Safety interlock recommendation system

By combining edge devices and cloud platforms, a safety interlock recommendation system utilizes machine learning to analyze process data in real time, identify potential safety interlock events, and provide proactive suggestions. This solves the problems of workflow interruptions and frequent safety event triggering caused by reactive management in existing technologies, and achieves efficient and safe industrial process management.

CN116097252BActive Publication Date: 2026-08-04ABB (SCHWEIZ) AG
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ABB (SCHWEIZ) AG
Filing Date
2021-09-14
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

Existing safety interlocking systems are mainly based on reactive management, which leads to workflow interruptions and frequent triggering of safety incidents. They are difficult to effectively utilize the experience and lessons learned by human operators and lack early identification and proactive prevention of potential safety interlocking events.

Method used

The safety interlock recommendation system, which combines edge devices and cloud platforms, analyzes process data in real time through online and offline machine learning models, identifies potential safety interlock events, and provides proactive action suggestions. It is continuously improved by incorporating feedback from human experts.

Benefits of technology

It enables proactive safety management of industrial processes, reduces the triggering of safety interlock events, improves production efficiency and safety, reduces costs, and continuously optimizes safety design using machine learning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116097252B_ABST
    Figure CN116097252B_ABST
Patent Text Reader

Abstract

The present invention relates to a safety interlock recommendation system (10), comprising at least one process data source (20) and an edge device (30), wherein the process data source (20) is configured to provide IOS device flow data (Dp) to the edge device (30); wherein the edge device (30) includes an operational technology edge application unit (31), namely an OT edge application unit, and a flow analysis unit (32); wherein the OT edge application unit (31) is configured to provide operational technology flow data, namely OT flow data (Dot); wherein the flow analysis unit (32) includes an online machine learning model configured to determine online analysis data (Daon) using the provided process flow data (Dp) and the provided OT flow data (Dot); wherein the OT edge application unit (31) is configured to determine short-term recommendations (Rs) using the online analysis data (Daon).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a safety interlock recommendation system and its control method. Background Technology

[0002] Most safety interlock logic is designed to reactively manage rather than proactively manage unwanted situations. This approach waits for unwanted situations to occur—for example, designated as causes in the Cause & Effect (C&E) matrix—and then deals with them—for example, designated as results in the C&E matrix—rather than taking actions to fundamentally prevent them from happening. Furthermore, human operators do not directly monitor the likelihood of impending interlocks but manage alarms triggered by discrete values ​​reaching predetermined thresholds and act accordingly. Therefore, when events actually occur, human operators are suited to handle them. This reactive approach leads to workflow disruptions and ultimate losses, either in the form of plant, plant area, or equipment shutdowns, or in more critical forms such as property damage, environmental impact, or even personal injury. Consequently, the process loses productivity for maintenance and repair.

[0003] A reactive approach to managing interlocking scenarios begins, for example, with an explicit analysis of pre-defined elements in the interlocking logic using a C&E matrix. Restricting management to a reactive style prevents potential improvements through exploration and continuous learning from being influenced by existing data on the process and its interlocks. Using traditional engineering methods and human analysis to exert human effort to comprehensively cover all alternative factors and their combinations is complex. This complexity increases the number of variables in large plants and processes. It can also lead to difficulties in inferring the relationships between actual process causes and effects that were considered irrelevant during interlocking system design and are difficult to deduce without the aid of analyzing large amounts of process data.

[0004] Furthermore, without sufficient documentation, the human decisions made by experts in response to specific interlocking situations, such as adjusting the high-high level threshold of a container, cannot be recognized. Even when these decisions and their rationale are documented, they are often attributed to their costly investment, as they remain difficult to retrieve and reuse effectively. This loss of accumulated lessons complicates the process of achieving mature and stable safety sensitivity through continuous improvement.

[0005] Therefore, improved technologies for replacing industrial process data sources may be advantageous. Summary of the Invention

[0006] The object of the invention is achieved by the subject matter of the independent claims, wherein other embodiments are incorporated in the dependent claims.

[0007] In a first aspect, a safety interlock recommendation system is provided, comprising at least one process data source and an edge device. The process data source is configured to provide process flow data to the edge device. The edge device includes an Operational Technology Edge Application Unit (OT Edge Application Unit) and a Flow Analysis Unit. The OT Edge Application Unit is configured to provide Operational Technology Flow Data, i.e., OT Flow Data. The Flow Analysis Unit includes an online machine learning model configured to determine online analytical data using the provided process flow data and the provided OT Flow Data. The OT Edge Application Unit is configured to determine short-term recommendations using the online analytical data.

[0008] Preferably, the stream analysis unit is configured to determine short-term recommendations in real time.

[0009] Preferably, exploratory analysis reveals interlock indicators that include early signs of potential safety interlock events, the actual root cause of potential safety interlock events, and / or contributing causal factors that could lead to undesirable situations that could result in potential safety interlock events. Interlock indicators that cannot be captured are captured by using known confined alarm systems and their predetermined measures and thresholds. For example, conventional confined monitoring of container overflow is accomplished through confined monitoring of a predetermined high-level alarm (e.g., 70% container fill), which precedes a high-high-level alarm (e.g., 90% container fill). Exploratory analysis allows for the identification of interlock indicators, in this case, early signs of overflow. Interlock indicators include common patterns of change within observed flow data (specifically, sensor data from the process data source). In this case, common patterns of change observed involve container level readings and readings from other sensors, such as pumping rates at the upstream pump, flow rates at the outlet pipe, and / or the percentage of valve opening in the upstream section of the equipment.

