SCADA systems

SCADA components, RTUs, communication media, polling versus report by exception, protocols, cybersecurity and link/polling-time calculations.

Drafted with Aria, reviewed by the AiCanCode.org team. Spotted an error? Use Give Feedback at the bottom of the page.

Why it matters

Water supply networks, oil and gas pipelines, electricity transmission and distribution, metro rail power and irrigation canals are spread over tens to thousands of kilometres. Supervisory control and data acquisition (SCADA) lets a few operators in one control centre watch and command all of it. SCADA engineering — RTUs, communication links, protocols and cybersecurity — is a large employer of instrumentation graduates in India's smart-city, power and water sectors.

Key ideas

What SCADA does. It acquires data (analog values, statuses, counters, alarms) from remote sites, presents it to operators, stores it, and sends supervisory commands (start a pump, open a breaker, change a set point). Fast closed-loop control normally stays local, in the RTU or PLC at the site; SCADA supervises it.

Components.

  • Field instruments and devices — transmitters, flowmeters, valve actuators, breakers, pump starters.
  • RTU (remote terminal unit) or PLC at each site — reads I/O, runs local logic, time-stamps events, buffers data, and communicates with the master. RTUs are built for wide temperature ranges, low power (often solar) and weak links. In substations, IEDs (intelligent electronic devices such as protection relays) also act as data sources.
  • Communication system — licensed radio, GSM/4G, fibre, leased lines, power-line carrier, VSAT satellite. Links may be slow, costly and intermittent.
  • Master station — redundant SCADA servers with front-end processors, a real-time database, historian, alarm and event processing, and HMI clients in the control centre. In power systems it is extended into an energy management system (EMS) or distribution management system (DMS).

Data collection methods.

  • Polling — the master asks each RTU in turn. Simple and deterministic; the polling cycle time grows with the number of RTUs and the data per RTU.
  • Report by exception (unsolicited reporting) — the RTU sends only values that changed by more than a deadband, plus periodic integrity polls. Much less traffic and faster alarm delivery on slow links.
  • Sequence of events (SOE) — status changes are time-stamped at the RTU to millisecond resolution (with GPS-synchronised clocks), so the order of breaker trips can be reconstructed regardless of when the data reaches the master.
  • Store and forward — data is buffered in the RTU during a link outage and back-filled into the historian later.

Protocols. Modbus RTU (serial) and Modbus TCP — simple master/slave register reads; DNP3 — widely used in water and power, supports time-stamped events, unsolicited reporting and data classes; IEC 60870-5-101/104 — telecontrol for power grids; IEC 61850 — substation automation. Serial characters usually carry start, stop and parity bits, so a byte costs 10 or 11 bits on the line.

SCADA versus DCS. SCADA is event- and data-driven, works over wide areas and unreliable links, and leaves control local. A DCS is a tightly integrated, high-speed system inside one plant that executes the control loops itself. The distinction blurs as both use Ethernet and the same HMI software.

Cybersecurity. SCADA once relied on isolation ("air gap"); today's networks are connected, and attacks such as Stuxnet (2010) and the Ukrainian grid attacks showed the risk. Good practice follows IEC 62443: zones and conduits, firewalls and a DMZ between corporate IT and the control network, secure remote access, authentication on protocols (DNP3 Secure Authentication), patch and backup management, and monitoring.

Formulas

t_tx = N_bits / R

  • t_tx: transmission time (s); N_bits: bits sent including framing (start, parity, stop bits); R: line bit rate (bit/s).

N_bits = N_bytes × b_char

  • b_char: bits per character on the line (10 for 8-N-1, 11 for 8-E-1 or 8-N-2).

T_cycle = Σ (t_request + t_response + t_turnaround) over all RTUs

  • Polling cycle time (s); t_turnaround: RTU response delay plus modem/radio key-up time.

R_required = n_values × bits_per_value × updates_per_second × (1 + overhead)

  • Data rate needed for continuous updates (bit/s).

Worked examples

Example 1 (standard) — link loading. An RTU must send 200 analog values every second; each value is 16 bits, and protocol overhead adds 25 %. (a) What bit rate is needed? (b) Can a 9600 bit/s radio link carry this?

  1. R_required = 200 × 16 × 1 × 1.25 = 4000 bit/s.
  2. Link utilisation = 4000/9600 = 0.417 (about 42 %).
  3. The link can carry it in principle, but with other RTUs sharing the channel, retries and turnaround delays, report-by-exception with deadbands would be the safer design.

Example 2 (GATE level) — polling cycle. A master polls 50 RTUs at 19 200 bit/s. Each poll (request + response) is 40 bytes in total, sent as 11-bit characters, and each RTU adds a turnaround delay of 30 ms. (a) Find the time per RTU and the full polling cycle. (b) What is the worst-case delay before a new alarm at an RTU reaches the master?

  1. Bits per poll = 40 × 11 = 440 bits.
  2. Transmission time per RTU = 440/19 200 = 0.0229 s = 22.9 ms.
  3. Time per RTU = 22.9 + 30 = 52.9 ms.
  4. Polling cycle = 50 × 52.9 ms = 2.65 s.
  5. (b) An alarm that occurs just after its RTU has been polled waits almost a full cycle before the next poll, so the worst-case delay is about 2.6 s plus the poll itself (≈ 2.7 s). Unsolicited reporting (e.g. DNP3) would deliver it within one message time, and SOE time-stamps preserve the true event time either way.

