PD IEC TR 62351 is a series on Power systems management and associated information exchange. Power systems management and associated information exchange allows our customers to select important power supply parameters over a digital communication interface. PD IEC TR 62351‑90‑1 is a technical report, addresses the handling of access control of users and automated agents to data objects in power systems by means of role-based access control (RBAC) as defined in IEC TS 62351-8. IEC TS 62351-8 defines three different profiles to distribute role information and also defines a set of mandatory roles to be supported. Adoption of RBAC has shown that the defined mandatory roles are not always sufficient, and it is recommended that the method for defining custom roles be standardized to ensure interoperability. Hence, the main focus of PD IEC TR 62351‑90‑1 lies in developing a standardized method for defining and engineering custom roles, their role-to-right mappings and the corresponding infrastructure support needed to utilize these custom roles in power systems. This is achieved by defining categories and sub level categories, which provide a distinction of actions, connected with dedicated rights as well as a proposal for a format to distribute the custom role-to-right mappings. Moreover, a format is being proposed to distribute the information on custom defined roles and associated rights by utilizing XACML as an established standard for access control.
PD IEC TR 62351‑90‑1 on power systems management and associated information exchange is useful for:
The power system sector is adopting security measures to ensure the reliable delivery of energy. One of these measures comprises Role-based Access Control, allowing utility operators, energy brokers and end-users to utilize roles to restrict the access to equipment and energy automation functionalities on a need-to-handle basis. The specific measures to realize this functionality have been defined in the context of IEC TS 62351-8. PD IEC TR 62351‑90‑1 defines three profiles for the transmission of role-based access control related information. This information includes, but not limited to, being contained in public key certificates, attribute certificates, or software tokens. Moreover, especially for IEC 61850, it defines a set of mandatory roles and associated rights. IEC 61850 also allows the definition of custom roles and associated rights, but this is not specified in a way to ensure interoperability.
PD IEC TR 62351‑90‑1 targets the provisioning of guidance for the implementation of role-based access control. More specifically it focuses on means to describe custom roles, as well as the management of these new roles and associated rights, which are typically administered in a management tool and enforced in the endpoints. By defining categories, the workflow is simplified for defining new roles and associated rights besides the predefined roles in IEC TS 62351-8 as well as the assignment to subjects. Consequently, the information exchange necessary to distribute the role-based access control information is also a target of PD IEC TR 62351‑90‑1 to ensure interoperability between different vendor’s products. This is achieved by utilizing the existing standard XACML. Using PD IEC TR 62351‑90‑1 you can address the handling of access control of users and automated agents to data objects in power systems by means of role-based access control as defined in IEC TS 62351-8.IEC TR 62351-90-1:2018