Service Reference Variant

6.23 · Update Security Credentials (CoS)

Service details

Identifiers, rules, and applicability

Service reference
6.23
Service Reference Variant
6.23
DUIS section
3.8.76
Command variants
1
DUIS possible responses
AcknowledgementService Response from Device - GBCSPayloadFutureDatedDeviceAlertMessageCountersigned SMETS1 Response
Critical
No
Sensitive response
No
Protection against replay
Yes
On demand
Yes
Future dated
DSP + Device
DSP scheduled
No
DCC only
No
SMETS1 applicability
Yes
SAPC requirement
Mandatory
DUIS applicability
3.0, 3.1, 4.0, 5.0, 5.1, 5.2, 5.3

Specific Errors

Response codes and descriptions

Response CodeResponse Code Description
E062301
Invalid MPxN - The MPxN included in the Request does not match the Primary Import MPxN associated to the Device in the Smart Metering Inventory
E062302
Invalid Supplier Prepayment Top Up Floor Seq Number - The Supplier Prepayment Top Up Floor Seq Number data item is not applicable to the Device Type or has not been included where it is applicable to the Device Type
E062303
Device Type / Certificate Type mismatch - The Certificate Type is not applicable to the Device Type or not all Certificate Type applicable to the Device Type have been included in the Request or a certificate with an incorrect key usage has been provided for a Certificate Type
E062304
User / Certificate mismatch - At least one of the Certificates included in the Request Body does not correspond to the User submitting the Request or a certificate with an incorrect Remote Party Role has been provided for a replacement Certificate
E062305
CoS Party / Certificate mismatch - The target Device holds a CoS Certificate in the CoS Party Trust Anchor Cell that is not an active CoS Party Certificate
E062306
Incorrect MPID - The MPID (Market Participant ID) included within the Certificate that is used to sign the Request does not correspond to the Registered Supplier for the MPxN associated with the Device

Source: DUIS 3.8.76.3

GBCS Use Case

Use cases, device coverage, and applicability

Use Case / Message Code
CS02b0x0107
DUIS Applicability
v3.0 – v5.3
GBCS Applicability
v1.0 – v4.3
GBCS Criticality
Critical
Sensitive Response
No
Future Dated
DeviceDSP
CommandESMEAlways GBT
CommandGSMEAlways GBT
CommandGPFAlways GBT
CommandHCALCSNot always GBT
SMETS1 Applicable
NoYes
Eligible Roles
EISESMEHCALCS
GISGSMEGPF
SMETS1 note

