Reading Time: 5 minutes

“The software-defined meter replaces hardware limitations with software possibilities, but every new possibility also becomes a new responsibility. Flexibility is its greatest strength; disciplined control must be its greatest safeguard.” – MJ Martin

The Meter Becomes a Computing Platform

The software-defined meter, or SDM, represents a logical next step for water, gas, and electricity metering.  Instead of manufacturing numerous hardware configurations, a manufacturer can develop a common electronic platform and enable functions through software, configuration, or licencing.  Communications protocols, interval data, alarms, analytics, demand measurement, remote disconnect capabilities, and other functions could potentially be activated after installation.

The concept is attractive, but it changes the meter fundamentally.  A traditional meter is primarily a measuring instrument with electronics attached.  An SDM becomes a computer that happens to measure water, gas, or electricity.  That distinction introduces an entirely different risk profile.

Cold Weather Is More Than an Oscillator Problem

Oscillator stability is a legitimate Canadian concern.  Quartz oscillator frequency varies with temperature, ageing, load capacitance, and other conditions.  Temperature-related frequency drift can particularly affect radio communications, timekeeping, and systems requiring precise timing. (Analog Devices)

However, oscillator drift does not necessarily translate directly into metrological error.  A well-designed meter can employ separate precision references, compensated clocks, dedicated metrology processors, and calibration algorithms.  The real question should therefore be: whether the complete meter maintains metrological, communications, and computational performance throughout its specified environmental range.

This is particularly important in Canada.  Measurement Canada’s historical requirements for outdoor electricity meters include testing at temperatures as low as -40°C, while current gas-meter specifications include testing down to -30°C for non-temperature-controlled environments. (ISED Canada)

Cold also increases battery impedance, reduces available battery capacity, changes electronic component characteristics, and can affect displays, sensors, capacitors, radios, and memory.  An SDM intended to operate for twenty years must therefore be treated as an environmental system, not simply as a processor with a crystal oscillator.

Cybersecurity Becomes Metrology

Perhaps the greatest SDM concern is cybersecurity.  Remote software modification creates enormous operational value, but it also creates a pathway into the meter.  A compromised update mechanism could theoretically alter configuration, disable communications, corrupt measurement functions, or affect thousands of meters simultaneously.

Measurement Canada already recognizes this distinction between legally relevant and non-legally relevant software.  Its requirements address software identification, authentication, integrity, security, traceable updates, and protection against unauthorized modification. (ISED Canada)  Internationally, OIML D 31:2023 establishes similar principles for software-controlled measuring instruments. (Legal Metrology International)

The analogy is aviation.  Updating the entertainment system on an aircraft is fundamentally different from updating the flight-control computer.  SDMs require equally rigorous separation between communications applications and legally relevant metrology.

Ransomware

The recent attack vectors aimed at Canadian municipalities and utilities should also give an operator a reason for serious concern. A recent IBM report offers that 20% of all municipal and utility operators in Canada have been under cyber attacks during the past 24 months. Can these attacks reach into a software-defined meter?

The expectation is, yes, indeed they can.

Cyber insurance companies have rejected most ransomware claims since operators failed to maintain software / firmware at current standards and also failed to train their own staff on a monthly basis as per the terms and conditions of the cybersecurity insurance policies. So, operators inflict their own pain to the cybersecurity challenges.

The Fleet-Wide Failure Problem

Software also creates correlated risk.  A mechanical defect might affect a production batch.  A defective firmware release could potentially affect an entire installed population overnight.

Utilities should therefore demand signed firmware, secure boot, cryptographic authentication, staged deployment, rollback capability, watchdog recovery, redundant firmware images, event logging, and the ability for the meter to continue measuring safely if an update fails.  NIST has specifically identified insecure meter firmware updates as a smart-grid cybersecurity concern. (NIST Publications)

Obsolescence, Licencing, and Vendor Dependence

There is another danger that receives less attention.  A meter may physically survive twenty years while its processor, memory capacity, cryptographic algorithms, operating system, communications stack, or software support becomes obsolete much sooner.

Feature licencing also changes the commercial relationship.  A utility may technically own the meter while remaining dependent upon the manufacturer to activate functions.  Capabilities that were once purchased as equipment could become subscriptions, licence keys, or recurring software charges.

An SDM therefore creates potential vendor lock-in at a level traditional meters rarely possessed.

And how do the current geopolitical dynamics potentially influence these SDMs? Is this situation so different than Canada’s data sovereignty concerns with the purchase of the USA F-35 fighter jets?

Data, Privacy, and Configuration Control

As SDMs become more intelligent, they will collect increasingly granular information.  Interval consumption, voltage conditions, reverse flow, pressure, temperature, leak signatures, outage information, tamper events, and behavioural patterns can create tremendous operational value, but also greater privacy and cybersecurity obligations.

Configuration management becomes equally critical.  When thousands of physically identical meters can behave differently because of software configuration, the utility must know precisely which functions, firmware versions, parameters, security certificates, and metrological configurations exist in every meter.

The meter’s digital configuration effectively becomes part of the asset record.

The Question Utilities Should Ask

The software-defined meter is not inherently less reliable than today’s meter.  Properly engineered, it could actually become more resilient, adaptable, and valuable throughout its service life.  But procurement philosophy must change. Utilities should ask:

  • What happens at -40°C?  What happens when an update fails halfway through installation? 
  • Can the previous firmware be restored? 
  • Who controls the cryptographic keys? 
  • Can the meter continue measuring if communications software crashes? 
  • Can another vendor maintain the meter twenty years from now? 
  • What happens when today’s encryption becomes obsolete? 
  • And, perhaps most importantly, can one software defect disable ten meters, ten thousand meters, or one million meters?

Software-defined metering moves flexibility from the factory into the field.  That is its greatest advantage.  It is also its greatest vulnerability.


About the Author:

Michael Martin is the Vice President of Technology with Metercor Inc., a Smart Meter, IoT, and Smart City systems integrator based in Canada. He has more than 40 years of experience in systems design for applications that use broadband networks, optical fibre, wireless, and digital communications technologies. He is a business and technology consultant. He was a senior executive consultant for 15 years with IBM, where he worked in the GBS Global Center of Competency for Energy and Utilities and the GTS Global Center of Excellence for Energy and Utilities. He is a founding partner and President of MICAN Communications and before that was President of Comlink Systems Limited and Ensat Broadcast Services, Inc., both divisions of Cygnal Technologies Corporation (CYN: TSX).

Martin served on the Board of Directors for TeraGo Inc (TGO: TSX) and on the Board of Directors for Avante Logixx Inc. (XX: TSX.V).  He has served as a Member, SCC ISO-IEC JTC 1/SC-41 – Internet of Things and related technologies, ISO – International Organization for Standardization, and as a member of the NIST SP 500-325 Fog Computing Conceptual Model, National Institute of Standards and Technology. He served on the Board of Governors of the University of Ontario Institute of Technology (UOIT) [now Ontario Tech University] and on the Board of Advisers of five different Colleges in Ontario – Centennial College, Humber College, George Brown College, Durham College, Ryerson Polytechnic University [now Toronto Metropolitan University].  For 16 years he served on the Board of the Society of Motion Picture and Television Engineers (SMPTE), Toronto Section. 

He holds three master’s degrees – in business (MBA), communication (MA), and education (MEd). As well, he has three undergraduate diplomas and seven major certifications in business, computer programming, internetworking, project management, media, photography, and communication technology. He has completed over 80 next generation MOOC (Massive Open Online Courses) [aka Micro Learning] continuous education programs in a wide variety of topics, including: Economics, Python Programming, Internet of Things, Cloud, Artificial Intelligence and Cognitive systems, Blockchain, Agile, Power BI, Big Data, Design Thinking, Security, Indigenous Canada awareness, and more.

Martin is a volunteer, a photographer, a learner, a technologist, a philosophizer, and a romantic optimist.