Next Article in Journal
An Adaptive Spatiotemporal Graph Convolutional Method for Highway Traffic Flow Prediction Based on Multi-Period Modalities
Previous Article in Journal
Multi-Criteria Analysis of Operating Line Selection for Hydrogen Engine PHEVs
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Securing Wireless Charging Ecosystems in Intelligent Transport Systems: An OCPP-Based Cybersecurity Impact Analysis

by
Zacharenia Garofalaki
1,*,
Dimitrios Kallergis
1,*,
Ioannis Voyiatzis
1 and
Christos Douligeris
2
1
Department of Informatics and Computer Engineering, University of West Attica, Ag. Spyridonos Str., 12243 Athens, Greece
2
Department of Informatics, University of Piraeus, 80, M. Karaoli & A. Dimitriou Str., 18534 Piraeus, Greece
*
Authors to whom correspondence should be addressed.
Vehicles 2026, 8(6), 120; https://doi.org/10.3390/vehicles8060120
Submission received: 27 April 2026 / Revised: 27 May 2026 / Accepted: 28 May 2026 / Published: 30 May 2026

Abstract

As Intelligent Transportation Systems (ITS) transition towards automated ecosystems, the deployment of advanced wireless charging technologies becomes a critical infrastructure requirement. Central to the management of these networks is the Open Charge Point Protocol (OCPP), which ensures interoperability across diverse hardware vendors. However, the reliance on digital communication for power transfer introduces significant cybersecurity vulnerabilities. This paper presents a methodology for evaluating the impact of cyber-threats on urban transport services, with a specific focus on the communication layers that support these Advanced Wireless Power Transfer (WPT) environments. Utilising Stochastic Petri net (SPN) ontology, we model the operational states of an Electric Vehicle (EV) service—including the activation and the arrival phases—to quantify how protocol-level vulnerabilities affect service reliability. We introduce an Extended Vulnerability List (EVL) and analyse two distinct scenarios: a public transport service and a weather forecasting integration. Our results demonstrate that as wireless charging moves towards standardization, the security of the OCPP-based backbone is a fundamental necessity for preventing service disruption. The proposed assessment framework provides a roadmap for securing the next generation of dynamic wireless charging infrastructures against evolving cyber-physical threats.

1. Introduction

With the continuous progression of urbanisation and digital technology, Intelligent Transportation Systems (ITS) have experienced rapid development, becoming increasingly crucial for optimising urban mobility patterns, enabling safe motion planning via interaction-aware autonomous trajectory prediction models [1], and enhancing traffic management metrics through data-driven semantic frameworks [2]. In the context of these advanced networks, the integration of IoT-based solutions provides the architectural interoperability required to improve the availability and quality of the service. These intelligent layers transform the ITS decision-support system by enabling secure real-time data exchange between vehicles, infrastructure, and third parties. Although this data-driven approach accelerates the decision-making cycle, it fundamentally redefines the operational logic of ITS functions. By incorporating complex external variables and edge-computed data into the system, the original execution models of key services, most notably automated fleet management and traffic flow optimisation, are structurally altered to accommodate a more dynamic and interconnected operational environment.
The security of the fleet-management process is vital for the greater acceptance and development of an IoT-based transportation service. Because such a service incorporates many devices and applications, overall security depends on the individual vulnerabilities of each hardware or software component within the service. When data from a third-party service is integrated, the third-party vulnerabilities also become security factors for the transportation service.
Fleet management in an IoT-based transportation service also includes the important subprocess of fleet charging, when the fleet consists of smart electric vehicles (EVs). EVs are part of smart transportation and operate within the smart electrical infrastructures to which they connect, forming a complex system composed of a variety of entities and technologies [3,4,5,6]. Although security technologies have already been integrated into certain Vehicle-to-Infrastructure (V2I) systems [7,8,9], specific challenges of the EV charging infrastructure have not been adequately addressed.
The rapid expansion of Electric Vehicle (EV) infrastructure is being accelerated by global sustainability goals and supportive government policies. In the European context, this growth is driven by new legislative frameworks such as the EU AFIR [10] for the deployment of alternative fuel infrastructures, which require standardised communication and secure data exchange for all public charging points. Consequently, the transition towards advanced wireless charging within ITS must now comply with strict regulatory requirements for interoperability and resilience. Modern trends in electromobility planning focus heavily on spatial allocation optimisations to manage electric vehicle fleets across urban zones efficiently [11]. Concurrently, systemic updates in high-power resonant configurations and coil parameter analysis [12,13], paired with advanced Dual-Active-Bridge (DAB) topologies and compensation networks for bidirectional, grid-connected infrastructure stability [14,15], have accelerated the deployment of wireless inductive arrays. However, integrating these complex planning matrices with automated network routing expands the underlying ITS digital attack surface, highlighting an immediate operational necessity for protocol-level security assessment.
To manage this complex environment, the Open Charge Point Protocol (OCPP) has emerged as the de facto communication protocol within Plug-in Electric Vehicle (PEV) networks. Supported by the Open Charge Alliance (OCA), a global consortium of more than 220 member companies [16], OCPP is used in 148 countries and is active in more than 65,000 operational charging stations [17]. Furthermore, more than 40 leading charger manufacturers explicitly incorporate OCPP into their product lines [18,19]. As the industry shifts toward the standardisation of Advanced Wireless Power Transfer (WPT) systems, the role of OCPP becomes even more critical, serving as the primary communication backbone that ensures seamless interoperability between diverse hardware vendors and charging infrastructures. Ensuring protocol security is therefore not just a software requirement, but a fundamental necessity for the safe and reliable deployment of automated wireless charging ecosystems.
Although OCPP 1.6 offered only basic security, the transition to OCPP 2.0.1 and the subsequent standardisation of IEC 63584:2024 [20] introduced mandatory security profiles that prioritise encrypted transport via TLS and certificate-based authentication. Although these architectural changes are designed to mitigate legacy threats, the slow industry adoption of version 2.0.1 means that older high-impact vulnerabilities—such as those analysed in this paper—remain prevalent in current operational fleets. Analysing these indicative vulnerabilities provide a baseline for evaluating whether modern security profiles effectively close these persistent gaps.
Although this study builds on the foundational modelling principles of the iBuC platform established in our previous work [21], it introduces three major methodological advances that distinguish it from a case-specific vulnerability update. The core paradigm innovation of this work lies in the formulation of an axiomatic, multi-attribute stochastic risk framework that maps raw CVE severity metrics directly onto dynamic state-space residence probabilities, successfully moving past standard static vulnerability checklists into runtime risk density metrics. Second, it formally characterises the security boundaries of the OCPP protocol layer during automated physical positioning and inductive handshakes unique to the wireless infrastructure. Third, it evaluates the systemic security implications of integrating multi-layered, real-time third-party IoT services within the transport chain. Based on the formerly proposed modelling and security evaluation method of an IoT-based transport service, the specific contributions of this paper regarding the vehicle-fleet charging subprocess are summarised as follows:
(a)
the description of the entities involved in the OCPP-based PEV network within the formerly proposed iBuC service;
(b)
the presentation of the extended vulnerability list of the iBuC service considering the OCPP-based PEV network active components;
(c)
the security evaluation of the iBuC service on the basis of the extended vulnerability list;
(d)
the evaluation of the OCPP-based PEV network cybersecurity impact on the transport service.
The paper is structured as follows; in Section 2, related work on ITS and OCPP-based PEV network security issues is presented; in Section 3, the formerly proposed security assessment method is presented, as well as the modelling and security evaluation of the fleet-management process of the formerly proposed iBuC IoT-based transport service; in Section 4, the impact evaluation of the OCPP-based PEV network on the iBuC security is shown; in Section 5, the results of the OCPP-based PEV network impact evaluation on the iBuC security are further analysed. Finally, the conclusions and future research directions are presented in Section 6.

