Method and apparatus for automating process hazard and safety plc application validation
By interacting with AI-based analysis and simulation tools, a multi-agent system is used to automatically analyze potential hazards in industrial processes and generate safety requirements. This solves the problem of difficulty in automating the analysis and verification of PLC applications in existing technologies, improving analysis efficiency and the correctness of safety PLCs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SCHNEIDER ELECTRIC SYSTEMS USA INC
- Filing Date
- 2021-10-14
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies struggle to automate and efficiently analyze potential hazards in industrial processes and validate the effectiveness of safe programmable logic controller (PLC) applications, leading to the potential for manual conversion to overlook critical safety requirements.
By employing AI-based analysis and simulation tools, an industrial process is simulated through a multi-agent system to identify potential hazards and generate safety requirements. Subsequently, the PLC application is tested to confirm its effectiveness in preventing hazards.
It has achieved automated process hazard analysis and safety requirement generation, improved analysis efficiency, ensured the correctness and safety of PLC applications, and reduced the risk of human error.
Smart Images

Figure CN114384855B_ABST
Abstract
Description
Technical Field
[0001] This disclosure generally relates to hazard / safety analysis of industrial processes, and more specifically, to performing automated or semi-automated hazard / safety analysis of industrial processes using one or more artificial intelligence-based tools. Background Technology
[0002] As part of a Safety Instrumented System (SIS), a safety PLC (Programmable Logic Controller) is a critical layer of protection used to prevent industrial accidents in plants such as oil refineries and chemical plants. Additional layers of protection exist, including basic process control systems and physical methods such as pressure relief valves. To program a safety PLC to prevent accidents, safety personnel define process hazards and assign them to different layers of protection within the plant; and a safety requirements specification (SRS) is written. The safety PLC's application program is then developed to meet the requirements of the safety requirements specification. Summary of the Invention
[0003] According to embodiments, a system and method are provided for automatically or semi-automatically analyzing process hazards and verifying protection mechanisms for industrial processes. The system and method involve establishing communication between a simulation tool and a process hazard analysis tool. The simulation tool is configured to simulate the operation of an industrial process based on a process model. The simulation tool and the process hazard analysis tool are executed on one or more computers or across one or more computers. The method and system may also involve: using the process hazard analysis tool, based on information about the industrial process learned from the simulation tool, creating conditions for hazards in the industrial process; for each hazard, simulating the hazard using the simulation tool and attempting to prevent the hazard using the process hazard analysis tool by introducing one or more protection mechanisms from a plurality of potential protection mechanisms into the industrial process; and evaluating the effectiveness of the introduced protection mechanism for each hazard, and based on the evaluation effectiveness, creating safety requirements (e.g., SRS, etc.) for the industrial process. The system and method may also involve generating an application for a safety programmable logic controller (PLC) in a safety instrumentation system (SIS) to meet the safety requirements; and testing the application to confirm that the application can prevent hazards in the industrial process.
[0004] In some embodiments, to simulate hazards and / or assess effectiveness, the process hazard analysis tool implements multiple agents for interacting with the simulation tool and for altering operating conditions in the industrial process simulated by the simulation tool. The multiple agents may include: at least one first agent for causing hazardous conditions in the industrial process simulated by the simulation tool, and at least one second agent for introducing protective mechanisms to prevent hazardous conditions in the industrial process simulated by the simulation tool.
[0005] In some embodiments, to simulate hazards and / or assess effectiveness, the process hazard analysis tool is configured to: initiate multiple adversarial agent groups, each including a first agent and a second agent; for each adversarial agent group, randomly assign one or more inputs associated with the process model to be used by the adversarial agent group to control the operational state of an industrial process simulated by the simulation tool; for each adversarial agent group, assign reward points when the respective first agent increases the chance of an associated hazard and / or when the respective second agent decreases the chance of an associated hazard; for each adversarial agent group, create a protection configuration including a protection layer for the associated hazard based on the interaction between the first and second agents of the adversarial agent group; for each adversarial agent group, calculate a reward score for the adversarial agent group using a reward function based on the reward points accumulated by the adversarial agent group; and eliminate one or more duplicate adversarial agent groups from the multiple adversarial agent groups based on the reward scores of the multiple adversarial agent groups.
[0006] In some embodiments, the process hazard analysis tool can create safety requirements for an industrial process based on the protection configurations of the remaining adversarial agent groups from multiple adversarial agent groups. Furthermore, the application can be tested using both the process hazard analysis tool and a simulation tool to confirm its ability to prevent hazards in the industrial process. The first agent of the process hazard analysis tool can result in hazardous conditions in the industrial process simulated by the simulation tool. The application can prevent the hazardous conditions in the industrial process simulated by the simulation tool.
[0007] In some embodiments, the process hazard analysis tool can be further configured to generate a causal matrix relating to the inputs and outputs of the simulation tool when simulating an industrial process, and to create safety requirements based on the causal matrix. Additionally, inputs may include protection mechanisms added by a second agent to the industrial process simulated by the simulation tool. Outputs may also include the state of the operating conditions of the industrial process simulated by the simulation tool.
[0008] In some embodiments, the protection mechanism may include at least one safety instrumentation system comprising a set of equipment designed to reduce risks arising from specific hazards. Furthermore, the first agent and / or the second agent may be configured to control and monitor operating conditions in an industrial process simulated by the simulation tool, based on a process model constrained by physical laws, scientific laws, and / or natural laws.
[0009] Additional objectives and advantages will be set forth in part in the description which follows, and will be apparent in part from the description, or may be learned by practice of this disclosure and / or the claims. At least some of these objectives and advantages may be realized and obtained by means of the elements and combinations particularly pointed out in the appended claims.
[0010] It should be understood that the foregoing general description and the following detailed description are exemplary and illustrative only, and not intended to limit the disclosed or claimed invention. The claims should enjoy their full scope, including equivalents. Attached Figure Description
[0011] The descriptions of various example embodiments are explained with reference to the accompanying drawings.
