What GOOSE does
IEC 61850 GOOSE is a publisher/subscriber multicast service for fast event information. A relay publishes a dataset—such as protection start, trip, breaker position or block—and multiple IEDs subscribe without a central controller in the real-time path. Repeated transmissions and state/sequence counters support speed and supervision.
GOOSE can replace many hardwired inter-panel signals, but the Ethernet network and SCL configuration then become part of the protection system. “IEC 61850 capable” does not prove that a particular end-to-end trip will meet its time, security or availability requirement.
1. Good MV applications
| Application | Published signal | Subscriber action |
|---|---|---|
| Zone-selective interlocking | Feeder protection start/block. | Incomer delays high-set operation for downstream fault. |
| Bus/arc protection | Arc zone and overcurrent/trip. | Trip all source breakers feeding the affected bus zone. |
| Breaker failure | BF initiate or backup trip. | Adjacent/incomer breakers trip after supervised logic. |
| Switchgear interlocking | Breaker, truck and earthing-switch states/permissives. | Block unsafe close or movement. |
| Automatic transfer | Source healthy, breaker open, bus lockout, transfer permissive. | Execute controlled main-tie-main sequence. |
| Load shedding | Underfrequency/undervoltage stage and priority group. | Open selected feeders. |
2. Engineer the signal semantics
For every GOOSE point define source logical node/data object, true/false meaning, quality use, subscriber, normal state, fail state, required transfer time and what happens on message loss. A Boolean called “BLOCK” is ambiguous: does true block, does false permit, and what should loss of communication do? Name the engineering intent, not only the relay variable.
Use a controlled signal list linked to the SCD file and schematic. Include dataset order; a dataset change can remap subscribers even when point names look unchanged.
3. Network performance
Protection GOOSE should use an engineered LAN with managed switches, VLANs and priority where required, multicast filtering, traffic and storm controls that do not block valid protection bursts, and documented latency under maximum credible load. Separate or logically segregate protection traffic from non-critical management traffic. Avoid unmanaged switches and office-network features with unknown recovery time.
The required end-to-end time includes publisher processing, network/switch latency, subscriber processing and output operation. Measure it at FAT/SAT. IEC 61850-5 performance classes and the application requirement guide the target; do not assume every message needs the same time.
4. Retransmission and supervision
After a state change, GOOSE frames are retransmitted quickly and then at increasing intervals. Subscribers monitor time-allowed-to-live and state/sequence information. Engineer an alarm for subscription failure and decide whether the application fails secure, fails dependable or falls back to time-delayed protection.
| Application | Typical loss-of-GOOSE philosophy |
|---|---|
| ZSI block lost | Incomer may revert to time-delayed coordination to avoid overtrip, with urgent alarm. |
| Transfer permissive lost | Block automatic close; operator investigates. |
| Bus trip channel lost | Critical scheme may require redundant path or hardwired backup. |
| Breaker status lost | Block topology-dependent automatic operation and use conservative zone logic. |
The correct response depends on whether security or dependability has the greater consequence. Document the decision in the protection philosophy.
5. SCL lifecycle
ICD/IID files describe IED capability; the system configuration tool creates the SCD; each IED receives an extracted CID or equivalent. Treat the SCD as a controlled system source, not a by-product on one engineer’s laptop. Require version, owner, change log, tool version and backups. A field relay replacement must use the approved SCD-derived configuration and verified network identity.
6. Redundancy and common-mode failure
PRP or HSR can provide zero-recovery redundancy for a single network failure, but duplicate paths do not protect against wrong datasets, a common power supply, misconfigured multicast filtering or one incorrect trip logic shared by both networks. Hardwired backup or independent protection may still be appropriate for critical trips.
7. Cybersecurity
GOOSE traditionally relies on a trusted substation LAN. Apply physical access control, network segmentation, switch hardening, unused-port shutdown, role-based engineering access, configuration integrity and monitoring. IEC 62351-6 defines security mechanisms for IEC 61850-derived protocols, but product and performance support must be confirmed. Security controls must not introduce unverified latency or availability risk.
8. Testing workflow
- Validate SCD syntax and publisher/subscriber mapping against the signal list.
- Use a protocol analyzer/test set to check APPID, VLAN/priority, MAC, dataset, state/sequence and quality.
- Operate each source signal and verify every subscriber logic point and physical output.
- Measure end-to-end time with maximum network load.
- Disconnect one link/switch/network and verify redundancy and alarms.
- Stop a publisher or alter quality/test flag to verify fail-state logic.
- Test in IEC 61850 test/simulation mode without unintended plant trip, then prove the final live path under controlled conditions.
- Archive packet capture, SCD hash and as-left IED files.
9. Hardwire or GOOSE?
Use a requirements decision, not ideology. GOOSE is strong for multi-subscriber, cross-panel and topology-rich logic and provides supervision/data reuse. Hardwire is transparent, independent of the LAN and familiar to maintenance teams. Hybrid schemes are common: GOOSE for permissives/blocks and hardwired independent trip, or dual GOOSE networks with time-delayed hardwired backup. The chosen architecture must be testable by the owner for its entire life.
Related protection guides
Engineering limitation
This guide explains a defensible engineering workflow; it is not a project setting calculation. Final protection functions, settings, wiring and trip logic must be based on the approved single-line diagram, short-circuit and coordination studies, equipment data, grid code, relay manual, and verified commissioning results. Changes require formal protection-management control.
References and further reading
- IEC 61850-8-1:2011 — mapping of MMS and GOOSE services
- IEC 61850-7-2:2010 — abstract communication services and publisher/subscriber models
- IEC TS 60255-216-1:2025 — requirements/tests for digital-input/output protection functions
- IEC TR 61850-10-3:2022 — system testing of IEC 61850 applications
- SEL — Improving Reliability and Security of GOOSE Protection Algorithms — configuration and supervision guidance
Standards must be applied using the edition required by the project, utility and local law. Standards summaries on public pages are not substitutes for the controlled documents.