A reliable power substation communication network gets five things right: the IEC 61850 process, bay, and station levels; access and backbone switching tiers; deterministic redundancy; precision time synchronization; and cybersecurity built in from the start. A weak link in any of these degrades protection, control, and event records for the substation itself.

What does the IEC 61850 three-level model actually require from the network?

The IEC 61850 standard organizes substation communication into three levels. The process level is where devices interface directly with switching and monitoring equipment. The bay level is where intelligent electronic devices (IEDs), such as protection relays, meters, and controllers, act on that data. The station level aggregates that data for SCADA and site-wide monitoring. Time-critical traffic has to move between these levels fast and predictably, including GOOSE messages (Generic Object-Oriented Substation Event, used for trip commands and status changes) and Sampled Values (streamed digitized measurements). The switching layer connecting these levels can't be generic industrial Ethernet gear, because it needs to meet IEC 61850-3's electromagnetic compatibility and environmental requirements. Those requirements are stricter than standard industrial ratings, because substations sit close to high-voltage switching equipment.

How should backbone and access switching be layered?

A substation network typically needs two switching tiers: access and backbone. The access tier sits closest to bay-level IEDs, aggregating a handful of devices per bay with just enough ports for that bay's traffic. The backbone tier aggregates traffic across bays and carries it to the station level. This tier needs far more throughput and uplink capacity, often stepping up to multi-gigabit or 10-gigabit fiber. It also needs switching capacity headroom, so new bays can be added later without a redesign. Some substation networks also need to route traffic between sites, not just within one. In that case, the backbone tier needs Layer 3 routing, not just Layer 2 switching. Retrofitting routing into a Layer 2-only backbone later means replacing hardware, not reconfiguring it, so this is a decision best made early.

What redundancy protocols actually prevent downtime?

Substation redundancy solves two different problems. Network-level redundancy keeps traffic flowing when a link or switch fails. Ring protocols such as RSTP (Rapid Spanning Tree Protocol), ITU-T G.8032 Ethernet Ring Protection Switching (ERPS), or MRP (Media Redundancy Protocol) handle this, rerouting traffic within tens of milliseconds of a failure. Device-level redundancy protects IEC 61850 devices that can't tolerate even that brief reconvergence window. IEC 62439-3 defines two zero-packet-loss protocols for this: Parallel Redundancy Protocol (PRP) and High-availability Seamless Redundancy (HSR). PRP duplicates traffic across two independent LANs, so a single failure never interrupts delivery. HSR duplicates traffic around a ring instead. Devices that aren't natively PRP- or HSR-capable can still join a redundant network through a “redbox,” an intermediary that bridges single-attached devices into the redundant LAN or ring. A well-designed substation network runs both layers together: ring protocols keep the switching fabric itself resilient, and PRP or HSR protects the specific devices that need zero packet loss.

Why does precision timing matter as much as switching?

Every protection relay, event recorder, and disturbance-monitoring device in a substation needs to agree on the same time reference. Without it, operators can't reconstruct the correct sequence of events during a fault, and protection devices can't coordinate correctly either. IEEE 1588 Precision Time Protocol (PTP) delivers this, typically in its power-utility profile (IEEE C37.238, IEC/IEEE 61850-9-3), distributed across the network from a GNSS-referenced grandmaster clock. A single grandmaster can't serve every device directly in a large substation without becoming a bottleneck, so the switching fabric shares the timing load. Switches acting as PTP boundary clocks re-time each hop. Transparent clocks compensate for the delay traffic accumulates passing through a switch. Both roles keep end-to-end time deviation low across a large, multi-hop network.

How is substation cybersecurity actually built in, rather than bolted on?

Substations combine high availability requirements, wide geographic spread, and often long-lived legacy equipment, which makes retrofitted security difficult and makes secure-by-design hardware genuinely valuable, not just a checkbox. The relevant benchmark is the IEC 62443 series. IEC 62443-4-1 certifies that a vendor's product development process follows a secure lifecycle. IEC 62443-4-2 certifies that the product itself meets defined technical security requirements: access control, network segmentation, and encryption designed in, not layered on after deployment. The two certifications answer different questions.