[0010] Preferably, short-term recommendations are used to initiate proactive actions to prevent potential safety interlock events in industrial plants.

[0011] As used in this article, the term "process data source" includes any process flow data source (specifically, intelligent field devices that may have their own reporting data, such as Internet of Things (IoT) devices) as well as traditional process data sources that can be connected to a control system platform.

[0012] As used in this document, the term "edge device" refers to a self-owned device capable of collecting data and performing rapid on-site analysis, computation, filtering, and preparing the data for uploading to a higher level, such as a cloud platform that performs storage, longer-term, and more complex computations. Therefore, edge devices include Internet of Things (IoT) edge devices or classic distributed control systems (DCS), specifically, classic DCS disconnected from the Internet.

[0013] As used herein, the term "process flow data" includes real-time operational data, specifically, real-time operational data from a process data source or another edge device. Process flow data includes real-time data provided by a process data source.

[0014] As used herein, the term "OT stream data" includes security-related data from operational technology application units hosted on edge devices. Operational technology application units preferably include alarm systems and process control systems. OT stream data preferably includes security-related data from operational application technology units hosted on edge devices.

[0015] Preferably, the operational technology unit includes an OT edge application. The OT edge application relates to applications for operating process data sources and OT edge devices. Preferably, the OT edge application is supervised or at least partially controlled by a user acting as a human operator. Preferably, the OT edge application includes process control systems, alarm systems, and / or safety interlock applications. The process control system is configured to manage the executed process, including providing operational instructions to the process data source for controlling the process data source.

[0016] Preferably, as used herein, the term "user" includes human operators, specifically, human operators operating in an industrial environment. For example, a user refers to a human operator manipulating an industrial process within an industrial plant.

[0017] As used in this article, the term "edge device" refers to an edge computing device located close to a controlled process data source, thereby allowing low-latency communication with the process data source.

[0018] Preferably, the online machine learning model is referred to as an interlocking flow operation recommender. Hosted in an edge device, the online machine learning model aims to improve short-term operations by proactively identifying impending interlocking situations and recommending actions for human operators. For example, if a container is approaching a low-to-low level that could stop the pump and affect downstream operations, consider increasing the flow rate at its inlet for a specific time period (e.g., 10 minutes). Preferably, the pre-trained online machine learning model continuously explores OT flow data and reacts in near real-time. This proximity of the edge device to the controlled process data source, specifically, along with low latency achieved using latent variable modeling, where discrete observations correlate with theoretically continuous, known data curves that cannot be directly measured, is crucial for time-critical safety situations.

[0019] Preferably, the process data source includes at least one sensor, at least one actuator, at least one controller and / or at least one human input interface, each configured to provide streaming data.

[0020] Preferably, the edge device provides continuous streaming data processing with low response time. This allows for the determination of real-time recommendations.

[0021] Therefore, edge devices allow for short-term operational improvements by proactively identifying impending interlocking situations and recommending actions for the user. For example, if a container is approaching a low-to-low level that could stop the pump and affect downstream conditions, it is recommended to consider increasing the flow rate at its inlet for a specific time period (e.g., 10 minutes).

[0022] Therefore, safety interlock recommendation systems allow the use of machine learning capabilities to support proactive management of safety interlocks in industrial processes. Proactive systems do not replace the original reactive approach, but rather refine it by using early identification of the accessibility of undesirable situations and how to handle them.

[0023] The provided safety interlock recommendation system enables effective and safe operation of industrial plants. For example, in industrial plants where poorly tuned instruments and loops frequently trigger interlocks, the system proactively predicts operational problems and thoroughly analyzes them to identify the root causes.

[0024] The provided safety interlock recommendation system achieves effective safety design. The system monitors and analyzes safety-related events to identify potential design improvements, thereby reducing the triggering of safety-related interlocks.

[0025] The safety interlock recommendation system provided ensures safety. Even in plants where loops and interlocks are operating effectively, our proposed solution can monitor safety conditions by continuously analyzing plant event history and helps prevent operations from approaching safety critical conditions.

[0026] The proposed safety interlock recommendation system achieves low cost. Implementing this system as a product is relatively inexpensive because it requires no additional hardware and can potentially operate in parallel with the control system, collecting data and producing results without interfering with actual operation.

[0027] Therefore, an improved safety interlock recommendation system is provided.

[0028] In a preferred embodiment, the streaming data includes dynamic time-series data that is directly related to controlled processes in the industrial plant.

[0029] In a preferred embodiment, the online machine learning model performs online exploratory analysis to determine online analytical data. Online exploratory analysis includes association mining and root cause analysis.

[0030] In other words, the online machine learning model begins with the discovery of correlations between input elements and continues with root cause analysis. Based on this root cause analysis, the online machine learning model outputs online recommendations for proactive actions to avoid potential safety interlocking events.

[0031] In the context of container overflow instances, exploratory analysis allows early signs of overflow to be identified as patterns in which the observed level readings of the targeted container change in conjunction with readings from other sensors, such as the pumping rate of the upstream pump, the flow rate ratio in the outlet pipe, and / or the percentage of valve opening in the upstream section of the equipment.

[0032] Therefore, an improved safety interlock recommendation system is provided.

[0033] In a preferred embodiment, correlation mining includes: detecting operational patterns in streaming data including process flow data and OT flow data, and wherein root cause analysis includes: detecting root causes in the streaming data for potential safety interlock events.

