Overview: BSI-TR-compliant security modules for all market roles
Interaction Between Market Roles and Secure Communication in Accordance with BSI TR-03109 (© MTG)
Grid Operator (NB)
The grid operator is responsible for grid stability, grid-oriented control decisions, redispatch measures, and processes in accordance with Section 14a of the German Energy Economy Act (EnWG). To fulfill these responsibilities, the grid operator requires high-resolution measurement data, schedules, and control-relevant information in order to systematically integrate decentralized generation units and to control the grid dynamically and preventively rather than purely reactively. As a central interface, the grid operator coordinates the exchange of data and schedules with relevant market participants. The MTG CryptoController (MCC pEMT) is available as an on-premises solution. It provides the necessary cryptographic components for secure measurement data reception in accordance with TAF 9 and TAF 10, regardless of the manufacturer. The MTG CryptoController features an open interface (MCC API). This allows for easy integration of grid cockpit and backend applications—enabling scalable, multi-tenant, and compliant grid processes in accordance with BSI TR-03109. The BDEW Web API can also be used via the MCC BDEW API in on-premises operations or through the DARZ energy@Web API service.
On-Premises Scenario: The grid operator uses the MCC pEMT to receive TAF9/TAF10 grid status data and the MCC BDEW-API to send switching orders to the MSB (© MTG)
Supplier (LF) and Direct Marketer (DV)
Suppliers and direct marketers use the smart metering system in a market-oriented and competitive manner. As the SMGW rollout progresses, new applications for control and metering data are emerging that are built on the SM-PKI-based infrastructure. To receive metering data via the Smart Meter Gateway or to send switching commands, they act as External Market Participants (EMTs) and use the SMGW’s secure, encrypted communication channel. The MTG CryptoController (MCC) establishes the TR-compliant connection between the application and the smart meter infrastructure. It encapsulates the cryptographic complexity of the BSI requirements and enables secure market access as an EMT.
Metering Point Operator (MSB)
The Metering Point Operator (MSB) operates the smart meter gateway infrastructure and control boxes. It measures, receives meter data via the SMGW’s reporting channel, processes it, and forwards it to authorized market roles via market communication. At the same time, as the “GWA,” the MSB is responsible for secure technical administration in accordance with BSI TR-03109, including certificate management. To do this, the MSB requires specialized software applications such as Gateway Administration (GWA), Meter Data Management (MDM), and CLS management for controllable consumption devices via the CLS channel. The MTG CryptoController (MCC) provides the necessary cryptographic components for this purpose, independent of the manufacturer. These applications can be easily integrated via the MCC API –ensuring secure, encrypted, and BSI TR-03109-compliant communication.
Manufacturer SMGW (GWH)
Smart meter gateway manufacturers can use the MTG CryptoController (MCC) and the MTG Metering CA to quickly and flexibly equip their hardware with the required quality seal certificates. Three out of five SMGW manufacturers are already using this technology. As an additional component, the MCC supports the cryptographically secure generation and processing of the Electronic Order Form (eBS) and Delivery Note (eLS).
Technical Integration of Cryptography
Central Crypto Middleware in the SM-PKI
The MTG CryptoController (MCC) product family consists of various cryptographic modules and offers a highly secure, standardized, and vendor-neutral middleware infrastructure for Smart Meter PKI communication in the German energy market. The MCC’s cryptographic modules enable the secure, regulatory-compliant, and future-proof integration of smart metering systems into new or existing IT, backend, and process landscapes of metering point operators, grid operators, suppliers, direct marketers, and other market participants.
A wide range of applications from metering point operators, grid operators, suppliers, direct marketers, manufacturers, and other market participants are integrated via the MCC API in a use-case-specific manner and in compliance with BSI TR-03109.
MCC in the OSI Reference Model according to BSI TR-03109 in SMGW communication (© MTG)
Key Functions of the MTG CryptoController
Central crypto middleware in the SM-PKI
- Clear separation of the application layer and security
- Comprehensive certificate management: certificate store, application, and renewal following the dual-control principle
- Multi-tenant capability
- Scalability: Expandable both horizontally and vertically
- Redundancy: Fault-tolerant architecture
- Compliance: with TR-03109 and the Smart Metering PKI Certificate Policy
TLS Communication & Certificate Validation
- TR-compliant TLS communication with root CA and sub-CAs
- Automatic validation of certificate chains (Root CA, Sub-CA, EMT, GWA, SMGW)
- Automatic retrieval of current revocation lists
- Automatic retrieval of renewed SMGW certificates
Cryptographic Functions
- XML encryption, XML decryption, XML signing, XML signature verification for eBS and eLS
- CMS encryption and decryption
- Integration with SM-PKI (Sub-CA & Root-CA)
- mTLS communication with SMGW, GWA, pEMT, aEMT
Key management
- Secure management of private keys in the HSM
- High availability and scalability through clustering
- Passive EMTs can use the MTG Crypto Module (in accordance with Security Level 1) instead of an HSM
Cryptographic components
MCC pEMT
The MTG CryptoController pEMT (MCC pEMT) enables passive external market participants to receive consumption data via the reporting channel in compliance with TR. The software decrypts the data packets – which are explicitly encrypted for this pEMT, signed by the SMGW, and formatted according to the tariff application cases (TAF) – and verifies the integrity and validity of the signature.
