SlideShare a Scribd company logo
1 of 20
Download to read offline
The Brazilian experience
Smart meter security assessment
in smart grid projects
March 2017
José Reynaldo Formigoni Filho, MSc
Information and Communication Security Technology Manager
CPqD Foundation
AGENDA
Smart grid and smart meters’ deployment in Brazil
Smart meter’s threats and frauds in Brazil
Smart meter security assessment R&D project
Security test procedures and results
Concluding remarks
THE GRID DEPLOYMENT: CURRENT
BRAZILIAN SITUATION
• R&D Phase
• Pilot Projects
• Government funds
First wave of
smart grid
• Smart metering
commercial deployments
• Automation and
operations integration
Second wave of
smart grid
•Distributed generation and
storage
•EV
•IT-OT integration
• Big data analytics
Third wave of
smart grid
Developed
countries
Brazil
FOREIGN POWER COMPANIES IN BRAZIL
THE SMART GRID DEPLOYMENT: CURRENT
BRAZILIAN SITUATION
• 13 pilots R&D projects
• US$ 100 mi from Aneel Funds
• Total of smart meters: almost 200.000
Digital City
10.000
Cidade Inteligente
10.000 EDP Bandeirante
Cidade Inteligente
10.000 Elektro
Eletropaulo Digital
84.000
Cidade do Futuro
4.200
Smart Grid
27.000
Cidade Inteligente - Búzios
10.000 - Ampla
Redes Inteligentes Celpe
850
Energia Mais
Celge
Smart Grid
EV and
DG
Cidade Inteligente
Aquirás - Coelce
20.000
Parintins Smart Grid
3000
COMMERCIAL SMART METER DEPLOYMENT
• Industrial and commercial
medium and large customers
(Group A): almost 100% are
using electronic meters (the
minority of these are smart
meters)
• Residencial and commercial
small customers (Group B): the
deployment has just started
Rio de Janeiro: 1 million
smart meters for Group B in 5
years
2 million smart meters for
Group B
THE MAIN THREATS
• Energy usage frauds:
Fraud energy consumption,
is a major threat and
concern of the utilities,
because it directly affects
their income
• Propagation of malicious
code to other meters
through the AMI: one of the
most dangerous threats with
high possibility to spread
malwares, which may cause
irreparable loss to the power
company.
• Malicious interruption of
electricity: terrorist acts, promotion
of chaos
• User privacy violation: data from
smart meters can show client
behavior
The most important
threat in Brazil
NON TECHNICAL LOSSES
The cyberattacks are within 5,74%
and are targeted at industrial and
commercial customers
Non technical losses (MV and LV)
Technical losses (MV and LV)
Total losses (MV and LV)
Total losses for each group in 2016
HOW BRAZIL IS DEALING WITH
THE CYBERSECURITY PROBLEM?
• Brazil does not have a minimum cybersecurity framework for the power sector
• Aneel has not dealt with this subject as a critical infrastructure problem to the country
• How are the companies facing this problem?
Group 1
Foreign Controller
• Bring the methodologies
from abroad and do the
adaptations for the
Brazilian reality
Group 2
Brazilian Controller
With know How
• They are trying to
develop their own
framework based on
experiences from USA
and EC
Group 3
Brazilian Controller
Without know How
• They are hiring R&D
Centers and Universities
to help them develop
their own framework
SECURITY ASSESSMENT METHODOLOGY FOR SMART METER
• Name: R&D in security assessment for smart meters
• Client:
• Sponsor: Aneel R&D Fund
• 30-month project totally executed by CPqD Foundation
• Number of customers: 2.4 mi
• 8th biggest power company in Brazil
• Number of cities: 228
SECURITY ASSESSMENT METHODOLOGY FOR SMART METER
Goal 1
Methodology for security
assessment
Goal 2
Smart Meter Cyber Security
Laboratory Deployment
Goal 3
Security analysis and
tests of smart meter
State of the art survey for
smart meter security
Specification of the test
environment
Development of the
security assessment
methodology for smart
meter
Security tests
Implementation of Smart Meter
Security Training Platform
Laboratory deployment
Laboratory operation
Knowledge and
technology transfer
Security Assessment for Smart Meters
Functional tests
