Power Engineering 
K-JIANG
NameDescriptionContent
Current Location:

GE 889 Generator Protection System Security Overview

From:GE | author:Mr.Chen | Time :2025-01-17 | 268 view: | 🔊 Click to read aloud ❚❚ | Share:

The following security features are available:

BASIC SECURITY

The basic security feature is present in the default offering of the 889 relay. The

889 introduces the notion of roles for different levels of authority. Roles are used as login

names with associated passwords stored on the device. The following roles are available

at present: Administrator, Operator, Factory and Observer, with a fixed permission

structure for each one. Note that the Factory role is not available for users, but strictly used

in the manufacturing process.

The 889 can still use the Setpoint access switch feature, but enabling the feature can be

done only by an Administrator. Setpoint access is controlled by a keyed switch to offer

some minimal notion of security.

CYBERSENTRY

The CyberSentry Embedded Security feature is a software option that provides advanced

security services. When the software option is purchased, the Basic Security is

automatically disabled.

CyberSentry provides security through the following features:

• An Authentication, Authorization, Accounting (AAA) Remote Authentication Dial-In

User Service (RADIUS) client that is centrally managed, enables user attribution, and

uses secure standards based strong cryptography for authentication and credential

protection.

• A Role-Based Access Control (RBAC) system that provides a permission model that

allows access to 889 device operations and configurations based on specific roles

and individual user accounts configured on the AAA server. At present the defined

roles are: Administrator, Operator and Observer.

• Strong encryption of all access and configuration network messages between the

EnerVista software and 889 devices using the Secure Shell (SSH) protocol, the

Advanced Encryption Standard (AES), and 128-bit keys in Galois Counter Mode (GCM)

as specified in the U.S. National Security Agency Suite B extension for SSH and

approved by the National Institute of Standards and Technology (NIST) FIPS-140-2

standards for cryptographic systems.

• Security event reporting through the Syslog protocol for supporting Security

Information Event Management (SIEM) systems for centralized cyber security

monitoring.

There are two types of authentication supported by CyberSentry that can be used to

access the 889 device:

• Device Authentication – in which case the authentication is performed on the

889 device itself, using the predefined roles as users (No RADIUS involvement).

– 889 authentication using local roles may be done either from the front panel or

through EnerVista.

• Server Authentication - in which case the authentication is done on a RADIUS server,

using individual user accounts defined on the server. When the user accounts are

created, they are assigned to one of the predefined roles recognized by the 889

– 889 authentication using RADIUS server may be done only through EnerVista.

FASTPATH: WiFi and USB do not currently support CyberSentry security. For this reason WiFi is

disabled by default if the CyberSentry option is purchased. WiFi can be enabled, but be

aware that doing so violates the security and compliance model that CyberSentry is

supposed to provide.

Enervista Viewpoint Monitor does not currently support CyberSentry security.

With the CyberSentry security option, many communication settings cannot be changed

remotely. All communication settings can still be changed through the relay front panel.

