Protocols and data

IEC 60870 commands, select-before-operate and confirmation

How an IEC 60870-5-101 or 104 command works: direct execute and select-before-operate, activation confirmation and termination, command qualifiers, and checking the real equipment state.

A control centre sends a double command to open breaker CB-1. The RTU answers with a positive activation confirmation. The control system marks the breaker open. The double-point status still reads closed, because the breaker's own interlock blocked the trip after the RTU had accepted the command. The confirmation was correct. The control system's reading of it was wrong.

In IEC 60870-5-101 and 104, the acknowledgement, the confirmation, the termination and the equipment state are separate messages. This guide follows one command through all of them and lists what each one proves.

This guide is part of the IEC 60870 and IEC 61850 series.

The stages of a command

StageMessageWhat it proves
ActivationCommand ASDU, cause 6Only that the control centre's own log recorded a send
Transport acknowledgement (IEC 104 only)S or I frame whose receive sequence number covers the commandThe outstation's transport layer received the frame. It says nothing about the application.
Positive activation confirmationCause 7, P/N bit clearThe outstation's application accepted the command
Negative activation confirmationCause 7, P/N bit setThe outstation refused the command. No reason is sent.
Address or type rejectionCause 44, 45, 46 or 47, P/N bit setThe type, cause, common address or object address is unknown to the outstation
Activation terminationCause 10The outstation finished executing the command, if it is configured to send this
Return informationStatus point, cause 11 or 3The outstation measured a change in the equipment state

The outstation mirrors the command ASDU in its replies. The type, common address, object address and command value stay the same, and only the cause and the P/N bit change. The receiver correlates replies with commands on those fields.

Direct execute and select-before-operate

Single commands (type 45), double commands (type 46) and set points (types 48, 49 and 50: normalised, scaled and short floating point) can be sent in two ways. The mode is set by the S/E bit, bit 8 of the command qualifier octet (SCO, DCO or QOS). A value of 1 means select; 0 means execute.

In direct execute, one message is sent with the S/E bit clear. The outstation checks the command and acts on it at once.

In select-before-operate (SBO), the first message has the S/E bit set. The outstation checks the command, reserves the point and confirms with cause 7. The second message is the same command with the S/E bit clear. The outstation executes only if the execute matches the selected object address and value. A mismatch gets a negative confirmation.

SBO stops a single corrupted or misdirected message from operating plant, because two consistent messages are necessary. The outstation can also check interlocks and the local/remote switch during the select, before anything moves.

The select timeout is an outstation setting, and defaults differ widely. The PcVue IEC 104 server defaults to 5 s. The ABB RER620 relay defaults to 30 s, with a range of 1 to 65 s. If the execute arrives after the timeout, the selection has lapsed and the outstation refuses the execute.

To cancel a pending selection, the control centre sends the same command with cause 8 (deactivation). The outstation answers with cause 9 (deactivation confirmation). Not every outstation supports deactivation of commands, so check the interoperability list. Some outstations also refuse a second select on a point that is already selected.

Check the grid operator's telecontrol specification and interoperability list for the required mode. SBO is common for breaker and disconnector commands. Record the mode for each command point in the point list.

Command qualifiers

Single and double commands carry a qualifier of command (QU) in bits 3 to 7 of the same octet:

QUMeaning
0No additional definition. The outstation's configuration decides the output.
1Short pulse
2Long pulse
3Persistent output

The short and long pulse durations are system parameters in the outstation. They are not sent in the message. QU 0 is common, so the output behaviour is often invisible to the control centre. Record the real output for each point in the point list.

A double command uses a 2-bit double command state (DCS): 1 is off and 2 is on. The values 0 and 3 are not permitted, and outstations reject them. A single bit error in the DCS therefore produces a rejected command, not the opposite command. A single command has no such protection, because its one bit changes between off and on. How the outstation wires a double command to relays (for example, separate open and close coils) is an implementation detail and not part of the protocol.

A worked select-before-operate sequence

The control centre closes a breaker with a double command over IEC 104. Common address 12, object address 2001 (hexadecimal D1 07 00, least significant byte first), QU 1 for a short pulse. The breaker status is double point object address 1001, type 31 with a CP56Time2a time tag. In this example the RTU has a 30 s select timeout and a 500 ms short pulse.

Time (s)DirectionTypeCause octetQualifier or valueMeaning
0.000To RTU4606DCO 86Select, close (DCS 2), short pulse (QU 1), S/E 1
0.045From RTU4607DCO 86Positive confirmation of the select
0.060To RTU4606DCO 06Execute: same command, S/E 0
0.105From RTU4607DCO 06Positive confirmation of the execute
0.290From RTU310BDIQ 02, time tag 10:15:02.237Breaker closed (DPI 2), cause 11
0.610From RTU460ADCO 06Activation termination: pulse finished

The cause octet also holds the P/N bit (hexadecimal 40) and the test bit (hexadecimal 80). A refused execute therefore comes back as cause octet 47, not 07. A command to an object address that the RTU does not know comes back as 6F (cause 47 with P/N set).

Note the order. On this RTU the status change arrives before the termination, because the breaker closed during the pulse. On another RTU, or with a persistent output, the termination can arrive first. The correlation logic must accept either order.

