← Latest papers
💻 computer science

Physical-Layer Signal Injection Attacks on EV Charging Ports: Bypassing Authentication via Electrical-Level Exploits

This paper exposes critical physical-layer vulnerabilities in major EV charging protocols by demonstrating how a malicious device called PORTulator can bypass authentication to sabotage charging processes, and proposes hardware-based countermeasures using dynamic high-frequency PWM signals to secure the infrastructure.

Original authors: Hetian Shi, Yi He, Shangru Song, Jianwei Zhuge, Jian Mao

Published 2026-05-04
📖 5 min read🧠 Deep dive

Original authors: Hetian Shi, Yi He, Shangru Song, Jianwei Zhuge, Jian Mao

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine your electric car (EV) is like a high-tech house, and the charging station is the front door. To let electricity in, the car and the charger have to shake hands and say, "Hello, I'm safe to plug in."

This paper, titled "Physical-Layer Signal Injection Attacks on EV Charging Ports," reveals that this handshake is surprisingly weak. It's like a door that opens if you just knock on the wood in a specific rhythm, without checking if you actually have a key.

Here is the breakdown of what the researchers found, using simple analogies:

1. The Weak Handshake (The Vulnerability)

When you plug your car in, the charger checks two main things to make sure you are really there and ready to charge:

  • The "Are You There?" Check (CC Port): The charger looks for a specific electrical resistance (like a specific weight on a scale) to confirm the plug is inserted.
  • The "How Much Power?" Check (CP Port): The car sends a rhythmic signal (like a blinking light) to tell the charger how much electricity it can handle.

The Problem: The researchers found that these checks rely on simple, static electrical signals. They don't use complex passwords or digital encryption. It's like a security guard who only checks if you are wearing a red hat, rather than checking your ID card. If an attacker can fake a red hat, they can trick the guard.

2. The "Magic Wand" (PORTulator)

To prove this weakness, the researchers built a device called PORTulator.

  • What it is: A tiny, hidden gadget that fits inside the charging gun (the handle you hold).
  • How it works: It's like a "remote control" for the electrical handshake. Once hidden inside a public charger, it can whisper fake signals to the car or the charger.
  • The Stealth: It's so small and unobtrusive that you wouldn't notice it, and it can be controlled wirelessly from a distance (like using a remote to change a TV channel).

3. The Three Tricks (The Attacks)

Using PORTulator, the researchers demonstrated three ways to break the system:

  • Trick 1: The "Do Not Disturb" Sign (Denial of Service)
    The attacker sends a fake signal that says, "The plug is loose!" or "There is an error!"

    • Result: The charger panics and immediately stops the charging session. It's like someone shouting "Fire!" in a movie theater, causing everyone to run out, even though there is no fire.
  • Trick 2: The "Stuck Door" (Deadlock Attack)
    This is the most dangerous trick. The attacker tricks the car into thinking the plug is fully inserted and locked, before the car has actually finished its safety checks.

    • Result: The car's mechanical lock snaps shut, trapping the charging gun inside. The user cannot unplug the car, even if they press the release button. The car is now "hostage."
    • The Ransom: The researchers showed how an attacker could then display a fake "Support" website (via an NFC tag on the gun) demanding payment to "unlock" the car. It's a physical version of ransomware.
  • Trick 3: The "Backdoor" (CAN Bus Injection)
    In some car models, the charging port is directly connected to the car's internal nervous system (the CAN Bus).

    • Result: By sending the right fake signals, the attacker can bypass the car's safety guards. They can trick the car into charging even when the battery is overheating, potentially damaging the battery or causing a fire. It's like tricking a car's thermostat into turning off the fire alarm while the engine is on fire.

4. How Widespread is This?

The researchers tested this on 20 different charging piles and 7 different international charging standards (including those used in China, Europe, the US, and North America).

  • The Verdict: Almost all of them were vulnerable. The problem isn't just one bad charger; it's that the "rules of the road" for how cars and chargers talk to each other are too simple.

5. The Fix (How to Lock the Door)

The paper suggests upgrading the "handshake" to make it harder to fake:

  • Add a "Memory" Component: Instead of just a simple resistor (a static weight), use a component that changes its behavior based on how fast the signal is sent. It's like a lock that only opens if you knock in a specific rhythm that changes every second.
  • Dynamic Signals: Instead of a fixed signal, use a signal that constantly shifts. An attacker trying to copy a static signal would fail because the "password" is always moving.

Summary

The paper warns that our electric car charging infrastructure is built on a foundation of trust that is too easily broken. By simply faking a few electrical signals, an attacker can stop your car from charging, trap your car to the charger, or even force it to charge dangerously. The solution is to upgrade the "handshake" from a simple knock on the door to a complex, changing digital conversation.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →