Yukon IMS IED Management Software Brochure

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 8

COOPER POWER

SERIES

Yukon™ IED
Manager Suite
Reliability, security and compliance
for utility automation systems
Eaton’s Cooper Power™ series
Yukon™ IED Manager Suite (IMS) provides power system operators
with a complete suite of software applications to remotely manage
all installed intelligent electronic devices (IEDs).
Utilities are increasingly turning to integration and With thousands of IEDs being Yukon IED Manager Suite
deployed in substations and in is composed of the following
automation to enhance power system performance the field utilities are now faced software modules:
and reliability. Intelligent Electronic Devices (IEDs) are with a growing management • Enterprise Gateway:
and compliance challenge.
Manages communications
the cornerstone of their efforts. Installed throughout Yukon IED Manager Suite with field devices
the utility, they protect the network, monitor critical provides utilities with the tools • Security Server:
necessary to manage their fleet
equipment, detect problems, and prevent outages. of intelligent devices in a secure
Provides authentication
and authorization services,
and automated manner:
However, IEDs are produced by a variety of ties in to Microsoft®
• Keep track of IED inventory Active Directory®
manufacturers and feature proprietary technologies as • Provide compliance reports • Passthrough Manager:
well as multiple protocols and data formats, with little and auditable logs Provides secure remote
maintenance access,
or no security. This can create a maintenance and • Provide secure remote access
auto-login, command filtering
compliance nightmare. • Retrieve fault records, SOE, • Configuration Manager:
and oscillography
Retrieves device settings,
Yukon™ IED Manager Suite (IMS) helps solve these • Manage device monitors for changes
problems. Not only does it integrate all IEDs into configuration settings • Password Manager:
a cohesive, manageable whole, it also provides • Manage passwords Updates device passwords
Manage firmware Update Manager:
complete, enterprise-wide access to operational and •
and settings updates

Updates device firmware
non-operational data in a highly secure environment. • Event Manager:
Retrieves fault records,
SOE, and oscillography


2 EATON CORPORATION Yukon™ IED Manager Suite
IMS Security Server Automated IED management saves time and reduces errors
The Yukon™ IMS Security  
Server provides authentication
and authorization services
for all IMS modules, PASSTHROUGH
EVENT CONFIGURATION PASSWORD
IED MANAGER UPDATE MANAGER
for Substation Modernization
MANAGER MANAGER MANAGER WEB CLIENT
CLIENT AND AGENT WEB CLIENT
WEB CLIENT WEB CLIENT WEB CLIENT

Platform™ (SMP™) Gateway,


and for managed field devices. SECURITY MANAGER

DATA
HISTORIAN
Centralized access OTHER PASS-
EVENT CONFIG PASSWORD UPDATE
management for SMP Gateway SCADA CONTROL
CENTERS
THROUGH
MANAGER MANAGER MANAGER MANAGER
MANAGER
and IED Manager Suite
DATA BRIDGE

Eaton’s Cooper Power


series Yukon IMS Security ENTERPRISE GATEWAY
Server provides centralized
authentication and authorization
services for IMS and SMP
Gateway. It integrates with
Microsoft® Active Directory®
service to provide single sign-on
capability to field devices. When
used with Passthrough Manager,
users no longer need to know IED
passwords and can connect to
field devices using their standard
corporate credentials.
Additionally, IMS Security Server
implements role-based access
control, managing access by
user, by group, by regions,
by substation, and by IED.
The Yukon IMS Security • Hide IED and gateway Centralize permission Generate operation and
Server leverages your existing passwords from users, management and role-based compliance reports
corporate security infrastructure reducing the need for access control • Detailed user and
and provides centralized shared accounts • Define groups of users group permissions
authentication and authorization • Implement two-factor
services for field devices. • Define groups of SMP • User activity report
authentication for remote
Gateways and IEDs
Key features access to field devices
• Define operations that groups
• Single sign-on and central Centralize user management can perform
authentication and • Revoke access to all critical • Assign users to groups to grant
authorization database
cyber assets with a single access to devices
• Secure access to all IMS operation
modules, the Eaton’s Cooper • Create applicative accounts and
Power series SMP Gateway,
set minimum password length
and all connected IEDs
and complexity requirements
• Simplified permissions • Grant access to individual
management for Eaton’s
applicative accounts,
Cooper Power series products
individual Microsoft®
• Compliant with applicable Active Directory® accounts,
NERC-CIP standards or Active Directory® groups

Help comply with NERC CIP-004


• Manage IMS permsions
and CIP-007 without needing Windows®
operating system
• Add, modify, and remove administrative permissions
access rights from a central
location, rapidly
• Review consolidated
access logs
• Implement central access
monitoring and reporting
• Track user access to critical
cyber assets

EATON CORPORATION Yukon™ IED Manager Suite 3


IMS Passthrough • Supports all common protocols
HTTP, HTTPS, SSH, Telnet, etc.
Manager • Connection settings,
passwords, and communication
The Yukon IMS encryption is preconfigured
Passthrough Manager in Passthrough Manager:
users connect as if they were
provides an enterprise- in the substation
level secure single point Helps meet NERC CIP
of access to IEDs for requirements
remote maintenance • Provides intermediate device
and engineering. functionality as required by
CIP-005-5
Secure, transparent access • Two-factor authentication
to remote IEDs support through Active
Directory
Eaton’s Cooper Power series
Passthrough Manager provides • Individual user accounts
users at the substation or
enterprise level with secure
• Auto-login hides device
NERC CIP compliant access passwords from users
to substation devices, using • Command filtering prevents
familiar native vendor tools, users from remotely changing
as if they were connected IED passwords or sending
directly to the IED. harmful commands
Passthrough Manager is a • Secure TLS encrypted
client/server application. communications
• Passthrough Client, installed • When used with Eaton’s
on user workstations or on Cooper Power series
a shared application server, SMP Gateway, provides a
intercepts all data directed to secure connection from the
the IED and securely forwards enterprise to the substation
it to the server Electronic Perimeter
• Passthrough Server provides
authentication and authorization IMS Configuration user interface with the
following functionalities:
from supported IEDs, not just
ASCII text.
services, and forwards
data to the IED, either Manager • Monitor the configuration • Firmware and software
directly, or through a secure settings of Eaton’s Cooper version information
communications link to the The Yukon IMS Power series SMP Gateway
Eaton’s Cooper Power series • Hardware information
SMP Gateway
Configuration Manager and supported IEDs on demand,
or on a scheduled basis • Patches and service packs
automatically retrieves
Key features • Retrieve and store configuration • Device settings and
and stores all IED files in a centralized database configuration
Authentication and configuration settings, • Define a configuration baseline
authorization Configuration management,
detects changes to the • Detect changes to reporting, and notification
Authentication through

application user database or
baseline configuration, configuration settings
IMS Configuration Manager
Microsoft® Active Directory® and notifies appropriate • Notify system administrators tracks device change history
for single sign-on of any detected change and notifies system
users. The IMS administrators of any change
Maintain the history of
• Centralized user permission Configuration Manager •
configuration changes in
to the baseline configuration.
management
provides utilities with a an auditable database • Define device baseline
• Access rights based on region configuration
and IED powerful tool to help meet With its advanced features,
NERC CIP configuration Configuration Manager provides • Automatic e-mail notification
Transparent remote access utilities with a tool to simplify of detected changes
management requirements. compliance with NERC CIP-010
View configuration changes
• Users can connect to any requirements.

substation IED to which they View side-by-side comparison
Centralized management of IED •
have been granted access Key features of settings from different
settings and firmware versions
• Provide transparent remote versions or devices
Eaton’s Cooper Power series Retrieval, monitoring, and
access to IEDs from View device change history
Yukon IMS Configuration Manager change detection

any application and generate reports
provides a secure browser-based
• Supports devices using IMS Configuration Manager
retrieves all available information
• Retrieve current or previous
multiple IP ports versions of configuration
settings from the database

4
EATON CORPORATION Yukon™ IED Manager Suite
NERC CIP compliance
functionalities
The following features help
compliance with the NERC
CIP-009 and CIP-010
requirements:
• Critical cyber assets
configuration change history
• Configuration change automatic
notification
• Configuration restoration
and backup (simplified with
the storage of all the
information required to
restore managed devices)

