Alain Fiocco. Sr. Director CTO Office afiocco@cisco.com



Similar documents
Security in Smart Grid / IoT. Nenad Andrejević Comtrade Solutions Engineering

INTEGRATING SUBSTATION IT AND OT DEVICE ACCESS AND MANAGEMENT

Cisco 1000 Series Connected Grid Routers

The Internet of Things

October Field Area Communication Networks for Digital Oil and Gas Fields

CONECTIVIDAD EN LA ERA DEL IOT THE INTERNET OF THINGS

Cisco Aironet 1520 Series Lightweight Outdoor Access Points

Communication Architecture for AMI and other Smart Grid/Smart City Applications. Presented By: Reji Kumar Pillai President - ISGF

AMI and DA Convergence: Benefits of Growing Your Smart Grid Infrastructure with a Multi Technology Approach

The Internet of Things (IoT) and Industrial Networks. Guy Denis Rockwell Automation Alliance Manager Europe 2015

RuggedCom Solutions for

Cradlepoint COR IBR350 Specifications

Easily Connect, Control, Manage, and Monitor All of Your Devices with Nivis Cloud NOC

Manufacturing and the Internet of Everything

ECB1220R. Wireless SOHO Router/Client Bridge

ZoneFlex Smart n 5GHz Outdoor Wireless Bridge. The First Centrally Managed n 5GHz Outdoor Wireless Bridge BENEFITS

ENHWI-N n Wireless Router

QuickSpecs. Model. Key features Can connect wired device to a wireless network Single radio IEEE a/b/g Two external antennas Indoor enclosure

CradlepointCOR IBR350Specifications

Cisco WAP321 Wireless-N Selectable-Band Access Point with Single Point Setup

Primary Voice Services over BreezeMAX Carrier class telephony and broadband data for new and incumbent networks

Unifying Smart Grid Communications using SIP

Smart Cities are the Internet of Things

HP ProCurve Wireless Access Point 10ag Overview

3G Wireless-N Smart Energy Gateway

Cisco RV 120W Wireless-N VPN Firewall

Key requirements for Interoperable IoT systems

ESR b/g/n SOHO Router

HP E-M110 Access Point Series. Product overview. Key features. Data sheet

WISE-4000 Series. WISE IoT Wireless I/O Modules

APPENDIX 3 LOT 3: WIRELESS NETWORK

THE FUTURE OF SMART GRID COMMUNICATIONS

802.11b/g/n SOHO Router 2.4GHz 150Mbps 11N AP/Router

How To Use A Cisco Wvvvdns4400N Wireless-N Gigabit Security Router For Small Businesses

Supporting Municipal Business Models with Cisco Outdoor Wireless Solutions

Ha-VIS FTS 3000 Introduction and features

ZoneFlex 7731 Smart n 5GHz Outdoor

ZoneFlex 7731 SMART N 5GHZ OUTDOOR POINT-TO-POINT, POINT-TO-MULTIPOINT WIRELESS BRIDGE

Smart Substation Security

QuickSpecs. Models HP WA2110 Single Radio a/b/g Access Point HP WA2220 Dual Radio a/b/g Access Point

AC Wireless Dual Band ADSL2+ Modem Router. Highlights

Cisco Nexus 7000 Series Supervisor Module

TK C -25 C 95% RH EMC TK701G TK701U TK704G TK704U TK704W. TK-Series Cellular Router

Cisco Outdoor Wireless Network Serves Up Automatic Meter Reading

The Internet of Things: Opportunities & Challenges

ESR b/g/n SOHO Router

How To Set Up A Cisco Wap121 Wireless N Access Point With Single Point Setup

Secure Networking for Critical Infrastructure. Ilan Barda March 2014

Cisco Catalyst 4500-X Series Switch Family

PANDUIT Physical Layer Infrastructure Management. EMC Smarts Integration Module

Intelligent Street lighting management using ZigBee. Martin SCHULTE-HOBEIN Field Application Engineer, EMEA Digi International

Gigabit Multi-Homing VPN Security Router

Cisco Conference Connection

Pronto Cloud Controller The Next Generation Control

HP AP8760 Dual Radio a/b/g Access Point Overview

Cisco RV220W Network Security Firewall

ESR (Go Green Series) Wireless-N Broadband Router / AP / Repeater. 2.4 GHz b/g/n 300 Mbps

EnergyICT. Energy Metering Management solutions, worldwide experiences. Vincent Dehullu. IDEA District Cooling Symposium - Dubai October 30, 2007

Cisco RV110W Wireless-N VPN Firewall

EdgeRouter Lite 3-Port Router. Datasheet. Model: ERLite-3. Sophisticated Routing Features. Advanced Security, Monitoring, and Management

Layer 2 Network Encryption where safety is not an optical illusion Marko Bobinac SafeNet PreSales Engineer

High-performance VoIP Traffic Optimizer Client Solution

Erich W. Gunther Chairman and CTO - EnerNex Corporation Chairman UtilityAMI, OpenHAN, AMI-SEC erich@enernex.com

Itron and Cisco Grid Intelligence

11 Internet of Things (IoT) Protocols You Need to Know About

Cloud-based Wireless LAN for Enterprise, SMB, IT Service Providers and Carriers. Product Highlights. Relay2 Enterprise Access Point RA100 Datasheet

Going Critical. How to Design Advanced Security Networks for the Nation s Infrastructure. w w w. G a r r e t t C o m. C o m

Cisco RV180 VPN Router

802.11n WLAN Access Point

ARUBA RAP-100 SERIES REMOTE ACCESS POINTS

5GHz 300Mbps a/n Wireless Outdoor Access Point

AC 750. Wireless Dual Band ADSL2+ Modem Router. Highlights

End to End WiMAX Network Solution

Wireless Field Data Backhaul

Internet of things (IOT) applications covering industrial domain. Dev Bhattacharya

Communication Networks. We are securing the past in a fast moving future. FOX605 multiservice platform.

EAP N Wall Mount Access Point / WDS AP / Universal Repeater

Datasheet. Advanced Network Routers. Models: ERPro-8, ER-8, ERPoe-5, ERLite-3. Sophisticated Routing Features

Best Practices for Outdoor Wireless Security

ECB GHz Super G 108Mbps Access Point/Client Bridge/Repeater/WDS AP/

running operation mode painless TECHNICAL SPECIFICATION WAN/LAN: One 10/100 Fast Ethernet RJ-45 WPS (WiFi Protected Setup) WAN (Internet connection)

Cisco ENG new SG500XG switch 16 port 10-Gigabit switch

Secure Networking for Critical Infrastructure Using Service-aware switches for Defense-in-Depth deployment

Cisco RV110W Wireless-N VPN Firewall

ZigBee IP Stack Overview Don Sturek Pacific Gas and Electric (PG&E) 2009 ZigBee Alliance. All rights reserved. 1

Cisco TelePresence MSE 8000

Demystifying Wireless for Real-World Measurement Applications

ARUBA RAP-3 REMOTE ACCESS POINT

Cisco RV220W Network Security Firewall

Utility Telecom Forum. Robert Sill, CEO & President Aegis Technologies February 4, 2008

Wi-Fi for the Smart Grid:

3G uplink for Primary or Backup; Support L2TP VPN, Firewall, Anti-DoS, Anti-ARP, Anti-Scanning;

Key Features. Multiple Operation Modes ENH500 can operate into four different modes with Access Point, Client Bridge, Client Router and WDS Mode.

Cisco SR 520-T1 Secure Router

Cisco Enhanced High-Speed WAN Interface Cards

VRGIII N Series Triple Play Gateway

AirTight C-60 Access Point

Juniper Update Enabling New Network Architectures. Debbie Montano Chief Architect, Gov t, Edu & Medical dmontano@juniper.

Transcription:

Alain Fiocco Sr. Director CTO Office afiocco@cisco.com

BILLIONS OF DEVICES The Internet of Things Is Already Here 50 40 50 Billion Smart Objects 30 20 10 0 Source: Cisco IBSG, 2011 Inflection Point 12.5 25 7.2 6.8 7.6 TIMELINE 2010 2015 2020 Rapid Adoption Rate of Digital Infrastructure: 5X Faster Than Electricity and Telephony World Population

PROCESS MANUFACTURING ENERGY TRANSPORTATION CITIES RETAIL 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3

IoT Device Characteristics

Assumptions & Constraints for Protocols

Field Area Network (FAN) Wide Area Network Field Area Network Router Neighborhood Area Network 6

IoT Architectural Philosophy Closed Systems Various Protocols (Little external interaction) (Modbus, SCADA, BACnet, LON, HART) Standardized Interfaces (Wireless/Wired) Standardized Networks (IP Based/ISO Stack) Protocol Gateways (Inherently complex, inefficient and fragmented networks) Proprietary Networks (Usually layer 2 based) From Distributed Intelligence (e.g. Fog Computing) To

