Computer program-implemented method for automated verification of unload valve opening sequence logic and read non-transient storage media
Patent Information
- Application Number
- BR102025001867
- Authority / Receiving Office
- BR · BR
- Patent Type
- Applications
- Publication Date
- 2026-08-11
Smart Images

Figure 00000024_0000 
Figure 00000024_0001 
Figure 00000025_0000
Description
[0001] The present invention is relevant to the oil and gas industry, more specifically related to the automated verification of sequences that can be described by priorities and rules for composing those priorities. It has particular application in the sequencing of BDV (“Blowdown Valves” - pressure relief valves or discharge valves) openings in offshore production units and refers to an automated testing or verification method. The method is implemented by a computer program that automates the tests, with the practical advantage of allowing a much larger number of test cases or scenarios and with better traceability compared to the approach prior to the invention. Fundamentals of the Invention
[0002] Blowdown valves (BDVs) are valves that remain closed during normal operation of production units, such as oil platforms, and are opened in emergency scenarios, such as in cases of fire in the production area. Their purpose is to relieve the gas inventory for the flare, thus avoiding potentially serious consequences.
[0003] A flare is a safety device that burns gas in a controlled manner, preventing its direct release into the atmosphere. The flow rate of gas released by the flare must be controlled so as not to exceed its operational limit.
[0004] Due to the large gas inventories accumulated in Petition 870250007719, dated 01 / 30 / 2025, page 43 / 68 2 / 19 production units, such as FPSO-type offshore platforms, the simultaneous opening of the BDVs could exceed the flare capacity. In many cases, therefore, it is necessary to sequence the opening of the BDV valves in emergency scenarios to ensure that the flare capacity is not exceeded.
[0005] The proper sequencing for opening these valves depends on the emergency scenario, the characteristics of the BDVs involved, the flow rate of each BDV valve, and the flare capacity. This sequencing needs to adapt in real time, considering the operator's actions, who can manually open any BDV at any time, as well as the possibility of simultaneous scenarios.
[0006] The logic that implements the automatic sequencing of BDVs in the various possible scenarios is therefore complex, dynamic (it cannot be established with fixed times) and needs to be correct to avoid severe damage to facilities, people or the environment, as would be the case if the flare capacity were exceeded.
[0007] Verifying the functionality of the implemented logic through testing takes on a combinatorial nature, due to the numerous possibilities of concurrent scenarios and manual interventions by operators. Furthermore, it is not possible to predict with precision when these interventions may occur.
[0008] The technical problem, therefore, relates to verifying the functioning of the logic implemented in the systems that control the sequencing of the BDVs, in order to guarantee its correctness for a large number of possible scenarios. The approach prior to the invention consists of manual testing of Petition 870250007719, dated 01 / 30 / 2025, page 44 / 68 3 / 19 scenarios, in which the people responsible for verifying the correct functioning of the logic manually simulate the characteristic conditions of each possible scenario, the operator's intervention at agreed times, and the occurrence of concurrent scenarios.
[0009] The logic behavior is recorded and then compared with the expected behavior, calculated using spreadsheets that take into account the application of prioritization rules and the characteristics of the BDVs. It is necessary to calculate the sequencing for each combination, record the actions and times, and produce detailed reports. This supervised testing process is costly, as it must test all predefined scenarios, extends over several days, and requires close observation.
[0010] In order to overcome these limitations described above, the present invention establishes a test method for automated verification of the sequencing logic of the opening of Blowdown Valves (BDVs) or discharge valves. The method is implemented by a computer program, with the practical advantage of allowing unsupervised testing of a large number of cases (or scenarios), much larger than would be possible manually, in much less time (hours instead of weeks), at a lower cost. State of the Art
[0011] Document US7869889B2 describes a distributed and adaptive intelligent logic with multiple communication devices for reliable safety system shutdown to monitor and control field devices in chemical and other industrial processes. The final elements of Petition 870250007719, dated 01 / 30 / 2025, page 45 / 68 4 / 19 System and method include emergency isolation valves, flow control valves, valve actuators, pump controllers and motor starters.
[0012] The proposal in this document defines a logic that is adaptable to dynamic conditions and avoids unnecessary shutdowns. The present invention, however, does not define the BDV drive logic, nor the infrastructure necessary for the execution of the logic. The logic is a consequence of the flare flow rate limit, the BDV flow rate characteristic, the priorities, and the rules for changing these priorities.
[0013] More specifically, the present invention proposes a method for testing the logic implemented in the logic executor. That is, a method is desired that ensures that the implemented logic behaves as expected. If applied to the aforementioned document, the invention would aim to verify whether what was proposed in said document has been implemented correctly and is operating correctly, as expected. In short, the present invention deals with testing the implemented logic to ensure that the implementation was correct, and not the logic itself.
[0014] In turn, document US8720267B2 addresses a system for online testing of an emergency shut-off valve to improve the Safety Integrity Level (SIL) rating and analyzes certain scenarios using partial stroke testing of an emergency shut-off valve coupled to a supplemental fuel control valve.
[0015] Note that this document refers to the partial valve test, to ensure that when required, the valve performs the function for which it was designed. Unlike the Petition 870250007719, dated 01 / 30 / 2025, pp. 46 / 68 5 / 19 of the present invention, the aforementioned document makes no reference to the logic tests that might eventually require the activation of this valve. It is irrelevant to the present invention how the BDVs are tested to ensure they operate when required. The present invention focuses on logic testing and not on the valves themselves.
[0016] Finally, document US9523971B2 describes a method for monitoring and controlling valves in industrial process control and automation (including in the oil and gas industry) to acquire valve parameters through a port and send the parameters to any portable device via NFC for analysis. Unlike the present invention, it should be noted that this document focuses on testing the functionality of the system components and not on testing the logic of valve opening sequencing, as is the case with the present invention.
[0017] More clearly, the present invention does not propose the “automated verification and control of components (such as valves)”, nor does it propose to define the logic required by these components. The present invention proposes to establish a method for testing the sequencing logic of BDVs, a logic that is well established but difficult to implement and verify.
[0018] Some advantages of the present invention can be highlighted related to economic and productivity benefits, since the present invention significantly reduces the time and resources required for verifying the sequencing logic implemented in control systems. Without the invention, the tests were performed manually, one by one, with continuous supervision by the analysts. Petition 870250007719, dated 01 / 30 / 2025, page 47 / 68 6 / 19
[0019] The tabulated results needed to be compared manually, or in a non-standardized way, using Excel or other means, to determine the differences between the expected and obtained behavior. Furthermore, the expected result itself needed to be calculated by the analysts for each test case. The increased reliability of the sequencing program results in a reduced risk of failures, minimizing equipment and production losses.
[0020] There are also health and safety advantages, since the increased reliability of the sequencing program also reduces the risk of failures that could result in fires and explosions, thus preventing injuries and deaths. Advantages related to reliability, since the proposed method allows a high number of tests to be carried out, as many as necessary, in a fraction of the time that would be required by the manual method.
[0021] By increasing the number of test cases, the number of untested scenarios is reduced and, consequently, confidence increases that the sequencing program will not fail when required. Finally, there are environmental advantages, as the increased reliability of the sequencing program results in a lower risk of failures that could fuel fires and explosions, potentially causing spills and environmental damage. Brief description of the invention
[0022] The present invention relates to a computer program-implemented method for automated verification of the sequencing logic of blowdown valve (BDV) opening. The method is implemented by a program. Petition 870250007719, dated 01 / 30 / 2025, pp. 48 / 68 7 / 19 of a computer that was developed specifically for this purpose, with the practical advantage of allowing a much larger number of test cases (or scenarios) compared to the approach prior to the invention. The method is based on a scenario-based prioritization study, in which, given a set of scenarios to be tested, the decay curves of the BDVs and the prioritization rules, a method implemented by a computer program is used in a chained manner, comprising the main steps of: 1. standardization of the scenario definition; 2. calculation of the BDV sequencing that respects the capacity limit of the flare and the prioritization rules for each scenario; 3. translation of this sequencing into a visual format that allows analysis by a specialist; 4. automated testing of each scenario; and 5. generation of a report with the test results, indicating whether or not the implemented logic met the expected sequencing.
