Migrating from SONET/SDH and TDM to IP/MPLS for Reliable Protection and Control in Electric Utilities
By Mauricio SUBIETA, Ph.D., CISSP, Energy CTO and Head of Technology Nokia, USA

Electric utilities have long relied on SONET/SDH and TDM-based technologies to transport mission-critical teleprotection traffic for applications such as line differential protection, distance protection, and overcurrent protection. These legacy systems, often interfaced via serial T1/E1 or C37.94 connections, provide deterministic and low-latency communication, requirements essential for maintaining grid reliability and fault response performance. However, the telecommunications industry is rapidly phasing out support for these technologies, and many of the platforms currently in use are nearing or have already reached end-of-life status. This has left utilities with an urgent need to modernize their communications infrastructure without compromising the stringent performance expectations of protection and control systems.
This article discusses the migration path from legacy TDM-based infrastructure to modern packet-based communications, leveraging IP/MPLS as a robust, scalable, and highly reliable transport solution. Utilities can now encapsulate legacy TDM and serial-based traffic within converged packet networks using circuit emulation techniques, such as CPIPES, which enable transparent transport of C37.94 and T1/E1 traffic over Ethernet and IP/MPLS.
These CPIPEs allow utilities to continue using their existing protection relays and specialized equipment while benefiting from the operational efficiencies and flexibility of packet-switched networks.
A converged IP/ Multi-Protocol Label Switching (MPLS) network offers numerous advantages beyond simple transport replacement. It provides native support for Quality of Service (QoS), traffic engineering, and multi-service convergence, enabling utilities to run protection, SCADA, voice, and corporate IT traffic on a single network infrastructure. Advanced features such as Adaptive Delay Control and Active Multipath ensure hitless failover and fast recovery, meeting the zero-packet-loss and low-latency requirements of protection schemes even during network failures. This level of resiliency was historically only achievable with dedicated fiber or specialized hardware, and its availability in a standards-based packet network represents a major step forward for utility communications.
SONET/SDH and TDM-based Transport of Teleprotection Traffic
Synchronous Optical Networking (SONET) and Synchronous Digital Hierarchy (SDH) have long served as the technologies transporting mission-critical teleprotection traffic in power utility transmission networks. These systems encapsulate protection signals into virtual containers (VCs) or synchronous payload envelopes (SPEs), mapped to optical carrier levels in SONET or synchronous transport modules in SDH. This structure ensures that critical communications, such as line differential protection, distance protection, and overcurrent protection, are transmitted with guaranteed latency and isolation, supporting sub-10 ms end-to-end performance required by relay schemes.
Serial T1 (1.544 Mbps) and E1 (2.048 Mbps) interfaces have historically been used to transport teleprotection traffic over dedicated timeslots. Teleprotection relays connected via RS-232 or V.35 interfaces to multiplexers that aggregated multiple channels onto a T1/E1 span, enabling deterministic paths with tightly bounded jitter. IEEE C37.94 defines a standardized optical interface transporting up to 12 multiplexed 64 kbps channels over multimode fiber, delivering predictable propagation delay ideal for line differential relaying.

