Protocols and data

IEC 60870-5-101 vs IEC 60870-5-104

IEC 101 and IEC 104 compared: serial polling and TCP port 2404, k, w and t0 to t3, field sizes and time tags, one point in both encodings, and tunnels versus converters.

IEC 60870-5-101 and IEC 60870-5-104 are the telecontrol protocols that grid operators and utilities use between control centres and remote stations: RTUs at substations, wind and solar farms, battery sites and large loads. IEC 101 runs on serial links. IEC 104 carries the same kind of application message over TCP/IP, on port 2404 by default. Many substations use IEC 61850 inside the station and keep IEC 104 for the link to the control centre.

The two point lists look alike, but the encodings differ in three places that matter for a retrofit: the link layer, the size of the address fields, and the time tags that are permitted.

The standards and editions

The current IEC 101 publication is IEC 60870-5-101:2003+AMD1:2015, consolidated edition 2.1. The current IEC 104 publication is IEC 60870-5-104:2006+AMD1:2016, consolidated edition 2.1, which includes the corrigendum of August 2023.

Each device has an interoperability list, a checklist from the standard that records which options it implements. Get the list for both ends before you write a point list. Compare these entries first. A mismatch in any of them stops the two ends understanding each other:

  • balanced or unbalanced transmission (IEC 101);
  • the octet counts of the link address, cause of transmission, common address and object address (IEC 101);
  • which time-tagged types the device sends and accepts;
  • which commands it accepts with a time tag, and whether it uses select-before-operate.

Side by side

IEC 60870-5-101IEC 60870-5-104
TransportSerial: RS-232, RS-485, modem or radioTCP/IP over Ethernet or a WAN
Addressing of the stationLink address of 0, 1 or 2 octetsIP address and TCP port, 2404 by default
Link procedureUnbalanced (the primary station polls) or balanced (either end can send)Client and server over TCP, with STARTDT and STOPDT
FramingFT1.2: fixed frames start 0x10, variable frames start 0x68 L L 0x68, both end 0x16APCI: start 0x68, one length octet, four control octets
Flow controlOne outstanding frame; confirm or single character 0xE5Up to k numbered I frames outstanding; timers t0 to t3
Cause of transmission1 or 2 octets2 octets
Common address1 or 2 octets2 octets
Object address1, 2 or 3 octets3 octets
Time-tagged typesCP24Time2a (3 octets) and CP56Time2a (7 octets)CP56Time2a only: types 30 to 40 for monitoring, 58 to 64 for commands
Typical linksPoint-to-point serial, radio, leased lines, multidrop lines with many outstationsPrivate IP networks, fibre WANs, cellular links with a private APN

The IEC 104 field sizes are fixed by the standard. Some products let you change them. A device configured that way is no longer interoperable with a standard IEC 104 station.

How IEC 101 moves data

IEC 101 uses the FT1.2 frame format. A fixed-length frame carries only a control field and a link address, and is used for link functions such as a poll. A variable-length frame carries an ASDU. The single character 0xE5 is a positive acknowledgement.

In unbalanced mode, the controlling station is the only primary station. It polls each outstation in turn, and an outstation sends only when it is asked. Data is split into class 1 (high priority, usually events) and class 2 (low priority, usually cyclic values). An outstation sets the ACD bit in its reply when it has class 1 data waiting, and the controlling station then requests class 1 data. Unbalanced mode works on a multidrop line with many outstations.

In balanced mode, each end can start a transfer, so an outstation sends an event as soon as it happens. Balanced mode is limited to point-to-point and multiple point-to-point links.

On a multidrop line, the poll cycle sets the reporting latency. FT1.2 sends 11 bits per character, so at 9,600 bit/s the 19-octet reply in the example below takes about 22 ms on the line, and each poll adds a 5-octet request, two turnarounds and the outstation's response time. An event waits until the controlling station reaches that outstation in the cycle. If each exchange takes 60 ms including turnarounds, a line with 30 outstations has a cycle of about 1.8 s.

How IEC 104 manages a connection

Each IEC 104 frame (APDU) starts with a 6-octet APCI: the start byte 0x68, a length octet that counts the rest of the frame, and four control octets. The largest APDU is 255 octets. There are three frame formats:

  • I frames carry an ASDU, with a 15-bit send sequence number N(S) and a 15-bit receive sequence number N(R);
  • S frames carry only N(R), to acknowledge I frames when there is no data to send back;
  • U frames carry STARTDT and STOPDT, which start and stop data transfer, and TESTFR, which tests an idle link.

A new TCP connection starts in the STOPDT state with both sequence numbers at zero. The controlled station sends no I frames until it receives STARTDT act and returns STARTDT con.

