Security Credentials - Honeywell AS302P Operating Instructions Manual

Single phase smart meter
Table of Contents

Advertisement

44
AS302P Single Phase Smart Meter
____________________________________________________________________
If any of the above items fail then the meter will generate an Event which: will be saved in the Security Log and will
generate an Alert. The meter will report Command Execution Successful (event code 0x8154) or Failed (event code
0x8155) to the Sender of the Command. If this is a Future Dated Command then a Response will be sent indicating the
Command has been received and on activation one of the following events 0x8F66 (Success) and 0x8F67 (Failure) will be
triggered (based on the command outcome).

27.2. Security Credentials

The AS302P generates Public-Private Keys to support Cryptographic Algorithms, initiated by a Command. These are the
Device, Signing and Key Agreement Certificates.
Once a device has been installed then the Supplier should send an 'Issue Security Credentials Command' to the meter
within seven days of installation. It is recommended that these are unique to that meter.
All Keys that are stored in the Meter are unique to that Meter (therefore will not be on any other Meter), so a Breach of
Security on a Single Device will not affect any other Meter in the population.
The Meter securely stores the Private Keys and has the capability of formatting and sending via its HAN Interface a
Certificate Signing Request containing the corresponding Public Key and Meter Identifier.
A Command from the DCC will be received to replace the Security Certificates on the Device, an Alert is sent showing
Success or Failure. An entry is saved in the Security Log.
The meter also stores the Public Key Agreement Values for the roles that will communicate with it, these are received from
the DCC during the Install and Commission Process.
For the Public Key Certificate, the meter securely holds the Security Credentials from the Certificates. During replacement
of the Security Credentials the meter ensures the existing Credentials are securely held until the replacement process is
complete.
The meter supports:
Elliptic Curve DSA
Elliptic Curve DH
SHA-256
In executing and creating any Command, Response or Alert, the meter is capable of applying Cryptographic Algorithms
(alone or in combination) for:
Digital Signing
Digital Signature Verification
Hashing
Message Authentication
Encryption and Decryption
© Honeywell - M450 001 1D - 23.05.2019

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents