Schweitzer Engineering Laboratories SEL-3022 User manual

SEL-3022
Wireless Encrypting Transceiver
Instruction Manual
20050615
Attention
The SEL-3022 is a cryptographic device. Limit access to the
SEL-3022, SEL-5809 Settings Software, SEL-5810 Virtual
Serial Software, and SEL-3022 Instruction Manual to authorized
personnel only. Do not copy these items. Securely store these
items when not in use. Destroy these items when no longer
needed.
Preliminary Copy

The software (firmware), drawings, commands, and messages are copyright protected by the United States
Copyright Law and International Treaty provisions. All rights are reserved.
You may not copy, alter, disassemble, or reverse-engineer the software. You may not provide the software to
any third party.
All brand or product names appearing in this document are the trademark or registered trademark of their
respective holders.
ACSELERATOR, Connectorized, Job Done, MIRRORED BITS, Schweitzer Engineering Laboratories, , SEL,
SELOGIC, SEL-PROFILE, and CONSELTANT are registered trademarks of Schweitzer Engineering
Laboratories, Inc.
The English language manual is the only approved SEL manual.
©2005 Schweitzer Engineering Laboratories. All rights reserved.
This product is covered by U.S. Patent(s) Pending, and Foreign Patent(s) Issued and Pending.
This product is covered by the standard SEL 10-year warranty. For warranty details, visit www.selinc.com or
contact your customer service representative. PM3022-01
CAUTION: Removal of enclosure
panels exposes circuitry which may
cause electrical shock which can result in
injury.
!
ATTENTION: Le retrait des
panneaux du boîtier expose le circuit qui
peut causer des chocos électriques pouvant
entraîner des blessures.
!
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Cryptographic Manual—Do Not Copy
Table of Contents
List of Tables........................................................................................................... iii
List of Figures...........................................................................................................v
Preface...................................................................................................................... vii
Section 1: Introduction & Specifications
Introduction ............................................................................................................1.1
Product Overview...................................................................................................1.2
Application Overview ............................................................................................1.5
Connections, Reset Button, and LED Indications..................................................1.6
Software System Requirements ...........................................................................1.10
General Safety and Care Information ..................................................................1.11
Specifications .......................................................................................................1.12
Section 2: Installation
Introduction ............................................................................................................2.1
Dimension Drawing ...............................................................................................2.2
Setting Up Your PC or PDA With the SEL-5809 and SEL-5810 Software...........2.3
Initializing the SEL-3022.......................................................................................2.7
Section 3: Job Done Example
Introduction ............................................................................................................3.1
Job Done Example 1 ..............................................................................................3.2
Section 4: Settings and Commands
Introduction ............................................................................................................4.1
Serial Port Settings.................................................................................................4.2
Wireless Port Settings ............................................................................................4.3
Communication Status Command..........................................................................4.6
Device Information ................................................................................................4.7
Section 5: Testing and Troubleshooting
Introduction ............................................................................................................5.1
Testing Philosophy .................................................................................................5.2
Communications Channel Diagnostics ..................................................................5.4
Self-Tests................................................................................................................5.6
Troubleshooting .....................................................................................................5.7
Factory Assistance..................................................................................................5.8
Preliminary Copy