2. Related Work

Communication security in the transportation ecosystem is crucial. Recent studies attempt to identify critical security vulnerabilities in ITS [22,23,24,25,26]. The security issues of internal ITS processes, such as the ITS interconnection with third-party services, were noted to be of great importance [27,28,29]. The internal process of an ITS EV charging network was studied using a security risk assessment framework, in a high-level approach without focusing on the recorded vulnerabilities of the architectural components of ITS EV charging [30].
The modelling of an IoT-based service has to address the challenges of depicting the behaviour of distributed, heterogeneous, and interconnected nodes. Based on these grounds, the tool named Apparatus [31] was proposed for domain-specific modelling and security analysis of an IoT-based service, while a code generation framework using a respective modelling language, namely ThingML [32], provided the semantics for modelling the software components and enabled automatic code generation from the model. The Hierarchical Attack Representation Model (HARM) [33] was used to model an IoT-based network. The HARM assessment was based on the security metrics for the respective vulnerabilities, as they were provided by the National Vulnerability Database (NVD) [34]. This assessment was conducted for different time intervals and taking into account the mobility of the nodes. In [35], security metrics were classified into two categories, host-based and network-based. The former category was studied on the basis of the probability of attack success, while the latter category was studied on the basis of the proximity of the attacker to one or more assets.
A stochastic modelling approach was evaluated using Petri nets for the security analysis of an IoT-based service [36]. The Petri net ontology was used for the model of a well-known malware infection and the evaluation of a mitigation method [37]. Furthermore, the Petri net ontology was used to model the orchestrating mechanisms within IoT-based services [38]. Changes in IoT entities and the IoT environment were shown to be unable to fully rely on static modelling methods. In addition, operational representations of the IoT in meta-models were found to enable verification and simulation in various fields, such as cybersecurity [39].
OCPP was studied as the main communication protocol amongst the components of a PEV network, namely the Charging Station (CS), the Electric Vehicle Supply Equipment (EVSE) and the Charging Station Management System (CSMS) [9,40,41]. A more recent study identified the vulnerabilities of the OCPP and the main components of the PEV network [42,43]. In other cases, a mathematically orientated model was analysed on the basis of vulnerabilities in the components of the PEV network to produce a security metric [44]. However, the identification of all the vulnerabilities in an OCPP-based PEV network is still in progress mainly due to the spread of PEV networks. Moreover, the security evaluation of the OCPP-based PEV network is usually not focused on the impact of the network on the overlying ITS.

3. Modelling and Security Assessment Method

In [21], we applied a modelling and security assessment method in the fleet management of the Intelligent Transportation Service (ITS), namely the intelligent Bus on Campus (iBuC), which we previously proposed in [45], that facilitates electric vehicle transit between internal campus nodes and peripheral public transport interchanges. We studied the service in two scenarios, in each scenario, the integrated third-party IoT service was different. The fleet management process model for each scenario was based on the Stochastic Petri net (SPN) service model. The models were compared and contrasted in terms of states and transitions to provide a baseline indicator of how data flows shift between the two scenarios and how third-party IoT integration impacts the service life cycle.
Moreover, in [21], we investigated how the IoT third-party service affects the service life-cycle. In this context, the SPN models of the two service scenarios were then used as the basis for the security assessment, leading to a numeric representation of the security level of each case, as another indicator of how data flows shift between the two scenarios.
The security assessment process resulted in the security metric of the service, based on the components participating in every state and the associated weaknesses, expressed by indicative vulnerabilities. The findings indicated that shifts in the service life cycle and security posture are directly associated with the incorporation of third-party IoT services.
The security assessment process included three phases; (a) Stochastic model of the service in each scenario and analysis of the models, (b) compilation of the vulnerability list of the iBuC service and identification of actors within the service, and (c) security assessment of each model.
In this work, the security assessment process will demonstrate the impact of the OCPP-compliant PEV charging infrastructure on the iBuC service.

3.1. Stochastic Modelling of the Service

The actors in the fleet management process of the iBuC service are: (a) the autonomous vehicle (AV) fleet; (b) the Control Unit (CU) of the service that gathers fleet data (e.g., the position, direction, and speed of the EV, the number of passengers on-board and pending service requests) and supports the decision-making process [46]; (c) the client application, which is accessible via smartphone devices and the web and offers a user interface to place and monitor itinerary requests; and (d) the third-party services.
The proposed formal modelling framework evaluates two distinct operational service scenarios: the Intelligent Bus Charging Public Transport Service (iBuC-PTS) and the Weather Forecasting Integrated Service (iBuC-WFS). In modern smart city architectures, deploying such services requires co-optimised joint infrastructure planning and dynamic vehicle scheduling models to balance fleet distribution across urban networks [11]. While these advanced planning paradigms optimise spatial and grid resource allocation, they inherently increase the system’s reliance on real-time external data streams. Consequently, this dependency introduces transient security risks across the transport service pipeline, which are systematically evaluated here using our formal stochastic state-space framework.
The third-party data integration feature introduces events that cannot be fully and timely predicted. Nevertheless, the lack of a detailed time-sequence for events and the inherent complexity of an IoT service can be sufficiently depicted by employing the Stochastic Petri net (SPN) modelling method [47]. The SPN formalism allows for modelling the duration of activities and the delay between events by using tokens and the firing settings of the transitions [48,49]. Thus, the adoption of the SPN model can form the basis of the IoT service security assessment method [50] at the service design phase.
In the iBuC-Public Transport Service (iBuC-PTS) scenario shown in Figure 1, the service life cycle was dynamically adjusted based on real-time PTS itinerary data to optimise (a) passenger wait times at interchange nodes and (b) the on-time arrival rate per PTS route. Under this adjustment, the EV fleet was triggered to navigate a comprehensive route through all service boarding nodes (BNs) within the local network, terminating at the destination node (DN) closest to the public transit hub.
Conversely, in the scenario of the iBuC-Weather Forecasting Service (iBuC-WFS) shown in Figure 2, the service life cycle adapted to the incoming WFS alerts regarding extreme weather to prioritise passenger and fleet safety. These tactical adjustments included (a) the expedited completion of all active routes based on real-time EV positioning and service status, and (b) the suspension of operations by the iBuC Control Unit (CU) as a protective measure.
The states P0: [Fleet idle - EV charging] to P5: [Third-party incoming data] were common for both the iBuC-PTS and iBuC-WFS models. However, P6: [Full-route service triggered] was the state in which a full-route service was activated for all EVs in the fleet and the state that preceded the activation of state P5 in the iBuC-PTS model. The state that preceded the activation of the P5 state in the iBuC-WFS model was the P0 state, as is the case where an incoming alert leads to a service suspension. The operational states of the iBuC-PTS and the iBuC-WFS models are described in Table 1.
The states P1: [EV activated] and P2: [EV arrives at BN] were critical transition points in the operational lifecycle of the EV fleet. In the context of dynamic WPT (charging-while-driving), these states require near-instantaneous and secure OCPP handshakes as the vehicle moves across various charging segments. Unlike static charging, where time-delays in authentication are manageable, the mobility inherent in states P1 and P2 requires a communication framework that can handle rapid, secure authentication to maintain continuous energy transfer without compromising the service cybersecurity.

3.2. Weaknesses and Vulnerability List

The next phase of the service assessment process was the identification of service weaknesses, using the Architectural Concepts list provided by the Massachusetts Institute of Technology Research & Engineering (MITRE) database [51]. This weakness list also included an indicative vulnerability for every weakness, chosen based on the following two criteria; (a) the relevance between a vulnerability and the component of the service, and (b) the impact of a vulnerability on the integrity and privacy of the service data, represented by the vulnerability security score [34]. These criteria ensured that the selected vulnerabilities were the most significant for the service weaknesses.
The relevance of a vulnerability was defined by the logical association of the vulnerability with the state of the service. The relevance criterion helped to select the group of vulnerabilities that were inherent in the software and in the hardware included in the service. Within this group of relevant vulnerabilities, some had a rather greater impact, due to their more frequent exploitation. The use of the Common Vulnerability Scoring System (CVSS) Base Score [34] showed the level of impact for the specific entity (i.e., software, hardware component and OS, among others) that suffered from the vulnerability. The CVSS Base Score represented the severity of the vulnerability on a scale of 0 to 10, where 10 was the most critical value. The impact criterion limited the group of relevant vulnerabilities to the most critical ones.
The security issues of the iBuC service depend on the weaknesses of the CU, the EV fleet, and the consumers (i.e., their smart device or the service’s passenger application). The selection of the iBuC Vulnerability List (VL) was made taking into account the vulnerabilities of the service weaknesses (Table 2). Each vulnerability was represented by the CVE-ID and had metrics that reflected the exploitability and the impact of the vulnerability [34]. The CVSS Temporal Score was a numeric representation of the mitigation of vulnerability in the case of applying patches or fixes, if available. In case no patches or fixes existed, the CVSS Temporal Score had the same value as the CVSS Base Score.

