RAD s Service Assured Networking Solutions for. Power Utilities



Similar documents
RAD s Solutions for. Power Utility. Communications. Service Assured Networking

Operational Core Network

Homeland Security Solutions

INTEGRATING SUBSTATION IT AND OT DEVICE ACCESS AND MANAGEMENT

Communication Networks. We are securing the past in a fast moving future. FOX605 multiservice platform.

SGTech Europe 2015 September 22 th Amsterdam. Pedro Gama, Head of SCADA & Telecom Department at EDP Distribuição, SA

Secure Networking for Critical Infrastructure. Ilan Barda March 2014

Telephone Company Lease Line Elimination. Dewey Day Principal Operational Technology Architect Pacific Gas & Electric

IP/MPLS. Marios Parperis - Alcatel-Lucent Energy Systems Integration Division. October Alcatel-Lucent 2010 All Rights Reserved

1. Cyber Security. White Paper Data Communication in Substation Automation System (SAS) Cyber security in substation communication network

Endless possibilities

THE FUTURE OF SMART GRID COMMUNICATIONS

Smart Substation Security

Secure Networking for Critical Infrastructure Using Service-aware switches for Defense-in-Depth deployment

John M Shaw Presentation to UTC Region 7 February 19, 2009 jshaw@garrettcom.com

Smart Solutions for Network IP Migration

Failsafe Protection for Utility Critical Infrastructure

LTE Solution and Requirements for Smart Grids

TELECOMMUNICATIONS FOR POWER UTILITIES

DNP Serial SCADA to SCADA Over IP: Standards, Regulations Security and Best Practices

NERC CIP Substation Cyber Security Update. John M Shaw Presentation to UTC Region 7 February 19, 2009 jshaw@garrettcom.com

SecFlow Security Appliance Review

Securing Modern Substations With an Open Standard Network Security Solution. Kevin Leech Schweitzer Engineering Laboratories, Inc.

How To Extend A Cell Phone Over Wireless To A Long Distance Over A Cell Tower

FibeAir I500R High Capacity Wireless Network Solution

RuggedCom Solutions for

Virtual Privacy vs. Real Security

Cisco Smart Grid: Substation Automation Solutions for Utility Operations

John Ragan Director of Product Management. Billy Wise Communications Specialist

Communications network solutions for smart grids Answers for infrastructure & cities.

How To Build A Network For Mining

MIGRATING PUBLIC SAFETY NETWORKS TO IP/MPLS

Industrial Network Security for SCADA, Automation, Process Control and PLC Systems. Contents. 1 An Introduction to Industrial Network Security 1

How To Run A Telephony System Over An Ip Or Ipmux (Tcmux) On A Network (Ipmux) With A Pbip) Or Ipip (Ipip) On An Ip/Ethernet/Mp

Power network telecommunication

System 800xA Networks Control. Monitor. Communicate.

Cost-effective Wireless Alternatives to Corporate Leased-line Connectivity. White Paper

Secure SCADA Network Technology and Methods

CYBER SECURITY: SYSTEM SERVICES FOR THE SAFEGUARD OF DIGITAL SUBSTATION AUTOMATION SYSTEMS. Massimo Petrini (*), Emiliano Casale TERNA S.p.A.

State of Texas. TEX-AN Next Generation. NNI Plan

Network Cyber Security. Presented by: Motty Anavi RFL Electronics

Network Technology CMP-354-TE. TECEP Test Description

GE DigitalEnergy. Integrated Substation Control System (iscs) IEC based Substation Automation Solutions

How Proactive Business Continuity Can Protect and Grow Your Business. A CenturyLink White Paper

Technology Spotlight on Cellular Data Networking for SCADA system networks. Presented by Teamwork Solutions, Inc.

Alcatel-Lucent 1850 TSS Product Family. Seamlessly migrate from SDH/SONET to packet

SafeNet Network Encryption Solutions Safenet High-Speed Network Encryptors Combine the Highest Performance With the Easiest Integration and

CTS2134 Introduction to Networking. Module 07: Wide Area Networks

How To Manage An Ip Telephony Service For A Business

SCADA System Security. ECE 478 Network Security Oregon State University March 7, 2005

High Speed Encryption Made in Germany

Cisco Mobile Network Solutions for Commercial Transit Agencies

10 Gigabit Ethernet: Scaling across LAN, MAN, WAN

October Field Area Communication Networks for Digital Oil and Gas Fields

White paper. Reliable and Scalable TETRA networks

Local Area Networks (LANs) Blueprint (May 2012 Release)

