Start here
How a Utility Sees Its Grid
Last session ended on Schweitzer Engineering Laboratories (SEL) relays and SCADA — on what gets measured at a substation. This session is about what happens to that measurement next: how it leaves the yard, what carries it, what language it speaks, how it gets a trustworthy timestamp, what a control center actually does with it, and — at the end — how one real utility, Entergy, does all of that across four states.
The path we'll follow
- The problem — a grid is enormous and instantaneous at the same time.
- A little history — from a man reading a meter to wide-area measurement.
- What SCADA actually is — and how it differs from the energy management system (EMS) and its relatives — DMS, OMS, ADMS.
- The link — media: fiber, microwave, radio, leased line, cellular, satellite, power-line carrier. Then the copper detail that still bites you.
- Protocols — Modbus, Distributed Network Protocol 3 (DNP3), IEC 61850, the Inter-Control Center Communications Protocol (ICCP) — and security.
- Time — GPS, sequence-of-events, and synchrophasors.
- What they do with the data — state estimation, contingency analysis, outage management, self-healing feeders, advanced metering infrastructure (AMI), market dispatch.
- The case study — Entergy, entirely from the public record — including an honest look at where that record stops, and why.
1 · The problem
Enormous and Instantaneous at the Same Time
A power system is unusual among engineered systems because it is extreme in two opposite directions at once.
It is geographically enormous
Entergy's transmission system alone is roughly 16,100 circuit miles of line and about 1,300 substations at 69 kV to 500 kV, spread over about 114,000 square miles of Arkansas, Louisiana, Mississippi and east Texas, serving around 3 million customers.
You cannot put a qualified person at every one of those 1,300 substations, every hour of every day. Even if you could afford it, they would each only see their own fence line.
It is electrically instantaneous
There is essentially no storage in the middle. Generation and load must balance continuously, and a disturbance propagates across the interconnection in a fraction of a second — faster than any human decision loop.
The electromechanical swings that precede a wide-area collapse live around 0.1–0.8 Hz. A problem that develops in a couple of seconds cannot be managed by a phone call between substations.
So the requirement writes itself
If you cannot put a person everywhere, and the thing you are watching moves faster than a person can travel, then you must bring the measurement to the person — fast enough to matter, accurately enough to trust, and reliably enough that it still arrives during the storm that made you need it.
That is the entire job description of utility communications. Everything else in this lecture is engineering detail hanging off that one sentence.
The case that proved it: 14 August 2003
If you have not run across this one before, it is the event the whole industry still measures itself against. On the afternoon of 14 August 2003, a cascading failure that began in northern Ohio spread across eight US states and into Ontario and took down the grid for roughly 50 million people. Most of the cascade happened in about seven minutes.
The physical triggers were ordinary and, individually, survivable: a generating unit tripped, and then several heavily loaded transmission lines sagged into trees that had not been trimmed back far enough. Grids are built to absorb that sort of thing. What turned a bad afternoon into a blackout was something else entirely — the control center could not see what was happening. The utility's alarm processor had failed, and it failed silently, so the operators were reading a screen that had quietly stopped telling them the truth. They spent the critical hour believing their system was healthy.
The joint US–Canada task force published its findings in 2004, and the consequences are why this course exists in the form it does: reliability standards stopped being voluntary guidance and became mandatory and enforceable, and the industry began a serious push into faster, time-synchronized wide-area measurement — the synchrophasor work we will get to later in this lecture.
2 · A little history
From a Man With a Clipboard to Wide-Area Measurement
Utility telemetry did not arrive fully formed. Each stage solved the previous stage's limitation, and — importantly — none of the old stages fully disappeared. You will still find every one of these in service somewhere today.
- Attended substations. A human read gauges and phoned the load dispatcher. Latency measured in minutes; coverage limited to where you paid someone to stand.
- Telemetering. A transducer converted a measurement into a current, a voltage, or an audio tone sent over a leased telephone pair. One quantity, one pair — expensive, and it drifted with the weather. The word "telemetering" is older than the word "SCADA".
- Digital RTUs. The first microprocessor outstations multiplexed many points onto one link. Proprietary serial protocols (Telegyr / L&G 8979 is the classic 1970s example) followed, and some are still polled today.
- Control-center SCADA, then the energy management system. Once you have many RTUs on one master, you can build a control room. Add a network model on top and you have an EMS — an energy management system, not an emergency one — that can reason about the system rather than just display it.
- Station Ethernet. IEC 61850 moved the substation's internal wiring onto a local area network (LAN) and replaced runs of copper with messages.
- Wide-area measurement. GPS-synchronized phasor measurement gave, for the first time, a simultaneous picture across hundreds of miles.
3 · Definitions
What SCADA Actually Is — and What It Is Not
The acronym is doing real work and it is worth unpacking one word at a time.
| Word | What it means in practice |
|---|---|
| Supervisory | A human (or an automated scheme acting for one) supervises. SCADA does not close the protection loop — it does not decide in 2 ms that a fault exists. That is the relay's job, and the relay does it locally, without asking anybody. |
| Control | Commands go out: open a breaker, close a recloser, switch a capacitor bank, raise a tap. This is the half that makes SCADA more than a monitoring system — and the half that makes it a security target. |
| And Data | Measurements come in: analog values, digital status, counters, alarms. |
| Acquisition | Acquisition is an activity, not a technology. Any system that gathers field measurements is doing data acquisition — including, as we'll see, a synchrophasor network. |
The critical limitation
Plain SCADA has no model of the network. It knows that the point tagged
BUS7-MW currently reads 143.2, and it knows there is a button that opens breaker
52-7. It does not know that those two things are electrically related, and it cannot
answer "what happens if that line trips?"
That limitation is precisely why the layers above SCADA exist — and it is the subject of the next slide.
3 · Definitions
SCADA vs EMS vs DMS vs OMS vs ADMS
These get used interchangeably in conversation and they are not interchangeable at all. They differ by what they know and what question they answer.
| System | Where it lives | What it adds | The question it answers |
|---|---|---|---|
| SCADA Supervisory Control And Data Acquisition | Transmission and distribution | Real-time telemetry acquisition plus supervisory control. No network model. | "What is this point doing right now, and can I operate it?" |
| EMS Energy Management System | Bulk transmission | A network model on top of SCADA: state estimation, contingency analysis, optimal power flow, generation dispatch and interchange. | "What is the whole network doing, and what would happen if something changed?" |
| DMS Distribution Management System | Distribution | Feeder model, switching orders, volt/VAR optimization, fault location, isolation and service restoration (FLISR) logic. | "How should this feeder be configured, and what is it doing between the few points I actually measure?" |
| OMS Outage Management System | Distribution / customer | Correlates customer calls and smart-meter last-gasp messages against the feeder model to predict the failed device. Incident management, not real-time control. | "What is broken, how many customers are out, and who do I send?" |
| ADMS Advanced Distribution Management System | Distribution | The modern consolidation of distribution SCADA + DMS + OMS onto one shared network model. | All three of the above, without three databases disagreeing with each other. |
Note the asymmetry between transmission and distribution. Transmission has historically been heavily instrumented, so its EMS leans on measurement. Distribution has far fewer telemetered points per mile, so its DMS leans much harder on the model and on estimation. That difference shows up again later when we look at why synchrophasors are a transmission technology.
3 · Definitions
The Control Hierarchy — Five Layers, One Reason
Every layer exists because the layer below it cannot see far enough or think fast enough.
- IED — Intelligent Electronic Device. Any microprocessor-based device out in the substation that measures, protects, or controls: a protective relay, a meter, a regulator controller. It is "intelligent" because it makes its own decisions locally rather than waiting to be told.
- RTU — Remote Terminal Unit. The substation's data concentrator. It gathers points from the IEDs, puts them on a common protocol and time base, and presents one stream to the control center.
