Automatic transfer, load shedding and restoration must be engineered as one coordinated state machine. Transfer preserves supply, shedding preserves source stability/capacity, and restoration returns load without retriggering the disturbance. Unsafe schemes arise when each function has separate timers, stale topology, competing command authority or no defined abort/recovery state.
This guide designs MV bus/incomer/coupler automation with protection independence, source-quality validation, synchrocheck, priority, communications failure behavior and end-to-end testing.
1. Define objectives and prohibited outcomes
- Maintain critical loads after loss of one source where capacity/topology permit.
- Prevent paralleling sources not rated/authorized for parallel operation.
- Prevent closing onto a faulted bus/feeder or active lockout.
- Keep source/transformer/generator loading within emergency/continuous limits.
- Shed low-priority load before frequency/voltage collapse or source overload.
- Restore gradually only after stable conditions and adequate reserve.
- Never block protection trips or breaker-failure action.
2. Inputs and their quality
| Input group | Required information |
|---|---|
| Source | Voltage/frequency/live-dead, phase sequence, transformer/generator availability and capacity |
| Topology | Incomer/coupler/feeder double-point position, truck/disconnector/earthing state |
| Protection | Trip cause, lockout, bus/arc/transformer fault, breaker failure and reclose state |
| Equipment | Breaker mechanism/DC readiness, trip/close circuit, maintenance/local mode |
| Loading | Source/bus/feeder P, I, demand, reserve and priority |
| System | Auto enable, authority, time/communication quality and sequence state |
Every required input needs a freshness/quality rule. “Last good voltage” after VT/IED link loss must not authorize transfer.
3. Transfer philosophies
| Mode | Sequence | Main constraint |
|---|---|---|
| Open transition | Open failed source, verify open/dead as required, close alternate | Supply interruption and residual bus voltage |
| Fast transfer | Rapid source change within phase/frequency criteria | Motor residual voltage, timing and source relationship |
| In-phase transfer | Predict/close within acceptable phase window | Accurate voltage/frequency/phase measurement |
| Closed transition | Briefly parallel then open original source | Paralleling rating, protection and utility authorization |
| Manual supervised | Operator sequence with automatic checks | Human timing/authority and clear feedback |
4. Cause qualification
- Distinguish source undervoltage from VT fuse/MCB failure, dead-bus measurement loss and downstream fault depression.
- Use appropriate voltage threshold, delay and phase criteria to ride through acceptable disturbances without delaying real loss.
- Block transfer for busbar/arc/transformer fault, breaker failure or lockout that makes alternate energization unsafe.
- Coordinate with upstream reclosing and generator/transformer protection.
- Record the initiating cause and conditions that qualified it.
- Do not initiate from a single unvalidated SCADA analog.
5. State-machine design
- IDLE/armed with all prerequisites supervised.
- DETECT/QUALIFY source loss or overload.
- BLOCK CHECK for protection, maintenance, topology and authority.
- OPEN/SHED required breakers with bounded confirmation timeout.
- VERIFY open/dead/synchronism and alternate source capacity.
- CLOSE alternate/coupler with one authorized attempt.
- CONFIRM final topology, voltage and load.
- RESTORE staged loads under stability/reserve checks.
- COMPLETE with latched event record or ABORT/LOCKOUT with operator action.
Every state needs entry, action, exit, timeout, restart and manual-takeover behavior. A controller reboot must not resume from an ambiguous output state.
6. Load-shedding design
- Create consequence-based priority groups: essential, process critical, restart-sensitive and interruptible.
- Initiate from frequency/ROCOF, voltage, source overload, transformer limit or transfer-state logic as justified.
- Calculate required MW/Mvar/current relief including motor behavior and contingency margin.
- Use stages and minimum separation to observe response; avoid simultaneous unnecessary over-shedding.
- Verify breaker availability/current state before counting expected relief.
- Alarm a failed shed command and escalate/issue the next action by defined logic.
- Maintain fairness/rotation only if it cannot compromise priority.
7. Restoration logic
- Require stable voltage/frequency/source reserve for a defined dwell time.