• Name: Smart meter security assessment laboratory
• Number of labs: 2 (CPqD and Elektro)
• Short term subjects:
• Perform all tests specified by the methodology (security and fuctional tests)
• Offer the security assessment evaluation for other power companies and smart meters
suppliers.
• Medium term subject:
• To become the first national laboratory for RTM 586 (the Brazilian Standard for fuctional
requirements) certified by Inmetro*, our national metrology institute
• To become the first national laboratory for security assessment certified by Inmetro*
LABORATORY DEPLOYMENT
*INMETRO – Instituto Nacional de Metrologia
TEST RESULTS: GENERAL OVERVIEW
• Number of manufacters: 6
• Number of smart meter models tested: 8
• Main assumptions:
• Hadware and software tests were performed
• Intrusion tests performed: "black box” approach
• The tests were performed at CPqD. A subset of these tests
were performed at the Elektro’s lab.
TEST PROCEDURES
• Initial hardware evaluation of the smart meter
• Copy of the non-volatile memory
• Data capture at the bus
• Entropy analysis of information collected from the electronic
components
• Searching for cryptographic keys on information collected
from the electronic components
• Firmware analysis
• Exploiting vulnerabilities in the firmware
HARDWARE TEST RESULTS
• It is the first set of security tests to be done
• Normally, the manufacturers do not provide any information related to
the hardware architecture of smart meters
• Tester’s skills:
• Electrical circuits
• Communication protocols (I2C, SPI, serial)
• Embedded systems
• Microcontroller architecture
• Reading datasheets and layouts of printed circuit boards (PCB)
TEST RESULTS
• Functional tests (RTM 586)
• 14 smart meters tested
• In 13 of them was possible to access the metering
parameter via optical interface
• Security tests
• A 100% presented software and hardware vulnerabilities
CONCLUDING REMARKS
• The Brazilian power companies have begun to pay more attention to the
cybersecurity problem
• Currently, Aneel does not have a clear position on this subject
• Companies already face problems with fraud in electronic meters for
commercial and industrial customers
• The problem will be much greater with the deployment of smart meters for
residential consumers
CONCLUDING REMARKS
• Discussions on standardization and certification of security requirements
for smart meters are in early stages
• Aneel's major concern regarding the insertion of minimum security
requirements in smart meters is cost increase because our tariff is based on
cost
• However, considering the amount of vulnerability found in our tests, some
actions should be taken by the government bodies to mitigate the problem.
CONCLUDING REMARKS – PAPERS AND BOOK
The Book
• Published by Elektro at the end of
2016
• Only in Portuguese!
International papers:
• Smart Meters Security Assessment in the Brazilian
Scenario. The Third International Conference on Smart
Grids, Green Communications and IT Energy-aware
Technologies - Lisbon, Portugal. March 24, 2013
• A Fast Attack against a Smart Meter Authentication
Protocol. Proc. of the 3rd International Conference on
Informatics, Environment, Energy and Applications. IEEA
2014. China, 27-28 March, 2014.
• MeterGoat: A Low Cost Hardware Platform for Teaching
Smart Meter Security. ICCGI 2014 - The Ninth International
Multi-Conference on Computing in the Global Information
Technology - Sevilha – Espanha. June 22, 2014
• Implementation Aspects of MeterGoat, a Smart Meter
Security Training Platform. SINCONF 2014 - The 7th
Internation Conference on Security of Information and
Networks - Glasgow - Reino Unido. September 1, 2014
reynaldo@cpqd.com.br
TRANSFORMANDO
EM REALIDADE
w w w . c p q d . c o m . b r
José Reynaldo Formigoni Filho
Information and Communication Security Technology Manager
CPqD Foundation
Tel.: +55 19 3705-7121 / Fax: +55 19 3705-6833
Cel.: +55 19 99838-2321
reynaldo@cpqd.com.br
www.cpqd.com.br
THANK YOU!

