Security

K-Sign Demonstrates EV Charger Hacking to OCA; Discusses Linkage to International Security Guide

TECHWORLD ·

케이사인이 국제 충전표준기구 OCA 플러그페스트에서 실무진에 EV 충전기 해킹 시연을 선보인 후 기념촬영을 하고 있다. [제공=케이사인]

✦ AI Summary

K-Sign said on the 2nd that it demonstrated an EV charging protocol security fuzzer to OCA working-level officials.

The demonstration took place during an OCA Plugfest held in South Korea and disclosed the process leading to remote code execution through the DataTransfer message in OCPP 1.6 and the CWE-121 vulnerability.

OCA emphasized the need for a security testing framework separate from conformity certification, and follow-up topics included jointly hosting a testing event, linking with domestic testing and certification agencies, and participating in Pwn2Own Automotive.

K-Sign said on the 2nd that it demonstrated an EV charging protocol security fuzzer to working-level officials from the Open Charge Alliance (OCA). The security fuzzer is being developed as a national R&D project, and the demonstration focused on areas related to international standards for electric vehicle charging.

The meeting took place during an OCA Plugfest, an interoperability testing event, held in South Korea. At the event, K-Sign presented the EV charging security fuzzer under development along with actual attack scenarios.

The protocol demonstrated was OCPP 1.6, a charger control protocol. The attack path used the DataTransfer message in OCPP 1.6, and K-Sign disclosed how a buffer overflow vulnerability in the charger software stack, CWE-121, could lead to remote code execution.

K-Sign said the key point of the demonstration was the conditions under which the attack succeeds. When the same message was sent while the charger was in standby, it was normally rejected, but when it was sent during charging, the vulnerability was triggered and the charger software's control flow was taken over.

The demonstration was designed to visually confirm whether the attack succeeded, and the configuration vulnerability was remote code execution (RCE). During the demo, abnormal function execution showed a function being called that would not normally be invoked, and on the charger display, an arbitrary web page was shown.

In subsequent discussions on cooperation, OCA shared the Security Operating Guide it is revising, and K-Sign requested mapping of verifiable requirements items for the fuzzer. As follow-up topics, the two sides proposed jointly hosting a security testing event dedicated to the charging industry, linking with domestic testing and certification agencies, and participating in Pwn2Own Automotive.

K-Sign said industry awareness of charging infrastructure security remains low. That need was underscored by the fact that ElaadNL's test subjects included more than 40 chargers, and that about 24% of the test results revealed buffer-related vulnerabilities.

The source of that record is an OCA guide.

OCA expressed concern that OCPP certification is being misunderstood as guaranteeing charger safety, and stressed the need for a security testing framework separate from conformity certification.

Kim Seok-hwi, a senior member of K-Sign's R&D team, said chargers are connection points to regional power grids, and that if multiple chargers were seized at the same time, the impact could extend beyond information leaks to physical damage, citing a large-scale blackout as an example. He also said this demonstration was not a laboratory-level assumption but a reproduction and verification of the structure of an actual publicly disclosed vulnerability, and that the company plans to use it as an opportunity to reflect domestic technology in international standardization discussions.

Source: TECHWORLD · Lee Gwang-jae
Original: https://www.epnc.co.kr/news/articleView.html?idxno=406406

References

This article was produced with the help of an automated content generation algorithm.


Source: TECHWORLD

View original

This article was summarized and organized by BizCrush based on the original article from TECHWORLD. For exact quotations and full details, please refer to the original article.