Overview
This technical reference describes how to lock down user programs, hardware configuration, and online access on a Siemens SIMATIC S7-300 PLC, with primary examples drawn from the CPU 315-2DP family used in substation automation. It consolidates the four protection mechanisms available in the SIMATIC environment: CPU password levels, Know-How Protection (KHP) on individual blocks, S7-Block Privacy introduced with STEP 7 V5.5, and the SIMATIC Logon central user administration service. The objective is to raise the bar against program theft, configuration tampering, and unauthorized commissioning access while keeping legitimate maintenance workflows operational.
Threat Model for a Substation PLC
Before configuring any switch in STEP 7, identify the adversary you are defending against. For most substation installations three threat classes are realistic:
- Casual browsing: a maintenance technician with a PG running STEP 7 connecting through a PROFIBUS or PROFINET segment. CPU password levels defeat this class.
- Targeted IP extraction: a contractor attempting to clone the program into a competitive offer, or to reverse-engineer substation-specific logic. Know-How Protection, Block Privacy, and tight management of project archives address this class.
- Active tampering: an attacker attempting to alter set points, raise alarm thresholds, or push the system into an unsafe state. CPU write protection plus network segmentation plus physical cabinet locks address this class.
Each layer below maps to one or more of these threat classes.
S7-300 CPU Protection Architecture
The S7-300 protection model in STEP 7 (versions V5.x through supported TIA Portal migrations) consists of four independently configurable layers:
| Layer | Configured in | Protects against |
|---|---|---|
| CPU access password | HW Config → CPU Properties → Protection tab | Unauthorized online read/write of the CPU |
| HMI access permission | HW Config → CPU Properties → Protection tab | Unauthenticated HMI sessions |
| Block-level Know-How Protection (KHP) | Block Properties → Know-How Protection tab | Source disclosure of compiled FC/FB/OB/DB |
| S7-Block Privacy (STEP 7 V5.5) | CPU firmware >= V3.0 and a separate project setting | Higher-resistance copy protection for FC/FB |
SIMATIC Logon can additionally tighten access to the Web server and OPC UA server of the CPU 31x PN, but it does not replace any of the layers above. Real-world deployments should treat the four layers as cumulative, not as alternatives.
Configuring the CPU Password and Levels in HW Config
The CPU access password is the first line of defense. Procedure for an S7-300 station (CPU 315-2DP shown; the steps apply to any CPU 312, 314, 315, 316, 317, 318 with the same UI):
- Open SIMATIC Manager and load the project containing the S7-300 station.
- Double-click Hardware to open HW Config.
- Select the CPU (for example
CPU 315-2DP, MLFB6ES7 315-2EH14-0AB0) in the rack. - Open Properties on the CPU object.
- Switch to the Protection tab.
- Set the Password field. Use a minimum of 8 characters; mix cases, digits, and at least one symbol. Do not reuse plant-wide or operator-panel passwords.
- Pick the desired protection level from the three radio buttons:
- No protection (default) — anyone with the project may download and start.
- Write protection — a password is required for every write/online operation that modifies the CPU. Read-back (Monitor/Modify, Upload Station to PG) is still allowed without a password.
- Write/read protection (complete protection) — a password is required for any online access including read-only operations such as Upload Station to PG.
- Configure the HMI access selector at the bottom of the same dialog: choose Accessible with password so HMIs are also forced through authentication.
- Click OK, then Save and Compile (Station → Save and Compile).
- Download the hardware configuration to the CPU via PLC → Download to Target System. The CPU enters STOP if it is running.
Password Level Comparison
| Level | Read without password | Write without password | HMI without password | Use case |
|---|---|---|---|---|
| 1 — None | Yes | Yes | Optional | Engineering bench, test racks |
| 2 — Write protection | Yes | No | Optional | Production line, casual observers present |
| 3 — Write/Read protection | No | No | Optional | Substation, third-party maintenance |
For a substation automation project, level 3 in combination with HMIs accessing through the same password is the correct baseline. Selected soft-PLCs (WinLC) lift the level to a per-user model — those stations are out of scope for the S7-300 hardware line covered here.
Know-How Protection (KHP) on Blocks
KHP is the per-block obfuscation mechanism in STEP 7. It applies to FC, FB, OB, and DB blocks and is independent of the CPU password.
Procedure in STEP 7 V5.x
- Open the S7 Program / Blocks container in SIMATIC Manager.
