OCPP: Driving The Security Standard for EV Charging Platforms

Why the Open Charge Alliance OCPP EV Security Certificate is critical for your infrastructure safety and stability.

Electric Vehicles Hit the Road

The Electric Vehicle (EV) revolution is here. While there are about 16 million electric vehicles on the road today, that number is expected to jump to almost 229 million by 2030. Factors like robust regulatory support and strong consumer interest make these projections seem increasingly likely.

EV share of new passenger vehicle sales by market graph

With the proliferation and adoption of electric vehicles accelerating, electric vehicle chargers will increasingly adorn parking lots and garages. Buildings and facilities of all kinds will have hundreds of EV chargers connected to the cloud. This will enable EV smart charging to take advantage of the lowest rates and grid incentives. All of these cloud-connected EV charging solutions present a major concern to consumers and charge point operators alike. But as EV chargers manufactured by a variety of vendors start communicating over the internet, how will building owners and managers ensure security?

Risky Business

Securing computer networks is not new. Indeed, each day devices become increasingly smarter, requiring new ways to secure them. Examples of this include industrial control systems and Internet of Things (IoT) devices. EV charging networks are no different. In fact, during the last six months alone, attackers leveraged numerous EV charging platform vulnerabilities to wreak havoc.

As hackers seek to penetrate these systems, there are numerous ways that insecure systems can be exploited. These can include charging fraud through vehicle impersonation and direct attacks on charging networks causing a large-scale disruption of EV charging.

EV charger manufacturers, charge point operators and building owners must now consider how to mitigate these risks. Third-party security certifications provide independent verification that the software you are using is properly secured. Find out more about these important credentials to ensure you are working with a company that takes security seriously.

Open Charge Alliance and EV Security

EV chargers and software management systems communicate via the OCPP protocol. It is governed by the Open Charge Alliance (OCA) which formally certifies products for compliance.

OCA is a global consortium of public and private electric vehicle infrastructure leaders that have come together to promote open standards through the adoption of the Open Charge Point Protocol (OCPP) and the Open Smart Charging Protocol (OSCP).

Its mission is to foster global development, adoption, and compliance of communication protocols in the EV charging infrastructure and related standards through collaboration, education, testing, and certification.

Many companies claim OCPP ‘Support’ or ‘Compliance’, however, only very few have been fully certified by the Open Charge Alliance. Indeed, even fewer companies have pursued the OCPP Security Certification. The Security Certificate creates a global standard for security for electric vehicle charging. The security part of OCPP was developed to strengthen and mature the future development and standardization of OCPP. OCPP security has been designed to meet the following security objectives:

  1. To allow the creation of a secure communication channel between the Central System and Charge Point. Strong cryptographic measures protect the integrity and confidentiality of messages on this channel.
  2. To provide mutual authentication between the Charge Point and the Central System. Both parties should be able to identify who they are communicating with.
  3. To provide a secure firmware update process by allowing the Charge Point to check the source and the integrity of firmware images, and by allowing non-repudiation of these images.
  4. To allow logging of security events to facilitate monitoring the security of the smart charging system.

Prior to selecting EV charging hardware and an EV software vendor to manage your charging fleet, make sure you find out if they are OCPP Certified. Only certified companies are eligible to use the badges below.  This could make the difference between your EV experience being a smooth sail or a train wreck.

OCPP fully certified mark OCPP security certified mark

To find out more about securing your EV chargers, reach out to Wevo Energy at info@wevo.energy or visit us on the web at https://wevo.energy/

__________________________________

1  https://www.openchargealliance.org/
2  OCPP 1.6 Security Whitepaper (3rd edition)

 

SHARE

We thought that you would be interested in reading these articles:

Talk to our Specialist

Fill in the form below to book a 30 minute no-obligation consulting session.

Your information will be processed as detailed in our privacy policy.

Skip to content