Skip to content

Smart IEC 61850 interoperability: canonical convergence, type-safe RCB mutation, unified acquisition #144

Description

@masarray

Problem

A physical SIPROTEC 7SX85 interoperability case exposed a concrete engine defect and a broader architectural gap.

Observed field evidence on ARSAS 1.6.40 / ARIEC61850 1.6.40:

  • discovery succeeded: 33 LD, 2 static DataSets, 12 static members, 12 RCBs (6 BRCB + 6 URCB);
  • static URCB activation succeeded;
  • static BRCB activation failed with MMS type-inconsistent (7) on ResvTms=60;
  • six BRCB-backed signals therefore remained unavailable in Static DataSet report-only mode;
  • the current client-compatibility path encodes ResvTms using MmsDataValue.Unsigned(...), while the IEC 61850 BRCB semantic type is signed integer / INT16;
  • individual signal selection can still fall through the stricter hybrid availability path to MMS polling even when the signal is already covered by a configured static DataSet/RCB.

This must not be solved as a one-off Siemens/vendor patch.

Architectural invariant

IP Discovery and Open SCL are two bootstrap/evidence sources for the same IED, not two runtime systems.

Both paths must converge into the same canonical model, connection/session lifecycle, acquisition planner, reporting executor, control runtime and diagnostics.

IP Discovery ─┐
              ├─> Canonical IED Model -> Common Connection System
Open SCL ─────┘                           -> Common Acquisition Planner
                                          -> Common Reporting Executor
                                          -> Common Control Runtime

The bootstrap cost may differ: Open SCL should use bounded live reconciliation instead of needlessly repeating full discovery, but downstream behavior must be the same.

Non-negotiable design rules

  1. No protocol decision from UI strings.
  2. No vendor-name branching for normal interoperability.
  3. No raw MMS scalar type embedded in reporting business logic.
  4. No mutation without typed preconditions.
  5. No write success without readback/proof where applicable.
  6. Missing evidence must not be treated as negative evidence.
  7. No retry without a classified reason and bounded evidence-driven strategy.
  8. ARSAS must not duplicate IEC 61850 protocol semantics owned by ARIEC61850.
  9. No positional report projection without authoritative ordered DataSet membership.
  10. Physically qualified behavior must not be replaced by an unqualified "cleaner" implementation.

Target architecture

Introduce an evidence-driven interoperability layer that composes:

  • IEC semantic contracts;
  • SCL declaration evidence;
  • canonical/live MMS model evidence;
  • live MMS TypeSpecification;
  • DataSet directory/order evidence;
  • RCB ownership/reservation evidence;
  • association capabilities;
  • previous proven stable capability evidence;
  • current transaction/readback/report-traffic evidence.

Planning and mutation execution must be separate:

  • Planner: pure/deterministic, no mutation;
  • Executor: just-in-time revalidation, minimum mutation, bounded compatibility ladder;
  • Verifier: readback + actual InformationReport proof;
  • Cleanup: ownership-safe transactional rollback.

Implementation phases

P-1 — Canonical convergence contract

  • one canonical IED model for Discovery and Open SCL;
  • one connection/session lifecycle;
  • one acquisition planner;
  • one reporting executor;
  • one control runtime;
  • source provenance retained as evidence, not as a forked runtime behavior switch;
  • architecture regression proving equivalent model/acquisition plans from Discovery vs Open SCL for the same IED.

P0 — Immediate RCB type correctness

  • centralize well-known RCB field semantics;
  • encode ResvTms as MMS signed integer, never unsigned;
  • audit every direct RCB scalar write/release;
  • add exact BER/type regression tests;
  • remove duplicated hard-coded MmsDataValue.* choices from activation paths.

P1 — Type-aware mutation

  • exact/bounded GetVariableAccessAttributes preflight for the mutation surface;
  • reconcile IEC semantic type with live MMS TypeSpecification;
  • type-safe semantic write builder;
  • if a write returns type-inconsistent, revalidate exact live type and retry only when one safe semantic conversion is proven;
  • no blind "try several types" behavior.

P2 — Evidence/confidence model

Track granular evidence independently, e.g.:

  • RCB identity;
  • DataSet binding;
  • ordered membership;
  • RptEna state;
  • owner/reservation state;
  • field type;
  • write permission;
  • report traffic.

Differentiate:

  • missing evidence;
  • reduced confidence;
  • positive blocker evidence;
  • proven success.

P3 — Transactional RCB lifecycle

  • snapshot;
  • JIT preconditions;
  • receiver-before-write;
  • minimum writes;
  • readback;
  • one-shot GI when appropriate;
  • actual InformationReport proof;
  • rollback only fields/reservations owned or changed by this client;
  • explicit cleanup state: Clean / Partial / Residue / Unknown.

P4 — Unified acquisition planner

For every selected signal, regardless of UI entry path:

  1. configured static DataSet/RCB coverage;
  2. bounded dynamic reporting only for residual points when policy allows;
  3. MMS polling only for true residual coverage.

When one selected point belongs to a static DataSet, subscribe to the full ordered DataSet on the wire and project only the selected subset into the UI/runtime.

P5 — SCL/live convergence

Classify divergence explicitly:

  • ExactMatch;
  • RuntimeReduced;
  • RuntimeExpanded;
  • OrderMismatch;
  • BindingMismatch;
  • MissingConfiguredMember;
  • ExtraRuntimeMember;
  • RCBFamilyMismatch.

Authority is contextual:

  • offline engineering: SCL;
  • online report index/order: live DataSet directory;
  • user-friendly semantic identity: canonical/SCL + live evidence;
  • ownership/reservation: live runtime state.

