MP168 CPL Security Improvements

Proposer Gordon Hextall (Security Sub-Committee)
Lead Analyst Kev Duddy
Date raised 11/06/2021
StageImplemented
Implementation date 11 September 2023
Latest update This modification was implemented on 11 September 2023.

What is the issue?

Smart Energy Code (SEC) Appendix Z ‘CPL Requirements Document’ requires the Panel to check that a communication requesting a firmware Image to be associated with a Device Model on the Central Products List (CPL) originates from the person who created the Image and is endorsed by a Supplier. At present, the nature of the signatures used by manufacturers do not enable cryptographic authentication that the communication originates from a specific manufacturer beyond reasonable doubt. Neither a Supplier nor the Panel can therefore suitably verify the authenticity of the communication and therefore fully meet the SEC obligation.

What is the solution?

The DCC shall publish the Infrastructure Key Infrastructure (IKI) Certificate Revocation List (CRL) on-line for a range of uses that require authentication of IKI. In addition, the SEC legal drafting shall be updated to reflect that any organisation that needs to authenticate IKI Certificates is given access to and is required to check the CRL when receiving requests authenticated with an IKI token.

Who is impacted?

Large Suppliers
Small Suppliers
DCC
Other SEC Parties (Device Manufacturers)

What SEC documents are affected?

Section A ‘Definitions and Interpretations
Section L ‘SMKI and DCC Key Infrastructure’
Appendix D ‘SMKI Registration Authority Policies and Procedures’
Appendix Q ‘IKI Certificate Policy’

Timeline

11 Jun 2021
Draft Proposal raised
28 Sep 2021
Converted to Modification Proposal

Modification documents

MP168 Modification Report Consultation responses
26/07/2023
MP168 Conclusions Report v1.0
26/07/2023
MP168 Modification Report Consultation
21/06/2023
MP168 Refinement Consultation responses
25/05/2023
MP168 legal text v1.0
22/05/2023
MP168 Refinement Consultation
03/05/2023
MP168 Working Group summary - April 2023
21/04/2023
MP168 Working Group summary - May 2022
12/05/2022
MP168 Business Requirements v1.0
05/05/2022
MP168 Modification Report v1.0
11/06/2021
No files
No files
No files
No files
No files

If you believe there is a problem with this modification, please let us know HERE.