Utility device management.
Abstract
Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for managing utility device operations. In one aspect, a utility apparatus includes a processing apparatus that manages data processing tasks for the utility apparatus. The utility apparatus also includes a communications apparatus, coupled to the processing apparatus, that is configured to transmit and receive data over a network. A metrology apparatus is coupled to the processing apparatus, the metrology apparatus being configured to measure and provide meter data that includes at least a measure of utilized utility services. A network apparatus is also coupled to the processing apparatus, the network apparatus being configured to coordinate communication between devices that belong to a home area network. A utility identification module interface is coupled to the processing apparatus, the utility identification module having an interface that removably receives a utility identification module.

Term
5 yearsleft in the term
Expires 8 September 2031.
- Priority
- Filed
- Granted
- Today
- Expires
21 claims: 6 independent, 15 dependent
- 1REIVINDICACIONES 1. Un aparato para servicios públicos, í caracterizado porque comprende:un aparato de ¡procesamiento que administra tareas de procesamiento de datos para el I aparato de servicios públicos;un aparato de cpmunicaciones acoplado al aparato de procesamiento, el aparato de comunicaciones se configura para transmitir y recibir datos sobre una red;un aparato de metrología acoplado al aparato . t de procesamiento, el aparato de metrología se configura para medir y proporcionar datos de medidor que incluyen al menos una medida de los servicios públicos utilizados;un aparato de red acoplado al aparato de procesamiento, el aparato de red se configura para coordinar comunicación entre dispositivos que pertenecen a una red de área ¡doméstica;y una interfase de módulo de identificación ¡de servicios públicos, acoplada al aparato de procesamiento, ¡el módulo de identificación de servicios públicos tiene interfase que recibe en forma desprendible un módulo de identificación de servicios públicos, en donde el módulo de identificación de servicios públicos incluye al menos un procesador y un almacenamiento de datos que almacena datos de configuración que configuran el aparato de procesamiento para comunicar con el aparato de comunicaciones, el aparato de metrología, y el aparato de red.
- 2El aparato de servicios públicos de conformidad con la reivindicación 1, caracterizado porque además comprende un módulo de identificación de servicios públicos desprendibles que almacena datos de configuración que se asocian respectivamente con el aparato de comunicaciones, el aparato de metrología, y el aparato de red.
- 3El aparato de servicios públicos de conformidad con la reivindicación 2, caracterizado porque los datos de configuración que se asocian con el aparato de comunicaciones especifican al menos una clave de cifrado con ía cual datos i transmitidos a un aparato de administración' de red de i servicios públicos son cifrados.
- 4El aparato de servicios públicos d;e conformidad con la reivindicación 2, caracterizado porque ¡los datos de configuración que se asocian con ' el aparato de metrología especifican al menos una clave de seguridad qué se requiere para comunicar con el aparato de metrología.
- 5El aparato de servicios públicos de conformidad con la reivindicación 2, caracterizado porque los datos de configuración que se asocian con el aparato de red especifican al menos una clave de seguridad de red que se requiere para comunicar sobre la red de área doméstica o una red de área vecina.
- 6El aparato de servicios públicos de conformidad I con la reivindicación 5, caracterizado porque ¡los datos de configuración además especifican:dispositivos qÍue pertenecen a la red de área doméstica;ajustes de comunicaciones asociados con la red de área doméstica, en donde los ajustes de ^comunicaciones especifican pares de dispositivos que están en comunicación entre sí;y características de > seguridad de los dispositivos que pertenecen a la red de área'doméstica. 7. El aparato de servicios públicos de conformidad con la reivindicación 5, caracterizado porque la red de área doméstica es una red ZigBee en donde dispositivos se comunican de acuerdo con un protocolo de comunicaciones ZigBee. 8. El aparato de servicios públicos de conformidad con la reivindicación 2, caracterizado porque cada uno de datos de configuración respectivos se almacenan y dividen de acuerdo con el aparato al cual corresponden los datos de configuración.
- 79. El aparato de servicios públicos de conformidad con la reivindicación 1, caracterizado porque el módulo de identificación de servicios públicos es un componente de equipo físico seguro.
- 810. Un método, caracterizado porque comprende:determinar por un aparato de procesamiento de servicios públicos un aparato de servicios públicos, que el aparato de procesamiento de servicios públicos requiere datos de configuración para interactuar con al menos uno de un aparato de metrología asociado con el aparato de procesamiento de servicios públicos y un aparato de red que se asocia con el aparato de procesamiento de servicios públicos;detectar por el aparato de procesamiento de servicios públicos, un módulo de identificación de servicios públicos desprendible que está en comunicación con el aparato de procesamiento de servicios públicos, el módulo de identificación de servicios públicos almacena datos de configuración requeridos por el aparato de procesamiento de servicios públicos para interactuar con al menos uno del aparato de metrología y el aparato de red;recibir, por el aparato de procesamiento de servicios públicos y del módulo de identificación de servicios públicos, los datos de configuración;e interactuar, por el aparato de procesamiento de servicios públicos con al menos uno del aparato de metrología y el aparato de red utilizando los datos de configuración.
- 911. El método de conformidad con,la reivindicación 10, caracterizado porque:recibir los datos de configuración comprende: recibir del módulo de identificación de servicios públicos desprendible, datos de cifrado que especifican una clave · de cifrado que se utiliza para transmitir datos de reporte a un aparato de administración de red que administra una red de servicios públicos a la cual pertenece el aparato de servicios públicos;y recibir, del módulo de identificación de servicios públicos desprendible, datos de enrutamiento que especifican uno o más dispositivos de red ¡i que pertenecen a una misma red en malla como el aparato de servicios públicos y que están en comunicación con el aparato de servicios públicos;y además comprende transmitir datos de medidor que son cifrados con la clave de cifrado a un dispositivo de red selecto especificado por los datos de enrutamiento.
- 1012. El método de conformidad con la reivindicación 11, caracterizado porque recibir datos de enrutamiento además comprende:recibir datos geográficos que especifican una ubicación geográfica del aparato de servicios públicos;y recibir datos de destino que especifican un ideñtificador de red asociado con el aparato administrador de red¿
- 1113. El método de conformidad con la reivindicación 10, caracterizado porque además comprende:recibir, de otro aparato, una prueba de autenticación que solicita una respuesta a la prueba;y· proporcionar una respuesta a la prueba de autenticación.
- 1214. El método de conformidad con la reivindicación 13, caracterizado porque además comprende determinar por el otro aparato, que la respuesta a la prueba de autorización es una respuesta válida, en donde una respuesta válida es una respuesta que autentica el aparato de servicios públicos como en un estado sin manipulación indebida. ί
- 1315. El método de conformidad con la reivindicación 14, caracterizado porque además comprende:determinar por el otro aparato, que la respuesta válida se recibió fuera de un tiempo de respuesta umbral;y proporcionar por» el otro aparato, datos de manipulación indebida al I aparato de administración de red que reporta recepción de una respuesta ¡ f válida fuera del tiempo de respuesta umbral. ¡ I !
- 1416. El método de conformidad con la reivindicación 13, caracterizado porque ademas comprende:I. determinar por el otro aparato que la respuesta a la prueba i l de ;autorización es una respuesta inválida, en donde una respuesta inválida es una respuesta que falla en autenticar i el aparato de servicios públicos como en un estado sin manipulación indebida;y proporcionar por el otro aparato, I datos de manipulación indebida al aparato de administración ! ¡ de ;red que reporta recepción de la respuesta inválida. I
- 1517. El método de conformidad con la reivindicación 10, caracterizado porque recibir los datos de configuración comprende recibir, por el aparato de utilidad aparato de procesamiento y del módulo de identificación ¡de servicios ¡' I· públicos, datos de red de área doméstica asociados con una red de área doméstica que se asocian con úna ubicación » i· i geográfica del aparato de servicios públicos. í·
- 1618. El método de conformidad con la reivindicación ! I 17,, caracterizado porque recibir los datos de ¡ red de área doméstica comprende recibir, del módulo de identificación de servicios públicos, un conjunto de identificadores de dispositivos para dispositivos que pertenecen a la red de área doméstica, un conjunto de claves de seguridad que se emplean para comunicar sobre la red de área 'doméstica, y ajustes de seguridad para dispositivos que pertenecen a la red de área doméstica.
