India's growing fleet of electric buses could be vulnerable to remote shutdown and control if their Vehicle Control Units (VCUs) and associated software originate from China, warns Sudhir Mehta, Chairman and Managing Director of Eka Mobility. The concern follows a government advisory on critical vulnerabilities in electric vehicles, prompted by incidents where a Chinese app, BAT-BMS, was used to remotely immobilize e-rickshaws.
Sovereignty of Software is Key
Mehta emphasized that vehicle control software must be sovereign and controlled within India. VCUs are the digital brains of connected electric vehicles, governing crucial functions such as battery management, motor control, power electronics, vehicle movement, and over-the-air software updates. "One who controls the VCU can immobilise the vehicle and also make the vehicle move on its own," Mehta stated.
The issue gained prominence after the government issued an urgent advisory to the automobile industry. Videos circulating showed e-rickshaws unexpectedly halting due to the misuse of the BAT-BMS app, developed by China's Shenzhen Grenergy Technology.
Indian Manufacturers and Chinese Partnerships
Several Indian electric bus manufacturers have technical collaborations with Chinese companies for critical technologies. Hyderabad-based Olectra Greentech, for instance, partners with China's BYD, importing battery management systems (BMS) and some motor components. Similarly, Gurugram-based PMI Electro has a collaboration with China's Beiqi Foton Motor Co., and notably secured a significant order for 5,210 electric buses under the government's PM E-Drive scheme.
While Eka Mobility also sources battery cells from China, Mehta highlighted his company's substantial investment in owning and controlling its vehicle control software, having secured an order for around 3,500 e-buses itself.
National Security and Data Implications
Mehta's concerns extend beyond cybersecurity to national security. He pointed out that connected vehicles constantly generate operational data, including location, movement, and usage patterns. Public transport vehicles like electric buses often transmit additional sensitive information, such as camera feeds, to government authorities.
"In a worst-case scenario, a compromised vehicle could even be remotely controlled, creating significant safety and security risks," Mehta warned, stressing the critical importance of protecting this information.
If vehicle control software originates outside India and automakers do not possess the source code, they become dependent on external entities for software modifications and troubleshooting. This dependency raises serious questions about cybersecurity, vehicle safety, and operational control, especially as India aims for large-scale electrification of public transport.
Government Advisory and Future Steps
In response to these threats, the government has advised the industry to take immediate steps to safeguard India’s electric vehicle ecosystem. This includes auditing battery communication interfaces, eliminating unsecured default settings, addressing weak authentication protocols, and securing over-the-air pathways.
For India's electric vehicle future, securing the digital infrastructure of these vehicles is as crucial as their adoption. Developing indigenous vehicle control software within India is seen as a vital step towards ensuring national security and operational autonomy.