TDMoIP. TDMoIP. Unique Access Solutions. TDM-Based Solutions over Packet-Switched Networks

rad partners Complementary RAD Group Products

3G Cellular RTU Solutions. Activate Your Remote Monitoring Application

Network System Design Lesson Objectives

1+1: Protected Microwave Links

Carrier-Grade Ethernet for Power Utilities

DATA SECURITY 1/12. Copyright Nokia Corporation All rights reserved. Ver. 1.0

Unifying Smart Grid Communications using SIP

AMI and DA Convergence: Benefits of Growing Your Smart Grid Infrastructure with a Multi Technology Approach

AltaLink IP/MPLS Network. Nov 3, 2011 Stephen VanderZande

Going Critical. How to Design Advanced Security Networks for the Nation s Infrastructure. w w w. G a r r e t t C o m. C o m

Best Practices: The Key Things You Need to Know Now About Secure Networking Layer 1 (SONET), Layer 2 (ATM), and Layer 3 (IP) Encryption Technologies

Power network telecommunication

CompTIA Network+ (Exam N10-005)

the amount of data will grow. It is projected by the industry that utilities will go from moving and managing 7 terabytes of data to 800 terabytes.

IP/MPLS Networks for Public Safety

WAN Failover Scenarios Using Digi Wireless WAN Routers

Our story EION s WOrldWIdE headquarters IN OttAWA, canada EION leadership

Securing Distribution Automation

PLCs and SCADA Systems

Huawei One Net Campus Network Solution

High Performance, Secure VPN Servers for Remote Utility, Industrial Automation Systems:

Supporting Municipal Business Models with Cisco Outdoor Wireless Solutions

P-Series: Purpose Built Business and Mobile Backhaul ONTs

Converged TDM and IP- Based Broadband Solutions White Paper. OnSite OS-10 Multi-Service over SDH Provisioning

How Much Cyber Security is Enough?

Primary Data Center. Remote Data Center Plans (COOP), Business Continuity (BC), Disaster Recovery (DR), and data

ENTERPRISE CONVERGED NETWORK SOLUTION. Deliver a quality user experience, streamline operations and reduce costs

Please purchase PDF Split-Merge on to remove this watermark.

State of New Mexico Statewide Architectural Configuration Requirements. Title: Network Security Standard S-STD Effective Date: April 7, 2005

Wireless Field Data Backhaul

Pseudo-Wires: The Full-Service Alternative to TDM Access WHITE PAPER


Your single source for network transmission solutions.

TDM services over IP networks

1.264 Lecture 37. Telecom: Enterprise networks, VPN

Secure Substation Automation for Operations & Maintenance

Application Notes Multi-service EDD-Ethernet Demarcation Device

MANAGEMENT INFORMATION SYSTEMS 8/E

Cisco Wireless Security Gateway R2

Transcription:

RAD s Service Assured Networking Solutions for Power Utilities

Toolbox Firewall & Encryption High Reliability Ruggedized Smooth Migration Resiliency Performance Monitoring Cyber Security End-to-End Management Service Assured Networking for Power Utilities For more than 30 years, RAD has worked closely with its worldwide power utility customers to provide field-proven communication solutions that address the automation, Teleprotection and core operational network needs of their transmission and distribution (T&D) grids. RAD s Service Assured Networking offers the best solutions for highly reliable and cyber-secure operational networks, with a wealth of tools that lead the migration to packet switched networks and meet the key requirements of power utility communications networks.

Any Service Native/ Pseudowire Carrier- Grade Ethernet IP Teleprotection Timing Virtualization Any Deployment Mode Operational WAN Substation/Station LAN Mobility Any Infrastructure Fiber Copper Wireless Mission-Critical Reliability Fail-safe operations and resiliency over TDM, PSN and OTN cores High availability, seamless redundancy (HSR) and minimal end-to-end latency for differential and distance protection communications Robust operation in harsh environments (IEC 61850-3, IEEE 1613) Smooth Migration Resolve SDH/SONET product obsolescence with future-proof support for legacy RTUs, voice and data, together with next-gen IEDs and packet communications IEC 61850 substation automation and SCADA connectivity Smart Grid backhaul Cyber Security Boost NERC-CIP compliance 3-tier defense provides ultimate electronic security perimeter (ESP) protection from internal and external cyber attacks Real-time video transmission for always-on site security

RAD Solutions for Power Utility Communications Control Room EMS/DMS RADview Video Customer Surveillance Server Billing Server Fiber Optic Legacy SDH/ SONET Fiber Optic SecFlow ETX// New PSTN/OTN 2G/3G/LTE Network Small Substation ETX/Megaple RTU IED Fiber Optic Fiber Optic SecFlow A

