Power Engineering 
K-JIANG
NameDescriptionContent
Current Location:

GE 889 Generator Protection System Security Overview

From:GE | author:Mr.Chen | Time :2025-01-17 | 225 view: | Share:

The following security features are available:

BASIC SECURITY

The basic security feature is present in the default offering of the 889 relay. The

889 introduces the notion of roles for different levels of authority. Roles are used as login

names with associated passwords stored on the device. The following roles are available

at present: Administrator, Operator, Factory and Observer, with a fixed permission

structure for each one. Note that the Factory role is not available for users, but strictly used

in the manufacturing process.

The 889 can still use the Setpoint access switch feature, but enabling the feature can be

done only by an Administrator. Setpoint access is controlled by a keyed switch to offer

some minimal notion of security.

CYBERSENTRY

The CyberSentry Embedded Security feature is a software option that provides advanced

security services. When the software option is purchased, the Basic Security is

automatically disabled.

CyberSentry provides security through the following features:

• An Authentication, Authorization, Accounting (AAA) Remote Authentication Dial-In

User Service (RADIUS) client that is centrally managed, enables user attribution, and

uses secure standards based strong cryptography for authentication and credential

protection.

• A Role-Based Access Control (RBAC) system that provides a permission model that

allows access to 889 device operations and configurations based on specific roles

and individual user accounts configured on the AAA server. At present the defined

roles are: Administrator, Operator and Observer.

• Strong encryption of all access and configuration network messages between the

EnerVista software and 889 devices using the Secure Shell (SSH) protocol, the

Advanced Encryption Standard (AES), and 128-bit keys in Galois Counter Mode (GCM)

as specified in the U.S. National Security Agency Suite B extension for SSH and

approved by the National Institute of Standards and Technology (NIST) FIPS-140-2

standards for cryptographic systems.

• Security event reporting through the Syslog protocol for supporting Security

Information Event Management (SIEM) systems for centralized cyber security

monitoring.

There are two types of authentication supported by CyberSentry that can be used to

access the 889 device:

• Device Authentication – in which case the authentication is performed on the

889 device itself, using the predefined roles as users (No RADIUS involvement).

– 889 authentication using local roles may be done either from the front panel or

through EnerVista.

• Server Authentication - in which case the authentication is done on a RADIUS server,

using individual user accounts defined on the server. When the user accounts are

created, they are assigned to one of the predefined roles recognized by the 889

– 889 authentication using RADIUS server may be done only through EnerVista.

FASTPATH: WiFi and USB do not currently support CyberSentry security. For this reason WiFi is

disabled by default if the CyberSentry option is purchased. WiFi can be enabled, but be

aware that doing so violates the security and compliance model that CyberSentry is

supposed to provide.

Enervista Viewpoint Monitor does not currently support CyberSentry security.

With the CyberSentry security option, many communication settings cannot be changed

remotely. All communication settings can still be changed through the relay front panel.