IMS Password Password Manager builds on


the Eaton’s Cooper Power
• Provide IED passwords
to field personnel on a
Authorized users can:
View current password for any
Manager

series Yukon IED Manager need-to-know basis
device account
Suite foundation to provide • Request a password change
The Yukon IMS Password you with everything you need
to implement your password
when work is done
• Copy password to clipboard

Manager provides a management process: • Print Current Passwords


• Request password change for
accounts, IEDs, or selected
comprehensive set of tools • Secure encrypted storage
report for emergency use
substation devices
if communications fail
and reports to manage IED of IED and Eaton’s Cooper
• Print reports
Power series SMP Gateway • Print Password Age report
passwords and help meet passwords to plan and schedule With Password Manager,
regulatory requirements. • Simple-to-use Web-based
password updates you are in control of the process.
management interface with Every device type seems to have
• Utilize Password Usage and
Centralized management of IED granular access control its own password policy, even
Password Change History
passwords when provided by the same
reports to demonstrate
• Password length, complexity, manufacturer. You can select the
Password management is a compliance during audits
and character set can be best password for each device
key requirement of all security assigned for each device Password Manager provides type. You can also select the
programs such as NERC CIP. type and model you with a secure, easy-to-use device accounts or access levels
Compliance requires that utilities Web-based interface: you want to manage.
implement a process to:
• Complete operational and
compliance reports • Navigate through regions, Password Manager is reliable.
• Manage inventory of devices substations, devices, Lose the device password
and accounts
• Fail-safe operation protects
and accounts and remote access becomes
against password loss
Track and manage the use impossible, requiring expensive
• • Secure role-based access
of shared accounts Password Manager works the field maintenance. Password
control: users can only view
same way you do: Manager has been designed to
Generate compliant passwords devices to which they have
• handle all potential failure modes
• Reduce the need for shared access; users can only perform
and provide fail-safe operations.
• Protect access to passwords accounts by hiding device operations they are authorized
passwords through the use to do For increased reliability,
• Update passwords on
of Passthrough Manager passwords are managed centrally,
a regular basis
auto-login capability not locally, and the database can
• Provide compliance reports be replicated to protect against
data loss.

EATON CORPORATION Yukon™ IED Manager Suite 5


IMS Update Key features Features and benefits Event retrieval
Simple-to-use Web-based Automatic upon event
Manager
• •
Superior notification
management interface with occurrence, when using
granular access control • Automated e-mail notification Eaton’s Cooper Power series
The Yukon IMS Update • Comprehensive Search • Event data automatically
SMP Gateway
Manager helps keep capability by device name, attached to the message • Scheduled at configurable
IEDs secure and reliable model, and firmware version
• Events can be sent to several
intervals

by automating the • Select devices and group users at a time • On demand via Web interface
them by “batches”
firmware update Remote access
• Keep event history for
• Select from available multiple-event analysis
process. firmware versions • Download event and
waveform files using a Web
• Comprehensive search
• Request update immediately, browser, no need to connect capability
Automating firmware updates
or at a scheduled time to device • Event grouping for
Frequent firmware updates
• Automatically convert Diagnose the event remotely simplified analysis
have become a necessary fact •
SMP Gateway settings
of life to ensure the reliability • Retrieved event data is stored
and load the appropriate • Reduce substation visits
and security of substation and in native format and converted
modules according to the
field devices. New features are to COMTRADE on demand
software license Efficient team management
being added, problems are being
corrected, and vulnerabilities • Complete operational • Dispatch alarms based on
are regularly being identified. and compliance reports region and type of event
Updating device firmware • Manage user access based
in a timely manner can also on geography or teams
be mandatory for devices
that have to meet the CIP-007
IMS Event Manager • Browser-based
acknowledgement mechanism
Security Patch Management
requirements.
The Yukon™ IMS Event means one person takes
ownership of the alarm
As the number of managed Manager provides
devices grows, updating corporate-wide access
firmware manually becomes
a tedious and error-prone to fault, event, and
procedure. disturbance data from
Update Manager is a companion
module to the Configuration
substation devices.
Manager that provides the
following capabilities: Automated processing of
power system events
• Web-based user interface
Eaton’s Cooper Power series
• View current firmware version Yukon IMS Event Manager
for supported devices automatically retrieves event
• Select devices and request data from fault recorders and
update to a new firmware protection relays, notifies the
version, immediately, or at proper users, and sends the
a scheduled time event data along with the
notification. Users can now
• View and print reports have all the information they
need to rapidly diagnose and
Update Manager builds on the
act on problems, dispatch repair
Eaton’s Cooper Power series
crews, and eventually restore
Yukon IED Manager Suite
service by remote connection
foundation to provide you with
to the affected device.
everything you need to manage
firmware and settings updates • Instant, automatic e-mail
for supported devices. notification of power
disturbances
Update Manager supports
Eaton’s Cooper Power • Browser-based access to
series SMP Gateway, event history and event files
CBC-8000 capacitor bank control,
GridAdvisor™ Series II smart
sensor, with more devices
being added regularly.

