Access control and cybersecurity
Cybersecurity measures are implemented to secure safe
operation of the protection and control functions. The relay
supports these measures with configuration hardening
capabilities, encrypted communication, Ethernet filter and rate
limiter, security event logging and user access control.
The relay supports role-based user authentication and
authorization with individual user accounts as defined in IEC
62351-8. All user activity is logged as security events to an
audit trail in a nonvolatile memory and sent as messages to the
SysLog server. The nonvolatile memory does not need battery
backup or regular component exchange to maintain the
memory storage. File transfer and Web HMI use communication
encryption protecting the data in transit.
Also, the communication link between the relay configuration tool
PCM600 and the relay is encrypted. All rear communication
ports and optional protocol services can be activated according
to the required system setup.
User accounts can be managed by PCM600 or centrally. A
central account management is an authentication infrastructure
that offers a secure solution for enforcing access control to
relays and other systems within a substation. This incorporates
management of user accounts, roles and certificates and the
distribution of such, a procedure completely transparent to the
user. The central server handling user accounts can be, for
example, SDM600 or an Active Directory (AD) server such as
Windows AD.
The relay supports full Public Key Infrastructure as defined by
IEC 62351-9. With this, the user can ensure that the certificates
used in secured communication are from a user-approved
provider instead of device self-signed certificates.
wechat/whatsapp:
+86-181-4410-0983
Email: kongjiangauto@163.com
Copyright © 2009 - 2024 Cld , All Rights Reserved K-JIANG All rights reserved