Hardwired Trips Versus IEC 61850 GOOSE in MV Switchgear

A risk-based comparison of hardwired, GOOSE and hybrid MV trip paths covering performance, failure modes, redundancy, configuration and testing.

Hardwired and IEC 61850 GOOSE trips are different implementations of the same protection function—not opposing ideologies. A copper contact path can fail silently at a fuse, terminal or coil. A GOOSE path can be fast and continuously supervised yet share switches, time/configuration tools or subscriber logic. The correct choice follows a quantified dependability, security, performance, maintenance and cybersecurity study.

This guide compares source-to-coil hardwired trips with GOOSE-based inter-IED trips in MV switchgear. It covers latency, retransmission, supervision, PRP/HSR, VLAN/QoS, common-cause failure, SCL, network load, cybersecurity, testing, hybrid schemes and a decision matrix. It does not assume that the breaker trip coil is digital: in most MV installations, even a GOOSE scheme ends in a physical IED output, DC circuit and shunt-trip coil.

Executive conclusions

  • Define the required protection transfer time, dependability, security, independence, diagnostics and maintenance behavior before selecting the medium.
  • A hardwired intertrip path contains DC source, branch protection, output contacts, cable, test links, terminals and receiving trip logic/coil; review the complete loop.
  • A GOOSE path contains publisher logic, Ethernet interface, network links/switches/redundancy, subscriber configuration/quality logic and final output/coil; review the complete chain.
  • GOOSE uses event-driven multicast with rapid retransmission; performance depends on end devices, network design, load and configuration—not the protocol name alone.
  • PRP/HSR can provide seamless recovery from one network element failure, but only when LAN A/B or ring paths, power supplies and devices avoid common failure.
  • GOOSE offers strong online supervision and reduces copper, but configuration errors can affect many bays simultaneously.
  • Hardwired trips are visually traceable and independent of Ethernet, but they can have latent open circuits and scale poorly for many destinations.
  • Cybersecurity controls must protect engineering access, SCL/configuration and network devices without adding unvalidated latency or single points to time-critical protection.
  • Hybrid architecture is often strongest: local breaker trip remains direct hardwired while inter-bay permissives, blocking or backup trips use engineered GOOSE with appropriate fallback.
  • Test every required path, failover, publisher/subscriber loss, quality/test state and final breaker operation end-to-end; a successful GOOSE packet capture alone is not a trip test.

1. Compare functions, not just wires and packets

RequirementQuestion
PerformanceMaximum transfer time and jitter from source element to receiving output?
DependabilityProbability of operating when required; which failures are detectable?
SecurityProbability of no unwanted trip; how are false/stale/test messages handled?
AvailabilityWhat remains after one device, supply, cable, switch or configuration failure?
IndependenceDo Main 1/Main 2 truly avoid common hardware, network and engineering failures?
MaintainabilityCan one bay/path be tested without risking adjacent service equipment?
LifecycleHow are drawings/SCL, firmware, switches, tools, spares and competence managed?
CybersecurityHow are access, integrity, event logging and recovery controlled?

2. Complete hardwired trip chain

Protection element → physical output → optional master/interposing relay → DC cable/test links/terminals → receiving logic or trip coil → breaker mechanism
  • DC source/end-of-discharge voltage and branch protection;
  • output contact making/carrying/DC inductive breaking duty;
  • wire loop resistance and coil-terminal voltage;
  • test-link/terminal normal position and trip-circuit supervision;
  • dual coils/paths and shared returns;
  • interposing relay pickup/release time and failure;
  • cable route, fire/EMC and cross-panel interface;
  • 52a/52b cut-off and coil pulse duty.

A hardwired path can be very deterministic but not automatically supervised end-to-end. TCS often supervises the final coil circuit, while an upstream intertrip cable contact may need separate supervision or periodic proof testing.

3. Complete GOOSE trip chain

Protection element → publisher dataset/GOOSE control block → IED Ethernet port → LAN path(s) → subscriber → quality/logic → physical output/DC trip coil → breaker mechanism
  • correct logical node/data object and dataset bit order/type;
  • APPID, MAC, VLAN and priority engineering;
  • publisher state/sequence, retransmission and supervision;
  • subscriber acceptance of quality, test and simulation states;
  • network path, switch configuration, multicast handling and load;
  • PRP/HSR duplicate handling where used;
  • IED CPU/logic execution and output operate time;
  • final hardwired output, DC branch and breaker coil;
  • SCL/firmware/network configuration governance.