SEL-3022 Transceiver Instruction Manual Date Code 20050615
Table of Contentsii Cryptographic Manual—Do Not Copy
Appendix A: Firmware and Manual Versions
Firmware............................................................................................................... A.1
Instruction Manual................................................................................................ A.2
Appendix B: Firmware Upgrade Instructions
Introduction ...........................................................................................................B.1
Factory Assistance.................................................................................................B.8
Appendix C: Wireless Operator Interface Security
Introduction ...........................................................................................................C.1
Wireless Interface Security Overview ...................................................................C.2
IEEE 802.11 WEP Security...................................................................................C.5
The SEL Security Application...............................................................................C.9
Appendix D: Certificates
Glossary................................................................................................................ GL.1
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Cryptographic Manual—Do Not Copy
List of Tables
Table 1.1 DCE (Female DB9) ..........................................................................1.8
Table 1.2 Operating Systems and Wireless
Modules Tested With the SEL-5809 Settings Software ............1.10
Table 4.1 Settings: DCE Port............................................................................4.2
Table 4.2 Settings: Wireless..............................................................................4.3
Table 4.3 Settings: WEP Keys..........................................................................4.4
Table 4.4 Settings: User....................................................................................4.4
Table 4.5 Settings: Operator .............................................................................4.5
Table 4.6 Settings: Security Officer..................................................................4.5
Table 4.7 Status Command Names and Descriptions.......................................4.6
Table 4.8 Identification .....................................................................................4.7
Table 4.9 Status: Device ...................................................................................4.7
Table 4.10 Status: Output Alarm ........................................................................4.8
Table 4.11 Status: Virtual Serial Port .................................................................4.8
Table 5.1 Status: Comm....................................................................................5.4
Table 5.2 Device Status: Device Status ............................................................5.4
Table 5.3 SEL-3022 Self-Test Capabilities ......................................................5.6
Table 5.4 Troubleshooting ................................................................................5.7
Table A.1 Firmware Revision History..............................................................A.1
Table A.2 Instruction Manual Revision History...............................................A.2
Table C.1 Number of Years Required to Guess an SEL-3022 Password ....... C.13
Preliminary Copy

This page intentionally left blank
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Cryptographic Manual—Do Not Copy
List of Figures
Figure 1.1 Typical SEL-3022 and
SEL-5810 Virtual Serial Software Application...........................1.2
Figure 1.2 Encrypted Packet Stream ..................................................................1.4
Figure 1.3 Typical Connections for the SEL-3022.............................................1.6
Figure 1.4 Typical Alarm Output Installation ....................................................1.8
Figure 2.1 SEL-3022 Dimension Drawing ........................................................2.2
Figure 2.2 Windows Run Command ..................................................................2.3
Figure 2.3 Product Unregistered Prompt............................................................2.4
Figure 2.4 Select a Device Type to Create .........................................................2.7
Figure 2.5 Specify New Device Location ..........................................................2.8
Figure 2.6 Opening Device ................................................................................2.8
Figure 2.7 Identification Screen .........................................................................2.9
Figure 2.8 Status: Device .................................................................................2.10
Figure 2.9 Settings: Wireless............................................................................2.10
Figure 2.10 Settings: WEP Keys........................................................................2.11
Figure 2.11 Settings: User..................................................................................2.11
Figure 2.12 Settings: Operator ...........................................................................2.12
Figure 2.13 Settings: Security Officer................................................................2.12
Figure 2.14 Confirm Send Prompt .....................................................................2.13
Figure 2.15 Send Operation Message ................................................................2.13
Figure 2.16 Select Items to Print........................................................................2.14
Figure 2.17 Print Window ..................................................................................2.14
Figure 3.1 Remotely Located Recloser Control.................................................3.2
Figure 3.2 Job Done Example SEL-5809 Top Level View ................................3.3
Figure 3.3 Select a Wireless Session for DNP3 Job Done Example..................3.4
Figure 3.4 Settings: DCE Port............................................................................3.4
Figure 3.5 Status: Virtual Serial Port With Connection Status Red...................3.5
Figure 3.6 Communication Parameters Window in ACSELERATOR ..................3.6
Figure 3.7 Status: Virtual Serial Port With Connection Status Green................3.6
Figure 3.8 Reading Settings Via the SEL-3022 .................................................3.7
Figure 3.9 Monitoring SEL-651R Meter Data Via the SEL-3022 .....................3.8
Figure 3.10 Status: Virtual Serial Port Connection Status Red............................3.9
Figure 3.11 Specify Device to Export to
SEL-5810 Virtual Serial Software.............................................3.10
Figure 3.12 Export Encrypted User Configuration File.....................................3.10
Figure 3.13 Store Encrypted File .......................................................................3.11
Figure 3.14 Password Prompt in
SEL-5810 Virtual Serial Software.............................................3.12
Figure 3.15 Communication Parameters Window in ACSELERATOR ................3.13
Figure 3.16 Reading SER Report Via ACSELERATOR .......................................3.14
Figure B.1 PC to SEL-3022 Connection............................................................ B.2
Figure B.2 SEL-3022 and SEL-5809 Connection Parameters........................... B.2
Preliminary Copy

