📖 ABSTRACT/OVERVIEW
Smart electricity meters are being deployed across Nigeria by distribution companies as part of metering improvement programmes, but the firmware security of these devices has not been assessed, raising concerns about tamper attacks, data falsification, and remotely exploitable vulnerabilities in grid-connected metering infrastructure. This study assessed the firmware security posture of smart meters deployed by three Nigerian distribution companies in Lagos, Kano, and Enugu, covering two hardware platforms (Hexing HXE12 and Landis+Gyr E450). A structured firmware security analysis methodology was applied, including firmware extraction via JTAG and SPI interfaces, static analysis using Binwalk and Ghidra disassembly, dynamic analysis using firmware emulation in QEMU, and cryptographic implementation review. Analysis of four firmware versions across the two platforms revealed hardcoded DLMS/COSEM encryption keys in two firmware versions (50 percent of analysed images), absent firmware signature verification on three of four images enabling unsigned firmware installation, and a stack buffer overflow in the HXE12 TCP/IP stack reachable via the AMI network interface. Cryptographic key storage in non-volatile memory without hardware security module protection was found in all four images. Proof-of-concept demonstration of the buffer overflow vulnerability was responsibly disclosed to the respective vendor. The study fills a critical gap in African smart meter security research and recommends NERC mandate firmware security assessment as a condition of meter type approval, and require distribution companies to deploy smart meters only on hardware platforms with secure boot and hardware-protected key storage.
Keywords: smart meter security, firmware analysis, Nigeria electricity, AMI security, embedded systems vulnerability
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