Virtual I/O Testing and Simulation During IEC 61850 FAT

A safe FAT method for virtual publishers/subscribers, GOOSE/SV fault injection, automation, physical-output isolation and SAT handover.

Virtual I/O testing must prove the same cause-and-effect chain as hardwired I/O while preventing simulated traffic from operating live plant. A test set can publish GOOSE or SV, subscribe to outputs and emulate IEDs, but a green packet check is not enough: the SCL mapping, quality, test/simulation states, logic, timing, alarms, output isolation and restoration must all be verified.

This guide defines a safe IEC 61850 FAT method for virtual inputs/outputs, including test architecture, simulation acceptance, negative cases, automated evidence and transition to SAT.

1. What counts as virtual I/O

  • GOOSE subscription replacing a binary input.
  • GOOSE publication replacing a hardwired trip/status output.
  • SV stream replacing analogue CT/VT relay inputs.
  • MMS reports/controls replacing conventional SCADA points.
  • Simulated publisher/subscriber or merging unit in a test set/software.
  • Virtual process model driving breaker/disconnector/interlock states.
  • Captured/replayed network traffic—only under a controlled, isolated method.

2. FAT objectives

ObjectiveEvidence
Correct mappingSource LN/DO/DA/dataset to intended subscriber input/application
Correct functionProtection/interlock/control result and physical/virtual output
PerformanceDefined application-to-application and total operating time
Bad-data responseTimeout, quality, ConfRev, loss/jitter and time failure behavior
Safe test modeNo unauthorized live output; visible modes/blocks
RecoverabilityNormal operation after test removal, reboot and configuration restore

3. Freeze the test baseline

  • Approved SCD, ICD/IID/CID/device files and semantic change report.
  • IED hardware, firmware, options, settings and enabled subscriptions.
  • Switch, VLAN, multicast, QoS, PRP/HSR and PTP configurations.
  • GOOSE trip/interlocking and SV channel matrices.
  • Test-set software, licence, adapter and calibrated timing version.
  • Output-isolation and energized-plant boundary plan.
  • Unique test case IDs and pass limits linked to requirements.

4. Test architecture

  • Closed FAT network: preferred for unrestricted negative traffic and timing tests.
  • Bay-isolated test VLAN/ports: requires proven filters and physical output isolation.
  • Test set as publisher: emulates GOOSE/SV with exact SCL parameters.
  • Test set as subscriber: captures publication values, counters and time.
  • Hardware-in-the-loop: real IEDs/process I/O with a primary-process simulator.
  • Virtual IED/digital model: scalable but must have a validated fidelity boundary.

Document which components are real, simulated and bypassed. A result cannot claim complete end-to-end proof if the output module, DC trip circuit or breaker mechanism was not included.

5. Test and simulation semantics

IEC 61850 supports quality/test and simulation mechanisms, but exact activation and acceptance vary by device/edition. The method must state publisher flag/state, subscriber simulation enable, logical-node/device behavior and physical-output policy.

  • Use the standardized test/simulation mechanisms supported by the IED—not an undocumented address swap.
  • Ensure the subscriber accepts a simulated stream only when explicitly enabled.
  • Make test/simulation/block status visible locally and at HMI.
  • Log who enabled it and when.
  • Prevent simultaneous ambiguous live and simulated publishers.
  • Define behavior if the test set or network is lost while simulation is enabled.
  • Require independent restoration to normal mode.

6. Output safety

  • Physically isolate trip/close circuits where an unintended output could operate plant or endanger personnel.
  • Use relay/device output blocking only when its behavior is proven and clearly indicated.
  • Separate logic test from output proof; later test the real output under a controlled plant condition.
  • Verify dual trip coils and process I/O outputs individually.
  • Prevent a simulated permissive/interlock from being retained after test.
  • Label temporary fibers/test ports and apply lockout/tagout.
  • Include restoration of test switches, MCBs, links and settings in the test record.

7. GOOSE positive tests

  • Assert/reset each dataset member and confirm intended subscriber application.
  • Verify stNum change, sqNum retransmission and stable heartbeat.
  • Measure source change to subscriber application/output.
  • Confirm unintended IEDs do not act.
  • Test simultaneous members and events.
  • Verify quality/timestamp/logs/HMI indication.
  • Trace test result to matrix row, SCL control block and subscriber ExtRef.

