EP2812841A1 - Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul - Google Patents
Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodulInfo
- Publication number
- EP2812841A1 EP2812841A1 EP13702195.2A EP13702195A EP2812841A1 EP 2812841 A1 EP2812841 A1 EP 2812841A1 EP 13702195 A EP13702195 A EP 13702195A EP 2812841 A1 EP2812841 A1 EP 2812841A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- security module
- identifier
- smart meter
- gateway
- smart
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/71—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
- G06F21/73—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information by creating or determining hardware identification, e.g. serial numbers
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/86—Secure or tamper-resistant housings
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2129—Authenticate client device independently of the user
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2139—Recurrent verification
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/70—Services for machine-to-machine communication [M2M] or machine type communication [MTC]
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y04—INFORMATION OR COMMUNICATION TECHNOLOGIES HAVING AN IMPACT ON OTHER TECHNOLOGY AREAS
- Y04S—SYSTEMS INTEGRATING TECHNOLOGIES RELATED TO POWER NETWORK OPERATION, COMMUNICATION OR INFORMATION TECHNOLOGIES FOR IMPROVING THE ELECTRICAL POWER GENERATION, TRANSMISSION, DISTRIBUTION, MANAGEMENT OR USAGE, i.e. SMART GRIDS
- Y04S40/00—Systems for electrical power generation, transmission, distribution or end-user application management characterised by the use of communication or information technologies, or communication or information technology specific aspects supporting them
- Y04S40/20—Information technology specific aspects, e.g. CAD, simulation, modelling, system security
Definitions
- the invention relates to a method for personalizing a smart meter device with a security module, a computer program product, a security module and a smart meter device.
- the term "smart metering” is generally understood as the idea of equipping customers with electronic energy consumption recording devices, in order to provide not only simple detection of the amount of energy consumed, for example via a network, to both the customer and the energy supplier. It is possible that the customer can inform himself in real time about his current energy consumption.
- energy consumption is understood to mean the consumption of the customer with regard to any kind of energy that is supplied to households and companies, which includes not only the forms of electricity, water and gas, but also any other forms of energy such as district heating.
- smart meters are meters of energy consumed, and the consumer can be either a natural or a legal person measurable forms of energy such as electricity, gas, water or heat
- the aim of using smart meters is the implementation of smart metering systems, which would, for example, enable the levying of variable power charges depending on overall demand and network load, thereby making it possible to make better use of energy grids.
- a smart meter gateway also called a concentrator, as a central communication unit which can communicate with individual or several smart meters.
- the gateway is able to communicate with devices in the so-called "Home Area Network” and with devices in the "Wide Area Network".
- the home area network includes all smart meters that are connected to the gateway, as well as eg private computing units of the consumers.
- the private computing units can be used, for example, for information about current energy consumption values recorded with the smart meters.
- the Wide Area Network is designed to allow communication from gateway and authorized market participants.
- the gateway can collect the data of all smart meters and provide them to a higher-level collection point, for example an energy supplier or a metering point operator.
- the invention has for its object to provide a method for personalizing a smart meter device with a security module, a computer program product, a security module and a smart meter device.
- the objects underlying the invention are achieved by the features of the independent claims. Preferred embodiments of the invention are indicated in the dependent claims.
- the invention relates to a method for personalizing a smart meter device with a security module, wherein the security module is designed as a communication interface of the device with an external computer system, wherein a unique identifier is stored in the security module, the method comprising inseparably connecting the security module to the device comprises, wherein after connecting the device is identifiable by the unique identifier.
- Embodiments of the invention could have the advantage that the personalization process can permanently assign a unique identity to the device. For this purpose, it is not necessary, for example, to provide the device with an identity during a manufacturing process. This would be associated with high costs and high technical complexity, particularly with regard to safety requirements to be met during the production process.
- the assignment of identities is linked to a particularly secure production environment, eg a so-called trust center. This could be necessary, in particular, when assigning identities to fee-based surveys with respect to the energy consumption values recorded with the smart meter assigned to the device. Due to the irreversible connection of the device with a separately available security module, it is sufficient to produce only the security module in the secure production environment and to provide the identity.
- the subsequent coupling of security module and device then provides the device with the same identity that was also assigned to the security module.
- the security module As a communication interface for external computer systems, it is ensured that a corresponding communication process of, for example, consumption data at measuring points In this case, the security module can, for example, ensure that the transmitted data in principle also have the unique identifier "globally unique identifier" (GUID).
- GUID globally unique identifier
- the inseparable connection of the security module to the device comprises a mechanical connection thereof.
- Mechanical bonding may include, for example, a soldering operation, a welding operation, or a bonding operation of the security element and device.
- a permanent mechanical locking of the security element in the device is also possible.
- the security module could be cast in a housing of the device, so that the destruction of the security module and / or the device results due to the "breaking" of this cast connection.
- the mechanical connection should take place in such a way that a subsequent removal of the security module from the device leads to an at least partial - preferably automatic - functional inability of the device and / or the security module.
- the mechanical contacting between the security element and the device could be designed such that, when the security module is subsequently removed from the device, electrical contacts in the device and / or the security module are automatically interrupted irreparably and automatically.
- the mechanical contact between the security element and the device could be such that irreversible destruction of electronic components of the device and / or the security module takes place during "soldering off" of the security element - necessary to ensure the basic functions of the device, including the transmission of smart meter data to meter operators and / or energy suppliers.
- the malfunction of the device and / or the security module automatically occurs in the event of subsequent removal of the security module from the device at the latest after restarting the device and / or the security module.
- the partial malfunctioning comprises a permanent failure of the communication capability of the device with the external computer system.
- the external computer system is a meter operator and / or utility
- it will discover that there is a problem with the device due to lack of communication capability.
- the meter operator and / or utility will automatically seek this device, e.g. have a technician on site check the device.
- manipulations of the device can be detected reliably and quickly.
- the partial inoperability results from a mechanical destruction of the device and / or the security module due to the subsequent removal.
- the subsequent removal starts an electronic deactivation process on the device and / or the security module, the partial inoperability resulting from the deactivation process.
- This deactivation process may be hardware and / or software controlled.
- a module of the device can make a regular check for the presence of the security module. If it is determined that the security module has been removed, then this module may deactivate the device or individual functions of the device as described above. It is also possible that the module initiates a partial self-destruction of its electrical circuits or elements.
- a connection process on the device and / or the security module is started due to the connection of the security module to the device, wherein the inseparable connection of the security module to the device as a result of the linking process a logical link of the security module with the device comprises.
- a logical link is understood to be a software-controlled process which uniquely couples the device to the security module.
- the logical link is made via an identifier, which connects the device and the security module. This may be an identifier which is identical for device and security module. It is also possible, however, that from eg a device ID of the device and an odul-ID of the security module, a new identifier is generated, which uniquely links the device ID and the module ID. Possible here would be a hash process on the device ID and the module ID.
- the use of an identifier generally has the advantage that embodiments can be realized without great mechanical expense, which results in a high cost savings.
- the gateway can not subsequently be replaced by another gateway in an unauthorized manner. For example, this could prevent a measuring point operator from providing values from a "hacked" gateway, which is only sporadically connected to corresponding smart meters and therefore does not actually carry out any real energy consumption recording at all.
- the linking process be performed.
- an internal counter of the security module could be used, so that a repeated use of the security module, e.g. is prevented in various devices.
- the linking process comprises a transmission of the identifier of the security module to the device and, subsequently, an irreversible storage of the identifier received by the device in the device.
- the transmission of the identifier takes place automatically at the time of the first startup of the device connected to the security module. This ensures that on the one hand at any time before the device Commissioning can be equipped with current safety modules, but is clearly personalized after commissioning.
- the identifier of the security module and / or the irreversibly stored identifier can not be changed. A change of the identifier is thus possible only by replacing the security module and device.
- a regular automatic check takes place as to whether the identifier stored in the security module is still identical to the identifier stored in the device, wherein in the event of a lack of identity, a message is sent to it external computer system is transmitted and / or an electronic deactivation process on the device and / or the security module is started, with a partial inoperability of the device and / or the security module resulting from the deactivation process.
- This e.g. Deactivation process that can be implemented as a software or hardware has already been described above and can be implemented analogously in this embodiment.
- the regular automatic check can take place at fixed times, at random times or even with predefined events.
- a predefined event could e.g. Transmission of consumption data recorded by the smart meter via the security module to a metering point operator and / or energy supplier or, in general, any read access to the recorded consumption data by external systems.
- External systems can be the devices in the "Home Area Network" and the "Wide Area Network”.
