Delivering emergency backstop readiness with secure PKI
This case study explores how SwitchDin delivered an interim public key infrastructure that enabled a leading distribution network to secure its consumer energy resources and meet the emergency backstop deadline without waiting for the national solution.
About the client
Our customer is a major Australian distribution network service provider (DNSP). It owns, operates and maintains the electricity distribution infrastructure serving well over a million homes and businesses across metropolitan and regional Australia.
As a network operator, its job is to deliver safe, reliable and affordable electricity while enabling the grid up to distributed energy resources: rooftop solar, home batteries and electric vehicles. It plays a leading role in modernising the grid for Australia's clean energy transition.
Strategic focus
Keep the network safe and reliable
Enable greater renewable energy adoption and customer choice
Prepare the grid for rapidly increasing DER participation
Deliver a smarter, more resilient electricity network
The challenge
A hard deadline to secure a fast growing fleet of energy devices.
As rooftop solar penetration increases, networks need a trusted way for distributed energy systems to communicate with utility systems. Every inverter, battery and gateway must be able to verify its identity, and every instruction from the network must be trusted in return.
Depending on the connection model, communication may occur directly with individual devices or gateways, or through an authorised aggregator or OEM platform. In either case, the Utility Server and the connecting system must be able to verify each other’s identity, ensuring that data and network instructions come from a trusted source. Without this mutual trust, managing a large and growing fleet of connected devices creates a material risk for critical grid infrastructure.
What is the Emergency Backstop?
The emergency backstop is a grid safety measure, not a day-to-day control. It lets a network briefly turn down or pause rooftop solar exports, but only during rare emergencies and only when instructed by the market operator, to keep the grid stable and avoid outages.
Outside those rare events, the emergency backstop does not affect normal system operation. The solar system continues to operate normally, supporting on-site consumption and exports in accordance with its usual settings. To work, each system has to communicate over CSIP-AUS and stay connected, and that communication has to be secure and trusted. That is where PKI comes in.
Alongside other networks, our customer needed a secure public key infrastructure (PKI) to underpin all of this. The emergency backstop framework put a hard clock on it: they needed the capability, including the PKI, in place quickly rather than at some point in the future.
What they needed
Secure communication between DER devices/aggregators and utility systems
A foundation to implement the emergency backstop framework on time
Compliance with the CSIP-AUS and IEEE 2030.5 standards
Trusted authentication of manufacturers (OEMs), utilities and devices
An interim solution that bridges to the future National Energy PKI (NEPKI)
What success looked like
The project had two priorities: meeting the immediate regulatory deadline and establishing a solution that could scale as the network’s DER fleet grew.
Strengthen cybersecurity: Protect communications across a large, multi-vendor device fleet.
Build for scale: Support increasing numbers of rooftop solar connections.
Why SwitchDin
A partner that could deliver now, and scale later
The network needed a provider with genuine PKI experience, standards leadership and the operational maturity to deliver under pressure. SwitchDin fits on every count.
Proven expertise in PKI for integrating DER with utilities
Recognised leadership in CSIP-AUS implementation
Partnership with DigiCert for utility-grade PKI technology
Experience with Australian networks and equipment manufacturers
Alignment with Australian Government Gatekeeper PKI principles
Scalable architecture aligned with the future National Energy PKI (NEPKI)
An interim PKI service, built with DigiCert
SwitchDin delivered an interim public key infrastructure service in partnership with DigiCert, giving the network a trusted way to connect and manage consumer energy resources.
In plain terms, PKI is the system of digital certificates that lets devices and systems prove who they are and communicate securely. Every trusted party gets a certificate, those certificates form a chain of trust back to a shared Smart Energy Root Certificate Authority used across participating networks.
What the service provides
Beyond the trust chain above, the service handles the day to day work of running it:
Organisation verification of OEMs and personal verification of Certificate Manager
Verified digital identities for OEMs and utilities, with secure certificate issuance
Governance and policy management for the whole trust framework
Ongoing technical support and PKI operations
Together, these enable trusted communication between utilities and consumer energy resources using the IEEE 2030.5 protocol, the backbone of the emergency backstop.
Outcomes and benefits
A coordinated PKI model designed to align with the future national framework, reducing the need for each participating network to establish and operate a separate PKI
Compliance with relevant Australian energy standards
Utility-grade cybersecurity and more secure management of consumer energy resources
Simplified onboarding of DER manufacturers
A proven support model delivered jointly by SwitchDin and DigiCert
Greater grid reliability and network resilience
Safer connection of rooftop solar
Practical support for Australia’s renewable energy transition
A bridge to the national picture
The interim PKI is designed as a stepping stone. Because the shared SERCA model mirrors the architecture planned for the National Energy PKI (NEPKI), the network is well placed to migrate when the national solution is ready, without rework. In the meantime it has the secure, standards-based foundation it needs to keep connecting consumer energy resources safely as penetration climbs.
Securing distributed energy at national scale? Talk to us about PKI, emergency backstop and ISO 2030.5 readiness.