IEC 60870-5-104 gives these defaults:

ParameterDefaultMeaning
k12 I framesLargest number of I frames sent and not yet acknowledged. At k, the sender stops.
w8 I framesThe receiver acknowledges at the latest after w I frames. Recommendation: w not more than two-thirds of k.
t030 sTime-out for connection establishment
t115 sTime-out for an acknowledgement of a sent I frame or U frame. At t1, the sender closes the connection.
t210 sTime-out for an acknowledgement when there is no data to send. t2 must be less than t1.
t320 sIdle time before a TESTFR is sent

When fewer than w frames arrive, the receiver waits for t2 before it sends an S frame. The acknowledgement therefore reaches the sender after t2 plus the transit time. With the defaults, that leaves 5 s for the round trip before t1 closes the connection. A cellular link with a 1 s round trip is inside that margin. A link that stalls for more than 5 s under load is not, and the symptom is a connection that closes and reopens during bursts of events. Increase t1, or reduce t2, so that t1 exceeds t2 plus the worst round trip you measure. Change the values at both ends at the same time.

Redundant connections

A controlled station can accept more than one TCP connection, for example from a main and a standby control centre. The connections form a redundancy group with one event queue, and only one connection in the group is active (in STARTDT) at a time. When the control centre switches to the standby connection, events that were sent but not acknowledged on the old connection must still be in the queue. When the queue is full, lib60870, for example, deletes the oldest event and keeps the new one. Agree the queue depth with the operator, and test a switchover during a burst of events.

This example sends a site active power export of 12.5 MW as a short floating-point value, type 13 (M_ME_NC_1), cause 3 (spontaneous), common address 1 and object address 4001 (0x0FA1).

On IEC 104, as I frame N(S) = 5, N(R) = 3:

Hex frame
68 12 0A 00 06 00  0D 01 03 00 01 00 A1 0F 00  00 00 48 41 00
APCI               ASDU header and address     value      QDS

The length octet 0x12 (18) counts the four control octets and the 14-octet ASDU. The control octets hold N(S) and N(R) shifted left by one bit: 5 becomes 0x0A and 3 becomes 0x06. The cause field is 2 octets (03 00: cause 3, originator address 0). The common address is 2 octets (01 00) and the object address is 3 octets (A1 0F 00). The value 12.5 is the IEEE 754 single 0x41480000, sent low octet first. QDS 0x00 means good quality.

On IEC 101, in unbalanced mode with a 1-octet link address (5), a 1-octet cause, a 1-octet common address and a 2-octet object address, the same value goes out as a reply to a class 1 request:

Hex frame
68 0D 0D 68  08 05  0D 01 03 01 A1 0F  00 00 48 41 00  58 16
header       C  A   ASDU header and address  value  QDS  CS end

The ASDU is 11 octets here and 14 on IEC 104. A converter has to rebuild every ASDU to the other field sizes. It cannot pass the bytes through.

A tunnel is not a converter

A serial device server can carry an IEC 101 byte stream across a TCP network. The endpoints still speak IEC 101, with FT1.2 frames and IEC 101 polling. MZ Automation's library documents this as a separate transport for tunnelling IEC 101, distinct from IEC 104. The control centre must have an IEC 101 master that can use a TCP socket. An IEC 104 client does not understand the stream.

A tunnel also adds network latency to every poll and reply. The IEC 101 link timers of the master must allow for it, or the master declares the outstation failed.

A protocol converter implements both standards. It polls or accepts IEC 101 on the RTU side, runs an IEC 104 server on the network side, and maps each point.

An IEC 101 tunnel compared with an IEC 101 to IEC 104 converter Top: a serial device server carries the IEC 101 byte stream from the RTU over a TCP network, and the control centre still needs an IEC 101 master. Bottom: a protocol converter polls the RTU in IEC 101, runs an IEC 104 server on the network side, rebuilds every ASDU to the IEC 104 field sizes and adds the hour and date to the time tags. tunnel RTU IEC 101 outstation Serial server bytes in, bytes out Control centre IEC 101 master FT1.2 101 in TCP converter RTU IEC 101 outstation Converter maps every point Control centre IEC 104 client IEC 101 IEC 104 Both ends still speak IEC 101 Rebuilds each ASDU: 11 octets become 14, and adds the hour and date to CP24Time2a
A tunnel carries IEC 101 bytes over TCP to an IEC 101 master. A converter speaks IEC 101 to the RTU and IEC 104 to the control centre, and rebuilds every ASDU on the way.

