Time-Synchronization and Station-Network Secondary Schematics

A practical IEC/IEEE 61850-9-3 guide from application accuracy budgets and GNSS grandmasters to redundant networks, IED clients and commissioning.

Time synchronisation is a protection/control input with a measurable accuracy, availability and failure state—not an Ethernet accessory marked “NTP available.” The required architecture depends on whether time supports human logs, millisecond SOE, disturbance-record correlation, travelling-wave/location functions, synchrophasors or sampled-value protection.

This guide explains how to document GNSS clocks, PTP, IRIG-B, NTP/SNTP, PRP/HSR station networks, IED ports, quality and holdover in MV switchgear secondary schematics, then verify the complete time path under failure.

Executive rules

  • Allocate a required accuracy/availability class to each application before selecting a time protocol.
  • Use IEC/IEEE 61850-9-3 PTP only with a compatible profile, network design and clock support; generic “IEEE 1588 capable” is insufficient.
  • Draw the complete path from reference/GNSS antenna through grandmaster, network clocks or distribution, cable/port and IED client.
  • Redundant clocks are not independent if they share one antenna, receiver, DC feed, network or configuration.
  • Propagate time quality/uncertainty and alarm loss/degradation; never keep marking stale time as synchronised.
  • Define holdover accuracy versus duration and oscillator/environment—not only “holdover supported.”
  • Keep PTP, NTP, IRIG and local time-zone/display rules consistent; avoid double offset or leap handling errors.
  • Test failover, GNSS loss, network asymmetry/load, reboot and long holdover end-to-end.

1. Standards and profiles

ReferenceApplication
IEC/IEEE 61850-9-3:2016PTP profile for power utility automation supporting highest IEC 61850-5/IEC 61869-9 synchronisation classes
IEC 61850-5:2013+AMD1:2022Communication requirements for automation functions/device models, including performance context
IEC 62439-3:2021 (with 2023 corrigendum)PRP and HSR seamless redundancy protocols
IEC 61850-6:2009+A1:2018+A2:2024Configuration exchange and system relationships
IEC 61850-3:2013Environmental/general requirements for utility communication/automation IEDs
IEC TS 60255-216-1:2025General requirements/tests for protection functions using digital SV/GOOSE/time inputs
Equipment/project profilesExact PTP mechanism, accuracy, holdover, IRIG format, NTP behaviour and diagnostics

Freeze exact editions and profile options. PTP devices using different profiles, delay mechanisms, domains or transport assumptions can all be “PTP compliant” yet fail to interoperate.

2. Build an application accuracy matrix

ApplicationEngineering question
HMI/alarm logsWhat correlation and operator resolution is required?
SOECan the required source timestamp ordering distinguish breaker/protection sequence?
Disturbance recordsMust files from multiple IEDs align waveform phase/events?
GOOSE/controlIs absolute time functional or only for diagnostics? What happens if lost?
Sampled valuesWhat synchronisation class is required by MU/protection/application?
Synchrophasor/travelling-waveWhat phase/location error results from time error and holdover?
Billing/energyWhat interval, time-zone and legal clock requirements apply?

State accuracy at the IED application timestamp/sample—not merely at the grandmaster output. Include distribution error, path asymmetry, client accuracy and uncertainty. A protection function that does not require absolute time must continue safely on time loss while flagging records appropriately.

3. Protocol selection

MethodStrengthLimit/typical use
PTP IEC/IEEE 61850-9-3High-accuracy packet time on engineered EthernetProfile/network clock/client interoperability essential
IRIG-BDedicated distribution, simple path visibilityExact modulated/unmodulated format, year/quality extensions, delay and fan-out must match
1 PPS + serial timePrecise edge plus date/time informationTwo signals/latency association and cable delay
NTP/SNTPWidely supported for servers/HMIs/IED logsGenerally not suitable for the highest-accuracy protection/process-bus applications
Local/free-runningNo network dependencyDrift; only for noncorrelated use or controlled holdover

4. Reference and grandmaster architecture

  • GNSS constellation(s), antenna type/location, sky view and surge/lightning protection.
  • Antenna cable type/length/loss/delay, connector, grounding and fire penetration.
  • Primary/secondary grandmaster and Best Master Clock/selection policy.
  • Independent DC feeds, clock hardware/firmware and antenna/reference failure domains.
  • Local oscillator and specified holdover versus temperature/age/time.
  • External UTC/reference, leap second and time-zone/display policy.
  • Alarm contacts/SNMP/IEC 61850 status for reference, antenna, PTP, oscillator and output health.
  • Secure management, configuration backup and access control.