6
EATON CORPORATION Yukon™ IED Manager Suite
Yukon IED Comprehensive logging
capability
Manager Suite • All user operations are logged
Reliability, security and • All system operations
compliance for utility are logged
automation systems • Logs are stored in
the database
Key system features • Built-in Log Viewer
application with searching
Architecture and filtering capability
• High performance multi- • Logs are simultaneously
threaded architecture published to syslog server
designed to support parallel or SIEM for processing,
operations on a large number monitoring, and storage
of devices
• Built on industry-standard Supported device types
Microsoft® Windows • AREVA MiCOM
Server operating system
and Microsoft® SQL • Eaton’s Cooper Power
Server database series Form 6, CBC-8000,
GE UR, GE SR
• Simple-to-use Web-based
management interfaces with • SEL
granular access control • And many more
Connectivity See “Substation Devices
Supported by IMS” document
• IMS supports devices for a list of supported IEDs. Client software requirements Processor type
accessible directly through
an IP address, through a port IMS Management Console is a • Minimum: Pentium™
Supported gateway types
switch, or supported data Windows® client application that IV-compatible processor
concentrators and gateways • Eaton’s Cooper Power runs on the IMS server. or faster
series SMP Gateway
• Supports up to four cascaded • Windows® Server 2008 Processor speed
communications gateways • SEL-2020 and SEL-2030
• Windows Server 2012
® • Minimum: 1.0 GHz
• Communications settings and • NovaTech™ Orion
IMS Passthrough Client and • Recommended: 2.0 GHz
timeouts are fully configurable Agent run on a user workstation or faster
to support slow data links Server software requirements
or shared application server. RAM
Comprehensive reporting Operating system • Windows® 7 operating system • Minimum: 4 GB
capabilities Windows® Server 2008 R2
• • Windows® 8 operating system • Recommended: 16 GB
• Complete library of • Windows® Server 2012 R2 or more
predefined reports for Server hardware requirement
operations and compliance Web server Disk
IMS hardware requirements
• Comprehensive reporting • Microsoft Internet
® depend on the number • Minimum: 100 GB
capabilities built-on Microsoft® Information Services (IIS) of monitored IEDs and • Recommended: 500 GB
SQL Server Reporting Services Version 6.0 or later the number of event and
with RAID, SAN or NAS
configuration files stored for
• Reports can be customized each of these IEDs. Virtualization support
to meet your requirements Database
• MS SQL Server 2008R2 The following are typical • Microsoft® Hyper-V
minimum requirements.
• MS SQL Server 2012
• VMware® ESX
and VMware ESXi
• MS SQL Server 2014
• Citrix® XenApp

EATON CORPORATION Yukon™ IED Manager Suite 7


For Eaton product information,
call 1-877-277-4636 or visit:
www.eaton.com/cooperpowerseries

Eaton Corporation
1000 Eaton Boulevard
Cleveland, OH 44122
United States
Eaton.com

Eaton’s Cooper Power Systems Division


2300 Badger Drive Eaton, Cooper Power, SMP and Yukon are
Waukesha, WI 53188 valuable trademarks of Eaton in the U.S. and
United States other countries. You are not permitted to use
Eaton.com/CooperPowerseries the Eaton Trademarks without the prior written consent of Eaton.

© 2015 Eaton Microsoft® Windows® are registered trademarks of Microsoft


All Rights Reserved Corporation in the United States and other countries.
Printed in USA
Publication No. BR913001EN All other trademarks are property
August 2015 of their respective owners.

You might also like