[0023] Furthermore, the present invention relates to a non-transient, computer-readable storage medium comprising instructions stored therein, wherein the instructions, when read by a computer, cause the computer to execute the steps of the method as defined above. With the method of the present invention, it is possible to perform a test on a much larger number of scenarios than would be possible manually, in much less time (hours instead of weeks), with greater accuracy and lower cost, increasing confidence in the program that performs the sequencing of the BDVs. Brief description of the Figures
[0024] Figure 1 is a diagram of an architecture for a Computer Implemented Method for Automated Verification Petition 870250007719, dated 01 / 30 / 2025, page 49 / 68 8 / 19 of the Logic for Sequencing the Opening of Blowdown Valves (BDVs) following a scenario-based prioritization study, according to one of the modalities of this request.
[0025] Figure 2 is a graph representing the results of an algorithm that ensures that each BDV, when opened, does not exceed the Flare limit.
[0026] Figure 3 illustrates the “black box” test: the computer-implemented method executes the inputs representing the test scenario and observes the outputs. Once the expected sequence is calculated, the method gives a verdict on the correctness of the implemented program when the observed behavior coincides or does not coincide with the expected behavior. Detailed Description of the Invention
[0027] The present invention provides a Computer Implemented Method for Automated Verification of Blowdown Valve (BDV) Opening Sequencing Logic following scenario prioritization studies and a Computer-Readable Non-Transient Storage Medium. In general, the method comprises the following steps: 1) standardization of scenario definition; 2) calculation of blowdown valve sequencing taking into account the capacity limit of the safety equipment (flare) and the prioritization rules for each scenario; 3) translation of the sequencing into a format that configures the execution of the scenarios and allows a visual representation; 4) automated testing of each scenario; and 5) generation of a report with the test results, indicating whether the implemented logic met the expected sequencing.
[0028] In order to understand the scenarios and objectives of Petition 870250007719, dated 01 / 30 / 2025, pages 50 / 68 9 / 19 method, assume that the industrial unit is subdivided into subprocesses built in separate modules and then assembled and interconnected on an FPSO-type production platform.
[0029] Each module is named M01, M02, etc., and contains a set of BDVs that relieve (depressurize) the Flare (safety equipment) in case of a confirmed fire in the module area. Note that the operator can manually activate, at any time, the BDVs of other adjacent modules or even a specific BDV to mitigate the consequences.
[0030] Given the above, it is also important to consider that a BDV, when opened, relieves the flare of a higher initial flow rate that decreases exponentially over time as the inventory is relieved. The decay of the flow rate of a BDV frees up space in the flare for the opening of other BDVs without exceeding its maximum flow rate.
[0031] Given this, an example of a possible scenario would be a confirmed fire in module M01 with the consequent action of the operator opening BDV-002, 30s after the fire confirmation. In this scenario, the BDVs of module M01 must open in the correct sequence, without exceeding the maximum flow rate of the Flare, in addition to accommodating the flow rate of BDV-002, that is, BDV-002 must open soon after 30 seconds, as soon as the decay of the flow rate of the already opened BDVs allows.
[0032] In this case, the opening sequence of the M01 module's BDVs is delayed until the flow rate of BDV-002 drops to a point where other BDVs can open. With the opening of the BDVs, the gas inventory is sent to the Flare and the unit is depressurized, preventing explosions and greater damage. Note that the number of possible scenarios is combinatorial since it is not possible to predict which modules will have fire in the area, at what time, Petition 870250007719, dated 01 / 30 / 2025, pp. 51 / 68 10 / 19 nor when the operator will perform manual actions.
[0033] There must be prioritization rules to determine a depressurization queue dynamically, at runtime. For example, there could be a rule that prioritizes the manually triggered BDV over the others. This BDV then moves ahead of the others in the queue.
[0034] Other rules may, for example, determine that the priority for opening the BDVs when fire is detected in module M01 and then in module M02 is different from that when fire occurs in module M02 and then in module M01. When fire occurs in two modules simultaneously, there may be a rule that prioritizes the opening of the BDVs of one module over the other.
