Home
Parent Menu
IntelliGrid Project Power System Functions IntelliGrid Environments IntelliGrid Vision Technical Analysis Technology List Additional Information Printable Deliverables
Same Level Menu
Env1 High Speed Intra-Substation Env2 High Speed Inter-Substation Env3 High Secure Intra-Substation Env4 Inter Field Equipment Env5 Critical DAC Env6 Non-Critical DAC Env7 Intra-Control Center Env8 Inter-Control Center Env9 Control Centers to ESPs Env10 RTOs to Market Participants Env11 Control Center to Customers Env12 Control Centers to Corporate Env13 Intra-Corporation Env14 Inter-Corporation Env15 DER Monitoring and Control Env16 Intra-Customer Site Env17 Inter-Customer Sites Env18 Customer to ESP Env19 HV Generation Plant Env20 Maintenance
Child Menu
Questions/Comments
Questions
Responses
Control Center to Customers Environment - #11
This
environment encompasses the requirements for what has traditionally
been called commercial or industrial metering. It includes the
requirements for any data exchange that travels directly to the
control center from a customer site, without involving substations or
data aggregators.
Typical Applications: Metering of large
customers, control of distributed energy resources, limiting demand
under heavy loads by requesting customers drop off.
Characteristics: Business-to-business
communications, but involving operational rather than monetary data.
Medium to high volumes of data coming from many sources, but only
moderately high security requirements because of the nature of the
data. Configuration may change significantly on a monthly basis.
Similar Environments: Similar in
requirements to Critical Operations DAC except attackers could not do
as much damage by controlling this environment, and the quality of
service need not be as quite as high. It is otherwise similar,
technologically, to other business-to-business environments.
Definition: This environment is defined
by the following requirements:
Communication and Information Requirements that Define this Environment
Configuration Requirements
Support interactions between a few "clients" and many "servers"
Support interactions across widely distributed sites
Support multi-cast or broadcast capabilities
Support the frequent change of configuration and/or location of end devices or sites
Quality of Service Requirements
Support medium availability of information flows of 99.0+ (~3.5 days)
Security Requirements
Provide Authorization Service for Access Control (resolving a policy-based access control decision to ensure authorized entities have appropriate access rights and authorized access is not denied)
Provide Confidentiality Service (only authorized access to information, protection against eavesdropping)
Provide Inter-Domain Security Service (support security requirements across organizational boundaries)
Provide Audit Service (responsible for producing records, which track security relevant events)
Provide Security Policy Service (concerned with the management of security policies)
Provide Firewall Transversal
Provide Privacy Service (the ability to ensure person information is not disclosed)
Provide User Profile and User Management (combination of several other security services)
Provide Security Protocol mapping (the ability to convert from one protocol to another)
Provide Security Discovery (the ability to determine what security services are available for use)
Network and System Management Requirements
Provide Network Management (management of media, transport, and communication nodes)
Provide System Management (management of end devices and applications)
Data Management Requirements
Support the management of large volumes of data flows
Support extensive data validation procedures
Support management of data whose types can vary significantly in different implementations
Support specific standardized or de facto object models of data
Provide discovery service (discovering available services and their characteristics)
Provide conversion and protocol mapping
Support the management of data across organizational boundaries
Recommended Technologies
Energy Industry-Specific Technologies
Utility Field Device Related Data Exchange Technologies
Utility Control Center Related Data Management Technologies
Customer Interface Data Management Technologies Communications Industry Technologies
Access Technologies
Networking Technologies
IP-based Transport Protocols
Link Layer and Physical Technologies
Computer Systems Related Technologies
General Internet and De Facto Data Management Technologies
eCommerce Related Data Management Technologies Security Technologies
Policy and Framework Related Technologies
General Security Technologies
PKI - Public Key Infrastructure (X.509)
- Security,
Kerberos
- Security,
FIPS 140-2 Security Requirements for Cryptographic Modules
- Security,
FIPS 197 for Advanced Encryption Standard (AES)
- Security,
Role-Based Access Control
- Security,
PKCS
- Security,
Intrusion Detection Technologies
- Security, Network Management,
Intrusion Prevention Systems (IPS)
- Security, Network Management,
Service Level Agreements (SLA)
- Security,
Media and Network Layer Technologies
Transport Layer Security Technologies
Application Layer Security Technologies
RFC 2228 FTP Security Extensions
- Security,
Internet Mail Extensions
- Security,
RFC 2086 IMAP4 ACL extension
- Security,
SNMP Security
- Security, Network Management,
RFC 1305 Network Time Protocol (Version 3) Specification, Implementation
- Security,
IEC 62351-3 Security for Profiles including TCP/IP
- Security,
IEC 62351-4 Security for Profiles including MMS (ISO-9506)
- Security,
IEC 62351-5 Security for IEC 60870-5 and Derivatives
- Security,
IEC 62351-6 Security for IEC 61850 GOOSE, GSSE, and SMV Profiles
- Security,
XML Related Technologies Network and Enterprise Management Technologies
Network Management Technologies
Web-based Network Management Security Services
Common Security Services
Audit Common Service
- Security,
Authorization for Access Control
- Security,
Confidentiality
- Security,
Firewall Traversal
- Security,
Inter-Domain Security
- Security,
Security Policies
- Security,
Privacy Service
- Security,
Security Protocol Mapping
- Security,
Security Service Availability Discovery Service
- Security,
User and Group Management
- Security,
Network and System Management Services
Enterprise Management Services
Inventory Management
- Network Management,
Communication System/Network Discovery
- Network Management,
Routing Management
- Network Management,
Traffic Management
- Network Management,
Traffic Engineering
- Network Management,
System/Network Health-Check Analysis
- Network Management,
System/Network Fault Diagnosis
- Network Management,
System/Network Fault Correcting
- Network Management,
Service Level Agreement (SLA) Determination and Maintenance
- Network Management,
System/Network Performance Analysis
- Network Management,
System/Network Performance Diagnosis
- Network Management,
Performance Tuning/Correction
- Network Management,
Accounting and/or Billing
- Network Management,
Data Management Common Services
Data Management Common Services Common Platform Services
Common Platform Services Data Management Best Practices
Data Management Security Best Practices
Security Frameworks and Policy Documents
ISO/IEC Security Best Practices
- Security,
ISO/IEC 18014-3:2004 Information technology -- Security techniques -- Time-stamping services -- Part 3: Mechanisms producing linked tokens
- Security,
Federal Security Best Practices
- Security,
CICSI 6731.01 Global Command and Control System Security Policy
- Security,
IETF Security Best Practices Internet Requests for Comments (RFCs)
- Network Management,
RFC 1102 Policy routing in Internet protocols
- Network Management,
RFC 1322 A Unified Approach to Inter-Domain Routing
- Network Management,
RFC 1351 SNMP Administrative Model
- Network Management,
RFC 2008 Implications of Various Address Allocation Policies for Internet Routing
- Network Management,
RFC 2196 Site Security Handbook
- Network Management,
RFC 2276 Architectural Principles of Uniform Resource Name Resolution
- Security,
RFC 2386 A Framework for QoS-based Routing in the Internet
- Security, Network Management,
RFC 2505 Anti-Spam Recommendations for SMTP
- Security,
RFC 2518 HTTP Extensions for Distributed Authoring - WEBDAV
- Network Management,