[0034] In a preferred embodiment, the interlocking safety recommendation system includes a cloud platform. Edge devices are configured to use stored streaming data to determine batch data. The cloud platform includes a batch analytics unit and a cloud application unit. The batch analytics unit includes an offline machine learning model configured to use the batch data to determine offline analytics data. The cloud application unit is configured to use the offline analytics data to determine long-term operational recommendations.

[0035] As used in this article, the term "batch data" includes both OT stream data and process stream data collected over time. Therefore, further processing of batch data does indeed lead to non-real-time analysis.

[0036] Preferably, long-term operational recommendations are also known as non-real-time operational recommendations because, compared to short-term recommendations, long-term operational recommendations are determined based on batch data rather than real-time data.

[0037] Preferably, the cloud platform provides periodic processing of batch data with high precision. This enables long-term operation recommendations, specifically operation recommendations and / or engineered recommendations. Preferably, the long-term operation recommendations are referred to as non-real-time operation recommendations.

[0038] Although edge devices have advantages over cloud platforms in terms of timing, their processing and data storage capabilities are limited.

[0039] Therefore, edge devices and cloud platforms offer a combination of streaming data processing and batch data processing.

[0040] Preferably, the results from edge devices and cloud platforms are presented to human operators and interlocking engineers through interactive applications and web services.

[0041] Therefore, the safety interlock recommendation system employs a hybrid processing technique that combines streaming data processing with batch data processing. On one hand, edge devices provide continuous streaming data processing with high response times, which is crucial for real-time operational recommendations. On the other hand, the cloud platform provides periodic batch processing with high accuracy, which is required for longer-term operational and engineered recommendations.

[0042] Therefore, an improved safety interlock recommendation system is provided.

[0043] In a preferred embodiment, the offline machine learning model performs offline exploratory analysis to determine offline analysis data. Offline exploratory analysis includes association mining and root cause analysis.

[0044] In a preferred embodiment, correlation mining includes detecting operational patterns in a batch of data, and root cause analysis includes detecting root causes in the batch of data for potential security interlock events.

[0045] Association mining includes identifying patterns of recurrence of interlocking alarms or incidents that are inconsistent with the causes initially specified in the interlocking logic, such as causes in the causality matrix (C&E matrix), and root causes identified based on machine learning that have been accepted by human operators.

[0046] Therefore, an improved safety interlock recommendation system is provided.

[0047] In a preferred embodiment, the cloud platform includes a cloud storage device. The cloud storage device is configured to provide stored data to the batch analysis unit. The stored data includes additional stored data related to the security interlock recommendation system. An offline machine learning model is configured to use the provided stored data to determine offline analysis data.

[0048] Preferably, the stored data includes information technology stored data, i.e., IT stored data, operational technology stored data, i.e., OT stored data, and safety interlock recommendation stored data. IT stored data includes interlock designs (e.g., causal matrices) and input-output list data defining at least some of the inputs and outputs of industrial plant components. OT stored data includes operational data, safety interlock incidents, and alarm events. Safety interlock recommendation stored data includes operational recommender logs (tracking previous long-term operational recommendations) and reengineering recommender logs (tracking previous reengineering recommendations).

[0049] Therefore, an improved safety interlock recommendation system is provided.

[0050] In a preferred embodiment, the cloud application unit is configured to use offline analytics data to determine reengineering recommendations. These reengineering recommendations include potential design enhancements to existing interlocking logic.

[0051] Preferably, the interlocking logic includes a threshold for a security interlocking recommendation system used to activate security interlocking events.

[0052] Reengineering recommendations might involve tuning some safety thresholds, introducing new interlocks, or editing suboptimal interlock causes or consequences. For example, if a container overflow interlock is currently designed to only monitor the container level and close the inlet valve as a consequence, reengineering recommendations could suggest adding the upstream pump speed as an additional cause for monitoring. Having this component in the cloud allows it to perform heavy computations on the massive amounts of data present in cloud storage devices.

[0053] Preferably, the offline machine learning model includes an interlock batch reengineering recommender hosted in the cloud, aimed at long-term engineering improvements by identifying potential design enhancements to existing interlock logic and recommending them to users (specifically, safety interlock engineers). Preferably, the reengineering recommendations concern tuning some safety thresholds, introducing new interlocks, or editing suboptimal interlock causes or consequences; for example, if a container overflow interlock is currently designed to only monitor the container level and close the inlet valve as a consequence, the system could recommend adding the speed of the pre-pump as an additional cause for monitoring. Having an offline machine learning model component in the cloud allows it to perform heavy computations on the massive amounts of data present in cloud storage.

[0054] For example, if a safety interlock for a specific container overflow is designed in the interlock logic to monitor the container level and close its inlet as a response action, but it also has some repeatedly accepted recommendations regarding another suggested root cause (such as the speed of the upstream pump), then an offline machine learning model recommends adding the speed of the upstream pump as an additional cause element in the interlock design. Finally, improvements to the interlock logic are reflected in the robustness of the safety of the process it controls.

[0055] Therefore, an improved safety interlock recommendation system is provided.

[0056] In a preferred embodiment, the cloud application unit is configured to use the provided storage data to determine long-term engineering recommendations and / or long-term operational recommendations.

[0057] Preferably, the association mining and root cause analysis for the offline machine learning model are generated by training the ML algorithm on a cloud storage device (e.g., a repository of operational data, safety incidents and alarm events, I / O information, interlocking designs, etc.). However, this is not the end of the training phase, but rather the first iteration, as the system aims to be a "continuous learner." To achieve this, the system maintains logs for recommendations generated by operating and reengineered components that have timed out, as well as offline feedback from human operators on them (e.g., decisions to accept, reject, or edit ML recommendations). These logs can then be used to retrain the ML algorithm and update the offline machine learning model to improve the quality of offline analysis data and long-term operational and reengineered recommendations. This automatic reuse of acquired human knowledge facilitates continuous improvement of internal plant processes within their context.

