Centralized Authorization for Secure Mobile Meter Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Automated Metering Infrastructure (AMI) and Automated Meter Reading (AMR) systems lack secure methods for mobile meter readers to access meters without compromising security, as they cannot securely communicate with meters due to the lack of a centralized authorization system.

Innovation Solution

A method is implemented where a mobile meter reader requests authorization from a host computing system, which generates and encodes a digital signature for secure communication with the meter, ensuring that the private key remains centralized and not distributed to the mobile device, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric key cryptographic techniques are implemented to secure communications, then security is improved, but the private key must be distributed to communication devices which creates security vulnerabilities

Engineering Contradiction:
Improvecommunication securityVSAvoidunauthorized access risk from distributed private keys
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key from the mobile communication device and relocates it to a centralized secure server. The mobile device only stores a public key and receives encrypted authorization tokens from the server, eliminating the security vulnerability of distributing private keys while maintaining cryptographic security for meter access communications

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a centralized secure server as an intermediary between the meter and mobile devices. This server acts as a trusted mediator that holds the private key securely, generates encrypted authorization tokens, and manages access control, thereby enabling secure communications without distributing private keys to mobile devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If mobile meter readers are used to access meters, then operational flexibility is improved, but security control becomes difficult without centralized authorization management

Engineering Contradiction:
Improvemobile access flexibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary authorization where the centralized server pre-generates encrypted authorization tokens containing digital signatures before mobile devices access meters. This preliminary security setup allows mobile devices to operate flexibly in the field while maintaining centralized security control through pre-established cryptographic credentials

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent adds a centralized authorization management dimension to the mobile access system. By introducing a server layer that operates in a different dimension (centralized cloud infrastructure versus distributed mobile devices), the system achieves both mobile flexibility and centralized security control through multi-dimensional architecture

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2449722B1Secure meter access from a mobile reader
Publication Date: 2017.08.16 ITRON INC
  • EP2449722B1 patent drawingFigure 1
  • EP2449722B1 patent drawingFigure 2
  • EP2449722B1 patent drawingFigure 3

AI summary

Generally described, the disclosed subject matter is directed to improved processes for securely accessing a meter. In accordance with one embodiment, a method for providing a mobile meter reader with an authorization that may be used to establish a secure session with a meter is implemented. In particular, the method includes issuing a request for authorization to access the meter from the mobile meter reader. If the mobile meter reader maintains sufficient rights, an authorization having an encoded digital signature is generated at a host computer system and provided to the mobile meter reader. Then the method formulates and transmits an authorization command to the meter having the encoded digital signature that was generated by the host computing system.