- the device is a smart meter or a smart meter gateway associated with the smart meter or multiple smart meters.
- a gateway is assigned to a smart meter if the smart meter makes its recorded energy consumption values available via the gateway to an energy supplier or metering point operator.
- the gateway can only be used as the central communication interface for one or more connectable smart meters act. Whether access to the measurement data captured by the smart meter takes place indirectly via the gateway to the smart meter, or whether the smart meter stores the measurement data in the gateway is insignificant and both possible.
- the security module is a chip card.
- the identifier is a public key of the security module and / or an IPv6 address of the security module.
- the latter has the particular advantage that it is also possible at the same time to clearly address the security module and thus the device in the Internet via the identifier. This could be relevant for the automated retrieval of consumption data collected by the smart meters.
- the use of the public key has the advantage that this automatically ensures a clear and personalized identification of the security module. Since preferably a trust center or a trusted service manager will assign trustworthy certificates to the security module at the same time, the "official party" ensures that the required public key has actually been assigned by this trusted authority Directory server verifiable, thus excluding the use of forged identifiers.
- the identifier is a certificate of the security module.
- the certificate could in turn have the public key of the security module.
- This initially has the advantage that the authenticity of the identifier can be checked by third parties.
- a challenge-response method could be used to communicate measured data acquired with the smart meter, which requires a prior mutual certificate check.
- This certificate is used anyway, so that the additional explicit and separate transfer of identifiers deleted.
- the identifier itself is included in a certificate of the security module. This also ensures an official verifiability of the authenticity of the identifier by third parties.
- the said certificates may have been created according to a Public Key Infrastructure (PKI) standard, for example according to the X.509 standard. It should be noted that the described certificates can be stored on a public directory server.
- PKI Public Key Infrastructure
- the invention relates to a computer program product having instructions executable by a processor for performing the method steps described above.
- the invention relates to a security module for use in the method described above.
- the invention relates to a smart meter device for receiving a security module as described above.
- the security module and the smart meter device have analogous capabilities and functionalities, which were described above with regard to the method.
- the security module is preferably configured in its delivery state such that only a trustworthy entity is able to perform a communication after successful authentication with the security module.
- This trustworthy entity may be that which the security module previously provided with the identifier. This ensures that, in particular, a charge-relevant configuration of the smart metering is left only to such a point, which is classified as trustworthy both by the authorized market participants, ie, for example, the metering point operators and the actual energy suppliers, as well as the end users.
- Charge-relevant configuration determines with respect to a smart meter who is authorized, for example, to charge the amount of energy detected by the smart meter. Furthermore, it can also be determined which persons, such as end users and authorized market participants, are allowed to have access to the functions and information available with respect to the smart meter to what extent. Since this determination is made on the part of a trusted body, this ensures that abuse of these functions and information by unauthorized third parties is excluded.
- the information may include eg location information of the smart meter, values measured by the smart meter, location information of the storage area or any values contained in the storage area.
- a communication via the communication interface of the device with the external computer system by a secure transmission which is an end-to-end encryption between the computer system and the security module! used.
- a secure transmission which is an end-to-end encryption between the computer system and the security module! used.
- This makes it possible to establish the connection between the security module and the computer system over any networks since, due to the end-to-end encryption, no changes of the data transmitted over the connection can be made by third parties.
- the invention may be implemented by allowing all communications between the computer system and the security module to be via any type of network.
- the latter is also known under the name: "Powerline data transmission" and includes devices for data transmission over existing communication or power grids.
- FIG. 1 is a block diagram of a system for implementing the method described above.
- FIG. 2 shows a flow chart of a method for personalizing a smart meter device.
- FIG. 3 shows a flow chart of a method for checking a personalization of a smart meter device
- FIG. 4 shows a block diagram of a smart meter system
- FIG. 5 shows a flow diagram of a method for initializing a memory area
- FIG. 6 shows a flow diagram of a method for providing a security module.
- similar elements will be denoted by like reference numerals.
- FIG. 1 shows a block diagram of a system for implementing a method for personalizing a smart meter device with a security module.
- the smart meter device is a smart meter gateway 138, which is coupled to smart meters 142, 144 via the interface 1 18.
- a security module 100 serves as the communication interface of the gateway 138 with an external computer system 166. The communication takes place via an interface (interface) 16 of the security module 100.
