Power Engineering 
K-JIANG
NameDescriptionContent
Current Location:

GE 889 Generator Protection System Security Overview

From:GE | author:Mr.Chen | Time :2025-01-17 | 294 view: | 🔊 Click to read aloud ❚❚ | Share:

The following security features are available:

BASIC SECURITY

The basic security feature is present in the default offering of the 889 relay. The

889 introduces the notion of roles for different levels of authority. Roles are used as login

names with associated passwords stored on the device. The following roles are available

at present: Administrator, Operator, Factory and Observer, with a fixed permission

structure for each one. Note that the Factory role is not available for users, but strictly used

in the manufacturing process.

The 889 can still use the Setpoint access switch feature, but enabling the feature can be

done only by an Administrator. Setpoint access is controlled by a keyed switch to offer

some minimal notion of security.

CYBERSENTRY

The CyberSentry Embedded Security feature is a software option that provides advanced

security services. When the software option is purchased, the Basic Security is

automatically disabled.

CyberSentry provides security through the following features:

• An Authentication, Authorization, Accounting (AAA) Remote Authentication Dial-In

User Service (RADIUS) client that is centrally managed, enables user attribution, and

uses secure standards based strong cryptography for authentication and credential

protection.

• A Role-Based Access Control (RBAC) system that provides a permission model that

allows access to 889 device operations and configurations based on specific roles

and individual user accounts configured on the AAA server. At present the defined

roles are: Administrator, Operator and Observer.

• Strong encryption of all access and configuration network messages between the

EnerVista software and 889 devices using the Secure Shell (SSH) protocol, the

Advanced Encryption Standard (AES), and 128-bit keys in Galois Counter Mode (GCM)

as specified in the U.S. National Security Agency Suite B extension for SSH and

approved by the National Institute of Standards and Technology (NIST) FIPS-140-2

standards for cryptographic systems.

• Security event reporting through the Syslog protocol for supporting Security

Information Event Management (SIEM) systems for centralized cyber security

monitoring.

There are two types of authentication supported by CyberSentry that can be used to

access the 889 device:

• Device Authentication – in which case the authentication is performed on the

889 device itself, using the predefined roles as users (No RADIUS involvement).

– 889 authentication using local roles may be done either from the front panel or

through EnerVista.

• Server Authentication - in which case the authentication is done on a RADIUS server,

using individual user accounts defined on the server. When the user accounts are

created, they are assigned to one of the predefined roles recognized by the 889

– 889 authentication using RADIUS server may be done only through EnerVista.

FASTPATH: WiFi and USB do not currently support CyberSentry security. For this reason WiFi is

disabled by default if the CyberSentry option is purchased. WiFi can be enabled, but be

aware that doing so violates the security and compliance model that CyberSentry is

supposed to provide.

Enervista Viewpoint Monitor does not currently support CyberSentry security.

With the CyberSentry security option, many communication settings cannot be changed

remotely. All communication settings can still be changed through the relay front panel.

