Remote-control point-to-point testing must prove the complete chain from the exact control-center object to the physical breaker auxiliary contacts—and every safe rejection path in between. A successful protocol response proves only a communication/service stage; it does not prove output voltage, coil energization, mechanism movement or current interruption.
This guide defines a controlled FAT/SAT method for IEC 104/DNP3/IEC 61850 remote breaker operation, including authority, SBO/direct control, interlocks, failure injection, timing, cybersecurity and evidence.
1. Map the end-to-end chain
- Dispatcher/operator HMI object and user role.
- Control-center SCADA command service/front end.
- WAN, firewall/router and telecontrol session.
- Station gateway/RTU mapping and command state machine.
- IEC 61850 MMS/other southbound command to bay IED.
- Bay authority, interlock/synchrocheck and application logic.
- Binary output/interposing relay/control wiring/DC.
- Breaker close/open coil and mechanism.
- Independent 52a/52b position feedback through the return path.
- Command termination, alarm/SOE and audit at all destinations.
2. Safety prerequisites
- Approved test method, switching program, responsibility and communications.
- Clear primary-system condition, isolation/earthing and permission from system operations.
- Arc-flash/electrical safety controls and exclusion from mechanism hazards.
- Verified breaker rating, control DC, mechanical readiness and trip/close circuits.
- Protection/interlock/test-mode status documented; no uncontrolled bypass.
- One authorized command origin; block unintended local/automatic/reclose actions.
- Stop criteria and immediate local/emergency trip capability.
- Never energize live equipment merely to complete a communications test when simulation is sufficient.
3. Freeze test configuration
- Control-center database/graphics, gateway map, SCD and IED settings/logic.
- Protocol profiles, addresses/object indexes, control model and pulse durations.
- Firmware/software, redundant-node active state, time source and certificates.
- Wiring drawings, terminal schedules and breaker auxiliary-contact scheme.
- Point-list test sheet with stable point IDs and expected results.
- As-left hashes/revisions and rollback package.
4. Verify indications before control
| Input/state | Expected proof |
|---|---|
| 52a/52b | Open/closed/intermediate/invalid from physical contacts to HMI |
| Local/station/remote | Raw selector and evaluated authority at all levels |
| Interlock/synchrocheck | Permissive and detailed blocking cause |
| Mechanism/DC | Spring/drive ready, trip/close circuit and auxiliary supply |
| Quality/time | Fresh valid state with source timestamp/time quality |
| Protection/lockout | Correct trip/reclose/block/reset status |
Remote close should not begin if the control center cannot prove a fresh, valid and unambiguous breaker/topology state.
5. Positive open/close test
- Select the exact station, voltage, bay, breaker and action.
- Verify HMI shows current state, authority, checks and operator identity.
- For SBO, confirm selection reservation and timeout; then operate.
- Capture northbound request/response and gateway southbound transaction.
- Measure IED output and coil current/voltage where the test plan permits.
- Observe mechanism operation and independent 52a/52b transition.
- Confirm command termination and final control-center state.
- Verify SOE/alarm/audit with source timestamps and correct user/origin.
- Repeat open and close only under approved primary conditions.
6. Negative/interlock tests
- Wrong authority/local or maintenance mode.
- Breaker position invalid/intermediate/stale or IED communication failed.
- Earthing switch/disconnector/truck topology blocks close.
- Protection lockout, breaker-failure/arc/bus trip or reclose block active.
- Mechanism not ready, DC/close circuit failed or spring uncharged.
- Synchrocheck/live/dead-bus criteria not satisfied where required.
- Operate without selection, wrong client/object/value or expired selection.
- Unauthorized user/network client.
- Every case must reject without output and return a precise cause.
7. Timing measurements
| Interval | Measurement purpose |
|---|---|
| Operator execute to gateway receipt | Control-center/WAN path |
| Gateway receipt to IED operate | Mapping/session processing |
| IED operate to output/coil | Control logic/output delay |
| Coil energization to 52a/52b | Breaker mechanism/contact time |
| Feedback to HMI update | Return reporting/WAN/display |
| Total execute to confirmed state | Operator-perceived completion |
Use synchronized instruments/source timestamps and state the uncertainty. Auxiliary-contact time is not necessarily main-contact current-interruption time; breaker analyzer testing addresses the latter.
8. Communication-failure injection
- Lose WAN before select, between select/operate and after IED execution before response.
- Restart/fail over control-center front end, gateway and HMI at each stage.
- Fail IEC 61850 association/reporting and one/both station LAN paths.
- Delay/drop/duplicate response in controlled test equipment where possible.
- Verify no blind repeat, latent queued command or inherited selection.
- Reconcile actual breaker state before permitting a new command.
- Confirm bad/stale quality and event replay after restoration.
9. Redundancy and competing controls
- Prove only one active control-center/gateway authority.
- Attempt simultaneous station/remote/automatic/local requests and verify priority.
- Fail active server/gateway during SBO and operate.
- Verify no duplicate output or command on failover/failback.
- Confirm report/event buffers and final feedback remain consistent across redundant nodes.
- Alarm standby/synchronization failure before testing the second failure.
10. Output and breaker discrepancy tests
- Command accepted but output/interposing relay prevented.
- Output/coil energized but breaker mechanically fails to move.
- Breaker moves slowly and remains intermediate beyond discrepancy timer.
- 52a/52b contacts disagree or one feedback wire fails.
- Late position arrives after command timeout.
- Confirm negative termination/discrepancy alarm and no automatic repeated close/open unless explicitly designed.
- Use breaker-failure protection tests separately with controlled current/conditions.
11. Cybersecurity validation
- Correct user role succeeds; unauthorized role/client/path fails.
- Audit includes user/client/origin, object/action, select/operate, rejection/result and time.
- Test certificate/session expiry or security-service loss under a planned safe condition.
- Confirm firewalls/allowlists permit only approved masters and protocol flows.
- Mode/interlock logic remains local and safe if remote security services fail.
- Preserve packet/log evidence securely and remove temporary test access afterward.
12. Evidence and defect control
- Stable test-case and point IDs, preconditions and authorization.
- Stimulus, expected/actual result at each layer and measured timing.
- SCADA/IED/gateway/breaker analyzer logs and packet captures.
- Photos/readings of output/coil/auxiliary contacts where appropriate.
- Configuration revisions/hashes and active redundancy state.
- Defect, risk, correction, regression scope and witnessed retest.
- As-left breaker state, modes, blocks/bypasses and restored protections.
13. Final restoration checklist
- Remove simulations, test flags, jumpers and temporary accounts/routes.
- Restore protection, reclose, interlocks, authority and automatic schemes.
- Confirm breaker/switch final position and control-center topology.
- Clear/acknowledge test alarms only under procedure; retain audit/SOE.
- Reconcile as-built files and test defects.
- Obtain operations handback and record return-to-service time.
14. Stage the test from simulation to live equipment
- Database/offline review: verify object identity, addresses, control model, authority and expected feedback without issuing commands.
- Protocol simulator: prove northbound select/operate/termination and negative cases with no breaker output enabled.
- IED secondary test: exercise bay logic, simulated inputs and output indication with the coil circuit isolated under procedure.
- Control-circuit test: prove interposing relay, DC polarity/voltage, pulse duration and continuity using a safe test load or isolated mechanism as specified.
- Mechanism operation: operate the disconnected/test-position breaker where suitable and verify 52a/52b travel.
- Installed primary SAT: perform only the approved operations required to prove the final topology/control-center chain, under system-operator switching authority.
Each stage should close its defects before the next increases physical consequence. Simulation proves protocol logic but cannot replace the final wiring/mechanism check; live operation should not be used to discover database or address errors that could have been removed earlier.
References and further reading
- IEC 61850-10 consolidated edition 2.1 — Conformance/performance testing
- IEC 61850-8-1 consolidated edition — MMS control/report mapping
- IEC 61850-7-2 consolidated edition — ACSI control services
- IEC 60870-5-104 consolidated edition — Remote telecontrol
- IEC TS 60870-5-604:2016 — IEC 104 conformance tests
- IEC TS 60870-5-7:2025 — Secure IEC 101/104 extensions
- IEC 62351-6:2020 — IEC 61850 security
Engineering note: The acceptance endpoint is the independently verified breaker position and safe system state—not a green “command sent” message.