dena DIVE: digital identities as trust anchors in the energy system
The dena project DIVE equips machines and plants in the energy system with digital, verifiable identities. This article explains the principle of self-sovereign identity and verifiable credentials, the relationship to the established smart meter PKI, the three tested use cases and the framework set by eIDAS 2.0 and the EUDI wallet. It also covers what energy utilities, metering point operators and aggregators should take from it now.
DIVE stands for Digital Identities as Trust Anchors in the Energy System, a project by the dena Future Energy Lab on behalf of the German Federal Ministry for Economic Affairs. From 2021 to 2024, partners from science, technology and law worked on digital machine identities, and in September 2025 a five-part final report series appeared. The result: the technology is ready for use and can be introduced with little effort. DIVE relies on self-sovereign identity, meaning verifiable credentials that a plant carries itself, and it builds on the existing smart meter gateway infrastructure. Digital identities work like passports in the digital space, confirming a plant's location, availability or ownership. Three use cases were tested: high-resolution guarantees of origin, participation of small plants in flexibility markets, and fast supplier switching at charging stations. What matters is the relationship to the central smart meter PKI under BSI TR-03109-4: the two trust models complement each other, they do not replace one another. The legal frame comes from eIDAS 2.0, Regulation EU 2024/1183, which requires an EU Digital Identity Wallet in every member state by the end of 2026. Governance, interoperability with the SM-PKI and data protection remain open.
What DIVE shows and why it matters
The dena Future Energy Lab has shown with the DIVE project that machines and plants in the energy system can be equipped with verifiable digital identities. And that real market processes can be automated with them, from registration to guarantee of origin. The five-part final report series from September 2025 draws a clear conclusion: the technology is ready for use and can be introduced with little effort.
DIVE stands for Digital Identities as Trust Anchors in the Energy System. The project was run by the dena Future Energy Lab on behalf of the German Federal Ministry for Economic Affairs, with six partners from science, technology and law. Not a lab experiment far from practice, but a real-world testbed with actual plants.
Why this matters: the power system increasingly relies on millions of small, decentralised plants. Trusting them without being able to check them invites fraud and error. Checking every plant by hand drowns you in effort. Digital identities are the path in between.
The digital identity gap in the energy system
The core problem has a name: the digital identity gap. Millions of plants feed in, store or consume power, but their properties cannot be checked quickly and automatically today. Registration, guarantee of origin, supplier switch, much of it runs manually, slowly and error-prone.
One look at the scale makes the gap tangible. Germany runs over five million photovoltaic systems, plus home storage, heat pumps and electric cars that generate, store or consume power in real time. They are replacing the old central power plants, for which a handful of central identities was enough.
Each of these plants would need a digital passport. Professor Jens Strüker of the Research Center for Energy Economics puts it plainly: DIVE is a building block to close the identity gap and integrate decentralised producers and consumers without friction. A building block for a cheaper and faster energy transition. That is the real economic lever, not the technology as such.
How DIVE works technically
DIVE builds on self-sovereign identity. Each plant receives a decentralised identifier and carries verifiable credentials about its properties. Authenticity is checked against verifiable registries, without a central authority brokering every single query.
What matters is what DIVE does not do: put new hardware in every basement. The project integrates existing components, the smart meter gateway, energy management systems, digital credentials and verifiable registries. The plant owner keeps control over which credentials to share. That is the heart of data sovereignty.
The implementation was carried by a mixed team: Energy Web, the Research Center for Energy Economics, OLI Systems, Fraunhofer FIT, BOTLabs with the KILT protocol, and the law firm Fieldfisher for the legal side. This is about machine identities in the broader sense, the kind that AI agents and other non-human identities also need, only here for plants instead of software.
DIVE and the SM-PKI: two trust models
For trust in metering, Germany has long had an infrastructure, the central smart meter PKI. It and the DIVE approach solve the same question with opposite architectures. This is not a contest. They are two tools for two jobs.
The SM-PKI is central and regulated. A certificate chain from the BSI-managed root certificate downward ensures that a smart meter gateway really talks to the right counterpart. How this infrastructure scales to millions of devices is a topic of its own. The SSI credentials of DIVE, by contrast, hang on the plant itself and describe what it is and may do.
| Feature | SM-PKI (central) | DIVE / SSI (decentralised) |
|---|---|---|
| Architecture | Hierarchical, root and sub-CA | Decentralised, identifier per plant |
| Technology | X.509 certificates, BSI TR-03109-4 | Verifiable credentials, open standards |
| Job | Secures the communication channel | Proves the properties of the plant |
| Control | BSI and market actors | Plant owner |
The SM-PKI secures the line, the SSI credentials describe the plant. Think both together and you get an energy system that both communicates securely and knows who it is talking to.