- 1719. El método de conformidad con la reivindicación 17, caracterizado porque además comprende coordinar comunicación entre dispositivos que pertenecen a la red de área doméstica. ¡
- 1820. El método de conformidad con la reivindicación 19, caracterizado porque:recibir datos de ¡red de área doméstica comprende recibir, desde el módulo de identificación de servicios públicos, una clave de seguridad de red para la red de área doméstica;y coordinar comunicación entre dispositivos que pertenecen! a la red de área doméstica comprende: recibir, de un nuevo! dispositivo, una solicitud para unirse a la red de área ¡doméstica;y proporcionar la clave de red al nuevo dispositivo en respuesta a la solicitud.
- 1921. El método de conformidad con la reivindicación 19, caracterizado porque la coordinación de la, comunicación entre dispositivos que pertenecen a la red de áfea doméstica, comprende coordinar comunicaciones entre dispositivos que se ’ l· comunican sobre la red de área doméstica de acuerdo con una norma de comunicaciones ZigBee. 1 ! 22. El método de conformidad con la reivindicación 19,, caracterizado porque recibir los datos de ¡configuración además comprende recibir, por el aparato de procesamiento de ¡ I servicios públicos y del módulo de identificación de í í ' l servicios públicos, una clave de seguridad es que se requiere i ¡ para comunicar con el aparato de metrología que ¡se asocia con el ¡aparato de servicios públicos. i 23. El método de conformidad con,la reivindicación I
- 2022,:caracterizado porque además comprende: obtener los datos I í ¡ ¡ de medidor, en donde los datos de medidor comprenden al menos una¡ medida de servicios públicos utilizados;¡y generar un I paquete de comunicación que incluye los datos de medidor, en ! donde el paquete de comunicación está cifrado utilizando los datos de cifrado. ¡ 24. Un sistema, caracterizado porque comprende: un primer punto extremo en una red de servicios ¡públicos, el ;iprimer punto extremo tiene una interfase d¡e módulo de , i l· identificación de servicios públicos, que recibe en forma desprendible un primer módulo de identificación¡de servicios públicos, en donde el primer módulo de identificación de I servicios públicos almacena datos que se asocian con una > ¡ cuenta de servicios públicos particular, y en donde el primer punto extremo se configura para medir utilización de servicios públicos, asociar la medición ! con datos especificados por el módulo de identificación ¡de servicios públicos que se ha recibido en forma desprendible por el primer punto extremo, y transmitir las medidas sobre una red de servicios públicos;un segundo punto extremo en la red de servicios públicos, el segundo punto extremo tiene una interfase de módulo de identificación de servicios públicos que recibe en forma desprendible un segundo módulo de identificación de servicios públicos, en donde el segundo módulo de identificación de servicios públicos almacena datos que se asocian con una misma cuenta de servicios públicos particular como el primer módulo de identificación de servicios públicos, el segundo punto extremo se localiza en una ubicación geográfica diferente del primer punto extremo, el segundo punto extremo se configura para medir utilización de servicios públicos, asociar la medida con datos especificados por el segundo módulo de identificación de servicios públicos, y transmitir las medidas por la red de servicios públicos;un aparato de administración de red en comunicación con el primer punto extremo y el segundo punto extremo, el aparato de administración de red se configura para recibir las mediciones del primer punto extremo y el segundo punto extremo y asociar las mediciones con la misma cuenta de servicios públicos particular, con base en las mediciones que se asocian respectivamente cón los datos especificados por el primer módulo de identificación de servicios públicos y el segundo módulo de identificación de servicios públicos. 25. El método de conformidad con la reivindicación
- 2124, caracterizado porque las mediciones recibidas del primer punto extremo y el segundo punto extremo que están asociadas 5 con la misma cuenta de servicios públicos particular, son mediciones para utilización de servicio públicos que ocurren a un mismo tiempo.
Independent claims21
257 paragraphs in 12 sections, as filed
(54) Title: ADMINISTRATION OF A DEVICE FOR PUBLIC SERVICES. (54) Title: UTILITY DEVICE MANAGEMENT.
(57) Summary
Methods, systems, and apparatus, including computer programs that encode on a computer storage medium, for managing utility device operations. In one aspect, a utility apparatus includes a processing apparatus that manages data processing tasks for the utility apparatus. The utility apparatus also includes a communications apparatus, coupled to the processing apparatus, that is configured to transmit and receive data over a network. A metrology apparatus is coupled to the processing apparatus, the metrology apparatus is configured to measure and provide meter data that includes at least one utility measurement used. A network appliance is also coupled to the processing appliance, the network appliance is configured to coordinate communication between devices that belong to a home area network. A utility identification module interface is coupled to the processing apparatus, the utility identification module has an interface that removably receives a utility identification module.
(57) Abstract
Methods, systems, and apparatus, including Computer programs encoded on a Computer storage medium, for managing utility device operations. In one aspect, a utility apparatus ineludes to Processing apparatus that manages data Processing tasks for the utility apparatus. The utility apparatus also ineludes a Communications apparatus, coupled to the Processing apparatus, that is configured to transmit and receive data over a network. A metrology apparatus is coupled to the processing apparatus, the metrology apparatus being configured to measure and provide meter data that ineludes at least a measure of utilized utility Services. A network apparatus is also coupled to the processing apparatus, the network apparatus being configured to coordinate communication between devices that belong to a home area network. A utility Identification module interface is coupled to the processing apparatus, the utility Identification module having an interface that removably receives a utility Identification module.
ADMINISTRATION OF PUBLIC SERVICES DEVICE
CROSS REFERENCE TO RELATED REQUESTS
This application claims priority from US Patent Application Serial Number 12 / 891,915, filed on September 28, 2010, the content of which is incorporated by reference in its entirety.
BACKGROUND
This specification refers to security, identification and maintenance of public service terminal or endpoint.
Utility meters have become integral elements of distributed data networks. For example, utility meters and other utility devices may include transceivers that allow the device to provide usage data (for example data specifying energy use or water use), network status data (for example data that specify network operating characteristics) and other network data, to a public service operator. The transceivers associated with these devices also allow the devices to receive configuration data that can be used to maintain proper configuration of the devices and / or control data that can be used to (remotely) change a meter mode of operation (for example remote service disconnection).
Utility meters are also used to drive or manage Home Area Networks (HANs). For example, üri utility meter can be configured to communicate with smart devices, which communicate according to a specified communication standard (eg ZigBee Smart Energy). In turn, the utility meter can store network configuration data and / or device identifiers that are required to coordinate communication between smart devices.
Because utility meters have become an integral part of distributed data networks, it is important that these utility: public meters are implemented with security features that protect against attacks on utility meters and data networks. Additionally, it is also important to reduce t
amount of time that a utility meter is out of service such as after meter replacement and / or a power outage.
COMPENDIUM
In general, an innovative aspect of the subject matter described in this specification can be incorporated into an apparatus that includes a processing apparatus that handles
I, data processing tasks for him! public service apparatus; a communications apparatus coupled to the processing apparatus, the communications apparatus is configured to transmit and receive data over a network; a l · · metrology apparatus coupled to the processing apparatus, the! Metrology apparatus is configured to measure and provide meter data that includes at least one measure of utilities used; a network device attached to the processing appliance, the network appliance is configured to coordinate communication between 'devices that' I!
they belong to a home area network; and an interface of
I module for the identification of public services | coupled to the processing apparatus, the public services identification module has an interface that removably receives a public services identification module, where the services identification module: The audience includes at least one processor and one Edata storage that stores configuration data that the processing apparatus configures to communicate with the communications apparatus, the metrology apparatus, and the network apparatus. Other modalities of this aspect include corresponding I, systems, methods and computer programs. ¡'. i.
<sup>:</sup> These and other modalities, each may optionally include one or more of the following features. The
The device can include an identification module of!
Removable utilities that stored configuration data that are associated respectively with the communications apparatus, the metrology apparatus, and the network apparatus. The configuration data that is associated with the communications appliance can specify at least one encryption key with which data transmitted to a utility network management appliance is encrypted. The configuration data that is associated with the metrology appliance can specify at least one security key that is required to communicate with the metrology appliance.
The configuration data that is associated with the network appliance can specify at least one network security key that is required to communicate over the home area network or a neighboring area network, i The configuration data further specifies: devices that they belong to the home area network; communications settings associated with the home area network, where the communications settings specify pairs of devices that are in communication with each other; and characteristics of, security of the devices that belong to the home area network.
The home area network may be a ZigBee network, where the devices communicate according to a ZigBee communication protocol. Each of: the respective configuration data can be stored and divided according to the apparatus to which the configuration data corresponds. The utility identification module can be a component of secure physical equipment.
In general, another aspect of the subject matter described in this specification may be incorporated into methods that include the actions of determining, by a utility processing apparatus of a utility apparatus, that the utility processing apparatus requires configuration data to interact with at least one of a metrology apparatus associated with the utility processing apparatus and a network apparatus that is associated with the utility processing apparatus; detecting by the utility processing apparatus, a removable utility identification module that is in communication with the utility processing apparatus, the utility identification module stores configuration data required by the utility processing apparatus audiences to interact with at least one of the metrology apparatus and the network apparatus; receive, by the utility processing apparatus and the utility identification module, the configuration data; and interacting, by the utility processing apparatus, with at least one of the metrology apparatus and the network apparatus using the configuration data. Other modalities of this aspect include corresponding computer systems, apparatus and programs, configured to carry out the actions of the methods, encoding the storage device in a computer.
Each of these and other embodiments may optionally include one or more of the following features. Receive configuration data which may include receiving, from the removable utility identification module, encryption data that specifies an encryption key that is used to transmit report data to a network management appliance that manages a utility network to which belongs the apparatus of public services; and receiving, from the removable public services identification module, routing data specifying one or more network devices that belong to the same mesh network as the public services apparatus and that are in communication with the public services apparatus. Additionally, methods may include transmitting meter data that is encrypted with the encryption key to a select network device specified by the routing data.
Receiving routing data may also include receiving geographic data that specifies a geographic location of the utility appliance; and receiving destination data specifying a network identifier associated with the network management apparatus.
Methods may further include receiving, from another apparatus, an authentication test requesting a response to the test; and provide response to the authentication test. Methods may further include determining, by the other apparatus, that the authorization test response is a valid response, wherein a valid response is a response that authenticates the utility apparatus as being in a tamper-free state. .
Methods may further include determining, by the i
and another device, that the valid response was received outside of a!
threshold response time; and provide by the other device, tamper data to the<sup>1</sup> network management appliance reporting receipt of valid response outside threshold response time.
Methods may further include determining, by the other apparatus, that the response to the authorization test is an invalid response, wherein an invalid response is a response that fails to authenticate the utility apparatus as in a state without tampering; and providing by the other apparatus, tamper data to the network management apparatus reporting receipt of the invalid response. Receiving configuration data
I!
may include receiving, by the processing apparatus of the [
utility module and identification module: utility I, home area network data associated with a home area network that is associated with a
I geographical location of the public services apparatus.
¡
Receiving the data from the home area network may include receiving, from the utility identification module, a set of device identifiers for devices belonging to the home area network, a set of security keys that are used to communicate
I
I about home area network and security settings for í
devices that belong to the home area network.
'Methods may also include<sup>1</sup> coordinate communication between devices that belong to the home area network. Receiving data from the home area network may include receiving, from the módulo identification module
utilities, a network security key for the home area network 15. Coordinating communication between devices that belong to the home area network may include receiving, from a new device, a request to join the home area network; and provide the network key to the new device in response to the: i request. ;
I
Coordinating communication between devices that belong to the home · area network may include coordinating communications between devices that communicate over the home area network in accordance with a ZigBee communication standard. Receiving the configuration data may further include receiving, by the utility processing apparatus and the utility identification module, a security key that is required to communicate with the metrology apparatus that is associated with the public services.
Methods may further include obtaining: meter data, where meter data comprises at least one measure of the utilities used; and generating a communication packet including the meter data, wherein the communication packet is encrypted using the encryption data.
In general, another aspect of the subject matter described in this specification can be incorporated into a system that includes a first endpoint in a public service network, the first endpoint has a public service identification module interface that is removably received a first module for identifying public services, where the first public services identification module stores data that is associated with a particular public services account, and where the first end point is configured to measure the utilization of public services, associate the measurement with data specified by the identification of public services that has been detachably received by the first extreme point, and transmit the measures over a network of public services; one second
I extreme point in the public services network<sup>1</sup>,, the second endpoint has a public service identification module interface that removably receives a second service identification module
I | public, where the second module of public service identification stores data that is associated with the same particular public service account as the first module of public service identification, the second
I endpoint is located in a geographic location
I different from the first endpoint, the second endpoint is configured to measure utilization of public services, associate the measurement with data specified by the second module of identification of public services and transmit; i the measure on the network of public services; ün a network management device in communication with the first endpoint and the second endpoint, the network management device is configured to receive measurements from the; first end point and the second end point and associate the measures with the same account of particular public services based on the measures that are respectively associated with the data specified by the first module of identification of public services) and the second module of identification of public services. Other modalities of this aspect include corresponding computer systems, apparatus and programs, configured to perform the actions of the methods, encoded in computer storage devices.
Particular modalities of the subject matter described in this specification can be implemented to achieve one or more of the following advantages. Utility meters can be configured more quickly by using a removable utility identification module that stores configuration data for the meter instead of retrieving configuration data over a utility network. Meter security is enhanced by using encryption and / or test / response techniques to restrict access to the metrology, communications, and / or home network device that is implemented in the meter. Meter exchange processes (i.e. meter swap / replace) are simplified because the data required by a newly installed meter (or other utility device) is available from a utility module that was previously removed from the meter installed. Data that identifies a meter as a Trust Center for a home area network, can be stored in the utility identification module instead of fixed meter components. Periodic determination of a tamper status of a utility meter reduces the likelihood of unauthorized access and fraudulent activity.
The details of one or more modalities of the subject matter described in this specification are set forth in the accompanying drawings and the following description. Other characteristics, aspects and advantages of the subject matter will be apparent from the description, <drawings and claims.
BRIEF DESCRIPTION OF THE DRAWINGS
Figure 1 is an exemplary environment in which public service identification modules can be implemented.
Figure 2 is a block diagram of an endpoint including an identification module interface.
I of public services.
Figure 3 is a flow chart of an exemplary process for setting up a utility meter.
Figure 4 is a flow chart of an exemplary process for determining a tamper state of a utility meter.
Similar reference numbers and designations in the various drawings indicate similar elements.
DETAILED DESCRIPTION
Utility meters are configured to receive a removable utility identification module, which securely stores configuration data that is required by the utility meter to provide meter data / eg!
data specifying energy use) and coordinate communications over a home area network (HAN = Home Area Network) and / or a neighboring area network (NAN = Neighborhood Area Network). As described below, the configuration data may include for example encryption keys,
I keys, network identifiers, HAN and / or NAN communications settings, initial routing settings,; security settings for devices that belong to the home area network and other data (for example user account data) that is used by the meter to provide meter data and coordinate communications over a HAN and / or
a NAN. The public service identification modules!
they are configured to provide the configuration data in response to verifying that the configuration data is provided to a device (or user) that is authorized to receive the data. For example, public service identification modules can be configured for! I.
implement test response techniques, use various encryption techniques, or otherwise require that the device requesting the configuration data verify that it is authorized to receive the configuration data. Additionally, a tamper state for each endpoint that includes a utility identification module can be determined using test / response techniques that are initiated for example by other endpoints that are located near the endpoint on a management device. network.
Figure 1 is an exemplary environment 100 where public service identification modules can be implemented. Network environment 100 includes a utility network 101 where a plurality of endpoints 102 are coupled (eg communicatively coupled) to a collector 104. Endpoints 102 can be any device that includes a transmitter, receiver, or transceiver capable of communicating over the utility network 101. For example, endpoints 102 may be utility meters (or other utility devices such as switches, transformers, or capacitor banks), computing devices, or other devices that transmit data in utility network 101. Endpoints 102 or other network components that are implemented in and / or enabled to communicate over a specified network, are referred to as belonging to the network.
The following description refers to endpoints 102 as energy meters that belong to an energy distribution network. However, the following description is applicable to other types of endpoints 102 that belong to utility networks or other networks. For example, the following description applies to
I gas and water meters that respectively are installed in gas and water distribution networks.
Endpoints 102 monitor and report various operating characteristics of service network 101, including measures of utilization of public services. For example, when endpoints 102 are implemented as energy meters in a power distribution network, endpoints 102 report utility measures used by providing data from the meter that specifies measures of total energy consumption, power consumption, and energy over a specified period of time, peak power consumption, instantaneous voltage, peak voltage, minimum voltage and other measures related to energy consumption and energy management (eg charging information). The [
Meter data may also include status data that specifies a state of the power meter (for example, operating in a normal operating mode, emergency power mode, or other state such as a recovery state after a power outage) . In gas and water distribution networks, meters can measure similar characteristics related to the use of gas and water (for example flow and total pressure).
In some implementations, symbols 106 including meter data representing utility utilization measurements (eg data representing energy consumption measures and / or status data) are transmitted continuously or intermittently over the network of utilities 101. Each symbol 106 can include data from a single endpoint or data from multiple endpoints. For example, symbol 106a can include data from endpoint 102a only, while symbol 106b can include data from endpoint 102a as well as data from endpoint 102c.
Endpoints 102 transmit symbols 106 over communication channels. Communication channels are portions of the spectrum over which data is transmitted. The center frequency and bandwidth of each communication channel may depend on the communication system in which they are implemented.
In some implementations, the communication channels for utility meters (for example, energy, gas and / or water meters) are channels of a wireless mesh network. In these implementations, each of the endpoints 102 transmits data on a specified radio frequency channel. Each of the endpoints 102 in a mesh network is also configured to receive data from other endpoints 102 and 'relay this data to a destination (eg collector 104 or network management apparatus 108) on the communication channels. For example, each of the endpoints 102a-102e communicatively couples with at least one other endpoint 102 in the utility network 101 and each endpoint 102 can transmit data to and / or receive data from other endpoints 102 to which the point ¡, end 102, is coupled.
I
Each of the endpoints 102 can transmit symbols 106 through network 101 using routing data. Routing data specifies one or more network devices that belong to the same mesh network as a particular endpoint and are in direct communication with the particular endpoint. In some implementations, endpoints 102 maintain routing data using a routing table that specifies a list of endpoints 102 and other i
network devices with which endpoint 102 can communicate. For example, endpoint 102a is communicatively coupled to endpoints 102b and 102c. In this example, endpoint 102a can hold
I a routing table that includes references (eg serial numbers or other endpoint identifiers) that are associated with endpoints 102b and 102c. When node 102a is ready to transmit symbol 106a through utility network 101, node
102a can access its routing table to select a node 102 that will receive symbol 106a. In turn, the node can encode and / or add data to the symbol specified by node 102 that is to receive symbol 106a. Endpoints 102 may encrypt symbols 106 that are transmitted through public service network 101 to prevent access by third parties.
The extreme points 102 also, can be í
Implemented in a Power Line Communication Network (PLC = Power Line Communication) that dynamically allocates available bandwidth according to a multiple access spectrum allocation technique with 'Orthogonal Frequency Division (OFDMA = Orthogonal Frequéncy Division Multiple Access) or another channel allocation technique (for example Multiple Access with Time Division, Multiple Access with Code Division and other Multiple Access techniques with Frequency Division). In these implementations, the endpoints transmit data using the same conductors (eg power lines) over which the power is transmitted. Endpoints 102 that are implemented in a PLC network can also maintain a routing table to specify network elements that should receive data transmitted by endpoints 102 and can also use encryption techniques!
to ensure that data is transmitted.
In Figure 1, end points' 102a-102e transmit symbols 106 over communication channels to collector 104. Collector 104 is a data processing apparatus that receives symbols 106 from end points 102a 102e and transmits data representing the symbols 106 to a network management apparatus 108 over a 'data network li
110. For example, the collector 104 may be a router, server, or other data processing appliance that is configured to receive symbols 106 and has already been h
retransmit symbols 106 over I data network 110 or!
create new data packages that include data from
I <sub>z</sub> i symbols 106 (eg consolidated packets including data from two or more symbols 106) and transmitting those new data packets over data network 110. While a! If only collector 104 is illustrated, utility network 101 may include many different collectors 1Ó4 that can each communicate with many thousands of endpoints 102.
The data network 110 may be a 'wide area network (WAN = Wide Area Network), ilocal area network (LAN = t
Local Area Network), Internet or any other communication network. Data network 110 can be implemented as a wired or wireless network. Wired networks can include any restricted media networks including but not limited to implemented networks; using metallic cable conductors, fiber optic materials or waveguides. Wireless networks include all free-space propagation networks including but not limited to networks implemented using radio waves and optical free-space networks.
In some implementations, the data network 110 couples the collector 104 to the network management apparatus 108. The network management apparatus 108 is a data processing apparatus that monitors and / or controls the utility network 101. The apparatus 108 management system can control different characteristics of the network
I of public services 101, based on data received from endpoints 102 that are installed in the service network 101.
For example, in a power distribution network, the network management apparatus 108 may receive data that; indicate that energy use is significantly higher in a particular portion of a power grid than in other portions of the power grid. Based on these data, the network management apparatus 108 can assign
I additional resources to that particular portion of the network (is i
say load balancing) and provide data to a user device 106 specifying that there is increased energy use in the particular portion of the power network.
The network management apparatus 108 may provide symbol data 106 to a user device 112 that can be accessed, for example, by a network operator, maintenance personnel and / or customers. For example, data identifying the increased energy use described above may be provided by a user device 112 accessible by the network operator, who in turn determines an appropriate action regarding the increased use. Additionally, data identifying a time-in-use measure and / or peak band measure may also be provided to user device 112. Similarly, if there has been a power outage, network management apparatus 112 may provide data to User devices 112 that are accessible by clients to provide information regarding the existence of the interruption and potentially provide information that estimates the duration of the interruption.
Environment 100 also includes a home area network 114. A home area network is a network in which residential and / or commercial smart devices communicate. Home area network 114 includes smart devices 116a-116d that are configured to communicate with other smart devices belonging to home area network 114. Smart devices can include computers, printers, lighting systems, heating and cooling systems, security systems as well as sensors and other devices. For example, devices 116a and 116c may be sensors (eg motion detectors, acoustic sensors, temperature sensors, or other sensors), which are installed in a home (or business) that
For example, they detect environmental conditions in the home. In turn, these sensors can transmit; data representing environmental conditions on the home area network 114. A lighting system 116b and / or cooling system 116d can receive the data, and in response to receiving the data, make adjustments (ie turn off lamps and / or set thermostat settings) for those systems. For example, if the data specifies that motion has been detected in the home, the lighting system may turn on lamps in a location where motion was detected.
To facilitate communications between the different smart devices 116 that are installed in the home area network 114, each of the smart devices 116 can transmit or receive data according to a specified communication protocol. For example, each of the devices 116a-116d in FIG. 1 can transmit data according to the ZigBee compliant protocol, such that other devices in the home area network 114 that are configured to communicate over the home network Domestic area 114 can receive the data and take action in response to receiving the data.
, An end point 102a can belong! to the network of ί
utilities 101, a neighboring area network (not shown), and home area network 114. Therefore, endpoint 102a can transmit data through utility network 101, the neighboring area network, thus like the l
home area network 114 (for example in accordance with specified ZigBee or other communication protocols). For example, as described above, endpoint 102a can measure public services that have been used at a site where endpoint 102a is installed, and transmit symbols 106 that report the measurements of public services used over the network. of public services 101. Additionally, endpoint 102a may be a coordinator for the home area network <sup>1</sup> I
114 (or the NAN) and facilitate communications over the home area network 114 (or over the NAN).
A home area network coordinator is a data processing apparatus that handles communication over the home area network. The coordinator of a network of
The home area stores home area network data associated with the home area network such as a network key, a set of device identifiers, security settings (eg encrypted or unencrypted communications required), and security keys (ie encryption keys and / or passwords) for devices that belong to the home area network, passwords and other information that is required to facilitate communications over a home area network. Because the coordinator can store configuration data associated with each of the devices (for example devices 116a - 116d) that belong to the home area network, the coordinator can operate as a trusted party that: receives a request for a key security required to communicate with the smart device; In particular, verify that the applicant is authorized to communicate with the particular smart device and provide the security key to the applicant in response to the verification. Additionally, the coordinator may limit access to passwords or other credentials that are required to communicate with access and / or otherwise interact with smart devices 116a-116d.
A network area network coordinator is a data processing apparatus that handles communications over the neighboring area network. The NAN coordinator can
<td>to stock</td><td>data</td><td>of</td><td>area network v</td><td><sup>r</sup>ecina</td><td>associates</td><td>with</td><td>NAN such</td>
<td>like a</td><td>key</td><td></td><td>network for</td><td>the</td><td>network a</td><td colspan="2">set of</td>
<td colspan="2">identifiers</td><td>of</td><td>device</td><td>than</td><td>specifies</td><td>than</td><td>points</td>
<td>extreme</td><td colspan="2">(or others</td><td>devices</td><td>of</td><td colspan="2">communications)</td><td>is it so</td>
authorized to communicate about the NAN, security settings for the NAN, network passwords and security keys for the
ΝΑΝ :.
Configuration data (for example, data specifying security keys and other security-related data such as encryption techniques and communications settings) should be stored in a secure location so that access to this data is limited Devices that have been determined are authorized to access the data. For example, points; Endpoint 102 can use encryption techniques and other security technologies (for example, certificate authentication techniques) to securely store configuration data in an endpoint data store.
It is also desirable that the configuration data be readily available to facilitate communications over the home area network 114. For example, consider that the devices 116a and 116b try to communicate with each other over the home area network 114 and / or that the point End 102a is a power meter that is required to provide a measure of energy use every 10 minutes. It further considers that endpoint 102a was recently installed (for example, to replace another endpoint 102 that was the coordinator of home area network 114), and that endpoint 102a downloads configuration data required to communicate over the home network. utilities 101 and the home area network 114 of the administration apparatus 108.
In this example, endpoint 102 may not be able to transmit symbols 106 over utility network 101 or coordinate communications over home area network until download of configuration data from network management apparatus 108 is complete. . In this way, the meter data (eg specifying energy utilization measures) will not be provided to the network management apparatus 108 and communications over the home area network 114 will not occur until the data download is complete Of configuration. Furthermore, if the home area network data (i.e. configuration data for the home area network) is not available from the network management apparatus 108, communications over the home area network 114 may be further delayed until The home area network data is provided to the endpoint 102a (for example, until the home area network is manually reconfigured).
For example, when a new utility meter is installed to replace a previously installed utility meter, the configuration of the utility meter generally requires that the configuration data be downloaded, and some level of manual configuration of the utility meter. public. Thus, when a new utility meter is installed, the utility meter may not be able
I to communicate over the public service network, the NAN or the HAN, for a relatively long period of time.
To reduce the time during which meter data and / or communications over the home area network are not available, a removable utility identification module 116 is used to store configuration data for an endpoint 102. The removable utility identification 116 is a data processing apparatus that stores data in a secure manner. For example, the UIM may be a secure physical equipment device that stores data that is used to facilitate the secure transfer of data over communication networks. The UIM can also securely store data that is used to prevent unauthorized access to a metrology device and / or a HAN / NAN device. !, E1 UIM can be installed in a secured location (for example, within an endpoint) or with security devices (for example, interlocking mechanisms) that prevent unauthorized access to the UIM. Additionally, some or all of the data stored in the UIM may be encrypted or otherwise protected against access by unauthorized devices.
Storing the configuration data in a *
public services identification module<sup>!</sup> removable
116 it allows configuration data from a particular endpoint to be transferred to a new endpoint without requiring the new endpoint to download the configuration data from a network management appliance 108, l · and without requiring reconfiguration of the new endpoint as the coordinator of the home area network 114.
For example, when the particular endpoint is removed, the removable utility identification module 116 is removed from the particular endpoint by an authorized technician 122 and placed in the! new extreme point. Once the new endpoint is activated (eg energized), the new endpoint will have access to the configuration data that is stored in the utility identification module 116. In this way, the new endpoint will be able to communicate over the public services network 101 and coordinate communications over the <sup>1</sup> I home area network 114 using the configuration data, while maintaining the security of the configuration data.
As described in more detail below, the configuration data that is stored in the utility identification module may include data from i
configuration required for the endpoint to interact with at least one of a communications apparatus, a metrology apparatus, and a network apparatus. For example, the utility identification module can store communications settings, such as PHY / MAC settings (for example, a list of frequencies over which communications are to be transmitted), routing data (for example, routing tables specifying endpoint and / or access point addresses such as collector addresses) and encryption keys required to communicate over the utility network, security keys (for example, passwords) that are required to interact with a metrology appliance that provides meter data, and / or a network key for a home area network, a set of smart devices that belong to the domestic area, and security keys and characteristics of smart devices. The utility identification module may also store account data that specifies a user account (eg account number and / or geographic location of the endpoint) with which the endpoint is associated.
<td rowspan="2">The removable</td><td rowspan="2">module 116</td><td rowspan="2">identification of can for example</td><td colspan="3">public services</td>
<td>to be</td><td>a</td><td>card</td>
<td>intelligent</td><td>ISO / IEC</td><td colspan="2">7816 which is configured</td><td>for</td><td>use</td>
<td>techniques of</td><td>encryption</td><td>(for example AES 256</td><td>or a</td><td>pair</td><td>of keys</td>
<td colspan="2">public / private)]</td><td colspan="2">to secure the data.</td><td colspan="2">He module</td>
utility identification can have · a marking form factor (eg an IDO form factor) and placed on a utility interface module interface (eg an electrical interface plug) at an endpoint 102 . Alternately, the utility identification module may be resident on a larger card 118 and is removably received by an endpoint 102a utility identification module interface 120 (eg, a meter and / or a HAN coordinator) that includes a card slot and electrical contact points that connect to the utility identification module 116. In some implementations, the interface of the 'utility identification module 120 can be secured (eg, within the endpoint) to limit access i
to the public services identification module 116 (for example, limit access to authorized technicians or other authorized individuals). :
The particular public service identification module 116 / public service identification module 120 configurations are provided for example purposes, but other configurations may be employed. For example, a contactless smart card can be used as an identification module.
utilities, and a contactless smart card interface can be used as the interface, utility identification module. Similarly, the utility identification module can be implemented in a processing apparatus that interfaces with an endpoint 102a USB port.
FIGURE 2 is a block diagram of an endpoint 102 that includes a utility identification module interface 201. Endpoint 102 includes a utility meter processing apparatus 204 that manages performed data processing tasks by endpoint 102, controls communications between components of endpoint 102, and controls communications transmitted and / or received by endpoint 102. As described in more detail below, processing apparatus 204 is also responsible for controlling access to secure data that is stored in the public service identification module. The processing apparatus is coupled to the utility identification module interface 201. The utility identification module interface 201 removably receives, interfaces with, and / or couples with a user identification module 202 that stores configuration data that is used by processing apparatus 204 to manage data processing tasks for endpoint 102, as described below.
Processing apparatus 204 is coupled to a metrology apparatus 206 which is a data processing apparatus that is configured to measure and provide meter data specifying utility measurements used. As described above, meter data may include, for example, fuel consumption measurements.
I total power, power consumption over a specified period of time, peak power consumption, instantaneous voltage, peak voltage, minimum voltage, and other measures related to power consumption and power management (for example, charging information). The meter data may also include status data that specifies a state of the power meter (for example, that it operates in a normal operating mode, emergency power mode, or other state such as a recovery state after an interruption power).
When endpoint 102 is programmed (or requested) to provide meter data, for example to a utility operator, processing apparatus 204 requests meter data from metrology apparatus 206. In some implementations, the request to The meter data may require running a metrology application (or script) which when executed causes the metrology appliance to provide the requested meter data. To prevent fraudulent activity (for example, tampering with the meter), the execution of t
The .metrology application can be restricted to authenticated users by using for example a password or other access restriction techniques (for example, test / response verification).
i!
Passwords (or other data) required to trigger execution of the metrology application (or otherwise access to the meter data) may be stored in UIM 202, such that 'I processing device 204 may be required, to request the UIM 202 password. Requests for UIM 202 data can also be restricted to authenticated devices. (Or users). Therefore, the request may include data (for example, an authenticated certificate, a valid response to a security test, or a password) that [
demonstrates that the processing apparatus is authorized to receive the requested data. In response to determining that processing apparatus 204 is i
authorized to receive the requested data, UIM 202 í
provides the requested data (for example, data from the
I meter) to the processing apparatus.