The absence of contention and store-and-forward behavior, coupled to the point-to-point connectivity model, makes these technologies inherently suitable for teleprotection, where deterministic delivery within milliseconds is required. However, these platforms are reaching end of life with diminishing vendor support, scarcity of spare parts, and declining expertise, making maintenance increasingly costly. Their rigid bandwidth allocation and lack of native IP and Ethernet integration hinder accommodation of growing traffic volumes driven by distributed energy resources (DERs), electric vehicle (EV) charging infrastructure, and AI-enabled grid analytics.
Packet-based Networks and IP/MPLS for Mission-Critical Traffic
Electric utilities are increasingly deploying packet-based technologies to modernize their communications infrastructure, replacing aging TDM, SONET, and SDH legacy systems. Among these, IP/MPLS stands out as the most suitable candidate, offering a unique mix of flexibility, determinism, and performance. IP/MPLS combines the dynamic routing capabilities of IP with the predictable behavior of pre-established label-switched paths (LSPs). Packets entering the network are assigned short numerical labels, enabling label switch routers to forward traffic efficiently without traditional IP lookups, ensuring deterministic transport with precise QoS policies essential for teleprotection, SCADA, and distribution automation.
IP/MPLS is particularly well-suited to support teleprotection applications. Through advanced traffic engineering, operators can precisely control path selection and resource allocation, while QoS prioritization guarantees preferential treatment for the most critical traffic. MPLS pseudowires and circuit emulation services facilitate migration of serial T1/E1 and C37.94 interfaces onto the IP/MPLS backbone without disrupting existing protection schemes. The Fast Reroute mechanism recovers from failures within 50 milliseconds, Active Multipath ensures hitless failover, and adaptive delay control maintains symmetric latency across redundant paths. IP/MPLS also supports IEEE 1588 Precision Time Protocol transport, ensuring sub-microsecond timing accuracy required for advanced protection applications.
A Comparison Between SDH/SONET and IP/MPLS
MPLS enables connection-oriented paths across a connectionless IP network, allowing advanced traffic engineering and efficient use of network resources, and supports both Layer 1 and Layer 2 services concurrently over optical fiber, microwave, and copper. While migrating from TDM and SDH/SONET to IP/MPLS may seem like a significant shift, both technologies share fundamental principles. The following sections highlight these commonalities.
Framed-based Data Transmission: TDM and SDH/SONET use fixed-size frames at constant rates. MPLS uses variable-size frames and adapts transmission to traffic. It can emulate fixed-rate circuits for TDM or send on-demand for IP/Ethernet, efficiently handling both small constant flows and large bursty traffic.
Circuit-based Connections: Utilities provision an end-to-end circuit for transport in both TDM/SDH/SONET and MPLS networks. In the former, a channel bank is positioned in front of the SDH/SONET add-drop multiplexer, and legacy interfaces are multiplexed into timeslots within an E1 or DS1 carrier before being cross-connected across the SDH/SONET network.
Legacy DS1/E1 circuits can be transported over MPLS as pseudo wire circuits within an LSP. In an IP/MPLS environment, the bandwidth reserved for each LSP can be any value within the line rate, rather than being restricted to rigid 2 Mb/s or 1.544 Mb/s increments, providing greater flexibility in capacity planning. The physical route of an LSP can be explicitly defined or dynamically computed according to policies or constraints such as required bandwidth, hop count, and link characteristics.
Multi-protocol Traffic Support: Both SDH/SONET and MPLS networks can transport multiprotocol data within their respective framing structures. Whether it is TDM traffic, Frame Relay, or Ethernet and IP packets, these diverse protocols can be encapsulated and delivered reliably. MPLS frames can also be transported directly over SDH/SONET infrastructure using the Packet over SONET/SDH framing format defined in IETF RFC 2615.

While an SDH/SONET network can carry Ethernet and IP traffic, it primarily acts as a transport layer without integrated awareness of higher-layer services. In contrast, MPLS provides extensive multiprotocol support that goes beyond simple transport. MPLS networks natively integrate bridging and routing capabilities, enabling operators to deliver both Layer 2 Ethernet VPNs and Layer 3 IP VPN services within a unified infrastructure (see Figure 1). This flexibility allows utilities to perform Layer 2 and Layer 3 aggregation, support a wide variety of service types, and efficiently deliver differentiated network service offerings to different applications and operational domains. By supporting encapsulation of legacy protocols alongside modern IP and Ethernet traffic, MPLS enables seamless convergence of services and simplifies network architectures as utilities transition from TDM-centric designs to flexible, packet-based environments. (see Figure 1).
Quality-of-Service Assurance: Because TDM-based utility applications are sensitive to delay and jitter, their traffic must be handled with the highest priority. When traffic arrives at a router, it is classified based on header markings and assigned to different priority queues. TDM traffic, including teleprotection, is placed in high-priority queues where it is serviced continuously to minimize delay and jitter.
SDH/SONET supports traffic delivery with guaranteed quality of service through its rigid framing hierarchy. However, this structure treats all applications uniformly, reserving fixed bandwidth even for bursty, non-critical traffic, ensuring QoS but often resulting in inefficient capacity use.

By contrast, MPLS was designed to deliver guaranteed QoS with greater flexibility and efficiency. IP/MPLS networks classify, police, and rate-limit traffic from each application before it enters the network, enabling operators to assign appropriate priorities to each flow. Critical TDM and teleprotection traffic receives dedicated, low-latency treatment while bandwidth is optimized for less sensitive applications. Legacy traffic can be prioritized at the highest QoS level to guarantee it always falls within the committed information rate. Applying hierarchical QoS further enables a defined group of services to share a fixed portion of capacity, ensuring fairness and predictable performance among different service classes.
Strong Network Resilience: Current SDH/SONET networks use automatic protection switching (1+1 APS) and ring topologies for link and nodal protection. These mechanisms have proven extremely reliable, delivering recovery within 50 ms after a fault.
IP/MPLS offers greater flexibility through Fast Reroute, which dynamically redirects traffic to pre-established backup LSPs, achieving sub-50 ms restoration. Unlike SDH/SONET, which reserves bandwidth exclusively for protection, MPLS maintains fully utilized links while still ensuring rapid failover. Segment Routing further enhances resiliency by enabling the source node to define explicit forwarding paths and quickly redirect traffic around faults without full LSP reconvergence.
MPLS uniquely supports geo-redundant protection, enabling traffic to automatically fail over to a secondary control center if the primary site is compromised (see Figure 2). This capability provides unmatched operational continuity for critical services during severe incidents.
Extensive OAM Features: SDH/SONET’s operations, administration, and maintenance (OAM) capabilities, including alarm propagation, remote defect indication, and loss-of-signal detection, have been essential to daily network operations for utilities.


