SCADA Architecture for MV Switchgear: IED, RTU, Gateway, HMI and Control Center

A complete station-to-control-center architecture guide for data ownership, MMS reporting, IEC 104 mapping, remote control, failure modes and cybersecurity.

A robust MV SCADA architecture preserves local protection during loss of HMI, gateway or control-center communication while providing unambiguous, secure and time-consistent monitoring/control. The IED, RTU, gateway, station HMI and control center have different responsibilities; duplicating logic or authority across them creates inconsistent states and unsafe remote switching.

This guide designs the complete station-to-control-center path using IEC 61850 MMS/GOOSE and IEC 60870-5-104, with data ownership, command authority, redundancy, cybersecurity, failure modes and FAT/SAT.

1. Functional layers

LayerPrimary roleShould remain independent from
Protection/control IEDProtection, local control, measurements, event/report sourceControl-center availability
RTU/station gatewayProtocol/data concentration, telecontrol interface, bufferingPrimary protection decision
Station HMI/controllerLocal operation, single-line, alarms, station automationRemote WAN availability
Control-center SCADAFleet supervision, remote control, alarm/event operationsFast local interlocking/protection
Engineering/asset systemsSettings, configuration, records and maintenanceRoutine operator control path

2. Typical information flow

  • IEDs provide IEC 61850 MMS reports, controls, measurements, events and files to station clients.
  • GOOSE remains station/process peer-to-peer for protection/interlocking, not normally routed through a control center.
  • Gateway maps selected IEC 61850 data/control semantics to IEC 60870-5-104 or another control-center protocol.
  • Station HMI subscribes to reports and executes local commands under authority/interlock rules.
  • Control center receives curated points/quality/time and sends authorized commands.
  • Engineering file/settings access uses a separate controlled path.

3. IED responsibilities

  • Protection and breaker-failure logic must not depend on RTU/HMI/WAN.
  • Acquire primary status/measurements with value, quality and timestamp.
  • Execute local interlocking/synchrocheck or provide required distributed interface.
  • Expose standardized LNs/data objects and report/control behavior.
  • Store events/disturbance records through station communication loss.
  • Supervise breaker trip circuit/device health and communication.
  • Enforce local/remote, test, blocked and operator authority states.

4. RTU/gateway responsibilities

  • Terminate/control approved station and telecontrol protocol connections.
  • Map IEC 61850 object value, quality, time and control semantics without silent loss.
  • Perform data concentration, scaling/deadband and event buffering only under approved rules.
  • Maintain control select/execute/cancel and feedback correlation.
  • Manage WAN redundancy and reconnect/backfill.
  • Expose gateway/IED communication quality distinctly from process quality.
  • Keep mapping/database version tied to the SCD and point list.

5. HMI design

  • Single-line matches physical bay names/topology and shows intermediate/invalid states.
  • Quality/time/stale/communication failure is visible; do not freeze a value as healthy.
  • Alarm priority, grouping, shelving and acknowledgment follow consequence/operations rules.
  • Control dialogs show device, command, authority, interlock/synchrocheck and final feedback.
  • Test/simulation/override/block states are prominent.
  • Redundant HMI servers/clients have defined failover and no duplicate commands.
  • Operator actions are uniquely audited with time and result.

6. Point-list and semantic mapping

Point fieldRequired content
SourceIED/LD/LN/DO/DA or RTU input and physical equipment
SCADA addressIEC 104 common address/IOA/type or target protocol mapping
ValueSingle/double point, measured type, units, scale/deadband
Quality/timeSource quality mapping, timestamp origin/class, stale rule
ControlSBO/direct, qualifier/pulse, authority, interlock and feedback
AlarmPriority, text, normal state, delay, grouping and responsibility
TestFAT/SAT case, simulator/source, expected result

7. Reporting and event handling

  • Engineer buffered/unbuffered report controls, datasets, triggers, optional fields, integrity and GI.
  • Provide enough report instances/reservations for redundant HMI/gateway clients.
  • Test reconnect, buffer overflow and event order after outage.
  • Use source timestamps and preserve time quality through gateway.
  • Distinguish process change, communication restore and substituted value.
  • Control measurement deadband so protection-relevant/operational changes are not hidden.
  • Do not flood SCADA with high-rate process-bus data not needed operationally.