[0058] In a preferred embodiment, the edge device is configured to receive online user feedback regarding previous short-term recommendations. The online machine learning model is configured to be retrained using the online user feedback.

[0059] In a preferred embodiment, the cloud storage device is configured to receive offline user feedback regarding previous long-term operational recommendations and / or previously reengineered recommendations. The offline machine learning model is configured to be retrained using this offline user feedback.

[0060] In a preferred embodiment, the online machine learning model and / or the offline machine learning model uses a Bayesian network.

[0061] To fully perform root cause analysis, it is important to determine which data elements to include in the analysis, and two main techniques can be used. The first is raw data analysis using the collected data holistically; the second is a feature-based approach where relevant data elements are selected as individual observations. Note that classical statistical methods used for association mining and root cause analysis are found to be ineffective for low-frequency interlocking scenarios because there are typically few records in static log databases. Similarly, using decision tree learning is not feasible because it requires a large dataset for training and testing the model, and the decision tree learning along the guiding observations (or in other words, tree nodes) has a good interpretation of the decisions. In contrast, Bayesian Decision Theory (BDT), for example, implemented using Bayesian networks, performs well in this scenario. BDT uses the probability and risk of observed patterns to quantify the trade-offs between various classifications (i.e., regular normal situations and different undesirable interlocking scenarios). These patterns are identified as deviations in the values ​​of data elements between regular and interlocking scenarios, such as deviations in signal amplitude, period, or synchronization phase. The advantage of Bayesian Data Theory (BDT) lies in its ability to incrementally evaluate data as it becomes available, without requiring prior information about process variables or the types of anomalies that might be encountered. That is, it updates the predicted probabilities of interlocks as more evidence (i.e., interlock records) becomes available, thus it does not need to start with a dataset containing many frequent records for each interlock. Therefore, using a Bayesian algorithm to build a predictive model is better suited for forecasting security interlocks, their associated causes, the equipment involved, and their consequences. Cross-validation techniques should be used to validate the model and check its predictive accuracy. Furthermore, it may be useful to model unusually rare interlocks by utilizing extremum theory to establish a distribution of interlock scenarios across thresholds.

[0062] Typically, keeping human experts in the loop is unavoidable. While the goal is to automate root cause analysis and reduce reliance on expert knowledge, maintaining critical field experts to monitor, validate, and manage the root cause analysis process, and to ensure all relevant parameters are taken into account, remains crucial. Therefore, for human experts in the loop, whether "safety interlock designers" or "human operators," a deep understanding of the hazards and risks associated with the interlocking process and its instrumentation is essential. Their strong decision-making skills are also critical, as they impact process safety in both the short and long term. Additionally, as with all ML-based solutions, data quality is a critical success factor and should therefore be properly maintained, taking into account consistency across different input sources.

[0063] According to another aspect of the present invention, a method for recommending safety interlocks includes the steps of: providing streaming data to an edge device via a process data source, the edge device including an Operation Technology Unit (OT) and a Streaming Analysis Unit. The method further includes the step of: providing operational technology streaming data, i.e., OT streaming data, via an edge device unit including an Operation Technology Edge Application Unit (OT Edge Application Unit) and a Streaming Analysis Unit. The method further includes the step of: an online machine learning model of the Streaming Analysis Unit performing exploratory analysis using the provided streaming data and the provided OT data to determine online analysis data. The method further includes the step of: determining short-term recommendations using the online analysis data.

[0064] Therefore, this method can be adapted to run and / or be virtualized on existing hardware infrastructure, thus requiring minimal or no additional hardware costs.

[0065] According to another aspect of the invention, a computer program is provided, including instructions that, when executed by a computer, cause the computer to perform a method for recommending safety interlocks as described herein.

[0066] Preferably, the simulation feature is implemented within the safety interlock recommendation system, where users can change the values ​​of some process safety-related parameters to see the results of the changes before actually implementing them on the operating process. For example, users can test changes in the operating level by examining how safety predictions look when a specific valve is open or closed. This can also be used to test changes in the design level by simulating the results of altering existing interlock designs or adding entirely new interlocks.

[0067] Although the system is designed for safety interlocks, it can be applied to process interlocks to enhance process performance, not just safety, assuming that more data is available for process interlock events and their triggering process variables compared to safety interlock events. Therefore, the system can help identify and resolve poor automation performance, such as instability, poor process operation (e.g., operating too close to extreme conditions), poor interlock design, and even poor process design. For example, at the operational level, it helps operators understand the accessibility of process interlocks. For instance, to understand that a process interlock will stop a pump supplying a fluid tank when it is empty, since a pump stoppage will stop or slow down the downstream process, it is certainly valuable to help predict when such conditions might occur. Preferably, the cost of triggering process interlocks based on historical information about process interruptions and shutdowns is known. Preferably, applications such as dashboards and simulation features are very helpful for operators and process engineers in proactively improving process performance.