  • Kollmorgen AKT2G-AC-FAN-001 fan cartridge
  • Kollmorgen AKT-AN-820-000 8-Channel Analog Input Terminal
  • Kollmorgen 4-Channel Analog Input Terminal (AKT-AN-420-000)
  • METSO D201379 PC Board PLC & ADD-ON Board
  • Metso PDP403 Distributed Processing Unit
  • METSO D201505 / D201463 network controller
  • METSO ntel D33025 Motherboard
  • METSO ACN MR D201463 DCS Controller
  • METSO ACN MR D201505R DCS Controller
  • METSO ACN MR D201380 DCS Controller
  • METSO ACN MR D201139 DCS Controller
  • METSO ACN MR D202214 DCS Controller
  • METSO ACN MR D202275 DCS Controller
  • Metso D201376 Industrial Analog Input Module
  • Metso D201134 Process Control Module
  • Metso d200175 ver: 2.04 personality module
  • Metso D200137 ACN RT Node with D200175
  • METSO ACN CS CONTROLLER D201925 VER 2.15
  • METSO D100644 Electrical Automation Module
  • Kollmorgen CB06560 PRD-B040SAIB-62 Control Module
  • Servostar 310 Kollmorgen Servo Amplifier
  • Kollmorgen S20330-SRS Digital AC Servo Drives
  • Kollmorgen S22460-SRS Digital AC Servo Drives
  • Kollmorgen S70602-NANANA S700 Servo Driver
  • BJRL-20012-110001 Kollmorgen Goldline Smart Drives
  • Kollmorgen SAM-DA-400-07B-P4N-F SAM Servo Amplifiers
  • Kollmorgen CP320260 Servo Drive
  • Kollmorgen S72402-NANANA - AC servo drives
  • Kollmorgen E33NRHA-LNN-NS-00 Precision Motion Control Module
  • Kollmorgen S20360-SRS Servo Drive
  • Kollmorgen E33NCHA-LNN-NS-00 Precision Motion Control Module
  • Kollmorgen CR06200-000000 Servo Drive
  • Kollmorgen DIGIFAS7201 Digital Industrial Servo
  • CB06251 Kollmorgen Servo Drive
  • Kongsberg TRX32 FILTER (303067B) | Elektro Marine
  • Kongsberg MRU-M-MB3 | Motion Reference Unit
  • Kongsberg TRX32 303088 | eight-channel I/O module
  • Kongsberg MRU2 Motion Reference Unit
  • KONGSBERG MRU-M-SU1 Industrial Measurement Unit
  • Kongsberg RMP201-8 Versatile Remote Input/output System
  • Kongsberg dPSC 8100183 Dual Process Segment Controller
  • YOKOGAWA YS1700-100/A06/A31 Programmable indicating controller
  • YOKOGAWA YS1700-100/A06/A31 Programmable Indicating Controller
  • KS9-5*A | Yokogawa | MXL DSC Cabl
  • KS8-5*A | Yokogawa | MXL DSC Cabl
  • KS2-05*A | Yokogawa | MXL DSC Cabl
  • YOKOGAWA PW482-10 S2 Power Supply Module
  • Yokogawa SCP451-11 S1 Processor Module
  • YOKOGAWA SR1030B62 High-Frequency Module
  • Yokogawa CP451-50 S2 Processor Module
  • YOKOGAWA AAI143-H50 Analog I/O Modules
  • YOKOGAWA AMM42 2-Wire Transmitter Input Multiplexer Module
  • SDV144-S63 | Yokogawa | Digital Input Module
  • Yokogawa AIP830-111 Operation Keyboard for Single loop Operation
  • Yokogawa S9361DH00 Control Module / Terminal Board
  • Yokogawa ATK4A-00/S1 KS Cable Interface Adapter
  • YOKOGAWA PW701 Power Supply Module
  • YOKOGAWA Dual-Redundant V-Network Router AVR10D-A22010
  • YOKOGAWA PW441-10 Communication Module
  • YOKOGAWA VI451-10 S2 Communication Module
  • Yokogawa VC401-10 Coupler Modules
  • Yokogawa ALP121 PROFIBUS-DP Communication Module
  • Yokogawa NFAI841-S00/A4S00 Analog Input/Output Module
  • YOKOGAWA AIP591 Transceiver Control Module
  • YOKOGAWA AIP578 Transceiver Control Module
  • YOKOGAWA PW501 Power Supply Unit Brand
  • Yokogawa YNT511D-V42 Bus Repeater Module
  • YOKOGAWA AIP171 Transceiver Control Module
  • YOKOGAWA VI702 Vnet/IP Interface Card