- ISO — Independent System Operator and RTO — Regional Transmission Organization. Both are the neutral party that operates the bulk transmission grid and its market across many utilities at once, so no single utility controls the shared network. The two names mean nearly the same thing in practice; the RTO label carries a wider regional footprint. The Midcontinent Independent System Operator (MISO), which Entergy joined and which we come back to later, is an RTO.
- Reliability Coordinator (RC). This is the role the ISO or RTO plays at the top of the diagram, and it is the widest view of the grid that exists. The RC watches the bulk power system across many utilities at once, looking for problems that no single utility can see from inside its own fence line — because the utility can only see its own territory, and a cascade does not respect territory. The RC has the authority to issue directives that a utility must follow. It does not operate that utility's equipment itself; the next callout explains why that distinction matters.
Check your understanding · 1
Architecture and Vocabulary
Answer each one in your head — or out loud — before revealing it.
4 · The link
Why a Utility Wants to Own the Wire
Now we get to the physical link itself — the actual wire, fiber, and radio that carry all of this. But it needs a motive first, because the single strongest driver of utility media choice is not bandwidth and it is not cost.
The awkward truth about utility communications
A utility needs its communications most during exactly the conditions that break communications: hurricanes, ice storms, tornado outbreaks, wide-area outages. A commercial telecom link that is 99.9% available sounds excellent until you notice that the 0.1% is correlated with the emergency.
Media you own
- You set the restoration priority — your circuit is not queued behind a shopping mall.
- You control the physical route, so you know what is single-point-of-failure.
- You engineer the power supply — station battery, not a carrier's cabinet.
- Security scope is yours, which matters directly under NERC Critical Infrastructure Protection (CIP).
- No monthly circuit charge across 1,300 sites.
Media you lease or share
- Cheap and fast to deploy — often the only option to a remote site.
- Somebody else's outage is now your outage.
- Carrier cell sites can lose power in the very event you need to watch.
- Public networks congest during widespread emergencies.
- Third-party dependency inside your electronic security perimeter.
Keep that principle in hand. When we get to the Entergy case study, it is the lens that makes the published facts make sense.
4 · The link
Fiber, and Why Optical Ground Wire (OPGW) Is the Transmission Workhorse
If a utility can get fiber to a transmission substation, it generally does. The reason is an elegant piece of double-duty engineering called OPGW — Optical Ground Wire.
- What it is. A conventional overhead shield wire, but with optical fibers built into a tube inside a strong, conducting metallic sheath.
- Why it is economical. The line needs a shield wire regardless, and the structures and right-of-way already exist. You are adding fiber to a cable you were going to string anyway — not building a separate telecom route across 114,000 square miles.
- What it buys you. Immense bandwidth, immunity to electromagnetic interference (EMI) and to ground potential rise, no electrical connection between substations, and latency limited essentially by the speed of light in glass.
- The failure mode that matters. It is one physical object doing two jobs. Ice loading, conductor galloping, a tower failure, or a construction strike takes out lightning shielding and communications together, at the same instant, in the weather that caused it. That is a genuine argument for a diverse second path, not a theoretical one.
Related but distinct: ADSS (all-dielectric self-supporting) fiber is non-conducting cable lashed below the conductors, used where OPGW does not fit the structure or the outage to restring the shield wire cannot be taken. And ordinary buried or duct fiber serves urban substations.
4 · The link
When You Cannot Run Fiber — Microwave, Radio, Leased Line
Licensed point-to-point microwave
- The classic utility answer where fiber is uneconomic: mountainous terrain, river crossings, long rural spans, or a site not on a transmission corridor.
- Licensed is the operative word. Utility backbones commonly use licensed bands (6 GHz is a traditional utility favorite) precisely so the license gives legal interference protection. Unlicensed spectrum offers no such guarantee.
- Owned end to end, high capacity, and independent of any carrier — which is exactly the ownership argument from two slides ago.
- Constraints: needs maintained line of sight and tower infrastructure; rain fade at higher frequencies; path obstruction from new construction or tree growth; real engineering work to design the path.
Licensed narrowband radio
- Low bandwidth, long reach, very tolerant of terrain. Historically the workhorse for distribution SCADA, reclosers and capacitor bank control where a few hundred bytes every few seconds is genuinely all you need.
- Utilities have long held licensed VHF/UHF and 900 MHz allocations for this. Cheap per site, and it keeps working when commercial networks are saturated.
Leased telecom circuits
- Fills gaps, particularly to sites well off a utility corridor, and historically the way the earliest telemetering got home at all.
- Introduces a third-party dependency: restoration priority, route diversity and security posture are partly somebody else's decision. Legacy analog leased pairs have also been actively withdrawn by carriers, which has forced a lot of migration work.
4 · The link
Cellular, Satellite, and Power-Line Carrier
Public cellular (LTE / 5G)
- The practical choice at scale on distribution: distribution automation devices, and the backhaul from smart-meter collectors. Coverage already exists, per-site cost is low, and bandwidth is generous.
- The tradeoff is structural, not technical: you depend on a public carrier. Networks congest during a widespread event, and cell sites can lose power during the very outage the utility needs to see. Utilities mitigate with priority-service arrangements, dual carriers, and by not putting anything consequence-critical on it.
Satellite
- Reaches sites nothing else reaches, and survives regional terrestrial destruction — which makes it attractive as an emergency and restoration path and for storm-response command posts.
- Traditional geostationary service carries roughly a quarter-second of round-trip latency from orbital geometry alone, which rules it out for anything time-critical. Low-earth-orbit services have changed that number substantially, but the dependency on a commercial operator remains.
Power-line carrier (PLC)
- Superimposes a high-frequency signal directly onto the high-voltage conductors, coupled on through capacitors and confined by line traps.
- Historically important for teleprotection — transfer trip between line ends — and low-bandwidth SCADA, because it needed no separate medium at all: the conductor was already there.
- Very low bandwidth, and it degrades in exactly the wrong conditions — faults, switching transients, and weather noise on the line. Largely displaced by fiber where fiber exists, but still in service.
| Medium | Bandwidth | Latency | Storm behavior | Owned? | Typical use |
|---|---|---|---|---|---|
| Fiber / OPGW | Very high | Lowest | Excellent until the structure fails — then it fails with the shield wire | Utility | Transmission backbone, teleprotection, station links |
| Licensed microwave | High | Low | Good; rain fade, needs the tower to survive | Utility | Backbone where fiber is uneconomic |
| Licensed narrowband radio | Low | Low–moderate | Robust and independent | Utility | Distribution SCADA, reclosers, capacitor banks |
| Leased circuit | Varies | Varies | Depends on the carrier | Third party | Gap filling, legacy sites |
| Cellular LTE / 5G | High | Low but variable | Congests; sites can lose power | Third party | Distribution automation, AMI backhaul |
| Satellite | Moderate | High (GEO) / moderate (LEO) | Survives regional terrestrial loss | Third party | Remote sites, emergency and restoration |
| Power-line carrier | Very low | Low | Degrades with faults and switching | Utility | Legacy teleprotection, legacy SCADA |
Check your understanding · 2
Media and Ownership
4 · The link
The Copper That Still Matters — Twisted Pair and RS-485
Fiber gets the glory, but a great deal of real utility data still starts life on a pair of copper wires inside the substation, and that is where most field troubleshooting actually happens.
Single-ended vs differential — the one distinction everything follows from
RS-232 is single-ended: the receiver measures one signal conductor against a shared ground. Anything that shifts that conductor's voltage, or shifts the ground reference between the two ends, is added straight onto the signal and is indistinguishable from data.
RS-485 is differential: the receiver reads the difference between line A and line B, and does not use ground as its reference at all.
