Sie sind auf Seite 1von 11

April 2017

ISBN 978-1-922017-10-9

Smart Meters: What does a


connected house really mean?
Key Findings:

Smart meters are revolutionising Australian households, but while the energy
sector is pedaling the benefits, the risks are not being fully communicated.
Smart meters can either be one-way or two-way communication devices, with
two-way devices being more expensive and less secure.
Security, privacy and competition issues need greater consideration to fully
realise benefits for consumers.
As evidenced in Victoria, the introduction of electricity smart meters has not
been a success based on cost-benefit analysis. Utilities introducing smart water
meters can learn significantly from this experience.

1 Smart Meters what does a connected house really mean?


Introduction

Smart meters electronically record


water, electricity and gas usage and About the Author
transmit this data to the utility Nigel Phair is an influential analyst on
operator in real-time. Smart meters the intersection of technology, crime and
are at the core of the global Internet society. He has published two acclaimed
of Things (IoT), and their books on the international impact of
communications abilities record and cybercrime, is a regular media
track details of water, electricity and commentator and provides executive
gas usage in homes and businesses advice on strategic digital issues. In a 21
to increase the overall efficiency and year career with the Australian Federal
reliability of an outdated and Police he achieved the rank of Detective
Superintendent and headed up
overburdened water, gas and
investigations at the Australian High
electrical grid. It is important that any
Tech Crime Centre for four years.
introduction of smart meters
provides benefits for consumers and
utility operators.
About the Centre
for Internet Safety
What is a Smart Meter? The Centre for Internet Safety at the
A smart meter is a digital device University of Canberra was created to
located at a home or business that foster a safer, more trusted Internet by
measures the amount of water, providing thought leadership and policy
electricity or gas used, virtually in advice on the social, legal, political and
real-time. Unlike a traditional meter, economic impacts of cybercrime and
a smart meter electronically reads threats to cyber security.
and stores the usage of water, The Centre is hosted within the Faculty
electricity or gas over short intervals of Business, Government & Law at the
and then remotely sends this University. The University of Canberra is
information to energy distributors Australia's capital university and focuses
and retailers. Smart meters may on preparing students for a successful
operate in two formats. One is where and rewarding career.
there is a one-way transmission of
data. That is, the amount of water, www.canberra.edu.au/cis
electricity or gas which is used is
collected at a pre-set interval and
transmitted to the provider. This is
the most cost effective and secure
method, which still provides
significant consumer and operator
benefits.

Smart Meters what does a connected house really mean? 2


The second method, and that used objects that have networking
most commonly in electricity connectivity, the IoT can bring many
installations is a two-way advantages to businesses of all
communication where not only is shapes and sizes. And as the IoT
usage transmitted to the energy enters our everyday world, it brings
provider, but the electricity provider with it more opportunities for change
can also push data and instructions and innovation.
back to the meter. This method is
Smart meters are a classic IoT
more costly and opens up cyber
advancement. It is predicted IoT will
security and privacy issues.
have an economic impact of more
For the purposes of this research we than $11 trillion per year by 2025. i
will separate smart meters into two
categories, electricity and water.
These two categories are very Electricity
distinct in how a smart meter may
Smart electricity meters generally
function, for example an electric
offer two-way, digital communication
smart meter already has power
systems that record electricity usage
available, whereas a smart water
usually every 30 minutes,
meter requires power to be
automatically sending this data to a
delivered. They are also at very
customers electricity distributor.
different stages of roll-out in society,
The concept is to end estimated bills
with smart electric meters already
and manual meter readings. Having
mandated in Victoria and at
real-time usage allows consumers to
advanced stages in other
change electricity suppliers without a
jurisdictions, whereas smart water
manual meter reading. They are also
meters are very nascent in
designed to provide data that enable
residential or commercial use.
customers to make choices about
The water industry, like many others, how much energy they use by
is currently undergoing a process of allowing them to access accurate
transformation through the use of real-time information about their
ICT and near real time data electricity consumption, either
generation. The aim is to increase through a web portal, smart phone
operational and management application or an in-home display.
efficiencies, whilst reducing Such access via interactive devices
expenditure and carbon footprint is designed to provide information
through smart water metering. about hourly, daily, weekly and
seasonal consumption, so users can
view their real-time energy usage.
The Internet of Things
Smart meters will be at the core of
the global IoT, and their
Water
communication abilities will record Smart water meters not only give
and track details of energy usage in residents an accurate and up to date
homes and businesses in order to picture on their water consumption
increase the overall efficiency and habits, they also help utilities to
reliability of often outdated and detect thousands of potential leaks
overburdened utility networks. IoT in their infrastructure and at
covers quite an array of things, and properties potentially saving water
it is easy to become overwhelmed and money.
by the subject. Simply relating to

