Temporal Convolutional Network Approach to Secure Open Charge Point Protocol (OCPP) in Electric Vehicle Charging
Not Available
SEARCH · Search NASA
Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.
Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.
Not Available
With the growing adoption of Electric Vehicles (EVs), there is an increasing need for a reliable EV charging infrastructure. To help meet this need, the report “Recommendations for Minimum Required Error Codes for Electric Vehicle Charging Infrastructure,” recommends a set of minimum required error codes (MRECs) and their functional and responsibility classification. Charger manufacturers, charging station operators, EV manufacturers, and other stakeholders in the North American market are encouraged to uniformly adopt the MRECs to enhance EV charging error reporting, interpretation, and diagnostics. This document serves as a guide to enable uniform implementation of the MRECs using the Open Charge Point Protocol (OCPP).
The electric vehicles (EVs) market keeps growing globally; thus, it is critical to secure the EV charging communication protocols in order to guarantee reliable and fair charging operations among the customers. The Open Charge Point Protocol (OCPP) 2.0.1 supports the communication between the Electric Vehicle Supply Equipment (EVSE) and Charging Station Management Systems (CSMSs); therefore, it becomes vulnerable to several types of attacks, which aim to jeopardize smart charging, billing, and energy management. Specifically, OCPP 2.0.1 allows the self-reporting of the State of Charge (SOC) values, which makes it vulnerable to spoofing-based cyberattacks, which target manipulating the scheduling priorities, distorting the load forecasts, and extending the charging sessions in an unfair manner. In this paper, we try to address this type of attack by providing a comprehensive analysis of the SOC spoofing attacks and introducing a novel unsupervised detection framework based on the One-Class Support Vector Machine (OCSVM) algorithm. Specifically, two types of attack scenarios are analyzed (i.e., priority manipulation and session extension) by deriving engineered features that capture the nonlinear relationships under normal charging behavior. Detailed simulation-based results are derived by utilizing the DESL-EPFL Level 3 EV charging dataset. Our results demonstrate high F1-score and recall in identifying spoofed SOC values and that the proposed OCSVM model demonstrates superior performance compared to alternative clustering and deep-learning based detectors.
Pacific Northwest National Laboratory is conducting in-depth research aimed at exploring how zero trust security principles can be effectively applied to electric vehicle charging infrastructure. This investigation seeks to enhance the resilience and reliability of these systems against cyber threats, ensuring secure and uninterrupted access to charging services for electric vehicle users and electric supply. Zero trust is a security concept centered on the belief that system operators should not automatically trust users or systems based on their location, whether inside or outside the organization, but instead must verify everything trying to connect to their systems before granting access. A key aspect of the project is to demonstrate and validate zero trust approaches targeted to electric vehicle (EV) charging infrastructure. It has been observed that both open-source and commercial solutions often overlook the specific protocols employed in managing EV charging stations and proceeded with a general, protocol-agnostic approach. While these strategies effectively block non-authorized routes to the charging infrastructure, they do not tackle the situations where attackers may exploit legitimate access channels, such as the inattentive operator model posited by the Idaho National Laboratory. To address this gap, this paper proposes and discusses a new security service targeted to the Open Charge Point Protocol (OCPP), which is the de facto protocol for the management of charging stations and serves a critical role in the broader adoption of electric vehicles. The design and architecture of the proposed OCPP security service are discussed in detail, outlining how it aims to safeguard charging station management system (CSMS) functions. The service is particularly important in scenarios where the charging station operator (CSO), responsible for the maintenance and operation of charging stations, and the charging network provider (CNP), which manages the charging network's accessibility and billing, are separate entities. This distinction is crucial because CSOs and CNPs often have different priorities, objectives, and operational responsibilities, which may not always align perfectly. For instance, a CSO might prioritize uptime and customer satisfaction, while a CNP might focus on maximizing revenue and network utilization. Such misalignment can create security vulnerabilities, as each entity might implement different policies and standards, potentially leaving gaps in the overall security posture.
High-power charging (HPC) concept will be a critical enabler for the wide-scale adoption and integration of electric vehicles (EVs). HPC hubs will have a significant impact on achieving this goal, particularly when considering the charging requirements of next-generation medium and heavy-duty vehicles (MD/HD) used in various vocational scenarios. This emphasizes the significance of evaluating and confirming the technical planning and multi-level operation of HPC hubs through modeling, protocol implementation, and simulation before hardware demonstration. The focus of this study is to develop the architecture, modeling, communication, and real-time controller hardware-in-the-loop (C-HIL) simulation of HPC hubs using the DC distribution system approach. Specifically, this work demonstrates the practical implementation of a custom Smart Energy Management System (SEMS) for a real-time C-HIL HPC hub simulation using the Open Charge Point Protocol (OCPP) for communication. OCPP is implemented on the Node-Red framework and the custom controller is executed in Python. We developed a rule-based controller to demonstrate the proposed approach.
