Qi Xie, Jie Wang
Vehicle-to-Grid (V2G) technology enables bidirectional energy exchange between electric vehicles (EVs) and the power grid, offering a sustainable solution for energy management. However, V2G systems are susceptible to significant security and privacy threats. Recently, Shureshkumar et al. proposed an authentication protocol to secure V2G communication, but subsequent research by Yu et al. revealed vulnerabilities in their approach, including susceptibility to charging station (CS) capture attacks. Yu et al. proposed an improved protocol, but it still fails to address critical issues. In this paper, we further analyze these vulnerabilities and demonstrate that both internal and external adversaries can exploit existing protocols to launch user and charge station impersonation attacks, CS capture attacks, and man-in-the-middle attacks. To address these challenges, we propose a novel PUF-based lightweight authentication protocol specifically designed for V2G communication. The proposed protocol leverages Physical Unclonable Functions (PUFs) and advanced cryptographic techniques to achieve enhanced security properties, including three-factor authentication, dynamic pseudonym updates. Through formal security analysis under the random oracle model, we validate the robustness of the protocol against a wide range of attacks. Additionally, our evaluation demonstrates that the proposed scheme achieves superior security features with minimal computational overhead, making it ideal for resource-constrained V2G environments.