Technician in a hi-vis vest checking a grey metering and inverter cabinet at the base of a rooftop photovoltaic array on a flat roof, with solar panels and rooftops behind under a grey sky

dena DIVE: digital identities as trust anchors in the energy system

Millions of small plants feed in, store and consume power. How does the system know a plant really is what it claims to be? DIVE tested an answer.

The dena project DIVE equips machines and plants in the energy system with digital, verifiable identities. This article explains the principle of self-sovereign identity and verifiable credentials, the relationship to the established smart meter PKI, the three tested use cases and the framework set by eIDAS 2.0 and the EUDI wallet. It also covers what energy utilities, metering point operators and aggregators should take from it now.

Summary

DIVE stands for Digital Identities as Trust Anchors in the Energy System, a project by the dena Future Energy Lab on behalf of the German Federal Ministry for Economic Affairs. From 2021 to 2024, partners from science, technology and law worked on digital machine identities, and in September 2025 a five-part final report series appeared. The result: the technology is ready for use and can be introduced with little effort. DIVE relies on self-sovereign identity, meaning verifiable credentials that a plant carries itself, and it builds on the existing smart meter gateway infrastructure. Digital identities work like passports in the digital space, confirming a plant's location, availability or ownership. Three use cases were tested: high-resolution guarantees of origin, participation of small plants in flexibility markets, and fast supplier switching at charging stations. What matters is the relationship to the central smart meter PKI under BSI TR-03109-4: the two trust models complement each other, they do not replace one another. The legal frame comes from eIDAS 2.0, Regulation EU 2024/1183, which requires an EU Digital Identity Wallet in every member state by the end of 2026. Governance, interoperability with the SM-PKI and data protection remain open.

What DIVE shows and why it matters

The dena Future Energy Lab has shown with the DIVE project that machines and plants in the energy system can be equipped with verifiable digital identities. And that real market processes can be automated with them, from registration to guarantee of origin. The five-part final report series from September 2025 draws a clear conclusion: the technology is ready for use and can be introduced with little effort.

DIVE stands for Digital Identities as Trust Anchors in the Energy System. The project was run by the dena Future Energy Lab on behalf of the German Federal Ministry for Economic Affairs, with six partners from science, technology and law. Not a lab experiment far from practice, but a real-world testbed with actual plants.

2021-2024
Project duration
practical phase with partners
5 reports
Final series
published September 2025
3
Use cases
tested in practice
6
Project partners
technology, research, law

Why this matters: the power system increasingly relies on millions of small, decentralised plants. Trusting them without being able to check them invites fraud and error. Checking every plant by hand drowns you in effort. Digital identities are the path in between.

The digital identity gap in the energy system

The core problem has a name: the digital identity gap. Millions of plants feed in, store or consume power, but their properties cannot be checked quickly and automatically today. Registration, guarantee of origin, supplier switch, much of it runs manually, slowly and error-prone.

The digital identity gap is the absence of a reliable, automatically verifiable identity for plants in the energy system. Without it, every property, such as location, capacity or ownership, has to be proven laboriously and often by hand.

One look at the scale makes the gap tangible. Germany runs over five million photovoltaic systems, plus home storage, heat pumps and electric cars that generate, store or consume power in real time. They are replacing the old central power plants, for which a handful of central identities was enough.

Each of these plants would need a digital passport. Professor Jens Strüker of the Research Center for Energy Economics puts it plainly: DIVE is a building block to close the identity gap and integrate decentralised producers and consumers without friction. A building block for a cheaper and faster energy transition. That is the real economic lever, not the technology as such.

How DIVE works technically

DIVE builds on self-sovereign identity. Each plant receives a decentralised identifier and carries verifiable credentials about its properties. Authenticity is checked against verifiable registries, without a central authority brokering every single query.

Self-Sovereign Identity (SSI) is an identity model in which a plant carries and controls its identity and credentials itself, instead of querying them from a central authority. The credentials are cryptographically signed and can be checked against a verifiable registry.
Metering technician checking a modern digital electricity meter and a separate communication module in a grey meter cabinet in the utility room of a multi-family building
DIVE replaces no hardware, it builds on it. The smart meter gateway and the communication modules in the meter cabinet provide the data basis on which the digital credentials are created.

