A robust MV SCADA architecture preserves local protection during loss of HMI, gateway or control-center communication while providing unambiguous, secure and time-consistent monitoring/control. The IED, RTU, gateway, station HMI and control center have different responsibilities; duplicating logic or authority across them creates inconsistent states and unsafe remote switching.
This guide designs the complete station-to-control-center path using IEC 61850 MMS/GOOSE and IEC 60870-5-104, with data ownership, command authority, redundancy, cybersecurity, failure modes and FAT/SAT.
1. Functional layers
| Layer | Primary role | Should remain independent from |
|---|---|---|
| Protection/control IED | Protection, local control, measurements, event/report source | Control-center availability |
| RTU/station gateway | Protocol/data concentration, telecontrol interface, buffering | Primary protection decision |
| Station HMI/controller | Local operation, single-line, alarms, station automation | Remote WAN availability |
| Control-center SCADA | Fleet supervision, remote control, alarm/event operations | Fast local interlocking/protection |
| Engineering/asset systems | Settings, configuration, records and maintenance | Routine operator control path |
2. Typical information flow
- IEDs provide IEC 61850 MMS reports, controls, measurements, events and files to station clients.
- GOOSE remains station/process peer-to-peer for protection/interlocking, not normally routed through a control center.
- Gateway maps selected IEC 61850 data/control semantics to IEC 60870-5-104 or another control-center protocol.
- Station HMI subscribes to reports and executes local commands under authority/interlock rules.
- Control center receives curated points/quality/time and sends authorized commands.
- Engineering file/settings access uses a separate controlled path.
3. IED responsibilities
- Protection and breaker-failure logic must not depend on RTU/HMI/WAN.
- Acquire primary status/measurements with value, quality and timestamp.
- Execute local interlocking/synchrocheck or provide required distributed interface.
- Expose standardized LNs/data objects and report/control behavior.
- Store events/disturbance records through station communication loss.
- Supervise breaker trip circuit/device health and communication.
- Enforce local/remote, test, blocked and operator authority states.
4. RTU/gateway responsibilities
- Terminate/control approved station and telecontrol protocol connections.
- Map IEC 61850 object value, quality, time and control semantics without silent loss.
- Perform data concentration, scaling/deadband and event buffering only under approved rules.
- Maintain control select/execute/cancel and feedback correlation.
- Manage WAN redundancy and reconnect/backfill.
- Expose gateway/IED communication quality distinctly from process quality.
- Keep mapping/database version tied to the SCD and point list.
5. HMI design
- Single-line matches physical bay names/topology and shows intermediate/invalid states.
- Quality/time/stale/communication failure is visible; do not freeze a value as healthy.
- Alarm priority, grouping, shelving and acknowledgment follow consequence/operations rules.
- Control dialogs show device, command, authority, interlock/synchrocheck and final feedback.
- Test/simulation/override/block states are prominent.
- Redundant HMI servers/clients have defined failover and no duplicate commands.
- Operator actions are uniquely audited with time and result.
6. Point-list and semantic mapping
| Point field | Required content |
|---|---|
| Source | IED/LD/LN/DO/DA or RTU input and physical equipment |
| SCADA address | IEC 104 common address/IOA/type or target protocol mapping |
| Value | Single/double point, measured type, units, scale/deadband |
| Quality/time | Source quality mapping, timestamp origin/class, stale rule |
| Control | SBO/direct, qualifier/pulse, authority, interlock and feedback |
| Alarm | Priority, text, normal state, delay, grouping and responsibility |
| Test | FAT/SAT case, simulator/source, expected result |
7. Reporting and event handling
- Engineer buffered/unbuffered report controls, datasets, triggers, optional fields, integrity and GI.
- Provide enough report instances/reservations for redundant HMI/gateway clients.
- Test reconnect, buffer overflow and event order after outage.
- Use source timestamps and preserve time quality through gateway.
- Distinguish process change, communication restore and substituted value.
- Control measurement deadband so protection-relevant/operational changes are not hidden.
- Do not flood SCADA with high-rate process-bus data not needed operationally.
8. Remote control chain
- Operator selects exact device and intended action.
- SCADA verifies user role, authority and fresh topology/quality.
- Command passes through approved WAN/gateway protocol mapping.
- IED/station control checks local/remote, interlock/synchrocheck and control model.
- Output operates breaker/switch.
- Independent position feedback and termination return.