3 Smart Meters what does a connected house really mean?


Smart water meters have telecommunications sector some
electromagnetic levels which are decades ago prior to phone number
very low, using just 25mW power portability being introduced.
emission. Mobile phones use 80
times more (2,000mW) and Wi-Fi
four times higher (100mW).ii Transmit and Receive
Smart meters work under one of two
concepts. Those that only transmit
Why Introduce Smart Meters? data of household usage patterns
The smart water metering market and those that not only transmit this
emerged to provide near real time data, but can also receive data from
data and analytics to deliver more the network. The majority of
predictive and proactive services. electricity meters contain two-way
The backbone of this effort is radios.
Advanced Metering Infrastructure
One-way meters which only transmit
(AMI) technology. AMI can provide
are the safest and most secure
a remote and constant data link
option. They are low in energy use
between utilities, meters and
(critical for water infrastructure
consumers. Communications are
where meters have to be separately
delivered through various
powered), cheaper to manufacture
technologies including power line
(by a factor of six), still allow users to
communications, telephony,
track their consumption via smart
broadband, fibre optic cable,
phone apps, are significantly more
wireless radio frequency and cellular
secure against cyber-attack and
transmissions.iii
offer much better privacy
The timely collection and analysis of protections.
water usage data, and the timely
Two-way meters, where the network
relaying of this data to the water
can push data to the meter open
user, can result in significant
significant security and privacy
changes in water use behaviour.
issues. Hackers can compromise
The benefits include immediate leak
the smart meter (and where part of a
detection and consequent remedial
smart-home infrastructure, cause
action that can save precious
much more damage) causing
quantities of water.
financial and potentially physical
Smart electricity meters have been damage for only a very small benefit
in existence for some time, but as to the consumer. Utility providers
has been seen from the Victorian can notify change of tariffs
government Auditor-Generals report, depending upon load and/or time of
the supposed benefits to consumers day whilst providing total energy
have not been realised. Consumers services. Whilst this may seem
have been slow to shop around for desirable to some households, there
better energy deals, which could be is limited education provided on the
put down to lack of communications informed consent consumers are
to consumers to notify them of their providing, often making it hard for
options, lack of real competition in them to switch providers.
the retail energy market and the
Water utilities often debate whether
inability for consumers to easily
to fully convert to AMI or run an
change from one provider to
Automatic Meter Reading (AMR)
another. Whilst there are consumer
water grid instead. The truest of
protection laws to enable
smart water grid definitions requires
competition, the electricity market in
AMI technology and its enabling two-
particular is at the same stage as the
way communications. Many water