Two grandmasters fed from a common splitter/antenna are redundant against one clock failure but not antenna cable damage, jamming or bad reference. Document the intended failure coverage.

5. PTP network design

  • Profile, domain, message rates, transport and peer-to-peer/end-to-end delay mechanism.
  • Grandmaster, boundary-clock, transparent-clock and ordinary-clock roles.
  • One-step/two-step support and correction-field handling.
  • Switch residence-time/asymmetry specifications and fibre/copper path delay.
  • VLAN/priority/QoS and interaction with GOOSE/SV/MMS traffic.
  • Maximum hops/topology and network load/failure cases.
  • PRP LAN A/B or HSR duplicate paths and PTP behaviour on both.
  • Boundary between PTP-aware and non-aware switches; do not assume generic Ethernet switches preserve accuracy.
  • Management/statistics for offset, path delay, clock class, grandmaster ID and port state.

6. PRP/HSR interaction

IEC 62439-3 PRP sends duplicate frames over two independent LANs; HSR sends duplicates around a ring/mesh path to achieve zero recovery time for a single element failure. This does not automatically make time sources or PTP correction independent.

  • Define whether grandmasters/clients are doubly attached or connected through RedBox functions.
  • Maintain LAN A/B physical, power and configuration separation.
  • Check duplicate-discard and path-delay/asymmetry behaviour for PTP profile implementation.
  • Monitor wrong-lane, duplicate, sequence and lost-redundancy counters.
  • Test each LAN/ring direction independently and under simultaneous high traffic.
  • A seamless packet path can still deliver wrong time if the selected grandmaster/reference is wrong.

7. IRIG-B and hardwired time diagrams

  • Exact IRIG code/encoding: modulated versus unmodulated/DC level and supported extensions.
  • Output type/level, impedance, fan-out, isolation and maximum cable/load.
  • Dedicated distribution amplifier channel and its power/failure alarm.
  • Cable type, length, shield/earth, delay and termination.
  • Input connector/polarity and IED configuration.
  • Date/year/time-quality handling; not all legacy IRIG inputs carry identical information.
  • Channel-to-IED allocation and redundant-source changeover.
  • Test port and safe injection without disturbing other clients.

8. NTP/SNTP distribution

  • Use redundant servers/reference addresses and defined polling/selection.
  • Set UTC internally; apply local time and daylight rules only at presentation layer unless a contractual requirement states otherwise.
  • Define maximum offset/age before quality becomes invalid and an alarm operates.
  • Separate management/SCADA server synchronisation from process-bus/PTP requirements.
  • Control routes, authentication/security capability and external upstream access.
  • Test server switch, packet delay/loss and client clock step/slew behaviour.
  • Prevent a large corrective step from reordering SOE or invalidating historian intervals without flagging it.

9. Time quality and holdover

StateRequired behaviour
Locked/synchronisedMeet declared accuracy and report selected reference
Reference degradedAlarm; propagate quality/accuracy class before limit is exceeded
HoldoverRun from oscillator with elapsed-time/uncertainty tracked
Out of specificationMark time invalid/unsynchronised; affected functions apply defined fallback
RecoveringControlled step/slew and event-quality handling; avoid false “healthy” before stability

Specify holdover error as a curve or maximum versus duration and environment. “24-hour holdover” without accuracy is meaningless. Define which protection functions block, degrade or continue; most conventional local overcurrent functions should not be disabled merely because absolute time is lost.

10. Illustrative end-to-end accuracy budget

Do not allocate the entire application tolerance to the grandmaster. Build a worst-case budget at the IED output:

  • reference/GNSS receiver uncertainty and antenna/cable compensation error;
  • grandmaster timestamp/output error;
  • boundary/transparent-clock residual and switch residence-time error;
  • link asymmetry, SFP/fibre/copper path and patching difference;
  • client clock recovery/servo and oscillator error;
  • application timestamp/sampling alignment and quantisation;
  • measurement/test-instrument uncertainty and acceptance margin.

For an illustrative application limit of ±X, allocate individual worst-case limits so their justified combination plus test uncertainty remains below X with margin; do not insert arbitrary numerical values. Evaluate normal topology, each redundant path, maximum approved network load, temperature range and the defined holdover duration. Record whether errors are bounded, statistically independent or correlated—a simple root-sum-square can be unsafe for common systematic offsets.

