Protocols and data

IEC 60870 ASDUs, causes of transmission and addresses

How to read an IEC 60870-5-101 or 104 point list: type identification, cause of transmission, common address and information object address, with an IEC 104 frame decoded byte by byte.

Every IEC 60870-5-101 and 104 message that carries data holds an ASDU, an application service data unit. The ASDU gives the encoding of the value (the type), the reason it was sent (the cause of transmission), the station or logical device (the common address) and the point (the information object address). Typical mapping faults come from reading one of these without the others: a correct IOA under the wrong common address, a float read as a scaled integer, or an interrogation response stored as an event.

The fields

IEC 60870-5-101 defines the data unit identifier at the start of each ASDU. IEC 60870-5-104 uses the same identifier with fixed field sizes.

FieldContentSize in IEC 104Options in IEC 101
Type identificationEncoding of the information objects1 byte1 byte
Variable structure qualifierNumber of objects, 0 to 127 (bits 1 to 7), and the SQ bit (bit 8)1 byte1 byte
Cause of transmissionCause, 0 to 63 (bits 1 to 6), the P/N bit (bit 7) and the T bit (bit 8)1 byte1 byte
Originator addressThe controlling station that caused the message, 0 if not used1 byte0 or 1 byte
Common address (CA)Station or logical device2 bytes1 or 2 bytes
Information object address (IOA)Point3 bytes for each object1, 2 or 3 bytes
Information elementsValue, quality and any time tagDepends on the typeDepends on the type

In IEC 101 the sizes of the cause, common address and object address are system parameters in the interoperability list, so both ends must agree them. A wrong field size shifts every later byte. Renumbering points cannot correct it.

The SQ bit changes the layout of the objects. With SQ = 0, every object carries its own IOA. With SQ = 1, the ASDU carries one IOA, then the elements for that address and the addresses that follow it in order. A type 13 ASDU with SQ = 1, 10 objects and IOA 2001 carries values for IOAs 2001 to 2010 and only 3 bytes of address. A decoder that expects an IOA before every value reads float bytes as addresses, and every value after the first is wrong.

The T bit marks a test message. Do not store a value with T = 1 as process data. The originator address identifies the controlling station that sent a command, and is 0 when not used. When two control centres share an outstation, each can set its own originator address. The outstation copies it into its confirmations, so each centre can match the confirmations to its own commands.

A frame on the wire

This IEC 104 I-frame carries an active power of 2,340.5 kW from common address 12, IOA 1001, sent because the value changed:

68 12 00 00 00 00 0D 01 03 00 0C 00 E9 03 00 00 48 12 45 00

BytesFieldDecoded
68Start byteStart of an IEC 104 frame
12Length18 bytes follow
00 00 00 00Control fieldI-format, send and receive sequence numbers 0
0DType identification13, M_ME_NC_1
01Variable structure qualifierSQ = 0, 1 object
03Cause of transmission3, spontaneous; P/N = 0, T = 0
00Originator address0, not used
0C 00Common address12
E9 03 00IOA1001 (0x0003E9)
00 48 12 45Short float0x45124800, 2,340.5
00Quality descriptor0, no quality flags set

Every multi-byte field is sent least significant byte first. A decoder that reads the fields in the opposite order gets common address 3,072 (0x0C00) and IOA 15,270,656 (0xE90300). It reads the float as 6.6 × 10⁻³⁹, which a historian stores without complaint. The IEEE 754 float converter shows the bytes of any value. The timestamps and quality guide decodes the quality bits and the time tag.

Type identification

The type says how to decode the information elements. IEC 60870-5-101 clause 7.3 defines each type. Some common types:

TypeNameContent
1M_SP_NA_1Single-point status: 0 off, 1 on
3M_DP_NA_1Double-point status: 1 off, 2 on, 0 intermediate, 3 indeterminate
9M_ME_NA_1Measured value, normalised (16-bit)
11M_ME_NB_1Measured value, scaled (16-bit)
13M_ME_NC_1Measured value, short floating point (32-bit)
15M_IT_NA_1Integrated totals (counters)
30, 31, 36, 37M_SP_TB_1, M_DP_TB_1, M_ME_TF_1, M_IT_TB_1Types 1, 3, 13 and 15 with a CP56Time2a time tag
45, 46C_SC_NA_1, C_DC_NA_1Single and double commands
50C_SE_NC_1Set point command, short floating point
100C_IC_NA_1General interrogation command
101C_CI_NA_1Counter interrogation command
103C_CS_NA_1Clock synchronisation command

The prefix M marks monitor-direction data from the outstation. The prefix C marks commands to it. IEC 104 uses the 7-byte CP56Time2a time tag only. The IEC 101 types with the 3-byte CP24Time2a tag, such as 2, 4 and 14, do not occur in IEC 104.

