What is HSR?
HSR (High-availability Seamless Redundancy) is an Ethernet ring redundancy protocol, defined in IEC 62439-3, in which every node sends each frame in both directions around the ring at the same time, so that a single cable or device failure loses no frames and the recovery time is zero. The receiver uses whichever copy arrives first and discards the duplicate. HSR is the ring-based sibling of PRP and is used above all in digital substations built to IEC 61850, where protection relays cannot afford to miss even a millisecond of communication.
π§ How does HSR work?
In an HSR ring every device has two network ports, A and B. Such a device is called a DANH (Doubly Attached Node with HSR). The principle in five steps:
- Duplicate β the sender makes two copies of each frame and inserts an HSR tag carrying the same sequence number in both
- Both directions β copy A travels clockwise, copy B anticlockwise
- Forward β every intermediate node forwards frames in hardware, typically within a few microseconds per hop
- Discard the duplicate β the receiver recognises the pair of source MAC address and sequence number, passes the first frame to the application and drops the second
- Remove from the ring β a unicast frame is not forwarded any further by its destination; a multicast frame travels the whole ring and is removed by the node that originally sent it
If the ring breaks at one point, only the copy coming from the other side arrives. No fault detection, no switchover and no recalculation of the topology is needed: the recovery time is literally zero.
The HSR tag
| Field | Size | Purpose |
|---|---|---|
| EtherType | 16 bits | Value 0x892F identifies an HSR frame |
| Path identifier | 4 bits | Network ID and whether this is the A or B copy (relevant when coupling with PRP) |
| LSDU size | 12 bits | Length of the payload, for a quick consistency check |
| Sequence number | 16 bits | Together with the source MAC address, the key for duplicate detection |
The tag adds 6 bytes, so frames become slightly longer than the classic Ethernet maximum. This only matters inside the ring.
π§ What do a RedBox and a QuadBox do?
Not every device speaks HSR. A laptop, camera or older relay has only one network port. You connect these Singly Attached Nodes (SANs) through a RedBox (Redundancy Box). The RedBox adds the HSR tag on the deviceβs behalf and removes duplicates, so the ring sees it as a full HSR node.
A RedBox supports several modes:
- HSR-SAN β connects ordinary devices or an ordinary LAN to the ring
- HSR-PRP β connects an HSR ring to the two networks (LAN A and LAN B) of a PRP network
- HSR-HSR β couples two HSR rings; such a device is called a QuadBox
A QuadBox has four ring ports, two per ring. To avoid creating a new single point of failure, you always couple two rings with two QuadBoxes. This allows hierarchical designs, for instance a station ring with subordinate rings per bay or voltage level.
π°οΈ How was HSR standardised?
HSR was originally called HASAR, after the initials of the five utility-sector vendors that created it: Hirschmann, ABB, Siemens, Alstom and RuggedCom. IEC 62439-3 covers PRP and HSR together, while MRP is specified in part 2 of the same series.
| Edition | Year | Main change |
|---|---|---|
| 1.0 | 2010 | First publication of PRP and HSR |
| 2.0 | 2012 | Dedicated EtherType 0x892F for HSR (edition 1 shared 0x88FB with PRP), HSRβPRP coupling, clock synchronisation to IEC 61588, test modes |
| 3.0 | 2016 | Technical corrections, PTP with end-to-end delay measurement alongside peer-to-peer |
| 4.0 | 2021 | Current edition (December 2021), amended by a corrigendum in 2023 |
π How does HSR compare with PRP, MRP, RSTP and DLR?
All five provide redundancy in Ethernet networks, but with fundamentally different mechanisms. HSR and PRP send everything twice and therefore never switch over; MRP, RSTP and DLR block a port and only open it when a fault occurs.
| Feature | HSR | PRP | MRP | RSTP | DLR |
|---|---|---|---|---|---|
| Standard | IEC 62439-3 | IEC 62439-3 | IEC 62439-2 | IEEE 802.1D/802.1w | ODVA (EtherNet/IP) |
| Topology | Ring | Two separate networks | Ring | Any (tree, mesh) | Ring |
| Recovery time | 0 ms | 0 ms | 10β500 ms (depending on class) | Tens of ms to seconds | < 3 ms for 50 nodes |
| Frame loss on failure | No | No | Yes, during recovery | Yes, during recovery | Yes, briefly |
| Extra hardware | No switches needed, but HSR in every device | Duplicate network | Ring manager | None | Ring supervisor |
| Bandwidth | Ring carries double traffic | Each network carries everything once | Normal | Normal | Normal |
| Typical use | Substations, synchronised drives | Substations, process industry | PROFINET machines | Office and backbone networks | EtherNet/IP installations |
In short, PRP is more flexible and scales better but requires two complete networks. HSR saves switches and cabling, but each ring has limited capacity. A broader overview of ring protocols is available under Ring Redundancy.
π Where is HSR used?
- Digital substations β IEDs such as protection relays and merging units exchange GOOSE messages and Sampled Values. IEC 61850 names PRP and HSR as the redundancy protocols for the station bus and the process bus.