4. GOOSE behavior in practical terms

GOOSE maps IEC 61850 data to Layer-2 Ethernet multicast under IEC 61850-8-1. A state change is transmitted rapidly and then retransmitted at increasing intervals; steady-state repetitions allow subscribers to detect loss. This architecture avoids waiting for a request/response scan, but delivery remains dependent on the publisher, network and subscriber.

  • Configure the required application/transfer-time performance from IEC 61850-5 and the scheme study.
  • Measure publisher-to-subscriber and source-to-output performance; packet transit alone excludes logic/output time.
  • Engineer multicast so required ports receive traffic without uncontrolled flooding.
  • Use VLAN priority/QoS consistently; incorrect priority or queue configuration can be worse than none.
  • Set subscriber timeout/loss behavior: alarm, block, fallback or trip only when the function analysis justifies it.
  • Handle reboot and state-number initialization without false operation.

5. Performance and latency budget

Ttotal = Tsource logic + Tpublisher + Tnetwork + Tsubscriber logic + Toutput + Tcoil/mechanism
  • For hardwire, replace publisher/network/subscriber transfer with output/interposing/cable/receiving input timing.
  • Use worst-case, not average latency, including IED CPU load and network background traffic.
  • Include redundant-path duplicate processing and switch queueing.
  • Measure jitter and loss under credible sampled-value/engineering traffic.
  • Do not count breaker mechanism time inside communication performance if the acceptance criterion separates them.
  • Record test method, time reference and instrument accuracy.

6. Dependability and latent failures

Hardwired latent failureGOOSE latent/common failure
Broken wire/loose terminalWrong SCL dataset or subscriber mapping
Open fuse/MCB or lost DCCommon switch/PSU/network configuration failure
Welded/failed output contactIED Ethernet port/firmware defect
Test link left openTest/simulation flag mishandled
Shared return defeats dual pathsLAN A/B share route, switch or engineering file
Insufficient coil voltageNetwork path healthy but final coil path failed

GOOSE subscription supervision can reveal loss quickly; it cannot prove the final relay output or coil operates. Hardwired TCS can supervise the coil path; it may not supervise the initiating intertrip contact/cable. Combine online diagnostics with periodic functional tests.

7. Security against unwanted trips

  • Use explicit publisher identity/dataset/configuration and subscriber logic.
  • Validate data quality, test and simulation attributes according to the test philosophy.
  • Do not convert any GOOSE timeout into a trip by default; choose fail-safe action from system risk.
  • Control maintenance mode and test sets so simulated messages cannot reach service subscribers.
  • For hardwire, control induced voltage, contact leakage, cross-connection and test jumpers.
  • Use two-out-of-two/one-out-of-two logic only where the protection dependability/security study supports it.
  • Log configuration, user action, publisher loss and unexpected state changes.

8. PRP and HSR redundancy

IEC 62439-3:2021 defines PRP and HSR. PRP sends duplicate frames over two independent LANs; HSR sends duplicates in opposite directions around a ring. Receivers discard duplicates. Both can provide zero recovery time for a single network-element failure when correctly engineered.

  • PRP LAN A and LAN B should not share the same switch, power supply, fibre route or maintenance action where independence is claimed.
  • HSR ring failures, node bypass and maintenance states require topology-specific review.
  • A doubly attached node can still fail internally; network redundancy is not IED redundancy.
  • Redundancy boxes/proxies can become single points for single-attached equipment.
  • Monitor each path and duplicate/discard counters; seamless service can hide degraded redundancy.
  • Test link/switch/node failures under real GOOSE load and record no output disturbance.

9. Network engineering controls

  • traffic-flow matrix for GOOSE, MMS, SV, PTP and engineering traffic;
  • bandwidth/queue calculation for normal, burst and failure states;
  • managed-switch port, VLAN, priority and multicast configuration;
  • storm control/filtering proven not to discard required protection traffic;
  • physical topology, fibre type, SFP, port speed and power redundancy;
  • separate protection/security management planes as designed;
  • network monitoring without mirror-port overload or unauthorized access;
  • configuration backups, firmware compatibility, time and event logs;
  • future traffic margin with explicit acceptance threshold.

10. SCL and configuration governance

  • Maintain authoritative system specification/configuration files and IED capability/configuration sources.
  • Control IED name, logical device/node, dataset, GOOSE control block, destination addressing and subscriber mapping.
  • Check dataset order/type changes; a semantic name can remain while bit position changes.
  • Version SCL, IED settings, switch configurations and drawings as one release.
  • Use automated consistency checks plus independent functional review.
  • Record engineering tool/IED firmware versions and checksums.
  • Prevent unauthorized online edits and retain rollback files.
  • Regression-test every affected publisher and subscriber after a change.