- Right-click the block (for example
FC 100) and choose Object Properties. - Switch to the Know-How Protection tab.
- Tick Block know-how protection.
- Enter and confirm a password. Use a different password from the CPU password.
- Click OK. The block icon in the project tree changes to a padlock overlay.
- Compile and download the project.
Behavior
- The CPU executes the block as normal. Watchdogs, scan times, and I/O behavior are unaffected.
- Without the KHP password an operator with STEP 7 can upload the block to the PG, but cannot view the STL, LAD, FBD, or SCL source. The block is replaced by a placeholder showing only the input, output, and static interface.
- Reordering of variables inside the block interface is no longer guaranteed visible.
- KHP does not encrypt the compiled code at rest on the MMC; the MMC is a separate physical-access concern.
S7-Block Privacy (STEP 7 V5.5 / FW V3.0)
S7-Block Privacy is the hardened successor to KHP and was first delivered with STEP 7 V5.5. Its principal claims are:
- The block is tied to the CPU serial number (or MMC serial number); a stolen block refuses to run on a foreign CPU.
- The block cannot be reverse-compiled even with the password.
- It requires a CPU whose firmware supports privacy S7-blocks.
Firmware Prerequisites
The original support list for S7-Block Privacy targeted SIMATIC S7-400 CPUs. The feature was later extended to the SIMATIC S7-300 family under two conditions:
- The CPU must run firmware V3.0 or higher. For the CPU 315-2DP family the relevant MLFBs and FW levels are:
-
6ES7 315-2AG10-0AB0— FW up to V2.x; not eligible. -
6ES7 315-2EH13-0AB0— FW up to V3.x; eligible after FW upgrade. -
6ES7 315-2EH14-0AB0— FW up to V3.x; eligible from stock. -
6ES7 315-2FJ14-0AB0— third-party-suitable variant; eligible from stock.
-
- The project must be edited with STEP 7 V5.5 or later (including the Service Packs).
Procedure
- In SIMATIC Manager, select the block to be privacy-locked.
- Open Object Properties → Know-How Protection.
- Switch the mode from Block know-how protection to S7-Block Privacy.
- Enter the password. Choose bind to serial number of the CPU and select the target CPU by serial number (read it via PLC → Accessible Nodes with the PG connected to the CPU).
- Compile and download. The block runs only on the bound CPU.
SIMATIC Logon Service for Centralised Access
SIMATIC Logon is an authentication service that ties selected S7-300 services to a Windows-side user database. On a CPU 31x PN it can gate the Web server, OPC UA server, and (since TIA Portal V14) certain PG-side functions. It does not, however, replace the CPU password; the two run in parallel and grant different access scopes.
Prerequisites
- CPU 31x PN (for example CPU 315-2 PN/DP, MLFB
6ES7 315-2EH14-0AB0) with firmware V3.x. - SIMATIC Logon software installed on the engineering station or a domain controller.
- CPU configured with a valid IP address and reachable from the SIMATIC Logon station.
Activation procedure on the S7-300
- In TIA Portal, open the project → CPU Properties → Protection & Security tab.
- Tick Use SIMATIC Logon for access to Web server / OPC UA server.
- Choose the user roles mapped to read-only and read/write access.
- Compile and download.
- Configure users in SIMATIC Logon on the Windows host and assign them to the chosen roles.
For engineers who still run STEP 7 V5.x on the S7-300, the activation page lives under CPU Properties → Protection → Activate SIMATIC Logon. Selecting it without first provisioning the Logon server stops the CPU at startup with a diagnostic buffer entry indicating the authentication service is not reachable.
CPU 315-2DP Specific Considerations
The CPU 315-2DP family has the largest installed base of any S7-300 substation CPU. Five notes specific to this device:
| Concern | Detail |
|---|---|
| MPI/DP interface role | The first interface is fixed MPI/DP. Treat any MPI cable on a spare laptop as a maintenance attack surface. |
| PROFIBUS DP master secret | DP master does not authenticate DP slaves. A bogus slave on the segment can drive outputs; pair DP isolation with the CPU password. |
| Spare second interface | On the -2EH14 variant the second interface is PROFINET. Disable unused services (Web server, SNMP, FTP client, LLDP forwarding). |
| Memory card | The SIMATIC MMC is required for firmware V3.0+. Lock the MMC to this CPU with PLC → Assign MMC; the block then refuses to run on another CPU even if the CPU password is known. |
| Diagnostic buffer | Failed login attempts are buffered. Read the buffer via PLC → Diagnostic Buffer to detect probing. |
Hardware and Physical Anti-Tamper Measures
The strongest defense on an unattended substation site is outside the software stack. Apply these in addition to the configurations above:
- Cabinet control. Swing-handle lock with a registered key system; hinge covers on DIN rails; tamper-evident seals on the CPU and the MMC door.