- the computer system is the system of a measuring point operator and / or of an energy supplier who would like to charge energy consumption data recorded with the smart meters 142, 144.
- the data transmission is in this case e.g. controlled by the software module 120 of the processor 126 of the gateway 138.
- the security module 100 may communicate with the computer system 166 via the network 600, eg, a powerline connection or the internet. Similarly, communication via the interface 1 16 with the computer system 150 of FIG. 4 is possible. This is described in detail below.
- a unique identifier 108 is stored in the security module 100.
- the security module 100 is pre-personalized, for example, in the form of a chip card or an integrated circuit IC, ASIC or "chip", ie equipped with identifier 108 and cryptographic key material not described in more detail here.
- the security module is inserted into the gateway 138 according to the method steps described in FIG. 2 in step 700.
- the gateway provides a corresponding receptacle for the safety module with contacts 604 for this purpose! 100 ready.
- the processor 126 of the gateway 138 can communicate via the interface 1 18 with the security module via its non-illustrated counterpart contacts.
- a mechanical locking of the security module in the gateway 138 preferably takes place in step 702. As a result, it is no longer possible to subsequently remove the security module from the gateway 138 without destroying the contacts 604.
- the identifier 108 of the security module is automatically assigned to the gateway 138.
- Steps 704 and 706 are optional and could be used instead of, or in addition to, the mechanical locking process.
- the gateway 138 is put into operation, whereby a copying process of the identifier 108 from the security module to a memory area 136 of the gateway 138 is automatically initiated in step 706.
- a copy 128 of the identifier 108 is stored in the memory 136.
- the copying process can be controlled, for example, by means of program instructions 602 during initial commissioning, ie, initiation of the gateway 138.
- the described steps result in an inseparable connection of the security module 100 to the gateway 138, wherein after the connection the gateway can be identified by the unique identifier 128.
- Step 800 is to check if identifiers 128 and 108 are identical or if there is any ID 108 at all. If the security module 100 were to be replaced by another security module, the identifiers 128 and 108 would no longer match. Since the identifier 128 is preferably stored irreversibly in the memory 136, the replacement of the security module does not allow the identifier 128 to be replaced by another one without further ado.
- step 802 If it is determined in step 802 that the identifiers are identical, the method jumps back to step 800 and is quasi looped again, possibly time-triggered. On the other hand, if it is determined in step 802 that the identifier 108 either does not exist or there is no identity between the identifiers 108 and 128, steps 804-808 may be performed.
- Step 804 comprises the notification of the suspected presence of a manipulation or malfunction to an external computer system, eg the system 166 in FIG. 1.
- Step 806 comprises the partial deactivation of the functions of the gateway, so that in particular an energy supplier or measuring parts operator can independently determine the manipulation due to, for example, incorrect transmitted data or even the absence of data transmissions.
- Step 808 is also optional and involves outputting a local signal at the gateway such that a user is visually or acoustically capable of detecting a partial inoperability that has occurred. An end user's local computer connected to the gateway 138 could also be informed of this by the signal in step 808.
- FIG. 4 shows the block diagram of FIG. 1 in detailed form.
- a memory area 136 of a gateway 138 associated with a plurality of smart meters 142, 144, 146, 148 can be initialized.
- This initialization process serves to provide consumers and utilities with a convenient means of communicating energy consumption data in a secure manner.
- the described computer system 150 is preferably a computer system of a trustworthy entity, which is also referred to as "Trusted Service Manager" or "TSM”.
- the smart meters 142-148 serve to detect various energy consumption values relating to, for example, gas (smart meter 142), water (smart meter 144), electricity (smart meter 146), and other unspecified forms of energy (smart meter 148).
- the smart meters are connected via corresponding communication links 192 to the interface 1 18 of the gateway 138.
- the security module 100 is already firmly and inseparably connected to the gateway 138, so that a total of the combination of the gateway 138 and the security module 100 an inseparable unit 140 is given.
- the gateway 138 and the security module 100 communicate via respective interfaces 1 18 and 1 16 with each other.
- a communication connection 190 This can be, for example, a powerline connection or a communication connection via a mobile telecommunications network or the Internet.
- the security module 100 has an electronic memory 102 with protected memory area 106 and 108.
