Search papers, labs, and topics across Lattice.
This study investigates the vulnerability of the German Smart Metering Infrastructure (SMI) to delay attacks on control signals transmitted via the Controllable Local System (CLS) channel. By integrating theoretical analysis with experimental validation, the authors reveal that an on-path attacker can exploit these vulnerabilities to induce significant frequency deviations in the power grid, with potential impacts extending to load shedding across multiple CLS devices. The findings underscore the need for robust mitigation strategies, including configuration restrictions and protocol extensions, to enhance the security of smart metering systems against such threats.
An on-path attacker can exploit timing constraints in the German Smart Metering Infrastructure to induce dangerous frequency deviations, risking widespread load shedding.
This work analyzes the feasibility of delay attacks on control signals transmitted via the Controllable Local System (CLS) channel of the German Smart Metering Infrastructure (SMI). It combines theoretical analysis with experimental validation under a threat model aligned to the Common Criteria Protection Profile for the Smart Meter Gateway (SMGW) and assess the potential impact on the power grid if the identified attack vector is exploited across multiple CLS channels simultaneously. We also outline mitigation strategies, including SMGW configuration restrictions, implementation-level changes, and protocol extensions. Our results show that an on-path attacker in the Wide Area Network (WAN) with sufficient contextual knowledge can feasibly execute delay attacks, with a theoretical upper bound of roughly 48 hours for some deployed protocol configurations. Projecting from a single CLS to several hundred thousand CLS devices indicates such an adversary could cause a significant frequency deviation potentially resulting in load shedding. Scaling the attack requires contextual knowledge for each targeted implementation and configuration; whether this knowledge can be broadly reused across CLS channels is uncertain but may become easier to obtain as standardization progresses. Time restricted transmissions in the FNN Steuerbox and in applications using CLS.EEDI are implementation-specific and can therefore be addressed by manufacturers. By contrast, ensuring application-data time limitations in TLS~1.3 requires protocol-level extensions. The TLS extensions proposed here offer a sustainable mitigation while preserving backward compatibility. Other communication channels outside the SMI (for example, proprietary remote terminal units used to control a CLS) are outside this work's scope and may exhibit similar or worse vulnerabilities.