The time tag needs the most care. A CP24Time2a tag holds milliseconds (0 to 59,999) and minutes (0 to 59) only. The converter adds the hour and date, usually from its own clock. An event that occurs at 10:59:59.8 and reaches the converter at 11:00:00.3 gets the wrong hour unless the converter compares the minutes in the tag with its own time. Synchronise the RTU and converter clocks, and test the rollover.

These are the faults to test for:

Fault in the converterWhat the control centre seesTest
Rebuilds the CP24Time2a tag with the hour from its own clockEvents near the hour stamped one hour wrongForce an event at xx:59:59 and read the time tag on the IEC 104 side
Sends events without a time tag, or with its receipt timeEvent times that follow the poll cycle, not the processToggle a status input and compare the RTU's event log with the control centre
Drops the quality bits (IV, NT, SB, BL, OV)Values from a failed RTU shown as goodDisconnect the RTU and check that IV or NT is set on its points
Answers a general interrogation from its own cache while the RTU link is downStale values with cause 20 and good qualityBreak the serial link, send C_IC_NA_1, and check the quality
Confirms a command before the RTU confirms itA positive ACTCON for a command that failedSend a command to an RTU that rejects it

The application contract

Both standards need a signed point list and the interoperability list of each end. For each point, the list gives:

  • the type identification, for example M_ME_NC_1 (13) for a short float or M_ME_TF_1 (36) for a short float with a CP56Time2a tag;
  • the common address and information object address;
  • the unit, the scale and the sign convention, for example export positive;
  • the causes of transmission that the point uses: spontaneous (3), periodic (1), or interrogated by general interrogation (20);
  • for commands, the type (for example C_SC_NA_1, 45, or C_SC_TA_1, 58, with a time tag), whether it uses select-before-operate or direct execute, and the point that reports the result.

Agree the clock source. The control centre can set the outstation clock with C_CS_NA_1 (103), or both ends can use NTP. Agree what happens at start-up and after a lost connection. A general interrogation returns current values. Events that occurred during an outage are recovered only if the outstation buffers them. The ASDU guide explains the fields, the timestamps guide the time tags and quality, and the command guide the control sequence.

Security

The base protocols do not authenticate the other end and do not encrypt data. There are two standard additions:

  • IEC 62351-3 is a TLS profile for protocols that use TCP/IP. IANA registers TCP port 19998 for secure IEC 104.
  • IEC TS 60870-5-7:2025 applies the IEC 62351-5 application-layer authentication to IEC 101 and IEC 104. It lets a station check that an ASDU came from an authorised user and was not changed.

Ask which of these the equipment implements, and test them at commissioning. Where it implements neither, the protection comes from the network: a private circuit or private APN, an IPsec VPN between the sites, and a firewall that accepts TCP 2404 only from the control centre's addresses. An IEC 101 tunnel over a shared network needs the same controls.

Telecontrol and EpiSensor systems

Edge does not include an IEC 60870-5-101 or IEC 60870-5-104 interface. Where a grid operator requires telecontrol from a site, the operator's RTU or a substation gateway provides it. An EpiSensor system measures and controls the site behind that RTU. For example, the RTU receives the operator's setpoint on IEC 104, and a ZDR demand response controller and circuit-level metering report the response that the site actually delivered. Write the boundary between the two systems into the point list: which signals the RTU owns, and which come from the EpiSensor system through a separate interface.

Common questions

What is the difference between IEC 101 and IEC 104?

IEC 60870-5-101 runs on serial links, with FT1.2 frames, a link address and a balanced or unbalanced link procedure. IEC 60870-5-104 runs over TCP/IP, with a 6-octet APCI, numbered frames and its own flow control. The application messages are similar but not identical: IEC 104 fixes the address field sizes and permits only CP56Time2a time tags. A device set up for one does not talk to the other without a converter.

What port does IEC 60870-5-104 use?

TCP port 2404 by default. IANA also registers TCP port 19998 for secure IEC 104, which is used for TLS connections.

What are k and w in IEC 104?

Flow-control parameters. k is the largest number of I frames a station may send without an acknowledgement, 12 by default. w is the number of I frames after which the receiver must acknowledge, 8 by default. The standard recommends that w does not exceed two-thirds of k. If an I frame is not acknowledged within t1 (15 s by default), the sender closes the connection.

Is IEC 104 secure?

Not by itself. The base protocol has no authentication and no encryption. IEC 62351-3 adds TLS, and IEC TS 60870-5-7 applies the IEC 62351-5 authentication to IEC 101 and IEC 104. Where the equipment supports neither, the protection is the network: a private circuit or APN, a VPN, and a firewall rule for port 2404.