1、#BHUSA BlackHatEventsSmart Charging,Smarter Hackers:The Unseen Risks of ISO 15118 Salvatore Gariuolo#BHUSA BlackHatEventsDr.Salvatore GariuoloSenior Threat ResearcherAbout me#BHUSA BlackHatEvents.1.The ISO 15118 Standard.A strategic response to the EV surgeHow ISO 15118 changes the threat landscapeC
2、onclusion and key takeawaysAgenda2.Old Risks,New Risks?3.The Hidden Risks of Compliance#BHUSA BlackHatEvents1.The ISO 15118 StandardA Strategic Response to the EV Surge#BHUSA BlackHatEventsGrid Strain.As of today,approx.27 Million EVsEV Surge:What is the problem?3%of the global fleetBy 2040,we expec
3、t 600 Million EVs30%of the global fleet#BHUSA BlackHatEventsExcess electricity can disrupt grids frequencyRenewables supply 50%-but theyre intermittentConsumption can adjust quickly-generation cantPower Grids:A Fragile BalanceApril 2025,A lesson from Spain:The entire grid was disconnected to prevent
4、 a full collapse.#BHUSA BlackHatEventsGrid Stress:What is the solution?Upgrade Grid InfrastructureGlobal investment needs could exceed$4.5 billion per yearSmart charging and V2G communication Dynamic charging based on grid conditions and user preferences EVs can absorb excess electricity and feed it
5、 back when needed#BHUSA BlackHatEventsISO 15118:Three Key BenefitsGrid-efficientUser-friendlySecure Smart Charging Vehicle-to-Grid.Plug&Charge Multiple Profiles Public Key Infrastructure Transport Layer SecurityAcross two versions:ISO 15118-2 and ISO 15118-20.#BHUSA BlackHatEvents2.Old Risks,New Ris
6、ks?How ISO 15118 changes the threat landscape#BHUSA BlackHatEventsA.Mitigated RisksHow does Plug&Charge work?-Authentication and Authorization through PKI-Data transmission encrypted via TLSDigital CertificatePrivate KeyNo more RFID cloning or card skimmingNo more eavesdropping on session ID and dat