A critical interlock must not treat a received Boolean as permanently true merely because the last GOOSE frame said so. It must know that the publisher is alive, the dataset/configuration is correct, the value has valid quality, the message is not simulated or in an unauthorized test state, and the process combination is physically plausible. When any of those conditions fail, the interlock must enter a deliberately engineered safe state.
This article develops GOOSE supervision, test/simulation handling and fail-safe logic for MV breaker, disconnector, earthing-switch, bus-coupler and transfer interlocking, with SCL controls, diagnostics and full FAT/SAT cases.
1. Interlocking objectives
- Prevent closing onto an earthed or unsafe circuit.
- Prevent disconnector operation while carrying prohibited current.
- Enforce breaker/disconnector/earthing-switch sequence.
- Prevent paralleling sources without approved synchronism or scheme conditions.
- Coordinate bus coupler, incomer, transfer and backfeed states.
- Reject commands when required process position/quality is unavailable.
- Allow an authorized local/emergency path only under a documented safety procedure.
Mechanical key and switchgear interlocks required for personnel safety remain valuable independent barriers. GOOSE interlocking coordinates distributed states; it should not silently remove local mechanical/electrical safeguards.
2. What must be supervised
| Layer | Supervision object | Failure consequence |
|---|---|---|
| Publisher process input | 52a/52b, disconnector/earth contacts, voltage/live-dead state | Wrong but well-formed GOOSE data |
| Publisher application | Logical node/data/quality and dataset update | Frozen or incorrect state |
| GOOSE protocol | stNum, sqNum, timeAllowedToLive, ConfRev, test/simulation | Stale, lost, mismatched or test data accepted |
| Network | Both paths, ports, queues, multicast/VLAN | Frame loss/delay or hidden loss of redundancy |
| Subscriber application | ExtRef mapping, timeout, quality and interlock equation | Wrong signal or unsafe fallback |
| Output/control | Command rejection, close/trip circuit and local bypass | Unsafe primary operation |
3. stNum, sqNum and timeAllowedToLive
When a published dataset changes, the state number (stNum) changes and frames are retransmitted rapidly; the sequence number (sqNum) advances for transmissions within that state. The publisher advertises timeAllowedToLive, allowing a subscriber to decide when the last received state is no longer live.
- Timeout must create an explicit communication-invalid condition and alarm.
- Do not extend validity with an arbitrary long subscriber timer that defeats the publisher’s liveness contract.
- Handle publisher restart, counter wrap and configuration download without unwanted commands.
- Sequence gaps are diagnostics, not automatically proof that the application missed the current state; evaluate stNum and final received state.
- Monitor abnormal update/retransmission rates that could indicate input chatter or a storm.
- Record last valid receipt, publisher identity, counters and timeout cause for maintenance.
4. ConfRev and dataset integrity
Configuration revision indicates that dataset configuration has changed. A publisher and subscriber that disagree about member order or content can interpret a valid frame incorrectly. Every dataset change requires controlled SCL engineering, ConfRev coordination and regression testing.
- Trace ExtRef to publisher IED, logical device/node, data object/attribute and dataset member.
- Validate GoCB name, GoID, dataset, APPID, multicast MAC, VLAN and priority.
- Use unique project registers; identical bays invite copy/paste mistakes.
- Block/alarm a revision mismatch according to device capabilities; never silently reinterpret positions.
- Compare SCL semantically after changes and independently review critical interlocks.
- Archive exact SCD/CID/settings loaded at FAT and site.
5. Quality must enter the logic
IEC 61850 data includes quality and time information in the model. The interlock should use both value and validity. A closed indication with invalid/questionable quality is not equivalent to a trustworthy closed position.
- Use complementary contacts and detect impossible 52a/52b combinations with travel allowance.
- Detect intermediate/stuck positions and contact chatter.
- Supervise source I/O/module health and process power.
- Define how oldData, invalid/questionable, test, operator-blocked or substituted states are treated where supported.
- Separate “unknown” from “open” and “closed” in the internal state model.
- Show operators the failed prerequisite and source—not a generic “interlock active.”
6. Test and simulation are different controls
IEC 61850 test/simulation mechanisms allow commissioning data to be identified and selectively accepted. Implementation details vary by edition and IED. The project must document how a publisher marks test data, how a subscriber enables simulated messages, which logical-node/device behavior changes, and whether physical outputs remain armed.
| State | Purpose | Risk if uncontrolled |
|---|---|---|
| Test quality/behavior | Mark values/functions under test | Live subscriber acts on maintenance data |
| Simulation acceptance | Permit test equipment to emulate a publisher | Imposter stream operates live process |
| Output block/isolation | Prevent physical command while logic is exercised | Trip/close of energized equipment |
| Subscription block | Temporarily isolate an input path | Protection/interlock remains unknowingly unavailable |
- Entering test mode requires authorization, visible local/remote indication and event logging.
- Test and live GOOSE must never be accepted simultaneously in an ambiguous way.
- Output isolation must be physical where safety/consequence requires it.
- Every test/block state needs an alarm and restoration checklist.
- Loss of the test set must not leave a simulated permissive latched.
- Return to service requires independent confirmation of live publishers, valid quality and normal mode.
