This study re-examines the protocol introduced in A robust ECC-based authentication framework for energy internet (EI)-based vehicle to grid communication system by Itoo et al. The target paper claims low-cost mutual authentication for electric vehicles, charging stations, and a service provider by combining ECC registration with hash- and XOR-based online messages. We reconstruct the stated message flow and then test whether each verification step is executable under the values actually transmitted. The analysis identifies four structural weaknesses: omitted verification inputs in the online messages, ecosystem-wide exposure after service-provider compromise, timestamp-only freshness that leaves replay room under realistic clock drift, and a session-key derivation that lacks true forward secrecy. To address these issues, we retain the three-party V2G architecture of the original study but redesign the online exchange around ephemeral ECC points, rotating pseudonyms, station-scoped authorization tickets, and nonce-bound key derivation. Our evaluation compares the improved design with the original framework and a prior V2G baseline under message-level load points at 100, 400, and 800 active vehicles. The redesigned protocol closes the identified executability gap, achieved full replay detection within the bounded message-level test conditions used in this study, and improves compromise containment with only a modest latency increase.
Haewon Byeon (Thu,) studied this question.