Technical Manual
GE Reason H49
104
H49/EN M/C22
8.1.2
Secured File Transfer
Files are exchanged through a secure file transfer protocol such as:
•
Secure Shell (SSH)
, provides confidentiality and integrity of data in client-server
architectures by encrypting data
•
SSH File Transfer Protocol / Secure File Transfer Protocol (SFTP)
, provides
secure file transfer capabilities. This is an extension of the Secure Shell protocol
(SSH) protocol.
•
HyperText Transfer Protocol Secure (HTTPS)
for secure communication over a
computer network widely used on the Internet. Connections are encrypted by
Transport Layer Security (TLS) or Secure Sockets Layer (SSL)
Non-secured protocols are disabled.
8.1.3
Authorization
Authorization is both the process of a security administrator granting rights to users
and the process of checking user account permissions for access to devices.
The permissions define both the environment the user sees and the way he/she can
interact with it.
When successfully authenticated, the user can only perform actions for which
privileges have been explicitly granted to him/her. These permissions are set by a
security administrator and stored locally or on the authentication server.
8.1.3.1
Role-Based Access
Reason H49 uses the concept of Roles and Rights. This process consists in assigning
local authorized users to one predefined roles and is known as Role-Based-Access
Control (RBAC).
A role is a collection of privileges. Different roles and different access rights can be
associated with a user.
This action is done in the
Security > User Accounts
page of the web user interface:
The available roles are:
Attribute
Description
Viewer
A "Viewer" can only display data or read information.
A "Viewer" is not authorized to change other
passwords, nor to visualize the security logs.
Engineer
An "Engineer" can only access data useful to run the
system. He/she works in the substation and can act
on a sub-system. He/she has observer rights plus
specific rights to trigger commands.
The "Engineer" is not authorized to change other
passwords, nor to visualize the security logs.
Содержание Reason H49
Страница 10: ...Technical Manual GE Reason H49 10 H49 EN M C22 1 2 Ordering Options ...
Страница 157: ......