Convergence of Applications Business Application #1 Business Application #2 Business Application #3 Business Application #1 Business Application #2 Business Application #3 Converged Application Infrastructure Network #1 Network #2 Network #3 Converged IP-Based Network Device #1 Device #2 Device #3 Device #1 Device #2 Device #3 Existing Proprietary Vertical Applications and Networks Converged Network Based on Open Standards and Common Data Models

Why Distribute Computing? Traditional Computing Model (Terminal/Mainframe, Client-Server, Web) IoT Computing Model Assumes Infinite, Bandwidth, 0 Delay Data Center/ Cloud Endpoint Speed of Light Latency-Critical Responsiveness Required Resiliency Security Data Grows Faster Than Bandwidth Data Center/ Cloud Fog Device Assumes Limited Bandwidth, Variable Delay, and Intermittent Connectivity IOx Assumes Limited Bandwidth, Variable Delay, and Intermittent Connectivity

Well Established Eco-Systems Fog computing use cases Build Your Own Interface Application Layer Gateway Protocol Translation Application Layer Security Application Data Processing Distributed Control

IoT Protocol Stack : Smartgrid example

Open Standards IP-based Reference Model Application Layer Transport Layer Network Layer Mgmt Data Link Layer Physical Layer LLC M A C Web Services, EXI, SOAP, RestFul,HTTPS/CoAP IPv6 RPL IEEE 802.15.4e MAC enhancements UDP/TCP IPv6 802.1x / EAP-TLS & IEEE 802.11i based Access Control IPv6 over PPP 6LoWPAN (RFC 6282) IPv6 over Ethernet (RFC 2464) (RFC 5072) IEEE 802.15.4 including FHSS IEEE 802.15.4g 2.4GHz, 915, 868MHz DSSS, FSK, OFDM Metering IEC 61968 CIM, ANSI C12.22, DLMS/COSEM, IEEE 1901.2 802.15.4 frame format IEEE 1901.2 NB-PLC OFDM IEEE 802.11 Wi-Fi IEEE 802.11 Wi-Fi 2.4, 5 GHz, Sub-GHz SCADA IEC 61850, 60870 DNP3/IP, Modbus/TCP, IEEE 802.3 Ethernet IEEE 802.3 Ethernet UTP, FO DNS, NTP, IPfix/Netflow, SSH RADIUS, AAA, LDAP, SNMP, (RFC 6272 IP in Smart Grid) Security (DTLS/TLS) Addressing, Routing, Multicast, QoS, Security 2G, 3G, LTE Cellular 2G, 3G, LTE Cellular IP or Ethernet Convergence SubL. IEEE 802.16 WiMAX IEEE 802.16 WiMAX 1.x, 3.xGHz Open Standards at all levels to ensure interoperability and reduce technology risk for utilities 15-20 years lifetime and future proofing Internet has 25 years lifetime and is continuously evolving

Field Area Network Architecture SIEM DB DMS DMS DMS SCADA CG-NMS SIEM Certificate Intrusion Authority Prevention MDM CIS MDM Billing & Pre-Payment Mgmt ORS Data Integrity & privacy: IPSec Traffic prioritization: IP QoS Scalable & reliable IP VPN MDMS AMI Head-End HER Public or Private IP Infrastructure Directory Services Access Control Network & Security Services Data Center, Enterprise Apps Zero Touch Provisioning Users and devices Authentication Devices management Open standards Neighborhood Area Network (NAN): IEEE 802.15.4g/e RF or/and IEEE 1901.2 PLC Mesh IPv6 based communications 6LoWPAN, RPL, Fully Secured AES 128 encryption, IEEE 802.1x authentication, IEEE 802.11i key management Network Management CoAP based, Zero Touch Provisioning, Over-the-Air firmware upgrade

Security Architecture Certificate-based identities, user names & passwords Role based Access Control 802.1x-based access control for meters, routers, grid devices Link-layer encryption in RF Mesh Group-based key generation and management (mesh) Network-layer encryption for WAN Backhaul (IPSec) Directory Services Certificate Authority AAA Server Security Services Field Area Router (FAR) CGR 1000 Series Intrusion Prevention Public or Private WAN Neighborhood Area Network (RF Mesh) NMS AMI Head-End HES SIEM FAN Aggregation Layer within Substation Automation Network Mobile Workforce Secure Device Identity via Digital Certificates Strong user identities with Role-Based Access Time-stamped logs, correlation at SIEM Separation of AMI vs. non-ami traffic, segmentation 15 Smart Meters Secure storage for encryption keys Secure encryption keys Network-layer encryption (IPSec) Link-layer encryption (AES-128)

