System overview
3.4 CPUs
Automation system
52
System Manual, 12/2017, A5E03461182-AE
3.4.5
Security
Security means protection of technical systems against sabotage, espionage and human
error.
Protection functions
To set up secure networks, the SIMATIC S7-1500 automation system offers an integrated
security concept from authorization levels up to block protection:
Protection function
Description
Access protection
Protection against unauthorized configuration changes through four authorization levels
and integrated firewall
Know-how protection
Protection against unauthorized access and modifications to algorithms by means of pass-
word protection
Copy protection
Protection against duplication of programs by linking individual blocks with the serial num-
ber of the original memory card on the SIMATIC memory card
Locking the CPU
Protection against unauthorized access by locking the front cover with a seal or a lock
You can find additional information about security mechanisms of the SIMATIC automation
systems in the "Security" document at SIMATIC S7 controllers
https://support.industry.siemens.com/cs/ww/en/view/77431846
Secure Communication
It is becoming increasingly necessary to transfer data to external computers in encrypted
form via Intranet or public networks.
SIMATIC S7-1500 CPUs with firmware version 2.0 and higher support the Internet PKI (RFC
5280) with STEP 7 as of V14. This makes the configuration and the operation of Secure
Communication possible, for example:
●
Hypertext Transfer Protocol Secure (HTTPS)
●
Secure Open User Communication
●
Secure Communication with OPC UA
A public key infrastructure (PKI) can issue, distribute and check digital certificates. For S7-
1500 CPUs, you create certificates for various applications in the CPU properties in STEP 7,
for example: TLS certificates for Secure Open User Communication, Web server certificates,
OPC UA certificates.
Communications processors with integrated security functions
For special requirements of your plant, use communications processors with integrated
security functions such as access protection using a firewall, protection against data
manipulation using VPN, FTPS, HTTPS, SNMPv3 and secure NTP.
Summary of Contents for Simatic S7-1500/ET 200MP
Page 1: ......