Tamper-proof inverter with security card for stand-alone operation without internet

The inverter with a security card ensures secure, autonomous operation by verifying control commands from certified sources, preventing unauthorized shutdowns and maintaining functions offline.

DE202025002371U1Active Publication Date: 2026-04-30HOGL PETER GEORG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
HOGL PETER GEORG
Filing Date
2025-08-18
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

Existing inverters in photovoltaic, battery storage, and hybrid energy systems are vulnerable to unauthorized remote shutdowns and manipulation due to remote access capabilities and proprietary firmware outside the operator's control, necessitating a secure, autonomous operation without internet dependency.

Method used

An inverter equipped with a security card that acts as a hardware firewall, cryptographically verifying control commands from certified sources, ensuring only authorized commands are executed, and maintaining operational functions independently.

Benefits of technology

The solution provides tamper-proof operation, preventing unauthorized shutdowns and ensuring all functions operate autonomously without an internet connection, with a replaceable security card for key updates and local command logging.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000003_0000
    Figure 00000003_0000
  • Figure 00000004_0000
    Figure 00000004_0000
  • Figure 00000005_0000
    Figure 00000005_0000
Patent Text Reader

Abstract

Inverter for converting direct current to alternating current, comprising: a DC input for connecting a direct current source, power electronics for generating alternating current, a control unit for regulating voltage and frequency, characterized in that the inverter is equipped with a slot or adapter for receiving a security card, the security card is designed as a hardware firewall and communication filter, the incoming control commands are cryptographically checked, only commands originating from an EU-certified source and validly digitally signed are permitted, and the inverter is designed for autonomous operation without an internet connection, whereby remote shutdown via the internet is technically impossible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field:

[0001] The invention relates to an inverter for converting direct current to alternating current, in particular for photovoltaic systems, battery storage systems, wind turbines or hybrid energy systems, with an integrated safety device to ensure tamper-proof control and operation without external communication dependency. State of the art:

[0002] Common inverters are often equipped with remote access capabilities that allow the system to be controlled or shut down via the internet. Many devices available on the market, especially those manufactured outside Europe, pose a risk of unauthorized remote shutdown or manipulation by unauthorized parties. These systems sometimes use proprietary firmware and cloud services that are outside the system operator's control. Therefore, there is a need for inverters that can be operated securely independently of external communication and whose control is carried out exclusively by trusted, certified sources. Purpose of the invention:

[0003] The object of the present invention is to provide an inverter that is protected against unauthorized remote shutdowns, whose control commands can only originate from certified, authorized sources, that is fully functional even without an internet connection, and that autonomously performs all operating and protection functions. Solution to the problem:

[0004] The task is accomplished by an inverter equipped with a slot or adapter for a security card. This security card acts as a hardware firewall and communication filter, cryptographically verifying all incoming control commands. Only commands originating from an EU-certified source and validly digitally signed are authorized for execution. The inverter is designed to operate without an internet connection, and remote shutdown via the internet is technically impossible. All operational and grid protection functions are fully maintained even in autonomous mode. Examples of implementation:

[0005] In a preferred embodiment, the security card comprises its own processor and non-volatile memory for storing cryptographic keys. The security card can be designed as a replaceable module, allowing for easy replacement in the event of key compromise. The security card's communication filter logs all incoming control commands and provides a local log output that can be evaluated by the operator. The inverter can be used in both grid-connected and off-grid systems.

Claims

[1] Inverter for converting direct current to alternating current, comprising: a DC input for connecting a direct current source, power electronics for generating alternating current, a control unit for regulating voltage and frequency, characterized by that the inverter is equipped with a slot or adapter for receiving a security card, the security card is designed as a hardware firewall and communication filter, incoming control commands are cryptographically checked, only commands originating from an EU-certified source and validly digitally signed are permitted, and the inverter is set up for self-sufficient operation without an internet connection, whereby remote shutdown via the internet is technically impossible. [2] Inverter according to claim 1, wherein the security card comprises its own processor and non-volatile memory for storing cryptographic keys. [3] Inverter according to claim 1 or 2, wherein the security card is designed as an interchangeable security module, the replacement of which enables an update of the cryptographic keys. [4] Inverter according to any of the preceding claims, wherein the communication filter of the security card logs all incoming commands and provides a local log output. [5] Inverter according to any of the preceding claims, wherein the control unit is configured to perform all operating and network protection functions completely autonomously, even in the absence of external communication. [6] System for operating an inverter according to one of the preceding claims, comprising the steps: receiving a control command, forwarding the command to the security card, cryptographically checking the command, releasing the blocking of the command depending on the test result, continuing to operate the system in autonomous mode without an internet connection. [7] Inverter according to any of the preceding claims , characterized by that it has an integrated reader for a starter chip card, wherein the starter chip card contains cryptographic keys and / or certificates required for the activation of the inverter, and wherein the inverter can only be operated if a valid starter chip card is present. [8] System for operating an inverter according to any of the preceding claims, comprising the steps of: (a) reading a starter chip card or a functionally equivalent security module via an integrated reader, (b) verifying the authenticity of the card using a cryptographic signature and / or a certificate, (c) enabling the inverter to operate only if the verification is successful, (d) refusing operation if the card is missing or invalid. [9] System comprising an inverter according to one of the preceding claims, a starter chip card or a functionally equivalent security module, and an optimal external authentication server, wherein the starter chip card contains cryptographic keys and / or certificates and the inverter can only be operated if a valid starter chip card is present. [10] Inverter according to any of the preceding claims, characterized bythat the authentication unit is designed as a portable or body-worn device (including key fob, handheld device, smartwatch, smartphone) and communicates with the inverter via a secure wireless connection. [11] Inverter according to claim 10, characterized by that the wireless connection uses at least one of the following technologies: Bluetooth Low Energy, Stub - GH2 - radio system, LoRa, WLAN, cellular network, ZigBee, UHF-RFD. [12] Inverter according to one of claims 10 or 11, characterized by that authentication is performed using challenge-response, one-time password, multi-factor authentication or rolling code. [13] Inverter according to any one of claims 10 to 12 characterized by , that a time-limited release is implemented, after which the inverter automatically returns to a safe locked state. [14] Inverter according to any one of claims 10 to 13 characterized by that the mobile authentication unit is powered by battery, rechargeable battery or via energy harvesting. [15] Inverter according to any one of claims 10 to 14 characterized by that the mobile authentication unit is designed for operation at large spatial distances (e.g. - 1 km) via LoRa or mobile communications. [16] Inverter according to any one of claims 10 to 15 characterized by that the mobile authentication unit is housed in a waterproof and shockproof casing.