[0068] More preferably, machine learning-based recommendations are combined at the operational and engineering level with a “technical explanation” of how the model arrives at such recommendations. For example, if a decision tree algorithm is used to build the model, it can simply represent the path taken to reach a particular recommendation. This can be achieved using existing interpretable A1 libraries (e.g., ELI5, Shap, etc.). However, given an A1 explanation, it can become very complex and difficult to interpret for other advanced ML algorithms (such as neural networks). Therefore, they may be difficult for human operators or interlocking engineers to interpret. In summary, the current state of these interpretable A1 libraries primarily helps data scientists understand the behavior of ML models, but extensive ongoing research and efforts are needed to expand the level of explanation to provide end-users.

[0069] The above aspects and examples will become apparent and illustrated with reference to the embodiments described below. Attached Figure Description

[0070] The following describes exemplary embodiments with reference to the accompanying drawings:

[0071] Figure 1 An embodiment of the safety interlock recommendation system is shown;

[0072] Figure 2 An embodiment of a method for recommending safety interlocks is shown;

[0073] Figure 3 Another embodiment of the safety interlock recommendation system is shown;

[0074] Figure 4 This illustrates the process of preparing a machine learning model for a safety interlocking recommendation system; and

[0075] Figure 5 Another embodiment of a method for recommending safety interlocks is shown. Detailed Implementation

[0076] Figure 1A safety interlock recommendation system 10 is described, comprising multiple process data sources 20 and edge devices 30. The edge devices include sensors, actuators, controllers (whose process-related data can be grouped under one or more control system platforms), and input interfaces (specifically, manual input interfaces). Process data sources 20 are configured to provide process flow data DP to edge devices 30. Edge devices 30 include an Operation Technology Unit 31, i.e., an OT unit, and a Flow Analysis Unit 32. The OT edge application unit 31 is configured to provide operation technology flow data, i.e., OT flow data Dot. The Flow Analysis Unit 32 includes an online machine learning model configured to determine online analysis data Daon using the provided process flow data DP and the provided OT flow data Dot. The OT edge application unit 31 is configured to determine short-term recommendations Rs using the online analysis data Daon. The OT edge application unit 31 is also configured to provide operation instructions C to process data sources 20 to improve control of process data sources 20, specifically using short-term recommendations Rs.

[0077] Figure 2 A method for recommending safety interlocks is described, comprising the following steps: In a first step S10, process flow data DP is provided to an edge device 30 via a process data source 20. The edge device 30 includes an Operation Technology Edge Application Unit 31 (OT Edge Application Unit) and a flow analysis unit 32. In a second step S20, operation technology flow data, i.e., OT flow data, is provided via the OT Edge Application Unit 31. In a third step S30, the online machine learning model of the flow analysis unit 32 performs exploratory analysis using the provided flow data and the provided OT data to determine the online analysis data Daon. In a fourth step S40, the online analysis data Daon is used to determine a short-term recommendation Rs.

[0078] Figure 3 Shown in a more detailed view Figure 1 Another embodiment of the security interlock recommendation system. Edge device 30 includes an OT edge application unit 31, a stream analysis unit 32, an edge device storage device 33, and an edge device data manager 34. Edge device data manager 34 includes an ingestion unit 34a, an enrichment unit 34b, and a processing unit 34c. The security interlock recommendation system 10 also includes a cloud platform 40. Cloud platform 40 includes a batch analysis unit 41, a data conduit 42, a cloud storage device 43, and a cloud application unit 44. Cloud storage device 43 includes an information technology storage device 43a (IT storage), an operational technology storage device 43b (OT storage), and a recommendation storage device 43c.

[0079] Process data source 20 provides process flow data DP, which is real-time dynamic time-series data directly related to the controlled process executed by process data source 20. Process flow data DP includes, for example, equipment temperature, pressure, flow rate, and / or on / off status. Process flow data DP is continuously collected from different levels of the industrial plant (specifically, an industrial safety system including a safety interlock recommendation system), i.e., data including process alarms and control data is collected from the process control layer, data including safety trips and interlock data is collected from the safety protection layer with its shutdown system, and data including consequences reduction via pressure reducing (relief) valves and fire and gas data is collected from the mitigation layer with its emergency response.

[0080] Furthermore, the process data source 20 includes an input interface that provides users (specifically, human operators or safety interlock engineers) with the option to manually enter other safety-related input channels, such as information about the status of the ruptured disc. Additionally, users are provided with the option to manually enter and edit information fields or even complete events to address lost data or data that is difficult to collect automatically, such as resolving dates and times.

[0081] The wider the range of data elements collected related to process safety, the more accurate the results and insights can be obtained through the stream analysis unit 32 or the batch analysis unit 41 and their respective online and offline machine learning models.

[0082] Process flow data DP is provided to the edge device data manager 34. Additionally, the edge device data manager 34 provides operation technology flow data Dot, i.e., OT flow data. OT flow data Dot includes real-time data related to process control or alarms in the industrial plant, as well as the control processes themselves performed therefrom. Enrichment unit 34c processes the OT flow data Dot, and ingestion unit 34a processes the process flow data Dp. Processing unit 34c uses these two outputs to determine flow data Ds based on the OT flow data Dot and process flow data Dp. In other words, flow data Ds is related to the process flow data Dp enriched by the OT flow data Dot. Flow data Ds is provided to the edge device storage device 33 for collecting real-time data of flow data Ds over longer time frames. Flow data Ds is also provided to the flow analysis unit 32. Flow analysis unit 32 includes an online machine learning model, also referred to as an interlocking flow operation recommender. The online machine learning model uses the provided flow data Ds to determine online analysis data Daon. In other words, the machine learning model provides machine learning insights related to safety interlocking. The online analysis data Daon is provided to the OT edge application unit 31, where it is used to determine short-term recommendations Rs, specifically through a safety interlocking application that includes a real-time monitoring and control unit and a real-time interlocking operation recommender. The short-term recommendations Rs are provided to the user U for evaluation. The user U provides online feedback Fon, which is stored in the edge device storage device 33 along with the streaming data Ds. Furthermore, the streaming analysis unit 32 uses the online feedback Fon together with the streaming data Ds to determine the online analysis data Daon.

