Thread Content
SIS stands for Safety Instrumented System. It takes emergency measures against potential hazards in plants or equipment, and responds promptly to situations that are worsening, bringing them into a predefined safe shutdown state thereby minimizing risks and losses and ensuring the safety of production equipment, the environment, and personnel. Currently, SIS is widely used in process industries such as the petrochemical sector, and it constitutes an important part of automatic control in industrial plants. Basic principles of SIS: SIS is defined as an instrumentation system that implements one or more safety instrumented functions. SIS includes measuring instruments, logic operators and final components, as well as associated software and components. Currently, systems such as the Instrument Protection System IPS, Safety Interlocking System SIS, Emergency Shutdown System ESD, Pressure Protection System HIPPS, and Fire and Gas Protection System F&GS all fall under the category of Safety Instrumented Systems. During the startup, shutdown, operation, and maintenance of production units, SIS provides safety protection for personnel health, plant equipment, and the environment. Whether it is the risk of failures in the production equipment itself, hazards caused by human factors, or those resulting from force majeure, the SIS should immediately respond appropriately by generating the necessary logical signals, thereby enabling safe interlocks or shutdown of the production equipment, preventing the occurrence of hazards and the spread of accidents, and minimizing potential damage. Safety instrumented systems should possess high reliability, availability, and maintainability. It can still provide safety protection even when the safety instrument system itself fails. Key features of SIS: 1. Certain safety integrity level. SIS takes into account the entire safety lifecycle of the system, proposes methods for assessing the safety integrity level (SIL), and standardizes the tools and measures used to achieve the required functional safety. The design and development process of SIS systems must comply with IEC61508, and they must pass functional safety assessments and certifications conducted by independent organizations (such as TüV in Germany) to obtain certification certificates before they can be used in industrial environments. 2. Higher availability and maintainability: The components of a SIS system should take into full account the safety instrument functions that can be achieved by each individual component, the logical redundancy structures used, and whether a single fault within the system could lead to its unintended shutdown. At the same time, it is also necessary to consider whether online maintenance of faulty components is possible when the system is operating with faults, without the need to shut down the entire system. 3. Fault-tolerant multi-redundancy systems: SIS systems typically employ a multi-redundancy architecture to enhance the system’s tolerance to hardware failures, ensuring that a single failure does not result in the loss of the system’s safety functions. Such as the triple modular redundancy (TMR) structure, which is common in SIS systems: it integrates three isolated, parallel control systems (each referred to as a sub-circuit) along with extensive diagnostic functions into one system, providing highly reliable and error-free control without any interruptions through a three-out-of-two voting mechanism. 4. Comprehensive fault self-diagnosis capability: The safety integrity requirements for SIS systems also include requirements to avoid failures and to control system faults; moreover, each component of the system must have defined fault diagnosis procedures and behaviors in the event of a failure. The overall system diagnostic coverage generally exceeds 90%. The hardware of the SIS system boasts high reliability and is capable of withstanding most environmental stresses, such as electromagnetic interference in the field, allowing it to be effectively used in various industrial environments. 5. Fast response speed: SIS systems have excellent real-time performance; the response time from an input change to an output change is generally between 50 and 100 ms, with some smaller SIS systems having an even shorter response time. 6. Sequence of Events Recording Function: To facilitate better accident analysis and post-event review, SIS systems typically come equipped with a Sequence of Events (SOE) function, which allows for the recording, in chronological order, of the times at which various specified input and output values as well as status variables change. The accuracy of this recording is usually on the millisecond level. 7. Functional safety design of the product: It ensures the safety of the entire circuit ranging from sensors to actuator elements, and includes functions for monitoring issues such as input/output (I/O) short circuits and open circuits. Differences between SIS and process control systems such as DCS: 1. DCS is used for continuous measurement in production processes, conventional control (continuous, sequential, batch, etc.), and operational control management, to ensure the stable operation of production facilities ; SIS is used to monitor the operating condition of production facilities, to promptly address any abnormal conditions, minimize potential hazards, and keep both personnel and the production facilities in a safe state. 