Smart Meter Security Module Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current smart meter systems lack secure and authorized communication methods for transmitting energy consumption-specific measurement data elements from smart meters to energy suppliers and metering point operators, risking data protection and unauthorized access.
Innovation Solution
A method involving a security module with unique identification, direct mutual authentication using certificates, and secure data transmission ensures that only authorized systems can access and read measurement data elements and configuration data, with a trusted service manager initializing communication channels to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If direct mutual authentication using certificates is implemented between the security module and the first computer system, then data protection and security are improved, but device complexity increases due to the need for certificate management and authentication protocols
Solution Approach 1:
The security module is pre-configured with certificates and authentication credentials before deployment. The trusted service manager pre-establishes the authentication framework and certificate validation rules, so that when the first computer system connects, mutual authentication can occur immediately without requiring complex runtime certificate management or intermediary systems.
2Reliability
If a trusted service manager is used to initialize communication channels and manage security module configuration, then security and authorization control are improved, but device complexity and system architecture complexity increase
Solution Approach 1:
The security module is designed to be self-configuring through automated interaction with the trusted service manager. During initialization, the security module automatically receives its configuration data, establishes communication channels, and configures its authentication credentials without requiring manual intervention or complex deployment procedures. This self-service capability reduces the operational complexity despite the presence of the trusted service manager.
3Reliability
If configuration data and measurement data elements are securely stored and transmitted through the security module, then data protection is improved, but loss of time occurs during secure transmission and authentication processes
Solution Approach 1:
Configuration data and measurement data element specifications are pre-configured and cached in the security module during initialization by the trusted service manager. This pre-caching eliminates the need for repeated secure retrieval and validation of these data definitions during normal operation, significantly reducing transmission time while maintaining security. The security module has immediate access to authorized data elements without requiring time-consuming authentication queries for each data request.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a method for communicating energy consumption-specific measurement data elements detected by a smart meter (142; 144; 146; 148) between a smart meter device (138; 142; 144; 146; 148) and a first computer system (166) of a utility company and/or operator of a measuring system, the device (138; 142; 144; 146; 148) having a security module (100), said security module (100) serving as the sole communication interface of the device (138; 142; 144; 146; 148) with the first computer system (166), the device having configuration data required for its operation, and the device being associated with an indication (125) of those measurement data elements and/or configuration data for which the first computer system (166) has a read access authorization, the method comprising the steps of: establishing a first communication channel between the first computer system (166) and the security module (100); mutually authenticating the computer system (166) and the security module (100), authentication being carried out with the aid of a first certificate (104) of the security module (100) and with the aid of a second certificate of the first computer system (166); once mutual authentication has been completed, transmitting via the security module (100) at least a part of the measurement data elements and/or configuration data specified in the indication (125) to the first computer system (166) by secured transmission.