[0083] Online feedback Fon allows user U (specifically, human experts) to accept, edit, or reject short-term machine learning-based recommendations Rs from system 10. This also applies to long-term operational recommendations R1 or re-engineered recommendations Re from cloud platform 40. Since some input elements are in the form of natural language text, such as interlock incident reports, they require processing using predefined classification criteria for interlock causes and effects (e.g., a list of plant interlock results including pump shutdown, tank overflow, etc., and a list of interlock causes including pipe blockage, motor temperature, etc.). Therefore, NLP analyzes the text input, attempting to identify any causal or consequential elements that enrich the data passed to the recommender model.

[0084] The Safety Interlock Recommendation System 10 also allows for supplier-independent input data. For example, even if the process uses the ABB 800×a control system and the Safety Instrumented System (SIS), it can collect target data from any supplier whose diversity can enhance safety. Therefore, a classic OPC server is provided for collecting data from various systems, just as is done with advanced process control (APC) solutions.

[0085] The data conduit 42 of the cloud platform 40 receives batch data Db from the edge device storage device 33. The batch data Db includes collected streaming data Ds, online feedback Fon, and online analysis data Daon. This batch data Db is provided to the cloud storage device 43 and the batch analysis unit 41 via the data conduit 42. The batch analysis unit 41 includes at least one offline machine learning model that uses the batch data Db to provide offline analysis data Daoff. In this case, the batch analysis unit 41 includes two offline machine learning models, referred to as the interlocking batch operation recommender and the interlocking batch reengineering recommender. The interlocking batch operation recommender determines the offline analysis data Daoff related to the operation of the industrial plant. Based on this offline analysis data Daoff, the cloud application unit 44 (specifically, the interlocking operation recommender) provides a long-term operation recommendation R1 to the user U. The interlocking batch reengineering recommender determines the offline analysis data Daoff related to the interlocking design itself. Based on this offline analysis data Daoff, the cloud application unit 44 (specifically, the interlocking engineering recommender) provides a reengineering recommendation Re to the user U. Based on user feedback from edge device 30, cloud application unit 44 is configured to receive offline feedback Foff from user U, who is a human operator or safety interlock engineer. Offline feedback Foff may relate to long-term operational recommendation R1 or reengineering recommendation Re. Offline feedback Foff is provided to cloud storage device 43, stored therefrom, and reassigned to batch analysis unit 41. Batch analysis unit 41 uses offline feedback Foff to determine offline analysis data Doff. Offline analysis data Doff is also provided to cloud storage device 43 for further processing. Cloud storage device 43 includes IT storage device 43a, which stores data related to interlock design (e.g., causal matrices) and input-output list data defining at least a portion of the inputs and outputs of industrial plant components. Additionally, cloud storage device 43 includes OT storage device 43b, which stores data related to operational data, safety interlock incidents, and alarm events. The cloud storage device 43 includes a recommendation storage device 43c that stores data related to the operation recommender log and the reengineering recommender log, the operation recommender log tracking previous long-term operation recommendations and the reengineering recommender log tracking previous reengineering recommendations.

[0086] In other words, cloud storage device 43 is a static safety interlock log database, which is a historical record of previous interlock situations in the plant, such as interlock start date and time, interlock resolution date and time, parent plant and process, process data, original interlock causes conforming to the C&E matrix, relevant root causes and proactive recommendations given by the ML-based system, and the severity of interlock results and result / maintenance time periods at predetermined scales.

[0087] For the interlock operation recommender, specifically the real-time interlock operation recommender and the interlock operation recommender, it promptly returns accurate predictions of when user U approaches a safety interlock event. Unlike manually configured alarm systems that generate interlock alarms based on monitoring predetermined measures, these predictions of interlock events are based on exploratory analysis of a wide range of input data elements and their associations. Short-term recommendations Rs and long-term operation recommendations R1 supplement the output of the alarm system with unseen predictions. The accessibility of an event is calculated depending on its nature. For example, the accessibility of an event with a categorical value such as changing the binary state of a safety valve (i.e., open or closed) is a purely time-based value, e.g., safety valve X closes within 20 minutes. However, the accessibility of an interlock event with a value such as the overflow state of a container (e.g., reactor Y high level = 90%) is calculated using a non-linear formula; it can be logarithmic because the accessibility of a critical safety overflow may increase at a faster rate as the threshold approaches. Along with accessibility information, the safety interlock recommendation system 10 provides proactive recommendations to user U to mitigate the effects of undesirable process downtime. The recommended mitigation measures are based on root cause analysis performed automatically by the system.

[0088] The interlock batch reengineering recommender returns recommendations to users (specifically, safety interlock designers) to improve interlock design based on long-term observations of patterns in detected root causes, safety interlock events, and interlock engineering. It can also improve the discovery of correlations between safety interlock incidents and human-related factors in incident logs (such as the operator logging the incident and the time the interlock occurred, e.g., lunch breaks, night shifts, shift changes, holiday seasons, etc.). In other words, intelligent systems analysis exhausts every possible input data, not just process-related data.

