User's Manual
Title: 
AJ102 Data Concentrator Unit User Manual 
Ver. 
1.4 
Page:   
15  of  23 
6  Security 
6.1  Physical Security 
The DCU has two seals for the terminal cover, one seal for the RF antenna box. It is impossible to access 
the DCU internal part unless physically and transparently destroy the seals and the DCU face or terminal 
cover. The DCU records the main cover removal event and terminal cover removal event in both power on 
condition and power off condition. 
The DCU detects the meter dismantle/removal event. 
6.2  Communication Security   
The DCU supports state-of-art security for data access and data transportation basing on a role-based 
security. Each role has its own access privileges. Here below table lists all the roles, their privileges, 
security mechanism: 
Role   
Client ID 
Privileges 
Security Mechanism 
Public 
16 
Read limited DCU information, like the DCU serial 
number. 
No 
Read-Only 
2 
Read DCU 
LLS Mechanism id 1 
Read-Write 
1 
Read DCU, configure DCU parameters 
HLS Mechanism id 2 
6.3  Keys of DCU 
The DCU has the following keys for each DLMS HLS client.   
No 
Type Name 
Description 
1 
Authentication key 
Ensure data integrity and authenticity 
2 
Encryption key 
Ensure data confidentiality 
3 
Master key 
Use to change other keys 
Each DCU has its own individual keys once out of factory. 
All the keys are updatable from central system. 
6.4  Communication Security to Meters 
DCU follows smart meter’s security policy. All communication to meters are authenticated and encrypted. 