8. GOOSE negative tests

  • Stop publisher and verify timeAllowedToLive timeout/fail-safe action.
  • Drop, delay, duplicate and reorder frames.
  • Restart publisher/subscriber and verify no false command.
  • Change APPID, MAC, VLAN, GoID, ConfRev or dataset member order.
  • Emulate adjacent-bay publisher and duplicate source.
  • Apply invalid/questionable/test quality and simulation states.
  • Fail each PRP/HSR path and apply representative network load.

9. SV tests

  • Publish exact rate/profile/frame structure, channel order and scaling.
  • Inject phase current/voltage, residual/neutral, polarity and phase rotation.
  • Test low/rated/protection range, frequency and transient behavior appropriate to function.
  • Introduce sample loss, duplicate, delay, out-of-order and stream timeout.
  • Change svID, APPID, ConfRev, rate and dataset order.
  • Apply bad quality/test/simulation and loss/drift/step of time synchronization.
  • Verify function-specific block/restraint/fallback and operating time.

10. MMS, HMI and control tests

  • Reports: trigger, quality, timestamp, integrity/GI, buffered recovery and overflow.
  • Controls: direct/SBO, origin, interlock/synchrocheck, termination and rejection reason.
  • Client loss/reconnect and duplicate clients.
  • Gateway mapping and command source.
  • Test-mode indication and alarm routing.
  • Event chronology across IEDs.
  • Settings/configuration access restrictions during FAT and operation.

11. Automation without false confidence

Automated tests improve repeatability and coverage, especially for hundreds of ExtRefs, but the script and expected result require independent review. Include equipment state, test mode and physical safety prerequisites before execution.

  • Generate cases from the approved matrix/SCD.
  • Version-control scripts and test-set configurations.
  • Record raw packet, IED event and measured output automatically.
  • Use deterministic cleanup after every failed/aborted case.
  • Require manual witness for critical physical trip/interlock tests.
  • Never replay captured live traffic on an operational network.
  • Report skipped/not-applicable cases explicitly.

12. Cybersecurity

  • Treat the test set as a privileged publisher and protect its access/configuration.
  • Isolate FAT networks and control connection to live station networks.
  • Scan removable media/files and validate SCL/test packages.
  • Use unique accounts and logs; remove temporary access after test.
  • Detect residual rogue/duplicate publishers.
  • Store captures securely because they reveal topology and protection behavior.
  • Repeat affected tests after security/firmware changes.

13. FAT completion and SAT handover

  1. Close defects and repeat all impacted cases.
  2. Clear simulation/test/subscription/output blocks and verify normal quality.
  3. Freeze SCD/CIDs/settings/switch/time and test scripts with hashes.
  4. Export result matrix, captures, events and calibration/uncertainty.
  5. Document virtual components not physically proven.
  6. Convert those gaps into SAT primary/contact/output/breaker cases.
  7. At site, verify installed fibers/ports and real primary association.
  8. After SAT, reconcile field changes and rerun affected regression.

14. Measurement and traceability

  • Synchronize the test set, packet capture and IED event sources or document correlation uncertainty.
  • Use a defined trigger point: simulated process change, published frame, subscriber application, binary output or breaker current.
  • Record minimum/maximum/distribution across repeated operations, not one favorable result.
  • Preserve raw PCAP, test-set COMTRADE/configuration, IED event report and output waveform.
  • Record network load, failed path, clock state, test/simulation flags and device CPU/application state.
  • Link evidence to requirement, matrix row, SCL control block and test case revision.
  • State calibration date and uncertainty for time/current/voltage measurements.

15. Virtual model fidelity limits

Virtual elementCan proveCannot prove alone
GOOSE publisherSubscriber mapping, logic, timeout and timingReal source contact/protection decision
SV publisherRelay algorithm, stream/quality/time responsePhysical sensor/MU accuracy and saturation
Virtual breakerSequence, interlock and breaker-failure logicCoil voltage, travel and arc interruption
Network emulatorControlled loss/delay/jitter/loadEvery vendor switch/optical/EMC behavior
Digital twinScalable scenario and regression testingBehavior outside its validated model boundary

16. FAT acceptance checklist

  • All publishers/subscribers trace to the released SCD.
  • Positive, negative, timeout, restart, test and redundancy cases are complete.
  • Physical outputs were isolated and every temporary state was restored.
  • Performance passed under specified load and single network failure.
  • Skipped physical chain elements appear in the SAT obligation list.
  • Automated scripts/results are versioned and independently reviewed.
  • As-left IED/network/time status is healthy and simulation disabled.

References and further reading

Engineering note: Virtual I/O is a test method, not a scope reduction. Any sensor, process output, DC trip circuit or breaker excluded from FAT must appear as an explicit SAT obligation.

LearnSwitchgear

Search the engineering library