[0035] These prioritization rules impact the depressurization queue in real time. That is, the program that implements and executes the sequencing of the BDVs must react to real conditions and change the depressurization queue according to the rules.
[0036] Whatever the scenario, the sequencing program (set of instructions executable by computer) must calculate the depressurization queue, estimate at each instant the available capacity in the Flare, compare it with the initial flow rate of the BDV with the highest priority in the depressurization queue, and authorize the opening of that valve when there is available capacity in the Flare.
[0037] Due to the complexity and risks involved, it is imperative to test as many scenarios as possible in order to ensure that the program implemented in the sequencing executor will behave as expected. The objective of the method of the present invention is precisely to allow a way Petition 870250007719, dated 01 / 30 / 2025, pp. 52 / 68 11 / 19 practice of testing a large number of scenarios to verify the correctness of the sequencing program implemented in the sequencing executor.
[0038] The method is represented in Figure 1, with the steps numbered from 1 to 5. Description of Stage 1 - Test Specification
[0039] In step 1, the analyst standardizes the definition of the scenarios, describing the set of scenarios he wants to test in a file with the test specification. In this file, the analyst names the scenario and the sequence of activations (fire confirmed and manual activations by the operator) of that scenario. For example, in scenario 1 the analyst wants to know if the BDV sequencing logic will execute correctly if there is a fire in module M01 at time zero, followed by the operator opening BDV-002 at time 30 seconds.
[0040] Another scenario, named scenario 2, could be fire in module M03 followed by fire in adjacent modules M05 and M08 at times 0, 40 and 80 seconds respectively, in addition to the activation by the operator of the BDVs existing in module M02, at time 60 seconds.
[0041] Specifically, the test specification is performed using a JSON file, describing the test scenarios as follows: { “scenarios”: [ { “name”:”scenario 1”, “activations”:[ Petition 870250007719, dated 01 / 30 / 2025, pp. 53 / 68 12 / 19 {“qual:M01, “activation:fire, “delay:0.0}, {“qual:BDV002,“activation:manual,“delay:30.} ]}, { “name:scenario 2, “activations:[ {“qual:M03, “activation:fire, “delay:0.0}, {“qual:M05, “activation:fire, “delay:40.0}, {“qual:M08, “activation:fire, “delay:80.0}, {“qual:M02, “activation:manual, “delay:60.0} ]} ]}
[0042] The analyst can add as many scenarios as necessary. Once the scenarios are specified, proceed to step 2 of the method. Description of Step 2 - Sequencing Algorithm
[0043] The test scenario specification is then translated in step 2 into a set of BDV sequences, one sequence for each scenario. The sequencing algorithm must receive the scenario specification from the previous step, the priority tables for each BDV, and the rules that allow the calculation of the queue or sequence of depressurization of the discharge valves which, together with the flow rates and decay rates, allow the composition for each scenario of the BDV opening sequence.
[0044] The algorithm must ensure that each BDV, when Petition 870250007719, dated 01 / 30 / 2025, pp. 54 / 68 13 / 19 open, do not exceed the maximum operating flow rate of the Flare. Figure 2 illustrates this issue: the graph shows that the next BDV will only be opened (indicated in the graph by an instantaneous rise in the Flare flow rate) when the decay of the flow rate in the previous BDVs allows the BDV to open without exceeding the maximum flow rate of the Flare, which in the example shown in the figure is 600,000 m3 / day.
[0045] Note that the method uses prioritization rules, but does not define them. The prioritization rules are defined externally and imported into the test method. These same rules were used in the implementation of the sequencing program that we want to test.
[0046] To illustrate how the algorithm works, imagine that the VBDs of module M01 and those of module M02 have the priority defined in Table 1 below, and that there is VBD sharing between the modules. A rule could be that if there is a fire in module M01 and then in module M02, module M01 must finish its sequencing before the sequencing of the VBDs of module M02 begins.
