GOOSE Supervision, Test Modes and Fail-Safe Design for Critical Interlocking

A signal-level guide to GOOSE liveness, quality, simulation, unknown-state logic, safe fallback, overrides and negative testing for MV interlocks.

A critical interlock must not treat a received Boolean as permanently true merely because the last GOOSE frame said so. It must know that the publisher is alive, the dataset/configuration is correct, the value has valid quality, the message is not simulated or in an unauthorized test state, and the process combination is physically plausible. When any of those conditions fail, the interlock must enter a deliberately engineered safe state.

This article develops GOOSE supervision, test/simulation handling and fail-safe logic for MV breaker, disconnector, earthing-switch, bus-coupler and transfer interlocking, with SCL controls, diagnostics and full FAT/SAT cases.

1. Interlocking objectives

  • Prevent closing onto an earthed or unsafe circuit.
  • Prevent disconnector operation while carrying prohibited current.
  • Enforce breaker/disconnector/earthing-switch sequence.
  • Prevent paralleling sources without approved synchronism or scheme conditions.
  • Coordinate bus coupler, incomer, transfer and backfeed states.
  • Reject commands when required process position/quality is unavailable.
  • Allow an authorized local/emergency path only under a documented safety procedure.

Mechanical key and switchgear interlocks required for personnel safety remain valuable independent barriers. GOOSE interlocking coordinates distributed states; it should not silently remove local mechanical/electrical safeguards.

2. What must be supervised

LayerSupervision objectFailure consequence
Publisher process input52a/52b, disconnector/earth contacts, voltage/live-dead stateWrong but well-formed GOOSE data
Publisher applicationLogical node/data/quality and dataset updateFrozen or incorrect state
GOOSE protocolstNum, sqNum, timeAllowedToLive, ConfRev, test/simulationStale, lost, mismatched or test data accepted
NetworkBoth paths, ports, queues, multicast/VLANFrame loss/delay or hidden loss of redundancy
Subscriber applicationExtRef mapping, timeout, quality and interlock equationWrong signal or unsafe fallback
Output/controlCommand rejection, close/trip circuit and local bypassUnsafe primary operation

3. stNum, sqNum and timeAllowedToLive

When a published dataset changes, the state number (stNum) changes and frames are retransmitted rapidly; the sequence number (sqNum) advances for transmissions within that state. The publisher advertises timeAllowedToLive, allowing a subscriber to decide when the last received state is no longer live.

  • Timeout must create an explicit communication-invalid condition and alarm.
  • Do not extend validity with an arbitrary long subscriber timer that defeats the publisher’s liveness contract.
  • Handle publisher restart, counter wrap and configuration download without unwanted commands.
  • Sequence gaps are diagnostics, not automatically proof that the application missed the current state; evaluate stNum and final received state.
  • Monitor abnormal update/retransmission rates that could indicate input chatter or a storm.
  • Record last valid receipt, publisher identity, counters and timeout cause for maintenance.

4. ConfRev and dataset integrity

Configuration revision indicates that dataset configuration has changed. A publisher and subscriber that disagree about member order or content can interpret a valid frame incorrectly. Every dataset change requires controlled SCL engineering, ConfRev coordination and regression testing.

  • Trace ExtRef to publisher IED, logical device/node, data object/attribute and dataset member.
  • Validate GoCB name, GoID, dataset, APPID, multicast MAC, VLAN and priority.
  • Use unique project registers; identical bays invite copy/paste mistakes.
  • Block/alarm a revision mismatch according to device capabilities; never silently reinterpret positions.
  • Compare SCL semantically after changes and independently review critical interlocks.
  • Archive exact SCD/CID/settings loaded at FAT and site.

5. Quality must enter the logic

IEC 61850 data includes quality and time information in the model. The interlock should use both value and validity. A closed indication with invalid/questionable quality is not equivalent to a trustworthy closed position.

  • Use complementary contacts and detect impossible 52a/52b combinations with travel allowance.
  • Detect intermediate/stuck positions and contact chatter.
  • Supervise source I/O/module health and process power.
  • Define how oldData, invalid/questionable, test, operator-blocked or substituted states are treated where supported.
  • Separate “unknown” from “open” and “closed” in the internal state model.
  • Show operators the failed prerequisite and source—not a generic “interlock active.”

6. Test and simulation are different controls

IEC 61850 test/simulation mechanisms allow commissioning data to be identified and selectively accepted. Implementation details vary by edition and IED. The project must document how a publisher marks test data, how a subscriber enables simulated messages, which logical-node/device behavior changes, and whether physical outputs remain armed.

StatePurposeRisk if uncontrolled
Test quality/behaviorMark values/functions under testLive subscriber acts on maintenance data
Simulation acceptancePermit test equipment to emulate a publisherImposter stream operates live process
Output block/isolationPrevent physical command while logic is exercisedTrip/close of energized equipment
Subscription blockTemporarily isolate an input pathProtection/interlock remains unknowingly unavailable
  • Entering test mode requires authorization, visible local/remote indication and event logging.
  • Test and live GOOSE must never be accepted simultaneously in an ambiguous way.
  • Output isolation must be physical where safety/consequence requires it.
  • Every test/block state needs an alarm and restoration checklist.
  • Loss of the test set must not leave a simulated permissive latched.
  • Return to service requires independent confirmation of live publishers, valid quality and normal mode.