IP/MPLS offers a comprehensive suite of end-to-end OAM tools that provide similar and often more granular visibility and control. Capabilities such as LSP ping and traceroute allow precise verification of label-switched path connectivity, while virtual circuit connectivity verification tools ensure end-to-end service integrity. Bidirectional Forwarding Detection (BFD) enables rapid fault detection and failure notification within milliseconds, supporting fast reroute and hitless failover. These IP/MPLS OAM mechanisms are further complemented by the native OAM features of the underlying transport technologies, whether Ethernet, microwave, or SDH/SONET, allowing the utility to monitor performance, detect degradation, and quickly isolate faults across all network layers.
Support for Time Synchronization: In an SDH/SONET network, frequency synchronization essential for TDM transport is achieved by recovering line timing directly from the SDH/SONET interface. An IP/MPLS network can provide equivalent precision by recovering timing from an SDH/SONET interface, a Synchronous Ethernet link, or a packet microwave link. For applications requiring phase and time-of-day synchronization, SDH/SONET networks typically rely on an external GPS receiver at each remote site, creating a single point of failure. If the GPS signal degrades or the receiver fails, synchronization is lost and devices must revert to holdover mode, where clock accuracy quickly deteriorates.
In contrast, IP/MPLS networks can natively transport phase and time-of-day using the Precision Time Protocol as defined in IEEE 1588-2008 and further profiled in IEC/IEEE 61850-9-3 for utility substation automation. Modern MPLS platforms integrate PTP hardware timestamping and boundary clock functions, enabling highly accurate time distribution across multiple network spans. This capability provides resilient, redundant synchronization without relying solely on local GPS receivers, supporting the precise timing needed for advanced substation automation and teleprotection.
IP/MPLS Circuit Emulation Service: CPIPE
An IP/MPLS network uses Circuit Emulation Service (CES), also known as a CPIPE, to transport legacy TDM application data. Key engineering considerations for provisioning CES include latency, jitter, and synchronization, as different TDM services have varying requirements.

Latency for TDM traffic consists of packetization delay at ingress, network transit delay, and jitter buffer or playout delay at egress. To optimize performance, IP/MPLS routers must enable utilities to fine-tune packetization and jitter buffer parameters according to network topology.
Using IP/MPLS CES functionality makes interworking with legacy TDM networks straightforward. CES maintains all information necessary to emulate a TDM circuit end-to-end, delivering the same predictable quality of experience as traditional infrastructure. This capability ensures seamless migration to a packet-based network while preserving TDM service continuity (see Figure 3).
TDM Packetization: The ingress IP/MPLS router receives digital frames at fixed intervals (e.g., 1 byte every 125 microseconds for a DS0 circuit) and encapsulates them into MPLS frames containing two labels: a tunnel label identifying the LSP and a service label identifying the pseudowire circuit for the CPIPE service (see Figure 4).

It is essential that the 3-bit Traffic Class field is marked appropriately to reflect an expedited QoS class, with the exact value determined by the utility’s QoS policy. Utilities can choose to transmit each byte immediately with minimal packetization delay or wait to accumulate a configured number of bytes before transmission, trading lower bandwidth efficiency for reduced delay. Smaller payloads increase frame rate and bandwidth consumption but minimize packetization and end-to-end delay, while larger payloads reduce bandwidth use at the cost of higher delay. By carefully configuring payload size based on network design and the delay budget of TDM applications, utilities can meet stringent latency requirements and optimize performance
MPLS Per-Hop Behavior: During label switching, the priority of MPLS frames carrying TDM traffic is indicated by the EXP field (see Figure 5). With correct marking and careful network engineering, these frames are placed in the highest-priority queue and forwarded without unnecessary queuing delay. As a result, each label-switching hop adds negligible delay, and frames are switched immediately with minimal jitter.
TDM Behavior at Service Egress: When MPLS frames carrying TDM payloads arrive, the payload is extracted into a playout buffer (see Figure 6). To absorb transit jitter, playout begins only after the buffer is half full. Buffer size should be configured based on packet size and estimated network jitter, which depends on factors like hop count and link speed. The network engineers at the utility should measure delay and jitter during design to ensure proper settings before deployment.
End-to-End Delay Considerations: With careful network design, CPIPE services can consistently meet strict QoS requirements. At the ingress point, the CPIPE packetizes TDM data, introducing a predictable delay that can be adjusted as needed. Increasing the packetization interval allows each MPLS frame to carry more TDM payload, improving bandwidth efficiency. On egress, a playout buffer absorbs delay variations accumulated during transit, enabling precise reconstruction of the TDM signal to legacy interfaces.

