Select-before-operate (SBO) reduces wrong-object and stale-intent risk; direct operate reduces transaction steps and latency. Neither model makes an unsafe switching scheme safe. The final security depends on fresh process state, exclusive control authority, interlocks, command origin, positive termination, independent position feedback, communications behavior and disciplined operator design.
This guide compares IEC 61850 normal/enhanced direct and SBO control concepts and relates them to IEC 60870-5-104/DNP3 remote-control workflows for MV breakers, disconnectors and earthing switches.
1. The four practical IEC 61850 control models
| Model | Sequence | Result assurance | Typical use |
|---|---|---|---|
| Direct with normal security | Operate | Service response plus process feedback | Low-consequence or tightly controlled automatic action |
| SBO with normal security | Select, then operate | Selection ownership plus response/feedback | Operator control needing wrong-object protection |
| Direct with enhanced security | Operate, command termination | Positive/negative termination plus feedback | Fast single-step action requiring explicit result |
| SBO with enhanced security | Select, operate, command termination | Selection and explicit completion/failure | High-consequence operator switching |
Product and project implementation must be confirmed from the IEC 61850 model/SCL and conformance documentation. “Enhanced security” here refers to the IEC 61850 control-service result sequence; it is not a claim of encryption or cybersecurity.
2. Direct operate sequence
- Client identifies the exact control object and desired state.
- Client sends the operate request with origin, control number and required parameters.
- IED validates authority, object state, test/check conditions and command consistency.
- Application logic evaluates interlock/synchrocheck and drives the output if permitted.
- Client receives service response; enhanced model also provides command termination.
- Independent auxiliary-contact/process feedback confirms the final equipment state.
The one-step model is efficient, but a mistaken object reference can immediately reach the control logic. HMI confirmation dialogs and server-side validation remain important.
3. SBO sequence
- Client requests selection of one object/state according to the implemented SBO service.
- IED accepts or rejects and reserves the selected object for that client/origin context.
- HMI presents the selected device, current state, target state, authority and checks.
- Operator/client issues operate within the configured selection timeout.
- IED confirms that operate matches the selection and re-evaluates all required conditions.
- Selection is consumed, cancelled or times out; final result and process feedback are returned.
Selection is temporary intent, not an interlock bypass and not proof the switching conditions will still be valid at operate time. Conditions must be checked again when the operate request is executed.
4. Risk comparison
| Risk/criterion | SBO | Direct operate |
|---|---|---|
| Wrong object/operator slip | Better defense through explicit reservation/second step | Relies more on HMI/client and server validation |
| Latency/transactions | Higher | Lower |
| Client/network loss between steps | Must release/expire selection safely | No selection state |
| Concurrent clients | Reservation can serialize one object | Authority/arbitration still needed |
| Automation simplicity | Additional state machine | Simpler for deterministic schemes |
| Stale condition protection | Not inherent; recheck at operate | Not inherent; check at operate |
| Cyber authentication | Not inherent | Not inherent |
5. Which MV devices deserve SBO?
- Remote operator breaker control: SBO with enhanced result handling is often justified, especially where many similar bays are displayed.
- Disconnectors/earthing switches: high consequence, topology dependency and slower motion favor deliberate SBO plus strong interlocks.
- Station-local HMI: SBO can still be valuable; physical proximity does not remove wrong-object risk.
- Automatic transfer/load-shedding: direct control may be appropriate when a validated automatic state machine must act promptly and object identity is fixed.
- Maintenance/test commands: segregate roles/modes and prevent accidental production operation.
- Emergency trip: should not be delayed by an operator-style selection workflow if the safety/protection philosophy requires immediate trip.
6. Selection timeout and ownership
- Set a timeout long enough for the intended operator workflow but short enough to avoid a forgotten lock.
- Show selection owner and remaining/expired state at the HMI where supported.
- Define behavior on client disconnect, redundant-client failover, IED restart and mode change.
- Reject another client’s operate unless the project intentionally defines an arbitration method.
- Cancellation should be explicit on operator cancel or page/context change where feasible.
- Alarm repeated selection failures or an object remaining reserved abnormally.
- Use synchronized event/audit logs to reconstruct select, operate, cancel, timeout and result.
7. Control checks and interlocks
IEC 61850 control requests can indicate whether interlock and synchrocheck checks are expected, but project implementation and safety logic must be explicit. A client cannot safely declare the power system interlocked; the authoritative logic should be close to the process and independent of the remote WAN.
- Fresh, valid open/closed/intermediate position.
- Correct local/station/remote authority and device service state.
- Breaker truck, disconnector and earthing-switch topology.
- Spring charged, mechanism ready, DC healthy and trip/close circuit available.
- Protection lockout, breaker failure, arc/bus trip and maintenance blocks.
- Synchrocheck/dead-bus/live-bus criteria for closing where required.
- Re-check every dynamic condition at operate, even after a successful select.