[0047] Thus the priority queue becomes that of Table 2, such that the priorities of module M01 are maintained and those of module M02 come next, that is, BDV-05 becomes the fourth and BDV-04 becomes the fifth valve in the sequencing since BDV-01 was prioritized in module M01. Table 1: Example of BDV priorities in case of confirmed fire in each module separately. BDV M01 M02 BDV-01 1 3 BDV-02 3 Petition 870250007719, dated 01 / 30 / 2025, pages 55 / 68 14 / 19 BDV-03 2 BDV-04 2 BDV-05 1 Table 2: Priority queue and sequencing after applying the example rule. BDV Queue Sequence BDV-01 1 0.0s BDV-02 2 10.0s BDV-03 3 45.0s BDV-04 4 53.0s BDV-05 5 77.0s
[0048] To complete Table 2, the sequencing algorithm needs to define the trigger times for each BDV in the sequence. This is done by considering the following flow decay rule: V_bdv(t) = Vmax_bdv * e^(-(t-tü)*C_bdv), where: t0 is the moment when the BDV is activated; t is the elapsed time, with t > t0; V_bdv(t) is the flow rate of the BDV at time t; For t < t0, V_bdv(t) is zero; Vmax_bdv is the maximum flow rate of the BDV and occurs at t = t0; C_bdv is a decay constant of the respective BDV.
[0049] For implementation in digital systems, the formula can be simplified to: V_bdv(t) = V_bdv(t-dt)*R_bdv, where: R_bdv = e^(-dt*C_bdv) is a constant decay ratio; dt = a period between flow samplings;
[0050] Thus, applying the formula, the flow rate in a BDV behaves as follows: t0= t0 -> V_bdv(t0) = Vmax_bdv; Petition 870250007719, dated 01 / 30 / 2025, pp. 56 / 68 15 / 19 t1= t0 + dt -> V_bdv(t1) = V_bdv(t0) * R_bdv; t2= t1 + dt -> V_bdv(t2) = V_bdv(t1) * R_bdv; t3= t2 + dt -> V_bdv(t3) = V_bdv(t2) * R_bdv; and so on.
[0051] With this formula and the characteristics of the BDVs (Vmax_bdv and R_bdv), the sequencing algorithm is able to predict future flows and all BDVs and compare them with the Flare limit in order to define the moment when the next BDV in the sequence could be triggered without exceeding that limit.
[0052] Furthermore, based on the formula and specific characteristics of the BDVs (Vmax_bdv and R_bdv), the priority relationships established between them, and the fire detection times in the modules, the algorithm performs a temporal simulation, calculating, for each time interval tk (k= [0, 1, 2,...]), the occupied flow rate of the Flare system. This calculation considers the BDVs already opened and their respective flow rate decay curves, verifying if the idle capacity of the Flare is sufficient to accommodate the next BDV with priority for opening.
[0053] The BDV with the highest priority should be opened as soon as the algorithm determines that its activation will not exceed the Flare's capacity limit. For each opening performed, the algorithm records in memory the BDV identification and the exact moment it was triggered. The algorithm terminates when all programmed BDVs have been effectively opened. At the end, the algorithm provides a sequential set of triggers, specifying each opened BDV and its respective opening time.
[0054] As an example, for the calculation of the times in Table 2, Petition 870250007719, dated 01 / 30 / 2025, pp. 57 / 68 16 / 19 The algorithm calculates that 10 seconds after the opening of BDV-01, the flow rate will have decreased enough to allow the opening of BDV-03. Similarly, the algorithm calculates that the sum of the flow rates of BDV-01 and BDV-03 will have decreased enough for the opening of BDV-02 at time t=45 seconds, and so on for the other BDVs in the sequence.
[0055] Thus, the prioritization rules determine the depressurization queue which, given the flow rates and decay of each BDV, results in the sequence of opening of the BDVs (Table 2). Description of Step 3 - Test Setup and Viewing Table 3: Sensors to Indicate Fire Detected in the Modules Module Sensors M01 Voting 2oo3 between FGS-001A, FGS-001B and FGS-001C M02 Voting 2oo3 between FGS-002A, FGS-002B and FGS-002C M03 Voting 2oo3 between FGS-003A, FGS-003B and FGS-003C
[0056] Step 3 introduces into the method the configuration and visualization of the sequencing calculated in the previous step, translating the sequencing into a format that configures the execution of the scenarios and allows for a visual representation. The scenarios are grouped into two files: the first, “Sequencing Activations”, which details the sensors that trigger the scenarios under test, while the second, “Sequencing Matrix”, details the valves activated in each scenario, in the correct order and at the correct activation times.
