IEC 61850
IEC 61850 includes several models and communication services. Identify the service, timing requirements and engineering context before designing a gateway or data consumer.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
The IEC 61850 and IEC 62351 normative publications are licensed and versioned per part; exact editions, amendments, engineering profiles, SCL schema, conformance blocks, and product records are required for implementation.
On this page
Overview#
IEC 61850 is a multipart standards family for power utility automation communication and engineering. It combines semantic information models, abstract services, configuration language, and communication mappings. It isn't one wire protocol and doesn't have one family wide edition number: each part, amendment, technical report, and schema has its own status. IEC61850 SERIES
IEC 61850 appears in substations, distributed energy systems, microgrids, and gateways that can affect a site's electrical resilience. It can carry monitoring data, but it also supports protection and control functions with severe physical consequences. General physical security integrations should remain read only and isolated from protection/control paths unless they form part of the approved engineered power system.
Parts and layers#
| Area | Common IEC 61850 part | Purpose |
|---|---|---|
| General/requirements | Parts 1 to 5 | Scope, terminology, requirements, project and communication context |
| Configuration | Part 6 | System Configuration Language (SCL) and engineering exchange |
| Concepts | Part 7-1 | Basic communication structure and modelling principles |
| Services | Part 7-2 | Abstract Communication Service Interface (ACSI) |
| Common data classes | Part 7-3 | Reusable typed data structures and attributes |
| Logical nodes/data objects | Part 7-4 and domain extensions | Standard semantic names and compositions |
| MMS and Ethernet mapping | Part 8-1 | Mapping of relevant services to MMS and Ethernet, including GOOSE |
| Sampled Values mapping | Part 9-2 | Sampled Values communication |
| Conformance testing | Part 10 | Conformance test framework |
| Time synchronisation profile | IEC/IEEE 61850-9-3 | Precision Time Protocol profile for power utility automation |
| Cybersecurity | IEC 62351 series, especially Part 6 for IEC 61850 | Security mechanisms plus related transport, role, and key management parts |
Engineering must pin every applicable part and schema edition. “Edition 2,” “Ed. 2.1,” or “IEC 61850 compliant” without a part list, conformance statement, and product capability record isn't an actionable interoperability claim.
Semantic model#
The model organizes a server/IED into logical devices, logical nodes, data objects, and data attributes. Logical node classes and standardised data object names carry domain meaning; common data classes define structured values and service related attributes.
IED / server
logical device
logical node
data object
data attribute
value + quality + timestamp and other class-defined attributes
An integration point should retain:
- IED/server identity, logical device instance, logical node class and instance;
- complete object reference and functional constraint;
- data object and attribute names, common data class, base type, range, unit, multiplier, and configuration revision;
- value, quality, timestamp, and source/report provenance;
- namespace/model extension and the applicable part or vendor profile;
- dataset/report control association where delivered by reports;
- command model and authority where the object is controllable.
Don't normalise a data attribute to a scalar while discarding quality and timestamp. Quality can express validity, source, test, operator blocking, and detail flags. An old but numerically plausible measurement must not appear current or valid.
Names are semantic only inside the applicable model and edition. Vendor/private logical nodes, data objects, and namespaces require an explicit mapping; similarity to a standard abbreviation isn't proof of equivalent behaviour.
ACSI is an abstraction#
The Abstract Communication Service Interface defines services for data access, datasets, reporting, logging, controls, setting groups, files, Generic Substation Events, and Sampled Values at an abstract level. Part 8-1 and Part 9-2 map relevant services to concrete communication profiles.
Avoid treating ACSI terminology as literal wire encoding. A product API, MMS object, GOOSE dataset, and SCL element can represent related concepts while having different lifecycle and security behaviour. Bind the semantic object reference to the actual mapping, dataset, and configured IED revision.
System Configuration Language#
SCL is XML based engineering exchange defined by IEC 61850-6. Common file roles include:
| File type | Typical role | Boundary to verify |
|---|---|---|
| SSD | System specification description | Requirements/topology intent; not an as built device configuration |
| ICD | IED capability description | Product capability offered for engineering |
| SCD | System configuration description | Integrated system design and communication/data flow configuration |
| CID | Configured IED description | Configuration intended for a particular IED |
| IID | Instantiated IED description | IED specific instantiated information used in engineering exchange |
Exact file roles and allowed content depend on the applicable SCL edition and workflow. Preserve schema version, tool and product version, project revision, source, approval, and cryptographic hash. Validate XML securely: disable external entities and unapproved external retrieval, cap size/depth/counts, resolve namespaces exactly, reject duplicate identities/references, and require referential integrity.
