Energy Central EnergyPulse Home
Home Subscribe Login Contribute to Energy Pulse Advertise on Energy Pulse About Energy Pulse Feedback to Energy Pulse
Search Articles:   
  You are here: Home > Communications & Security > Article Display


Free Newsletter
Sign up today for your free subscription to the EnergyPulse Weekly Update - delivered directly to your e-mail box.
e-mail:


 

Communicating Smart Meter Value

Sep 9 2010 - 2010-01-01 12:00:00 - Your City

If you are involved in Management or Customer Service and are responsible for communicating the value of smart meters to your utility customers, you don’t want to miss this online discussion - Communicating Smart Meter Value.  more...

Social Media: The new frontier in recruiting, communications and marketing

Sep 13 2010 - 2010-01-01 12:00:00 - Your City

Join social media mavens Matthew Burks and Amanda Shewmake as they provide an insider's perspective on how HR, communications and marketing professionals in energy companies can harness the power of social media to be more effective and productive. more...

Eliminating Obstacles and Delivering the Benefits of the Smart Grid - IBM's Optimized Energy Value Chain (OEVC)

Sep 14 2010 - 2010-01-01 12:00:00 - Your City

The convergence of power and information technologies in the smart grid has created opportunities for finer grained and broader controls of energy flows. These opportunities can improve electric service in multiple dimensions: lower cost, greater reliability, greater customer satisfaction, and more...

Achieving Operational Excellence - What to Consider Before Implementing or Upgrading Your Distribution Management Solutions

Sep 16 2010 - 2010-01-01 12:00:00 - Your City

Significant cost over runs. Changing business requirements. A well thought out plan is essential. Attend this free webcast discussion to hear inside hear three experts in utility operations discuss what utilities need to evaluate when they are considering upgrading or more...

Outsmarting the Smart Grid: IT, Security and Communication Infrastructure  Challenges & Opportunities for Utilities

Sep 21 2010 - 2010-01-01 12:00:00 - Your City

The smart grid is shifting the playing field for utilities. And when the game changes, it pays to be prepared. A nimble solutions partner can help you design the solutions that keep operations on track, even as new challenges come more...

1st CSP Today Concentrated Solar Thermal Power Summit India

Sep 7 2010 - Sep 8 2010 - New Delhi India

Deliver a profitable, productive and commercially successful large scale CSP business in India. Building on the success of past events in USA, Europe & MENA, CSP Today brings to New Delhi the most relevant international experience for the concentrated solar more...

Offshore Wind Energy in North America's Great Lakes Conference

Sep 9 2010 - Sep 10 2010 - Toronto

Two day conference that tackles the most important challenges. A blend of European knowledge from the companies who have been installing offshore wind turbines for the last decade alongside local state governing bodies and leading project developers. Permitting, securing long more...

Autovation 2010

Sep 12 2010 - Sep 15 2010 - Austin, TX - USA

Autovation 2010 is a not-to-miss educational forum that will attract utility executives from around the world looking for new ways to optimize their operations through automation technologies. more...

Global Sustainable Bioenergy North American Convention

Sep 14 2010 - Sep 16 2010 - Minneapolis, MN - USA

The North American convention provides a remarkable opportunity to play a part in guiding renewable energy policy for the 21st century. Attendees will create a resolution that, along with similar resolutions already drafted on four other continents, will help set more...

GridWise Global Forum

Sep 21 2010 - Sep 23 2010 - Washington, DC - USA

Hosted by the GridWise(R) Alliance and the U.S. Department of Energy, the GridWise Global Forum will convene thought leaders from the highest levels of government, business, NGOS, and academia from around the world to discuss the ultimate enabling potential of more...

1. Intro to Nat Gas Trading & Hedging 2. Option Applications in Energy

Sep 20 2010 - Sep 23 2010 - Houston, TX - USA

Introduction to Natural Gas Trading & Hedging - This program provides a comprehensive understanding of the structures that underlie Natural Gas trading. Beyond Essentials: Option Applications in Energy - This course provides a solid practical and conceptual (non-quantitative) understanding of more...

Electric Business Understanding Seminar

Sep 20 2010 - Sep 21 2010 - Houston, TX - USA

Electric Business Understanding provides a comprehensive overview of the electric industry. Position yourself for career advancement by gaining a solid understanding of how the electric business works including key physical, market, and regulatory aspects and how market participants navigate this more...

Electric Market Dynamics Seminar

Sep 22 2010 - Sep 23 2010 - Houston, TX - USA

Electric Market Dynamics offers participants an in-depth understanding of North American electric markets and how they function. Enhance your career by furthering your knowledge of market structures, pricing mechanisms, services offered in markets, and how various participants use the markets more...

