Remote-Control Point-to-Point Testing from Control Center to Circuit Breaker

A staged and safety-controlled FAT/SAT method that proves remote commands, rejections, physical outputs, breaker operation and independent feedback.

Remote-control point-to-point testing must prove the complete chain from the exact control-center object to the physical breaker auxiliary contacts—and every safe rejection path in between. A successful protocol response proves only a communication/service stage; it does not prove output voltage, coil energization, mechanism movement or current interruption.

This guide defines a controlled FAT/SAT method for IEC 104/DNP3/IEC 61850 remote breaker operation, including authority, SBO/direct control, interlocks, failure injection, timing, cybersecurity and evidence.

1. Map the end-to-end chain

  1. Dispatcher/operator HMI object and user role.
  2. Control-center SCADA command service/front end.
  3. WAN, firewall/router and telecontrol session.
  4. Station gateway/RTU mapping and command state machine.
  5. IEC 61850 MMS/other southbound command to bay IED.
  6. Bay authority, interlock/synchrocheck and application logic.
  7. Binary output/interposing relay/control wiring/DC.
  8. Breaker close/open coil and mechanism.
  9. Independent 52a/52b position feedback through the return path.
  10. Command termination, alarm/SOE and audit at all destinations.

2. Safety prerequisites

  • Approved test method, switching program, responsibility and communications.
  • Clear primary-system condition, isolation/earthing and permission from system operations.
  • Arc-flash/electrical safety controls and exclusion from mechanism hazards.
  • Verified breaker rating, control DC, mechanical readiness and trip/close circuits.
  • Protection/interlock/test-mode status documented; no uncontrolled bypass.
  • One authorized command origin; block unintended local/automatic/reclose actions.
  • Stop criteria and immediate local/emergency trip capability.
  • Never energize live equipment merely to complete a communications test when simulation is sufficient.

3. Freeze test configuration

  • Control-center database/graphics, gateway map, SCD and IED settings/logic.
  • Protocol profiles, addresses/object indexes, control model and pulse durations.
  • Firmware/software, redundant-node active state, time source and certificates.
  • Wiring drawings, terminal schedules and breaker auxiliary-contact scheme.
  • Point-list test sheet with stable point IDs and expected results.
  • As-left hashes/revisions and rollback package.

4. Verify indications before control

Input/stateExpected proof
52a/52bOpen/closed/intermediate/invalid from physical contacts to HMI
Local/station/remoteRaw selector and evaluated authority at all levels
Interlock/synchrocheckPermissive and detailed blocking cause
Mechanism/DCSpring/drive ready, trip/close circuit and auxiliary supply
Quality/timeFresh valid state with source timestamp/time quality
Protection/lockoutCorrect trip/reclose/block/reset status

Remote close should not begin if the control center cannot prove a fresh, valid and unambiguous breaker/topology state.

5. Positive open/close test

  1. Select the exact station, voltage, bay, breaker and action.
  2. Verify HMI shows current state, authority, checks and operator identity.
  3. For SBO, confirm selection reservation and timeout; then operate.
  4. Capture northbound request/response and gateway southbound transaction.
  5. Measure IED output and coil current/voltage where the test plan permits.
  6. Observe mechanism operation and independent 52a/52b transition.
  7. Confirm command termination and final control-center state.
  8. Verify SOE/alarm/audit with source timestamps and correct user/origin.
  9. Repeat open and close only under approved primary conditions.

6. Negative/interlock tests

  • Wrong authority/local or maintenance mode.
  • Breaker position invalid/intermediate/stale or IED communication failed.
  • Earthing switch/disconnector/truck topology blocks close.
  • Protection lockout, breaker-failure/arc/bus trip or reclose block active.
  • Mechanism not ready, DC/close circuit failed or spring uncharged.
  • Synchrocheck/live/dead-bus criteria not satisfied where required.
  • Operate without selection, wrong client/object/value or expired selection.
  • Unauthorized user/network client.
  • Every case must reject without output and return a precise cause.

