Wicked Problem, Parsimonious Solution: Securing Electric Vehicle Charging Station Software

Abstract

Electric vehicle charging infrastructure presents a suite of novel cyber-physical threats. Among this infrastructure, charging stations are the most vulnerable elements. The software in the charging station supply equipment is particularly vulnerable. Currently, the software is an attack surface that is largely unprotected and poorly characterized. To represent the vulnerabilities in this attack surface, we advocate for applying modern software quality assurance to characterize vulnerabilities in electric vehicle charging station software. Specifically, we advocate for the application of hierarchical software quality assurance (HSQA) to specialized electric vehicle charging station software. HSQA provides a comprehensive view of the code quality and security - from the level of individual vulnerabilities (e.g., CVEs) to high level characteristics (e.g., CIA Triad). HSQA incorporates quality and security considerations throughout the software development lifecycle. Thus, our position is that HSQA is an excellent approach for assessing electrical vehicle charging station software.

Description

Citation

Sheppard, E., Wadhams, Z., Arford, D., Izurieta, C., & Reinhold, A. M. (2025, August). Wicked Problem, Parsimonious Solution: Securing Electric Vehicle Charging Station Software. In 2025 IEEE International Conference on Cyber Security and Resilience (CSR) (pp. 679-686). IEEE.

Endorsement

Review

Supplemented By

Referenced By

Creative Commons license

Except where otherwise noted, this item's license is described as Copyright IEEE 2025