Smart Meter Gateway with subsequently activatable network management functionality and method for subsequently activating a network management functionality of a Smart Meter Gateway
The smart meter gateway with a hardware-secured network management client and certificate memory allows for secure, cost-effective activation of network management functionality, addressing the challenge of subsequent activation without compromising security standards.
Patent Information
- Application Number
- DE102024105386
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-02-27
- Publication Date
- 2025-08-07
- Estimated Expiration
- 2044-02-27
AI Technical Summary
Existing smart meter gateways lack the ability to enable subsequent activation of network management functionality while maintaining stringent security requirements, particularly due to the absence of necessary infrastructure and the limitations of certificate runtime, leading to increased costs and potential security vulnerabilities.
A smart meter gateway with a mobile radio module and processor that supports a network management client, equipped with a certificate memory accessible only via hardware signals, allows for the secure storage and activation of network management profiles and certificates at a later stage, ensuring compliance with security standards through hardware-based configuration.
Enables secure and cost-effective activation of network management functionality at a later time, reducing operational costs and minimizing security risks by ensuring certificates and configurations are applied via secure communication channels.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] Smart Meter Gateways (SMGW) are the central components of intelligent metering systems. They receive meter data, store it, and prepare it for market participants. Accordingly, they serve as the central communication unit of intelligent metering systems, through which communication - with the Local Metrological Network (LMN) with consumption measuring points of one or more consumers, - with the home network (Home Area Network, HAN) of the end user, in particular with controllable energy consumers or energy producers, and - with the Wide Area Network (WAN), in particular with the SMGW administrator and external market participants.
[0002] Smart meter gateways are subject to strict security guidelines. Compliance with these guidelines must be demonstrated in a certification process conducted by the BSI. All security-critical elements subject to certification are summarized in the so-called "Target of Evaluation" (TOE).
[0003] According to the current state of the art, the connection of network communication is usually realized via mobile radio modules outside the TOE.
[0004] One problem arises from the fact that for the operational operation of SMGWs, the (large) network operators need the ability to monitor the connection quality of the mobile network connection and, if necessary, correct the network connection configuration. For security and organizational reasons, this is usually done in completely separate departments that have nothing to do with the actual supply network monitoring and do not exercise official Gateway Administrator (GWA) rights.
[0005] In order to implement such network management (NwMgmt) functions, it is known to use separate communication modules that connect the modem of the mobile radio module with the functionality of a router using their own operating system - typically an embedded Linux system - so that the communication module can forward data relating to network management functions and data relating to communication with the gateway administrator or external market participants in a differentiated manner.
[0006] During the certification of an SMGW, care is taken to ensure that no measured values or switching operations (functionality of the SMGW), nor any configured communication channels, can be compromised. Nevertheless, communication to the SMGW could be deliberately disrupted by a compromised network management system, which could prevent service availability and ultimately affect the stability of the entire supply network.
[0007] Therefore, functionalities such as Network Management, which is located directly on the LTE module, are subject to strict security requirements. This includes cryptographically secured communication with appropriate certificates.
[0008] These certificates must be transferred via a fully secure communication chain from the issuing Certificate Authority (CA) to a secure storage area of the LTE module. Furthermore, the remaining NwMgmt-specific configuration must also be applied to the LTE module using a tamper-proof mechanism.
[0009] The application of certificates has therefore already taken place during the production of the SMGW in the manufacturer's specially secured production area.
[0010] However, many SMGW operators (metering point operators) are not yet able to provide the infrastructure for network management immediately upon initial SMGW rollout. This means they would like to initially roll out SMGWs that do not yet support network management, but plan to integrate these into a network management infrastructure at a later date.
[0011] At the time of such subsequent activation in the field, certificates and configuration must of course already be applied to the LTE module.
