E-rickshaw battery hack by Chinese apps exposes India's critical cybersecurity gaps in connected systems, urging robust national strategy and global standard adoption.
E-rickshaws in Delhi experienced stalling due to vulnerabilities in their Battery Management Systems (BMS), exploited by certain Chinese apps.
The Ministry of Electronics and Information Technology (MeitY) directed Google and Apple to remove the problematic apps.
The incident highlighted that modern batteries are software-defined, connected systems, making them susceptible to cyber vulnerabilities that can disrupt critical operations.
India currently lacks a comprehensive cybersecurity strategy specifically for connected battery systems, despite having institutions like CERT-In and NCIIPC.
Detailed Insights:
The exploited apps were originally diagnostic tools for technicians, but weak or default credentials in some BMS units allowed unauthorized Bluetooth access to critical functions.
Such vulnerabilities in software-defined systems pose risks not only to electric vehicles but also to critical infrastructure like power grids, telecommunication systems, industrial automation, and defense platforms.
While CERT-In provides guidance on secure software development and vulnerability disclosure, its guidelines are not binding and offer limited specific advice for connected battery products.
The National Critical Information Infrastructure Protection Centre (NCIIPC) protects designated critical infrastructure sectors such as power and transport, but connected battery systems in EVs and consumer products often fall outside its direct jurisdiction.
Existing sectoral regulations and security assurance mechanisms from the Central Electricity Authority, Department of Telecommunications, and MeitY address cybersecurity in fragmented ways and do not specifically cover Bluetooth-enabled BMS and their management apps.
The security of modern battery systems, which integrate hardware and software from global sources, is heavily dependent on the integrity of their digital supply chain.
International frameworks like the US Secure Software Development Framework, the EU Cyber Resilience Act, and the Digital Battery Passport emphasize auditing software provenance, firmware integrity, and vulnerability management across the digital supply chain.
India can enhance its battery cybersecurity by integrating CERT-In guidance on secure software development, Software Bills of Materials (SBOMs), vulnerability disclosure, and cybersecurity audits into national battery standards.
Scientific/Technical Concepts Involved:
Battery Management System (BMS): An electronic system that monitors and manages a rechargeable battery pack to ensure safe operation, optimal performance, and extended lifespan.
Software Bills of Materials (SBOMs): A comprehensive, machine-readable inventory of all components, libraries, and modules used in a software product, aiding in vulnerability tracking and supply chain risk mitigation.
Digital Supply Chain: The interconnected network of digital processes, software, and data involved in the design, production, and delivery of a product, extending beyond physical components.
Coordinated Vulnerability Disclosure (CVD): A process where a vulnerability is disclosed to the public only after responsible parties have had sufficient time to patch or remedy the issue, minimizing potential harm.