Overview: BSI-TR-compliant security modules for all market roles
A wide range of applications from MSBs, NBs, suppliers, direct marketers, manufacturers and other market participants are integrated via the MCC API in a use-case-specific manner and in accordance with BSI-TR-03109.
The MTG CryptoController (MCC) product family comprises various cryptographic modules and offers a highly secure, standardised and vendor-neutral middleware infrastructure for smart meter PKI communication in the German energy market. The MCC’s cryptographic modules enable the secure, regulatory-compliant and future-proof integration of smart metering systems into new or existing IT, backend and process environments used by metering point operators, network operators, suppliers, direct marketers and other market participants.
Cryptographically secured exchange of electronic delivery notes and order forms between the manufacturer/GWH and MSB – including signature, key assignment and end-to-end encryption.
The SMGW manufacturer equips the SMGW with initial quality seal certificates (SMGW-G certificates) during the production process.
Secure administration channel between GWA and SMGW in accordance with BSI TR-03109 for device management.
Secure reporting channel between the SMGW and the MSB for the receipt of measurement data in accordance with TAF.
Secure reporting channel between the SMGW and the NB for high-resolution measurement data for use in support of the grid.
Secure reporting channel between SMGW and LF or DV for high-resolution metering data for market-related or competitive use.
The active EMT transmits switching commands via the SMGW’s CLS / HAN channel to the CLS device (e.g. control box)
The active EMT transmits switching commands via the SMGW’s CLS / HAN channel to the CLS device (e.g. control box)
The MSB transmits the switching information to the network operator via API identifier API0002; the network operator confirms this in its response.
The network operator transmits the switching order to the MSB via API identifier API0001; the MSB confirms it in its response.
The network operator uses API identifier API0003 to request the MaLo ID from the supplier or service provider in order to uniquely identify the market location for the 24-hour supplier switch.
A switch order can be sent to the MSB via API identifier API0001; following verification and prioritisation, the MSB confirms the order.
A wide range of applications from MSBs, NBs, suppliers, direct marketers, manufacturers and other market participants are integrated via the MCC API in a use-case-specific manner and in accordance with BSI-TR-03109.
The MTG CryptoController (MCC) product family comprises various cryptographic modules and offers a highly secure, standardised and vendor-neutral middleware infrastructure for smart meter PKI communication in the German energy market. The MCC’s cryptographic modules enable the secure, regulatory-compliant and future-proof integration of smart metering systems into new or existing IT, backend and process environments used by metering point operators, network operators, suppliers, direct marketers and other market participants.
The Metering Point Operator (MSB) operates the smart meter gateway infrastructure and control boxes. It measures, receives meter data via the SMGW’s reporting channel, processes it, and forwards it to authorized market roles via market communication. At the same time, as the “GWA,” the MSB is responsible for secure technical administration in accordance with BSI TR-03109, including certificate management. To do this, the MSB requires specialized software applications such as Gateway Administration (GWA), Meter Data Management (MDM), and CLS management for controllable consumption devices via the CLS channel. The MTG CryptoController (MCC) provides the necessary cryptographic components for this purpose, independent of the manufacturer. These applications can be easily integrated via the MCC API –ensuring secure, encrypted, and BSI TR-03109-compliant communication.
The grid operator is responsible for grid stability, grid-oriented control decisions, redispatch measures, and processes in accordance with Section 14a of the German Energy Economy Act (EnWG). To fulfill these responsibilities, the grid operator requires high-resolution measurement data, schedules, and control-relevant information in order to systematically integrate decentralized generation units and to control the grid dynamically and preventively rather than purely reactively. As a central interface, the grid operator coordinates the exchange of data and schedules with relevant market participants. The MTG CryptoController (MCC pEMT) is available as an on-premises solution. It provides the necessary cryptographic components for secure measurement data reception in accordance with TAF 9 and TAF 10, regardless of the manufacturer. The MTG CryptoController features an open interface (MCC API). This allows for easy integration of grid cockpit and backend applications—enabling scalable, multi-tenant, and compliant grid processes in accordance with BSI TR-03109. The BDEW Web API can also be used via the MCC BDEW API in on-premises operations or through the DARZ energy@Web API service.
