S7-300 Program Protection: CPU Passwords, KHP, and Block Privacy

David Krause12 min read
S7-300SiemensTechnical Reference
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

Overview

This technical reference describes how to lock down user programs, hardware configuration, and online access on a Siemens SIMATIC S7-300 PLC, with primary examples drawn from the CPU 315-2DP family used in substation automation. It consolidates the four protection mechanisms available in the SIMATIC environment: CPU password levels, Know-How Protection (KHP) on individual blocks, S7-Block Privacy introduced with STEP 7 V5.5, and the SIMATIC Logon central user administration service. The objective is to raise the bar against program theft, configuration tampering, and unauthorized commissioning access while keeping legitimate maintenance workflows operational.

Design principle: PLC password protection is a deterrent and an integrity control, not a cryptographic secret. Any insider with physical access to the CPU and an MPI/DP/PN adapter can recover a program. Treat the protection levels described here as one layer of a defense-in-depth strategy that also includes cabinet locks, network segmentation, removable memory card control, and credential management.

Threat Model for a Substation PLC

Before configuring any switch in STEP 7, identify the adversary you are defending against. For most substation installations three threat classes are realistic:

  1. Casual browsing: a maintenance technician with a PG running STEP 7 connecting through a PROFIBUS or PROFINET segment. CPU password levels defeat this class.
  2. Targeted IP extraction: a contractor attempting to clone the program into a competitive offer, or to reverse-engineer substation-specific logic. Know-How Protection, Block Privacy, and tight management of project archives address this class.
  3. Active tampering: an attacker attempting to alter set points, raise alarm thresholds, or push the system into an unsafe state. CPU write protection plus network segmentation plus physical cabinet locks address this class.

Each layer below maps to one or more of these threat classes.

S7-300 CPU Protection Architecture

The S7-300 protection model in STEP 7 (versions V5.x through supported TIA Portal migrations) consists of four independently configurable layers:

Layer Configured in Protects against
CPU access password HW Config → CPU Properties → Protection tab Unauthorized online read/write of the CPU
HMI access permission HW Config → CPU Properties → Protection tab Unauthenticated HMI sessions
Block-level Know-How Protection (KHP) Block Properties → Know-How Protection tab Source disclosure of compiled FC/FB/OB/DB
S7-Block Privacy (STEP 7 V5.5) CPU firmware >= V3.0 and a separate project setting Higher-resistance copy protection for FC/FB

SIMATIC Logon can additionally tighten access to the Web server and OPC UA server of the CPU 31x PN, but it does not replace any of the layers above. Real-world deployments should treat the four layers as cumulative, not as alternatives.

Configuring the CPU Password and Levels in HW Config

The CPU access password is the first line of defense. Procedure for an S7-300 station (CPU 315-2DP shown; the steps apply to any CPU 312, 314, 315, 316, 317, 318 with the same UI):

  1. Open SIMATIC Manager and load the project containing the S7-300 station.
  2. Double-click Hardware to open HW Config.
  3. Select the CPU (for example CPU 315-2DP, MLFB 6ES7 315-2EH14-0AB0) in the rack.
  4. Open Properties on the CPU object.
  5. Switch to the Protection tab.
  6. Set the Password field. Use a minimum of 8 characters; mix cases, digits, and at least one symbol. Do not reuse plant-wide or operator-panel passwords.
  7. Pick the desired protection level from the three radio buttons:
    • No protection (default) — anyone with the project may download and start.
    • Write protection — a password is required for every write/online operation that modifies the CPU. Read-back (Monitor/Modify, Upload Station to PG) is still allowed without a password.
    • Write/read protection (complete protection) — a password is required for any online access including read-only operations such as Upload Station to PG.
  8. Configure the HMI access selector at the bottom of the same dialog: choose Accessible with password so HMIs are also forced through authentication.
  9. Click OK, then Save and Compile (Station → Save and Compile).
  10. Download the hardware configuration to the CPU via PLC → Download to Target System. The CPU enters STOP if it is running.
Critical: The CPU 31x-2 DP/PN share a single CPU password. Recovering the password for a CPU 300/400 in the field is very difficult. Store the password in a credential manager (Siemens TIA Password Manager, KeePass, or a SIMATIC Logon central store) before placing the station in service.

Password Level Comparison

Level Read without password Write without password HMI without password Use case
1 — None Yes Yes Optional Engineering bench, test racks
2 — Write protection Yes No Optional Production line, casual observers present
3 — Write/Read protection No No Optional Substation, third-party maintenance

For a substation automation project, level 3 in combination with HMIs accessing through the same password is the correct baseline. Selected soft-PLCs (WinLC) lift the level to a per-user model — those stations are out of scope for the S7-300 hardware line covered here.