Open source Node-Red "nodes" to support the Open Charge Point Protocol (OCPP) 2.0.1 protocol.
An MQTT (Message Queuing Telemetry Transport) and OCPP (Open Charge Point Protocol) based remote smart charging controller framework for AC Electric Vehicle Supply Equipments (EVSEs). The code in this repo allows for the National Laboratory of the Rockies (NLR) controls to interface with the real Distributed Energy Resource Management System (DERMS) and EVSEs in NLR's ESIF Optimization and Control Laboratory (OCL). Different charge management algorithms can be tested to determine which power allocation method is most effective with the overall goal of demonstrating clear and well documented test results as well as providing functional control algorithms which could be utilized to provide effective smart charge management (SCM) at EV charging stations. Different power allocation methods are programmed in lab_demo_controller.py and include allocation based on first come first served, equal sharing, state of charge (SOC), priority factors, and behind the meter control methods.
The rapid growth of electrified transportation, including light- and medium-duty electric vehicles (EVs) as a mobility solution requires a reliable EV-charging infrastructure. To advance charging reliability, the ChargeX Consortium reports “Recommendations for Minimum Required Error Codes for Electric Vehicle Charging Infrastructure” and “Implementation Guide for Minimum Required Error Codes in Electric Vehicle Charging Infrastructure” provided recommendations for a set of minimum required error codes (MRECs), their functional and responsibility classifications, and a guide for their implementation, using Open Charge Point Protocol (OCPP) versions 1.6J4 and 2.0.1.5 These reports outline a recommended practice for consistent error reporting and interpretation, which is essential for communicating issues uniformly across the complex and diverse EV-charging ecosystem. However, MRECs are just one part of diagnosing issues; another critical part is obtaining enough information about the current state and performance of the various charging components to identify root causes for each of the error codes. This additional diagnostics data can be used by technicians or automated systems to understand the context around an issue, allowing for timely resolution, decreased maintenance costs, and increased charging reliability. During everyday operations, data are regularly collected and analyzed across the ecosystem. Although sharing of all that available data would be great for diagnostics, concerns on data ownership, privacy, and original equipment manufacturer (OEM) intellectual property pose a challenge. To overcome this obstacle, this report proposes a set of minimum required diagnostic information (MRDI) and recommends that the industry implement these uniformly across the North American EV charging ecosystem. MRDI provides a means to exchange only data deemed necessary for root cause determination.
Open Charge Point Protocol (OCPP) 1.6 is widely used in the electric vehicle (EV) charging industry to communicate between Charging System Management Services (CSMSs) and Electric Vehicle Supply Equipment (EVSE). Unlike OCPP 2.0.1, OCPP 1.6 uses unencrypted websocket communications to exchange information between EVSE devices and an onpremise or cloud-based CSMS. In this work, we demonstrate two machine-in-the-middle (MITM) attacks on OCPP sessions to terminate charging sessions and gain root access to the EVSE equipment via remote code execution (RCE). Second, we demonstrate a malicious firmware update with a code injection payload to compromise an EVSE. Lastly, we demonstrate two methods to prevent availability of the EVSE or CSMS. One of these, originally reported by SaiFlow, prevents traffic to legitimate EVSE equipment using a DoS-like attack on CSMSs by repeatedly connecting and authenticating several CPs with the same identities as the legitimate CP. These vulnerabilities were demonstrated with proof-of-concept exploits in a virtualized Cyber Range at Wright State University and/or with a 350 kW Direct Current Fast Charger (DCFC) at Idaho National Laboratory. The team found that OCPP 1.6 could be protected from these attacks by adding secure shell (SSH) tunnels to the protocol, if upgrading to OCPP 2.0.1 was not an option. Index Terms—Electric vehicle charging, cybersecurity, OCPP, cyberattack, cyber-resilience. INSPEC Accession Number: 23981565
To systematically improve the public charging experience, EV charging industry stakeholders need to define and measure it precisely. Many stakeholders currently measure aspects of the charging experience, but they typically employ metrics that are either operational in nature, such as charger uptime and mean time between failures, or composite customer satisfaction indices. To improve the customer experience most effectively, the industry needs metrics that define the charging experience from the perspective of the customer, not business operations. Furthermore, industry practitioners need granular metrics to know what specific aspects of the charging experience need improvement. This report defines such customer-focused metrics, called key performance indicators (KPIs).
The Electric Vehicle Secure Architecture Laboratory Demonstration (EV SALaD) program is a demonstration of cybersecurity best practices for high-power electric vehicle (EV) charging infrastructure led by Idaho National Laboratory (INL), in collaboration with other DOE National Laboratories participating in the EVs at Scale Consortium.a Sandia National Laboratories (SNL) and Pacific Northwest National Laboratory (PNNL) participated in the first 2-year (FY22-23) demonstration cycle for EV SALaD. This report documents the FY23 demonstration, the second in a series of demonstrations and collaborations in deploying and operating cybersecure EV charging infrastructure. It includes a summary of improvements from the FY22 demonstration, technical analysis of the FY23 demonstration, how the research demonstrates cyber-physical and cybersecurity best practices for high-power EV charging infrastructure, and related impacts to national and energy security. For EV SALaD, the FY22 demonstration focused on the detection, ranking, and prioritization of anomalous events for high-power EV charging. The FY23 demonstration additionally included the demonstration of cybersecurity best practices, which included protection and mitigation solutions to prevent, respond, and recover from anomalous events. During the demonstrations, the multi-lab EV SALaD team conducted a Test Effect Payload (TEP)b evaluation on extreme fast charger (XFC) hardware equipped with Cerberus, a detection and response solution, to demonstrate anomaly detection and mitigation cybersecurity best practices against cyber-enabled events.
To systematically improve the public charging experience, EV charging industry stakeholders need to define and measure it precisely. Many stakeholders currently measure aspects of the charging experience, but they typically employ metrics that are either operational in nature, such as charger uptime and mean time between failures, or composite customer satisfaction indices. To improve the customer experience most effectively, the industry needs metrics that define the charging experience from the perspective of the customer, not business operations. Furthermore, industry practitioners need granular metrics to know what specific aspects of the charging experience need improvement. This report defines such customer-focused metrics, called key performance indicators (KPIs).
The Open Charge Point Interface (OCPI) is an open protocol that enables electric vehicle (EV) charging systems to work together across networks. It supports communication and data sharing between Charge Point Operators (CPOs), who manage charging stations, and e-Mobility Service Providers (eMSPs), who provide charging services to EV drivers. OCPI facilitates functions like user authorization, remote charge point control, charging session data exchange, and billing through Charge Detail Records (CDRs). This allows EV roaming, so drivers can charge at different networks without multiple accounts. As the EV market grows due to increased adoption and technological advancements, OCPI faces higher demands. This has revealed issues with CDR format consistency, timestamp standardization across regions, transmission of EV-side error codes for troubleshooting, and support for new use cases. These challenges can affect operations and user experience, particularly as the industry starts considering Vehicle-to-Grid (V2G) systems, where EVs supply energy to the grid, and Vehicle-to-Everything (V2X) technologies for broader energy interactions. Using feedback from the ChargeX Diagnostics taskforce discussions, industry 1-on-1 meetings, technical standards, and OCPI’s evolution through versions (e.g., OCPI 2.1.1, 2.2, and 2.2.1), this report identifies these issues and suggests practical recommendations. These aim to improve interoperability, streamline operations, and prepare OCPI for future trends in the EV charging ecosystem.
Nearly 30% of commercial building energy use is wasted due to equipment faults and HVAC controls problems. The result is increased emissions, compromised comfort and productivity, and less reliable coordination of building power needs with a clean grid. The energy impact alone represents $17 billion in potential savings. Today’s smart building software provides a robust solution to address these operational deficiencies. Energy management and information systems (EMIS) are saving up to 9% on average, with two-year paybacks. They are being incorporated into energy management processes, commissioning services, and utility programs. As effective as they are, two barriers prevent even deeper benefits; limited personnel to fix problems once they are identified, and the expense and time to manually implement changes in control systems. In partnership with the research community, the EMIS industry is developing new capabilities to overcome these barriers. Moving beyond siloed products for either fault detection and diagnostics, or optimal control, these new capabilities empower users to not only automatically identify faults, but also to push corrective action, and control improvements to their buildings. In this paper, several areas for enhancements are documented: ‘one-time’ correction of faults such as setpoints, schedules, and economizer lockouts; short-term active testing for automated proportional integral derivative (PID) loop tuning and functional testing; and continuous supervisory control for demand flexibility and year-round efficiency. Results are presented from a pair of partner implementations out of a dozen providers integrating these enhancements into their products, including field tests from across the country, and insights into operator acceptance and integration into operations and maintenance practices.