The size of this buffer directly affects latency: smaller buffers reduce delay but require very stable jitter, while larger buffers add delay but offer more tolerance for network variability. Fine-tuning packetization and jitter buffer settings, along with accounting for overall transit delays, delivers end-to-end deterministic performance. Supported by advanced QoS capabilities, this approach ensures CPIPE traffic is handled with consistent timing.
TDM Circuit Synchronization: Synchronization of the TDM circuit end to end is a critical requirement for CPIPE services. IP/MPLS platforms support a comprehensive range of synchronization options, including integrated GPS receivers, line timing via Ethernet or SDH/SONET/PDH interfaces, and timing-over-packet technologies such as IEEE 1588v2 Precision Time Protocol, differential clock recovery, and adaptive clock recovery (see Figure 7). This flexibility allows utilities to align CPIPE services with their existing synchronization infrastructure and maintain precise timing across the network.
Migration Steps from TDM/SONET/SDH to IP/MPLS
Migration can occur in many forms depending on available network resources and operational constraints. This paper outlines a migration scenario that provides a recommendation for electrical utilities, with the objective of minimizing disruption to existing applications. It is recommended that the transition from SDH/SONET to MPLS occur in three phases.
In Step 1, IP/MPLS routers are integrated with the existing SDH/SONET infrastructure (see Figure 8). This approach enables the delivery of new IP services and Ethernet connectivity while maintaining TDM services on the legacy network, reducing both costs and operational disruption. Utilities gain time to build familiarity with IP/MPLS capabilities before migrating critical TDM traffic.
In Step 2, IP/MPLS routers begin supporting traditional TDM services, including STM-1/OC-3, T1/E1, RS-232, V.35, X.21, and E&M, enabling these services to migrate away from the SDH/SONET infrastructure (see Figure 9). This transition can be staged gradually, allowing different interface types to coexist. Legacy TDM services can continue on existing multiplexers or move to the IP/MPLS routers, while new Ethernet interfaces support these applications.
In Step 3, the SDH/SONET network is fully decommissioned once all services have migrated (see Figure 10). The existing fiber plant is repurposed to interconnect the IP/MPLS routers directly, simplifying network architecture. Newer technologies such as Dense-Wavelength Division Multiplexing can then be implemented to increase the capacity of the installed physical fiber.
Conclusion – The migration from legacy SDH/SONET technologies to modern IP/MPLS networks represents an important evolution for utilities seeking to build resilient, scalable, and future-proof communication systems. IP/MPLS delivers flexibility through deterministic quality of service, traffic engineering, and advanced protection mechanisms including Fast Reroute, Adaptive Delay Control, and Active Multipath. These features ensure ultra-reliable, hitless failover and symmetric latency essential for teleprotection, IEC 61850-based automation, and real-time grid operations. Unlike traditional TDM systems that treat all traffic uniformly, IP/MPLS allow fine-grained prioritization and efficient bandwidth utilization, supporting seamless transition of TDM services via CPIPEs while enabling deployment of Ethernet and IP-based applications. Comprehensive OAM tools, robust synchronization transport using IEEE 1588v2 and IEC/IEEE 61850-9-3 power profiles, and integrated security mechanisms such as Layer 3 VPNs and IPsec establish a foundation that meets the demands of both legacy and next-generation utility operations. Utilities can further enhance their networks with segment routing, enabling deterministic path selection and improved resiliency for the modern grid.

Biography:
Dr. Mauricio Subieta is North American CTO for Nokia Energy’s Network Infrastructure Digital Industries division, where he leads the Industrial Cybersecurity Program and architects mission-critical networks, including Private LTE and 5G, for the energy sector. With more than 25 years of experience, he has held senior networking and security roles at Oklahoma Gas and Electric and designed wireless systems for major oil and gas operators such as Devon and Chesapeake Energy. His expertise spans next-generation networking (6G, SR TE), traffic optimization, protocol design, system development, and industrial control system cybersecurity.