Know-How Protection (KHP) on Blocks

KHP is the per-block obfuscation mechanism in STEP 7. It applies to FC, FB, OB, and DB blocks and is independent of the CPU password.

Procedure in STEP 7 V5.x

  1. Open the S7 Program / Blocks container in SIMATIC Manager.
  2. Right-click the block (for example FC 100) and choose Object Properties.
  3. Switch to the Know-How Protection tab.
  4. Tick Block know-how protection.
  5. Enter and confirm a password. Use a different password from the CPU password.
  6. Click OK. The block icon in the project tree changes to a padlock overlay.
  7. Compile and download the project.

Behavior

  • The CPU executes the block as normal. Watchdogs, scan times, and I/O behavior are unaffected.
  • Without the KHP password an operator with STEP 7 can upload the block to the PG, but cannot view the STL, LAD, FBD, or SCL source. The block is replaced by a placeholder showing only the input, output, and static interface.
  • Reordering of variables inside the block interface is no longer guaranteed visible.
  • KHP does not encrypt the compiled code at rest on the MMC; the MMC is a separate physical-access concern.
Common pitfall: KHP passwords are stored in the STEP 7 project file. If the project archive is shared with a contractor or stored on a backup server without encryption, the KHP password leaves with it. Decouple the password vault from the project archive by storing passwords outside the SIMATIC project directory.

S7-Block Privacy (STEP 7 V5.5 / FW V3.0)

S7-Block Privacy is the hardened successor to KHP and was first delivered with STEP 7 V5.5. Its principal claims are:

  • The block is tied to the CPU serial number (or MMC serial number); a stolen block refuses to run on a foreign CPU.
  • The block cannot be reverse-compiled even with the password.
  • It requires a CPU whose firmware supports privacy S7-blocks.

Firmware Prerequisites

The original support list for S7-Block Privacy targeted SIMATIC S7-400 CPUs. The feature was later extended to the SIMATIC S7-300 family under two conditions:

  1. The CPU must run firmware V3.0 or higher. For the CPU 315-2DP family the relevant MLFBs and FW levels are:
    • 6ES7 315-2AG10-0AB0 — FW up to V2.x; not eligible.
    • 6ES7 315-2EH13-0AB0 — FW up to V3.x; eligible after FW upgrade.
    • 6ES7 315-2EH14-0AB0 — FW up to V3.x; eligible from stock.
    • 6ES7 315-2FJ14-0AB0 — third-party-suitable variant; eligible from stock.
  2. The project must be edited with STEP 7 V5.5 or later (including the Service Packs).

Procedure

  1. In SIMATIC Manager, select the block to be privacy-locked.
  2. Open Object Properties → Know-How Protection.
  3. Switch the mode from Block know-how protection to S7-Block Privacy.
  4. Enter the password. Choose bind to serial number of the CPU and select the target CPU by serial number (read it via PLC → Accessible Nodes with the PG connected to the CPU).
  5. Compile and download. The block runs only on the bound CPU.
Known limitation: S7-Block Privacy protects FC and FB blocks only. It does not bind OB, system data, or hardware configuration. Encrypted FC/FB blocks cannot be transferred to CPUs that pre-date privacy support — the download fails with a diagnostic buffer entry indicating the firmware mismatch. Verify the firmware level on every downstream CPU before re-binding.

SIMATIC Logon Service for Centralised Access

SIMATIC Logon is an authentication service that ties selected S7-300 services to a Windows-side user database. On a CPU 31x PN it can gate the Web server, OPC UA server, and (since TIA Portal V14) certain PG-side functions. It does not, however, replace the CPU password; the two run in parallel and grant different access scopes.

Prerequisites

  • CPU 31x PN (for example CPU 315-2 PN/DP, MLFB 6ES7 315-2EH14-0AB0) with firmware V3.x.
  • SIMATIC Logon software installed on the engineering station or a domain controller.
  • CPU configured with a valid IP address and reachable from the SIMATIC Logon station.

Activation procedure on the S7-300

  1. In TIA Portal, open the project → CPU Properties → Protection & Security tab.
  2. Tick Use SIMATIC Logon for access to Web server / OPC UA server.
  3. Choose the user roles mapped to read-only and read/write access.
  4. Compile and download.
  5. Configure users in SIMATIC Logon on the Windows host and assign them to the chosen roles.

For engineers who still run STEP 7 V5.x on the S7-300, the activation page lives under CPU Properties → Protection → Activate SIMATIC Logon. Selecting it without first provisioning the Logon server stops the CPU at startup with a diagnostic buffer entry indicating the authentication service is not reachable.