[0012] However, a “predictive” application during the manufacturer’s safe production has several disadvantages: - The certificates have a strictly limited term, which means that the period within which activation can take place is also limited. - The meter operator often does not yet have the appropriate infrastructure, such as a public key infrastructure (PKI) and NwMgmt server, at the time of installation. Therefore, a server certificate or NwMgmt server configuration cannot be created at this time. - Since NwMgmt requires a completely separate communication channel, it may be necessary to maintain a "temporary" management server, which then carries out the configuration of the final customer-specific NwMgmt server. - If flat-rate certificates are installed for all SMGWs at the time of production, these are avoidable additional costs for the SMGWs that never receive NwMgmt.
[0013] DE 10 2016 112 278 A1 discloses a method for establishing fail-safe protection in a network comprising a client, a first server and a second server, the method comprising at least the following steps: one-time transmission of a main certificate assigned to the first server and at least one reserve certificate assigned to the second server to the client, submission of a request from the client to the first server, wherein after a successful request from the client to the first server, the first server authenticates itself to the client as the holder of the main certificate, and wherein if the request from the first server is unsuccessful, the client submits a request to the second server and the second server authenticates itself to the client as the holder of the reserve certificate.After successful authentication with the client, the first server or the second server establishes a secure connection between the client and the first server or the second server for the transmission of user data.
[0014] DE 10 2012 203 354 A1 relates to a method for personalizing a smart meter or smart meter gateway security module by a first computer system, wherein energy consumption-specific measurement data elements can be captured by the smart meter, wherein the security module has cryptographic functions for carrying out cryptographically encrypted communication of the measurement data elements received from the smart meter or the smart meter gateway with a second computer system of an energy supplier and / or metering point operator, wherein the method comprises the steps of: - providing the security module, - generating an asymmetric cryptographic key pair by the first computer system and storing the key pair in the security module, - signing the public key of the key pair to obtain a certificate and storing the certificate in the security module and / or a public directory server,wherein the signing is performed by the first computer system, wherein the security module is designed such that, after the key pair has been stored, initial communication access to the smart meter and / or the smart meter gateway is possible exclusively for the first computer system, wherein the security module can be enabled for communication with the second computer system through the initial communication access by the first computer system.
[0015] DE 10 2012 201 810 A1 discloses a method for initializing a memory area, wherein the memory area is assigned to a smart meter, the method comprising the steps of: - establishing a first communication channel between a first computer system and a security module, wherein the security module is assigned to the memory area, - authenticating the first computer system to the security module, - after successful authentication of the first computer system to the security module, receiving data from the first computer system by the security module through a secure transmission and storing the data in the memory area to initialize the memory area.
[0016] DE 10 2012 008 519 A1 describes an energy meter security system with a communication device that can be connected to an energy meter and an encryption module that is arranged in the communication device in a non-destructively removable manner, wherein the encryption module in the initial state allows restricted access to its functions.
[0017] The object of the invention is therefore to provide a smart meter gateway with subsequently activatable network management functionality and a method that enables a subsequent activation of a network management functionality of an already installed smart meter gateway in compliance with all security requirements in order to avoid the significant disadvantages described above.
[0018] These objects are achieved by a smart meter gateway having the features of patent claim 1 and by a method having the features of patent claim 2. Advantageous developments of the invention are the subject of the dependent patent claims.
[0019] The smart meter gateway according to the invention has a mobile radio module configured to forward measurement data to an authorized recipient via a mobile radio network. It also has a processor that interacts with a RAM and / or a flash memory to run metering software on an operating system, which reads and encrypts measurement data and transfers it to the mobile radio module for forwarding to an authorized recipient, in particular a network operator of an energy network, and to process different profiles and the functions defined therein.
[0020] The mobile radio module further comprises an embedded system that is configured or configurable to operate a network management client.
[0021] What is essential to the invention is that the mobile radio module additionally has a certificate memory which is configured in such a way that it can only be written to when the processor is processing a network management profile, with the writing being carried out via hardware signals and telegrams initiated by the processor.