Refusals and timeouts

A negative confirmation is a definite answer: the outstation refused and did nothing. The protocol does not say why. The ABB RER620 manual lists its reasons for a refusal: the wrong control direction, a DCS of 0 or 3, a point set to status-only, an interlock in the breaker, or remote mode not enabled. The protocol has no code for any of these, so each one arrives as a negative cause 7. The reason is only in the outstation's own event log.

Causes 44 to 47 are different. They mean the outstation could not find the type, cause, common address or object address. Vendors apply them differently. For example, the RER620 answers a single command sent to a double point with cause 47, although the object address exists.

A timeout leaves the outcome unknown. The outstation may have executed the command and its reply may have been lost. Before any retry, read the status point and the related measurements. Do not repeat a command automatically.

Master implementations keep these cases apart. Beckhoff's IEC 60870-5-10x driver reports a negative confirmation (IEC870_COMMERR_NEGACTCON), an unknown object address (IEC870_COMMERR_UNKNOWNOBJADDR), a select/execute timeout (IEC870_COMMERR_SELEXECTIMEOUT) and a missing termination (IEC870_COMMERR_ACTTERMTIMEOUT) as separate errors. A control system should log them separately too.

In IEC 104, the link timers set a limit on command timeouts. If the RTU does not acknowledge an I frame within t1 (15 s by default), the sender closes the connection. An I frame from the RTU, such as the activation confirmation, carries the acknowledgement in its receive sequence number. If the RTU has no I frame to send, it sends an S frame after w received frames (default 8) or after t2 (default 10 s). Set the control centre's confirmation timeout well below t1, and below the RTU's select timeout. After a reconnection, send a general interrogation and read the status before deciding what the last command did. The IEC 101 vs 104 guide explains k, w and the timers.

Time-tagged commands

IEC 104 adds command types 58 to 64, which carry a CP56Time2a time tag. For example, type 58 is a single command and type 59 a double command with a time tag. An outstation that supports them compares the tag with its own clock and can reject a command older than a configured maximum age. A drifted clock or a slow link then makes commands fail. Agree the maximum age, the time source and the outstation's response to an old command, and test them.

Check the real state

The equipment's state comes back on a separate monitoring point: a double-point status for a breaker (type 31 with a time tag), or a measured value for a set point. Cause 11 means "return information caused by a remote command" and cause 12 means a change caused by a local command. Use the outstation's time tag, not the time of receipt, to order the command and the change. The timestamps and quality guide explains CP56Time2a.

The status point proves only what the outstation's contact inputs report. For a set point or a load switch, also check a measurement of the process: current falls, power changes, frequency response follows the set point. The BESS command verification guide applies this to battery set points.

Commission control safely

  1. For each command point, agree with the equipment owner: the type, the mode (direct or SBO), the QU value and the real pulse duration, whether ACTTERM is sent, the select timeout, the feedback point and the causes it uses.
  2. Record these values in the interoperability list and the point list. The ABB REC 523 interoperability list, for example, has separate entries for direct and select-and-execute commands, for "ACTTERM used", and for each QU value.
  3. Test first against a simulator. Include a negative confirmation, an unknown object address, a lapsed selection, a deactivation and a lost connection between select and execute.
  4. On site, test one command at a time, with the owner present and the plant in a safe state.
  5. Log every frame with its time, cause octet, P/N bit, object address and value, and the physical result.
  6. Restart each end in turn and confirm that no selection or command survives the restart unexpectedly.

The local control guide lists the failure cases to plan for any automatic control.

Telecontrol and EpiSensor systems

Edge does not implement IEC 60870-5. Where a grid operator commands a site through a telecontrol RTU, the RTU executes those commands and reports their status.

An EpiSensor meter on the same circuit gives an independent measurement for the last stage: the current and power after the command, recorded by Edge. It does not depend on the RTU's contacts or its time tags.

A ZDR demand response controller acts on grid frequency locally, through its own relay or a Modbus set point. Its actions do not appear in the RTU's command log. If the RTU and the ZDR can both switch the same load, give them separate outputs, and agree which one has priority.

Common questions

What is select-before-operate in IEC 104?

A two-step command. The control centre sends the command with the select/execute (S/E) bit set, in bit 8 of the command qualifier. The outstation checks it and confirms with cause 7. The control centre then sends the same command with the S/E bit clear. The outstation executes it only if the point and value match the selection and the select timeout has not expired. A deactivation (cause 8) cancels a pending selection.

What does activation confirmation mean in IEC 60870-5?

Cause of transmission 7: the outstation's reply to a command. With the P/N bit clear, it accepted the command; with the P/N bit set, it refused it. It does not report whether the equipment has moved, and a refusal carries no reason code.

What is activation termination?

Cause of transmission 10: the outstation reports that it has finished executing the command. Its use is optional and is set for each point in the interoperability list.

Why does the breaker status arrive with cause 3 instead of cause 11?

Cause 11 marks a change caused by a remote command, but not every outstation links the change to the command. Many report it as an ordinary spontaneous change with cause 3. Correlate on the point and a time window, and accept either cause.