SCYC51010 58052515G PLC控制板 通过前端通信端口将笔记本电脑连接到IED。 •通过LAN/WAN远程。 2.6授权 已为LHMI和WHMI预定义了用户类别,每个类别具有 不同的权限和默认密码。 可以使用管理员用户权限更改默认密码。 默认情况下禁用用户授权,但WHMI始终使用 批准 1MRS756378 K第2节 参考文献615概述 参考文献615:19 应用手册 表5:预定义用户类别 用户名和用户权限 查看器只读访问 操作员•选择远程或本地状态(仅本地) •更改设置组 •控制 •清除指示 工程师•更改设置 •清除事件列表 •清除干扰记录 •更改系统设置,如IP地址、串行波特率 或干扰记录器设置 •将IED设置为测试模式 •选择语言 管理员•以上列出的所有 •更改密码 •出厂默认激活 有关PCM600的用户授权,请参阅PCM600文档。 2.6.1审计跟踪 615系列IED提供了大量事件记录功能。正常过程相关 普通用户可以使用PCM600中的事件查看器查看事件。关键 系统和IED安全相关事件记录在单独的非易失性审计中 管理员的跟踪。 审计跟踪是系统活动的按时间顺序记录 事件和/或变化序列的重建和检查 事件可以以一致的方式检查和分析过去的用户和流程事件 方法,借助于PCM600中的事件列表和事件查看器。IED存储 2048个系统事件到非易失性审计跟踪。此外,1024个进程事件 存储在非易失性事件列表中。审核跟踪和事件列表都根据 按照先进先出原则。 用户审计跟踪是根据IEEE选定的一组要求定义的 1686.日志记录基于预定义的用户名或用户类别。用户 IEC 61850-8-1、PCM600、LHMI和WHMI支持审计跟踪事件。 表6:审计跟踪事件 枚举说明/注释 配置更改配置文件已更改 固件更改 设置组远程用户更改了设置组远程 下一页续表 第2节1MRS756378 K 参考文献615概述 20参考文献615 应用手册 枚举说明/注释 设置组本地用户更改了设置组本地 控制远程DPC对象控制远程 控制本地DPC对象控制本地 测试开启测试模式开启 测试关闭测试模式关闭 设置提交设置已更改 时间变化 查看管理员访问的审核跟踪的审核日志 登录 注销 固件重置:由用户或工具发出的重置 审核溢出:时间段中的审核事件太多 PCM600事件查看器可用于与一起查看审核跟踪事件 正常事件。由于只有管理员有权读取审计跟踪, 必须在PCM600中正确配置授权。审核跟踪不能 重置,但PCM600事件查看器可以过滤数据。一些审核跟踪事件包括: 作为正常的过程事件也很有趣。 为了将审计跟踪事件也公开为正常过程事件, 通过配置/授权定义级别参数/ 权限日志记录。 表7:审计跟踪事件 审核跟踪事件权限日志记录 没有一个 配置 改变 背景 组 背景 组 控制 设置 编辑 配置更改x x x x 固件更改x x x x 设置组远程x x x 设置组本地x x x 遥控器x x 控制本地x x x上的测试 测试x x 设置提交x 时间变化 查看审核日志 登录 下一页续表 1MRS756378 K第2节 参考文献615概述 参考文献615:21 应用手册 审核跟踪事件权限日志记录 注销 固件重置 审计溢出 2.7通信 IED支持一系列通信协议,包括IEC 61850、IEC 60870-5-103、Modbus®和DNP3。操作信息和控制包括 可通过这些协议获得。然而, 例如,IED之间的水平通信仅由 IEC 61850通信协议。 IEC 61850通信实现支持所有监控和 控制功能。此外,参数设置、干扰记录和 可以使用IEC 61850协议访问故障记录。干扰记录 可用于标准COMTRADE文件中的任何基于以太网的应用程序 总体安排IED可以发送和接收来自其他IED的二进制信号(所谓 水平通信),其中 支持总传输时间为3毫秒的高性能等级。 此外,IED支持使用GOOSE发送和接收模拟值 消息传递。IED满足GOOSE跳闸性能要求 IEC 61850标准定义的配电变电站应用。这个 IED可以同时向statio上的五个不同客户端报告事件 SCYC51010 58052515G PLC控制板 SCYC51010 58052515G PLC控制板 Locally by connecting your laptop to the IED via the front communication port. • Remotely over LAN/WAN. 2.6 Authorization The user categories have been predefined for the LHMI and the WHMI, each with different rights and default passwords. The default passwords can be changed with Administrator user rights. User authorization is disabled by default but WHMI always uses authorization. 1MRS756378 K Section 2 REF615 overview REF615 19 Application Manual Table 5: Predefined user categories Username User rights VIEWER Read only access OPERATOR • Selecting remote or local state with (only locally) • Changing setting groups • Controlling • Clearing indications ENGINEER • Changing settings • Clearing event list • Clearing disturbance records • Changing system settings such as IP address, serial baud rate or disturbance recorder settings • Setting the IED to test mode • Selecting language ADMINISTRATOR • All listed above • Changing password • Factory default activation For user authorization for PCM600, see PCM600 documentation. 2.6.1 Audit trail 615 series IEDs offer a large set of event logging functions. Normal process related events can be viewed by the normal user with Event Viewer in PCM600. Critical system and IED security related events are logged to a separate non-volatile audit trail for the administrator. Audit trail is a chronological record of system activities that enable the reconstruction and examination of the sequence of events and/or changes in an event. Past user and process events can be examined and analyzed in a consistent method with the help of Event List and Event Viewer in PCM600. The IED stores 2048 system events to non-volatile audit trail. Additionally, 1024 