Smart Meter Security Module Initialization via Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current smart meter systems lack secure and trustworthy methods for initializing memory areas, which are critical for ensuring the integrity and privacy of energy consumption data, particularly in enabling secure communication between smart meters and authorized market participants.

Innovation Solution

A method for initializing a memory area assigned to a smart meter involves establishing a secure communication channel with a security module, authenticating the first computer system, and storing data for secure transmission, ensuring that only trustworthy entities can access and configure the smart meter, using end-to-end encryption and certificate-based authentication to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a smart meter gateway is provided as a central communication unit to enable communication with multiple smart meters and network devices, then communication functionality and data collection capability are improved, but the system becomes more vulnerable to unauthorized access and security breaches

Engineering Contradiction:
Improvecommunication functionalityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A security module is introduced as an intermediary component between the smart meter gateway and external computer systems. This security module acts as a mediator that authenticates incoming communication requests and controls access to the gateway, thereby maintaining communication functionality while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Authentication and authorization checks are performed in advance before allowing any communication between external systems and the smart meter gateway. The security module pre-validates credentials and establishes trusted communication channels, preventing unauthorized entities from gaining access to the system.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If memory areas in smart meters are initialized without secure authentication mechanisms, then the initialization process is simpler and faster, but the integrity and privacy of stored energy consumption data cannot be guaranteed

Engineering Contradiction:
Improveinitialization speedVSAvoiddata integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Authentication of the initializing system is performed before the memory initialization process begins. The security module verifies credentials and establishes a trusted connection in advance, ensuring that only authorized systems can initialize memory areas, thereby guaranteeing data integrity while maintaining efficient initialization procedures.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If only the first computer system can communicate with the security module during initialization, then security and control are improved, but the system lacks flexibility for future communication with other authorized entities

Engineering Contradiction:
Improvesecurity controlVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The first computer system performs preliminary authentication and configuration of the security module during initialization. It establishes the security module's communication capabilities and authorization rules in advance, enabling the security module to subsequently authenticate and communicate with other authorized entities (such as energy suppliers and metering operators) without compromising initial security control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module serves as an intermediary that the first computer system configures initially, but then independently manages. The security module mediates all subsequent communications, allowing the system to maintain strict security control while enabling flexible communication with multiple authorized parties through centralized authentication management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2812838B1Method for initializing a memory area that is associated with a smart meter
Publication Date: 2018.12.12 BUNDESDRUCKEREI GMBH
  • EP2812838B1 patent drawingFigure 1
  • EP2812838B1 patent drawingFigure 2
  • EP2812838B1 patent drawingFigure 3

AI summary

The invention relates to a method for initializing a memory area (136), the memory area (136) being associated with a smart meter (142; 144; 146; 148), and the method comprising the steps of: establishing a first communication channel between a first computer system (150) and a security module (100), the security module (100) being associated with the memory area (136), and the first computer system (150) being associated with a set of computer systems interconnected via a network; authenticating the first computer system (150) with respect to the security module (100), the initialization serving to enable communication of the security module (100) with other computer systems (166) of the set of computer systems, and a successful authentication with respect to the security module (100) prior to initialization of the memory area (136) exclusively being possible for the first computer system (150) of the set of computer systems; once the first computer system (150) has been successfully authenticated with respect to the security module (100), the security module (100) receiving data from the first computer system (150) by way of secure transmission and storage of the data in the memory area (136) in order to initialize the memory area (136), communication between a second computer system (166) of a utility company and/or operator of the measuring system and the security module (100) being only possible - while bypassing the first computer system (150) - owing to the stored data, the second computer system (166) being a computer system from among the set of computer systems.