I
Once the processing apparatus 204 has received the meter data from a metrology apparatus 206> the processing apparatus 204 provides the data from the meter to a communications apparatus 208 that is coupled to the processing apparatus 204. The Communications 208 is a data processing apparatus that is configured to transmit and receive data over a network (eg, a utility network). For example, communications apparatus 208 may receive meter data that is
provided by the processing apparatus ¡204, generating symbols including the meter data, and transmitting the symbols over a public service network to which the endpoint 102 belongs. The communication apparatus 208 can encrypt the meter data being include in
I symbols to prevent access to data by third parties. For example, communications apparatus 208 may encrypt meter data using AES, a public / private key pair, or another encryption technique using keys that are stored in UIM 202.
Encryption of meter data can be done by the processing apparatus, or using keys provided by the processing apparatus. For example, communications apparatus 208 may request that the processing apparatus encrypt meter data for transmission. Alternatively, the communications apparatus may request that the processing apparatus obtain keys necessary to encrypt the UlM 202 data, and the communications apparatus 208 be able to perform; encryption using the keys that are provided by the processing apparatus.
In some implementations, data transmission by communication apparatus 208 is performed in response to execution of a metrology application (or script) which when executed causes communication apparatus 208 to encrypt and / or transmit data about the public service network. To prevent fraudulent activity (for example, tampering with meter data or fraudulent access to the utility network), running the communications application (or other control of, or access to the communications appliance 208), may be restricted to device (or users) authenticated by using, for example, a password or other access restriction techniques (eg, test / response verification), similar to those above. <sup>!</sup>
For example, to control the <sup>!</sup> communications apparatus 208, processing apparatus 204 may be required to provide a password or otherwise verified that processing apparatus 204 is authorized to control communications apparatus 208 ,. In some implementations, the processing apparatus<sup>;</sup> 204 may also be required to specify transmission characteristics for the data being transmitted. For example, communications apparatus 208 may require that the apparatus be encrypted and / or described.
Processing 204 specify the encryption technique with which the data is to be encrypted as well as the routing information (ie an identifier for at least one network component that is to receive the transmitted data).
As described above, passwords or other data required to enable processing apparatus 204 to verify that it is authorized to control communications apparatus 208 can be stored in UIM 202. The (JIM 202 can also store encryption data that they specify an encryption key that is used to transmit data to a network management apparatus that manages the utility network to which endpoint 102 belongs. Additionally, JIM 202 can store routing data that specifies one or more network devices that belong to the same mesh network as endpoint 102 and are in direct communication with endpoint 102. Processing apparatus 204 can obtain the data required to cause the communications apparatus 208 to transmit the UIM meter data 202 in a manner similar to that described above.
Processing apparatus 204 is also coupled to network apparatus 210. Network apparatus 210 is a data processing apparatus that is configured to coordinate communication between devices that belong to the same home area network (eg, same network ZigBee) and / or the same neighboring area network as the network device 210. For example, network apparatus 210 may interact with devices (eg, smart devices 116a 116d in FIG. 1) to determine whether the devices are members of the same home area network as network apparatus 210, either a pair of Specific devices are authorized to communicate over the home area network and / or provide data required for devices to communicate with each other over the home area network. The
Network apparatus 210 can also interact with devices belonging to the same neighboring area network as network apparatus 210 and / or determine whether a particular device is authorized to transmit data on the network area network.
In some implementations, the home area network data (i.e. data that is required to facilitate communications over the home area network) and / or neighboring area network data (i.e. data that is required).
to communicate over a neighboring area network) are stored in UIM 202. For example, UIM 202 can store data that specifies a network key for the home area network (or NAN), a set of devices that belong to the home area network (or NAN), routing tables that are associated
I with the home area network (or NAN), pairs of 'devices i · that are authorized to communicate with each other, and / or security features of the devices that belong to the home area network (or NAN). Other data associated with the home area network (or NAN) can also be stored in the UIM, 202.
i
The network apparatus 210 can obtain the home area network data and / or the neighboring area network data from the UIM 202 (eg, through the processing apparatus 204) to coordinate communications between devices on the home network. domestic area and over the neighboring area network in a manner similar to that described above. For example, in response to a request from a device
I to communicate with another device, the network device 210 i
You can request that the processing apparatus 204 obtain and provide the data necessary to confirm that the two devices are authorized to communicate, as well as the data necessary to facilitate communications between the two devices (eg security keys associated with the devices). ¡
As previously described, UIM 202 stores configuration data that is respectively used to access and / or control operation of metrology appliance 206, communications appliance 208, and network appliance 210. In some implementations, the
UIM 202 can store the configuration data for each
1 'one of these respective devices in separate memory partition portions, wherein access to each memory partition is restricted using different passwords and / or different restriction techniques. For example, access to a password associated with metrology apparatus 206 may be granted by UIM 202, in response to receiving a particular response to a security test, while access to a list of devices that belong to the home area network. it may be granted in response to another response to a different security test. Partitioning the data keys in this way further secures the configuration data associated with each respective component of endpoint 102. For example, the partition limits access to configuration data to devices (or users) that have provided data required to have access to the particular partition where the configuration data for a particular endpoint component 102 is stored.
In some situations, the amount of time required to obtain the configuration data from UIM 202, may exceed a response time within which processing apparatus 204 is required to obtain and / or supply data to one of metrology apparatus 206, communications apparatus 208, and / or network apparatus 210. To reduce the time required to obtain the configuration data, the processing apparatus may include a data storage (for example Access Memory
Random) where particular configuration data can be temporarily stored. Saving configuration data in a data storage of the processing apparatus 204 may decrease the time required for the processing apparatus 204 to obtain the data because the memory access times of the data storage may be much less than the required time. to obtain the UIM 202 data. Because the configuration data is sensitive information, processing apparatus 204 may be required to periodically interact with ÜIM 202, another endpoint, and / or a network management apparatus) to verify that endpoint 102 is not in a state of tampering, as described in more detail below.
UIM 202 can be configured to perform all necessary calculations and processing to ensure that
Configuration data is stored in UIM 202. For example, UIM 202 may include a random number generator that is used to facilitate test / response authentication techniques. UIM 202 may also include a processor that is configured to encrypt the configuration data that is provided to the staging apparatus 204. For example, UIM 202 may include a
esador that is configured to implement a public / private key encryption technique, symmetric key encryption techniques and / or asymmetric key encryption techniques. Furthermore, each UIM 202 can be configured to operate with a particular endpoint 102 through a pairing process and the pairing of UIM 202 and endpoint 102 may require authentication. For example, on power-up (or periodically), processing apparatus 204 may receive a request from UIM 202 and / or a network management apparatus that provides data that verifies proper pairing of UIM 202 with endpoint 102. The data provided may for example be a hash result of an endpoint serial number, a response to an authentication test, or other authentication data.
In some implementations, more than one UIM 202 can be associated with a particular user account. For example, one UIM 202 may be designated to be installed in a fixed location (for example in the direction in which a particular energy meter is installed ), while the other UIM may be authorized to be used in a designated set of other endpoints that are on other sites (that is, on sites other than a site associated with the user's account). Both of these UIMs can include data that is associated with the same utility account (for example, electricity company account) and can be configured to measure energy usage.
Therefore, each of the UIMs can be installed at separate endpoints to obtain usage measurements from
Ί energy at the endpoints, associate the energy usage measurements at each of the endpoints with the same utility bill and provide the energy usage measurements, for example to a network management appliance, in such a way that the account with which UIMs are associated!
can be charged for use at two different sites. For example, a UIM may be required to be installed at an endpoint that is in the direction that is associated with the
I user account, while the second UIM may be authorized to be used in electric vehicles to track energy consumption when the electric vehicle is connected to charging stations or other charging locations that are not located in the address associated with the user's account.
A UIM 202 can be configured to store all the data described above and be used as a universal UIM that can be used at any extreme point. Alternately, only portions of the data described t
previously they can be stored in a UIM 202 that can be used at a specific set of endpoints. For example, a particular UIM can be configured to operate i
exclusively on a NAN device (for example a utility device that operates on NAN), so this particular UIM can only include meter data and data needed to communicate over NAN, but does not include customer account information . In another example, another UIM can be configured to operate exclusively on a HAN device (for example devices within a home or a meter in the home), such that this other i
UIM may only include data that specifies customer account information and data necessary to communicate about
HAN.