[0012] Figure 1 This is an overview of example components of an AI-based hazard (or safety) analysis system having one or more artificial intelligence (AI)-based analysis tools, according to exemplary embodiments.
[0013] Figure 2 The figure illustrates a functional block diagram of an AI-based analytics tool according to an exemplary embodiment, which employs multiple agents to analyze hazards in industrial (or other) processes and create safety requirements for those processes.
[0014] Figure 3 The figure illustrates a functional block diagram of an AI-based analysis tool according to an exemplary embodiment, which employs one or more agents to test the protective effectiveness of applications (such as security PLC applications) created using security requirements.
[0015] Figure 4 The figure illustrates an example method according to an exemplary embodiment, through which AI-based analytics tools can be used to analyze hazards in industrial processes and create safety requirements for those processes.
[0016] Figure 5 The figure illustrates an example method for implementing safety engineering and lifecycle management according to an exemplary embodiment, in which AI-based analytics tools can be used to analyze hazards in industrial processes and create safety requirements for those processes.
[0017] Figure 6The figure illustrates an example method according to an exemplary embodiment, through which an AI-based analytics tool can be used to enable an agent team to analyze hazards in an industrial process and to create safety requirements for that process using reward-based machine learning techniques.
[0018] Figure 7 The figure illustrates an example of hazard information identified by an AI-based analysis tool according to an exemplary embodiment.
[0019] Figure 8 The figure illustrates an example of Layers of Protection Analysis (LOPA) created by an AI-based analysis tool according to an exemplary embodiment.
[0020] Figure 9 The figure illustrates an example of a Security Requirements Specification (SRS) created by an AI-based analytics tool according to an exemplary embodiment.
[0021] Figure 10 The figure illustrates example components of a computer or computing system according to an exemplary embodiment. Detailed Implementation
[0022] A system and method are provided that automate the identification of process hazards in industrial processes using automated, artificial intelligence (AI)-based analytics tools coupled with a process model (for the industrial process being analyzed) used to simulate the process. Industrial processes can include plants, facilities, and other potentially hazardous processes. The system and method can automatically identify process hazards and protective mechanisms to prevent them from escalating into accidents. The results generated by the computer-implemented tools are captured, for example, in hazard analysis (e.g., identified potential hazards), layer-of-protection analysis, and safety requirement specifications. These safety requirements can then be used to create safety applications, such as programmable logic controllers (PLCs) used in automation or other industrial systems. After the safety application is created and integrated with PLC hardware or a PLC simulator, the program can be tested by the AI-based analytics tools to confirm that the PLC programming can prevent process hazards from escalating into accidents.
[0023] AI-based tools can include simulator tools that simulate industrial processes based on one or more process models, and process hazard analysis tools (such as analyzer tools) that interact with the simulator tools to control and analyze the process simulation in order to output information for developing safety requirements for the assessed process. Using AI-based tools, hazard analysis workflows can be modified to replace human-knowledge-based engineering with AI-based tools that can create outputs such as process hazard analyses, layer-of-protection (LOPA) analyses, causal matrices, and safety requirement specifications (SRS). After a safety PLC application is created and made available based on the output from this tool, the PLC program can be tested by the tool to confirm that the programming can prevent hazards in the industrial process.
[0024] For example, humans can create simplified process simulations (or process models) that capture the physics and constraints of industrial processes. The tool can utilize adversarial agents based on AI multi-agent interaction in a game-like setting. The first agent can create conditions for a hazard, while the second agent can attempt to prevent the hazard by introducing one or more protection mechanisms from a palette of available protection mechanisms. Process hazard analysis and protection layer analysis are the outputs when the hazard is defended by the second agent. Protection layers can include prevention layers that attempt to prevent a hazardous event from occurring, or mitigation layers that reduce the consequences after a hazardous event has occurred. Additional outputs for the causality matrix and safety requirement specifications are created based on the outputs of the process hazard analysis and protection layer analysis. After the safety PLC application is created, it can also be tested by an AI-based tool with process simulation and process hazard analysis by replacing the second agent in the tool with a safety PLC to confirm that the safety PLC application is adequate.
[0025] Using this approach, the automated generation of process hazard analysis, protection layers, and safety requirements saves time and effort, and provides useful information for creating applications (e.g., PLC programs) that can effectively prevent potential accidents in industrial processes. Automated creation of safety requirements in this manner offers greater confidence in quality compared to manual conversions that may unintentionally miss items. This tool can be used to directly test (or validate) safety PLC applications used to prevent accidents against process hazards, thus providing greater confidence in the correctness of safety PLC applications. Consequently, this system and method can improve the productivity of process hazard / safety analysis and reduce costs by shifting from a human-centered to an automated framework.
[0026] In some embodiments, simplified process simulation models / process models (e.g., physics-based environments) and process variables can be loosely modeled as simplified fluid flows. Furthermore, maximum constraints on components can be defined in the model. Similar to the concept of a "hide-and-seek" AI game, two agent "competitors" can be implemented using agent(s)(one or more) pairs that compromise and protect, with each agent remaining "visible" to the others within the group. The AI game concept can employ machine learning approaches by rewarding agents / groups for certain actions and using a reward function to differentiate groups in order to identify the optimal solution. For example, many pairs are introduced to find or identify all hazards and potential protective configurations against each hazard. When calculating the reward function for the group, duplicate pairs can be removed via a strategy (e.g., eliminating or not eliminating duplicate pairs and their analysis based on their reward scores). AI-based analytics tools can use group-based rewards for maximum protection, where the first agent in the group is rewarded by maximizing the risk of a hazard, while the second agent in the group is rewarded by reducing the risk of a hazard determined by the first agent. Each adversarial agent can earn points(one or more) when it takes an action that creates a hazardous condition. Each protection agent can earn one or more points when it takes a protection / mitigation action against its adversary agent. A reward function is calculated for each group based on the points earned by each of the group competitors.