-4 Next-Generation Multiservice Access Nodes ETX-5 Ethernet Service Aggregation Platform Large HV/MV Substation SecFlow IED RTU SecFlow Teleprotection Fiber Optic Modular Ruggedized SCADA-Aware Ethernet Switch/Router Fiber Optic ETX// Airmux-5000 Point-to-Multipoint Ethernet Radio LV Transformer MV LBS Meter Concentrator Camera Complete Solutions for WDM/OTN Applications with Encryption Wireless Airmux Ruggedized SCADAAware Security Gateway SecFlow-4 egaplex/ Light Voice Airmux SecFlow RADview Network Management System

Substation Multiservice Operational Networks Substation Teleprotection RTU FO Control Room (DMS) Voice SCADA Center Data Center RADview Connection on Demand FO ETX// Core PSN/OTN 10 GbE ETX// IEDs ETH Substation Teleprotection ETX// Access Network 1 GbE/10 GbE Voice RTU IEDs ETH ETH Teleprotection RTU IEDs Substation Utilizes RAD s powerful all-in-one -4 platform: Multiservice aggregation 10G core/access network builder Cyber attack prevention Cyber-secure and reliable communications between the substation and energy management system or distribution management system OTN/DWDM: long distance (up to 180 km) multitunneling fiber optic communications to remote substations at rates up to 100G Supports all substation communications: legacy voice and data devices, VoIP and PABX, SCADA RTUs, IEDs, automation and Teleprotection Optional gradual migration to new networks with hybrid TDM/PSN design and traffic duplication for reduced latency and better resiliency Adding new applications (cyber security, router) using RAD s innovative x86 module Full range of service provisioning, performance monitoring, diagnostics, and troubleshooting with the RADview management system

3-Tier ESP Protection Electronic Security Perimeter Voice Video IED RTU IED TP Device Connection Control (DCC) 802.1x Network Access Control ETH RS-232 SCADA-Aware Security FW, IPS, Anomaly Detection, etc. Man in the Middle Prevention MACSec Encryption and Integrity Strategically located to securely manage all electronic access to the substation s ESP, and to protect the cyber assets within it from external and internal attacks: Device connection control (DCC) using IEEE 802.1x Network Access Control to ensure authenticated and authorized internal substation connections SCADA-aware security layer, including firewall, intrusion prevention, anomaly detection, and more IEEE 802.1AE (MACSec) and IPSec encryption and data integrity verification to prevent sourcespoofing, session hijacking, Man in the Middle and Distributed Denial of Service (DDoS) attacks Boost compliance level with NERC-CIP (North American Electric Reliability Corporation Critical Infrastructure Protection) requirements for bulk electric systems (BES) protection Layered security approach addresses all vulnerability points including integrity, confidentiality (encryption), authentication, authorization, and auditing Access control, user authentication and privilegelevel associations for local and remote access using Secure Shell (SSH), TACACS or RADIUS

Distance and Differential Protection Communications IEC 61850, C37.94, DC Commands In/Out IEC 61850, C37.94, DC Commands In/Out HV Substation -4 with Teleprotection HV Power Flow HV Substation -4 with Teleprotection Distance/Differential Protection IEDs Distance/Differential Protection IEDs 1/10 GbE, E1/T1, STM-1/STM-4, C37.94 PSN/TDM Network or Point-to-Point Dark Fiber 1/10 GbE, E1/T1, STM-1/STM-4, C37.94 RADview The -4 supports high speed, reliable signaling for both distance and differential protection IEDs over TDM or packet networks Hardware protection with HSR ensures zero msec delay up to the communications link Guaranteed sub-2 msec end-to-end signaling latency across the network Supports most distance and differential relay IEDs: 24V 250V dry contacts, serial, G.703 codirectional, C37.94, 61850 GOOSE, etc. -4 Teleprotection complies with IEC 60834-1 Tested interoperability with distance and differential relay IEDs from leading vendors such as Alstom, ABB, Siemens, SEL, Schneider, etc. Network management and configuration with RADview system