Suppliers and direct marketers use the smart metering system in a market-oriented and competitive manner. As the SMGW rollout progresses, new applications for control and metering data are emerging that are built on the SM-PKI-based infrastructure. To receive metering data via the Smart Meter Gateway or to send switching commands, they act as External Market Participants (EMTs) and use the SMGW’s secure, encrypted communication channel. The MTG CryptoController (MCC) establishes the TR-compliant connection between the application and the smart meter infrastructure. It encapsulates the cryptographic complexity of the BSI requirements and enables secure market access as an EMT.
Smart meter gateway manufacturers can use the MTG CryptoController (MCC) and the MTG Metering CA to quickly and flexibly equip their hardware with the required quality seal certificates. Three out of five SMGW manufacturers are already using this technology. As an additional component, the MCC supports the cryptographically secure generation and processing of the Electronic Order Form (eBS) and Delivery Note (eLS).
The MCC API can be quickly and easily integrated into the relevant application to communicate with SMGWs or other market participants in accordance with BSI TR-03109-1.
Learn moreThe MTG CryptoController MAKO (MCC MAKO AS4) handles the BSI TR-03109-compliant security functions for AS4 market communication. The software automates certificate management within the SM-PKI and performs BSI-compliant encryption, decryption (e.g., Brainpool curves), and signing processes via a secure HSM connection.
Cryptographic Functions for the Electronic Delivery Note (eLS)
The electronic delivery note (eLS) contains the device and configuration data of the SMGW produced by the GWH for a specific GWA operation. This confidential data is encrypted using XML encryption and can only be decrypted by the respective GWA. By digitally signing the XML structure with the GW manufacturer key from the SM-PKI, the eLS becomes tamper-proof and its origin can be unequivocally verified. The MTG CryptoController eLS (MCC eLS) provides the necessary XML cryptography functionality for this purpose.
Cryptographic Functions for the Electronic Purchase Order (eBS)
The MTG CryptoController eLS (MCC eLS) secures the exchange of GWA-specific device and configuration data within the gateway order via the electronic order form (eBS). To do this, the GWA signs its initial configuration data (IKData) using its signature certificate from the SM-PKI; to protect these sensitive rollout details, the GWA encrypts this data for the GWH using the GWH’s GWG encryption certificate from the SM-PKI.
The MTG CryptoController pEMT (MCC pEMT) enables passive external market participants to receive consumption data via the reporting channel in compliance with TR. The software decrypts the data packets – which are explicitly encrypted for this pEMT, signed by the SMGW, and formatted according to the tariff application cases (TAF) – and verifies the integrity and validity of the signature.
The MTG CryptoController aEMT (MCC aEMT) secures active access to the active EMT in accordance with BSI TR-03109-1. The MCC software receives the WAN-CLS proxy channel TLS connections from the SMGW and forwards the data sent via this CLS proxy channel (e.g., CLS status messages) to the aEMT application. Conversely, the switching and configuration commands from the aEMT application are forwarded only to and via the SMGW CLS proxy channel assigned to the specific CLS device. This provides a secure, transparent channel between the aEMT application and the CLS device that complies with BSI TR-03109, allowing switching and control commands to be transmitted tamper-proof to the connected control boxes and CLS devices.
The MTG CryptoController GWA (MCC GWA) ensures the management and operation of the SMGW in accordance with the requirements of BSI TR-03109 and TR-03116-3 via the management, admin/service, and NTP channels. The GWA and SMGW mutually authenticate each other cryptographically using their SM-PKI certificates over the encrypted TLS tunnel. The transmitted data is additionally encrypted and signed using CMS, e.g., the configuration profiles for TAF and CLS proxy sent from the GWA to the SMGW, as well as the measurement, status, and log data sent by the SMGW. Furthermore, only the GWA can contact its SMGW using WakeUp packets signed by the MCC GWA. Furthermore, only the GWA can provide a secure channel for downloading firmware updates.