FIG. 3 is a flow chart of an exemplary process 300 for configuring a utility meter. Process 300 is a process by which a public utility meter processing apparatus determines ί
configuration data is required to interact with specified appliance, and detects a removable utility identification module that is in: communication
I with the utility meter processing apparatus. The utility meter processing apparatus receives the required configuration data from the service identification module!
public. In turn, the utility meter processing apparatus interacts with the specified apparatus.
Process 300 can be performed for example by endpoints 102 of Figure 1. The process can also be implemented as instructions stored on computer storage medium, such that the execution of instructions by the data processing apparatus causes the data processing apparatus perform process operations 300.
A determination is made that the configuration data is required to interact with at least one of a metrology apparatus, communications apparatus, and a network apparatus (302). In some implementations, the determination may be made by a utility meter processing apparatus of a utility meter. The determination can be made, for example, by determining that the current configuration data does not correspond to the configuration data that is required to interact with the metrology apparatus and / or the network apparatus. For example, a determination can be made that a password or other data that is required to access or control or otherwise interact with the network apparatus and / or the metrology apparatus is not included in the current configuration data.
A removable module for public service identification is detected (304). In some implementations, the removable utility identification module is a data processing apparatus, such as a smart card, that is in communication with the utility processing apparatus. For example, the removable utility identification module may be a smart card that is electrically connected to an interface of the utility identification module of the utility meter. The utility identification module stores configuration data required by the utility meter processing apparatus that interacts with at least one of the metrology apparatus and a network apparatus. The utility identification module can also store configuration data required by the utility meter processing apparatus to interact with a communications module that controls the transmission of data through a utility network to which the utility meter.
In some implementations, the removable utility identification module is detected during a startup sequence of a utility meter. For example, when the utility meter is energized in the utility meter processing apparatus, it can be determined whether a utility identification module is electrically connected to the utility meter (for example installed in a utility module interface). identification of public services). In other implementations the utility identification module is detected by inserting the utility identification module into a facility identification module interface. For example, while a utility meter is turned on, a utility identification module can be inserted into a utility identification module interface and insertion of the utility identification module can be detected.
Configuration data is received from the removable utility identification module (306). In some implementations, configuration data is received in response to a request by the utility meter processing apparatus. For example, in response to determining that configuration data is required and with respect to detecting a removable public service identification module, the processing apparatus may provide a request for the configuration data to the public service identification module.
In some implementations, the request for configuration data includes data specifying that the processing apparatus is authorized to receive the configuration data. For example, the request may include a password, an authorized certificate, or data that is<sup>:</sup> They have been encrypted according to a private key that is shared between the processing apparatus and the public services identification module.
; i<sup>1</sup> In other implementations, in response to the request, the utility identification module can respond to the request with a security test and
request that the processing apparatus provide one! I valid response in order to receive the Configuration 'I data.
requested. For example, the utility identification module may generate a random number,!
provide that number to the processing apparatus and
II, I request that the processing of computers and devices
I provide a hash (or result of another function)! . . Deli random number. If the hash of the random number that is provided by the processing apparatus corresponds to an expected hash of the random number that has been calculated by the utility identification module ,; then the i
Public services identification module will provide the requested configuration data to the processing apparatus. However, if the hash of the random number that is provided by the processing appliance does not correspond to the expected hash, the utility identification module will refuse to provide the data from | Requested icon settings and the utility identification module can increment a security counter representing a number of potential security breaches and / or potential attacks that have been detected.
In some implementations, configuration data for different devices may be stored in different memory partitions. In these implementations, access to the configuration data for each particular device may be limited to devices (or users) that have demonstrated that they are authorized to access the configuration data for the particular device (for example by providing a unique password or other unique data required to access the configuration data for the particular device).
As described above, configuration data may include passwords, security keys, and other data that is required to interact with a network apparatus, a metrology apparatus, and / or a communications apparatus. The configuration data that is received may also include encryption data that specifies an encryption key that is used to transmit meter data to a network management appliance that manages the utility network to which the utility meter belongs. . The configuration data that is received may also include routing data that specify one or more network devices that belong to the same mesh network as the utility meter and that are in direct communication with the utility meter. data specifying the geographic location of the utility meter it transmits, data as well as destination data specifying a network identifier (eg, an Internet protocol address) associated with a network device to which the data is transmitted (eg, network management apparatus). ¡
Using the encryption key and routing data, the processing appliance can provoke)
transmitting meter data that is encrypted with the Encryption key to a network device that is chosen! from the routing data. For example, the processing apparatus and / or
And a communications device can encrypt! the data using the encryption key and select from the routing data an endpoint, router, repeater or other network device to which the meter data is to be transmitted. The selection can be made for example based on a distance from the selected network device, from the utility meter that transmits the data as well as a quality of the transmission path between the utility meter and the network device (for example based on the ratio of signal to interference, distance and other factors).
You interact with at least one of the! metrology apparatus and network apparatus (308). Once the processing apparatus has received the configuration data, the processing apparatus can use the configuration data to interact with the network apparatus and / or the metrology apparatus. For example, the processing apparatus may provide home area network data to the network apparatus, thereby facilitating communication between devices on the home area network.
The home area network data can use for example i
a set of device identifiers for the devices that want to be a home area network, a set of data keys that are used to communicate over the home area network, and / or security settings for devices that belong to the area network domestic.
Additionally, the processing apparatus may use the configuration data to receive meter data from the metrology apparatus. For example, the processing apparatus may provide a password (or other data specifying that the processing apparatus is authorized to receive the meter data) that are received in the configuration data to the metrology apparatus, and receive the meter data in reply. Furthermore, the processing apparatus may use the configuration data to cause the meter data to be transmitted over
I a network of public services. For example, the processing apparatus may interact with a communications apparatus that couples to the processing apparatus to encrypt meter data and transmit the meter data to a network management apparatus.
FIG. 4 is a flow chart of an exemplary process 400 for determining a tamper state of a utility meter. Process 400 is a process by which a first meter provides proof of authentication to a second meter. The second meter receives the authentication test and provides the first meter with a response to the authentication test. The first meter determines whether the response is valid and optionally whether the response is received within a threshold time. If the response is invalid or the response is not received within the threshold time, the first meter provides tamper data to the network management apparatus. If the response is valid and optionally received within the threshold time, the first meter provides another authentication test at a later time.
Process 400 may for example be performed by endpoints 102 of Figure 1. The process may also be implemented as instructions stored on the computer storage medium such that the execution of instructions by the data processing apparatus causes the data processing apparatus performs the operations of process 400.
A first meter provides proof of authentication to a second meter (402). In some imjOlementations, the first meter provides a random number to the second meter and requests that the second meter provide a hash result (or result from another function) that authenticates the second meter. Other test / response techniques can also be used (eg passwords).
The second meter receives the authentication test (404) and provides a response to the test
I of <sup>:</sup> authentication (406). In some implementations, the response may be generated using an i application
response residing in a removable utility identification module that is associated with the second meter. For example, the answer application may generate a hash result of the random number and provide that result for transmission back to the first meter.
The first meter receives the response and determines if the response is valid (408). A valid response is a response that authenticates the second service meter!
public as in a state without tampering. For example, a valid response may be a response that corresponds to the expected response and / or is received within a specified threshold time of an expected time, as<sup>1</sup> t described below. In some implementations, determining whether the response is a valid response can be made by comparing the response with an expected response that has been calculated by the first meter. For example, the first meter can generate an expected hash result using the random number that is supplied to the second meter. When the hash result is received from the second meter, it is compared to the expected hash result that was calculated by the first meter. If the hash result and
the expected result correspond, the answer is a valid answer. Otherwise, the answer is not a valid answer.
If the first meter determines that the! answer no
I i
is a valid response, tamper data is provided to the network management apparatus 410. Tamper data is data that specifies that a particular meter has failed a test!
authentication. The tamper data may include, for example, identifiers that respectively identify the meter that provides the authentication test and the meter that provides the response, and data that specify a reason for providing the tamper data. For example, the tamper data may specify that a response hash result does not correspond to an expected hash result and / or that the response was received out of time!
threshold, as described below.
, If the first meter determines that the answer is ¡
a valid response, the first meter may provide another authentication test (402), for example | at a later time or on demand (ie in response to instructions to initiate a test). In some implementations, the first meter can determine if the valid response was received within a threshold response time (412). Threshold response time is an amount of time around an expected response time during which a valid response authenticates the second
I meter that is in a state without tampering. For example, the threshold response time can be set to 10% of 'an average amount of time (or other statistical measure) between test transmission and receipt of the test.