Ruggedized Substation LAN RADview Electronic Security Perimeter Teleprotection IP Phone Utility Primary WAN Secured Multiservice Gateway with Firewall IED Serial IEC 60870-5-101 Substation RTU HNI IED TCP IEC 60870-5-104 Server Utility Secondary WAN Voice Analog Server IED TCP DNP 3.0 HNI SecFlow-2 with Firewall SecFlow-2 SecFlow-2 IED Serial DNP 3.0 SCADA-Aware Security Gateway SecFlow-2 IED Serial DNP 3.0 IEDs IEC 61850 IED Serial Modbus Supports Ethernet-based substation communications for mission-critical automation traffic within the substation and to SCADA control centers Enables co-existence of RTUs and IEDs based on serial and Ethernet protocols Full redundancy over various topologies using fiber optic rings, 2G/3G cellular modems and external radio systems Enables secure, dedicated networks over fiber and/ or radio links using IPSec encryption and distributed security SCADA firewall suite Complies with IEC 61850-3 and IEEE 1613 environmental standards SCADA-aware security gateway detects and blocks anomalies and authenticates user access to IEDs and RTUs Built-in router enables seamless SCADA communications to both legacy and new RTUs by converting IEC 60870-5-101 to IEC 60870-5-104, Modbus serial to Modbus IP, as well as supporting DNP 3.0 and IEC 61850

Distribution Automation and Smart Metering Backhaul AMI/AMR Concentrator AMI/AMR Control RADview SecFlow-1 with Firewall PLC/Logger Distribution Automation DSO Network rd 3 Party Network Power Quality Monitoring 3ø MV Load Break Switchgear Control Billing Server SecFlow-1 with Firewall PLC/Logger MV Load Break Switchgear Control Cellular Network 3G/LTE Power Utility Intranet Airmux Airmux Base Station Airmux SecFlow-1 PLC/ Logger AMI/AMR Concentrator A comprehensive solution addressing the communications needs of energy consumption metering, variable tariff dissemination and MV distribution grid automation Seamless communications over fiber optics, wireless links, 2G/3G/LTE cellular networks, and telecom service provider networks Point-to-multipoint wireless connectivity supports high capacity traffic over licensed and unlicensed sub-6 GHz bands Integrated IPSec with SCADA-aware firewall to mitigate cyber security threats and fraud Self-learning of various data flows; accurate delivery of distribution automation and billing traffic to their respective control servers Transparent delivery of TCP-based data protocols including IEC 60870-5-104, IEC 61850, Modbus, DNP 3.0, etc. Supports communication for LBS (load break switchgears) control and power quality monitoring Complies with IEC 61850-3 and IEEE 1613 environmental standards for outdoor installations Network management and configuration with RADview system

Versatile Add-On Functions Substation Virtualized Functions Terminal Server SCADA Firewall Router Anomaly Detection Protocol Conversion Substation RTU Serial/TCP SONET/SDH PSN -4 with x86 Module Teleprotection IED Software-based functions running on an x86 field-pluggable server module integrated within RAD s -4 Reduces the number of physical network devices for better reliability, stronger cyber security and simpler operation Add functions as needed, including routing, SCADA-aware firewall, encryption, anomaly detection, terminal server, protocol conversion, data-frame encapsulation, and more Future-ready and flexible solution to meet new application needs All applications are tested and certified by RAD Small footprint and low power consumption, supporting reliable operations of multiple concurrent functions -4 Next-Generation Multiservice Access Nodes

The Power of RAD RAD is the preferred communications vendor for many energy utilities and system integrators around the world. Selected Customers PGE USA National Grid USA Hydro-Québec Canada Northeast Utilities USA New York Power Authority USA Empresa de Electricidade da Madeira Portugal Elia Belgium E.ON Germany Elektro Maribor EDF France Slovenia Enel Italy Terna Italy Endesa Spain Israel Electric Corp. Israel Ural Energosoyuz Russia Bhutan Power Corp. Bhutan RES Novosibirsk Russia Beijing Electronic Power Corp. China China Light & Power China Tata Power Company India KEPCO - Korea Electric Power Corp. Korea Taipower Taiwan Elektra Noreste Panama Ampla Brazil Eletronorte Brazil CELPE Brazil AES-SONEL Cameroon UETCL Uganda TANESCO Tanzania Maharashtra State Power Generation Co. India KenGen Kenya Kenya Power Kenya Provincial Electricity Authority Thailand PLN Indonesia Meralco Philipines COBEE Bolivia AES Eletropaulo Brazil NamPower Namibia TransGrid Australia Powercor Australia AES Gener Chile TrustPower New Zealand www.rad.com Specifications are subject to change without prior notification. The RAD name and logo are registered trademarks of RAD Data Communications Ltd. RAD product names are trademarks of RAD Data Communications Ltd. 2015 RAD Data Communications. All rights reserved. Catalog number 802601, Version 06/15