SCL can reveal network topology, multicast addressing, IED capabilities, datasets, control blocks, protection functions, and engineering access. Treat it as sensitive operational configuration. A syntactically valid file isn't safe to import; use schema, semantic, cross reference, edition, product capability, and change impact review.
Client/server and MMS#
Part 8-1 maps client/server behaviour to Manufacturing Message Specification (MMS) and associated network profiles. Typical functions include reading data, datasets, reporting, logs, controls, and file access. TCP port 102 is an IANA convention associated with ISO TSAP and is often relevant to MMS profiles; it isn't proof that a listener is IEC 61850 or authorised. IANA PORTS
Client/server sessions need explicit limits for association, outstanding requests, dataset size, report queueing, file size, idle/max lifetime, and reconnect. Separate:
- transport connection;
- MMS association and application identity;
- IEC 61850 service result;
- control termination or other asynchronous result;
- authoritative process state.
Reports, datasets, and data continuity#
Report Control Blocks select datasets and govern buffered or unbuffered reporting. Important configuration includes trigger options, integrity period, buffer time, reservation/ownership, configuration revision, sequence number, entry identifier, time of entry, and optional fields.
- Buffered reports can preserve events across a client disconnection subject to device buffer limits and configuration.
- Unbuffered reports don't provide that recovery property.
- Integrity reports and general interrogation/reconciliation serve different purposes from event delivery.
- Dataset/configuration changes can invalidate assumptions even when object names still resolve.
Expose report gaps, buffer overflow, sequence discontinuity, configuration revision mismatch, and stale subscription state. Don't silently resume from “now” and present the resulting event record as complete.
Controls#
IEC 61850 control models can include direct operation or select before operate and can use normal or enhanced security service behaviour. Control attributes carry model specific checks, origin information, control numbers, timestamps, test state, and response/termination behaviour.
Protocol control stages don't establish physical outcome:
authorization -> select (where required) -> operate request
-> service response -> command termination/status
-> process indication/measurement -> confirmed outcome
Keep each stage and failure reason. A timeout after an operate request is indeterminate until the authoritative process state is reconciled. Never automatically retry a protection, breaker, tap, output, or other non idempotent control based only on a transport or service timeout.
GOOSE#
Generic Object Oriented Substation Event (GOOSE) communication uses publisher/subscriber multicast at the data link layer under the Part 8-1 mapping. It is designed for time sensitive state/event exchange and uses repeated transmissions with state and sequence indicators to improve delivery probability. It has no transport connection or per subscriber application acknowledgment.
For every subscribed dataset preserve publisher identity, control block reference, dataset reference, application identifier, configuration revision, state number, sequence number, time allowed to live, quality, and arrival interface/path as applicable. Validate ordering and state changes under the selected edition/profile. A received Ethernet multicast frame isn't proof that an intended protection subscriber accepted or acted on it.
GOOSE multicast containment is a switch/VLAN and engineering design concern. Avoid bridging it into a general corporate or physical security multicast domain. Duplicate paths, topology changes, replay, misconfiguration, and publisher restart can create plausible repeated or stale states.
Sampled Values#
Sampled Values carry time related sampled measurements, commonly over Ethernet multicast under Part 9-2. Their rate and timing sensitivity are fundamentally different from ordinary event telemetry. Record sampled value control block, dataset, stream identifier, application identifier, configuration revision, sample counter/rate profile, synchronisation state, quality, and loss/reordering policy.
Don't route raw Sampled Values into a general integration platform by default. High packet rate, multicast replication, time dependence, and protection use can affect both operational safety and platform availability. If business monitoring needs an electrical measurement, obtain it through an approved lower rate read/report gateway designed by the power system owner.
Time and synchronisation#
Timestamp and time quality semantics affect event ordering, fault analysis, and protection behaviour. IEC/IEEE 61850-9-3 defines a Precision Time Protocol profile used in power utility automation, while products can expose other supported time methods for less stringent functions.
