Orbit Presentation - Lauttamus Communications & Security

advertisement
Channel Product Training
TM
GE MDS Orbit MCR Series
Product Manager: Judy LeStrange
Program Manager: Bill Yochum
Product Architect: Craig Page
Tedrow
1
GE Digital Energy
Internal
&
Confidential
HW Lead: Anthony Tatta
Executive Commercialization Review – Program Name Here
SW Lead: Jeff Wilczewski
GE’s Platform Summary
MDS Orbit Platform
What is it?
The MDS Orbit platform is the next generation
wireless communications solution integrating a
range of technologies, from cellular to private,
and licensed to unlicensed, supporting
customers’ needs for secure private, public and
hybrid communications networks.
GE’s Differentiated Value Proposition
•
The MDS Orbit platform provides a
comprehensive security framework enabling
•
customers to meet their current and future
standards. Networking capabilities extend and
simplify the communications infrastructure.
Meeting the needs for functional and application •
flexibility and ease of use, the MDS Orbit platform
of products provides consistent packaging and
configuration to streamline engineering,
operations, supply chain and support.
Comprehensive Security Framework
•
Secure the device
•
Secure the user
•
Secure the network
Advanced “System” Performance
•
Deterministic application performance (QoS)
•
Enable convergent networks
Ease of Use & Integration
•
Quickly create & scale hybrid networks
•
Integrate private to public communications
•
Multiple interface and enclosure options for
harsh environments
•
Flexible interface options
2
GE Title or job number
3/18/2016
MDS Orbit Platform Portfolio
Platform Highlights
Quality / Reliability
•
•
•
•
Built with IPC-610 Class 2
Standards
World class automated PCBA
manufacturing equipment
Automated Final Testing Suite
HALT& HASS Testing
*exact product variants
TBD
Security
• Secure boot
• Digitally signed SW
• Tamper detection
• Location based
• Magnetic based
• Radius Certification
• Signed (by customer) SW image
• Dual SW images
Networking
• RS 232 /485
• USB serial interface
• Network time protocol
• ModBus RTU/TCP
• Juniper style CLI
• IEC 61850
• Powerful Configurable Firewall
capability
• Port forwarding
• iPERF
• Extensive CEE format Event
logging
• SSH, HTTPs, SNMP
System Flexibility
• Bridging across NICs
• WiFi
• Cell
• Licensed
• Unlicensed
• Built in Terminal server
• Multiple VLAN support
• Dual SSIDs on WiFi
MDS Orbit Platform Overview
Superior Reliability
• Ruggedized die-cast aluminum
enclosure provides enhanced
thermal dissipation for extended
reliability
Comprehensive Security
•Industry leading, standards-based
security controls providing
authentication, integrity, and
confidentiality through strong
cryptographic algorithms
Multiple communication
technologies
• Designed to support global
private and public
communication networks
enabling hybrid wireless
solutions
Powerful Networking
•Adaptable to different network
designs and topologies by providing
bridging, routing, firewall and VLAN
capabilities lowering cost of network
installation and maintenance
Flexible Interface Combinations
•Multiple interface options (Ethernet,
serial) provides flexibility to match
specific application needs and
equipment
Advanced System Performance
•Quality of Service (QoS) through
traffic prioritization minimizes
latency and provides deterministic
application performance
Page 4
GE Internal & Confidential – Commercialization Plan Judy LeStrange
GE Digital Energy Orbit DistribuTech Demo
Distribution Substation
Wind Farm
Control Center
Handheld
Demo
Large Display Monitor
Live
Control Center
Camera
WiFi
IP Camera
ORBIT 900
D400
HMI
D400 HMI
Camera View
IXIA Iexplorer
App dash
ORBIT 900
ORBIT 900
F60
F60
Ethernet
Ethernet
4G
Internet
D400
Abused
ORBIT 4G
IXIA Traffic
Simulator
IXIA Traffic
Simulator
Internet
Remote
Demo
Feed
IXIA
Traffic
Generat
or
Application Example
Page 6
GE Internal & Confidential – Commercialization Plan… Judy Lestrange
TM
TM
MDS WiYZ
Orbit
Secure
Communications Framework
•
•
•
•
•
Operational
Security
Administrative
Security
Development
Security
Access
Control
Secure device
management
Secure
development
Authentication
Certificate
management
Secure
firmware
Data plane
security
Audit and
logging
Vulnerability
tracking
Username/password login
Role based access control
EAP-TLS authentication
IPsec VPN
Stateful Packet Inspection
•
•
•
•
•
SSH, HTTPS, Netconf
Complete certificate services
Multi-tier PKI integration
Extensive event logging
Syslog-over TLS
GE Internal
• Secure coding practices
• Third party testing
• Digitally signed firmware
Simplifying the Edge
• Built-in firewall eliminates need for a separate firewall, such as a
Cisco ASA, at edge
• 2 Ethernet ports eliminates need for an external switch when two
ports is sufficient
• Routing, port forwarding, and NAT capability eliminates need for
an external router
• Terminal server with TCP/UDP encapsulation eliminates a
separate terminal server device to reach legacy serial devices
• WiFi Access Point functionality with dual SSID support
eliminates need for standalone WiFi access point
WiFi
Access Point
GE Internal
Cisco ASA
firewall
Ethernet switch
Serial terminal
server
8
Orbit MCR Product Overview
3/18/2016
MCR-900 - Overview
• Similar to TransNET/EntraNET/iNET, but not backwards compatible
• Operates in the 902-928 MHz ISM Band
• Multiple Topologies
• Point-to-Point, Point-to-Multipoint, Store-and-Forward
• Medium Speed:
• 125kbps, 250kbps, 500kbps, 1Mbps, 1.25 Mbps
• Long Range:
• > 20 miles
• Same NIC hardware supports operating in all modes:
• Access Point
• Station
• Store-and-Forward up to 8 hops
• Power Output
• 20 dBm to 30 dBm in 1 dBm steps
Page 9
23 December 2011
900MHz ISM Details
902 to 928 MHz ISM band operation
Point to multipoint with Store-and-forward abilities
20 to 30 dBm transmit power
Five modulation rate / bandwidth combinations:
Mode
Rate (kbps)
Channels
Modulation
RF
bandwidth
125
FHSS
125
80
2-GFSK
152kHz
(20dB)
250
FHSS
250
80
2-GFSK
300kHz
(20dB)
500
DTS
500
80
2-GFSK
505kHz
(6dB)
1000
DTS
1000
80
4-GFSK
680kHz
(6dB)
1250
DTS
1250
80
4-GFSK
1320kHz
(6dB)
Selectable channel usage over 80 channels, 16 zones
GE Internal
Page 10
23 December 2011
900MHz ISM Details
10 to 400 msec dwell time to deliver low roundtrip latency
QoS with high/medium/low priority and extensive traffic classification
Confidentiality with 128-bit and 256-bit AES encryption
Store and forward (repeater) operation
GE Internal
Page 11
23 December 2011
Physical / Environmental
Cast aluminum enclosure
Power input 10 to 60 VDC
Power consumption
• 4 watts average (20% duty cycle)
• 3 watts in receive
• 8 watts peak
Class 1 / Div 2 certified
IEEE 1613 substation approved
GE Internal
12
Orbit MCR Product Overview
3/18/2016
Integrated DIN Rail Mount
Utility value/MM customers
Download