The three tested use cases
DIVE did not stop at theory. Three use cases were tested with real plants, each replacing manual approvals with automatic, verifiable identities. They show where the benefit becomes concrete.
First, guarantees of origin. A digital plant identity can prove in fine resolution when and where green power was produced, and so prevents double-marketing. That reaches directly into a field where guarantees of origin under the HkRNDV are already issued today, only more granular and automatic.
Second, flexibility. Small plants should take part in flexibility markets without every registration turning into a mountain of paper. With a verifiable identity, a plant registers itself and proves its capabilities. Exactly this automation is what congestion management under Redispatch 3.0 needs, as ever smaller units join in.
Third, the charging station. Today the electricity price at a public station is often tied to the operator. With digital identities the vehicle identifies itself and the driver picks their own supplier, in seconds instead of through a contract process. A small case with a big signal for competition.
eIDAS 2.0 and the EUDI wallet
DIVE does not stand alone. eIDAS 2.0 is creating the legal framework for verifiable digital identities across Europe, and DIVE is deliberately aligned with it. Regulation EU 2024/1183 entered into force on 20 May 2024.
The timeline is tight. By the end of 2026 all member states must provide an EU Digital Identity Wallet. Regulated sectors, including the energy industry, must then accept the wallet as an authentication method by the end of 2027. eIDAS 2.0 rests on the same W3C verifiable credentials and selective disclosure that DIVE uses.
For machine identities, though, binding governance is still missing. The legal part of the report series, DIVE 04, makes concrete proposals for a decentralised identity structure. The wallet for people is coming, the rules for the wallet of plants are still being written.
Challenges and risks
As convincing as the testbed is, nothing is rolled out yet. DIVE was a real-world lab, not a production system. Four points decide whether the proof becomes routine.
Governance first. Who operates the verifiable registries, who supervises them, under what rules? As long as that stays open, the institutional anchor is missing.
The trickiest point is interoperability with the regulated SM-PKI. A decentralised SSI model and a central, BSI-run certificate world have to mesh without softening the security requirements of metering. That is technically and legally demanding, and not yet solved.
Then there is data protection. Plant credentials can be personal, a home battery belongs to a household. Selective disclosure helps, but the principle of data minimisation under the GDPR has to be built in from the start. And finally, maturity: standardisation and market uptake take time. A successful testbed is not yet a nationwide standard.
What companies should do now
For energy utilities, metering point operators, aggregators and industry, early engagement pays off, without dropping existing obligations. Four steps keep the start manageable.
-
Read and place the DIVE reports
The five-part report series is the best available template. It assesses technology, use cases and law. Mirror your own identity architecture against it and you quickly see where your processes stand today.
-
Keep meeting SM-PKI, test SSI as a complement
The obligations from the smart meter PKI remain. SSI is not a replacement, it is a complementary option. Keeping both models in view prevents duplicate work later.
-
Prepare for EUDI wallet acceptance by 2027
The end-2027 deadline is set. Clarifying now which processes need a wallet connection, for guarantees of origin or flexibility, saves scramble later.
-
Pick a pilot process with high automation potential
Start where a lot is checked manually today. One process, cleanly automated, gives you the solid business case for the next.
DIVE has shown that digital identities for plants are ready for practice. Treat them as a complement to the SM-PKI, check your own architecture early and work toward the 2027 EUDI wallet deadline, and you are prepared when the proof becomes routine.
Further reading
Frequently asked questions
DIVE stands for Digital Identities as Trust Anchors in the Energy System. The project by the dena Future Energy Lab ran with partners from science, technology and law and published a five-part final report series in September 2025. It shows that machines and plants can be equipped with digital, verifiable identities and that real market processes can be automated with them.
Self-sovereign identity (SSI) means a plant carries its identity and properties itself, instead of having to query them from a central authority. Each plant receives a decentralised identifier and carries verifiable credentials about its location, availability or ownership. Authenticity is checked against verifiable registries. The plant owner decides which credentials to share.
The smart meter PKI under BSI TR-03109-4 is a central, hierarchical public key infrastructure using X.509 certificates. It secures the WAN communication of the smart meter gateways. DIVE relies on decentralised, verifiable credentials that the plant carries itself. The two do not exclude each other. The SM-PKI secures the communication channel, the SSI credentials prove the properties of the plant.
DIVE tested three use cases: high-resolution guarantees of origin that prevent double-marketing of green power, participation of small plants in flexibility markets, and fast switching of the electricity supplier at public charging stations. All three replace manual approvals with automatic, verifiable identities.
The EU regulation eIDAS 2.0 (Regulation EU 2024/1183) creates the legal framework for verifiable digital identities in Europe. By the end of 2026 all member states must provide an EU Digital Identity Wallet, and regulated sectors such as energy must accept it by the end of 2027. DIVE is deliberately aligned with this wallet and uses the same verifiable credentials.