IEC 62443 certification secures the product itself, while a unidirectional gateway secures the boundary where the OT network meets IT or business systems instead. This is typically where SCADA and historian data needs to leave the substation for reporting, while nothing should be able to come back in unchecked. This kind of gateway, also called a data diode, uses physical layer-1 isolation, not firewall rules, so data can only leave the OT side and never enter it. Because that return path doesn't exist physically, rather than being blocked only by policy, a data diode closes off an entire category of malware and ransomware paths that a misconfigured or bypassed firewall can't fully rule out.

Where ATOP's substation portfolio fits

ATOP's substation lineup maps directly onto the layers above. The below switches, carry IEC 61850-3 and IEEE 1613 certification for substation-grade EMC and environmental durability:

  EH9711 (access) RHG9528 / RHG9728 (backbone, L2) RHG9628 / RHG9828 (backbone, L3)
Role Process-to-bay access switching High-density Layer 2 backbone aggregation Backbone aggregation with routing between substations/sites
Ports 8× FE + 3× GbE SFP Up to 24× GbE + 4× 10G SFP uplinks Up to 24× GbE + 4× 10G SFP uplinks
Switching capacity 7.6 Gbps, 5.7 Mpps 128 Gbps, 95.24 Mpps 128 Gbps, 95.24 Mpps
Routing Layer 2 Layer 2 Layer 3
PTP hardware clock Transparent Clock Boundary + Transparent Clock Boundary + Transparent Clock
PoE Up to 90 W/port, 720 W total budget Up to 90 W/port, 720 W total budget
Operating temperature −40 to +75 °C −40 to +85 °C −40 to +85 °C
Certifications IEC 61850-3, IEEE 1613, IEC 62443-4-1/-4-2 IEC 61850-3, IEEE 1613, IEC 62443-4-1 IEC 61850-3, IEEE 1613, IEC 62443-4-1

For device-level redundancy, RGB7008 acts as a redbox, bridging single-attached devices into a PRP or HSR network in Redbox or Quadbox topologies. A Quadbox is four interconnected redboxes, used for added fault tolerance in larger networks. RGB7008 runs up to three HSR or PRP instances at once.

For timing, the NTS8610 grandmaster clock is certified to both IEC 61850-3 HV and IEEE 1613. Calnex Solutions, a third-party network-timing test lab with no ATOP affiliation, independently verified its PTP and PRTC-B accuracy within 40 ns, with holdover drift under 0.5 µs over 8 hours.

On cybersecurity, ATOP holds IEC 62443-4-1 ML2 certification for its secure development lifecycle, as of November 2025. The EH9711 has achieved IEC 62443-4-2 SL2 certification for the product itself: access control (802.1X, AAA, ACL, IP source guard), segmentation, and encryption are built into the switch, not added after deployment. ATOP intends to extend IEC 62443-4-2 certification across more of its substation portfolio.

For the IT/OT boundary itself, ATOP's partner, BlackBear Cyber Security, offers the BIG9000 Series unidirectional gateway. It's an FPGA-based data diode, rated −40°C to +70°C and IEC 62443-4-1 certified. It inspects Layer 3 to Layer 7 traffic and explicitly supports substation protocols, including IEC 61850, DNP3.0, and IEC 60870-5-104. An optional MACsec-encrypted variant adds last-mile protection for outgoing data. See BlackBear Cyber Security for the full specification.

A 220kV digital substation in Vietnam shows these pieces working together. Critical IEC 61850 devices ran PRP across two independent LANs for device-level redundancy. RHG9728 switches ran RSTP inside each LAN for network-level resilience. A GPS-referenced NTS8610 distributed NTP and PTP across both redundant paths, giving every device a common time reference. (For a full comparison of when to use HSR versus PRP specifically, see ATOP's dedicated guide to substation redundancy.)