Skip to content
Use case 057

Electrical Substation Protection Gateways

A deployment concept for Transmission utilities procuring substation communication and engineering gateways; Protection equipment OEMs integrating gateway platforms; Substation engineering contractors delivering utility-approved station designs.

Proposed deployment · Compatibility assessment required
Energy, Utilities and Resources

Why this environment matters

A substation gateway may connect protection equipment to supervision, engineering tools and a remote control centre. Those paths operate on different timescales and should not inherit the same authority. This proposal places the candidate NØNOS boundary around supervisory and engineering access while preserving independently assessed protection functions.

The security challenge

A relay-status reader might need event and measurement access without any ability to change a setting group. A maintenance tool may require a temporary write permission for one relay. A proposed broker would express those differences explicitly and would bind a change request to the target device and the approved maintenance activity.

How the capsule model could help

Protocol parsing could occur inside restricted capsules, with a dedicated adapter handling accepted operations. The gateway would not be placed into a time-critical trip path merely to gain uniform software architecture. Any such placement would need its own timing and safety assessment, including behavior under overload and failure. After a disturbance, engineers need to reconstruct which observations and actions preceded the trip. Gateway recovery should preserve event ordering and identify uncertain timestamps rather than smoothing them into a convenient narrative. A temporary runtime can forward evidence to durable storage, but that storage and its clock dependencies need separate design. The pilot would compare a recorded event stream with relay-side records while introducing communication faults and rejected engineering commands. Success would mean that authorised access remains narrow and diagnosis remains possible; it would not establish protection-system correctness.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

Substation protocols, time synchronisation, protection coordination and vendor support must be established for the actual equipment. The proposed operating-system boundary would not replace certified protection devices or an approved engineering-change process. Evaluation requirements: Use a status-only identity to request a setting-group change and verify rejection before relay access. Interrupt a maintenance session and confirm that its write authority cannot be reused after expiry. Reconcile gateway and relay event records across a restart with deliberately uncertain clock synchronisation.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

Keep the engineering session distinct from protection traffic

A relay-status reader might need event and measurement access without any ability to change a setting group. A maintenance tool may require a temporary write permission for one relay. A proposed broker would express those differences explicitly and would bind a change request to the target device and the approved maintenance activity.

Protocol parsing could occur inside restricted capsules, with a dedicated adapter handling accepted operations. The gateway would not be placed into a time-critical trip path merely to gain uniform software architecture. Any such placement would need its own timing and safety assessment, including behavior under overload and failure.

A trustworthy event order matters during recovery

After a disturbance, engineers need to reconstruct which observations and actions preceded the trip. Gateway recovery should preserve event ordering and identify uncertain timestamps rather than smoothing them into a convenient narrative. A temporary runtime can forward evidence to durable storage, but that storage and its clock dependencies need separate design.

The pilot would compare a recorded event stream with relay-side records while introducing communication faults and rejected engineering commands. Success would mean that authorised access remains narrow and diagnosis remains possible; it would not establish protection-system correctness.

Who could buy or integrate it?

  • Transmission utilities procuring substation communication and engineering gateways
  • Protection equipment OEMs integrating gateway platforms
  • Substation engineering contractors delivering utility-approved station designs

Industry examples: Schweitzer Engineering Laboratories, Siemens. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.

Market opportunity

Market benchmarks and device scenarios.

Published industry benchmark
US$47.8 billion

Substation automation

Global · 2024 · annual market estimate

Hardware, software and services for transmission and distribution substations, including new projects and retrofits.

Modelled global devices
200K–3.2M

Candidate OS endpoints

Hypothetical planning range · 2025

Low confidence: planning assumptions. Hardware compatibility, procurement and adoption have not been validated.

Illustrative annual licensing
$10M–$960M

USD / year at full model coverage

Device scenario × assumed US$50–$300 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Hypothetical global planning range, 2025 scenario: assume 200,000–800,000 high- and medium-voltage substations with digital integration × 1–4 candidate OS endpoints per site/asset = 200,000–3,200,000 endpoints. Counting unit: station protection/security gateways, not every feeder relay. Site and asset counts, and devices per site, are planning assumptions. The installed base has not been measured. Coverage is limited to the defined equipped subset; includes all candidate endpoints within that assumed subset. Hardware eligibility, certification, adoption and achievable NØNOS share are unverified; overlaps other cases.

Substation Automation Market Size, Share Report 2025-2030 ↗

Market context only; separate from device and site population estimates. Original monetary-market scope and geography are preserved in benchmark. This source does not establish the assumed worldwide site count or endpoint density.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints multiplied by an assumed annual USD price per endpoint. Pricing is a planning assumption, not a vendor quote. This illustrates the full scenario range, not revenue or total addressable market. It excludes adoption timing, procurement, certification, support costs, channel economics and achievable market share. Use cases can overlap, so their totals do not represent unique devices.

Research from 2026. Publisher estimates have not been independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.