Enterprise Resource Security Mastering Cryptographic Key Lifecycles
Smart Metering

BSI-TR-compliant security modules for all market roles and the BDEW Web API

The MTG CryptoController (MCC) is a long-proven middleware solution for implementing cryptography and secure TLS communication in accordance with the requirements of the Smart Meter PKI (BSI TR-3109). In addition, all services of the BDEW Web API can be implemented in compliance with regulations (LFW24, switching commands, switching information). Applications for metering point operators (GWA, MDM, CLS), grid operators, suppliers, direct marketers, and SMGW manufacturers can be connected to the appropriate cryptography modules via a simple interface, enabling reliable and scalable implementation of legal security requirements.

MTG CryptoController

Overview: BSI-TR-compliant security modules for all market roles

Metering Point Operator – Smart Metering
Interaction Between Market Roles and Secure Communication in Accordance with BSI TR-03109 (© MTG)

Technical Integration of Cryptography

Central Crypto Middleware in the SM-PKI

The MTG CryptoController (MCC) product family consists of various cryptographic modules and offers a highly secure, standardized, and vendor-neutral middleware infrastructure for Smart Meter PKI communication in the German energy market. The MCC’s cryptographic modules enable the secure, regulatory-compliant, and future-proof integration of smart metering systems into new or existing IT, backend, and process landscapes of metering point operators, grid operators, suppliers, direct marketers, and other market participants.

A wide range of applications from metering point operators, grid operators, suppliers, direct marketers, manufacturers, and other market participants are integrated via the MCC API in a use-case-specific manner and in compliance with BSI TR-03109.

MCC in the OSI Reference Model
MCC in the OSI Reference Model according to BSI TR-03109 in SMGW communication (© MTG)

Key Functions of the MTG CryptoController

Central crypto middleware in the SM-PKI
  • Clear separation of the application layer and security
  • Comprehensive certificate management: certificate store, application, and renewal following the dual-control principle
  • Multi-tenant capability
  • Scalability: Expandable both horizontally and vertically
  • Redundancy: Fault-tolerant architecture
  • Compliance: with TR-03109 and the Smart Metering PKI Certificate Policy
TLS Communication & Certificate Validation
  • TR-compliant TLS communication with root CA and sub-CAs
  • Automatic validation of certificate chains (Root CA, Sub-CA, EMT, GWA, SMGW)
  • Automatic retrieval of current revocation lists
  • Automatic retrieval of renewed SMGW certificates
Cryptographic Functions
  • XML encryption, XML decryption, XML signing, XML signature verification for eBS and eLS
  • CMS encryption and decryption
  • Integration with SM-PKI (Sub-CA & Root-CA)
  • mTLS communication with SMGW, GWA, pEMT, aEMT
Key management
  • Secure management of private keys in the HSM
  • High availability and scalability through clustering
  • Passive EMTs can use the MTG Crypto Module (in accordance with Security Level 1) instead of an HSM

What can we do for you?

For further information feel free to contact us!

WordPress Cookie Plugin by Real Cookie Banner