Hardwired and IEC 61850 GOOSE trips are different implementations of the same protection function—not opposing ideologies. A copper contact path can fail silently at a fuse, terminal or coil. A GOOSE path can be fast and continuously supervised yet share switches, time/configuration tools or subscriber logic. The correct choice follows a quantified dependability, security, performance, maintenance and cybersecurity study.
This guide compares source-to-coil hardwired trips with GOOSE-based inter-IED trips in MV switchgear. It covers latency, retransmission, supervision, PRP/HSR, VLAN/QoS, common-cause failure, SCL, network load, cybersecurity, testing, hybrid schemes and a decision matrix. It does not assume that the breaker trip coil is digital: in most MV installations, even a GOOSE scheme ends in a physical IED output, DC circuit and shunt-trip coil.
Executive conclusions
- Define the required protection transfer time, dependability, security, independence, diagnostics and maintenance behavior before selecting the medium.
- A hardwired intertrip path contains DC source, branch protection, output contacts, cable, test links, terminals and receiving trip logic/coil; review the complete loop.
- A GOOSE path contains publisher logic, Ethernet interface, network links/switches/redundancy, subscriber configuration/quality logic and final output/coil; review the complete chain.
- GOOSE uses event-driven multicast with rapid retransmission; performance depends on end devices, network design, load and configuration—not the protocol name alone.
- PRP/HSR can provide seamless recovery from one network element failure, but only when LAN A/B or ring paths, power supplies and devices avoid common failure.
- GOOSE offers strong online supervision and reduces copper, but configuration errors can affect many bays simultaneously.
- Hardwired trips are visually traceable and independent of Ethernet, but they can have latent open circuits and scale poorly for many destinations.
- Cybersecurity controls must protect engineering access, SCL/configuration and network devices without adding unvalidated latency or single points to time-critical protection.
- Hybrid architecture is often strongest: local breaker trip remains direct hardwired while inter-bay permissives, blocking or backup trips use engineered GOOSE with appropriate fallback.
- Test every required path, failover, publisher/subscriber loss, quality/test state and final breaker operation end-to-end; a successful GOOSE packet capture alone is not a trip test.
1. Compare functions, not just wires and packets
| Requirement | Question |
|---|---|
| Performance | Maximum transfer time and jitter from source element to receiving output? |
| Dependability | Probability of operating when required; which failures are detectable? |
| Security | Probability of no unwanted trip; how are false/stale/test messages handled? |
| Availability | What remains after one device, supply, cable, switch or configuration failure? |
| Independence | Do Main 1/Main 2 truly avoid common hardware, network and engineering failures? |
| Maintainability | Can one bay/path be tested without risking adjacent service equipment? |
| Lifecycle | How are drawings/SCL, firmware, switches, tools, spares and competence managed? |
| Cybersecurity | How are access, integrity, event logging and recovery controlled? |
2. Complete hardwired trip chain
- DC source/end-of-discharge voltage and branch protection;
- output contact making/carrying/DC inductive breaking duty;
- wire loop resistance and coil-terminal voltage;
- test-link/terminal normal position and trip-circuit supervision;
- dual coils/paths and shared returns;
- interposing relay pickup/release time and failure;
- cable route, fire/EMC and cross-panel interface;
- 52a/52b cut-off and coil pulse duty.
A hardwired path can be very deterministic but not automatically supervised end-to-end. TCS often supervises the final coil circuit, while an upstream intertrip cable contact may need separate supervision or periodic proof testing.
3. Complete GOOSE trip chain
- correct logical node/data object and dataset bit order/type;
- APPID, MAC, VLAN and priority engineering;
- publisher state/sequence, retransmission and supervision;
- subscriber acceptance of quality, test and simulation states;
- network path, switch configuration, multicast handling and load;
- PRP/HSR duplicate handling where used;
- IED CPU/logic execution and output operate time;
- final hardwired output, DC branch and breaker coil;
- SCL/firmware/network configuration governance.
4. GOOSE behavior in practical terms
GOOSE maps IEC 61850 data to Layer-2 Ethernet multicast under IEC 61850-8-1. A state change is transmitted rapidly and then retransmitted at increasing intervals; steady-state repetitions allow subscribers to detect loss. This architecture avoids waiting for a request/response scan, but delivery remains dependent on the publisher, network and subscriber.
- Configure the required application/transfer-time performance from IEC 61850-5 and the scheme study.
- Measure publisher-to-subscriber and source-to-output performance; packet transit alone excludes logic/output time.
- Engineer multicast so required ports receive traffic without uncontrolled flooding.
