🤖 AI Summary
This study addresses the risk of delay attacks targeting the Controllable Local System (CLS) channel within Germany’s smart metering infrastructure. By integrating threat modeling, network experimentation, and protocol analysis, it quantifies—for the first time—the theoretical upper bound of such attacks at approximately 48 hours and demonstrates their potential to destabilize grid frequency and trigger large-scale load shedding. The work proposes a TLS 1.3–compatible, protocol-level extension enforcing temporal constraints and validates the practical feasibility of these attacks through real-world smart meter gateway configurations. Findings indicate that combining vendor-specific implementation refinements with protocol enhancements can effectively mitigate the identified risks, while also cautioning that ongoing standardization efforts may inadvertently lower the barrier to launching such attacks.
📝 Abstract
This work analyzes the feasibility of delay attacks on control signals transmitted via the Controllable Local System (CLS) channel of the German Smart Metering Infrastructure (SMI). It combines theoretical analysis with experimental validation under a threat model aligned to the Common Criteria Protection Profile for the Smart Meter Gateway (SMGW) and assess the potential impact on the power grid if the identified attack vector is exploited across multiple CLS channels simultaneously. We also outline mitigation strategies, including SMGW configuration restrictions, implementation-level changes, and protocol extensions.
Our results show that an on-path attacker in the Wide Area Network (WAN) with sufficient contextual knowledge can feasibly execute delay attacks, with a theoretical upper bound of roughly 48 hours for some deployed protocol configurations. Projecting from a single CLS to several hundred thousand CLS devices indicates such an adversary could cause a significant frequency deviation potentially resulting in load shedding. Scaling the attack requires contextual knowledge for each targeted implementation and configuration; whether this knowledge can be broadly reused across CLS channels is uncertain but may become easier to obtain as standardization progresses.
Time restricted transmissions in the FNN Steuerbox and in applications using CLS.EEDI are implementation-specific and can therefore be addressed by manufacturers. By contrast, ensuring application-data time limitations in TLS~1.3 requires protocol-level extensions. The TLS extensions proposed here offer a sustainable mitigation while preserving backward compatibility.
Other communication channels outside the SMI (for example, proprietary remote terminal units used to control a CLS) are outside this work's scope and may exhibit similar or worse vulnerabilities.