Delay Attacks on Germany's Smart Metering Channel Could Reach a 48-Hour Upper Bound and Trigger Load Shedding at Scale
Combining theoretical analysis with experimental validation under a threat model aligned to the Common Criteria Protection Profile for the Smart Meter Gateway, the authors show an on-path WAN attacker with sufficient contextual knowledge can feasibly delay control signals on the CLS channel, with a theoretical upper bound of roughly 48 hours for some deployed protocol configurations. Projecting from a single CLS to several hundred thousand devices indicates a frequency deviation large enough to cause load shedding, though scaling requires per-implementation contextual knowledge whose reusability is uncertain. Time-restricted transmission issues in FNN Steuerbox and CLS.EEDI are implementation-specific and fixable by manufacturers, but enforcing application-data time limits in TLS 1.3 needs the backward-compatible protocol extensions they propose.
↳ Follow the thread