Thread Content
ESD (Emergency Shutdown Device): An emergency shutdown system, commonly used in petroleum and chemical industries. It is a control unit that operates independently of the DCS system, and it enables immediate shutdown or activation of equipment and other systems when dangerous conditions arise in the process. Most devices are equipped with high-end PLCs, which handle DI/DO points; currently, they mostly communicate with DCS systems. SIS (Safety Instrumented System): A safety instrumented system primarily used in high-speed operating equipment such as turbines and compressors. It monitors parameters such as the speed, vibration, displacement, and temperature of bearings in order to protect the equipment. Originally, it was designed as a combination of modules, functioning essentially as a combination with intelligent instruments. SIS is a safety instrumented system, and ESD is an emergency shutdown system; ESD is part of SIS. SIS consists of field instruments, logic processors, and actuators, all of which must be designed with safety in mind. A conventional ESD system is merely the logic processor part of SIS, which, of course, also needs to be designed safely. To give a random example, it may not be appropriate, but it can help clarify these concepts. Siemens’ PCS7 system. It includes S7-400H hardware, WinCC monitoring software, and Simaticnet communication software. Step7 programming software. Smart metering tools such as PDM. PCS7 is a combination of software and hardware; it represents a conceptual system. SIS works on basically the same principle. Essentially, the hardware system of SIS includes not only the SIS controller and IOs (such as Triconex, HIMA, Siemens 400FH). It should also include all other input components that interface with the controller, such as sensors, transmitters, and detection devices that have obtained TUV SIL certification ; It should also include all output components, such as actuators that have obtained TUV SIL certification (hydraulic safety actuators, pneumatic safety actuators, electric safety actuators), as well as certified field devices. In strict application sites, the valve body itself must also have a TUV certificate. For example, the safety valves in nuclear power plants must not only meet the quality standards for boilers and pressure vessels, but also come with nuclear inspection certificates as well as TUV safety certification, clearly indicating the SIL level. So, let’s understand these concepts again: a safety controller (this is the most scientific term used currently) is merely one component of the hardware in an SIS system. Manufacturers of safety controllers include Triconex, HIMA, Siemens, Moore, ICS, ABB, Emerson, and others. When these safety controllers are used for emergency shutdown applications, they are called ESD. Fire detection and gas alarm systems used in oil and gas fields are referred to as F&GS. Burn control systems used in hazardous environments are called BMS. ESD, F&GS, and BMS do not refer to Triconex, nor to HIMA, nor to the controllers produced by these manufacturers. Rather, the safety controllers made by these manufacturers are used in various different scenarios and serve different purposes, which is why they have different names. Next time someone asks you why Triconex is called ESD at one time, PSD at another, F&GS at yet another time, and BMS again. It is also called SIS. You should understand its meaning. These are all safety controllers, or safety control systems; the IEC standards once referred to them as safety systems (PES), namely safety-related electronic devices. In contexts referred to as ESD, it is ESD; in contexts referred to as F&GS, it is F&GS, whereas SIS represents a complete, systematic concept. As can be seen from its name, it is a complete concept, one that places more emphasis on integrity, a system. Overall safety is built upon various security mechanisms, including safety controllers (such as ESD, F&GS, BMS, etc.), safety-rated instruments, safety-rated actuators, safety-rated software (function block libraries, interlock specifications), and even \"safe communication functions\" (a term that is rarely used these days). The holistic concept of SIS should also include standards that apply throughout the entire lifecycle of the safety control system, such as the initial design, the construction phase, and commissioning ; Final trial operation, evaluation, and verification. Subsequent maintenance. Dismantling before the end of the safety lifecycle. In short, the concept of SIS is very comprehensive and extensive. The first to get confused is always the design institute, and then the design institute misleads the client into confusion. Then many people who work on SIS and adjust ESD, having done it for several years, are also a bit confused about the concepts. Why is the concept of SIS being mentioned more often in tenders these past few years? Theoretically, only ESD “need not” constitute a complete SIS control system. ESD is just one component of SIS, and it is located in the physical hardware; it is the most important component among them. Therefore, many people believe that SIS is the same as ESD. ESD is SIS. With ESD, there are also many surrounding supporting devices. A SIS control system can then be formed. What users want is a complete security control system; that’s why the bidding specifications have been referred to as SIS in recent years. To be honest, it’s still the same old approach, but at least it shows that our users have made progress in terms of their overall understanding of security – whether through being misled or through their own efforts, progress has been made