More Related Content

What's hot

International conference on networks, blockchain and internet of things (nb i...
International conference on networks, blockchain and internet of things (nb i...International conference on networks, blockchain and internet of things (nb i...
International conference on networks, blockchain and internet of things (nb i...ijwmn
 
International Conference on Networks, Blockchain and Internet of Things (NBIo...
International Conference on Networks, Blockchain and Internet of Things (NBIo...International Conference on Networks, Blockchain and Internet of Things (NBIo...
International Conference on Networks, Blockchain and Internet of Things (NBIo...ijasuc
 
12th International Conference on Ubiquitous Computing (UBIC 2021)
12th International Conference on Ubiquitous Computing (UBIC 2021) 12th International Conference on Ubiquitous Computing (UBIC 2021)
12th International Conference on Ubiquitous Computing (UBIC 2021) ijasuc
 
4 th International Conference on Networks and Communications (NET 2020)
4 th International Conference on Networks and Communications (NET 2020) 4 th International Conference on Networks and Communications (NET 2020)
4 th International Conference on Networks and Communications (NET 2020) ijp2p
 
Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...IJNSA Journal
 
6th International Conference on Networks & Communications (NWCOM 2020)
6th International Conference on Networks & Communications (NWCOM 2020)6th International Conference on Networks & Communications (NWCOM 2020)
6th International Conference on Networks & Communications (NWCOM 2020)dannyijwest
 
Call for papers - 4th International Conference on Networks and Communications...
Call for papers - 4th International Conference on Networks and Communications...Call for papers - 4th International Conference on Networks and Communications...
Call for papers - 4th International Conference on Networks and Communications...ijassn
 
Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...IJNSA Journal
 
certificato profisafe
certificato profisafecertificato profisafe
certificato profisafeAndrea Pinna
 
jtsec Arqus Alliance presentation
jtsec Arqus Alliance presentationjtsec Arqus Alliance presentation
jtsec Arqus Alliance presentationJavier Tallón
 
8th International Conference on Advanced Computing (ADCO 2021)
8th International Conference on Advanced Computing (ADCO 2021)8th International Conference on Advanced Computing (ADCO 2021)
8th International Conference on Advanced Computing (ADCO 2021)IJITCA Journal
 
7 th International Conference on Information Technology Converge Services( IT...
7 th International Conference on Information Technology Converge Services( IT...7 th International Conference on Information Technology Converge Services( IT...
7 th International Conference on Information Technology Converge Services( IT...ijcseit
 

What's hot (14)

International conference on networks, blockchain and internet of things (nb i...
International conference on networks, blockchain and internet of things (nb i...International conference on networks, blockchain and internet of things (nb i...
International conference on networks, blockchain and internet of things (nb i...
 
International Conference on Networks, Blockchain and Internet of Things (NBIo...
International Conference on Networks, Blockchain and Internet of Things (NBIo...International Conference on Networks, Blockchain and Internet of Things (NBIo...
International Conference on Networks, Blockchain and Internet of Things (NBIo...
 
2017 Industry of Things World USA, San Diego CA
2017 Industry of Things World USA, San Diego CA 2017 Industry of Things World USA, San Diego CA
2017 Industry of Things World USA, San Diego CA
 
12th International Conference on Ubiquitous Computing (UBIC 2021)
12th International Conference on Ubiquitous Computing (UBIC 2021) 12th International Conference on Ubiquitous Computing (UBIC 2021)
12th International Conference on Ubiquitous Computing (UBIC 2021)
 
4 th International Conference on Networks and Communications (NET 2020)
4 th International Conference on Networks and Communications (NET 2020) 4 th International Conference on Networks and Communications (NET 2020)
4 th International Conference on Networks and Communications (NET 2020)
 
Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...
 
6th International Conference on Networks & Communications (NWCOM 2020)
6th International Conference on Networks & Communications (NWCOM 2020)6th International Conference on Networks & Communications (NWCOM 2020)
6th International Conference on Networks & Communications (NWCOM 2020)
 
Call for papers - 4th International Conference on Networks and Communications...
Call for papers - 4th International Conference on Networks and Communications...Call for papers - 4th International Conference on Networks and Communications...
Call for papers - 4th International Conference on Networks and Communications...
 
Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...Call for Papers - International Conference on Networks, Blockchain and Intern...
Call for Papers - International Conference on Networks, Blockchain and Intern...
 
certificato profisafe
certificato profisafecertificato profisafe
certificato profisafe
 
jtsec Arqus Alliance presentation
jtsec Arqus Alliance presentationjtsec Arqus Alliance presentation
jtsec Arqus Alliance presentation
 
8th International Conference on Advanced Computing (ADCO 2021)
8th International Conference on Advanced Computing (ADCO 2021)8th International Conference on Advanced Computing (ADCO 2021)
8th International Conference on Advanced Computing (ADCO 2021)
 
Wild West Of IoT
Wild West Of IoTWild West Of IoT
Wild West Of IoT
 
7 th International Conference on Information Technology Converge Services( IT...
7 th International Conference on Information Technology Converge Services( IT...7 th International Conference on Information Technology Converge Services( IT...
7 th International Conference on Information Technology Converge Services( IT...
 

