中国电力 ›› 2019, Vol. 52 ›› Issue (1): 57-62,109.DOI: 10.11930/j.issn.1004-9649.201811139

• 信息物理电力系统(CPPS)专栏 • 上一篇    下一篇

电动汽车充电桩自动化渗透测试系统的研究和设计

孙舟, 潘鸣宇, 陈振, 袁小溪, 陈平   

  1. 国网北京电力科学研究院, 北京 100075
  • 收稿日期:2018-12-02 出版日期:2019-01-05 发布日期:2019-01-14
  • 作者简介:孙舟(1986-),男,硕士,高级工程师,从事电动汽车充换电技术研究,E-mail:sunzhou0812@163.com;潘鸣宇(1985-),男,硕士,高级工程师,从事充电网络规划运营和关键设备研制工作,E-mail:pan_my619@sina.com;陈振(1989-),男,硕士,助理工程师,从事电动汽车信息化管理系统和充电桩信息化系统研究,E-mail:zchen@tju.edu.cn;袁小溪(1989-),女,硕士,助理工程师,从事充换电设施选址规划研究,E-mail:498297227@qq.com;陈平(1966-),男,硕士,高级工程师,从事电力系统分析研究,E-mail:772093280@qq.com
  • 基金资助:
    国家电网公司科技项目(电动汽车充电桩信息安全检测评估方法研究及应用,520223170010)。

Research and Design of Automatic Penetration Testing System for Electric Vehicle Charging Piles

SUN Zhou, PAN Mingyu, CHEN Zhen, YUAN Xiaoxi, CHEN Ping   

  1. State Grid Beijing Electric Power Research Institute, Beijing 100075, China
  • Received:2018-12-02 Online:2019-01-05 Published:2019-01-14
  • Supported by:
    This work is supported by Science and Technology Project of State Grid Corporation of China (No.520223170010).

摘要: 信息物理系统(cyber physical systems,CPS)是集计算、通信与控制于一体的智能系统。电动汽车充电设施是一种典型的信息物理系统,但当前大量部署在现场的充电桩终端存在着用户入侵充电桩系统导致系统异常等安全隐患,亟须研究设计一套针对充电桩的自动化渗透测试系统。从指纹扫描、漏洞检测和漏洞挖掘3个方面对充电桩自动化渗透测试系统进行研究与设计,旨在检测已知漏洞和挖掘未知漏洞,有效地对电动汽车充电桩进行全方位的自动化安全检测,提高充电桩的安全防护等级,加强充电桩的安全防护能力,减少针对充电桩安全攻击所造成的信息泄露和经济损失。

关键词: 信息物理系统(CPS), 充电桩安全, 漏洞检测, 漏洞挖掘, 渗透测试

Abstract: Cyber physical system (CPS) is an intelligent system integrating computing, communication and control. As an important gateway to the energy internet, the electric vehicle charging facilities are responsible for important functions such as power supply, metering and billing, data interconnection and charging security, which is also a typical CPS system. There are many potential threats in the charging pile terminals in the field, such as system abnormality caused by user intrusion of charging pile system, which would subsequently threaten the security of the national grid. It is therefore necessary to study and design an automatic penetration testing system for charging piles. This paper makes a research and design of the charging pile automatic penetration testing system from three aspects: fingerprint scanning, vulnerability detection and vulnerability mining, which aims to detect the known vulnerabilities and discover unknown ones, and effectively carry out all-round automatic inspection of charging electric vehicles, subsequently improving the protection level of charging piles, and strengthening the protection capability of charging piles and reducing the information leakage and economic loss caused by the attacks on charging piles.

Key words: cyber physical system, charging pile security, vulnerability detection, vulnerability mining, penetration testing

中图分类号: