Thread Content
Could someone who is an expert in instrumentation help explain the difference between SIS and ESD, and what is DCS?
SIS – Safety Instrumented System, a system designed for ensuring safety. The function of this system is to bring the industrial production process/units into a safe state, in accordance with the designed safety functions (SIF), when a dangerous situation is detected. This system has safety integrity levels (SIL 1-4). Typically, the safety integrity level of the safety instrumented system is determined after conducting HAZOP (Hazard and Operability Analysis) and LOPA (Layer of Protection Analysis) on the process system. The design, manufacturing, verification, and maintenance processes of safety instrumented systems shall be carried out in accordance with the IEC 61511 international standard. ESD - Emergency Shutdown System, an emergency shutdown mechanism. The function of this system is also to detect dangerous situations, typically by shutting off or opening the terminal control unit (usually a valve), so as to bring the process equipment and devices into a safe state. An ESD system designed in accordance with IEC 61511 and possessing a SIL safety integrity level can be used as a SIS. DCS – Distributed control system, also known as a distributed control and monitoring system. This system handles the general control and monitoring of factory production. It is also known as BPCS (Basic Process Control System), the basic process control system.
SIS, or Safety Instrumented System, is a system designed to implement safety functions; the instruments incorporated into such a system must meet the requirements regarding safety integrity levels, which means they need to have SIL certification; ESD, Emergency Shutdown System ; DCS, Distributed Control System, the basic control system used in daily operations
The SIS system includes the ESD system; it’s just that now they are simply referred to as the SIS system
Interlock, PCL, DCS & BPCS vs. Trip, ESD & SIS – Li Da, 2018-5-9. There are two terms in automatic control in English, “interlock” and “trip”, which have similar meanings but also differences. These two English terms borrowed from other languages are both often translated as “interlocking” in Chinese, which is a fatal mistake that leads to conceptual confusion and can cause problems. In English, the term “interlock” originally referred to a type of relatively simple preventive protection device used to ensure that when a certain switch or valve is in a particular state, other related switches or valves must be in a corresponding specified state as well, in order to maintain system safety. “The meaning of “interlock” has expanded to refer to devices or system configurations used to prevent potential system hazards that may arise from human operational actions or certain actions carried out by the system’s control mechanisms. In other words, a device or mechanism that ensures that when Party A takes action, Party B must be in a certain specified state. “An “interlock” is generally designed to be capable of being switched interactively and returning to its normal state. The simplest example of such an interlock is the highway barriers at railway grade crossings: when a train is approaching, the barriers drop, stopping traffic on the road; pedestrians and vehicles must come to a halt and wait until the train has passed safely. Once the train has gone by, the barriers rise again, returning to their normal position that allows pedestrians to cross the grade crossing safely, thereby ensuring traffic safety. Of course, priority levels can be established, with rail transport being given a priority level. This “interlock” is often translated as “interlocking,” which has become the standard term; personally, I think “linkage” would be a better translation, as it refers to a mechanism of linkage with defined priorities that is also reversible in order to ensure safety. Calling it a “lock” is also possible, but it’s not a fixed lock that cannot be opened or closed frequently. In the industrial field, the English word “trip” originally meant “to start moving” or “to trigger.” In the field of automatic control, it refers to a type of automatic control device or mechanism that, when control parameters such as displacement, temperature, pressure, or flow rate reach certain pre-set limit values (thresholds), automatically initiates a predefined sequence of actions, such as turning on or off certain switches or valves, thereby enabling the system to enter a pre-set stable state. That is, when Party A’s actions or condition reach a predetermined threshold, Party B must take appropriate action promptly to eliminate the danger and bring Party A to a stable and controllable state; the simplest example of this is a safety valve. “\"Trip\" is different; to ensure completeness, \"trip\" is generally designed such that once a certain parameter reaches a preset threshold, the device or system will \"trigger\" or \"activate\", coming to a predetermined stable state. Moreover, manual inspection is required to confirm that everything is safe before it can be manually restored or reset, so as to allow it to proceed or return to its original state ; Generally, it is not designed or configured to automatically return to its original state once triggered, in order to eliminate safety hazards. A typical example is the safety valve: once the pressure in the system reaches its limit, the safety valve activates, allowing the pressure to be released and bringing the system back to a safe state. However, the system or device cannot nor should it recover automatically; it remains in this safe state until manual inspection is carried out to identify the cause, take corrective action, and retest and calibrate the safety valve. Additionally, the settings of the system or device must be reset from some stable or initial state. In my opinion, this “trip” should be translated as “takeoff” or “trigger”. “There are many other settings or devices related to \"trips\", such as centrifugal clutches used in high-speed rotating machinery to prevent overspeed, alloy fusible plugs for overload protection in hydraulic couplings, and burst discs for protecting low-pressure containers. The fundamental difference between the two lies in their design philosophy: “interlock” is designed for normal or interactive conditions, whereas “trip” is designed for occasional extreme events.
Today, these two concepts continue to evolve, particularly in the field of industrial automation. First, the control system and the safety system began to separate and operate independently. Initially, “interlock” was incorporated into PLCs or DCSs, and later it came under the control of BPCS, which is dedicated to process control ; The concept of “trip” was initially covered by the relatively independent ESD (Emergency Shutdown Device), and later by the newer, fully independent SIS (Safety Instrumented System) designed specifically for safety purposes; both systems represent extensions of the very idea behind “trip”. To use an analogy, in a football match, there are referees and line judges. When the ball is inside the boundary lines (on the playing field), it is the referee who decides whether the actions of the players from both teams are lawful or not, thereby ensuring that the game continues ; However, once the ball touches the sideline, it has reached the end of the game; it is no longer up to the referee to make a decision. Instead, the line judge raises a flag and blows a whistle to pause the game, after which play resumes according to the rules. Here, the role of DCS is similar to that of a referee on a football field; it may include many \"interlock\" functions and settings, which are akin to the rules used on the field to ensure the smooth progress of the game, thereby maintaining the proper operation of various systems within the device ; The role of ESD or SIS is similar to that of the referee on a football field – remaining vigilant at all times with safety as the top priority. Once the predetermined parameters are reached, hitting the set threshold, it will act immediately, causing the device to stop and enter a stable safe state. Then, manual inspection must be carried out first to rule out faults; only after ensuring safety can operation be resumed or started from the initial state.