What matters is what DIVE does not do: put new hardware in every basement. The project integrates existing components, the smart meter gateway, energy management systems, digital credentials and verifiable registries. The plant owner keeps control over which credentials to share. That is the heart of data sovereignty.

The implementation was carried by a mixed team: Energy Web, the Research Center for Energy Economics, OLI Systems, Fraunhofer FIT, BOTLabs with the KILT protocol, and the law firm Fieldfisher for the legal side. This is about machine identities in the broader sense, the kind that AI agents and other non-human identities also need, only here for plants instead of software.

DIVE and the SM-PKI: two trust models

For trust in metering, Germany has long had an infrastructure, the central smart meter PKI. It and the DIVE approach solve the same question with opposite architectures. This is not a contest. They are two tools for two jobs.

Smart meter PKI (SM-PKI) is the central, hierarchical public key infrastructure under BSI TR-03109-4. It works with X.509 certificates and a chain of root and sub-CA, and it secures the WAN communication between the participants in the smart meter gateway infrastructure.
Diagram with two columns: on the left the central SM-PKI with hierarchical X.509 certificates, root and sub-CA and securing the communication channel, on the right the decentralised DIVE and SSI approach with a decentralised identifier per plant, verifiable credentials and proving the plant properties, with a band below connecting both as complementary
Two trust models in the energy system. The central SM-PKI secures the communication channel, the decentralised SSI credentials prove the properties of the plant. Together they give the full picture.

The SM-PKI is central and regulated. A certificate chain from the BSI-managed root certificate downward ensures that a smart meter gateway really talks to the right counterpart. How this infrastructure scales to millions of devices is a topic of its own. The SSI credentials of DIVE, by contrast, hang on the plant itself and describe what it is and may do.

Feature SM-PKI (central) DIVE / SSI (decentralised)
Architecture Hierarchical, root and sub-CA Decentralised, identifier per plant
Technology X.509 certificates, BSI TR-03109-4 Verifiable credentials, open standards
Job Secures the communication channel Proves the properties of the plant
Control BSI and market actors Plant owner
Key point

The SM-PKI secures the line, the SSI credentials describe the plant. Think both together and you get an energy system that both communicates securely and knows who it is talking to.

The three tested use cases

DIVE did not stop at theory. Three use cases were tested with real plants, each replacing manual approvals with automatic, verifiable identities. They show where the benefit becomes concrete.

First, guarantees of origin. A digital plant identity can prove in fine resolution when and where green power was produced, and so prevents double-marketing. That reaches directly into a field where guarantees of origin under the HkRNDV are already issued today, only more granular and automatic.

Second, flexibility. Small plants should take part in flexibility markets without every registration turning into a mountain of paper. With a verifiable identity, a plant registers itself and proves its capabilities. Exactly this automation is what congestion management under Redispatch 3.0 needs, as ever smaller units join in.

Person charging an electric car at a public charging station in a supermarket car park, holding the charging cable and looking at the display of the grey charging pillar
The third use case: at the charging station the driver picks the electricity supplier freely, because vehicle and contract identify themselves through digital credentials. No fixed provider per station anymore.

Third, the charging station. Today the electricity price at a public station is often tied to the operator. With digital identities the vehicle identifies itself and the driver picks their own supplier, in seconds instead of through a contract process. A small case with a big signal for competition.

eIDAS 2.0 and the EUDI wallet

DIVE does not stand alone. eIDAS 2.0 is creating the legal framework for verifiable digital identities across Europe, and DIVE is deliberately aligned with it. Regulation EU 2024/1183 entered into force on 20 May 2024.