Similar to Smart metering security assessment in smart grid projects: the Brazilian Experience

Research Methodology Presentation - Research in Supply Chain Digital Twins
Research Methodology Presentation - Research in Supply Chain Digital TwinsResearch Methodology Presentation - Research in Supply Chain Digital Twins
Research Methodology Presentation - Research in Supply Chain Digital TwinsArwa Abougharib
 
"Iot on the field: making smart environments in everyday experience"
"Iot on the field: making smart environments in everyday experience""Iot on the field: making smart environments in everyday experience"
"Iot on the field: making smart environments in everyday experience"CSP Scarl
 
Insurance Innovation Award - Nedbank Insurance
Insurance Innovation Award - Nedbank InsuranceInsurance Innovation Award - Nedbank Insurance
Insurance Innovation Award - Nedbank InsuranceThe Digital Insurer
 
Energy efficiency in buildings
Energy efficiency in buildingsEnergy efficiency in buildings
Energy efficiency in buildingsArrowheadProject
 
Eurosmart etsi-e-io t-scs-presentation
Eurosmart etsi-e-io t-scs-presentationEurosmart etsi-e-io t-scs-presentation
Eurosmart etsi-e-io t-scs-presentationStefane Mouille
 
IoT-market-estimative
IoT-market-estimativeIoT-market-estimative
IoT-market-estimativeCleber Gomes
 
US Electronic Security Market Outlook 2020
US Electronic Security Market Outlook 2020US Electronic Security Market Outlook 2020
US Electronic Security Market Outlook 2020Neil Dave
 
PROJECT LIGTAS PRESENTATION.pptx
PROJECT LIGTAS PRESENTATION.pptxPROJECT LIGTAS PRESENTATION.pptx
PROJECT LIGTAS PRESENTATION.pptxJessaSiares
 
OSIRIS_European Utility Week 2015 - Vienna (arrastrado)
OSIRIS_European Utility Week 2015 - Vienna (arrastrado)OSIRIS_European Utility Week 2015 - Vienna (arrastrado)
OSIRIS_European Utility Week 2015 - Vienna (arrastrado)Jose Angel Velasco
 
Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...
Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...
Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...KTN
 
Presentation : Smart Grid based on research paper
Presentation : Smart Grid based on research paperPresentation : Smart Grid based on research paper
Presentation : Smart Grid based on research paperUsman Ksk
 
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationSolent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationNine23Ltd
 
Presentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawPresentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawftii
 
Presentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawPresentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawftii
 
Presentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawPresentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawRizkiawan Achadi
 
GARE du MIDIH Open Digital Platforms the adoption of a standards-based open...
GARE du MIDIH   Open Digital Platforms the adoption of a standards-based open...GARE du MIDIH   Open Digital Platforms the adoption of a standards-based open...
GARE du MIDIH Open Digital Platforms the adoption of a standards-based open...MIDIH_EU
 

Similar to Smart metering security assessment in smart grid projects: the Brazilian Experience (20)

Smart grid projects and ciber security in brazil conference
Smart grid projects and ciber security in  brazil conference Smart grid projects and ciber security in  brazil conference
Smart grid projects and ciber security in brazil conference
 
Research Methodology Presentation - Research in Supply Chain Digital Twins
Research Methodology Presentation - Research in Supply Chain Digital TwinsResearch Methodology Presentation - Research in Supply Chain Digital Twins
Research Methodology Presentation - Research in Supply Chain Digital Twins
 
"Iot on the field: making smart environments in everyday experience"
"Iot on the field: making smart environments in everyday experience""Iot on the field: making smart environments in everyday experience"
"Iot on the field: making smart environments in everyday experience"
 
Insurance Innovation Award - Nedbank Insurance
Insurance Innovation Award - Nedbank InsuranceInsurance Innovation Award - Nedbank Insurance
Insurance Innovation Award - Nedbank Insurance
 
Energy efficiency in buildings
Energy efficiency in buildingsEnergy efficiency in buildings
Energy efficiency in buildings
 
Technical Writting.pptx
Technical Writting.pptxTechnical Writting.pptx
Technical Writting.pptx
 