P6 — Stable capability fingerprint

Cache stable evidence such as type signatures/service support/model fingerprints, but never treat volatile state as durable:

  • volatile: RptEna, Owner, Resv, ResvTms, EntryID, SqNum;
  • these must be refreshed before mutation.

P7 — Qualification

Regression dimensions, not vendor branches:

  • BRCB ResvTms integer;
  • direct RptEna path;
  • explicit reservation fallback;
  • Owner unsupported vs foreign Owner;
  • SCL/live DataSet count/order mismatch;
  • GI unsupported/accepted/no-traffic cases;
  • RptEna accepted but readback false;
  • segmented/duplicate BRCB traffic;
  • association loss mid-transaction;
  • individual signal inside a static DataSet;
  • signals spanning multiple static DataSets;
  • true residual polling.

Qualification stages:
CodeVerified -> WireVerified -> PhysicalVerified.

First implementation slice

Start with P0/P1 foundation without changing production policy:

  1. add a central typed RCB field contract/encoder;
  2. migrate ResvTms, RptEna, Resv, GI mutation sites to that encoder;
  3. prove ResvTms=60 emits MMS INTEGER and cleanup ResvTms=0 emits MMS INTEGER;
  4. add tests that reject semantic/type mismatches;
  5. keep the field-proven activation order and receiver-before-write behavior unchanged.

Acceptance criteria for the first slice

  • no MmsDataValue.Unsigned(...) write remains for ResvTms;
  • centralized semantic encoder is the only normal path for the migrated RCB scalar fields;
  • existing URCB behavior is unchanged;
  • BRCB direct-RptEna primary path remains unchanged;
  • BRCB explicit reservation remains bounded compatibility fallback unless a higher-level proven plan requires it;
  • tests cover wire kind and range constraints;
  • no vendor-specific conditional logic is introduced;
  • no ARSAS-side IEC semantic duplication is introduced.

Field regression target

For the reported 7SX85 class of behavior:

  • static BRCB reservation must use correct signed integer semantics;
  • BRCB activation must no longer fail solely because ARIEC61850 emitted ResvTms as unsigned;
  • final success still requires RptEna/readback and InformationReport proof rather than assuming a successful write equals a working subscription.

Activity

  1. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    Implementation started in draft PR #145 on branch fix/144-smart-interop-p0.

    Current P0 slice:

    • central typed RCB scalar semantic contract;
    • ResvTms now maps to MMS signed INTEGER / non-negative INT16 semantics;
    • RptEna, Resv, GI scalar mutations routed through the same semantic boundary;
    • static-SCL, persistent-monitor and client-compatibility cleanup paths migrated;
    • wire regression added for integer tag [5] vs unsigned [6];
    • live TypeSpecification compatibility predicate added as the P1 foundation.

    .NET CI #703 is running. No merge/production repin is implied until CI and later physical validation pass.

  2. 107 remaining items

  3. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    P6 software gate is now green.

    CI-only integration PR #148 exact head 51fa7092e83472a125aae9a29f033d31f59e6281 passed .NET CI #758 end-to-end: provenance/source gate, restore, Release build, full tests, package, artifact and diagnostics upload.

    P6 / PR #150 now provides the engine-owned source-aware boundary:

    • MmsReportInventory carries authority with the data;
    • live MMS discovery stamps LiveMmsObserved;
    • SCL and canonical model projections remain structural, never operational live evidence;
    • MmsCanonicalReportInventoryProjection preserves exact configured DataSet/RCB identity with no indexed-name or live-state fabrication;
    • canonical static coverage -> exact live RCB target -> targeted availability is one engine contract;
    • unresolved targets never broaden automatically;
    • target budget overflow performs zero partial network work.

    CI #754 correctly caught a test-only enum typo before this gate; it was fixed without altering runtime policy.

    Next coordinated milestone is consumer adoption in ARSAS #446, but the engine lock/SCL-association files remain under active PR #425 ownership, so no competing repin or overwrite was made.

  4. masarray commented on Oct 7, 2026

    @masarray
    OwnerAuthor

    P6.1 targeted live RCB reconciliation is now software-gated.

    Stacked PR #151 adds the missing Open-SCL/Discovery-neutral bridge from canonical static coverage to actual live RCB evidence without full discovery. Combined exact head 9c5292570f55dd81be1b3a6b56f937e5ba1ed276 passed .NET CI #759 end-to-end.

    The new smart path enumerates NamedVariable only for the exact MMS domains participating in selected static coverage, filters to required BRCB/URCB classes, reads whole-RCB/DatSet evidence only for those candidates, and then reuses #150 exact-target preflight + #147 targeted availability. Domain/candidate budget overflow fails closed rather than probing a partial arbitrary subset.

    Next lane is ARSAS #446 consumer adoption, stacked on active ARSAS PR #425 so that thread ownership is preserved.

  5. masarray commented on Oct 8, 2026

    @masarray
    OwnerAuthor

    Consumer synchronization — P7.6A

    Engine P6.2 PR #153 exact commit 352c81e6a798635c6addcee0683235ca87ad416d remains the pinned, CI-proven engine authority for ARSAS P7.5 #476 and new P7.6A #480. P7.6A code SHA 1384185a1f42bcf2901e9be0f730863813420ba4 passed 11/11 ARSAS workflows, 1359 tests. It modifies consumer-side SCD AP endpoint provenance only; no engine fork/repin and no changed RCB wire protocol.

    Shared cross-thread handoff. P7.6A AP J↔F physical tests and Discovery/SCL dual-ingress parity remain open. Both projects are still stacked draft, not merged or released. Engine PR #154 remains CI-only/DO NOT MERGE.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions