Delay Attacks on the German Smart Metering Infrastructure: A Security Analysis of CLS Channel Timing Constraints
Fabio Stoll, Benjamin Pottkamp, Heiko Lorenz, Shalaka Kale, Jessica Rövekamp, Joachim Gerlach
Abstract
This work analyzes the feasibility of delay attacks on control signals transmitted via the Controllable Local System (CLS) channel of the German Smart Metering Infrastructure (SMI). It combines theoretical analysis with experimental validation under a threat model aligned to the Common Criteria Protection Profile for the Smart Meter Gateway (SMGW) and assess the potential impact on the power grid if the identified attack vector is exploited across multiple CLS channels simultaneously. We also outline mitigation strategies, including SMGW configuration restrictions, implementation-level changes, and protocol extensions. Our results show that an on-path attacker in the Wide Area Network (WAN) with sufficient contextual knowledge can feasibly execute delay attacks, with a theoretical upper bound of roughly 48 hours for some deployed protocol configurations. Projecting from a single CLS to several hundred thousand CLS devices indicates such an adversary could cause a significant frequency deviation potentially resulting in load shedding. Scaling the attack requires contextual knowledge for each targeted implementation and configuration; whether this knowledge can be broadly reused across CLS channels is uncertain but may become easier to obtain as standardization progresses. Time restricted transmissions in the FNN Steuerbox and in applications using CLS.EEDI are implementation-specific and can therefore be addressed by manufacturers. By contrast, ensuring application-data time limitations in TLS~1.3 requires protocol-level extensions. The TLS extensions proposed here offer a sustainable mitigation while preserving backward compatibility. Other communication channels outside the SMI (for example, proprietary remote terminal units used to control a CLS) are outside this work's scope and may exhibit similar or worse vulnerabilities.
Create a lesson
Related papers
Analog Pin Directionality as an Exfiltration Attack Surface in Mixed-Signal ICs
Ramana Ranganatham, Chirag Adiga, Michael Zuzak et al.
Characterizing Network Centralization and Observability in the Remote MCP Ecosystem
Muhammad Abdullah Sohail
When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic
Muhammad Abdullah Sohail
Hamming Ideals and Grobner Bases for ISD-like Syndrome Decoding
Roberto La Scala, Marco Marchesin, Sharwan K. Tiwari
ASLEval: Measuring Privacy Exposure Displacement in LLM Agent Sessions
Guosen Wu, Huizhen Huang, Guoxiong Long et al.
CASHEWS: Source Preprocessor for LLM-based Malicious Package Detection
Jean-Charles Noirot Ferrand, David Adei, Anders Møller et al.