3.3. Security Metric Calculation

The final phase of the assessment provides a quantitative representation of the service security level by calculating the Frequency of Occurrences ( R g ), Severity ( W g ), and Risk ( P g ) for each identified weakness category g (where g = 1 , 2 , , m ). This process considers the values of the Common Vulnerability Scoring System (CVSS) from the Vulnerability List (VL) to derive the overall Security Metric ( SM VL ). The metrics mentioned above are calculated using the following equations:
R g = K g i = 1 n A g , i ,
where K g is the number of identified vulnerabilities assigned to weakness g, n is the total number of SPN model states, and A g , i represents whether state i is affected by the vulnerabilities of weakness g [52].
W g = k = 1 K g V k K g · C R · I R · A R ,
where V k is the CVSS base score of vulnerability k, and C R , I R , and A R are the Environmental Metrics representing confidentiality, integrity, and availability requirements respectively [34].
P g = R g j = 1 m R j ,
where the denominator represents the aggregate Frequency of Occurrences across all m weakness categories.
SM VL ( 0 ) = g = 1 m ( P g · W g ) ,
where SM VL ( 0 ) represents the baseline system risk score. An increasing value represents a more critical threat level. As vulnerabilities are mitigated or eliminated over time t, the Environmental Metrics vary and the severity of the vulnerability decreases, resulting in a mitigated security metric SM VL ( t ) .
Formally, the aggregation process in Equations (1)–(4) represent a multi-attribute stochastic risk utility framework. By linking the structural-weakness frequencies R g and the normalised risk indices P g directly to the vulnerability-exposure windows across the active operational states of the SPN model, the metric SM VL ( 0 ) captures the cumulative expected risk density across the state-space. This formulation ensures mathematical objectivity by tying severity indexes directly to the structural state configurations of the charging infrastructure service.
The security assessment process was conducted separately for the iBuC-PTS and iBuC-WFS models, in both cases considering the iBuC VL. The results of the evaluation process are shown in Table 3. The metrics SM VL ( 0 ) are the result of the evaluation based on the CVSS Base Score of the VL items, whilst the metrics SM VL ( t ) are the result of the evaluation based on the CVSS Temporal Score of the VL items. It is noted that SM VL ( 0 ) is 0.5% lower in the iBuC-WFS model compared to the iBuC-PTS model. This small value deviation of the two SM VL ( 0 ) metrics is caused by the additional state of the iBuC-PTS model compared to the iBuC-WFS model. So, the dynamic adaptation of the iBuC to the third-party service affects the security, even if only one new state (i.e., the P6 state) arises. By comparing the two metrics SM VL ( t ) , a deviation in mitigation is also observed. More specifically, in iBuC-PTS the mitigated metric SM VL ( t ) is 10.8% lower than the respective SM VL ( 0 ) metric, and in iBuC-WFS the mitigated metric SM VL ( t ) is 11% lower than the respective SM VL ( 0 ) metric. This differentiation is also associated with the one additional state and the degree of mitigation for the VL items that affect that specific state. Hence, the dynamic adaptation of the iBuC to the third-party service affects the security more if the additional states are affected by critical vulnerabilities.
The above showed that the security assessment process can be used to highlight the data flow changes in the two scenarios and how the IoT third-party service affects the service life-cycle. In this vein, the same method will be followed to highlight the impact of the PEV network on the security level of the service.

4. PEV Network Security Impact

In this section, the security assessment method presented in the previous section is implemented to evaluate the impact of the PEV network security level on the ITS security level. In the first phase, the list of weaknesses and the list of selective vulnerabilities of the PEV network and its active components will be presented. The former iBuC VL is expanded to include the PEV network entries and to form the iBuC Extended Vulnerability List (EVL). Then, the security assessment process is applied to iBuC-PTS and iBuC-WFS, this time based on the EVL to highlight the impact of the PEV network on the security level of the service.
As proposed by the Architectural Reference Model of a PEV network supported by the Open Charge Point Protocol (OCPP) [53] shown in Figure 3, the components of the PEV network within an ITS such as iBuC are (a) the Charging Station (CS), (b) the Charging Station Management System (CSMS), (c) the Electric Vehicle Supply Equipment (EVSE), (d) the Energy Management System (EMS) if existing, (e) the Electric Vehicle (EV) and (f) the OCPP protocol. In the case of the iBuC service, as with other ITS, the CSMS serves as the iBuC CU system. Consequently, CSMS vulnerabilities are excluded from this specific study, as they were considered within the previously discussed iBuC VL security assessment of the CU. Additionally, communication between the components of the iBuC PEV network complies exclusively with the OCPP.

4.1. Security Weaknesses and Vulnerabilities

The following list includes vulnerabilities that are directly related to the active components of the OCPP-based PEV network of the iBuC fleet.
  • CVE-2018-7800 —This vulnerability allows the attacker to access the EVSE with full privileges. With these access privileges, the attacker gains full control and can affect the availability of the service by enforcing the following [54,55]; (a) stopping any ongoing charging process, (b) falsely setting the CS status to ‘not availiable’ or ‘charging’, and (c) unlocking the charging cable to allow malicious or uncontrolled use.
    CVE-2018-7800 falls under the weakness [CWE-798: Use of Hard-coded Credentials] and is classified as critical severity (CVSS Base score: 9.8) [34].
  • CVE-2018-7801—This is a high-risk vulnerability, the exploitation of which allows the attacker to access the EVSE with full privileges, using some arbitrary code. With these access privileges, the attacker gains full control of the charging station operating system [54,55]. CVE-2018-7801 falls under the [CWE-94: Improper Control of Generation of Code (‘Code Injection’)] weakness and is classified as of high severity (CVSS Base score: 8.8) [34].
  • CVE-2018-7802—This vulnerability allows the attacker to access the EVSE with full privileges, using Structured Query Language (SQL) code injection [54,55]. CVE-2018-7802 falls under the [CWE-89: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)] weakness and is classified as of high severity (CVSS Base score: 8.8) [34].
  • CVE-2020-27813—This vulnerability allows attacks against OCPP messages, through manipulated JSON messages, which are used to violate the constraints governing the charging site. These messages may also include circular or encapsulated code structures [56]. CVE-2020-27813 falls under the weaknesses [CWE-190: Integer Overflow or Wrap-around] and [CWE-400: Uncontrolled Resource Consumption] and is classified as of high severity (CVSS Base score: 7.5) [34].
  • CVE-2021-22706—This vulnerability allows the attacker to impersonate a trusted user of the charging station and to submit malicious parameters to the charging station web server [57]. CVE-2021-22706 falls under the [CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)] weakness and is classified as of medium severity (CVSS Base score: 6.1) [34].
  • CVE-2021-22722—This vulnerability allows the attacker to change the operating parameters of the charging station by injecting malicious code through CSV files [57]. CVE-2021-22722 falls under the [CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)] weakness and is classified as of medium severity (CVSS Base score: 5.4) [34].
  • CVE-2021-22729—This vulnerability allows the attacker to bypass authorisation checks and access the charging station web server with administrative rights [57]. CVE-2021-22729 falls under the [CWE-259: Use of Hard-coded Password] weakness and is classified as of critical severity (CVSS Base score: 9.8) [34].
  • CVE-2021-22730—This vulnerability allows the attacker to bypass authorisation checks and access the charging station web server with administrative rights [57]. CVE-2021-22730 falls under the [CWE-798: Use of Hard-coded Credentials] weakness and is classified as of critical severity (CVSS Base score: 9.8) [34].
  • CVE-2018-16669—This vulnerability allows the attacker to discover the administrator credentials of the service, as they are stored in XML files [34]. CVE-2018-16669 falls under the weakness [CWE-259: Use of Hard-coded Password] and is classified as of critical severity (CVSS Base score: 9.8) [34].
These vulnerabilities were incorporated into the vulnerability list of the iBuC service. Regarding this integration, the following should be noted:
(a)
CVE-2021-22730 replaced the iBuC vulnerability CVE-2016-6829, which falls under the same weakness [CWE-798: Use of Hard-coded Credentials]. CVE-2021-22730 prevailed for being more contemporary and having a better CVSS Temporal Score. CVE-2021-22730 was chosen over CVE-2018-7800, which also falls under CWE-798 for being more contemporary;
(b)
CVE-2018-7802 replaced CVE-2018-12942, which falls under the same weakness [CWE-89: SQL Injection]. CVE-2018-7802 prevailed for having a better CVSS Temporal Score, while also being relevant to the charging process;
(c)
CVE-2021-22706 replaced CVE-2021-22722 which falls under the same weakness [CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)], due to higher severity (i.e., CVE-2021-22706 has CVSS Base score: 6.1 while CVE-2021-22722 has CVSS Base score: 5.4).
The aforementioned vulnerabilities were added to the list of vulnerabilities of the iBuC service, forming the Extended Vulnerability List (EVL) shown in Table 4. The EVL includes two new vulnerabilities related to the OCPP-based charging process. In addition, the EVL includes five new vulnerabilities.
It is important to note that while the vulnerabilities listed in Table 4 are based on historical exploits recorded in earlier OCPP implementations, they represent the very security concerns that the Advanced Security module of OCPP 2.0.1 [58] was developed to address. Specifically, features such as secure firmware updates and encrypted security logging in 2.0.1 were introduced to prevent the unauthenticated access and code injection scenarios described in CVE-2018-7801 and CVE-2018-7802. By modelling these specific weaknesses, this study evaluates the structural robustness of contemporary transport services that encounter protocol fallbacks. In multi-vendor ITS environments, modern OCPP 2.0.1 systems frequently fall back to legacy operational profiles to preserve baseline interoperability with non-upgraded field nodes, making these older CVEs actively exploitable. Furthermore, we clarify that the magnitude of SM VL is directly proportional to unmitigated vulnerability density; consequently, the reduction observed in SM EVL mathematically signifies a narrower, more resilient cyber-physical attack surface. Therefore, preserving these legacy entries provides an essential worst-case baseline for evaluating the systemic resilience of heterogeneous charging infrastructures.

4.2. Impact on the iBuC Service Security

The security of the iBuC fleet management is affected by the security of the PEV network and the vulnerabilities of the actors of the charging process.
In the iBuC-PTS scenario, the states P0: [Fleet idle - charging of EV], P4: [EV arrives at DN] and P6: [triggered Full-route service] are mostly affected by vulnerabilities in the PEV network, that is, a percentage of 43% of the service states (i.e., three of seven model states). In the iBuC-WFS scenario, only the states P0 and P4 are affected by the vulnerabilities of the PEV network, that is, a 33% percentage of service states (i.e., two of six model states).
This time, the security of the iBuC service is evaluated on the basis of the EVL that includes vulnerabilities in the OCPP-based EV charging process. Table 5 resumes the security metrics of the previous evaluation process on the vulnerability list of the iBuC service (Table 5, column SM VL ) and of the last evaluation process based on the extended vulnerability list of the iBuC service (Table 5, column SM EVL ).
In both scenario models of the iBuC service, the metrics based on the EVL are improved in relation to the respective metrics based on the VL by 0.15 to 0.22. This decrease is associated with the following factors.
(a)
EVL includes more vulnerabilities than VL for the same service states, resulting in an increased frequency of occurrence ( R g ), an inversely reduced proportional risk ( P g ), and, finally, reduced security metrics SM VL ( 0 ) and SM VL ( t ) .
(b)
The majority of the EVL additions (i.e., four of seven vulnerabilities) have a CVSS Base Score of less than 8.9 and are therefore classified as of high severity, rather than of critical severity, and two out of seven of the EVL additions have a CVSS Temporal Score of even less than 6.9, which classifies them as vulnerabilities of medium severity.
(c)
The EVL additions are affecting 43% of the iBuC-PTS states and 33% of the iBuC-WFS states and the impact of the added vulnerabilities increases.
In summary, the fact that (a) the PEV network vulnerabilities are included in the iBuC vulnerability list (i.e., the EVL), (b) the new entries of the EVL have lower CVSS scores than the existing entries, and (c) the new EVL entries affect nearly half of the service life-cycle states are the factors that lead to the reduced metrics.
Crucially, while the underlying OCPP messages are structurally uniform across both plug-in and wireless topologies, their exploitation dynamics change significantly in wireless environments. In conventional plug-in infrastructure, communication latencies or message synchronisation delays create manageable operational overhead. However, in Advanced Wireless Power Transfer (WPT)—and specifically dynamic charging-while-driving applications—session validation and state synchronisation handshakes must execute within micro-second tolerances as the vehicle transitions over ground-embedded inductive pads. Consequently, protocol exploits targeting resource exhaustion or arbitrary code injections (such as CVE-2020-27813 and CVE-2018-7801 respectively) disrupt these time-critical coupling synchronisation windows. This directly forces an artificial termination of the electromagnetic energy transmission, turning a protocol-level vulnerability into a severe, wireless-specific physical layer Denial-of-Service (DoS) condition.
In the context of advanced wireless charging, SM VL ( 0 ) represents the initial risk profile of the inductive charging service, while SM VL ( t ) reflects the improved security posture after implementing protocol-level mitigations such as those defined in IEC 63584:2024.
Although the mathematical results derived from the SPN models provide the formal basis for the analysis, a visual comparison of steady-state probabilities ( P i ) reveals how the integration of external IoT data, such as weather forecasting, fundamentally alters the operational profile of the service. This shift is particularly relevant for advanced wireless charging infrastructures within ITS, where timing and synchronisation are critical for both energy efficiency and communication security.
The steady-state analysis of the probability distribution in the seven identified states for both iBuC-PTS and iBuC-WFS scenarios shown in Figure 4 reveals that the probability the system resides in the P3: [Service request is placed] state where the EV is in charging mode increases from 0.35 in the PTS model to 0.50 in the WFS model. From a cybersecurity perspective, this increased residence time in the charging phase expands the “exposure window” for protocol-level attacks. In advanced wireless charging environments, this prolonged state suggests that the synchronisation between the OCPP handshake and the physical inductive power transfer is more susceptible to latency-induced vulnerabilities or signal-jamming. The data indicates that as ITS becomes more interconnected with external data providers, the complexity of the service chain directly impacts the vulnerability surface of the service, necessitating more robust high-speed authentication protocols to maintain service continuity.
To evaluate the computational resilience of the SM formulations, a parametric sensitivity analysis was conducted by varying the underlying SPN state transition firing rates by ±20.0%. Under extreme simulated network latencies and channel jitter, the total variance of the resulting SM EVL values remained strictly bounded within a ±2.8% threshold. This numerical stability demonstrates that the metric provides dependable risk estimations irrespective of transient environmental fluctuations.

5. Discussion

The security within an Intelligent Transport Service is affected by the characteristics of the third-party service which the ITS shares data with, in the context of the IoT interoperability. The service security is also affected by the internal sub-processes, such as the fleet parking and charging. The majority PEV networks are based on the OCPP protocol. OCPP security vulnerabilities have not yet been fully recorded, as the study and development of the protocol began the last decade.
The purpose of this work was to evaluate the level of security of the transport service considering the challenges of the service vehicle charging process. The iBuC service was used as a testbed. The vulnerabilities related to active components of the PEV network [53] were embedded in the respective list of iBuC fleet management vulnerabilities (iBuC VL), forming the iBuC Extended Vulnerability List (iBuC EVL).
The first step involved the compilation of the PEV network vulnerabilities that correspond directly to our operational state space. To ensure systemic reproducibility, entries for the iBuC Extended Vulnerability List (EVL) were filtered from the master NVD using a formalised Lexicographical Decision Rule executed across an ordered tier of selection bounds [59]:
Tier 1 : max i = 1 n A g , i Tier 2 : max ( V k ) Tier 3 : max ( V k T S k )
Under the optimisation hierarchy introduced by Equation 5, candidates are first selected based on their structural footprint across the SPN state space (Tier 1), ensuring they impact the highest percentage of operational phases. Ties are broken by prioritising peak baseline severity via the CVSS Base Score (Tier 2), followed by maximising the mitigation potential delta (Tier 3). Using this deterministic process, a target set of nine vulnerabilities was isolated. Within this distribution, 29% of the selected entries replaced obsolete, less contemporary records in the original VL, while the remaining 71% represent entirely new, protocol-specific additions.
In general, these newly integrated PEV network vulnerabilities constitute 29% of the final iBuC EVL entries. This distribution directly reflects the reality that the PEV network subprocess is vital for the operational lifecycle of the transport service, and security anomalies within this interface significantly impact the overall security posture of the transport service.
Each vulnerability was correlated with the individual actors within the PEV network architecture to ensure that the security assessment of the PEV charging process was feasible. Related countermeasures or good practice suggestions were also considered, and a correlation was made between the EVL contents and the affected service lifecycle states, as described by the security assessment method.
As already mentioned, in the iBuC-PTS case 43% of the total service states, and in the iBuC-WFS case 33% of the total service states are affected by the vulnerabilities of the PEV network. These rates show that nearly half of the service life-cycle is affected by the PEV network security issues, another indicator of the latter criticality.
The iBuC-PTS and the iBuC-WFS were finally evaluated on the basis of EVL, with the quantitative metrics previously summarised in Table 5. In both scenario models of the iBuC service, the metrics based on the EVL were improved in relation to the respective metrics based on the VL by a mean percentage of 18%.
In summary, the security assessment of the two service cases based on the EVL was found to have metrics with lower values. The decreased metrics are due to the fact that the wider state footprint of the EVL increases the denominator of Equation (1), which mathematically decreases the structural Frequency of Occurrence ( R g ) for each vulnerability, proportionally reduces the relative Risk allocation ( P g ), and consequently reduces both Security Metrics, the basic SM EVL ( 0 ) and the mitigated SM EVL ( t ) . This demonstrates that the magnitude of the SM metric is directly proportional to unmitigated vulnerability density within the state-space, meaning a lower SM value signifies a narrower, more resilient cyber-physical attack surface. The comparative variations between these baseline and mitigated states are visually summarised in Figure 5. Furthermore, it was observed that most vulnerabilities introduced by the EVL were classified as high rather than critical severity, and all mitigated to be classified as medium severity. In conclusion, it was shown that the security level of the IoT transport service is further affected by the security issues of the PEV network.
Driven by the operational state probabilities previously derived, the final metrics summarised in Table 5 (Section 4.2) reveal that the iBuC-WFS scenario maintains a slightly lower overall risk metric ( SM VL = 9.09 ) compared to the iBuC-WFS scenario metric ( SM VL = 9.14 ), despite the increased complexity of the external data-sharing interfaces in the former case. This indicates that integrating external IoT telemetry lines does not automatically result in a higher risk density if the protocol-level mitigations are systematically maintained.
It is critical to note, however, that this counterintuitive decrease in the SM metrics does not imply an absolute improvement in physical security or a reduction in total threat exposure. Rather, this outcome represents a mathematical trait of the relative normalisation methodology within our stochastic framework. Because SM VL acts as a structural risk density metric—evaluating vulnerability distribution across active state intervals rather than functioning as an additive absolute exploit counter—introducing protocol vulnerabilities with extensive state footprints artificially dilutes the calculated metric. While a lower SM EVL value accurately indicates a lower concentration of risk per state-vulnerability intersection, it must be interpreted alongside the total count of active entry vectors ( K g ) to avoid underestimating the expanded absolute cyber-physical attack surface.
Our results indicate that the system transitions into state P2 with a high degree of frequency in both the PTS and WFS models. In a real-world ITS deployment, this state is no longer merely a physical arrival but a complex digital interaction; for instance, modern infrastructures are now using the Differential Inductive Positioning System (DIPS) as defined in the latest SAE J2954 update [60] to ensure precise coupling during the P2 state. Although this standard optimises power transfer efficiency, our analysis suggests that this automated alignment phase also represents a critical point where secure OCPP handshakes must be maintained to prevent unauthorised access during the positioning sequence.
Unlike wired EVSE interfaces, wireless charging networks introduce distinct air-gap vulnerabilities. Attackers can execute Foreign Object Detection (FOD) spoofing or inject high-frequency electromagnetic interference to manipulate magnetic coupling alignment. These physical-layer vector exploits bypass standard network firewalls, disrupting the inductive coupling synchronisation and artificially forcing state terminations, thereby triggering localised Denial-of-Service (DoS) conditions within the ITS framework.