Document clock source, grandmaster identity/path where applicable, accuracy class, synchronisation/holdover state, time quality mapping, UTC/leap behaviour, and monitoring. Receipt time isn't source time. Never let a general integration service reconfigure utility time distribution or infer trustworthy ordering from a timestamp whose quality is unknown.
Cybersecurity#
IEC 62351-6:2020 covers security for IEC 61850 profiles and works within a broader IEC 62351 family that includes TCP/IP transport security, MMS related profiles, role based access control, and key management. Exact applicability differs across client/server, GOOSE, and Sampled Values. IEC62351 6 IEC61850 CYBER
An engineering security profile should define:
- IED/application identity, certificate/trust lifecycle, roles, and authorisation;
- selected IEC 62351 parts/editions and product conformance evidence;
- protection for MMS association and client/server services;
- GOOSE/Sampled Values origin, integrity, replay, latency, and key management behaviour;
- management, engineering, SCL, firmware, test, and time service access;
- algorithm agility, renewal, failover, restore, revocation, and degraded mode behaviour;
- network segmentation and exact permitted publishers, subscribers, clients, and servers.
Cryptographic controls don't replace deterministic performance and fail safe engineering. Conversely, a dedicated VLAN, multicast filter, or station bus doesn't provide cryptographic source authenticity.
Physical security integration boundary#
Useful read only correlations can include power system health, loss of supply, equipment alarm, environment state, and gateway health. Keep protection trips, interlocks, GOOSE/Sampled Values, breaker control, setting groups, files, and time changes out of an ordinary security platform path.
station/process networks
|
v
power-owner approved IEC 61850 client or gateway
- explicit object/report allowlist
- no control, file, setting, or engineering services
- bounded reports and reconciliation
- quality/time/configuration revision preserved
|
v
one-way or tightly controlled normalized monitoring interface
|
v
physical-security event correlation
Don't configure live reports, browse an IED model, retrieve SCL/files, subscribe to GOOSE/Sampled Values, or test controls merely to validate documentation. Review approved SCL exports, capability/conformance records, synthetic fixtures, and owner provided evidence; leave operational acceptance to the power system owner under site procedures.
Failure cases to design#
- IED restarts with a changed configuration revision or incomplete report buffer;
- buffered report resume point is unavailable and event continuity is lost;
- dataset members or functional constraints change while display labels remain familiar;
- GOOSE publisher restarts, duplicates traverse redundant paths, or time allowed to live expires;
- Sampled Values lose synchronisation, packets, or expected rate while values remain plausible;
- SCL import is valid XML but incompatible with the IED, edition, namespace, or as built network;
- control service succeeds but command termination or process feedback fails;
- certificate/key rollover causes partial communication loss across redundant devices;
- a gateway flattens invalid/questionable quality to a normal numeric value;
- general network multicast or scanning affects deterministic station/process traffic.
Design and evidence checklist#
- Every applicable IEC 61850/62351 part, edition, amendment, SCL schema, and product conformance block pinned
- IED, logical device/node, object/attribute, functional constraint, common data class, and namespace retained
- Value, quality, timestamp, configuration revision, report/dataset provenance, and stale state preserved
- SCL source, hash, approval, tool/product version, schema, referential integrity, and change impact controlled
- MMS association, request limits, reports, files, reconnect, and authorisation bounded
- Buffered/unbuffered reporting, sequence/gap, buffer overflow, reservation, and resynchronization defined
- Control stages and authoritative process confirmation represented separately
- GOOSE/Sampled Values publisher, dataset, revision, sequence/time, multicast, and loss policy explicit
- Time source, synchronisation quality, holdover, and evidence uncertainty documented
- Applicable IEC 62351 identity, role, transport/message, key, restore, and degraded mode controls verified
- Physical security integration is read only and isolated from protection/control and engineering paths
- Evidence retains source configuration and quality rather than presenting normalised values as self proving facts
Sources#
- IEC61850 SERIES, IEC 61850 series collection, IEC Webstore, accessed 25 August 2026.
- IEC61850 PRINCIPLES, IEC 61850 technical principles, IEC 61850 official domain, accessed 25 August 2026.
- IEC61850 CYBER, IEC 61850 cybersecurity overview, IEC 61850 official domain, accessed 25 August 2026.
- IEC62351 6, IEC 62351-6:2020, IEC, security for IEC 61850.
- IANA PORTS, Service Name and Transport Protocol Port Number Registry, IANA,
iso-tsapentry, accessed 25 August 2026.