HCALCS is not a valid SMETS1 Device Type

DUIS Service Definition

Data items and DCC processing

Request data items

Table 205: UpdateSecurityCredentialsCoS (sr:UpdateSecurityCredentialsCoS) data items
Data ItemDescription / Valid SetTypeMandatoryDefaultUnits
ExecutionDateTimeA User shall only add this Data Item to the Service Request where they require the Service Request to be executed at a future date and time. The UTC date and time the User requires the Command to be executed on the Device, i.e. the date when the Supplier Credentials are to be replaced. Date-time in the future that is either <= current date + 30 days or the date = ‘3000-12-31T00:00:00Z’xs:dateTimeNoNoneUTC Date-Time
SupplierFloorSeqNumberNew Supplier Originator Counter (floor value) This value will be used to prevent replay of Update Security Credentials Commands, and other Commands, for the new controlling Remote Party.sr:floorSequenceNumber (Restriction of xs:nonNegativeInteger minInclusive = 0, maxInclusive = 9223372036854775807)YesNoneN/A
SupplierPrepaymentTopUpFloorSeqNumberOnly applicable when the Command changes Supplier Credentials and Counters on a Meter and the Counter for its Prepayment Top Ups is different to that used for other Commands This value will be used to prevent replay of Prepayment Top Up Commands.sr:floorSequenceNumber (Restriction of xs:nonNegativeInteger minInclusive = 0, maxInclusive = 9223372036854775807)ESME or GSME: No Otherwise: N/ANoneN/A
SupplierReplacementCertificatesThis structure provides a list of the replacement Certificatessr:ReplacementCertificatesCoSYesNoneN/A
CertificationPathCertificatesThis structure provides the Certificates needed to Confirm Validity of the new end entity Certificate against the root public key held on the Device. The number of these may be less than the number of replacement certificatessr:Certificate(xs:base64Binary minOccurs = “1”, maxOccurs = “3”)YesNoneN/A
ApplyTimeBasedCPVChecksSpecify whether the time based Confirm Validity checkshould be appliedxs:booleanYesNoneN/A
ImportMPxNThe reference number identifying the primary import electricity or gas metering point associated to the premises to which the Change of Supplier Applies.sr: ImportMPxN Restriction of xs:string (minLength = 1, maxLength = 13)YesNoneN/A
Table 206: SupplierReplacementCertificates (sr:ReplacementCertificatesCoS) data items
Data ItemDescription / Valid SetTypeMandatoryDefaultUnits
DigitalSigningCertificateThe new Supplier digital signing credentials to be placed in the Supplier Remote Party Role Key Usage digitalSignature (Cell Usage management) on the Device.sr:Certificate (xs:base64Binary)YesNoneN/A
KeyAgreementCertificateThe new Supplier key agreement credentials to be placed in the Supplier Remote Party Role Key Usage keyAgreement (Cell Usage management) on the Device.sr:Certificate (xs:base64Binary)HCALCS: N/A Otherwise: YesNoneN/A
KeyAgreementTopUpCertificateThe new Supplier key agreement credentials to be placed in the Supplier Remote Party Key Role Usage keyAgreement (Cell Usage prePaymentTopUp) on the Device, for those Suppliers that use different Originator Counters for Prepayment Top Up.sr:Certificate (xs:base64Binary)ESME or GSME: Yes Otherwise: N/ANoneN/A

Additional System Processing - DUIS

Where UpdateSecurityCredentials(CoS) Service Request fails access control or processing by the CoS Party, the DCC Systems shall generate DCC Alert N26 and send this DCC Alert to the original Service Request Sender. The Service Request shall not be processed any further by the DCC Systems.

Upon successful execution of an UpdateSecurityCredentials(CoS) Service Request, the DCC shall, for the specified DeviceID identified within the Service Request, perform the following actions.

  1. Generate DCC Alert N27 to notify the old Import Supplier or Gas Supplier of the successful change of Security Credentials to support the CoS event.
  2. Delete all active DCC Schedules on that Device owned by the old Import Supplier or Gas Supplier. For each deleted DCC Schedule a DCC Alert N17 will be sent to the old Import Supplier.
  3. Cancel all Future Dated Response Pattern (DSP) requests and all stored SMETS1 Future Dated Critical Service Requests for the specified Device submitted by the old Import Supplier or Gas Supplier not yet sent to the Device. For each cancelled Future Dated Response Pattern (DSP) Service Request a DCC Alert N38 will be sent to the old Import Supplier or Gas Supplier.
  4. The DCC Systems will stop monitoring all Future Dated Response Pattern (Device) Commands for that Device submitted by the old Import Supplier or Gas Supplier for which no response has been received from the Device. This activity shall not trigger the sending of any DCC Alerts to the old Import Supplier or Gas Supplier.

For each certificate specified in a Response or Alert from the Device as being successfully updated by the Update Security Credentials command, the DCC Systems shall update the Smart Metering Inventory with the new certificate identifier as a record of the certificate held in the relevant Trust Anchor Cell on that Device.

Message Patterns & Examples

Pattern explorer

Open Message Patterns →

SMETS1 Supporting Requirements

Device-model variations and equivalent steps

Review the Section 18 requirements and their applicability across the documented manufacturer, Device Type, model, and firmware profiles.

Open S1SR Requirements →