M2M Telefónica - Internet of Things Keynote
M2M Telefónica - Internet of Things KeynoteM2M Telefónica - Internet of Things Keynote
M2M Telefónica - Internet of Things Keynote
 
Smart Advanced Metering in the UK – An overview
Smart Advanced Metering in the UK – An overviewSmart Advanced Metering in the UK – An overview
Smart Advanced Metering in the UK – An overview
 
Eurosmart etsi-e-io t-scs-presentation
Eurosmart etsi-e-io t-scs-presentationEurosmart etsi-e-io t-scs-presentation
Eurosmart etsi-e-io t-scs-presentation
 
IoT-market-estimative
IoT-market-estimativeIoT-market-estimative
IoT-market-estimative
 
US Electronic Security Market Outlook 2020
US Electronic Security Market Outlook 2020US Electronic Security Market Outlook 2020
US Electronic Security Market Outlook 2020
 
PROJECT LIGTAS PRESENTATION.pptx
PROJECT LIGTAS PRESENTATION.pptxPROJECT LIGTAS PRESENTATION.pptx
PROJECT LIGTAS PRESENTATION.pptx
 
OSIRIS_European Utility Week 2015 - Vienna (arrastrado)
OSIRIS_European Utility Week 2015 - Vienna (arrastrado)OSIRIS_European Utility Week 2015 - Vienna (arrastrado)
OSIRIS_European Utility Week 2015 - Vienna (arrastrado)
 
Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...
Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...
Creating a Step Change in Cyber Security | ISCF DSbD Business-led Demonstrato...
 
Presentation : Smart Grid based on research paper
Presentation : Smart Grid based on research paperPresentation : Smart Grid based on research paper
Presentation : Smart Grid based on research paper
 
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS PresentationSolent Cyber Security Cluster Event 2, ACE/UoS Presentation
Solent Cyber Security Cluster Event 2, ACE/UoS Presentation
 
Presentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawPresentasi ftii intlcyberlaw
Presentasi ftii intlcyberlaw
 
Presentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawPresentasi ftii intlcyberlaw
Presentasi ftii intlcyberlaw
 
Presentasi ftii intlcyberlaw
Presentasi ftii intlcyberlawPresentasi ftii intlcyberlaw
Presentasi ftii intlcyberlaw
 
GARE du MIDIH Open Digital Platforms the adoption of a standards-based open...
GARE du MIDIH   Open Digital Platforms the adoption of a standards-based open...GARE du MIDIH   Open Digital Platforms the adoption of a standards-based open...
GARE du MIDIH Open Digital Platforms the adoption of a standards-based open...
 

More from José Reynaldo Formigoni Filho, MSc

More from José Reynaldo Formigoni Filho, MSc (10)

Blockchain no setor elétrico: conceitos, potenciais aplicações e iniciativas
Blockchain no setor elétrico: conceitos, potenciais aplicações e iniciativasBlockchain no setor elétrico: conceitos, potenciais aplicações e iniciativas
Blockchain no setor elétrico: conceitos, potenciais aplicações e iniciativas
 
Segurança em IoT - conceitos e iniciativas de padronização
Segurança em IoT - conceitos e iniciativas de padronizaçãoSegurança em IoT - conceitos e iniciativas de padronização
Segurança em IoT - conceitos e iniciativas de padronização
 
IoT + Blockchain: o mesh perfeito
IoT + Blockchain: o mesh perfeitoIoT + Blockchain: o mesh perfeito
IoT + Blockchain: o mesh perfeito
 
Plano Nacional de IoT e a Segurança Cibernética das Coisas
Plano Nacional de IoT e a Segurança Cibernética das CoisasPlano Nacional de IoT e a Segurança Cibernética das Coisas
Plano Nacional de IoT e a Segurança Cibernética das Coisas
 
(In)segurança em iot no setor elétrico
(In)segurança em iot no setor elétrico(In)segurança em iot no setor elétrico
(In)segurança em iot no setor elétrico
 
Tecnologia blockchain: uma visão geral
Tecnologia blockchain:  uma visão geralTecnologia blockchain:  uma visão geral
Tecnologia blockchain: uma visão geral
 
Tecnologia Blockchain: uma visão Geral (CPqD)
Tecnologia Blockchain: uma visão Geral (CPqD)Tecnologia Blockchain: uma visão Geral (CPqD)
Tecnologia Blockchain: uma visão Geral (CPqD)
 