May 2024
eIDAS 2.0 in force
Regulation EU 2024/1183
End 2026
EUDI wallet, all 27
member states must provide
End 2027
Acceptance duty
regulated sectors, energy included

The timeline is tight. By the end of 2026 all member states must provide an EU Digital Identity Wallet. Regulated sectors, including the energy industry, must then accept the wallet as an authentication method by the end of 2027. eIDAS 2.0 rests on the same W3C verifiable credentials and selective disclosure that DIVE uses.

For machine identities, though, binding governance is still missing. The legal part of the report series, DIVE 04, makes concrete proposals for a decentralised identity structure. The wallet for people is coming, the rules for the wallet of plants are still being written.

Challenges and risks

As convincing as the testbed is, nothing is rolled out yet. DIVE was a real-world lab, not a production system. Four points decide whether the proof becomes routine.

Governance first. Who operates the verifiable registries, who supervises them, under what rules? As long as that stays open, the institutional anchor is missing.

The trickiest point is interoperability with the regulated SM-PKI. A decentralised SSI model and a central, BSI-run certificate world have to mesh without softening the security requirements of metering. That is technically and legally demanding, and not yet solved.

Then there is data protection. Plant credentials can be personal, a home battery belongs to a household. Selective disclosure helps, but the principle of data minimisation under the GDPR has to be built in from the start. And finally, maturity: standardisation and market uptake take time. A successful testbed is not yet a nationwide standard.

What companies should do now

For energy utilities, metering point operators, aggregators and industry, early engagement pays off, without dropping existing obligations. Four steps keep the start manageable.

  1. Read and place the DIVE reports

    The five-part report series is the best available template. It assesses technology, use cases and law. Mirror your own identity architecture against it and you quickly see where your processes stand today.

  2. Keep meeting SM-PKI, test SSI as a complement

    The obligations from the smart meter PKI remain. SSI is not a replacement, it is a complementary option. Keeping both models in view prevents duplicate work later.

  3. Prepare for EUDI wallet acceptance by 2027

    The end-2027 deadline is set. Clarifying now which processes need a wallet connection, for guarantees of origin or flexibility, saves scramble later.

  4. Pick a pilot process with high automation potential

    Start where a lot is checked manually today. One process, cleanly automated, gives you the solid business case for the next.

Key point

DIVE has shown that digital identities for plants are ready for practice. Treat them as a complement to the SM-PKI, check your own architecture early and work toward the 2027 EUDI wallet deadline, and you are prepared when the proof becomes routine.

Further reading

Frequently asked questions

What is the dena DIVE project? +

DIVE stands for Digital Identities as Trust Anchors in the Energy System. The project by the dena Future Energy Lab ran with partners from science, technology and law and published a five-part final report series in September 2025. It shows that machines and plants can be equipped with digital, verifiable identities and that real market processes can be automated with them.

What are self-sovereign identities in the energy system? +

Self-sovereign identity (SSI) means a plant carries its identity and properties itself, instead of having to query them from a central authority. Each plant receives a decentralised identifier and carries verifiable credentials about its location, availability or ownership. Authenticity is checked against verifiable registries. The plant owner decides which credentials to share.

How do DIVE and the SM-PKI differ? +

The smart meter PKI under BSI TR-03109-4 is a central, hierarchical public key infrastructure using X.509 certificates. It secures the WAN communication of the smart meter gateways. DIVE relies on decentralised, verifiable credentials that the plant carries itself. The two do not exclude each other. The SM-PKI secures the communication channel, the SSI credentials prove the properties of the plant.

Which use cases did DIVE test? +

DIVE tested three use cases: high-resolution guarantees of origin that prevent double-marketing of green power, participation of small plants in flexibility markets, and fast switching of the electricity supplier at public charging stations. All three replace manual approvals with automatic, verifiable identities.

What does eIDAS 2.0 have to do with digital identities in the energy system? +

The EU regulation eIDAS 2.0 (Regulation EU 2024/1183) creates the legal framework for verifiable digital identities in Europe. By the end of 2026 all member states must provide an EU Digital Identity Wallet, and regulated sectors such as energy must accept it by the end of 2027. DIVE is deliberately aligned with this wallet and uses the same verifiable credentials.