HCBBS Forum (English)
Submit Chemical Projects / Find Solutions
Amplify Your Requirements on a Broader Chemical Platform *Engineering · Technology · Equipment · Solutions*
Submit Request

Questions regarding fail-safety

2022-08-09View Original

Thread Content

For an interlock, it is divided into an input section and an output section. For example, if the level of A is very high, the interlock opens valve B. From a fail-safe perspective, the output section involves the opening of the valve by the interlock; in the design process, it is sufficient to ensure that the relay loses power. But what about the input section? Since the level of A is an analog value, there are no actual contacts (unlike level switches). So how can fail-safety be understood in this case? Does it refer to a power loss in the circuits within the sis hardware itself? (Because the liquid level needs to be monitored via the AI module – does that mean there’s a power loss in the circuits inside the AI module?) )
Reply #22022-08-09
My understanding is that fail-safe refers to the actuator itself – that is, when there is a power or air supply failure, this actuator will operate in FC, FO, or FL modes – and it does not refer to circuit fail-safe
Reply #32022-08-09
Let’s discuss this; it’s not just me who isn’t clear about this issue
Reply #42022-08-09
I. The card module can also be set to a faulty state. II. For analog measurement points that have such a requirement, digital interlock points can also be added.
Reply #52022-08-09
Fault safety refers to ensuring the safety of process production in the event of failures (power loss, air loss). He is referring to the valves, not your analog values. Power loss refers to a situation where the valve loses power, or the control system loses power. The valve’s state must ensure process safety; for example, boiler fuel shut-off valves should be of the air-actuated type, with the control point set to the normally open position. In the event that the relay loses power, or the valve’s power supply circuit is interrupted, or the on-site air supply is lost, the valve will close. For the AI-induced point failures you mentioned, it is unable to detect them; you can use the channel failure detection function built into the DCS to carry out such detections, but the likelihood of false alarms increases in this case. In short, there is a conflict between production and safety; ensuring production and ensuring safety are always in opposition to each other.
Reply #62022-08-10
Only for valves? That’s not right, is it? Then why is the emergency stop button connected to a normally closed contact? It’s not a valve; it’s part of the interlock input, not the output
Reply #72022-08-10
This post was last edited by hxch150804 on 2022-8-10 at 11:23. I don’t understand what you mean; you say that the emergency stop button counts as an input – how does it achieve fault safety? Does it stay open when there is a fault at the normally closed point? I’ve only seen cases where the contacts couldn’t be separated. If it’s as you say, then there is no such thing as absolute safety. Those of us who work in logic just strive to achieve perfection, but it’s impossible to eliminate all vulnerabilities. Even Microsoft, despite being so powerful, still has to constantly release patches and look for vulnerabilities. So how can we ensure fault tolerance when it comes to input? If you need an emergency stop that remains in the on position, that’s also possible; normally keep it in that position, and when an emergency stop is required, turn it off. It depends on whether your system requires a constant on or constant off state – it’s like trying to explain something to an idiot.
Reply #82022-08-10
I mean, for emergency stops, I connect to normally closed contacts. Isn’t this done with fail-safe considerations in mind? The same is true for level switches – the high-level switch: I connect it to the normally closed terminal. Isn’t this also based on fault safety considerations? Is my understanding correct?
Reply #92022-08-10
The level switch is connected in a normally closed configuration; when power is lost, this level switch stops working properly – it malfunctions and can no longer cut off the flow How to ensure interlock operation? Do you guarantee production, or do you guarantee safety?
Reply #102022-09-04
The statement is incorrect; interlocking is divided into: the input section, the logic section, and the output section. Logic is the core component; once you understand logic, you’ll get it
Reply #112022-09-05
The fail-safe principle is a design principle that requires signal devices or systems to automatically revert to a safe state in the event of a malfunction. Regarding the input circuit mentioned by the original poster, the usual approach is as follows: 1. For analog signals, if the analog value cannot be read, the system automatically enters a safe state ; If the level gauge has a self-diagnosis function, it will output a maximum signal or completely cut off the signal ; If the instrument itself lacks reliability, a signal three-to-two or two-to-two approach is used ; 2. For contact signals, it is generally required that the contacts be normally closed or normally energized ; If higher requirements are needed, a series contact signal method is employed (choose one: electrical contact or arithmetic arrangement) to address it.

Submit a Project

**Looking for Chemical Technology, Equipment & Solutions?** No Registration Required Broader Platform Exposure | Global Chemical Service Provider Connections

Submit Request — Free Consultation

Disclaimer

This is an automated machine translation of the original thread. Some technical terms may have inaccuracies; the original text shall prevail. Click "View Original" at the top right to access the source page, which supports IP-based automatic real-time language translation. Please watch out for contact details and sales inducements to prevent fraud. All content and translations are for reference only, representing solely the poster's personal views. For enquiries, email service@hcbbs.com.