  • 2302-32-VLE-2 YOKOGAWA Data Acquisition Module
  • Yokogawa ATK4A-00 16-Channel KS Cable Interface Adapter
  • YOKOGAWA ALR121-S00 Serial Communication Module
  • CP461-50 | Yokogawa | Processor Module
  • Yokogawa AIP121-S00 Control Module
  • YOKOGAWA UR1800 Wireless Communication Module
  • Yokogawa| LC82 *A Redundant RL-Bus Interface Card
  • YOKOGAWA ST6 Industrial Control Module
  • YOKOGAWA ANR10D ER Bus Node Unit
  • YOKOGAWA SDV144-S13 S1 Digital Input Module
  • YOKOGAWA NFAI143-H00 analog I/O module
  • YOKOGAWA EB501 Bus Interface Module
  • Yokogawa CP451-10-S2 High-Performance Processor Module
  • YOKOGAWA V0/E1/TCAM/L08 High-Precision Temperature Controller
  • YOKOGAWA VO/E2/TCDM24/L8 High-Precision Temperature Controller
  • YOKOGAWA 16137-119 Process Control Module
  • YOKOGAWA 16114-500 I/O Module for Process Control Systems
  • Yokogawa PSCDM024DCBAN - Critical Discrete Module
  • YOKOGAWA 16137-151 Digital Input Module
  • YOKOGAWA 16137-188 Digital Input Module
  • YOKOGAWA 16137-222 Digital Input Module
  • YOKOGAWA 16137-223 Digital Input Module
  • YOKOGAWA 16137-153 Digital Input Module
  • Watlow SUB21/IV10 0-10 V input adaptor
  • Watlow ITOOLS/NONE/USB U SB configuration kit
  • Watlow CTR500000/000 100 A Current transformer
  • Watlow CTR400000/000 50 A Current transformer
  • Watlow CTR200000/000 25 A Current transformer
  • Watlow CTR100000/000 10 A Current transformer
  • Watlow SUB35/ACCESS/249R.1 2.49R Precision resistor
  • Vibro-meter vmf-RLC16-V111 200-570-101-015 200-570-000-111 Relay Card
  • Vibro-meter vmf-IOC4T 200560-101-017 200-560-000-111 I/O module
  • vmf cpum vmf-cmc16 200-530-111-013 200-530-100-014 Vibro-meter Monitoring system Modulee
  • Vibro-meter 200-595-045-114 | CPUM | Vibration Processor Module
  • Vibro-meter SIM-275A 200-582-500-013 state-of-the-art protection and monitoring module
  • Vibro-meter VM600 RLC16 200-570-000-111 200-570-101-015 Relay Card
  • Vibro-meter VM600 RPS6U 200-582-600-013 cutting-edge monitoring module
  • Vibro-meter VM600 CMC16 200-530-025-014 200-530-111-013 input/output card
  • Vibro-meter 200-570-000-014 200-570-101-013 VM600 Protection Module
  • Vibro-meter 620-002-000-113 620-003-111-112 VM600 XIO16T input/output card
  • Vibro-meter 600-003 620-001-001-116 VM600 XMV16 input/output card
  • Vibro-Meter 444-680-000-511 Level Detector & Proximity Sensor
  • Vibro-meter VM600 MPC4 200-510-111-034 200-510-070-113 Module
  • Vibro-Meter IOCN 200-566-000-113 | I/O Communication Node
  • Vibro-meter VM600 IOC16T 200-565-000-013 / 200-565-101-013 Industrial Control Module
  • Vibro-Meter 200-566-000-012 VM600 IOCN Communication board
  • Vibro-meter 200-560-000-113 VM600 power supplies Module
  • VIBRO 573-935-202C - High-Accuracy Interface Module
  • Vibro-meter 200-595-002-011 Modular Safety Relays
  • 200-560-000-016 VIBRO I/O Module
  • YOKOGAWA 8662570000 Terminal Module
  • YOKOGAWA 8596020000 Terminal Module
  • YOKOGAWA 8662560000 Terminal Module
  • YOKOGAWA PSCAMAAN | Process Control Analog Input Module
  • YOKOGAWA DR1030B60 High-Precision Pressure Transmitter
  • Yokogawa adv551 Digital I/O Modules
  • Yokogawa aai543 Analog I/O Modules (for FIO)
  • YOKOGAWA LR 4220E Level Controller Module
  • Yokogawa SR1008B62 Signal Relay Module