[0057] These files, automatically generated from the Petition 870250007719, dated 01 / 30 / 2025, pages 58 / 68 The previous phase, 17 / 19, of the method also incorporates the mapping of the read and write points of the equipment under test, which implements the sequencing logic, so as to allow the method to execute commands on the equipment under test and obtain the responses from that equipment.
[0058] As an example, suppose that fire detection in module M01 is done through a 2oo3 (2 out of 3) vote of the fire sensors FGS-001A, FGS-001B, and FGS-001C (see Table 3), meaning that fire must be detected by at least two of these three sensors to activate the sequencing of module M01. The sensor information, votes, addresses, and other necessary information for activation is provided to the method and translated into the file that configures the sensors.
[0059] In this way, the method is able to generate signals that trigger these sensors in various combinations. If the scenario under test involves fire detection in module M01, the configuration file informs the method that it is necessary to trigger combinations of at least two of these sensors and that a single sensor should not be able to trigger the scenario.
[0060] The second file formalizes the sequencing result, informing the method, in addition to the sequencing calculated in the previous phase, also the configuration so that the activation of the valves in the equipment under test can be detected. This file essentially consists of a Cause and Effect Matrix, where the causes are the signals from the 'Sequencing Activations' Matrix, which indicate the detection of fire in the module, and the effects, which correspond to the opening of the valves associated with each module, linked to a time constraint that defines the expected time for the valve to be opened. Petition 870250007719, dated 01 / 30 / 2025, pages 59 / 68 18 / 19 triggered by the sequencing logic executor.
[0061] These files can be used by the method to generate visualizations of the tests, allowing the analyst to visualize the sensors that will be triggered and the expected sequence of BDV triggering for each test scenario. Description of Step 4 - Test Execution
[0062] Step 4 is the execution of the tests or automated testing of each scenario. The method implemented by computer program, described in Veiga, HW, de Queiroz, MH, Farines, JM., de Lima, ML (2017). Automatic Conformance Testing of Safety Instrumented Systems for Offshore Oil Platforms. In: Petrucci, L., Seceleanu, C., Cavalcanti, A. (eds) Critical Systems: Formal Methods and Automated Verification. AVoCS FMICS 2017 2017. Lecture Notes in Computer Science(), vol 10471. Springer, Cham. https: / / doi.org / 10.1007 / 978-3-319-67113-0_4, generates the test signals and applies these tests to the sequencing executor loaded with the logic to be tested, and which implements the sequencing rules.
[0063] The tests are performed in a “black box,” meaning that it is not necessary to know the logic implemented in the sequencing executor, but only the expected behavior. Figure 3 exemplifies the “black box” test: The method implemented by the computer program forces the input sensors to activate the expected test scenario and records the outputs and their times, to verify the correctness of the implemented program, by comparing whether the observed behavior coincides with the expected behavior.
[0064] The method implemented by computer program Petition 870250007719, dated 01 / 30 / 2025, pages 60 / 68 19 / 19 allows interaction with the sequencing executor through standardized communication interfaces such as OPC-UA, for example. For each scenario, the test program will generate signal combinations that activate the scenario and will observe the executor's output to determine if the logic triggers the BDVs in the correct sequence and at the expected intervals.
[0065] The method enables the automatic execution of a series of test scenarios without human intervention, increasing the efficiency of the process.
[0066] After the tests are completed, the test software compiles the results into a report that differentiates between correct and incorrect scenarios, specifically identifying the valves that were activated outside of the programmed time. This report facilitates the rapid identification of faults, allowing for precise adjustments to the system. Description of Stage 5 - Test Results
[0067] In Step 5, the method generates a report with the test results, indicating whether the implemented logic met the expected sequence. The report contains the applied signals and the results of each test, allowing the analyst to know all the tests performed, their results, and reproduce them if desired.