<td>answer.</td><td>In this example,</td><td>a</td><td>valid reply received to</td>
<td>a time</td><td>what is inside</td><td>of</td><td>+/- 10% of the average time</td>
<td>authentic</td><td>to the meter like</td><td>in</td><td>a state without manipulation</td>
<td>improper.</td><td>However, if</td><td>a</td><td>valid response is received</td>
<td colspan="2">outside +/- 10% of the time</td><td colspan="2">average, the valid answer is not</td>
<td>authentic</td><td>to the meter like</td><td>in</td><td>a state without manipulation</td>
improper.
When a valid response is received within a threshold response time, the first meter may provide another authentication test (402), for example
I at a later time or on demand. When ! If the valid response is received outside the threshold response time, tamper data may be provided to the network management apparatus as described above.
In some implementations, process 400 or similar processes can be used to verify the; 'I integrity of the software or firmware that is installed at an endpoint. For example, in response to A test (or periodically), a UIM that is installed at an endpoint may generate a firmware / firmware signature (for example! A hash result using data associated with firmware and a random number provided) and compare the signature with a current valid signature. If the signature does not correspond to the current valid signature, tamper data may be provided to a 'network management appliance or a' tamper 'counter (i.e. a counter representing a number of potential security attacks on the extreme point).
Modalities of the subject matter and the operations described in this specification can be implemented in
I digital or software electronic circuits, support
Unchangeable logic or computer hardware including the structures described in this specification and their structural equivalents, or in combinations of one or more of them. Modalities of the subject matter described in this specification may be implemented as one or more computer programs, that is, one or more computer program instruction modules encoded in computer storage medium for execution by, or to control the operation of, data processing apparatus. Alternately or in addition, the program instructions may be encoded into an artificially generated propagated signal, for example a machine generated electrical, optical or electromagnetic signal, which is generated to encode information for transmission to receiving apparatus suitable for execution by an apparatus. data processing. A computer storage medium may be or be included in a computer readable storage device, a computer readable storage substrate, a serial or random access memory array or device, or a combination of one or more thereof. . Furthermore, while a computer storage medium is not a propagated signal, a computer storage medium can be a source or destination for computer program instructions encoded in an artificially generated propagated signal. The computer storage medium may also be or be included in one or more separate physical media or components (eg multiple CDs, discs or other storage devices).
The operations described in this specification may be implemented as operations performed by a data processing apparatus on data stored on one or more computer readable storage devices or received from other sources.
The term data processing apparatus encompasses all types of apparatus, devices and machines for processing data, including by way of example a programmable processor, a computer, a system on a chip, or multiple or combinations of the foregoing. The apparatus may include special purpose i logic circuits, for example a Field Programmable Gate Array (FPGA) or an Application Specific Integrated Circuit (ASIC = Application Specific Integrated Circuit). The apparatus may also include, in addition to physical equipment, code that creates an execution environment for the computer program in question, for example code that constitutes unalterable processor software, a protocol stack, a database management system, an operating system, a
I Runtime environment across platforms, a virtual machine, or a combination of one or more of them.
The apparatus and performance environment can achieve various
Different computing model infrastructures such as network services, network computing infrastructures and i
l · distributed computing.
Ί
I, A computer program (also known as a! Program, software, software application, script, or code) can be written in any form of programming language ^, including i
compiled or interpreted languages, languages! declarative i
I or procedural and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, object, or other unit suitable for use in a computing environment. A computer program,
I
It can, but does not require, correspond to a file in a! ί file system. A program can be stored in a portion of a file that holds other programs or data (for example, one or more scripts stored in ¡
a markup language document), in a [single file dedicated to the program in question, or in multiple files ί l · r
coordinated (for example, files that store one or more <sup>1</sup> | modules, sub-programs or portions of code). A program
Computer I can be deployed to run a
I;
computer or multiple computers that are [located at one site or distributed across multiple sites and <sup>1</sup><sub>( </sub>interconnected by a communications network. ¡
The logical processes and flows described in this specification can be performed by one or more programmable processors that run one or more computer programs to perform actions by operating on feed data and generating output. Logic processes and flows can also be performed by, and appliances can also be implemented as, special purpose logic circuits, for example an array of programmable gates in situ (FPGA) or an application specific integrated circuit (ASIC).
Suitable processors for executing a computer program include, by way of example, as many general-purpose and special-purpose microprocessors, and any one or more processors of any type of digital computer. In general, a processor will receive instructions and data from read-only memory or random access memory, or both. The essentials of a computer are a processor for performing actions according to instructions and one or more memory devices for storing instructions and data. In general, a computer will also include or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices to store data, eg, magnetic, magneto-optical, or optical discs. However, a computer does not require having these devices.
Suitable devices for storing instructions
Computer program and data I include all forms of nonvolatile memory, media and memory devices,
including by way of example semiconductor memory devices, for example EPROM, EEPROM, and r
i flash memory;
magnetic discs, for example internal hard drives or removable drives; magneto-optical discs; and CD-ROM and DVD-ROM discs. The processor and memory can be supplemented by, or incorporated into, special-purpose logic circuits.
While this specification contains many specific implementation details, these are not to be consolidated as limitations on the scope of any inventions or what may be claimed, but rather as descriptions of specific to particular particular modalities. Certain features that are described in this specification in the context of separate modalities can also be implemented in combination in a single modality. Rather, various features that are described in the context of a single modality can also be implemented in multiple modalities separately or in any convenient subcombination.
characteristics of ; inventions
Furthermore, although features described above that act in certain combinations and even initially claimed as such, one or more features of a claimed combination may in some cases be detached or cut from the combination, and the claimed combination may be directed to an undercombination or variation of a subcombination.
Similarly, while operations in the drawings are illustrated in a particular order, this will not be understood to require that such operations be performed in the particular order shown or in sequential order, or that all operations illustrated be performed, to achieve the desirable results. In certain circumstances, it may be
I advantageous multitasking and parallel processing. Furthermore, the separation of various components of the system in the previously described modalities should not be understood as requiring such separation in all modalities, and it should be understood that the described components and program systems can generally be integrated together into a single product. software
I or packed in multiple software products.
In this way, particular modalities of the subject matter have been described. Other embodiments are within the scope of the following claims. In some cases, the actions described in the claims can be performed in a different order and still achieve desirable results. Furthermore, the processes illustrated in the accompanying figures do not necessarily require the order
particular displayed or sequential order, to achieve desirable results. In certain implementations, parallel and multitask processing may be advantageous.
Contents12
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
17 members in 8 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 89191510 | United States of America | A | |
| 2011050845 | United States of America | W |
Members17
| Document | Office | Kind | |
|---|---|---|---|
| US2012078548A1 | United States of America | A1 | |
| CA2812906A1 | Canada | A1 | |
| WO2012047441A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2012047441A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2011312680A1 | Australia | A1 | |
| MX2013003158AThis record | Mexico | A | |
| MX2013003158AThis record | Mexico | A | |
| EP2622357A1 | European Patent Office (EPO) | A1 | |
| US8670946B2 | United States of America | B2 | |
| NZ609153A | New Zealand | A | |
| AU2011312680B2 | Australia | B2 | |
| BR112013007261A2 | Brazil | A2 | |
| EP2622357A4 | European Patent Office (EPO) | A4 | |
| EP2622357B1 | European Patent Office (EPO) | B1 | |
| CA2812906C | Canada | C | |
| BR112013007261B1 | Brazil | B1 | |
| BR112013007261B8 | Brazil | B8 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 2013003158
- Application
- 2013003158
Titles2
- English
- UTILITY DEVICE MANAGEMENT.
- Spanish
- ADMINISTRACION DE DISPOSITIVO DE SERVICIOS PUBLICOS.
Classification
- CPC, 16
- G01D4/02
- H04L12/2825
- Y04S20/221
- Y04S20/242
- Y02B70/30
- Y04S40/124
- Y04S20/222
- Y02B70/3225
- H02J13/14
- H02J13/1323
- H02J13/1335
- H02J13/1337
- H02J2105/42
- Y02B90/20
- Y04S20/20
- Y04S20/30
- IPC, 1
- G01R21 00