Smart Meters what does a connected house really mean? 4


utilities do not see a clear advantage The threats from smart meters are
of AMI on a cost-benefit analysis broad with criminals having attacked
and discovered AMR is the most fit- insecure smart utility devices for a
for-purpose response. A modern variety of purposes, in particular
one-way smart meter has a battery financial fraud. In Puerto Rico,
life of around 15 years, which is the criminals used laptops containing
life of the meter, whereas two-way, software widely available in the
or AMI technology reduces this to internet underground to make
around 8 years. iv In Victoria the service calls to both businesses
single largest benefit category of the and the general public. For fees
AMI program relates to the avoided ranging from $300 to $1,000 for
cost of replacing and manually residential customers and $3,000 for
reading the old accumulation commercial clients, these criminals
meters. However, accumulation successfully reprogrammed the
meter costs have been replaced with smart meters in order to save its
AMI smart meter costs that are clients up to 75 per- cent off their
much higher.v monthly electricity bills. According to
an investigation into the incident by
Receiving one-way information for
the FBI, the Puerto Rican electrical
accurate billing, leakage and non-
and power authority affected lost
revenue water detection solves the
nearly $400 million in revenues
bulk of water utility needs. Apart
annually as a result. Like all
from security and privacy
computers, smart meters are also
considerations, practically speaking
vulnerable to malware attacks, and
there is no need to send remote
security researchers at IOActive
upgrades or other notifications to a
have devised a worm capable of
house as centralised alarms will be
rapidly spreading from one infected
sufficient and utilities will rarely (if
AMI smart meter in a home to
ever) restrict water flows into homes,
another, eventually infecting a whole
even if this may be legally permitted.
neighbourhood and plunging it into
Essentially, one-way radio darkness.vii
transmission is more secure for the
This raises the issue of responsibility
customer.
for security. For behind the meter
scenarios (a house or business),
there are many providers of smart
Threats meters and poor security, versus in
The IoT ecosystem introduces risks front of the meter (the grid) there are
that include malicious actors fewer providers and much better
manipulating the flow of information security. The Australian energy
to and from network-connected sector is immature in this respect
devices or tampering with devices and requires a robust consumer
themselves, which can lead to the protection framework which
theft of sensitive data, loss of identifies and introduces controls for
consumer privacy, interruption of all risks involved.
business operations, slowdown of
Smart-meter information, much of
internet functionality through large-
which is transmitted in an
scale distributed denial-of- service
unencrypted format, can reveal
attacks, and potential disruptions to
details such as the brand and age of
critical infrastructure. vi
your appliances and when you are
using them in which rooms of your
home. Extrapolating such data

5 Smart Meters what does a connected house really mean?


reveals how much time you spend ambitions in the battle for what it is
cooking and when you turn on the calling the conscious home. But
TV in the bedroom.viii Nest thermostats and smoke
detectors with all their embedded
Researchers in Germany revealed
sensors are prodigious producers of
that smart meters could also tell
data, and just as the Android mobile
what television programs people
phones brought new advertising and
were watching at what times,
data sales opportunities, so will Nest
because of the specific electricity
Labs products. Google now owns
required to display the scenes of
not only your Web searches, email,
each show on the screen. By
mobile phone, maps, and location
measuring these in the aggregate,
but also your movements inside your
the researchers were able to create
own home.xi
individual profiles for all television
programs, and it turns out episode An insecure and accessible smart
71 of Star Trek has a different power meter is a great way to tell when
signature from episode 17 of Modern homeowners are away for extended
Family. Of course, there are periods of time. Rather than search
potentially billions to be made selling Facebook postings, burglars will just
this data to third parties. Indeed, in be able to tap into video feeds,
May 2014, WPP, the worlds largest query the refrigerator to see when
advertising agency, announced it the last time its door was opened, or
was teaming up with the London- simply ask the smart thermostat if it
based data analytics company Onzo is in extended holiday mode. The
to study ways to collect smart-meter Nest thermostat has already been
data in order to open the door of the successfully hacked allowing just
home to advertisers.ix that, giving hackers potential remote
access to the device, including
Working hand in hand with a AMI
monitoring whether an owner is
smart utility meter will be a homes
home via the embedded motion
smart thermostat. Nest Labs has
detector or even cranking up the
completely reimagined the clunky
heat full blast.xii
old thermostat, creating a Wi-Fi-
enabled thermostat replete with
cutting-edge sensors, including
temperature, motion detection,
Privacy
humidity, and light. Nest employs The promotion of privacy issues and
adaptive artificial intelligence the importance of the protection of
algorithms designed to learn what personal information is critical to
temperatures make people happy ongoing functioning of the online
and when. Nest also has an auto- environment. Today, almost all
away mode that determines when individuals have digital footprints,
there hasnt been any motion or light created via interaction on social
near the device, correctly deducing networks, through web search,
when residents are not at home. participation in e-commerce and
Nest has other products, such as its other online activities. Technology
multi-sensor Wi-Fi-enabled smoke can deliver significant benefits, but
alarm. Just a few years after its we need to take care: how our digital
founding, Nest was purchased by footprints are collected and
Google for $3.2 billion.x managed by the organisations we
have relationships with will have
Google clearly sees the
long term implications.
opportunities in the Internet of
Things, and Nest is a powerful
hardware product to anchor its