2. DCS is a “dynamic” system that continuously monitors, processes, and controls process variables, thereby providing dynamic control over the production process to ensure product quality and output volume ; SIS is a “static” system; under normal operating conditions, it continuously monitors the operation of the production equipment. Its output remains unchanged, and it has no impact on the production process ; Under abnormal operating conditions, logical operations are carried out according to the pre-defined design to enable safe interlocks or shutdown of the production unit. 3. SIS has stricter requirements regarding safety, reliability, and availability than DCS; therefore, in theory, the hardware for SIS and DCS should be installed separately. Design principles of SIS: When designing the safety system for instruments, the following basic principles must be followed: Reliability principle: The reliability of a system refers to the probability of failures occurring within a certain time interval. The reliability of the entire system is the product of the reliabilities of its individual components; a decrease in the reliability of any one component will lead to a decrease in the overall reliability of the system. People usually pay great attention to the reliability of logical control systems, often neglecting the reliability of sensing elements and actuating elements, which results in low reliability of the entire safety instrumented system and fails to reduce the risks associated with the controlled equipment. Availability refers to the probability that a repairable product will be functioning properly at a given moment when used under specified conditions. Availability does not affect the security of the system, but low availability of the system may prevent the equipment or factory from carrying out normal production. As for the safety instrumented system’s understanding of the process, attention should also be paid to the system’s availability, so as to accurately detect process accidents, minimize abnormal shutdowns of the plant, and reduce economic losses resulting from startups and shutdowns. Fail-safe principle: The fail-safe principle states that when the SIS fails due to internal or external reasons, the protected object (device) should shut down safely in a predetermined sequence and automatically enter a safe state. This is specifically manifested as follows: (1) The on-site switch instruments use normally closed contacts; under normal operating conditions, the contacts remain closed, and when the safety limit is reached, the contacts open, thereby triggering an interlock action ; (2) The solenoid valve operates with normal excitation; it remains energized when the interlock is not activated, but loses power when the interlock is activated ; (3) The contacts sent to the electrical distribution room for starting/stopping the motors are isolated by intermediate relays, and their excitation circuits should be fail-safe ; (4) As a control device, \"fail-safe\" means that it should at least engage in interlocking action when it itself fails, rather than when the process or equipment exceeds its operating limits. To enable safe parking in the predetermined order (which is safe for the process and equipment), fault detection is carried out within the required process safety time through hardware and software redundancy and fault-tolerance techniques, allowing automatic execution of correction procedures to eliminate the faults. Principle of process adaptation: The configuration of the safety instrumented system must be based on the operating patterns of the process, in order to serve the process both during normal and abnormal operations. Under normal conditions, the safety instrument system should not interfere with the operation of the process; it comes into play when dangerous situations arise in the process to ensure the safety of the industrial installation. This is the principle of adaptation in the system design process. Independent setup: The principle of independent setup means that the entire SIS system should be independent of the process control system (such as DCS), in order to reduce the likelihood of both control functions and safety functions failing. This allows the system to carry out its safety functions related to automatic protection and interlocking independently, without relying on the process control system. A unit that requires to be installed independently should have sensing elements, actuating elements, logical operation elements, and communication devices. A complex SIS should be reasonably divided into multiple subsystems; each subsystem should be relatively independent, and backup manual functions should be provided for grouping. Principle of minimum intermediate steps: SIS should have as few intermediate steps as possible. The more instruments there are in a circuit, the lower its reliability; this is typical in applications involving intrinsically safe circuits. Redundancy principle: For measuring instruments, for SIL1 safety instrumented functions, a single measuring instrument may be used ; For SIL2-level safety instrumented functions, redundant measuring instruments are recommended ; For SIL3-level safety instrumented functions, redundant measuring instruments should be used ; When high security is required, an “or” logical structure should be used ; When high availability is required, a “AND” logical structure should be used ; When both security and availability need to be ensured, a \"two-out-of-three\" logic structure should be adopted. For the final element, for SIL1-level safety instrumented functions, a single control valve can be used ; For SIL2-level safety instrumented functions, redundant control valves are recommended ; For SIL3-level safety instrumented functions, redundant control valves should be used ; One control valve and one shut-off valve can be used, or two shut-off valves can be used. The redundant configuration of control valves does not mean that such redundancy corresponds to a specific safety integrity level. In situations where it is not possible to configure control valves in a redundant manner, a single control valve should be used, but the accompanying solenoid valves should be arranged redundantly. For solenoids in safety instrumented systems, insulated coils that can withstand high temperatures, those designed for continuous operation under electrical voltage, and explosion-proof types should be preferred. When the process is operating normally, the solenoid valve should be energized (powered) ; During abnormal operation of the process, the solenoid valve is de-energized (no power). For logical controllers, for SIL1-level safety instrumented functions, redundant logical controllers are recommended ; For SIL2-level safety instrumented functions, redundant logic controllers should be used ; For SIL3-level safety instrumented functions, redundant logic controllers must be used. The communication interface between the safety instrumented system and the basic process control system should be configured redundantly, and the redundant communication interfaces should have diagnostic functions.