  • Beckhoff EL2622-0010 EtherCAT Terminal, 2-channel relay output
  • Beckhoff EL2622 | EtherCAT Terminal, 2-channel relay output
  • Beckhoff EL2612 | EtherCAT Terminal, 2-channel relay output, 125 V AC, 30 V DC, 0.5 A AC, 2 A DC
  • Beckhoff EL2602-0010 EtherCAT Terminal, 2-channel relay output
  • Beckhoff EL2602 | EtherCAT Terminal, 2-channel relay output, 230 V AC, 30 V DC, 5 A
  • Beckhoff EL2596-0010 | EtherCAT Terminal, 1-channel LED output, 0…48 V DC, 3 A
  • Beckhoff EL2596 | EtherCAT Terminal, 1-channel LED output, 0…24 V DC, 3 A
  • Beckhoff EL2595 | EtherCAT Terminal, 1-channel LED output, 2…48 V DC, 0.7 A
  • Beckhoff EL2574 | EtherCAT Terminal, 4-channel LED output, pixel LED
  • Beckhoff EL2564-0010 | EtherCAT Terminal, 4-channel LED output
  • Beckhoff EL2564 | EtherCAT Terminal, 4-channel LED output
  • Beckhoff EL2535-0100 | EtherCAT Terminal, 2-channel PWM output
  • Beckhoff EL2535-0050 | EtherCAT Terminal, 2-channel PWM output
  • Beckhoff EL2535-0005 | EtherCAT Terminal, 2-channel PWM output, 24 V DC, 5 A, current-controlled
  • Beckhoff EL2535-0002 | EtherCAT Terminal, 2-channel PWM output, 24 V DC, 2 A, current-controlled
  • Beckhoff EL2522 | EtherCAT Terminal, 2-channel pulse train output
  • KEBA KEVIEW V2 341/C-4400 HMI TOUCHSCREEN UNIT
  • KEBA KEMRO K2-200 BL250/A BL 250/A Bus Coupler Module
  • Keba E-CON-14 Operator Interface Panel
  • KEBA CP 255/W Plc Module
  • KEBA CU 212 ZENTRALBAUGRUPPE
  • KEBA CU211/0 25817 Ind 06
  • KEBA RS 091 POWER SUPPLY MODULE
  • KEBA E-SP-CCEC/22180 Panel
  • KEBA E-CPU-186B Control Circuit Board D1633C
  • Keba Kemro K2-200 Control CP 255/X, Part. 072076
  • KEBA analog module, AR281, AR 281
  • KEBA BL250/B Bus link module
  • KEBA Kemro K2-400, DO 470/A, Part No. 054945
  • KEBA HAITAN SA900 Operator Panel
  • KEBA DO 321 module DO 321/B
  • KEBA KeTop C20t-t00-Ar0-KMT Tech Pendant by Karl Mayer
  • KEBA HT401/BENNINGER/5M/55268 TEACH PENDANT HT401BENNINGER/5M/55268
  • KEBA AR 281 ANALOGE INPUT BOARD
  • Engel Keba EC100 PLC Rack with PS244 CU211 PD242 AR181 TT081 DO321 DI325 (19821)
  • KEBA CU 313 Central Unit CU 313/C-SI/63036 Card 128MB
  • KEBA TM-240/A PLC MODULE
  • Keba D1633C E-Cpu-186B Cpu Control Circuit Board W/ D1630D
  • Keba Engel E-CON-CC100/A/22178 HMI Operator Control Display Panel
  • KEBA K2-200 CP 242/B controller module
  • KEBA KEVIEW V2 341/C-4400 HMI TOUCHSCREEN UNIT 84494 24 VDC
  • KEBA E-8-THERMO 1770B-1 Thermocouple circuit board
  • KEBA 3HAC12929-1 TEACH PENDANT
  • Keba KETOP C50 R/73810/06 KEBA PANEL OPERATOR DISPLAY
  • KEBA Kemro K2-400 DO 470/B 059707 Module
  • LENZE c300 controller
  • LENZE p500 controller
  • LENZE p300 controller
  • LENZE v200-P monitor
  • LENZE v200-C monitor
  • LENZE v800-P industrial PC
  • LENZE v800-C industrial PC
  • LENZE EtherCAT-CAN gateway x750
  • LENZE V450 Web Panel
  • LENZE v430 web panel
  • Beckhoff EL2521-0024 | EtherCAT Terminal, 1-channel pulse train output
  • Beckhoff EL2521 | EtherCAT Terminal, 1-channel pulse train output, incr. enc. simulation, RS422, 50 mA
  • Beckhoff EL2502-0010 | EtherCAT Terminal, 2-channel PWM output
  • Beckhoff EL2502 | EtherCAT Terminal, 2-channel PWM output, 24 V DC, 0.5 A
  • DEIF MVR-T216 Transformer Differential Protection
  • DEIF MVR-T215 Transformer Protection
  • DEIF MVR-M257 Motor Protection
  • DEIF MVR-M255 Motor Protection
  • DEIF MVR-M215 Motor Protection
  • DEIF MVR-M210 Motor Protection
  • DEIF MVR-G257 Generator Differential Protection
  • DEIF MVR-G215 Generator Protection
  • DEIF MVR-F255 Directional Feeder Protection
  • DEIF MVR-F201 Basic Feeder Protectio
  • DEIF LMR-122D Loss of mains relay
  • DEIF LMR-111D Loss of mains relay
  • DEIF APU-4 Advanced G59 and G99 protection unit
  • SAACKE FSC-01V3.02/V3.00 Industrial Combustion Controller
  • GE Multilin 750-P5-G5-S5-HI-A20-G 750 Management Relay
  • GE Multilin 750-P5-G5-D5-HI-A20-R 750/760 Feeder Mgmt Relay Series
