Automation Glossary • HSR vs PRP

What Is the Difference Between HSR and PRP Redundancy?

Merobix Engineering • • 7 min read

Ring-healing schemes like MRP and DLR are fast, but they all share one property: there is a brief moment after a failure when traffic is interrupted while the network reconfigures. For a handful of critical applications, most famously electrical substations, even a few milliseconds of loss is unacceptable. HSR and PRP are the two standards designed to eliminate that moment entirely, achieving zero recovery time by sending every frame twice over separate paths so that a failure of one path is simply not noticed. This guide explains how PRP and HSR differ, how their duplicate frames and discard logic work, what a RedBox does, and why high-availability SCADA networks choose seamless redundancy over any bumped ring.

Back to Blog

HSR vs PRP in one line: HSR and PRP are the two seamless redundancy schemes defined in IEC 62439-3, both giving zero recovery time by sending duplicate copies of every frame over separate paths and discarding the duplicate at the receiver. PRP, the Parallel Redundancy Protocol, sends the two copies over two completely independent parallel LANs. HSR, High-availability Seamless Redundancy, sends the two copies in opposite directions around a single ring. Both let a network survive a link failure with no interruption, at the cost of duplicated traffic and specialised nodes or RedBoxes.

Two Ways to Achieve Zero Recovery Time

PRP and HSR start from the same insight: the only way to have truly zero recovery time is never to depend on a single path in the first place. Instead of sending a frame once and having a backup route ready to activate, both protocols send two identical copies of every frame at the same moment over two different paths. If both copies arrive, the receiver uses the first and throws away the second. If one path has failed, one copy still arrives, and the receiver simply never notices that anything went wrong. There is no detection, no reconfiguration and no gap, because the redundancy is in the traffic itself rather than in a recovery mechanism.

PRP achieves this with two separate, parallel networks. A device that participates directly in PRP has two Ethernet ports, one attached to LAN A and one to LAN B, and these two LANs are entirely independent of each other, with their own switches and cabling and no connection between them. Every frame the device sends goes out both ports into both LANs, and the two networks carry the copies independently. Because the LANs share nothing, a fault in one, whether a cut cable, a failed switch or a configuration error, cannot affect the other, and the surviving LAN continues to deliver frames without interruption.

HSR achieves the same zero-loss result but over a single ring rather than two separate LANs. A device that participates in HSR has two ring ports, and it sends a copy of each frame out of both ports so the two copies travel around the ring in opposite directions. A receiver on the ring gets the frame from whichever direction reaches it first and discards the later duplicate. Because a single break in the ring still leaves a path from sender to receiver in at least one direction, the traffic survives. HSR trades PRP's fully separate infrastructure for a more economical single ring, while keeping the seamless behaviour.

Duplicate Nodes, RedBoxes and Discard Logic

The nodes that speak these protocols natively have their own names. A device with two ports attached to both PRP LANs is a Doubly Attached Node for PRP, a DANP, and the equivalent for HSR is a Doubly Attached Node for HSR, a DANH. These nodes handle the duplication on send and the discarding on receive, and to do so they add a small piece of information to each frame that identifies the pair of copies, so the receiver can recognise the second copy of a frame it has already accepted and drop it. This duplicate-discard logic is what makes the redundancy invisible to the application above it.

Not every device can be a DANP or DANH, because ordinary equipment has only one Ethernet port and no knowledge of the redundancy protocol. To include such devices, both schemes use a redundancy box, universally called a RedBox. A RedBox connects a single-port ordinary device to the redundant network on its behalf, duplicating the device's frames onto both paths on send and discarding duplicates on receive, so that the plain device appears to the network as if it were a doubly attached node. This lets a network mix native redundant devices with ordinary ones without giving up the seamless behaviour.

The discard mechanism has to be robust because it is doing subtle work: correctly identifying which incoming frames are duplicates of ones already delivered, without ever accidentally dropping a genuine new frame that happens to look similar. The protocols manage this with sequence information carried in the redundancy tag and with rules about how long to remember recently seen frames. When it works, the application sees a single, clean stream of frames with no duplicates and no gaps, entirely unaware that behind the scenes every frame was sent twice and one copy of each was quietly thrown away.

Why High-Availability SCADA Chooses Seamless

The reason to pay for the duplicated traffic and specialised hardware of HSR or PRP is that some applications genuinely cannot tolerate any interruption. The archetypal example is the electrical substation, where protection and control messages must be delivered without a gap because a lost cycle at the wrong instant can matter for equipment and safety. In these environments the standards that govern substation automation call for seamless redundancy, and PRP and HSR are the mechanisms that provide it. A bumped ring that heals in even a few milliseconds is not acceptable when the requirement is truly zero loss.

The trade-off is deliberate and clear-eyed. Seamless redundancy costs more: PRP requires two complete parallel networks, HSR requires ring-capable devices or RedBoxes, and both consume extra bandwidth because every frame is duplicated. In return the network survives a link or device failure with no interruption whatsoever and, just as importantly, without any recovery event to configure watchdogs around. Where MRP and DLR ask the application to ride through a brief bump, PRP and HSR remove the bump, so there is nothing to ride through and nothing to tune.

For a high-availability SCADA network the choice comes down to how much a moment of lost communication costs. Most industrial monitoring is well served by bumped ring schemes, because a sub-second interruption during a rare fault is harmless to supervisory data. But where the process cannot lose a single message, in critical power infrastructure and comparable settings, the seamless zero-recovery behaviour of PRP and HSR justifies the added infrastructure. Choosing between them then becomes an architectural question: PRP's fully independent parallel LANs offer the strongest isolation, while HSR's single ring is more economical to wire, and the right answer depends on the site's tolerance for cost against its appetite for independence.

Frequently Asked Questions

What is the main difference between HSR and PRP?

Both are seamless, zero-recovery-time schemes under IEC 62439-3 that send every frame twice and discard the duplicate at the receiver. The difference is the topology. PRP sends the two copies over two completely independent parallel LANs with separate switches and cabling. HSR sends the two copies in opposite directions around a single ring. PRP offers stronger isolation between the paths, while HSR is more economical because it needs only one ring.

What is a RedBox in HSR and PRP?

A RedBox, or redundancy box, connects an ordinary single-port device to a PRP or HSR network on its behalf. It duplicates the device's frames onto both redundant paths when sending and discards duplicates when receiving, so the plain device appears to the network as a doubly attached node. RedBoxes let a seamless network include standard equipment that does not speak the redundancy protocol itself.

Why not just use MRP or DLR instead of HSR or PRP?

MRP and DLR are bumped schemes: after a failure there is a brief interruption while the network reconfigures, typically around 200 milliseconds for MRP or under 3 milliseconds for DLR. HSR and PRP have zero recovery time because they never rely on a single path. For most monitoring a brief bump is harmless, but critical applications like substation protection cannot tolerate any loss, so they use seamless redundancy despite its higher cost.

From Definitions to a Live Dashboard

Merobix reads your field devices into a cloud SCADA - the real thing behind these terms, live in days from any browser.

Request a Free Demo +1 (903) 307-7300
More in Automation Glossary
Rapid Spanning Tree (RSTP)  •  802.1AS gPTP  •  Target Flow Meter  •  Elbow Flow Meter  •  Dall Tube  •  Pitot-Static Tube  •  All Automation Glossary →
Free SCADA operator training
Merobix University - 70 video lessons & 261 quiz questions, from first login to compliance reporting. No demo call required.
Start free →