7. Fail-safe is signal-specific

For most safety interlocks, missing or invalid prerequisite information should inhibit a close/open command and alarm. But “de-energize to trip” or “trip on communication loss” is not a universal rule. Determine the safe state from hazard, protection dependability, plant continuity and backup systems.

GOOSE inputTypical loss responseReason
Earthing switch open permissiveRemove close permissiveUnknown earth position must not permit energization
Remote disconnector positionReject affected controlUnknown topology
Transfer-trip commandDo not fabricate trip from ordinary loss; alarm/use independent backup as designedSecurity versus dependability
Blocking signalUse approved delayed/local backup or secure restraintLoss can cause overtrip
Parallel-source permissiveRemove permissivePrevent unintended paralleling

8. Build a three-state process model

Model each required position as valid open, valid closed or unknown/invalid, with an optional valid intermediate state during travel. Then express the interlock using explicit valid prerequisites. This avoids Boolean logic in which communication failure accidentally becomes “not closed,” which may be interpreted as open.

  • Require `valid AND open` rather than simply `NOT closed`.
  • Use travel timers only for normal mechanism transition; timeout becomes unknown/failure.
  • Include local selector, truck position, spring/pressure and voltage/live-dead status where required.
  • Separate hard safety prerequisites from operational permissives.
  • Document every bypass and who can activate it.
  • Show the evaluated cause-and-effect equation in the approved matrix.

9. Network supervision

  • Supervise subscriber GOOSE status per publisher/control block, not just Ethernet link up.
  • Monitor LAN A/B or HSR ring independently; seamless redundancy can hide a failed side.
  • Collect switch port errors, drops, queue utilization, multicast/filter state and redundancy supervision.
  • Alarm duplicate/unauthorized APPID/MAC or unexpected publisher source.
  • Test timeout across normal, high load, path failure and publisher reboot.
  • Route actionable alarm detail to HMI and maintenance logs.
  • Coordinate alarm flood suppression without hiding multiple failed prerequisites.

10. Local override and emergency operation

A local emergency override may be necessary for restoration, but it is an operational safety system—not a hidden engineering shortcut. It should require controlled access, clear mimic/primary confirmation, documented switching procedure, local responsibility and event logging. Hardware interlocks that protect personnel should not be bypassable by ordinary software control.

  • Separate “local control” from “interlock bypass.”
  • Use key/role authorization and time-limited or maintained indication.
  • Block remote control during local bypass as required.
  • Annunciate at bay and station; include in shift handover.
  • Require restoration and independent verification.
  • Test the override path during commissioning without normalizing its routine use.

11. FAT negative-test matrix

  1. Prove every allowed and prohibited primary switching combination.
  2. Change each source contact, including complementary discrepancy and travel timeout.
  3. Remove each GOOSE publisher and network path; verify timeout and command inhibition.
  4. Restart publisher/subscriber and verify counters/relearning without false command.
  5. Apply wrong ConfRev, APPID, dataset/member order and adjacent-bay stream.
  6. Inject invalid/questionable/old/test quality and simulated messages.
  7. Enable/disable simulation and output isolation in every permitted sequence.
  8. Apply network load, loss, duplicate and delayed frames.
  9. Fail PRP A/B or HSR links and verify latent-path alarms.
  10. Test simultaneous failure of two prerequisites and alarm clarity.
  11. Operate local/remote selector, approved override and restoration.
  12. Capture SCL, packet trace, IED event, command result and physical mechanism response.

12. SAT and lifecycle

  • Verify physical contact wiring and bay/process association by operating real devices.
  • Prove cross-bay signals and labels one at a time.
  • Test the installed network, redundant paths and HMI alarms.
  • Confirm simulated/test traffic cannot affect other live bays.
  • Clear all test/block/override states with two-person or independent check.
  • Baseline timeout, counters and path supervision.
  • After any SCL, relay, switch, firmware or interlock change, perform semantic impact review and regression test.
  • Periodically test timeout, path loss and local override restoration.
  • Reconcile field changes into the master SCD and interlocking matrix.

13. Acceptance checklist

  • Every interlock input has value, quality, liveness and source supervision.
  • Unknown is not treated as open or closed.
  • Timeout and bad-quality response is defined per signal.
  • Test/simulation/output-isolation behavior is documented and visible.
  • SCL subscriptions and ConfRev are independently checked.
  • Network A/B/ring and subscriber status are monitored.
  • All permitted/prohibited/abnormal combinations pass FAT/SAT.
  • Overrides are controlled, logged and restored independently.
  • Mechanical/electrical safety interlocks remain coordinated.
  • As-built evidence supports future regression testing.

References and further reading

Engineering note: Fail-safe design is a property of the complete switching hazard and protection philosophy. It cannot be inferred from whether a GOOSE bit is normally zero or one.

LearnSwitchgear

Search the engineering library