- Grid operation and energy β high- and medium-voltage substations, converter stations and wind farms
- Synchronised drives β for example in printing machines, where several axes under motion control must stay in exact step
- Power electronics β control of large inverters, where a communication loss immediately leads to a trip
π How many devices fit in an HSR ring?
Because every frame travels the ring twice, only about half the bandwidth is available for multicast traffic: a full-duplex 100 Mbit/s ring delivers 100 Mbit/s, not 200. The forwarding delay per hop also accumulates; with cut-through forwarding in hardware it is around 5 microseconds per node at 100 Mbit/s. Vendors therefore cap the ring size; Cisco, for example, supports a maximum of 50 nodes per ring.
A worked example for a 50 Hz grid: one Sampled Values stream according to IEC 61850-9-2LE sends 80 samples per cycle, i.e. 4,000 frames per second, adding up to just over 5 Mbit/s. Ten merging units already need about 53 Mbit/s, and because this multicast traffic circles the whole ring it loads every link. In practice:
- Choose 1 Gbit/s for rings carrying process bus traffic; 100 Mbit/s is sufficient for station buses with only GOOSE and MMS
- Keep rings with Sampled Values small and spread the remaining devices over several rings
- Couple rings through QuadBoxes or a PRP backbone rather than building one large ring
- Filter multicast using VLANs or multicast filtering on RedBoxes, so traffic is not forwarded unnecessarily
- Calculate the latency β number of hops times the per-node delay, plus the queuing time behind large frames
β±οΈ How does time synchronisation work over HSR?
Protection functions such as differential protection compare measurements from different merging units and therefore need an accuracy of about 1 microsecond. You achieve this with the Precision Time Protocol (IEEE 1588 / IEC 61588). IEC 62439-3 contains the PTP Industry Profile in Annex C, and for the energy sector there is IEC/IEEE 61850-9-3:2016, the Power Utility Profile. Both describe how PTP messages travel over PRP and HSR; the Annex C profile achieves an accuracy of 1 microsecond in a ring of 16 HSR nodes. Because every node forwards the clock messages, HSR nodes act as a transparent clock that corrects for the residence time at each hop, while a RedBox can additionally act as a boundary clock.
π What are the security risks of HSR?
HSR improves availability, not security. The HSR tag has no authentication or encryption. An attacker with access to the ring can inject frames with a forged source MAC address and sequence number, causing nodes to discard the genuine frame as a duplicate. A flood of multicast traffic also hits the entire ring, because every node forwards it.
Countermeasures:
- Physical security β the ring runs through every device, so every free port and every RedBox is an entry point
- Network segmentation β keep the HSR ring a closed zone according to IEC 62443 and connect to the outside only through a firewall
- Port security on RedBoxes β allow only known devices on the SAN side
- Network monitoring β note that some equipment does not support port mirroring (SPAN) on HSR ports; monitor through a RedBox or network tap and feed alerts to an OT SOC
- Application-level security β use IEC 62351 to authenticate GOOSE and Sampled Values where the equipment supports it
β Frequently asked questions
What does HSR mean in networking?
HSR stands for High-availability Seamless Redundancy, an Ethernet redundancy protocol from IEC 62439-3. HSR sends every frame in both directions around a ring, so the connection keeps working without interruption after a single failure. HSR is mainly used in substations and other critical OT networks.
Does HSR need switches?
No, HSR does not in principle need separate switches, because every HSR device forwards frames to the next node in the ring itself. Only devices without HSR support need a RedBox. Every node in the ring must, however, support HSR in hardware to keep the forwarding delay low.
Which is better, HSR or PRP?
It depends on the size and the traffic. HSR is cheaper because no second network is needed, but the ring carries double traffic and in practice is limited to a few dozen nodes at most. PRP scales better with many devices and heavy traffic but requires two completely separate networks; HSR and PRP are often combined through RedBoxes.
What happens when an HSR ring has two failures?
With two failures at the same time an HSR ring is split into two segments, and devices on either side can no longer reach each other. HSR protects against a single failure only. The first failure must therefore be detected and repaired quickly, which HSR devices support through supervision frames and diagnostics.
Can HSR be used together with PTP?
Yes, HSR is designed to work with the Precision Time Protocol. IEC 62439-3 and the power profile IEC/IEEE 61850-9-3 describe how PTP messages travel around an HSR ring and how nodes correct for the transit delay. This lets an HSR network reach the accuracy of about 1 microsecond that process bus applications require.
Is HSR suitable for general industrial automation?
HSR can be used in any Ethernet environment, but it is less common outside the energy sector. In machine building and factory automation, MRP and DLR are more widespread, because a recovery time of a few milliseconds is usually sufficient there. HSR makes the most sense where even a single lost frame causes a fault or a trip.
π In summary
HSR sends every frame in both directions around a ring, delivering zero recovery time and no frame loss on a single failure, without extra switches. The price is double traffic on the ring and a limited number of nodes; combine HSR with PRP, PTP and sound segmentation for reliable and secure substation networks.
