User's Manual
Table Of Contents
- Table of Contents
- List of Tables
- List of Figures
- Figure1.1 Typical SEL3022 and SEL5810 Virtual Serial Software Application 1.2
- Figure1.2 Encrypted Packet Stream 1.4
- Figure1.3 Typical Connections for the SEL3022 1.6
- Figure1.4 Typical Alarm Output Installation 1.8
- Figure2.1 SEL3022 Dimension Drawing 2.2
- Figure2.2 Windows Run Command 2.3
- Figure2.3 Product Unregistered Prompt 2.4
- Figure2.4 Select a Device Type to Create 2.7
- Figure2.5 Specify New Device Location 2.8
- Figure2.6 Opening Device 2.8
- Figure2.7 Identification Screen 2.9
- Figure2.8 Status: Device 2.10
- Figure2.9 Settings: Wireless 2.10
- Figure2.10 Settings: WEP Keys 2.11
- Figure2.11 Settings: User 2.11
- Figure2.12 Settings: Operator 2.12
- Figure2.13 Settings: Security Officer 2.12
- Figure2.14 Confirm Send Prompt 2.13
- Figure2.15 Send Operation Message 2.13
- Figure2.16 Select Items to Print 2.14
- Figure2.17 Print Window 2.14
- Figure3.1 Remotely Located Recloser Control 3.2
- Figure3.2 Job Done Example SEL-5809 Top Level View 3.3
- Figure3.3 Select a Wireless Session for DNP3 Job Done Example 3.4
- Figure3.4 Settings: DCE Port 3.4
- Figure3.5 Status: Virtual Serial Port With Connection Status Red 3.5
- Figure3.6 Communication Parameters Window in acSELerator 3.6
- Figure3.7 Status: Virtual Serial Port With Connection Status Green 3.6
- Figure3.8 Reading Settings Via the SEL3022 3.7
- Figure3.9 Monitoring SEL651R Meter Data Via the SEL3022 3.8
- Figure3.10 Status: Virtual Serial Port Connection Status Red 3.9
- Figure3.11 Specify Device to Export to SEL5810 Virtual Serial Software 3.10
- Figure3.12 Export Encrypted User Configuration File 3.10
- Figure3.13 Store Encrypted File 3.11
- Figure3.14 Password Prompt in SEL5810 Virtual Serial Software 3.12
- Figure3.15 Communication Parameters Window in acSELerator 3.13
- Figure3.16 Reading SER Report Via acSELerator 3.14
- FigureB.1 PC to SEL3022 Connection B.2
- FigureB.2 SEL3022 and SEL-5809 Connection Parameters B.2
- FigureB.3 SEL5809 Settings Software Connection Method B.3
- FigureB.4 SEL-5809 Opening Connection B.3
- FigureB.5 Status: Device Window B.4
- FigureB.6 Confirmation Prompt B.4
- FigureB.7 Send Operation Prompt B.4
- FigureB.8 Configuring Serial Port Settings in the Terminal Software B.5
- FigureB.9 Send File Prompt B.6
- FigureB.10 Sending Confirmation Window B.6
- FigureB.11 Terminal Invalid Firmware Error Message B.7
- FigureB.12 Terminal Valid Firmware Message B.7
- FigureC.1 Two Independent Layers of Cryptographic Security Protect the SEL3022 Wireless Operato...
- FigureC.2 Operation of the HMAC SHA-1 Keyed Hash Authentication Function C.9
- FigureC.3 Operation of the AES Encryption Function C.10
- FigureC.4 SEL3022 Security Application Overview C.11
- FigureC.5 Wireless Interface Session Authentication Dialog C.15
- Preface
- Introduction & Specifications
- Installation
- Job Done Example
- Settings and Commands
- Testing and Troubleshooting
- Firmware and Manual Versions
- Firmware Upgrade Instructions
- Wireless Operator Interface Security
- Introduction
- Wireless Interface Security Overview
- IEEE 802.11 WEP Security
- The SEL Security Application
- Certificates
- Glossary
Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Introduction & Specifications
Product Overview
1.3
Cryptographic Manual—Do Not Copy
SEL-3022 Transceiver
The SEL-3022 consists of two communication ports: the EIA-232 and IEEE 802.11b.
The EIA-232 serial port connects to an IEDs EIA-232 serial port. The SEL-3022 and
IED exchange unencrypted data such as engineering access data. The SEL-3022 forms
an authentication message and encrypts the data received by the IED then passes it to
the IEEE 802.11b port. The IEEE 802.11b communication port transmits the encrypted
data to the PC/PDA running the SEL-5809 Settings Software or SEL-5810 Virtual
Serial Software. When the SEL-3022 802.11b port receives a message it decrypts and
authenticates the message. If the message decrypts and authenticates correctly the
message is passed to the serial port, otherwise the session is terminated.
SEL-5809 Settings Software and SEL-5810
Virtual Serial Software
The SEL-5809 Settings Software and SEL-5810 Virtual Serial Software are used to
communicate with the SEL-3022. The SEL-5809 Settings Software consists of three
major functions or roles: Security Officer, Operator, and User. The security officer has
access to all of the SEL-3022 configuration parameters including the cryptographic
settings. The operator has access to all of the SEL-3022 configuration parameters
except the cryptographic settings. Both the security officer and operator modes are
used to configure the SEL-3022. The user role generates a virtual serial port that allows
applications to encrypt and decrypt data between the PC and the IED that the
SEL-3022 is connected to. In the user role you cannot modify SEL-3022 configuration
parameters. To change roles you must exit the current role and reestablish a connection
to the new access level.
The SEL-5810 Virtual Serial Software is a subset of the SEL-5809 Settings Software,
and only allows connection to the SEL-3022 in the user role.
Your company security officer, or person in charge of configuring cryptographic
settings, would typically use the SEL-5809 Settings Software to configure the
SEL-3022 transceivers. After the SEL-3022 transceivers have been configured the
security officer can configure a PC and PDA with the SEL-5810 Virtual Serial
Software for field personnel (i.e., workers who need engineering access to the IEDs
connected to the SEL-3022 transceivers, but who do not need to configure the
SEL-3022 transceivers).
Both the SEL-5809 Settings Software and SEL-5810 Virtual Serial Software allow you
to integrate your standard EIA-232 serial port programs with wireless port via the
SEL-5810 Virtual Serial Software encrypting engine to a 802.11b port. When the SEL-
5809 Settings Software/SEL-5810 Virtual Serial Software receives a message from a
PC program,
ACSELERATOR for example, the virtual serial port generates an
authentication message that is appended to the original message, which is then
encrypted. The SEL-5809 Settings Software/SEL-5810 Virtual Serial Software then
passes the encrypted message to the 802.11b port for transmission to the SEL-3022.
Preliminary Copy