  • B&R X20cBB80 X20 Base module
  • B&R X20cBC00E3 Bus controller
  • 3BSE006503R1 PFSA 140, Roll Supply Unit
  • ABB PFSC230 cable set 25m for DTU
  • SAACKE F-GDSA 143303 Controller SHIPS UPS
  • GE ENERGY HYDRAN H201Ci-1 One-Channel Controller
  • B&R X20cBC0087 Bus controller
  • B&R X20cBC0083 Bus controller
  • B&R X20cBC0043-10 Bus controller
  • B&R X20cBM32 X20 bus module, coated, for double-width modules
  • B&R X20cBM31 X20 bus module, coated, for double-width modules
  • B&R X20cBM12 X20 bus module, coated, 240 VAC keyed
  • B&R X20cBM11 Bus module, 24 VDC keyed
  • B&R X20cBM01 Power supply bus module
  • B&R X20EM1613 compact yet powerful controller
  • Prosoft PS-QS-1211-F Universal QuickServer Gateway
  • Prosoft PS-QS-1011-F Universal QuickServer Gateway
  • Prosoft PS-QS-2110-F Universal QuickServer Gateway
  • Prosoft PS-QS-2210-F Universal QuickServer Gateway
  • Prosoft PS-QS-2010-F Universal QuickServer Gateway
  • Prosoft PS-QS-3210-F Universal QuickServer Gateway
  • Prosoft PS-QS-3110-F Universal QuickServer Gateway
  • Prosoft PS-QS-3010-F Universal QuickServer Gateway
  • Mitsubishi AJ71C21-A MELSEC PLC Programmable Controller
  • Mitsubishi Q80BD-J71BR11 PLC Interface Board PCB Card
  • MITSUBISHI QJ71GP21S-SX COMMUNICATION NETWORKING PLC MODULE
  • A2ACPU21 MITSUBISHI PLC A2ACPU21
  • A3ACPU MITSUBISHI MELSEC
  • Eaton / Cutler-Hammer: AE16KNS0AB BiMatallic Man/Auto Reset
  • EATON MOELLER MFD-CP8-ME Power Supply
  • EATON 9PX1500IRTM 9PX marine UPS
  • Eaton EASY819-AC-RC easy programmable relay
  • Eaton, Touchscreen, XV-102-B4-35TQRF-10-PLC, 3,5 Inch
  • EATON 101073735-001 LEG MODULE BOARD, PENT w/ 100A
  • Eaton Cutler Hammer OEM Contact Kit 6-26-2 3 Pole
  • EATON CORPORATION E84BAN / E84BAN Series
  • Eaton, Touchscreen, XV-102-B6-35MQR-10-PLC, 3,5 Inch
  • Eaton Easy touch display XV-102-A0-35TQRB-1E4
  • EATON PXQ-ST2-1A1 Quality Analysis System Kit, 700/1200 VAC
  • EATON PXQ-ST1-1A1 Quality Analysis System Kit, 700/1200 VAC
  • TMEIC KPAD-3122A A3XAP02 LCD Display With Key Pad
  • Nidec Drives S100-02463 General Purpose Micro AC Drive
  • Nidec Drives S100-02463 General Purpose Micro AC Drive
  • Nidec Drives S100-01D13 General Purpose Micro AC Drive
  • Nidec Drives S100-01D73 General Purpose Micro AC Drive
  • ABB 3BUS208720-001 POWER SIGNAL INTERCONNECT
  • METSO A413345 Industrial Control Module
  • METSO A413177 Industrial Control Module
  • METSO A413222 Address Module Count Verification
  • METSO D100532 Control Module
  • METSO ADC5483-D200136L Power Supply Module
  • METSO A413313 Industrial Control Module
  • METSO A413310 Industrial Control Module
  • METSO A413659 Industrial Control Module
  • METSO D100314 Industrial Reliability Enhancement Component
  • METSO A413665 Industrial Control Module
  • METSO A413325 IPU Power Unit Module
  • METSO A413654 Real-time Control Module
  • METSO A413110 Industrial Process Control System
  • METSO A413160 Industrial Process Control System
  • METSO A413144 Industrial Control Module
  • METSO A413152 Industrial Control Module
  • METSO A413146 Timer & Memory Management Module
  • METSO PIC2 A413240A PCB Board
  • METSO A413150 Industrial Control Module
  • METSO A413140 analog input module
  • METSO A413111 analog input module
  • METSO AIU-8 A413125 analog input module
  • METSO 02VA0093 Control Module for Industrial Automation
  • METSO 020A0082 Process Control Optimization Module
  • METSO 02VA0153 Control Module for Industrial Automation
  • METSO 02VA0193 IOP Module
  • METSO 02VA0175 I/O Module
  • METSO D100308 Expansion Module
  • Metso D200175 Personality Module
  • Metso Automation D201471 Version 01 Or 05 DOI4 Module
  • Metso Automation D201138 IBC Controller Module
  • Metso Automation DOI4R0 PLC Card. 3D-27
  • Metso Automation D201776 ACN PO DC PLC Control Server Computer
  • ABB AC 800PEC CIO-FU PC D235 A101 3BHE032025R0101 Combined Input Output
  • ABB PFSA240 Roll DC Supply Unit 3BSE073476R1
  • ABB PFSA107-Z42 DTU Stressometer Digital Transmission Unit
  • GE AT868-2-1-1 Panametrics Ultrasonic Liquid Flow Transmitter
  • Beckhoff EKM1101 | EtherCAT Coupler with ID switch and diagnostics
  • Beckhoff EK1101-0080 | EtherCAT Coupler with ID switch, Fast Hot Connect
  • Beckhoff EK1101-0010 | EtherCAT Coupler with ID switch, Extended Distance
  • Beckhoff EK1101-0008 | EtherCAT Coupler with ID switch and M8 connection
  • Beckhoff EK1101 | EtherCAT Coupler with ID switch
  • Beckhoff EK1000 | EtherCAT TSN Coupler
  • Beckhoff EK1100-0008 | EtherCAT Coupler with M8 connection
  • Beckhoff EC1100 | EtherCAT Coupler, RJ45, angled, push-in
  • Beckhoff EK1100 | EtherCAT Coupler
  • KEBA KeDrive D3-DP Supply unit
  • KEBA KeDrive D3-DU Motion control accessories
  • KEBA KeDrive D3-DU 3x5 Safety controller
  • KEBA KeDrive D3-DA axis controller BG3+4
  • KEBA KeDrive D3-DA axis controller BG1+2
  • KEBA KeDrive D3-DP 310 supply module
  • KEBA KeDrive D3-DL 300 charging module
  • KEBA ServoOne Drive system for safe automation solutions
  • KEBA KeDrive D5 The single-axis controller without compromise
  • KEBA KeControl C5 - UE 550 USB expansion card
  • KEBA KeControl C5 - FE 560 Multi-protocol fieldbus expansion card
  • KEBA KeControl C5 - FE 573 EtherCAT master expansion card
  • KEBA KeControl C5 - FE 571 EtherCAT master expansion card
  • KeDrive D3 controls D3-DU 365/B Control modules
  • KeDrive D3 controls D3-DU 365/A Control modules
  • KeDrive D3 controls D3-DU 335/B Control modules
  • KeDrive D3 controls D3-DU 335/A Control modules
  • KeDrive D3 controls D3-DU 360/B Control modules
  • KeDrive D3 controls D3-DU 360/A Control modules
  • KeDrive D3 controls D3-DU 330/B Control modules
  • KeDrive D3 controls D3-DU 330/A Control modules
  • KEBA KeControl C1 Control modules CP 057/Y
  • KEBA KeControl C1 Control modules CP 056/Y
  • KEBA KeControl C1 Control modules CP 056/E
  • KEBA KeControl C1 Control modules CP 035/M
  • KEBA KeControl C5 CP 507/C Control units
  • KEBA KeControl C5 CP 507/A Control units
  • KEBA KeControl C5 CP 505/A Control units
  • KEBA KeControl CP 503/A Control units
  • KEBA KeControl C5 CP 530/C Control modules
  • KEBA KeControl C5 CP 520/C Control modules
  • KEBA KeControl C5 - CP 5x0 Control modules
  • KEBA KeControl C5 - CP 50x Controls / Control units
  • KEBA KeSafe C5 SDM 570 Extension Module
  • KEBA KeSafe C5 SCP 501 Safety Controller
  • KEBA KeDrive D3-ES energy storage device