Smart Meters what does a connected house really mean? 6


If there is one thing thats certain, it and where appropriate anonymised;
is that online interactions with what future adjacent commercial
customers can generate an amazing services will be pushed to the
array of specific and general data consumer; and how they can opt out
which, depending on the service, of future personalised services in
such as a smart meter, can be tied the future.
to an individual.
The Privacy Act 1988 regulates how
There are many privacy concerns personal information is handled. It
surrounding the collection and use of defines personal information as:
the information contained in the
information or an opinion, whether
digital footprints we leave during
true or not, and whether recorded in
online transactions. However to put
a material form or not, about an
this in context we need to
identified individual, or an individual
understand the length and nature of
who is reasonably identifiable.
the relationship between a customer
and, for example, an e-commerce Common examples are an
website, an energy retailer or utility individuals name, signature,
company. We also need to address, telephone number, date of
understand how such information is birth, medical records, bank account
collected and the context of which it details and commentary or opinion
is likely to be used. about a person.xiii As technology
solutions for billing, customer
Personalisation is a function of an
service, asset management and
organisations knowledge of a
modelling will become more
customer. Collection of data will
advanced and offer a greater depth
always warrant consideration of the
and accuracy in analytical ability, the
privacy implications and concerns by
definition of personally identifiable
consumers, businesses and
information needs to be broadened
regulators - and brings significant
in this context, ensuring consumers
obligations to the entity collecting the
with two-way AMI technology have
data.
greater control over the data their
A consumers decision to participate meter/s produce, whilst energy
in an online transaction is a result of utilities and retailers enforce data
their own cost-benefit analysis. sharing policies which are dynamic
Product personalisation experiences and context dependent. Critically
must be clear to consumers allowing does the customer:
them to measure the vendors
know what data is being
reputation and allow them to value a
collected?
more personalised service whilst
contrasting privacy concerns. The know what the data will be
previously mentioned Nest used for?
technology pushes the boundaries
know who will have access to
on this, where Google will integrate
it?
the information captured with other
data such as web search or geo- give consent - informed
location. Energy utilities and consent - for its collection?
retailers need to fully explain the
have the ability to opt out of
cost-benefit analysis to a consumer
such data collection and still
of two-way smart meter technology,
be able to use the service?
including how a dwelling (and the
people tied to it) will be identified

7 Smart Meters what does a connected house really mean?


These questions are consistent with This was on the basis that 4 per cent
the trend towards personalisation of consumers would take up flexible
and the notion that some of us may
electricity price offers, however, only
choose to provide information in
exchange for better deals, better 0.27 per cent have done so. There
targeted products, and better was a goal to reach 15 per cent
services. uptake by end of 2017. Accelerating
the uptake and benefits from flexible
The February 2017 passing of the price offers relies on retailers
Privacy Amendment (Notifiable Data providing better value-for-money
Breaches) Bill 2016 establishes a options compared to the existing flat
mandatory data breach notification tariffs, and increasing consumer
scheme in Australia. This
awareness of the availability and
amendment will mean energy
utilities and retailers covered by benefits of such offers.xiv
the Privacy Act need to notify any Improved communications to
individuals affected by a data breach consumers, combined with plain
that is likely to result in serious harm English information, much the same
though these Entities will likely way as the finance industry provides
struggle to assess the seriousness easy to read information for their
of harm, given that individuals customers. Under the national
impacted by a breach may have energy retail law, energy retailers
varying tolerances for what is
must offer fair contracts with clear
deemed harmful to them.
terms and conditions so customers
Additionally, the Office of the can understand the energy offer and
Australian Information provide a written summary of the
Commissioner will be advised of offer (called an Energy Price Fact
these breaches, and can determine Sheet) when marketing to
if further action is required. The law customers.xv
also gives the Information
Commissioner the ability to direct a
business to notify individuals about a Building Public Trust in Data
serious data breach.
A significant problem in cyber
The new scheme will strengthen the security is data manipulation. We
protections afforded to a consumers
are now in the era of Big Data,
personal information, and is
designed to improve transparency in where organisations base pivotal
the way that the public and private decisions on information they collect,
sectors respond to serious data presume accurate and analyse.
breaches. It will also give individuals Assuring data integrity means
the opportunity to take steps to securing the environments where its
minimise the damage that can result stored, transmitted, and accessed.
from unauthorised use of their Smart meters as part of the IoT-
personal information. powered home provides many
opportunities and threats for data
Competition integrity. Criminals are not only
focused on data theft, but are now
The 2011 cost-benefit analysis for examining IoTs weaknesses to
the Victorian role out of smart discover where data manipulation at
electricity meters estimated that the micro level can have the largest
$778 million of benefits associated downstream macro impacts. The
with the uptake of flexible tariffs. Mirai-based botnet attack the first

