Time synchronisation is a protection/control input with a measurable accuracy, availability and failure state—not an Ethernet accessory marked “NTP available.” The required architecture depends on whether time supports human logs, millisecond SOE, disturbance-record correlation, travelling-wave/location functions, synchrophasors or sampled-value protection.
This guide explains how to document GNSS clocks, PTP, IRIG-B, NTP/SNTP, PRP/HSR station networks, IED ports, quality and holdover in MV switchgear secondary schematics, then verify the complete time path under failure.
Executive rules
- Allocate a required accuracy/availability class to each application before selecting a time protocol.
- Use IEC/IEEE 61850-9-3 PTP only with a compatible profile, network design and clock support; generic “IEEE 1588 capable” is insufficient.
- Draw the complete path from reference/GNSS antenna through grandmaster, network clocks or distribution, cable/port and IED client.
- Redundant clocks are not independent if they share one antenna, receiver, DC feed, network or configuration.
- Propagate time quality/uncertainty and alarm loss/degradation; never keep marking stale time as synchronised.
- Define holdover accuracy versus duration and oscillator/environment—not only “holdover supported.”
- Keep PTP, NTP, IRIG and local time-zone/display rules consistent; avoid double offset or leap handling errors.
- Test failover, GNSS loss, network asymmetry/load, reboot and long holdover end-to-end.
1. Standards and profiles
| Reference | Application |
|---|---|
| IEC/IEEE 61850-9-3:2016 | PTP profile for power utility automation supporting highest IEC 61850-5/IEC 61869-9 synchronisation classes |
| IEC 61850-5:2013+AMD1:2022 | Communication requirements for automation functions/device models, including performance context |
| IEC 62439-3:2021 (with 2023 corrigendum) | PRP and HSR seamless redundancy protocols |
| IEC 61850-6:2009+A1:2018+A2:2024 | Configuration exchange and system relationships |
| IEC 61850-3:2013 | Environmental/general requirements for utility communication/automation IEDs |
| IEC TS 60255-216-1:2025 | General requirements/tests for protection functions using digital SV/GOOSE/time inputs |
| Equipment/project profiles | Exact PTP mechanism, accuracy, holdover, IRIG format, NTP behaviour and diagnostics |
Freeze exact editions and profile options. PTP devices using different profiles, delay mechanisms, domains or transport assumptions can all be “PTP compliant” yet fail to interoperate.
2. Build an application accuracy matrix
| Application | Engineering question |
|---|---|
| HMI/alarm logs | What correlation and operator resolution is required? |
| SOE | Can the required source timestamp ordering distinguish breaker/protection sequence? |
| Disturbance records | Must files from multiple IEDs align waveform phase/events? |
| GOOSE/control | Is absolute time functional or only for diagnostics? What happens if lost? |
| Sampled values | What synchronisation class is required by MU/protection/application? |
| Synchrophasor/travelling-wave | What phase/location error results from time error and holdover? |
| Billing/energy | What interval, time-zone and legal clock requirements apply? |
State accuracy at the IED application timestamp/sample—not merely at the grandmaster output. Include distribution error, path asymmetry, client accuracy and uncertainty. A protection function that does not require absolute time must continue safely on time loss while flagging records appropriately.
3. Protocol selection
| Method | Strength | Limit/typical use |
|---|---|---|
| PTP IEC/IEEE 61850-9-3 | High-accuracy packet time on engineered Ethernet | Profile/network clock/client interoperability essential |
| IRIG-B | Dedicated distribution, simple path visibility | Exact modulated/unmodulated format, year/quality extensions, delay and fan-out must match |
| 1 PPS + serial time | Precise edge plus date/time information | Two signals/latency association and cable delay |
| NTP/SNTP | Widely supported for servers/HMIs/IED logs | Generally not suitable for the highest-accuracy protection/process-bus applications |
| Local/free-running | No network dependency | Drift; only for noncorrelated use or controlled holdover |
4. Reference and grandmaster architecture
- GNSS constellation(s), antenna type/location, sky view and surge/lightning protection.
- Antenna cable type/length/loss/delay, connector, grounding and fire penetration.
- Primary/secondary grandmaster and Best Master Clock/selection policy.
- Independent DC feeds, clock hardware/firmware and antenna/reference failure domains.
- Local oscillator and specified holdover versus temperature/age/time.
- External UTC/reference, leap second and time-zone/display policy.
- Alarm contacts/SNMP/IEC 61850 status for reference, antenna, PTP, oscillator and output health.
- Secure management, configuration backup and access control.
Two grandmasters fed from a common splitter/antenna are redundant against one clock failure but not antenna cable damage, jamming or bad reference. Document the intended failure coverage.
5. PTP network design
- Profile, domain, message rates, transport and peer-to-peer/end-to-end delay mechanism.
- Grandmaster, boundary-clock, transparent-clock and ordinary-clock roles.
- One-step/two-step support and correction-field handling.
- Switch residence-time/asymmetry specifications and fibre/copper path delay.
- VLAN/priority/QoS and interaction with GOOSE/SV/MMS traffic.
- Maximum hops/topology and network load/failure cases.
- PRP LAN A/B or HSR duplicate paths and PTP behaviour on both.
- Boundary between PTP-aware and non-aware switches; do not assume generic Ethernet switches preserve accuracy.
- Management/statistics for offset, path delay, clock class, grandmaster ID and port state.
6. PRP/HSR interaction
IEC 62439-3 PRP sends duplicate frames over two independent LANs; HSR sends duplicates around a ring/mesh path to achieve zero recovery time for a single element failure. This does not automatically make time sources or PTP correction independent.
- Define whether grandmasters/clients are doubly attached or connected through RedBox functions.
- Maintain LAN A/B physical, power and configuration separation.
- Check duplicate-discard and path-delay/asymmetry behaviour for PTP profile implementation.
- Monitor wrong-lane, duplicate, sequence and lost-redundancy counters.
- Test each LAN/ring direction independently and under simultaneous high traffic.
- A seamless packet path can still deliver wrong time if the selected grandmaster/reference is wrong.
7. IRIG-B and hardwired time diagrams
- Exact IRIG code/encoding: modulated versus unmodulated/DC level and supported extensions.
- Output type/level, impedance, fan-out, isolation and maximum cable/load.
- Dedicated distribution amplifier channel and its power/failure alarm.
- Cable type, length, shield/earth, delay and termination.
- Input connector/polarity and IED configuration.
- Date/year/time-quality handling; not all legacy IRIG inputs carry identical information.
- Channel-to-IED allocation and redundant-source changeover.
- Test port and safe injection without disturbing other clients.
8. NTP/SNTP distribution
- Use redundant servers/reference addresses and defined polling/selection.
- Set UTC internally; apply local time and daylight rules only at presentation layer unless a contractual requirement states otherwise.
- Define maximum offset/age before quality becomes invalid and an alarm operates.
- Separate management/SCADA server synchronisation from process-bus/PTP requirements.
- Control routes, authentication/security capability and external upstream access.
- Test server switch, packet delay/loss and client clock step/slew behaviour.
- Prevent a large corrective step from reordering SOE or invalidating historian intervals without flagging it.
9. Time quality and holdover
| State | Required behaviour |
|---|---|
| Locked/synchronised | Meet declared accuracy and report selected reference |
| Reference degraded | Alarm; propagate quality/accuracy class before limit is exceeded |
| Holdover | Run from oscillator with elapsed-time/uncertainty tracked |
| Out of specification | Mark time invalid/unsynchronised; affected functions apply defined fallback |
| Recovering | Controlled step/slew and event-quality handling; avoid false “healthy” before stability |
Specify holdover error as a curve or maximum versus duration and environment. “24-hour holdover” without accuracy is meaningless. Define which protection functions block, degrade or continue; most conventional local overcurrent functions should not be disabled merely because absolute time is lost.
10. Illustrative end-to-end accuracy budget
Do not allocate the entire application tolerance to the grandmaster. Build a worst-case budget at the IED output:
- reference/GNSS receiver uncertainty and antenna/cable compensation error;
- grandmaster timestamp/output error;
- boundary/transparent-clock residual and switch residence-time error;
- link asymmetry, SFP/fibre/copper path and patching difference;
- client clock recovery/servo and oscillator error;
- application timestamp/sampling alignment and quantisation;
- measurement/test-instrument uncertainty and acceptance margin.
For an illustrative application limit of ±X, allocate individual worst-case limits so their justified combination plus test uncertainty remains below X with margin; do not insert arbitrary numerical values. Evaluate normal topology, each redundant path, maximum approved network load, temperature range and the defined holdover duration. Record whether errors are bounded, statistically independent or correlated—a simple root-sum-square can be unsafe for common systematic offsets.
11. Failure-response matrix
| Failure | Expected state | Operational decision |
|---|---|---|
| One GNSS/grandmaster lost | Transfer to qualified alternate; alarm redundancy loss | Continue if end-to-end accuracy remains valid |
| Both external references lost | Enter tracked holdover | Continue only functions whose requirement remains met |
| PTP path asymmetry/offset exceeds limit | Degraded/invalid quality, actionable alarm | Block or degrade only affected time-dependent functions |
| Wrong/rogue grandmaster selected | Identity/change/anomaly alarm | Isolate/revert according to cyber and operating procedure |
| LAN A or B lost | Redundancy alarm; no application time step | Repair while remaining path monitored |
| IED time client fails | IED records marked unsynchronised | Local non-time-dependent protection remains available |
12. What station-network schematics must show
- IED/switch/clock device tags, port numbers and media/connector/fibre type;
- LAN/VLAN/PRP/HSR domains, switch roles and redundant power sources;
- PTP clock roles/domains/profile and time client method per port;
- GOOSE/SV/MMS/SCADA/engineering/time flows and publishers/subscribers where relevant;
- IP/MAC/logical addressing references without exposing sensitive credentials;
- patch panel/ODF, fibre pairs, cable IDs, route and spare ports/cores;
- network-management/security zones, firewalls/gateways and external links;
- test taps/ports, configuration files and ownership boundaries;
- time-quality/clock/network alarms to HMI/SCADA.
13. Cyber and reference threats
- GNSS jamming, spoofing, antenna damage and common reference errors.
- Rogue/bad-priority grandmaster and unauthorised PTP announce/configuration changes.
- Network delay/asymmetry or congestion manipulation.
- Unauthorised NTP source/DNS/routing change.
- Clock management credentials, firmware and configuration compromise.
- Physical patching of time/network ports.
- Monitoring for grandmaster identity change, offset jump, satellite/reference anomaly and multi-source disagreement.
- Independent sanity check/holdover and response procedures proportionate to consequence.
14. FAT/SAT and periodic test
- Static-verify profile/domain/clock role, network topology, cabling and client configuration.
- Measure IED timestamp/sample offset with traceable equipment at normal traffic and temperature.
- Verify SOE/disturbance-record alignment using simultaneous injected events/waveforms.
- Remove GNSS/reference, antenna, each grandmaster/DC feed and distribution channel.
- Fail PRP LAN A/B or each HSR direction/switch/port; observe PTP offset and alarms.
- Apply high traffic, link asymmetry and switch reboot/failover within approved safe test setup.
- Measure holdover drift versus time and recovery/step-slew behaviour.
- Change/wrong-profile/domain/rogue-clock scenarios in an isolated test network.
- Verify invalid/degraded quality reaches IED, HMI, SCADA and records without disabling unaffected protection.
- Archive topology/configuration/firmware, clock statistics, instrument traceability and baseline.
15. Frequent mistakes
| Mistake | Consequence | Correction |
|---|---|---|
| “PTP capable” specified | Profile/role mismatch | Specify 61850-9-3 options and topology |
| Clock output accuracy only | IED timestamp error unknown | End-to-end accuracy budget/test |
| Dual clocks share antenna/DC | Hidden common failure | State and engineer independence coverage |
| Time loss blocks all protection | Unnecessary loss of fault clearing | Function-specific fallback |
| Holdover duration without error | Unknown record/protection accuracy | Accuracy-versus-time requirement |
| NTP used for sampled values | Insufficient/unstated accuracy | Application-specific time method |
| Only healthy-network test | Failover/asymmetry defects latent | Failure/load/holdover tests |
16. Design-release checklist
- Accuracy/availability/holdover assigned per application?
- Exact PTP/IRIG/NTP profiles/formats frozen?
- Reference/antenna/DC/network common modes analysed?
- PTP roles, domains, delay mechanism and hops approved?
- PRP/HSR time behaviour and LAN independence proven?
- Time quality/uncertainty/fallback propagated?
- UTC/time-zone/leap policy consistent?
- Cyber/reference anomaly monitoring defined?
- Physical/logical schematics include ports, media, flows and alarms?
- End-to-end offset/SOE/SV tests specified?
- Failure/holdover/recovery tests included?
- Configuration and clock-performance baseline controlled?
References and further reading
- IEC/IEEE 61850-9-3:2016 — Power-utility PTP profile
- IEC 61850-5:2013+AMD1:2022 — Communication requirements
- IEC 62439-3:2021 — PRP and HSR
- IEC 61850-6:2009+A1:2018+A2:2024 — SCL configuration language
- IEC 61850-3:2013 — General requirements for utility IEDs
- IEC TS 60255-216-1:2025 — Digital-interface protection functions
Engineering note: Do not adopt illustrative time accuracies. Derive them from the selected application, standards class and verified IED/network/clock performance.