[0068] For each test, the report indicates the verdicts: OK, when the valves were activated at the expected intervals; NOK when at least one BDV did not open or did not respect the sequence at the right time.
Claims
1. Computer-implemented method for automated verification of the sequencing logic of discharge valve opening, characterized by the fact that it comprises the following steps: 1) standardization of scenario definition; 2) Calculation of the sequencing of the discharge valves, taking into account the capacity limit of the safety equipment and the prioritization rules for each scenario; 3) translation of the sequencing into a format that configures the execution of the scenarios and allows for a visual representation; 4) Automated testing of each scenario; and 5) generation of a report with the test results, indicating whether the implemented logic fulfilled the expected sequencing.
2. Method, according to claim 1, characterized in that the automated verification is a consequence of the flow limit of the safety equipment, the flow characteristic of the discharge valves, the priorities and the rules for changing these priorities.
3. Method, according to claim 1 or 2, characterized in that it consists of a test of the sequencing logic of the discharge valves ensuring that the logic behaves as expected.
4. Method, according to any of claims 1 to 3, characterized in that the set of computer-executable instructions: calculate the depressurization queue or sequencing, estimate the available capacity in the safety equipment, Petition 870250007719, dated 01 / 30 / 2025, p.62 / 68 2 / 4 compare with the initial flow rate of the discharge valve with the highest priority in the depressurization queue, and authorize the opening of this valve when there is available capacity in the safety equipment.
5. Method, according to any one of claims 1 to 4, characterized in that in step 1 the analyst describes the set of scenarios to be tested in a file with the test specification, in which the scenario and the sequence of activations of the scenario are named in the file.
6. Method, according to any one of claims 1 to 5, characterized in that the test specification describes the test scenarios, in which the analyst optionally adds a plurality of scenarios.
7. Method, according to any one of claims 1 to 6, characterized in that in step 2 the specification of the test scenarios is translated into a set of discharge valve sequences, with one sequence for each scenario. 8.A method, according to any one of claims 1 to 7, characterized in that in step 2 the sequencing instruction set receives the specification of the scenarios from step 1, the priority tables for each discharge valve, and the rules that allow the calculation of the depressurization queue, which, together with the flow rates and decay rates, allow the instruction set to compose the opening sequence of the discharge valves for each scenario.
9. A method, according to any one of claims 1 to 8, characterized in that it uses externally defined prioritization rules, in which the prioritization rules determine the depressurization queue, based on the flow rates and decay of each discharge valve. 10.Method, according to any one of claims 1 to 9, characterized in that in step 3 the scenarios are translated into two files allowing the configuration of the tests and the visualization of the scenarios, where the first file details the actuations and their configurations; and the second file refers to the sequencing of the opening of the discharge valves.
11. Method, according to any one of claims 1 to 10, characterized in that step 4 comprises the generation of the test signals and the application of these tests in the sequencing executor loaded with the logic to be tested, and which implements the sequencing rules.
12. Method, according to any one of claims 1 to 11, characterized in that in step 4 the execution of the tests is done without knowing the logic implemented in the sequencing executor, but only the expected behavior. 13.Method, according to any one of claims 1 to 12, characterized in that the test instruction set interacts with the sequencing executor through standardized communication interfaces, preferably OPCUA.
14. Method, according to any one of claims 1 to 13, characterized in that after the completion of the tests in step 4, the results are compiled into a report by the instruction set, in which the report differentiates between correct and incorrect scenarios, specifically identifying the valves that were activated outside the programmed time.
15. Method, according to any one of claims 1 to 14, characterized in that the report contains the applied signals and the results of each test. 16.A method, according to any one of claims 1 to 15, characterized in that the report indicates the verdicts: OK, when the discharge valves are activated at the expected intervals; NOK, when at least one discharge valve does not open or does not respect the sequence at the correct time.
17. A computer-readable non-transient storage medium characterized in that it comprises a set of stored instructions, wherein the instructions, when read by a computer, cause the computer to execute the steps of the method as defined in claims 1 to 16.