IEC 60870-5-101 and IEC 60870-5-104 are the telecontrol protocols that grid operators and utilities use between control centres and remote stations: RTUs at substations, wind and solar farms, battery sites and large loads. IEC 101 runs on serial links. IEC 104 carries the same kind of application message over TCP/IP, on port 2404 by default. Many substations use IEC 61850 inside the station and keep IEC 104 for the link to the control centre.
The two point lists look alike, but the encodings differ in three places that matter for a retrofit: the link layer, the size of the address fields, and the time tags that are permitted.
The standards and editions
The current IEC 101 publication is IEC 60870-5-101:2003+AMD1:2015, consolidated edition 2.1. The current IEC 104 publication is IEC 60870-5-104:2006+AMD1:2016, consolidated edition 2.1, which includes the corrigendum of August 2023.
Each device has an interoperability list, a checklist from the standard that records which options it implements. Get the list for both ends before you write a point list. Compare these entries first. A mismatch in any of them stops the two ends understanding each other:
- balanced or unbalanced transmission (IEC 101);
- the octet counts of the link address, cause of transmission, common address and object address (IEC 101);
- which time-tagged types the device sends and accepts;
- which commands it accepts with a time tag, and whether it uses select-before-operate.
Side by side
| IEC 60870-5-101 | IEC 60870-5-104 | |
|---|---|---|
| Transport | Serial: RS-232, RS-485, modem or radio | TCP/IP over Ethernet or a WAN |
| Addressing of the station | Link address of 0, 1 or 2 octets | IP address and TCP port, 2404 by default |
| Link procedure | Unbalanced (the primary station polls) or balanced (either end can send) | Client and server over TCP, with STARTDT and STOPDT |
| Framing | FT1.2: fixed frames start 0x10, variable frames start 0x68 L L 0x68, both end 0x16 | APCI: start 0x68, one length octet, four control octets |
| Flow control | One outstanding frame; confirm or single character 0xE5 | Up to k numbered I frames outstanding; timers t0 to t3 |
| Cause of transmission | 1 or 2 octets | 2 octets |
| Common address | 1 or 2 octets | 2 octets |
| Object address | 1, 2 or 3 octets | 3 octets |
| Time-tagged types | CP24Time2a (3 octets) and CP56Time2a (7 octets) | CP56Time2a only: types 30 to 40 for monitoring, 58 to 64 for commands |
| Typical links | Point-to-point serial, radio, leased lines, multidrop lines with many outstations | Private IP networks, fibre WANs, cellular links with a private APN |
The IEC 104 field sizes are fixed by the standard. Some products let you change them. A device configured that way is no longer interoperable with a standard IEC 104 station.
How IEC 101 moves data
IEC 101 uses the FT1.2 frame format. A fixed-length frame carries only a control field and a link address, and is used for link functions such as a poll. A variable-length frame carries an ASDU. The single character 0xE5 is a positive acknowledgement.
In unbalanced mode, the controlling station is the only primary station. It polls each outstation in turn, and an outstation sends only when it is asked. Data is split into class 1 (high priority, usually events) and class 2 (low priority, usually cyclic values). An outstation sets the ACD bit in its reply when it has class 1 data waiting, and the controlling station then requests class 1 data. Unbalanced mode works on a multidrop line with many outstations.
In balanced mode, each end can start a transfer, so an outstation sends an event as soon as it happens. Balanced mode is limited to point-to-point and multiple point-to-point links.
On a multidrop line, the poll cycle sets the reporting latency. FT1.2 sends 11 bits per character, so at 9,600 bit/s the 19-octet reply in the example below takes about 22 ms on the line, and each poll adds a 5-octet request, two turnarounds and the outstation's response time. An event waits until the controlling station reaches that outstation in the cycle. If each exchange takes 60 ms including turnarounds, a line with 30 outstations has a cycle of about 1.8 s.
How IEC 104 manages a connection
Each IEC 104 frame (APDU) starts with a 6-octet APCI: the start byte 0x68, a length octet that counts the rest of the frame, and four control octets. The largest APDU is 255 octets. There are three frame formats:
- I frames carry an ASDU, with a 15-bit send sequence number N(S) and a 15-bit receive sequence number N(R);
- S frames carry only N(R), to acknowledge I frames when there is no data to send back;
- U frames carry STARTDT and STOPDT, which start and stop data transfer, and TESTFR, which tests an idle link.