[0089] Another considered output of the safety interlock recommendation system 10 is a knowledge base in the cloud storage device 43, created by acquiring knowledge about both operational and engineering levels from human operators' responses to ML recommendations (i.e., accepting, rejecting, or editing). This acquired knowledge is then reused to relearn offline and online machine learning models and improve their performance.

[0090] The output can be presented within a safety dashboard or even integrated with a conventional alarm management system, displayed on a large screen in the control room and / or on a mobile app for user mobility. The set of operator actions for the proposed predictions and recommendations is then simply input into the computer for later batch analysis. The dashboard offers several useful features, including: presenting continuous process safety status by tracking safety interlocks or selected subsets thereof in past, current, and ML-predicted future states. It can also be considered an extension of the 800×A interlock observer. It measures and continuously presents overall process safety KPIs as quantitative metrics defined by safety experts; for example, it could be a formula based on the frequency and cost of approaching safety interlocks within a specific time period. It measures the cost of triggering safety interlocks based on the amount of time a workflow is shut down or interrupted and not operating at maximum capacity. This can be presented as a total cost trend for all safety interlocks or as a single cost trend for each selected interlock within a selected time period. It can also be presented along with information about how the intelligent system can help you improve by reducing this time-varying cost. It generates alerts for sudden, unexpected behavior of specific interlocks. This requires a baseline of default configurations or manual configuration by the user. For example, the user determines the frequency threshold for issuing interlock warnings about interlocks triggering more frequently than predicted. Even better, users can create customized warnings based on domain experience. Since the intelligent system can predict the accessibility of several interlocks at similar or close operating times, it should prioritize them according to the severity of their impact or the effort required to avoid them. Interlock reengineering recommendations should also provide similar features. Support should be provided for generating periodic reports on all analyzed information, dashboards, interlock status, etc. Users should also be able to customize the reports and how they are automatically stored on a server and / or sent via email.

[0091] Figure 4 The entire process of preparing a machine learning model for a safety interlock recommendation system 10, which is used as an operating component or a reengineered component, is described. This process is continuous, as it trains the machine learning model, uses the model in production, and enters a retraining cycle to benefit from both newly collected data, model predictions and recommendations, and feedback from human operators.

[0092] Before implementing the safety interlocking recommendation system 10, a machine learning model needs to be trained. For online machine learning models, unsupervised machine learning algorithms (e.g., Bayesian networks) are trained on available records on IT storage device 43a and OT storage device 43b. The trained algorithm produces a model that is evaluated, tested, packaged, and ultimately deployed on its intended host as the edge or cloud. It is important to validate the resulting model through a human domain expert who judges its correctness in identifying near-interlocking situations and recommended actions. Training data records can come from previous projects or currently running installations. To build an offline machine learning model for the interlocking batch reengineering recommender, the same process is repeated, but with additional data input from the recommendation storage device 43c. This includes timeout feedback from humans on the reengineered recommendations Re. The frequency of retraining the model is determined based on the monitored recommendation frequency and the feedback returned to the system.

[0093] In other words, Figure 4 Data storage device 43 is shown. Based on IT storage device 43a and OT storage device 43b, the pre-production workflow of the safety interlock recommendation system 10 is executed in steps Z1 to Z4. In step Z1, data is prepared, and in another step Z2, online and offline machine learning models are trained. In another step Z3, the machine learning models are tested. In another step Z4, the machine learning models are packaged and deployed. Subsequently, the production workflow of the safety interlock recommendation system 10 is shown in steps Z5 to Z7. In step Z5, the online and offline machine learning models provide online analysis data Daon and offline analysis data Daoff based on online data (specifically, streaming data Ds). In step Z6, short-term recommendation Rs and long-term operational recommendation R1 are provided based on online analysis data Daon and offline analysis data Daoff. In step Z7, online feedback Fon and offline feedback Foff are determined using short-term recommendation Rs and long-term operational recommendation R1. This information is then stored in the recommendation storage device 43c of cloud storage device 43.

[0094] Figure 5The operational and engineered workflow of the safety interlock recommendation system 10 is illustrated. In step Y1, process safety-related actions are continuously collected and monitored. In step Y2, an online machine learning model (specifically, a short-term recommender model) automatically analyzes the collected records to calculate the accessibility of interlock situations. In step Y3, once a specific interlock is approaching, the recommender system recommends that the operator take proactive action against the identified root cause to reverse its negative outcome. In step Y4, a human expert (i.e., a human operator) evaluates the recommendation and decides whether to accept or reject it. The decision is recorded in a database for later use to enhance the performance of the online machine learning model. Steps Y1 through Y4 are repeated. In step Y5, an offline machine learning model (specifically, an interlock batch reengineering recommender) automatically and continuously analyzes the system interlock log database to capture correlations for recurring interlock situations. This is used for automatic comparison between detected root causes and causes captured in the existing interlock design (e.g., the system's cause and effect C&E matrix). The interlock batch reengineering recommender suggests corresponding adjustments / modifications to the existing interlock design. In step Y6, human experts (i.e., safety interlock designers) evaluate the reengineering recommendations Re and decide whether to accept or reject them. As in step Y4, the decisions made are also recorded for later use in enhancing the performance of the offline machine learning model.