[0022] An important aspect of the invention is to define a separate network management configuration profile in addition to the typical configuration profiles of a smart meter gateway, such as meter profiles, evaluation profiles, HAN or proxy communication profiles, with which the gateway administrator can configure the connection of external devices such as meters or CLS and influence the recording, processing and transmission of measured values, and to store at least the necessary certificates in the certificate memory of the mobile radio module when processing this network management configuration profile and to optionally carry out further configuration steps to set up a network management system and / or to put it into operation.
[0023] Because the certificate store is only accessed via hardware signals from the secure area formed by components of the Target of Evaluation, manipulation by third parties is virtually impossible with this approach. The processing of a given profile can be initiated at a specified time, which can be achieved in particular through intervention by the gateway administrator via their secure and certified communication channel; however, the additional network communication profile can also be uploaded at a later time via secure communication channels, for example, when the gateway administrator performs a software or driver update. This ensures activation at a later time and / or the inclusion of parameters that were not yet known at the time of rollout of the smart meter gateway.
[0024] Accordingly, the method according to the invention for subsequently activating a network management functionality of a smart meter gateway according to the invention is characterized in that the processor processes a provided network management profile for setting up and / or activating the network management functionality and, in doing so, certificates are stored in the certificate memory of the communication module, which interacts in particular with the embedded system that is set up to operate a network management client.
[0025] It is particularly preferred if, when processing the network management profile, the mobile radio module is also configured for the network management functionality.
[0026] It is also advantageous if the network management functionality is activated when the network management profile is processed, whereby the correct activation of the network management functionality is preferably also verified.
[0027] It is particularly preferred if the gateway administrator forwards the network management profile to the smart meter gateway to control the configuration and activation of the network management functionality. According to German regulations, the gateway administrator is responsible for the secure operation of smart meter gateways. This task is assumed by the primary or competitive meter operator or a company commissioned by the primary or competitive meter operator.
[0028] The meter operator, in cooperation with the gateway administrator, is responsible for the secure technical operation of the intelligent metering system. His tasks include, in particular, the commissioning, configuration, administration, monitoring, maintenance and IT connection of measuring devices and other technical equipment connected to the smart meter gateway. The gateway administrator has a secure communication channel, particularly for uploading updates to the smart meter gateway, and is certified for this purpose.
[0029] This means, in particular, that by forwarding the separate, dedicated network management profile by the gateway administrator, the upload of this network management profile to the smart meter gateway via existing, secure, and certified communication channels into the secure area of the smart meter gateway's target of evaluation can be ensured. Preferably, the network management profile is generated, signed, and encrypted by the smart meter gateway manufacturer, and then made available to the gateway administrator. This encryption is particularly preferred, using an official, public certificate provided by the authorized recipient.
[0030] If LTE parameters for a separate network management communication, a server certificate of a network management server, network management device certificates and / or an IP address of a network management server are stored in the network management profile, this enables configuration and commissioning of the network management functionality to the respective extent.
[0031] The invention is explained in more detail below by way of example using figures. Fig. 1 shows an embodiment of a smart meter gateway.
[0032] The Fig. The smart meter gateway 1 shown in Figure 1 has a target of evaluation 2, which includes a processor 3 interacting with a RAM 4 and a flash memory 5. A modem 10 of a mobile radio module 9 is connected via an interface 8.
[0033] In addition to the modem 10, the mobile radio module 9 includes an embedded system 11 on which a network management client 12 can be executed. The mobile radio module 9 also includes a certificate store 13.
[0034] The certificate store 13 interacts with the network management client 12 to communicate encrypted with the network management server via the mobile network, a network management APN (access point), and an internal network management network. For this purpose, certificates must be stored in it.
[0035] The processor 3 interacts in particular with the main memory 4 and the flash memory 5 to operate a metering software 19 on an operating system 18.
[0036] Within the scope of this operation, different profiles can be executed on the operating system 18 by the processor 3, in particular the profile with which measurement data, in particular from devices from a local metrological network, are read out and transmitted in encrypted form to the mobile radio module 9, which forwards them to the authorized recipient 15 via the modem 10 and the mobile radio network 14.
