A low-speed electric vehicle battery that answers to Bluetooth is a switch an attacker can throw, and India is updating its L-category rulebook to test against exactly that risk. Amendment No. 5 to the AIS-156-2020 standard adds Clause 6.12 for BMS units carrying Bluetooth Classic, Bluetooth Low Energy or other wireless interfaces, with one pass/fail question: can an unapproved phone or device connect and reach safety-critical functions?
Labs must attempt to read live voltage, current, temperature and state of charge values, flip contactors and relays, switch charging and discharging on or off, run cell balancing, reset faults, rewrite configuration and protection thresholds, and push firmware over the wireless link. Test rigs pair Android and iOS handsets with BLE GATT browsers, Bluetooth Classic terminals and protocol analyzers, working on a full vehicle or a bench setup with the pack live. The battery is examined exactly as a customer receives it, with no pre-test security hardening, at a state of charge between 40 and 60 percent.
The mandate grew out of July incidents in which moving e-rickshaws lost power while strangers operated free BMS phone apps, reports that reached CERT-In and prompted action. Inspections blamed low-cost packs that carried default credentials or none at all. Officials removed the misused applications, and the Ministry of Heavy Industries briefed SIAM, ACMA and testing agencies on Bluetooth BMS weaknesses. Pack makers must now hand over the full wireless surface: chipset, Bluetooth profiles, exposed services and characteristics, intended pairing method and every command the interface accepts.
India already phases AIS-189 cyber rules aligned with UN R155 for connected vehicles by 2029. The AIS-156 amendment delivers the same assurance earlier to e-rickshaws and low-speed two- and three-wheelers, the segment where the July incidents proved a wireless BMS can be a remote safety risk.