8. Remote control chain

  1. Operator selects exact device and intended action.
  2. SCADA verifies user role, authority and fresh topology/quality.
  3. Command passes through approved WAN/gateway protocol mapping.
  4. IED/station control checks local/remote, interlock/synchrocheck and control model.
  5. Output operates breaker/switch.
  6. Independent position feedback and termination return.
  7. Timeout/discrepancy creates an alarm; no blind repeated command.

9. Control authority

  • Define hierarchy: bay local, station HMI, remote control center and automatic schemes.
  • Only one authority should command a device at a time, with visible mode.
  • Local emergency control and interlock bypass are different states.
  • Loss of HMI/WAN should not unexpectedly transfer authority without indication.
  • Stale/invalid position must normally reject remote control.
  • Record mode changes and control origin.
  • Test conflicting/simultaneous commands and client failover.

10. Redundancy and failure modes

FailureExpected behavior
One IED/network pathFunction-specific redundancy/quality alarm; local protection maintained as designed
Gateway failureStandby failover or remote loss; local HMI/protection remain
HMI server/clientRedundant client/server or local bay control remains
WAN/control centerStation continues; events buffered; authority clear
Time sourceProtection/time-specific fallback; events marked unsynchronized
Database/mapping errorPrevented by version/independent point-to-point SAT
DC/common switchPhysical independence and alarms prevent common outage

11. Cybersecurity

  • Segment station, gateway/DMZ, control-center and engineering zones.
  • Permit only required MMS, IEC 104, time and management conduits.
  • Use IEC 62351 mechanisms supported for relevant protocols and test interoperability.
  • Unique accounts/roles, jump-host remote access, audit and least privilege.
  • Protect SCD/point databases/HMI graphics/settings and gateway mapping.
  • Monitor unauthorized command, login, configuration, protocol anomaly and time change.
  • Back up/restore redundant servers/gateways and maintain incident manual-control procedures.

12. FAT/SAT

  1. Freeze SCD, point list, gateway/HMI database, graphics and protocol settings.
  2. Point-to-point test every status, measurement, quality, time, alarm and control.
  3. Test IEC 61850 reports/controls and IEC 104 mapping/conformance profile.
  4. Verify local/station/remote authority, SBO/direct and interlock rejection.
  5. Fail IED links, station LAN, gateway, HMI, WAN and time source.
  6. Test redundant client/server/gateway failover and return without duplicate controls.
  7. Test buffer/reconnect/event ordering, bad quality and stale data.
  8. Validate cyber allow/deny rules, accounts, logs and backup restore.
  9. At SAT, operate actual switchgear and verify control-center round trip.
  10. Archive as-built databases/configurations/hashes and results.

13. Capacity and performance engineering

  • Count MMS clients/report instances, gateway points, IEC 104 connections, command rate and future bays.
  • Model normal telemetry plus disturbance-event bursts, integrity scans, reconnect backfill and file transfers.
  • Specify end-to-end status/alarm/control response and timestamp accuracy by function.
  • Size gateway/HMI CPU, memory, storage, event buffers and network with margin.
  • Test event storms and buffer overflow; critical alarms/controls must remain usable.
  • Use deadband and reporting intelligently—never to hide quality or breaker position changes.
  • Measure failover/reconnect and duplicate/missing event behavior.

14. Alarm and event philosophy

  • Assign priority from required operator response/consequence, not device vendor default.
  • Use consistent equipment/bay/cause/action text.
  • Differentiate protection operate, breaker failure, communication loss, bad quality and test/block state.
  • Preserve source event time and indicate unsynchronized/estimated time.
  • Define acknowledgment, shelving, suppression and flood handling with audit.
  • Correlate redundant duplicate alarms without hiding independent path failures.
  • Periodically rationalize standing/chattering alarms and verify field cause.

15. Handover package

  • SLD/topology and network/security/authority diagrams.
  • SCD, point list, IEC 104 interoperability profile and gateway database.
  • HMI graphics/alarm philosophy, user roles and operating procedures.
  • Server/gateway/switch/time firmware and configuration backups.
  • FAT/SAT point-to-point, failure, failover and cyber results.
  • As-left hashes, asset identities, licences, spares and restore instructions.
  • Maintenance regression set and periodic control/authority/failover tests.

References and further reading

Engineering note: Protection should not wait for SCADA, and SCADA should never mask bad process quality. Preserve local autonomy and carry the source semantics to the operator/control center.

LearnSwitchgear

Search the engineering library