DALI · Concepts
Security
The protections built into a station, what they do for you, and how to deploy a station safely on your network.
A station is a measurement device that often sits on a plant or utility network. It is built not to assume that network is trusted. This page describes the protections a station gives you and what Aeron recommends you do when you install one. It follows the Aeron XTM Cybersecurity Manual, which is available from Aeron on request, and describes firmware 4.1 where the two differ.
Standards
Aeron develops the XTM against these standards:
| Standard | Status |
|---|---|
| IEC 62443-4-1, secure product development | In progress |
| IEC 62443-4-2, component security requirements | In progress |
| CEA Cyber Security in Power Sector regulations (India) | Aligned |
| OWASP ASVS Level 2, for the web console | Internal target |
| Indian IT Act, 2000 | Aligned. The station records sensor data and station health. The only personal data it keeps is who signed in, in its activity log. |
Signing in
On firmware 4.1 and later:
- No shared station passwords. Every sign-in goes through the person's own Live3 account: an access code, a signed access link, or Continue with Live3. There is no password on the station for anyone to guess or pass around. See Roles and access.
- Codes are personal and short-lived. An access code is made for one person, one station and one role, changes every minute, and works once.
- Links are signed and checked on the station. An access link is signed by Aeron, names one station, expires within 30 days, works once, and can be cancelled from Live3.
- Guessing is slowed and then blocked. Every failed sign-in adds a delay, and too many failures from one address, or on one station, blocks further attempts for a while.
- Being nearby is not enough. Reaching a station over Bluetooth on its own only gives read-only access.
- Sessions end. You are signed out after 30 minutes without activity.
Doing only what your role allows
- The station checks your role on the server for every page and every action, not just by hiding buttons. See the full table in Roles and access.
- Refused attempts are recorded in the activity log.
- Stored passwords (Wi-Fi, cellular, hotspot, cloud upload) are never sent to your browser when a page loads. An Admin can choose to show one, and that is logged.
The activity log
The station records sign-ins and sign-outs, refused attempts, configuration changes, data downloads, remote support sessions and firmware actions. Each entry records when, who, their role, where from, what, and the outcome.
Each entry is chained to the one before it with a keyed hash, so editing or deleting an old entry breaks the chain. Entries are kept for 180 days. See Activity logs.
Network exposure
The station keeps a small surface on the network:
| Port | Service | Notes |
|---|---|---|
| 443 (TCP) | The web console, over HTTPS | Uses the station's own certificate. Your browser may warn the first time. |
| 80 (TCP) | Redirects to HTTPS | Also answers the hotspot's sign-in page on the station's own Wi-Fi. |
| 502 (TCP) | Modbus TCP slave | Optional. Read-only: it answers read requests only and changes nothing. Modbus has no sign-in of its own, so limit it to your SCADA network. |
| 22 (TCP) | Service access for Aeron | No credentials are given to customers. Block it from your networks. |
It runs no Telnet, no FTP server, no file sharing and no SNMP.
- Allow-list. A station can be limited to answering only the network ranges you list. Requests from anywhere else are refused and logged. It is set in the station's configuration rather than on a console page; ask Aeron to set it at commissioning.
- Remote support is off by default and, when on, uses an outgoing connection that ends by itself. See Remote support.
- Network changes undo themselves if they cut the station off. See Networking.
Your data
| Where | Protection |
|---|---|
| On the SD card | Files are encrypted (AES-256). A card taken out of the station cannot be read elsewhere. |
| On internal storage | Inside the sealed enclosure; not removable. |
| Copied to a USB drive | Plain CSV, so you can open it anywhere. The USB export switch is off unless an Admin turns it on, and each change to it is logged. |
| The SD card slot | Can be switched off by an Admin. |
| Uploads to Live3 | HTTPS. |
| Uploads to your cloud (firmware 4.1 and later) | Encrypted (TLS) by default. Sending without encryption to MQTT or TCP needs you to confirm the receiver is on a private network. Passwords and keys you enter are write-only: the page never shows them back. Only transports that are safe to configure are offered. |
| Legacy FTP and HTTP uploads | Not encrypted. Use them only on a private network, and prefer HTTPS or a cloud destination. |
Firmware
On firmware 4.1 and later, releases are signed by Aeron, and a station checks every part of a release before installing it. Installing needs an Admin, and it is switched off on each station until you turn it on. A failed install is rolled back. See Firmware updates.
Time
A station takes its time from your NTP server when it can reach one, and from GPS otherwise. Large jumps in time are logged, and the station starts a new data file at a jump so older records are never overwritten. The sign-in session timer does not use the clock at all.
Recommended deployment
For a station on any network that is not fully isolated:
- Put the station behind your plant-edge firewall or SCADA DMZ. Do not give it a public internet address.
- Allow outgoing traffic only to the places it uploads to, and to Live3 if you use it.
- Block incoming traffic from outside your operations network. For remote engineering access, use your own VPN, or Aeron remote support when needed.
- Block port 22 from your networks.
- Turn off the Modbus TCP slave if you do not use it. If you do, allow port 502 only from your SCADA network.
- Ask Aeron to turn on the allow-list for your operations subnet.
- Upload over HTTPS or an encrypted cloud destination, not plain FTP or HTTP.
- Use your own NTP server for time. See Set the time.
- Leave USB export and remote support off unless you need them.
- Give people the lowest role that does their job: User for anyone who only reads data.
Contact Aeron at support@aeronsystems.com to receive Aeron's product security advisories.