The practical numbers a tech needs
- RS-232: commonly quoted around 50 ft / 15 m — but that is a rule of thumb. The standard actually limits total load capacitance (2500 pF), so low-capacitance cable at a low baud rate can exceed it and cheap cable at high baud may not reach it.
- RS-485: about 4000 ft / 1200 m, up to 32 unit loads on a multi-drop bus — and that distance is a low-data-rate figure. Distance and speed trade against each other.
- Termination: exactly two 120 Ω terminators, one at each physical end of the trunk, never on a mid-bus device. With the bus de-energized, two in parallel measure about 60 Ω across the pair. Reading about 120 Ω means one is missing; about 40 Ω means somebody enabled a termination jumper in the middle.
- Ethernet copper: 100 m per segment — and unlike the serial figures, that one is a hard limit. It does not stretch by slowing down. Add a switch, or go fiber.
4 · The link
EMI in a Substation — and What Actually Fixes It
A substation is close to the worst electromagnetic environment in which anyone seriously expects data to survive.
Where the noise comes from
- Breaker and disconnect operation — fast switching transients with very high dv/dt, radiating broadband energy.
- Capacitor bank switching — a large step change into a mostly inductive network.
- Power-frequency magnetic fields from bus work and transformers, coupling into any loop.
- Lightning, and the ground potential rise it produces: during a fault or strike, "ground" at one end of the yard is genuinely at a different potential from "ground" at the other.
- VFD output leads anywhere nearby in a plant environment.
Two coupling mechanisms, two different fixes
- Capacitive (electric-field) coupling is fixed by a shield. A nearby conductor at fast-changing voltage pushes displacement current across the capacitance to your wire; the shield intercepts it and drains it to the single ground point.
- Inductive (magnetic) coupling is fixed by the twist. A changing magnetic field induces voltage in the loop formed by the pair; twisting makes each successive loop wound the opposite way, so the induced voltages alternate polarity and largely cancel. A thin foil shield does very little about a low-frequency magnetic field.
That is why good instrument and comms cable is both twisted and shielded: two different problems, two different fixes.
Grounding the shield — one end only
Ground a shield at both ends and the ground-potential difference between the two locations now has a complete path: up one ground connection, along the shield, back through the earth. Current circulates in the shield, and a shield carrying current sits right alongside your pair coupling noise into it — the exact opposite of its job. It may also carry fault current it was never sized for.
Land it at one point only — conventionally the control-panel / receiver end, on the instrument ground bus. The shield still drains capacitively coupled noise; the loop stays open.
And the honest answer
Fiber is immune to all of it. No conductor means no induced current, no ground loop, no common-mode range to exceed, and complete galvanic isolation between two ends of a yard that may be several kilovolts apart during a fault. A great deal of the utility migration to fiber was driven by noise immunity and isolation, not by bandwidth.
5 · Protocols
Modbus — the Baseline, and Its Limits
Modbus (Modicon, 1979) is the simplest thing that works, and that is exactly why it is still everywhere. Understanding what it cannot do is the cleanest way to understand why utility protocols look the way they do.
How it works
- Strictly solicited master/slave polling. The master asks; a slave answers. A slave never speaks first.
- Four data areas: coils (read/write bits), discrete inputs (read-only bits), input registers (read-only 16-bit words), holding registers (read/write 16-bit words).
- Trivial to implement on almost any microcontroller, and universally supported.
What it does not have — and why each absence hurts
| Missing | Operational consequence |
|---|---|
| No timestamps | The master knows when the answer arrived, not when the event happened. After a disturbance you cannot reconstruct the order of operations — and order is what tells you whether a relay operated correctly or caused the problem. |
| No unsolicited reporting | A breaker trip waits in the register until its turn in the poll comes round. Nothing pushes. |
| No event queue | If a status changes twice between polls, you see the final value and never learn the first change happened at all. |
| No data-quality flags | A register reading zero could mean "the measurement is genuinely zero", "the device is offline", "the transducer failed", or "this value is stale". Modbus cannot tell you which. An operator — or a state estimator — has no way to distinguish a real zero from a dead zero. |
The latency arithmetic
Polling is sequential, so total scan time grows with device count. Put thirty devices on a serial multi-drop bus, each taking tens of milliseconds to poll and answer, and the worst-case age of any one value is the whole scan cycle. Add a slow wide area network (WAN) link and the scan stretches further.
5 · Protocols
DNP3 — Built Because Utilities Needed Something Else
DNP3 appeared in the early 1990s and is standardized as IEEE 1815. It became the North American utility telemetry standard for one reason: it closes every gap on the previous slide, in a way that suits slow, expensive, harsh wide-area links.
| Feature | What it actually buys you |
|---|---|
| Unsolicited responses | The outstation pushes the instant a value changes. A breaker trip does not wait for the next scan. |
| Event classing (Class 0/1/2/3) | Class 0 is the full static picture; Classes 1–3 are event buffers at different priorities. The master can ask "what changed since last time?" — report-by-exception — instead of re-reading everything. On a narrowband link that is the difference between usable and useless. |
| Millisecond timestamps at the source | The outstation stamps the event when it happens, using its own synchronized clock. This is what makes sequence-of-events reconstruction possible across a whole system. |
| Data-quality flags | online/offline, restart, communications-lost, over-range, locally forced. An operator and a state estimator can finally tell a real zero from a stale one. |
| Select-before-operate | A control command is a two-step handshake: select the point, confirm it echoes back correctly, then operate. A single corrupted frame cannot open a breaker. |
| Secure Authentication (SAv5) | Added later: cryptographic authentication of commands, so the outstation can verify who is telling it to open a breaker. Note that word later — see the security slide. |
For scale: conventional SCADA scan cycles on this kind of system typically run 2–4 seconds. That is entirely adequate for steady-state situational awareness, and — as we will see under synchrophasors — nowhere near fast enough for system dynamics. Hold on to that number; we are going to do arithmetic with it later.
Related family member: IEC 60870-5-101 (serial) and -104 (its TCP/IP form) occupy the same role as DNP3 and dominate outside North America. Same problem, different committee.
Check your understanding · 3
Modbus, DNP3, and Scan Time
5 · Protocols
IEC 61850 — Inside the Substation
IEC 61850 is not "DNP3 over Ethernet." It differs in kind: it defines a standardized object model — consistent, self-describing data names across vendors — plus several transports for different jobs.
- MMS — client/server on the station bus: engineering access, reports, supervisory control. This is the conventional "talk to the device" traffic.
- GOOSE — connectionless publisher/subscriber multicast Ethernet for time-critical trip and status signals, delivered in a few milliseconds. Its real significance: it replaces hardwired copper trip and interlock wiring between relays with messages on a LAN.
- Sampled Values (IEC 61850-9-2) — merging units digitize the current transformer (CT)/voltage transformer (VT) signals at the process level and stream raw waveform samples at strictly periodic high rates to the protection IEDs.
5 · Protocols
ICCP, and the Slide That Ties the Protocols Together
ICCP — control center to control center
ICCP, formally IEC 60870-6 / TASE.2, is the protocol used between organizations: utility to RTO, utility to neighboring utility, utility to independent power producer. It carries real-time and historical measurements, control and scheduling data, interchange and energy accounting, and operator text messages. It is built on ISO 9506 (MMS).
Because it crosses a trust boundary between separate companies, ICCP links are treated as a NERC CIP Electronic Security Perimeter concern in their own right.
The practical bridge between generations is the substation gateway / automation controller — an SEL Real-Time Automation Controller (RTAC) is the example most of you have seen. It speaks legacy serial on one port and modern Ethernet on another, converting, concentrating, scaling and time-aligning, which is what lets a utility migrate gradually instead of replacing a substation wholesale.
