Cordova AMI/AMR Security Advanced Meter Infrastructure / Automatic Meter Reading Security 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Outline Wireless Comes of Age Emerging Technology - AMI/AMR Vulnerabilities Vulnerabilities Ignored Regulation and Management Secure Smart Meters Secure the Smart Grid Selected Smart Solutions Conclusion 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Advanced Meter Infrastructure Automatic Meter Reading Security is critical 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Coming of Age Human meter readers – were relatively cheap; quick and easy to install; rugged and extremely reliable over long periods of use Multiple types of AMR techniques and technologies Wireless emerged - new problems including security, range limitations, spectrum interference and reliability issues Financial concerns about future operational and support costs Advanced AMR networks would provide the best solution to the “cash flow delay” – typically 30-90 days 25% of water meters in the United States are now equipped with AMR Over 4 million gas and electric meters installed – 12/1/09 11/18/2018 Cordova AMI/AMR Security
AMI/AMR Vulnerabilities Meters provide gateway to Smart Grid Notorious memcpy, strcpy, strcat used in OS Physical access to meters not protected No authentication No encryption Retrofitted PLC specs readily available Easy to hack 11/18/2018 Cordova AMI/AMR Security
Vulnerabilities Ignored President Obama’s stimulus package Billions up for grab Specifies security measures be implemented Meters installed despite buggy SW Retrofit costs may be as high as 60 times the regular cost Stimulus causes vendors to clam up 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Securing Smart Meters 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Securing Smart Meters Regulation and Management Examples: Railroad, telecom, Internet New guidelines adopted Vendors boast about solutions New innovative ideas 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Secure the Smart Grid Secure Development Lifecycle (SDL) Authentication Encryption Radio frequency hopping Controllers, collection points, meters all enabled with best security practices Train Staff 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Selected Solutions Itron OpenWay® Collection Engine with Enhanced Security Texas Instruments Smart Meters with Secure Pre-Payment MBUS3 fully compliant Open Metering System (OMS) 11/18/2018 Cordova AMI/AMR Security
Secure Smart Grid Solution 11/18/2018 Cordova AMI/AMR Security
TI Secure Smart Meters with Pre-Payment Triple DES, SHA-1 crypto-algorithms, ANSI X9.63 session key Mutual authentication – authorized tag and reader complete transaction Flexible and configurable memory Supports up to five applications on one card or token ISO/IEC 14443 with ISO/IEC 7816 command set support 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security MBUS3 Supports S1, S2, T1 and T2 modes AES-128 encryption Battery lifetimes in excess of 14 years Master module - support up to 64 slaveswith unique encryption keys Unique auto-message generation feature Message mailboxes supports individual communication with several slaves in parallel Autonomous repeater that will store and retransmit slave messages 11/18/2018 Cordova AMI/AMR Security
Smart Infrastructure Implementation Percentages 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security Conclusion US playing catch-up to the International community Stimulus package worth billions causing vulnerabilities to be ignored Existing installations require retrofit Regulatory agencies adopt guidelines Security is critical to protect against Internet based common vulnerabilities Vendors boast secure solutions Secure installations begin Questions? 11/18/2018 Cordova AMI/AMR Security
Cordova AMI/AMR Security References [1] http://www.itron.com/pages/ news_press_individual.asp?id=itr_016976.xml [2] http://loftyperch.com/index/use_lang/EN/page/408.html [3] http://www.theregister.co.uk/ 2009/06/12/smart_grid_security_risks/ [4] http://earth2tech.files.wordpress.com/ 2009/10/sgigselections_category1.pdf [5] http://www.ensec.org/index.php?option= com_content&view=article&id= 218:making-a-secure-smart-grid-a-reality&catid=100:issuecontent&Itemid=352 [6] http://www.metering.com/node/16162 [7] http://www.ti.com/rfid/shtml/apps-smartmetering.shtml 11/18/2018 Cordova AMI/AMR Security