EV Charging & Smart Energy Security

Root of Trust
Tamper Detection
PIN Encryption
PUF

With Europe’s public charger base scaling from 1.1M to over 3.5M units by 2030, TROPIC01 provides the auditable, EU-sourced secure element built for the current control-board redesign cycle.

About

Build compliance and trust Into every EV charger

EV charger hardware design teams now face multiple converging regulatory requirements, particularly in the EU where ISO 15118-20 and the Cyber Resilience Act (CRA) support is mandated for future devices from 2027. Unattended outdoor boxes connected to critical energy grids and payment systems are prime cybersecurity targets. Researchers at Saiflow were recently able to access an EV charger using default login credentials demonstrating the need for implementing stricter security measures in this hardware class such as a root-of-trust.

Tropic Square manufactures TROPIC01, an auditable, EU-sourced secure element designed to serve as a device integrity anchor. We secure the hardware boot chain, protect per-device OCPP client certificates, store metering keys, and execute cryptographic handshakes inside side-channel-resistant silicon. By combining open firmware transparency with published vulnerability handling, TROPIC01 provides the inspectable evidence compliance officers and auditors demand.

Charge Controller Communications Board
Host Linux SoM
– High-Throughput Session Streaming (TLS)
- OpenSSL Provider Integration
SPI Bus (Noise Channel)
Tropic01 – Secure Element
– P-256 Handshake Signing
– OCPP 2.0.1 Client Keys
– Secure Boot & Monotonic
– PUF Silicon Identity
Cellular / Ethernet Gateway
Backend / Billing Settlement

What Security Benefits Integrating TROPIC01 Provides

1
ISO 15118-2 P-256 Handshake Execution

Handles NIST P-256 (secp256r1) signature operations natively inside hardened silicon. The charger’s TLS private key remains isolated in hardware, while high-throughput session streaming is passed cleanly to the host Linux processor.

2
Purpose-Built HSM vs. TPM Trade-Offs

Meets ISO 15118 HSM key custody guidelines as an outdoor-hardened secure element. Features physical glitch/EM defense and inspectable, auditable firmware. This gives compliance leads auditable evidence for CRA files where black-box TPMs fail.

3
Individual device identities

Isolated per-charger client credentials via the Physically Unclonable Function (PUF) ensure a rooted charger cannot clone network identity or alter CSMS billing systems.

4
Hardware Monotonic Counters & State Protection

Enforces non-resettable sequence tracking to lock out firmware rollback attacks and deliver tamper-evident logs for cryptographic energy metering.

TS1302 Evaluation board

Every part an EV charger integration touches, on one USB-C stick.

IC1 – TROPIC01 secure element

P-256 handshake signing, OCPP client keys, secure boot anchoring and PUF identity. Keys never leave the die.

IC2 — Host MCU (STM32U5)

Stands in for the charge controller's Linux SoM. Runs libtropic and drives the secure element over SPI.

SPI bus breakout

VCC · GPO · SDI · SDO · SCK · CSN · GND — the same four-wire interface plus handshake pins used on the control board.

USB-C power & console

Bus-powered bench setup. Plug into a laptop and evaluate the full host–secure element chain; no external supply.

SPI bus breakout

VCC · GPO · SDI · SDO · SCK · CSN · GND — the same four-wire interface plus handshake pins used on the control board.

USB-C power & console

Bus-powered bench setup. Plug into a laptop and evaluate the full host–secure element chain; no external supply.

How TROPIC01 maps onto the EV charging environment

TROPIC01’s features map well to the needs of EV charging stations in high exposure sites with little to no monitoring and surveillance.

Purpose-Built Hardware Security

Secure elements are built specifically for exposure in less secure environments like the outdoors. TROPIC01 acts as a standards-legitimate HSM tailored for unattended EV chargers—combining active mesh shields, PUF key generation, and fault-injection (EM/glitch) defenses. It serves as an alternative HSM implementation to the TPM 2.0 suggested in ISO15118 guidelines.

TLS & OCPP 2.0.1 Handshake Protection

Executes TLS handshake signatures, and holds per-charger client certificate keys for OCPP Security Profile 3. Private keys never leave hardened silicon—preventing fleet credential cloning while bulk session streaming remains on the host.

Root of Trust & Secure Boot

TROPIC01 anchors the host Linux boot chain; before the application processor initialises, the secure element cryptographically verifies the bootloader and kernel signatures, preventing unauthorized firmware modifications, rollback attacks, and persistent root compromises. This silicon-enforced device integrity gives platform architects the verifiable evidence required to satisfy CRA secure-by-design mandates.

TRNG & key custody

TROPIC01 combines dual hardware True Random Number Generators (2x TRNG compliant with NIST SP 800-90B and AIS31) with isolated key custody to secure critical charge controller operations. High-entropy generation guarantees cryptographically robust TLS handshakes.

Ready Integration with Linux SoM

TROPIC01 connects to the primary Linux SoM via a standard SPI, integrating cleanly into the charge controller architecture.

TRY TROPIC01

Start with the devboard

Globally available, ships within days, everything needed to run the examples and verify the certificate chain.