5 · Protocols
Security — Because None of the Legacy Protocols Authenticated Anything
Look back at Modbus, DNP3 as originally written, and IEC 60870-5. Every one of them was designed for a private, physically isolated link, and every one of them accepts a well-formed command without asking who sent it. That assumption stopped being true the moment those links touched routable networks.
Ukraine, 23 December 2015
- Spear-phishing with malicious Office documents delivered BlackEnergy3.
- Roughly nine months of reconnaissance (initial phishing around March 2015), during which attackers mapped the SCADA environment and harvested credentials — including virtual private network (VPN) access into the operational network.
- On the day, they used those credentials to log into SCADA/human-machine interface (HMI) workstations at three regional distribution companies and manually opened breakers at about 30 substations, cutting power to roughly 225,000 customers.
- They compounded it deliberately: corrupted firmware pushed to serial-to-Ethernet converters (bricking hardware so it could not be recovered remotely), KillDisk wiper malware on operator workstations, scheduled disconnection of control-center UPS systems, and a telephone denial-of-service against the call center so genuine outage reports could not get through. Recovery required engineers to drive to substations and operate breakers by hand.
Ukraine, 17 December 2016 (Kyiv)
- About a fifth of Kyiv lost power for roughly an hour, caused by Industroyer / CrashOverride.
- The structural contrast is the lesson. 2015 was hands-on-keyboard: steal credentials, drive the HMI like a legitimate operator. Industroyer was purpose-built malware that spoke the substation's own control protocols — modules targeting IEC 60870-5-101, IEC 60870-5-104, IEC 61850 and OPC DA — constructing valid protocol-level commands to open breakers automatically, with no human at an HMI at all.
The framework: NERC CIP and the Purdue model
- NERC CIP is mandatory and the Federal Energy Regulatory Commission (FERC)-enforced for the Bulk Electric System (approved 2008), spanning CIP-002 through CIP-014 plus newer additions such as CIP-015 on internal network security monitoring. Its distinguishing feature versus most security frameworks is binding financial penalties — which is why it drives so much North American OT security spending.
- Mechanics worth knowing by name: Electronic Security Perimeters (ESPs) with controlled Electronic Access Points (EAPs), and CIP-005's requirement that interactive remote access into high- and medium-impact systems pass through a controlled intermediate system with multi-factor authentication and session logging.
- The Purdue model is the layered reference architecture — business IT at the top, a DMZ in the middle, supervisory control, basic control and the process below. NERC CIP's ESP/EAP concept is essentially Purdue's segmentation operationalized for the electric sector.
6 · Time
Time — the Part That Decides Blame
Before GPS-disciplined clocks, every RTU and relay ran its own free-running clock. If two devices near a fault each logged an event, you could not tell which happened first — which is exactly the thing you need to know to decide whether a relay tripped correctly in response to a fault, or mis-tripped and caused the cascade.
| Method | What it is | Typical accuracy and notes |
|---|---|---|
| Inter-Range Instrumentation Group time code, format B (IRIG-B) | The long-standing analog/serial time code, fed from a GPS receiver and distributed by coax or fiber to every IED in the station. | Still very widely deployed. Accuracy in a real distribution plant is typically in the microsecond to tens-of-microseconds range, depending on how it is engineered. |
| IEEE 1588 PTP | The packet-network successor. Hardware-timestamped Ethernet exchanges, riding the same LAN a process-bus substation already needs. | Sub-microsecond, down to tens of nanoseconds when engineered well — orders of magnitude tighter than typical IRIG-B distribution. Convertible to and from IRIG-B for mixed-vintage gear. |
| NTP | Ordinary network time protocol. | Milliseconds at best over a real network. Fine for logs and workstations; not adequate for synchrophasors — we will prove that with arithmetic two slides from now. |
Sequence of Events (SOE) recording
Once every device in a substation — and every substation sharing the same time discipline — stamps its own events, those logs merge after the fact into one master timeline. The traditional threshold for correctly ordering relay and breaker operations is 1 ms.
Coarser timing does not fail loudly; it fails by making genuinely sequential events look simultaneous. That is the difference between
- "relay A operated correctly, 40 ms before relay B, exactly as designed", and
- "we cannot tell which one failed first."
One of those closes an investigation. The other starts an argument between a utility, a manufacturer, and possibly a regulator.
6 · Time
Synchrophasors — What the "Synchro" Actually Means
A phasor is magnitude and phase angle. Any protective relay can compute a local phasor — it has been doing that for decades, because that is how distance protection works. That is not new and it is not the invention.
What the angle is referenced to — the part people guess wrong
The phase angle is not measured between two phases of the power system. That is the intuitive guess and it is wrong.
A PMU computes the positive-sequence phasor and reports its angle relative to a cosine function at nominal system frequency, locked to UTC — that is the definition in IEEE C37.118. The reference is therefore a time reference: an imaginary rotating vector that every phasor measurement unit (PMU) on the continent agrees on, because every one of them is locked to the same satellite clock.
Do not frame this as "SCADA vs PMU"
That framing is tempting and it is wrong. SCADA is a category — supervisory control and data acquisition. Synchrophasor measurement is data acquisition, and PMU data is routinely fed into the EMS alongside conventional telemetry. The industry name for the synchrophasor side is WAMS — Wide Area Measurement System — precisely because it is a parallel acquisition system, not a replacement.
It is equally wrong to say "PMUs timestamp and SCADA does not." DNP3 carries millisecond timestamps on events. Timestamping is not the distinction.
6 · Time
Deriving the Clock Requirement — Why ±1 µs, and Why NTP Cannot Do It
This is a derivation you can check every step of, and it explains a specification that otherwise looks arbitrary.
IEEE C37.118 allows 1% Total Vector Error (TVE). Take the pessimistic case where that entire budget is spent on phase error:
At 60 Hz, one full cycle is 16.67 ms of time. So convert that angle into time:
So 26.5 µs of timing error alone would consume the entire 1% error budget — leaving nothing for transducer error, analog front end, quantization, off-nominal frequency, harmonics, or the estimation algorithm itself.
Hence the industry specification: PMU clocks are held to ±1 µs, roughly 25 times margin against the total budget.
Which also tells you the failure mode to watch for in the field
- A PMU that loses GPS lock does not stop producing numbers. It flags the loss in its status word and coasts on its internal oscillator, drifting steadily out of specification.
- That is why the C37.118 frame carries time-quality flags and a status word, and why any competent phasor data concentrator (PDC) or application checks them. Data that looks fine and is silently un-synchronized is worse than no data.
- GPS antenna problems, cable water ingress, and jamming or spoofing are therefore real operational concerns, not exotic ones.
6 · Time
Rate vs Synchronization — Two Separate Problems
These two arguments get collapsed into one constantly. Keep them apart.
Problem one: the rate, and Nyquist
If you are sampling something that moves, there is a hard limit on what you can see, and it is not a matter of equipment quality. You must sample at least twice as fast as the fastest thing you want to observe. Sample slower than that and the signal does not merely get rougher — it comes back as a different, slower signal that was never there. That false signal is called an alias.
Half your sampling rate is the fastest frequency you can honestly resolve. That half-rate number is the Nyquist limit. Sample at 100 times a second and you can resolve up to 50 Hz; sample once every 4 seconds and you can resolve up to 0.125 Hz, and nothing faster.
You have already seen this: a wagon wheel in an old film that appears to turn slowly backwards. The wheel is spinning far faster than the camera's 24 frames per second, so the camera reports a slow backward rotation that is not happening. The camera is not broken and the film is not blurry — the answer is confidently wrong.
That is why this matters here. Undersampling a grid oscillation does not throw an alarm or show up as noise on the screen. It hands the operator a clean, plausible, slow-moving trend — and the operator has no way to tell it from the truth. Aliasing is not a loss of resolution. It is a lie that looks like data.