Types 9 and 11 carry a 16-bit signed integer, not a physical value. For type 9, divide the integer by 32,768 to get a fraction from -1 to +0.99997, then multiply by the full-scale value. With a full scale of 1,000 kW, a raw value of 16,384 is 0.5, or 500 kW. For type 11, the integer is the value multiplied by an agreed factor: 2,340.5 kW with a factor of 10 is sent as 23,405. Neither type carries its full scale or factor. A receiver with the wrong factor produces a plausible wrong number.

A floating-point type does not carry the unit either. A value of 2,340.5 in type 13 could be kW, kVA or A. The unit, sign convention and measurement point must be in the point list that both parties agree.

Cause of transmission

Common cause of transmission values:

CauseMeaning
1Periodic or cyclic
3Spontaneous: the value changed
5Requested
6Activation: a command
7Activation confirmation
8, 9Deactivation, and its confirmation
10Activation termination: the command has finished
11, 12Return information caused by a remote command, or by a local command
20Interrogated by station: an answer to a general interrogation
21 to 36Interrogated by group 1 to 16
37Requested by general counter interrogation, for integrated totals
44Unknown type identification
45Unknown cause of transmission
46Unknown common address
47Unknown information object address

Read the cause with the type and the P/N bit. Cause 7 with P/N = 1 is a negative confirmation: the outstation refused the command. The command guide follows a command through each cause.

Addresses

A point is identified by its common address and its information object address together, on one connection. The type is not part of the address. IOA 1001 can exist under common address 12 and under common address 13, and on every RTU in an estate. The IP address (IEC 104) or link address (IEC 101) identifies the connection, not the point.

One IEC 104 connection can serve several common addresses. The highest value, 65535 with a 2-byte field or 255 with a 1-byte field, is the global address. A controlling station uses it for station-wide functions such as general interrogation, and each common address answers under its own address. Not every function may use it. The lib60870 outstation refuses a read command (type 102), a test command (types 104 and 107) or a delay acquisition command (type 106) sent to the global address, with cause 46.

The interoperability list also states whether the IOA is structured or unstructured. Some tools and vendor point lists show a structured IOA as three decimal octets. IOA 1001 is 0x0003E9. It can appear as 0.3.233 in one tool and as 233.3.0 in another. Convert both lists to a single integer before comparing them.

A worked point-list entry:

FieldValue
ConnectionSubstation RTU A, 10.40.1.20 port 2404
Common address12
IOA1001
Type13, M_ME_NC_1 (short float, no time tag)
MeaningActive power at the grid connection point
Unit and signkW, import positive
Deadband50 kW
Expected causes3 (spontaneous, when the value moves more than the deadband), 20 (general interrogation)

Give measured power, a power set point and a read-back of the active set point separate rows, even when their names look alike. Measured power is M_ME_NC_1 in the monitor direction. The set point is C_SE_NC_1, type 50, in the control direction, and its confirmation arrives on the same IOA with cause 7. A read-back of the set point is another monitored point with its own IOA.

Test rejection as well as acceptance

Commission at least one point of each type in the point list. Compare the decoded type, common address, IOA, cause, unit and value with the agreed point list.

Then connect an IEC 104 master simulator in place of the control system and send commands that the outstation must refuse. Do this during acceptance testing, before the outstation controls live plant.

  1. Send a command type that the outstation does not support. Expect cause 44.
  2. Send a supported command with cause 3 instead of 6. Expect cause 45.
  3. Send a command to a common address that the outstation does not serve. Expect cause 46.
  4. Send a command to an IOA that is not configured. Expect cause 47.

An outstation that replies returns the request with the new cause and the P/N bit set. Behaviour for an unknown common address varies. The lib60870 outstation returns cause 46 only when the application tells the library which common addresses exist. Some outstations discard the request and send nothing. Record the expected result of each case in the interoperability list, and keep the point list revision and the test results together.

Telecontrol and EpiSensor systems

Edge does not implement IEC 60870-5-101 or 104. On a site with a telecontrol link, the RTU or substation gateway carries the grid operator's points, and an EpiSensor system measures the site behind it. The IEC 101 vs 104 guide explains where the boundary sits.

Common questions

What is an ASDU in IEC 60870-5-104?

The application service data unit: the part of a message that carries telecontrol data. It starts with a data unit identifier (type, variable structure qualifier, cause of transmission, originator address and common address) followed by one or more information objects, each with its information object address and value.

What does cause of transmission 3 mean?

Spontaneous: the outstation sent the value because it changed. Cause 20 means the value was sent in answer to a general interrogation, and cause 1 means periodic or cyclic transmission.

What is an IOA in IEC 104?

The information object address: a 3-byte number in IEC 104 that identifies one point or function within a common address. It is sent least significant byte first, so IOA 1001 appears on the wire as E9 03 00. The same IOA can exist under another common address or on another connection.

What is M_ME_NC_1?

Type identification 13: a measured value as a short (32-bit) floating-point number, with a quality descriptor and no time tag. The same measurement with a CP56Time2a time tag is M_ME_TF_1, type 36.