SEL-3022 Transceiver Instruction Manual Date Code 20050615
List of Figuresvi Cryptographic Manual—Do Not Copy
Figure B.3 SEL-5809 Settings Software Connection Method ...........................B.3
Figure B.4 SEL-5809 Opening Connection .......................................................B.3
Figure B.5 Status: Device Window ....................................................................B.4
Figure B.6 Confirmation Prompt........................................................................B.4
Figure B.7 Send Operation Prompt ....................................................................B.4
Figure B.8 Configuring Serial Port Settings in the Terminal Software..............B.5
Figure B.9 Send File Prompt..............................................................................B.6
Figure B.10 Sending Confirmation Window........................................................B.6
Figure B.11 Terminal Invalid Firmware Error Message ......................................B.7
Figure B.12 Terminal Valid Firmware Message ..................................................B.7
Figure C.1 Two Independent Layers of Cryptographic
Security Protect the SEL-3022 Wireless Operator Interface ......C.2
Figure C.2 Operation of the HMAC SHA-1
Keyed Hash Authentication Function .........................................C.9
Figure C.3 Operation of the AES Encryption Function...................................C.10
Figure C.4 SEL-3022 Security Application Overview ....................................C.11
Figure C.5 Wireless Interface Session Authentication Dialog.........................C.15
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Cryptographic Manual—Do Not Copy
Preface
Manual Overview
The SEL-3022 Wireless Encrypting Transceiver Instruction Manual describes common
aspects of the wireless encrypting transceiver application and use. It includes the
necessary information to install, set, test, and operate the transceiver.
An overview of each manual section and topics follows:
Preface. Describes the manual organization and conventions used to present
information.
Section 1: Introduction & Specifications. Introduces SEL-3022 applications,
cabling and external connections, and PC and PDA Software system
requirements. This section also lists specifications.
Section 2: Installation. Provides dimension drawings on the SEL-3022 and
instructions for setting up your PC or PDA, and initializing the
SEL-3022.
Section 3: Job Done Example. Provides a Job Done®example for applying the
SEL-3022 to an SEL-651R Recloser Control mounted twenty feet above
the street.
Section 4: Settings and Commands. This section lists all the SEL-3022 settings
including those for serial port, wireless port, encryption parameters, and
SCADA protocol. Includes information on the communication status
command for analyzing and monitoring the status of the SEL-3022 serial
port communication channel.
Section 5: Testing and Troubleshooting. Describes the SEL-3022 self-test along
with troubleshooting guidelines.
Appendix A: Firmware and Manual Versions. Lists firmware and manual revision
dates and description of modifications.
Appendix B: Firmware Upgrade Instructions. Describes the procedure to update
the firmware stored in flash memory.
Appendix C: Wireless Operator Interface Security. Discusses how the SEL-3022
incorporates a wireless LAN interface including recommended security
settings. Explains the additional AES encryption and cryptographic
authentication employed on the wireless operator interface.
Appendix D: Certificates. Describes certificates related to the SEL-3022.
Preliminary Copy