7. Timing measurements

IntervalMeasurement purpose
Operator execute to gateway receiptControl-center/WAN path
Gateway receipt to IED operateMapping/session processing
IED operate to output/coilControl logic/output delay
Coil energization to 52a/52bBreaker mechanism/contact time
Feedback to HMI updateReturn reporting/WAN/display
Total execute to confirmed stateOperator-perceived completion

Use synchronized instruments/source timestamps and state the uncertainty. Auxiliary-contact time is not necessarily main-contact current-interruption time; breaker analyzer testing addresses the latter.

8. Communication-failure injection

  • Lose WAN before select, between select/operate and after IED execution before response.
  • Restart/fail over control-center front end, gateway and HMI at each stage.
  • Fail IEC 61850 association/reporting and one/both station LAN paths.
  • Delay/drop/duplicate response in controlled test equipment where possible.
  • Verify no blind repeat, latent queued command or inherited selection.
  • Reconcile actual breaker state before permitting a new command.
  • Confirm bad/stale quality and event replay after restoration.

9. Redundancy and competing controls

  • Prove only one active control-center/gateway authority.
  • Attempt simultaneous station/remote/automatic/local requests and verify priority.
  • Fail active server/gateway during SBO and operate.
  • Verify no duplicate output or command on failover/failback.
  • Confirm report/event buffers and final feedback remain consistent across redundant nodes.
  • Alarm standby/synchronization failure before testing the second failure.

10. Output and breaker discrepancy tests

  • Command accepted but output/interposing relay prevented.
  • Output/coil energized but breaker mechanically fails to move.
  • Breaker moves slowly and remains intermediate beyond discrepancy timer.
  • 52a/52b contacts disagree or one feedback wire fails.
  • Late position arrives after command timeout.
  • Confirm negative termination/discrepancy alarm and no automatic repeated close/open unless explicitly designed.
  • Use breaker-failure protection tests separately with controlled current/conditions.

11. Cybersecurity validation

  • Correct user role succeeds; unauthorized role/client/path fails.
  • Audit includes user/client/origin, object/action, select/operate, rejection/result and time.
  • Test certificate/session expiry or security-service loss under a planned safe condition.
  • Confirm firewalls/allowlists permit only approved masters and protocol flows.
  • Mode/interlock logic remains local and safe if remote security services fail.
  • Preserve packet/log evidence securely and remove temporary test access afterward.

12. Evidence and defect control

  • Stable test-case and point IDs, preconditions and authorization.
  • Stimulus, expected/actual result at each layer and measured timing.
  • SCADA/IED/gateway/breaker analyzer logs and packet captures.
  • Photos/readings of output/coil/auxiliary contacts where appropriate.
  • Configuration revisions/hashes and active redundancy state.
  • Defect, risk, correction, regression scope and witnessed retest.
  • As-left breaker state, modes, blocks/bypasses and restored protections.

13. Final restoration checklist

  • Remove simulations, test flags, jumpers and temporary accounts/routes.
  • Restore protection, reclose, interlocks, authority and automatic schemes.
  • Confirm breaker/switch final position and control-center topology.
  • Clear/acknowledge test alarms only under procedure; retain audit/SOE.
  • Reconcile as-built files and test defects.
  • Obtain operations handback and record return-to-service time.

14. Stage the test from simulation to live equipment

  1. Database/offline review: verify object identity, addresses, control model, authority and expected feedback without issuing commands.
  2. Protocol simulator: prove northbound select/operate/termination and negative cases with no breaker output enabled.
  3. IED secondary test: exercise bay logic, simulated inputs and output indication with the coil circuit isolated under procedure.
  4. Control-circuit test: prove interposing relay, DC polarity/voltage, pulse duration and continuity using a safe test load or isolated mechanism as specified.
  5. Mechanism operation: operate the disconnected/test-position breaker where suitable and verify 52a/52b travel.
  6. Installed primary SAT: perform only the approved operations required to prove the final topology/control-center chain, under system-operator switching authority.

Each stage should close its defects before the next increases physical consequence. Simulation proves protocol logic but cannot replace the final wiring/mechanism check; live operation should not be used to discover database or address errors that could have been removed earlier.

References and further reading

Engineering note: The acceptance endpoint is the independently verified breaker position and safe system state—not a green “command sent” message.

LearnSwitchgear

Search the engineering library