[0027] A predefined set of risk mitigation "tools / palettes" can be provided, from which AI can select for protection. Each mitigation action can have its associated risk reduction profile (e.g., 1oo2 (two-choice) output shutdown valve arrangement, pressure relief valve, 2oo3 (three-choice) sensor arrangement, 1oo2 sensor arrangement, sensor type - pressure, temperature, flow, level, gas detector, flame detector, other shutdown mechanisms, etc.). Total risk reduction can be assigned to each layer of the protection analysis, for example, assigning a reduction with a factor of 10 to the DCS layer and the remainder to the SIS layer. A new paradigm for testing logic solver programming (e.g., safety PLC applications) can be provided: the logic solver can be directly tested using AI / plant simulation to validate the protection.
[0028] These and other exemplary features of this disclosure will be described in more detail below with reference to the accompanying drawings.
[0029] Figure 1This is an overview of example components of an artificial intelligence (AI)-based hazard / safety analysis system 100 according to an exemplary embodiment. System 100 may implement AI-based analysis tools (or AI-based analysis software / programs) 150 for analyzing hazards for a simulated industrial process based on one or more process models, and for creating safety requirements that can be used to create safety applications such as safety PLCs for automation or other systems. The one or more process models may define specifications for the industrial process to be simulated, including but not limited to: components / equipment and their specifications / constraints, including input and output parameters, process flows (of components / equipment and between components / equipment) based on physical parameters (e.g., laws of physics, scientific laws, and / or laws of nature), and any other information that can be used to simulate the industrial process to be analyzed. For example, if the industrial process uses column distillation, the process model may include information about the physical properties of the distillation piping used in the distillation, such as the rated temperature, pressure, etc., that the piping can withstand before catastrophic damage.
[0030] AI-based analysis tools 150 may include process hazard analysis tools (also known as process safety analysis tools), such as analyzer tool 160, and may also include simulation tools 180, all of which can operate on computing environment 120 within system 100. Simulation tool 180 includes simulator 190, which is configured to simulate an industrial process (or other process) based on process model(s) 192. Analyzer tool 160 is configured to interact with simulator 190, for example, using machine learning techniques, to analyze hazards (or hazardous conditions) in the simulated process and create safety requirements for that process. Analyzer tool 160 may employ a multi-agent approach, where multiple agents 170 may play adversarial roles to increase the chance of hazardous conditions or cause hazardous conditions during the simulation, and / or use protective mechanisms to reduce the chance of hazardous conditions or mitigate / prevent hazardous conditions during the simulation. Protective mechanisms may be provided from risk mitigation tools / palettes 172. Risk mitigation tools / palette 172 can be a predefined set of risk mitigation "tools / palettes" from which analyzer tool 160 and its agents(s) can select one or more protection mechanisms to prevent or mitigate hazards. Each mitigation action can have an associated risk reduction profile (e.g., 1oo2 (two-choice) output shut-off valve arrangement, pressure relief valve, 2oo3 (three-choice) sensor arrangement, 1oo2 sensor arrangement, sensor type - pressure, temperature, flow, level, gas detector, flame detector, other shut-off mechanisms, etc.).
[0031] By using these agents 170, the analyzer tool 160 can identify all potential hazards in an industrial process, and different potential protective configurations (e.g., different layers of protection or independent layers of protection) for each identified hazard. A reward-based strategy can be employed to evaluate the actions of the agents 170 in order to identify the optimal or best protective configuration for each potential hazard (e.g., the configuration with the minimum risk of hazard occurrence or the highest chance of preventing hazard). The analyzer tool 160 can then create a mapping (e.g., a causal matrix) of causal relationships between the identified hazards and potential protective configurations and other components of the simulated process. Using these relationships, the analyzer tool 160 can create safety requirements (e.g., SRS) for the simulated process. Various examples of the multi-agent approach are described herein.
[0032] The computing environment 120 may include one or more computers 130, which can communicate with each other and other systems and devices via a network 110. AI-based analytics tools 150 and other programs may be implemented on a single computer 130, across multiple computers 130, or in a cloud computing environment using one or more computers 130. Other programs may include program generators, such as PLC program generators (or code generators), which can use the security requirements created by the AI-based analytics tools 150 to generate security applications for PLCs. The security applications can also be operated on a PLC simulator or PLC, and the AI-based analytics tools 150 can be used to test the security applications to ensure their protective effectiveness.
[0033] Figure 2The diagram illustrates a functional block diagram of an AI-based analysis tool 150 according to an embodiment. This tool employs agents 170 to analyze hazards in an industrial process and create safety requirements for that process. In this example, the analyzer tool 160 may employ agents 170, such as adversarial agent groups, each of which includes a pair of agents, such as a first agent 170A and a second agent 170B. The first agent 170A, or adversarial agent, is configured to increase (or cause) the occurrence of a hazard or hazardous condition during a simulation process performed by simulator 190. The second agent 170B, or protective agent, is configured to reduce (or mitigate / prevent) the occurrence of a hazard or hazardous condition during the simulation process using a protective mechanism selected from a predefined set of risk mitigation tools / palettes 172 or protective mechanisms. Agents 170A and 170B in each group can compete against each other to identify potential hazards and associated protective configurations. The analyzer tool 160 may continue to introduce new agent groups until all possible hazards and protective configurations for the simulation process are identified. In various embodiments, the analyzer tool 160 may randomly assign one or more inputs to each agent group, which may be identified in the process model to change the state of operating conditions during the simulation process.
[0034] In some embodiments, the analyzer tool 160 may also employ a reward system, such as reward-based machine learning techniques, during agent group competition to identify the maximum protective configuration for each potential hazard or all hazards. For example, a first agent 170A may be rewarded for maximizing hazard risk, while a second agent 170B may be rewarded for reducing the hazard risk determined by the first agent 170A. Each first agent 170A may receive one or more points (or other values) when it takes an action or creates a hazardous condition. Each second agent 170B may receive points (or other values) when it takes a protective / mitigation action against its adversarial agent. A reward function is calculated for each group based on the points of each agent contestant. Duplicate agent groups may be removed based on the group's reward score, calculated for each group based on one or more reward functions according to the group's accumulated points, using a predefined strategy. For example, if a group has a low reward score, its analysis is eliminated (or not considered).