- the protected memory area 106 serves to store a private key of the security module 100 and the memory area 108 serves to store the identifier of the security module "GUID" (Gaily unique identifier
- the GUID may be an IPv6 address of the security module 100.
- the electronic memory 102 may further include a memory area 104 for storing a certificate.
- the certificate includes a public key associated with the private key stored in the protected storage area 106.
- the certificate may have been created according to a Public Key Infrastructure (PKI) standard, for example according to the X.509 standard.
- PKI Public Key Infrastructure
- the certificate does not necessarily have to be stored with the electronic memory 102 of the security module 100.
- the certificate can also be stored in a public directory server.
- the security module 100 has a processor 110 for executing program instructions 1 12 and 1 14.
- a processor 110 for executing program instructions 1 12 and 1 14.
- the cryptographic protocol may be, for example, a Chalienge response protocol based on a symmetric key or an asymmetric key pair. It is also possible, of course, mutual authentication of security module and trusted entity or energy supplier.
- the program instructions 114 are used for end-to-end disclosure of data to be transmitted between the security module 100 and the trusted entity 150 or the energy provider 166.
- a symmetric key can be used, which is agreed, for example, during the execution of the cryptographic protocol between the security module 100 and the other users 150 or 166.
- the trusted entity 150 also has the previously described electronic memory 152 and a protected memory area 156 for storing a private key of the trusted entity.
- the memory 152 may also contain a certificate 154 of the trustworthy entity. However, this certificate can also be stored on a central certificate server.
- a processor 158 of the trusted entity 150 has the program instructions 1 12 and 1 14 described above with respect to the security module 100 for implementing a cryptographic protocol and performing an end-to-end encryption.
- the cryptographic protocol and the end-to-end encryption can be used for communication via the interface 164 with the utility 166 or with the security module 100.
- the certificate 154 in turn includes a public key associated with the private key stored in the protected storage area 156.
- the "energy supplier” 166 is a computer system of the energy supplier, which in turn has an electronic memory 168 and a processor 178. Furthermore, an interface 186 is assigned to this computer system, via which a communication with the trusted entity 50 or the Security module is enabled.
- the electronic memory 168 of the power supplier 166 has a protected memory area 172 with a private key, wherein the private key is associated with a public key which is also contained in a certificate 170 in the electronic memory 168.
- a memory area for one or more applications is provided in the memory 168, wherein these applications enable, for example, a fee-based configuration of the gateway 138. Also stored in the electronic memory 168 may be measurement data 176 previously received from the gateway 138.
- the processor 178 includes program instructions 180 for detecting the consumption data provided by the gateway 138 and, optionally, for executing method steps for consumption accounting in dependence on the determined measurement data (program instructions 182).
- the program instructions for executing steps of a cryptographic protocol 12 and program instructions (not shown) for carrying out an end-to-end encryption can also be provided, whereby these program instructions enable secure communication with the trusted entity 150 or the security module 100 , If a new customer is now to be assigned to the energy supplier 166, for example, after a first installation of the smart meter 142-148 and the provision of gateway 138 with security module 102, an initialization process of the security module could take place.
- This initialization process could be triggered by the fact that the new customer (an end user) or a specific technical entity, which had installed the smart meter, to the utility 166 to report accordingly.
- This message should preferably include the GUID 108 of the security module 100, since this allows a clear identification of the security module 100 with respect to the energy provider 166.
- a trustworthy entity can be a so-called "Trusted Service Manager TSM", ie an officially certified entity which certifies the respective identity of the communication partner in electronic communication processes.
- the energy supplier 166 is authenticated in step 202.
- the certificate 170 of the energy provider is checked by the trustworthy entity 150.
- the trustworthy entity 150 may perform a challenge-response procedure in the event of a positive certificate verification, in which case a random number is generated which is encrypted with a public key of the energy provider 166 contained in the certificate 170 and transmitted to the energy provider 166.
- the utility 166 can then decrypt the random number with its private key 172 and send it back in plain text. If the random number now received by the trusted entity 150 matches the random number described above, the authenticity of the utility 166 is actually secured.
- an end-to-end encryption channel may then be established at step 204 over the communication link 188 between power supply 166 and trusted entity 150.
- the program instructions 1 14 of the processor 158 of the trustworthy entity can be used.
- the trusted entity 150 receives a request to upload a power collection application 174 of the power supplier 166 and the memory 136 of the gateway 138.