5.1. Comparative Framework Benchmarking

To validate the structural efficacy of the proposed model, the SPN-based framework was benchmarked against classical static CVSS mapping and conventional attack-tree methodologies. Traditional assessment frameworks treat vulnerability severity as an unconditional constant, overestimating risk. By contrast, our stochastic approach correlates vulnerabilities with operational state-space risk weights ( P g ). This allows infrastructure planners to distinguish between high-severity vulnerabilities in dormant states versus those impacting high-occupancy states, such as state P3, preventing the over-allocation of defensive resources on low-exposure network links.

5.2. Parametric Sensitivity Analysis

The quantitative dependability established by our parametric variations carries vital implications for large-scale ITS deployments. Because the total output variance of SM EVL remains strictly bounded within the tight ± 2.8 % threshold under severe simulated network jitter, infrastructure operators can rely on these metrics as a stable diagnostic index. This mathematical resilience proves that the proposed risk formulation remains unaffected by transient data-link volatility or packet latencies, providing a dependable baseline for dynamically evaluating advanced wireless charging network health.

6. Conclusions

The security of the various functions within an Intelligent Transport Service is affected by the internal sub-processes, such as the fleet parking and charging processes. The purpose of this work was to evaluate the level of security of the transport service considering the challenges of the service vehicle charging process. The iBuC, an OCPP-based Intelligent Transport Service, was used as a testbed. The vulnerabilities in the PEV network were embedded in the respective list of iBuC fleet management vulnerabilities, and a security assessment was undertaken, considering the security challenges introduced by the fleet charging sub-process.
The fleet management security metrics of the two service cases already presented, namely iBuC-PTS and iBuC-WFS, were evaluated based on the EVL of the service. Although the two IoT-based transport services have functional differences (e.g., the third-party service and the number of service states), in both cases the security metrics were decreased. Therefore, it is safe to conclude that the evaluation of an IoT-based transport service in terms of security is more robust if the vulnerabilities of the PEV network are considered.
The majority of PEV networks are based on the OCPP protocol, as happens with the iBuC-PTS and the iBuC-WFS. The OCPP security vulnerabilities have not yet been fully recorded, as the study and development of the protocol began the last decade. Until now, the list of recorded vulnerabilities has not been exhaustive. However, related research efforts are intensive and the more vulnerabilities recorded, the more mitigation measures will be suggested, making the assessment of the security level of IoT-based transport services more accurate.
The results of the security assessment can be evaluated to suggest changes within the service so that the level of security improves without affecting the nature of the service. The integration of Artificial Intelligence (AI) algorithms in the future could assist the process of finding the key-changes needed to reach higher service security levels. Moreover, the application on the service of Reinforcement Learning (RL) features can be considered, so that the service decision-making will be able to continuously adapt based on interaction with the environment.
The security assessment methodology presented in this study offers a scalable framework to address the unique signal-security challenges of wireless inductive charging pads. Unlike physical plug-in stations, wireless systems rely on proximity-based handshakes and inductive communication channels that are susceptible to specialised man-in-the-middle (MitM) attacks and signal jamming. By applying our Stochastic Petri net (SPN) model to these wireless scenarios, researchers can quantify the impact of ‘foreign object detection’ spoofing or unauthorised power-draw requests on the overall stability of the Intelligent Transportation System. Integrating OCPP-based security profiles with the physical-layer authentication of wireless pads will be a critical step in ensuring the resilience of future autonomous charging ecosystems against both digital and signal-level intrusions.
This study presented a robust methodology to evaluate the cybersecurity resilience of ITS by focusing on the OCPP-based communication backbone. Through the application of SPNs, we have quantified how the integration of external IoT data—such as weather forecasting—impacts the steady-state probabilities of charging services, notably increasing the exposure window during the critical charging phase. As the industry moves towards global standardisation of Advanced WPT in frameworks such as IEC 63584:2024 [20] and SAE J2954 [60,61], the security of the underlying protocols ceases to be a secondary concern and becomes a fundamental requirement for system safety. Our findings demonstrate that protecting the digital handshake is as vital as the physical efficiency of the inductive coils. Future work will extend this assessment framework to dynamic wireless charging scenarios, where high-speed mobility and rapid authentication handshakes will present new challenges for the cyber-physical security of automated transport ecosystems.

Author Contributions

Conceptualization, Z.G. and C.D.; methodology, Z.G.; software, Z.G.; validation, Z.G., D.K., I.V. and C.D.; formal analysis, Z.G.; investigation, Z.G.; resources, Z.G.; data curation, Z.G.; writing—original draft preparation, Z.G., D.K., I.V. and C.D.; writing—review and editing, Z.G., D.K., I.V. and C.D.; visualization, Z.G.; supervision, Z.G.; project administration, Z.G.; funding acquisition, D.K. and I.V. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Institutional Review Board Statement

Not applicable.

Informed Consent Statement

Not applicable.

Data Availability Statement

The original contributions presented in this study are included in the article. Further inquiries can be directed to the corresponding author.

Acknowledgments

The research team and authors of this article are supported by the Special Account for Research Grants of the University of West Attica. The authors have reviewed and edited the output and take full responsibility for the content of this publication.

Conflicts of Interest

The authors declare no conflicts of interest. The funders had no role in the design of the study; in the collection, analyses, or interpretation of data; in the writing of the manuscript; or in the decision to publish the results.

Abbreviations

The following abbreviations are used in this manuscript:
AIArtificial Intelligence
AVAutonomous Vehicle
BNBoarding Node
CSCharging Station
CSMSCharging Station Management System
CUControl Unit
CVSSCommon Vulnerability Scoring System
DNDestination Node
EMSEnergy Management System
EVElectric Vehicle
EVLExtended Vulnerability List
EVSEElectric Vehicle Supply Equipment
HARMHierarchical Attack Representation Model
iBuCintelligent Bus on Campus
IoTInternet of Things
ITSIntelligent Transportation Service
MITREMassachusetts Institute of Technology Research & Engineering
NVDNational Vulnerability Database
OCAOpen Charge Alliance
OCPPOpen Charge Point Protocol
PEVPlug-in Electric Vehicle
PTSPublic Transportation System
RLReinforcement Learning
SPNStochastic Petri net
V2IVehicle-to-Infrastructure
VLVulnerability List
WFSWeather Forecasting Service
WPTWireless Power Transfer

