Technology

The technology design focuses on practical cybersecurity controls for distributed energy installations without disrupting existing EMS and manufacturer workflows.

Architecture Principles

The gateway is positioned between DER devices and external services following three principles:

  • Operator sovereignty over critical commands
  • Vendor-neutral integration
  • Non-disruptive deployment

Security Functions

  • Command mediation
    • Authorisation of remote actions before they reach DER devices.
  • Independent logging
    • Local audit trail available independently of vendor clouds.
  • Access segmentation
    • Separation of maintenance, EMS and owner control channels.
  • Update governance
    • Owner-approved firmware and configuration changes.

Integration Modes

The gateway adapts to common topologies:

  • Direct connection to manufacturer cloud
  • Operation behind third-party EMS
  • Mixed PV and PV+BESS environments
  • Sites with local internet breakout

Compatibility & Deployment

Deployment models reflect different national practices where many DER sites operate outside classical SCADA architectures while still relying on manufacturer and EMS connectivity.

Designed for gradual adoption without interrupting energy production:

  • Works with multiple inverter brands
  • Applicable to PV and PV+BESS sites
  • Suitable for installations below SCADA integration
  • Deployable without production downtime

Architecture to be validated in real operational pilot environments in Estonia, with applicability to broader European DER contexts.