Interlock, PCL, DCS & BPCS vs. Trip, ESD & SIS – Li Da, 2018-5-9. There are two terms in automatic control in English, “interlock” and “trip”, which have similar meanings yet also differ from each other. These two English terms borrowed from other languages are both often translated as “interlocking” in Chinese, which is a fatal mistake that leads to conceptual confusion and can cause problems. In English, the term “interlock” originally referred to a type of relatively simple preventive protection device used to ensure that when a certain switch or valve is in a particular state, other related switches or valves must be in a corresponding specified state as well, in order to maintain system safety. “The meaning of “interlock” has expanded to refer to devices or system configurations used to prevent potential system hazards that may arise from human operational actions or certain actions carried out by the system’s control mechanisms. In other words, a device or mechanism that ensures that when Party A takes action, Party B must be in a certain specified state. “An “interlock” is generally designed to be capable of being switched interactively and returning to its normal state. The simplest example of such an interlock is the highway barriers at railway grade crossings: when a train is approaching, the barriers drop, stopping traffic on the road; pedestrians and vehicles must come to a halt and wait until the train has passed safely. Once the train has gone by, the barriers rise again, returning to their normal position that allows pedestrians to cross the grade crossing safely, thereby ensuring traffic safety. Of course, priority levels can be established, with rail transport being given a priority level. This “interlock” is often translated as “interlocking,” which has become the standard term; personally, I think “linkage” would be a better translation, as it refers to a mechanism of linkage with defined priorities that is also reversible in order to ensure safety. Calling it a “lock” is also possible, but it’s not a fixed lock that cannot be opened or closed frequently. In the industrial field, the English word “trip” originally meant “to start moving” or “to trigger.” In the field of automatic control, it refers to a type of automatic control device or mechanism that, when control parameters such as displacement, temperature, pressure, or flow rate reach certain pre-set limit values (thresholds), automatically initiates a predefined sequence of actions, such as turning on or off certain switches or valves, thereby enabling the system to enter a pre-set stable state. That is, when Party A’s actions or condition reach a predetermined threshold, Party B must take appropriate action promptly to eliminate the danger and bring Party A to a stable and controllable state; the simplest example of this is a safety valve. “\"Trip\" is different; to ensure completeness, \"trip\" is generally designed such that once a certain parameter reaches a preset threshold, the device or system will \"trigger\" or \"activate\", coming to a predetermined stable state. Moreover, manual inspection is required to confirm that everything is safe before it can be manually restored or reset, so as to allow it to proceed or return to its original state ; Generally, it is not designed or configured to automatically return to its original state once triggered, in order to eliminate safety hazards. A typical example is the safety valve: once the pressure in the system reaches its limit, the safety valve activates, allowing the pressure to be released and bringing the system back to a safe state. However, the system or device cannot nor should it recover automatically; it remains in this safe state until manual inspection is carried out to identify the cause, take corrective action, and retest and calibrate the safety valve. Additionally, the settings of the system or device must be reset from some stable or initial state. In my opinion, this “trip” should be translated as “takeoff” or “trigger”. “There are many other settings or devices related to \"trips\", such as centrifugal clutches used in high-speed rotating machinery to prevent overspeed, alloy fusible plugs for overload protection in hydraulic couplings, and burst discs for protecting low-pressure containers. The fundamental difference between the two lies in their design philosophy: “interlock” is designed for normal or interactive conditions, whereas “trip” is designed for occasional extreme events.
Today, these two concepts continue to evolve, particularly in the field of industrial automation. First, the control system and the safety system began to separate and operate independently. Initially, “interlock” was incorporated into PLCs or DCSs, and later it came under the control of BPCS, which is dedicated to process control ; The concept of “trip” was initially covered by the relatively independent ESD (Emergency Shutdown Device), and later by the newer, fully independent SIS (Safety Instrumented System) designed specifically for safety purposes; both systems represent extensions of the very idea behind “trip”. To use an analogy, in a football match, there are referees and line judges. When the ball is inside the boundary lines (on the playing field), it is the referee who decides whether the actions of the players from both teams are lawful or not, thereby ensuring that the game continues ; However, once the ball touches the sideline, it has reached the end of the game; it is no longer up to the referee to make a decision. Instead, the line judge raises a flag and blows a whistle to pause the game, after which play resumes according to the rules. Here, the role of DCS is similar to that of a referee on a football field; it may include many \"interlock\" functions and settings, which are akin to the rules used on the field to ensure the smooth progress of the game, thereby maintaining the proper operation of various systems within the device ; The role of ESD or SIS is similar to that of the referee on a football field – remaining vigilant at all times with safety as the top priority. Once the predetermined parameters are reached, hitting the set threshold, it will act immediately, causing the device to stop and enter a stable safe state. Then, manual inspection must be carried out first to rule out faults; only after ensuring safety can operation be resumed or started from the initial state.
ESD is that thing you tap with your hand, SIS refers to automatic interlocks, and DCS is used for daily operations; I think that’s it