CPU 315-2DP Specific Considerations

The CPU 315-2DP family has the largest installed base of any S7-300 substation CPU. Five notes specific to this device:

Concern Detail
MPI/DP interface role The first interface is fixed MPI/DP. Treat any MPI cable on a spare laptop as a maintenance attack surface.
PROFIBUS DP master secret DP master does not authenticate DP slaves. A bogus slave on the segment can drive outputs; pair DP isolation with the CPU password.
Spare second interface On the -2EH14 variant the second interface is PROFINET. Disable unused services (Web server, SNMP, FTP client, LLDP forwarding).
Memory card The SIMATIC MMC is required for firmware V3.0+. Lock the MMC to this CPU with PLC → Assign MMC; the block then refuses to run on another CPU even if the CPU password is known.
Diagnostic buffer Failed login attempts are buffered. Read the buffer via PLC → Diagnostic Buffer to detect probing.

Hardware and Physical Anti-Tamper Measures

The strongest defense on an unattended substation site is outside the software stack. Apply these in addition to the configurations above:

  • Cabinet control. Swing-handle lock with a registered key system; hinge covers on DIN rails; tamper-evident seals on the CPU and the MMC door.
  • Network segmentation. Place the S7-300 on an isolated VLAN with the SCADA gateway at the only routing point. Disable auto-cross on adjacent switches to prevent a stealth hub cable from giving parallel access.
  • Disable unused services. On the PN interface, turn off the Web server if not required; turn off FTP server; turn off LLDP forward if the SCADA server reads it via a separate system.
  • Cover unused ports. Blanking plates on every unused PROFIBUS-DP connector, MPI connector, and PN port reduce the risk of accidental connection.
  • Document ports. Stick the connection scheme and approved tools on the inside of the cabinet door.

Known Attack Surfaces and Limits

Siemens' protection system is engineered for industrial use cases and has documented limitations. State them in the cyber-security plan rather than pretending they do not exist:

  • Password brute force. CPU passwords of 8 characters are brute-force-resistant in a substation remote-attack model, not against a determined attacker with a stolen MMC and unlimited time.
  • On-CPU password reset. Reading out the password via the diagnostic buffer on certain old firmware versions was historically possible; CPU 31x with FW V3.0+ removed the well-known paths.
  • Physical extraction. With direct access to the MMC and a SIMATIC Field PG, the block metadata (including KHP-encrypted bodies) can be read. S7-Block Privacy plus MMC-locking mitigates, but does not eliminate, this vector.
  • Replay. An attacker who can read the project archive from a backup can produce identical KHP behaviour on a similar CPU. Treat the backup chain with the same protection as the cabinet.

Verification and Commissioning Checklist

After configuring the layers above, prove them on the live CPU before sign-off:

# Check Expected result
1 Connect PG with empty CPU password Online connect denied; diagnostic buffer shows password error
2 Connect PG with valid CPU password Online connect accepted, project visible
3 Upload KHP-protected FC 100 to an empty PG Block uploaded, STL/SCL hidden, interface visible
4 Upload S7-Block-Privacy-protected FC 101 to another CPU of same MLFB CPU enters STOP with block-not-for-this-CPU error
5 Read diagnostic buffer with valid password Buffer shows login-failure entries if any earlier failed attempt was made
6 Verify SIMATIC Logon mapping (for PN CPUs) Web server rejects anonymous users; accepts mapped role users
7 Test HMI without password HMI session is denied at level 3

Document the password handover in the commissioning report and store the password outside the project file. Standard practice is to seal the credential envelope with the as-built documentation and register it in the site's password management system.

FAQ

What happens if I forget the CPU password on an S7-300?

For S7-300 CPUs running firmware V3.0 or higher, password reset requires a Siemens Support intervention and a notarised authorization, because the password is bound to the MMC. There is no general field reset path. Always store CPU passwords in a separate credential vault before commissioning.

Can someone upload my program if they have STEP 7 but no password?

Only if the CPU access protection is set to level 1 or level 2 (write protection). With level 3 (write/read protection) the Upload Station to PG function is denied without the password, regardless of whether the blocks are KHP-protected or not.

What is the difference between Know-How Protection and S7-Block Privacy?

KHP hides the source code of a block but the compiled block is otherwise freely transferable. S7-Block Privacy binds the block to a specific CPU serial number, so the block refuses to run on any other CPU and is harder to reverse. S7-Block Privacy requires STEP 7 V5.5 or later and CPU firmware V3.0 or higher on the S7-300.

Does S7-Block Privacy protect OB and DB blocks?

No. The privacy feature applies to FC and FB blocks. Organisation blocks, system data, and hardware configuration are protected by the CPU access password level only.

Which firmware version of CPU 315-2DP is required for S7-Block Privacy?

Firmware version V3.0 or higher is required. The stock MLFB 6ES7 315-2EH14-0AB0 ships with an eligible version; older MLFBs such as 6ES7 315-2AG10-0AB0 must be upgraded before the privacy option becomes available.

Back to blog