MCC aEMT
The MTG CryptoController aEMT (MCC aEMT) secures active access to the active EMT in accordance with BSI TR-03109-1. The MCC software receives the WAN-CLS proxy channel TLS connections from the SMGW and forwards the data sent via this CLS proxy channel (e.g., CLS status messages) to the aEMT application. Conversely, the switching and configuration commands from the aEMT application are forwarded only to and via the SMGW CLS proxy channel assigned to the specific CLS device. This provides a secure, transparent channel between the aEMT application and the CLS device that complies with BSI TR-03109, allowing switching and control commands to be transmitted tamper-proof to the connected control boxes and CLS devices.
MCC BDEW-API
Based on the MTG CryptoController (MCC BDEW-API), the requirements of the BDEW Web API were implemented, and the system and API were expanded accordingly. This enhancement not only enables the MaLo ID to be queried via API identifier API0003 as part of the 24-hour supplier switch (LFW24), but also supports the secure and compliant transmission of switching commands. These can be transmitted by suppliers ( ) and grid operators via the API identifiers API0001 and API0002 to the responsible metering point operator (MSB). Future API identifiers specified by the BDEW and extensions to the BDEW Web API can also be flexibly supported and integrated into the MCC platform.
The MCC BDEW API provides the associated directory service, which resolves requests for API identifiers from external market participants and maps them to the corresponding web service. If the API identifier is not registered locally, the request is forwarded to the relevant BDEW API directory service.
MCC in the OSI reference model according to BSI TR-03109 in the BDEW Web API (© MTG)
MCC GWA
The MTG CryptoController GWA (MCC GWA) ensures the management and operation of the SMGW in accordance with the requirements of BSI TR-03109 and TR-03116-3 via the management, admin/service, and NTP channels. The GWA and SMGW mutually authenticate each other cryptographically using their SM-PKI certificates over the encrypted TLS tunnel. The transmitted data is additionally encrypted and signed using CMS, e.g., the configuration profiles for TAF and CLS proxy sent from the GWA to the SMGW, as well as the measurement, status, and log data sent by the SMGW. Furthermore, only the GWA can contact its SMGW using WakeUp packets signed by the MCC GWA. Furthermore, only the GWA can provide a secure channel for downloading firmware updates.
MCC eLS
Cryptographic Functions for the Electronic Delivery Note (eLS)
The electronic delivery note (eLS) contains the device and configuration data of the SMGW produced by the GWH for a specific GWA operation. This confidential data is encrypted using XML encryption and can only be decrypted by the respective GWA. By digitally signing the XML structure with the GW manufacturer key from the SM-PKI, the eLS becomes tamper-proof and its origin can be unequivocally verified. The MTG CryptoController eLS (MCC eLS) provides the necessary XML cryptography functionality for this purpose.
Cryptographic Functions for the Electronic Purchase Order (eBS)
The MTG CryptoController eLS (MCC eLS) secures the exchange of GWA-specific device and configuration data within the gateway order via the electronic order form (eBS). To do this, the GWA signs its initial configuration data (IKData) using its signature certificate from the SM-PKI; to protect these sensitive rollout details, the GWA encrypts this data for the GWH using the GWH’s GWG encryption certificate from the SM-PKI.
MCC MAKO AS4
The MTG CryptoController MAKO (MCC MAKO AS4) handles the BSI TR-03109-compliant security functions for AS4 market communication. The software automates certificate management within the SM-PKI and performs BSI-compliant encryption, decryption (e.g., Brainpool curves), and signing processes via a secure HSM connection.
MCC in the OSI reference model according to BSI TR-03109 in AS4 communication (© MTG)
MCC GWH
Thanks to the MTG CryptoController, manufacturers of smart meter gateways can equip their hardware with the required quality seal certificates in a scalable and fail-safe manner and manage the key material securely within an HSM.
Leading SMGW manufacturers rely on the MTG CryptoController in production (© MTG)