Secure AMI End Device Configuration via Program Recipe

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches to reconfiguring end devices in advanced metering infrastructure (AMI) networks lack efficiency and stability, and expose security vulnerabilities, particularly when dealing with multiple vendors and varying communication protocols and topologies.

Innovation Solution

A method for configuring end devices via an AMI network using a program recipe that includes configuration parameters, where the program recipe is decrypted and validated by the end device, allowing for secure and efficient communication without exposing configuration details to the AMI head-end, and enabling atomic delivery and validation of the program recipe.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing reconfiguration approaches are used, then end devices can be programmed remotely, but configuration data is exposed to AMI head-end systems creating security vulnerabilities

Engineering Contradiction:
Improveremote reconfiguration capabilityVSAvoidexposure of sensitive configuration information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption layer between the AMI head-end system and the end device. The configuration data is encrypted using device-specific keys before transmission, and only decrypted by the target end device. This intermediary encryption mechanism allows remote reconfiguration to proceed while preventing direct exposure of sensitive configuration information to the AMI head-end, thus resolving the security vulnerability without sacrificing operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If step-by-step reconfiguration is used, then reconfiguration can be performed, but partial configuration may result if network communications interrupt the programming sequence

Engineering Contradiction:
Improvereconfiguration processVSAvoidconfiguration completeness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by validating the entire configuration program against the device's generic program table before execution begins. The AMI head-end system verifies that the configuration program is complete and valid in advance, ensuring that if network communications are interrupted during transmission, the device can still execute the complete validated program or reject it entirely, preventing partial and potentially harmful configurations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies beforehand cushioning by implementing atomic delivery mechanisms and transactional integrity checks. The configuration is delivered as an atomic unit with validation ensuring completeness before execution. If interruption occurs, the system can rollback or retry the complete configuration package, cushioning against the harmful effects of partial configuration and ensuring reliability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Adaptability or versatility

If vendor-specific programming tools are used for each end device manufacturer, then device-specific configuration can be achieved, but system complexity increases as number of devices and device types increases

Engineering Contradiction:
Improvedevice-specific configuration capabilityVSAvoidmanagement complexity of multiple programming tools
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by defining a standardized generic program table that serves as a common framework for all end devices regardless of manufacturer. This generic program table includes standardized data structures, validation rules, and configuration parameters that can be universally applied. Vendor-specific configuration needs are accommodated through this universal framework without requiring separate programming tools for each vendor, thus reducing management complexity while maintaining device-specific adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9068858B2Generic and secure AMI end device configuration
Publication Date: 2015.06.30 ELSTER SOLUTIONS LLC
  • US9068858B2 patent drawing
  • US9068858B2 patent drawing
  • US9068858B2 patent drawing

AI summary

A metering device may be configured to communicate with other devices on a plurality of metering communication networks, such as an advanced metering infrastructure (AMI) network. For example, a metering end device may be programmed or reconfigured via an AMI network. A metering end device may receive, via the AMI network, a program recipe comprising one or more configuration parameters. The program recipe may be specific to the end device and formatted according to a generic program table of the end device. The end device may decrypt and validate the program recipe. The end device may implement the decrypted program recipe to configure the end device with the one or more configuration parameters.