Smart Meters what does a connected house really mean? 8


comprised entirely of ordinary allowing an attacker to simply
internet-connected home products ask the smart meter to join
such as digital video recorders and the network and receive keys
web cameras of October 2016 in return.
directed huge volumes of internet Hardcoded credentials,
traffic to cause a distributed denial of allowing administrator access
service attack. Typically, criminals with passwords as simple
looking to build a botnet have to find and guessable as the
a way to infect tens of thousands of vendors name.
PCs with malware. In contrast, IoT Code simplified to work on
devices are far easier to break into. low-power devices skipping
And criminals can build much bigger important checks, allowing
botnets simply because of the larger nothing more than a long
number of devices that are available communication to crash the
to exploit.xvi device.
Every digital home must have There is also a role for government.
protected IoT devices. Over the past 60 years governments
Manufactures must produce secure- have mandated cars to be safer,
by-design smart meters which can legislating for them to be equipped
be patched and updated against with seat belts, airbags, anti-lock
known security vulnerabilities. brakes, etc. Now consumers look
Consumers need to be educated for the star safety rating when
and empowered to change default buying a new car and make choices
user names and passwords of IoT based on safety equipment. We
need to bring this thinking into the
devices, whilst acknowledging that
online environment, particularly
two-way AMI devices increase
smart meters and develop digital
security risks. Policy makers need to security standards that generate a
regulate device manufactures, positive impact. A safe user
making them accountable for experience should be coded into
securing their products. every connected smart meter.
*This research and analysis has
Responses been funded by Taggle Systems
As with all cyber security efforts, IoT
risk mitigation needs to be a Case Study: Victorian
constantly evolving and shared Government Introduction of
responsibility between government Smart Meters
and the private sector.
Unfortunately, in a rush to market, In 2006, the Victorian Government
many smart meter vendors are mandated the rollout of smart meters
either not building in security-by- to all households and small
design or providing weak security businesses across Victoria.
protocols, including: Consumers have been paying for
this since 2009, not through tax
Encryption keys using weak dollars, but through additional
or outdated encryption charges applied to their electricity
methods. bills. When the rollout was
Pairing standards with no announced, the benefits were
authentication required, promoted widely. However, when