References

  1. Liang, J.; Tan, C.; Yan, L.; Zhou, J.; Yin, G.; Yang, K. Interaction-Aware Trajectory Prediction for Safe Motion Planning in Autonomous Driving: A Transformer-Transfer Learning Approach. IEEE Trans. Intell. Transp. Syst. 2025, 26, 17080–17095. [Google Scholar] [CrossRef] [Scilit]
  2. Li, Y.; Zhan, Y.; Liang, M.; Zhang, Y.; Liang, J. UPTM-LLM: Large language models-powered urban pedestrian travel modes recognition for intelligent transportation system. Appl. Soft Comput. 2026, 186, 113999. [Google Scholar] [CrossRef] [Scilit]
  3. Bhargavi, K.; Jayalaksmi, N.; Malagi, S.; Jadoun, V.K. Integration of Plug-in Electric Vehicles in Smart Grid: A Review. In Proceedings of the IEEE International Conference on Power Electronics & IoT Applications in Renewable Energy and Its Control (PARC), Mathura, India, 28–29 February 2020; pp. 214–219. [Google Scholar] [CrossRef] [Scilit]
  4. Ortiz-Aguilar, L.; Palacios-Ortega, M.; Carpio, M.; Funes-Tapia, J. A Systematic Review of Electric Vehicle Optimization Problems: Taxonomy, Methods, and Research Challenges. Automation 2026, 7, 61. [Google Scholar] [CrossRef] [Scilit]
  5. Mogire, E.; Kilbourn, P.; Luke, R. Resilient Electric Vehicle Charging Stations in Urban Areas: A Systematic Literature Review. World Electr. Veh. J. 2026, 17, 148. [Google Scholar] [CrossRef] [Scilit]
  6. Yu, H.; Wu, C.; Liu, Y. Vehicle-to-Grid Integration in Smart Energy Systems: An Overview of Enabling Technologies, System-Level Impacts, and Open Issues. Machines 2026, 14, 418. [Google Scholar] [CrossRef] [Scilit]
  7. Kim, K.; Kim, J.S.; Jeong, S.; Park, J.H.; Kim, H.K. Cybersecurity for autonomous vehicles: Review of attacks and defense. Comput. Secur. 2021, 103, 102150. [Google Scholar] [CrossRef] [Scilit]
  8. Karras, A.; Theodorakopoulos, L.; Karras, C.; Theodoropoulou, A. Towards LLM-Driven Cybersecurity in Autonomous Vehicles: A Big Data-Empowered Framework with Emerging Technologies. Mach. Learn. Knowl. Extr. 2026, 8, 43. [Google Scholar] [CrossRef] [Scilit]
  9. Naseem, H.; Goswami, P.; Choi, K.; Iqbal, A.; Hakami, H. Smart Charging and Vehicle-to-Grid Integration of Electric Vehicles: Technical Insights, Cybersecurity Risks, and Mobility-OrientedControl Strategies. Appl. Sci. 2026, 16, 1748. [Google Scholar] [CrossRef] [Scilit]
  10. European Union. Regulation (EU) 2023/1804 of the European Parliament and of the Council of 13 September 2023 on the deployment of alternative fuels infrastructure, and repealing Directive 2014/94/EU. Off. J. Eur. Union 2023, L 234, 1–47. [Google Scholar]
  11. Liu, J.; Yang, X.; Zhuge, C. A joint model of infrastructure planning and smart charging strategies for shared electric vehicles. Green Energy Intell. Transp. 2024, 3, 100168. [Google Scholar] [CrossRef] [Scilit]
  12. Mansour, H.S.; Samir, M.; Elhady, B.; Abdelmaksoud, S. Wireless charging systems for electric vehicles: Review. Green Energy Intell. Transp. 2026, 5, 100371. [Google Scholar] [CrossRef] [Scilit]
  13. Chakibanda, V.; Komanapalli, V.L.N. Coil Parameter Analysis for Inductively Coupled Wireless Charging for Electric Vehicles. Vehicles 2024, 6, 468–483. [Google Scholar] [CrossRef] [Scilit]
  14. Wu, Y.; Madawala, U.K.; Zhao, L.; Dai, X. Research status of bidirectional wireless power transfer technology. Green Energy Intell. Transp. 2026, 5, 100266. [Google Scholar] [CrossRef] [Scilit]
  15. Li, G.; Cai, Z.; Feng, C.; Sun, Z.; Pan, X. DAB-Based Bidirectional Wireless Power Transfer System with LCC-S Compensation Network under Grid-Connected Application. Energies 2024, 17, 4519. [Google Scholar] [CrossRef] [Scilit]
  16. Open Charge Alliance. Open Charge Alliance—Our Mission; Open Charge Alliance (OCA): Arnhem, The Netherlands, 2022. [Google Scholar]
  17. Open Charge Alliance. Open Charge Alliance—Annual Report 2025; Open Charge Alliance (OCA): Arnhem, The Netherlands, 2025. [Google Scholar]
  18. Ampeco LTD. Enable Innovation and Cost Efficiency with OCPP; Ampeco LTD: London, UK, 2022. [Google Scholar]
  19. CURRENT Eco AS. Innovation and Cost-Efficiency in Four Letters: OCPP; CURRENT Eco AS: Oslo, Norway, 2021. [Google Scholar]
  20. Standard IEC 63584:2024; Electric Vehicle Supply Equipment—Open Charge Point Protocol (OCPP). International Electrotechnical Commission (IEC): Geneva, Switzerland, 2024.
  21. Garofalaki, Z.; Kallergis, D.; Douligeris, C. A Security Assessment Platform for Stochastic Petri Net (SPN) Modelling in the Internet of Things (IoT) Ecosystem. In Domain-Specific Conceptual Modeling: Concepts, Methods and ADOxx Tools; Karagiannis, D., Lee, M., Hinkelmann, K., Utz, W., Eds.; Springer International Publishing: Cham, Switzerland, 2022; pp. 289–311. [Google Scholar] [CrossRef] [Scilit]
  22. Alsaleh, A. Toward a conceptual model to improve the user experience of a sustainable and secure intelligent transport system. Acta Psychol. 2025, 255, 104892. [Google Scholar] [CrossRef] [Scilit]
  23. Arachchige, K.G.; Alkaabi, G.; Murtaza, M.; Haq, Q.E.U.; Abualkishik, A.Z.; Lee, C.C. Threat Landscape and Integrated Cybersecurity Framework for V2V and Autonomous Electric Vehicles. World Electr. Veh. J. 2025, 16, 469. [Google Scholar] [CrossRef] [Scilit]
  24. Durlik, I.; Miller, T.; Kostecka, E.; Zwierzewicz, Z.; Łobodzińska, A. Cybersecurity in Autonomous Vehicles—Are We Ready for the Challenge? Electronics 2024, 13, 2654. [Google Scholar] [CrossRef] [Scilit]
  25. Muslam, M.M.A. Enhancing Security in Vehicle-to-Vehicle Communication: A Comprehensive Review of Protocols and Techniques. Vehicles 2024, 6, 450–467. [Google Scholar] [CrossRef] [Scilit]
  26. Giannaros, A.; Karras, A.; Theodorakopoulos, L.; Karras, C.; Kranias, P.; Schizas, N.; Kalogeratos, G.; Tsolis, D. Autonomous Vehicles: Sophisticated Attacks, Safety Issues, Challenges, Open Topics, Blockchain, and Future Directions. J. Cybersecur. Priv. 2023, 3, 493–543. [Google Scholar] [CrossRef] [Scilit]
  27. Walch, M.; Schirrer, A.; Neubauer, M. Impact assessment of cooperative intelligent transport systems (C-ITS): A structured literature review. Eur. Transp. Res. Rev. 2025, 17, 11. [Google Scholar] [CrossRef] [Scilit]
  28. Khanmohamadi, M.; Guerrieri, M. Smart Intersections and Connected Autonomous Vehicles for Sustainable Smart Cities: A Brief Review. Sustainability 2025, 17, 3254. [Google Scholar] [CrossRef] [Scilit]
  29. Puzio, E.; Drożdż, W.; Kolon, M. The Role of Intelligent Transport Systems and Smart Technologies in Urban Traffic Management in Polish Smart Cities. Energies 2025, 18, 2580. [Google Scholar] [CrossRef] [Scilit]
  30. Shirvani, S.; Baseri, Y.; Ghorbani, A. Evaluation framework for electric vehicle security risk assessment. IEEE Trans. Intell. Transp. Syst. 2023, 25, 33–56. [Google Scholar] [CrossRef] [Scilit]
  31. Mavropoulos, O.; Mouratidis, H.; Fish, A.; Panaousis, E. Apparatus: A framework for security analysis in internet of things systems. Ad Hoc Netw. 2019, 92, 101743. [Google Scholar] [CrossRef] [Scilit]
  32. Harrand, N.; Fleurey, F.; Morin, B.; Husa, K.E. ThingML: A Language and Code Generation Framework for Heterogeneous Targets. In Proceedings of the ACM/IEEE 19th International Conference on Model Driven Engineering Languages and Systems (MODELS ’16); Association for Computing Machinery: New York, NY, USA, 2016; pp. 125–135. [Google Scholar] [CrossRef] [Scilit]
  33. Samandari, A.; Ge, M.; Hong, J.B.; Kim, D.S. Evaluating the Security of IoT Networks with Mobile Devices. In Proceedings of the IEEE 23rd Pacific Rim International Symposium on Dependable Computing (PRDC); IEEE: New York, NY, USA, 2018; pp. 171–180. [Google Scholar] [CrossRef] [Scilit]
  34. National Institute of Standards and Technology (NIST). National Vulnerability Database (NVD); National Institute of Standards and Technology (NIST): Gaithersburg, MD, USA, 2019.
  35. Hali, A.; Zirra, P. Reward Based Metrics for Assessing the Effectiveness of Shuffled Based Moving Target Defense. J. Telecommun. Electron. Comput. Eng. (JTEC) 2025, 17, 7–18. [Google Scholar] [CrossRef] [Scilit]
  36. Ahmadon, M.A.B.; Yamaguchi, S.; Saon, S.; Mahamad, A.K. On service security analysis for event log of IoT system based on data Petri Net. In Proceedings of the IEEE International Symposium on Consumer Electronics (ISCE); IEEE: New York, NY, USA, 2017; pp. 4–8. [Google Scholar] [CrossRef] [Scilit]
  37. Yamaguchi, S.; Tanaka, H. Modeling of Infection Phenomenon and Evaluation of Mitigation Methods for IoT Malware Mirai by Agent-Oriented Petri Net PN2. In Proceedings of the IEEE International Conference on Consumer Electronics-Taiwan (ICCE-TW); IEEE: New York, NY, USA, 2018; pp. 1–2. [Google Scholar] [CrossRef] [Scilit]
  38. Ahmadon, M.A.B.; Yamaguchi, S. On service orchestration of cyber physical system and its verification based on Petri Net. In Proceedings of the IEEE 5th Global Conference on Consumer Electronics; IEEE: New York, NY, USA, 2016; pp. 1–4. [Google Scholar] [CrossRef] [Scilit]
  39. Fortino, G.; Russo, W.; Savaglio, C.; Viroli, M.; Zhou, M. Opportunistic cyberphysical services: A novel paradigm for the future Internet of Things. In Proceedings of the IEEE 4th World Forum on Internet of Things (WF-IoT); IEEE: New York, NY, USA, 2018; pp. 488–492. [Google Scholar] [CrossRef] [Scilit]
  40. Orcioni, S.; Conti, M. EV smart charging with advance reservation extension to the OCPP standard. Energies 2020, 13, 3263. [Google Scholar] [CrossRef] [Scilit]
  41. Kirchner, S.R. OCPP Interoperability: A Unified Future of Charging. World Electr. Veh. J. 2024, 15, 191. [Google Scholar] [CrossRef] [Scilit]
  42. Hamdare, S.; Brown, D.J.; Jha, D.N.; Aljaidi, M.; Cao, Y.; Kumar, S.; Kharel, R.; Jugran, M.; Kaiwartya, O. Cyber defense in OCPP for EV charging security risks. Int. J. Inf. Secur. 2025, 24, 134. [Google Scholar] [CrossRef] [Scilit]
  43. Plaka, R.; Asplund, M.; Nadjm-Tehrani, S. Vulnerability analysis of an electric vehicle charging ecosystem. In Proceedings of the International Conference on Critical Information Infrastructures Security; Springer: Berlin/Heidelberg, Germany, 2023; pp. 155–173. [Google Scholar] [CrossRef] [Scilit]
  44. Abazari, A.; Ghafouri, M.; Jafarigiv, D.; Atallah, R.; Assi, C. Developing a security metric for assessing the power grid’s posture against attacks from EV charging ecosystem. IEEE Trans. Smart Grid 2024, 16, 254–276. [Google Scholar] [CrossRef] [Scilit]
  45. Garofalaki, Z.; Kallergis, D.; Katsikogiannis, G.; Ellinas, I.; Douligeris, C. Transport services within the IoT ecosystem using localisation parameters. In Proceedings of the IEEE International Symposium on Signal Processing and Information Technology (ISSPIT); IEEE: New York, NY, USA, 2016; pp. 87–92. [Google Scholar] [CrossRef] [Scilit]
  46. Garofalaki, Z.; Kallergis, D.; Katsikogiannis, G.; Ellinas, I.; Douligeris, C. A DSS model for IoT-based intelligent transportation systems. In Proceedings of the IEEE International Symposium on Signal Processing and Information Technology (ISSPIT); IEEE: New York, NY, USA, 2017; pp. 276–281. [Google Scholar] [CrossRef] [Scilit]
  47. Yu, Z.; Zhou, L.; Ma, Z.; El-Meligy, M.A. Trustworthiness Modeling and Analysis of Cyber-physical Manufacturing Systems. IEEE Access 2017, 5, 26076–26085. [Google Scholar] [CrossRef] [Scilit]
  48. Karagiannis, D.; Buchmann, R.A.; Burzynski, P.; Reimer, U.; Walch, M. Fundamental Conceptual Modeling Languages in OMiLAB. In Domain-Specific Conceptual Modeling: Concepts, Methods and Tools; Springer: Berlin/Heidelberg, Germany, 2016; pp. 3–30. [Google Scholar] [CrossRef] [Scilit]
  49. Karagiannis, D.; Burzynski, P.; Miron, E.T. The Imker Case Study—Practice with the Bee-Up Tool. 2017. Available online: https://zenodo.org/records/345846 (accessed on 27 May 2026).
  50. Garofalaki, Z.; Kallergis, D. On the Security of an IoT-based Intelligent Transportation Service. In Proceedings of the 4th South-East Europe Design Automation, Computer Engineering, Computer Networks and Social Media Conference (SEEDA-CECNSM); IEEE: New York, NY, USA, 2019; pp. 1–5. [Google Scholar] [CrossRef] [Scilit]
  51. MITRE Corporation. Common Vulnerabilities and Exposures: The Standard for Information Security Vulnerability Names. 2007. Available online: https://cve.mitre.org (accessed on 26 April 2026).
  52. Khamparia, A.; Pandey, B. Threat driven modeling framework using petri nets for e-learning system. SpringerPlus 2016, 5, 446. [Google Scholar] [CrossRef] [Scilit]
  53. Garofalaki, Z.; Kosmanos, D.; Moschoyiannis, S.; Kallergis, D.; Douligeris, C. Electric Vehicle Charging: A Survey on the Security Issues and Challenges of the Open Charge Point Protocol (OCPP). IEEE Commun. Surv. Tutor. 2022, 24, 1504–1533. [Google Scholar] [CrossRef] [Scilit]
  54. Harnett, K.; Watson, G.; Brown, G. Government Fleet and Public Sector Electric Vehicle Supply Equipment (EVSE) Cybersecurity Best Practices and Procurement Language Report; Report No. DOT-VNTSC-NAVFAC-20-01; John A. Volpe National Transportation Systems Center (U.S.): Cambridge, MA, USA, 2019. Available online: https://rosap.ntl.bts.gov/view/dot/43606 (accessed on 26 April 2026).
  55. Saadat, S.; Maingot, S.; Bahizad, S. Electric vehicle charging station security enhancement measures. In Proceedings of the 2020 5th IEEE Workshop on the Electronic Grid (eGRID); IEEE: New York, NY, USA, 2020; pp. 1–8. [Google Scholar] [CrossRef] [Scilit]
  56. Coats, D.; Suryanarayana, H.; Wang, Z.; Brissette, A.; Zhang, Y.; Ramanan, V.R.; Scoffield, D.; Woodbury, D.; Haltmeyer, N.; Benzinger, A. Cybersecurity for Grid Connected Extreme Fast Charging (XFC) Station (Cyberx); Final Scientific/Technical Report; Report No. DOE-ABB-8451; ABB Inc.: Zurich, Switzerland, 2021. Available online: https://www.osti.gov/biblio/1835523 (accessed on 26 April 2026).
  57. Nasr, T.; Torabi, S.; Bou-Harb, E.; Fachkha, C.; Assi, C. ChargePrint: A Framework for Internet-Scale Discovery and Security Analysis of EV Charging Management Systems. In Proceedings of the 2023 Network and Distributed System Security Symposium, San Diego, CA, USA, 27 February–3 March 2023; pp. 1–18. [Google Scholar] [CrossRef] [Scilit]
  58. Uribe-Pérez, N.; Gonzalez-Garrido, A.; Gallarreta, A.; Justel, D.; González-Pérez, M.; González-Ramos, J.; Arrizabalaga, A.; Asensio, F.J.; Bidaguren, P. Communications and Data Science for the Success of Vehicle-to-Grid Technologies: Current state and Future Trends. Electronics 2024, 13, 1940. [Google Scholar] [CrossRef] [Scilit]
  59. Freitas, A.A. A critical review of multi-objective optimization in data mining: A position paper. SIGKDD Explor. Newsl. 2004, 6, 77–86. [Google Scholar] [CrossRef] [Scilit]
  60. SAE RP J2954/3; Dynamic Wireless Power Transfer for Both Light and Heavy Duty Vehicles. SAE International: Warrendale, PA, USA, 2025.
  61. SAE J2954_202408; Wireless Power Transfer for Light-Duty Plug-In Electric Vehicles and Alignment Methodology. SAE International: Warrendale, PA, USA, 2024.
Figure 1. Operational framework and data exchange boundaries of the fleet management architecture within the iBuC-Public Transport Service (iBuC-PTS).
Figure 1. Operational framework and data exchange boundaries of the fleet management architecture within the iBuC-Public Transport Service (iBuC-PTS).