process events are stored in non-volatile event list. Both audit trail and event list work according to the FIFO principle. User audit trail is defined according to the selected set of requirements from IEEE 1686. The logging is based on predefined usernames or user categories. The user audit trail events are supported in IEC 61850-8-1, PCM600, LHMI and WHMI. Table 6: Audit trail events Enum Explanation/note Configuration change Configuration files changed Firmware change Setting group remote User changed setting group remotely Table continues on next page Section 2 1MRS756378 K REF615 overview 20 REF615 Application Manual Enum Explanation/note Setting group local User changed setting group locally Control remote DPC object control remote Control local DPC object control local Test on Test mode on Test off Test mode off Setting commit Settings has been changed Time change View audit log Administrator accessed audit trail Login Logout Firmware reset Reset issued by user or tool Audit overflow Too many audit events in the time period PCM600 Event Viewer can be used to view the audit trail events together with normal events. Since only the administrator has the right to read audit trail, authorization must be properly configured in PCM600. The audit trail cannot be reset but PCM600 Event Viewer can filter data. Some of the audit trail events are interesting also as normal process events. To expose the audit trail events also as normal process events, define the level parameter via Configuration/Authorization/ Authority logging. Table 7: Audit trail events Audit trail event Authority logging None Configuration change Setting group Setting group, control Settings edit Configuration change x x x x Firmware change x x x x Setting group remote x x x Setting group local x x x Control remote x x Control local x x Test on x x Test off x x Setting commit x Time change View audit log Login Table continues on next page 1MRS756378 K Section 2 REF615 overview REF615 21 Application Manual Audit trail event Authority logging Logout Firmware reset Audit overflow 2.7 Communication The IED supports a range of communication protocols including IEC 61850, IEC 60870-5-103, Modbus® and DNP3. Operational information and controls are available through these protocols. However, some communication functionality, for example, horizontal communication between the IEDs, is only enabled by the IEC 61850 communication protocol. The IEC 61850 communication implementation supports all monitoring and control functions. Additionally, parameter settings, disturbance recordings and fault records can be accessed using the IEC 61850 protocol. Disturbance recordings are available to any Ethernet-based application in the standard COMTRADE file format. The IED can send and receive binary signals from other IEDs (so called horizontal communication) using the IEC61850-8-1 GOOSE profile, where the highest performance class with a total transmission time of 3 ms is supported. Further, the IED supports sending and receiving of analog values using GOOSE messaging. The IED meets the GOOSE performance requirements for tripping applications in distribution substations, as defined by the IEC 61850 standard. The IED can simultaneously report events to five different clients on the station bus. The IED can support five simultaneous clients. If PCM600 reserves one client connection, only four client connections are left, for example, for IEC 61850 and | SCYC51010 58052515G PLC控制板 | | | |