SEL-3022 Transceiver Instruction Manual Date Code 20050615
Preface
Manual Overview
viii Cryptographic Manual—Do Not Copy
Page Numbering
This manual shows page identifiers at the top of each page; see the figure
below.
Page Number Format
The page number appears at the outside edge of each page; a vertical bar separates the
page number from the page title block. The page numbers of the SEL-3022 Serial
Encrypting Transceiver Instruction Manual are represented by the following building
blocks:
➤Section number
➤Actual page number in the particular section
The section title is at the top of the page title block, with the main subsection reference
in bold type underneath the section title.
Cross-References
Cross-references are formatted as described below in both the hard copy and electronic
documentation for the SEL-3022. In the electronic documentation, clicking with the
mouse on cross-references takes you to the referenced location.
➤References to figures, tables, examples, and equations include only
the referenced item:
➢Table 3.1 (3indicates the section number)
➢Figure 4.5 (4indicates the section number)
➤References to headings on another page include the heading title and
the page number:
➢Disconnect Monitoring on page 3.8
Introduction & Specifications
Title Block Page Number
Product Overview
1.3
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Preface
Manual Overview
ix
Cryptographic Manual—Do Not Copy
Examples
This instruction manual uses several example illustrations and instructions to explain
how to effectively operate the SEL-3022. These examples are for demonstration
purposes only; the firmware identification information or settings values included in
these examples may not necessarily match those in the current version of your
SEL-3022.
Safety Information
This manual uses hazard statements, formatted and defined as follows:
Indicates a potentially hazardous
situation that, if not avoided, may
result in minor or moderate injury or
equipment damage.
!
CAUTION
Indicates a potentially hazardous
situation that, if not avoided, could
result in serious injury or death.
!
WARNING
Indicates an imminently hazardous
situation that, if not avoided, will result
in death or serious injury.
!
DANGER
Preliminary Copy

This page intentionally left blank
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Cryptographic Manual—Do Not Copy
Section 1
Introduction & Specifications
Introduction
This section includes the following overviews of the SEL-3022 Wireless Encrypting
Transceiver:
➤Product Overview
➤Application Overview
➤Connections, Reset Button, and LED Indications
➤Software System Requirements
➤General Safety and Care Information
➤Specifications
Preliminary Copy

SEL-3022 Transceiver Instruction Manual Date Code 20050615
Introduction & Specifications
Product Overview
1.2 Cryptographic Manual—Do Not Copy
Product Overview
The SEL-3022 Wireless Encrypting Transceiver is an EIA-232 to IEEE 802.11b, or
WiFi, encryption device that adds strong encryption and authentication features to the
data sent across wireless ports. The companion SEL-5809 Settings Software and
SEL-5810 Virtual Serial Software programs allow legacy Personal Computer (PC)
programs, such as HyperTerminal®, Relay Gold®, or ACSELERATOR® SEL-5030
Software, that use EIA-232 serial ports to securely communicate with the SEL-3022
via PC or Personal Digital Assistant (PDA) wireless (IEEE 802.11b) ports. See
Figure 1.1.
The SEL-3022, with the SEL-5809 Settings Software and SEL-5810 Virtual Serial
Software securely transmits and receives data between Intelligent Electronic Devices
(IEDs) and PCs (or PDAs) via an IEEE 802.11b wireless connection. The SEL-3022
and SEL-5810 Virtual Serial Software provide a retrofit solution that allows you to
continue to use standard PC programs while providing encrypted and authenticated
wireless connectivity with IEDs. See Figure 1.1.
Figure 1.1 Typical SEL-3022 and
SEL-5810 Virtual Serial Software Application
PC Application SEL-5810
SEL-651R
SEL-3022
with antenna
AcSELerator or
HyperTerminal or
SEL-3022 Settings SW
Virtual
Serial
Port
Encryption
Engine
802.11b
Port
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Introduction & Specifications
Product Overview
1.3
Cryptographic Manual—Do Not Copy
SEL-3022 Transceiver
The SEL-3022 consists of two communication ports: the EIA-232 and IEEE 802.11b.
The EIA-232 serial port connects to an IEDs EIA-232 serial port. The SEL-3022 and
IED exchange unencrypted data such as engineering access data. The SEL-3022 forms
an authentication message and encrypts the data received by the IED then passes it to
the IEEE 802.11b port. The IEEE 802.11b communication port transmits the encrypted
data to the PC/PDA running the SEL-5809 Settings Software or SEL-5810 Virtual
Serial Software. When the SEL-3022 802.11b port receives a message it decrypts and
authenticates the message. If the message decrypts and authenticates correctly the
message is passed to the serial port, otherwise the session is terminated.
SEL-5809 Settings Software and SEL-5810
Virtual Serial Software
The SEL-5809 Settings Software and SEL-5810 Virtual Serial Software are used to
communicate with the SEL-3022. The SEL-5809 Settings Software consists of three
major functions or roles: Security Officer, Operator, and User. The security officer has
access to all of the SEL-3022 configuration parameters including the cryptographic
settings. The operator has access to all of the SEL-3022 configuration parameters
except the cryptographic settings. Both the security officer and operator modes are
used to configure the SEL-3022. The user role generates a virtual serial port that allows
applications to encrypt and decrypt data between the PC and the IED that the
SEL-3022 is connected to. In the user role you cannot modify SEL-3022 configuration
parameters. To change roles you must exit the current role and reestablish a connection
to the new access level.
The SEL-5810 Virtual Serial Software is a subset of the SEL-5809 Settings Software,
and only allows connection to the SEL-3022 in the user role.
Your company security officer, or person in charge of configuring cryptographic
settings, would typically use the SEL-5809 Settings Software to configure the
SEL-3022 transceivers. After the SEL-3022 transceivers have been configured the
security officer can configure a PC and PDA with the SEL-5810 Virtual Serial
Software for field personnel (i.e., workers who need engineering access to the IEDs
connected to the SEL-3022 transceivers, but who do not need to configure the
SEL-3022 transceivers).
Both the SEL-5809 Settings Software and SEL-5810 Virtual Serial Software allow you
to integrate your standard EIA-232 serial port programs with wireless port via the
SEL-5810 Virtual Serial Software encrypting engine to a 802.11b port. When the SEL-
5809 Settings Software/SEL-5810 Virtual Serial Software receives a message from a
PC program, ACSELERATOR for example, the virtual serial port generates an
authentication message that is appended to the original message, which is then
encrypted. The SEL-5809 Settings Software/SEL-5810 Virtual Serial Software then
passes the encrypted message to the 802.11b port for transmission to the SEL-3022.
Preliminary Copy

