Download as pdf or txt
Download as pdf or txt
You are on page 1of 4

eTechnology

Embedded
web technology
adding a new dimension
to protection and control
Daniel Tabara, Hendro Rijanto, Bruno Sabbattini

Since the first relays featuring integrated protection and control functionality appeared some
years ago, more and more relays with dual functionality have come onto the market. Soon,
however, even these units will find it hard to compete in certain areas of application. A new
class of relay is on the way.

The first web-enabled relays are making their way into the marketplace, and the benefits they
offer are enormous. Besides letting users remotely monitor substations, the relays themselves
can be controlled and parameterized from a remote location. And the possibilities are not
restricted to Internet functionality; GPS, CAN bus, LON and Ethernet technologies will also play
a role in future substation development. A good example of this new kind of protection and
control device is ABB’s multifunctional relay, REF542plus.

C
ontrol and protection equipment parameterized using the same method. embedded web technology to turn units
for utility and industrial substations, Protection and control functions are into Internet appliances. These can then
often referred to as ‘secondary technology’, treated separately to reflect the separation be connected to a computer network to
has gone through a revolution of late. of these tasks in a utility. access and store data, and can be
Microprocessors have made it possible to Now, Internet technology is entering managed and controlled remotely.
unify their separate functions in one single the field of protection and control. Why, the question could be asked,
unit and then configure the combined Anticipating this trend, ABB has web- would a company want to turn an
functionality, via software, on a PC. enabled the REF542plus to prepare it for already successful product into an
This is what ABB has done in its the new era. Although talk here is Internet appliance? The obvious answer
‘REF542plus’ – a new-generation relay for mainly of the Internet, there are a whole is to share the data it collects with other
medium- and high-voltage installations. host of other technologies that have to computers in the user’s company, but a
Its technology platform not only allows be seen as options for substation owners better reason is to make the front panel
control functions and their logic to be (see box). accessible everywhere, allowing the
configured with user-friendly FUnction operator to monitor and control the
PLAn (FUPLA) software, but also the Embedded web-server instrument from, for example, another
numerous protection functions and their Of all the changes that are taking place, building. An embedded web-server
parameters to be selected and the most revolutionary is the use of makes this possible. All the user needs is

16 ABB Review 2/2001


Transmission and Distribution

The REF542plus protection and control device can be used with many
GPS new and emerging technologies.

control equipment. In other words, the requires extra memory space and
E-mail REF542 plus
web client software used in browsers calculating power, more and more of
can communicate with any server using today’s protection and control devices
the HTTP (web) server protocol and are able to handle this.
displaying HTML pages. The XML Using a PC and standard browser,
SMS protocol – the very latest in file format- parameters can then be read and
ting – allows dynamic rather than static changed, or commands sent, in a way
file display. with which the user will already be
a computer with a standard web browser The embedded web-server delivers familiar. The web server forms the
enabling communication with the instru- HTML-formatted graphic pages to web interface to the real data in the embed-
ment – in other words, the PC becomes browsers and communicates with other ded system. There is absolutely no need
the device’s front panel. servers on the network. There are two for the PC to be installed locally!
Some utility managers will, of course, possible ways to integrate software in an Many advantages can, of course,
raise the objection that ‘Anyone with embedded electronic device in order to already be gained with an integrated
web access can shut down my substation.’ obtain this kind of web-server: web-server for local access, without any
These worries are unfounded. It is ■ Integrate minimal web functionality remote connection. For instance, a
important to remember that the solution on the embedded electronics and set up technician carrying no more than a
is web technology, not the World Wide a link to a separate PC which contains standard notebook with a standard
Web. the actual web server. This solution browser can walk through a plant and
Web technology is all about using makes sense when a local PC is anyway link up to protection and control devices
mature, well-known Internet technologies available. via any interface (eg, RS232, Bluetooth,
and standards, such as HTML, Extensible ■ Integrate all the web functionality in etc) in order to read values, send
Markup Language, XML, and HTTP for the embedded system for a genuinely commands and change parameters. And
industrial electronics and protection and embedded web-server. Although this he can be sure of maximum security,

Apart from the Internet, technologies likely to influence future substation development are:

GPS (Global Positioning System) CAN bus (Controller Area Network)


Originally introduced by the US military, a high-precision This was invented for the automotive sector, but is used
version of this system has been available for civilian today in many industrial fields.
applications since May of last year. It will be used in LON (Local Operating Network)
substations mainly for highly accurate time stamping and Developed for home automation, the LON has already
synchronization. found its way into a broad array of industries.
Mobile communication Ethernet
Although conceived for personal use, more and more Originally intended for networking computers, the Ethernet
embedded applications offer this feature, allowing has extended its reach to points much closer to the
communication with installations in locations without easy process.
access to standard telephone lines.

ABB Review 2/2001 17


eTechnology

Web user interface. The REF542plus relay is fitted with an embedded


web-server that allows it to be accessed, via a browser, on a notebook.

should include the kind of tools that may have additional mechanisms (authenti-
be used (hardware, software, protocols) cation, passwords, plausibility checks) in
and the people allowed to access the place as protection against any ‘internal’
installation, giving details of when and attacks.)
how. Whether a connection to the World
since the different levels can only be Wide Web is likely or not, all possible Callback
accessed with passwords or hardware points of attack must be identified. If an operator or service engineer has to
keys. Several security options are available to be able to connect to an installation via
Although this method applies only to users, and some of these are looked at in his browser from anywhere in the world,
local access, it still has numerous the following. then the network will obviously have to
advantages: be open to the world. A link to the
Closed network telecom network with authorization for
■ There is usually no need for a Connecting protection and control units callback connections only, offers the best
dedicated local command interface – at via a closed network based on Ethernet security here. The operator can then access
the very least, it is reduced to an has several special advantages for the plant from either his home or office
absolute minimum – as the notebook security. using his PC and modem, or from
browser takes over this functionality. This is nothing new, of course, and anywhere else using his notebook.
■ Only standard software and hardware many of today’s installations are ‘Callback’ guarantees that only certain
(the browser and notebook) are needed. equipped with a control system based at telephone connections have substation
These are usually already provided for least to some extent on Ethernet, yet access. The phone number has to be
other purposes. there are hardly any at all which use kept secret to prevent so-called ‘denial of
■ There are no weak points which Ethernet at all levels! Ethernet tends to service’ attacks, in which someone with
could be vulnerable to external be preferred for office automation, bad intentions tries to block access by
interference as a local, physical although components are available today repeatedly dialing the number.
connection to the device is used. with both the real-time capability and the
environmental compatibility demanded Read-only access
Security strategy for industrial applications. If the substation network is connected to
The more often remote access is used, Against this background, Ethernet- the Internet by means of a gateway, an
the more important security becomes. based closed networks are certain to find operator can access the installation from
While the means for achieving the much wider use in substation automation. any Internet-enabled PC, regardless of
required level of security are available Many advantages are to be gained by where it is located.
already today, they still have to be integrating embedded web-servers in field One possible security strategy here
applied rigorously. A network devices and running standard browsers is to provide only read-only access
specification is therefore incomplete on PCs, especially since the PC can be to external connections. This gives
without details of the security and installed anywhere to allow remote the person connected to the installation
privacy measures to be taken. monitoring, remote diagnosis and even a clear picture of the state of the plant,
The importance of security cannot be remote control and parameterization. allowing conclusions to be drawn and
emphasized enough. First and foremost, And since the network is closed, all action to be taken if necessary. Although
a strategy has to be drawn up which points of possible attack are confined there is a risk of ‘denial of service’
covers every conceivable aspect. It locally. (It is, however, still advisable to attacks with such a strategy, the damage

18 ABB Review 2/2001


Notebook CAN GPS Analog Block diagram of the REF542plus
Bus
with 20 mA
browser as
control unit
RS232
Embedded Protection
web-server & control LON
REF542 plus Modbus Obviously, the demands vary with the
Ethernet
IEC 60870-5-103 application. The relay’s modular structure
Remote 8 analog
control unit voltage/current Binary I/Os takes care of this problem. For example,
with RS485 inputs
the type and number of binary I/Os can
be extended as required. And a large
number of protocols and interfaces are
U/I I/O
available for linking the relay to the
higher-level control system.

Borrowing to go forward
these could cause is limited since the ‘REF542plus’ Technologies originally developed for
means of access remains intact. The REF542plus is representative of the other applications continue to find their
new generation of combined protection way into the protection and control field.
Cryptology, firewalls and control relays. ABB engineers have The benefits this is bringing are evident
If every Internet-enabled PC is to have designed it to accommodate many of the already in ABB’s new combined protec-
full substation access – allowing remote technologies mentioned above: tion and control device, REF542plus. This
control and remote parameterization via ■ A real web-server is integrated within web-enabled relay is a prime example of
the World Wide Web – efforts will have the device. a product which, through the integration
to be made at every level to prevent ■ Different options exist for local of cutting-edge technologies from other
attack by people with malicious intent. control: with browser or local control sectors, has raised the bar for remote
For example, all data transfers will have unit. monitoring of substations.
to be encrypted. (Data encryption is ■ Synchronization via GPS is possible.
already widely used on the Internet, ■ Interfaces for CAN or LON are
although in applications like online available, as is an Ethernet interface.
banking that do not make the same real- ■ Alarm functions via SMS or e-mail are
time demands on the system that industrial possible.
plants and substations do.) It is anyway ■ Communication via embedded GSM Authors
advisable only to send commands over can be enabled for locations where there
Dr. Daniel Tabara
the Internet which, if tampered with, are no standard telecom lines. ABB Secheron SA
would cause little or no damage. In CH-1211 Geneva
Switzerland
addition, there will be security mechan- Although designed with emerging
daniel.tabara@ch.abb.com
isms in place which have been developed technologies in mind, the REF542plus
Dr. Hendro Rijanto
specifically for automation technology. can, of course, also be used in a ABB Calor Emag
Internal networks (Intranets) are often conventional environment. Its eight DE-40472 Ratingen
Germany
protected by so-called firewalls – analog voltage and current inputs can be hendro.rijanto@de.abb.com
hardware and/or software units which used to connect conventional voltage Bruno Sabbattini
filter all external traffic according to and current transformers as well as the ABB Corporate Research Ltd
CH-5405 Baden
configurable rules. To some extent, these latest sensors, resistive voltage dividers
Switzerland
filtering mechanisms can be integrated in and Rogowski coils. All kinds of bruno.sabbattini@ch.abb.com
the software of embedded web-servers. transducers can be combined.

ABB Review 2/2001 19

You might also like