[0035] Figure 3A functional block diagram of an AI-based analysis tool 150 is shown. This tool employs one or more agents 170 to test the protective effectiveness of a security application 310 (such as a security PLC application running on a PLC simulator or PLC). In this example, the analyzer tool 160 may employ one or more first agents 170A or one or more adversarial agents to increase (or cause) the occurrence of hazards or dangerous conditions during simulation by the simulator 190, similar to... Figure 1 and Figure 2 The embodiments described herein. A security application 310, which can act as a protection agent, attempts to mitigate the actions of the first agent 170A and any hazards or dangerous conditions during the simulation process. The analyzer tool 160 can continue to introduce new first agents 170 until all possibilities leading to hazards have been exhausted, and after that, evaluate the protective effectiveness of the security application (e.g., whether the security application is able to mitigate all potential hazards during the simulation process).
[0036] Figure 4 The figure illustrates an example method 400 according to an embodiment, through which an AI-based analysis tool (e.g., 150) can be used to analyze hazards in an industrial process and create safety requirements for that process.
[0037] At box 402, communication is established between the simulation tool (e.g., 180) and the process hazard analysis tool (e.g., 160). The simulation tool is configured to simulate the operation of an industrial process based on a process model. The simulation tool and the process hazard analysis tool can be executed on one or more computers or across one or more computers.
[0038] At box 404, using the process hazard analysis tool, conditions for hazards in the industrial process are created based on information about the industrial process learned from the simulation tool.
[0039] At box 406, for each of the hazards, a simulation tool is used to model the hazard, and an attempt is made to prevent the hazard using a process hazard analysis tool. The process hazard analysis tool can introduce one or more protection mechanisms from multiple predefined potential protection mechanisms into an industrial process to mitigate / prevent the hazard.
[0040] At box 408, the effectiveness of the protective mechanisms introduced for each hazard is assessed, and based on the effectiveness of the assessment, safety requirements (e.g., SRS) are created for the industrial process.
[0041] At box 410, an application is generated for the safety programmable logic controller in the safety instrumentation system to meet the safety requirements.
[0042] At box 412, the application is tested to confirm its ability to prevent hazards in industrial processes. In some embodiments, process hazard analysis tools and simulation tools may be used to test the application.
[0043] Figure 5 The figure illustrates an example method 500 for implementing safety engineering and lifecycle management according to an embodiment. In this example method, an AI-based analytics tool (e.g., 150) can be used to analyze hazards in an industrial process and create safety requirements for that process. As previously described, AI-based analytics tools employing multiple agents can provide various analyses and outputs, such as process hazard analysis, layer of protection analysis (LOPA), causal matrices, and safety requirement systems (SRS).
[0044] For example, method 500 begins at box 502, where an AI-based analysis tool performs and outputs a process hazard analysis. The process hazard analysis can identify potential hazards in the simulated process.
[0045] At box 504, the AI-based analytics tool performs and outputs LOPA, which includes protective configurations that mitigate each potential hazard, as well as risk metrics associated with the protective configurations and potential hazards.
[0046] At box 506, AI-based analytics tools create (or generate) a causal matrix. The matrix can include information such as, for example, a mapping of causal relationships between identified hazards, potential protective configurations, and other components in the simulation process.
[0047] In box 508, an AI-based analysis tool generates an SRS for the simulation process. The SRS can be generated based on the relationships identified in the causal matrix, as well as analysis of the simulation process, etc.
[0048] At box 510, the SRS is used to create a safety application, such as one for hardware integration. In some embodiments, the safety application is used with the PLC. The safety application can be automatically generated using a program generator based on the SRS, or it can be manually created / decoded based on the SRS.
[0049] At box 512, the security application is tested. In some embodiments, AI-based analytics tools can be used to test the security application implemented via a PLC or other simulator, or on the PLC.
[0050] At box 514, perform additional security application tests on the security application.
[0051] At box 516, perform factory acceptance testing.
[0052] At box 518, perform site acceptance testing.
[0053] At box 520, the factory operation phase is implemented.
[0054] Figure 6 The illustration depicts a method 600 according to an embodiment, by which an AI-based analytics tool (e.g., 150) is used to implement agent groups (also referred to as "agent teams") to analyze hazards in an industry (or other process) and to create safety requirements for the process using reward-based machine learning techniques. In this example, the AI-based analytics tool may introduce agent teams that interact with a process simulator to control a simulated process. Each agent team may include a first (or adversarial) agent and a second (or protective) agent.
[0055] At box 602, the AI-based analytics tool initiates a new agent group, where the first and second agents interact with the simulator to induce and defend against hazards during the simulation, respectively. The new agent group can be purposefully or randomly assigned specific inputs, such as one or more defined by the process model, to alter the state of the operating conditions of the simulation process.
[0056] At box 604, the AI-based analytics tool provides the simulator with one or more inputs from the first agent to attempt to induce a hazard (or hazardous condition) and applies rewards for increasing the risk of hazard. For example, reward points or other values may be given to the first agent for increasing the chance of hazard or causing hazard.
[0057] At box 606, the AI-based analytics tool provides the simulator with input(s) from the second agent(s) to defend against dangers that the first agent is attempting to cause, and applies rewards for reducing the risk of danger. For example, reward points or other values may be given to the second agent for reducing the chance of danger or preventing danger.
[0058] At box 608, an AI-based analysis tool determines whether the game competition between the first and second agents of the adversarial team has ended. For example, the game competition can be considered complete if: (1) the game competition conducted by the agent team discovers a potential danger and a protective configuration against that danger (e.g., a protection layer); (2) the game competition conducted by the agent team does not discover any potential danger after a predefined period (e.g., timeout); and (3) other game completion rules. If the game competition has not ended, method 600 returns to boxes 606 and 608. Otherwise, method 600 proceeds to box 610.
[0059] At box 610, an AI-based analytics tool creates a LOPA for potential hazards identified by the agent group and associated protection configurations (e.g., protection layers).