Gas and Electric Business Understanding Seminar

Oct 5 2010 - Oct 6 2010 - Los Angeles, CA - USA

Gas and Electric Business Understanding provides a comprehensive overview of the natural gas and electric industries. Position yourself for career success by gaining a solid understanding of how each business works, including key physical, market and regulatory aspects, as well more...

Energy Central
Power Network




Communications & Security


We know you have something to say!
There is an immediate need for articles on the hot topics in the Power Industry! EnergyPulse, like no other publication, also provides a means for our readers to immediately interact with experts like you.
 
Contribute Today!
Please view our Author Guidelines and send submissions to the editor.

Click For More Articles on Communications & Security
 
Building the Smart Grid: Proven Methods to Secure the Future
5.19.09   Joshua Pennell, President and Founder, IOActive
Michael Davis, Senior Security Consultant, IOActive

Article Viewed 8169 Times
5 Comments
E-mail Article Printer Friendly
 
  • Comment On Article
  • About The Author
  • More Articles By This Author

    The push for greener, more efficient energy distribution is driving the rapid development and deployment of Advanced Metering Infrastructure (AMI) technology, or smart meters. Smart meters are considered to be just one technology platform within an overall suite of maturing smart grid energy management technologies. These technologies will foster the modernization of the nation's electrical power infrastructure into what will ultimately become the cornerstone for the power grid of tomorrow. In conjunction with the approved $4.5 billion economic stimulus package, the need to create U.S. jobs and a rapidly evolving market space, this long-awaited advancement to the U.S. power infrastructure has become a reality today. But is the technology ready?

    This new generation of energy distribution technology promises to deliver real-time information, and enable the near-instantaneous balance of supply and demand. Utilities and consumers alike will benefit from the smart grid's ability to sense system overloads and reroute power to prevent, or minimize, potential outages. Yet, as with any new innovation promising such benefits, there is both opportunity and associated risk. Without considering the risks, we may never truly see the benefits.

    In April, IOActive researchers were able to identify multiple programming errors on a series of smart meter platforms ranging from the inappropriate use of banned functions to protocol implementation issues. The research team was able to "weaponize" these attack vectors, and create an in-flash rootkit, which allowed them to assume full system control of all exposed smart meter capabilities, including remote power on, power off, usage reporting, and communication configurations. The initial attack vector could also be leveraged to deploy a worm, much like the Blaster worm that wreaked havoc on computer systems in 2003. The consequences of such threats are potentially widespread and devastating.

    And hardware attacks are on the rise, due in large part to the relative ease with which they can be launched. While most software developers build base-level security into their products, hardware level has long been overlooked. Simply acquire a smart meter, and it is easy enough to reverse-engineer the device due to the lack of encryption at the hardware level. Or decode the device's communications by listening to the spectrum of radio patterns emitted by the smart meter. Neither method requires an overspecialized background or significant financial investment. Consider that most utility meters sit outside private residences and businesses, with little or no physical security to prevent access, and you have a recipe for tampering.

    Think this scenario is unlikely? Unfortunately, it's far more likely than people care to imagine. A Department of Energy lab recently published a statistic showing that there were roughly 250 exploits for control systems on any given day in 2006-2007. It was reported to take roughly 131 days to patch and remediate those vulnerabilities -- leaving the window open for exploitation.

    Beyond the ease of threat, the reality is that utility companies are viewed as recession-proof, and thus always earning money. This makes them an attractive target for criminals. Vulnerabilities in the smart grid could cause utilities to lose system control of their metering infrastructure to unauthorized third parties, exposing them to fraud, extortion attempts, lawsuits, widespread system interruption, massive blackouts or worse. The severity of the situation is driving the release of the Critical Electric Infrastructure Protection Act (CEIPA), a new bill solely focused on addressing cybersecurity concerns of the U.S. power grid. And it's only just beginning.

    All of this indicates that the security maturity of the smart meter market warrants immediate inquiry and evaluation. With more than two million smart meters in field use today, and an additional 17 million devices on order by over 73 participating utilities, the threat is not a localized concern. Furthermore, smart meter technology is expected to last 10 to 20 years in the field.

    So can the smart grid be saved? While there are clearly challenges ahead, it's not too late. The utility sector can, and should, protect their investment by demanding that smart meter devices come equipped with the types of security protection afforded to computers on a standard enterprise network.

    The challenge to building a secure smart grid power infrastructure is to quickly enact methods that support both asset owners and smart grid vendors. Typical of most emerging industries and first-to-market initiatives, the smart grid AMI community lacks a formal Secure Development Lifecycle (SDL) to guide and govern the release of sound quality technology and products. Including a requirement to conduct independent third-party security assessments of all smart grid technology will further enable the smart grid AMI industry to deploy their technology in a secure, mindful fashion without causing significant time-to-market delays.

