Hardware-in-the-Loop Evaluation of Authenticated IEC 61850 Communication in Digital Substations
The increasing digitization and interconnection of substations, driven by networked intelligent electronic devices (IEDs) that function as mission-critical Industrial IoT (IIoT) endpoints, exposes time-critical IEC 61850 communications, particularly Sampled Values (SV) and Generic Object Oriented Substation Events (GOOSE), to cyber threats while also imposing stringent latency constraints on any security enhancement. This paper presents an IEC 61850-aligned hybrid digital twin (HDT) testbed that enables end-to-end cyber–physical evaluation of authenticated SV and GOOSE messaging in a close-to-realistic substation environment. The proposed HDT couples a MATLAB/Simulink power-system model (process layer) with a hardware-based communication layer comprising heterogeneous IED emulation using industrial single-board computers, Node-RED application logic, and managed Ethernet switching to reproduce station, bay, and process level interactions using SV, GOOSE, and MMS. Building on the secure SV concept, the work implements extended protocol data units to realize both Secure Sampled Values (SeSV) and Secure GOOSE (SeGOOSE) using symmetric message authentication mechanisms, specifically HMAC (SHA-256/SHA-512 variants) and AES-GMAC (128/192/256). Performance is evaluated through per-stage processing time (publisher/subscriber MAC generation and verification) and end-to-end round-trip travel time (RTTT) spanning SV publication, IED decision processing, and GOOSE actuation signaling. Results demonstrate that authenticated SV/GOOSE operation remains within IEC 61850 timing expectations under the tested configurations, with measured RTTT of approximately 1.3 ms without authentication and up to 10 ms with authentication depending on algorithm choice and platform. The testbed provides a scalable, hardware-validated methodology for quantifying the practical latency cost of IEC 61850 message authentication and supports systematic cybersecurity experimentation for digital substations and smart-grid cyber–physical systems.