regardless. Similarly, (I personally heard a deputy sales manager at a well-known DCS company say that Siemens’ PCS7 DCS is essentially the same as the S7-400 PLC, and the S7-400 PLC is in turn the same as PCS7 DCS) – many things are not simply equivalent to one another! ITCC. Control of high-speed rotating equipment, such as steam turbine unit control, air compressor control, and blast furnace blower control. Even turbine engine control is a separate concept from gas turbine control. For example, Triconex controllers can perform ITCC in addition to ESD and F&GS functions. Systems such as ESD, F&GS, and those under the SIS concept require certification, and a SIL rating certificate from TUV is essential. For ITCC, a TUV certification is not mandatory. The same item from the same manufacturer can have different uses in various situations, which is why it has different names. By the same logic, if you have a great deal of money, you can use a Triconex system for PLCs, or a small DCS. At this point, you can still refer to Triconex as a PLC or a DCS – either term is acceptable. CCC focuses on ITCC, not ESD ; Yokogawa and Emerson’s safety systems are basically designed for ESD and F&GS only, without ITCC functionality. Triconex handles both ESD and ITCC. SIS: Safety Instrumented System; ESD: Emergency shutdown, which is commonly referred to as ESD in the petrochemical industry. On high-pressure pipelines it is called HIPPS, on boilers it is called FSSS, and on turbines it is called ETS. ESD is part of SIS and constitutes a relatively important component; SIS = ESD + interconnections + field instruments or actuators. Calling ESD as SIS is not a very reasonable designation; many projects now require that SIS systems meet the SIL3 standard. It is not sufficient for just the ESD component to reach SIL3 level – the instruments on site also need to meet this standard, and the entire control circuit as a whole must achieve SIL3. When ESD first entered the Chinese market, ICS was the leading company in this field, followed by HONEYWELL, and then Triconex distributed by Conixen. It was not until after 2000 that HIMA entered the market. It seems that Triconex and HIMA have a larger market share these days. Additionally, ITCC is a term coined by Conixion; due to some conflicts with the contents of IEC61508 and IEC61511, it is said that design institutes are now changing it back to CCS. Referring to the ETS+DEH configuration in power systems, I personally believe it is better to separate control functions from protection functions for compressors. In terms of the PCS (Process Control System) used in oil refineries, the overall integrated control system of such refineries consists of DCS, ESD, CCS, MMS, and CGTCS, with the DCS playing a key role in control functions. Esd (Emergency Shutdown Device) – an emergency shutdown system (including SOE) that is independent of the DCS system; it is part of the SIS (Safety Instrumented System). The main function of this safety instrumented system is to enable the immediate activation or deactivation of pipelines and equipment in case of dangerous situations, thereby providing protection. In terms of design, it differs from DCS in terms of system architecture and communication methods; it uses a 2-out-of-3 voting Triconex system and HART communication, while communicating with DCS via Ethernet. To ensure the coordinated and safe operation of the entire plant, the ESD system also needs to communicate with the CCS (Compressor Control System), MMS (Machine Monitoring System), CSTCS (Gas Turbine Control System), and MCC (Motor Control Center) in order to meet the safety protection requirements. SIS is a safety instrumented system, and ESD is part of SIS. The SIS consists of field instruments, ESD systems, and emergency on/off valves, and uses HART+4---20mA communication lines; each ESD circuit must undergo a SIL assessment. To achieve SIL2 or SIL3 safety levels, methods such as using two solenoid valves to control the emergency shut-off valve, three differential pressure transmitters to measure the same liquid level, and one radar instrument along with one ultrasonic instrument to measure the same liquid level are employed. Of course, SIL calculations must be performed for verification to ensure that the system meets the requirements. Definition and differences of instrument safety levels: What are the differences between SIL1, SIL2, and SIL3? Given that SIS is related to the safety of personnel, equipment, and the environment, various countries have established relevant standards and regulations to ensure that the design, manufacturing, and use of SIS are carried out in an orderly manner. And authoritative certification bodies verify the safety level that the product can achieve. The main standards, specifications, and certification bodies include: the industry standard SHB-Z06-1999 \"Guidelines for the Design of Emergency Shutdown and Safety Interlock Systems in the Petrochemical Industry\", established by China’s Petrochemical Group. In 2006 and 2007, Chinese standards GB/T20438 and GB/T21109, which also adopt IEC61508 and IEC61511, were successively issued; thus China’s functional safety standards began to regulate functional safety activities in the country. The IEC 61508/61511 standards, established by the International Electrotechnical Commission in 1997, specify the hardware, software, and applications for safety interlock systems composed of electromechanical devices (relays), solid-state electronic devices, and programmable electronic devices (PLCs). ISA-S84.01-1996 \"Application of Safety Instrumented Systems in the Process Industry\", established by the American Instrumentation Society. AICHE (CCPS)-1993, Guidelines for the Safe Automation of Chemical Processes, established by the American Institute of Chemical Engineers. HSE PES-1987, issued by the Health and Safety Executive in the UK, \"Applications of Programmable Electronic Systems in Safety.