Engineering a GOOSE Trip and Interlocking Matrix for MV Switchgear

A complete design and assurance template connecting MV protection/interlock cause-and-effect to SCL, network parameters and end-to-end tests.

A GOOSE matrix is not merely a list of publisher and subscriber IEDs. For every trip, blocking, permissive and interlock signal it must define the exact IEC 61850 data reference, engineering purpose, required transfer time, quality and timeout handling, test/simulation behavior, redundancy, safe fallback and physical output. Without those fields, a syntactically correct SCD can still implement an unsafe protection scheme.

This guide provides a field-ready matrix structure, workflow, review method and FAT/SAT program for MV feeders, incomers, couplers, bus sections, earthing switches, breaker failure and transfer schemes.

1. Start with cause and effect

  • What primary condition initiates the signal?
  • Which protection/control function decides it?
  • Which IED publishes it and from which LN/data object?
  • Which subscribers act, alarm or record?
  • What physical equipment changes state?
  • What is the required total clearing/control time?
  • What happens if the signal, quality, publisher, network or time source fails?

Build the cause-and-effect table from SLD, protection philosophy, control narrative, trip schedule and interlocking diagram before assigning APPIDs or multicast addresses.

2. Minimum matrix columns

Column groupRequired fields
IdentityUnique signal ID, function, zone/bay, drawing/reference
PublisherIED, LD, LN, DO/DA, dataset, GoCB, ConfRev
CommunicationGoID, APPID, multicast MAC, VLAN, PCP, Min/Max retransmission
SubscriberIED, ExtRef/input, internal logic/use and destination output
PerformanceIEC 61850-5 class/project limit, endpoints, total scheme time
Data stateNormal/operate values, quality, timeAllowedToLive/timeout
Failure/testInvalid/stale response, test/simulation acceptance, safe fallback
AssuranceRedundant path, FAT case, SAT case, result/evidence

3. Use exact IEC 61850 references

  • Record publisher IED/logical device/logical node and data object/attribute.
  • Distinguish protection start, operate, conditioned trip and breaker position.
  • Use standardized LNs/data objects where supported instead of unstructured GGIO signals.
  • Record dataset member position because a member-order error can misinterpret a valid frame.
  • Map subscriber ExtRef to the same source and intended internal function.
  • Verify edition/namespace and vendor ICD support.
  • Generate the communication matrix from, or reconcile it with, the released SCD.

4. Classify signal purpose

TypeTypical exampleFailure concern
Direct tripBus differential or upstream breaker-failure tripDependability and total clearing time
PermissiveTransfer-trip/accelerated scheme permissionLoss reduces dependability; stale true may overtrip
BlockingReverse/blocking protection signalLoss may cause insecure operation
InterlockEarth switch open or source topology validUnknown state must not become permissive
InitiateBreaker failure, autoreclose or load sheddingDuplicate/stale initiation
Status/alarmBreaker/disconnector/device healthOperational visibility and logic dependencies

5. Performance fields

Assign the communication requirement using the project-governing IEC 61850-5 edition and protection study. State measurement endpoints; switch latency or ping is not application transfer time.

  • Source application change to subscriber application response.
  • Subscriber output contact where a process output is used.
  • Total protection decision to breaker current interruption.
  • Normal, worst credible traffic and one-redundancy-path conditions.
  • Maximum, not only average, plus test uncertainty and margin.
  • Any intentional delay, seal-in, debounce or pulse duration.
  • Breaker-failure timer coordination with communication and breaker time.

6. Quality, timeout and safe fallback

For each subscriber, define behavior for invalid/questionable quality, test, simulation, old/stale data, ConfRev mismatch, publisher restart and complete timeout. “Hold last state” is rarely acceptable without a time limit and risk analysis.

  • Use `valid AND open`, not merely `NOT closed`, for interlock permissives.
  • Remove a permissive when its source becomes invalid.
  • Analyze blocking-signal loss carefully; a default false may cause overtrip.
  • Do not create a direct trip merely from ordinary communication loss unless the protection philosophy explicitly requires it.
  • Alarm the exact publisher/control block and affected function.
  • Define fallback local/delayed protection and operator action.

7. Test and simulation columns

  • Can the publisher mark data as test?
  • Can the subscriber accept simulated GOOSE and under which enabled state?
  • Is the physical output blocked, isolated or live?
  • What HMI/local indication and audit event appear?
  • Can a test stream from another bay be accepted accidentally?
  • What restoration sequence clears simulation, subscription blocks and output isolation?
  • Who independently verifies normal state before energization?

8. Communication allocation

  • Allocate APPID, multicast MAC, VLAN and PCP from one controlled register.
  • Keep protection datasets minimal and stable.
  • Coordinate MinTime/MaxTime retransmission and subscriber timeAllowedToLive handling.
  • Define LAN A/B or HSR ring membership and publisher/subscriber ports.
  • Calculate stable plus event-burst bandwidth and queue loading.
  • Configure Layer-2 multicast forwarding only to required ports.
  • Detect duplicate addresses and publishers before FAT.

9. Example logic rows

FunctionPublisher eventSubscriber actionLoss fallback
Bus trip87B/PTRC conditioned tripTrip all zone breakers, initiate BF as designedAlarm; independent backup protection remains
Earth interlockValid earth switch open positionPermit breaker close with all other prerequisitesRemove permissive
BF upstream tripRBRF backup operateTrip upstream/coupler breakersBackup coordination per study
Blocking schemeReverse/start/block assertedRestrain accelerated elementApproved secure/delayed fallback
Bus transferSource/breaker/topology permissiveEnable transfer sequenceAbort/reject transfer

10. Review gates

  1. Protection review: cause, zone, timing, backup and failure philosophy.
  2. Primary/control review: equipment states, sequence and mechanical/electrical interlocks.
  3. IEC 61850 review: LN/DO/DA, dataset, ExtRef and quality semantics.
  4. Network review: address, VLAN/priority, multicast, capacity and redundancy.
  5. Cyber review: publisher trust, access, monitoring and test-equipment containment.
  6. Commissioning review: injectable test point, physical isolation and measurable evidence.
  7. Configuration authority: SCD/CID/matrix revision and approvals agree.

11. FAT/SAT test generation

Every matrix row should generate positive and negative test cases. Automate traceability, but do not substitute automated packet checks for physical function proof.

  • Assert and reset the real publisher input/function.
  • Verify every intended subscriber and absence at unintended subscribers.
  • Measure application transfer and physical output/breaker time.
  • Stop publisher, fail each network path and apply load.
  • Inject wrong ConfRev/member order/APPID and adjacent-bay stream.
  • Apply invalid/test/simulation quality and subscriber modes.
  • Restart devices and restore redundancy.
  • Record packet capture, relay events, output/current and pass limit.
  • At SAT, prove actual contacts, labels, fibers and breakers.

12. Change control

  • Assign a unique matrix revision tied to the SCD release.
  • Semantic-diff datasets, subscribers, addresses and failure responses.
  • A change to one publisher can affect many subscribers; use reverse dependency queries.
  • Require updated FAT/SAT cases and impact-based regression.
  • Reconcile field changes into the master SCD and matrix.
  • Archive hashes of SCD/CIDs/settings/switch configs and evidence.
  • Periodically compare live configurations with the approved baseline.

13. Practical matrix validation rules

  • Every safety/performance-critical row has at least one publisher, subscriber, application action and test case.
  • Every subscriber ExtRef resolves to one approved publisher member unless intentional redundancy/voting is documented.
  • Every trip subscriber traces to a physical output/coil or a named onward GOOSE path.
  • Every interlock prerequisite includes validity and timeout behavior.
  • No two control blocks share an address/APPID in the same engineered scope.
  • Dataset changes have updated ConfRev and affected-subscriber review.
  • Every redundant path has an alarm/test proving the failed side is visible.
  • Every test/simulation-enabled row defines output isolation and restoration.
  • Each performance limit has endpoints, load state and uncertainty.
  • Every orphan publisher/member is justified or removed.

14. Common anti-patterns

Anti-patternRiskCorrection
One row per GoCB, not per function/memberDifferent subscriber/failure behavior hiddenUse member/application-level rows
Only IED names recordedWrong LN/data/member remains ambiguousRecord full object reference and ExtRef
“Fail safe” entered without stateReviewers interpret differentlyState inhibit/trip/block/fallback/alarm explicitly
Timing copied from brochureEndpoints and load undefinedProject performance requirement and measured chain
Spreadsheet and SCD divergeTests validate obsolete intentAutomated reconciliation and release tie
Only positive FATTimeout, wrong stream and restart unprovenGenerate negative cases for every critical row

15. Handover deliverables

  • Approved matrix in human-readable and machine-importable form.
  • Released SCD and target CIDs/device files.
  • Address/VLAN/priority/multicast register and switch configuration.
  • Function-specific FAT/SAT results with raw captures/events.
  • Timeout/test/override operating instructions and alarm list.
  • As-built deviations, hashes, firmware/tool versions and rollback package.
  • Maintenance regression set and periodic redundancy/timeout proof plan.

References and further reading

Engineering note: The matrix is the executable interface contract between the protection philosophy and SCL. If timeout, quality and physical consequence are absent, the contract is incomplete.

LearnSwitchgear

Search the engineering library