Power Engineering 
K-JIANG
NameDescriptionContent
Current Location:

GE 889 Generator Protection System Security Overview

From:GE | author:Mr.Chen | Time :2025-01-17 | 112 view: | Share:

The following security features are available:

BASIC SECURITY

The basic security feature is present in the default offering of the 889 relay. The

889 introduces the notion of roles for different levels of authority. Roles are used as login

names with associated passwords stored on the device. The following roles are available

at present: Administrator, Operator, Factory and Observer, with a fixed permission

structure for each one. Note that the Factory role is not available for users, but strictly used

in the manufacturing process.

The 889 can still use the Setpoint access switch feature, but enabling the feature can be

done only by an Administrator. Setpoint access is controlled by a keyed switch to offer

some minimal notion of security.

CYBERSENTRY

The CyberSentry Embedded Security feature is a software option that provides advanced

security services. When the software option is purchased, the Basic Security is

automatically disabled.

CyberSentry provides security through the following features:

• An Authentication, Authorization, Accounting (AAA) Remote Authentication Dial-In

User Service (RADIUS) client that is centrally managed, enables user attribution, and

uses secure standards based strong cryptography for authentication and credential

protection.

• A Role-Based Access Control (RBAC) system that provides a permission model that

allows access to 889 device operations and configurations based on specific roles

and individual user accounts configured on the AAA server. At present the defined

roles are: Administrator, Operator and Observer.

• Strong encryption of all access and configuration network messages between the

EnerVista software and 889 devices using the Secure Shell (SSH) protocol, the

Advanced Encryption Standard (AES), and 128-bit keys in Galois Counter Mode (GCM)

as specified in the U.S. National Security Agency Suite B extension for SSH and

approved by the National Institute of Standards and Technology (NIST) FIPS-140-2

standards for cryptographic systems.

• Security event reporting through the Syslog protocol for supporting Security

Information Event Management (SIEM) systems for centralized cyber security

monitoring.

There are two types of authentication supported by CyberSentry that can be used to

access the 889 device:

• Device Authentication – in which case the authentication is performed on the

889 device itself, using the predefined roles as users (No RADIUS involvement).

– 889 authentication using local roles may be done either from the front panel or

through EnerVista.

• Server Authentication - in which case the authentication is done on a RADIUS server,

using individual user accounts defined on the server. When the user accounts are

created, they are assigned to one of the predefined roles recognized by the 889

– 889 authentication using RADIUS server may be done only through EnerVista.

FASTPATH: WiFi and USB do not currently support CyberSentry security. For this reason WiFi is

disabled by default if the CyberSentry option is purchased. WiFi can be enabled, but be

aware that doing so violates the security and compliance model that CyberSentry is

supposed to provide.

Enervista Viewpoint Monitor does not currently support CyberSentry security.

With the CyberSentry security option, many communication settings cannot be changed

remotely. All communication settings can still be changed through the relay front panel.

  • Emerson PMCSPANA/IH PMC Carrier Installation and Use Manual
  • Emerson PMCSPAN26E-010 Secondary PMC expansion
  • Emerson PMCSPAN26E-002 Primary PMC expansion
  • Emerson PMCSPAN16E-010 Secondary PCI expansion
  • Emerson PMCSPAN16E-002 Primary PCI expansion
  • A-B 1783-HMS4C4CGN Stratix 5400 Ethernet Managed Switches
  • A-B 1783-RA5TGC4G Stratix 4300 Remote Access Routers
  • A-B 1783-CMS10DP Stratix 5200 Ethernet Managed Switches
  • A-B 1783-CMS20DP Stratix 5200 Ethernet Managed Switches
  • A-B 1783-CMS20DP Stratix 5200 Ethernet Managed Switches
  • A-B 1783-HMS8S4CGN Stratix 5400 Ethernet Managed Switches
  • A-B 1783-CMS6B Stratix 5200 Ethernet Managed Switches
  • A-B 1783-RA5TGW Stratix 4300 Remote Access Routers
  • A-B 1783-RA2TGWC4G Stratix 4300 Remote Access Routers
  • A-B 1783-US8T/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-US5TG/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-RA2TGW Stratix 4300 Remote Access Routers
  • A-B 1783-US8T/A Stratix 2000 Ethernet Unmanaged Switches—Series A
  • A-B 1783-US6T2F/A Stratix 2000 Ethernet Unmanaged Switches—Series A
  • A-B 1783-US4T1F Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US5TG Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US4T1H Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US6T2TG2H Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US5T/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-US6T2TG2F Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US6T2H/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-US4T1H/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-US14T2S Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US6T2F Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US7T1H Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US16T2S Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-RA2TGC4G Stratix 4300 Remote Access Routers
  • A-B 1783-US16T/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-US7T1F/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-RA2TGB Stratix 4300 Remote Access Routers
  • A-B 1783-LMS5 Stratix 2500 Ethernet Lightly Managed Switches
  • A-B 1783-US7T1F Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US4T1F Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US16T Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US8T Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US6T2H/A Stratix 2000 Ethernet Unmanaged Switches—Series A
  • A-B 1783-US4T1F/B Stratix 2000 Ethernet Unmanaged Switches—Series B
  • A-B 1783-US8TG2GX Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US6T2H Stratix 2000 Ethernet Unmanaged Switches
  • A-B 1783-US5T 5 Port Unmanaged Switch
  • MOOG D138-002-002 Industrial Control Module
  • MOOG D138-003-001 Industrial Control Module
  • MOOG CA98502-001 Accessories for Ruggedized Motion Controller
  • MOOG D691-078D servo valve
  • MOOG CA65866-001 MSD Motion Controller
  • MOOG C43148-001 QD10 16/16 Digital l/0 module
  • MOOG D138-002-012 Main control unit
  • MOOG CA94286-001 Accessories for Ruggedized Motion Controller
  • MOOG D136-001-008 MSCI MSD Motion Controller
  • MOOG B95906-001 MSCI Motion Controller
  • MOOG B95865-001 CAN Termination Resistors
  • MOOG QEBUS-CAN Module
  • MOOG D136-003-001 Interfaces of Ruggedized Motion Controller
  • MOOG RDI0 16/16 Digital Module
  • MOOG D136-003-004 Interfaces of Ruggedized Motion Controller
  • MOOG D391-001-003 MSD MOTION CONTROLLER
  • MOOG D138-002-003 Industrial Control Module
  • MOOG MSC-R-10 16/8 Digital and PT100 Module
  • MOOG CB08987-001 Ruggedized Motion Controller
  • MOOG RDISP 22 Operator Panel DISPLAYS
  • MOOG D136-003-002 Interfaces of Ruggedized Motion Controller
  • MOOG CA65865-001 MSCl Motion Controller
  • MOOG B95863-001 CAN Connection Cables
  • MOOG QA10 16/4 Analog Module
  • MOOG D136-006-001 EtherCAT slave interface
  • MOOG D391-001-001 MSD MOTION CONTROLLER
  • MOOG D136-003-005 Interfaces of Ruggedized Motion Controller
  • MOOG D137-004-003 TFT Touch screen display
  • MOOG D138-002-003 Industrial Control Module
  • MOOG D138-003-010 Industrial Control Module
  • MOOG CB03223-001 Accessories for Ruggedized Motion Controller
  • MOOG B95864-001 CAN Termination Resistors
  • MOOG QD10 16/16 Digital Module
  • MOOG D391-001-002 MSD MOTION CONTROLLER
  • MOOG D138-001-010 Industrial Control Module
  • MOOG D138-001-005 Industrial Control Module
  • MOOG D138-001-002 Industrial Control Module
  • MOOG D138-001-001 Industrial Control Module
  • MOOG D137-002-001 Digital I/O modules
  • MOOG QEBUS-CAN Extension module
  • MOOG D137-001-010 Connection modules
  • MOOG D137-001-004 Digital I/O modules for E-Bus
  • MOOG D137-001-007 Digital extension module
  • MOOG G391-001-001 MSD Motion Controller
  • MOOG D138-002-001 Motion Controller
  • MOOG D137-004-004 TFT Touch screen display
  • MOOG D136-002-005 Ruggedized Motion Controller Interface
  • MOOG D137-001-006 Digital extension module
  • MOOG D136-002-004 Ruggedized Motion Controller Interface
  • MOOG D137-004-006 TFT Touch screen display
  • MOOG G391-001-002 MSD Motion Controller
  • MOOG D137-004-005 TFT Touch screen display
  • MOOG D137-001-005 Digital extension module
  • MOOG D136E001-001 Programmable Processor Module
  • MOOG D138-006-001 operation panel
  • MOOG G122-829-001 Programmable Processor Module
  • MOOG G761-3002B Industrial servo valves
  • MOOG T161-902A-00-B4-2-2A Servo Controller
  • MOOG M128-010-A001B DC Power Module
  • MOOG G391-001-003 MSD Motion Controller
  • MOOG D138-002-002 Motion Controller
  • MOOG D137-001-011 Digital extension module
  • MOOG D136-002-003 Ruggedized Motion Controller Interface
  • MOOG D136-002-002 Ruggedized Motion Controller Interface
  • MOOG D136-001-008a Ruggedized Motion Controller Interface
  • MOOG D136-001-007 Ruggedized Motion Controller Interface
  • MOOG D136-001-001 Ruggedized Motion Controller Interface
  • MOOG 914-GBE Gigabit Ethernet (GbE) Media Converter
  • MOOG 914-0300-00 ADVANCED MODULAR MULTIPLEXER SYSTEM
  • ABB UCD224A103 digital input/output module
  • ABB PDD205A0121 power distribution device
  • ABB PDD205A1121 power distribution device
  • ABB DSDX453 Digital input/output (DIO) expansion card
  • ABB DSPC454 Processor Board
  • ABB 81EU01E-E Input Module
  • ABB TK457V050 Temperature Controller
  • ABB DSRF197K01 Ethernet communication module
  • ABB TK802F power supply cable
  • ABB 3BHE039203R0101 IGCT module board
  • ABB 3BHB004027R0101 IGCT module board
  • ABB 3BHB003154R0101 IGCT module board
  • ABB PM864AK01-eA Processor Unit
  • ABB CI868K01-eA high-performance communication module