9 Smart Meters what does a connected house really mean?


the government reviewed the better manage demand. Initial
program in 2011 it was clear there calculations indicated a 10%
would be no overall benefit to reduction in per capita consumption
consumers, but instead a likely cost could likely delay the new plant by 4-
of $319 million. When the 5 years.
continuation of the rollout was
A demand management initiative
announced, it was said to be the
was planned around that target,
'better option' for Victoria, but it was
which included an extensive social
not made clear that this was based
marketing campaign, starting with a
on excluding the costs that
comprehensive consumer survey.
consumers had already incurred.
Observing that outdoor water use
By the end of 2015, Victorians had was the major contributor to the
paid an estimated $2.239 billion in peak demand in the critical dry
metering charges, which includes season (which determined capacity
the cost of the rollout and connection requirements), the campaign
of smart meters. The Department of focussed on watering lawns & using
Economic Development, Jobs, water-wise plants
Transport & Resources does not
An important element for the
have a full understanding of the cost
initiative was obtaining detailed
of the program, which it does not
information around usage patterns
track.
and water losses, of which MRC had
Further, the single largest benefit little or no information. After much
achieved to datewhich accounts research into technology options,
for around 40 per cent, or $1.4 billion MRC settled on a Low Power Wide
of the total expected $3.2 billion Area Network (LPWAN)
benefits from smart meters over the communications platform from
life of the programrelates to the Taggle Systems, to enable
avoided costs of accumulation automatic reading of its meters on
meters for things such as their an hourly basis. As an emerging
installation and manual meter technology, while LPWAN was
reading. These costs are saved as identified as a higher risk option, it
smart meters replace the old enabled MRC to achieve its
accumulation meters, but they do objectives at a price point that
not represent any additional value facilitated a positive business case.
generated by the program.
Increasing from 80,000 (approx.
Furthermore, the overall costs of the
40,000 meters twice a year) to
smart meters program significantly
around 300 million meter reads per
outweigh these savings.xvii
year, required a specialised software
system to deal with the large
quantity of data.
Case Study: Mackay Regional
Council The data analysed highlighted many
aspects of consumption which were
previously unknown. Identifying
In 2011, challenged by a growing customers water leaks and
population increasing pressure on informing them quickly, resulted
water infrastructure, Mackay average leak duration reducing from
Regional Council (MRC) was fast 150 to 60 days.
reaching capacity in its main water
The data has also helped MRC to
treatment plant. While one option
significantly improve its level of
was to build a new water treatment
consumer engagement. A dedicated
plant ($100M price tag), the non-
customer portal enables consumers
capital solution identified was to

Smart Meters what does a connected house really mean? 10


xi n 7. Goodman
to view their daily consumption, xii ibid
understand how they compare to xiii Australian Office of the Information

their peers, and set up customised Commissioner. Privacy Act.


alerts to help manage consumption. https://www.oaic.gov.au/privacy-
law/privacy-act/
Daily per capita consumption (lpd), xiv n 5. Victorian Auditor-General
has dropped 15% from around 240 xv Australian Energy Regulator. Managing

litres to 200. The $100M treatment Energy Services at Home. Fact sheet
xvi Vijayan, J. What you need to know about the
plant, initially planned for 2022, has
been pushed back to 2032. Capital botnet that broke the internet.
http://www.csmonitor.com/World/Passcode/
deferment and cost efficiencies,
2016/1026/What-you-need-to-know-about-
have enabled MRC to freeze prices the-botnet-that-broke-the-internet
for water and sewerage for two xvii n 5. Victorian Auditor-General.
years.
MRCs outstanding work was
recognised in 2016, winning both
national and international awards for
transforming their water business.

i IBM. 2016. The Internet of Things is changing


the world.
https://www.ibm.com/blogs/internet-of-
things/changing-world-iot/
ii Pearce, T.

http://www.teresapearce.org.uk/2014/04/s
mart-water-meters-frequently-asked-
questions-faqs/
iii Water & Wastewater International. Smart

Water Meter Networks an Intelligence


Network?
http://www.waterworld.com/articles/wwi/p
rint/volume-26/issue-5/regulars/creative-
finance/smart-water-metering-networks-an-
intelligent-investment.html
iv ibid
v Victorian Auditor-General. 2015. Realising

the benefits of Smart Meters.


http://www.audit.vic.gov.au/publications/20
150916-Smart-Meters/20150916-Smart-
Meters.pdf
vi U.S. Department of Homeland Security.

Strategic Principles for Security the Internet of


Things.
https://www.dhs.gov/sites/default/files/publ
ications/Strategic_Principles_for_Securing_the
_Internet_of_Things-2016-1115-FINAL_v2-
dg11.pdf
vii Goodman, M. 2016. Future Crimes. Random

House
viii ibid
ix ibid
x https://nest.com

11 Smart Meters what does a connected house really mean?

Das könnte Ihnen auch gefallen