The field of electric vehicle charging involves a complex combination of actors, devices, networks, and protocols. These protocols are being developed without a clear focus on security. In this paper, we give an overview of the main roles and protocols in use in the Netherlands. We describe a clear attacker model and security requirements, show that in light of this many of the protocols have security issues, and provide suggestions on how to address these issues. The most important conclusion is the need for end-to-end security for data in transit and long-term authenticity for data at rest. In addition, we highlight the need for improved authentication of the EV driver, e.g. by using banking cards. For the communication links we advise mandatory use of TLS, standardization of TLS options and configurations, and improved authentication using TLS client certificates.
翻译:电动车辆收费领域涉及行为者、装置、网络和规程的复杂组合。这些规程是在没有明确侧重于安全的情况下制定的。在本文件中,我们概述了荷兰使用的主要作用和规程。我们描述了一个明确的攻击者模式和安全要求。我们描述了一个明确的攻击者模式和安全要求。我们从许多规程中可以看出,这些规程有安全问题,并就如何解决这些问题提出了建议。最重要的结论是过境数据需要端到端的安全,休息数据需要长期的真实性。此外,我们强调需要改进对EV驱动器的认证,例如使用银行卡。对于通信联系,我们建议强制使用TLS,使TLS选项和配置标准化,并改进使用TLS客户证书的认证。