identified 4 CVEs and several other privacy and secu-
rity risks in the products. Unfortunately, the affected
companies did not react to the responsible disclosure
procedure and did not fix the underlying issues. Fi-
nally, this paper provides several recommendations
in Sect. 6. We believe that the recommendations are
generic and valid for any smart metering system, not
only those considered in the case study.
According to Art. 58 GDPR, European data pro-
tection authorities can, for example, order the con-
troller or processor to bring processing operations
into compliance with the provisions of this Regula-
tion [...], impose a temporary or definitive limitation
including a ban on processing, and impose an admin-
istrative fine. Schneier expects that EU enforcement
will be harsh (Schneier, 2018, Chapter 10). Manu-
facturers of smart gadgets should start to take the law
and the risks for data protection seriously if they plan
to sell the goods on European markets.
We believe that our recommendations show that
privacy and energy efficiency are not in conflict.
ACKNOWLEDGMENTS
This work was supported in part by the Brno Univer-
sity of Technology grant FIT-S-20-6293 (Application
of AI methods to cyber security and control systems).
REFERENCES
Article 29 Data Protection Working Party (2011). Opinion
12/2011 on smart metering. Available online at
https://ec.europa.eu/justice/article-29/documentation/
opinion-recommendation/files/2011/wp183\ en.pdf.
Asghar, M. R., D
´
an, G., Miorandi, D., and Chlam-
tac, I. (2017). Smart meter data privacy: A
survey. IEEE Communications Surveys Tutorials,
19(4):2820–2835.
Brunschwiler, C. (2013). Wireless M-Bus Se-
curity. Whitepaper Black Hat USA 2013.
https://www.compass-security.com/fileadmin/Datein/
Research/Praesentationen/blackhat\ 2013\ wmbus\
security\ whitepaper.pdf.
Chen, F., Dai, J., Wang, B., Sahu, S., Naphade, M., and
Lu, C.-T. (2011). Activity analysis based on low sam-
ple rate smart meters. In Proceedings of the 17th
ACM SIGKDD International Conference on Knowl-
edge Discovery and Data Mining, pages 240–248,
New York, NY, USA. ACM.
Cuijpers, C. and Koops, B.-J. (2012). Smart metering and
privacy in Europe: lessons from the Dutch case. In
Gutwirth, S., Leenes, R. E., de Hert, P., and Poullet,
Y., editors, European data protection: Coming of age,
pages 269–293. Springer.
Erol-Kantarci, M. and Mouftah, H. T. (2013). Smart grid
forensic science: applications, challenges, and open
issues. IEEE Communications Magazine, 51(1):68–
74.
European Commision (2011). M/487 EN: Programming
Mandate Addressed to CEN, CENELEC and ETSI
to Establish Security Standards. Available online at
http://ec.europa.eu/growth/tools-databases/mandates/
index.cfm?fuseaction=search.detail&id=472#.
Hurri, P., Neuvo, N., Mikkola, T., Bunn, E., Kaakkola, I.,
and Kivimaa, K. (2011). Smartgrid energy-usage-
data storage and presentation systems, devices, proto-
col, and processes including a visualization, and load
fingerprinting process. US Patent US8949050B2 of
BASEN CORP.
Kelly, J. and Knottenbelt, W. (2015). The UK-DALE
dataset, domestic appliance-level electricity demand
and whole-house demand from five UK homes. Mas-
ter’s thesis.
Kumar, P., Lin, Y., Bai, G., Paverd, A., Dong, J. S.,
and Martin, A. (2019). Smart grid metering net-
works: A survey on security, privacy and open re-
search issues. IEEE Communications Surveys Tuto-
rials, 21(3):2886–2927.
Lisovich, M. A., Mulligan, D. K., and Wicker, S. B. (2010).
Inferring personal information from demand-response
systems. IEEE Security Privacy, 8(1):11–20.
Mengozzi, P. (2018). Opinion of advocate general men-
gozzi. CJEU Case C-25/17, ECLI:EU:C:2018:57.
Orlando, D. and Vandevelde, W. (2021). Smart meters’ roll
out, solutions in favour of a trust enhancing law in the
eu. Journal of Law, Technology and Trust, 2(1).
Rouf, I., Mustafa, H., Xu, M., Xu, W., Miller, R., and
Gruteser, M. (2012). Neighborhood watch: Security
and privacy analysis of automatic meter reading sys-
tems. In Proceedings of the 2012 ACM Conference on
Computer and Communications Security, pages 462–
473, New York, NY, USA. ACM.
Schneier, B. (2018). Click here to kill everybody : secu-
rity and survival in a hyper-connected world. W.W.
Norton & Company Ltd. ISBN 978-0-393-60888-5.
van Megen, F. and Mueller, U. (2010). Classifying devices
by fingerprinting voltage and current consumption.
US Patent US20110313582A1 of Microsoft Technol-
ogy Licensing LLC.
Wigan, M. (2014). User issues for smart meter technology.
IEEE Technology and Society Magazine, 33(1):49–53.
SECRYPT 2022 - 19th International Conference on Security and Cryptography
58