\" German **standards include standards for safety system manufacturers – DIN V VDE 0801, standards for process operators – DIN V 19250 and DIN V 19251, and standards for combustion management systems – DIN VDE 0116, among others. The German Technical Inspection Association (TÜV) is an independent and authoritative certification body that, in accordance with German standards (DIN), classifies the safety levels achieved by ESD as AK1 to AK8, with AK8 representing the highest safety level. Among them, AK4, AK5, and AK6 are SIS products certified by TUV for use in the petroleum and chemical industries. Different industrial processes (such as production scale, types of raw materials and products, and the complexity of processes and equipment) have varying safety requirements. The aforementioned international standards classify it into several Safety Integrity Levels (SIL: Safety Integrity Level). The Safety Integrity Level (SIL) is a discrete level used to specify the safety integrity requirements assigned to the safety functions of E/E/PE safety-related systems. Safety integrity levels can be divided into 4 grades; SIL4 represents the highest level of safety integrity (with the lowest average probability), while SIL1 is the lowest level ; The higher the safety integrity level, the greater the probability that the required safety functions must be implemented ; Based on the usage pattern of safety-related systems, the required frequency can be divided into a low-demand operation mode (1 time per year). According to the GB/T 20438 standard, the target failure probability and target risk reduction for safety integrity under different operation modes are shown in Tables 1-1 and 1-2 below. By employing different operating mode architectures, it is possible to use several systems with lower safety integrity levels to meet the requirements of a function with a higher safety integrity level (for example, using an SIL2 system and an SIL1 system together to fulfill the requirements of a SIL3 function). Different process routes (production scale, types of raw materials and products, complexity of processes and equipment, etc.) have varying safety requirements. For a specific process, whether it is necessary to install a SIS and what level of SIS should be used depends on conducting a risk assessment of that particular process. A Hazard and Operability Study (HAZOP) must be carried out to identify the safety instrument functions (SIFs) that are relevant to this analysis; once such SIFs are identified, a Safety Integrity Level (SIL) is determined based on the frequency of occurrence of risks and the severity of their consequences. After establishing the integrity level of a particular safety instrument function (SIL), an appropriate SIS can then be installed. As can be seen from Table 1-3, if the required SIF for a certain process is rated as SIL 2, then a SIS with an AK4 rating is sufficient, and its failure rate in response (PFD) ranges from one percent to one in a thousand. It should be noted that SISs with different safety levels can only ensure that the failure rate of response (PFD) remains within a certain range. The higher the safety level of an SIS, the lower its PFD, meaning the likelihood of an accident is reduced; however, this does not change the consequences resulting from an accident. Therefore, the assessment of the process safety integrity level is a very important task. However, at present, there are no standards or specifications in our country for assessing the safety integrity level. Certain evaluation methods are provided in international and foreign standards. The risk matrix (RISK MATRIX) assessment method presented below can be used as a reference. This method uses the frequency (probability) of process accidents and their severity as indicators for risk assessment, and quantifies these frequency and severity levels artificially into several grades to create a matrix table (see Table 3). This is used to determine the safety integrity level of the process. The SIL level cannot be modified through configuration; it is determined through calculation. The SIL level of a system indicates the applications for which it is suitable; of course, a system with SIL3 rating can also be used in applications requiring SIL2. Furthermore, according to IEC61508, a SIS (Safety Instrumented System) requires that not only the control system itself have a SIL rating, but also the instruments and valves on site must have such ratings. It is not sufficient for only the various components that make up a control loop – such as monitoring instruments, control systems, and actuators – to have SIL ratings; rather, it is necessary to calculate the PFD of the entire control loop. If the calculated PFD falls within the SIL2 range, then that control loop meets the required SIL rating. Determining whether a control loop should be rated at SIL2 or SIL3 is based on a comprehensive analysis of factors such as the importance of that control loop within the entire production facility and its impact on safety. In China, however, everything is simplified by various parties involved; ordinary instruments and actuators without any SIL rating are used, with only the control systems requiring a SIL rating. There is no effort to determine exactly what SIL rating is needed, and in the petrochemical industry, SIS systems are all set at the SIL3 level.