Energy & Utilities
Metering and grid-edge equipment that has to be trusted from a pole
Architecture specified · RTL in progress · no Nelix silicon yet
energy & utilities context
Revenue and control both rest on a reading nobody can verify
A distribution utility bills against measurements taken by devices it cannot physically supervise, and increasingly makes automated decisions from the same data. Commercial losses in many networks are dominated not by technical loss but by measurement tampering and data substitution.
The equipment also has to keep working through the conditions it is monitoring. Supply is intermittent, ambient temperatures are high, and backhaul is narrow or absent for long periods. Replacement cycles are measured in decades, so whatever is installed now has to remain defensible for a very long time.
Why current compute does not serve it
The constraints are structural: placement, power, connectivity and service life, not missing features on a datasheet.
-
Measurement and processing are separate devices
A metrology front end connected to a processor over a board-level bus creates a boundary where readings can be intercepted or substituted, and the utility sees only the resulting register.
-
Security is a boot-time check
Secure boot verifies an image at power-on and then stops observing. A device compromised after boot continues to report normally for the rest of its service life.
-
Analytics assume connectivity
Anomaly detection that runs in a head-end system cannot act during the outages and backhaul failures when it would be most useful.
-
Power loss corrupts state
Equipment designed for stable supply treats brownout as an exception. In practice it produces inconsistent state, lost intervals and manual reconciliation.
Measurement, inference and attestation inside one trust domain
SecureGrid is specified to place metrology, tamper detection and optional local inference inside a single trust domain anchored by TrustCore, so a reading is measured, encrypted and attested without crossing an unprotected boundary.
Where local analysis is required, InferEdge runs it as a bounded transaction under an explicit energy budget, and the result carries an attestation bundle binding it to the device, firmware and model that produced it. A head-end system can then reject anything that does not match approved configuration before it reaches billing or control.
This is a design programme, not a product on a shelf. The architecture is specified and under RTL development, with FPGA validation the next milestone.
Specified, not measured. RTL in progress; FPGA next; no Nelix silicon yet.
- Span that closes
- Span where in and out disagree
- Attenuated light = energy unaccounted for
Where Nelix sits in this system
Metrology, tamper detection and optional inference sit inside one trust domain, so a reading is attested before it crosses an unprotected boundary.
From the meter to a reading the head-end can refuse
One path through capture, attestation, optional inference and narrowband report — design intent, not a fielded sequence.
-
Capture
Measure at the meter, inside the trust domain
-
Attest
Bind the reading to device identity and firmware
-
Infer
Optional local anomaly detection under an energy budget
-
Report
Export a narrowband attestation bundle to the head-end
The mechanisms that address them
Technical mechanisms in the specification. None of these figures have been characterised in silicon.
-
Attested metrology
Measurements are encrypted and attested at capture rather than after transfer, removing the board-level substitution point.
-
Tamper state that survives power cycling
Enclosure, magnetic and electrical tamper events are recorded as trust-state transitions that cannot be cleared by removing power.
-
Local anomaly inference
Detection runs on the device during outages, so a loss event is identified when it happens rather than when backhaul returns.
-
Interval integrity across outage
Checkpointed execution and validated restore mean an interruption produces a recoverable state rather than a gap requiring reconciliation.
-
Narrowband attestation
Attestation bundles are sized for the bandwidth these networks actually have, not for a broadband link.
-
Cryptographic retirement
A decommissioned meter has its key material zeroised so it cannot be reused to impersonate a live device.
What changes if the architecture delivers
Operational consequences stated as design intent, not as measured field results.
-
Losses attributable to a device
When a reading carries provenance, an anomaly can be traced to a specific unit and configuration rather than inferred from aggregate discrepancy.
-
Fewer truck rolls
Local detection and recoverable state reduce the site visits caused by tamper investigation and interval reconciliation.
-
Defensible billing data
Disputed consumption can be answered with evidence about the device and firmware that produced the reading.
-
Equipment that outlives the procurement
Signed update and post-quantum-capable signing are specified for a service life that will outlast current cryptographic assumptions.
Platform layers involved
The product family this sector is specified against. Each page states programme stage honestly.
What we need from this sector now
PartnershipPre-silicon is the right time for a utility to influence this architecture. What we need now is operational reality from people who run these networks.
- Operational requirements from metering and distribution teams
- Field data on tamper methods and loss patterns
- Pilot sites for FPGA-based validation ahead of silicon
- Review of measurement integrity and attestation requirements
Other sectors
-
Sector
Telecommunications
Unmanned radio sites where energy and access are the binding constraints
Sector detail -
Sector
Industrial Infrastructure
Condition monitoring on plant that will outlive several generations of compute
Sector detail -
Sector
Government
Compute whose provenance an institution can establish for itself
Sector detail -
Sector
Edge AI
Inference that completes on the device and proves what produced it
Sector detail -
Sector
Secure Embedded Systems
Devices that have to stay trustworthy for the next fifteen years
Sector detail