11. Cybersecurity

IEC 62351 addresses security for power-system communications, including IEC 61850 profiles. Apply the owner’s risk-based security architecture to engineering access, network devices, credentials/keys where used, logs, remote maintenance and incident recovery.

  • least-privilege roles and controlled engineering workstations;
  • authenticated configuration transfer and approved files/checksums;
  • physical/port security and disabled unused services/ports;
  • network segmentation without breaking required multicast/redundancy;
  • monitoring for configuration change, unexpected publisher and traffic anomaly;
  • backup/restore and replacement-switch/IED procedures;
  • security mechanism latency/load validated for the protection function;
  • test-mode controls and removable-media governance.

12. Maintainability and human factors

Hardwired maintenanceGOOSE maintenance
Physical continuity, terminal and contact inspectionPublisher/subscriber/SCL and network-path verification
Visible test links but risk of left-open pathLogical test/simulation but risk of hidden active test state
Drawing-heavy changes and more copperFewer wires but configuration/tool competence required
Point-to-point fault isolationNetwork diagnostics can show broad health but needs specialist tools
Modification local to one circuitOne dataset/config change can affect many subscribers

Provide technician-readable signal lists, network diagrams, subscription matrices, normal test states and recovery playbooks—not SCL files alone.

13. Where hybrid architecture is strong

  • IED directly hardwires its local trip coil; GOOSE distributes breaker-failure/backtrip to adjacent bays.
  • Main 1 and Main 2 use segregated GOOSE networks and separate final hardwired outputs/coils.
  • GOOSE provides interlocking/permissive with a conservative fallback; safety-critical mechanical interlocks remain physical.
  • Critical intertrip has both independently initiated hardwired and GOOSE paths when risk justifies, with security against common false trip.
  • GOOSE transfers rich status/diagnostics while a simple hardwired watchdog/fallback preserves minimum function.

Hybrid does not automatically mean redundant. Trace DC supplies, IED CPUs, input measurements, final coils, network and engineering process to find what remains common.

14. Application decision matrix

CriterionHardwire tends to favourGOOSE tends to favour
One local outputSimple direct pathLimited benefit unless digital architecture exists
Many destinations/logic signalsCopper/contact complexityEfficient multicast and semantics
Online path supervisionNeeds added circuits/testsNative communication supervision
Change isolationLocal physical modificationPowerful but broad configuration impact
EMC/long cross-panel routeCopper mitigation neededFibre network attractive
Skills/tool maturityTraditional test competenceRequires SCL/network/cyber competence
RedundancySeparate cables/contacts/DCPRP/HSR plus separate IED/output/DC

15. FAT/SAT test matrix

  • Source protection element to receiving IED/output and actual breaker trip.
  • Measured total transfer time/jitter under normal and worst credible network/IED load.
  • Correct dataset values, quality, test/simulation and subscriber logic.
  • Publisher reboot, subscriber reboot, link/switch/power failure and restoration.
  • PRP LAN A/B or HSR path failure with no trip disturbance; alarm degraded redundancy.
  • Unexpected/duplicate/stale/timeout behavior and no false trip.
  • VLAN/QoS/multicast and storm-control operation under background/burst traffic.
  • Final output DC contact duty, coil voltage and trip-circuit supervision.
  • Main 1/Main 2 common-cause/segregation and simultaneous operation.
  • Engineering/test access, configuration backup/checksum and unauthorized change alarm.
  • Hardwired fallback/interlock and maintenance-mode restoration.
  • End-to-end SOE/oscillography/network capture correlated to one time source.

Common mistakes

  • Calling GOOSE inherently less reliable or inherently superior.
  • Comparing a copper wire with a network while ignoring outputs, supplies and coils.
  • Using average packet latency instead of worst source-to-output time.
  • Putting redundant GOOSE paths through one switch/PSU/duct.
  • Assuming subscription supervision proves the trip coil.
  • Flooding multicast because switch filters were never engineered.
  • Changing a dataset without regression-testing every subscriber.
  • Accepting test/simulation messages in service logic.
  • Adding security appliances without validating delay/failure mode.
  • Testing packets but never tripping the breaker end-to-end.

Official standards and primary references

Engineering note: Choose hardwire, GOOSE or hybrid only after drawing both complete source-to-coil chains and testing their single failures. The medium is not the protection function; the engineered system is.

LearnSwitchgear

Search the engineering library