While photovoltaics (PV) play an increasingly central role in Europe’s clean energy transition and energy independence, a hidden vulnerability threatens this progress: the software-based remote access to inverters, the critical “brains” of any PV system.

“Today, over 200 GW of European PV capacity is already linked to inverters manufactured in China – the equivalent of more than 200 nuclear power plants,” said Christoph Podewils, the European Solar Manufacturing Council (ESMC) Secretary General.

“This means Europe has effectively surrendered remote control of a vast portion of its electricity infrastructure.”

[…]

Further concerns include:

  • 70% of all inverters installed in 2023 came from Chinese vendors, mainly Huawei and SunGrow.
  • These two companies alone already control remote access to 168 GW of PV capacity in Europe (DNV Report, p. 40), by 2030, this figure is projected to exceed 400 GW – comparable to the output of 150–200 nuclear power plants.
  • One of these vendors [China’s Huawei] is already banned from the 5G sector in many countries and is currently under investigation in Belgium for bribery and corruption.

[…]

In light of these findings, the ESMC calls for the immediate development of an EU “Inverter Security Toolbox”, modeled after the successful 5G Security Toolbox. This would involve:

  • A comprehensive risk assessment of inverter manufacturers.
  • A requirement that high-risk vendors must not be permitted to maintain an online connection to European electricity systems.
  • Consideration of outright bans for such vendors from connecting to the grid.
  • A replication of Lithuania’s proactive legislation – banning inverters from China – across all EU Member States – ensuring security measures apply to PV systems of all sizes.
  • SkyNTP@lemmy.ml
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    1
    ·
    2 days ago

    Here’s an idea: instead, ban devices that do not function without an internet connection. Devices are not “smart” when you have no sovereignty over them.

    • cynar@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Just to play devil’s advocate. There was recently an unverified report that some inverters contained an undocumented cellular modem. If true, it could, in theory, allow for remote modification or control, even when fully “offline” as far as the client was concerned. Basically a mobile phone based back door.

      The solution is better verification, rather than bans however. Grid scale devices should have the hardware randomly audited. The software should also be audited and check summed. This would be burdensome at domestic levels, but seems reasonable at grid levels.

    • varyingExpertise@feddit.org
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      Absolutely this. I have limited experience with the whole home automation market, but I find the Shelly model to be perfect: Local access via BLE or LAN ist always enabled out of the box, cloud (run by Shelly) requires a checkbox to be activated.