11. Failure-response matrix

FailureExpected stateOperational decision
One GNSS/grandmaster lostTransfer to qualified alternate; alarm redundancy lossContinue if end-to-end accuracy remains valid
Both external references lostEnter tracked holdoverContinue only functions whose requirement remains met
PTP path asymmetry/offset exceeds limitDegraded/invalid quality, actionable alarmBlock or degrade only affected time-dependent functions
Wrong/rogue grandmaster selectedIdentity/change/anomaly alarmIsolate/revert according to cyber and operating procedure
LAN A or B lostRedundancy alarm; no application time stepRepair while remaining path monitored
IED time client failsIED records marked unsynchronisedLocal non-time-dependent protection remains available

12. What station-network schematics must show

  • IED/switch/clock device tags, port numbers and media/connector/fibre type;
  • LAN/VLAN/PRP/HSR domains, switch roles and redundant power sources;
  • PTP clock roles/domains/profile and time client method per port;
  • GOOSE/SV/MMS/SCADA/engineering/time flows and publishers/subscribers where relevant;
  • IP/MAC/logical addressing references without exposing sensitive credentials;
  • patch panel/ODF, fibre pairs, cable IDs, route and spare ports/cores;
  • network-management/security zones, firewalls/gateways and external links;
  • test taps/ports, configuration files and ownership boundaries;
  • time-quality/clock/network alarms to HMI/SCADA.

13. Cyber and reference threats

  • GNSS jamming, spoofing, antenna damage and common reference errors.
  • Rogue/bad-priority grandmaster and unauthorised PTP announce/configuration changes.
  • Network delay/asymmetry or congestion manipulation.
  • Unauthorised NTP source/DNS/routing change.
  • Clock management credentials, firmware and configuration compromise.
  • Physical patching of time/network ports.
  • Monitoring for grandmaster identity change, offset jump, satellite/reference anomaly and multi-source disagreement.
  • Independent sanity check/holdover and response procedures proportionate to consequence.

14. FAT/SAT and periodic test

  1. Static-verify profile/domain/clock role, network topology, cabling and client configuration.
  2. Measure IED timestamp/sample offset with traceable equipment at normal traffic and temperature.
  3. Verify SOE/disturbance-record alignment using simultaneous injected events/waveforms.
  4. Remove GNSS/reference, antenna, each grandmaster/DC feed and distribution channel.
  5. Fail PRP LAN A/B or each HSR direction/switch/port; observe PTP offset and alarms.
  6. Apply high traffic, link asymmetry and switch reboot/failover within approved safe test setup.
  7. Measure holdover drift versus time and recovery/step-slew behaviour.
  8. Change/wrong-profile/domain/rogue-clock scenarios in an isolated test network.
  9. Verify invalid/degraded quality reaches IED, HMI, SCADA and records without disabling unaffected protection.
  10. Archive topology/configuration/firmware, clock statistics, instrument traceability and baseline.

15. Frequent mistakes

MistakeConsequenceCorrection
“PTP capable” specifiedProfile/role mismatchSpecify 61850-9-3 options and topology
Clock output accuracy onlyIED timestamp error unknownEnd-to-end accuracy budget/test
Dual clocks share antenna/DCHidden common failureState and engineer independence coverage
Time loss blocks all protectionUnnecessary loss of fault clearingFunction-specific fallback
Holdover duration without errorUnknown record/protection accuracyAccuracy-versus-time requirement
NTP used for sampled valuesInsufficient/unstated accuracyApplication-specific time method
Only healthy-network testFailover/asymmetry defects latentFailure/load/holdover tests

16. Design-release checklist

  • Accuracy/availability/holdover assigned per application?
  • Exact PTP/IRIG/NTP profiles/formats frozen?
  • Reference/antenna/DC/network common modes analysed?
  • PTP roles, domains, delay mechanism and hops approved?
  • PRP/HSR time behaviour and LAN independence proven?
  • Time quality/uncertainty/fallback propagated?
  • UTC/time-zone/leap policy consistent?
  • Cyber/reference anomaly monitoring defined?
  • Physical/logical schematics include ports, media, flows and alarms?
  • End-to-end offset/SOE/SV tests specified?
  • Failure/holdover/recovery tests included?
  • Configuration and clock-performance baseline controlled?

References and further reading

Engineering note: Do not adopt illustrative time accuracies. Derive them from the selected application, standards class and verified IED/network/clock performance.

LearnSwitchgear

Search the engineering library