Every IEC 60870-5-101 and 104 message that carries data holds an ASDU, an application service data unit. The ASDU gives the encoding of the value (the type), the reason it was sent (the cause of transmission), the station or logical device (the common address) and the point (the information object address). Typical mapping faults come from reading one of these without the others: a correct IOA under the wrong common address, a float read as a scaled integer, or an interrogation response stored as an event.
The fields
IEC 60870-5-101 defines the data unit identifier at the start of each ASDU. IEC 60870-5-104 uses the same identifier with fixed field sizes.
| Field | Content | Size in IEC 104 | Options in IEC 101 |
|---|---|---|---|
| Type identification | Encoding of the information objects | 1 byte | 1 byte |
| Variable structure qualifier | Number of objects, 0 to 127 (bits 1 to 7), and the SQ bit (bit 8) | 1 byte | 1 byte |
| Cause of transmission | Cause, 0 to 63 (bits 1 to 6), the P/N bit (bit 7) and the T bit (bit 8) | 1 byte | 1 byte |
| Originator address | The controlling station that caused the message, 0 if not used | 1 byte | 0 or 1 byte |
| Common address (CA) | Station or logical device | 2 bytes | 1 or 2 bytes |
| Information object address (IOA) | Point | 3 bytes for each object | 1, 2 or 3 bytes |
| Information elements | Value, quality and any time tag | Depends on the type | Depends on the type |
In IEC 101 the sizes of the cause, common address and object address are system parameters in the interoperability list, so both ends must agree them. A wrong field size shifts every later byte. Renumbering points cannot correct it.
The SQ bit changes the layout of the objects. With SQ = 0, every object carries its own IOA. With SQ = 1, the ASDU carries one IOA, then the elements for that address and the addresses that follow it in order. A type 13 ASDU with SQ = 1, 10 objects and IOA 2001 carries values for IOAs 2001 to 2010 and only 3 bytes of address. A decoder that expects an IOA before every value reads float bytes as addresses, and every value after the first is wrong.
The T bit marks a test message. Do not store a value with T = 1 as process data. The originator address identifies the controlling station that sent a command, and is 0 when not used. When two control centres share an outstation, each can set its own originator address. The outstation copies it into its confirmations, so each centre can match the confirmations to its own commands.
A frame on the wire
This IEC 104 I-frame carries an active power of 2,340.5 kW from common address 12, IOA 1001, sent because the value changed:
68 12 00 00 00 00 0D 01 03 00 0C 00 E9 03 00 00 48 12 45 00
| Bytes | Field | Decoded |
|---|---|---|
| 68 | Start byte | Start of an IEC 104 frame |
| 12 | Length | 18 bytes follow |
| 00 00 00 00 | Control field | I-format, send and receive sequence numbers 0 |
| 0D | Type identification | 13, M_ME_NC_1 |
| 01 | Variable structure qualifier | SQ = 0, 1 object |
| 03 | Cause of transmission | 3, spontaneous; P/N = 0, T = 0 |
| 00 | Originator address | 0, not used |
| 0C 00 | Common address | 12 |
| E9 03 00 | IOA | 1001 (0x0003E9) |
| 00 48 12 45 | Short float | 0x45124800, 2,340.5 |
| 00 | Quality descriptor | 0, no quality flags set |
Every multi-byte field is sent least significant byte first. A decoder that reads the fields in the opposite order gets common address 3,072 (0x0C00) and IOA 15,270,656 (0xE90300). It reads the float as 6.6 × 10⁻³⁹, which a historian stores without complaint. The IEEE 754 float converter shows the bytes of any value. The timestamps and quality guide decodes the quality bits and the time tag.
Type identification
The type says how to decode the information elements. IEC 60870-5-101 clause 7.3 defines each type. Some common types:
| Type | Name | Content |
|---|---|---|
| 1 | M_SP_NA_1 | Single-point status: 0 off, 1 on |
| 3 | M_DP_NA_1 | Double-point status: 1 off, 2 on, 0 intermediate, 3 indeterminate |
| 9 | M_ME_NA_1 | Measured value, normalised (16-bit) |
| 11 | M_ME_NB_1 | Measured value, scaled (16-bit) |
| 13 | M_ME_NC_1 | Measured value, short floating point (32-bit) |
| 15 | M_IT_NA_1 | Integrated totals (counters) |
| 30, 31, 36, 37 | M_SP_TB_1, M_DP_TB_1, M_ME_TF_1, M_IT_TB_1 | Types 1, 3, 13 and 15 with a CP56Time2a time tag |
| 45, 46 | C_SC_NA_1, C_DC_NA_1 | Single and double commands |
| 50 | C_SE_NC_1 | Set point command, short floating point |
| 100 | C_IC_NA_1 | General interrogation command |
| 101 | C_CI_NA_1 | Counter interrogation command |
| 103 | C_CS_NA_1 | Clock synchronisation command |
The prefix M marks monitor-direction data from the outstation. The prefix C marks commands to it. IEC 104 uses the 7-byte CP56Time2a time tag only. The IEC 101 types with the 3-byte CP24Time2a tag, such as 2, 4 and 14, do not occur in IEC 104.
