quantum-resilient cryptography is a global undertaking and likely represents the largest transition in computing history. The nascent state of EV public key infrastructure, combined with limited adoption of the vehicle secure charging features, presents an opportunity to establish a preference for quantum-resistant cryptography as a step on the migration path. Delays will stunt the efforts as rapidly accelerating EVs sales and huge infrastructure investments will create large growing bases of long-lived vehicles and infrastructure. Migration preparations can commence while NIST continues the process to standardize post-quantum cryptography (PQC), which are quantum-resilient algorithms designed to be secure against traditional and quantum computing threats. The first step in preparing EV charging is to identify the presence of traditional public key cryptography algorithms and applications. With this objective in mind, this report is intended to advise the vehicle manufacturers, charging station manufacturers, charging station operators, charge network providers and other EV charging stakeholders with information on traditional PKC application and the potential risks when PKC becomes insecure. This report, the first in a series of reports discussing the topics existing at the confluence of post-quantum cryptography adoption and EV charging, identifies traditional public key applications employed and identifies potential consequences of leaving EV charging infrastructure vulnerable to quantum computing. The focus remains squarely on the of EV charging and infrastructure with respect to PKC and is believed by the authors to complement the NIST SP 1800-38 Migration to Post-Quantum Cryptography. While the report is centered on infrastructure, there are implications to vehicles.

33 ADVANCED PROPULSION SYSTEMS↗

Sample Cybersecurity Clauses for EV Charging Infrastructure Procurements

This is the final version of PNNL-34373, with sponsor updates. The proposed sample cybersecurity clauses for EVCI procurements are designed to assist in managing the risk of cyberattacks that may degrade the safety, security, and reliability of EVCI. The sample clauses are intended to be tailored and incorporated into procurement specifications for equipment and services related to the National EV Infrastructure Formula Program deployments. Widespread adoption of the sample cybersecurity procurement language will integrate cybersecurity throughout the life cycle of the infrastructure.

33 ADVANCED PROPULSION SYSTEMS↗