Scope this carefully — the argument applies to conventional scan-based telemetry at 2–4 seconds, not to "SCADA" as a category.
- Electromechanical inter-area oscillations — the phenomenon that precedes this class of instability — sit roughly in the 0.1–0.8 Hz band.
- Scanning every 2–4 s is a sampling rate of 0.25–0.5 Hz, giving a Nyquist ceiling of 0.125–0.25 Hz.
- That ceiling sits at or below the bottom of the oscillation band. Those modes cannot be resolved — and crucially it does not fail visibly. It aliases: a real 0.6 Hz oscillation can present as a slow drift that looks like something else entirely.
- A PMU reporting at 30 Hz gives a Nyquist ceiling of 15 Hz — two orders of magnitude of headroom.
Problem two: the synchronization
Poll an RTU at 30 Hz and you have fixed the Nyquist problem — and you still do not have what a PMU gives you, because you have no common angular reference. Conventional scanning is also asynchronous per point: each analog is read when its poll comes round, so values arrive at different instants and the picture is smeared across the scan cycle. There is no system-wide simultaneous snapshot to be had at any rate.
| Conventional scan telemetry | Synchrophasor measurement | |
|---|---|---|
| Content | Magnitude only — MW, MVAR, kV, breaker status; typically RMS averaged over a window | Magnitude and phase angle |
| Acquisition | Asynchronous, per point — no simultaneous system-wide snapshot is possible | Synchronous by construction — every estimate referenced to the same UTC instant |
| Transport | Polled / report-by-exception (DNP3) | Pushed as a continuous stream (IEEE C37.118) |
| Rate | One sample per 2–4 s | 30–60 per second |
What a PMU reports — and what it categorically cannot
In every C37.118 frame
- Voltage phasors — magnitude and angle
- Current phasors — magnitude and angle
- Frequency at that bus
- ROCOF — rate of change of frequency
- UTC timestamp with time-quality flags
- Status word — validity, sync lock, triggers
- Optionally a few digital/analog channels
P and Q are derived from the V and I phasors, not measured.
Not available from a PMU at all
- Breaker and disconnect position; tap-changer position — the whole discrete status picture
- Alarms, equipment health, transformer temperature, SF₆ pressure, battery status
- Anything non-electrical
- Control. A PMU has no control capability whatsoever. You cannot open a breaker with one.
Check your understanding · 4
Time, Phasors, and What They Can Tell You
6 · Time — a footnote worth having
Why It Is an "Estimate," Not a Measurement
This question comes up every time, and the answer is genuinely interesting rather than pedantic.
The relay really does measure: a real ADC sampling instantaneous volts and amps, exactly as it always has for protection. Those samples are honest measurements. But a phasor is not an instantaneous quantity. Magnitude and angle are properties of a sinusoid. "What is the phasor at this instant?" has no answer — in the same way that "what is the shaft RPM at this exact instant?" has no answer. You must observe a span of time first.
What the relay actually does
A PMU function inside a relay needs no new analog front end — the hardware was already sampling V and I at high rate for protection. What was added is the maths and a precise time reference. That is exactly why synchrophasors became a firmware feature rather than a separate product category. The sequence is:
- Sample V and I as it always has.
- Run a discrete Fourier transform (DFT)-based phasor estimate over a sliding window, typically one full cycle.
- Time-align that estimate to the UTC second boundary using a GPS-disciplined clock — IRIG-B from a satellite clock, or IEEE 1588 PTP on newer gear.
- Report at a configured rate — 1, 2, 5, 10, 20, 30 or 60 messages per second.
In plain terms: it fits a 60 Hz sinusoid to the samples in that window and reports the amplitude and phase of the best fit.
Four reasons "estimate" is the honest word
- It is a fit over a window, not an instant — and the single result must then be assigned to one reference instant, which is a choice.
- The maths assumes a pure sinusoid at exactly nominal frequency. Real systems drift — 59.97, 60.02 — and off-nominal frequency causes spectral leakage and error. PMUs run frequency tracking and compensation to fight it, which is itself an admission that the raw computation is approximate.
- During a transient the phasor is genuinely ill-defined. In a fault or power swing the waveform is not a steady sinusoid at all. A number still comes out, but it is a best fit to something that does not actually possess a phasor. This is the deepest reason.
- Harmonics, noise, DC offset and CT saturation all perturb the fit.
Going further: why a PMU and a revenue meter can legitimately disagree
From phasors, with V = |V|∠θv and I = |I|∠θi, complex power is voltage times the conjugate of current: S = V · I* = |V||I| ∠(θv − θi), giving P = |V||I| cos θ and Q = |V||I| sin θ. The conjugate is the convention that makes Q positive for lagging (inductive) current. For three phase from positive-sequence phasors, S3φ = 3 · V₁ · I₁*.
A revenue meter instead uses the fundamental definition, P = (1/T)∫v(t)·i(t)dt — multiply instantaneous v and i sample by sample and average. That holds regardless of waveform.
The two part company under distortion. P = |V||I| cos θ is valid only for pure sinusoids at the same frequency; with harmonics P = Σ VnIncos θn and only same-order harmonics contribute, while apparent power S = Vrms × Irms still includes every harmonic. So S² = P² + Q² + D², where D is distortion power — the power triangle becomes a pyramid. A PMU reports P and Q from fundamental-frequency phasors only, because the DFT filtered the harmonics out by design; a revenue meter integrates v·i and captures everything. On a clean transmission bus they agree closely; on a distorted bus — VFDs, rectifiers, arc furnaces — they will not, and the revenue meter is the one telling the truth about energy. Neither is broken; they answer different questions.
7 · What they do with it
State Estimation — the Keystone
All of that data arrives somewhere. This is the most interesting software in the control center, and the cleanest demonstration of why an EMS is more than a prettier SCADA.
The definition
The state of a power system is the voltage magnitude and phase angle at every bus. Know V and θ everywhere, plus the network model, and every line flow and injection follows directly from the power-flow equations.
The problem
- Phase angle classically cannot be measured at all.
- Every transducer carries error, so all measurements are noisy.
- Some are missing, stale, or simply wrong — failed transducer, comms drop, stuck value.
- Raw measurements contradict one another. Measure a line's flow at both ends and the two numbers disagree, thanks to losses and measurement error. Kirchhoff does not close at the bus.
You cannot run a contingency study against a picture that does not obey physics.
The estimator takes the entire redundant, noisy measurement set plus the network model and solves a weighted least-squares problem: find the set of bus voltages and angles that best fits all measurements simultaneously, each weighted by how much it is trusted. A topology processor runs first, reading breaker and disconnect status to establish how the network is actually configured right now.
And this is where PMUs pay off
Classic state estimation must infer every phase angle, because nothing measures it. PMUs measure it directly. Feeding that in gives better accuracy (angles measured rather than inferred) and sharper bad-data detection (more independent information to cross-check against).
And the deep one: with sufficient PMU coverage the estimation problem becomes linear. Conventional state estimation is nonlinear and solved iteratively; a fully PMU-observable system can be solved directly, in one pass — faster, and guaranteed to converge.
Remember that phrase — synchrophasor-assisted state estimation. It comes back in the case study, attached to a real project in Louisiana.
7 · What they do with it
Everything Else the Data Feeds
State estimation is the keystone, but it is not the product. Here is what sits on top of it, and alongside it.
Contingency analysis
"If this line trips, does anything overload?" The EMS runs through a list of credible single (N−1) and sometimes double contingencies continuously, and flags any that would produce a violation. This can only be answered against an estimated state — never against raw telemetry, because raw telemetry does not obey physics.
Outage management
Customer calls plus smart-meter last-gasp messages, correlated against the feeder model, to predict which device actually failed — rather than dispatching a crew to each of 400 individual complaints. Then crew assignment, estimated restoration times, and the customer-facing outage map.