7. Fail-safe is signal-specific
For most safety interlocks, missing or invalid prerequisite information should inhibit a close/open command and alarm. But “de-energize to trip” or “trip on communication loss” is not a universal rule. Determine the safe state from hazard, protection dependability, plant continuity and backup systems.
| GOOSE input | Typical loss response | Reason |
|---|---|---|
| Earthing switch open permissive | Remove close permissive | Unknown earth position must not permit energization |
| Remote disconnector position | Reject affected control | Unknown topology |
| Transfer-trip command | Do not fabricate trip from ordinary loss; alarm/use independent backup as designed | Security versus dependability |
| Blocking signal | Use approved delayed/local backup or secure restraint | Loss can cause overtrip |
| Parallel-source permissive | Remove permissive | Prevent unintended paralleling |
8. Build a three-state process model
Model each required position as valid open, valid closed or unknown/invalid, with an optional valid intermediate state during travel. Then express the interlock using explicit valid prerequisites. This avoids Boolean logic in which communication failure accidentally becomes “not closed,” which may be interpreted as open.
- Require `valid AND open` rather than simply `NOT closed`.
- Use travel timers only for normal mechanism transition; timeout becomes unknown/failure.
- Include local selector, truck position, spring/pressure and voltage/live-dead status where required.
- Separate hard safety prerequisites from operational permissives.
- Document every bypass and who can activate it.
- Show the evaluated cause-and-effect equation in the approved matrix.
9. Network supervision
- Supervise subscriber GOOSE status per publisher/control block, not just Ethernet link up.
- Monitor LAN A/B or HSR ring independently; seamless redundancy can hide a failed side.
- Collect switch port errors, drops, queue utilization, multicast/filter state and redundancy supervision.
- Alarm duplicate/unauthorized APPID/MAC or unexpected publisher source.
- Test timeout across normal, high load, path failure and publisher reboot.
- Route actionable alarm detail to HMI and maintenance logs.
- Coordinate alarm flood suppression without hiding multiple failed prerequisites.
10. Local override and emergency operation
A local emergency override may be necessary for restoration, but it is an operational safety system—not a hidden engineering shortcut. It should require controlled access, clear mimic/primary confirmation, documented switching procedure, local responsibility and event logging. Hardware interlocks that protect personnel should not be bypassable by ordinary software control.
- Separate “local control” from “interlock bypass.”
- Use key/role authorization and time-limited or maintained indication.
- Block remote control during local bypass as required.
- Annunciate at bay and station; include in shift handover.
- Require restoration and independent verification.
- Test the override path during commissioning without normalizing its routine use.
11. FAT negative-test matrix
- Prove every allowed and prohibited primary switching combination.
- Change each source contact, including complementary discrepancy and travel timeout.
- Remove each GOOSE publisher and network path; verify timeout and command inhibition.
- Restart publisher/subscriber and verify counters/relearning without false command.
- Apply wrong ConfRev, APPID, dataset/member order and adjacent-bay stream.
- Inject invalid/questionable/old/test quality and simulated messages.
- Enable/disable simulation and output isolation in every permitted sequence.
- Apply network load, loss, duplicate and delayed frames.
- Fail PRP A/B or HSR links and verify latent-path alarms.
- Test simultaneous failure of two prerequisites and alarm clarity.
- Operate local/remote selector, approved override and restoration.
- Capture SCL, packet trace, IED event, command result and physical mechanism response.
12. SAT and lifecycle
- Verify physical contact wiring and bay/process association by operating real devices.
- Prove cross-bay signals and labels one at a time.
- Test the installed network, redundant paths and HMI alarms.
- Confirm simulated/test traffic cannot affect other live bays.
- Clear all test/block/override states with two-person or independent check.
- Baseline timeout, counters and path supervision.
- After any SCL, relay, switch, firmware or interlock change, perform semantic impact review and regression test.
- Periodically test timeout, path loss and local override restoration.
- Reconcile field changes into the master SCD and interlocking matrix.
13. Acceptance checklist
- Every interlock input has value, quality, liveness and source supervision.
- Unknown is not treated as open or closed.
- Timeout and bad-quality response is defined per signal.
- Test/simulation/output-isolation behavior is documented and visible.
- SCL subscriptions and ConfRev are independently checked.
- Network A/B/ring and subscriber status are monitored.
- All permitted/prohibited/abnormal combinations pass FAT/SAT.
- Overrides are controlled, logged and restored independently.
- Mechanical/electrical safety interlocks remain coordinated.
- As-built evidence supports future regression testing.
References and further reading
- IEC 61850-8-1 consolidated edition — GOOSE mapping
- IEC 61850-7-2 consolidated edition — Abstract communication services
- IEC 61850-7-4 consolidated edition — Logical nodes/data objects
- IEC 61850-6 edition 2.2 — SCL
- IEC TR 61850-10-3:2022 — Functional testing
- IEC TS 60255-216-1:2025 — Protection functions using GOOSE/SV
- IEC 62351-6:2020 — IEC 61850 protocol security
Engineering note: Fail-safe design is a property of the complete switching hazard and protection philosophy. It cannot be inferred from whether a GOOSE bit is normally zero or one.