Based on the MTG CryptoController (MCC BDEW-API), the requirements of the BDEW Web API were implemented, and the system and API were expanded accordingly. This enhancement not only enables the MaLo ID to be queried via API identifier API0003 as part of the 24-hour supplier switch (LFW24), but also supports the secure and compliant transmission of switching commands. These can be transmitted by suppliers ( ) and grid operators via the API identifiers API0001 and API0002 to the responsible metering point operator (MSB). Future API identifiers specified by the BDEW and extensions to the BDEW Web API can also be flexibly supported and integrated into the MCC platform.
The MCC BDEW API provides the associated directory service, which resolves requests for API identifiers from external market participants and maps them to the corresponding web service. If the API identifier is not registered locally, the request is forwarded to the relevant BDEW API directory service.
Thanks to the MTG CryptoController, manufacturers of smart meter gateways can equip their hardware with the required quality seal certificates in a scalable and fail-safe manner and manage the key material securely within an HSM.
Cryptographically secured exchange of electronic delivery notes and order forms between the manufacturer/GWH and MSB – including signature, key assignment and end-to-end encryption.
The SMGW manufacturer equips the SMGW with initial quality seal certificates (SMGW-G certificates) during the production process.
Secure administration channel between GWA and SMGW in accordance with BSI TR-03109 for device management.
Secure reporting channel between the SMGW and the MSB for the receipt of measurement data in accordance with TAF.
Secure reporting channel between the SMGW and the NB for high-resolution measurement data for use in support of the grid.
Secure reporting channel between SMGW and LF or DV for high-resolution metering data for market-related or competitive use.
The active EMT transmits switching commands via the SMGW’s CLS / HAN channel to the CLS device (e.g. control box)
The active EMT transmits switching commands via the SMGW’s CLS / HAN channel to the CLS device (e.g. control box)
The MSB transmits the switching information to the network operator via API identifier API0002; the network operator confirms this in its response.
The network operator transmits the switching order to the MSB via API identifier API0001; the MSB confirms it in its response.
The network operator uses API identifier API0003 to request the MaLo ID from the supplier or service provider in order to uniquely identify the market location for the 24-hour supplier switch.
A switch order can be sent to the MSB via API identifier API0001; following verification and prioritisation, the MSB confirms the order.
Technical Integration of Cryptography
Central Crypto Middleware in the SM-PKI
The MTG CryptoController (MCC) product family consists of various cryptographic modules and offers a highly secure, standardized, and vendor-neutral middleware infrastructure for Smart Meter PKI communication in the German energy market. The MCC’s cryptographic modules enable the secure, regulatory-compliant, and future-proof integration of smart metering systems into new or existing IT, backend, and process landscapes of metering point operators, grid operators, suppliers, direct marketers, and other market participants.
A wide range of applications from metering point operators, grid operators, suppliers, direct marketers, manufacturers, and other market participants are integrated via the MCC API in a use-case-specific manner and in compliance with BSI TR-03109.
Key Functions of the MTG CryptoController
Central crypto middleware in the SM-PKI
- Clear separation of the application layer and security
- Comprehensive certificate management: certificate store, application, and renewal following the dual-control principle
- Multi-tenant capability
- Scalability: Expandable both horizontally and vertically
- Redundancy: Fault-tolerant architecture
- Compliance: with TR-03109 and the Smart Metering PKI Certificate Policy
TLS Communication & Certificate Validation
- TR-compliant TLS communication with root CA and sub-CAs
- Automatic validation of certificate chains (Root CA, Sub-CA, EMT, GWA, SMGW)
- Automatic retrieval of current revocation lists
- Automatic retrieval of renewed SMGW certificates
Cryptographic Functions
- XML encryption, XML decryption, XML signing, XML signature verification for eBS and eLS
- CMS encryption and decryption
- Integration with SM-PKI (Sub-CA & Root-CA)
- mTLS communication with SMGW, GWA, pEMT, aEMT
Key management
- Secure management of private keys in the HSM
- High availability and scalability through clustering
- Passive EMTs can use the MTG Crypto Module (in accordance with Security Level 1) instead of an HSM