Skip to main content
Sector

Energy & Utilities

Metering and grid-edge equipment that has to be trusted from a pole

Architecture specified · RTL in progress · no Nelix silicon yet

energy & utilities context

Tamper exposure at the grid edge
Tamper exposure at the grid edge
THE CHALLENGE

Revenue and control both rest on a reading nobody can verify

A distribution utility bills against measurements taken by devices it cannot physically supervise, and increasingly makes automated decisions from the same data. Commercial losses in many networks are dominated not by technical loss but by measurement tampering and data substitution.

The equipment also has to keep working through the conditions it is monitoring. Supply is intermittent, ambient temperatures are high, and backhaul is narrow or absent for long periods. Replacement cycles are measured in decades, so whatever is installed now has to remain defensible for a very long time.

LIMITATIONS

Why current compute does not serve it

The constraints are structural: placement, power, connectivity and service life, not missing features on a datasheet.

  1. Measurement and processing are separate devices

    A metrology front end connected to a processor over a board-level bus creates a boundary where readings can be intercepted or substituted, and the utility sees only the resulting register.

  2. Security is a boot-time check

    Secure boot verifies an image at power-on and then stops observing. A device compromised after boot continues to report normally for the rest of its service life.

  3. Analytics assume connectivity

    Anomaly detection that runs in a head-end system cannot act during the outages and backhaul failures when it would be most useful.

  4. Power loss corrupts state

    Equipment designed for stable supply treats brownout as an exception. In practice it produces inconsistent state, lost intervals and manual reconciliation.

Semiconductor die macro
Semiconductor die macro
APPROACH

Measurement, inference and attestation inside one trust domain

SecureGrid is specified to place metrology, tamper detection and optional local inference inside a single trust domain anchored by TrustCore, so a reading is measured, encrypted and attested without crossing an unprotected boundary.

Where local analysis is required, InferEdge runs it as a bounded transaction under an explicit energy budget, and the result carries an attestation bundle binding it to the device, firmware and model that produced it. A head-end system can then reject anything that does not match approved configuration before it reaches billing or control.

This is a design programme, not a product on a shelf. The architecture is specified and under RTL development, with FPGA validation the next milestone.

Specified, not measured. RTL in progress; FPGA next; no Nelix silicon yet.

Distribution Utility infrastructure
Distribution network with loss localised to one span A conceptual map of an electricity distribution feeder in three parts. Across the top, a delivered-energy profile: an expected staircase that steps down at each transformer tap, and an actual line that follows it until the second meter, then ramps away across a single span and stays low, leaving a constant unaccounted gap. In the middle, the feeder trunk leaves a substation and runs past four metering points to a head-end port, with three step-down transformers tapping off it into clusters of service pads; the span between the second and third meter is drawn in the muted status colour with attenuated light. Underneath, energy in and energy out are compared as paired bars for each span. Every span balances except that one, where the outgoing bar is short and the shortfall is left as an open outline. The loss is therefore localised to one span rather than to the whole feeder. Distribution domain Energy delivered along the feeder Expected Unaccounted Substation Feeder head Bus bars Metering macro M1 M2 M3 M4 Energy balance Energy in over energy out, span by span One span, not one feeder Closes In ≠ out Closes In Out Xfmr 1 Step-down Xfmr 2 Step-down Xfmr 3 Step-down Service points Head-end One feeder, metered end to end
  • Span that closes
  • Span where in and out disagree
  • Attenuated light = energy unaccounted for
Metering every span turns a feeder-wide loss estimate into a single span you can send a crew to. Conceptual system visualization · design intent · not measured field data
SecureGrid trust domain · design intent
POSITION

Where Nelix sits in this system

Metrology, tamper detection and optional inference sit inside one trust domain, so a reading is attested before it crosses an unprotected boundary.

Capture and attestation at the measurement point
Capture and attestation at the measurement point
PATHWAY

From the meter to a reading the head-end can refuse

One path through capture, attestation, optional inference and narrowband report — design intent, not a fielded sequence.

  1. Capture

    Measure at the meter, inside the trust domain

  2. Attest

    Bind the reading to device identity and firmware

  3. Infer

    Optional local anomaly detection under an energy budget

  4. Report

    Export a narrowband attestation bundle to the head-end

CAPABILITIES

The mechanisms that address them

Technical mechanisms in the specification. None of these figures have been characterised in silicon.

  1. Attested metrology

    Measurements are encrypted and attested at capture rather than after transfer, removing the board-level substitution point.

  2. Tamper state that survives power cycling

    Enclosure, magnetic and electrical tamper events are recorded as trust-state transitions that cannot be cleared by removing power.

  3. Local anomaly inference

    Detection runs on the device during outages, so a loss event is identified when it happens rather than when backhaul returns.

  4. Interval integrity across outage

    Checkpointed execution and validated restore mean an interruption produces a recoverable state rather than a gap requiring reconciliation.

  5. Narrowband attestation

    Attestation bundles are sized for the bandwidth these networks actually have, not for a broadband link.

  6. Cryptographic retirement

    A decommissioned meter has its key material zeroised so it cannot be reused to impersonate a live device.

OUTCOMES

What changes if the architecture delivers

Operational consequences stated as design intent, not as measured field results.

  1. Losses attributable to a device

    When a reading carries provenance, an anomaly can be traced to a specific unit and configuration rather than inferred from aggregate discrepancy.

  2. Fewer truck rolls

    Local detection and recoverable state reduce the site visits caused by tamper investigation and interval reconciliation.

  3. Defensible billing data

    Disputed consumption can be answered with evidence about the device and firmware that produced the reading.

  4. Equipment that outlives the procurement

    Signed update and post-quantum-capable signing are specified for a service life that will outlast current cryptographic assumptions.

What we need from this sector now

Partnership

Pre-silicon is the right time for a utility to influence this architecture. What we need now is operational reality from people who run these networks.

  • Operational requirements from metering and distribution teams
  • Field data on tamper methods and loss patterns
  • Pilot sites for FPGA-based validation ahead of silicon
  • Review of measurement integrity and attestation requirements