- Use VLAN priority/QoS consistently; incorrect priority or queue configuration can be worse than none.
- Set subscriber timeout/loss behavior: alarm, block, fallback or trip only when the function analysis justifies it.
- Handle reboot and state-number initialization without false operation.
5. Performance and latency budget
- For hardwire, replace publisher/network/subscriber transfer with output/interposing/cable/receiving input timing.
- Use worst-case, not average latency, including IED CPU load and network background traffic.
- Include redundant-path duplicate processing and switch queueing.
- Measure jitter and loss under credible sampled-value/engineering traffic.
- Do not count breaker mechanism time inside communication performance if the acceptance criterion separates them.
- Record test method, time reference and instrument accuracy.
6. Dependability and latent failures
| Hardwired latent failure | GOOSE latent/common failure |
|---|---|
| Broken wire/loose terminal | Wrong SCL dataset or subscriber mapping |
| Open fuse/MCB or lost DC | Common switch/PSU/network configuration failure |
| Welded/failed output contact | IED Ethernet port/firmware defect |
| Test link left open | Test/simulation flag mishandled |
| Shared return defeats dual paths | LAN A/B share route, switch or engineering file |
| Insufficient coil voltage | Network path healthy but final coil path failed |
GOOSE subscription supervision can reveal loss quickly; it cannot prove the final relay output or coil operates. Hardwired TCS can supervise the coil path; it may not supervise the initiating intertrip contact/cable. Combine online diagnostics with periodic functional tests.
7. Security against unwanted trips
- Use explicit publisher identity/dataset/configuration and subscriber logic.
- Validate data quality, test and simulation attributes according to the test philosophy.
- Do not convert any GOOSE timeout into a trip by default; choose fail-safe action from system risk.
- Control maintenance mode and test sets so simulated messages cannot reach service subscribers.
- For hardwire, control induced voltage, contact leakage, cross-connection and test jumpers.
- Use two-out-of-two/one-out-of-two logic only where the protection dependability/security study supports it.
- Log configuration, user action, publisher loss and unexpected state changes.
8. PRP and HSR redundancy
IEC 62439-3:2021 defines PRP and HSR. PRP sends duplicate frames over two independent LANs; HSR sends duplicates in opposite directions around a ring. Receivers discard duplicates. Both can provide zero recovery time for a single network-element failure when correctly engineered.
- PRP LAN A and LAN B should not share the same switch, power supply, fibre route or maintenance action where independence is claimed.
- HSR ring failures, node bypass and maintenance states require topology-specific review.
- A doubly attached node can still fail internally; network redundancy is not IED redundancy.
- Redundancy boxes/proxies can become single points for single-attached equipment.
- Monitor each path and duplicate/discard counters; seamless service can hide degraded redundancy.
- Test link/switch/node failures under real GOOSE load and record no output disturbance.
9. Network engineering controls
- traffic-flow matrix for GOOSE, MMS, SV, PTP and engineering traffic;
- bandwidth/queue calculation for normal, burst and failure states;
- managed-switch port, VLAN, priority and multicast configuration;
- storm control/filtering proven not to discard required protection traffic;
- physical topology, fibre type, SFP, port speed and power redundancy;
- separate protection/security management planes as designed;
- network monitoring without mirror-port overload or unauthorized access;
- configuration backups, firmware compatibility, time and event logs;
- future traffic margin with explicit acceptance threshold.
10. SCL and configuration governance
- Maintain authoritative system specification/configuration files and IED capability/configuration sources.
- Control IED name, logical device/node, dataset, GOOSE control block, destination addressing and subscriber mapping.
- Check dataset order/type changes; a semantic name can remain while bit position changes.
- Version SCL, IED settings, switch configurations and drawings as one release.
- Use automated consistency checks plus independent functional review.
- Record engineering tool/IED firmware versions and checksums.
- Prevent unauthorized online edits and retain rollback files.
- Regression-test every affected publisher and subscriber after a change.
11. Cybersecurity
IEC 62351 addresses security for power-system communications, including IEC 61850 profiles. Apply the owner’s risk-based security architecture to engineering access, network devices, credentials/keys where used, logs, remote maintenance and incident recovery.
- least-privilege roles and controlled engineering workstations;
- authenticated configuration transfer and approved files/checksums;
- physical/port security and disabled unused services/ports;
- network segmentation without breaking required multicast/redundancy;
- monitoring for configuration change, unexpected publisher and traffic anomaly;
- backup/restore and replacement-switch/IED procedures;
- security mechanism latency/load validated for the protection function;
- test-mode controls and removable-media governance.
