# GOOSE with PRP or HSR: Supervise the Trip, Not Just the Link

> Specify degraded-state GOOSE trip logic, test single-path failures and distinguish network redundancy from a dead publisher, stale data or failed trip output.

- **Category:** Protection & Control
- **Author:** Voltformer Engineering
- **Publication date:** 2026-10-07
- **Reading time:** 6 min read
- **Key topics:** GOOSE supervision, PRP redundancy, HSR redundancy, Trip logic
- **Body language:** en
- **URL:** https://voltformer.com/articles/iec-61850-goose-prp-hsr-failover-trip-supervision

### 1. Redundancy is only one protection boundary

A healthy Ethernet link does not prove a usable trip message. PRP and HSR improve network availability, but a publisher can stop producing valid data, a subscriber can reject a changed configuration, or an output circuit can fail after reception. Specify each boundary separately. The public [IEC 62439-3:2021 scope](https://webstore.iec.ch/en/publication/64423) describes seamless redundancy; it does not promise that every protection application survives every common-mode failure. Start with the required protection behavior during loss of communication, then select the network. The broader [digital-substation guide](https://voltformer.com/articles/iec-61850-substation-automation-goose-and-sampled-values-for-protection) provides the architectural context.

### 2. Define signals and independence

For each subscribed signal identify the publisher, dataset, control block, configuration revision, Ethernet addressing, VLAN, quality handling and supervision behavior supported by the IED. Separate a direct trip from a permissive, blocking signal or interlock: their consequences on loss are different. Record power supplies, fibre routes, switches and any redundancy boxes shared by the two paths. Two ports on a common switch are not independent networks. [IEC 61850-8-1](https://webstore.iec.ch/en/publication/6021) is the communication-mapping reference; the public page also identifies its consolidated amendment. Use purchased normative text and device implementation documents for actual acceptance requirements rather than inventing a clause from the abstract.

### 3. Illustrative timing budget

Suppose a project allows 20 ms from the publisher's input transition to the subscriber's trip-output assertion. Allocate 3 ms to publishing, 2 ms to network transit, 4 ms to subscriber processing and 3 ms to output assertion. The subtotal is 12 ms, leaving 8 ms margin.

$$
3 + 2 + 4 + 3 = 12;   20 - 12 = 8
$$

These are illustrative allocations, not measured relay specifications or IEC limits. A separate 30 ms reconvergence interval would already exceed this budget before any later retransmission is received. Do not add recovery delay to a seamless PRP/HSR model as though it were ordinary failover; instead test actual delivery on the surviving path. Breaker interruption time belongs to a separate total fault-clearing budget.

### 4. Choose the topology and failure response

| Condition | Evidence to observe | Engineering decision |
|---|---|---|
| One PRP LAN lost | Valid reception and redundancy alarm | Continue the approved trip function |
| One HSR path interrupted | Valid reception and ring/path alarm | Verify remaining topology and loading |
| Publisher lost | Subscription timeout and invalid data | Apply signal-specific degraded logic |
| Output circuit failed | Trip-circuit supervision and breaker response | Escalate through independent backup |

PRP uses separate networks; HSR uses redundant routes through its topology. Neither cures loss of the source IED. The [SEL design paper](https://cms-cdn.selinc.com/assets/Literature/Publications/Technical%20Papers/7194_ArcFlashProtection_MW_20250401_Web.pdf?v=20250924-185312) shows why reconvergence and GOOSE retransmission can interact unfavorably. This is a reason to prove timing under failure, not to assign a universal acceptable delay.

### 5. Write the cause-and-effect matrix

For a blocking scheme, disappearance of the block may reduce security; holding an old block indefinitely may reduce dependability. For a permissive scheme, loss usually removes permission but must not silently disable independent local backup. For direct tripping, stale data should not be treated as a fresh command unless the documented application explicitly defines that behavior. Agree the choice with the protection owner and demonstrate it with the exact firmware. Include restart, configuration mismatch, test/simulation modes and return to service. Alarms need an owner and an actionable message, rather than merely a network diagnostic buried in an event log.

### 6. Commission observable failures

Use an isolated test environment or an approved outage plan. Demonstrate both the trip and the absence of unwanted trips while interrupting each network path in turn. Repeat with publisher power loss, subscriber restart, background traffic and a deliberately mismatched test configuration. Capture input transition, transmitted state, received validity and output assertion on a common traceable time basis. Require the supplier's configuration files and supported supervision objects, plus switch configuration and route drawings. Record duplicate-handling evidence where available. Connect communication-loss behavior to the [breaker-failure intertrip review](https://voltformer.com/articles/breaker-failure-50bf-timing-mv-intertrip-coordination), including the backup path's independence.

### 7. Practical questions

#### Does zero recovery time mean zero message latency?

No. It describes the redundancy mechanism. Publishing, transit, subscription processing and outputs still take time.

#### Can a PRP alarm substitute for GOOSE supervision?

No. Network-path health and valid subscribed data answer different questions; both belong in the scheme evidence.

#### Should loss of GOOSE always trip the breaker?

No universal response is appropriate. The signal's protection role, available backup and project operating policy determine the degraded-state action.

### 8. Primary references

- [IEC 62439-3:2021](https://webstore.iec.ch/en/publication/64423)
- [IEC 61850-8-1](https://webstore.iec.ch/en/publication/6021)
- [SEL — Arc-Flash](https://cms-cdn.selinc.com/assets/Literature/Publications/Technical%20Papers/7194_ArcFlashProtection_MW_20250401_Web.pdf?v=20250924-185312)

[← Back to Scope](https://voltformer.com/articles.md) · [View Related Equipment](https://voltformer.com/catalog) · [JSON](https://voltformer.com/articles/iec-61850-goose-prp-hsr-failover-trip-supervision.json)