A new TCP connection starts in the STOPDT state with both sequence numbers at zero. The controlled station sends no I frames until it receives STARTDT act and returns STARTDT con.
IEC 60870-5-104 gives these defaults:
| Parameter | Default | Meaning |
|---|---|---|
| k | 12 I frames | Largest number of I frames sent and not yet acknowledged. At k, the sender stops. |
| w | 8 I frames | The receiver acknowledges at the latest after w I frames. Recommendation: w not more than two-thirds of k. |
| t0 | 30 s | Time-out for connection establishment |
| t1 | 15 s | Time-out for an acknowledgement of a sent I frame or U frame. At t1, the sender closes the connection. |
| t2 | 10 s | Time-out for an acknowledgement when there is no data to send. t2 must be less than t1. |
| t3 | 20 s | Idle time before a TESTFR is sent |
When fewer than w frames arrive, the receiver waits for t2 before it sends an S frame. The acknowledgement therefore reaches the sender after t2 plus the transit time. With the defaults, that leaves 5 s for the round trip before t1 closes the connection. A cellular link with a 1 s round trip is inside that margin. A link that stalls for more than 5 s under load is not, and the symptom is a connection that closes and reopens during bursts of events. Increase t1, or reduce t2, so that t1 exceeds t2 plus the worst round trip you measure. Change the values at both ends at the same time.
Redundant connections
A controlled station can accept more than one TCP connection, for example from a main and a standby control centre. The connections form a redundancy group with one event queue, and only one connection in the group is active (in STARTDT) at a time. When the control centre switches to the standby connection, events that were sent but not acknowledged on the old connection must still be in the queue. When the queue is full, lib60870, for example, deletes the oldest event and keeps the new one. Agree the queue depth with the operator, and test a switchover during a burst of events.
One measurement on both links
This example sends a site active power export of 12.5 MW as a short floating-point value, type 13 (M_ME_NC_1), cause 3 (spontaneous), common address 1 and object address 4001 (0x0FA1).
On IEC 104, as I frame N(S) = 5, N(R) = 3:
68 12 0A 00 06 00 0D 01 03 00 01 00 A1 0F 00 00 00 48 41 00
APCI ASDU header and address value QDSThe length octet 0x12 (18) counts the four control octets and the 14-octet ASDU. The control octets hold N(S) and N(R) shifted left by one bit: 5 becomes 0x0A and 3 becomes 0x06. The cause field is 2 octets (03 00: cause 3, originator address 0). The common address is 2 octets (01 00) and the object address is 3 octets (A1 0F 00). The value 12.5 is the IEEE 754 single 0x41480000, sent low octet first. QDS 0x00 means good quality.
On IEC 101, in unbalanced mode with a 1-octet link address (5), a 1-octet cause, a 1-octet common address and a 2-octet object address, the same value goes out as a reply to a class 1 request:
68 0D 0D 68 08 05 0D 01 03 01 A1 0F 00 00 48 41 00 58 16
header C A ASDU header and address value QDS CS endThe ASDU is 11 octets here and 14 on IEC 104. A converter has to rebuild every ASDU to the other field sizes. It cannot pass the bytes through.
A tunnel is not a converter
A serial device server can carry an IEC 101 byte stream across a TCP network. The endpoints still speak IEC 101, with FT1.2 frames and IEC 101 polling. MZ Automation's library documents this as a separate transport for tunnelling IEC 101, distinct from IEC 104. The control centre must have an IEC 101 master that can use a TCP socket. An IEC 104 client does not understand the stream.
A tunnel also adds network latency to every poll and reply. The IEC 101 link timers of the master must allow for it, or the master declares the outstation failed.
A protocol converter implements both standards. It polls or accepts IEC 101 on the RTU side, runs an IEC 104 server on the network side, and maps each point.
The time tag needs the most care. A CP24Time2a tag holds milliseconds (0 to 59,999) and minutes (0 to 59) only. The converter adds the hour and date, usually from its own clock. An event that occurs at 10:59:59.8 and reaches the converter at 11:00:00.3 gets the wrong hour unless the converter compares the minutes in the tag with its own time. Synchronise the RTU and converter clocks, and test the rollover.