- the request is made for initializing the memory 136
- the GUID 128 of the gateway 138 which is contained in the memory 136, is also transmitted to the trustworthy entity.
- the GUID 128 of the memory 136 is identical to the GUID 08 of the memory 102 of the security module 100.
- the trusted entity 150 is able to uniquely address the desired gateway 138 for rendering the application 174.
- the trustworthy entity 150 establishes a communication channel to the security module 100 via the communication connection 190.
- the trustworthy entity 150 authenticates itself to the security module 100, wherein the authentication, in addition to a verification of the certificate 154 by the security module, for example, again comprises a challenge-response procedure on the part of the security module 100.
- the security module 100 could again generate a random number, encrypt it with the public key of the trusted entity 150 and send it to the trusted entity 150.
- the trusted entity 150 would decrypt the encrypted random number with its private key 156 and send the decrypted random number back to the security module 100 in plain text. If the security module determines that the thus-received decrypted random number matches the originally encrypted random number, authentication of the trustworthy entity is given.
- step 212 namely the establishment of a communication channel with end-to-end encryption between the trusted entity 150 and the security module 100.
- step 212 namely the establishment of a communication channel with end-to-end encryption between the trusted entity 150 and the security module 100.
- step 214 the security module 100 receives the energy collection application 174 from the trusted entity.
- the trusted entity stores the most frequently sent energy-sensing applications in a local memory of the trusted entity, so it is not necessary to constantly open the applications 174 of the client when opening new customers Power supplier 166 to the trusted entity 150 to transfer.
- the application Upon receipt of the power sensing application in step 214, the security module! 100, the application in the memory 136 of the gateway 138.
- the application 174 is an application to capture power consumption for water and power
- the application is stored as the application 132 in the memory 136.
- This application is capable of processing energy consumption data from the smart meter 144.
- the memory 136 may include corresponding gas sensing applications (134) and other applications 130 for detecting other forms of energy.
- the storage of the energy acquisition application by the security module 100 in the gateway 138 is indicated by the step 216 in FIG.
- the trusted entity 150 In addition to receiving the power sensing application in step 214 by the security module 100, it is also possible for the trusted entity 150 to receive power provider-specific permissions or specific specifications of network data elements that are also stored in a wider area 125 of the memory 136. These authorizations or specifications of measured data elements make it possible to determine in advance which information the energy supplier 166 is allowed to receive from the gateway 138 at all. For this purpose, it is possible, for example, for the trustworthy entity 150 to define specific permissions for each energy provider in advance, which apply globally to all energy suppliers 166 and which, in principle, are transmitted to the gateway 138 with the transmission of energy acquisition applications.
- configuration data may relate to the technical configuration of the smart meters and / or the gateway.
- the gateway 138 is now able to acquire measurement data relating to energy consumption, for example from the smart meter 144 and the smart meter 146.
- the corresponding measurement data are stored in the memory area 124 of the memory 36.
- the measurement data 124 consists of various Measurement data elements which may include, for example: time of acquisition of the measurement data, individual measurement data points at the respective time, information on the occurrence of the measurement data (for example current, voltage, water pressure, water temperature, gas pressure).
- the measurement data 124 can be subjected to further evaluation via the applications 130, 132 and 134, resulting in evaluated measurement data which can likewise be stored as "measurement data elements" in the memory area 124.
- the evaluated measurement data may be accumulated energy consumption values act.
- the authorizations 125 described above or the specifications of the measured data elements make it possible to determine from the outset which of these measured data elements 124 the energy supplier 126 is allowed to retrieve at all. Furthermore, this makes it possible to determine in advance how much such retrieval is permitted. Such a detailed and timely retrieval of the measurement data 124 could be undesirable, since knowledge of the use of electronic devices gain by short time intervals of measurements and user profiles can be created, but an end customer may not be interested in doing so.
- the security module 100 and the gateway 138 are inextricably linked.
- these form a structural unit 140, as shown schematically in FIG.
- the method steps explained in simplified form in the flowchart of FIG. 4 could be carried out.
- step 400 the security module 100 is first provided. Thereupon, in step 402, storage of key material and certificates in the security module occurs.
- the security module could have a corresponding cryptographic unit by means of which the private key 106 is generated independently.
- the trustworthy entity it is also possible for the trustworthy entity to generate the private key and store it in the security module in a storage area that is not accessible from the outside.