Smart Grid Forum 2016 Segurança IoT v3
Smart Grid Forum 2016 Segurança IoT v3Smart Grid Forum 2016 Segurança IoT v3
Smart Grid Forum 2016 Segurança IoT v3
 
Gestão de Risco e Maturidade WS Aneel 2016 v3
Gestão de Risco e Maturidade WS Aneel 2016 v3Gestão de Risco e Maturidade WS Aneel 2016 v3
Gestão de Risco e Maturidade WS Aneel 2016 v3
 
Cibersegurança no Setor Elétrico: Ações internacionais e proposta para mitiga...
Cibersegurança no Setor Elétrico: Ações internacionais e proposta para mitiga...Cibersegurança no Setor Elétrico: Ações internacionais e proposta para mitiga...
Cibersegurança no Setor Elétrico: Ações internacionais e proposta para mitiga...
 

Recently uploaded

Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...NETWAYS
 
Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸mathanramanathan2005
 
miladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptxmiladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptxCarrieButtitta
 
Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...
Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...
Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...marjmae69
 
Open Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdf
Open Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdfOpen Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdf
Open Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdfhenrik385807
 
Work Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxWork Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxmavinoikein
 
OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...
OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...
OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...NETWAYS
 
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...NETWAYS
 
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSimulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSebastiano Panichella
 
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)Basil Achie
 
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...Salam Al-Karadaghi
 
Event 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptxEvent 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptxaryanv1753
 
Genshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptxGenshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptxJohnree4
 
Genesis part 2 Isaiah Scudder 04-24-2024.pptx
Genesis part 2 Isaiah Scudder 04-24-2024.pptxGenesis part 2 Isaiah Scudder 04-24-2024.pptx
Genesis part 2 Isaiah Scudder 04-24-2024.pptxFamilyWorshipCenterD
 
James Joyce, Dubliners and Ulysses.ppt !
James Joyce, Dubliners and Ulysses.ppt !James Joyce, Dubliners and Ulysses.ppt !
James Joyce, Dubliners and Ulysses.ppt !risocarla2016
 
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...NETWAYS
 
The Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism PresentationThe Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism PresentationNathan Young
 
call girls in delhi malviya nagar @9811711561@
call girls in delhi malviya nagar @9811711561@call girls in delhi malviya nagar @9811711561@
call girls in delhi malviya nagar @9811711561@vikas rana
 
Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170Escort Service
 

Recently uploaded (20)

Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Rohini Delhi 💯Call Us 🔝8264348440🔝
 
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
OSCamp Kubernetes 2024 | A Tester's Guide to CI_CD as an Automated Quality Co...
 
Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸Mathan flower ppt.pptx slide orchids ✨🌸
Mathan flower ppt.pptx slide orchids ✨🌸
 
miladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptxmiladyskindiseases-200705210221 2.!!pptx
miladyskindiseases-200705210221 2.!!pptx
 
Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...
Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...
Gaps, Issues and Challenges in the Implementation of Mother Tongue Based-Mult...
 
Open Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdf
Open Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdfOpen Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdf
Open Source Strategy in Logistics 2015_Henrik Hankedvz-d-nl-log-conference.pdf
 
Work Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptxWork Remotely with Confluence ACE 2.pptx
Work Remotely with Confluence ACE 2.pptx
 
OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...
OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...
OSCamp Kubernetes 2024 | Zero-Touch OS-Infrastruktur für Container und Kubern...
 
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
Open Source Camp Kubernetes 2024 | Running WebAssembly on Kubernetes by Alex ...
 
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with AerialistSimulation-based Testing of Unmanned Aerial Vehicles with Aerialist
Simulation-based Testing of Unmanned Aerial Vehicles with Aerialist
 
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
NATIONAL ANTHEMS OF AFRICA (National Anthems of Africa)
 
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
Exploring protein-protein interactions by Weak Affinity Chromatography (WAC) ...
 
Event 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptxEvent 4 Introduction to Open Source.pptx
Event 4 Introduction to Open Source.pptx
 
Genshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptxGenshin Impact PPT Template by EaTemp.pptx
Genshin Impact PPT Template by EaTemp.pptx
 
Genesis part 2 Isaiah Scudder 04-24-2024.pptx
Genesis part 2 Isaiah Scudder 04-24-2024.pptxGenesis part 2 Isaiah Scudder 04-24-2024.pptx
Genesis part 2 Isaiah Scudder 04-24-2024.pptx
 
James Joyce, Dubliners and Ulysses.ppt !
James Joyce, Dubliners and Ulysses.ppt !James Joyce, Dubliners and Ulysses.ppt !
James Joyce, Dubliners and Ulysses.ppt !
 