12. Maintainability and human factors
| Hardwired maintenance | GOOSE maintenance |
|---|---|
| Physical continuity, terminal and contact inspection | Publisher/subscriber/SCL and network-path verification |
| Visible test links but risk of left-open path | Logical test/simulation but risk of hidden active test state |
| Drawing-heavy changes and more copper | Fewer wires but configuration/tool competence required |
| Point-to-point fault isolation | Network diagnostics can show broad health but needs specialist tools |
| Modification local to one circuit | One dataset/config change can affect many subscribers |
Provide technician-readable signal lists, network diagrams, subscription matrices, normal test states and recovery playbooks—not SCL files alone.
13. Where hybrid architecture is strong
- IED directly hardwires its local trip coil; GOOSE distributes breaker-failure/backtrip to adjacent bays.
- Main 1 and Main 2 use segregated GOOSE networks and separate final hardwired outputs/coils.
- GOOSE provides interlocking/permissive with a conservative fallback; safety-critical mechanical interlocks remain physical.
- Critical intertrip has both independently initiated hardwired and GOOSE paths when risk justifies, with security against common false trip.
- GOOSE transfers rich status/diagnostics while a simple hardwired watchdog/fallback preserves minimum function.
Hybrid does not automatically mean redundant. Trace DC supplies, IED CPUs, input measurements, final coils, network and engineering process to find what remains common.
14. Application decision matrix
| Criterion | Hardwire tends to favour | GOOSE tends to favour |
|---|---|---|
| One local output | Simple direct path | Limited benefit unless digital architecture exists |
| Many destinations/logic signals | Copper/contact complexity | Efficient multicast and semantics |
| Online path supervision | Needs added circuits/tests | Native communication supervision |
| Change isolation | Local physical modification | Powerful but broad configuration impact |
| EMC/long cross-panel route | Copper mitigation needed | Fibre network attractive |
| Skills/tool maturity | Traditional test competence | Requires SCL/network/cyber competence |
| Redundancy | Separate cables/contacts/DC | PRP/HSR plus separate IED/output/DC |
15. FAT/SAT test matrix
- Source protection element to receiving IED/output and actual breaker trip.
- Measured total transfer time/jitter under normal and worst credible network/IED load.
- Correct dataset values, quality, test/simulation and subscriber logic.
- Publisher reboot, subscriber reboot, link/switch/power failure and restoration.
- PRP LAN A/B or HSR path failure with no trip disturbance; alarm degraded redundancy.
- Unexpected/duplicate/stale/timeout behavior and no false trip.
- VLAN/QoS/multicast and storm-control operation under background/burst traffic.
- Final output DC contact duty, coil voltage and trip-circuit supervision.
- Main 1/Main 2 common-cause/segregation and simultaneous operation.
- Engineering/test access, configuration backup/checksum and unauthorized change alarm.
- Hardwired fallback/interlock and maintenance-mode restoration.
- End-to-end SOE/oscillography/network capture correlated to one time source.
Common mistakes
- Calling GOOSE inherently less reliable or inherently superior.
- Comparing a copper wire with a network while ignoring outputs, supplies and coils.
- Using average packet latency instead of worst source-to-output time.
- Putting redundant GOOSE paths through one switch/PSU/duct.
- Assuming subscription supervision proves the trip coil.
- Flooding multicast because switch filters were never engineered.
- Changing a dataset without regression-testing every subscriber.
- Accepting test/simulation messages in service logic.
- Adding security appliances without validating delay/failure mode.
- Testing packets but never tripping the breaker end-to-end.
Official standards and primary references
- IEC 61850-8-1:2011+AMD1:2020 consolidated edition — current GOOSE/MMS mapping.
- IEC 61850-5:2013+AMD1:2022 — current communication performance and function requirements.
- IEC 61850-6:2009+AMD1:2018+AMD2:2024 — current SCL configuration description requirements.
- IEC 61850-10:2012+AMD1:2025 — current conformance-testing requirements.
- IEC TR 61850-90-4:2020 — current network engineering guidance for GOOSE, sampled values, redundancy and time.
- IEC 62439-3:2021 (including 2023 corrigendum) — current PRP/HSR seamless redundancy requirements.
- IEC 62351-6:2020 — security requirements relevant to IEC 61850 communication profiles.
- IEC 62271-1:2017+AMD1:2021 — current switchgear auxiliary/control and trip-circuit context.
Engineering note: Choose hardwire, GOOSE or hybrid only after drawing both complete source-to-coil chains and testing their single failures. The medium is not the protection function; the engineered system is.