Common mistakes

  • Using 8 bits per byte for serial links and forgetting start, parity and stop bits.
  • Putting fast control loops in the SCADA master instead of the RTU/PLC; a link failure then stops control.
  • Polling everything at the same fast rate instead of grouping data by priority and using report by exception.
  • Using the arrival time at the master as the event time; use RTU time-stamps for sequence of events.
  • Treating the air gap as security; connections through laptops, USB drives and vendor remote access bypass it.
  • Ignoring clock synchronisation between RTUs, which makes SOE logs useless.

For GATE IN

SCADA appears mainly in conceptual questions: components and their roles, polling versus report by exception, SCADA versus DCS, common protocols and communication media. Numericals are short data-communication calculations — transmission time, bit rate, polling cycle time — so be careful with framing bits and units.

Quick check

  1. A 2400-bit message is sent at 9600 bit/s. How long does it take?
  2. What does an RTU do when the communication link fails?
  3. Name two protocols that support time-stamped event reporting.
  4. Why is report by exception preferred on slow radio links?

Answers: 1. 0.25 s. 2. It continues local logic and control, and buffers time-stamped data for later transmission. 3. DNP3 and IEC 60870-5-101/104 (also IEC 61850). 4. It sends only changed values, cutting traffic and delivering alarms faster than waiting for the next poll.

Try answering each one aloud before you open it.

  1. 1.What is a SCADA system and what are its main components?Concept

    A SCADA (Supervisory Control and Data Acquisition) system is used for monitoring and controlling industrial processes. Its main components include: 1) Human-Machine Interface (HMI) for user interaction, 2) Remote Terminal Units (RTUs) or Programmable Logic Controllers (PLCs) for data collection and control, 3) Communication infrastructure for data transmission, and 4) A central server or database for data processing and storage.

  2. 2.Explain the role of Human-Machine Interface (HMI) in a SCADA system.Concept

    The Human-Machine Interface (HMI) in a SCADA system serves as the user interface that allows operators to interact with the system. It provides graphical displays of the process data, alarms, and controls, enabling operators to monitor the system status and make informed decisions. HMIs are crucial for visualizing complex data in an understandable format.

  3. 3.Why are Remote Terminal Units (RTUs) used in SCADA systems?Application

    Remote Terminal Units (RTUs) are used in SCADA systems to collect data from sensors and devices in the field and transmit it to the central SCADA server. They also execute control commands from the server to the field devices. RTUs are essential for extending the reach of SCADA systems to remote or geographically dispersed locations.

  4. 4.What happens if the communication link between the RTU and the SCADA server fails?Application

    If the communication link between the RTU and the SCADA server fails, the RTU may continue to operate autonomously based on pre-programmed logic. However, real-time monitoring and control from the central server will be lost, potentially leading to delayed responses to process changes or alarms. Redundancy and backup communication paths are often implemented to mitigate such risks.

  5. 5.How does a SCADA system improve process efficiency?Application

    A SCADA system improves process efficiency by providing real-time data monitoring and control, which allows for quick detection and correction of process deviations. It enables predictive maintenance by analyzing trends and identifying potential equipment failures before they occur. Additionally, SCADA systems optimize resource usage by automating control processes and reducing human intervention.

  6. 6.What are the security challenges associated with SCADA systems?Concept

    SCADA systems face security challenges such as vulnerability to cyber-attacks, unauthorized access, and data breaches. These systems often control critical infrastructure, making them attractive targets for attackers. Implementing robust cybersecurity measures, such as firewalls, encryption, and regular security audits, is essential to protect SCADA systems from these threats.

  7. 7.Explain the difference between SCADA and DCS (Distributed Control System).Concept

    SCADA systems are designed for monitoring and controlling processes over large geographical areas, often using RTUs and communication networks. In contrast, Distributed Control Systems (DCS) are used for process control within a localized area, typically in a single facility, using a network of controllers. DCS systems are more focused on process control, while SCADA systems emphasize data acquisition and monitoring.

  8. 8.Why is redundancy important in SCADA systems?Application

    Redundancy in SCADA systems is important to ensure reliability and continuous operation in case of component failures. By having backup systems or communication paths, SCADA systems can maintain functionality even if a primary component fails. This is crucial for critical infrastructure where downtime can lead to significant safety and financial consequences.

  9. 9.Calculate the data transmission rate required for a SCADA link that must carry 500 sensor readings per second, each 16 bits in size.Numerical

    The raw payload is 500 × 16 = 8000 bit/s. That is only a lower bound: each reading also carries protocol overhead (addresses, function codes, CRC, time-stamps), and on a serial link every byte costs 10–11 bits with start, parity and stop bits, so the line rate needed is typically 1.5–2 times higher. In practice you would choose a link of at least about 19.2 kbit/s, or reduce traffic with report by exception and deadbands.

  10. 10.A SCADA system has a polling interval of 2 seconds. How many times will it poll a device in one hour?Numerical

    To find the number of polls in one hour, divide the total time in seconds by the polling interval: 3600 seconds/hour ÷ 2 seconds/poll = 1800 polls/hour. Therefore, the SCADA system will poll the device 1800 times in one hour.

Finished this topic? Mark it so your progress, study plan and readiness keep up.

Stuck on something here?