India has strengthened cybersecurity requirements for electric vehicle (EV) battery management systems (BMS), introducing mandatory testing for systems that use Bluetooth and other wireless communication interfaces, The Economic Times reported.
The new provisions under AIS-156 are aimed at preventing unauthorised devices or applications from accessing or controlling critical functions of rechargeable electrical energy storage systems (REESS).
The requirements apply to BMS equipped with Bluetooth Classic, Bluetooth Low Energy (BLE) and other wireless interfaces capable of accessing battery information or issuing commands.
Under the revised framework, testing agencies will attempt to discover and connect to the BMS using standard Bluetooth scanning and inspection tools rather than the manufacturer’s authorised application.
The tests will examine whether an unauthorised device can access live information such as battery voltage, current, temperature and state of charge. They will also check whether it can control charging or discharging, operate battery contactors, alter protection settings or carry out firmware read, write or update operations.
The BMS must prevent safety-critical commands from being executed unless the connected device or application has successfully completed authentication and authorisation.
Testing will include attempts to operate contactors, enable or disable charging and discharging, change cell-balancing functions, modify battery protection settings and initiate BMS reset or shutdown.
These checks will also be conducted under simulated vehicle-running conditions to ensure that cybersecurity controls remain effective when the battery is operating normally.
The new requirements also cover replay, spoofing and man-in-the-middle attacks.
In replay testing, laboratories will capture legitimate wireless commands and attempt to send them again. The BMS must reject such commands and demonstrate safeguards such as session keys, nonces, counters or timestamp checks.
For spoofing tests, a rogue device may attempt to imitate the identity of a legitimate BMS. The manufacturer’s companion application must be able to identify and reject the fake device, while the pairing process must prevent communication keys from being exposed.
The amendment also examines whether cyberattacks or abnormal wireless traffic could interfere with essential battery protection.
During denial-of-service or “bluesmacking” tests, the BMS will face large numbers of connection requests, oversized data packets and malformed Bluetooth frames while operating under simulated driving conditions.
Despite such attacks, critical safeguards against overcharging, over-discharging, excessive temperature, overcurrent and short circuits must continue to function. Abnormal wireless traffic must not cause unintended operation of contactors, relays or switches.
Testing will further cover malformed and out-of-specification wireless requests to ensure they cannot trigger safety-critical functions or weaken battery protection.
BMS manufacturers will also have to provide information about their wireless interfaces, including the chipset used, Bluetooth profiles and services, pairing method and commands or functions that can be accessed through the connection.
The revised requirements mark a broader move to ensure that wireless connectivity in EV batteries does not create a pathway for unauthorised access to functions directly linked to vehicle and battery safety.