Types 9 and 11 carry a 16-bit signed integer, not a physical value. For type 9, divide the integer by 32,768 to get a fraction from -1 to +0.99997, then multiply by the full-scale value. With a full scale of 1,000 kW, a raw value of 16,384 is 0.5, or 500 kW. For type 11, the integer is the value multiplied by an agreed factor: 2,340.5 kW with a factor of 10 is sent as 23,405. Neither type carries its full scale or factor. A receiver with the wrong factor produces a plausible wrong number.
A floating-point type does not carry the unit either. A value of 2,340.5 in type 13 could be kW, kVA or A. The unit, sign convention and measurement point must be in the point list that both parties agree.
Cause of transmission
Common cause of transmission values:
| Cause | Meaning |
|---|---|
| 1 | Periodic or cyclic |
| 3 | Spontaneous: the value changed |
| 5 | Requested |
| 6 | Activation: a command |
| 7 | Activation confirmation |
| 8, 9 | Deactivation, and its confirmation |
| 10 | Activation termination: the command has finished |
| 11, 12 | Return information caused by a remote command, or by a local command |
| 20 | Interrogated by station: an answer to a general interrogation |
| 21 to 36 | Interrogated by group 1 to 16 |
| 37 | Requested by general counter interrogation, for integrated totals |
| 44 | Unknown type identification |
| 45 | Unknown cause of transmission |
| 46 | Unknown common address |
| 47 | Unknown information object address |
Read the cause with the type and the P/N bit. Cause 7 with P/N = 1 is a negative confirmation: the outstation refused the command. The command guide follows a command through each cause.
Addresses
A point is identified by its common address and its information object address together, on one connection. The type is not part of the address. IOA 1001 can exist under common address 12 and under common address 13, and on every RTU in an estate. The IP address (IEC 104) or link address (IEC 101) identifies the connection, not the point.
One IEC 104 connection can serve several common addresses. The highest value, 65535 with a 2-byte field or 255 with a 1-byte field, is the global address. A controlling station uses it for station-wide functions such as general interrogation, and each common address answers under its own address. Not every function may use it. The lib60870 outstation refuses a read command (type 102), a test command (types 104 and 107) or a delay acquisition command (type 106) sent to the global address, with cause 46.
The interoperability list also states whether the IOA is structured or unstructured. Some tools and vendor point lists show a structured IOA as three decimal octets. IOA 1001 is 0x0003E9. It can appear as 0.3.233 in one tool and as 233.3.0 in another. Convert both lists to a single integer before comparing them.
A worked point-list entry:
| Field | Value |
|---|---|
| Connection | Substation RTU A, 10.40.1.20 port 2404 |
| Common address | 12 |
| IOA | 1001 |
| Type | 13, M_ME_NC_1 (short float, no time tag) |
| Meaning | Active power at the grid connection point |
| Unit and sign | kW, import positive |
| Deadband | 50 kW |
| Expected causes | 3 (spontaneous, when the value moves more than the deadband), 20 (general interrogation) |
Give measured power, a power set point and a read-back of the active set point separate rows, even when their names look alike. Measured power is M_ME_NC_1 in the monitor direction. The set point is C_SE_NC_1, type 50, in the control direction, and its confirmation arrives on the same IOA with cause 7. A read-back of the set point is another monitored point with its own IOA.
Test rejection as well as acceptance
Commission at least one point of each type in the point list. Compare the decoded type, common address, IOA, cause, unit and value with the agreed point list.
Then connect an IEC 104 master simulator in place of the control system and send commands that the outstation must refuse. Do this during acceptance testing, before the outstation controls live plant.
- Send a command type that the outstation does not support. Expect cause 44.
- Send a supported command with cause 3 instead of 6. Expect cause 45.
- Send a command to a common address that the outstation does not serve. Expect cause 46.
- Send a command to an IOA that is not configured. Expect cause 47.
An outstation that replies returns the request with the new cause and the P/N bit set. Behaviour for an unknown common address varies. The lib60870 outstation returns cause 46 only when the application tells the library which common addresses exist. Some outstations discard the request and send nothing. Record the expected result of each case in the interoperability list, and keep the point list revision and the test results together.
Telecontrol and EpiSensor systems
Edge does not implement IEC 60870-5-101 or 104. On a site with a telecontrol link, the RTU or substation gateway carries the grid operator's points, and an EpiSensor system measures the site behind it. The IEC 101 vs 104 guide explains where the boundary sits.
Common questions
What is an ASDU in IEC 60870-5-104?
The application service data unit: the part of a message that carries telecontrol data. It starts with a data unit identifier (type, variable structure qualifier, cause of transmission, originator address and common address) followed by one or more information objects, each with its information object address and value.
What does cause of transmission 3 mean?
Spontaneous: the outstation sent the value because it changed. Cause 20 means the value was sent in answer to a general interrogation, and cause 1 means periodic or cyclic transmission.
What is an IOA in IEC 104?
The information object address: a 3-byte number in IEC 104 that identifies one point or function within a common address. It is sent least significant byte first, so IOA 1001 appears on the wire as E9 03 00. The same IOA can exist under another common address or on another connection.
What is M_ME_NC_1?
Type identification 13: a measured value as a short (32-bit) floating-point number, with a quality descriptor and no time tag. The same measurement with a CP56Time2a time tag is M_ME_TF_1, type 36.