- the public key belonging to the private key is attached to the certificate, which then is signed by the trusted entity and stored in the memory 102 of the security module.
- the security module is then inserted into the gateway in step 404, for example in the form of a chip card, and an inseparable connection between security module and gateway is made.
- security module and gateway could be electronically coupled to each other such that removal of the security module from the gateway would result in automatic destruction of the security module.
- an automatic logical link between the security module 100 and the gateway 138 takes place in step 406. For example, this could be done by irreversibly writing the GUID 108 of the security module into the memory 136 of the gateway 138 as GUID 128. In this case, it should be ensured on the part of the security module 100, for example, that communication with the gateway 138 for providing measurement data elements and via the energy provider 166 only takes place if an identity of the GUIDs 108 and 128 is given.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Mathematical Physics (AREA)
- Storage Device Security (AREA)
- Telephonic Communication Services (AREA)
- Arrangements For Transmission Of Measured Signals (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP23155836.2A EP4220462B1 (de) | 2012-02-07 | 2013-01-18 | Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul |
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102012201810A DE102012201810A1 (de) | 2012-02-07 | 2012-02-07 | Verfahren zur Initialisierung eines Speicherbereichs, welcher einem Smart-Meter zugeordnet ist |
| DE201210203034 DE102012203034A1 (de) | 2012-02-28 | 2012-02-28 | Verfahren zur Personalisierung einer Smart Meter Vorrichtung mit einem Sicherheitsmodul |
| PCT/EP2013/050900 WO2013117405A1 (de) | 2012-02-07 | 2013-01-18 | Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23155836.2A Division EP4220462B1 (de) | 2012-02-07 | 2013-01-18 | Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2812841A1 true EP2812841A1 (de) | 2014-12-17 |
Family
ID=47631412
Family Applications (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP13702195.2A Ceased EP2812841A1 (de) | 2012-02-07 | 2013-01-18 | Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul |
| EP23155836.2A Active EP4220462B1 (de) | 2012-02-07 | 2013-01-18 | Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul |
Family Applications After (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP23155836.2A Active EP4220462B1 (de) | 2012-02-07 | 2013-01-18 | Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul |
Country Status (2)
| Country | Link |
|---|---|
| EP (2) | EP2812841A1 (de) |
| WO (1) | WO2013117405A1 (de) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2001059544A2 (en) * | 2000-02-14 | 2001-08-16 | Rainbow Technologies B.V., Netherlands | Security module system, apparatus and process |
| US20050033701A1 (en) * | 2003-08-08 | 2005-02-10 | International Business Machines Corporation | System and method for verifying the identity of a remote meter transmitting utility usage data |
| US20050039040A1 (en) * | 2003-03-31 | 2005-02-17 | Ransom Douglas S. | System and method for seal tamper detection for intelligent electronic devices |
| US20070138657A1 (en) * | 2005-12-21 | 2007-06-21 | International Business Machines Corporation | Physically highly secure multi-chip assembly |
| US7830021B1 (en) * | 2005-09-06 | 2010-11-09 | Rockwell Collins, Inc. | Tamper resistant packaging with transient liquid phase bonding |
-
2013
- 2013-01-18 EP EP13702195.2A patent/EP2812841A1/de not_active Ceased
- 2013-01-18 WO PCT/EP2013/050900 patent/WO2013117405A1/de not_active Ceased
- 2013-01-18 EP EP23155836.2A patent/EP4220462B1/de active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2001059544A2 (en) * | 2000-02-14 | 2001-08-16 | Rainbow Technologies B.V., Netherlands | Security module system, apparatus and process |
| US20050039040A1 (en) * | 2003-03-31 | 2005-02-17 | Ransom Douglas S. | System and method for seal tamper detection for intelligent electronic devices |
| US20050033701A1 (en) * | 2003-08-08 | 2005-02-10 | International Business Machines Corporation | System and method for verifying the identity of a remote meter transmitting utility usage data |