RFC 2527 Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework
- Network Management,
Security Technology Documents
IETF Internet Requests for Comments (RFCs) on Security Technologies
Alternative Technologies
Utility Field Device Related Data Exchange Technologies
Networking Technologies
IP-based Transport Protocols
Link Layer and Physical Technologies
IEEE 802.1d Spanning Tree Protocol (STP)
- Network Management,
IEEE 802.1w Rapid Spanning Tree Protocol (RSTP)
- Network Management,
Hubs/Repeaters
- Configuration,
Bridges/Switches
- Configuration,
Routers
- Configuration,
Digital Signal (DSx), Time-division multiplexing, the T-carriers, T1, fractional T1
- Configuration,
Frame Relay
- Configuration,
Wireless Technologies
Code-Division Multiple Access 2000 (CDMA-2000)
- Configuration,
TDMA Cellular Wireless - IS-136
- Configuration,
CDMA Cellular Wireless - IS-95
- Configuration,
Cellular Digital Packet Data (CDPD)
- Configuration,
Global System for Mobile Communication (GSM)
- Configuration,
Short Message Service (SMS)
- Configuration,
Trunked Mobile Radio (TMR, TETRA, Project25)
- Configuration,
IEEE 802.16 Broadband Wireless Access Standards
- Configuration,
Radio Frequency Identification (RFID)
- Data Management
Virtual Private Networking Technologies
General Internet and De Facto Data Management Technologies
Network Management Technologies
Web-based Network Management
Alternative Best Practices
Data Management
ISO/IEC Documents on Security Technologies
ISO/IEC 7816-4:1995/Amd 1:1997 secure messaging on the structures of APDU messages
- Security,
ISO/IEC 7816-8:1999 Identification cards -- Integrated circuit(s) cards with contacts -- Part 8: Security related
- Security,
ISO/IEC 7816-9:2000 Identification cards -- Integrated circuit(s) cards with contacts -- Part 9: Additional
- Security,
ISO/IEC 9594-8:2001 Information technology -- Open Systems Interconnection -- The Directory: Public-key and attribute certificate frameworks
- Security,
ISO 9735-5:2002 Electronic data interchange for administration, commerce and transport (EDIFACT) -- Application level syntax rules (Syntax version number: 4, Syntax release number: 1) -- Part 5: Security rul
- Security,
ISO/IEC 10164-9:1995 Information technology -- Open Systems Interconnection -- Systems Management: Objects and attributes for access control
- Security,
ISO/IEC 10181-1:1996 Information technology -- Open Systems Interconnection -- Security frameworks for open systems: Overview
- Security,
ISO/IEC 10181-3:1996 Information technology -- Open Systems Interconnection -- Security frameworks for open systems: Access control framework
- Security,
ISO 10202-8:1998 Financial transaction cards -- Security architecture of financial transaction systems
- Security,
ISO/IEC TR 13335-1:1996 Information technology -- Guidelines for the management of IT Security -- Part 1: Concepts and models for IT Security
- Security,
ISO/IEC TR 13335-2:1997 Information technology -- Guidelines for the management of IT Security -- Part 2: Managing and planning IT Security
- Security,
ISO/IEC TR 13335-5 Information technology - Guidelines for the management of IT Security - Part 5: Management guidance on network security
- Security,
ISO/IEC 13888-1:1997 Information technology -- Security techniques -- Non-repudiation -- Part 1: General
- Security,
ISO/IEC 15408-1:1999 Information technology -- Security techniques -- Evaluation criteria for IT security -- Part 1: Introduction and general mode
- Security,
ISO/IEC 15408-2:1999 Information technology -- Security techniques -- Evaluation criteria for IT security -- Part 2: Security functional requirements
- Security,
ISO/IEC 17799:2000 Information technology -- Code of practice for information security management
- Security,
Federal Documents on Security Technologies
IETF Internet Requests for Comments (RFCs) on Security Technologies
RFC 1040 Privacy enhancement for Internet electronic mail: Part I: Message
- Security,
RFC 1423 Privacy Enhancement for Internet Electronic Mail: Part III: Algorithms, Modes, and Identifiers
- Security,
RFC 1352 SNMP Security Protocols
- Network Management,
RFC 1579 Firewall-Friendly FTP
- Security,
RFC 1827 IP Encapsulating Security Payload (ESP)
- Security,
RFC 1940 Source Demand Routing: Packet Format and Forwarding Specification (Version 1)
- Network Management,
RFC 1968 The PPP Encryption Control Protocol (ECP)
- Security,
RFC 2040 The RC5, RC5-CBC, RC5-CBC-Pad, and RC5-CTS Algorithms
- Security,
RFC 2045 Multi-Purpose Internet Mail Extensions (MIME) and Secure/MIME
- Security,
RFC 2086 IMAP4 ACL extension
- Security,
RFC 2093 Group Key Management Protocol (GKMP) Specification
- Security,
RFC 2228 FTP Security Extensions
- Security,
RFC 2230 Key Exchange Delegation Record for the DNS
- Security,
RFC 2244 ACAP -- Application Configuration Access Protocol
- Security,
RFC 2246 The TLS Protocol Version 1.0
- Security,
RFC 2313 PKCS #1: RSA Encryption Version 1.5
- Security,
RFC 2315 PKCS #7: Cryptographic Message Syntax Version 1.5
- Security,
RFC 2356 Sun's SKIP Firewall Traversal for Mobile IP
- Security,
RFC 2406 IP Encapsulating Security Payload (ESP)
- Security,
RFC 2437 PKCS #1: RSA Cryptography Specifications Version 2.0
- Security,
RFC 2440 OpenPGP Message Format
- Security,
RFC 2408 Internet Security Association and Key Management Protocol (ISAKMP)
- Security,
RFC 2409 The Internet Key Exchange (IKE)
- Security,
RFC 2459 Internet X.509 Public Key Infrastructure Certificate and CRL Profile
- Security,
RFC 2510 Internet X.509 Public Key Infrastructure Certificate Management Protocols
- Security,
RFC 2511 Internet X.509 Certificate Request Message Format
- Security,
RFC 2527 Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework
- Security,
RFC 2547 BGP/MPLS VPNs
- Security, Network Management,
RFC 2560 X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP
- Security,
RFC 2764 A Framework for IP Based Virtual Private Networks
- Security, Network Management,
RFC 2753 A Framework for Policy-based Admission Control
- Security,
RFC 2797 Certificate Management Messages over CMS
- Security,
RFC 2875
- Security,
RFC 2888 Secure Remote Access with L2TP
- Security,
RFC 2898 PKCS #5: Password-Based Cryptography Specification Version 2.0
- Security,
RFC 2946 Telnet Data Encryption Option
- Security,
RFC 2977 Mobile IP Authentication, Authorization, and Accounting Requirements
- Security,
RFC 2979 Behavior of and Requirements for Internet Firewalls
- Security,
RFC 2985 PKCS #9: Selected Object Classes and Attribute Types Version 2.0
- Security,
RFC 3053 IPv6 Tunnel Broker
- Network Management,
RFC 3268 Advanced Encryption Standard (AES) Ciphersuites for Transport Layer Security (TLS)
- Security,
RFC 3280 Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile
- Security,
RFC 3369 Cryptographic Message Syntax (CMS)
- Security,
RFC 3370 Cryptographic Message Syntax (CMS) Algorithms
- Security,
RFC 3414 User-based Security Model (USM) for version 3 of the Simple Network Management Protocol (SNMPv3)
- Network Management,
RFC 3447 Public-Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1
- Security,
RFC 3647 Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework
- Security,
Other Security Technolog
IEEE 802.11b Web Encryption Protocol
- Security,
IEEE 802.11i Security for Wireless Networks
- Security,
RSA Documents on Security Technologies
- Security,
RSA PKCS #8 Private-Key Information Syntax Standard
- Security,
RSA PKCS #12 Personal Information Exchange Syntax Standard, version 1.0.
- Security,
OASIS Documents on Security Technologies
- Security,
WC3 XML Key Management Specification (XKMS 2.0) Bindings
- Security,
W3C The Platform for Privacy Preferences 1.1 (P3P1.1) SpecificationW3C Working Draft 27 April 2004
- Security,
AGA-12 Cryptographic Protection of SCADA Communications General Recommendations.
- Security,
ANSI INCITS 359-2004 Role Based Access Control (RBAC)
- Security,
EPRI 1002596 ICCP TASE.2 Security Enhancements
- Security,
NERC Certificate Policy for the Energy Market Access and Reliability Certificate (e MARC) Program Version 2.4
- Security,
WebDAV Access Control Extensions to WebDAV
- Security,
WPA WI-FI Protected Access
- Security,
WPA2 WI-FI Protected Access Version 2
- Security,
Possible Technologies
Utility Field Device Related Data Exchange Technologies
Networking Technologies
Wireless Technologies