- Restore highest-priority load first, subject to inrush/motor-start and transformer limits.
- Use one stage at a time and verify measured response before continuing.
- Abort/pause on instability, overload, bad measurement or failed breaker feedback.
- Limit automatic retries and prevent oscillation between shed/restore.
- Consider process restart sequence and cold-load pickup, not only steady-state kW.
- Provide operator approval where consequences/uncertainty justify it.
8. Protection and control coordination
- Protection trips take priority over automation close requests.
- Coordinate transfer dead time with motor protection, undervoltage release and process ride-through.
- Review short-circuit level and protection settings for alternate/coupled topology.
- Breaker failure and bus/arc protection must lock out unsafe transfer paths.
- Synchrocheck/dead-bus logic remains at the final close gate.
- Local/maintenance authority and earthing/truck interlocks block automatic closing.
- Reclose and transfer logic must not issue conflicting commands.
9. Centralized versus distributed implementation
- Bay IEDs provide local final interlock/output and fast protection-independent state.
- Station controller may own multi-bay sequence/topology/load calculation.
- GOOSE can transfer fast supervised peer signals; define timeout/fail-safe behavior.
- SCADA provides enable, initiation/abort, monitoring and audit, not the only final close interlock.
- Central logic needs redundant power/compute/network or a safe manual degraded mode.
- One approved state-machine owner prevents duplicate station/SCADA automation.
10. Failure and cyber behavior
- On lost/stale required input, block new automatic close and hold/abort safely.
- On output uncertainty, reconcile breaker position before retry.
- Prevent split-brain redundant controllers and duplicate commands.
- Role-protect auto enable, thresholds, priorities, bypass and manual force.
- Audit every mode/setting change, cause, state transition and command result.
- Segment/allowlist automation flows and protect SCL/logic/settings.
- Restore from a signed/tested release; never use unverified standby configuration.
11. Study inputs before implementation
- Load-flow for normal, contingency, transfer and restoration stages.
- Short-circuit/protection study for alternate topology.
- Motor residual-voltage/inrush and transformer cold-load pickup where relevant.
- Source/utility paralleling and synchronism constraints.
- Breaker operating/clearing times and mechanism/control voltage limits.
- Communications/timing and common-mode failure analysis.
- Operating philosophy and manual fallback switching procedure.
12. FAT/SAT dynamic tests
- Freeze state diagrams, settings, SCD/logic, load priorities and test model.
- Simulate each valid initiation and every block cause.
- Vary voltage/frequency/load around thresholds/delays/hysteresis.
- Fail breaker to open/close, use intermediate/invalid feedback and late operation.
- Lose VT/IED/GOOSE/controller/LAN/time and restart/fail over the controller in every state.
- Test competing manual/remote/reclose/protection commands.
- Apply load model to prove shedding magnitude and staged restoration stability.
- Verify no duplicate close, unsafe parallel or automatic retry after ambiguity.
- At SAT, use staged secondary injection and approved breaker operations.
- Archive SOE, waveform/network evidence, timings and as-built logic/settings.
13. Commissioning and operational governance
- Commission first in monitor/advisory mode and compare proposed actions with operator decisions.
- Enable closed-loop stages only after topology, measurement and remote-control quality is demonstrated.
- Train operators on every armed, blocked, running, abort and manual-recovery state.
- Review every automatic operation or near-miss against the study/model and SOE.
- Revalidate after source, transformer, feeder, protection setting, load priority, breaker-time or firmware/network change.
- Periodically test failover, block inputs and a representative end-to-end sequence without creating unacceptable system risk.
References and further reading
- IEC 61850-5 consolidated edition — Function and performance requirements
- IEC 61850-7-4 consolidated edition — Logical nodes/data objects
- IEC 61850-8-1 consolidated edition — GOOSE/MMS controls
- IEC 61850-6 edition 2.2 — SCL engineering
- IEC 61850-10 edition 2.1 — Conformance/performance testing
- IEC 62351-6:2020 — IEC 61850 security
Engineering note: Never count a load as shed or a source as transferred until independent breaker feedback and stable electrical measurements confirm the physical result.