FLISR — the self-healing loop
Fault Location, Isolation and Service Restoration. Intelligent reclosers detect a fault, isolate the faulted section between two switching points, and then reroute power to the healthy sections from an alternate source — automatically, in well under a minute. Customers beyond the fault never lose supply at all; only the isolated section stays out for the crew.
Volt/VAR optimization
Coordinated control of capacitor banks, regulators and tap changers across a feeder to hold voltage inside limits while reducing losses — and, in conservation voltage reduction schemes, to deliberately run the feeder near the bottom of the allowed band to shave demand.
AMI — the second data firehose
Metering is architecturally a separate system from SCADA, with a different owner inside the utility (revenue, not operations) and typically a separate network. Interval consumption every 15–60 minutes, a last-gasp message on power loss, a restoration message on return, meter voltage, and remote connect/disconnect. A smart meter cannot open a breaker.
Market and dispatch
Where an RTO exists, telemetry also feeds security-constrained economic dispatch and the energy markets. This is the layer where "what is the grid doing" becomes "what should each generator produce in the next five minutes, at what price."
| AMI | SCADA | |
|---|---|---|
| Purpose | Billing, outage inference, grid-edge visibility | Real-time operational monitoring and control |
| Reports | Interval consumption, last-gasp and restoration, meter voltage, remote connect/disconnect | Breaker status, voltages, currents, MW/MVAR flows, alarms, equipment health |
| Cadence | 15-minute to hourly reads, plus event pings | Sub-second to a few seconds |
| Network | Customer metering network | Operational control network, separate |
A concrete pairing: a substation transformer reporting real-time MW/MVAR loading and breaker status every few seconds — versus 10,000 downstream residential meters each reporting yesterday's hourly kWh once a day, with the occasional last-gasp ping. Utilities increasingly correlate the two, cross-checking AMI last-gasp patterns against SCADA breaker events to localise an outage faster. They remain architecturally distinct systems.
8 · The case study
Entergy — Who Actually Controls What
Everything from here on is Entergy, and everything from here on is from the public record. Start with the organizational question, because it determines where the data goes.
First, what MISO is
MISO — Midcontinent Independent System Operator, renamed from Midwest ISO in 2013 specifically because it had expanded into the South. Formed 1998; became the first FERC-approved RTO in 2001. Roughly 15 states plus Manitoba, about 45 million people. It is non-profit, owns no transmission, and generates no power. That independence is the entire point of the institution.
Why an RTO operates the grid at all — FERC Orders 888 (1996) and 2000 (1999). The problem being solved was structural, not technical: a vertically integrated utility that owns generation and controls transmission access has an obvious incentive to favor its own plants over a competitor's cheaper ones. Handing dispatch and transmission access to an independent operator removes that conflict of interest. MISO runs security-constrained economic dispatch every five minutes across the footprint, operates the day-ahead and real-time energy markets, and acts as Reliability Coordinator.
The integration
Entergy's operating companies joined MISO as transmission-owning members on 19 December 2013, fully integrated during 2014.
| MISO does | Entergy does |
|---|---|
| Real-time balancing of supply and demand across the region | Owns, builds, staffs and maintains the T&D infrastructure |
| Reliability Coordination — the NERC-defined wide-area situational awareness and emergency authority | Local operations, crew dispatch, outage response and restoration |
| Wholesale energy market operation | Retail service, regulated by state commissions |
| Regional transmission planning under its FERC tariff | — |
Concrete anchors
- Entergy's system: about 16,100 circuit miles, about 1,300 substations, 69 kV–500 kV, about 114,000 square miles, about 3 million customers.
- MISO built a dedicated South Region Operations Center in Little Rock, Arkansas to serve the enlarged footprint — groundbreaking March 2014, roughly $22 M, operational by spring 2015. That is the control room now performing reliability coordination and market functions for the Entergy footprint.
- Claimed savings: Entergy cites roughly $1.3 billion in customer savings 2014–2018, and $1.78 billion 2014–2020, from MISO membership.
8 · The case study
How Does Entergy Link to 1,300 Substations?
This is the question that motivated the lecture, and it deserves a straight answer in three parts.
Part 1 — the honest scope statement
Part 2 — what is published, and it is not nothing
- One transport fact is published in detail, because it goes through a different regulatory door: the metering network. Entergy Louisiana's own customer FAQ states that each meter carries a network radio, transmits to an electric network access point on a nearby pole, and that access point relays data to Entergy over a secure cellular network. That is a classic RF-mesh neighborhood collection with cellular backhaul — and note, not per-meter cellular, which is what most people assume.
- Synchrophasors are confirmed by name in a DOE primary source — PMUs, GPS clocks, substation computers and phasor data concentrators, across four states. Details on the next-but-one slide. That tells you there is a transport path capable of carrying continuous 30-per-second streams from those substations to a concentrator, even though the medium is not named.
- Aggregate distribution-automation counts are published — nearly 400 self-healing networks, 1,483 reclosers — which tells you thousands of field devices are communicating, on something.
Part 3 — so, what is the answer? It is a mixture, and here is the engineering logic
The correct answer to "which medium does a utility this size use" is: all of them, and the choice is driven by consequence. This is the general industry pattern from earlier in the lecture, applied to what we know about Entergy's footprint — offered as the engineering logic, not as a claim about any specific Entergy site.
| Asset class | Media family generally used | Why |
|---|---|---|
| Transmission substations, teleprotection | Utility-owned fiber — largely OPGW on the transmission corridor — with licensed microwave where fiber is uneconomic | Highest consequence; needs owned transport, lowest latency, storm-independent restoration priority, and it must stay inside the utility's own security scope |
| Backbone where fiber does not reach | Licensed point-to-point microwave | Owned, high capacity, licensed spectrum gives enforceable interference protection; no carrier dependency |
| Distribution automation — reclosers, capacitor banks | Licensed narrowband radio and/or public cellular | Thousands of low-bandwidth devices; per-site cost dominates; a communications gap is survivable |
| AMI metering | RF mesh to a pole-top collector, cellular backhaul — published by Entergy | Hundreds of thousands of endpoints; not operational control; billing-cadence data |
| Legacy teleprotection | Power-line carrier, where it survives | The conductor was already there; being steadily displaced by fiber |
| Remote sites, storm restoration | Satellite, leased circuits | Reaches what nothing else reaches; survives regional terrestrial loss |
8 · The case study
The Metering Layer — and Why It Is the Best-Documented Part
There is a reason the customer-facing metering layer is documented in far more technical detail than core grid control, and it is worth teaching in its own right: AMI deployments go through public utility-commission cost-recovery dockets. To recover the cost from ratepayers, the utility must describe what it is building, in public, to a regulator, on the record. Grid control has no equivalent public door.
Entergy Louisiana's deployment
- Approved by the Louisiana Public Service Commission following an application for approval to implement a permanent advanced metering system with cost recovery.
- Installation began February 2019; targeted for completion end of 2020 in New Orleans and end of 2021 for the rest of Louisiana.
- Architecture, from Entergy's own customer FAQ: each meter carries a network radio → transmits to an electric network access point on a nearby pole → that access point relays to Entergy over a secure cellular network.
8 · The case study
Self-Healing Networks — FLISR With Published Results
Entergy began a self-healing network distribution-automation program in early 2020, using intelligent reclosers to detect a fault, isolate it, and reroute power around it. That is textbook FLISR — the automated loop from slide 28, in production.
| Measure | Figure |
|---|---|
| Self-healing networks deployed | Nearly 400 |
| Reclosers | 1,483 |
| Feeder circuits involved | 890 |
| Share of Entergy's roughly 3,600 total circuits | About 25% |
| Customers covered | More than 500,000 |
The measured outcome — the number worth remembering
In a January 2026 winter-weather event, Entergy reports that 19 automated transfers avoided more than 12,000 customer interruptions and about 770,000 outage-minutes.