- Timeout/discrepancy creates an alarm; no blind repeated command.
9. Control authority
- Define hierarchy: bay local, station HMI, remote control center and automatic schemes.
- Only one authority should command a device at a time, with visible mode.
- Local emergency control and interlock bypass are different states.
- Loss of HMI/WAN should not unexpectedly transfer authority without indication.
- Stale/invalid position must normally reject remote control.
- Record mode changes and control origin.
- Test conflicting/simultaneous commands and client failover.
10. Redundancy and failure modes
| Failure | Expected behavior |
|---|---|
| One IED/network path | Function-specific redundancy/quality alarm; local protection maintained as designed |
| Gateway failure | Standby failover or remote loss; local HMI/protection remain |
| HMI server/client | Redundant client/server or local bay control remains |
| WAN/control center | Station continues; events buffered; authority clear |
| Time source | Protection/time-specific fallback; events marked unsynchronized |
| Database/mapping error | Prevented by version/independent point-to-point SAT |
| DC/common switch | Physical independence and alarms prevent common outage |
11. Cybersecurity
- Segment station, gateway/DMZ, control-center and engineering zones.
- Permit only required MMS, IEC 104, time and management conduits.
- Use IEC 62351 mechanisms supported for relevant protocols and test interoperability.
- Unique accounts/roles, jump-host remote access, audit and least privilege.
- Protect SCD/point databases/HMI graphics/settings and gateway mapping.
- Monitor unauthorized command, login, configuration, protocol anomaly and time change.
- Back up/restore redundant servers/gateways and maintain incident manual-control procedures.
12. FAT/SAT
- Freeze SCD, point list, gateway/HMI database, graphics and protocol settings.
- Point-to-point test every status, measurement, quality, time, alarm and control.
- Test IEC 61850 reports/controls and IEC 104 mapping/conformance profile.
- Verify local/station/remote authority, SBO/direct and interlock rejection.
- Fail IED links, station LAN, gateway, HMI, WAN and time source.
- Test redundant client/server/gateway failover and return without duplicate controls.
- Test buffer/reconnect/event ordering, bad quality and stale data.
- Validate cyber allow/deny rules, accounts, logs and backup restore.
- At SAT, operate actual switchgear and verify control-center round trip.
- Archive as-built databases/configurations/hashes and results.
13. Capacity and performance engineering
- Count MMS clients/report instances, gateway points, IEC 104 connections, command rate and future bays.
- Model normal telemetry plus disturbance-event bursts, integrity scans, reconnect backfill and file transfers.
- Specify end-to-end status/alarm/control response and timestamp accuracy by function.
- Size gateway/HMI CPU, memory, storage, event buffers and network with margin.
- Test event storms and buffer overflow; critical alarms/controls must remain usable.
- Use deadband and reporting intelligently—never to hide quality or breaker position changes.
- Measure failover/reconnect and duplicate/missing event behavior.
14. Alarm and event philosophy
- Assign priority from required operator response/consequence, not device vendor default.
- Use consistent equipment/bay/cause/action text.
- Differentiate protection operate, breaker failure, communication loss, bad quality and test/block state.
- Preserve source event time and indicate unsynchronized/estimated time.
- Define acknowledgment, shelving, suppression and flood handling with audit.
- Correlate redundant duplicate alarms without hiding independent path failures.
- Periodically rationalize standing/chattering alarms and verify field cause.
15. Handover package
- SLD/topology and network/security/authority diagrams.
- SCD, point list, IEC 104 interoperability profile and gateway database.
- HMI graphics/alarm philosophy, user roles and operating procedures.
- Server/gateway/switch/time firmware and configuration backups.
- FAT/SAT point-to-point, failure, failover and cyber results.
- As-left hashes, asset identities, licences, spares and restore instructions.
- Maintenance regression set and periodic control/authority/failover tests.
References and further reading
- IEC 61850-8-1 consolidated edition — MMS, reports, controls and GOOSE
- IEC 60870-5-104 consolidated edition — Network telecontrol protocol
- IEC TS 60870-5-604:2016 — IEC 104 conformance tests
- IEC 61850-6 edition 2.2 — SCL
- IEC 62351-6:2020 — IEC 61850 security
- IEC 62443-3-3:2013 — System security requirements
Engineering note: Protection should not wait for SCADA, and SCADA should never mask bad process quality. Preserve local autonomy and carry the source semantics to the operator/control center.