[0060] At box 612, the AI-based analytics tool calculates a reward score for the agent group based on the group's accumulated reward points, using one or more reward functions. The reward functions can be customized to help identify which agent group has a more effective protection configuration solution in the presence of duplicate agent groups (e.g., agent groups identifying the same dangers).
[0061] At box 614, an AI-based analysis tool determines whether any duplicate agent groups exist, and if so, which of the duplicate agent groups has a lower reward score. If no duplicate agent groups exist, method 600 proceeds to box 618. If duplicate agent groups exist, method 600 proceeds to box 616, where the duplicate agent groups with lower reward scores are removed. In this way, it is possible to discover (or retain) the most effective protection configuration for each identified hazard during the simulation process. Thereafter, method 600 proceeds to box 618.
[0062] At box 618, the AI-based analysis tool determines whether to check for more hazards. For example, has the adversarial agent team for the simulation process already explored all possible hazards (e.g., the agent team performed all combinations of inputs, analysis timed out, etc.)? If not, method 600 returns to box 604 to initiate a new agent team. Otherwise, if no more hazards will be checked, method 600 terminates.
[0063] against Figure 4-6 The methods shown and described are provided as examples. As those skilled in the art will understand, the various operations described in these methods can be modified while still retaining the same or similar functionality (e.g., some operations may be implemented or combined in a different order, or may be omitted).
[0064] Examples of information analyzed and created by AI-based analytics tools in Figure 7-9 The example is shown below. For illustrative purposes, in this example, the tool analyzes an industrial process that includes column distillation. Figure 7 The illustration shows an example of hazard information identified by an AI-based analytics tool based on process hazard analysis. Examples of identified hazards could include: if a cooling failure occurs due to cooling water loss, the column will suffer catastrophic damage (e.g., Hazard #1). An example of a protection layer analysis created by the AI-based analytics tool is shown in... Figure 8As shown, it may include the following information: (1) impact and severity, (2) initiation cause, (3) process design, (4) distributed control system (DCS), (5) alarms, (6) safety instrumentation system (SIS), and (7) relief valves, and (8) mitigation probability. In this example, impact and severity refer to identified hazards, such as hazard #1 (catastrophic rupture of the distillation column) and the target probability of its occurrence, such as 10. -6 Or 1x10 -6 For danger #1, the triggering factor might be something that occurs once every 10 years (e.g., 10...). -1 The probability of cooling water loss is [missing information]. The protective layer may include:
[0065] • Process Design: More Robust Pipelines (10 -2 ),
[0066] • DCS: Logic used to monitor the shutdown of the DCS (10 -1 ),
[0067] Alert: No.
[0068] • Safety Instrumented System (SIS): The over-temperature logic in the SIS will be shut down (10 -3 ),as well as
[0069] • Relief valve: Yes (10 -2 ).
[0070] Mitigation probability refers to the likelihood that a protective layer (which is independent in this example) can mitigate the danger, for example, risk probability = (2)x(3)x(4)x(5)x(6)x(7) = 10 -9 This is better than the target standard 10 for danger #1. -6 Small, and therefore meets the target criteria. Each identified hazard for an industrial process can have an associated LOPA, which is created based on a hazard / safety analysis performed by an AI-based tool. Figure 8 The LOPA in this example is provided only as an example. Each industrial process being analyzed may have multiple identified hazards (or hazardous conditions) and different layers of protection (including...). Figure 8 (Protection mechanisms not described in the text) can be identified to address different hazards.
[0071] Furthermore, for this example of column distillation, examples of the types of information contained in the Safety Requirements Specification (SRS) created by AI-based analytics tools can be found in... Figure 9The following is illustrated. For example, to address hazard #1, the Safety Logic Solver (SRS) could include: if the cooling water flow sensor measures a low flow rate for more than 10 seconds, the safety logic solver should shut down the system. The SRS can be derived by an AI-based analytics tool from a causal matrix (or similar relational information), which identifies causal relationships associated with the industrial process defined by the simulated process model and the hazard analysis performed by the AI-based analytics tool. Examples of information in this matrix could be, for example: low flow rate, then shutdown via SIS, etc.
[0072] Figure 7-9 The example embodiments and their above descriptions are provided as non-limiting examples of information or data that may be reflected or included in hazard information, LOPA, causal matrices, and SRS.
[0073] Figure 10 The figure illustrates example components of a computer system (or computing system) 1000 according to an embodiment. For example... Figure 10 As shown, the computer system 1000 may include, for example, a memory 1020, one or more processors 1030, a clock 1040, one or more output devices 1050, one or more input devices 1060, a communication device 1070, and a bus system 1080 between the components of the computer system.
[0074] Memory 1020 may store computer-executable code, programs, software, or instructions that, when executed by one or more processors, control the operation of computer system 1000, including the various methods / processes described herein. Memory 1020 may also store other data used by computer system 1000 or its components to perform the operations described herein. This other data may include, but is not limited to: process models (one or more) of the industrial process to be analyzed, hazard analysis data (e.g., identified hazards), protection layers (e.g., LOPA), causal relationships (e.g., causal matrix), safety requirements (e.g., SRS), one or more safety applications, and other information described herein.
[0075] One or more output devices 1050 may include display devices, printing devices, speakers, etc. For example, one or more output devices 1050 may output a hazard / safety analysis report or other data or information such as those described herein to a display or current graphical user interface (GUI).
[0076] One or more input devices 1060 may include any user input device, such as a mouse, trackball, microphone, touchscreen, joystick, console, keyboard / keyboard, touchscreen, or other user-operable device. One or more input devices 1060 may also accept data from external sources, such as other devices and systems.
[0077] One or more processors 1030, which interact with other components of the computer system, are configured to control or implement various operations described herein. These operations may include implementing AI-based tools to analyze industrial processes, creating applications based on analytical information (e.g., SRS) generated by AI-based tools, testing the created applications using AI-based tools, and other processes described herein.
[0078] The above describes example components of a computer system (such as a computer, server, or other data processing system). Output device 1050 and input device 1060 can communicate with processor 1030 via a local bus or network, respectively. The computer system can be a distributed processing system.