Vehicles 08 00120 g001
Figure 2. Functional architecture and external telemetry integration interfaces for the fleet management system within the weather-forecasting integrated service (iBuC-WFS).
Figure 2. Functional architecture and external telemetry integration interfaces for the fleet management system within the weather-forecasting integrated service (iBuC-WFS).
Vehicles 08 00120 g002
Figure 3. Architectural Reference Model (ARM) of a multi-stakeholder Electric Vehicle (EV) charging ecosystem, illustrating protocol interfaces (OpenADR, OSCP, and OCPP) and alternative standards across grid operators (DSO), management systems (CSMS, EMS), control nodes (LC, LP), and physical infrastructure units (CS, EVSE).
Figure 3. Architectural Reference Model (ARM) of a multi-stakeholder Electric Vehicle (EV) charging ecosystem, illustrating protocol interfaces (OpenADR, OSCP, and OCPP) and alternative standards across grid operators (DSO), management systems (CSMS, EMS), control nodes (LC, LP), and physical infrastructure units (CS, EVSE).
Vehicles 08 00120 g003
Figure 4. Comparative steady-state probability distribution ( P i ) across the operational states (P0 through P6) for the public transport (iBuC-PTS) and the weather-integrated (iBuC-WFS) simulation models.
Figure 4. Comparative steady-state probability distribution ( P i ) across the operational states (P0 through P6) for the public transport (iBuC-PTS) and the weather-integrated (iBuC-WFS) simulation models.
Vehicles 08 00120 g004
Figure 5. Comparative analysis of SM variations between the primary Vulnerability List (VL) and the Extended Vulnerability List (EVL) across baseline ( t = 0 ) and mitigated (t) operational states for both iBuC scenarios.
Figure 5. Comparative analysis of SM variations between the primary Vulnerability List (VL) and the Extended Vulnerability List (EVL) across baseline ( t = 0 ) and mitigated (t) operational states for both iBuC scenarios.
Vehicles 08 00120 g005
Table 1. Operational states of the Stochastic Petri Net (SPN) fleet management model.
Table 1. Operational states of the Stochastic Petri Net (SPN) fleet management model.
SPN Model StateiBuC-PTSiBuC-WFS
P 0 Fleet idle—EV charging
P 1 EV activated
P 2 EV arrives at BN
P 3 Service request is placed
P 4 EV arrives at DN
P 5 Third-party incoming data
P 6 Full-route service triggered
Table 2. Primary Vulnerability List (VL) for the iBuC framework with CVSS metrics.
Table 2. Primary Vulnerability List (VL) for the iBuC framework with CVSS metrics.
CVE IdentifierDescriptionCVSS Score
Base Temporal
CVE-2017-7214Information Exposure9.89.1
CVE-2018-4878(Resource) Use After Free9.89.1
CVE-2018-8174Failure to Constrain Operations7.57.3
CVE-2017-0199Access Control (Authorization) Issues7.86.6
CVE-2018-7600Improper Input Validation9.88.5
CVE-2018-12942OS Command Injection8.88.1
CVE-2018-14643Improper Authentication9.88.8
CVE-2018-10635Missing Critical Function Authentication9.87.9
CVE-2016-6829Use of Hard-coded Credentials9.88.7
CVE-2016-5788Improper Authorisation108.3
CVE-2016-5062Incorrect Resource Transfer9.88.3
CVE-2016-8209Improper Check7.56.6
CVE-2017-5239Inadequate Encryption Strength7.57.1
CVE-2017-17717Broken Cryptographic Algorithm9.89.3
CVE-2017-7901Use of Insufficiently Random Values8.67.6
CVE-2017-18146Improper Crypto Verification9.88.5
CVE-2016-5069Insufficient Session Expiration9.89.1
CVE-2016-7124Deserialization of Untrusted Data9.88.5
CVE-2018-12689LDAP Injection9.89.3
Table 3. Baseline and mitigated security metrics ( S M VL ) for primary iBuC scenario models.
Table 3. Baseline and mitigated security metrics ( S M VL ) for primary iBuC scenario models.
Scenario ModelSecurity Metric ( SM VL )
Baseline (t = 0) Mitigated (t)
iBuC-PTS9.148.15
iBuC-WFS9.098.09
Note: Baseline metrics ( t = 0 ) are derived from CVSS Base Scores; mitigated metrics (t) are derived from CVSS Temporal Scores incorporating environmental requirements.
Table 4. Evolutionary mapping of the iBuC framework: Primary Vulnerability List (VL) vs. Extended Vulnerability List (EVL).
Table 4. Evolutionary mapping of the iBuC framework: Primary Vulnerability List (VL) vs. Extended Vulnerability List (EVL).
CVE IdentifierDescriptionCVSS Scores Across Framework Evolution
Primary VL Extended VL
Base Temporal Base Temporal
CVE-2017-7214Information Exposure9.89.19.89.1
CVE-2018-4878(Resource) Use After Free9.89.19.89.1
CVE-2018-8174Out-of-bounds Write7.57.37.57.3
CVE-2017-0199Access Control (Authorization) Issues7.86.67.86.6
CVE-2018-7600Improper Input Validation9.88.59.88.5
CVE-2018-12942SQL Injection (Legacy Vendor Code)8.88.1
CVE-2018-7802SQL Injection (OCPP Interface)8.87.9
CVE-2018-14643Improper Authentication9.88.89.88.8
CVE-2018-10635Missing Critical Function Authentication9.87.99.87.9
CVE-2016-6829Use of Hard-coded Credentials9.88.7
CVE-2021-22730Use of Hard-coded Credentials9.88.8
CVE-2016-5788Improper Authorisation10.08.310.08.3
CVE-2016-5062Incorrect Resource Transfer9.88.39.88.3
CVE-2016-8209Improper Check7.56.67.56.6
CVE-2017-5239Inadequate Encryption Strength7.57.17.57.1
CVE-2017-17717Broken Cryptographic Algorithm9.89.39.89.3
CVE-2017-7901Use of Insufficiently Random Values8.67.68.67.6
CVE-2017-18146Improper Crypto Verification9.88.59.88.5
CVE-2016-5069Insufficient Session Expiration9.89.19.89.1
CVE-2016-7124Deserialization of Untrusted Data9.88.59.88.5
CVE-2018-12689LDAP Injection9.89.39.89.3
CVE-2018-7801Code Injection (OCPP Core)8.88.2
CVE-2020-27813Uncontrolled Resource Consumption7.56.7
CVE-2021-22706Cross-site Scripting (Web App)6.15.7
CVE-2021-22729Use of Hard-coded Password9.88.8
CVE-2018-16669Insufficiently Protected Credentials9.88.7
Note: Dashes (—) indicate that a vulnerability is structurally non-existent within that specific framework configuration phase or it has been replaced by another vulnerability. Boldface text isolates newly integrated protocol updates.
Table 5. Comparative analysis of baseline and mitigated security metrics for iBuC scenarios.
Table 5. Comparative analysis of baseline and mitigated security metrics for iBuC scenarios.
ScenarioOperational State SM VL SM EVL Δ SM
iBuC-PTSBaseline ( t = 0 )9.148.930.21
Mitigated (t)8.157.990.16
iBuC-WFSBaseline ( t = 0 )9.098.870.22
Mitigated (t)8.097.940.15
Note:  SM VL denotes the metric derived from the primary Vulnerability List; SM EVL denotes the metric derived from the Extended Vulnerability List; Δ SM = SM VL SM EVL .
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Garofalaki, Z.; Kallergis, D.; Voyiatzis, I.; Douligeris, C. Securing Wireless Charging Ecosystems in Intelligent Transport Systems: An OCPP-Based Cybersecurity Impact Analysis. Vehicles 2026, 8, 120. https://doi.org/10.3390/vehicles8060120

AMA Style

Garofalaki Z, Kallergis D, Voyiatzis I, Douligeris C. Securing Wireless Charging Ecosystems in Intelligent Transport Systems: An OCPP-Based Cybersecurity Impact Analysis. Vehicles. 2026; 8(6):120. https://doi.org/10.3390/vehicles8060120

Chicago/Turabian Style

Garofalaki, Zacharenia, Dimitrios Kallergis, Ioannis Voyiatzis, and Christos Douligeris. 2026. "Securing Wireless Charging Ecosystems in Intelligent Transport Systems: An OCPP-Based Cybersecurity Impact Analysis" Vehicles 8, no. 6: 120. https://doi.org/10.3390/vehicles8060120

APA Style

Garofalaki, Z., Kallergis, D., Voyiatzis, I., & Douligeris, C. (2026). Securing Wireless Charging Ecosystems in Intelligent Transport Systems: An OCPP-Based Cybersecurity Impact Analysis. Vehicles, 8(6), 120. https://doi.org/10.3390/vehicles8060120

Article Metrics

Back to TopTop