PTP, SNTP and IRIG-B Time Synchronization in Digital Substations

A practical time-architecture guide for SV alignment, protection, event records and SCADA using PTP, SNTP and IRIG-B with failure testing.

Time synchronization in a digital substation is not one requirement. Sample alignment for differential protection, synchronism check, sequence-of-events records and SCADA timestamps need different accuracy, availability and failure behavior. PTP, SNTP and IRIG-B therefore cannot be selected by asking which is “most accurate”; the engineer must define the application, time-error budget, topology, holdover, quality indication and recovery behavior.

This guide compares IEC/IEEE 61850-9-3 PTP, SNTP and IRIG-B, then develops a practical architecture, accuracy budget, redundancy strategy and FAT/SAT program for MV IEC 61850 systems.

1. Five different timing needs

ApplicationWhy time mattersConsequence of excessive error
Sampled Values from multiple MUsAlign instantaneous current/voltage samplesFalse differential/phase error or protection restraint
Synchrocheck/phasor functionsCompare phase at defined instantsUnsafe close or rejected valid close
Sequence of eventsOrder trips, contacts and alarms across IEDsWrong root-cause analysis
Fault recordsCorrelate waveforms/events among baysDifficult or misleading disturbance analysis
SCADA/asset dataCommon operational time of dayBad logs, trends and audit records

Specify accuracy at the end application, not merely at the grandmaster output. Network delay/asymmetry, receiver timestamping, oscillator, cable, converters and IED processing all consume the budget.

2. PTP: precision across Ethernet

Precision Time Protocol distributes time through timestamped network messages and estimates path delay. IEC/IEEE 61850-9-3:2016 defines the PTP power-utility automation profile based on IEC 61588/IEEE 1588. Profile compliance matters: devices can all say “PTP” yet disagree on profile, domain, delay mechanism, transport, message rate or best-master behavior.

  • Grandmaster: provides traceable time, often disciplined by GNSS or another reference.
  • Ordinary clock: end device such as MU, relay or recorder.
  • Boundary clock: terminates PTP on one port and regenerates it on others using its local clock.
  • Transparent clock: measures/corrects residence time through a bridge.
  • Best-master/selection: chooses the active time source according to profile and dataset/priority rules.

Hardware timestamping and PTP-aware network elements generally support the tightest requirements. A PTP packet passing through an unaware switch may still work, but variable residence time and asymmetry must fit the application budget.

3. SNTP: useful, but for a different job

Simple Network Time Protocol is a network time-of-day service commonly used for IED clocks, logs, HMI and SCADA where the required accuracy is less demanding than aligned process-bus sampling. It is easy to route and widely supported, but variable Ethernet/IP stack and server delays limit deterministic precision.

  • Use redundant servers and defined polling/selection behavior.
  • Document UTC/local-time handling; protection IEDs should not be manually shifted for daylight saving.
  • Verify leap-second/time-step behavior and event-record continuity.
  • Do not use a successful SNTP status as proof that SV publishers are phase aligned.
  • Separate time-source reachability from time accuracy; a reachable server can be wrong.
  • Monitor offset, stratum/source identity and last successful synchronization where devices expose them.

4. IRIG-B: dedicated serial time code

IRIG-B is a serial time-code family defined by IRIG Standard 200. It is commonly distributed from a master clock using modulated carrier or DC level-shift (DCLS) electrical/optical forms. “IRIG-B” alone is incomplete: the exact code, modulation, electrical level, connector, year/control functions and whether a separate 1 PPS is used must be stated.

  • Dedicated wiring provides a clear path and can isolate critical IEDs from packet-network load.
  • Distribution amplifiers/converters and long copper runs add delay, distortion and common failure points.
  • Unmodulated DCLS and modulated forms are not directly interchangeable.
  • Some legacy implementations do not convey year/time-quality information in the way the application expects.
  • One-way distribution does not automatically report path health; supervise the receiving IED’s lock/quality.
  • Fiber distribution improves EMC/isolation but needs powered converters and spare management.

5. Comparison

CriterionPTP power profileSNTPIRIG-B
MediumEthernetIP/EthernetDedicated serial electrical/optical
Best applicationHigh-precision distributed clocks/SV alignmentIED/HMI time of day and logsDedicated IED/recorder time, legacy systems
Network supportProfile-aware clocks/switch functions importantOrdinary routed network possibleDistribution amplifiers/converters
Path-delay handlingMeasured/corrected by protocol architectureEstimated with less deterministic stacksFixed path, compensate/qualify if needed
ScalabilityHigh with engineered networkHighMore physical outputs/cabling
Failure visibilityRich quality/state possibleServer/client status variesReceiver lock plus distribution monitoring

6. Convert time error to protection error

For a sinusoidal quantity, approximate phase displacement from time error as Δφ = 360 f Δt, where f is hertz and Δt is seconds. At 50 Hz, 1 µs corresponds to 0.018°; at 60 Hz, 0.0216°. The relevant protection error is often the differential timing error between two MUs, not their common offset from UTC.