SEL-3022 Transceiver Instruction Manual Date Code 20050615
Introduction & Specifications
Product Overview
1.4 Cryptographic Manual—Do Not Copy
When the SEL-5809 Settings Software/SEL-5810 Virtual Serial Software receives a
message from the wireless port, it decrypts and authenticates the message and passes it
to the virtual serial port which in turn passes it to your PC program. See Figure 1.2.
Figure 1.2 Encrypted Packet Stream
PC With SEL-5809 Settings Software or SEL-5810 Virtual Serial Software
SEL-5809 or SEL-5810
Security Application
Serial PC
Application
AES
Encryption
Key
AcSELerator
®
Software (2)
Hyperterml.ht
WEP
Encryption
Key
802.11b Wireless Module
Secured
Data
HMAC SHA-1
Authentication
and
AES Encryption
802.11b
Radio
WEP
Encryptor
HMAC
Authentication
Key
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Introduction & Specifications
Application Overview
1.5
Cryptographic Manual—Do Not Copy
Application Overview
The SEL-3022 is ideal for applications where engineering access communication is
required but the IED is installed in a location where physical access is limited. For
example, often recloser controls are mounted in inconvenient locations either because
of power line location or to keep them out of reach of unauthorized users. In either
case, for an engineer or lineman to communicate with the recloser control, he must
traverse these obstacles to gain physical access to the IED. This includes opening the
recloser control cabinet, which will expose the inside of the control to the weather.
Through use of the SEL-3022, the lineman simply drives within distance of the
recloser control, establishes a wireless communication link using the SEL-5810 Virtual
Serial Software, and then retrieves the fault location data or modifies settings—all from
the comfort and safety of his vehicle. Further, because this communication link does
not require the lineman to open the recloser control, the internal electronic panel is not
exposed to rain, snow, or dust.
Preliminary Copy

SEL-3022 Transceiver Instruction Manual Date Code 20050615
Introduction & Specifications
Connections, Reset Button, and LED Indications
1.6 Cryptographic Manual—Do Not Copy
Connections, Reset Button,
and LED Indications
The figure below shows typical connections for the SEL-3022.
Figure 1.3 Typical Connections for the SEL-3022
Power Supply Connections
You can apply 5 to 24 Vdc directly to the SEL-3022 power terminals, which are
available either as compression terminals or a 2.5 mm jack. If the power source voltage
is not within the 5 to 24 Vdc range, use an auxiliary power supply to provide 5 to 24
Vdc to the SEL-3022. See Specifications on page 1.12 for power requirements.
+
PC
Computer
or PDA with
802.11b
12 Vdc
802.11b link from
computer to SEL-3022
EIA-232
PWR
SEL-651R
Recloser Control
SP
Preliminary Copy