    The SDL is a proven tool for saving money, and decreasing exposure to risk. Studies show that overall project costs are 60 times higher when gaps in information security controls are addressed late in the development cycle, as opposed to projects where security is implemented in the design phase. Championed by Microsoft, the SDL contributed to a massive reduction in the number of security bulletins issued for Windows Server 2003 and SQL Server 2000.

    In light of where we are with the application of smart grid technology, there is still time to stop. Private industry is ready and well positioned to take on this challenge to help pave the way towards a secure smart grid infrastructure that will benefit generations to come. Already at the forefront of the research efforts around AMI security, the industry has been intimately involved in the development and refinement of the SDL.

    And as the old saying goes, "measure twice, cut once." Utilities should embrace their role as the stewards of the energy "ecosystem," and hold smart meter vendors accountable for the security of their products. By demanding that their suppliers adopt secure development practices, and requiring them to undergo third-party security auditing, energy utilities can thrive from the benefit of the smart grid while insuring the future safety of the nation's critical infrastructure.

    For information on purchasing reprints of this article, contact Tim Tobeck ttobeck@energycentral.com.
    Copyright 2010 CyberTech, Inc.
     
    E-mail Article Printer Friendly
     
  • Click Here For More Articles on Communications & Security


  • Click Here For More Articles By Joshua Pennell
  • Do you agree or disagree with this article? Send in your own article.

     

    Readers Comments

    Date Comment
    Len Gould
    5.20.09
    "utility companies are viewed as recession-proof, and thus always earning money. This makes them an attractive target for criminals." -- Typical of the (absence of) logic in use in the article. Why not simply throw a sheet over your head and stand in the corner going "Whooo Whoooo"?

    Bob Amorosi
    5.20.09
    Len,

    If the utility industry is reading this article, or have been thinking this way for a long time - which I suspect is the case, is it any wonder why there has been so little support for introducing real-time electricity markets for all consumers as in your IMEUC proposals.

    Besides fighting over who would bear the costs for the in-home technologies, it would require consumers to communicate with THEIR smart meters to get access to the grid. The latter I'm sure conjures up nightmares for utility officials of security breaches, especially given THEIR meters are their only billing mechanism that determines their income.

    In essence my perception has been most utility companies have shuddered at the concept of anyone communicating with THEIR smart meters, and will only allow it if governments or industry regulators force them to.

    Times are a changin’ though. I read on another EP article lately that Texas is passing state legislation that will force all Texas utility companies to provide all customers smart meters equipped with a standardized communication portal into their homes (like Itron’s Open-Way system, or similar Zigbee radio transceivers). I don’t recall exactly by when but it is something like by 2015, presumably at least to enable consumer real-time energy monitoring and also enable utility demand response capabilities through AMI systems.

    Bob Amorosi
    5.20.09
    Len,

    The article is "Advanced Meters in Texas Provide Billing Benefits" by Steve Schugart, just published on EP May14th. The rollout completion date for the whole state is by 2014. Another primary function enabled by the communication portal into residential homes will include customer pre-paid energy billing.

    Len Gould
    5.27.09
    Bob. Agreed, a lot of resistance there. To the point where Google has teamed up with Toronto Hydro to develop a widget to add to the Google toolbar which communicates with the utility central database in order to display meter data. Apparently it can only access the previous days readings..... what nonsense. No doubt utilities will try to use it to show regulators that they are providing the data to customers, though. Day-old meter readings are almost as usless for customers as no meter readings.

    Bob Amorosi
    5.28.09
    Len,

    The previous day's meter data is all that Toronto Hydro is allowed to make available to customers because the mandate given to Ontario's utility companies (by the Ontario government's smart meter initiative) was to collect meter readings only once or twice a day. The data must be ready to access by customers by 8:00am the next morning to view if desired, typically on the utility's website.

    Real-time feedback to all customers is not part of their current plans unless government forces them to provide it through new legislation, or if given the money (by someone) to do so.

    Interestingly some utility people have told me in the past they believed real-time feedback to all customers will be eventually needed in the future, which can be many years out for the traditional pace change in their industry and by our government. Governments take many years to react because they will want to study its benefits to death before committing any tax revenues to implement broad-based new mandates.

    Add your comments:
    Please log in to leave a comment!

    Top

        Home | Register | Subscribe | Contribute | Advertise | About Us | Feedback
       Copyright © 2002-2010, CyberTech, Inc. - All rights reserved. Read our Terms of Service.