[0079] It should also be understood that the exemplary embodiments disclosed and taught herein are susceptible to many different modifications and alternatives. Therefore, the use of singular terms, such as, but not limited to, “a”, is not intended to limit the number of items. Furthermore, the naming conventions used for the various components, functions, features, thresholds, and other elements used herein are provided as examples and may be given different names or labels. The use of the term “or” is not limited to exclusive “or” and may also mean “and / or”.
[0080] It should be understood that the development of actual, real-world commercial applications incorporating aspects of the disclosed embodiments will require numerous implementation-specific decisions to achieve the developer's ultimate goals for the commercial implementation. Such implementation-specific decisions may include, but are not limited to, compliance with system-related, business-related, governmental-related, and other constraints that may vary depending on the specific implementation, location, and time. While the developer's efforts may be complex and time-consuming in an absolute sense, such efforts will be routine for those skilled in the art who benefit from this disclosure.
[0081] Using the description provided herein, example embodiments can be implemented as machines, processes, or articles by using standard programming and / or engineering techniques to produce programming software, firmware, hardware, or any combination thereof.
[0082] Any resulting program having computer-readable program code can be embodied on one or more tangible or non-transitory computer-usable media, such as resident memory devices, smart cards or other removable memory devices, or transmission devices, thereby forming a computer program product or article of manufacture according to the embodiments. Thus, the terms "article of manufacture" and "computer program product" as used herein are intended to cover computer programs that are permanently or temporarily present on any computer-usable or storage medium or in any transmission medium on which such programs are transmitted.
[0083] The processor(s) or controller(s) described herein may be a processing system, which may include one or more processors, such as a CPU, controller, or other processing unit, that control the operation of the device or system described herein. Memory / storage devices may include, but are not limited to: hard disks, solid-state drives, optical disks, removable memory devices (such as smart cards, SIM cards, WIM cards), semiconductor memories (such as RAM, ROM, PROM), etc. Transmission media or networks include, but are not limited to: wireless communication (e.g., radio frequency (RF) communication, Bluetooth). Transmission of Wi-Fi, Li-Fi, etc., the Internet, intranets, telephone / modem-based network communications, hardwired / wired communication networks, satellite communications, and other fixed or mobile network systems / communication links.
[0084] While specific embodiments and applications of this disclosure have been illustrated and described, it should be understood that this disclosure is not limited to the precise constructions and compositions disclosed herein, and various modifications, alterations and variations may be apparent from the foregoing description without departing from the invention as defined in the appended claims.
Claims
1. A method for analyzing process hazards and verifying protection mechanisms in industrial processes, comprising: Communication is established between a simulation tool and a process hazard analysis tool, the simulation tool being configured to simulate the operation of the industrial process based on a process model, the simulation tool and the process hazard analysis tool being executed on one or more computers or across one or more computers; Using the process hazard analysis tool, based on information about the industrial process learned from the simulation tool, conditions for hazards in the industrial process are created; For each of the hazards, the simulation tool is used to simulate the hazard, and an attempt is made to prevent the hazard by using a process hazard analysis tool and introducing one or more protection mechanisms from multiple potential protection mechanisms into the industrial process; The effectiveness of the protective mechanisms introduced for each of the hazards is assessed, and safety requirements are created for the industrial process based on the effectiveness of the assessments. An application program is generated for the safety programmable logic controller in the safety instrumentation system to meet the aforementioned safety requirements; as well as The application was tested to confirm that it could prevent the hazards in the industrial process.
2. The method as described in claim 1, wherein, To simulate the hazard and / or assess its effectiveness, the process hazard analysis tool implements multiple agents for interacting with the simulation tool and for changing the operating conditions in the industrial process simulated by the simulation tool. These agents include: At least one first agent is used to cause hazardous conditions in the industrial process simulated by the simulation tool, and At least one second agent is provided to introduce a protection mechanism to prevent hazardous conditions in the industrial process simulated by the simulation tool.
3. The method as described in claim 2, wherein, To simulate the hazard and / or assess its effectiveness, the process hazard analysis tool is configured as follows: Initiate multiple adversarial proxy groups, each of which includes a first proxy and a second proxy; For each adversarial agent group, one or more inputs associated with the process model are randomly assigned for use by the adversarial agent group to control the operational state of the industrial process simulated by the simulation tool; For each adversarial agent group, reward points are assigned when the respective first agent increases the chance of the associated danger and / or when the respective second agent decreases the chance of the associated danger; For each adversarial agent group, based on the interaction between the first agent and the second agent of the adversarial agent group, a protection configuration including a protection layer for the associated danger is created; For each adversarial agent group, a reward score is calculated for the adversarial agent group based on the accumulated reward points of the adversarial agent group using a reward function; as well as Duplicate adversarial agent groups are eliminated from the plurality of adversarial agent groups based on their reward scores.
4. The method of claim 3, wherein the process hazard analysis tool creates safety requirements for the industrial process based on the protection configurations of the remaining adversarial agent groups from the plurality of adversarial agent groups.
5. The method of claim 4, wherein, The application was tested using the process hazard analysis tool and the simulation tool to confirm that the application could prevent the hazards in the industrial process, wherein the first agent of the process hazard analysis tool caused hazardous conditions in the industrial process simulated by the simulation tool, and the application prevented the hazardous conditions in the industrial process simulated by the simulation tool.
6. The method of claim 2, wherein the process hazard analysis tool is further configured to generate a causal matrix relating to the inputs and outputs of the simulation tool when simulating the industrial process, and to create the safety requirements based on the causal matrix.
7. The method of claim 6, wherein the input includes the second agent adding a protection mechanism to the industrial process simulated by the simulation tool.
8. The method of claim 6, wherein, The output includes the state of the operating conditions of the industrial process as simulated by the simulation tool.
9. The method of claim 2, wherein the protection mechanism comprises at least one safety instrumentation system, the safety instrumentation system comprising a set of equipment designed to reduce the risk arising from a specific hazard.