Sub-1GHz Regulations around the World Ultra NarrowBand China 2 W ** Europe India Hong-Kong Iran UAE 2 W ** USA Canada Chile Colombo Mexico Argentina Uruguay Venezuela 902-928MHz 4 W * Brazil 902-907.5, 915-928 MHz 4 W * Australia 915-928MHz Korea 917-923.5MHz 4 W * S.A. 4 W ** Israel 2 W * Malaysia 2 W ** China 2 W ** Allocated Frequency bands Licensed/unlicensed (ISM) Transmit power Time transmitting Japan (2012) 915-930MHz 4 W* 0.5 / 0.02 W * Licensed/unlicensed Hong-Kong 920-924 MHz Thailand 2 W * Singapore 0.5 W ** Singapore 2 W ** 840 850 860 870 880 890 900 910 920 930 940 950 MHz * e.i.r.p. ** e.r.p. Source: CEPT - DKE 731.09r1 JSC E.U CEPT new frequency bands discussion (870-876MHz 500mW and 915-921MHz 25mW) 2013-2014 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16

Wi-SUN Alliance Vision: Drive industry to embrace open standards and interoperability. Definition of Wi-SUN profile based on IEEE 802.15.4g/e Reduce technology risk Testing Certification www.wi-sun.org 17

Certification for products built on the IEEE 1901.2 Low-Frequency, Narrow-Band Powerline Communications standard Leverages HomePlug s long established programs & expertise in testing & certifying powerline networking products. HomePlug will promote the adoption of Netricity products to foster an ecosystem served by multiple technology vendors. The Netricity program is supported by HomePlug Alliance member companies:

twitter: @alainfiocco email: afiocco@cisco.com

Connected Grid Network Management The Connected Grid NMS Solution provides grid operators Scalable, Utility Ops communication management Enterprise-class visibility for up to 10M endpoints Secure network commissioning, monitoring and life cycle management via well-defined interfaces Integration with Utility Operations and Enterprise Bus The Cisco Connected Grid Device Manager provides Device level network monitoring and troubleshooting 23

CG-NMS Visualization

Cisco 1240 Connected Grid Router Outdoor Model (Pole Mounted) GPS Antenna Battery Backup Ethernet Switch 2GE WAN (Cu or SFP), 4FE LAN 2 RS 232/RS 485 Serial Ports Ruggedized, IP67 Ethernet (RJ-45) Connector Four Module Slots Integrated Antennas for: RF Mesh, WiMAX, 2G/3G, WiFi Liquid Tight (IP67) Adapter Estimated dimensions: 30.5 cm (H) x 20.3 (W) x 19 cm (D) = 12 (H) x 8.0 (W) x 7.5 (D) Antennas shown above are optional; can be deployed with external antennas

Cisco 1120 Connected Grid Router Indoor Model (Din-Rail Mounted) Fiber WAN 2 GE SFP Ethernet Switch 2GE WAN, 6FE Serial RS-232, RS-485 Console and Alarm Ports Three Phase AC Input GPS Antenna Slot 1 Integrated AC and DC PS Module Slots DC Input Slot 2 Wi-Fi Antenna Substation hardened IEC61850-3 and IEEE1613-compliant Fixed memory Din-rail mounted Convection cooled No fans and/or moving parts Increased operating temp Dimensions 8.9 cm (H) x 22.9 cm (W) x 20 cm (D) = 3.5" (H) x 9.0" (W) x 7.8" (D)

Industrial Router 500 915 MHz RF Mesh DA Gateway LEDs viewable from top and front Two Serial Ports One 10/100 Ethernet Port Reset Switch Transport Distribution Automation and SCADA over IPv6 RF Mesh Ruggedized for harsh industrial environments Compact size and low power Authentication and encryption IP quality of service RF mesh aggregated by CGR1000 Series Managed by Connected Grid NMS and Device Manager 915 MHz RF Connector USB Port 9-60 VDC PWR/Alarm Form Factor Specifications Compact form factor: 4.5 x 5.5 x 1.25 Fixed configurations- Panel / DIN rail mount IP-30 rating IEC 61850-3 / IEEE 1613 Extended Temperature range (-40C to +70C) Mounting Feet (can be moved to front and back)