Investment scale
Entergy states more than $10 billion over the last five years on strengthening transmission and distribution infrastructure. Grid resiliency also appears in Entergy Corporation's SEC proxy filings (DEF 14A, FY2021) — a useful demonstration that reliability engineering reaches the boardroom, not just the engineering department.
8 · The case study
Synchrophasors at Entergy — Confirmed, by Name, With Numbers
This one is worth dwelling on, because it is Entergy-specific, primary-sourced, and public — and it is not an inference from MISO membership. The US Department of Energy's own project page lists Entergy Services, Inc. individually as a grant recipient and PMU installer.
The project
Under the the American Recovery and Reinvestment Act (ARRA) Smart Grid Investment Grant program, awarded 2010, Entergy Services, Inc. received funding to refurbish and expand its existing synchrophasor system across Arkansas, Louisiana, Mississippi and the non-ERCOT portion of east Texas.
| Item | Figure |
|---|---|
| New PMUs installed | 18 |
| Federal contribution | $4,611,000 |
| Total project cost | $9,222,000 |
What it deployed: PMUs, GPS clocks, substation computers, phasor data concentrators, and a visualization application — plus applications for post-mortem disturbance review, voltage stability analysis, oscillation monitoring, and synchrophasor-assisted state estimation.
Context — how big is 18 PMUs?
- Pre-stimulus, around 2009, North America had roughly 150–200 networked PMUs in total.
- The SGIG program added roughly 1,380 more between 2007 and 2015 — about a ten-fold increase — reaching over 2,500 networked PMUs and 100+ phasor data concentrators, with close to 1,700 production-grade units giving near-total visibility of the bulk power system.
- In the footprint, MISO is a well-documented early adopter: over 344 installed PMUs reporting 30 times per second, against roughly every 4 seconds for legacy SCADA. That ratio — 120:1 — is the cleanest way to make the wide-area-measurement point land.
- MISO is also on record working through NERC user groups to reuse ICCP infrastructure to carry synchrophasor data, with an established ICCP-style link to PJM and TVA for phasor exchange.
8 · The case study
What They Monitor, Why, and What They Do With It
Pulling the whole lecture together into one table. Every row is something covered earlier; the right-hand column is the point of the whole exercise.
| What is measured | Roughly how often | Why it is measured | What is actually done with it |
|---|---|---|---|
| Breaker and disconnect status | On change, pushed | You cannot model a network whose configuration you do not know | Feeds the topology processor, which must run before state estimation. Also drives the operator one-line and the outage prediction. |
| Bus voltages, line currents, MW/MVAR flows | Every 2–4 s | Loading, limits, losses, voltage support | Fed to state estimation → contingency analysis → "are we N−1 secure right now?" Also to MISO for dispatch. |
| Synchrophasors — V and I magnitude and angle, frequency, ROCOF | 30 per second | Angular difference across a path is system stress; and oscillations live faster than a 4-second scan can see | Oscillation monitoring, voltage-stability analysis, post-mortem disturbance review, and synchrophasor-assisted state estimation — all four named in Entergy's DOE project. |
| Equipment health — transformer temperature, SF₆ pressure, battery, alarms | On change / periodic | Failure prevention and maintenance planning; none of it is electrical measurement | Maintenance dispatch and asset management. Note a PMU cannot supply any of this — only SCADA can. |
| Disturbance records — SOE, fault records, dynamic disturbance records | On event | Establishing what happened and in what order | Post-event analysis, relay misoperation investigation, and NERC PRC-002-4 compliance obligations. |
| Distribution — recloser status, fault indication, feeder loading | Seconds | Locate and isolate a fault before a crew is even dispatched | FLISR: automated isolate-and-transfer. Entergy's published result — 19 transfers, 770,000 outage-minutes avoided. |
| AMI — interval kWh, last gasp, restoration, meter voltage | 15–60 min, plus events | Billing; and the grid edge is otherwise invisible | Billing and settlement; outage prediction and confirmation of restoration; voltage complaints; remote connect/disconnect. |
And the answer to "how does Entergy control it all?" — Entergy's own operators monitor and control Entergy's facilities through Entergy's own control centers, with local operations, crew dispatch and restoration staying with Entergy. MISO, from the Little Rock South Region Operations Center, holds functional control for dispatch and acts as Reliability Coordinator, exchanging data and directives across the organizational boundary — the ICCP role from slide 19 — rather than reaching into Entergy's field equipment itself.
8 · The case study
Where the Public Record Stops — and Why That Is the Lesson
Everything in this case study came from public sources. It is worth being explicit about where that record ends, because the shape of the gap is itself informative.
What you cannot get, for Entergy or any US utility
- Actual SCADA architecture and network diagrams
- IP addressing and cyber-asset inventories
- Control-center communication paths and media assignments per substation
- Specific vendor products and configurations in operational systems
- Which substations have which capability
Two distinct legal regimes — worth separating
NERC CIP — the mandatory framework
FERC-enforced cybersecurity standards for the Bulk Electric System. CIP-011 specifically governs information protection, requiring utilities to keep architecture, network diagrams, IP addressing, device inventories and communication paths out of public disclosure. Violations carry binding financial penalties — which is exactly why utilities publish aggregate counts and general technology names and nothing more.
CEII — the disclosure exemption
Critical Energy/Electric Infrastructure Information, administered by FERC under 18 CFR § 388.113. Detailed engineering, vulnerability or design information about critical energy infrastructure is statutorily exempt from FOIA and from state public-records disclosure.
And it is not "security through obscurity"
Worth saying out loud, because the objection always comes up. The actual controls — electronic security perimeters, multi-factor authentication, monitoring, protocol authentication — do not depend on the topology being secret. They work whether or not an adversary knows the layout. Withholding the architecture denies an adversary the reconnaissance step, and both Ukraine incidents show that reconnaissance is the necessary precursor to an attack: nine months of it in the 2015 case, before a single breaker moved.
Check your understanding · 5
The Case Study
9 · Close
What This Means for You in the Field
Step back from the utility scale for a moment. Most of you will not design an EMS. Here is what this lecture is worth on a working day.
Six things that will come up in your actual job
- You will troubleshoot the physical layer first, and be right most of the time. Polarity, termination, shield grounding, cable route and distance. Confirm the wire before you argue about the register map. That habit alone will make you useful faster than anything else in this lecture.
- You will meet three generations of equipment in one building. A serial relay from the 1990s, an Ethernet IED from the 2010s, and a gateway translating between them. Migration is gradual everywhere, because a rip-and-replace substation outage is unaffordable. Being fluent across generations is a genuinely marketable skill.
- You will care about time more than you expect. When something goes wrong, the first question is always "in what order?" If the clocks were not disciplined, that question has no answer and the investigation stalls. Check GPS lock, check the time-quality flags, check the IRIG-B or PTP distribution — before you need them.
- You will learn to read a quality flag. A value on a screen is not automatically a measurement. "Comms lost", "restart", "locally forced", "over-range" are the difference between a real zero and a dead zero, and operators and engineers make real decisions on that distinction.
- You are part of the security boundary. The Ukraine attacks did not start in the substation. They started with a phishing email and a stolen credential in an office. Your laptop, your remote access, your habit of writing configuration details in a public place — those are in scope. This is a regulated obligation with financial penalties attached, not a preference.
- You will be asked what a system can and cannot tell you. A PMU cannot tell you a breaker's position. A smart meter cannot open one. Modbus cannot tell you when something happened. Knowing the limits of each system is what separates someone who operates equipment from someone who understands it.