10. The method of claim 2, wherein the first agent and / or the second agent is configured to control and monitor operating conditions in the industrial process simulated by the simulation tool according to the process model constrained by physical laws, scientific laws, and / or natural laws.
11. A system for analyzing process hazards and verifying protection mechanisms in industrial processes, comprising: Memory; as well as One or more processors, said one or more processors being configured to: Communication is established between a simulation tool and a process hazard analysis tool, the simulation tool being configured to simulate the operation of the industrial process based on a process model, the simulation tool and the process hazard analysis tool being executed on one or more computers or across one or more computers; Using the process hazard analysis tool, based on information about the industrial process learned from the simulation tool, conditions for hazards in the industrial process are created; For each of the hazards, the simulation tool is used to simulate the hazard, and an attempt is made to prevent the hazard by using a process hazard analysis tool and introducing one or more protection mechanisms from multiple potential protection mechanisms into the industrial process; The effectiveness of the protective mechanisms introduced for each of the hazards is assessed, and safety requirements are created for the industrial process based on the effectiveness of the assessments. An application program is generated for the safety programmable logic controller in the safety instrumentation system to meet the aforementioned safety requirements; as well as The application was tested to confirm that it could prevent the hazards in the industrial process.
12. The system of claim 11, wherein, To simulate the hazard and / or assess its effectiveness, the process hazard analysis tool implements multiple agents for interacting with the simulation tool and for changing the operating conditions in the industrial process simulated by the simulation tool. These agents include: At least one first agent is used to cause hazardous conditions in the industrial process simulated by the simulation tool, and At least one second agent is provided to introduce a protection mechanism to prevent hazardous conditions in the industrial process simulated by the simulation tool.
13. The system of claim 12, wherein, To simulate the hazard and / or assess its effectiveness, the process hazard analysis tool is configured as follows: Initiate multiple adversarial proxy groups, each of which includes a first proxy and a second proxy; For each adversarial agent group, one or more inputs associated with the process model are randomly assigned for use by the adversarial agent group to control the operational state of the industrial process simulated by the simulation tool; For each adversarial agent group, reward points are assigned when the respective first agent increases the chance of the associated danger and / or when the respective second agent decreases the chance of the associated danger; For each adversarial agent group, based on the interaction between the first agent and the second agent of the adversarial agent group, a protection configuration including a protection layer for the associated danger is created; For each adversarial agent group, a reward score is calculated for the adversarial agent group based on the accumulated reward points of the adversarial agent group using a reward function; as well as Eliminate duplicate (one or more) adversarial agent groups from the plurality of adversarial agent groups based on their reward scores.
14. The system of claim 13, wherein the process hazard analysis tool creates safety requirements for the industrial process based on the protection configurations of the remaining adversarial agent groups from the plurality of adversarial agent groups.
15. The system of claim 14, wherein, The application was tested using the process hazard analysis tool and the simulation tool to confirm that the application could prevent the hazards in the industrial process, wherein the first agent of the process hazard analysis tool caused hazardous conditions in the industrial process simulated by the simulation tool, and the application prevented the hazardous conditions in the industrial process simulated by the simulation tool.
16. The system of claim 12, wherein the process hazard analysis tool is further configured to generate a causal matrix relating to the inputs and outputs of the simulation tool when simulating the industrial process, and to create the safety requirements based on the causal matrix.
17. The system of claim 16, wherein the input includes the second agent adding a protection mechanism to the industrial process simulated by the simulation tool.
18. The system of claim 16, wherein, The output includes the state of the operating conditions of the industrial process as simulated by the simulation tool.
19. The system of claim 12, wherein the protection mechanism comprises at least one safety instrumentation system, the safety instrumentation system comprising a set of equipment designed to reduce the risk arising from a specific hazard.
20. The system of claim 12, wherein the first agent and / or the second agent is configured to control and monitor operating conditions in the industrial process simulated by the simulation tool according to the process model constrained by physical laws, scientific laws and / or natural laws.
21. A tangible computer medium storing computer-executable code, which, when executed by one or more processors, is configured to implement a method for analyzing process hazards and verifying protection mechanisms for industrial processes, the method comprising: Communication is established between a simulation tool and a process hazard analysis tool, the simulation tool being configured to simulate the operation of the industrial process based on a process model, the simulation tool and the process hazard analysis tool being executed on one or more computers or across one or more computers; Using the process hazard analysis tool, based on information about the industrial process learned from the simulation tool, conditions for hazards in the industrial process are created; For each of the hazards, the simulation tool is used to simulate the hazard, and an attempt is made to prevent the hazard by using a process hazard analysis tool and introducing one or more protection mechanisms from multiple potential protection mechanisms into the industrial process; The effectiveness of the protective mechanisms introduced for each of the hazards is assessed, and safety requirements are created for the industrial process based on the effectiveness of the assessments. An application program is generated for the safety programmable logic controller in the safety instrumentation system to meet the aforementioned safety requirements; as well as The application was tested to confirm that it could prevent the hazards in the industrial process.
22. A method for analyzing process hazards and protection mechanisms in industrial processes, comprising: Simulate industrial processes based on process models; Introducing hazards into the simulation of the industrial process; One or more protection mechanisms from multiple potential protection mechanisms are introduced into the simulation of the industrial process to defend against introduced hazards; The effectiveness of the protection mechanisms introduced in the simulation of the industrial process is assessed for the hazards introduced, and safety requirements are created for the industrial process based on the effectiveness of the assessment. as well as An application is generated for the controller in the safety instrumentation system to meet the aforementioned safety requirements.
23. The method of claim 22, further comprising: The application was tested against a hazard in another simulation of the industrial process to confirm that the application could prevent the hazard in the industrial process.
24. The method of claim 22, wherein, Introducing hazards and / or assessing effectiveness employs multiple agents for interacting with the simulation of the industrial process and for changing the operating conditions in the simulation of the industrial process, said multiple agents including: At least one first agent is used to cause dangerous conditions to be introduced into the simulation of the industrial process, and At least one second agent is provided to introduce a protection mechanism to prevent hazardous conditions in the simulation of the industrial process.
