Experts fear hacking of new smart meters


Substation Relay Protection Training

Our customized live online or in‑person group training can be delivered to your staff at your location.

  • Live Online
  • 12 hours Instructor-led
  • Group Training Available
Regular Price:
$699
Coupon Price:
$599
Reserve Your Seat Today

Smart meter cybersecurity faces scrutiny as utilities deploy smart grid devices with wireless links, remote disconnect, and encryption. Experts cite NIST standards, penetration testing, and monoculture risks from widespread Itron deployments.

 

Breaking Down the Details

Smart meter cybersecurity secures smart grid meters, protecting wireless data and remote disconnect with encryption.

  • NIST draft standards guide smart grid security practices
  • Utilities use unique encryption and layered defenses
  • Tamper detection alerts on meter removal or casing open

 

As California's utilities roll out millions of "smart meters" in the coming years, they're creating, for the first time, the possibility that the electricity infrastructure could be hacked through a home, security consultants say.

 

With San Diego Gas & Electric Co. and Southern California Edison installing 7.3 million smart meters — upgrading their entire customer base — they're essentially attaching small computers to each house, each equipped with wireless communications back to the utilities.

Utilities say they have been hardening the smart meters against security holes since they began development, but security consultants say they are worried: If criminals cracked the system, they could remotely install a virus that could shut down power for millions of customers.

The new smart meters will have a host of capabilities, as part of the broader smart grid trend many utilities pursue today: They will credit homeowners who produce their own electricity via solar cells or wind turbines, be able to wirelessly communicate data to the utility and let utilities turn off the power remotely, among other functions that could be added.

"Were it telemetry only, then the only compromise is privacy," said Mike Davis, senior security consultant for the security service IOActive. "When you add remote disconnect, then you increase the attractiveness of the meter as a target."

Davis and his team hacked into smart meters, a known hacking target last spring as part of a proof-of-concept they showed off at a Las Vegas security conference last summer.

They reverse engineered meters they bought on eBay and found in trash bins near installation sites. Then they installed a computer virus that would replicate itself across the wireless network and block the utility from each meter as it went.

Representatives from Edison and SDG&E said that the demonstration didn't change their work at all; that they've been working on security since they started development three years ago.

But Davis noted that utilities now require secure recycling of old meters, and eBay won't allow that sort of gear to be sold on the site any longer. Davis said they have done such a good job keeping the meters out of his hands that he hasn't hacked the most recent meters because he can't find one through legal means.

The demonstration may have also driven the federal government to create standards for smart meters in the previously unregulated smart meter arena. The National Institute of Standards and Technology, a branch of the Department of Commerce, released a draft of standards in September.

"Our security complies with the emerging smart grid standards in NIST," said Paula Campbell, director of the Edison Smart Connect Program.

"There's unique encryption, all designed with the goal in mind of minimizing the vulnerabilities."

The encryption would apply primarily to over-the-air communications from the devices. In theory, a criminal could sit in a car up to a mile away from a site and attempt to hack the WiFi signal of the devices, as researchers caution could be possible under certain conditions.

Baker said that would be pretty hard.

"It's called security in depth," Baker said. "The old technology is there's one key that could open every door in the neighborhood. In the systems employed today, you need a different key for every room in your house to thwart hackers effectively in practice."

Alternatively, a hacker could just try to wire directly into a meter.

All the devices will include a detector that sends an alert to the utility if the meter is shaken, removed or even if the front cover is taken off.

"How you respond to that, isolate that, control that in an organized fashion, it's part of our overall security program," said Chris Baker, chief information officer for SDG&E.

Davis, though, said he thinks the utilities are just buying a product, and it's the manufacturers who are rushing to market.

Itron Inc., the Washington-based supplier of smart meters to both Edison and SDG&E, pooh-poohed Davis' demonstration this summer.

"We believe our implementation is very secure and cannot be subjected to the kind of attacks shown by IOActive in their demonstration of unsecured equipment," company spokeswoman Kim Papich said in an e-mailed statement.

In a separate statement, Itron said it hired outside companies to test their systems. Both SDG&E and Edison said they also had contracted with third parties to conduct "penetration tests," in which security professionals search for security bugs and weaknesses.

Davis said he is pleased that there is third-party testing, but he is still worried about creating a monoculture of devices. Because all the smart meters installed by SDG&E and Edison will be made by the same company and use the same software, they're only as strong or as weak as any one unit.

Related News

Turkish powership to generate electricity from LNG in Senegal

Karpowership LNG powership in Senegal will supply 15% of the grid, a 235 MW floating…
View more

German official says nuclear would do little to solve gas issue

Germany Nuclear Phase-Out drives policy amid gas supply risks, Nord Stream 1 shutdown fears, Russia…
View more

The Impact of AI on Corporate Electricity Bills

AI Energy Consumption strains corporate electricity bills as data centers and HPC workloads run nonstop,…
View more

Analysis: Why is Ontario’s electricity about to get dirtier?

Ontario electricity emissions forecast highlights rising grid CO2 as nuclear refurbishments and the Pickering closure…
View more

Quebec Power Imports Signal Shift in Electricity Balance

Quebec is importing electricity from the United States as rising domestic demand and reduced hydropower…
View more

How Canada can capitalize on U.S. auto sector's abrupt pivot to electric vehicles

Canadian EV Manufacturing is accelerating with GM, Ford, and Project Arrow, integrating cross-border supply chains,…
View more

Sign Up for Electricity Forum’s Newsletter

Stay informed with our FREE Newsletter — get the latest news, breakthrough technologies, and expert insights, delivered straight to your inbox.

Electricity Today T&D Magazine Subscribe for FREE

Stay informed with the latest T&D policies and technologies.
  • Timely insights from industry experts
  • Practical solutions T&D engineers
  • Free access to every issue

Live Online & In-person Group Training

Advantages To Instructor-Led Training – Instructor-Led Course, Customized Training, Multiple Locations, Economical, CEU Credits, Course Discounts.

Request For Quotation

Whether you would prefer Live Online or In-Person instruction, our electrical training courses can be tailored to meet your company's specific requirements and delivered to your employees in one location or at various locations.