Hierarchical Key Derivation for Smart Meter Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transmission methods in smart meter systems are vulnerable to security breaches due to the need to transmit master keys to insecure communication devices, which can lead to attacks on central units.

Innovation Solution

Deriving a third key from the master key using a definable parameter, such as time or event values, and transmitting this third key to communication participants, allowing the second key to be derived for secure data transmission without exposing the master key, thereby enhancing end-to-end security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the master key is transmitted to mobile data collectors for key derivation, then data transmission can be performed, but security is compromised as the master key can be accessed by third parties

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The master key is segmented through key derivation to create multiple hierarchical key levels (first key, second key, third key). Each derived key serves specific purposes and has limited scope, preventing any single key from providing complete system access. This segmentation ensures that even if one derived key is compromised, the master key remains secure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Derived keys act as intermediaries between the master key and actual data transmission operations. Instead of transmitting the master key directly to mobile data collectors, the system uses derived keys (third key transmitted to data collector, second key for actual transmission) as secure intermediaries that enable transmission without exposing the master key to insecure devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the master key is stored securely in the central unit, then security is improved, but the master key must still be transmitted to communication participants for key derivation

Engineering Contradiction:
ImprovesecurityVSAvoidmaster key exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The essential functionality of the master key is extracted through key derivation to create derived keys that can be transmitted to communication participants. The master key itself remains securely stored in the central unit and is never transmitted. The derived keys contain only the necessary information for specific transmission tasks, separating the master key's security function from transmission requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Derived keys are treated as temporary, disposable credentials with limited validity and scope. Each derived key is generated on-demand for specific transmission sessions and can be discarded afterward. This eliminates the need for long-term secure storage of master keys in insecure devices, as derived keys have limited lifecycle and scope.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If derived keys are transmitted to data collection devices, then end-to-end security is enabled, but the exposure period of derived keys creates vulnerability

Engineering Contradiction:
Improveend-to-end securityVSAvoidkey exposure period
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

Key derivation and transmission follows a periodic pattern where keys are generated, transmitted, used for a specific duration, and then discarded. The system establishes key validity periods and uses time-based or event-based counters to limit key lifespan. This periodic key rotation minimizes the exposure period of any single derived key, reducing the window for potential attacks.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3457625B1Data transmission method
Publication Date: 2022.04.13 DIEHL METERING SYSTEMS GMBH
  • EP3457625B1 patent drawingFigure 1
  • EP3457625B1 patent drawingFigure 2a~2c
  • EP3457625B1 patent drawingFigure 3a~3b

AI summary

Method for data transmission, in particular for consumption data transmission, between a central unit (1) and at least one consumption meter (2), wherein a data collection device (3) is provided between the central unit (1) and the consumption meter (2), which receives the data from the consumption meter (2) and transmits it to the central unit (1), the data being transmitted encrypted using a key, wherein a master key (5) is provided which is accessible to the central unit (1) and the consumption meter (2), and a second key (6) is used for data transmission, which is generated using the master key (5), wherein the central unit (1) and/or the respective consumption meter (2) derive a third key (7) from the master key (5), in particular using at least one definable parameter (8), and the third key (7) is transmitted to the data collection device (3).wherein the second key (6) is derived from the third key (7) by the central unit (1), the consumption meter (2) and/or the data collection device (3), and data transmission is carried out using the second key (6).