These are the faults to test for:
| Fault in the converter | What the control centre sees | Test |
|---|---|---|
| Rebuilds the CP24Time2a tag with the hour from its own clock | Events near the hour stamped one hour wrong | Force an event at xx:59:59 and read the time tag on the IEC 104 side |
| Sends events without a time tag, or with its receipt time | Event times that follow the poll cycle, not the process | Toggle a status input and compare the RTU's event log with the control centre |
| Drops the quality bits (IV, NT, SB, BL, OV) | Values from a failed RTU shown as good | Disconnect the RTU and check that IV or NT is set on its points |
| Answers a general interrogation from its own cache while the RTU link is down | Stale values with cause 20 and good quality | Break the serial link, send C_IC_NA_1, and check the quality |
| Confirms a command before the RTU confirms it | A positive ACTCON for a command that failed | Send a command to an RTU that rejects it |
The application contract
Both standards need a signed point list and the interoperability list of each end. For each point, the list gives:
- the type identification, for example M_ME_NC_1 (13) for a short float or M_ME_TF_1 (36) for a short float with a CP56Time2a tag;
- the common address and information object address;
- the unit, the scale and the sign convention, for example export positive;
- the causes of transmission that the point uses: spontaneous (3), periodic (1), or interrogated by general interrogation (20);
- for commands, the type (for example C_SC_NA_1, 45, or C_SC_TA_1, 58, with a time tag), whether it uses select-before-operate or direct execute, and the point that reports the result.
Agree the clock source. The control centre can set the outstation clock with C_CS_NA_1 (103), or both ends can use NTP. Agree what happens at start-up and after a lost connection. A general interrogation returns current values. Events that occurred during an outage are recovered only if the outstation buffers them. The ASDU guide explains the fields, the timestamps guide the time tags and quality, and the command guide the control sequence.
Security
The base protocols do not authenticate the other end and do not encrypt data. There are two standard additions:
- IEC 62351-3 is a TLS profile for protocols that use TCP/IP. IANA registers TCP port 19998 for secure IEC 104.
- IEC TS 60870-5-7:2025 applies the IEC 62351-5 application-layer authentication to IEC 101 and IEC 104. It lets a station check that an ASDU came from an authorised user and was not changed.
Ask which of these the equipment implements, and test them at commissioning. Where it implements neither, the protection comes from the network: a private circuit or private APN, an IPsec VPN between the sites, and a firewall that accepts TCP 2404 only from the control centre's addresses. An IEC 101 tunnel over a shared network needs the same controls.
Telecontrol and EpiSensor systems
Edge does not include an IEC 60870-5-101 or IEC 60870-5-104 interface. Where a grid operator requires telecontrol from a site, the operator's RTU or a substation gateway provides it. An EpiSensor system measures and controls the site behind that RTU. For example, the RTU receives the operator's setpoint on IEC 104, and a ZDR demand response controller and circuit-level metering report the response that the site actually delivered. Write the boundary between the two systems into the point list: which signals the RTU owns, and which come from the EpiSensor system through a separate interface.
Common questions
What is the difference between IEC 101 and IEC 104?
IEC 60870-5-101 runs on serial links, with FT1.2 frames, a link address and a balanced or unbalanced link procedure. IEC 60870-5-104 runs over TCP/IP, with a 6-octet APCI, numbered frames and its own flow control. The application messages are similar but not identical: IEC 104 fixes the address field sizes and permits only CP56Time2a time tags. A device set up for one does not talk to the other without a converter.
What port does IEC 60870-5-104 use?
TCP port 2404 by default. IANA also registers TCP port 19998 for secure IEC 104, which is used for TLS connections.
What are k and w in IEC 104?
Flow-control parameters. k is the largest number of I frames a station may send without an acknowledgement, 12 by default. w is the number of I frames after which the receiver must acknowledge, 8 by default. The standard recommends that w does not exceed two-thirds of k. If an I frame is not acknowledged within t1 (15 s by default), the sender closes the connection.
Is IEC 104 secure?
Not by itself. The base protocol has no authentication and no encryption. IEC 62351-3 adds TLS, and IEC TS 60870-5-7 applies the IEC 62351-5 authentication to IEC 101 and IEC 104. Where the equipment supports neither, the protection is the network: a private circuit or APN, a VPN, and a firewall rule for port 2404.