A GOOSE matrix is not merely a list of publisher and subscriber IEDs. For every trip, blocking, permissive and interlock signal it must define the exact IEC 61850 data reference, engineering purpose, required transfer time, quality and timeout handling, test/simulation behavior, redundancy, safe fallback and physical output. Without those fields, a syntactically correct SCD can still implement an unsafe protection scheme.
This guide provides a field-ready matrix structure, workflow, review method and FAT/SAT program for MV feeders, incomers, couplers, bus sections, earthing switches, breaker failure and transfer schemes.
1. Start with cause and effect
- What primary condition initiates the signal?
- Which protection/control function decides it?
- Which IED publishes it and from which LN/data object?
- Which subscribers act, alarm or record?
- What physical equipment changes state?
- What is the required total clearing/control time?
- What happens if the signal, quality, publisher, network or time source fails?
Build the cause-and-effect table from SLD, protection philosophy, control narrative, trip schedule and interlocking diagram before assigning APPIDs or multicast addresses.
2. Minimum matrix columns
| Column group | Required fields |
|---|---|
| Identity | Unique signal ID, function, zone/bay, drawing/reference |
| Publisher | IED, LD, LN, DO/DA, dataset, GoCB, ConfRev |
| Communication | GoID, APPID, multicast MAC, VLAN, PCP, Min/Max retransmission |
| Subscriber | IED, ExtRef/input, internal logic/use and destination output |
| Performance | IEC 61850-5 class/project limit, endpoints, total scheme time |
| Data state | Normal/operate values, quality, timeAllowedToLive/timeout |
| Failure/test | Invalid/stale response, test/simulation acceptance, safe fallback |
| Assurance | Redundant path, FAT case, SAT case, result/evidence |
3. Use exact IEC 61850 references
- Record publisher IED/logical device/logical node and data object/attribute.
- Distinguish protection start, operate, conditioned trip and breaker position.
- Use standardized LNs/data objects where supported instead of unstructured GGIO signals.
- Record dataset member position because a member-order error can misinterpret a valid frame.
- Map subscriber ExtRef to the same source and intended internal function.
- Verify edition/namespace and vendor ICD support.
- Generate the communication matrix from, or reconcile it with, the released SCD.
4. Classify signal purpose
| Type | Typical example | Failure concern |
|---|---|---|
| Direct trip | Bus differential or upstream breaker-failure trip | Dependability and total clearing time |
| Permissive | Transfer-trip/accelerated scheme permission | Loss reduces dependability; stale true may overtrip |
| Blocking | Reverse/blocking protection signal | Loss may cause insecure operation |
| Interlock | Earth switch open or source topology valid | Unknown state must not become permissive |
| Initiate | Breaker failure, autoreclose or load shedding | Duplicate/stale initiation |
| Status/alarm | Breaker/disconnector/device health | Operational visibility and logic dependencies |
5. Performance fields
Assign the communication requirement using the project-governing IEC 61850-5 edition and protection study. State measurement endpoints; switch latency or ping is not application transfer time.
- Source application change to subscriber application response.
- Subscriber output contact where a process output is used.
- Total protection decision to breaker current interruption.
- Normal, worst credible traffic and one-redundancy-path conditions.
- Maximum, not only average, plus test uncertainty and margin.
- Any intentional delay, seal-in, debounce or pulse duration.
- Breaker-failure timer coordination with communication and breaker time.
6. Quality, timeout and safe fallback
For each subscriber, define behavior for invalid/questionable quality, test, simulation, old/stale data, ConfRev mismatch, publisher restart and complete timeout. “Hold last state” is rarely acceptable without a time limit and risk analysis.
- Use `valid AND open`, not merely `NOT closed`, for interlock permissives.
- Remove a permissive when its source becomes invalid.
- Analyze blocking-signal loss carefully; a default false may cause overtrip.
- Do not create a direct trip merely from ordinary communication loss unless the protection philosophy explicitly requires it.
- Alarm the exact publisher/control block and affected function.
- Define fallback local/delayed protection and operator action.
7. Test and simulation columns
- Can the publisher mark data as test?
- Can the subscriber accept simulated GOOSE and under which enabled state?
- Is the physical output blocked, isolated or live?
- What HMI/local indication and audit event appear?
- Can a test stream from another bay be accepted accidentally?
- What restoration sequence clears simulation, subscription blocks and output isolation?
- Who independently verifies normal state before energization?
8. Communication allocation
- Allocate APPID, multicast MAC, VLAN and PCP from one controlled register.
- Keep protection datasets minimal and stable.
- Coordinate MinTime/MaxTime retransmission and subscriber timeAllowedToLive handling.
- Define LAN A/B or HSR ring membership and publisher/subscriber ports.
- Calculate stable plus event-burst bandwidth and queue loading.
- Configure Layer-2 multicast forwarding only to required ports.
- Detect duplicate addresses and publishers before FAT.
9. Example logic rows
| Function | Publisher event | Subscriber action | Loss fallback |
|---|---|---|---|
| Bus trip | 87B/PTRC conditioned trip | Trip all zone breakers, initiate BF as designed | Alarm; independent backup protection remains |
| Earth interlock | Valid earth switch open position | Permit breaker close with all other prerequisites | Remove permissive |
| BF upstream trip | RBRF backup operate | Trip upstream/coupler breakers | Backup coordination per study |
| Blocking scheme | Reverse/start/block asserted | Restrain accelerated element | Approved secure/delayed fallback |
| Bus transfer | Source/breaker/topology permissive | Enable transfer sequence | Abort/reject transfer |
10. Review gates
- Protection review: cause, zone, timing, backup and failure philosophy.
- Primary/control review: equipment states, sequence and mechanical/electrical interlocks.
- IEC 61850 review: LN/DO/DA, dataset, ExtRef and quality semantics.
- Network review: address, VLAN/priority, multicast, capacity and redundancy.
- Cyber review: publisher trust, access, monitoring and test-equipment containment.
- Commissioning review: injectable test point, physical isolation and measurable evidence.
- Configuration authority: SCD/CID/matrix revision and approvals agree.
11. FAT/SAT test generation
Every matrix row should generate positive and negative test cases. Automate traceability, but do not substitute automated packet checks for physical function proof.
- Assert and reset the real publisher input/function.
- Verify every intended subscriber and absence at unintended subscribers.
- Measure application transfer and physical output/breaker time.
- Stop publisher, fail each network path and apply load.
- Inject wrong ConfRev/member order/APPID and adjacent-bay stream.
- Apply invalid/test/simulation quality and subscriber modes.
- Restart devices and restore redundancy.
- Record packet capture, relay events, output/current and pass limit.
- At SAT, prove actual contacts, labels, fibers and breakers.
12. Change control
- Assign a unique matrix revision tied to the SCD release.
- Semantic-diff datasets, subscribers, addresses and failure responses.
- A change to one publisher can affect many subscribers; use reverse dependency queries.
- Require updated FAT/SAT cases and impact-based regression.
- Reconcile field changes into the master SCD and matrix.
- Archive hashes of SCD/CIDs/settings/switch configs and evidence.
- Periodically compare live configurations with the approved baseline.
13. Practical matrix validation rules
- Every safety/performance-critical row has at least one publisher, subscriber, application action and test case.
- Every subscriber ExtRef resolves to one approved publisher member unless intentional redundancy/voting is documented.
- Every trip subscriber traces to a physical output/coil or a named onward GOOSE path.
- Every interlock prerequisite includes validity and timeout behavior.
- No two control blocks share an address/APPID in the same engineered scope.
- Dataset changes have updated ConfRev and affected-subscriber review.
- Every redundant path has an alarm/test proving the failed side is visible.
- Every test/simulation-enabled row defines output isolation and restoration.
- Each performance limit has endpoints, load state and uncertainty.
- Every orphan publisher/member is justified or removed.
14. Common anti-patterns
| Anti-pattern | Risk | Correction |
|---|---|---|
| One row per GoCB, not per function/member | Different subscriber/failure behavior hidden | Use member/application-level rows |
| Only IED names recorded | Wrong LN/data/member remains ambiguous | Record full object reference and ExtRef |
| “Fail safe” entered without state | Reviewers interpret differently | State inhibit/trip/block/fallback/alarm explicitly |
| Timing copied from brochure | Endpoints and load undefined | Project performance requirement and measured chain |
| Spreadsheet and SCD diverge | Tests validate obsolete intent | Automated reconciliation and release tie |
| Only positive FAT | Timeout, wrong stream and restart unproven | Generate negative cases for every critical row |
15. Handover deliverables
- Approved matrix in human-readable and machine-importable form.
- Released SCD and target CIDs/device files.
- Address/VLAN/priority/multicast register and switch configuration.
- Function-specific FAT/SAT results with raw captures/events.
- Timeout/test/override operating instructions and alarm list.
- As-built deviations, hashes, firmware/tool versions and rollback package.
- Maintenance regression set and periodic redundancy/timeout proof plan.
References and further reading
- IEC 61850-8-1 consolidated edition — GOOSE mapping
- IEC 61850-5 consolidated edition — Function communication requirements
- IEC 61850-6 edition 2.2 — SCL
- IEC 61850-7-4 consolidated edition — Logical nodes/data objects
- IEC TR 61850-10-3:2022 — Functional testing
- IEC TS 60255-216-1:2025 — Digital protection interoperability tests
Engineering note: The matrix is the executable interface contract between the protection philosophy and SCL. If timeout, quality and physical consequence are absent, the contract is incomplete.