| US7830021B1 (en) * | 2005-09-06 | 2010-11-09 | Rockwell Collins, Inc. | Tamper resistant packaging with transient liquid phase bonding |
| US20070138657A1 (en) * | 2005-12-21 | 2007-06-21 | International Business Machines Corporation | Physically highly secure multi-chip assembly |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4220462A3 (de) | 2023-09-06 |
| EP4220462B1 (de) | 2024-11-27 |
| EP4220462A2 (de) | 2023-08-02 |
| WO2013117405A1 (de) | 2013-08-15 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2812839B2 (de) | Verfahren zur kommunikation von energieverbrauchsspezifischen messdatenelementen von einer smart meter vorrichtung an ein computersystem eines energieversorgers und/oder messstellenbetreibers | |
| WO2015124726A1 (de) | Verfarhen und system zum erstellen und zur gültigkeitsprüfung von gerätezertifikaten | |
| EP3337085B1 (de) | Nachladen kryptographischer programminstruktionen | |
| EP2812837B1 (de) | Verfahren zur personalisierung eines smart meter oder smart meter gateway sicherheitsmoduls | |
| DE102012203518B4 (de) | Verfahren zur Kommunikation von energieverbrauchsspezifischen Messdatenelementen von einer Smart Meter Vorrichtung an ein Computersystem eines Energieversorgers und/oder Messstellenbetreibers | |
| DE112011104941T5 (de) | Langzeit-Signaturendgerät, Langzeit-Signaturserver, Langzeitsignaturendgeräteprogramm und Langzeit-Signaturserverprogramm | |
| EP2850860A1 (de) | Sicherung eines energiemengenzählers gegen unbefugten zugriff | |
| DE102012203354B4 (de) | Verfahren zur Personalisierung eines Smart Meter oder Smart Meter Gateway Sicherheitsmoduls | |
| EP2812840B1 (de) | Verfahren zur initialisierung eines speicherbereichs, welcher einem smart-meter zugeordnet ist | |
| WO2016091415A1 (de) | Verfahren und vorrichtung zur überwachung einer zertifizierungsstelle | |
| DE102012203034A1 (de) | Verfahren zur Personalisierung einer Smart Meter Vorrichtung mit einem Sicherheitsmodul | |
| DE102012203356B4 (de) | Verfahren zur Initialisierung eines Speicherbereichs, welcher einem Smart-Meter zugeordnet ist | |
| EP4220462B1 (de) | Verfahren zur personalisierung einer smart meter vorrichtung mit einem sicherheitsmodul | |
| DE102016112278A1 (de) | Verfahren zur Herstellung einer Ausfallsicherung in einem Netzwerk | |
| EP2812838B1 (de) | Verfahren zur initialisierung eines speicherbereichs, welcher einem smart-meter zugeordnet ist | |
| WO2019096489A1 (de) | Verfahren und vorrichtung zur behandlung von authentizitätsbescheinigungen für entitäten, insbesondere von personenbezogenen, dienstbezogenen und/oder objektbezogenen digitalen zertifikaten | |
| WO2019052864A1 (de) | Verfahren zum einstellen einer referenzzeit | |
| EP3563520B1 (de) | Kommunikation eines netzwerkknotens in einem datennetz | |
| DE102014223374A1 (de) | Verfahren zum automatischen Verwalten eines elektrischen Geräts, elektrisches Gerät, Rechenvorrichtung zum automatischen Verwalten eines elektrischen Geräts und System | |
| EP4261726A1 (de) | Verwalten von ereignisdaten eines realen objekts in einer verwaltungsschale | |
| EP3025479A1 (de) | Client-einrichtung und verfahren zum prägen einer client-einrichtung auf mindestens eine server-einrichtung | |
| DE102012209123A1 (de) | Vorrichtung, System und Verfahren zur entfernten Inbesitznahme und Etablierung von Geheimnissen in Maschinen zu Maschinen Kommunikation |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20140908 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20180328 |
|
| APBK | Appeal reference recorded |
Free format text: ORIGINAL CODE: EPIDOSNREFNE |
|
| APBN | Date of receipt of notice of appeal recorded |
Free format text: ORIGINAL CODE: EPIDOSNNOA2E |
|
| APBR | Date of receipt of statement of grounds of appeal recorded |
Free format text: ORIGINAL CODE: EPIDOSNNOA3E |
|
| APAF | Appeal reference modified |
Free format text: ORIGINAL CODE: EPIDOSCREFNE |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| APBT | Appeal procedure closed |
Free format text: ORIGINAL CODE: EPIDOSNNOA9E |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20230215 |
|
| P01 | Opt-out of the competence of the unified patent court (upc) registered |
Effective date: 20230526 |