IEC 60870-5-104 Set of Standards

Jun 5
17:06

2020

Sandra Moraes

Sandra Moraes

  • Share this article on Facebook
  • Share this article on Twitter
  • Share this article on Linkedin

The IEC 60870-5-104 is one among the six parts of IEC standard 60870. It was released by the International Electrotechnical Commission, in the year 2000. IEC 60870-5 gives a communication profile to transmit basic telecontrol messages among two systems. It makes use of data circuits within the system. A protocol standard was created by the International Electrotechnical Commission Technical Committee. This is for teleprotection, telecontrol and related telecommunications of electric power systems. The outcome was IEC 60870-5.

mediaimage

IEC 104 is the extension of IEC 101. The only exception is differences in the link layer,IEC 60870-5-104 Set of Standards Articles network layer, transport layer and physical layer services. IEC 60870-5-104 uses a router to connect to the Wide Area Network and Transmission Control Protocol/Internet Protocol network to connect to the Local Area Network. The IEC 60870-5-104 application level is maintained like that of IEC 60870-5-101, where some data types and facilities are left out. For the purpose of transfer of data through serial line and ethernet, two distinctive link layers are suitable for that purpose and are defined in the IEC 60870-5-104. Different kinds of mechanisms for effective management of network data synchronisation are there in the control field data of IEC 60870-5-104. 

 

The problem with the IEC 60870-5-104 is that it's not secure by design. A security standard called IEC 62351 was published by the International Electrotechnical Commission Technical Committee, that carries out end-to-end encryption. The IEC 62351 prevents playback attack, forging packets and man-in-the-middle attack. But vendors are hesitant to use it on their networks, because of the rise in complexity. 

 

Short timestamps are not supported by IEC 60870-5-104, IEC61850 SCL Engineering and the address element's length is adjusted to a particular value. But both the IEC 60870-5-104(transport profile) and IEC 60870-5-101(application layer) are combined without considering this restriction. If the standard is applied by a device, then it can cause problems. 

An interoperability list is used to check the interoperability among devices. In the interoperability list, the applicable functions will be marked. This indicates the function range. 

 

There is a concurrent transmission of data among several devices and services since the standard facilitates communication through a standard network. This is considered as the greatest benefit of IEC 60870-5-104.

 

The advantages and disadvantages of IEC 60870-5-104 and IEC 60870-5-101 are similar. Problems that need to be emphasised are both the usage of data encryption and internet as well as the definition of communication of redundant systems.

 

Interoperability

 

The interoperability document specifies the available application functions and its choices. It also distinguishes the cause of transmission and the supported application service data unit. The control centre knows the method to configure the communication with the device by making use of the interoperability document. By using an interoperability document the control centre can understand whether the RTU is compatible with its necessary functions or not. Choose the compatible choices contrasting the remote station and control centre interoperability documents.

 

Profiles

 

The profiles are a set of documented requirements that choose a particular group of options from the ones accessible in the standard IEC 60870-5-101 or IEC 60870-5-104(IEC 61850). Normally the utility profiles specify distinct points configured with certain uses in their system and addresses ranges for the various data types. The motivation for the profiles is to clear up any concern of inaccurate standards and also the limitation of the available choices to choose the most suitable one depending on the utility needs. While a different profile might be asking to send them using the floating-point Application service data unit and spontaneous transmission. The RTU manufacturer should examine if the device meets the profile requirements as stated by the utility prior to their devices can be installed in their system. To ensure whether their profile is implemented or not, the utility will request for an RTU testing. The utility provides a test specification. The conformance test will be conducted with this. 

 

The International Electrotechnical Commission defines documents for IEC 60870-5-601 or IEC 60870-5-604 along with the test procedures to ratify the stations that make use of these standards. The test cases to be carried out is conditional on the device capabilities described in their interoperability.

 

Security Inclusion With IEC 60870 5-104

 

Both IEC 60870-5-101 and IEC 60870-5-104 are prone to data modification through hijack attack because both these standards don't include data authentication. In a security measure, there are tables with a complete list of private networks, authorised IP addresses and firewalls in the remote station. But nowadays these security measures are considered poor. The TC 57 WG15 experts are developing an extension for the safety of remote control communications. The technical specification IEC 62351-5 gives an account of the important topics related to the safety of IEC 60870-5-101 and IEC 60870-5-104. The latest application service data unit messages are described in The technical specification IEC 60870-5-7. IEC 62351-100-1 specifies the test procedures to ratify secure implementations.