Smart Meter Security Module Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current smart meter systems lack secure and authorized communication methods for transmitting energy consumption-specific measurement data elements from smart meters to energy suppliers and metering point operators, risking data protection and unauthorized access.

Innovation Solution

A method involving a security module with unique identification, direct mutual authentication using certificates, and secure data transmission ensures that only authorized systems can access and read measurement data elements and configuration data, with a trusted service manager initializing communication channels to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct mutual authentication using certificates is implemented between the security module and the first computer system, then data protection and security are improved, but device complexity increases due to the need for certificate management and authentication protocols

Engineering Contradiction:
Improvedata protectionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security module is pre-configured with certificates and authentication credentials before deployment. The trusted service manager pre-establishes the authentication framework and certificate validation rules, so that when the first computer system connects, mutual authentication can occur immediately without requiring complex runtime certificate management or intermediary systems.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a trusted service manager is used to initialize communication channels and manage security module configuration, then security and authorization control are improved, but device complexity and system architecture complexity increase

Engineering Contradiction:
Improveauthorization controlVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security module is designed to be self-configuring through automated interaction with the trusted service manager. During initialization, the security module automatically receives its configuration data, establishes communication channels, and configures its authentication credentials without requiring manual intervention or complex deployment procedures. This self-service capability reduces the operational complexity despite the presence of the trusted service manager.

Inventive Principle:
Principle #25Self-service

3Reliability

If configuration data and measurement data elements are securely stored and transmitted through the security module, then data protection is improved, but loss of time occurs during secure transmission and authentication processes

Engineering Contradiction:
Improvedata protectionVSAvoidtransmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Configuration data and measurement data element specifications are pre-configured and cached in the security module during initialization by the trusted service manager. This pre-caching eliminates the need for repeated secure retrieval and validation of these data definitions during normal operation, significantly reducing transmission time while maintaining security. The security module has immediate access to authorized data elements without requiring time-consuming authentication queries for each data request.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2812839B2Method for communication of energy consumption-specific measurement data elements between a smart meter device and a computer system of a utility company and/or operator of a measuring system
Publication Date: 2022.11.30 BUNDESDRUCKEREI GMBH
  • EP2812839B2 patent drawingFigure 1
  • EP2812839B2 patent drawingFigure 2
  • EP2812839B2 patent drawingFigure 3

AI summary

The invention relates to a method for communicating energy consumption-specific measurement data elements detected by a smart meter (142; 144; 146; 148) between a smart meter device (138; 142; 144; 146; 148) and a first computer system (166) of a utility company and/or operator of a measuring system, the device (138; 142; 144; 146; 148) having a security module (100), said security module (100) serving as the sole communication interface of the device (138; 142; 144; 146; 148) with the first computer system (166), the device having configuration data required for its operation, and the device being associated with an indication (125) of those measurement data elements and/or configuration data for which the first computer system (166) has a read access authorization, the method comprising the steps of: establishing a first communication channel between the first computer system (166) and the security module (100); mutually authenticating the computer system (166) and the security module (100), authentication being carried out with the aid of a first certificate (104) of the security module (100) and with the aid of a second certificate of the first computer system (166); once mutual authentication has been completed, transmitting via the security module (100) at least a part of the measurement data elements and/or configuration data specified in the indication (125) to the first computer system (166) by secured transmission.