25. The method of claim 24, wherein, Introducing hazards and / or assessing effectiveness includes: Initiate multiple adversarial proxy groups, each of which includes a first proxy and a second proxy; For each adversarial agent group, one or more inputs associated with the process model are randomly assigned for use by the adversarial agent group to control the operational state of the simulated industrial process; For each adversarial agent group, reward points are assigned when the respective first agent increases the chance of the associated danger and / or when the respective second agent decreases the chance of the associated danger; For each adversarial agent group, based on the interaction between the first agent and the second agent of the adversarial agent group, a protection configuration including a protection layer for the associated danger is created; For each adversarial agent group, a reward score is calculated for that adversarial agent group based on its accumulated reward points using a reward function; and Duplicate adversarial agent groups are eliminated from the plurality of adversarial agent groups based on their reward scores.
26. The method of claim 25, wherein, The security requirements for the industrial process are created based on the protection configurations of the remaining adversarial agent groups from the plurality of adversarial agent groups.
27. The method of claim 26, further comprising: The application was tested in another simulation of the industrial process, in which the first agent caused the introduction of hazardous conditions in the other simulation of the industrial process, and the application prevented the hazardous conditions in the other simulation of the industrial process.
28. The method of claim 24, further comprising: Generate a causal matrix relating the inputs to the simulation leading to the industrial process and the outputs from the simulation of the industrial process. The security requirements are created based on the causal matrix, and the inputs include the addition of protection mechanisms to the simulation of the industrial process by the second agent, and / or the output includes the state of the operating conditions of the simulation of the industrial process.
29. The method of claim 24, wherein, The protection mechanism includes at least one safety instrumentation system, which comprises a set of equipment designed to reduce the risk caused by a specific hazard.
30. The method of claim 24, wherein, The first agent and / or the second agent are configured to control and monitor the operating conditions in the simulation of the industrial process according to the process model constrained by physical laws, scientific laws and / or natural laws.
31. A system for analyzing process hazards and protection mechanisms in industrial processes, comprising: Memory; and One or more processors are configured as follows: Simulate industrial processes based on process models; Introducing hazards into the simulation of the industrial process; One or more protection mechanisms from multiple potential protection mechanisms are introduced into the simulation of the industrial process to defend against introduced hazards; The effectiveness of the protection mechanisms introduced in the simulation of the industrial process is assessed for the hazards introduced, and safety requirements are created for the industrial process based on the effectiveness of the assessment. as well as An application is generated for the controller in the safety instrumentation system to meet the aforementioned safety requirements.
32. The system of claim 31, wherein, The one or more controllers are further configured to test the application against a hazard in another simulation of the industrial process to confirm that the application can prevent the hazard in the industrial process.
33. The system of claim 31, wherein, To introduce hazards and / or assess effectiveness, the one or more controllers are configured to employ multiple agents for interacting with the simulation of the industrial process and for changing the operating conditions in the simulation of the industrial process, the multiple agents including: At least one first agent is used to cause dangerous conditions in the simulation of the industrial process, and At least one second agent is provided to introduce a protection mechanism to prevent hazardous conditions in the simulation of the industrial process.
34. The system of claim 33, wherein, In order to introduce hazards and / or assess effectiveness, the one or more controllers are configured to: Initiate multiple adversarial proxy groups, each of which includes a first proxy and a second proxy; For each adversarial agent group, one or more inputs associated with the process model are randomly assigned for use by the adversarial agent group to control the operational state of the simulated industrial process; For each adversarial agent group, reward points are assigned when the respective first agent increases the chance of the associated danger and / or when the respective second agent decreases the chance of the associated danger; For each adversarial agent group, based on the interaction between the first agent and the second agent of the adversarial agent group, a protection configuration including a protection layer for the associated danger is created; For each adversarial agent group, a reward score is calculated for the adversarial agent group based on the accumulated reward points of the adversarial agent group using a reward function; as well as Duplicate adversarial agent groups are eliminated from the plurality of adversarial agent groups based on their reward scores.
35. The system of claim 34, wherein, The security requirements for the industrial process are created based on the protection configurations of the remaining adversarial agent groups from the plurality of adversarial agent groups.
36. The system of claim 35, wherein, The one or more controllers are further configured to: The application is tested in another simulation of the industrial process, whereby the first agent causes hazardous conditions in the other simulation of the industrial process, and the application prevents the hazardous conditions in the other simulation of the industrial process.
37. The system of claim 33, wherein, The one or more controllers are further configured to: Generate a causal matrix relating the inputs to the simulation leading to the industrial process and the outputs from the simulation of the industrial process. The security requirements are created based on the causal matrix, and the inputs include the addition of protection mechanisms to the simulation of the industrial process by the second agent, and / or the output includes the state of the operating conditions of the simulation of the industrial process.
38. The system of claim 33, wherein, The protection mechanism includes at least one safety instrumentation system, which comprises a set of equipment designed to reduce the risk caused by a specific hazard.
39. The system of claim 33, wherein, The first agent and / or the second agent are configured to control and monitor the operating conditions in the simulation of the industrial process according to the process model constrained by physical laws, scientific laws and / or natural laws.
40. A non-transitory computer medium storing computer-executable code, said computer-executable code, when executed by one or more processors, configured to implement a method for analyzing process hazards and protection mechanisms for industrial processes, said method comprising: Simulate industrial processes based on process models; Introducing hazards into the simulation of the industrial process; One or more protection mechanisms from multiple potential protection mechanisms are introduced into the simulation of the industrial process to defend against introduced hazards; The effectiveness of the protection mechanisms introduced in the simulation of the industrial process is assessed for the hazards introduced, and safety requirements are created for the industrial process based on the effectiveness of the assessment. as well as An application is generated for the controller in the safety instrumentation system to meet the aforementioned safety requirements.
41. The non-transitory computer medium as claimed in claim 40, wherein, The method further includes: The application was tested against a hazard in another simulation of the industrial process to confirm that the application could prevent the hazard in the industrial process.