  • Derive allowable differential-current/phase error from the protection stability requirement.
  • Allocate error to grandmaster, network asymmetry, clocks, MU sampling and subscriber.
  • Include temperature, oscillator aging and holdover duration.
  • Distinguish steady offset, jitter, drift and a sudden time step.
  • Apply margin and measurement uncertainty.

7. Time source and UTC integrity

  • Use independent traceable sources where availability requires them.
  • GNSS antenna, cable, receiver and sky view are a common end-to-end dependency; protect against surge and interference.
  • Define behavior for GNSS loss, spoofing/jamming suspicion and bad time announcements.
  • Provide holdover with specified accuracy versus temperature and outage duration.
  • Manage UTC offset/leap seconds consistently; store/event in UTC and convert for display under a controlled policy.
  • A source whose quality degrades must announce it; receivers must use the quality information.
  • Record active grandmaster identity and changes for disturbance analysis.

8. Redundancy without a common mode

Two grandmasters sharing one GNSS antenna, one DC supply, one network switch or identical wrong configuration are not fully independent. Map reference, receiver, clock, power, network, fiber and IED dependencies.

  • Separate reference antennas/sources and physical routes where consequence warrants.
  • Use independent DC feeders and monitor supplies.
  • Verify PTP behavior over PRP/HSR; seamless data redundancy does not automatically guarantee clock correctness.
  • Prevent frequent grandmaster oscillation by engineered priorities and quality handling.
  • Test transition in both directions, including return of the preferred source.
  • Alarm loss of one source/path before holdover or total loss.

9. Failure response by application

Time conditionPossible responseEngineering decision
Short holdover within accuracyContinue and alarm/degrade qualityProven oscillator and duration
SV publishers lose alignmentBlock/restraint or switch to backup strategyDifferential security vs dependability
SNTP unavailableContinue protection; mark event time unsynchronizedProtection independence from time-of-day
Grandmaster step/changeSlew, step or controlled resyncDevice behavior and function tolerance
IRIG input lostInternal holdover plus alarmReceiver oscillator and log quality
Time valid but wrongMay be undetected without cross-checkMultiple-source plausibility and security monitoring

10. PTP network engineering

  • Freeze the IEC/IEEE 61850-9-3 profile, domain and device roles.
  • Check one-step/two-step and peer-to-peer/end-to-end delay support as applicable to the profile.
  • Use approved VLAN/priority treatment consistently; do not congest the time queue.
  • Limit hop count and path asymmetry; qualify every switch/RedBox/QuadBox.
  • Monitor transparent/boundary clock correction and errors.
  • Prevent unintended grandmasters from winning selection.
  • Calculate failure topology: the surviving path may have different hops/asymmetry.

11. Cybersecurity

  • Restrict clock, switch and time-server configuration to least privilege.
  • Protect management interfaces and log source/priority/config changes.
  • Monitor for rogue grandmasters, abrupt offsets, impossible location/source changes and GNSS alarms.
  • Segment timing traffic while preserving the approved profile.
  • Back up configurations and test rollback.
  • Coordinate firmware/security updates with timing and protection regression tests.
  • Do not assume encryption/authentication alone detects a trusted but wrong reference.

12. FAT and SAT

  1. Approve per-application accuracy, availability, holdover and failure response.
  2. Verify profile/code, domain, UTC settings, leap behavior and device compatibility.
  3. Measure offset at every critical end device with a calibrated reference.
  4. Test steady state, network load and redundant-path operation.
  5. Remove each GNSS/reference, grandmaster, switch/link and DC supply.
  6. Measure holdover drift across the specified duration/temperature where required.
  7. Force grandmaster changeover and return; look for time/phase steps and protection operation.
  8. Test PTP quality, SV smpSynch, IED clock alarms and event timestamps.
  9. For IRIG-B, verify exact code/modulation, amplitude/waveform, delay, year and receiver lock.
  10. For SNTP, verify both servers, polling/recovery and UTC/local display.
  11. Correlate injected events at multiple IEDs and quantify ordering error.
  12. Archive configurations, captures, calibrated uncertainty and as-built time paths.

13. Acceptance checklist

  • Each function has an accuracy and outage requirement.
  • Protocol/profile/code and all device roles are unambiguous.
  • End-to-end time-error budget includes asymmetry and holdover.
  • Common antenna, power, switch, route and configuration failures are identified.
  • Receivers expose time quality and applications act on it correctly.
  • Source loss, wrong time, changeover and recovery are tested.
  • Protection remains secure/dependable during the approved failure modes.
  • Operations receive actionable alarms and can identify the active source.
  • As-built drawings/configuration and periodic proof tests are assigned.

References and further reading

Engineering note: Clock accuracy displayed by a grandmaster is not the end-device accuracy. Acceptance must measure the complete path and the application response to bad or missing time.

LearnSwitchgear

Search the engineering library