Reference
Sources and Where to Read Further
Free, credible, and pitched at about this level
- NASPI — naspi.org. The Synchrophasor Technology Fact Sheet and Synchrophasor Starter Kit are short DOE/NERC-affiliated primers, plus Bob Cummings' retrospective "The 2003 Blackout, Twenty Years Later." NASPI's own graphics are the safest choice if you need a reusable synchrophasor figure.
- SANS ICS / E-ISAC, Analysis of the Cyber Attack on the Ukrainian Power Grid: Defense Use Case (March 2016). The authoritative public technical report, written for power-system defenders. Free PDF.
- DOE, Secure ICCP Integration Considerations and Recommendations. A genuine primary technical document on ICCP, and a natural bridge from protocols into security.
- IEEE Smart Grid tutorial library — smartgrid.ieee.org/resources — includes a "SCADA and EMS Primer for Engineers" covering history, hardware and software, typical configurations and advanced EMS applications. The deeper version of today's lecture.
Entergy and MISO — the case-study sources used here
- Entergy RTO FAQ — entergy.com/stormcenter/rto
- Entergy transmission system — entergy.com/transmission
- Entergy Louisiana advanced meters FAQ — entergylouisiana.com/residential/am-faq
- Entergy blog, self-healing networks — entergy.com/blog; Entergy Future Ready — entergy.com/future
- LPSC public docket portal — lpscpubvalence.lpsc.louisiana.gov
- US DOE Office of Electricity, ARRA SGIG project page, "Entergy Services, Inc.: Deployment and Integration of Synchrophasor Technology" — energy.gov/oe
- DOE, Synchrophasor Technology Advancement in ARRA Projects (March 2016)
- PR Newswire — "MISO Completes Largest-Ever Power Grid Integration" (2013); "MISO Uses Real-Time Synchrophasor Technologies"
- SEC EDGAR — Entergy Corp DEF 14A, FY2021
Standards named in this lecture
- IEEE 1815 — DNP3
- IEC 61850 — substation automation; 61850-9-2 Sampled Values
- IEC 60870-5-101 / -104 — telecontrol; IEC 60870-6 / TASE.2 — ICCP
- IEEE C37.118 — synchrophasor measurement (.1) and data transfer (.2)
- IEEE 1588 — Precision Time Protocol; IRIG-B — time code
- NERC PRC-002-4 — disturbance monitoring and reporting, effective 1 April 2024
- NERC CIP-002 to CIP-015 — critical infrastructure protection; 18 CFR § 388.113 — FERC CEII
Reference
Glossary — Every Acronym in This Lecture
This industry runs on initialisms, and they are introduced in this lecture in the order the engineering needs them rather than alphabetically. This page collects all of them in one place, so nothing here depends on remembering an acronym from twenty pages earlier.
| Term | Stands for | What it means here |
|---|---|---|
| ADMS | Advanced Distribution Management System | Distribution SCADA, DMS and OMS consolidated onto one shared network model. |
| ADSS | All-Dielectric Self-Supporting cable | An all-plastic fiber cable with no metal in it, so it can be strung near energized conductors. |
| AMI | Advanced Metering Infrastructure | The two-way smart-meter network. Separate from SCADA; reports usage, outages and voltage. |
| ARRA | American Recovery and Reinvestment Act (2009) | The federal stimulus law whose Smart Grid Investment Grant funded Entergy's synchrophasor expansion. |
| CEII | Critical Energy/Electric Infrastructure Information | The FERC category that exempts detailed utility engineering information from public disclosure. |
| CIP | Critical Infrastructure Protection | The NERC standards mandating cybersecurity controls for the bulk electric system. |
| CT / VT | Current Transformer / Voltage Transformer | Step high voltage and current down to safe, standard levels a relay or meter can measure. |
| DFT | Discrete Fourier Transform | The math that fits a sine wave to a window of samples, producing a magnitude and an angle. |
| DMS | Distribution Management System | Feeder model, switching orders, volt/VAR optimization. |
| DNP3 | Distributed Network Protocol 3 | Utility telemetry protocol that timestamps at the source and reports by exception. |
| DOE | Department of Energy | Federal agency; ran the Smart Grid Investment Grant program. |
| EMI | Electromagnetic Interference | Unwanted noise coupled into a signal conductor from switching, lightning, or magnetic fields. |
| EMS | Energy Management System | SCADA plus a network model: state estimation, contingency analysis, dispatch. Energy, not emergency. |
| FERC | Federal Energy Regulatory Commission | Regulates wholesale power and interstate transmission; backs NERC's enforcement. |
| FLISR | Fault Location, Isolation and Service Restoration | The self-healing loop: detect the fault, isolate it, reroute around it, automatically. |
| GOOSE | Generic Object Oriented Substation Event | IEC 61850 fast peer-to-peer message between relays, in milliseconds. |
| HMI | Human-Machine Interface | The operator's on-screen control panel for a SCADA system. |
| ICCP | Inter-Control Center Communications Protocol | Lets one control center exchange real-time data with another utility's or an RTO's. Also called TASE.2. |
| IED | Intelligent Electronic Device | Any microprocessor-based field device: relay, meter, regulator controller. Decides locally. |
| IRIG-B | Inter-Range Instrumentation Group time code, format B | The serial time signal, fed from GPS, that distributes accurate time to every device in a substation. |
| ISO / RTO | Independent System Operator / Regional Transmission Organization | The neutral operator of the bulk grid and its market across many utilities. |
| IT / OT | Information Technology / Operational Technology | The business network versus the control-system network. The boundary attackers cross. |
| LAN | Local Area Network | A network confined to one site — the Ethernet inside a single substation. |
| MISO | Midcontinent Independent System Operator | The RTO running the market and reliability coordination for Entergy's footprint. Entergy joined 19 December 2013. |
| NASPI | North American SynchroPhasor Initiative | The DOE/NERC-affiliated group coordinating synchrophasor deployment. |
| NERC | North American Electric Reliability Corporation | Writes and enforces mandatory grid-reliability rules across the US and Canada. |
| OMS | Outage Management System | Correlates customer calls and meter last-gasp messages to predict the failed device. |
| OPGW | Optical Ground Wire | A shield wire with optical fibers inside it — the transmission fiber workhorse. |
| PDC | Phasor Data Concentrator | Collects streams from many PMUs, time-aligns them, forwards one combined stream. |
| PLC | Power-Line Carrier | Communication injected onto the power conductor itself. (Not a programmable logic controller here.) |
| PMU | Phasor Measurement Unit | Measures voltage and current magnitude and phase angle many times a second, GPS-timestamped. |
| RC | Reliability Coordinator | The widest view of the grid that exists; sees across many utilities and can issue directives. |
| ROCOF | Rate of Change of Frequency | How fast frequency is moving, not just where it is. |
| RTAC | Real-Time Automation Controller | SEL's substation gateway: legacy serial on one side, modern Ethernet on the other. |
| RTU | Remote Terminal Unit | The substation's data concentrator; one stream to the control center. |
| SCADA | Supervisory Control And Data Acquisition | Remotely see (data acquisition) and operate (supervisory control) field equipment. No network model. |
| SEL | Schweitzer Engineering Laboratories | Relay and substation-automation manufacturer. |
| SOE | Sequence of Events | The time-ordered record of what tripped first — only trustworthy if the clocks agree. |
| TVE | Total Vector Error | The combined magnitude-and-angle error of a phasor measurement. The 1% limit is where the ±1 µs clock budget comes from. |
| UTC | Coordinated Universal Time | The single global time standard, distributed by GPS, that every synchrophasor locks to. |
| VPN | Virtual Private Network | An encrypted remote-access tunnel into a network. |
| WAMS | Wide Area Measurement System | The GPS-synchronized synchrophasor system running alongside conventional SCADA. |
| WAN | Wide Area Network | A network spanning long distances between sites — substation to control center. |