Date Code 20050615 Instruction Manual SEL-3022 Transceiver
Introduction & Specifications
Connections, Reset Button, and LED Indications
1.7
Cryptographic Manual—Do Not Copy
IMPORTANT: Do NOT wire power to both the compression
terminals and the 2.5 mm jack. Use only one power
connection at a time.
Alarm Output Connection
Use the solid-state alarm contact to alert you to problems either with the
communications channel or the SEL-3022. See Section 5: Testing and Troubleshooting
for more details. To maintain the UL rating of the SEL-3022, connect the alarm output
contact as follows:
1. Use an external load to limit current to less than 100 mA through the
alarm contact. There is no means within the SEL-3022 to limit
current through the alarm contact. You must ensure that the external
circuit connected to the SEL-3022 limits the current. For example, a
typical SEL contact input draws 4 mA. Figure 1.4 shows a typical
connection of a wetting source (125 Vdc), the SEL-3022 solid-state
output, an SEL-2030 contact input, and an optional load resistor. In
this case, because the contact input impedance limits the current to
less than 100 mA, the load resistor is not necessary. If the sensing
input does not have a means of limiting the current to less than 100
mA, then you must use a high wattage resistor. Select a load resistor
with the proper wattage rating to limit the current. For example,
assume the wetting source is 125 Vdc and that the sensing input
requires 10 mA to assert. You can use the following calculation to
determine the load resistor: 125 Vdc/ 10 mA = 12.5 kΩ. Calculate the
minimum wattage: (10 mA)2 • 12.5 kΩ= 1.25 W. You would
typically double this parameter to 2.5 W to ensure proper operation
over temperature and life. You should verify proper derating with the
resistor data sheet.
2. Circuit protection should include an in-line fuse rated for 0.5 A or
less with a voltage rating greater than the voltage you intend to use.
Figure 1.4 shows a typical alarm output installation.
CAUTION: Current through the alarm output must be limited to less
than 100 mA.
!
Preliminary Copy

SEL-3022 Transceiver Instruction Manual Date Code 20050615
Introduction & Specifications
Connections, Reset Button, and LED Indications
1.8 Cryptographic Manual—Do Not Copy
Figure 1.4 Typical Alarm Output Installation
Serial Port Pin-Out Connection
The SEL-3022 has a fully compliant DCE serial port. SEL offers many cable
configurations for use between the SEL-3022 and other devices.
The serial port pin-out descriptions for the DCE port are as follows.
Table 1.1 DCE (Female DB9)
Pin Description
1 Data Carrier Detect (Output)
2 Transmitted Data (Output)
3 Received Data (Input)
4 Data Terminal Ready (Input)
5Ground
6 Data Set Ready (Output)
7 Request to Send (Input)
8 Clear to Send (Output)
9 Ring Indicator (Output)
SEL-3022
Alarm Output Contact
Do not apply 125 Vdc
directly to the SEL-3022
power supply connections
Typical SEL contact
inputs draw 4 mA of
nominal wetting source voltage
SEL-2030
Contact Input
Wetting Voltage
125 Vdc
0.5 A, 250 V
Fast Blow Fuse
Optional Load
Resistor
+
—
Preliminary Copy
Table of contents
Other Schweitzer Engineering Laboratories Transceiver manuals
Popular Transceiver manuals by other brands

Entel
Entel HT446 owner's manual

Siemens
Siemens 7XV5654-0BA00 Directions for use

Yaesu
Yaesu FT-897 operating manual

Vertex
Vertex VX-8GR Technical supplement

Snell & Wilcox
Snell & Wilcox SHDFTRX0WQ2 Operation manual

Technisonic Industries Limited
Technisonic Industries Limited TFM-566 Installation and operating instructions