- Network segmentation. Place the S7-300 on an isolated VLAN with the SCADA gateway at the only routing point. Disable auto-cross on adjacent switches to prevent a stealth hub cable from giving parallel access.
- Disable unused services. On the PN interface, turn off the Web server if not required; turn off FTP server; turn off LLDP forward if the SCADA server reads it via a separate system.
- Cover unused ports. Blanking plates on every unused PROFIBUS-DP connector, MPI connector, and PN port reduce the risk of accidental connection.
- Document ports. Stick the connection scheme and approved tools on the inside of the cabinet door.
Known Attack Surfaces and Limits
Siemens' protection system is engineered for industrial use cases and has documented limitations. State them in the cyber-security plan rather than pretending they do not exist:
- Password brute force. CPU passwords of 8 characters are brute-force-resistant in a substation remote-attack model, not against a determined attacker with a stolen MMC and unlimited time.
- On-CPU password reset. Reading out the password via the diagnostic buffer on certain old firmware versions was historically possible; CPU 31x with FW V3.0+ removed the well-known paths.
- Physical extraction. With direct access to the MMC and a SIMATIC Field PG, the block metadata (including KHP-encrypted bodies) can be read. S7-Block Privacy plus MMC-locking mitigates, but does not eliminate, this vector.
- Replay. An attacker who can read the project archive from a backup can produce identical KHP behaviour on a similar CPU. Treat the backup chain with the same protection as the cabinet.
Verification and Commissioning Checklist
After configuring the layers above, prove them on the live CPU before sign-off:
| # | Check | Expected result |
|---|---|---|
| 1 | Connect PG with empty CPU password | Online connect denied; diagnostic buffer shows password error |
| 2 | Connect PG with valid CPU password | Online connect accepted, project visible |
| 3 | Upload KHP-protected FC 100 to an empty PG | Block uploaded, STL/SCL hidden, interface visible |
| 4 | Upload S7-Block-Privacy-protected FC 101 to another CPU of same MLFB | CPU enters STOP with block-not-for-this-CPU error |
| 5 | Read diagnostic buffer with valid password | Buffer shows login-failure entries if any earlier failed attempt was made |
| 6 | Verify SIMATIC Logon mapping (for PN CPUs) | Web server rejects anonymous users; accepts mapped role users |
| 7 | Test HMI without password | HMI session is denied at level 3 |
Document the password handover in the commissioning report and store the password outside the project file. Standard practice is to seal the credential envelope with the as-built documentation and register it in the site's password management system.
FAQ
What happens if I forget the CPU password on an S7-300?
For S7-300 CPUs running firmware V3.0 or higher, password reset requires a Siemens Support intervention and a notarised authorization, because the password is bound to the MMC. There is no general field reset path. Always store CPU passwords in a separate credential vault before commissioning.
Can someone upload my program if they have STEP 7 but no password?
Only if the CPU access protection is set to level 1 or level 2 (write protection). With level 3 (write/read protection) the Upload Station to PG function is denied without the password, regardless of whether the blocks are KHP-protected or not.
What is the difference between Know-How Protection and S7-Block Privacy?
KHP hides the source code of a block but the compiled block is otherwise freely transferable. S7-Block Privacy binds the block to a specific CPU serial number, so the block refuses to run on any other CPU and is harder to reverse. S7-Block Privacy requires STEP 7 V5.5 or later and CPU firmware V3.0 or higher on the S7-300.
Does S7-Block Privacy protect OB and DB blocks?
No. The privacy feature applies to FC and FB blocks. Organisation blocks, system data, and hardware configuration are protected by the CPU access password level only.
Which firmware version of CPU 315-2DP is required for S7-Block Privacy?
Firmware version V3.0 or higher is required. The stock MLFB 6ES7 315-2EH14-0AB0 ships with an eligible version; older MLFBs such as 6ES7 315-2AG10-0AB0 must be upgraded before the privacy option becomes available.