Smart Meter Security Module Personalization via Asymmetric Key Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart meter and smart meter gateway security systems face challenges in ensuring secure and authorized communication, particularly in preventing unauthorized access and data tampering, while maintaining the integrity and uniqueness of energy consumption data.

Innovation Solution

A method for personalizing a smart meter or smart meter gateway security module involves generating an asymmetric cryptographic key pair, signing the public key with a certificate, and irreversibly binding it to the device, ensuring only authorized entities can communicate and access the data, with a unique identifier for secure and tamper-proof operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security module is installed in a smart meter or smart meter gateway, then secure communication and data integrity are improved, but the complexity of the system increases due to the need for cryptographic key management and certificate validation

Engineering Contradiction:
Improvesecure communicationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-installing a security module with cryptographic capabilities in the smart meter or smart meter gateway before operation. The security module is configured with necessary cryptographic algorithms and initial security parameters during manufacturing or deployment, so that secure communication can be established immediately without complex runtime configuration. This resolves the contradiction by preparing security infrastructure in advance, reducing operational complexity while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a security module as an intermediary component between the smart meter/gateway and external systems. This security module handles all cryptographic operations, key management, and certificate validation, acting as a mediator that isolates the complex security functions from the main smart meter system. By delegating security tasks to this dedicated intermediary component, the overall system complexity is managed while ensuring reliable secure communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic key pairs and certificates are stored in the security module, then access control and authorization are improved, but the time required for initial setup and personalization increases

Engineering Contradiction:
Improveaccess controlVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating and storing asymmetric cryptographic key pairs and certificates in the security module during the personalization phase, before the smart meter becomes operational. The security module is configured with these cryptographic credentials in advance, allowing immediate establishment of secure communication channels without time-consuming setup procedures during deployment. This resolves the contradiction by performing cryptographic configuration beforehand, ensuring strong access control while minimizing setup time during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module is designed to be self-sufficient with embedded cryptographic capabilities, automatically managing key pairs and certificates without requiring external intervention during operation. The module performs self-configuration and self-validation of cryptographic credentials, reducing the time and manual effort needed for setup while maintaining rigorous access control standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If an irreversible binding process is implemented between the security module and smart meter, then prevention of unauthorized access and tampering is improved, but the ability to replace or upgrade security modules is reduced

Engineering Contradiction:
Improvetamper preventionVSAvoidmodule replaceability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary anti-action by implementing an irreversible binding mechanism between the security module and the smart meter or smart meter gateway during initial installation. This binding process creates cryptographic and physical links that prevent removal or replacement of the security module, thereby proactively preventing unauthorized access and tampering before they can occur. The irreversible nature of this binding ensures tamper prevention while the system is designed to accept this trade-off in terms of module replaceability, as the primary goal is security integrity.

Inventive Principle:
Principle #9Preliminary anti-action

4Loss of information

If a unique identifier is assigned and stored in the security module, then tracking and identification of devices are improved, but the risk of identifier theft and cloning increases

Engineering Contradiction:
Improvedevice identificationVSAvoididentifier theft risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent applies asymmetry by using asymmetric cryptographic key pairs where the unique identifier is derived from or protected by the private key that never leaves the security module. The public key or derived identifier can be stored and transmitted for device identification purposes, but the underlying private key remains securely confined within the security module. This asymmetric structure enables device tracking and identification while preventing identifier theft and cloning, as the security of the unique identifier is cryptographically bound to the secure hardware environment.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentEP2812837B1Method for personalizing a security module for a smart meter or smart meter gateway
Publication Date: 2019.05.01 BUNDESDRUCKEREI GMBH
  • EP2812837B1 patent drawingFigure 1
  • EP2812837B1 patent drawingFigure 2
  • EP2812837B1 patent drawingFigure 3

AI summary

The invention relates to a method for personalizing a smart meter or smart meter gateway security module (100) by means of a first computer system (150), energy consumption-specific measurement data elements being detectible by means of the smart meter (142; 144; 146; 148), the security module (100) having cryptographic functions for carrying out a cryptographically encoded communication of the measurement data elements received by the smart meter (142; 144; 146; 148) or the smart meter gateway (138) and a second computer system (166) of a utility company and/or operator of a measuring system, the method comprising the steps of: making the security module (100) available; generating an asymmetrical cryptographic pair of keys by means of the first computer system and storing the pair of keys in the security module (100); signing the public key of the pair of keys to obtain a certificate and storing the certificate in the security module (100) and/or in a public directory server (610), the signing being carried out by the first computer system (150), and the security module (100) being designed such that once the pair of keys is stored, an initial communication access to the smart meter (142; 144; 146; 148) and/or to the smart meter gateway (138) is only enabled for the first computer system (150), the initial communication access by the first computer system (150) enabling a release of the security module (100) for communication with the second computer system (166).