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
OSCamp Kubernetes 2024 | SRE Challenges in Monolith to Microservices Shift at...
 
The Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism PresentationThe Ten Facts About People With Autism Presentation
The Ten Facts About People With Autism Presentation
 
call girls in delhi malviya nagar @9811711561@
call girls in delhi malviya nagar @9811711561@call girls in delhi malviya nagar @9811711561@
call girls in delhi malviya nagar @9811711561@
 
Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170Call Girls In Aerocity 🤳 Call Us +919599264170
Call Girls In Aerocity 🤳 Call Us +919599264170
 

Smart metering security assessment in smart grid projects: the Brazilian Experience

  • 1. The Brazilian experience Smart meter security assessment in smart grid projects March 2017 José Reynaldo Formigoni Filho, MSc Information and Communication Security Technology Manager CPqD Foundation
  • 2. AGENDA Smart grid and smart meters’ deployment in Brazil Smart meter’s threats and frauds in Brazil Smart meter security assessment R&D project Security test procedures and results Concluding remarks
  • 3. THE GRID DEPLOYMENT: CURRENT BRAZILIAN SITUATION • R&D Phase • Pilot Projects • Government funds First wave of smart grid • Smart metering commercial deployments • Automation and operations integration Second wave of smart grid •Distributed generation and storage •EV •IT-OT integration • Big data analytics Third wave of smart grid Developed countries Brazil
  • 5. THE SMART GRID DEPLOYMENT: CURRENT BRAZILIAN SITUATION • 13 pilots R&D projects • US$ 100 mi from Aneel Funds • Total of smart meters: almost 200.000 Digital City 10.000 Cidade Inteligente 10.000 EDP Bandeirante Cidade Inteligente 10.000 Elektro Eletropaulo Digital 84.000 Cidade do Futuro 4.200 Smart Grid 27.000 Cidade Inteligente - Búzios 10.000 - Ampla Redes Inteligentes Celpe 850 Energia Mais Celge Smart Grid EV and DG Cidade Inteligente Aquirás - Coelce 20.000 Parintins Smart Grid 3000
  • 6. COMMERCIAL SMART METER DEPLOYMENT • Industrial and commercial medium and large customers (Group A): almost 100% are using electronic meters (the minority of these are smart meters) • Residencial and commercial small customers (Group B): the deployment has just started Rio de Janeiro: 1 million smart meters for Group B in 5 years 2 million smart meters for Group B
  • 7. THE MAIN THREATS • Energy usage frauds: Fraud energy consumption, is a major threat and concern of the utilities, because it directly affects their income • Propagation of malicious code to other meters through the AMI: one of the most dangerous threats with high possibility to spread malwares, which may cause irreparable loss to the power company. • Malicious interruption of electricity: terrorist acts, promotion of chaos • User privacy violation: data from smart meters can show client behavior The most important threat in Brazil
  • 8. NON TECHNICAL LOSSES The cyberattacks are within 5,74% and are targeted at industrial and commercial customers Non technical losses (MV and LV) Technical losses (MV and LV) Total losses (MV and LV) Total losses for each group in 2016
  • 9. HOW BRAZIL IS DEALING WITH THE CYBERSECURITY PROBLEM? • Brazil does not have a minimum cybersecurity framework for the power sector • Aneel has not dealt with this subject as a critical infrastructure problem to the country • How are the companies facing this problem? Group 1 Foreign Controller • Bring the methodologies from abroad and do the adaptations for the Brazilian reality Group 2 Brazilian Controller With know How • They are trying to develop their own framework based on experiences from USA and EC Group 3 Brazilian Controller Without know How • They are hiring R&D Centers and Universities to help them develop their own framework
  • 10. SECURITY ASSESSMENT METHODOLOGY FOR SMART METER • Name: R&D in security assessment for smart meters • Client: • Sponsor: Aneel R&D Fund • 30-month project totally executed by CPqD Foundation • Number of customers: 2.4 mi • 8th biggest power company in Brazil • Number of cities: 228