[0095] Figure Labels

[0096] 10 Safety Interlock Recommendation System

[0097] 20 Process Data Sources

[0098] 30 edge devices

[0099] 31OT Edge Application Unit

[0100] 32 Flow Analysis Unit

[0101] 33 Edge device storage devices

[0102] 34 Edge Device Data Manager

[0103] 34a intake unit

[0104] 34b enrichment unit

[0105] 34c processing unit

[0106] 40 Cloud Platform

[0107] 41 Batch Analysis Units

[0108] 42 Data Cable

[0109] 43 cloud storage devices

[0110] 43a IT storage device

[0111] 43b OT storage device

[0112] 43c Recommended Storage Device

[0113] 44 Cloud Application Unit

[0114] DP process flow data

[0115] Rs short-term recommendations

[0116] Recommended long-term operation of Rl

[0117] Re-engineering recommendations

[0118] C Operation Instructions

[0119] Dot Operation Techniques Flow Data

[0120] Db Batch Data

[0121] Ds stream data

[0122] Dsto stores data

[0123] Daon Online Data Analysis

[0124] Daoff offline data analysis

[0125] Fon Online Feedback

[0126] Foff offline feedback

[0127] U users

[0128] S10 provides streaming data to edge devices.

[0129] S20 provides operational technology flow data

[0130] S30 performs exploratory analysis to determine the online analytical data.

[0131] S40 determines short-term recommendations

[0132] Z1 Data Preparation

[0133] Z2 trains machine learning models.

[0134] Z3 Test Machine Learning Model

[0135] Z4 Packaging and Deployment

[0136] Z5 provides analytical data

[0137] Z6 is recommended.

[0138] Z7 Confirmed Feedback

[0139] Y1 Collection and Monitoring Process - Safety-Related Measures

[0140] Records collected by Y2 analysis

[0141] Y3 recommends proactive actions.

[0142] Y4 Accept or Reject Operation Recommendation

[0143] Y5 Analysis Database

[0144] Y6 accepts or rejects engineering recommendations

Claims

1. A safety interlock recommendation system, comprising: At least one process data source, Edge devices, The process data source is configured to provide process flow data to the edge device; the process flow data includes real-time operational data. The edge device includes an operational technology edge application unit, namely an OT edge application unit, and a flow analysis unit; The OT edge application unit is configured to provide operational technology flow data, i.e., OT flow data; wherein the OT flow data includes security-related data from the OT edge application unit. The flow analysis unit includes an online machine learning model configured to determine online analysis data using flow data including provided process flow data and provided OT flow data; The OT edge application unit is configured to use the online analytics data to determine short-term recommendations for proactive actions to avoid potential safety interlock events; The online machine learning model is configured to perform online exploratory analysis to determine the online analysis data; The online exploratory analysis mentioned above includes association mining and root cause analysis; The association mining mentioned above includes: detecting operational patterns in the streaming data; The root cause analysis includes detecting the root causes of potential safety interlock events in the streaming data.

2. The system according to claim 1, The streaming data includes dynamic time-series data that is directly related to the controlled processes in the industrial plant.

3. The system according to claim 1 or 2, comprising: cloud platform The edge device is configured to use the stored streaming data to determine batch data; The cloud platform includes a batch analysis unit and a cloud application unit; The batch analysis unit includes an offline machine learning model configured to use the batch data to determine offline analysis data. The cloud application unit is configured to use the offline analytics data to determine long-term operational recommendations.

4. The system according to claim 3, The offline machine learning model performs offline exploratory analysis to determine the offline analysis data; The offline exploratory analysis includes association mining and root cause analysis.

5. The system according to claim 3, wherein the association mining comprises: Detect the operation mode in the batch data; Furthermore, the root cause analysis includes detecting the root causes of potential safety interlock events in the batch data.

6. The system according to claim 3, The cloud platform mentioned above includes cloud storage devices. The cloud storage device is configured to provide stored data to the batch analysis unit; The stored data includes additional stored data related to the safety interlock recommendation system; The offline machine learning model is configured to use the provided stored data to determine the offline analysis data.

7. The system according to claim 3, The cloud application unit is configured to use the offline analytics data to determine reengineering recommendations; The reengineering recommendations mentioned above include potential design enhancements for existing interlocking logic.

8. The system according to claim 3, The cloud application unit is configured to use the provided storage data to determine long-term engineering recommendations and / or long-term operational recommendations.

9. The system according to claim 1 or 2, The edge device is configured to receive online user feedback regarding previous short-term recommendations; The online machine learning model is configured to be retrained using the online user feedback.

10. The system according to claim 6, The cloud storage device is configured to receive offline user feedback regarding previous long-term operational recommendations and / or previous reengineering recommendations; The offline machine learning model is configured to be retrained using the offline user feedback.

11. The system according to claim 3, The online machine learning model and / or the offline machine learning model used Bayesian networks.

12. A method for recommending safety interlocks, comprising the following steps: Process flow data is provided to edge devices by processing data sources; wherein the process flow data includes real-time operational data. The edge device includes an Operational Technology Edge Application Unit (OT Edge Application Unit) and a Flow Analysis Unit. The OT edge application unit provides operational technology flow data, i.e., OT flow data; wherein the OT flow data includes security-related data from the OT edge application unit. The online machine learning model of the flow analysis unit uses flow data, including the provided process flow data and the provided OT flow data, to determine the online analysis data. The online analytics data is used to determine short-term recommendations for proactive actions to avoid potential safety interlock events; The determination of the online analysis data through the online machine learning model includes performing online exploratory analysis to determine the online analysis data; The online exploratory analysis mentioned above includes association mining and root cause analysis; The association mining mentioned above includes: detecting operational patterns in the streaming data; The root cause analysis includes detecting the root causes of potential safety interlock events in the streaming data.

13. A computer program product comprising instructions that, when executed by a computer, cause the computer to perform the method according to claim 12.