[0037] In order to set up the network management functionality and to store the certificates in the certificate store 13, the manufacturer of the smart meter gateway 1 additionally creates network management profiles in which, in particular, LTE parameters such as APN, user, password, IP version, etc. of the network management communication channel to the network management server, a server certificate of the network management server, its IP address as well as network management device certificates are stored and also instructions for storing the certificates and setting up and activating the network management functionality are included, which can be executed by the processor 3 when it executes this network management profile.The network management profile is signed with the official, public certificate of the network operator and made available to the gateway administrator via the secure processes set up for this purpose, who stores it in the Target of Evaluation 2 of the Smart Meter Gateway 1, as symbolized by the left part of the arrow 20, where it is processed by the processor 3.
[0038] During processing, the processor causes, as symbolized by the middle and right part of the arrow 20, hardware signals to be sent via the configuration interface 8, with which the network management client 12 is configured and, in particular, the certificates are written into the certificate store 13, which can only be written in this way.
[0039] In particular, it becomes clear that the time at which these processes are executed can be selected by the gateway administrator, who is commissioned by the meter operator role, and can also be after the (initial) commissioning of the smart meter gateway. List of reference symbols 1 Smart Meter Gateway 2 Target of Evaluation 3 processors 4 RAM 5 flash memory 7 Configuration interface 8 Interface 9 Mobile radio module 10 modems 11 embedded system 12 Network Management Client 13 Certificate stores 14 Mobile network 15 authorized recipients 18 Operating system 19 Metering Software 20 Arrow
Claims
[1] Smart Meter Gateway (1) with a mobile radio module (9) which is configured to forward measurement data to an authorized recipient (15) via a mobile radio network (14), and with a processor (3) which interacts with a main memory (4) and / or a flash memory (5) to run, on the one hand, metering software (19) on an operating system (18), with which measurement data is read out and encrypted and transferred to the mobile radio module (9) for forwarding to the authorized recipient (15), and, on the other hand, to process different profiles and functions defined therein, wherein the mobile radio module (9) further comprises an embedded system (11) which is configured or can be configured to operate a network management client (12), characterized bythat the mobile radio module (9) additionally has a certificate memory (13) which is set up in such a way that it can only be written to when the processor is processing a separate network management profile, wherein the writing is carried out via hardware signals and / or telegrams initiated by the processor (3). [2] Method for the subsequent activation of a network management functionality of a smart meter gateway (1) according to claim 1, characterized by that the processor (3) processes a separate network management profile for setting up and / or activating the network management functionality, whereby certificates are stored in the certificate memory (13) of the communication module (9). [3] Method according to claim 2, characterized by that when processing the network management profile, the configuration of the mobile radio module (9) for the network management functionality is also carried out. [4] Method according to claim 2 or 3, characterized bythat when the network management profile is processed, the network management functionality is also activated. [5] Method according to claim 4, characterized by that the correct activation of the network management functionality is verified when the network management profile is processed. [6] Method according to one of claims 2 to 5, characterized by that the network management profile is forwarded to the Smart Meter Gateway (1) by a gateway administrator to control the configuration and activation of the network management functionality. [7] Method according to claim 6, characterized by that the network management profile is created, signed and encrypted by the manufacturer of the Smart Meter Gateway (1) and then made available to the gateway administrator. [8] Method according to claim 7, characterized bythat the network management profile is encrypted with a public certificate provided by the authorized recipient (15). [9] Method according to one of claims 2 to 8, characterized by that LTE parameters for a separate network management communication, a server certificate of a network management server, network management device certificates and / or an IP address of a network management server are stored in the network management profile.
Citation Information
Patent Citations
Securing an energy meter against unauthorized access
DE102012008519A1
Method for initializing a memory area assigned to a smart meter
DE102012201810A1
Method for personalization of smart meter or smart meter gateway of security module in e.g. household, involves enabling initial communication accesses on smart meter and / or smart meter gateway is enabled for first computer system
DE102012203354A1
Procedure for establishing failover in a network
DE102016112278A1