{"title":"Protection of consumer data in the smart grid compliant with the German smart metering guideline","authors":"A. Biselli, Elke Franz, M. P. Coutinho","doi":"10.1145/2516930.2516933","DOIUrl":null,"url":null,"abstract":"Smart metering systems obtain fine-grained consumption data of their users. This allows for effective load balancing, but at the same time threatens consumers' privacy. Since the electricity provider only needs the characteristics of a region, not individuals, approaches like one by Mármol et al. suggest to aggregate data to protect consumer privacy. However, an implementation of such an approach also has to consider the legal and regulatory situation. In Germany, the technical guideline TR-03109 issued by the Federal Office for Information Security specifies demands which have to be fulfilled so that a smart meter gateway can be certified for use. These specifications imply limitations to the protocol design. Within this paper, we discuss the applicability of the method presented by Mármol et al. under consideration of the German Smart Metering guideline. Where conformity is not given, we offer a solution to overcome these restrictions by adapting their method and introduce a third party aggregator who does not have to be trusted. Our method comes with additional communication effort but behaves well in terms of memory and computational overhead. The achieved privacy level outreaches a purely pseudonymous value transmission. Also it does not contradict the postulations of TR-03109, making it an applicable choice for privacy protection in real-world smart metering systems.","PeriodicalId":303004,"journal":{"name":"ACM workshop on Smart Energy Grid Security","volume":"29 19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-11-08","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ACM workshop on Smart Energy Grid Security","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2516930.2516933","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8
Abstract
Smart metering systems obtain fine-grained consumption data of their users. This allows for effective load balancing, but at the same time threatens consumers' privacy. Since the electricity provider only needs the characteristics of a region, not individuals, approaches like one by Mármol et al. suggest to aggregate data to protect consumer privacy. However, an implementation of such an approach also has to consider the legal and regulatory situation. In Germany, the technical guideline TR-03109 issued by the Federal Office for Information Security specifies demands which have to be fulfilled so that a smart meter gateway can be certified for use. These specifications imply limitations to the protocol design. Within this paper, we discuss the applicability of the method presented by Mármol et al. under consideration of the German Smart Metering guideline. Where conformity is not given, we offer a solution to overcome these restrictions by adapting their method and introduce a third party aggregator who does not have to be trusted. Our method comes with additional communication effort but behaves well in terms of memory and computational overhead. The achieved privacy level outreaches a purely pseudonymous value transmission. Also it does not contradict the postulations of TR-03109, making it an applicable choice for privacy protection in real-world smart metering systems.
智能计量系统获取用户的细粒度消费数据。这允许有效的负载平衡,但同时威胁到消费者的隐私。由于电力供应商只需要一个地区的特征,而不需要个人的特征,因此Mármol等人的方法建议汇总数据以保护消费者隐私。但是,这种方法的实施还必须考虑到法律和监管情况。在德国,联邦信息安全办公室(Federal Office for Information Security)发布的技术指南TR-03109规定了智能电表网关获得使用认证必须满足的要求。这些规范暗示了协议设计的局限性。在本文中,我们讨论了Mármol等人在考虑德国智能计量指南的情况下提出的方法的适用性。在没有给出一致性的情况下,我们提供了一个解决方案,通过调整他们的方法来克服这些限制,并引入一个不必被信任的第三方聚合器。我们的方法需要额外的通信工作,但在内存和计算开销方面表现良好。实现的隐私级别超出了纯粹的假名价值传输。此外,它与TR-03109的规定并不矛盾,使其成为现实世界智能计量系统中隐私保护的适用选择。