  • GE Multilin 750-P5-G5-D5-HI-A20-G Management Relay
  • GE Multilin 750-P5-G1-D5-HI-A20-R Multilin 1A Zero Sequence Current Inputs
  • GE Multilin 750-P1-G1-S1-HI-A20-R-T-H Feeder Management Relays
  • GE Multilin 750-P1-G1-S1-HI-A20-R Feeder Management Relays
  • GE Multilin 750-P1-G1-D1-HI-A20-R Base Unit 750 Relay
  • GE Multilin 239-RTD-AN-H motor protection relay
  • GE Multilin 489-P5-HI-A20-T-H Generator Management Relay for 489 Series
  • GE Multilin 489-P5-HI-A20-T Generator Management Relay for 489 Series
  • GE Multilin 489-P5-HI-A20-E-H Relay Motor Management
  • GE Multilin 489-P1-LO-A20 489 Motor Management Relay Base Unit
  • GE Multilin SR469-P5-LO-A20-T Motor Management Relay
  • GE Relay from GE Grid Solutions SR469-P5-LO-A20-E
  • GE Multilin SR469-P5-LO-A20 Motor Management Relay with Case
  • GE Multilin SR469-P5-HI-A20-T 469 Series Relay
  • GE Multilin SR469-P1-HI-A1-E-H 469 Series Relay
  • GE Multilin SR469-P1-H1-A1-E 469 Series Relay
  • GE Multilin 469-P5-LO-A20-T Phase Current Input 5 A Phase CT Secondaries
  • GE Multilin 469-P5-LO-A20-E LO Control Power with 4-20mA Analog Outputs
  • GE Multilin 469-P5-LO-A20 Motor Management Relay
  • GE Multilin 469-P5-HI-A20-E-H Motor Management Relay
  • GE Multilin 469-P5-HI-A20 469 Motor Management Relay
  • GE Multilin 469-P1-HI-A1-E-H 469 Base Unit Motor Management Relay
  • GE Multilin 469-P1-H1-A1-E 469 Motor Mgmt Relay
  • Beckhoff ED2504 | EtherCAT Terminal, 4-channel PWM output
  • Beckhoff EL2262 | EtherCAT Terminal, 2-channel digital output
  • Beckhoff EL2258 | EtherCAT Terminal, 8-channel digital output
  • Beckhoff EL2252 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 0.5 A, timestamp
  • Beckhoff EL2212 | EtherCAT Terminal, 2-channel digital output
  • Beckhoff EL2202-0100 | EtherCAT Terminal, 2-channel digital output
  • Beckhoff EL2202 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 0.5 A, push-pull, tristate
  • Beckhoff EL2124 | EtherCAT Terminal, 4-channel digital output, 5 V DC, 20 mA
  • Beckhoff EL2088 | EtherCAT Terminal, 8-channel digital output, 24 V DC, 0.5 A, ground switching
  • Beckhoff EL2084 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 0.5 A, ground switching
  • Beckhoff EL2068 | EtherCAT Terminal, 8-channel digital output, 24 V DC, 0.5 A, with channel diagnostics
  • Beckhoff EL2044 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 2 A, with extended diagnostics
  • Beckhoff EL2042 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 2 x 4 A/1 x 8 A
  • Beckhoff ED2034 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 2 A, push-in, with channel diagnostics
  • Beckhoff EL2034 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 2 A, with diagnostics
  • Beckhoff ED2032 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 2 A, push-in, with channel diagnostics
  • Beckhoff EL2032 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 2 A, with diagnostics
  • Beckhoff EL2024-0010 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 2 A
  • Beckhoff EL2024 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 2 A
  • Beckhoff EL2022 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 2 A
  • Beckhoff EL2014 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 0.5 A, with extended diagnostics
  • Beckhoff ELX2008 | EtherCAT Terminal, 8-channel digital output, 24 V DC, 30 mA, Ex i
  • Beckhoff ED2008 | EtherCAT Terminal, 8-channel digital output, 24 V DC, 0.5 A, push-in
  • Beckhoff EL2008 | EtherCAT Terminal, 8-channel digital output, 24 V DC, 0.5 A
  • Beckhoff EL2004 | EtherCAT Terminal, 4-channel digital output, 24 V DC, 0.5 A
  • Beckhoff ELX2002 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 45 mA, Ex i
  • Beckhoff EL2002 | EtherCAT Terminal, 2-channel digital output, 24 V DC, 0.5 A
  • TMEIC TM21-TG Series 2-Pole Generator
  • TMEIC TM21-TG Series 4-Pole Generator for Turbine Drive
  • TMEIC Air-Cooled Type Synchronous Generators