  • 11. SECURITY ASSESSMENT METHODOLOGY FOR SMART METER Goal 1 Methodology for security assessment Goal 2 Smart Meter Cyber Security Laboratory Deployment Goal 3 Security analysis and tests of smart meter State of the art survey for smart meter security Specification of the test environment Development of the security assessment methodology for smart meter Security tests Implementation of Smart Meter Security Training Platform Laboratory deployment Laboratory operation Knowledge and technology transfer Security Assessment for Smart Meters Functional tests
  • 12. • Name: Smart meter security assessment laboratory • Number of labs: 2 (CPqD and Elektro) • Short term subjects: • Perform all tests specified by the methodology (security and fuctional tests) • Offer the security assessment evaluation for other power companies and smart meters suppliers. • Medium term subject: • To become the first national laboratory for RTM 586 (the Brazilian Standard for fuctional requirements) certified by Inmetro*, our national metrology institute • To become the first national laboratory for security assessment certified by Inmetro* LABORATORY DEPLOYMENT *INMETRO – Instituto Nacional de Metrologia
  • 13. TEST RESULTS: GENERAL OVERVIEW • Number of manufacters: 6 • Number of smart meter models tested: 8 • Main assumptions: • Hadware and software tests were performed • Intrusion tests performed: "black box” approach • The tests were performed at CPqD. A subset of these tests were performed at the Elektro’s lab.
  • 14. TEST PROCEDURES • Initial hardware evaluation of the smart meter • Copy of the non-volatile memory • Data capture at the bus • Entropy analysis of information collected from the electronic components • Searching for cryptographic keys on information collected from the electronic components • Firmware analysis • Exploiting vulnerabilities in the firmware
  • 15. HARDWARE TEST RESULTS • It is the first set of security tests to be done • Normally, the manufacturers do not provide any information related to the hardware architecture of smart meters • Tester’s skills: • Electrical circuits • Communication protocols (I2C, SPI, serial) • Embedded systems • Microcontroller architecture • Reading datasheets and layouts of printed circuit boards (PCB)
  • 16. TEST RESULTS • Functional tests (RTM 586) • 14 smart meters tested • In 13 of them was possible to access the metering parameter via optical interface • Security tests • A 100% presented software and hardware vulnerabilities
  • 17. CONCLUDING REMARKS • The Brazilian power companies have begun to pay more attention to the cybersecurity problem • Currently, Aneel does not have a clear position on this subject • Companies already face problems with fraud in electronic meters for commercial and industrial customers • The problem will be much greater with the deployment of smart meters for residential consumers
  • 18. CONCLUDING REMARKS • Discussions on standardization and certification of security requirements for smart meters are in early stages • Aneel's major concern regarding the insertion of minimum security requirements in smart meters is cost increase because our tariff is based on cost • However, considering the amount of vulnerability found in our tests, some actions should be taken by the government bodies to mitigate the problem.
  • 19. CONCLUDING REMARKS – PAPERS AND BOOK The Book • Published by Elektro at the end of 2016 • Only in Portuguese! International papers: • Smart Meters Security Assessment in the Brazilian Scenario. The Third International Conference on Smart Grids, Green Communications and IT Energy-aware Technologies - Lisbon, Portugal. March 24, 2013 • A Fast Attack against a Smart Meter Authentication Protocol. Proc. of the 3rd International Conference on Informatics, Environment, Energy and Applications. IEEA 2014. China, 27-28 March, 2014. • MeterGoat: A Low Cost Hardware Platform for Teaching Smart Meter Security. ICCGI 2014 - The Ninth International Multi-Conference on Computing in the Global Information Technology - Sevilha – Espanha. June 22, 2014 • Implementation Aspects of MeterGoat, a Smart Meter Security Training Platform. SINCONF 2014 - The 7th Internation Conference on Security of Information and Networks - Glasgow - Reino Unido. September 1, 2014 reynaldo@cpqd.com.br
  • 20. TRANSFORMANDO EM REALIDADE w w w . c p q d . c o m . b r José Reynaldo Formigoni Filho Information and Communication Security Technology Manager CPqD Foundation Tel.: +55 19 3705-7121 / Fax: +55 19 3705-6833 Cel.: +55 19 99838-2321 reynaldo@cpqd.com.br www.cpqd.com.br THANK YOU!