Basic concepts and configuration principles of safety instruments
Thread Content
1. A Safety Instrumented System (SIS) is a system that implements one or more safety instrumented functions; it consists of measuring instruments, logic controllers, final elements, and related software. As part of the system, there are also communication interfaces and human-machine interfaces. The system is fault-safe in design. 2. Safety Instrumented Function (SIF) refers to the safety protection functions or safety control functions implemented using measuring instruments, logic controllers, final elements, and related software, in order to prevent or reduce the occurrence of hazardous events or to maintain a safe state of the process. 3. Risks, safety risks: Specific hazardous events and their potential consequences that are expected to occur. Safety: Simply put, a risk that is acceptable is considered safe. 4. Safety integrity, Safety Integrity Level (SIL): Safety integrity refers to the average probability that the SIS will fulfill the SIF under specified conditions and within a specified time. Safety Integrity Level (SIL): The level of a safety function, ranging from SIL1 to SIL4 from low to high. This specification requires that the highest safety integrity level for the allocation of safety functions be SIL3. Low-demand operation mode: SIL1 corresponds to an average annual failure probability of 10-1 to 10-2; SIL2 corresponds to an average annual failure probability of 10-2 to 10-3; SIL3 corresponds to an average annual failure probability of 10-3 to 10-4. Elements of SIL assessment: 1) Determining the SIL for each SIF; 2) Establishing requirements for diagnosis, maintenance, and testing, including the testing interval. 5. A Basic Process Control System (BPCS) is a system that responds to process measurements as well as input signals from other devices, instruments, control systems, or operators; it generates output signals in accordance with process control rules, algorithms, and methods in order to achieve process control and the operation of related equipment. (Understanding it as control systems other than SIS, systems that do not execute SIFs.) 6. Protective layers are measures to reduce risks through prevention, control, mitigation, etc. Safety life cycle: the entire process from the design of the engineering solution until all safety instrument functions cease to be in use. It is divided into three phases: 1) the engineering design phase, from conceptual design to the completion of detailed engineering design. In the field of process control, professionals shift from being participants in the process prior to receiving the SIL assessment and review to becoming the drivers. 2) During the integration, commissioning, and acceptance testing phase, the integrator plays the leading role. 3) During the operation and maintenance phase, the owner’s own control team plays a primary role. III. Measurement InstrumentsMeasurement instruments include two types: analog and digital instruments.
1. General provisions
● Intelligent transmitters with a 4–20mA + HART signal format are preferred for measurement instruments.
● In areas prone to explosions, intrinsically safe instruments should be used.
● The protection rating of measurement instruments installed on-site should be at least IP65.
● Measurement instruments and their sensing points should be installed separately.
● Fieldbuses or other communication methods should not be used as input signals for the SIS.
2. Principles for separate installation and redundancy of measurement instruments
● For SIFs requiring SIL1 level of safety: Measurement instruments can share resources with the BPCS, and a single instrument may be sufficient.
● For SIFs requiring SIL2 level of safety: Measurement instruments should be separated from the BPCS, and redundant instruments are recommended.
● For SIFs requiring SIL3 level of safety: Measurement instruments must be separated from the BPCS, and redundant instruments are necessary.
3. Redundancy methods
● When high safety is required by the system, an “OR” logic structure should be used.
● When high availability is required, an “AND” logic structure should be employed.
● When both high safety and high availability are required, a two-out-of-three logic structure should be used.
IV. Final Elements
Final elements include control valves (regulating valves, isolation valves), solenoid valves, motors, and other actuating devices.
1. General provisions
● Pneumatic control valves are preferred over electric control valves for final elements.
● When pneumatic control valves are used to implement safety instrument functions, the SIS should take priority in operation; that is, the solenoid valve associated with a regulating valve should be installed between the positioner and the actuator, while the solenoid valve associated with an isolation valve should be installed on the actuator itself. The power supply for solenoid valves should be provided by the SIS. ● Pneumatic control valves should preferably use single-cylinder actuators with spring return; when double-cylinder actuators are used, an air storage tank or a dedicated instrument air supply line is recommended. ● In areas prone to explosions, explosion-proof solenoid valves and valve position switches should be used. ● The protection rating of solenoid valves and valve position switches installed on-site should not be lower than IP65. 2. Principles for independent and redundant installation of control valves ● For SIFs requiring SIL1: Control valves can share resources with the BPCS, but the SIS should take precedence, and a single control valve can be used. ● For SIFs requiring SIL2: Control valves should be separate from the BPCS, and redundant control valves are recommended. ● For SIFs requiring SIL3: Control valves must be separate from the BPCS, and redundant control valves are required. 3. Redundancy methods ● Control valve redundancy can be achieved using one control valve and one shut-off valve, or two shut-off valves. ● When high safety levels are required in the system, redundant solenoid valves should operate based on an “or” logic structure. ● When high availability is required in the system, redundant solenoid valves should operate based on an “and” logic structure. 5. Logic controllers Logic controllers should preferably be programmable electronic systems; in simpler applications, relay systems can be used, or a combination of programmable electronic systems and relay systems can be employed. 1. General provisions: When the logic controller is a programmable electronic system, ● The total response time of the logic controller should be between 100 ms and 300 ms; the total response time refers to the entire time required for a signal to travel from its point of entry to its point of exit within the logic controller. ● The load on the central processing unit of the logic controller should not exceed 50%. ● The internal communication load of the logic controller should not exceed 50%; in the case of Ethernet-based communication, this load should not exceed 20%.
2. Principles for standalone and redundant configuration of logic controllers ● For SIL1 requirements: The logic controller should be separated from the BPCS, and redundant logic controllers can be used. ● For SIL2 requirements: The logic controller must be separated from the BPCS, and redundant logic controllers are recommended. ● For SIL3 requirements: The logic controller must be separated from the BPCS, and redundant logic controllers are necessary.
3. Configuration principles for logic controllers ● Logic controllers that meet SIL requirements should be able to fulfill the SIF requirements independently. ● The software and hardware versions of the logic controller must be officially released. ● The central processing unit, I/O units, power supply units, communication units, etc., of the logic controller should be separate components, allowing for online replacement of these components without affecting the normal operation of the logic controller. ● The logic controller should have software and hardware diagnostic and testing functions, with diagnostic and testing information displayed and recorded on the engineer station and/or operator station. ● System failures of the logic controller should be indicated on the operator station of the SIS, but they can also be indicated on the operator station of the BPCS.
4. Interface configuration principles for logic controllers ● The signal channels of I/O cards should have optical or electromagnetic isolation; I/O cards should not use digital signals over fieldbuses. ● Signals from multiple measuring instruments that monitor the same process variable should be connected to different input cards. ● Redundant output components should be connected to different output cards, with each output channel connecting to only one output component