8. Normal versus enhanced security result handling
A service acceptance means the communication/service request was accepted; it is not equivalent to current interruption or contact closure. Enhanced control models add command-termination behavior so the server can report positive or negative completion. Even then, the SCADA application should correlate termination with an independent XCBR/XSWI position and discrepancy timer.
- Differentiate service error, application rejection, output operation and final primary state.
- Present LastApplError/additional cause information in useful operator diagnostics.
- Do not automatically repeat a timed-out close/open without verifying actual position and cause.
- Handle late feedback after timeout without issuing a contradictory second command.
- Record partial/inconsistent outcomes as alarms requiring investigation.
9. HMI human-factors requirements
- Use one-line topology matching physical bay labels and distinguish open/closed/intermediate/invalid.
- Selection highlighting must be unmistakable and disappear on timeout/cancel.
- Confirmation should state station, voltage, bay, device, current state and requested state.
- Show authority, interlock/synchrocheck availability and bad/stale quality before operate.
- Do not preselect a dangerous default action when the dialog opens.
- Prevent double-clicks, duplicate requests and commands from stale cached screens.
- Return precise rejection/termination reason rather than generic “command failed.”
10. Communications and redundancy
- Define what happens if the response is lost after the IED has executed the command.
- Use unique control numbers/origin and server logic to detect duplicates as supported.
- During gateway/HMI failover, only one active authority may originate commands.
- For SBO, failover must not inherit an ambiguous selection unless explicitly supported/tested.
- Prohibit remote control when process state/reporting is not fresh enough for safe operation.
- Keep local emergency/manual operation available according to the switchgear safety philosophy.
- Measure end-to-end control and feedback times under worst event/network load.
11. IEC 104 and DNP3 translation
A gateway mapping IEC 61850 controls to IEC 104 or DNP3 must preserve select/direct semantics, command qualifier/value, timeout, origin where possible, activation/termination and feedback. The two sides are not bit-for-bit identical. Document every semantic that cannot be carried, where the state machine resides and how gateway restart behaves mid-command.
- Never implement a northbound select as only an HMI visual selection if the server-side reservation is required.
- Do not report successful IEC 104 activation or DNP operate response until the defined underlying stage has completed.
- Prevent one northbound master from operating an object selected by another.
- Map negative termination/rejection to an actionable cause and alarm.
- Test command sequences with packet loss, duplicate frames, delayed responses and gateway reboot.
12. Cybersecurity requirements
- SBO is not authentication, authorization, integrity protection or encryption.
- Enforce unique users/roles at HMI/control center and least privilege at IED/gateway.
- Use relevant IEC 62351 security profiles where supported and proven interoperable.
- Protect command pathways with network zoning, allowlists, secure remote access and monitoring.
- Log user, client, origin, object, selection, operate, result, feedback and configuration change.
- Rate-limit/alarm command abuse without blocking required emergency operation.
- Manage certificates/keys/time and incident recovery as operational dependencies.
13. FAT/SAT test matrix
- Verify the configured control model from SCL and actual IED model.
- Execute valid direct/SBO sequences and measure response, termination and feedback.
- Attempt operate without select, wrong object/value, wrong client and expired selection.
- Change interlock, authority, position quality and synchrocheck between select and operate.
- Cancel selection; disconnect/restart client; restart IED/gateway during selection.
- Lose response after execution and verify no blind duplicate command.
- Fail redundant client/gateway and test split-brain prevention.
- Test mechanism failure, no position change, intermediate state and late feedback.
- Generate event storm/network loading and verify bounded control performance.
- Attempt unauthorized role/network command and inspect audit/alarms.
- At SAT, operate actual breaker/switch under approved safe conditions.
- Archive packet captures, event logs, timings, as-built settings/SCL and defects.
14. Decision rules
- Choose SBO when operator wrong-object risk and multi-client serialization justify the extra state/latency.
- Choose direct operate for fixed, validated automatic functions where selection adds no meaningful safety and timing matters.
- Prefer enhanced result handling for consequential primary-equipment commands.
- Use independent process feedback for every model.
- Never use SBO as a substitute for interlocking, fresh data, exclusive authority or cybersecurity.
- State the choice per controllable object in the SCL/point database and test specification.
References and further reading
- IEC 61850-8-1 consolidated edition — MMS mapping and control services
- IEC 61850-7-2 consolidated edition — ACSI control models
- IEC 61850-6 edition 2.2 — SCL configuration
- IEC 60870-5-104 consolidated edition — Telecontrol commands
- IEC 62351-5:2023 — Security for IEC 60870-5 derivatives
- IEC 62351-6:2020 — Security for IEC 61850 profiles
- UCAIug conformance certificate example — tested IEC 61850 control blocks
Engineering note: Select confirms temporary intent; operate requests action; command termination reports application outcome; only independent primary position proves the equipment state.