Secure Element for Smart Metering Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart metering systems are vulnerable to remote attacks on their central controllers, allowing unauthorized access and tampering with metrology data, which can lead to under-billing and privacy breaches.

Innovation Solution

A metering system with a secure element positioned between the metrology unit and the controller, storing digital metrology data locally before transmission, using cryptographic elements for protection and authentication, and ensuring the controller lacks direct access to the storage, thus preventing tampering and maintaining data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the controller directly processes and transmits metrology data, then the system structure is simpler and response time is shorter, but the system becomes vulnerable to remote attacks and data tampering

Engineering Contradiction:
Improvedata integrityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A secure element is introduced as an intermediary component between the metrology unit and the controller. This secure element stores metrology data locally and provides authenticated access to the controller, preventing direct access to sensitive data while maintaining system functionality. The secure element acts as a mediator that protects data integrity without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into distinct functional modules: the metrology unit for data collection, the secure element for data storage and protection, and the controller for processing and transmission. This segmentation isolates the secure storage function from the control function, allowing the controller to be compromised without affecting data integrity, while maintaining overall system reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic security measures are implemented in the controller, then data protection improves, but the controller becomes a larger target for attacks and more complex

Engineering Contradiction:
ImprovesecurityVSAvoidcontroller complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic security functions are extracted from the controller and relocated to a dedicated secure element. This separation removes the security burden from the controller, reducing its complexity while maintaining strong data protection. The secure element handles all cryptographic operations independently, allowing the controller to focus on processing and communication functions.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If metrology data is stored locally before transmission, then data integrity is protected against controller compromise, but storage capacity requirements increase

Engineering Contradiction:
Improvedata integrityVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Metrology data is stored locally in the secure element before transmission to the controller. This preliminary storage action ensures that even if the controller is compromised during transmission or processing, the original data remains protected and intact in the secure element. The local storage provides a safety buffer that maintains data integrity throughout the data lifecycle.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2543974B1Metering system having improved security
Publication Date: 2014.02.26 NXP BV
  • EP2543974B1 patent drawingFigure 1
  • EP2543974B1 patent drawingFigure 2a~2b
  • EP2543974B1 patent drawingFigure 3~4

AI summary

Metering system (200) comprising a metrology unit (120) configured for obtaining digital metrology data representing a measured physical quantity representing use of a utility (210), a controller (110) configured for transmitting protected usage information based on the digital metrology data to an external server (220), and a secure element (240), wherein the secure element is arranged between the metrology unit and the controller, the secure element being connected to the metrology unit for receiving from the metrology unit the digital metrology data, the secure element being connected to the controller for sending the protected usage information to the controller, and the secure element comprises a local storage (246) for storing data dependent upon the received digital metrology data, the stored data representing the received digital metrology data for at least a predetermined period of time.