CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Identity-based crypto removes plaintext keys from CCS charging

Identity-based cryptography replaces plaintext key delivery in the CCS charging handshake.

CarThreat Staff
Last updated: August 12, 2026 3:59 am
By
ctadmin
1 Min Read
SHARE

EV charging has a quiet weak spot: the pairing handshake that locks the connection between car and charger can expose plaintext keys. Researchers at the University of Alabama demonstrate a key establishment scheme for CCS charging that removes certificates and plaintext delivery from the process.

The work targets SLAC, the pairing step in Combined Charging System sessions where the vehicle and charger negotiate over power-line communication. The team says today’s approach delivers a network master key in a way that leaves the exchange exposed to man-in-the-middle attacks at the PLC layer. Their design uses identity-based cryptography to derive keys non-interactively and in a decentralized way, eliminating the extra message exchanges and certificate overhead of ECDH-based alternatives.

Combined with policy-controlled fallback, the approach also reduces downgrade opportunities during SLAC key establishment. The result is a handshake with fewer moving parts and less plaintext on the wire, which matters as chargers become a favorite research target: Pwn2Own Automotive contestants and independent teams have repeatedly found flaws in charger authentication and payment flows.

The demo was presented at VehicleSec 2026. The authors say the scheme can be integrated into the existing SLAC process without new hardware.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Charging InfrastructureConnected VehiclesCybersecurityElectric Vehicles (EVs)Threat IntelligenceVulnerabilities
SOURCES:USENIX VehicleSec 2026
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Policy & Compliance

Gipuzkoa’s Automotive Sector Gears Up for Cyber Resilience Act Compliance

By
ctadmin
June 19, 2026
Cybersecurity

BYD’s New In-House Chip Reshapes Self-Driving Compute Strategy

By
ctadmin
May 30, 2026
Cybersecurity

Dealer-installed alarm exposes 2 million cars to Bluetooth theft attacks

By
ctadmin
July 21, 2026
Cybersecurity

EV charger worm escapes a Tesla wall plug and hops to rival brands

By
ctadmin
August 22, 2026
Policy & Compliance

How the EU Cyber Resilience Act Reshapes Compliance for Software Defined Vehicles

By
ctadmin
June 19, 2026
Developer workstation showing code analysis for QNX embedded systems
Cybersecurity

Unlocking QNX IFS Images for Binary Whitelisting in Automotive Embedded Systems

By
ctadmin
May 25, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • ISO/SAE 21434
  • UNECE R155
  • Regulations
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?