Abstract:
The invention relates to the field of a security framework for transmitting communication messages between a Substation LAN and packet-switched WAN, in particular, a network interface for transmitting protection data in a power network. The present invention provides a network interface for transmitting communication data including protection data of a power communication network, between a Substation Ethernet LAN and a packet-switched WAN usually in Layer 2. The network interface comprises: a firewall and a layer 3 router being connected with each other and adapted to transmit the communication data excluding the protection data; and a layer 2 bypass being in parallel with the firewall and the layer 3 router, and adapted to transmit the protection data. According to a further aspect, the present invention also provides a method for transmitting such communication data.
Abstract:
The present invention proposes the use of transparent transmission of teleprotection commands in the form of GOOSE or GSSE messages, as defined by the Generic Substation Event (GSE) class model by the standard IEC 61850, between substations combined with Channel Supervision and Monitoring (CSM) equivalent to CSM offered by conventional teleprotection equipment. This approach avoids the disadvantage of non-transparent transmission when using the gateway approach and of the lack of the CSM functionality when using the tunnelling approach.
Abstract:
The present invention discloses a method of transmitting time-critical messages in an OSI layer 2 network tunnel from an IED in a first substation to an IED in a second substation over a WAN, wherein each of the first and second substation comprises an edge IED and is associated with a substation LAN, wherein each of the time-critical messages comprises message parameters. The method comprises the steps of: a) creating a translation table comprising corresponding values of the message parameters, between the LANs and the WAN, b) defining a virtual IED model in the second substation using the translated values of the message parameters, to impersonate the IED of the first substation, c) translating the message parameters according to the translation table, d) forwarding the time-critical messages from the IED in the first substation to the WAN, and e) receiving the time-critical messages by the IED of the second substation from the WAN.