Cryptographic Backend for Secure Meter Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing energy metering systems lack robust security measures for secure communication over networks, particularly in remote metering infrastructure, making them vulnerable to compromise and data integrity issues.

Innovation Solution

A cryptographic backend system utilizing asymmetric key generation, signing and encryption servers, and key management protocols to ensure secure communication between utilities and meters, employing protocols like C12.22 for secure data transmission and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic backend systems with asymmetric key generation and signing servers are implemented, then security and data integrity are improved, but device complexity and infrastructure requirements worsen

Engineering Contradiction:
ImprovesecurityVSAvoidinfrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a cryptographic backend system as an intermediary component between the metering infrastructure and external networks. This backend includes signing servers and key management systems that mediate all secure communications, providing cryptographic services without requiring complex security implementations in each meter device. The intermediary handles key generation, signing operations, and certificate management centrally, thus improving overall system security while keeping individual device complexity manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic functionality is segmented into distinct modular components: a cryptographic backend system, signing servers, key management modules, and meter-side clients. This segmentation allows each component to be independently deployed, managed, and optimized. The complex cryptographic operations are isolated in dedicated servers rather than distributed across all devices, reducing the complexity burden on individual devices while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If secure communication protocols with asymmetric encryption are used, then data authenticity is improved, but processing time and computational overhead worsen

Engineering Contradiction:
Improvedata authenticityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary cryptographic actions by pre-generating asymmetric key pairs and signing certificates during device initialization and provisioning phases. Public keys and certificates are pre-distributed to meters before they begin operational communication. This preliminary setup eliminates the need for real-time key generation and certificate creation during data transmission, significantly reducing processing time while maintaining strong authentication capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cryptographic system supports dynamic parameter adjustments, including configurable key lengths, signature algorithms, and security policy parameters. The system can adapt cryptographic parameters based on security requirements and performance constraints, allowing optimization of the balance between authentication strength and processing speed. Different communication scenarios can use different cryptographic parameter sets to achieve optimal performance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9037844B2System and method for securely communicating with electronic meters
Publication Date: 2015.05.19 ITRON INC
  • US9037844B2 patent drawing
  • US9037844B2 patent drawing
  • US9037844B2 patent drawing

AI summary

An infrastructure for securely communicating with electronic meters is described, which enables secure communication between a utility and a meter located at a customer, over a communication link or connection such as via a network. This enables messages to be sent from the utility to the meter and vice versa in a secure manner. The network provides a communication medium for communicating via the C12.22 protocol for secure metering. A cryptographic backend is used to cryptographically process messages to be sent to the meter and to similarly cryptographically process messages sent from the meter. By providing appropriate cryptographic measures such as key management, confidentiality and authentication, the meter can only interpret and process messages from a legitimate utility and the utility can ensure that the messages it receives are from a legitimate meter and contain legitimate information.